Tooleux

SPECK Encrypt

SPECK (2)

Encrypt text with SPECK64/128 using a password.

Runs in your browser. Nothing leaves your device.
Encrypt text with SPECK64/128 (NSA lightweight cipher) in your browser. CBC mode, PBKDF2 key derivation. Free, offline, runs client-side. Read more Show less

What is SPECK?

SPECK is a family of lightweight block ciphers published by the NSA in 2013. It is designed for embedded systems, IoT devices, and constrained environments where AES would be too slow or too large. It uses only three operations: addition, rotation, and XOR (the ARX design family).

This tool implements SPECK64/128: a 64-bit block with a 128-bit key and 27 rounds. That is the smallest and most commonly documented variant.

A note on trust

SPECK was designed by the NSA and has received significantly less third-party cryptanalysis than AES. It is not a replacement for AES in general-purpose use. This tool exists for users who need to interoperate with a system that specifies SPECK, or who are studying lightweight cryptography. For new encryption work, use AES-GCM or ChaCha20-Poly1305.

How to use

Enter your plaintext, enter a password, and press Encrypt. The output is a single Base64 string containing the random salt, random IV, and ciphertext. Copy it and paste into SPECK Decrypt with the same password.

The password is used to derive a 128-bit SPECK key via PBKDF2-SHA-256 with 100,000 iterations. The IV is random and unique per message.

Mode of operation

SPECK is a block cipher and only encrypts a single 64-bit block at a time. To encrypt arbitrary-length text, this tool uses CBC mode with PKCS#7 padding. CBC chains each block to the previous one using XOR, so identical plaintext blocks produce different ciphertext blocks.

CBC does not provide authentication. For authenticated encryption, use AES-GCM or ChaCha20-Poly1305. This tool exists for interoperability, not for new systems.

FAQ

Is SPECK secure?

No known practical attack exists against the full SPECK64/128, and it has been analyzed for over a decade. However, its trust profile is different from AES: AES won an open international competition and has been scrutinized by the entire cryptographic community. SPECK was designed in secret by the NSA. Some cryptographers deliberately avoid it.

Why 27 rounds?

27 is the official round count for SPECK64/128 from the NSA paper "The SIMON and SPECK Families of Lightweight Block Ciphers" (2013). Different SPECK variants have different round counts (SPECK128/128 uses 32 rounds, SPECK128/256 uses 34).

Can I decrypt data from another SPECK implementation?

Only if that implementation uses SPECK64/128 with CBC mode and the same byte order. SPECK has multiple byte-order conventions in the wild; this tool uses little-endian, which matches the NSA reference implementation.

What is the difference between SPECK and SIMON?

SIMON and SPECK were published together by the NSA. SIMON is optimized for hardware (it uses only AND, XOR, and rotations), SPECK is optimized for software (it uses addition, rotation, and XOR). Both come in the same range of block and key sizes.

Can I use SPECK for password storage?

No. It is an encryption cipher, not a hash. For password hashing use Argon2id or scrypt.

Command line equivalent
# No standard CLI tool ships SPECK; use a scripting language.

# Python with the reference implementation from the NSA paper
# https://github.com/inmcm/Simon_Speck_Ciphers

# Node with the simon-speck npm package
npm i simon-speck
node -e '
const speck = require("simon-speck");
const key = Buffer.from("1b1a1918131211100b0a090803020100", "hex");
const pt = Buffer.from("3b7265747475432d", "hex");
const cipher = new speck.Speck(key, speck.SPECK_64_128);
console.log(cipher.encrypt(pt).toString("hex"));
'

# SPECK64/128 test vector
# Key: 1b1a1918 13121110 0b0a0908 03020100
# Pt:  3b726574 7475432d
# Ct:  (see the NSA paper for the exact value in your byte order)
Loads a test value into the form
Plaintext
Ciphertext