sgcCrypto Feature Matrix

Everything sgcCrypto does, mapped across the 43 units on disk. There are no components and no design-time properties here: every row below is a function or procedure you call directly. Full source code ships in every license. Anchors below take you to the six capability families the units fall into, plus the TLS 1.3 and TLS 1.2 engine the same pack builds on top of them.

sgcCrypto has no components. The 43 units below export plain functions, there is no Tsgc* class and no sgcCrypto_Reg.pas. Add a unit to your uses clause and call the function.

Already included. sgcCrypto ships free inside sgcWebSockets Standard, Professional and Enterprise, and inside All-Access. It is also sold standalone (bundling the sgcWebSockets Core runtime) for customers who only own Core. See Pricing.

Symmetric

AES, CCM, ChaCha20, Poly1305, 5 units

Hashing & KDF

SHA-2/3, BLAKE2, Argon2, 11 units

Signatures & key exchange

Ed25519, X25519, Schnorr, RSA, 10 units

PKI

X.509, ASN.1, RSA & EC CSR, 5 units

Post-quantum

ML-KEM, ML-DSA, SLH-DSA, 6 units

OTP & misc

HOTP/TOTP, encoding, ZIP AES, 6 units

TLS 1.3 and 1.2 engine

iohNativeTLS, X25519MLKEM768, pure Pascal

43 Source Units

Every sgcCrypto_*.pas unit under sgcWebSockets/delphi/Source/, grouped by family.

UnitFamilyWhat it does
sgcCrypto_AESSymmetricAES-CBC, AES-GCM (AEAD), AES-CTR.
sgcCrypto_ModesSymmetricAES-ECB, OFB, CFB, CTS, CCM (AEAD), Key Wrap / Key Wrap with Padding, and the seven padding schemes.
sgcCrypto_CMACSymmetricAES-CMAC and AES-GMAC message authentication.
sgcCrypto_ChaChaSymmetricChaCha20, XChaCha20, Salsa20, XSalsa20.
sgcCrypto_Poly1305SymmetricPoly1305 MAC, ChaCha20-Poly1305 and XChaCha20-Poly1305 AEAD.
sgcCrypto_SHA2Hashing & KDFSHA-1, SHA-224, SHA-256, SHA-384, SHA-512.
sgcCrypto_KeccakHashing & KDFSHA-3, SHAKE128/256, cSHAKE, KMAC.
sgcCrypto_Blake2bHashing & KDFBLAKE2b, keyed or unkeyed.
sgcCrypto_Blake2sHashing & KDFBLAKE2s, keyed or unkeyed.
sgcCrypto_HMACHashing & KDFHMAC-SHA1/256/384/512.
sgcCrypto_KDFHashing & KDFPBKDF2, KDF1, KDF2 and X9.63, selectable hash.
sgcCrypto_HKDFHashing & KDFHKDF extract-and-expand.
sgcCrypto_ScryptHashing & KDFscrypt memory-hard KDF.
sgcCrypto_Argon2Hashing & KDFArgon2d, Argon2i, Argon2id.
sgcCrypto_SipHashHashing & KDFSipHash-2-4 keyed hash.
sgcCrypto_TLSHHashing & KDFTLSH fuzzy hash and similarity diff.
sgcCrypto_Ed25519Signatures & key exchangeEd25519 sign / verify.
sgcCrypto_X25519Signatures & key exchangeX25519 Diffie-Hellman.
sgcCrypto_Ed448Signatures & key exchangeEd448 sign / verify.
sgcCrypto_X448Signatures & key exchangeX448 Diffie-Hellman.
sgcCrypto_GF448Signatures & key exchangeInternal GF(2^448-2^224-1) field arithmetic for Ed448/X448.
sgcCrypto_ECCurvesSignatures & key exchangeECDSA / ECDH over secp256k1, Brainpool P256r1/P384r1/P512r1 and NIST P-256/P-384/P-521, DER signatures, key export/import, and BIP-340 Schnorr.
sgcCrypto_ECSignatures & key exchangeGeneral EC sign/verify as JWS (ES256/384/512), ECDH.
sgcCrypto_RSASignatures & key exchangeRSA PKCS#1 v1.5 sign, PKCS#1 v1.5 / PSS verify, from PEM or raw.
sgcCrypto_RSA_KeysSignatures & key exchangeRSA keygen, OAEP (with independent MGF1 hash), PSS, PKCS#1 v1.5 sign/verify/encrypt/decrypt, PKCS#1 and PKCS#8 DER/PEM export and import.
sgcCrypto_ECIESSignatures & key exchangeECIES seal / open hybrid encryption over X25519.
sgcCrypto_ASN1PKIDER reader, PEM codec, PKCS#1/SEC 1 key parsing.
sgcCrypto_DERPKIDER writer primitives.
sgcCrypto_BigIntegerPKIInternal arbitrary-precision integer arithmetic.
sgcCrypto_X509PKIX.509 parse, verify, chain with pathLenConstraint and nameConstraints, CSR verify, CRL, revocation. Reads RSA, EC, Ed25519, ML-DSA, SLH-DSA and ML-KEM public keys.
sgcCrypto_X509_GenPKISelf-signed, CA-issued and PKCS#10 CSR generation, signed with RSA, EC, ML-DSA or SLH-DSA, with URI and IPv6 subject alternative names and nameConstraints.
sgcCrypto_MLKEMPost-quantumML-KEM key encapsulation (FIPS 203), 3 parameter sets, with SubjectPublicKeyInfo, PKCS#8 and PEM key import and export.
sgcCrypto_MLKEM_PolyPost-quantumInternal polynomial ring arithmetic behind ML-KEM.
sgcCrypto_MLKEM_HybridPost-quantumHybrid X25519 + ML-KEM key encapsulation, X-Wing, and the RFC 10024 TLS 1.3 hybrid key shares.
sgcCrypto_MLDSAPost-quantumML-DSA digital signatures (FIPS 204), 3 parameter sets, with SubjectPublicKeyInfo, PKCS#8 and PEM key import and export.
sgcCrypto_MLDSA_PolyPost-quantumInternal polynomial ring arithmetic behind ML-DSA.
sgcCrypto_SLHDSAPost-quantumSLH-DSA signatures (FIPS 205), 6 SHAKE parameter sets, with SubjectPublicKeyInfo, PKCS#8 and PEM key import and export.
sgcCrypto_OTPOTP & miscHOTP, TOTP, constant-time verify window.
sgcCrypto_EncodingOTP & miscConstant-time compare, secure zero, hex/Base64url/Base32.
sgcCrypto_Zip_AE2OTP & miscWinZip AES encryption for ZIP entries, AE-1 / AE-2.
sgcCrypto_LegacyOTP & miscMD4, MD5, HMAC-MD5, DES-ECB, RIPEMD-160 and HMAC-RIPEMD160, for interoperability only.
sgcCrypto_RandomOTP & miscCross-platform CSPRNG.
sgcCrypto_Int64OTP & miscInternal 64-bit integer emulation for Delphi 7.

