HC16 File Crypter documentation by EddyHawk
---
What
---
HC16 is a file encrypter coded by EddyHawk (me).
It is part of PROTAGON File Crypter (PFC) series done by me.
HC16 uses HC-128 cipher.
It also uses MD4 & SHA-256 hash functions, and HMAC & PbKDF2 constructions,
 all taken/adapted from WE Pascal sources.

---
What is HC-128
---
HC-128 (Hongjun Wu Cipher - 128bit key) is a stream cipher designed by
 Hongjun Wu [2006]. It is a synchronous stream cipher having 128bit key,
 128bit IV, & claiming 128bit security. It's a submission to ECRYPT/eSTREAM
 and has been included in eSTREAM portfolio along with RABBIT, SALSA20/12,
 SOSEMANUK, GRAIN v1, MICKEY v2, & TRIVIUM.
HC-128 is faster, tweaked, lower-security variant of HC-256 stream cipher by
 the same designer.
Key & IV setup highest performance is ~27.3k cycles using optimized C on
 Pentium M, claimed by the designer.
(En/De)cryption highest performance is 3.05 cycles/byte using optimized C on
 Pentium M, claimed by the designer.
HC-128 is relatively easy to be implemented.
HC-128 outputs 4 byte (32bit) at a time. But its optimized code from
 the designer is actually coded to output 64 byte (512bit) at a time.

HC-128 requirement: 4kb memory for P & Q tables.
HC-128 restriction: 2^64 bit keystream per pair of key/passphrase & nonce.

HC-128 has slow key schedule, partly due to its 'big' dropping (1024 iterations
 of next_state function)
Unbroken status: as 2015, 9 years
Yet there are reports that HC-128 may be vulnerable to cache-timing attacks

---
What is WE Pascal source
---
Wolfgang Ehrhardt (WE) creates an excellent collection of crypt Pascal sources
 which is freely available in Internet, supporting Borland Pascal 7,
 all flavors of Borland Delphi, Free Pascal Compiler, & Virtual Pascal,
 in single source.

MD4 & SHA-256 hash functions and HMAC & PbKDF2 constructions for HC16
 are taken/adapted from that collection [CRC_Hash 25 Aug 2014], then compiled
 under Virtual Pascal v2.1b279.

---
HC16 specific features
---
Optimized PbKDF2-HMAC-SHA256 48,000 iterations with 256bit output.

Very simple self-test is included in HC16 & automatically activated during
 HC16 run.

Besides implementing optimized HC-128 key schedule, I did further size & speed
 optimization to the key schedule. Optimized encryption isn't implemented since
 it causes another overhead to key schedule & since the output must be at least
 512bit.

HC16 also xors keystream with plaintext using my 'xorbuf'
Due to the way HC-128 is implemented, 'xorbuf' doesn't require another file
 buffer to hold keystream.
'xorbuf' now calculate buf content size on each call, reducing performance
 slightly for long run, but much improved performance for short run.

Thematical fit
HC-128 uses some of SHA-256 internal functions, and HC16 uses SHA-256.

End.