Renting the Cracking Machine with a Cost-and-Time Analysis of Exhaustive DES-56 Key Search in the Cloud

arXiv:2607.23443 · cs.CR · Submitted 2026-07-26 · Read on arXiv

Gonzalo Sharif Curi Martínez, Rodrigo Ramele

cs.CR

Submitted: 2026-07-26

License: http://creativecommons.org/licenses/by/4.0/

The gist: The Data Encryption Standard (DES), with its 56-bit key, has been considered cryptographically broken since 1998.

Terminology

Abstract

The Data Encryption Standard (DES), with its 56-bit key, has been considered cryptographically broken since 1998. However, a concrete, reproducible measurement of the cost and time required to perform an exhaustive key search using today's commodity cloud infrastructure has not been widely reported in recent literature. In this paper we present a distributed brute-force system built on AWS EC2 that partitions the 2 56 keyspace across 37 c6i.2xlarge instances running a C/OpenMP worker, achieving a measured throughput of 2.91,M,keys/s per instance (about 108 times 10 6 keys/s aggregate). We conduct 15 independent trials covering keyspace offsets from 10 6 to 1.5 times 10 10 keys, measuring wall-clock time and monetary cost per trial. For small offsets (at most 10 8), total time is dominated by AWS instance boot latency (about;90,s), yielding a mean of 116.8 plus or minus20.1,s at 0.41 per attack. For larger offsets the search time dominates and grows linearly: a key at offset 1.5 times 10 10 requires about; 87 minutes and 18. At the measured aggregate throughput of 108,M,keys/s, exhausting the full 2 56 keyspace with these 37 instances would take about; 21 years; however, because the workload is embarrassingly parallel and cloud capacity is elastic, the same search can be traded for money almost linearly. Extrapolating our measured cost, a complete exhaustive search would cost about; 1.2 M and, with a sufficiently large fleet, could be completed in about one day. The system is thus practical for bounded-subspace attacks at negligible cost, and full DES exhaustion, while expensive, is firmly within reach of a well-funded attacker using only commodity cloud resources.

Related papers