How Unrar Processes Mixed Encryption Algorithms
This article explains how the unrar utility detects,
manages, and extracts files protected by different encryption algorithms
within the same archive. While most modern RAR archives apply a uniform
encryption standard, non-solid archives allow individual files to
maintain distinct header flags and cryptographic parameters. Below is a
detailed breakdown of how unrar parses file-level metadata,
switches cryptographic contexts, re-derives decryption keys, and handles
decompression across varying encryption algorithms.
Block-Level Metadata and Header Parsing
A RAR archive is organized as a sequential series of discrete blocks.
In a standard, non-solid archive where archive headers are unencrypted,
unrar reads the archive sequentially, inspecting each
file's header block individually.
Every file header contains metadata flags indicating whether the
subsequent data stream is encrypted. If encryption is detected, the
header specifies the target archive format version (such as RAR 4.x or
RAR 5.0) and stores the unique salt and initialization vector (IV)
assigned to that specific file payload. Because this metadata is
declared on a per-file basis rather than globally, unrar
treats each entry as an independent cryptographic unit.
Algorithm Identification and KDF Execution
When unrar encounters an encrypted file entry, it
identifies the required cryptographic scheme based on the block type and
format specification:
- Legacy/RAR 4.x Specifications: Typically utilize AES-128 in Cipher Block Chaining (CBC) mode. The key derivation function (KDF) relies on a proprietary key-stretching loop utilizing multiple iterations of SHA-1.
- RAR 5.0 Specifications: Utilize AES-256 in CBC mode. The key derivation adheres to standard PBKDF2 using HMAC-SHA256 with high iteration counts.
If multiple algorithms exist within the same file container—most
commonly seen when appending new files with modern tools to an older
format archive without recompression—unrar dynamically
invokes the matching KDF routine. Using the single user-provided
password combined with the file-specific salt stored in that file’s
header, unrar computes a dedicated key and initialization
vector for that specific file.
Cryptographic Context Switching
unrar maintains modular decryption engines. Once a
file's specific key and IV are computed:
- Context Teardown:
unrarterminates or flushes the cryptographic cipher state used by the preceding file. - Context Initialization: It instantiates a new cipher object matching the algorithm required by the current file (e.g., reconfiguring from an AES-128 to an AES-256 decryptor).
- Stream Decryption and Decompression: Encrypted data packets pass through the active cipher engine before being handed off to the decompression engine (such as the RAR LZSS variant).
- Verification: Decrypted data is verified against the checksum (CRC32 for older formats, BLAKE2sp for RAR 5.0) defined in the file header.
This teardown-and-initialization cycle repeats for every subsequent file entry encountered in the archive stream.
Architectural Constraints
This dynamic processing behavior operates strictly under specific archive conditions:
- Non-Solid Archives Only: In a solid archive, all files are merged into a continuous, single data stream before compression and encryption. A solid stream can only be encrypted with one continuous algorithm and key context.
- Unencrypted Archive Headers: If an archive is created with the header encryption option (where filenames and directory trees are hidden), the entire archive structure is locked behind a single global cipher format. Per-file algorithmic variation is impossible because the master header enforces the encryption standard across the entire container.