Unrar Encryption Support for RAR5 Archives
When extracting RAR5 archives, the unrar utility
exclusively supports the AES-256 (Advanced Encryption
Standard with a 256-bit key) encryption algorithm. Introduced with the
RAR 5.0 format specification, this standard completely replaced the
older AES-128 implementation used in RAR 4.x archives, modernizing the
format's cryptographic security and protecting against modern
brute-force and cryptanalytic attacks.
The Primary Cipher: AES-256
RAR5 format specifications mandate the use of
AES-256 operating in CBC (Cipher Block
Chaining) mode. When unrar processes an encrypted
RAR5 archive, it relies entirely on this standard symmetric-key cipher
to decrypt the compressed data streams. Unlike some other archive
formats that support multiple legacy or alternative ciphers (such as
ZipCrypto or Blowfish), the RAR5 format does not offer multiple
encryption algorithm options; AES-256 is the sole, non-negotiable cipher
implemented by unrar for this version.
Key Derivation: PBKDF2 with HMAC-SHA256
To transform user-provided passwords into 256-bit AES encryption
keys, unrar utilizes PBKDF2
(Password-Based Key Derivation Function 2) driven by
HMAC-SHA256.
Key elements of this process include:
- Salt Value: An 8-byte (64-bit) or larger cryptographic salt is used to protect against rainbow table attacks.
- Iteration Count: A significantly higher number of derivation iterations is enforced compared to RAR 4.x, intentionally slowing down hardware-accelerated and GPU-based dictionary and brute-force attacks.
Header Encryption Support
In addition to encrypting raw file data, unrar supports
decrypting RAR5 archives with encrypted headers. When this feature is
enabled during archive creation, the entire archive structure—including
file names, sizes, timestamps, and metadata—is encrypted using the same
AES-256 standard. In this mode, unrar requires the correct
password immediately upon opening the archive before it can read the
directory table or list contents.
Data Integrity via BLAKE2sp
While not an encryption cipher, data integrity verification is an
essential part of the RAR5 decryption pipeline in unrar.
For encrypted RAR5 files, checksum validation often utilizes the
BLAKE2sp cryptographic hash function rather than
traditional CRC32. This allows unrar to reliably verify
that decrypted data has not been corrupted or tampered with before
writing it to disk.