On the Security of DES

  • Adi Shamir
Conference paper
Part of the Lecture Notes in Computer Science book series (LNCS, volume 218)


The purpose of this note is to describe some anomalies found in the structure of the S-boxes in the Data Encryption Standard. These anomalies are potentially dangerous, but so far they have not let to any successful cryptanalytic attack. While their significance is still unknown, they clearly demonstrate the deficiencies of current certification techniques and the need for provably secure cryptosystems.

