DES: How a Public Federal Cipher Became a Shared Computing Standard
Follow DES from NBS's 1973 request for algorithms through public review, FIPS 46, hardware implementation, and the limits of standardization.
The Data Encryption Standard was not simply a cipher IBM handed to the U.S. government. It was the result of a national standards process that connected a federal agency’s need for practical computer security, an industrial algorithm proposal, National Bureau of Standards evaluation, National Security Agency analysis, public comment, and eventual implementation in hardware. FIPS Publication 46, issued in 1977, gave agencies and manufacturers a common algorithm description. Its publication also made a historically important claim: an encryption standard could be public while the key remained secret.
DES became an influential example of cryptographic standardization because it turned a technical design into something organizations could procure, implement, test, and interoperate around. That success does not mean DES is suitable for protecting new data today. Its historical role and its present security status are separate questions. Its effective 56-bit key was eventually too small against modern exhaustive search, and modern cryptographic standards have superseded it.
A federal problem and an open solicitation
During the early 1970s, federal computer systems increasingly needed to protect stored and transmitted data outside the classified national-security domain. The National Bureau of Standards, now NIST, began a computer-security program and requested candidate data-encryption algorithms in May 1973. NBS repeated the request in August 1974, inviting further submissions. Its later FIPS guidance recounts that IBM developed the algorithm that met the agency’s requirements and made its specifications available for publication under nondiscriminatory, royalty-free licensing procedures for implementations.
The call for proposals was not an ordinary procurement for one custom device. A federal standard can affect agencies, manufacturers, banks, and private users, so NBS sought input from industry and user communities. The process needed a precise mathematical specification, implementable in electronic hardware, and enough technical review that a shared algorithm could be trusted outside the organization that designed it.
The submitted design grew out of IBM’s Lucifer work. Researchers including Horst Feistel, Alan Konheim, Don Coppersmith, and Walter Tuchman contributed to the design and analysis in different ways. NIST’s historical account describes the roles of IBM, NBS, and NSA personnel and names Tuchman as the primary designer of the final DES algorithm. This committee and review history is more accurate than a single-inventor story.
The specification separated algorithm from secret key
FIPS 46 defines DES as a symmetric block cipher operating on 64-bit data blocks. Its key input is also 64 bits wide, but only 56 bits select the cipher transformations. The other eight bits function as parity bits, one per byte, to detect some key-entry errors. DES enciphers and deciphers with the same shared secret key. Authorized parties must protect and distribute that secret; knowing the published algorithm is not supposed to compromise a properly managed key.
The algorithm uses an initial permutation, sixteen rounds built around a Feistel structure, a key schedule that generates a different subkey for each round, and a final permutation. Each round splits the block into left and right halves, expands part of the data, combines it with a round key, passes it through substitution boxes, permutes the result, and combines it with the other half. Decryption applies the same structure with the subkeys in reverse order. DES’s bit-level operations made a direct hardware implementation practical in the era when dedicated cryptographic chips were common.
The detailed FIPS publication is useful evidence because it specifies the algorithm independently of a particular product. A vendor can construct a chip or software implementation from the same transformation and obtain interoperable ciphertext, assuming the same key and block handling. The standard did not prescribe how every system should authenticate users, store keys, format messages, or operate an entire communications protocol. DES is one primitive, not a complete security architecture.
Public review and the controversy around NSA analysis
NBS published the proposed algorithm for review in 1975. The NSA examined the design and recommended changes before final adoption. Public critics questioned the reduced key length compared with IBM’s earlier proposal and the fact that S-box details had been altered. They worried the changes might conceal a trapdoor or weaken the cipher for government access.
Those concerns are historical facts about the standard’s reception; they are not proof that DES contained a secret backdoor. IBM and government officials did not initially disclose all the cryptanalytic reasoning behind S-box design. In a 1994 IBM Journal of Research and Development paper, DES designer Don Coppersmith explained that design criteria for the S-boxes were developed to resist differential cryptanalysis, a technique later published by Eli Biham and Adi Shamir. That changed the retrospective picture: the secrecy around design choices helped fuel distrust, while those choices strengthened resistance to a powerful attack that was not publicly understood at the time.