Encryption & MACs

AES in the modes production code actually uses, plus the ChaCha20/Poly1305 AEAD family.

CapabilityFunctionNotes
AES-CBCsgcAES_CBC_Encrypt / sgcAES_CBC_DecryptPKCS#7 padding, 16-byte IV. Key length selects the cipher: 16/24/32 bytes = AES-128/192/256.
AES-CBC, no paddingsgcAES_CBC_Encrypt_NoPad / sgcAES_CBC_Decrypt_NoPadThe mode Java writes as AES/CBC/NoPadding. The input must already be a multiple of 16 bytes; an unaligned input raises instead of being silently padded into something the other side cannot read.
AES-GCM (AEAD)sgcAES_GCM_Encrypt / sgcAES_GCM_Decrypt12-byte IV recommended. 16-byte tag, compared in constant time; decrypt returns False and empty plaintext on a failed tag.
AES coresgcAES_GetCore / sgcAES_SetCoreaescConstantTime is the default, a bitsliced core that never indexes memory with a secret byte or branches on one, which closes the cache timing channel on the key and the plaintext. aescTable is the classic table core, which leaks through the data cache and was slower in every measurement, so it is kept only as a fallback. GHASH, which authenticates GCM, multiplies under a mask instead of branching on the key. Set the core once at start up, before any worker thread runs.
AES-CCM (AEAD)sgcAES_CCM_Encrypt / sgcAES_CCM_DecryptThe AEAD constrained and IoT stacks specify, Zigbee, 802.15.4, Bluetooth and the TLS CCM suites, because it needs only the block cipher and no GHASH table. Nonce 7 to 13 bytes, tag 4 to 16 bytes, verified in constant time.
AES-CTRsgcAES_CTRSRTP-style AES-CM (RFC 3711). Symmetric call, no padding, 128-bit big-endian counter.
AES-ECBsgcAES_ECB_Encrypt / sgcAES_ECB_DecryptNo IV, no chaining. Included for interoperability with formats that specify it.
Padding schemessgcPad_Add / sgcPad_Remove, sgcAES_CBC_EncryptPad / DecryptPad, sgcAES_ECB_EncryptPad / DecryptPadTsgcPadding covers None, PKCS#7, Zero, ANSI X9.23, ISO 7816-4, ISO 10126-2 and TBC, so CBC and ECB can read and write data from a system that did not choose PKCS#7. sgcPad_Remove returns False down the same path for every kind of bad pad.
AES-OFB / AES-CFBsgcAES_OFB, sgcAES_CFB_Encrypt / sgcAES_CFB_DecryptStream-cipher-style feedback modes.
AES-CTSsgcAES_CTS_Encrypt / sgcAES_CTS_DecryptCiphertext stealing: encrypts data not a multiple of the block size with no padding overhead.
AES Key WrapsgcAES_KeyWrap / sgcAES_KeyUnwrapRFC 3394, for wrapping one key under another.
AES Key Wrap with PaddingsgcAES_KeyWrapPad / sgcAES_KeyUnwrapPadRFC 5649, for key material not a multiple of 8 bytes.
AES-CMACsgcAES_CMAC / sgcAES_CMAC_VerifyRFC 4493 message authentication code.
AES-GMACsgcAES_GMAC / sgcAES_GMAC_VerifyGCM's authentication-only mode: the whole message travels as additional data, nothing is encrypted. The IV must never repeat under one key, and the 16-byte tag is compared in constant time.
Low-level block primitivessgcAES_ExpandKey, sgcAES_EncryptBlock, sgcAES_DecryptBlockExposed for the mode and MAC units above; call these directly only to build a mode not already provided.
ChaCha20sgcChaCha20RFC 8439, 96-bit nonce, 32-bit counter.
XChaCha20sgcXChaCha20192-bit extended nonce, safe for random nonce generation at scale.
Salsa20 / XSalsa20sgcSalsa20 / sgcXSalsa20The predecessor stream cipher family, both nonce sizes.
Subkey derivationsgcHChaCha20 / sgcHSalsa20What the X-variants use internally to derive a subkey from the first 16 nonce bytes.
Poly1305 MACsgcPoly1305 / sgcPoly1305_VerifyOne-time authenticator, RFC 8439. Never reuse a Poly1305 key.
ChaCha20-Poly1305 AEADsgcChaCha20Poly1305_Encrypt / _DecryptThe AEAD cipher behind TLS 1.3's second cipher suite and SSH.
XChaCha20-Poly1305 AEADsgcXChaCha20Poly1305_Encrypt / _DecryptSame AEAD, 192-bit nonce, the construction libsodium calls crypto_aead_xchacha20poly1305_ietf.

