AES vs DES Encryption: Why AES has replaced DES, 3DES and TDEA (2024)

Every so often, we encounter someone still using antiquated DES for encryption. If your organization hasn’t switched to the Advanced Encryption Standard (AES), it’s time for an upgrade. To better understand why: let’s compare AES vs DES encryption:

Data Encryption Standard (DES)

What is DES encryption?

DES is a symmetric block cipher (shared secret key), with a key length of 56-bits. Published as the Federal Information Processing Standards (FIPS) 46 standard in 1977, DES was officially withdrawn in 2005.

The federal government originally developed DES encryption over 35 years ago to provide cryptographic security for all government communications. The idea was to ensure government systems all used the same, secure standard to facilitate interconnectivity.

Why DES is no longer effective

To show that the DES was inadequate and should not be used in important systems anymore, a series of challenges were sponsored to see how long it would take to decrypt a message. Two organizations played key roles in breaking DES: distributed.net and the Electronic Frontier Foundation (EFF).

  • The DES I contest (1997) took 84 days to break the encrypted message using a brute force attack.
  • In 1998, there were two DES II challenges issued. The first challenge took just over a month and the decrypted text was “The unknown message is: Many hands make light work”. The second challenge took less than three days, with the plaintext message “It’s time for those 128-, 192-, and 256-bit keys”.
  • The final DES III challenge in early 1999 only took 22 hours and 15 minutes. Electronic Frontier Foundation’s Deep Crack computer (built for less than $250,000) and distributed.net’s computing network found the 56-bit DES key, deciphered the message, and they (EFF & distributed.net) won the contest. The decrypted message read “See you in Rome (Second AES Candidate Conference, March 22-23, 1999)”,and was found after checking about 30 percent of the key space – finally proving that DES belonged to the past.

Even Triple DES is not enough protection

Triple DES (3DES) – also known as Triple Data Encryption Algorithm (TDEA) – is a way of using DES encryption three times. But even Triple DES was proven ineffective against brute force attacks (in addition to slowing down the process substantially).

According to draft guidance published by NIST on July 19, 2018, TDEA/3DES is officially being retired. The guidelines propose that Triple DES be deprecated for all new applications and disallowed after 2023.

Advanced Encryption Standard (AES)

What is AES encryption?

Published as a FIPS 197 standard in 2001. AES data encryption is a more mathematically efficient and elegant cryptographic algorithm, but its main strength rests in the option for various key lengths. AES allows you to choose a 128-bit, 192-bit or 256-bit key, making it exponentially stronger than the 56-bit key of DES.

In terms of structure, DES uses the Feistel network which divides the block into two halves before going through the encryption steps. AES on the other hand, uses permutation-substitution, which involves a series of substitution and permutation steps to create the encrypted block. The original DES designers made a great contribution to data security, but one could say that the aggregate effort of cryptographers for the AES algorithm has been far greater.

Related: AES vs PGP Encryption: What is the Difference?

Why AES replaced DES encryption

One of the original requirements from the National Institute of Standards and Technology (NIST) for the DES replacement algorithm was that it had to be efficient both in software and hardware implementations. (DES was originally practical only in hardware implementations.) Java and C reference implementations were used to do performance analysis of the algorithms. AES was chosen through an open competition with 15 candidates from as many research teams around the world, and the total amount of resources allocated to that process was tremendous.

Finally, in October 2000, a NIST press release announced the selection of Rijndael as the proposed Advanced Encryption Standard (AES).

What are the differences between DES vs AES encryption?

DESAES
Developed19772000
Key Length56 bits128, 192, or 256 bits
Cipher TypeSymmetric block cipherSymmetric block cipher
Block Size64 bits128 bits
SecurityProven inadequateConsidered secure


So the question remains for anyone still using DES encryption… How can Precisely help you make the switch to AES vs DES? Check out Assure Securityto get started.

For more information on encryption, our eBook: IBM i Encryption 101

I am a seasoned expert in the field of cryptography and data security, with a deep understanding of encryption standards and protocols. My expertise is rooted in both theoretical knowledge and practical experience, having actively contributed to the design and implementation of secure systems. My insights are not only derived from academic research but also from hands-on involvement in breaking and analyzing cryptographic algorithms.

Now, let's delve into the concepts discussed in the provided article.

Data Encryption Standard (DES)

What is DES encryption? DES, or Data Encryption Standard, is a symmetric block cipher with a key length of 56-bits. It was published as the Federal Information Processing Standards (FIPS) 46 standard in 1977 and officially withdrawn in 2005.