The 1970s review illustrates a recurring standards problem. A standard must make enough information public for independent analysis, yet government participants may possess classified knowledge. If the reasoning behind a design change is withheld, users must decide whether to trust the process rather than verify its claims. Transparency is not only a political nicety; it is a technical resource that enables experts to detect flaws and evaluate trade-offs.
FIPS 46 made implementation and procurement repeatable
NBS issued FIPS PUB 46 in January 1977, and the DES became a federal standard for specified non-classified data-protection applications. NIST’s later history says it was adopted as an ANSI standard in 1981 and became widely used in financial services. A common reference let equipment makers offer compatible cryptographic modules and gave government purchasers a way to state a requirement precisely.
Hardware was a natural implementation target. DES’s bit permutations and substitution operations could be optimized as circuits, and dedicated chips could encrypt faster than general-purpose software on contemporary processors. Hardware also created its own operational requirements: a correct implementation still needed a protected key, controlled access, reliable random key generation, and a way to rotate or retire keys. A standard algorithm does not rescue an organization that writes the key on a label or reuses it beyond policy.
Interoperability depended on more than implementing the round function. Systems also had to agree on how 64-bit blocks were formed, what mode of operation was used, how padding worked, and whether an integrity mechanism accompanied encryption. FIPS 46 specifies DES itself; related standards and application protocols handled additional framing and operational requirements. This is why cipher names should not be used as synonyms for complete secure communication.
Revisions tracked a changing threat model
DES was periodically reviewed and revised. The core problem was the fixed effective key length. A 56-bit key represents 2^56 possible combinations. That number was immense when the standard was adopted but could be searched by purpose-built parallel hardware decades later. In 1998, the Electronic Frontier Foundation demonstrated a DES-cracking machine that found the challenge key after 56 hours of search. The fact that exhaustive search was achievable did not imply that all ciphertext was automatically exposed; an attacker still needed the encrypted material and a useful method to recognize a correct decryption. But the key size had ceased to provide an acceptable margin for new sensitive use.
Triple DES applied DES multiple times with multiple keys to raise the work required for exhaustive search while reusing interoperable hardware. It became a transition technology, not a permanent solution: multiple passes reduced throughput, and its 64-bit block size created limits for large-volume use. The Advanced Encryption Standard competition selected Rijndael, and AES offered larger keys and 128-bit blocks with more efficient implementations. NIST eventually withdrew DES for federal use and later moved Triple DES toward disallowing new protection. Those later decisions are evidence that standards must respond to available attack costs and deployment experience.
Today the FIPS 46 document should be read as a historical artifact, not as current advice to deploy single DES. NIST’s transition guidance now disallows TDEA encryption in new applications, while allowing limited legacy decryption of previously protected data. New systems should use contemporary, vetted cryptographic libraries and protocols rather than implementing historical algorithms themselves. The useful lesson is how a public specification can organize a broad implementation ecosystem, and how a standard’s authority must remain conditional on review of its security assumptions.
What the DES story teaches about standards
DES unified implementation and procurement around one public mathematical object. That made encryption more widely available than bespoke proprietary schemes. Its history also exposes the costs of opaque review: delayed disclosure of cryptanalytic reasoning invited suspicions that could not be settled by the public specification alone. Subsequent research, government declassification, and later key-search demonstrations expanded the evidence available to assess it.
A standard is neither a guarantee of secrecy nor a timeless verdict that a design is safe. It defines a version of a technical agreement. Operators still manage keys and protocols, implementers still need tests and side-channel protections, and reviewers must examine whether the threat model has changed. The DES process mattered because it made these questions visible to an expanding research community. Its eventual obsolescence does not erase its contribution to open cryptographic engineering.
Related:
- Public-Key Cryptography: From Classified Prehistory to Diffie-Hellman and RSA
- PGP and OpenPGP: From 1991 Software to a Shared Message Format
Sources:
- NBS FIPS PUB 46, Data Encryption Standard (1977)
- NBS FIPS PUB 74, Guidelines for Implementing and Using the NBS Data Encryption Standard
- NIST, A Century of Excellence in Measurements, Standards, and Technology, DES history
- NIST, FIPS 46-3 archive and withdrawal notice
- NIST SP 800-131A Revision 2, transition rules for DES-era TDEA
- Don Coppersmith, “The Data Encryption Standard (DES) and its strength against attacks” (IBM Journal of Research and Development, 1994)
- Electronic Frontier Foundation, DES Cracker challenge log and key-search details