Digests, MACs & Password Hashing

Every mainstream hash family, plus PBKDF2, HKDF, scrypt and all three Argon2 variants.

CapabilityFunctionNotes
SHA-1 / SHA-2sgcSHA1, sgcSHA224, sgcSHA256, sgcSHA384, sgcSHA512FIPS 180-4. SHA-1 is kept for interoperability, not recommended for new signatures.
SHA-3sgcSHA3_224 / _256 / _384 / _512FIPS 202, the Keccak sponge, structurally independent from SHA-2.
SHAKE128 / SHAKE256sgcSHAKE128 / sgcSHAKE256Extendable-output functions: request any digest length.
cSHAKE128 / cSHAKE256sgcCSHAKE128 / sgcCSHAKE256Domain-separated SHAKE, NIST SP 800-185, the basis for KMAC.
KMAC128 / KMAC256sgcKMAC128 / sgcKMAC256Keccak-based MAC with a variable output length.
BLAKE2bsgcBlake2b / sgcBlake2b_KeyedRFC 7693, digests up to 64 bytes, built-in keying (no separate HMAC needed).
BLAKE2ssgcBlake2s / sgcBlake2s_KeyedRFC 7693, digests up to 32 bytes, tuned for 32-bit platforms.
Streaming digestssgcBlake2b_Init/_Update/_Final, matching calls on Keccak/Blake2sFor hashing data too large to hold in memory at once.
HMACsgcHMAC_SHA1 / _SHA256 / _SHA384 / _SHA512RFC 2104 keyed hashing over the SHA-1/2 family.
RIPEMD-160 / HMAC-RIPEMD160sgcRIPEMD160, sgcHMAC_RIPEMD160ISO/IEC 10118-3 and RFC 2286. The 160-bit digest Bitcoin addresses layer over SHA-256, and the one OpenPGP names.
PBKDF2sgcPBKDF2, sgcPBKDF2_SHA1 / _SHA256 / _SHA512RFC 8018. Only mildly memory-hard; prefer Argon2id or scrypt when you can choose.
HKDFsgcHKDF_Extract_SHA256 / _SHA384, sgcHKDF_Expand_SHA256 / _SHA384, sgcHKDF_SHA256 / _SHA384RFC 5869, extract-then-expand key derivation, the standard way to turn a shared secret into several keys.
KDF1 / KDF2 / X9.63sgcKDF1, sgcKDF2, sgcKDF_X963The counter-mode derivations ISO 18033-2, IEEE 1363a and ANSI X9.63 define, which is what RSA-KEM and ECIES name. KDF1 counts from 0 and KDF2 from 1, a difference that has caused real interoperability bugs, so check which one your spec means.
scryptsgcScryptRFC 7914, memory-hard, resists GPU/ASIC attack far better than PBKDF2.
Argon2sgcArgon2 (d / i / id), sgcArgon2id convenience wrapperRFC 9106, the Password Hashing Competition winner. Full interface with optional secret (pepper) and associated data.
SipHash-2-4sgcSipHash24 / sgcSipHash24_ValueFast keyed PRF for hash-table keys, resists hash-flooding denial of service.
TLSH fuzzy hashsgcTLSH, sgcTLSH_Init/_Update/_FinalLocality-sensitive hash for near-duplicate detection, not a cryptographic digest.
TLSH similarity scoresgcTLSH_DiffDistance between two TLSH digests; lower means more similar.

Ed25519/Ed448, X25519/X448, secp256k1, Brainpool & RSA

Sign, verify and derive shared secrets across five distinct curve families plus RSA.

