How 7-Zip Derives AES-256 Keys from Passwords
When securing archives with AES-256 encryption, 7-Zip transforms arbitrary-length user passwords into fixed 256-bit cryptographic keys using an intensive hashing process. This article details the internal mechanics of 7-Zip's custom key derivation function (KDF), covering UTF-16LE password encoding, SHA-256 stretching across 524,288 iterations, salt integration, and the generation of initialization vectors for the underlying cipher.
Password Encoding and Normalization
The key derivation process begins by standardizing the user-supplied password string. Regardless of the operating system or host environment, 7-Zip converts the text into a byte array formatted as UTF-16LE (Little-Endian Unicode). This step ensures consistent byte representation across different platforms, guaranteeing that an archive created on Windows can be decrypted on Linux or macOS using the identical password.
The SHA-256 Hashing Loop
Standard AES-256 encryption requires a 32-byte (256-bit) key, whereas user passwords vary widely in length and entropy. To map the password to this fixed size while defending against dictionary attacks, 7-Zip employs a key-stretching technique using the SHA-256 cryptographic hash function.
Unlike standard PBKDF2 implementations, 7-Zip uses a proprietary iteration loop:
- Iteration Count: 7-Zip executes \(2^{19}\) rounds (524,288 iterations) of SHA-256.
- Buffer Preparation: In each cycle, the algorithm feeds the user's encoded password along with an iteration counter into the SHA-256 context.
- Continuous State Updates: The hash state updates continuously across all 524,288 cycles, ensuring that cracking software must compute over half a million hash operations for every single password candidate tested.
Salt and Initialization Vector (IV) Handling
To prevent precomputed dictionary attacks and rainbow table lookups, 7-Zip incorporates salt and random initialization vectors:
- Archive Headers and File Data: When encrypting data, 7-Zip generates a random salt (typically up to 16 bytes long) stored in the archive header.
- Salt Integration: The salt is combined with the password data throughout the hashing loop. This ensures that identical passwords used on different archives yield completely distinct encryption keys.
- IV Generation: In addition to the encryption key, AES operating in Cipher Block Chaining (CBC) mode requires a 16-byte IV. The final output of the SHA-256 derivation process provides both the 256-bit encryption key and the parameters needed to initialize the cipher.
AES-256 Cipher Execution
Once the 524,288 iterations finish, the resulting 32-byte hash acts directly as the AES-256 key. The archive engine then initializes standard AES-256 in CBC mode:
- If "Encrypt file names" is enabled, the derived key encrypts the entire header metadata, concealing file names, sizes, and directory structures.
- If file name encryption is disabled, the header remains unencrypted, but individual file data streams are encrypted independently using the derived key and per-stream IVs.
Cryptographic Strengths and Limitations
7-Zip's key derivation design provides strong defense against low-cost brute-force attempts due to the 524,288 SHA-256 iterations. However, because SHA-256 requires minimal RAM per calculation, the derivation process is compute-bound rather than memory-hard. Consequently, specialized hardware such as GPUs, FPGAs, and ASICs can parallelize password-guessing attempts more efficiently than they could against modern memory-hard functions like Argon2 or scrypt.