FISCES File Crypter documentation by EddyHawk
---
What
---
FISCES is a file encrypter coded by EddyHawk (me).
It is part of PROTAGON File Crypter (PFC) series done by me.
FISCES uses Twofish cipher, CFB128 block cipher mode, MD4 & SHA-512
 hash functions, and HMAC & PbKDF2 constructions, all taken from
 WE Pascal sources.

---
What is Twofish
---
Twofish is a cipher designed by all-American cryptographers:
 Bruce Schneier, John Kelsey, Doug Whiting, David Wagner, Chris Hall,
 plus Niels Ferguson [1998].
It's a 128bit block Feistel-network cipher having 128-256 bit key & 16 rounds.
It's the successor of Blowfish 64bit block cipher by Bruce Schneier.
It's a submission to AES process and managed to become 1 of five AES finalists,
 along with Mars, RC6, Rijndael, & Serpent.

Best known attacks on Twofish:
 5 round w/o post-whitening requiring 2^22.5 chosen plaintexts pairs &
  2^51 computations of g function [Twofish team, 1998].
 6 round w/ pre-whitening under 128bit key using impossible differential
  attack requiring 2^64 chosen plaintexts & 1.84 * 2^128 1-round crypts
  [Biham, Furman, ?]
 6 round w/ pre-whitening under 192bit key using impossible differential
  attack requiring 12 * 2^64 chosen plaintexts & 13 * 2^160 1-round crypts
  [Biham, Furman, ?]
 6 round w/ pre-whitening under 256bit key using impossible differential
  attack requiring 24 * 2^64 chosen plaintexts & 24.2 * 2^192 1-round crypts
  [Biham, Furman, ?]
 7 round under 192bit key using impossible differential attack requiring
  2^95.9 known-plaintexts & 2 * 2^192 1-round crypts [Biham, Furman, ?]
 7 round under 256bit key using impossible differential attack requiring
  2^97.46 known-plaintexts & 2^226.48 1-round crypts [Biham, Furman, ?]
 7 round w/ full whitening requiring 2^127 chosen plaintexts & 2^126/2^190
  /2^253 time for 128/192/256 bit key [Lucks, 2000].
 8 round w/o post-whitening requiring 2^127 chosen plaintexts & 2^126/2^190
  /2^253 time for 128/192/256 bit key [Lucks, 2000].
Best known analysis is by [Moriai, Yin, 2000], managing to find
 truncated differentials on full 16 rounds, eventhough unable to convert it
 into working attack.

IP status: public domain.
Unbroken status: as 2015, 17 years.

Best known key schedule performance is
 8,600 cycles for 128bit key, on Pentium Pro, in C language.
Best known encryption performance is
 16.1 cycles/byte under 128bit key, on Pentium Pro, in ASM language.

Requirements: 4.5kb static data.
Limitations:
 Decryption is slightly slower than encryption.
 Slow key schedule compared to contemporary block ciphers.

---
What is WE Pascal source
---
Wolfgang Ehrhardt (WE) creates an excellent collection of crypt Pascal sources
 which is freely available in Internet, supporting Borland Pascal 7,
 all flavors of Borland Delphi, Free Pascal Compiler, & Virtual Pascal,
 in single source.

Twofish block cipher for FISCES is taken by me from that collection
[TF 07 Jan 2013], then compiled under Virtual Pascal v2.1b279.

MD4 & SHA-512 hash functions and HMAC & PbKDF2 constructions for FISCES are
 also taken from that collection [CRC_Hash 25 Aug 2014], also compiled under
 Virtual Pascal v2.1b279.

---
FISCES specific features
---
256bit key, 16 rounds
 Twofish crypt speed is the same regardless of key size used (unlike AES which
 strictly bind key sizes to certain number of rounds), thus largest key size
 gives more strength without affecting crypt performance.
 True, 256bit key schedule is ~2x slower than 128bit key schedule, but it's
 natural and it's only called once.

---
FAQ
---
Why Twofish?
 Ugh, as alternative to AES?
Why use SHA-512 instead of Whirlpool, then?
 People uses Twofish if they doesn't want AES
 Whirlpool is based on W block cipher which is very similar to AES, also
  co-designed by AES co-designer.
 So I think such people will stay away from anything AES-ish.
 Thus this is a fully non-AES solution for them.

End.