[{"data":1,"prerenderedAt":583},["ShallowReactive",2],{"navigation_docs":3,"-ciphers-idea":204,"-ciphers-idea-surround":578},[4,36],{"title":5,"path":6,"stem":7,"children":8,"icon":35},"Guide","\u002Fguide","1.guide\u002F01.index",[9,11,15,19,23,27,31],{"title":10,"path":6,"stem":7},"Getting Started",{"title":12,"path":13,"stem":14},"Encode and decode","\u002Fguide\u002Ftransform","1.guide\u002F02.transform",{"title":16,"path":17,"stem":18},"Analysis","\u002Fguide\u002Fanalysis","1.guide\u002F03.analysis",{"title":20,"path":21,"stem":22},"CLI","\u002Fguide\u002Fcli","1.guide\u002F04.cli",{"title":24,"path":25,"stem":26},"Agents","\u002Fguide\u002Fagents","1.guide\u002F05.agents",{"title":28,"path":29,"stem":30},"Custom ciphers","\u002Fguide\u002Fcustom","1.guide\u002F06.custom",{"title":32,"path":33,"stem":34},"Playground","\u002Fguide\u002Fplayground","1.guide\u002F07.playground","i-solar-book-2-linear",{"title":37,"path":38,"stem":39,"children":40,"icon":203},"Ciphers","\u002Fciphers","2.ciphers\u002F00.index",[41,43,47,51,55,59,63,67,71,75,79,83,87,91,95,99,103,107,111,115,119,123,127,131,135,139,143,147,151,155,159,163,167,171,175,179,183,187,191,195,199],{"title":42,"path":38,"stem":39},"Overview",{"title":44,"path":45,"stem":46},"Caesar","\u002Fciphers\u002Fcaesar","2.ciphers\u002F01.caesar",{"title":48,"path":49,"stem":50},"ROT-13","\u002Fciphers\u002Frot13","2.ciphers\u002F02.rot13",{"title":52,"path":53,"stem":54},"ROT-47","\u002Fciphers\u002Frot47","2.ciphers\u002F03.rot47",{"title":56,"path":57,"stem":58},"Atbash","\u002Fciphers\u002Fatbash","2.ciphers\u002F04.atbash",{"title":60,"path":61,"stem":62},"Affine","\u002Fciphers\u002Faffine","2.ciphers\u002F05.affine",{"title":64,"path":65,"stem":66},"Vigenère","\u002Fciphers\u002Fvigenere","2.ciphers\u002F06.vigenere",{"title":68,"path":69,"stem":70},"Trithemius","\u002Fciphers\u002Ftrithemius","2.ciphers\u002F07.trithemius",{"title":72,"path":73,"stem":74},"Alberti","\u002Fciphers\u002Falberti","2.ciphers\u002F08.alberti",{"title":76,"path":77,"stem":78},"Playfair","\u002Fciphers\u002Fplayfair","2.ciphers\u002F09.playfair",{"title":80,"path":81,"stem":82},"Polybius square","\u002Fciphers\u002Fpolybius","2.ciphers\u002F10.polybius",{"title":84,"path":85,"stem":86},"Morse code","\u002Fciphers\u002Fmorse","2.ciphers\u002F11.morse",{"title":88,"path":89,"stem":90},"Bacon's cipher","\u002Fciphers\u002Fbacon","2.ciphers\u002F12.bacon",{"title":92,"path":93,"stem":94},"Tap code","\u002Fciphers\u002Ftap-code","2.ciphers\u002F13.tap-code",{"title":96,"path":97,"stem":98},"ADFGVX","\u002Fciphers\u002Fadfgvx","2.ciphers\u002F14.adfgvx",{"title":100,"path":101,"stem":102},"Bifid","\u002Fciphers\u002Fbifid","2.ciphers\u002F15.bifid",{"title":104,"path":105,"stem":106},"Rail fence","\u002Fciphers\u002Frail-fence","2.ciphers\u002F16.rail-fence",{"title":108,"path":109,"stem":110},"Columnar transposition","\u002Fciphers\u002Fcolumnar","2.ciphers\u002F17.columnar",{"title":112,"path":113,"stem":114},"Enigma M3","\u002Fciphers\u002Fenigma","2.ciphers\u002F18.enigma",{"title":116,"path":117,"stem":118},"Beaufort","\u002Fciphers\u002Fbeaufort","2.ciphers\u002F19.beaufort",{"title":120,"path":121,"stem":122},"Autokey","\u002Fciphers\u002Fautokey","2.ciphers\u002F20.autokey",{"title":124,"path":125,"stem":126},"AES (ECB)","\u002Fciphers\u002Faes","2.ciphers\u002F21.aes",{"title":128,"path":129,"stem":130},"Triple DES (ECB)","\u002Fciphers\u002Ftriple-des","2.ciphers\u002F22.triple-des",{"title":132,"path":133,"stem":134},"AES (LRW)","\u002Fciphers\u002Faes-lrw","2.ciphers\u002F23.aes-lrw",{"title":136,"path":137,"stem":138},"AES (CBC)","\u002Fciphers\u002Faes-cbc","2.ciphers\u002F24.aes-cbc",{"title":140,"path":141,"stem":142},"AES (CFB)","\u002Fciphers\u002Faes-cfb","2.ciphers\u002F25.aes-cfb",{"title":144,"path":145,"stem":146},"AES (CTR)","\u002Fciphers\u002Faes-ctr","2.ciphers\u002F26.aes-ctr",{"title":148,"path":149,"stem":150},"AES (CCM)","\u002Fciphers\u002Faes-ccm","2.ciphers\u002F27.aes-ccm",{"title":152,"path":153,"stem":154},"AES (OFB)","\u002Fciphers\u002Faes-ofb","2.ciphers\u002F28.aes-ofb",{"title":156,"path":157,"stem":158},"AES (OCB)","\u002Fciphers\u002Faes-ocb","2.ciphers\u002F29.aes-ocb",{"title":160,"path":161,"stem":162},"Triple DES (CBC)","\u002Fciphers\u002Ftriple-des-cbc","2.ciphers\u002F30.triple-des-cbc",{"title":164,"path":165,"stem":166},"Rijndael (ECB)","\u002Fciphers\u002Frijndael","2.ciphers\u002F31.rijndael",{"title":168,"path":169,"stem":170},"AES (XTS)","\u002Fciphers\u002Faes-xts","2.ciphers\u002F32.aes-xts",{"title":172,"path":173,"stem":174},"AES (CBC-MAC)","\u002Fciphers\u002Faes-cbc-mac","2.ciphers\u002F33.aes-cbc-mac",{"title":176,"path":177,"stem":178},"Blowfish (ECB)","\u002Fciphers\u002Fblowfish","2.ciphers\u002F34.blowfish",{"title":180,"path":181,"stem":182},"DES (ECB)","\u002Fciphers\u002Fdes","2.ciphers\u002F35.des",{"title":184,"path":185,"stem":186},"DESX (ECB)","\u002Fciphers\u002Fdesx","2.ciphers\u002F36.desx",{"title":188,"path":189,"stem":190},"IDEA (ECB)","\u002Fciphers\u002Fidea","2.ciphers\u002F37.idea",{"title":192,"path":193,"stem":194},"Lucifer (ECB)","\u002Fciphers\u002Flucifer","2.ciphers\u002F38.lucifer",{"title":196,"path":197,"stem":198},"MARS (ECB)","\u002Fciphers\u002Fmars","2.ciphers\u002F39.mars",{"title":200,"path":201,"stem":202},"Serpent (ECB)","\u002Fciphers\u002Fserpent","2.ciphers\u002F40.serpent","i-solar-library-linear",{"id":205,"title":188,"body":206,"description":571,"extension":572,"links":573,"meta":574,"navigation":575,"path":189,"seo":576,"stem":190,"__hash__":577},"docs\u002F2.ciphers\u002F37.idea.md",{"type":207,"value":208,"toc":567},"minimark",[209,213,217,220,243,246,258,393,396,464,467,472,475,478,481,485,492,539,542,563],[210,211],"cipher-facts",{"name":212},"idea",[214,215,216],"p",{},"Xuejia Lai and James Massey built it at ETH Zurich. The first version from 1990 was called PES. Then differential cryptanalysis went public, they hardened the rounds and called it IPES, and in 1992 it became IDEA. Phil Zimmermann put it into PGP 2.0 in place of BassOmatic, his own cipher from PGP 1.0, which didn't hold up. The patents ran out in 2011 and now anyone can use it.",[214,218,219],{},"What makes IDEA odd is that it has no tables at all. Every 64-bit block is four 16-bit words, and a round mixes them with three operations that don't get along with each other:",[221,222,223,231,237],"ul",{},[224,225,226,230],"li",{},[227,228,229],"code",{},"⊕"," XOR,",[224,232,233,236],{},[227,234,235],{},"⊞"," addition modulo 2^16,",[224,238,239,242],{},[227,240,241],{},"⊙"," multiplication modulo 2^16 + 1, which is prime, so every word has an inverse. The word 0 stands for 2^16 there.",[214,244,245],{},"No two of them are distributive or associative with each other, and that's the whole trick. Eight rounds of that, then a half round that only multiplies and adds, so papers write 8.5 rounds. The 128-bit key gets cut into 52 subkeys of 16 bits: eight straight from the key, then the key rotates left by 25 bits and gets cut again. Decryption runs the same rounds with the inverted subkeys in reverse