nocscienceat.Aes256GcmRsaCryptoService 2.1.0

dotnet add package nocscienceat.Aes256GcmRsaCryptoService --version 2.1.0
                    
NuGet\Install-Package nocscienceat.Aes256GcmRsaCryptoService -Version 2.1.0
                    
This command is intended to be used within the Package Manager Console in Visual Studio, as it uses the NuGet module's version of Install-Package.
<PackageReference Include="nocscienceat.Aes256GcmRsaCryptoService" Version="2.1.0" />
                    
For projects that support PackageReference, copy this XML node into the project file to reference the package.
<PackageVersion Include="nocscienceat.Aes256GcmRsaCryptoService" Version="2.1.0" />
                    
Directory.Packages.props
<PackageReference Include="nocscienceat.Aes256GcmRsaCryptoService" />
                    
Project file
For projects that support Central Package Management (CPM), copy this XML node into the solution Directory.Packages.props file to version the package.
paket add nocscienceat.Aes256GcmRsaCryptoService --version 2.1.0
                    
#r "nuget: nocscienceat.Aes256GcmRsaCryptoService, 2.1.0"
                    
#r directive can be used in F# Interactive and Polyglot Notebooks. Copy this into the interactive tool or source code of the script to reference the package.
#:package nocscienceat.Aes256GcmRsaCryptoService@2.1.0
                    
#:package directive can be used in C# file-based apps starting in .NET 10 preview 4. Copy this into a .cs file before any lines of code to reference the package.
#addin nuget:?package=nocscienceat.Aes256GcmRsaCryptoService&version=2.1.0
                    
Install as a Cake Addin
#tool nuget:?package=nocscienceat.Aes256GcmRsaCryptoService&version=2.1.0
                    
Install as a Cake Tool

nocscienceat.Aes256GcmRsaCryptoService

AES-256-GCM and RSA crypto service for .NET 8+
Author: Klemens Urban, 0x4b55 Software Solutions

Overview

nocscienceat.Aes256GcmRsaCryptoService is a .NET library providing secure encryption and decryption using AES-256-GCM for data confidentiality and RSA for key protection and digital signatures. It supports .NET 8, .NET 9, and .NET 10.

Features

  • AES-256-GCM symmetric encryption for fast, secure data protection.
  • RSA encryption for secure key exchange and digital signatures.
  • X.509 certificate-based key management.
  • Integration with .NET dependency injection and configuration.
  • The certificate used is referenced by its fingerprint and, depending on the Boolean parameter localMachine, can originate from either the LocalMachine or CurrentUser certificate store.
  • AES256 key and nonce are randomly regenerated each time the Encrypt method is called, thus ensuring collision resistance.
  • Can be used in the context of dependency injection and outside of dependency injection via static methods.

Getting Started

Installation

Add the NuGet package to your project:


dotnet add package nocscienceat.Aes256GcmRsaCryptoService

Configuration for Dependency Injection

if using the the instance methodes add the following section to your appsettings.json:

"nocscienceat.Aes256GcmRsaCryptoService": { 
  "EncryptionCertificateThumbprint": "<your-encryption-certificate-thumbprint>", 
  "SigningCertificateThumbprint": "<your-signing-certificate-thumbprint>",
  "LocalMachine": true/false
}

Usage

Static Methods
using nocscienceat.Aes256GcmRsaCryptoService;
...
...
// Encrypt data: 
byte[] Encrypt(ReadOnlySpan<byte> plainTextSpan, string encryptionCertificateThumbprint, string signingCertificateThumprint, bool localMachine)

// Decrypt data: 
byte[] Decrypt(ReadOnlySpan<byte> cipherTextSpan, string encryptionCertificateThumbprint, string signingCertificateThumprint, bool localMachine)
Dependency Injection
// setup DI in program.cs
services.AddSingleton<ICryptoService, CryptoService>(); 

// usage in your service
public class MyService 
{ 
  private readonly ICryptoService _cryptoService;

  public MyService(ICryptoService cryptoService)
  {
    _cryptoService = cryptoService;
  }

  public void DoCrypto()
  {
    byte[] encrypted = _cryptoService.Encrypt(ReadOnlySpan<byte> plainTextSpan);
    byte[] decrypted = _cryptoService.Decrypt(ReadOnlySpan<byte> cipherTextSpan);
  }
}

Notes

  • Since the AES Key and Nonce are randomly generated for each encryption operation, the same plaintext will yield different ciphertexts on subsequent encryptions.
  • Since during Encryption the AES Key, Nonce and Tag are not only encrypeted (OaepSHA256 Padding) but also signed with the RSA Signing Certificate (HashAlgorithmName.SHA256, RSASignaturePadding.Pss), the Account executing the Encrypt method must have access to the Private Key of the Signing Certificate.
Product Compatible and additional computed target framework versions.
.NET net8.0 is compatible.  net8.0-android was computed.  net8.0-browser was computed.  net8.0-ios was computed.  net8.0-maccatalyst was computed.  net8.0-macos was computed.  net8.0-tvos was computed.  net8.0-windows was computed.  net9.0 is compatible.  net9.0-android was computed.  net9.0-browser was computed.  net9.0-ios was computed.  net9.0-maccatalyst was computed.  net9.0-macos was computed.  net9.0-tvos was computed.  net9.0-windows was computed.  net10.0 is compatible.  net10.0-android was computed.  net10.0-browser was computed.  net10.0-ios was computed.  net10.0-maccatalyst was computed.  net10.0-macos was computed.  net10.0-tvos was computed.  net10.0-windows was computed. 
Compatible target framework(s)
Included target framework(s) (in package)
Learn more about Target Frameworks and .NET Standard.

NuGet packages (1)

Showing the top 1 NuGet packages that depend on nocscienceat.Aes256GcmRsaCryptoService:

Package Downloads
nocscienceat.EncryptedConfigurationProvider

EncryptedConfigurationProvider for the .Net Configuration System

GitHub repositories

This package is not used by any popular GitHub repositories.

Version Downloads Last Updated
2.1.0 755 12/3/2025