PDF Encryption Explained: RC4 vs AES-128 vs AES-256
PDF encryption is the cryptographic protection applied to a PDF's content streams so the file cannot be read without a password. The PDF spec has supported several algorithms over its history, and not all of them are still safe. This page explains what each algorithm does, which PDF version introduced it, and which you should choose when protecting a file today.
Mechanism
How PDF encryption works
When a PDF writer encrypts a file, it generates a random file encryption key, uses that key to encrypt the content streams (and certain other strings in the file), and then stores the file encryption key in an encryption dictionary protected by the user's password. To open the file, a viewer asks for the password, derives a key from it, uses that key to decrypt the file encryption key, and then uses the file encryption key to decrypt the content.
The important consequence: the password is not stored in the file. What is stored is a value encrypted with the password. To verify a password, the viewer tries to decrypt that value and checks the result against a known plaintext marker. This is why there is no password recovery — the file does not contain the password, only something locked by it.
Algorithm
RC4 — deprecated and broken
RC4 is a stream cipher designed in 1987 and used widely in the 1990s (PDF, SSL, WEP). PDF 1.2 introduced 40-bit RC4; later versions extended it to 128-bit RC4. RC4 is now deprecated in PDF and considered broken for modern security use. Specifically:
- 40-bit RC4 is trivially brute-forceable on modern hardware.
- 128-bit RC4 is not brute-forceable, but RC4 has statistical biases that leak information about the plaintext, and several practical attacks on RC4-encrypted PDFs have been published.
- Modern viewers warn about or refuse to open RC4-encrypted files in some configurations.
Do not create new RC4-encrypted PDFs. If you encounter one, decrypt it (with the password) and re-encrypt with AES-128 or AES-256.
Algorithm
AES-128 — solid, widely supported
AES-128 was introduced in PDF 1.5 (2003, Acrobat 6/7). AES is a block cipher; AES-128 uses a 128-bit key. PDF's AES mode uses CBC with a random 16-byte initialization vector per string. AES-128 has no practical attacks against it and is widely supported by every modern PDF viewer. It is a reasonable default when AES-256 is not available.
Algorithm
AES-256 — the current standard
AES-256 was introduced in PDF 1.6 Extension Level 3 (2008, Acrobat 9). It uses a 256-bit key and, in the original PDF 1.6 Ext Level 3 design, derives the key from the password with SHA-256. A later revision (PDF 2.0 / Extension Level 8) added a stronger key derivation that uses PBKDF2 with many iterations, making brute-force much harder. This is sometimes called "AES-256 R6" or "Acrobat X compatibility."
Prefer AES-256 whenever your tool offers it. If you have a choice between the older and newer key derivation, pick the newer (PBKDF2-based) one.
History
Which PDF version introduced which algorithm
- PDF 1.2 (1996) — 40-bit RC4.
- PDF 1.3 (1999) — 128-bit RC4.
- PDF 1.5 (2003) — AES-128 (V4, R4).
- PDF 1.6 Ext Level 3 (2008) — AES-256 (V5, R5).
- PDF 2.0 / Ext Level 8 (2017) — AES-256 with PBKDF2 key derivation (V5, R6).
Practical
Which algorithm to choose
For new files: AES-256 with PBKDF2 key derivation (R6) if both signer and recipient viewers support it; otherwise AES-128. Never choose RC4 for a new file. The password matters more than the algorithm: a 6-character password on AES-256 is weaker than a 20-character random password on AES-128, because the attack surface is the password, not the cipher.
For opening old files: any modern viewer will handle all three. If you control the file, decrypt and re-encrypt with AES-256.
A useful sanity check: after protecting a PDF, try opening it in a different viewer than the one you used to encrypt it. If a second viewer can open it without warnings, the encryption is broadly compatible. If only the original tool can open it, you may have used a non-standard mode.
IXPDF
IXPDF's encryption capability today
IXPDF's current PDF engine (pdf-lib) does not support writing or reading encrypted PDFs. TheProtect PDF andUnlock PDF pages explain the limitation honestly and are marked Research Required. We are evaluating a browser-compatible encryption library that would let us offer AES-256 protection entirely in the browser, with no upload. Until then, see ourpassword protection guide for trusted local tools.
Keep reading