How 7-Zip Encrypts File Names in Archives
When securing compressed archives, standard encryption often leaves file and directory names exposed to anyone who opens the container. 7-Zip solves this privacy vulnerability through its proprietary 7z format by providing an "Encrypt file names" option, which encrypts the archive's internal metadata headers using 256-bit AES encryption. This process ensures that unauthorized users cannot read file names, inspect folder hierarchies, or see file sizes without first supplying the correct password.
The Limitation of Standard Archive Encryption
In traditional compression formats like standard ZIP, encryption is applied on a per-file basis. While the actual contents of each file are scrambled, the central directory structure remains unencrypted at the end of the archive. This directory contains metadata, such as:
- File and folder names
- Original and compressed file sizes
- Timestamps and file attributes
- CRC32 checksums
Because this central directory remains in plaintext, an attacker or forensic tool can read the entire catalog of files inside the archive without needing the decryption key. In many scenarios, file names alone can reveal proprietary source code structures, personal identities, financial records, or legal documents.
How Header Encryption Works in the 7z Format
7-Zip eliminates metadata leakage by encrypting the archive's central
directory, known as the header block. This feature is exclusive to the
.7z archive format and is not supported by standard
.zip specifications.
When the "Encrypt file names" option is enabled, 7-Zip executes the following process:
- Key Derivation: 7-Zip takes the user's password and derives an encryption key using the SHA-256 cryptographic hash function. To thwart brute-force and dictionary attacks, 7-Zip employs a key derivation function that applies extensive hashing iterations, slowing down automated guessing attempts.
- Metadata Packaging: The archive indexes all directory structures, file paths, file sizes, and attributes into a consolidated header block.
- Header Stream Compression: Before encryption, the header block is compressed to minimize overhead and obfuscate patterns.
- AES-256 Cipher Application: The compressed header block is encrypted using the Advanced Encryption Standard with a 256-bit key length (AES-256) in Cipher Block Chaining (CBC) mode, accompanied by an initialization vector (IV).
What the Attacker Sees
When an attacker opens a .7z file with encrypted file
names, the decompression utility reads only the minimal, unencrypted
start header. This start header contains only basic signature bytes
identifying the file as a 7z archive and an offset pointer to the main
header.
Because the main header is entirely ciphertext, the software cannot parse the table of contents. If an attacker attempts to inspect the file using an archive manager, a hex editor, or command-line tools, the software will immediately prompt for a password before displaying any visual elements. Until the correct key is provided to decrypt the header, the archive behaves like a completely opaque, random binary block, preventing both content theft and metadata reconnaissance.