{"id":327,"date":"2026-08-16T04:03:56","date_gmt":"2026-08-16T04:03:56","guid":{"rendered":"https:\/\/sites.wp.odu.edu\/kenneththomas100-\/?p=327"},"modified":"2026-08-18T04:05:56","modified_gmt":"2026-08-18T04:05:56","slug":"secure-document-exchange-vault","status":"publish","type":"post","link":"https:\/\/sites.wp.odu.edu\/kenneththomas100-\/2026\/08\/16\/secure-document-exchange-vault\/","title":{"rendered":"Secure Document Exchange Vault:\u00a0"},"content":{"rendered":"\n<h1 class=\"wp-block-heading\"><strong>Project Report<\/strong><\/h1>\n\n\n\n<p>This is a project I worked on in my CYSE 463 Crypto course.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><strong>1. Executive Summary<\/strong><\/h2>\n\n\n\n<p>For this project, I built the Secure Document Exchange Vault, a Python GUI application designed to simulate how a business might securely share encrypted files with its clients. Under the hood, it uses the cryptography library to implement a miniature Public Key Infrastructure (PKI). I wanted to demonstrate a complete cryptographic lifecycle, so the application handles asymmetric and symmetric key generation, secure password derivation using PBKDF2, and hybrid authenticated encryption (combining AES-GCM and RSA-OAEP). Ultimately, this setup guarantees that shared files remain completely confidential, unaltered, and verifiably tied to the original sender.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><strong>2. Cryptographic Design and Implementation<\/strong><\/h2>\n\n\n\n<h3 class=\"wp-block-heading\"><strong>A. Setting up the PKI and Certificate Authority<\/strong><\/h3>\n\n\n\n<p>To make the file exchange truly secure, the system needs a reliable way to verify identities. To accomplish this, the app acts as its own miniature Certificate Authority (CA). First, it generates a self-signed Root CA using a strong 4096-bit RSA private key. From there, it issues X.509 certificates to clients. These certificates are valid for 365 days and tie the user&#8217;s identity (their Common Name) to their public key, all backed by the Root CA&#8217;s digital signature.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\"><strong>B. Key Generation and Password Handling<\/strong><\/h3>\n\n\n\n<p>Users need two separate sets of asymmetric keys for this workflow:<\/p>\n\n\n\n<ul>\n<li><strong>Asymmetric Keys:<\/strong> The app generates an RSA-2048 key pair for securely trading encryption keys, and an Elliptic Curve key pair (using the NIST P-256 curve) for creating digital signatures.<\/li>\n<\/ul>\n\n\n\n<ul>\n<li><strong>PBKDF2 Derivation:<\/strong> I also included a feature to demonstrate secure password handling. The app uses PBKDF2 to take a user&#8217;s master password, mix it with a random 16-byte salt, and run it through 600,000 iterations of SHA-256. This derives a strong 256-bit symmetric key while making brute-force or dictionary attacks basically impossible.<\/li>\n<\/ul>\n\n\n\n<h3 class=\"wp-block-heading\"><strong>C. Hybrid Authenticated Encryption<\/strong><\/h3>\n\n\n\n<p>Encrypting large files directly with RSA is slow and has strict size limits, so I went with a hybrid encryption approach instead:<\/p>\n\n\n\n<ul>\n<li><strong>Symmetric Encryption (AES-GCM):<\/strong> Whenever a user encrypts a file, the app generates a fresh 256-bit AES key and a random 12-byte initialization vector (IV). It encrypts the actual file contents using AES-GCM (Galois\/Counter Mode). I specifically chose GCM because it natively generates an authentication tag to ensure file integrity, which completely eliminated the need to add a redundant HMAC pass.<\/li>\n<\/ul>\n\n\n\n<ul>\n<li><strong>Asymmetric Key Wrapping (RSA-OAEP):<\/strong> Once the file is encrypted, the app takes that random AES key and securely wraps it using the recipient&#8217;s RSA-2048 public key, specifically utilizing OAEP padding with SHA-256.<\/li>\n<\/ul>\n\n\n\n<h3 class=\"wp-block-heading\"><strong>D. Digital Signatures and Non-Repudiation<\/strong><\/h3>\n\n\n\n<p>Finally, we need to prove the document&#8217;s origin. Before encrypting, the sender&#8217;s app hashes and signs the raw file using their ECDSA private key. When the recipient goes to decrypt the file, the app pulls the sender&#8217;s X.509 certificate, checks that the trusted Root CA actually signed it, and then uses the public key inside to verify the digital signature on the file.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><strong>3. Threat Model &amp; Security Defenses<\/strong><\/h2>\n\n\n\n<ul>\n<li><strong>Interception &amp; Eavesdropping:<\/strong> Handled by the AES-256 encryption. Even if someone intercepts the .vault file in transit, the ciphertext is completely unreadable without the securely wrapped symmetric key.<\/li>\n\n\n\n<li><\/li>\n\n\n\n<li><strong>Tampering &amp; Modification:<\/strong> Covered by AES-GCM&#8217;s built-in authentication tag. If an attacker tries to flip a bit or alter the file, the GCM decryptor will immediately catch the mismatch and reject the payload.<\/li>\n\n\n\n<li><\/li>\n\n\n\n<li><strong>Impersonation &amp; Spoofing:<\/strong> Prevented by the combination of our PKI and ECDSA signatures. An attacker can&#8217;t forge a signature without stealing the sender&#8217;s private key, and they can&#8217;t slip in a fake public key certificate because it wouldn&#8217;t have the Root CA&#8217;s trusted signature.<\/li>\n<\/ul>\n","protected":false},"excerpt":{"rendered":"<p>Project Report This is a project I worked on in my CYSE 463 Crypto course. 1. Executive Summary For this project, I built the Secure Document Exchange Vault, a Python GUI application designed to simulate how a business might securely share encrypted files with its clients. Under the hood, it uses the cryptography library to&#8230; <\/p>\n<div class=\"link-more\"><a href=\"https:\/\/sites.wp.odu.edu\/kenneththomas100-\/2026\/08\/16\/secure-document-exchange-vault\/\">Read More<\/a><\/div>\n","protected":false},"author":30543,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":"","wds_primary_category":1},"categories":[1],"tags":[],"_links":{"self":[{"href":"https:\/\/sites.wp.odu.edu\/kenneththomas100-\/wp-json\/wp\/v2\/posts\/327"}],"collection":[{"href":"https:\/\/sites.wp.odu.edu\/kenneththomas100-\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/sites.wp.odu.edu\/kenneththomas100-\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/sites.wp.odu.edu\/kenneththomas100-\/wp-json\/wp\/v2\/users\/30543"}],"replies":[{"embeddable":true,"href":"https:\/\/sites.wp.odu.edu\/kenneththomas100-\/wp-json\/wp\/v2\/comments?post=327"}],"version-history":[{"count":2,"href":"https:\/\/sites.wp.odu.edu\/kenneththomas100-\/wp-json\/wp\/v2\/posts\/327\/revisions"}],"predecessor-version":[{"id":329,"href":"https:\/\/sites.wp.odu.edu\/kenneththomas100-\/wp-json\/wp\/v2\/posts\/327\/revisions\/329"}],"wp:attachment":[{"href":"https:\/\/sites.wp.odu.edu\/kenneththomas100-\/wp-json\/wp\/v2\/media?parent=327"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/sites.wp.odu.edu\/kenneththomas100-\/wp-json\/wp\/v2\/categories?post=327"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/sites.wp.odu.edu\/kenneththomas100-\/wp-json\/wp\/v2\/tags?post=327"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}