Encryption Library

The Encryption Library encodes a message string using bitwise XOR encoding. The key is combined with a random hash, and then it too gets converted using XOR. The Encryption Library provides a reasonable degree of security for encrypted sessions or other such "light" purposes. When the native encryp/decrypt handlers are available, they will be implemented for a higher degree of security.

Note: Encryp/decrypt is currently not working in the server engine, so these native handlers could not be used in revIgniter.

Setting your Key

A key is a piece of information that controls the cryptographic process and permits an encrypted string to be decoded. In fact, the key you chose will provide the only means to decode data that was encrypted with that key, so not only must you choose the key carefully, you must never change it if you intend to use it for persistent data.

It goes without saying that you should guard your key carefully. Should someone gain access to your key, the data will be easily decoded. If your server is not totally under your control it's impossible to ensure key security so you may want to think carefully before using it for anything that requires high security, like storing credit card numbers.

To take maximum advantage of the encryption algorithm, your key should be 32 characters in length (128 bits). The key should be as random a string as you can concoct, with numbers and uppercase and lowercase letters. Your key should not be a simple text string. In order to be cryptographically secure it needs to be as random as possible.

Your key can be either stored in your application/config/config.irev, or you can design your own storage mechanism and pass the key dynamically when encoding/decoding.

To save your key to your application/config/config.irev, open the file and set:

put "YOUR KEY" into gConfig["encryption_key"]

Message Length

It's important for you to know that the encoded messages the encryption function generates will be approximately 2.6 times longer than the original message. For example, if you encrypt the string "my super secret data", which is 21 characters in length, you'll end up with an encoded string that is roughly 55 characters (we say "roughly" because the encoded string length increments in 64 bit clusters, so it's not exactly linear). Keep this information in mind when selecting your data storage mechanism. Cookies, for example, can only hold 4K of information.

Initializing the Library

Like most other libraries in revIgniter, the Encryption library is initialized in your controller using the rigLoaderLoadLibrary handler:

rigLoaderLoadLibrary "Encrypt"

rigEncode()

Performs the data encryption and returns it as a string. Example:

put "My secret message" into tMsg

put rigEncode(tMsg) into tEncryptedString

You can optionally pass your encryption key via the second parameter if you don't want to use the one in your config file:

put "My secret message" into tMsg
put "superSecretKey" into tKey

put rigEncode(tMsg, tKey) into tEncryptedString

rigDecode()

Decrypts an encoded string. Example:

put "APANtByIGI1BpVXZTJgcsAG8GZl8pdwwa84" into tEncryptedString

put rigDecode(tEncryptedString) into tPlaintextString