[{"data":1,"prerenderedAt":546},["ShallowReactive",2],{"navigation_docs":3,"-ciphers-serpent":204,"-ciphers-serpent-surround":543},[4,36],{"title":5,"path":6,"stem":7,"children":8,"icon":35},"Guide","\u002Fguide","1.guide\u002F01.index",[9,11,15,19,23,27,31],{"title":10,"path":6,"stem":7},"Getting Started",{"title":12,"path":13,"stem":14},"Encode and decode","\u002Fguide\u002Ftransform","1.guide\u002F02.transform",{"title":16,"path":17,"stem":18},"Analysis","\u002Fguide\u002Fanalysis","1.guide\u002F03.analysis",{"title":20,"path":21,"stem":22},"CLI","\u002Fguide\u002Fcli","1.guide\u002F04.cli",{"title":24,"path":25,"stem":26},"Agents","\u002Fguide\u002Fagents","1.guide\u002F05.agents",{"title":28,"path":29,"stem":30},"Custom ciphers","\u002Fguide\u002Fcustom","1.guide\u002F06.custom",{"title":32,"path":33,"stem":34},"Playground","\u002Fguide\u002Fplayground","1.guide\u002F07.playground","i-solar-book-2-linear",{"title":37,"path":38,"stem":39,"children":40,"icon":203},"Ciphers","\u002Fciphers","2.ciphers\u002F00.index",[41,43,47,51,55,59,63,67,71,75,79,83,87,91,95,99,103,107,111,115,119,123,127,131,135,139,143,147,151,155,159,163,167,171,175,179,183,187,191,195,199],{"title":42,"path":38,"stem":39},"Overview",{"title":44,"path":45,"stem":46},"Caesar","\u002Fciphers\u002Fcaesar","2.ciphers\u002F01.caesar",{"title":48,"path":49,"stem":50},"ROT-13","\u002Fciphers\u002Frot13","2.ciphers\u002F02.rot13",{"title":52,"path":53,"stem":54},"ROT-47","\u002Fciphers\u002Frot47","2.ciphers\u002F03.rot47",{"title":56,"path":57,"stem":58},"Atbash","\u002Fciphers\u002Fatbash","2.ciphers\u002F04.atbash",{"title":60,"path":61,"stem":62},"Affine","\u002Fciphers\u002Faffine","2.ciphers\u002F05.affine",{"title":64,"path":65,"stem":66},"Vigenère","\u002Fciphers\u002Fvigenere","2.ciphers\u002F06.vigenere",{"title":68,"path":69,"stem":70},"Trithemius","\u002Fciphers\u002Ftrithemius","2.ciphers\u002F07.trithemius",{"title":72,"path":73,"stem":74},"Alberti","\u002Fciphers\u002Falberti","2.ciphers\u002F08.alberti",{"title":76,"path":77,"stem":78},"Playfair","\u002Fciphers\u002Fplayfair","2.ciphers\u002F09.playfair",{"title":80,"path":81,"stem":82},"Polybius square","\u002Fciphers\u002Fpolybius","2.ciphers\u002F10.polybius",{"title":84,"path":85,"stem":86},"Morse code","\u002Fciphers\u002Fmorse","2.ciphers\u002F11.morse",{"title":88,"path":89,"stem":90},"Bacon's cipher","\u002Fciphers\u002Fbacon","2.ciphers\u002F12.bacon",{"title":92,"path":93,"stem":94},"Tap code","\u002Fciphers\u002Ftap-code","2.ciphers\u002F13.tap-code",{"title":96,"path":97,"stem":98},"ADFGVX","\u002Fciphers\u002Fadfgvx","2.ciphers\u002F14.adfgvx",{"title":100,"path":101,"stem":102},"Bifid","\u002Fciphers\u002Fbifid","2.ciphers\u002F15.bifid",{"title":104,"path":105,"stem":106},"Rail fence","\u002Fciphers\u002Frail-fence","2.ciphers\u002F16.rail-fence",{"title":108,"path":109,"stem":110},"Columnar transposition","\u002Fciphers\u002Fcolumnar","2.ciphers\u002F17.columnar",{"title":112,"path":113,"stem":114},"Enigma M3","\u002Fciphers\u002Fenigma","2.ciphers\u002F18.enigma",{"title":116,"path":117,"stem":118},"Beaufort","\u002Fciphers\u002Fbeaufort","2.ciphers\u002F19.beaufort",{"title":120,"path":121,"stem":122},"Autokey","\u002Fciphers\u002Fautokey","2.ciphers\u002F20.autokey",{"title":124,"path":125,"stem":126},"AES (ECB)","\u002Fciphers\u002Faes","2.ciphers\u002F21.aes",{"title":128,"path":129,"stem":130},"Triple