CapabilityFunctionNotes
Ed25519 sign / verifysgcEd25519_Sign / sgcEd25519_Verify, sgcEd25519_PublicKeyRFC 8032. 32-byte public key, 64-byte signature. Verify rejects non-canonical points and S >= L per section 5.1.7. Signing is constant time in the secret scalar and in the per-message nonce: fixed four-bit windows, the table entry chosen by scanning all sixteen under a mask, and the complete addition formula of section 5.1.4. The public key comes from the 32-byte seed.
X25519 key exchangesgcX25519, sgcX25519_PublicKey, sgcX25519_SharedSecretRFC 7748 Diffie-Hellman over Curve25519.
Ed448 sign / verifysgcEd448_GenerateKeyPair, sgcEd448_Sign, sgcEd448_VerifyRFC 8032, the 448-bit (Goldilocks) EdDSA curve.
X448 key exchangesgcX448, sgcX448_PublicKey, sgcX448_SharedSecretRFC 7748 Diffie-Hellman over Curve448.
secp256k1sgcECDSA_SignHash / VerifyHash with eccSecp256k1The Bitcoin/Ethereum curve, SEC 2, in sgcCrypto_ECCurves.
Brainpool P256r1 / P384r1 / P512r1same functions with eccBrainpoolP256r1 / P384r1 / P512r1RFC 5639, common in EU eIDAS and government profiles.
NIST P-256 / P-384 / P-521same functions with eccP256 / eccP384 / eccP521TsgcECCurve now names seven curves, so key generation, signing, verification, ECDH and point compression all reach the NIST prime curves from raw key bytes, not only from a PEM file.
Deterministic ECDSA noncebuilt into sgcECDSA_SignHashRFC 6979: the nonce is derived from the private key and message, no RNG failure mode.
Constant-time scalar multiplicationinside sgcECDSA_SignHash, sgcECDH_SharedSecret and EC key generationEvery curve in sgcCrypto_ECCurves runs the same engine: Montgomery reduction, which has no data-dependent step, a fixed window whose count comes from the curve, table entries chosen by scanning all of them under a mask, and a complete addition formula that never looks at a coordinate to decide which case applies. The JOSE, WebAuthn and E2EE paths of sgcCrypto_EC run the same code.
ECDH (secp256k1 / Brainpool)sgcECDH_SharedSecretShared secret over the same four curves.
Point compressionsgcEC_Compress / sgcEC_DecompressStore or transmit the shorter compressed public-key form.
EC as JWS (ES256/384/512)sgcECDSA_SignJWS / sgcECDSA_VerifyJWSCurve selected automatically from the requested bit length, sign/verify directly from a PEM key, JOSE-oriented sibling of ECCurves.
Generic ECDHsgcECDHShared secret from a raw private key and peer public point.
Raw / DER ECDSA verifysgcECDSA_VerifyRaw / sgcECDSA_VerifyDERVerify against a raw (Qx, Qy, r, s) tuple or a DER-encoded signature.
DER ECDSA signing & conversionsgcECDSA_SignDER / sgcECDSA_VerifyDER, sgcECDSA_RawToDER / sgcECDSA_DERToRawX.509, CMS and TLS carry the DER ECDSA-Sig-Value, a SEQUENCE of INTEGER r then INTEGER s. JOSE and WebAuthn carry the raw R || S pair instead. Sign straight into either form, or convert an existing signature between them.
Schnorr signatures (BIP-340)sgcSchnorr_PublicKey, sgcSchnorr_Sign, sgcSchnorr_Verifysecp256k1 only, with x-only 32-byte public keys and 64-byte signatures: what Taproot, Nostr and Lightning use. sgcSchnorr_TaggedHash is exposed so the BIP-341 and BIP-342 tags can be built on the same construction.
RSA sign (PKCS#1 v1.5)sgcRSA_SignPKCS1From a PEM private key, SHA-1/256/384/512 digest.
RSA private key operationssgcRSA_SignPKCS1 and the other signing and decryption calls of sgcCrypto_RSA_KeysEach operation is blinded with a fresh random pair, run through a fixed-window exponentiation and a CRT recombination whose timing does not depend on the factors or the data, and checked against the public exponent before the result is returned. A fault in one CRT half would otherwise give away a factor in a single signature, so on a mismatch nothing is returned.
RSA verify (PKCS#1 v1.5 / PSS)sgcRSA_VerifyPKCS1, sgcRSA_VerifyPSS, and _Raw variants over a modulus/exponentRFC 8017. Verify works from a PEM key or raw modulus and exponent, no key-object construction required.
RSA key generationsgcRSA_GenerateKeyAny requested bit length, Miller-Rabin primality testing.
RSA-OAEP encryptionsgcRSA_OAEP_Encrypt / sgcRSA_OAEP_DecryptRFC 8017 optimal asymmetric encryption padding.
RSA-OAEP with an independent MGF1 hashthe five-parameter sgcRSA_OAEP_Encrypt / sgcRSA_OAEP_Decrypt overloadsPin the label hash and the MGF1 hash separately. OAEPWithSHA256AndMGF1Padding means SHA-256 for both in Bouncy Castle but SHA-256 with MGF1-SHA1 in SunJCE, and that mismatch is the usual reason Java interoperability fails.
RSA PKCS#1 v1.5 encryptionsgcRSA_PKCS1_Encrypt / sgcRSA_PKCS1_DecryptRFC 8017 section 7.2, the mode Java names RSA/ECB/PKCS1Padding. Decrypt takes the same path for every failure so it gives a padding oracle nothing to work with. Prefer OAEP for anything new.
RSA-PSS / PKCS#1 signingsgcRSA_PSS_Sign / Verify, sgcRSA_PKCS1_Sign / VerifySign directly from a generated TsgcRSAPrivateKey.
RSA key exportsgcRSA_ExportPrivateKeyPEM, sgcRSA_ExportPublicKeyPEM, matching DER callsPKCS#1 and SubjectPublicKeyInfo encodings.
PKCS#8 and SEC 1 key exportsgcRSA_ExportPrivateKeyPKCS8DER / PKCS8PEM, sgcEC_ExportPrivateKeyPKCS8DER / PKCS8PEM, sgcEC_ExportPrivateKeySEC1DER / SEC1PEM, sgcEC_ExportSubjectPublicKeyInfo, sgcEC_ExportPublicKeyPEMThe BEGIN PRIVATE KEY container Java, .NET and most modern tooling expect, alongside the SEC 1 BEGIN EC PRIVATE KEY form and the SubjectPublicKeyInfo a certificate embeds. Unencrypted, so what comes back is bare key material.
RSA and EC key importsgcRSA_ImportPrivateKeyDER / PEM, sgcRSA_ImportPublicKeyDER / PEM, sgcEC_ImportPrivateKeyDER / PEM, sgcEC_ImportPublicKeyDER / PEMThis did not exist before: a generated key could be written out but never read back in. Import accepts PKCS#1, PKCS#8, SEC 1 and SubjectPublicKeyInfo, DER or PEM, recomputes the CRT parameters or the public point when the file omits them, and returns False on malformed input rather than raising, so untrusted files are safe to hand it.
ECIES seal / opensgcECIES_GenerateKeyPair, sgcECIES_Seal, sgcECIES_OpenHybrid encryption to an X25519 public key: ephemeral ECDH plus an AEAD, one call each way.

