ROCFORT file crypter documentation by EddyHawk
---
What
---
ROCFORT is a file encrypter coded by EddyHawk (me).
It is part of PROTAGON File Crypter (PFC) series done by me.
ROCFORT uses ROCFORT cipher.
It also uses SHA-512 hash function taken from WE Pascal sources.
It also uses EPHS password scrambler & DAZZ-128 hash function.

---
What is ROCFORT cipher
---
It's a byte-oriented stream cipher having 0-2048 bit key & 0-2048 bit IV.
It's an independent upgrade of, or fixes to RC4 cipher designed by Ronald
 Rivest.

 Modifications to ARCFOUR (RC4 stream cipher by Ronald Rivest),
 by EddyHawk, in attempt to strengthen it and avoid its known weaknesses,
 try to maintain simplicity & speed, if possible try to make it faster.
 also attempt faster implementation. written in Pascal
 (Virtual Pascal 2.1b279),
 the cipher thus now called ROCFORT (ROn's Code FOuR-Tified)
 the modifications:
 KSA part:
 -reversed fill state: (255..0) instead of (0..255),
  meant to increase resistance against Mantin's attack
 -cyclic usage of passphrase is removed (each passphrase char is now only
  processed once, and the rest of 256 iterations are simply dropping)
  meant to avoid run-length passphrases generating identical state (& thus
  identical keystream)
  Orr D. notifies us that this can't yet handle all zeroes & zeroes padded
  passphrases, and claims that this change is still vulnerable to his
  differential attack. so, to be improved later.
 -adds 1..keylength in each droppings after the real key_adding
  to avoid all zeroes & zeroes padded passphrases giving identical keystream
 -key_to_state is run twice (total 512 iterations)
  equal to dropping 256 bytes (MARC-4), but simply dropping is kinda wasting
  meant to increase resistance against Mantin's attack
  the drawback: increasing key schedule time
 -at the end of key_to_state, i & j values are set to be state-dependant &
  passed to next operations (to the 2nd key_to_state & to the (en/de)cryption),
  adapted from Mantin's suggestion
 -key_to_state loop is modified to not overwrite varied i & j & made identic so
  it can simply be called twice
 -internal support for IV/nonce, applied to the state:
   1st key-to-state
   IV-to-state
   2nd key-to-state
  the above arrangement is meant to cut off attacker's knowledge of the initial
  states
 -IV is processed reversed, adapted from Klein's suggestion, and also aim to
  differentiate between keysetup & IVsetup (they are made not identical)
 -i & j values aren't passed to iv_setup (so key_to_state acts as if iv doesn't
  exist), again to reduce iv's direct influence to the state
 PRGA part:
 -PCFB (Plaintext & Ciphertext FeedBack), which is meant to:
  -increase resistance against 'xor 2 ciphtexts from 2 different plaintexts
   under the same key, thus removing keystreams from ciphtexts and resulting
   simply plaintext1 xor plaintext2'
  -give less reliance to cumbersome IV generation & handling
  -maintain identical encryption & decryption (keystream xor plaintext),
   otherwise PFB alone will be sufficient
 -PCFB is combined with 'jumper' which will also influence swapping
  'jumper' also used to affect more bytes in the state, thus strengthening
  the possible weakness of using feedback (may allow successful known-plaintext
  attacks). jumper is spread as 3 new feedback variables: S[plain], S[ciph],
  S[ byte(S[plain]+S[ciph]) ], S[ S[ byte(S[plain]+S[ciph]) ] ]
 -PFB/CFB/PCFB allows synchronous stream cipher like this to be used as hash
  function & MAC
 -swapping is done after output instead of before output, following Klein's
  suggestion, meant to increase resistance against his attack

---
What is WE Pascal source
---
Wolfgang Ehrhardt (WE) creates a collection of crypt Pascal sources which is
freely available in Internet, supporting Borland Pascal 7, all flavors of
Borland Delphi, Free Pascal Compiler, & Virtual Pascal, in single source.

SHA-512 hash function and HMAC construction for ROCFORT
are taken from that collection [CRC_Hash 25 Aug 2014], compiled under
Virtual Pascal v2.1b279.

End.