The Twofish Algorithm
Twofish was Bruce Schneier's answer to Blowfish's biggest weakness — and one of the five finalists in the competition that ultimately chose AES. Learn how its Feistel network, PHT mixing, and key-dependent S-boxes work.
Interactive Twofish Visualizer
🔐 Twofish Encryption
The Twofish Algorithm
Introduction
Twofish is Bruce Schneier’s direct successor to Blowfish, designed in 1998 by a team including Schneier, John Kelsey, Doug Whiting, David Wagner, Chris Hall, and Niels Ferguson. It was submitted to NIST’s AES competition and made it all the way to the final round of five candidates — losing out only to Rijndael (AES), but never suffering any practical cryptanalytic break of its own. Twofish remains free, unpatented, and available for anyone to use.
Table of Contents
- Fixing Blowfish’s Weakness
- How Twofish Works
- The Pseudo-Hadamard Transform
- Security Status
- Twofish vs. AES: Why Rijndael Won
- FAQ
- References
Fixing Blowfish’s Weakness
Blowfish’s biggest structural flaw was its 64-bit block size, which leaves it exposed to birthday-bound attacks (like Sweet32) once enough data has been encrypted under one key. Twofish’s most immediate design goal was simple: keep Blowfish’s spirit of fast, software-friendly, key-dependent design, but move to a full 128-bit block — matching what NIST required for any AES candidate.
How Twofish Works
Twofish operates on 128-bit blocks, split into four 32-bit words rather than the two 32-bit halves a classic Feistel cipher like DES or Blowfish uses. It runs 16 rounds, and each round:
- Passes two of the four words through a key-dependent function called g (itself built from four key-dependent 8-bit S-boxes combined through a fixed MDS — Maximum Distance Separable — matrix multiplication in a finite field, similar in spirit to AES’s MixColumns).
- Combines the two g outputs using a Pseudo-Hadamard Transform (PHT) — described below — along with two of the round’s key material words.
- XORs and rotates the results into the other two words.
- Swaps word pairs for the next round, much like the swap in a classical two-branch Feistel network, just generalized to four words instead of two.
Input and output whitening — XORing extra key material both before the first round and after the last — adds further protection against certain classes of attack that specifically target the outer rounds of a cipher.
Interactive Visualizer
The visualizer above demonstrates Twofish’s genuine structural shape — the four-word network, the PHT mixing step, and the rotate/XOR/swap pattern across all 16 rounds. As with the Blowfish demo, the underlying S-boxes here are derived from your key using a simplified method rather than Twofish’s real Reed-Solomon and MDS-matrix-based key schedule, which is too involved to faithfully reproduce in an in-browser teaching tool.
The Pseudo-Hadamard Transform
One of Twofish’s more distinctive design elements is the PHT, a fast, simple mixing operation applied to the two outputs (call them T0 and T1) of the g function each round:
F0 = (T0 + T1) mod 2³²
F1 = (T0 + 2·T1) mod 2³²
PHT provides strong diffusion — spreading the influence of each input bit widely — using only addition, which is extremely cheap on ordinary CPUs compared to more complex diffusion methods, continuing Twofish’s (and Blowfish’s) design philosophy of fast software performance over exotic mathematical machinery.
Security Status
No practical attack has ever broken full 16-round Twofish. Cryptanalysts found reduced-round attacks (breaking artificially weakened versions with fewer rounds) during the AES competition’s public analysis period, which is exactly the kind of scrutiny the process was designed to surface — and Twofish held up well enough to remain a finalist throughout.
Twofish vs. AES: Why Rijndael Won
NIST’s final decision between the five AES finalists (MARS, RC6, Rijndael, Serpent, and Twofish) came down to a combination of security margin, performance across many different hardware platforms, and implementation simplicity. Rijndael (AES) was chosen primarily for its excellent performance on both high-end and constrained hardware and its comparatively simple, elegant algebraic structure. Twofish was considered highly secure — with some analysts, including Schneier’s own team, arguing it had a larger security margin than Rijndael — but its more intricate key schedule made it somewhat slower to set up new keys and more complex to implement correctly across diverse platforms.
FAQ
Is Twofish still considered secure?
Yes — no practical attack against full-round Twofish exists. It remains a solid choice, though AES’s ubiquity, standardization, and hardware acceleration (AES-NI) make AES the default choice for nearly all new systems.
Why didn’t Twofish win the AES competition?
It wasn’t for lack of security — NIST’s decision weighed performance across many platforms and implementation simplicity alongside pure cryptographic strength, and Rijndael’s simpler structure and better all-around performance profile won out.
What’s the Pseudo-Hadamard Transform used for?
It’s Twofish’s core diffusion step — mixing the outputs of the g-function each round using only fast addition operations, spreading each input bit’s influence widely across the block with minimal computational cost.
How does Twofish compare to Blowfish?
Twofish uses a 128-bit block (fixing Blowfish’s Sweet32-style vulnerability from its 64-bit block), a four-word network instead of a classic two-half Feistel structure, and a more sophisticated (though still fast) key-dependent S-box generation process.
Is Twofish free to use?
Yes, like Blowfish, Twofish was placed in the public domain by its designers and remains completely free and unpatented for any use.
References
-
Schneier, B. et al. “Twofish: A 128-Bit Block Cipher.” AES submission, 1998. Available at: https://www.schneier.com/academic/twofish/
-
Wikipedia. “Twofish.” Available at: https://en.wikipedia.org/wiki/Twofish
-
NIST. “Report on the Development of the Advanced Encryption Standard (AES).” 2001 — the official comparison of all five AES finalists.