User Manual
Hybrid encryption combining rotor logic and AES‑256
RotorCrypt X ยท Step-by-Step Guide

00Change Language

RotorCrypt X supports 20 languages, reaching around 44.5 % of the world's population in their native language โ€“ equivalent to approximately 3.6 billion people.

๐Ÿ‡ฉ๐Ÿ‡ช ๐Ÿ‡ฌ๐Ÿ‡ง ๐Ÿ‡ซ๐Ÿ‡ท ๐Ÿ‡ช๐Ÿ‡ธ ๐Ÿ‡น๐Ÿ‡ท ๐Ÿ‡ฏ๐Ÿ‡ต ๐Ÿ‡จ๐Ÿ‡ณ ๐Ÿ‡ธ๐Ÿ‡ฆ ๐Ÿ‡ท๐Ÿ‡บ ๐Ÿ‡ต๐Ÿ‡น ๐Ÿ‡ต๐Ÿ‡ฐ ๐Ÿ‡ฎ๐Ÿ‡ฉ ๐Ÿ‡ฎ๐Ÿ‡น ๐Ÿ‡ฐ๐Ÿ‡ท ๐Ÿ‡ฒ๐Ÿ‡พ ๐Ÿ‡ต๐Ÿ‡ฑ ๐Ÿ‡ธ๐Ÿ‡ช ๐Ÿ‡ธ๐Ÿ‡ฌ ๐Ÿ‡ฌ๐Ÿ‡ท ๐Ÿ‡ฎ๐Ÿ‡ณ
Flag Language Native Speakers Code
๐Ÿ‡จ๐Ÿ‡ณChinese~ 940 Mio.ZH
๐Ÿ‡ช๐Ÿ‡ธSpanish~ 485 Mio.ES
๐Ÿ‡ฎ๐Ÿ‡ณHindi~ 345 Mio.IN
๐Ÿ‡ฌ๐Ÿ‡งEnglish~ 380 Mio.EN
๐Ÿ‡ธ๐Ÿ‡ฆArabic~ 360 Mio.AR
๐Ÿ‡ต๐Ÿ‡นPortuguese~ 240 Mio.PT
๐Ÿ‡ท๐Ÿ‡บRussian~ 150 Mio.RU
๐Ÿ‡ฏ๐Ÿ‡ตJapanese~ 125 Mio.JA
๐Ÿ‡ฐ๐Ÿ‡ทKorean~ 82 Mio.KR
๐Ÿ‡ซ๐Ÿ‡ทFrench~ 80 Mio.FR
๐Ÿ‡น๐Ÿ‡ทTurkish~ 80 Mio.TR
๐Ÿ‡ต๐Ÿ‡ฐUrdu~ 70 Mio.PK
๐Ÿ‡ฎ๐Ÿ‡นItalian~ 65 Mio.IT
๐Ÿ‡ฉ๐Ÿ‡ชGerman~ 75 Mio.DE
๐Ÿ‡ฎ๐Ÿ‡ฉIndonesian~ 43 Mio.ID
๐Ÿ‡ต๐Ÿ‡ฑPolish~ 40 Mio.PL
๐Ÿ‡ฒ๐Ÿ‡พMalay~ 19 Mio.MY
๐Ÿ‡ฌ๐Ÿ‡ทGreek~ 13 Mio.GR
๐Ÿ‡ธ๐Ÿ‡ชSwedish~ 10 Mio.SE
๐Ÿ‡ธ๐Ÿ‡ฌEnglish (Singapore)~ 2 Mio.SG
Total: ~ 3.6 billion native speakers  โ‰ˆ  44.5 % of the world's population (8.1 bn).

How to Change the Language

In the top right corner of the program window, click on the flag of your current language.
A menu opens with all 20 available languages, each shown with a flag and country name.
Select the desired language โ€“ the interface switches immediately, without restarting.
The manual will open automatically in the new language the next time it is accessed.
Note: The language setting is saved locally and is retained the next time the program starts.

01Create Contact

Before you can send an encrypted message, a contact must be created. The program does not store any real names โ€“ the contact's identity is stored internally in encrypted form. No one who opens the files on your hard drive can draw any conclusions about your contacts.

Click the contact button at the top of the program window.
Select "New Contact" and enter a name (max. 25 characters). This name only serves as a local identifier โ€“ only you see it on your device.
The program automatically creates an encrypted *.key file as well as an entry in contact.json. No readable name is stored in these files.
Select the newly created contact from the drop-down menu.
Note: If the same contact name is entered again, the program detects the conflict and reports it. Each contact name may only be used once.

