This package tries to smooth over some of the differences in encryption approaches (symmetric vs. asymmetric, sodium vs. openssl) to provide a simple interface for users who just want to encrypt or decrypt things.
The scope of the package is to protect data that has been saved to disk. It is not designed to stop an attacker targeting the R process itself to determine the contents of sensitive data. The package does try to prevent you accidentally saving to disk the contents of sensitive information, including the keys that could decrypt such information.
This vignette works through the basic functionality of the package.
It does not offer much in the way of an introduction to encryption
itself; for that see the excellent vignettes in the openssl
and sodium
packages (see vignette("crypto101")
and vignette("bignum")
for information about how encryption
works). This package is a wrapper around those packages in order to make
them more accessible.
To encrypt anything we need a key. There are two sorts of key “types” we will concern ourselves with here “symmetric” and “asymmetric”.
“symmetric” keys are used for storing secrets that multiple people need to access. Everyone has the same key (which is just a bunch of bytes) and with that we can either encrypt data or decrypt it.
a “key pair” is a public and a private key; this is used in communication. You hold a private key that nobody else ever sees and a public key that you can copy around all over the show. These can be used for a couple of different patterns of communication (see below).
We support symmetric keys and asymmetric key pairs from the
openssl
and sodium
packages (which wrap around
industry-standard cryptographic libraries) - this vignette will show how
to create and load keys of different types as they’re used.
The openssl
keys have the advantage of a standard key
format, and that many people (especially on Linux and macOS) have a
keypair already (see below if you’re not sure if you do). The
sodium
keys have the advantage of being a new library,
starting from a clean slate rather than carrying with it accumulated
ideas from the last 20 years of development.
The idea in cyphr
is that we can abstract away some
differences in the types of keys and the functions that go with them to
create a standardised interface to encrypting and decrypting strings, R
objects, files and raw vectors. With that, we can then create wrappers
around functions that create files and simplify the process of adding
encryption into a data workflow.
Below, I’ll describe the sorts of keys that cyphr
supports and in the sections following describe how these can be used to
actually do some encryption.
This is the simplest form of encryption because everyone has the same key (like a key to your house or a single password). This raises issues (like how do you store the key without other people reading it) but we can deal with that below.
openssl
To generate a key with openssl
, you can use:
which generates a raw vector
## aes c8:b8:54:4c:d4:aa:15:a0:dc:5b:59:a5:62:3c:dd:5c
(this prints nicely but it really is stored as a 16 byte raw vector).
The encryption functions that this key supports are
openssl::aes_cbc_encrypt
,
openssl::aes_ctr_encrypt
and
openssl::aes_gcm_encrypt
(along with the corresponding
decryption functions). The cyphr
package tries to abstract
this away by using a wrapper `cyphr::key_openssl
## <cyphr_key: openssl>
With this key, one can encrypt a string with
cyphr::encrypt_string
:
and decrypt it again with cyphr::decrypt_string
:
## [1] "my secret string"
See below for more functions that use these key objects.
sodium
The interface is almost identical using sodium symmetric keys. To
generate a symmetric key with libsodium you would use
sodium::keygen
This is really just a raw vector of length 32, without even any class attribute!
The encryption functions that this key supports are
sodium::data_encrypt
and sodium::data_decrypt
.
To create a key for use with cyphr
that knows this,
use:
## <cyphr_key: sodium>
This key can then be used with the high-level cyphr encryption functions described below.
With asymmetric encryption everybody has two keys that differ from everyone else’s key. One key is public and can be shared freely with anyone you would like to communicate with and the other is private and must never be disclosed.
In the sodium
package there is a vignette
(vignette("crypto101")
) that gives a gentle introduction to
how this all works. In practice, you end up creating a pair of keys for
yourself. Then to encrypt or decrypt something you encrypt messages with
the recipient’s public key and they (and only they) can decrypt
it with their private key.
One use for asymmetric encryption is to encrypt a shared secret (such as a symmetric key) - with this you can then safely store or communicate a symmetric key without disclosing it.
openssl
Let’s suppose that we have two parties “Alice” and “Bob” who want to talk with one another. For demonstration purposes we need to generate SSH keys (with no password) in temporary directories (to comply with CRAN policies). In a real situation these would be on different machines (Alice has no access to Bob’s key!) and these keys would be password protected.
path_key_alice <- cyphr::ssh_keygen(password = FALSE)
path_key_bob <- cyphr::ssh_keygen(password = FALSE)
Note that each directory contains a public key
(id_rsa.pub
) and a private key (id_rsa
).