X.509 Certificates & ASN.1

Read a certificate someone else issued, or generate one yourself, with a DER encoder and decoder underneath both.

CapabilityFunctionNotes
DER readersgcASN1_Read, sgcASN1_Next, sgcASN1_ContentWalks a DER structure node by node.
Strict DERsgcASN1_Read, sgcASN1_IsMinimalUnsignedIntegerEvery structure the unit reads is DER by specification, so lengths are held to the DER rules: the indefinite form is refused, and so is a long form the short form could have carried. An ECDSA signature whose INTEGERs are not minimally encoded is refused as well, so one signature cannot be written two ways and be taken for two different values.
PEM codecsgcPEM_Decode / sgcPEM_EncodeRFC 7468, the -----BEGIN ... -----END wrapper around DER.
RSA key parsingsgcASN1_ParseRSAPrivateKey / PublicKeyPKCS#1 (RFC 8017) key structures.
EC key parsingsgcASN1_ParseECPrivateKey / PublicKeySEC 1 key structures.
DER writer, structuralsgcDER_Sequence, sgcDER_Set, sgcDER_Tagged, sgcDER_ContextExplicit / ImplicitThe building blocks every certificate field is assembled from.
DER writer, valuessgcDER_Integer, sgcDER_OctetString, sgcDER_BitString, sgcDER_Boolean, sgcDER_NullPrimitive value encoders.
DER writer, strings & identifierssgcDER_OID, sgcDER_UTF8String, sgcDER_PrintableString, sgcDER_IA5String, sgcDER_TimeObject identifiers, the three string types X.509 uses, and UTCTime/GeneralizedTime.
Certificate parsingsgcX509_ParseFull certificate structure: subject, issuer, validity, public key, extensions.
Signature / chain verificationsgcX509_VerifySignedBy, sgcX509_VerifyChainVerify one certificate against an issuer, or walk and verify an array of DER certificates.
CRL parsing & revocationsgcX509_CRL_Parse, sgcX509_IsRevoked, sgcX509_CRL_VerifySignedByParse a Certificate Revocation List and check a serial number against it.
Name formattingsgcX509_SubjectRFC2253, sgcX509_IssuerRFC2253, sgcX509_SubjectOneLineRFC 2253 distinguished-name strings, for logging and display.
Extensions & SANssgcX509_GetExtension, sgcX509_GetCRLDistributionURIsRead arbitrary extension OIDs and CRL distribution point URIs.
Self-signed certificate generationsgcX509_CreateSelfSignedFull TsgcX509Options: subject DN, validity window, serial number, CA flag with path-length constraint, key usage, extended key usage, subject alternative names (including IPv4 SANs).
URI subject alternative namesTsgcX509Options.URIsuniformResourceIdentifier SANs, for a SPIFFE-style service identity rather than a host name. The value is written verbatim as IA5String content, so pass a full URI.
PKCS#10 CSR generationsgcX509_CreateCSRRFC 2986 certificate signing request from the same options record.
EC-signed certificates & CSRssgcX509_CreateSelfSignedEx, sgcX509_CreateCSREx, sgcX509_ECKey, sgcX509_RSAKeySign with an EC key as well as RSA by wrapping either one in a TsgcX509SignKey. An EC certificate is roughly a third the size of an RSA one and verifies far faster. TsgcX509Options.Hash still names only the SHA, the algorithm follows the key, so rhSHA256 with an EC key means ecdsa-with-SHA256.
CA issuancesgcX509_CreateSigned, sgcX509_CreateSignedFromCSRIssue a certificate signed by a CA key, either from an options record or from a parsed PKCS#10 request.
Post-quantum signing keyssgcX509_MLDSAKey, sgcX509_SLHDSAKeyWrap an ML-DSA or SLH-DSA key in a TsgcX509SignKey and hand it to sgcX509_CreateSelfSignedEx, sgcX509_CreateCSREx or the CA issuers. RFC 9881 for ML-DSA, RFC 9909 for SLH-DSA.
ML-KEM certificatessgcX509_CreateSigned with an ML-KEM subject keyRFC 9935. A CA can certify an ML-KEM public key, which cannot sign, so possession has to be proved some other way before the certificate is issued.
Post-quantum key types on readTsgcX509PublicKeyTypex509pkMLDSA, x509pkSLHDSA and x509pkMLKEM alongside x509pkRSA, x509pkEC and x509pkEd25519. sgcX509_Parse, sgcX509_VerifySignedBy and sgcX509_CSR_Verify all handle them.
Chain constraintssgcX509_VerifyChainEnforces the basicConstraints pathLenConstraint and the nameConstraints extension, over dNSName, iPAddress, rfc822Name, uniformResourceIdentifier and directoryName.
nameConstraints on generationTsgcX509Options.PermittedDNSNames, ExcludedDNSNames, PermittedIPRanges, ExcludedIPRangesWrites the permitted and excluded subtrees into a CA certificate, so the chain verifier above can enforce them.
IPv6 address SANsTsgcX509Options.IPAddressesAccepts IPv6 in any RFC 4291 text form, as well as IPv4.
PEM outputsgcX509_ToPEMWraps the generated DER as a ready-to-save PEM file.

