Unrar Encryption Support for RAR5 Archives

When extracting RAR5 archives, the unrar utility exclusively supports the AES-256 (Advanced Encryption Standard with a 256-bit key) encryption algorithm. Introduced with the RAR 5.0 format specification, this standard completely replaced the older AES-128 implementation used in RAR 4.x archives, modernizing the format's cryptographic security and protecting against modern brute-force and cryptanalytic attacks.

The Primary Cipher: AES-256

RAR5 format specifications mandate the use of AES-256 operating in CBC (Cipher Block Chaining) mode. When unrar processes an encrypted RAR5 archive, it relies entirely on this standard symmetric-key cipher to decrypt the compressed data streams. Unlike some other archive formats that support multiple legacy or alternative ciphers (such as ZipCrypto or Blowfish), the RAR5 format does not offer multiple encryption algorithm options; AES-256 is the sole, non-negotiable cipher implemented by unrar for this version.

Key Derivation: PBKDF2 with HMAC-SHA256

To transform user-provided passwords into 256-bit AES encryption keys, unrar utilizes PBKDF2 (Password-Based Key Derivation Function 2) driven by HMAC-SHA256.

Key elements of this process include:

  • Salt Value: An 8-byte (64-bit) or larger cryptographic salt is used to protect against rainbow table attacks.
  • Iteration Count: A significantly higher number of derivation iterations is enforced compared to RAR 4.x, intentionally slowing down hardware-accelerated and GPU-based dictionary and brute-force attacks.

Header Encryption Support

In addition to encrypting raw file data, unrar supports decrypting RAR5 archives with encrypted headers. When this feature is enabled during archive creation, the entire archive structure—including file names, sizes, timestamps, and metadata—is encrypted using the same AES-256 standard. In this mode, unrar requires the correct password immediately upon opening the archive before it can read the directory table or list contents.

Data Integrity via BLAKE2sp

While not an encryption cipher, data integrity verification is an essential part of the RAR5 decryption pipeline in unrar. For encrypted RAR5 files, checksum validation often utilizes the BLAKE2sp cryptographic hash function rather than traditional CRC32. This allows unrar to reliably verify that decrypted data has not been corrupted or tampered with before writing it to disk.