Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

DES encrypts data one 64-bit block at a time using a key encoded in 64 bits, but only 56 of those bits contribute to the encryption. It is now obsolete for protecting information: NIST withdrew the DES standard in 2005 and later ended approval of 3DES/TDEA for applying new protection. DES remains useful to understand as a historical cipher and a teaching example, not as a current security choice.

What DES does

DES, short for Data Encryption Standard, is a symmetric block cipher: the same secret key is used to encrypt and decrypt data. Its underlying encryption engine is called the Data Encryption Algorithm (DEA) in NIST’s TDEA specification. DES takes a 64-bit plaintext block and transforms it into a 64-bit ciphertext block.

The key is also represented as 64 bits, but that figure can be misleading. NIST’s description specifies 56 randomly generated bits used by the algorithm and eight additional bits that are not used in the encryption computation; those bits may be set to odd parity. The parity bits do not add cryptographic strength. NIST SP 800-67 Rev. 2 describes the DEA engine’s block and key dimensions.

A block cipher’s core transformation is not the same thing as a complete way to encrypt a file or message. A mode of operation determines how a cipher is applied across multiple blocks. The DES block transformation alone does not specify a mode, and the fact that DES can be described or implemented for study does not make it suitable for present-day protection.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

How the DES algorithm processes a block

At a high level, DES applies an initial permutation to the input, performs a key-dependent computation, and then applies the inverse permutation to produce the output. The central computation uses a key schedule and a function called f; the key schedule derives the round-specific material used during processing. The permutations help define the algorithm’s structure, but they should not be mistaken for the source of meaningful security on their own. NIST’s technical description of DEA specifies these stages.

  1. Input: The cipher receives one 64-bit plaintext block and the encoded 64-bit key, of which 56 bits are algorithm key material.
  2. Initial permutation: The input bits are rearranged according to a fixed permutation.
  3. Key-dependent computation: The algorithm processes the permuted block using the key schedule and function f.
  4. Output permutation: The inverse permutation is applied, yielding a 64-bit ciphertext block.

This outline explains the shape of DES without treating a historical algorithm description as a recommendation. In particular, it does not address how to securely package or protect modern data.

Is DES encryption still secure?

No. NIST withdrew FIPS 46-3, the DES standard, on May 19, 2005. The standard had been published on October 25, 1999. In its withdrawal announcement, NIST said: “These FIPS are withdrawn because FIPS 46-3, DES, no longer provides the security that is needed to protect Federal government information.” The statement is NIST’s dated rationale for withdrawing the federal standard, not a claim that DES became insecure on one particular day. See the NIST withdrawal announcement and FIPS 46-3 publication record.

The small 56-bit algorithm key is a central reason not to rely on DES for current protection. Its historical significance and straightforward structure make it useful in cryptography education, but those qualities do not compensate for its obsolete security status. Do not choose DES for new encryption or other current protection needs.

Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

How DES compares with 3DES/TDEA and AES

3DES, also called Triple DES or TDEA, combines operations using the DES/DEA engine. NIST describes TDEA as an interim replacement for DEA, but repeating DES operations did not make TDEA a lasting modern recommendation. AES is the NIST-backed migration comparison.

Aspect DES / DEA TDEA / 3DES AES context
Block size 64 bits, according to NIST’s DEA specification. 64 bits; NIST warns about collision limits for this block size. NIST identifies AES’s block size as 128 bits.
Standards status FIPS 46-3 was withdrawn in 2005. NIST withdrew SP 800-67 Rev. 2 effective January 1, 2024; TDEA is no longer approved for applying protection under the cited policy. NIST encouraged AES as the replacement in its 2005 DES withdrawal notice.
Practical takeaway Historical or educational study only. Legacy processing only where NIST’s transition guidance permits it. The modern migration direction in the cited NIST guidance.

NIST’s 2005 notice characterized AES as faster and stronger than DES. That is a dated statement in the context of the DES withdrawal announcement, not a general performance comparison across all implementations or platforms. NIST’s notice is the source for that characterization.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Why 3DES is not a current substitute

Although TDEA combines DES operations, it retains a 64-bit block size. In a July 11, 2017 notice, NIST explained that ciphertext collisions become likely at about 232 blocks encrypted under one TDEA key bundle. Such a collision can reveal information about corresponding plaintext blocks. This is a TDEA and 64-bit-block limitation; it should not be presented as a precise attack threshold for DES alone. NIST said the issue helped motivate AES’s 128-bit block size and urged TDEA users to migrate to AES. See NIST’s TDEA update.

NIST’s transition ended TDEA’s role in applying new protection after December 31, 2023. Since January 1, 2024, TDEA is no longer approved for that purpose under the withdrawn SP 800-67 Rev. 2. NIST’s 2023 notice still allows specified processing of data that was already protected, including decryption, key unwrapping, and MAC verification. Those are limited legacy operations, not permission to start protecting new data with TDEA. Details are in NIST’s withdrawal notice.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

What to use DES knowledge for

  • Learning: Use DES to study the structure of a classic block cipher, including permutations, key scheduling, and the distinction between a cipher’s block size and key size.
  • Historical or legacy analysis: Treat DES and TDEA as legacy algorithms. Any permitted processing of previously protected data should follow the applicable organizational and NIST guidance.
  • New protection: Do not deploy DES or TDEA. NIST’s cited guidance points users toward AES; select and configure a currently approved implementation and mode appropriate to the application.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.