/pyUmbral

Nucypher KMS implementation of Umbral using OpenSSL and Cryptography.io

Primary LanguagePython

pyUmbral

https://travis-ci.org/nucypher/pyUmbral.svg?branch=master

pyUmbral is a python implementation of David Nuñez's threshold proxy rencryption scheme: Umbral. Implemented with OpenSSL and Cryptography.io, pyUmbral is a referential and open-source cryptography library extending the traditional cryptological narrative of "Alice and Bob" by introducing a new actor, Ursula, who has the ability to take secrets encrypted for Alice and re-encrypt them for Bob.

Encapsulation

from umbral import pre, keys

# Generate umbral keys for Alice.
alices_private_key = keys.UmbralPrivateKey.gen_key()
alices_public_key = alices_private_key.get_pubkey()

# Encrypt data with Alice's public key.
plaintext = b'Proxy Re-encryption is cool!'
ciphertext, capsule = pre.encrypt(alices_public_key, plaintext)

# Decrypt data with Alice's private key.
cleartext = pre.decrypt(capsule, alices_private_key,
                        ciphertext, alices_public_key)

Fragmentation

# Generate umbral keys for Bob.
bobs_private_key = keys.UmbralPrivateKey.gen_key()
bobs_public_key = bobs_private_key.get_pubkey()

# Alice generates split re-encryption keys for Bob with "M of N".
kfrags = pre.split_rekey(alices_private_key, bobs_public_key, 10, 20)

Re-encryption

# Ursula re-encrypts the capsule to obtain a cfrag.
# Bob attaches the cfrags to the capsule.
for kfrag in kfrags:
    cfrag = pre.reencrypt(kfrag, capsule)
    capsule.attach_cfrag(cfrag)

# Bob activates and opens the capsule.
cleartext = pre.decrypt(capsule, bobs_private_key,
                        ciphertext, alices_public_key)

Features

  • Re-encryption Toolkit
  • Re-encryption Key Fragmentation
  • Key Encapsulation
  • Elliptic Curve Arithmetic

Quick Installation

The NuCypher team uses pipenv for managing pyUmbral's dependencies. The recommended installation procedure is as follows:

$ sudo pip3 install pipenv
$ pipenv install

Post-installation, you can activate the project virtual enviorment in your current terminal session by running pipenv shell.

For more information on pipenv, find the official documentation here: https://docs.pipenv.org/.

Academic Whitepaper

The Umbral scheme academic whitepaper and cryptographic specifications are availible on GitHub.

"Umbral A Threshold Proxy Re-Encryption Scheme" by David Nuñez https://github.com/nucypher/umbral-doc/blob/master/umbral-doc.pdf

Support & Contribute