The original S-boxes and algorithms of DES are designed to resist differential attack[11]. We propose eight more new S-boxes with the same cryptographic properties as S-boxes in DES. These 16 S-boxes are used to construct the extended DES, which is double the size of the original DES. The differential and linear cryptanalyses of the extended DES are given. The complexities of the two attacks are found to be 2112 and 2142 respectively.