Introduction
The classes in the .Net Framework cryptography namespace manage many details of cryptography for you. Some are wrappers for the unmanaged Microsoft CryptoAPI, while others are purely managed implementations. Cryptography protects data from being viewed or modified and provides secure channels of communication over otherwise insecure channels. For example, data can be encrypted using a cryptographic algorithm, transmitted in an encrypted state, and later decrypted by the intended party. If a third party intercepts the encrypted data, it will be difficult to decipher the data. We use a combination of algorithms and practices known as cryptographic primitives to create a cryptographic scheme. Those primitives are: private-key encryption, public-key encryption, cryptographic signing and cryptographic hashes.
Private-key encryption (symmetric cryptography)
In this article and code example I've used private-key encryption to encrypt files. Private-key encryption algorithms use a single private key to encrypt and decrypt data so it also referred to as symmetric encryption because the same key is used for encryption and decryption. Thus, we need a key and an initialization vector (IV) to encrypt and decrypt data. Without an IV the same input block of plaintext will encrypt to same output block of ciphertext, but with IV the output of two identical plaintext blocks are different and it is hard for unauthorized user to recover the key. The disadvantage of private-key encryption is that it presumes two parties have agreed on a key and IV and communicated their values. Also, the key must be kept secret from unauthorized users. Because of these problems, private-key encryption is often used in conjunction with public-key encryption to privately communicate the values of the key and IV.
The .NET Framework provides the following classes that implement private-key encryption algorithms:
- DESCryptoServiceProvider (DES algorithm)
- RC2CryptoServiceProvider (RC2 algorithm)
- RijndaelManaged (Rijndael algorithm)
- TrippleDESCryptoServiceProvider (TrippleDES algorithm)
Code explanation
In this simple example I use a Rijndael algorithm to encrypt files. First, to encrypt file, we have to make a key and IV (16 bytes each). Below is shown how to compose a key and an IV (key and IV have the same value) from password entered by user (Form1.EncryptFile() function):
Join the conversation! Your thoughts help the community grow.