Ralph Merkleβs Khufu cipher with 64-bit blocks and variable key lengths up to 512 bits. Uses key-dependent S-boxes in an unbalanced Feistel structure with rotation-based rounds. Named after Egyptian Pharaoh Khufu.
| Property | Value |
|---|---|
| Category | Block Ciphers |
| Sub-category | Block Cipher |
| Security status | β Broken |
| Complexity | Advanced |
| Inventor | Ralph Merkle |
| Year | 1990 |
| Origin | πΊπΈ United States |
| Source | algorithms/block/khufu.js |
| Parameter | Supported values |
|---|---|
| Key sizes | 1 byte (8 bits) to 64 bytes (512 bits) |
| Block sizes | 8 bytes (64 bits) |
Status: β Broken
| Issue | Description | Mitigation |
|---|---|---|
| Differential Cryptanalysis | Critical: Khufu can be broken using differential cryptanalysis with 2^43 chosen plaintexts | β |
3 vectors ship with this algorithm and run in the test suite. Byte values are hexadecimal.
Vector 1 β Regression vector - all zeros (no published Khufu KAT exists)
| Field | Value |
|---|---|
key |
0000000000000000 |
input |
0000000000000000 |
expected |
ecc679859341a480 |
Vector 2 β Regression vector - pattern data (no published Khufu KAT exists)
| Field | Value |
|---|---|
key |
fedcba9876543210 |
input |
0123456789abcdef |
expected |
f7e5b312192065ec |
Vector 3 β Regression vector - all ones (no published Khufu KAT exists)
| Field | Value |
|---|---|
key |
ffffffffffffffff |
input |
ffffffffffffffff |
expected |
ae396b43f43afa61 |