pyUmbral is a python implementation of David Nuñez's threshold proxy rencryption scheme: Umbral. Implemented with OpenSSL and Cryptography.io, pyUmbral is a referential and open-source cryptography library extending the traditional cryptological narrative of "Alice and Bob" by introducing a new actor, Ursula, who has the ability to take secrets encrypted for Alice and re-encrypt them for Bob.
Encapsulation
from umbral import pre, keys
# Generate umbral keys for Alice.
alices_private_key = keys.UmbralPrivateKey.gen_key()
alices_public_key = alices_private_key.get_pubkey()
# Encrypt data with Alice's public key.
plaintext = b'Proxy Re-encryption is cool!'
ciphertext, capsule = pre.encrypt(alices_public_key, plaintext)
# Decrypt data with Alice's private key.
cleartext = pre.decrypt(capsule, alices_private_key,
ciphertext, alices_public_key)
Fragmentation
# Generate umbral keys for Bob.
bobs_private_key = keys.UmbralPrivateKey.gen_key()
bobs_public_key = bobs_private_key.get_pubkey()
# Alice generates split re-encryption keys for Bob with "M of N".
kfrags = pre.split_rekey(alices_private_key, bobs_public_key, 10, 20)
Re-encryption
# Ursula re-encrypts the capsule to obtain a cfrag.
# Bob attaches the cfrags to the capsule.
for kfrag in kfrags:
cfrag = pre.reencrypt(kfrag, capsule)
capsule.attach_cfrag(cfrag)
# Bob activates and opens the capsule.
cleartext = pre.decrypt(capsule, bobs_private_key,
ciphertext, alices_public_key)
- Re-encryption Toolkit
- Re-encryption Key Fragmentation
- Key Encapsulation
- Elliptic Curve Arithmetic
The NuCypher team uses pipenv for managing pyUmbral's dependencies. The recommended installation procedure is as follows:
$ sudo pip3 install pipenv
$ pipenv install
Post-installation, you can activate the project virtual enviorment
in your current terminal session by running pipenv shell
.
For more information on pipenv, find the official documentation here: https://docs.pipenv.org/.
The Umbral scheme academic whitepaper and cryptographic specifications are availible on GitHub.
"Umbral A Threshold Proxy Re-Encryption Scheme" by David Nuñez https://github.com/nucypher/umbral-doc/blob/master/umbral-doc.pdf
- Issue Tracker: https://github.com/nucypher/pyUmbral/issues
- Source Code: https://github.com/nucypher/pyUmbral