{"id":345,"date":"2026-08-15T17:10:05","date_gmt":"2026-08-15T17:10:05","guid":{"rendered":"https:\/\/sites.wp.odu.edu\/kenneththomas100-\/?page_id=345"},"modified":"2026-08-18T17:16:58","modified_gmt":"2026-08-18T17:16:58","slug":"cryptography","status":"publish","type":"page","link":"https:\/\/sites.wp.odu.edu\/kenneththomas100-\/cryptography\/","title":{"rendered":"Cryptography"},"content":{"rendered":"\n<p>This course covers mathematical foundations, including information theory, number theory, factoring, and prime number generation; cryptographic protocols, including basic building blocks and protocols; cryptographic techniques, including key generation and key management, and applications; and cryptographic algorithms&#8211;DES, AES, stream ciphers, hash functions, digital signatures, etc.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Secure Document Exchange Vault:<\/h2>\n\n\n\n<p>CS 463 Taught me a ton about cryptography. It taught a lot of theory. However this project really applied that theory knowledge. It&#8217;s one thing to learn the theory. It&#8217;s an entirely different beast applying cryptography theory.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Project Report<\/h3>\n\n\n\n<p>1. Executive Summary<\/p>\n\n\n\n<p>For this project, I built the Secure Document Exchange Vault, a Python GUI application designed to simulate how a business might securely share encrypted files with its clients. Under the hood, it uses the cryptography library to implement a miniature Public Key Infrastructure (PKI). I wanted to demonstrate a complete cryptographic lifecycle, so the application handles asymmetric and symmetric key generation, secure password derivation using PBKDF2, and hybrid authenticated encryption (combining AES-GCM and RSA-OAEP). Ultimately, this setup guarantees that shared files remain completely confidential, unaltered, and verifiably tied to the original sender.<\/p>\n\n\n\n<p>2. Cryptographic Design and Implementation<\/p>\n\n\n\n<p>A. Setting up the PKI and Certificate Authority<\/p>\n\n\n\n<p>To make the file exchange truly secure, the system needs a reliable way to verify identities. To accomplish this, the app acts as its own miniature Certificate Authority (CA). First, it generates a self-signed Root CA using a strong 4096-bit RSA private key. From there, it issues X.509 certificates to clients. These certificates are valid for 365 days and tie the user&#8217;s identity (their Common Name) to their public key, all backed by the Root CA&#8217;s digital signature.<\/p>\n\n\n\n<p>B. Key Generation and Password Handling<\/p>\n\n\n\n<p>Users need two separate sets of asymmetric keys for this workflow:<\/p>\n\n\n\n<p>\u25cf &nbsp; Asymmetric Keys: The app generates an RSA-2048 key pair for securely trading encryption keys, and an Elliptic Curve key pair (using the NIST P-256 curve) for creating digital signatures.<\/p>\n\n\n\n<p>\u25cf &nbsp; PBKDF2 Derivation: I also included a feature to demonstrate secure password handling. The app uses PBKDF2 to take a user&#8217;s master password, mix it with a random 16-byte salt, and run it through 600,000 iterations of SHA-256. This derives a strong 256-bit symmetric key while making brute-force or dictionary attacks basically impossible.<\/p>\n\n\n\n<p>C. Hybrid Authenticated Encryption<\/p>\n\n\n\n<p>Encrypting large files directly with RSA is slow and has strict size limits, so I went with a hybrid encryption approach instead:<\/p>\n\n\n\n<p>\u25cf &nbsp; Symmetric Encryption (AES-GCM): Whenever a user encrypts a file, the app generates a fresh 256-bit AES key and a random 12-byte initialization vector (IV). It encrypts the actual file contents using AES-GCM (Galois\/Counter Mode). I specifically chose GCM because it natively generates an authentication tag to ensure file integrity, which completely eliminated the need to add a redundant HMAC pass.