How 7-Zip Uses Salt in AES Key Generation

When securing archives with AES-256, 7-Zip prevents precomputed attacks by combining the user's password with a cryptographically generated salt during key derivation. This article explains how 7-Zip generates, stores, and processes salt values through its iterative SHA-256 key derivation function to produce unique encryption keys.

Salt Generation

When a user encrypts an archive, 7-Zip generates a pseudo-random salt using the operating system's cryptographic random number generator (such as CryptGenRandom on Windows or /dev/urandom on Unix-like systems). In modern 7-Zip implementations, the salt is typically 16 bytes (128 bits) in length. A new, unique salt is generated for every archive, ensuring that two archives protected with the same password never share the same derived encryption key.

Storage in the Archive

The salt value is not secret and does not need to be encrypted. 7-Zip embeds the raw salt bytes directly into the .7z archive header alongside the encryption flags and iteration counters. Because decryption requires the exact salt used during encryption, storing it in the cleartext header allows the decompression utility to extract it and initialize the key derivation algorithm before prompting the user for the password.

Key Derivation Process

7-Zip derives the final 256-bit AES key using a custom key derivation function based on SHA-256 hashing with key stretching:

  1. Concatenation: The engine combines the user-supplied password and the generated salt into a single byte stream.
  2. Key Stretching: 7-Zip hashes the combined password and salt repeatedly over \(2^{19}\) (524,288) cycles of SHA-256.
  3. Counter Incorporation: In each iteration, 7-Zip incorporates the salt, the password, and an internal counter into the hash state. This creates significant computational overhead for potential attackers attempting brute-force attacks.
  4. Final Output: The final 32-byte digest produced by the last SHA-256 round serves as the 256-bit key for AES encryption in CBC (Cipher Block Chaining) mode.

Security Impact

By binding the salt to the password prior to the hundreds of thousands of SHA-256 iterations, 7-Zip neutralizes rainbow table attacks and precomputed dictionary tables. Attackers cannot precompute password hashes across multiple archives, as each archive's unique salt forces adversaries to recompute the entire iteration chain independently for each targeted file.