AES competition finalist by Adams and Tavares with 128-bit blocks and variable key lengths. Uses CAST-128 S-boxes with extended key schedule and 48 rounds. Conservative security design.
| Property | Value |
|---|---|
| Category | Block Ciphers |
| Sub-category | Block Cipher |
| Security status | 🎓 Educational Only |
| Complexity | Advanced |
| Inventor | Carlisle Adams, Stafford Tavares |
| Year | 1998 |
| Origin | 🇨🇦 Canada |
| Source | algorithms/block/cast.js |
| Parameter | Supported values |
|---|---|
| Key sizes | 16 bytes (128 bits) to 32 bytes (256 bits) in steps of 4 bytes |
| Block sizes | 16 bytes (128 bits) |
Status: 🎓 Educational Only
| Issue | Description | Mitigation |
|---|---|---|
| AES Competition Result | Not selected as AES - Rijndael chosen for better performance and analysis | Use AES (Rijndael) for standardized symmetric encryption |
| Limited adoption | Less analyzed than AES due to limited real-world deployment | Prefer widely-analyzed algorithms like AES for security-critical applications |
3 vectors ship with this algorithm and run in the test suite. Byte values are hexadecimal.
Vector 1 — CAST-256 128-bit key test vector (Crypto++ validated)
| Field | Value |
|---|---|
key |
2342bb9efa38542c0af75647f29f615d |
input |
00000000000000000000000000000000 |
expected |
c842a08972b43d20836c91d1b7530f6b |
Vector 2 — CAST-256 192-bit key test vector (Crypto++ validated)
| Field | Value |
|---|---|
key |
2342bb9efa38542cbed0ac83940ac298bac77a7717942863 |
input |
00000000000000000000000000000000 |
expected |
1b386c0210dcadcbdd0e41aa08a7a7e8 |
Vector 3 — CAST-256 256-bit key test vector (Crypto++ validated)
| Field | Value |
|---|---|
key |
2342bb9efa38542cbed0ac83940ac2988d7c47ce264908461cc1b5137ae6b604 |
input |
00000000000000000000000000000000 |
expected |
4f6a2038286897b9c9870136553317fa |