GreVault.Crypto
1.4.6
dotnet add package GreVault.Crypto --version 1.4.6
NuGet\Install-Package GreVault.Crypto -Version 1.4.6
<PackageReference Include="GreVault.Crypto" Version="1.4.6" />
<PackageVersion Include="GreVault.Crypto" Version="1.4.6" />
<PackageReference Include="GreVault.Crypto" />
paket add GreVault.Crypto --version 1.4.6
#r "nuget: GreVault.Crypto, 1.4.6"
#:package GreVault.Crypto@1.4.6
#addin nuget:?package=GreVault.Crypto&version=1.4.6
#tool nuget:?package=GreVault.Crypto&version=1.4.6
GreVault.Crypto
A lightweight cryptography utility library providing secure AES‑GCM encryption, Argon2i key derivation, and RSA key‑pair generation with hybrid encryption for GreVault projects.
Designed for simple, reliable, modern cryptographic primitives using string‑based (Base64/PEM) formats for easy storage and transmission.
Features
🔐 AES‑GCM encryption/decryption (Powered by BouncyCastle)
- 256‑bit symmetric keys
- 96‑bit (12‑byte) randomly generated nonce automatically prepended to ciphertext
- Base64‑encoded string inputs and outputs
🧬 Argon2i key derivation
- Strong password‑based key derivation
- Returns a Base64‑encoded 256‑bit derived key
🔑 Cryptographically Secure Key Generation
- Utility to generate 256‑bit Base64‑encoded encryption keys
🛡️ RSA Key Pair Generation (PEM)
- Generate RSA public/private key pairs as PEM‑encoded strings
- Ideal for asymmetric encryption, key wrapping, and secure sharing
🔐 RSA Hybrid Encryption (RSA‑OAEP + AES‑GCM)
- Encrypts data with a randomly generated AES‑256 key per operation
- AES key is wrapped with RSA‑OAEP (SHA‑256) using the recipient's public key
- Encrypted key and ciphertext are bundled into a single Base64 payload
- Decrypt with private key — no key management required by the caller
⚙️ Static, dependency‑light API
Third‑Party Software Notices
This software includes the following components:
Isopoh.Cryptography.Argon2
Copyright: Michael Heyman
License: Creative Commons Attribution 4.0 International (CC BY 4.0)
https://creativecommons.org/licenses/by/4.0/
Used for password hashing via Argon2.BouncyCastle.Cryptography
Copyright: The Bouncy Castle Project
License: MIT License
https://www.bouncycastle.org/licence.html
Used for cryptographic operations including AES‑GCM and RSA.
Installation
Install via NuGet:
dotnet add package GreVault.Crypto
Or search for GreVault.Crypto in the Visual Studio NuGet Package Manager.
Usage
🔑 Generating a Random Symmetric Key
string newKey = CryptoService.GenerateKey(); // 256-bit base64-encoded key
🔐 Encrypting a Secret (AES‑GCM)
string plaintext = "Hello, World!";
string base64Key = CryptoService.GenerateKey();
string encrypted = CryptoService.Encrypt(plaintext, base64Key);
🔓 Decrypting a Secret (AES‑GCM)
string decrypted = CryptoService.Decrypt(encrypted, base64Key);
🧬 Deriving a User Data Encryption Key (Argon2i)
string password = "my_secure_password";
string base64Salt = CryptoService.GenerateKey(); // 256-bit base64-encoded salt
string udek = CryptoService.GetUDEK(password, base64Salt);
🔐 RSA Key Pair Generation & Hybrid Encryption
📌 Generate RSA Key Pair (PEM Strings)
var (publicPem, privatePem) = CryptoService.GenerateKeyPairAsStrings();
Produces:
publicPem→ PEM‑encoded RSA public keyprivatePem→ PEM‑encoded RSA private key (should be encrypted before storage)
📌 Encrypt With Public Key (Hybrid RSA‑OAEP + AES‑GCM)
A fresh random AES‑256 key is generated per call, used to encrypt the data via AES‑GCM, then wrapped with RSA‑OAEP. The result is a single self‑contained Base64 payload.
string cipher = CryptoService.EncryptWithPublic("Hello RSA", publicPem);
📌 Decrypt With Private Key (UTF‑8 Output)
The AES key is unwrapped using the RSA private key, then used to decrypt the data. No key needs to be supplied by the caller.
string plaintext = CryptoService.DecryptWithPrivate(cipher, privatePem);
⚠️ Security Notes
- AES‑GCM nonces are randomly generated per encryption operation and automatically prepended to the ciphertext.
- RSA hybrid encryption generates a fresh random AES‑256 key per operation — the same plaintext will produce a different ciphertext every time.
- RSA encryption uses OAEP padding with SHA‑256 — raw/PKCS#1 v1.5 padding is not used.
- Argon2i is currently configured with:
- 4 MB memory cost (
MemoryCost = 4096) - 1 iteration (
TimeCost = 1) - 1 lane/thread (
Lanes = 1,Threads = 1) - 32‑byte output
- 4 MB memory cost (
- RSA private keys should always be encrypted with a password‑derived key before storage.
- The master key (UDEK) should never be passed as the AES key to
EncryptWithPublic— use it only within the key derivation hierarchy. - This library does not manage key storage — you must store keys securely.
License
This project is licensed under the MIT License.
See the LICENSE file for details.
| Product | Versions Compatible and additional computed target framework versions. |
|---|---|
| .NET | net10.0 is compatible. net10.0-android was computed. net10.0-browser was computed. net10.0-ios was computed. net10.0-maccatalyst was computed. net10.0-macos was computed. net10.0-tvos was computed. net10.0-windows was computed. |
-
net10.0
- BouncyCastle.Cryptography (>= 2.6.2)
- Isopoh.Cryptography.Argon2 (>= 2.0.0)
NuGet packages (1)
Showing the top 1 NuGet packages that depend on GreVault.Crypto:
| Package | Downloads |
|---|---|
|
GreVault.Remote.Config
This library provides a simple way to manage remote configuration for your application. It allows you to fetch configuration values from a remote server and cache them locally for offline use. |
GitHub repositories
This package is not used by any popular GitHub repositories.