PKEncrypt ~ Simple yet powerful encrypting library

Posts 1–15 of 15 · Page 1 of 1
PKEncrypt ~ Simple yet powerful encrypting library
Virus scans:
Virustotal
VirusJotti

Description:
PKEncrypt is a simple yet powerful encrypting class library, that encrypts and decrypts messages using 2 public keys, that you can select or have randomly generated.

Result:
From
Code:
Hello, World!
to
Code:
263507 369647 395267 395267 406247 161027 117107 318407 406247 417227 395267 365987 120767
with key1 = 3660, key2 = 485.

How does this work:
Code:
Target string is converted into a char array
Each member of the char array is converted into the corresponding integer according to its charcode
Then, the charcode is multiplied by key1, and is subtracted key2.
Repeat for each char, and write the result numbers out, seperating them by spaces.
(reverse procedure for decrypting the string)

Why I think this is strong:
While you *have* to have the key values in your code...
Looking at an encrypted message, even if you know what was done in order to get there, is impossible to decrypt without knowing at least the 2nd key.
Why the 2nd key? Because if you add the 2nd key to each number, you can find their similar multiples, and with a bit of trial and error, decrypt the message.
However since you dont know the 2nd key, it's impossible to get the original message

How to use:
Code:
In either C# or vb.net ->
Add a new reference of this library
Import PKEncrypt
Declare a new variable (in vb Dim pkt as PKTE = new PKTE)
To encrypt, pkt.Encrypt("string",key1,key2)
To decrypt, pkt.Decrypt("encrypted string",key1,key2)
Leave a thanks if this is useful

@Flengo @Hero
This section is pretty much dead, I'll still release, but since there are no minions here I'll mention u so u can approve
PKEncrypt_mpgh.net.rar5 KB · 9 downloads Clean
If you hardcode the keys in your project, it is too easy to bypass.

Nevertheless pretty cool idea and still useful to some people, keep your contribution up!
Don't roll your own cryptography. Everyone with a small knowledgment in cryptography would know this mantra. It says to not do strange things, eg. creating cryptographic algorithms at home, or encrypting a string many times with more keys.
You should not do your cryptographic algorithm at home because it's not tested from analysts, a good cryptographer can do a good and an actually powerful algorithm.

Quote Originally Posted by New View Post
Why I think this is strong:
While you *have* to have the key values in your code...
Looking at an encrypted message, even if you know what was done in order to get there, is impossible to decrypt without knowing at least the 2nd key.
Why the 2nd key? Because if you add the 2nd key to each number, you can find their similar multiples, and with a bit of trial and error, decrypt the message.
However since you dont know the 2nd key, it's impossible to get the original message
Considering your algorithm powerful just because you think it is not fine. A powerful cryptographic algorithm by definition consists in part of an algorithm being safe from some cryptoanalysis attacks. Such as analytic attacks, statistical attacks, differential attacks etc.

p.s: There is something not done properly in your example. Assuming the formula is:

and I want to encrypt the H letter, which is in charcode 72, using 3660 and 485 as first and second key, I'd get 263135 as result.
Your actual second key you encrypted with is (3660×72)-263507=13 or intuitively 13, not 485 as you show in the example.

p.p.s: It's possible to get the two keys, without even bruteforcing them. Assume I don't know you are using 123 as first key and 456 as second key. I know
Code:
plain -> a -> ciphertext following your formula -> 11475
plain -> b -> ciphertext following your formula -> 11598
The letters charcode is respectively 97 and 98. 11598-11475=123, first key. (123×97)-11475=456, I have the second key too.

p.p.p.s: If you want to bruteforce it's easy too, because you are using just a combination of numbers as keys. If you have n length of combinations of numbers, I would test 10^n combinations to get the right key, and I would use my computer resources to bruteforce just depending on the length.

EDIT:
You have explained how it works. Why should you do a library?
Quote Originally Posted by javalover View Post
Don't roll your own cryptography.
Just because something is bad / worse than other ways of cryptography, that doesn't mean I will stop trying to make it better.

Quote Originally Posted by javalover View Post
It's possible to get the two keys, without even bruteforcing them. Assume I don't know you are using 123 as first key and 456 as second key. I know
There is a difference from already knowing the algorithm, and not. Someone can't just see the numbers and instantly assume they are calculated by the algorithm I used.

Quote Originally Posted by javalover View Post
If you want to bruteforce it's easy too, because you are using just a combination of numbers as keys. If you have n length of combinations of numbers, I would test 10^n combinations to get the right key, and I would use my computer resources to bruteforce just depending on the length.
What if the algorithm was:

e = (k1(c)) - k2 - n

where n is the letter that is currently being changed into a number

So in the word Hello -> H -> 72 -> 263135 -> 263134 (because n was removed)
This would mean the second key would always change, it would become bigger and bigger.

