ANUB File Crypter documentation by EddyHawk
---
What
---
ANUB is a file encrypter coded by EddyHawk (me).
It is part of PROTAGON File Crypter (PFC) series done by me.
ANUB uses Anubis cipher, CFB128 block cipher mode,
 MD4 & Whirlpool hash functions, and HMAC & PbKDF2 constructions,
 all taken from WE Pascal sources.

---
What is Anubis
---
Anubis is a cipher designed by Paulo S.L.M. Barreto & Vincent Rijmen [2000].
It's a 128bit block cipher having 128/160/192/224/256/288/320 bit key &
12/13/14/15/16/17/18 rounds.
It's very similar to AES (Vincent Rijmen is co-designer of AES).
It's a submission to NESSIE process, and no weakness was found, but
unfortunately not selected because it's too similar to AES to become
alternative for AES.
NESSIE says that Anubis key schedule is complicated & seems strong, thus
perhaps Biryukov & Khovratovich's related-key attack to AES192 & AES256 isn't
applicable to Anubis.

Best known attack: saturation attack on 8 round requiring
 2^119 chosen plaintexts, 2^104 mem, & 2^204 time (thus only better than brute
 force when key size > 204bit) [NESSIE]
Unbroken status: as 2015, 15 years

Requirements: 6.5kb static data
Restrictions:

---
What is WE Pascal source
---
Wolfgang Ehrhardt (WE) creates an excellent collection of crypt Pascal sources
which is freely available in Internet, supporting Borland Pascal 7,
all flavors of Borland (Embarcadero) Delphi, Free Pascal Compiler,
& Virtual Pascal, in single source.

Anubis block cipher for ANUB is taken by me from that collection
[Anubis 07 Jan 2013], then compiled under Virtual Pascal v2.1b279.
WE implements the tweaked version of Anubis.

MD4 & Whirlpool hash function for ANUB is taken by me from the same collection
[CRC_Hash 25 Aug 2014], also compiled under Virtual Pascal v2.1b279.

---
ANUB specific features
---
Optimized PBKDF2-HMAC 9000 iterations with Whirlpool, 512bit output.

320bit key (18 rounds).

---
FAQ
---
Why implements Anubis crypter?
 An alternative for people who believe in AES & wish for safer variant.
 And it's not slow either compared to Twofish implementation here.

Why must be 320bit key (and thus 18 rounds)? 256bit key should be more than
enough!
 PFC always use the largest key size offered by the cipher whenever possible
 (The exception is AESir, since AES256 is actually weaker than AES192 under
 related-key attack).
 Anubis can't compete with AES in (de)crypt performance: even w/ 128bit key,
 it still slower than (optimized) AES w/ 256bit key (at least on P-IV).
 Thus Anub aims for higher safety instead by using larger key size.

Why choosing Whirlpool instead of SHA-512?
 Eventhough not NIST standard, Whirlpool is NESSIE chosen.
 Its designers also design Anubis (thus a matching pair).
 One of its designers are one of AES' designers (shared principles).
 Yes, Whirlpool gets a full attack, but so far it's just distinguish one and
 haven't yet led to more powerful attacks, so Whirlpool still safe to use.

End.