GreVault.Crypto 1.4.6

dotnet add package GreVault.Crypto --version 1.4.6
                    
NuGet\Install-Package GreVault.Crypto -Version 1.4.6
                    
This command is intended to be used within the Package Manager Console in Visual Studio, as it uses the NuGet module's version of Install-Package.
<PackageReference Include="GreVault.Crypto" Version="1.4.6" />
                    
For projects that support PackageReference, copy this XML node into the project file to reference the package.
<PackageVersion Include="GreVault.Crypto" Version="1.4.6" />
                    
Directory.Packages.props
<PackageReference Include="GreVault.Crypto" />
                    
Project file
For projects that support Central Package Management (CPM), copy this XML node into the solution Directory.Packages.props file to version the package.
paket add GreVault.Crypto --version 1.4.6
                    
#r "nuget: GreVault.Crypto, 1.4.6"
                    
#r directive can be used in F# Interactive and Polyglot Notebooks. Copy this into the interactive tool or source code of the script to reference the package.
#:package GreVault.Crypto@1.4.6
                    
#:package directive can be used in C# file-based apps starting in .NET 10 preview 4. Copy this into a .cs file before any lines of code to reference the package.
#addin nuget:?package=GreVault.Crypto&version=1.4.6
                    
Install as a Cake Addin
#tool nuget:?package=GreVault.Crypto&version=1.4.6
                    
Install as a Cake Tool

GreVault.Crypto

A lightweight cryptography utility library providing secure AES‑GCM encryption, Argon2i key derivation, and RSA key‑pair generation with hybrid encryption for GreVault projects.
Designed for simple, reliable, modern cryptographic primitives using string‑based (Base64/PEM) formats for easy storage and transmission.


Features

  • 🔐 AES‑GCM encryption/decryption (Powered by BouncyCastle)

    • 256‑bit symmetric keys
    • 96‑bit (12‑byte) randomly generated nonce automatically prepended to ciphertext
    • Base64‑encoded string inputs and outputs
  • 🧬 Argon2i key derivation

    • Strong password‑based key derivation
    • Returns a Base64‑encoded 256‑bit derived key
  • 🔑 Cryptographically Secure Key Generation

    • Utility to generate 256‑bit Base64‑encoded encryption keys
  • 🛡️ RSA Key Pair Generation (PEM)

    • Generate RSA public/private key pairs as PEM‑encoded strings
    • Ideal for asymmetric encryption, key wrapping, and secure sharing
  • 🔐 RSA Hybrid Encryption (RSA‑OAEP + AES‑GCM)

    • Encrypts data with a randomly generated AES‑256 key per operation
    • AES key is wrapped with RSA‑OAEP (SHA‑256) using the recipient's public key
    • Encrypted key and ciphertext are bundled into a single Base64 payload
    • Decrypt with private key — no key management required by the caller
  • ⚙️ Static, dependency‑light API


Third‑Party Software Notices

This software includes the following components:

  1. Isopoh.Cryptography.Argon2
    Copyright: Michael Heyman
    License: Creative Commons Attribution 4.0 International (CC BY 4.0)
    https://creativecommons.org/licenses/by/4.0/
    Used for password hashing via Argon2.

  2. BouncyCastle.Cryptography
    Copyright: The Bouncy Castle Project
    License: MIT License
    https://www.bouncycastle.org/licence.html
    Used for cryptographic operations including AES‑GCM and RSA.


Installation

Install via NuGet:

dotnet add package GreVault.Crypto

Or search for GreVault.Crypto in the Visual Studio NuGet Package Manager.


Usage

🔑 Generating a Random Symmetric Key

string newKey = CryptoService.GenerateKey(); // 256-bit base64-encoded key

🔐 Encrypting a Secret (AES‑GCM)

string plaintext = "Hello, World!";
string base64Key = CryptoService.GenerateKey();
string encrypted = CryptoService.Encrypt(plaintext, base64Key);

🔓 Decrypting a Secret (AES‑GCM)

string decrypted = CryptoService.Decrypt(encrypted, base64Key);

🧬 Deriving a User Data Encryption Key (Argon2i)

string password = "my_secure_password";
string base64Salt = CryptoService.GenerateKey(); // 256-bit base64-encoded salt
string udek = CryptoService.GetUDEK(password, base64Salt);

🔐 RSA Key Pair Generation & Hybrid Encryption

📌 Generate RSA Key Pair (PEM Strings)

var (publicPem, privatePem) = CryptoService.GenerateKeyPairAsStrings();

Produces:

  • publicPem → PEM‑encoded RSA public key
  • privatePem → PEM‑encoded RSA private key (should be encrypted before storage)

📌 Encrypt With Public Key (Hybrid RSA‑OAEP + AES‑GCM)

A fresh random AES‑256 key is generated per call, used to encrypt the data via AES‑GCM, then wrapped with RSA‑OAEP. The result is a single self‑contained Base64 payload.

string cipher = CryptoService.EncryptWithPublic("Hello RSA", publicPem);

📌 Decrypt With Private Key (UTF‑8 Output)

The AES key is unwrapped using the RSA private key, then used to decrypt the data. No key needs to be supplied by the caller.

string plaintext = CryptoService.DecryptWithPrivate(cipher, privatePem);

⚠️ Security Notes

  • AES‑GCM nonces are randomly generated per encryption operation and automatically prepended to the ciphertext.
  • RSA hybrid encryption generates a fresh random AES‑256 key per operation — the same plaintext will produce a different ciphertext every time.
  • RSA encryption uses OAEP padding with SHA‑256 — raw/PKCS#1 v1.5 padding is not used.
  • Argon2i is currently configured with:
    • 4 MB memory cost (MemoryCost = 4096)
    • 1 iteration (TimeCost = 1)
    • 1 lane/thread (Lanes = 1, Threads = 1)
    • 32‑byte output
  • RSA private keys should always be encrypted with a password‑derived key before storage.
  • The master key (UDEK) should never be passed as the AES key to EncryptWithPublic — use it only within the key derivation hierarchy.
  • This library does not manage key storage — you must store keys securely.

License

This project is licensed under the MIT License.
See the LICENSE file for details.


Product Compatible and additional computed target framework versions.
.NET net10.0 is compatible.  net10.0-android was computed.  net10.0-browser was computed.  net10.0-ios was computed.  net10.0-maccatalyst was computed.  net10.0-macos was computed.  net10.0-tvos was computed.  net10.0-windows was computed. 
Compatible target framework(s)
Included target framework(s) (in package)
Learn more about Target Frameworks and .NET Standard.

NuGet packages (1)

Showing the top 1 NuGet packages that depend on GreVault.Crypto:

Package Downloads
GreVault.Remote.Config

This library provides a simple way to manage remote configuration for your application. It allows you to fetch configuration values from a remote server and cache them locally for offline use.

GitHub repositories

This package is not used by any popular GitHub repositories.

Version Downloads Last Updated
1.4.6 124 5/7/2026
1.4.2 100 5/6/2026
1.4.0 126 4/21/2026