<\/p>\n\n\n\n<p>\u25cf &nbsp; Asymmetric Key Wrapping (RSA-OAEP): Once the file is encrypted, the app takes that random AES key and securely wraps it using the recipient&#8217;s RSA-2048 public key, specifically utilizing OAEP padding with SHA-256.<\/p>\n\n\n\n<p>D. Digital Signatures and Non-Repudiation<\/p>\n\n\n\n<p>Finally, we need to prove the document&#8217;s origin. Before encrypting, the sender&#8217;s app hashes and signs the raw file using their ECDSA private key. When the recipient goes to decrypt the file, the app pulls the sender&#8217;s X.509 certificate, checks that the trusted Root CA actually signed it, and then uses the public key inside to verify the digital signature on the file.<\/p>\n\n\n\n<p>3. Threat Model &amp; Security Defenses<\/p>\n\n\n\n<p>\u25cf &nbsp; Interception &amp; Eavesdropping: Handled by the AES-256 encryption. Even if someone intercepts the .vault file in transit, the ciphertext is completely unreadable without the securely wrapped symmetric key.<\/p>\n\n\n\n<p>\u25cf &nbsp; Tampering &amp; Modification: Covered by AES-GCM&#8217;s built-in authentication tag. If an attacker tries to flip a bit or alter the file, the GCM decryptor will immediately catch the mismatch and reject the payload.<\/p>\n\n\n\n<p>\u25cf &nbsp; Impersonation &amp; Spoofing: Prevented by the combination of our PKI and ECDSA signatures. An attacker can&#8217;t forge a signature without stealing the sender&#8217;s private key, and they can&#8217;t slip in a fake public key certificate because it wouldn&#8217;t have the Root CA&#8217;s trusted signature.<\/p>\n\n\n\n<p><\/p>\n\n\n\n<p><\/p>\n\n\n\n<p><\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Secure Vault Demo:<\/h2>\n\n\n\n<p>This is the guide for the secure vault I created using Python. The source code will be uploaded later.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Step by Step Guide:<\/h3>\n\n\n\n<p>This demonstrates a full cryptographic lifecycle, from establishing a root of trust to securely exchanging a file.<\/p>\n\n\n\n<p>Step 1: Initializing the Root CA and Trust<\/p>\n\n\n\n<p>Before users can securely share files, the system needs a Certificate Authority (CA) to establish trust and verify identities.<\/p>\n\n\n\n<p>1.&nbsp; Open the CA &amp; Certs tab.<\/p>\n\n\n\n<p>2.&nbsp; Click Make Root CA. This generates a secure 4096-bit RSA private key and creates a self-signed Root Certificate Authority. You will see a success message in the debug log at the bottom of the window.<\/p>\n\n\n\n<p>Step 2: Key Generation &amp; PBKDF2<\/p>\n\n\n\n<p>Next, the user needs to generate their own cryptographic keys.<\/p>\n\n\n\n<p>1.&nbsp; Switch to the Keys &amp; Passwords tab.<\/p>\n\n\n\n<p>2.&nbsp; Click Gen RSA Key. This generates an RSA-2048 key pair, which the system will use to securely wrap and exchange symmetric encryption keys.<\/p>\n\n\n\n<p>3.&nbsp; Click Gen EC Key. This generates an Elliptic Curve (NIST P-256) key pair, which the system will use to digitally sign files.<\/p>\n\n\n\n<p>4.&nbsp; (Optional) PBKDF2 Demonstration: Type a password into the &#8220;Password&#8221; field and click Derive Key. The system will take your password, combine it with a random 16-byte salt, and run it through 600,000 iterations of SHA-256 to securely derive a 256-bit symmetric key.<\/p>\n\n\n\n<p>Step 3: Issuing the User Certificate<\/p>\n\n\n\n<p>Now that the user has their keys, the Root CA must verify them.<\/p>\n\n\n\n<p>1.