order.",[214,247,248,249,252,253,257],{},"The key is 32 hex digits. Case doesn't matter and spaces are ignored. Text goes in as UTF-8 with PKCS#7 padding, ciphertext comes out as lowercase hex, and ",[227,250,251],{},"decode"," wants hex back. The mode is ECB, the same as ",[254,255,256],"a",{"href":177},"Blowfish",".",[259,260,265],"pre",{"className":261,"code":262,"language":263,"meta":264,"style":264},"language-ts shiki shiki-themes github-light github-light poimandres","const idea = create(\"idea\");\nconst key = \"0001 0002 0003 0004 0005 0006 0007 0008\";\nidea.encode(\"ATTACK AT DAWN\", { key }).text; \u002F\u002F \"1e79aa86c8a1f33bd0182e2668bd0bf6\"\nidea.decode(\"1e79aa86c8a1f33bd0182e2668bd0bf6\", { key }).text; \u002F\u002F \"ATTACK AT DAWN\"\n","ts","",[227,266,267,303,324,362],{"__ignoreMap":264},[268,269,272,276,280,283,287,291,295,298,300],"span",{"class":270,"line":271},"line",1,[268,273,275],{"class":274},"s1TYA","const",[268,277,279],{"class":278},"saoiD"," idea",[268,281,282],{"class":274}," =",[268,284,286],{"class":285},"sULi6"," create",[268,288,290],{"class":289},"sKlNE","(",[268,292,294],{"class":293},"scVjq","\"",[268,296,212],{"class":297},"sQ7BG",[268,299,294],{"class":293},[268,301,302],{"class":289},");\n",[268,304,306,308,311,313,316,319,321],{"class":270,"line":305},2,[268,307,275],{"class":274},[268,309,310],{"class":278}," key",[268,312,282],{"class":274},[268,314,315],{"class":293}," \"",[268,317,318],{"class":297},"0001 0002 0003 0004 0005 0006 0007 0008",[268,320,294],{"class":293},[268,322,323],{"class":289},";\n",[268,325,327,330,332,335,337,339,342,344,347,349,352,355,358],{"class":270,"line":326},3,[268,328,212],{"class":329},"spVlQ",[268,331,257],{"class":289},[268,333,334],{"class":285},"encode",[268,336,290],{"class":289},[268,338,294],{"class":293},[268,340,341],{"class":297},"ATTACK AT DAWN",[268,343,294],{"class":293},[268,345,346],{"class":289},", {",[268,348,310],{"class":329},[268,350,351],{"class":289}," }).",[268,353,354],{"class":329},"text",[268,356,357],{"class":289},"; ",[268,359,361],{"class":360},"sjhu3","\u002F\u002F \"1e79aa86c8a1f33bd0182e2668bd0bf6\"\n",[268,363,365,367,369,371,373,375,378,380,382,384,386,388,390],{"class":270,"line":364},4,[268,366,212],{"class":329},[268,368,257],{"class":289},[268,370,251],{"class":285},[268,372,290],{"class":289},[268,374,294],{"class":293},[268,376,377],{"class":297},"1e79aa86c8a1f33bd0182e2668bd0bf6",[268,379,294],{"class":293},[268,381,346],{"class":289},[268,383,310],{"class":329},[268,385,351],{"class":289},[268,387,354],{"class":329},[268,389,357],{"class":289},[268,391,392],{"class":360},"\u002F\u002F \"ATTACK AT DAWN\"\n",[214,394,395],{},"That key is the one from Lai's thesis example. OpenSSL still has IDEA, but only in the legacy provider:",[259,397,401],{"className":398,"code":399,"language":400,"meta":264,"style":264},"language-bash shiki shiki-themes github-light github-light poimandres","printf %s \"ATTACK AT DAWN\" | openssl enc -idea-ecb -provider legacy -provider default -K 00010002000300040005000600070008 | xxd -p\n# 1e79aa86c8a1f33bd0182e2668bd0bf6\n","bash",[227,402,403,459],{"__ignoreMap":264},[268,404,405,409,413,415,417,419,422,426,429,433,436,439,441,444,447,451,453,456],{"class":270,"line":271},[268,406,408],{"class":407},"s39Ir","printf",[268,410,412],{"class":411},"sX7Zv"," %s",[268,414,315],{"class":293},[268,416,341],{"class":297},[268,418,294],{"class":293},[268,420,421],{"class":274}," |",[268,423,425],{"class":424},"sseY5"," openssl",[268,427,428],{"class":411}," enc",[268,430,432],{"class":431},"sqT1Y"," -idea-ecb",[268,434,435],{"class":431}," -provider",[268,437,438],{"class":411}," legacy",[268,440,435],{"class":431},[268,442,443],{"class":411}," default",[268,445,446],{"class":431}," -K",[268,448,450],{"class":449},"siHFe"," 