This article was accepted into the corpus but its outbound wikilinks were never NER-processed — typical at the deepest BFS hop or when the run's entity cap was reached. No expansion funnel to show.
| IDEA (cipher) | |
|---|---|
| Name | IDEA |
| Designers | Xuejia Lai, James Massey |
| Publish date | 1991 |
| Derived from | Lai–Massey scheme |
| Key size | 128 bits |
| Block size | 64 bits |
| Structure | Substitution–permutation network |
| Rounds | 8.5 |
IDEA (cipher)
IDEA is a symmetric-key block cipher designed by Xuejia Lai and James Massey and published in 1991; it uses a 128-bit key and 64-bit block size to provide confidentiality for data processed by systems such as PGP (software), Lotus Notes, and various embedded platforms. The algorithm builds on the Lai–Massey scheme and was created at the Swiss Federal Institute of Technology in Zurich for robust resistance against classical cryptanalysis while being efficient on both software and hardware architectures. IDEA influenced later designs and standards and has been the subject of analysis by researchers from institutions including IBM, ETH Zurich, Bell Labs, and Masaryk University.
IDEA was introduced as an alternative to Data Encryption Standard limitations and to address concerns arising from DES (Data Encryption Standard) key length and structural weaknesses highlighted by researchers at National Institute of Standards and Technology and European Union Agency for Cybersecurity. The cipher gained early adoption through integration in Pretty Good Privacy implementations by Phil Zimmermann and in commercial products from companies like Lotus Development Corporation and PGP Corporation. Its design aimed to combine algebraic mixing operations to resist attacks demonstrated by analysts at Cryptography Research, Inc. and academic groups at Technische Universität Darmstadt and University of Cambridge.
IDEA employs eight rounds plus a final half-round following the Lai–Massey scheme and mixes three algebraic operations: addition modulo 2^16, multiplication modulo 2^16+1, and bitwise XOR—each operation chosen for distinct diffusion and nonlinearity properties analyzed by teams at ETH Zurich, University of Waterloo, and University of California, Berkeley. The 128-bit key is expanded into subkeys using a rotation and selection schedule studied in papers from École Polytechnique Fédérale de Lausanne and University of Bristol. The internal structure resembles a substitution–permutation network as examined by researchers at Massachusetts Institute of Technology, Stanford University, and Princeton University, and the combination of operations was intended to thwart linear and differential techniques developed by analysts at INRIA, Friedrich-Alexander-Universität Erlangen-Nürnberg, and Ruhr University Bochum.
IDEA's resistance to classical differential cryptanalysis and linear cryptanalysis was evaluated by cryptographers from Saarland University, Weizmann Institute of Science, and Royal Holloway, University of London. Attacks exploiting weak key patterns and related-key scenarios were proposed by teams at University of Maryland, Technische Universität München, and Georgia Institute of Technology, while higher-order cryptanalysis work was contributed by researchers at University of Oxford and University College London. Notable results include reduced-round cryptanalysis by analysts affiliated with New York University and Tel Aviv University, as well as algebraic approaches examined at University of Rennes 1 and Chinese Academy of Sciences. Despite these efforts, full-round practical breaks against the complete cipher remain unverified by groups at KTH Royal Institute of Technology and Karlsruhe Institute of Technology.
Implementations of IDEA have been produced in languages and platforms supported by teams at GNU Project, OpenBSD, and FreeBSD and integrated into toolchains maintained by Debian, Red Hat, and Canonical (company). Optimized implementations for microcontrollers and digital signal processors were developed at ARM Holdings, Intel Corporation, and Texas Instruments, while hardware cores were implemented by researchers at Xilinx and Altera (now Intel PSG). Performance comparisons against Rijndael (later AES), Blowfish, and Twofish were published by groups at University of Illinois Urbana-Champaign, Carnegie Mellon University, and NIST benchmarking projects, showing competitive throughput and low memory footprint on 1990s-era architectures.
After publication in 1991, IDEA was evaluated in academic venues including CRYPTO, EUROCRYPT, and ASIACRYPT, with influential analyses from International Association for Cryptologic Research participants. The cipher was incorporated in widely distributed products such as PGP, attracting attention from governments and standards bodies like ISO and IEEE. Discussions about adoption involved entities including European Commission, US Department of Defense, and private vendors at conferences like RSA Conference and Black Hat. While IDEA was never selected as a mandatory international block cipher standard in place of proposals later consolidated in AES competition, it remained a de facto choice in industry deployments through the late 1990s and early 2000s.
IDEA was subject to patent protection held by inventors and assignees, leading to licensing managed by organizations including Ascom Systec AG and legal negotiations involving firms like IBM and Phil Zimmermann's collaborators. Patent restrictions influenced adoption decisions by projects such as PGP (software) and distributions maintained by Red Hat and Debian Project until patents expired or were monetarily licensed. Litigation and licensing discussions engaged counsel from Morrison & Foerster and Latham & Watkins in contexts including export control considerations at US Department of Commerce and compliance reviews at European Court of Justice.
IDEA saw use in email encryption clients like Pretty Good Privacy and enterprise groupware such as Lotus Notes, and in secure file transfer systems implemented by vendors like Cisco Systems and Juniper Networks. It was used in smart card and embedded systems developed by Giesecke+Devrient and Infineon Technologies for payment and identity applications evaluated by EMVCo. Academic and government research labs at Los Alamos National Laboratory and Sandia National Laboratories deployed IDEA in experiments comparing symmetric ciphers for resource-constrained environments. Variants and mode-of-operation pairings with CBC mode and CFB mode were studied by teams at National Security Agency and international collaborators from Australian National University and University of Tokyo.