PHEL file crypter documentation by EddyHawk
---
What
---
PHEL is a file encrypter coded by EddyHawk (me).
It is part of PROTAGON File Crypter (PFC) series done by me.
PHEL uses PHELIX cipher, SHA-512 hash function, HMAC & PbKDF2 constructions,
 all taken from WE Pascal sources.

---
What is PHELIX
---
PHELIX is a stream cipher designed by Doug Whiting, Bruce Schneier,
 Stefan Lucks, & Frederic Muller [2005].
It's a synchronous stream cipher having 256bit key & 128bit nonce, claiming
 128bit security, and also support built-in MAC.
It's the successor of HELIX stream cipher [2003].
It's a submission to ECRYPT/eSTREAM and managed to enter eSTREAM Phase 2
 Profile I.
IP status: public domain.
Best encryption performance PHELIX is < 7 cycles/byte on Pentium M &
 < 14 cycles/byte on PIII (by the designers themselves)

Requirements:
Restrictions:

Best known attack: key-recovery attack requiring 2^34 chosen nonces,
 2^37 chosen-plaintext words, & 2^41.5 operations [Wu, Preneel, 2006].

Unbroken status: regarded by most as broken.

---
What is WE Pascal source
---
Wolfgang Ehrhardt (WE) creates a collection of crypt Pascal sources which is
freely available in Internet, supporting Borland Pascal 7, all flavors of
Borland Delphi, Free Pascal Compiler, & Virtual Pascal, in single source.

PHELIX stream cipher for PHEL is taken by me from that collection
[PHELIX 20 Nov 2006], then compiled under Virtual Pascal v2.1b279, thus
activating WE's 32bit assembly code for higher performance than pure 32bit
Pascal implementation.

SHA-512 hash function for PHEL is also taken from that collection
[CRC_Hash 25 Aug 2014], also compiled under Virtual Pascal v2.1b279.

---
My change to WE source
---
WE source is modified so Phelix won't run the unneeded Phelix_init.

---
PHEL specific features
---
256bit key, 128bit IV.

Phelix_AEAD computes the unused 128bit output of PbKDF2.

Phelix's built-in AEVD & its 128bit verification tag
 which is much faster than the usual HMAC-512-128 + MD4 combo

BASM32 core (WE's)

Random-data insertion

---
Caution
---
-Regarding PHELIX break
 ECRYPT eSTREAM regards PHELIX as broken, so do its own designers.
 Its predecessor, HELIX, is broken under similar attack.
 It's even weaker than HELIX in this respect.
 Even WE discontinue updating his PHELIX source.
 But D. J. Bernstein disagree that it's broken.
 And as far as I learned, it's still safe for PFC purpose.
  The break only matters if attacker can force those amount of nonces &
  plaintexts of his/her choosing to be undetectably crypted w/ targeted key,
  which can't happen in file encryption setting like PFC.

End.