00010002000300040005000600070008",[268,452,421],{"class":274},[268,454,455],{"class":424}," xxd",[268,457,458],{"class":431}," -p\n",[268,460,461],{"class":270,"line":305},[268,462,463],{"class":360},"# 1e79aa86c8a1f33bd0182e2668bd0bf6\n",[214,465,466],{},"The tests check eleven vectors from Botan 2, including the thesis example and the all-zero key, where every subkey is 0 and so every multiplication is by 2^16. Whole texts are checked against OpenSSL.",[468,469,471],"h2",{"id":470},"how-strong-is-it","How strong is it",[214,473,474],{},"For a cipher from 1991, surprisingly. The best attack on all 8.5 rounds is the biclique one by Khovratovich, Leurent and Rechberger from 2012, about 2^126 work instead of 2^128. That's a paper result, not a way in.",[214,476,477],{},"The weak spot is the key schedule. It's plain rotation, so a key with long runs of zero bits gives subkeys of 0 or 1, and multiplying by 1 changes nothing. Whole classes of such weak keys are known. With a random key the chance of hitting one is negligible, but a key someone typed by hand is a different story.",[214,479,480],{},"The block is only 64 bits too. After about 2^32 blocks under one key, collisions start to show up, the same thing that took down Triple DES and Blowfish in Sweet32.",[468,482,484],{"id":483},"why-ecb-leaks","Why ECB leaks",[214,486,487,488,491],{},"Same as every ECB here. Sixteen ",[227,489,490],{},"A","s are two equal blocks, and they come out as two equal blocks:",[259,493,495],{"className":261,"code":494,"language":263,"meta":264,"style":264},"idea.encode(\"A\".repeat(16), { key }).text;\n\u002F\u002F 14e5708749b11c09 14e5708749b11c09 46e751f52a939266\n",[227,496,497,534],{"__ignoreMap":264},[268,498,499,501,503,505,507,509,511,513,515,518,520,523,526,528,530,532],{"class":270,"line":271},[268,500,212],{"class":329},[268,502,257],{"class":289},[268,504,334],{"class":285},[268,506,290],{"class":289},[268,508,294],{"class":293},[268,510,490],{"class":297},[268,512,294],{"class":293},[268,514,257],{"class":289},[268,516,517],{"class":285},"repeat",[268,519,290],{"class":289},[268,521,522],{"class":449},"16",[268,524,525],{"class":289},"), {",[268,527,310],{"class":329},[268,529,351],{"class":289},[268,531,354],{"class":329},[268,533,323],{"class":289},[268,535,536],{"class":270,"line":305},[268,537,538],{"class":360},"\u002F\u002F 14e5708749b11c09 14e5708749b11c09 46e751f52a939266\n",[214,540,541],{},"Spaces added to show the blocks. The last one is only padding.",[214,543,544,545,548,549,552,553,555,556,559,560,562],{},"A key that isn't 32 hex digits is an ",[227,546,547],{},"InvalidOptionError",", a missing one a ",[227,550,551],{},"MissingOptionError",". On ",[227,554,251],{},", ciphertext that isn't whole 8-byte blocks of hex is a ",[227,557,558],{},"CipherError",". A wrong key almost always breaks the padding, and that's a ",[227,561,558],{}," too. So are decrypted bytes that aren't UTF-8. This one is plain TypeScript on 16-bit words, and the multiplication is not constant time. Puzzles and learning, not secrets.",[564,565,566],"style",{},"html pre.shiki code .s1TYA, html code.shiki .s1TYA{--shiki-light:#D73A49;--shiki-default:#D73A49;--shiki-dark:#91B4D5}html pre.shiki code .saoiD, html code.shiki .saoiD{--shiki-light:#005CC5;--shiki-default:#005CC5;--shiki-dark:#E4F0FB}html pre.shiki