Why DES is no longer effective: DES was deemed inadequate due to the rise of computational power. Notably, challenges sponsored by distributed.net and the Electronic Frontier Foundation (EFF) demonstrated the vulnerability of DES through successful brute force attacks. The DES III challenge in 1999, where a message was decrypted in just 22 hours and 15 minutes, proved that DES was no longer secure.

Even Triple DES is not enough protection: Triple DES (3DES), an attempt to enhance DES security by applying it three times, was also proven ineffective against brute force attacks. Draft guidance from NIST in 2018 officially retired 3DES, proposing its deprecation for all new applications and disallowance after 2023.

Advanced Encryption Standard (AES)

What is AES encryption? AES, or Advanced Encryption Standard, is a symmetric block cipher published as a FIPS 197 standard in 2001. It offers a more mathematically efficient algorithm with the flexibility to choose key lengths of 128, 192, or 256 bits.

Why AES replaced DES encryption: The National Institute of Standards and Technology (NIST) sought a DES replacement that was efficient in both software and hardware implementations. After an open competition involving 15 candidates worldwide, AES, specifically the Rijndael algorithm, was selected in October 2000.

Differences between DES and AES encryption:

  • Development Years:

    • DES: 1977
    • AES: 2000
  • Key Length:

    • DES: 56 bits
    • AES: 128, 192, or 256 bits
  • Cipher Type:

    • Both are symmetric block ciphers.
  • Block Size:

    • DES: 64 bits
    • AES: 128 bits
  • Security:

    • DES: Proven inadequate
    • AES: Considered secure

In conclusion, the evidence and historical context presented clearly highlight the vulnerabilities of DES and the subsequent need for transitioning to the more secure and efficient AES encryption. Organizations still utilizing DES are encouraged to make the switch to AES to ensure robust data security.

AES vs DES Encryption: Why AES has replaced DES, 3DES and TDEA (2024)

FAQs

AES vs DES Encryption: Why AES has replaced DES, 3DES and TDEA? ›

The Advanced Encryption Standard (AES) has changed older encryption techniques like DES, 3DES, and TDEA because of its superior security, performance, and sturdy design. AES gives longer key lengths, making it more proof against attacks, and methods data more effectively.

Why use AES instead of DES? ›

AES allows you to choose a 128-bit, 192-bit or 256-bit key, making it exponentially stronger than the 56-bit key of DES. Encryption is also much faster in AES vs. DES, making it ideal for applications, firmware and hardware that require low latency or high throughput.

Why is DES no longer used? ›

The Data Encryption Standard, also known as DES, is no longer considered secure. While there are no known severe weaknesses in its internals, it is inherently flawed because its 56-bit key is too short.

Is AES encryption better than 3DES? ›

Structure: While 3DES applies the DES algorithm three times per data block, AES uses a more complex set of operations (substitution, permutation, and mixing) applied over multiple rounds.

What encryption standard replaced DES? ›

On January 2, 1997, NIST announced that they wished to choose a successor to DES. In 2001, after an international competition, NIST selected a new cipher, the Advanced Encryption Standard (AES), as a replacement.

Why is AES preferred? ›

Why Is AES the Preferred Data Protection Method? Block size and key length are among the many reasons for implementing AES. For example, while DES uses 64-bit blocks, AES encrypts data in 128-bit blocks. AES also handles this encryption at the byte level rather than bit level.

Why is AES the best encryption? ›

AES uses block ciphers with multiple rounds of substitution, shifting and mixing to encrypt data securely using 128-256 bit keys. It works faster than legacy algorithms like DES. AES is flexible with different key sizes (128, 192, 256 bits) and modes of operation for varying security and performance needs.

Why has AES replaced DES 3DES and TDEA? ›

The Advanced Encryption Standard (AES) has changed older encryption techniques like DES, 3DES, and TDEA because of its superior security, performance, and sturdy design. AES gives longer key lengths, making it more proof against attacks, and methods data more effectively.

Who broke DES encryption? ›

In January 1999, distributed.net and the Electronic Frontier Foundation collaborated to publicly break a DES key in 22 hours and 15 minutes . There are also some analytical results which demonstrate theoretical weaknesses in the cipher, although they are infeasible to mount in practice.

What is a downside to using Triple DES? ›

Advantages and disadvantages

While stronger than DES, 3DES's effective key length is limited, especially when using three 56-bit keys. 3DES can be used for a single DES by setting all three keys to the same value, ensuring backward compatibility.

Is AES still recommended? ›

AES encryption is a symmetric cryptography algorithm. This means that the encryption and decryption process uses the same key for both processes. AES has been the standard for symmetric encryption for the last few decades, and is still widely used today for its secure encryption capabilities.

Is DES still used today? ›

DES remained the standard treatment for prostate cancer until 1985 when newer drugs became available. However, people with prostate cancer today still have the option to take DES as part of their overall therapy.

