"The passcode is “tangled” with the device’s UID, so brute-force attempts must be per-formed on the device under attack. A large iteration count is used to make each attempt slower. The iteration count is calibrated so that one attempt takes approximately 80 milliseconds. This means it would take more than 5½ years to try all combinations of a six-character alphanumeric passcode with lowercase letters and numbers."
There's more info on the file encryption in the paper, around page 8.
[0] http://www.apple.com/ipad/business/docs/iOS_Security_Feb14.p...