IBM's original S-Boxes for DES?

Steven M. Bellovin smb at
Thu Sep 30 12:25:20 EDT 2004

In message <1096535230.415bccbe98ef6 at>, Nicolai Moles
-Benfell writes:
>A number of sources state that the NSA changed the S-Boxes (and reduced the ke
>size) of IBM's original DES submission, and that these change were made to
>strengthen the cipher against differential/linear/?? cryptanalysis.
>Does anybody have a reference to, or have an electronic copy of these original

It was only to protect against differential cryptanalysis; they did not 
know about linear cryptanalysis.  See Don Coppersmith, The Data Encryption
Standard (DES) and its strength against attacks, IBM Journal of Research
and Development, Vol. 38, n. 3, pp. 243-250, May 1994.

		--Steve Bellovin,

The Cryptography Mailing List
Unsubscribe by sending "unsubscribe cryptography" to majordomo at

More information about the cryptography mailing list