And assuming you don't already know the algorithm, doesn't that also prevent it from a statistical analysis? Since the key2 is constantly changing, without changing much in the algorithm.
Quote Originally Posted by New View Post
Just because something is bad / worse than other ways of cryptography, that doesn't mean I will stop trying to make it better.
It means it is not as secure and powerful as you think. Your method is inspired to an ancient cryptographic algorithm, the Caesar cipherⓘ, a simple substitution cipher. It's like someone already did something like your one. It was probably secure before the 9th century AD, but no one knows. However since 9th century AD, it's no more secure and effective as analysts found a method to break it.

There is a difference from already knowing the algorithm, and not. Someone can't just see the numbers and instantly assume they are calculated by the algorithm I used.
Knowing the algorithm is taken for granted. How can I analyze an algorithm if I don't know how it works? If you ask someone to decrypt random numbers, how does he know it's an actual ciphertext or just random numbers? This is called Security by obscurityⓘ, you are not correctly applying cryptography.

What if the algorithm was:

e = (k1(c)) - k2 - n

where n is the letter that is currently being changed into a number

So in the word Hello -> H -> 72 -> 263135 -> 263134 (because n was removed)
This would mean the second key would always change, it would become bigger and bigger.
I don't understand.
Quote Originally Posted by javalover View Post
I don't understand.
e = (k1(c)) - k2 - n

The algorithm.


Each char adds 1 to n
n is an integer

For char H n = 1
For char e n = 2
For char l n = 3
For char l n = 4
For char o n = 5

etc
Quote Originally Posted by New View Post
e = (k1(c)) - k2 - n

The algorithm.


Each char adds 1 to n
n is an integer

For char H n = 1
For char e n = 2
For char l n = 3
For char l n = 4
For char o n = 5

etc
Quote Originally Posted by javalover View Post
I don't understand.
Define what does n represent, as number.
Quote Originally Posted by javalover View Post
Define what does n represent, as number.
The current char that is being encrypted | converted into a number, from left to right.
e = (k1(c)) - k2 - n
Define what does n represent, as number.
Quote Originally Posted by New View Post
The current char that is being encrypted | converted into a number, from left to right.
so, since you are trying to say you will substract the encrypted current char to the encrypted current char? will you do:

e = (k1(c))-k2) - (k1(c))-k2)
? Or didn't you want to say this?
Quote Originally Posted by javalover View Post
Or didn't you want to say this?
...

Quote Originally Posted by New View Post
...

What does changing the second key for each letter prevent?
Quote Originally Posted by javalover View Post
What does changing the second key for each letter prevent?
And assuming you don't already know the algorithm, doesn't that also prevent it from a statistical analysis? Since the key2 is constantly changing, without changing much in the algorithm.
It would mean there would be no pattern so it would impossible to do a statistical analysis.
Quote Originally Posted by New View Post
It would mean there would be no pattern so it would impossible to do a statistical analysis.
Ok, you didn't read what I wrote.

Quote Originally Posted by javalover View Post
Knowing the algorithm is taken for granted. How can I analyze an algorithm if I don't know how it works? If you ask someone to decrypt random numbers, how does he know it's an actual ciphertext or just random numbers? This is called Security by obscurityⓘ, you are not correctly applying cryptography.
This isn't how cryptography works. I will repeat you this is called security by obscurity, until you won't understand it.

You clearly don't know what cryptoanalysis are, how do you mind changing the key for each letter would prevent statistical analysis? Get the effort to study cryptography and stop stating your algorithm is powerful and you will try to make it powerful, you aren't a cryptographer.
Quote Originally Posted by javalover View Post
This isn't how cryptography works. I will repeat you this is called security by obscurity, until you won't understand it.

You clearly don't know what cryptoanalysis are, how do you mind changing the key for each letter would prevent statistical analysis? Get the effort to study cryptography and stop stating your algorithm is powerful and you will try to make it powerful, you aren't a cryptographer.
Stop telling me what to do.
Noone invited you here.
A random person on the internet can never tell me what to do or what not to do.
If I want to make my own algorithm, I'll do so. Someone like you cannot change my mind.
Geek all you want about cryptanalysis. What you say has zero effect on me.
End of story.
Posts 1–15 of 15 · Page 1 of 1

Post a Reply

Similar Threads

Tags for this Thread

None

Need help?