What is the Hybrid File Encryption Platform?
This application provides enterprise-grade cryptographic file protection by uniting the computational efficiency of symmetric AES-256 encryption with the key-distribution security of asymmetric RSA-2048 public-key cryptography. It ensures that files in transit or at rest remain impervious to eavesdropping and tampering even over untrusted networks.
What Problem Does It Solve?
Symmetric encryption (like AES) is fast enough for gigabyte-scale files but requires both sender and receiver to share a secret key in advance over a secure channel. Asymmetric encryption (like RSA) solves key distribution but is computationally too slow for bulk files. The hybrid model solves both: the file is encrypted instantly with a unique one-time symmetric AES key, and only that small key is encrypted with the recipient's public RSA key.
How Does It Work?
- Dynamic Ephemeral Key Generation: For every encryption event, a random 256-bit AES symmetric key and initialization vector (IV) are generated via cryptographically secure random number generators.
- Authenticated AES-GCM Encryption: The source file is encrypted using Galois/Counter Mode (GCM), providing both confidentiality and built-in authentication against data corruption or bit-flipping attacks.
- RSA-2048 Key Encapsulation: The ephemeral AES key is encrypted using the recipient's 2048-bit RSA public key (OAEP padding).
- Decryption Verification: The recipient uses their private RSA key to recover the AES key, validates the GCM authentication tag, and restores the original file.
Technology Stack
Python PyCryptodome / Cryptography AES-256-GCM RSA-2048 OAEP SHA-256 Hashing Security Auditing
Ahmed Raza's Contribution
Ahmed Raza engineered the cryptographic architecture, implemented secure key generation and padding schemes complying with NIST standards, and built the desktop and command-line execution interfaces.