Skip to content

DGKN@Labs Crypto Suite v7.0.0 — Evaluation Preview

Latest

Choose a tag to compare

@dogenc dogenc released this 14 Jun 12:35
· 5 commits to main since this release

DGKN@Labs Crypto Suite v7.0.0 — Evaluation Preview

⚠️ This is an evaluation preview — a learning project, not audited software.
Built in native C++ with the help of various AI models as I learn to code. The
cryptographic design is strong and hardened, but DGKN is Windows-only, new, and not
yet independently audited
. Please don't trust it with data of real value yet.
Inspired by TrueCrypt / VeraCrypt; this is my own independent C++ implementation.

What it is

A local, offline encrypted volume manager for Windows — no cloud, no telemetry, no
backdoors. Files live inside encrypted containers (or as standalone encrypted files) that
only open with the correct password plus a bound 2FA key factor.

Highlights

  • XChaCha20-Poly1305 authenticated encryption on every layer (tamper-detecting)
  • Argon2id memory-hard KDF (256 MiB) + HKDF-SHA256 — GPU/ASIC-resistant
  • 2FA secret as a second key factor for containers and single files
  • In-RAM virtual drive via WinFsp — no plaintext on disk while mounted
  • Fully encrypted headers — indistinguishable from random
  • Hardened binary — ASLR, DEP, CFG, CET shadow stack, /Qspectre
  • Keys locked in RAM (sodium_mlock) and zeroized on unmount
  • Hidden volumes, tamper-evident audit log, brute-force lockout, duress password

See the README for the full feature list and the honest threat model.

Install

Easiest: download DGKN-Setup.exe below and run it. Installs to
%ProgramFiles%\DGKN@Labs\Crypto Suite (or per-user without admin).

  • Virtual drive (mount as a drive letter) additionally needs the WinFsp driver,
    installed separately from https://winfsp.dev (no admin required to mount). File and
    container crypto work without it.
  • If your antivirus flags the binary, it's a common false-positive for crypto tools using
    memory-locking.

⚠️ Windows SmartScreen warning is expected (self-signed)

This is a source-available evaluation project signed with my own self-signed
certificate
— not a paid CA certificate. So when you run DGKN-Setup.exe, Windows
SmartScreen will show "Windows protected your PC / unknown publisher". That is normal
and expected here; it does not mean the file is malware — it only means the publisher
isn't validated by a commercial Certificate Authority.

To run it anyway: click More info → Run anyway.

To verify it's really my build (recommended):

  1. Check the digital signature matches the fingerprint published below:
    right-click DGKN-Setup.exe → Properties → Digital Signatures → Details.
  2. Check the SHA-256 hash against SHA256SUMS.txt (attached to this release):
    Get-FileHash DGKN-Setup.exe -Algorithm SHA256

Certificate fingerprint (SHA-1): 31D05A0D71F417F325EF8F263E72070D7F66D509
Subject CN=Code Signing CA, C=DE, valid 2026-06-14 → 2036-06-14.
Compare the Thumbprint shown in the signature details against this value.

Build from source

Fully supported and now path-independent — Qt is auto-detected:

git clone https://github.com/dogenc/dgknCryptoSuite.git
cd dgknCryptoSuite
vcpkg install libsodium:x64-windows argon2:x64-windows nlohmann-json:x64-windows catch2:x64-windows libqrencode:x64-windows
cmake -S . -B build -G Ninja -DCMAKE_BUILD_TYPE=Release -DCMAKE_TOOLCHAIN_FILE=C:/vcpkg/scripts/buildsystems/vcpkg.cmake -DVCPKG_TARGET_TRIPLET=x64-windows
cmake --build build

(Need Qt elsewhere? Pass -DCMAKE_PREFIX_PATH="C:/Qt/6.x/msvc2022_64".)

For security researchers

Please be critical. Bug reports, design critiques, and "this is wrong because…"
feedback are exactly what this preview is for. See SECURITY.md for the
threat model and a self-audit playbook.

Licensing

DGKN's own code is under an Evaluation License (free for personal
evaluation). Third-party open-source components keep their own licenses — see
THIRD-PARTY-NOTICES.txt.

Verifying the download

See "Windows SmartScreen warning is expected" above for full verification steps
(digital-signature fingerprint + SHA256SUMS.txt hash check).

MD5
4e728f7e6b6f3bed7e7f18443c050f6c

SHA-1
7322fc336bbe73708b934b929af3b63d7aab844f

SHA-256
36ceffed841c72d0b59450b85cbf202d1af49d91177d2e263b208db71dff14c1

Vhash
037056651d1d151az411e5z5055z32z28fz

Authentihash
add968614fa08ab57f85dfe3ff58f665121f5e3d01e862b7dc22efc807723c06

Imphash
eb0cbb54ca401e820f6974e6548a4451

Rich PE header hash
5db3d57b5f9d09ff0a01122f27ec03f7

SSDEEP
786432:Jyjn18lxNW3U+TUmH3CdKKpuPxcfYBqi4Lfh6LKE5GLB:Aj6lxNaU+THHSd7uPmf5Lf8V5GLB

TLSH
T1AC87331032CE827CD232E53647F997E6A0CA37162BAD584737417D39B260D92973DF2A

File type
Win32 EXE
executable
windows
win32
pe
peexe

Magic
PE32 executable (GUI) Intel 80386, for MS Windows

TrID
Microsoft Visual C++ compiled executable (generic) (36.5%) Win32 Dynamic Link Library (generic) (14.5%) Win64 Executable (generic) (14.4%) Win16 NE executable (generic) (11.1%) Win32 Executable (generic) (9.9%)

DetectItEasy
PE32 Installer: 7-Zip (26.01) Compiler: EP:Microsoft Visual C/C++ (6.0 (1720-9782)) [EXE32] Archive: 7-Zip (0.4) Compiler: Microsoft Visual C/C++ (19.36.35226) [C] Linker: Microsoft Linker (6.00.8047) Tool: Visual Studio (6.0)

Magika
PEBIN

File size
37.46 MB (39283496 bytes)

PEiD packer
Microsoft Visual C++