## [1] "id_rsa" "id_rsa.pub"
## [1] "id_rsa" "id_rsa.pub"
Below, the full path to the key (e.g., .../id_rsa
) could
be used in place of the directory name if you prefer.
If Alice wants to send a message to Bob she needs to use her private key and his public key
## <cyphr_keypair: openssl>
with this pair she can write a message to “bob”:
The secret is now just a big pile of bytes
## [1] 58 0a 00 00 00 03 00 04 04 02 00 03 05 00 00 00 00 05 55 54 46 2d 38 00 00
## [26] 02 13 00 00 00 04 00 00 00 18 00 00 00 10 ad 1c f5 1b ea 77 b4 be 1f 99 9d
## [51] 58 1b 70 c4 8f 00 00 00 18 00 00 01 00 1b 03 03 ba ee 53 47 0b fa d3 0c fc
## [76] 8b ad fd 91 36 47 9e 80 0f 11 de d3 2c da 6a 88 b8 7f ac 7e 95 33 f7 cf b4
## [101] 4e 2e 4a 10 08 2c 3d 8e 0a f9 2a 3b 61 bd d4 58 a4 a9 3d 1b 93 93 7d 4c f0
## [126] d2 1a 1a 46 ad 64 96 cd 29 df 9f d1 6b e8 77 12 b7 90 e0 3e bb 89 47 41 08
## [151] db 4a af 67 b1 e1 30 f9 d2 7e 03 37 7f 32 93 8a 15 fd e1 ac bd 15 b6 7d 81
## [176] 97 56 1e 1d 57 fa 5c 06 ad 9b 72 eb 3f b5 b5 3d 6f 5a e0 53 9c ca 36 46 72
## [201] b9 d7 43 12 81 5f fe e3 38 92 6c db 11 70 f3 48 a1 7f b1 5a db ff e2 1b f4
## [226] 1c 16 b7 af bf 5f 7f 9f bd df 9a c1 4f c7 42 b8 9a 9a e7 ee 8a bb cc 5a c0
## [251] 33 b1 1b 37 78 10 33 ae 2e cd c2 b4 cc 1b 02 b6 71 5a 68 5b d5 da 57 bf b8
## [276] 84 2d 5a 94 f9 72 98 5a 85 d6 aa 13 88 4e 19 bb d8 8b 90 e6 62 f4 00 e8 05
## [301] 3a 56 b7 61 6d 01 9a 48 7e 46 d0 b8 c5 b6 4e 84 8a 42 e9 00 00 00 18 00 00
## [326] 00 10 10 9f a9 55 e2 f3 19 f8 17 ce 0e 80 10 0f 10 f2 00 00 00 18 00 00 01
## [351] 00 bf aa 94 2b 08 70 5c 12 ee 2a dd a2 ec 81 aa 79 1b e3 71 33 a4 a3 65 c3
## [376] 88 af f9 23 aa 51 d7 e7 3a 0e d7 1c 08 65 cb 71 44 d2 e0 41 d1 7b 68 60 15
## [401] 61 ae 67 10 e3 17 35 41 ff 7c f1 e4 74 10 03 df a0 43 e4 47 cc ab e0 38 63
## [426] 51 9a 26 46 f8 46 4a 3b ee c6 ef ef 00 06 30 bc 5c 8f 4b 16 36 a4 2f 3e 5c
## [451] ec b1 e8 76 1a 0e 27 61 f9 f5 71 72 2b 13 35 1f 5b b4 01 7d fa b8 e0 fa 02
## [476] 4e 07 56 93 90 b1 6f 61 00 3a 6f bf b1 49 74 73 83 5d a6 15 cd 9a fc 39 f5
## [501] 42 f9 ad 9b 3e 7f b0 6b c4 f8 03 60 2a a5 bb f3 69 40 e8 00 39 9c 8b f2 c8
## [526] a7 ed d9 53 f7 1d 5c cd 70 37 a4 a5 19 be fb 82 16 0c 0e e7 ee 0f 7e de 1a
## [551] 4e 6f ae 96 98 0e 83 77 2b 8d 57 42 0d 3d 8c b7 5f f9 a3 ef 98 b4 ba 1b 40
## [576] 39 66 ea b2 5f d3 f8 b1 5b 2d a1 e6 ff 08 f8 4a 5d 17 1c 06 4d 0c 1a 19 97
## [601] 2f 63 2a 2c 44 43 ce 00 00 04 02 00 00 00 01 00 04 00 09 00 00 00 05 6e 61
## [626] 6d 65 73 00 00 00 10 00 00 00 04 00 04 00 09 00 00 00 02 69 76 00 04 00 09
## [651] 00 00 00 07 73 65 73 73 69 6f 6e 00 04 00 09 00 00 00 04 64 61 74 61 00 04
## [676] 00 09 00 00 00 09 73 69 67 6e 61 74 75 72 65 00 00 00 fe
Note that unlike symmetric encryption above, Alice cannot decrypt her own message:
## Error in openssl::decrypt_envelope(x$data, x$iv, x$session, key): OpenSSL error: 00B82B4BEE7F0000:error:03000082:digital envelope routines:EVP_CIPHER_CTX_set_key_length:invalid key length:../crypto/evp/evp_enc.c:1046:
For Bob to read the message, he uses his private key and Alice’s public key (which she has transmitted to him previously).
