I have been playing around with an old code I wrote using SHA1 to work with SHA256 or SHA512. I am fairly new in the cryptography world and I wondered if someone can tell me why my input value in the Encrypt method returns through the Decrypt method with a loss of 1-5 bytes.
I can run the methods with short strings no problem but apparently not larger e.g. 16 bytes +.
The two methods in Question are:
public string Decrypt(string data, EncryptionValue eV, string passPhrase)
{
byte[] bytes = Encoding.ASCII.GetBytes(eV.InitVector);
byte[] rgbSalt = Encoding.ASCII.GetBytes(eV.SaltValue);
byte[] buffer = Convert.FromBase64String(data);
byte[] rgbKey = new Rfc2898DeriveBytes(passPhrase, rgbSalt, eV.PassIterations, hash).GetBytes(eV.KeySize / 8);
var managed = Aes.Create("AesManaged");
managed.Padding = PaddingMode.PKCS7;
managed.Mode = CipherMode.CBC;
ICryptoTransform transform = managed.CreateDecryptor(rgbKey, bytes);
MemoryStream stream = new(buffer);
CryptoStream stream2 = new(stream, transform, CryptoStreamMode.Read);
byte[] buffer5 = new byte[buffer.Length];
int count = stream2.Read(buffer5, 0, buffer5.Length);
stream.Close();
stream2.Close();
return Encoding.UTF8.GetString(buffer5, 0, count);
}
public string Encrypt(string data, EncryptionValue eV, string passPhrase)
{
byte[] bytes = Encoding.ASCII.GetBytes(eV.InitVector);
byte[] rgbSalt = Encoding.ASCII.GetBytes(eV.SaltValue);
byte[] buffer = Encoding.UTF8.GetBytes(data);
byte[] rgbKey = new Rfc2898DeriveBytes(passPhrase, rgbSalt, eV.PassIterations, hash).GetBytes(eV.KeySize / 8);
var managed = Aes.Create("AesManaged");
managed.Padding = PaddingMode.PKCS7;
managed.Mode = CipherMode.CBC;
ICryptoTransform transform = managed.CreateEncryptor(rgbKey, bytes);
MemoryStream stream = new();
CryptoStream stream2 = new(stream, transform, CryptoStreamMode.Write);
stream2.Write(buffer, 0, buffer.Length);
stream2.FlushFinalBlock();
byte[] inArray = stream.ToArray();
stream.Close();
stream2.Close();
return Convert.ToBase64String(inArray);
}
The Encryption Value Class contains randomised randomised values and it's not the issue here but I am posting it anyway here:
public int PassIterations { get; set; }
public int KeySize { get; set; }
public string InitVector { get; set; }
public string SaltValue { get; set; }
The Iterations are around 1000 in all my tests. I've done tests with less and more. KeySize is always 256 or 128, InitVector = "~1B2c3D4e5F6g7H8";
I ran some tests and like I said, smaller strings are okay but I want it to be able to store at least 120 bytes. I thought this would work?