DES (ECB)","\u002Fciphers\u002Ftriple-des","2.ciphers\u002F22.triple-des",{"title":132,"path":133,"stem":134},"AES (LRW)","\u002Fciphers\u002Faes-lrw","2.ciphers\u002F23.aes-lrw",{"title":136,"path":137,"stem":138},"AES (CBC)","\u002Fciphers\u002Faes-cbc","2.ciphers\u002F24.aes-cbc",{"title":140,"path":141,"stem":142},"AES (CFB)","\u002Fciphers\u002Faes-cfb","2.ciphers\u002F25.aes-cfb",{"title":144,"path":145,"stem":146},"AES (CTR)","\u002Fciphers\u002Faes-ctr","2.ciphers\u002F26.aes-ctr",{"title":148,"path":149,"stem":150},"AES (CCM)","\u002Fciphers\u002Faes-ccm","2.ciphers\u002F27.aes-ccm",{"title":152,"path":153,"stem":154},"AES (OFB)","\u002Fciphers\u002Faes-ofb","2.ciphers\u002F28.aes-ofb",{"title":156,"path":157,"stem":158},"AES (OCB)","\u002Fciphers\u002Faes-ocb","2.ciphers\u002F29.aes-ocb",{"title":160,"path":161,"stem":162},"Triple DES (CBC)","\u002Fciphers\u002Ftriple-des-cbc","2.ciphers\u002F30.triple-des-cbc",{"title":164,"path":165,"stem":166},"Rijndael (ECB)","\u002Fciphers\u002Frijndael","2.ciphers\u002F31.rijndael",{"title":168,"path":169,"stem":170},"AES (XTS)","\u002Fciphers\u002Faes-xts","2.ciphers\u002F32.aes-xts",{"title":172,"path":173,"stem":174},"AES (CBC-MAC)","\u002Fciphers\u002Faes-cbc-mac","2.ciphers\u002F33.aes-cbc-mac",{"title":176,"path":177,"stem":178},"Blowfish (ECB)","\u002Fciphers\u002Fblowfish","2.ciphers\u002F34.blowfish",{"title":180,"path":181,"stem":182},"DES (ECB)","\u002Fciphers\u002Fdes","2.ciphers\u002F35.des",{"title":184,"path":185,"stem":186},"DESX (ECB)","\u002Fciphers\u002Fdesx","2.ciphers\u002F36.desx",{"title":188,"path":189,"stem":190},"IDEA (ECB)","\u002Fciphers\u002Fidea","2.ciphers\u002F37.idea",{"title":192,"path":193,"stem":194},"Lucifer (ECB)","\u002Fciphers\u002Flucifer","2.ciphers\u002F38.lucifer",{"title":196,"path":197,"stem":198},"MARS (ECB)","\u002Fciphers\u002Fmars","2.ciphers\u002F39.mars",{"title":200,"path":201,"stem":202},"Serpent (ECB)","\u002Fciphers\u002Fserpent","2.ciphers\u002F40.serpent","i-solar-library-linear",{"id":205,"title":200,"body":206,"description":536,"extension":537,"links":538,"meta":539,"navigation":540,"path":201,"seo":541,"stem":202,"__hash__":542},"docs\u002F2.ciphers\u002F40.serpent.md",{"type":207,"value":208,"toc":529},"minimark",[209,213,217,225,238,241,246,257,260,267,271,278,281,417,421,432,436,439,442,446,453,501,504,525],[210,211],"cipher-facts",{"name":212},"serpent",[214,215,216],"p",{},"Serpent is what Ross Anderson, Eli Biham and Lars Knudsen sent to the AES competition in 1998. It made the final five and came second in the vote at the last AES conference in 2000. Rijndael was faster and won. Serpent was slower and had the bigger safety margin, and that trade is pretty much the whole story of the choice.",[214,218,219,220,224],{},"The block is 16 bytes, like ",[221,222,223],"a",{"href":125},"AES",", and it's a substitution-permutation network, like AES too. But the pieces are much smaller. Every round:",[226,227,228,232,235],"ul",{},[229,230,231],"li",{},"XORs in a 128-bit round key,",[229,233,234],{},"runs 32 copies of one 4-bit S-box side by side over the block, a different S-box every round, eight of them in turn,",[229,236,237],{},"mixes the four 32-bit words with rotations, shifts and XORs.",[214,239,240],{},"That's 32 rounds. The last one swaps the mixing for one more round