7-Zip SDK AES Encryption Without Dependencies

The 7-Zip SDK (LZMA SDK) natively supports 256-bit AES encryption for 7z archives without requiring any third-party cryptography libraries or operating system dependencies. The SDK distribution bundles all necessary cryptographic algorithms—including the Rijndael cipher and SHA-256 hashing routines—directly within its source tree, allowing developers to build self-contained, encrypted archiving solutions.

Native Cryptographic Implementation

The 7-Zip SDK does not rely on external frameworks such as OpenSSL, Windows CryptoAPI (CAPI), or Cryptography Next Generation (CNG). Instead, the source code includes standalone C and C++ implementations of the core cryptographic primitives:

  • AES Core (Aes.c / AesOpt.c): Implements the AES (Rijndael) block cipher directly. It supports standard ECB and CBC modes utilized by the .7z container format.
  • SHA-256 (Sha256.c / Sha256Opt.c): Handles key derivation and password hashing to transform user passwords into 256-bit encryption keys natively.
  • 7z AES Filter (7zAes.cpp): Manages the integration between the archive stream filter pipeline and the encryption layer, handling initialization vectors (IV), salt generation, and cycle-based key derivation.

Hardware Acceleration Without External APIs

While the engine operates without external dependencies, it does not sacrifice performance. The SDK features built-in hardware acceleration via compiler intrinsics and assembly code (found in AesOpt.c). On modern x86 and x64 processors, the SDK automatically utilizes the Intel/AMD AES-NI instruction set if present, executing encryption rounds at the CPU hardware level without invoking platform-specific security libraries.

Integration Requirements

To enable AES encryption natively in a custom project using the 7-Zip SDK, developers must compile the specific cryptographic files alongside the standard archive and compression modules:

  1. Source File Inclusion: Ensure Aes.c, Sha256.c, and their respective optimization files are linked into the build. In C++ projects implementing full 7z format reading and writing, compile the corresponding filter objects located in the CPP/7zip/Crypto/ directory.
  2. Codec Registration: If using the COM-like interfaces inside the C++ SDK codebase, register the 7zAes codec ID (0x06F10701) so the archive stream pipeline can instantiate the encoder/decoder during file read/write operations.
  3. Header Encryption: The native implementation also supports full header encryption, allowing users to conceal file names, metadata, and directory hierarchies within the native .7z container without external tools.