← Latest papers
💻 computer science

Renting the Cracking Machine with a Cost-and-Time Analysis of Exhaustive DES-56 Key Search in the Cloud

This paper demonstrates that while a full exhaustive search of the 56-bit DES keyspace using commodity AWS EC2 instances would cost approximately $1.2 million and take about 21 years with a modest fleet, the search is practically feasible for well-funded attackers who can trade money for time to complete it in as little as one day, while smaller subspace attacks can be executed for negligible cost.

Original authors: Gonzalo Sharif Curi Martínez, Rodrigo Ramele

Published 2026-07-28✓ Author reviewed
📖 4 min read☕ Coffee break read

Original authors: Gonzalo Sharif Curi Martínez, Rodrigo Ramele

Original paper licensed under CC BY 4.0 (http://creativecommons.org/licenses/by/4.0/). This is an AI-generated explanation of the paper below. It is not written by the authors. For technical accuracy, refer to the original paper. Read full disclaimer

Imagine the world of digital locks and keys, where secret messages are scrambled so only the intended recipient can read them. For decades, one specific lock, called the Data Encryption Standard (DES), was the gold standard for keeping secrets safe. Think of DES as a massive combination lock with a dial that has 56 numbers on it. To crack it, a thief would have to try every single possible combination until the lock clicked open. Because the numbers are so high, it was once thought that only a super-computer or a massive, custom-built machine could ever try them all fast enough. But the world has changed. Today, we have "the cloud," which is like renting a giant, invisible army of computers by the minute instead of buying your own. The big question researchers have been asking is: If you just want to break this old lock, how much does it cost to rent that army, and how long will you have to wait? It's a question that matters because if the cost is low and the time is short, then the old lock isn't safe anymore, and we need to know exactly how vulnerable our old secrets really are.

This paper is like a daring experiment where two researchers, Gonzalo and Rodrigo, decided to find the answer by actually renting a cloud army to break the DES lock. They didn't build a special machine; they just used standard computers available to anyone with a credit card on Amazon's AWS cloud. They set up a team of 37 of these computers to work together, each checking a different slice of the massive number combinations. They treated the job like a giant scavenger hunt: they hid a "treasure" (a secret key) at different distances from the starting line and timed how long it took their computer army to find it.

The results were surprisingly fast and cheap for small distances. When the treasure was hidden close by (within the first 100 million combinations), the computers spent most of their time just waking up and getting ready to work. In these cases, the whole job took about two minutes and cost less than 50 cents. It was like paying a taxi driver a few dollars to drive you to the corner store; the drive itself was instant, but the time was mostly spent waiting for the driver to arrive.

However, as they hid the treasure further away, the story changed. When they pushed the search out to 15 billion combinations, the time spent actually looking for the key became the main factor. The computers worked steadily, finding the key in about 87 minutes for a cost of roughly $18. The researchers discovered that the computers were incredibly efficient, checking nearly 3 million combinations every second on a single machine. When you add up all 37 machines, they were checking over 100 million keys every second.

The most exciting part of their discovery is what happens if you really want to break the entire lock, not just a small part of it. The full lock has about 72 quadrillion possible combinations. With their current setup of 37 computers, it would take them about 21 years to check every single one. That sounds impossible, but the researchers showed that because the work is so easy to split up, you can trade money for time. If you had a very deep pocket and rented a massive fleet of about 140,000 computers, you could break the entire lock in just one day. The total cost for that massive effort would be around $1.2 million.

So, what does this mean? The paper proves that the old DES lock is effectively broken. If a bad guy has a small amount of money, they can crack a specific, limited part of the code for the price of a cup of coffee. If they have a lot of money, they can crack the entire code in a single day. The researchers also noted that while their computer-based approach was fast, using modern graphics cards (the kind used for video games) could make this even cheaper and faster, potentially cutting the time and cost down by another hundred times. The conclusion is clear: the 56-bit lock is no longer a barrier; it's just a matter of how much cash you are willing to spend to break it.

Drowning in papers in your field?

Get daily digests of the most novel papers matching your research keywords — with technical summaries, in your language.

Try Digest →