ML-KEM, ML-DSA & SLH-DSA

The three algorithms NIST finalized in August 2024 as FIPS 203, 204 and 205, plus a hybrid combiner for the migration period.

CapabilityFunctionNotes
ML-KEM key generationsgcMLKEM_GenerateKeyPair, sgcMLKEM_GenerateKeyPairFromSeedFIPS 203, formerly Kyber. Three parameter sets: mlkem512, mlkem768, mlkem1024.
ML-KEM encapsulatesgcMLKEM_Encapsulate, sgcMLKEM_EncapsulateWithSeedProduces a fresh 32-byte shared secret and the ciphertext that carries it. The public key gets the input checks of FIPS 203 section 7.2 first, so one of the wrong length, or one that fails the modulus check, raises.
ML-KEM decapsulatesgcMLKEM_DecapsulateA ciphertext of the right length that does not decrypt yields a pseudorandom secret (implicit rejection) instead of an error, so timing and error behavior reveal nothing. A ciphertext or private key of the wrong length, or a private key that fails the hash check, raises first, per the input checks of FIPS 203 section 7.3.
ML-KEM sizessgcMLKEM_PublicKeySize, PrivateKeySize, CiphertextSize, SharedSecretSizeByte lengths per parameter set, for buffer sizing.
Hybrid X25519 + ML-KEMsgcHybrid_GenerateKeyPair, sgcHybrid_Encapsulate, sgcHybrid_DecapsulateCombines a classical and a post-quantum shared secret through a KDF, so the result is never weaker than X25519 alone. The recommended way to deploy ML-KEM today.
ML-DSA key generationsgcMLDSA_GenerateKeyPair, sgcMLDSA_GenerateKeyPairFromSeedFIPS 204, formerly Dilithium. Three parameter sets: mldsa44, mldsa65, mldsa87.
ML-DSA sign / verifysgcMLDSA_Sign / sgcMLDSA_VerifyDeterministic or randomized signing per the FIPS 204 interface, plus a context string.
ML-DSA sizessgcMLDSA_PublicKeySize, PrivateKeySize, SignatureSizeByte lengths per parameter set.
SLH-DSA key generationsgcSLHDSA_GenerateKeyPair, sgcSLHDSA_GenerateKeyPairFromSeedFIPS 205, formerly SPHINCS+. Stateless hash-based signatures: security rests on the hash function alone, not on a lattice or curve assumption.
SLH-DSA sign / verifysgcSLHDSA_Sign / sgcSLHDSA_VerifySix SHAKE parameter sets: slhShake128s, slhShake128f, slhShake192s, slhShake192f, slhShake256s, slhShake256f. The s sets favor small signatures, the f sets favor fast signing.
SLH-DSA sizes & namingsgcSLHDSA_PublicKeySize, PrivateKeySize, SignatureSize, sgcSLHDSA_ParamsNameSLH-DSA signatures are large (7.8 KB to 49 KB depending on the set); size the buffer before you sign.
Public key export & import, DERsgcMLDSA_ExportSubjectPublicKeyInfo / ImportSubjectPublicKeyInfo, and the identical sgcMLKEM_* and sgcSLHDSA_* pairsX.509 SubjectPublicKeyInfo, so a post-quantum public key goes into the same structure an RSA or EC one does. RFC 9881, RFC 9909 and RFC 9935.
Private key export & import, DERsgcMLDSA_ExportPrivateKeyInfo / ImportPrivateKeyInfo, and the sgcMLKEM_* and sgcSLHDSA_* pairsPKCS#8 OneAsymmetricKey, versions 0 and 1. Import checks the key for consistency: an embedded public key that does not match is refused, the seed and expanded forms of the same key must agree, and an ML-DSA key must reproduce its stored t0 and tr. SLH-DSA recomputes PK.root from the seed, which costs about one key generation, so those imports take an aVerify parameter, True by default, that you can pass as False for a key your own application generated.
PEM export & importsgcMLDSA_ExportPublicKeyPEM, ExportPrivateKeyPEM, ImportPublicKeyPEM, ImportPrivateKeyPEM, and the sgcMLKEM_* and sgcSLHDSA_* setsRFC 7468, the -----BEGIN ... -----END wrapper, so the keys drop into the same files and tooling as the rest of the PKI.
Private key formTsgcPQCPrivateKeyFormatML-DSA and ML-KEM private keys have three forms. pqkfSeed writes the seed alone (32 bytes for ML-DSA, the 64-byte d||z seed for ML-KEM), pqkfExpanded writes the expanded key, pqkfBoth carries both. SLH-DSA has one private key form only.
Key generation with the seedsgcMLDSA_GenerateKeyPairAndSeed, sgcMLKEM_GenerateKeyPairAndSeedReturn the seed alongside the key pair, so a seed-form PKCS#8 or PEM file can be written straight after generation.
X-Wing hybrid KEMsgcXWing_GenerateKeyPair, sgcXWing_Encapsulate, sgcXWing_Decapsulatedraft-connolly-cfrg-xwing-kem-10: X25519 with ML-KEM-768 as a single KEM. Public key 1216 bytes, private key 32 bytes (the seed), ciphertext 1120 bytes, shared secret 32 bytes.
TLS 1.3 hybrid key sharessgcTLSHybrid_ClientKeyShare, sgcTLSHybrid_ServerKeyShare, sgcTLSHybrid_ClientSharedSecret, sgcTLSHybrid_GroupName, sgcTLSHybrid_AvailableThe RFC 10024 groups X25519MLKEM768, SecP256r1MLKEM768 and SecP384r1MLKEM1024 (IANA codepoints 0x11EC, 0x11EB, 0x11ED). These are not standalone KEMs, they only build a TLS key share.
ML-DSA for JSON Web TokensJWTOptions.Algorithms.MLDSA.PrivateKey, PublicKey, Enabled, sgcMLDSA_ExportPublicJWK, sgcMLDSA_ExportPrivateJWK, sgcMLDSA_ImportJWK, sgcMLDSA_ImportJWKAsPEMRFC 9964, in sgcHTTP_JWT_MLDSA rather than in an sgcCrypto_* unit. JWS algorithms ML-DSA-44, ML-DSA-65 and ML-DSA-87 (jwtMLDSA44, jwtMLDSA65, jwtMLDSA87), a PKCS#8 PEM on the client, a SubjectPublicKeyInfo PEM on the server, AKP JSON Web Keys, and no OpenSSL anywhere in the path.
Known-answer validationNIST ACVP vectorsML-KEM key generation, encapsulation and decapsulation, and ML-DSA and SLH-DSA key generation, signature generation and signature verification, are checked against the NIST ACVP known-answer vectors in the sgcWebSockets QA suite.

