Tweaked-IV-setup variant of Py6 by Biham and Seberry (2007): same reduced-state key setup and round function as Py6, but the IV mixing derives a doubled-width feedback buffer and folds mixed bytes back into later rounds, removing the equivalent-IV weakness. As implemented in the DarkCrypt Total Commander plugin, which hardcodes a 512-bit key and 256-bit IV.
| Property | Value |
|---|---|
| Category | Stream Ciphers |
| Sub-category | Rolling-Array Stream Cipher |
| Security status | Not classified |
| Complexity | Advanced |
| Inventor | Eli Biham, Jennifer Seberry |
| Year | 2007 |
| Origin | 🇮🇱 Israel |
| Source | algorithms/stream/darkcrypt-tpy6.js |
| Parameter | Supported values |
|---|---|
| Key sizes | 64 bytes (512 bits) |
| Nonce sizes | 32 bytes (256 bits) |
Status: not classified — treat as unverified.
| Issue | Description | Mitigation |
|---|---|---|
| Distinguishing / key-recovery attacks | Sekar, Paul and Preneel published attacks on TPy6’s keystream generation and proposed further redesigns (TPy6-A/B). | Use a vetted modern cipher. |
1 vector ship with this algorithm and run in the test suite. Byte values are hexadecimal.
Vector 1 — DarkCrypt TPy6 keystream
| Field | Value |
|---|---|
iv |
0000000000000000000000000000000000000000000000000000000000000000 |
key |
000102030405060708090a0b0c0d0e0f 101112131415161718191a1b1c1d1e1f 202122232425262728292a2b2c2d2e2f 303132333435363738393a3b3c3d3e3f |
input |
00000000000000000000000000000000 00000000000000000000000000000000 00000000000000000000000000000000 00000000000000000000000000000000 00000000000000000000000000000000 00000000000000000000000000000000 00000000000000000000000000000000 00000000000000000000000000000000 |
expected |
4ec12f0c0295bff2542946bafbcd0698 bfce5781b6e730547a0bd653c438f778 fa4150ff5a815d08d88e54a4d9158412 1ec60123ee8708f2fcafd257c677541e 1fa9fa5182aeda7d0fe0ae338b4933f0 8ba020d559a5a0650e283efdfaff8bf2 b3ed532b9882bc53749e1580469221cd c73489d2e9182ff380cda6b231e3eb66 |