key, so there are 33 of them. The designers said 16 rounds would already stop every attack they knew about, and doubled it anyway.",[242,243,245],"h2",{"id":244},"bitslice","Bitslice",[214,247,248,249,253,254,256],{},"The trick is how the S-boxes run. Take bit ",[250,251,252],"code",{},"j"," of each of the four words and you have a nibble. Push it through the S-box and put the four bits back at position ",[250,255,252],{},". Do that for all 32 positions and you've done 32 S-boxes at once, with nothing more than bitwise operations on whole words. No table lookups that depend on secret data, no bit permutation at the start or the end. The paper describes a standard mode with those permutations too, and the two give the same ciphertext.",[214,258,259],{},"This package does the lookups one nibble at a time instead of with the boolean formulas, because it's easier to read. So it's a teaching implementation, not constant time.",[214,261,262,263,266],{},"The key schedule stretches the key into 132 words with the golden ratio ",[250,264,265],{},"0x9e3779b9"," and a rotation, then runs every four of them through an S-box, starting from S3 and counting down. A key shorter than 256 bits gets a single 1 bit after it and zeros up to the end.",[242,268,270],{"id":269},"keys-and-bytes","Keys and bytes",[214,272,273,274,277],{},"The key is 32, 48 or 64 hex digits, a 128, 192 or 256-bit key. Case doesn't matter and spaces are ignored. Text goes in as UTF-8 with PKCS#7 padding, ciphertext comes out as lowercase hex, and ",[250,275,276],{},"decode"," wants hex back. The mode is ECB.",[214,279,280],{},"Words are little-endian, in the key and in the block, the byte order libgcrypt and Botan use. Some code out there reads them the other way round, and then the same key gives different ciphertext. If a vector doesn't match, check that first.",[282,283,288],"pre",{"className":284,"code":285,"language":286,"meta":287,"style":287},"language-ts shiki shiki-themes github-light github-light poimandres","const serpent = create(\"serpent\");\nconst key = \"0123456789abcdeffedcba9876543210\";\nserpent.encode(\"ATTACK AT DAWN\", { key }).text; \u002F\u002F \"33bd9b4c6955d0e186249aeca8b19dbf\"\nserpent.decode(\"33bd9b4c6955d0e186249aeca8b19dbf\", { key }).text; \u002F\u002F \"ATTACK AT DAWN\"\n","ts","",[250,289,290,326,347,386],{"__ignoreMap":287},[291,292,295,299,303,306,310,314,318,321,323],"span",{"class":293,"line":294},"line",1,[291,296,298],{"class":297},"s1TYA","const",[291,300,302],{"class":301},"saoiD"," serpent",[291,304,305],{"class":297}," =",[291,307,309],{"class":308},"sULi6"," create",[291,311,313],{"class":312},"sKlNE","(",[291,315,317],{"class":316},"scVjq","\"",[291,319,212],{"class":320},"sQ7BG",[291,322,317],{"class":316},[291,324,325],{"class":312},");\n",[291,327,329,331,334,336,339,342,344],{"class":293,"line":328},2,[291,330,298],{"class":297},[291,332,333],{"class":301}," key",[291,335,305],{"class":297},[291,337,338],{"class":316}," \"",[291,340,341],{"class":320},"0123456789abcdeffedcba9876543210",[291,343,317],{"class":316},[291,345,346],{"class":312},";\n",[291,348,350,353,356,359,361,363,366,368,371,373,376,379,382],{"class":293,"line":349},3,[291,351,212],{"class":352},"spVlQ",[291,354,355],{"class":312},".",[291,357,358],{"class":308},"encode",[291,360,313],{"class":312},[291,362,317],{"class":316},[291,364,365],{"class":320},"ATTACK