sgcCrypto does not claim ed25519187 or SPECK. ed25519187 has no published specification, and SPECK was withdrawn from ISO standardization in 2018; neither is implemented here.

A TLS 1.3 and TLS 1.2 Stack on Top of These Units

Written in Object Pascal on the sgcCrypto primitives and shipped in the same pack. It lives in the sgcSSL_NativeTLS* units, not in sgcCrypto_*, so it is not one of the 43 counted above.

CapabilityAPINotes
Select it on a clientTLSOptions.IOHandler := iohNativeTLSReplaces OpenSSL, SChannel and the platform TLS backends with the in-process Pascal engine. Nothing to deploy on any target.
Select it on a serverSSLOptions.IOHandler := iohNativeTLSWorks with the default Indy server engine and with the IOCP and EPOLL engines.
Protocol versionTLSOptions.VersionThe lowest version allowed. tls1_2 or tlsUndefined negotiates TLS 1.3 or TLS 1.2, tls1_3 allows TLS 1.3 only, and tls1_0 or tls1_1 raises a configuration error. SSLOptions.Version does the same on a server. For TLS 1.2 only, list only TLS 1.2 suites in CipherSuites.
Key exchange groupsTLSOptions.NativeTLS_Options.GroupsColon separated, OpenSSL style. Default X25519MLKEM768:X25519:secp256r1:secp384r1, so a handshake is post-quantum hybrid whenever the peer agrees. A build with SGC_CRYPTO_FIPS defaults to SecP256r1MLKEM768:SecP384r1MLKEM1024:secp256r1:secp384r1 instead. The three hybrid groups are TLS 1.3 only, so a TLS 1.2 connection uses X25519, secp256r1 or secp384r1.
Cipher suitesTLSOptions.NativeTLS_Options.CipherSuitesColon separated, OpenSSL style. Default TLS_AES_256_GCM_SHA384:TLS_CHACHA20_POLY1305_SHA256:TLS_AES_128_GCM_SHA256 for TLS 1.3, plus ECDHE_ECDSA and ECDHE_RSA with AES-128-GCM, AES-256-GCM and ChaCha20-Poly1305 for TLS 1.2. ECDHE with AES-CBC and the RSA key exchange are used only when named, for 20 TLS 1.2 suites in all. A build with SGC_CRYPTO_FIPS leaves ChaCha20-Poly1305 and the RSA key exchange out.
Trust rootsTLSOptions.RootCertFile, TLSOptions.NativeTLS_Options.UseSystemRootsRoots come from RootCertFile. Set UseSystemRoots to True to add the roots the operating system already trusts: the ROOT store on Windows, and on every other platform the first CA bundle file found among the standard locations. It never reads the macOS or iOS keychain or the Android store. It is off by default, so RootCertFile stays the source. The same property on SSLOptions applies to the client certificates a server verifies.
Chain buildingthe certificate chain the peer sendsThe chain is searched for a path from the leaf to a trust root, so extra certificates and any order are accepted, as RFC 8446 section 4.4.2 asks. The search backtracks, so a certificate that names the right issuer but leads nowhere no longer hides a valid path behind it. Revocation and certificate policies are not checked.
Protocol scopeRFC 8446, RFC 5246TLS 1.3 and TLS 1.2. No TLS 1.1, TLS 1.0 or SSL. TLS 1.2 uses the extended master secret of RFC 7627 and the RFC 8446 downgrade protection on both sides, refuses renegotiation and SHA-1 signatures (RFC 9155), and checks CBC records in constant time.
Not implementedn/aNo session resumption and no PSK, no 0-RTT, and no QUIC.
Peer verification eventOnSSLVerifyPeerNot available for this engine, which has its own verification hooks. Stay on OpenSSL or a platform backend if your code depends on that event.