03Encrypt Message

Select the desired contact from the drop-down menu.
Select the rotor count. Shareware version: max. 3 rotors; full version: significantly more โ€“ the more rotors, the more secure.
Enter your text into the input field. Directly above the input field, at the top right next to it, a character counter shows the remaining characters โ€“ 5 951 characters per message.
Click "Encrypt". After a brief animation sequence, the finished encryption block appears in the output field.
Note on processing time: The time required for encryption and decryption depends on three factors: the selected rotor count, the text length, and the speed of your computer. Many rotors combined with a long text on an older machine may take a few seconds โ€“ this is normal and not an error. The program shows a status indicator during processing.
Caution: If an encryption block is already present in the input field, a warning window appears. In this case, use the "Decrypt" button.

04Copy & Send Output

You can send the encryption block generated in the output field in two ways:

MethodProcedure
Copy manually Click "Copy Output". The block is placed on the clipboard. Paste it into your preferred app โ€“ messenger, email, text file, forum, or anywhere else.
Email directly Click "Send Email". Your default email program opens with the encryption block already inserted into the message field. You fill in the recipient and subject yourself.
Tip: The encryption block consists exclusively of standard text characters. It can be transferred without any problems in any text field, app, or email โ€“ it contains no special characters or binary data.

05Decrypt Message (Recipient)

Receive the encryption block from your contact โ€“ by email, messenger, or however it was transmitted.
Copy the complete block โ€“ from the first to the last character, without any additional spaces or line breaks at the beginning or end.
Even a single missing or extra character makes decryption impossible. The most common source of error is incomplete copying.
Paste the block into the program's input field.
Select the correct contact from the drop-down โ€“ the one from whom you received the message.
Click "Decrypt". The plain text appears in the output field.
Authentication error? If an error window appears, either the wrong contact was selected, or the message was altered in transit. Check the contact selection and ask the sender to resend the message.

06Send Reply & Complete Handshake

After decrypting the first message, the banner changes to yellow:

The Handshake is not yet complete! Your contact is now waiting for your reply in order to confirm the shared key on both sides.

Enter any reply into the input field.
Click "Encrypt".
Send the encryption block back to your contact.

Once the original sender has decrypted your reply, the banner turns green on both devices โ€“ the Handshake is complete on both sides.

08Damaged Files โ€“ What to Do?

The program works with two file types in the subfolder Key/ within the program directory:

FileContent
*.keyEncrypted session key โ€“ one file per contact
contact.jsonEncrypted contact list โ€“ contains no readable names

If one of these files has been damaged, deleted, or accidentally overwritten:

Delete the affected *.key file and/or contact.json.
The next time it starts, the program automatically detects that no file is present and creates new, empty files.
Important: Notify your contact that a completely new Handshake is required. Without a new Handshake, secure communication is no longer possible.
Caution: After deletion, all previous messages to this contact can no longer be decrypted. Back up important *.key files as a precaution on a USB stick or an external hard drive โ€“ never in the cloud (see terms of use).

09Rotor Count & Tips for Greater Security

The number of rotors directly affects how many encryption layers the Enigma layer creates:

VersionRotorsUse
Shareware Max. 3 Good for initial tests and the Handshake process
Full Version Significantly more Recommended for all sensitive content โ€“ the more rotors, the larger the key space
Recommendation โ€“ vary the rotor count: Do not use the same rotor count for every message. If you change the count for each message (e.g. sometimes 3, sometimes 7, sometimes 12 rotors), no recognisable pattern emerges in the transmitted blocks. This makes statistical analysis by third parties considerably more difficult โ€“ even if someone collects a large number of your messages.
On processing time: More rotors and longer texts mean more computational work. On a modern PC, this is barely noticeable. On older hardware or under certain operating systems, it may take a few seconds with many rotors and long texts. This is normal โ€“ simply wait until the status indicator disappears.

10Mobile Use โ€“ The Program on a USB Stick

RotorCrypt X is 100% portable. You can save the program, including all key files, on a USB stick and run it on any computer โ€“ without installation, without administrator rights, and without leaving any trace on the unfamiliar system.