code .sULi6, html code.shiki .sULi6{--shiki-light:#6F42C1;--shiki-default:#6F42C1;--shiki-dark:#E4F0FBD0}html pre.shiki code .sKlNE, html code.shiki .sKlNE{--shiki-light:#24292E;--shiki-default:#24292E;--shiki-dark:#A6ACCD}html pre.shiki code .scVjq, html code.shiki .scVjq{--shiki-light:#032F62;--shiki-default:#032F62;--shiki-dark:#A6ACCD}html pre.shiki code .sQ7BG, html code.shiki .sQ7BG{--shiki-light:#032F62;--shiki-default:#032F62;--shiki-dark:#5DE4C7}html pre.shiki code .spVlQ, html code.shiki .spVlQ{--shiki-light:#24292E;--shiki-default:#24292E;--shiki-dark:#E4F0FB}html pre.shiki code .sjhu3, html code.shiki .sjhu3{--shiki-light:#6A737D;--shiki-light-font-style:inherit;--shiki-default:#6A737D;--shiki-default-font-style:inherit;--shiki-dark:#767C9DB0;--shiki-dark-font-style:italic}html .light .shiki span {color: var(--shiki-light);background: var(--shiki-light-bg);font-style: var(--shiki-light-font-style);font-weight: var(--shiki-light-font-weight);text-decoration: var(--shiki-light-text-decoration);}html.light .shiki span {color: var(--shiki-light);background: var(--shiki-light-bg);font-style: var(--shiki-light-font-style);font-weight: var(--shiki-light-font-weight);text-decoration: var(--shiki-light-text-decoration);}html .default .shiki span {color: var(--shiki-default);background: var(--shiki-default-bg);font-style: var(--shiki-default-font-style);font-weight: var(--shiki-default-font-weight);text-decoration: var(--shiki-default-text-decoration);}html .shiki span {color: var(--shiki-default);background: var(--shiki-default-bg);font-style: var(--shiki-default-font-style);font-weight: var(--shiki-default-font-weight);text-decoration: var(--shiki-default-text-decoration);}html .dark .shiki span {color: var(--shiki-dark);background: var(--shiki-dark-bg);font-style: var(--shiki-dark-font-style);font-weight: var(--shiki-dark-font-weight);text-decoration: var(--shiki-dark-text-decoration);}html.dark .shiki span {color: var(--shiki-dark);background: var(--shiki-dark-bg);font-style: var(--shiki-dark-font-style);font-weight: var(--shiki-dark-font-weight);text-decoration: var(--shiki-dark-text-decoration);}html pre.shiki code .s39Ir, html code.shiki .s39Ir{--shiki-light:#005CC5;--shiki-default:#005CC5;--shiki-dark:#91B4D5}html pre.shiki code .sX7Zv, html code.shiki .sX7Zv{--shiki-light:#032F62;--shiki-default:#032F62;--shiki-dark:#ADD7FF}html pre.shiki code .sseY5, html code.shiki .sseY5{--shiki-light:#6F42C1;--shiki-default:#6F42C1;--shiki-dark:#91B4D5}html pre.shiki code .sqT1Y, html code.shiki .sqT1Y{--shiki-light:#005CC5;--shiki-default:#005CC5;--shiki-dark:#ADD7FF}html pre.shiki code .siHFe, html code.shiki .siHFe{--shiki-light:#005CC5;--shiki-default:#005CC5;--shiki-dark:#5DE4C7}",{"title":264,"searchDepth":305,"depth":305,"links":568},[569,570],{"id":470,"depth":305,"text":471},{"id":483,"depth":305,"text":484},"Lai and Massey's cipher from early PGP. No S-boxes, just XOR, addition and multiplication on 16-bit words under a 128-bit key. UTF-8 text in, hex out.","md",null,{},true,{"title":188,"description":571},"_UMly4vQ-spMd91xmi7gitXh7zzpnPHNISE5aFqJ2d4",[579,581],{"title":184,"path":185,"stem":186,"description":580,"children":-1},"Rivest's cheap fix for the DES key, one XOR before and one after. Same speed as DES, 184 key bits, UTF-8 text in, hex out.",{"title":192,"path":193,"stem":194,"description":582,"children":-1},"The IBM cipher DES was cut down from, as Arthur Sorkin published it in 1984. Sixteen Feistel rounds, two 4-bit S-boxes, 128-bit blocks and keys. UTF-8 text in, hex out.",1790332462864]