One-Time Passwords, Codecs & Encrypted ZIP

The utility layer: one-time codes, the encodings every other family leans on, and WinZip AES encryption.

CapabilityFunctionNotes
HOTPsgcHOTPRFC 4226, counter-based one-time password.
TOTPsgcTOTP, sgcTOTP_FromBase32RFC 6238, time-based one-time password; the Base32 variant accepts the secret exactly as an authenticator app displays it.
TOTP verificationsgcTOTP_VerifyChecks a submitted code across a window of steps in constant time, so neither the result nor its position leaks through timing. Does not itself stop replay; the caller tracks used codes.
Constant-time comparesgcConstantTimeEqualsUsed throughout the library for tag and MAC comparisons.
Secure zerosgcSecureZeroOverwrites a byte buffer so key material does not linger in memory.
HexsgcHexEncode / sgcHexDecodeLower-case hex, case-insensitive decode.
Base64urlsgcBase64UrlEncode / sgcBase64UrlDecodeRFC 4648 section 5, unpadded, the encoding JWT and JOSE use.
Base32sgcBase32Encode / sgcBase32DecodeRFC 4648 section 6, the encoding TOTP secrets and authenticator apps use.
WinZip AES key derivationsgcZipAE2_DeriveKeysPBKDF2-based key, authentication key and password verifier from a password and salt.
WinZip AES encrypt / decryptsgcZipAE2_Encrypt / sgcZipAE2_DecryptAE-1 and AE-2, AES-128/192/256, per-entry salt sizing via TsgcZipAESStrength.
WinZip entry packingsgcZipAE2_PackEntry / sgcZipAE2_UnpackEntryCombines salt, verifier, ciphertext and authentication code into the on-disk layout.
WinZip extra fieldsgcZipAE2_BuildExtraField / sgcZipAE2_ParseExtraFieldThe 0x9901 extra field that marks a ZIP entry as AES-encrypted.
Legacy hashes (interop only)sgcMD4, sgcMD5, sgcHMAC_MD5Kept for reading older formats and protocols; do not use in a new design.
Legacy cipher (interop only)sgcDES_EncryptECB / sgcDES_DecryptECB, sgcDES_NTLM7to8DES-ECB and the DES-based NTLM key-expansion step, both withdrawn (FIPS 46-3), kept for legacy interoperability.
Secure random bytessgcRandomBytes / sgcRandomFillBCryptGenRandom (Windows CNG) under MSWINDOWS, /dev/urandom elsewhere, one call either way.

Where sgcCrypto Runs

What is supported, stated precisely.

AreaDetail
Operating systemNo MSWINDOWS guard, or any other platform guard, wraps SGC_CRYPTO in sgcVer.inc. All 43 units compile for Win32, Win64, Linux64, macOS, iOS and Android.
Random number sourceThe one platform-aware unit, sgcCrypto_Random, selects a CSPRNG per target: BCryptGenRandom (Windows CNG) under MSWINDOWS, /dev/urandom on POSIX targets, behind the same sgcRandomBytes call. The bytes come straight from the operating system generator, with no generator of its own on top. On Windows, RtlGenRandom and then CryptGenRandom are used only when BCryptGenRandom is not available, and if no source can be read an exception is raised instead of returning weak bytes.
FIPS modeOptional SGC_CRYPTO_FIPS define, off by default, that removes every non-approved algorithm from the 43 units at compile time and checks a few parameter rules at run time. It keeps the library within FIPS-approved algorithms, but sgcCrypto is not a FIPS 140-3 validated module and the define is not a validation claim. FIPS Mode
DelphiDelphi 7 through RAD Studio 13 Florence. No native 64-bit integer type is assumed anywhere: sgcCrypto_Int64 and the TsgcBigInt type in sgcCrypto_BigInteger emulate the arithmetic the hashes, curves and post-quantum units need.
C++ BuilderC++ Builder through the generated headers, same source tree.
Design-time footprintNone. There is no sgcCrypto_Reg.pas, nothing is RegisterComponents'd, and no unit appears on a component palette page.
DependenciesNo OpenSSL binding, no external DLL. Every primitive is implemented directly in Object Pascal inside the unit you reference.
Source codeFull Object Pascal source in every paid tier, and in the edition packages that already include sgcCrypto.
RedistributionBinaries you build are royalty free, with no per-seat or per-server runtime fee.
Best value: All-AccessEvery eSeGeCe product, Premium Support included, from €1,059/year.
See All-Access pricing

Build with sgcCrypto

Download the free trial and call a function, no component required.