&nbsp; Go back to the CA &amp; Certs tab.<\/p>\n\n\n\n<p>2.&nbsp; Enter a name in the &#8220;Name&#8221; field (e.g., &#8220;Alice&#8221;).<\/p>\n\n\n\n<p>3.&nbsp; Click Sign Cert with CA. The Root CA signs an X.509 certificate binding the user&#8217;s name to their public key, valid for 365 days.<\/p>\n\n\n\n<p>Step 4: Encrypting a File<\/p>\n\n\n\n<p>With trust established, you can now encrypt a document. (It helps to have a sample .txt file ready on your computer).<\/p>\n\n\n\n<p>1.&nbsp; Switch to the Encrypt\/Decrypt tab.<\/p>\n\n\n\n<p>2.&nbsp; Click Encrypt File. Select your sample text file.<\/p>\n\n\n\n<p>3.&nbsp; Choose where to save the secure package (it will save with a .vault extension).<\/p>\n\n\n\n<p>What happens under the hood: The system generates a random AES-256 key and encrypts the file using AES-GCM (which provides both confidentiality and a built-in authentication tag for<\/p>\n\n\n\n<p>integrity). The AES key is then encrypted using the recipient&#8217;s RSA public key (RSA-OAEP). Finally, the file is signed with the sender&#8217;s EC private key (ECDSA).<\/p>\n\n\n\n<p>Step 5: Decrypting &amp; Verifying<\/p>\n\n\n\n<p>To simulate receiving the file, you will decrypt the .vault package you just created.<\/p>\n\n\n\n<p>1.&nbsp; Still on the Encrypt\/Decrypt tab, click Decrypt File.<\/p>\n\n\n\n<p>2.&nbsp; Select the .vault file you saved in Step 4.<\/p>\n\n\n\n<p>3.&nbsp; Choose where to save the decrypted output file.<\/p>\n\n\n\n<p>4.&nbsp; A popup will appear confirming success.<\/p>\n\n\n\n<p>What\u2019s happening: The system uses the RSA private key to unwrap the AES key and decrypts the payload, automatically checking the GCM integrity tag to ensure the file wasn&#8217;t tampered with. Finally, it checks the sender&#8217;s X.509 certificate against the Root CA, and verifies the ECDSA digital signature to prove the file&#8217;s authentic origin.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>This course covers mathematical foundations, including information theory, number theory, factoring, and prime number generation; cryptographic protocols, including basic building blocks and protocols; cryptographic techniques, including key generation and key management, and applications; and cryptographic algorithms&#8211;DES, AES, stream ciphers, hash functions, digital signatures, etc. Secure Document Exchange Vault: CS 463 Taught me a ton about&#8230; <\/p>\n<div class=\"link-more\"><a href=\"https:\/\/sites.wp.odu.edu\/kenneththomas100-\/cryptography\/\">Read More<\/a><\/div>\n","protected":false},"author":30543,"featured_media":0,"parent":0,"menu_order":0,"comment_status":"closed","ping_status":"closed","template":"","meta":{"footnotes":""},"_links":{"self":[{"href":"https:\/\/sites.wp.odu.edu\/kenneththomas100-\/wp-json\/wp\/v2\/pages\/345"}],"collection":[{"href":"https:\/\/sites.wp.odu.edu\/kenneththomas100-\/wp-json\/wp\/v2\/pages"}],"about":[{"href":"https:\/\/sites.wp.odu.edu\/kenneththomas100-\/wp-json\/wp\/v2\/types\/page"}],"author":[{"embeddable":true,"href":"https:\/\/sites.wp.odu.edu\/kenneththomas100-\/wp-json\/wp\/v2\/users\/30543"}],"replies":[{"embeddable":true,"href":"https:\/\/sites.wp.odu.edu\/kenneththomas100-\/wp-json\/wp\/v2\/comments?post=345"}],"version-history":[{"count":3,"href":"https:\/\/sites.wp.odu.edu\/kenneththomas100-\/wp-json\/wp\/v2\/pages\/345\/revisions"}],"predecessor-version":[{"id":350,"href":"https:\/\/sites.wp.odu.edu\/kenneththomas100-\/wp-json\/wp\/v2\/pages\/345\/revisions\/350"}],"wp:attachment":[{"href":"https:\/\/sites.wp.odu.edu\/kenneththomas100-\/wp-json\/wp\/v2\/media?parent=345"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}