Excerpted from NIST announcement of Draft Federal Information Processing Standard (FIPS) 463, Data Encryption Standard (DES), and Request for Comments: http://jya.com/nist011599.txt
Let E_{K}(I) and D_{K}(I) represent the DEA encryption and decryption of I using DEA key K respectively. Each TDEA encryption/decryption operation (as specified in ANSI X9.52) is a compound operation of DEA encryption and decryption operations. The following operations are used:
1. TDEA encryption operation: the transformation of a 64bit block I into a 64bit block ) that is defined as follows:
O = E_{K3}(D_{K2}(E_{K1}(I)))
2. TDEA decryption operation: the transformation of a 64bit block I into a 64bit block O that is defined as follows:
O = D_{K1}(E_{K2}(D_{K3}(I)))
The standard species the following keying options for bundle (K_{1}, K_{2}, K_{3})
1. Keying Option 1: K_{1}, K_{2} and K_{3} are independent keys;2. Keying option 2: K_{1} and K_{2} and [are?] independent keys and K_{3} = K_{1};
3. Keying Option 3: K_{1} = K_{2} = K_{3}.
A TDEA mode of operation is backward compatible with its single DEA counterpart if, with compatible keying options for TDEA operation,
1. An encrypted plaintext computed using a single DEA mode of operation can be decrypted correctly by a corresponding TDEA mode of operation; and2. An encrypted plaintext computed using a TDEA mode of operation can be decrypted correctly by a corresponding single DEA mode of operation.
When using keying Option 3 (K_{1} = K_{2} = K_{3}), TECB, TCBC, TCFB, amd TOFB modes are backward compatible with single DEA modes of operation ECB, CBC, CFB, OFB respectively.
The diagram in Appendix 2 illustrates TDEA encryption an TDEA decrytion.
(Note that the two appendices to FIPS 463 are not reproduced in this Federal Register notice. They are available in the complete draft of FIPS 463.)
[Note: NIST says by telephone message at (301) 9755237 bad weather has closed NIST and that draft of FIPS 463 is not yet available.]