SHACAT File Crypter documentation by EddyHawk
---
What
---
SHACAT is a file encrypter coded by EddyHawk (me).
It is part of PROTAGON File Crypter (PFC) series done by me.
SHACAT uses SHACAL-2 cipher, CFB256 block cipher mode,
 MD4 & SHA-256 hash functions, and HMAC & PbKDF2 constructions,
 all taken/adapted from WE Pascal sources.

---
What is SHACAL-2
---
SHACAL-2 is a specialized cipher underlying the SHA-256 hash function,
 thus it is originated from NSA. The cipher is formalized & submitted
 to NESSIE by Helena Handschuh & David Naccache.
It's a 256bit block cipher having 128-512 bit key & 64 rounds/steps.
It's a NESSIE chosen.

Best known attacks on SHACAL-2 are:
 related-key rectangle on 44 rounds requiring 2^333 related-key
  chosen-plaintexts & 2^497.2 time [Lu & Kim, 2008]
 biclique key-recovery on 64 rounds requiring 2^224 chosen plaintexts
  & 2^511.18 64-round crypts [Zheng & Wei, 2014]

IP status: standard
Unbroken? status: as of 2015, 13-15 years.

Requirements:
Limitations:

---
What is WE Pascal source
---
Wolfgang Ehrhardt (WE) creates an excellent collection of crypt Pascal sources
 which is freely available in Internet, supporting Borland Pascal 7,
 all flavors of Borland (Embarcadero) Delphi, Free Pascal Compiler,
 & Virtual Pascal, in single source.

SHACAL-2 block cipher for SHACAT is taken by me from that collection
 [Shacal2 07 Jan 2013], then compiled under Virtual Pascal v2.1b279.

MD4 & SHA-256 hash functions and HMAC & PbKDF2 constructions for AESir
 are also taken/adapted from that collection [CRC_Hash 25 Aug 2014],
 and also compiled under Virtual Pascal v2.1b279.

---
SHACAT specific features
---
Optimized double PbKDF2-HMAC-SHA256 48,000/1 iterations
 with 256/768bit output

From that 768bit output, 512bit of it (SHA256 block length)
 is also used as HMAC key for ciphertext, and then that HMAC
 is pre-updated with the rest (256bit).

512bit key, 256bit block, 64 rounds.

CFB256 mode.
 Only requires the encryption function of the block cipher.

Self-sufficiency.
 SHACAT use SHA-256 & SHACAL-2, which is the block cipher inside SHA-256.
 Technically, this allows code sharing. But SHACAT doesn't do it because
 WE implements them separately.

Shacal-2 cache-timing immunity.

---
FAQ
---
An attack on full rounds? Should we worry about its attack-safety?
 Not really. The crypto community seems to ignore the attack (dunno
 if it's valid or not). Moreover, the attack requires 2^511 time.

So there's no catch, right?
 Not really. It is slow. Only Serpent is slower than it.

End.