AT DAWN",[291,367,317],{"class":316},[291,369,370],{"class":312},", {",[291,372,333],{"class":352},[291,374,375],{"class":312}," }).",[291,377,378],{"class":352},"text",[291,380,381],{"class":312},"; ",[291,383,385],{"class":384},"sjhu3","\u002F\u002F \"33bd9b4c6955d0e186249aeca8b19dbf\"\n",[291,387,389,391,393,395,397,399,402,404,406,408,410,412,414],{"class":293,"line":388},4,[291,390,212],{"class":352},[291,392,355],{"class":312},[291,394,276],{"class":308},[291,396,313],{"class":312},[291,398,317],{"class":316},[291,400,401],{"class":320},"33bd9b4c6955d0e186249aeca8b19dbf",[291,403,317],{"class":316},[291,405,370],{"class":312},[291,407,333],{"class":352},[291,409,375],{"class":312},[291,411,378],{"class":352},[291,413,381],{"class":312},[291,415,416],{"class":384},"\u002F\u002F \"ATTACK AT DAWN\"\n",[242,418,420],{"id":419},"checked-against","Checked against",[214,422,423,424,427,428,431],{},"Botan's ",[250,425,426],{},"serpent.vec",". The tests run all 960 of its single-bit vectors, one bit set in the key or in the block, for 128, 192 and 256-bit keys, plus a handful of the others both ways. Whole texts with padding are checked against libgcrypt's ",[250,429,430],{},"GCRY_CIPHER_SERPENT"," in ECB.",[242,433,435],{"id":434},"how-strong-is-it","How strong is it",[214,437,438],{},"Nobody broke the full thing. The best attacks in print reach 12 of the 32 rounds, and even those need absurd amounts of data and time. VeraCrypt still offers it next to AES, for people who want that safety margin.",[214,440,441],{},"The block is 128 bits, so the Sweet32 collisions that hit Blowfish and Triple DES aren't a problem here.",[242,443,445],{"id":444},"why-ecb-leaks","Why ECB leaks",[214,447,448,449,452],{},"Same as every ECB here. Thirty-two ",[250,450,451],{},"A","s are two equal blocks, and they come out as two equal blocks:",[282,454,456],{"className":284,"code":455,"language":286,"meta":287,"style":287},"serpent.encode(\"A\".repeat(32), { key }).text;\n\u002F\u002F 9f4cec54f67f8b775b9dbf076814dd75 9f4cec54f67f8b775b9dbf076814dd75 70f039bebc4127e475704e5e8a1826a7\n",[250,457,458,496],{"__ignoreMap":287},[291,459,460,462,464,466,468,470,472,474,476,479,481,485,488,490,492,494],{"class":293,"line":294},[291,461,212],{"class":352},[291,463,355],{"class":312},[291,465,358],{"class":308},[291,467,313],{"class":312},[291,469,317],{"class":316},[291,471,451],{"class":320},[291,473,317],{"class":316},[291,475,355],{"class":312},[291,477,478],{"class":308},"repeat",[291,480,313],{"class":312},[291,482,484],{"class":483},"siHFe","32",[291,486,487],{"class":312},"), {",[291,489,333],{"class":352},[291,491,375],{"class":312},[291,493,378],{"class":352},[291,495,346],{"class":312},[291,497,498],{"class":293,"line":328},[291,499,500],{"class":384},"\u002F\u002F 9f4cec54f67f8b775b9dbf076814dd75 9f4cec54f67f8b775b9dbf076814dd75 70f039bebc4127e475704e5e8a1826a7\n",[214,502,503],{},"Spaces added to show the blocks. The last one is only padding.",[214,505,506,507,510,511,514,515,517,518,521,522,524],{},"A key that isn't 32, 48 or 64 hex digits is an ",[250,508,509],{},"InvalidOptionError",", a missing one a ",[250,512,513],{},"MissingOptionError",". On ",[250,516,276],{},", ciphertext that isn't whole 16-byte blocks of hex is a ",[250,519,520],{},"CipherError",". A wrong key almost always breaks the padding, and that's a ",[250,523,520],{}," too. So