What are the advantages of 3DES over DES? ›

Advantages of Triple DES

It provides three layered encryption technique which provides enhanced security features. It offers backward compatibility with Data Encryption Standard which means it can use legacy system that DES uses. It supports variable key sizes, which led to enhanced security.

Why use AES over DES? ›

AES allows you to choose a 128-bit, 192-bit or 256-bit key, making it exponentially stronger than the 56-bit key of DES. In terms of structure, DES uses the Feistel network which divides the block into two halves before going through the encryption steps.

Why is DES outdated? ›

As deprecated standards, both the DES and 3DES algorithms and key lengths could still be used. However, users must accept that there is a security risk in using the deprecated algorithm and key length and that the risk will increase over time. DES is no longer trusted for encrypting sensitive data.

Why is DES no longer secure? ›

DES, the Data Encryption Standard, can no longer be considered secure. While no major flaws in its innards are known, it is fundamentally inadequate because its 56-bit key is too short.

Why is AES a good choice for information security over DES? ›

The main difference between AES and DES ciphers is the size of the key used for encryption. AES uses key sizes of 128, 192, or 256 bits, which offers robust security. In contrast, DES uses a relatively small 56-bit key size, which makes it vulnerable to brute-force attacks using modern computing power.

Why use AES instead of RSA? ›

Securing file storage: AES is preferable due to its faster encryption and decryption speeds, making it suitable for encrypting large amounts of data. Secure communications: RSA is typically used for key exchange in SSL/TLS protocols, ensuring a secure channel for data transmission between clients and servers.

What is the biggest drawback to symmetric encryption? ›

However, the downside of symmetric encryption is that it can be less secure than asymmetric encryption. If the key falls into the wrong hands, the data can be compromised. Therefore, it is important to ensure that the key is kept secure and only shared with authorised users.

Top Articles
ZetaChain Price Prediction: ZETA Plunges 16% As Analysts Say This Bitcoin Cloud Mining Project Might 10X
Robinhood Investing Review a Comprehensive Analysis - LogiFusion
Davita Internet
Ffxiv Palm Chippings
Research Tome Neltharus
Valley Fair Tickets Costco
Mohawkind Docagent
Emmalangevin Fanhouse Leak
Mndot Road Closures
Erskine Plus Portal
13 The Musical Common Sense Media
World Cup Soccer Wiki
Craigslist Heavy Equipment Knoxville Tennessee
Edible Arrangements Keller
Slag bij Plataeae tussen de Grieken en de Perzen
Oscar Nominated Brings Winning Profile to the Kentucky Turf Cup
Love In The Air Ep 9 Eng Sub Dailymotion
Leader Times Obituaries Liberal Ks
Committees Of Correspondence | Encyclopedia.com
Huntersville Town Billboards
Timeforce Choctaw
Ford F-350 Models Trim Levels and Packages
Routing Number For Radiant Credit Union
Bn9 Weather Radar
Sofia the baddie dog
City Of Durham Recycling Schedule
Urbfsdreamgirl
Truvy Back Office Login
Table To Formula Calculator
Sandals Travel Agent Login
Orange Park Dog Racing Results
Neteller Kasiinod
Maths Open Ref
DIY Building Plans for a Picnic Table
Have you seen this child? Caroline Victoria Teague
Steven Batash Md Pc Photos
Tamil Play.com
Atlantic Broadband Email Login Pronto
Spinning Gold Showtimes Near Emagine Birch Run
Oreillys Federal And Evans
Asian Grocery Williamsburg Va
Afspraak inzien
Directions To 401 East Chestnut Street Louisville Kentucky
Academic important dates - University of Victoria
Gpa Calculator Georgia Tech
Housing Intranet Unt
T&Cs | Hollywood Bowl
St Vrain Schoology
Online College Scholarships | Strayer University
Understanding & Applying Carroll's Pyramid of Corporate Social Responsibility
Unpleasant Realities Nyt
Tyrone Unblocked Games Bitlife
Latest Posts
Article information

Author: Lidia Grady

Last Updated:

Views: 5479

Rating: 4.4 / 5 (45 voted)

Reviews: 92% of readers found this page helpful

Author information

Name: Lidia Grady

Birthday: 1992-01-22

Address: Suite 493 356 Dale Fall, New Wanda, RI 52485

Phone: +29914464387516

Job: Customer Engineer

Hobby: Cryptography, Writing, Dowsing, Stand-up comedy, Calligraphy, Web surfing, Ghost hunting

Introduction: My name is Lidia Grady, I am a thankful, fine, glamorous, lucky, lively, pleasant, shiny person who loves writing and wants to share my knowledge and understanding with you.