Secure Document Exchange Vault: 

Project Report

This is a project I worked on in my CYSE 463 Crypto course.

1. Executive Summary

For this project, I built the Secure Document Exchange Vault, a Python GUI application designed to simulate how a business might securely share encrypted files with its clients. Under the hood, it uses the cryptography library to implement a miniature Public Key Infrastructure (PKI). I wanted to demonstrate a complete cryptographic lifecycle, so the application handles asymmetric and symmetric key generation, secure password derivation using PBKDF2, and hybrid authenticated encryption (combining AES-GCM and RSA-OAEP). Ultimately, this setup guarantees that shared files remain completely confidential, unaltered, and verifiably tied to the original sender.

2. Cryptographic Design and Implementation

A. Setting up the PKI and Certificate Authority

To make the file exchange truly secure, the system needs a reliable way to verify identities. To accomplish this, the app acts as its own miniature Certificate Authority (CA). First, it generates a self-signed Root CA using a strong 4096-bit RSA private key. From there, it issues X.509 certificates to clients. These certificates are valid for 365 days and tie the user’s identity (their Common Name) to their public key, all backed by the Root CA’s digital signature.

B. Key Generation and Password Handling

Users need two separate sets of asymmetric keys for this workflow:

  • Asymmetric Keys: The app generates an RSA-2048 key pair for securely trading encryption keys, and an Elliptic Curve key pair (using the NIST P-256 curve) for creating digital signatures.
  • PBKDF2 Derivation: I also included a feature to demonstrate secure password handling. The app uses PBKDF2 to take a user’s master password, mix it with a random 16-byte salt, and run it through 600,000 iterations of SHA-256. This derives a strong 256-bit symmetric key while making brute-force or dictionary attacks basically impossible.

C. Hybrid Authenticated Encryption

Encrypting large files directly with RSA is slow and has strict size limits, so I went with a hybrid encryption approach instead:

  • Symmetric Encryption (AES-GCM): Whenever a user encrypts a file, the app generates a fresh 256-bit AES key and a random 12-byte initialization vector (IV). It encrypts the actual file contents using AES-GCM (Galois/Counter Mode). I specifically chose GCM because it natively generates an authentication tag to ensure file integrity, which completely eliminated the need to add a redundant HMAC pass.
  • Asymmetric Key Wrapping (RSA-OAEP): Once the file is encrypted, the app takes that random AES key and securely wraps it using the recipient’s RSA-2048 public key, specifically utilizing OAEP padding with SHA-256.

D. Digital Signatures and Non-Repudiation

Finally, we need to prove the document’s origin. Before encrypting, the sender’s app hashes and signs the raw file using their ECDSA private key. When the recipient goes to decrypt the file, the app pulls the sender’s X.509 certificate, checks that the trusted Root CA actually signed it, and then uses the public key inside to verify the digital signature on the file.

3. Threat Model & Security Defenses

  • Interception & Eavesdropping: Handled by the AES-256 encryption. Even if someone intercepts the .vault file in transit, the ciphertext is completely unreadable without the securely wrapped symmetric key.
  • Tampering & Modification: Covered by AES-GCM’s built-in authentication tag. If an attacker tries to flip a bit or alter the file, the GCM decryptor will immediately catch the mismatch and reject the payload.
  • Impersonation & Spoofing: Prevented by the combination of our PKI and ECDSA signatures. An attacker can’t forge a signature without stealing the sender’s private key, and they can’t slip in a fake public key certificate because it wouldn’t have the Root CA’s trusted signature.

Leave a Reply

Your email address will not be published. Required fields are marked *