are decrypted bytes that aren't UTF-8. Puzzles and learning, not secrets.",[526,527,528],"style",{},"html pre.shiki code .s1TYA, html code.shiki .s1TYA{--shiki-light:#D73A49;--shiki-default:#D73A49;--shiki-dark:#91B4D5}html pre.shiki code .saoiD, html code.shiki .saoiD{--shiki-light:#005CC5;--shiki-default:#005CC5;--shiki-dark:#E4F0FB}html pre.shiki code .sULi6, html code.shiki .sULi6{--shiki-light:#6F42C1;--shiki-default:#6F42C1;--shiki-dark:#E4F0FBD0}html pre.shiki code .sKlNE, html code.shiki .sKlNE{--shiki-light:#24292E;--shiki-default:#24292E;--shiki-dark:#A6ACCD}html pre.shiki code .scVjq, html code.shiki .scVjq{--shiki-light:#032F62;--shiki-default:#032F62;--shiki-dark:#A6ACCD}html pre.shiki code .sQ7BG, html code.shiki .sQ7BG{--shiki-light:#032F62;--shiki-default:#032F62;--shiki-dark:#5DE4C7}html pre.shiki code .spVlQ, html code.shiki .spVlQ{--shiki-light:#24292E;--shiki-default:#24292E;--shiki-dark:#E4F0FB}html pre.shiki code .sjhu3, html code.shiki .sjhu3{--shiki-light:#6A737D;--shiki-light-font-style:inherit;--shiki-default:#6A737D;--shiki-default-font-style:inherit;--shiki-dark:#767C9DB0;--shiki-dark-font-style:italic}html .light .shiki span {color: var(--shiki-light);background: var(--shiki-light-bg);font-style: var(--shiki-light-font-style);font-weight: var(--shiki-light-font-weight);text-decoration: var(--shiki-light-text-decoration);}html.light .shiki span {color: var(--shiki-light);background: var(--shiki-light-bg);font-style: var(--shiki-light-font-style);font-weight: var(--shiki-light-font-weight);text-decoration: var(--shiki-light-text-decoration);}html .default .shiki span {color: var(--shiki-default);background: var(--shiki-default-bg);font-style: var(--shiki-default-font-style);font-weight: var(--shiki-default-font-weight);text-decoration: var(--shiki-default-text-decoration);}html .shiki span {color: var(--shiki-default);background: var(--shiki-default-bg);font-style: var(--shiki-default-font-style);font-weight: var(--shiki-default-font-weight);text-decoration: var(--shiki-default-text-decoration);}html .dark .shiki span {color: var(--shiki-dark);background: var(--shiki-dark-bg);font-style: var(--shiki-dark-font-style);font-weight: var(--shiki-dark-font-weight);text-decoration: var(--shiki-dark-text-decoration);}html.dark .shiki span {color: var(--shiki-dark);background: var(--shiki-dark-bg);font-style: var(--shiki-dark-font-style);font-weight: var(--shiki-dark-font-weight);text-decoration: var(--shiki-dark-text-decoration);}html pre.shiki code .siHFe, html code.shiki .siHFe{--shiki-light:#005CC5;--shiki-default:#005CC5;--shiki-dark:#5DE4C7}",{"title":287,"searchDepth":328,"depth":328,"links":530},[531,532,533,534,535],{"id":244,"depth":328,"text":245},{"id":269,"depth":328,"text":270},{"id":419,"depth":328,"text":420},{"id":434,"depth":328,"text":435},{"id":444,"depth":328,"text":445},"Anderson, Biham and Knudsen's AES finalist from 1998. Thirty-two rounds of 4-bit S-boxes on 16-byte blocks, keys of 128, 192 or 256 bits. UTF-8 text in, hex out.","md",null,{},true,{"title":200,"description":536},"Ag8Cux3slw30Rn8Ks7HYe1Jw1QwzRi9KwCosAQWj31U",[544,538],{"title":196,"path":197,"stem":198,"description":545,"children":-1},"IBM's AES finalist from 1998. Thirty-two rounds on four 32-bit words, a 512-word S-box grown from SHA-1, keys of 128 to 448 bits. UTF-8 text in, hex out.",1790337935776]