Here's how: Copy the entire program folder (program file + Key/ folder) onto your USB stick. On any Windows computer: plug in the stick and run the program directly from it. All key files remain on the stick โ€“ nothing is stored on the unfamiliar computer.
Limitation: This only works as long as the USB port on the respective computer has not been locked by the system administrator. In some corporate networks or on government computers, USB ports are disabled for security reasons. In this case, the program cannot be started.
Important โ€“ protect your USB stick: Whoever takes possession of the stick has access to your key files. Treat it with the same care as a house key โ€“ never leave it unattended.

11Technical Security โ€“ Why It Is So Secure

This section explains in plain language what lies behind the encryption โ€“ no prior knowledge required.

The Encryption Has Several Independent Layers

The Enigma rotors are only one of several layers. A message passes through the program in four mutually independent stages. Each stage on its own would already offer substantial protection โ€“ together they are practically uncrackable:

โ‘  Enigma rotor layer (dynamic permutation through multiple rotors)
โ–ผ
โ‘ก AES-256-GCM encryption (worldwide military and government standard)
โ–ผ
โ‘ข HMAC signature (cryptographic tamper protection)
โ–ผ
โ‘ฃ HKDF key derivation + automatic key rotation after every message

For comparison: even if an attacker attacks layer โ‘ก with the world's fastest computer, they would still need to overcome layer โ‘  afterwards, and vice versa. The combination multiplies security instead of merely adding it up.

What Each Component Does

ComponentWhat it doesWhy it matters
RotorCrypt X Every character is passed through multiple rotating permutation stages. The wiring is dynamic โ€“ there is no fixed alphabet. The best-known weakness of the historical Enigma (a letter could never be encrypted to itself) is completely eliminated here.
Plugboard (65,530 positions) All 65,530 positions are connected in pairs โ€“ as with the historical Enigma, but with an astronomically larger key space. The plugboard alone already generates more possible configurations than there are atoms in the observable universe (see calculation below).
AES-256-GCM Modern block encryption used worldwide by military and intelligence services. Every message receives a unique random value (nonce). Even identical messages produce a completely different encryption block every time โ€“ no statistical analysis is possible.
HKDF (SHA-3-256) Separate keys for content and authentication are derived from a master key. Prevents a compromised sub-key from endangering other areas.
HMAC signature Every message is cryptographically signed. Any manipulation โ€“ even changing a single character โ€“ is detected. Decryption is refused and the recipient is warned.
Key rotation The key is automatically renewed after each message. A compromised key grants no access to past or future messages (Forward Secrecy).

How Large Is the Key Space? โ€“ The Number That Explains Everything

The key space is the number of all possible key combinations. The larger this number, the longer an attacker would need to try every possibility.

For context: The observable universe contains an estimated 1080 atoms. This number sounds unimaginably large โ€“ but it is tiny compared to what RotorCrypt X produces.

The key space K results from the combination of rotors (here: 50 rotors as an example for the full version) and the plugboard:

// Plugboard: number of all possible pairings of 65,530 positions Plugboard combinations = 65.530! / (2^32.765 ร— 32.765!) // Total key space K with 50 rotors K = 50! ร— 65.530^50 ร— Plugboard combinations // Base-10 logarithm (= how many digits does the number have?) logโ‚โ‚€(Plugboard) โ‰ˆ 143.581 logโ‚โ‚€(50! ร— 65.530^50) โ‰ˆ 305 โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€ logโ‚โ‚€(K) โ‰ˆ 231.543 // The number in short form: K โ‰ˆ 4 ร— 10^231.543 // This is a number with over 143,000 zeros after it. // Atoms in the universe: 10^80 โ†’ The key space is 10^143.806 times larger.
In simple terms: Imagine you are looking for one particular needle. Except the haystack is not the Earth, not the galaxy, not the universe โ€“ but 10143.806 universes stacked on top of one another. That is the key space of the Dynamic Enigma.

How Long Would an Attack Take?

Let us assume a completely unrealistic amount of computing power โ€“ far beyond what is possible today or is likely to become possible in the foreseeable future:

// Assumed computing power: 10^18 key tests per second // (already millions of times faster than all the supercomputers in the world combined) Time required = K รท 10^18 โ‰ˆ 4 ร— 10^143.868 seconds // 1 year โ‰ˆ 3.15 ร— 10^7 seconds Time required โ‰ˆ 1.3 ร— 10^143.861 years // Age of the universe โ‰ˆ 1.4 ร— 10^10 years // The attack would take 10^143.851 times longer than the age of the universe.
Conclusion: A classic brute-force attack is simply physically impossible. Not "very difficult" โ€“ physically impossible. The universe would come into being and pass away many times over before even a fraction of the combinations had been tried.

