note 116612 added to function.mcrypt-encrypt

From: Date: Thu, 29 Jan 2015 11:52:47 +0000
Subject: note 116612 added to function.mcrypt-encrypt
Groups: php.notes 
Request: Send a blank email to php-notes+get-201551@lists.php.net to get a copy of this message
The encryption has no authenticity check. It can be achieved with three methods, described in http://en.wikipedia.org/wiki/Authenticated_encryption#Approaches_to_Authenticated_Encryption Encrypt-then-MAC (EtM), Encrypt-and-MAC (E&M), MAC-then-Encrypt (MtE). The following is a suggestion for MtE: <?php public static function getMacAlgoBlockSize($algorithm = 'sha1') { switch($algorithm) { case 'sha1': { return 160; } default: { return false; break; } } } public static function decrypt($message, $key, $mac_algorithm = 'sha1', $enc_algorithm = MCRYPT_RIJNDAEL_256, $enc_mode = MCRYPT_MODE_CBC) { $message= base64_decode($message); $iv_size = mcrypt_get_iv_size($enc_algorithm, $enc_mode); $iv_dec = substr($message, 0, $iv_size); $message= substr($message, $iv_size); $message= mcrypt_decrypt($enc_algorithm, $key, $message, $enc_mode, $iv_dec); $mac_block_size = ceil(static::getMacAlgoBlockSize($mac_algorithm)/8); $mac_dec = substr($message, 0, $mac_block_size); $message= substr($message, $mac_block_size); $mac = hash_hmac($mac_algorithm, $message, $key, true); if($mac_dec == $mac) { return $password; } else { return false; } } public static function encrypt($message, $key, $mac_algorithm = 'sha1', $enc_algorithm = MCRYPT_RIJNDAEL_256, $enc_mode = MCRYPT_MODE_CBC) { $mac = hash_hmac($mac_algorithm, $message, $key, true); $mac = substr($mac, 0, ceil(static::getMacAlgoBlockSize($mac_algorithm)/8)); $message= $mac . $message; $iv_size = mcrypt_get_iv_size($enc_algorithm, $enc_mode); $iv = mcrypt_create_iv($iv_size, MCRYPT_RAND); $ciphertext = mcrypt_encrypt($enc_algorithm, $key, $message, $enc_mode, $iv); return base64_encode($iv . $ciphertext); } ?> ---- Server IP: 72.52.91.14 Probable Submitter: 188.122.91.5 ---- Manual Page -- http://php.net/manual/en/function.mcrypt-encrypt.php Edit -- https://master.php.net/note/edit/116612 Del: integrated -- https://master.php.net/note/delete/116612/integrated Del: useless -- https://master.php.net/note/delete/116612/useless Del: bad code -- https://master.php.net/note/delete/116612/bad+code Del: spam -- https://master.php.net/note/delete/116612/spam Del: non-english -- https://master.php.net/note/delete/116612/non-english Del: in docs -- https://master.php.net/note/delete/116612/in+docs Del: other reasons-- https://master.php.net/note/delete/116612 Reject -- https://master.php.net/note/reject/116612 Search -- https://master.php.net/manage/user-notes.php

« previous php.notes (#201551) next »