This course covers mathematical foundations, including information theory, number theory, factoring, and prime number generation; cryptographic protocols, including basic building blocks and protocols; cryptographic techniques, including key generation and key management, and applications; and cryptographic algorithms–DES, AES, stream ciphers, hash functions, digital signatures, etc.
Secure Document Exchange Vault:
CS 463 Taught me a ton about cryptography. It taught a lot of theory. However this project really applied that theory knowledge. It’s one thing to learn the theory. It’s an entirely different beast applying cryptography theory.
Project Report
1. Executive Summary
For this project, I built the Secure Document Exchange Vault, a Python GUI application designed to simulate how a business might securely share encrypted files with its clients. Under the hood, it uses the cryptography library to implement a miniature Public Key Infrastructure (PKI). I wanted to demonstrate a complete cryptographic lifecycle, so the application handles asymmetric and symmetric key generation, secure password derivation using PBKDF2, and hybrid authenticated encryption (combining AES-GCM and RSA-OAEP). Ultimately, this setup guarantees that shared files remain completely confidential, unaltered, and verifiably tied to the original sender.
2. Cryptographic Design and Implementation
A. Setting up the PKI and Certificate Authority
To make the file exchange truly secure, the system needs a reliable way to verify identities. To accomplish this, the app acts as its own miniature Certificate Authority (CA). First, it generates a self-signed Root CA using a strong 4096-bit RSA private key. From there, it issues X.509 certificates to clients. These certificates are valid for 365 days and tie the user’s identity (their Common Name) to their public key, all backed by the Root CA’s digital signature.
B. Key Generation and Password Handling
Users need two separate sets of asymmetric keys for this workflow:
● Asymmetric Keys: The app generates an RSA-2048 key pair for securely trading encryption keys, and an Elliptic Curve key pair (using the NIST P-256 curve) for creating digital signatures.
● PBKDF2 Derivation: I also included a feature to demonstrate secure password handling. The app uses PBKDF2 to take a user’s master password, mix it with a random 16-byte salt, and run it through 600,000 iterations of SHA-256. This derives a strong 256-bit symmetric key while making brute-force or dictionary attacks basically impossible.
C. Hybrid Authenticated Encryption
Encrypting large files directly with RSA is slow and has strict size limits, so I went with a hybrid encryption approach instead:
● Symmetric Encryption (AES-GCM): Whenever a user encrypts a file, the app generates a fresh 256-bit AES key and a random 12-byte initialization vector (IV). It encrypts the actual file contents using AES-GCM (Galois/Counter Mode). I specifically chose GCM because it natively generates an authentication tag to ensure file integrity, which completely eliminated the need to add a redundant HMAC pass.
● Asymmetric Key Wrapping (RSA-OAEP): Once the file is encrypted, the app takes that random AES key and securely wraps it using the recipient’s RSA-2048 public key, specifically utilizing OAEP padding with SHA-256.
D. Digital Signatures and Non-Repudiation
Finally, we need to prove the document’s origin. Before encrypting, the sender’s app hashes and signs the raw file using their ECDSA private key. When the recipient goes to decrypt the file, the app pulls the sender’s X.509 certificate, checks that the trusted Root CA actually signed it, and then uses the public key inside to verify the digital signature on the file.
3. Threat Model & Security Defenses
● Interception & Eavesdropping: Handled by the AES-256 encryption. Even if someone intercepts the .vault file in transit, the ciphertext is completely unreadable without the securely wrapped symmetric key.
● Tampering & Modification: Covered by AES-GCM’s built-in authentication tag. If an attacker tries to flip a bit or alter the file, the GCM decryptor will immediately catch the mismatch and reject the payload.
● Impersonation & Spoofing: Prevented by the combination of our PKI and ECDSA signatures. An attacker can’t forge a signature without stealing the sender’s private key, and they can’t slip in a fake public key certificate because it wouldn’t have the Root CA’s trusted signature.
Secure Vault Demo:
This is the guide for the secure vault I created using Python. The source code will be uploaded later.
Step by Step Guide:
This demonstrates a full cryptographic lifecycle, from establishing a root of trust to securely exchanging a file.
Step 1: Initializing the Root CA and Trust
Before users can securely share files, the system needs a Certificate Authority (CA) to establish trust and verify identities.
1. Open the CA & Certs tab.
2. Click Make Root CA. This generates a secure 4096-bit RSA private key and creates a self-signed Root Certificate Authority. You will see a success message in the debug log at the bottom of the window.
Step 2: Key Generation & PBKDF2
Next, the user needs to generate their own cryptographic keys.
1. Switch to the Keys & Passwords tab.
2. Click Gen RSA Key. This generates an RSA-2048 key pair, which the system will use to securely wrap and exchange symmetric encryption keys.
3. Click Gen EC Key. This generates an Elliptic Curve (NIST P-256) key pair, which the system will use to digitally sign files.
4. (Optional) PBKDF2 Demonstration: Type a password into the “Password” field and click Derive Key. The system will take your password, combine it with a random 16-byte salt, and run it through 600,000 iterations of SHA-256 to securely derive a 256-bit symmetric key.
Step 3: Issuing the User Certificate
Now that the user has their keys, the Root CA must verify them.
1. Go back to the CA & Certs tab.
2. Enter a name in the “Name” field (e.g., “Alice”).
3. Click Sign Cert with CA. The Root CA signs an X.509 certificate binding the user’s name to their public key, valid for 365 days.
Step 4: Encrypting a File
With trust established, you can now encrypt a document. (It helps to have a sample .txt file ready on your computer).
1. Switch to the Encrypt/Decrypt tab.
2. Click Encrypt File. Select your sample text file.
3. Choose where to save the secure package (it will save with a .vault extension).
What happens under the hood: The system generates a random AES-256 key and encrypts the file using AES-GCM (which provides both confidentiality and a built-in authentication tag for
integrity). The AES key is then encrypted using the recipient’s RSA public key (RSA-OAEP). Finally, the file is signed with the sender’s EC private key (ECDSA).
Step 5: Decrypting & Verifying
To simulate receiving the file, you will decrypt the .vault package you just created.
1. Still on the Encrypt/Decrypt tab, click Decrypt File.
2. Select the .vault file you saved in Step 4.
3. Choose where to save the decrypted output file.
4. A popup will appear confirming success.
What’s happening: The system uses the RSA private key to unwrap the AES key and decrypts the payload, automatically checking the GCM integrity tag to ensure the file wasn’t tampered with. Finally, it checks the sender’s X.509 certificate against the Root CA, and verifies the ECDSA digital signature to prove the file’s authentic origin.