What About Quantum Computers?

Quantum computers are considered the greatest future threat to encryption. The most effective quantum attack on symmetric encryption is called the Grover algorithm. It is faster than classical computers โ€“ but its advantage is often greatly overestimated.

Grover's algorithm halves the exponent โ€“ that is, the number of zeros. This sounds dramatic. But look at the numbers:

// Grover's algorithm halves the key space (square root of K) Effective quantum key space = โˆšK โ‰ˆ 2 ร— 10^115.771 // Assumed quantum computing power: 10^18 tests per second // (extremely optimistic โ€“ far beyond anything foreseeably achievable) Quantum attack time โ‰ˆ 2 ร— 10^115.771 รท 10^18 = 2 ร— 10^71.925 seconds Quantum attack time โ‰ˆ 6 ร— 10^71.917 years // Age of the universe โ‰ˆ 10^10 years // The quantum attack would still take 10^71.907 times longer than the age of the universe.
Direct conclusion: The exponent is halved by the quantum attack: from 231,543 to 115,771. Both numbers are so astronomically large that halving them makes no practical difference. An idealised quantum computer would still need 1071.907 times longer than the age of the universe. RotorCrypt X is also secure against quantum computers for all foreseeable timeframes.
Why the combination of layers is decisive: A quantum computer might attack a single layer (e.g. AES) faster. But it would then still need to overcome the Enigma rotor layer โ€“ which has its own, independent key space of 10231.543. The four layers together make any conceivable attack, whether classical or with a quantum computer, impossible for all practical purposes.

12New Security Features

Bootstrap Protection โ€“ K_current Never in Plain Text

The session key K_current is never transmitted unprotected during the first message exchange. A mathematically elegant circular HMAC dependency protects it:

How it works: K_current is XOR-encrypted with a mask (HKDF of the block HMAC). Since the HMAC itself depends on K_current, a circular dependency arises โ€“ an attacker would need K_current to compute the HMAC, and the HMAC to unmask K_current. This loop is mathematically unsolvable.

After the Handshake is complete (green banner), K_PERM provides additional protection โ€“ a permanent local key that never leaves the device.

Replay Protection โ€“ Every Message Only Once

Every message can only be decrypted once. If someone tries to reopen a message that has already been decrypted, a clear notification window appears:

This also protects against the scenario in which someone gains access to your computer and attempts to decrypt an intercepted message a second time.

Greater Capacity โ€“ 5,951 Characters Instead of 1,947

By optimising the internal block structure, a message can now hold 5,951 characters โ€“ significantly more than before. The block size of 13,600 bytes remains identical.

This corresponds to: approx. 2โ€“3 A4 pages of dense text โ€“ sufficient for most communication scenarios.

Further Improvements

FeatureDescription
Alphabetical Contact ListContacts are now always displayed sorted alphabetically โ€“ even after restarting the program.
Blank Contact at the TopA blank entry appears at the very top of the list โ€“ so no contact name is visible to bystanders.
Rotor Count ResetAfter decrypting, the rotor count is automatically cleared โ€“ so you consciously select a new count for each reply.
Improved SynchronisationIn the case of synchronisation issues, the reset process now runs fully automatically on both sides.

13Registration & Full Version

RotorCrypt X is available as shareware. The free version allows up to 3 rotors. The full version unlocks all 50 rotors.

Shareware Version

The first time the program starts, a license.key file is automatically created in the Key/ folder. This file identifies the shareware version. As long as no full-version licence is activated, a notification window appears when selecting more than 3 rotors.

Purchasing the Full Version

The full version is available via the integrated purchase option. To do so, go to the menu Help โ†’ Registration and click "Buy". After purchasing, you will receive a licence key by email.

Activating the Licence

Open Help โ†’ Registration.
Enter your name in the "Registered to:" field.
Enter the licence key from the email.
Click "Activate". The program checks the key and unlocks the full version.
Offline operation: Activation requires a one-time internet connection to verify the key. After successful activation, the program runs entirely offline โ€“ no further online checks.
Reinstallation: If you reinstall, simply enter your saved licence key again. The full version is restored immediately โ€“ without contacting the manufacturer.

Registration Window

StatusDisplay in the Window
Sharewareโš  Not activated โ€“ input fields visible, "Buy" button active
Full Versionโœ” Full version activated โ€“ name and key displayed, fields locked