-
Notifications
You must be signed in to change notification settings - Fork 0
Expand file tree
/
Copy pathencryption_engine.py
More file actions
82 lines (69 loc) · 3.17 KB
/
Copy pathencryption_engine.py
File metadata and controls
82 lines (69 loc) · 3.17 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
# --------------------------------------------------------------------------
# Project: AES-RSA Hybrid Encryption System
# Author: Mariam Ashraf
# Faculty: Engineering - Capital University (Formerly Helwan)
# Date: May 2026
# File: encryption_engine.py
# Description: Core Cryptography Engine. Implements AES-256-GCM, RSA-2048 (OAEP),
# and SHA-256 hashing for secure data encryption and integrity.
# --------------------------------------------------------------------------
import time
import hashlib
from Crypto.Cipher import AES, PKCS1_OAEP
from Crypto.PublicKey import RSA
from Crypto.Random import get_random_bytes
class CryptoEngine:
def __init__(self):
# Step 2: RSA Key Generation (Public/Private Pair)
self.key = RSA.generate(2048)
self.private_key = self.key.export_key()
self.public_key = self.key.publickey().export_key()
with open("private_key.pem", "wb") as f: f.write(self.private_key)
with open("public_key.pem", "wb") as f: f.write(self.public_key)
def get_file_hash(self, file_path):
"""Calculate SHA-256 hash to verify file integrity."""
sha256_hash = hashlib.sha256()
with open(file_path, "rb") as f:
for byte_block in iter(lambda: f.read(4096), b""):
sha256_hash.update(byte_block)
return sha256_hash.hexdigest()
def hybrid_encrypt(self, plaintext_bytes):
"""
Step 3: Hybrid Encryption Phase
1. Encrypt data using AES-256 (GCM mode for high security).
2. Encrypt the AES key using RSA (Public Key).
"""
start_time = time.time()
# 1. AES Encryption
aes_key = get_random_bytes(32) # 256-bit key
cipher_aes = AES.new(aes_key, AES.MODE_GCM)
ciphertext, tag = cipher_aes.encrypt_and_digest(plaintext_bytes)
# 2. RSA Encryption (Protecting the AES Key)
rsa_key = RSA.import_key(self.public_key)
cipher_rsa = PKCS1_OAEP.new(rsa_key)
encrypted_aes_key = cipher_rsa.encrypt(aes_key)
with open("encrypted_data.bin", "wb") as f:
f.write(cipher_aes.nonce + tag + encrypted_aes_key + ciphertext)
end_time = time.time()
execution_time = end_time - start_time
return {
"ciphertext": ciphertext,
"encrypted_aes_key": encrypted_aes_key,
"nonce": cipher_aes.nonce,
"tag": tag,
"time": execution_time
}
def hybrid_decrypt(self, encrypted_data):
"""
Step 4: Decryption Phase
1. Decrypt the AES key using RSA (Private Key).
2. Decrypt the data using the recovered AES key.
"""
# 1. Recover AES Key using RSA
rsa_key = RSA.import_key(self.private_key)
cipher_rsa = PKCS1_OAEP.new(rsa_key)
aes_key = cipher_rsa.decrypt(encrypted_data["encrypted_aes_key"])
# 2. Decrypt Data using AES
cipher_aes = AES.new(aes_key, AES.MODE_GCM, nonce=encrypted_data["nonce"])
decrypted_data = cipher_aes.decrypt_and_verify(encrypted_data["ciphertext"], encrypted_data["tag"])
return decrypted_data