Paul Crowley’s tweakable block cipher designed for disk sector encryption. Features unusually large 4096-bit (512-byte) blocks with 128-bit tweak parameter for sector addressing. Uses 6-round Feistel network with key-dependent state machine.
| Property | Value |
|---|---|
| Category | Block Ciphers |
| Sub-category | Block Cipher |
| Security status | ❌ Broken |
| Complexity | Advanced |
| Inventor | Paul Crowley |
| Year | 2000 |
| Origin | Not specified |
| Source | algorithms/block/mercy.js |
| Parameter | Supported values |
|---|---|
| Key sizes | 16 bytes (128 bits) |
| Block sizes | 512 bytes (4096 bits) |
Status: ❌ Broken
| Issue | Description | Mitigation |
|---|---|---|
| Differential Cryptanalysis | Broken by Scott Fluhrer at FSE 2001 with differential attack across all six rounds | — |
3 vectors ship with this algorithm and run in the test suite. Byte values are hexadecimal.
Vector 1 — Mercy all-zeros test with zero key and tweak
Source: Implementation-derived test vector (round-trip validated)
| Field | Value |
|---|---|
key |
00000000000000000000000000000000 |
tweak |
00000000000000000000000000000000 |
roundTrip |
Yes |
input |
00000000000000000000000000000000 00000000000000000000000000000000 00000000000000000000000000000000 00000000000000000000000000000000 … (512 bytes; the full value is in the source) |
expected |
406e45494bece167e520d9dcee31c9a2 c4422ad833f47e73a4d2133f0ceda06f 3c77bda3b4de72f0fa740a668836a030 1736e2af6a24a928a370bd4c246e0502 … (512 bytes; the full value is in the source) |
Vector 2 — Mercy incremental input pattern
Source: Implementation-derived test vector (round-trip validated)
| Field | Value |
|---|---|
key |
000102030405060708090a0b0c0d0e0f |
tweak |
fedcba9876543210fedcba9876543210 |
roundTrip |
Yes |
input |
000102030405060708090a0b0c0d0e0f 101112131415161718191a1b1c1d1e1f 202122232425262728292a2b2c2d2e2f 303132333435363738393a3b3c3d3e3f … (512 bytes; the full value is in the source) |
expected |
873a7c5888a267be835ff946630849af d73b64c6ca8bf7168cd2acb0b3c917fb bf7728c4147d1cd9982a4baf11a36bbc 42762c4deb30c16b0823b47bc6c79eee … (512 bytes; the full value is in the source) |
Vector 3 — Mercy with 0x55 pattern and non-zero tweak
Source: Implementation-derived test vector (round-trip validated)
| Field | Value |
|---|---|
key |
0123456789abcdef0123456789abcdef |
tweak |
0f0e0d0c0b0a09080706050403020100 |
roundTrip |
Yes |
input |
55555555555555555555555555555555 55555555555555555555555555555555 55555555555555555555555555555555 55555555555555555555555555555555 … (512 bytes; the full value is in the source) |
expected |
fc71cf4407ddadf52b8705483e1451e8 520594b10db497c900f4db40df081908 c6df8bd904b991dc55cad4b85b4407a6 099fb73ccf64c6a1a4af38f9b15cc5d2 … (512 bytes; the full value is in the source) |