With this keypair, Bob can decrypt Alice’s message
## [1] "secret message"
And send one back of his own:
## [1] 58 0a 00 00 00 03 00 04 04 02 00 03 05 00 00 00 00 05 55 54 46 2d 38 00 00
## [26] 02 13 00 00 00 04 00 00 00 18 00 00 00 10 03 f3 19 17 fc ca 93 a0 98 47 9c
## [51] d3 fc 42 7b 59 00 00 00 18 00 00 01 00 03 23 86 07 b8 99 b7 e5 d4 0e a7 7d
## [76] 0a 79 57 21 3f 9b 5c 33 84 c9 e0 2f f2 81 07 a1 c5 fe 06 c7 b2 b2 44 f0 21
## [101] a9 d5 ca e7 5e 2a 1b ff c6 d8 28 cc ce 43 78 7f 68 d1 5a 9c cc c3 64 e4 43
## [126] 7d 86 36 e0 81 73 cc b3 b3 dc 38 55 90 6a 35 58 66 64 8c b6 27 0d d8 c8 6b
## [151] a1 9d b9 57 f0 cb 6f 79 71 93 46 95 91 ec a5 78 9d d5 ad fa 8d 9c 2e 8c d1
## [176] dd ae 99 e3 8a 4c 6b 90 5a 7b 7b 8f 53 8c f7 91 1e bd a0 bd 35 e8 31 05 03
## [201] f9 e3 9c 3b 04 0e 0a ff 74 4f c5 43 c7 5a 34 12 dc 9e fe 90 fa 0a 55 43 bd
## [226] 2a 29 60 8a ea 68 b5 3a ea 46 fb cc 1f 84 2f 8f 86 e0 01 4a 67 c4 f2 0c c7
## [251] 5d 6e bb 84 a0 9d 51 e2 bc 0a 63 a7 ea 79 9d 6e 49 8e 63 7e a6 06 eb f4 82
## [276] 6c dc f0 ab 9c 3c af 0e ee 60 fb fd 6c 37 8d a9 d5 54 a2 02 17 33 56 ef cc
## [301] f1 a1 24 07 96 55 a9 88 7c b0 6f 14 3f 9a 8a 66 87 37 53 00 00 00 18 00 00
## [326] 00 10 fe d1 61 11 f3 1c 99 22 9e 48 b0 3b e8 50 df 46 00 00 00 18 00 00 01
## [351] 00 2c c4 0d ca cf 4b 51 b2 45 6f 60 8a 38 31 90 ad 4c da 13 8b 57 cd 77 e0
## [376] ee 84 3a b7 59 db cd 9f 8d 00 f2 09 36 bc b6 3e e2 05 fd cc 58 9f 56 d1 41
## [401] 64 59 d7 1b 94 bd 76 51 46 d7 dd d1 36 2d 7d fc 5c 16 00 0a b0 2d 4c 68 a0
## [426] da 61 e6 12 80 22 59 b2 5d ec 9d 8b 3f 28 9d 44 66 54 21 a7 f9 ae 29 4e 7c
## [451] 96 38 84 95 5f 4f 14 c6 ca 28 81 aa 21 a2 07 05 48 9c c7 ba 29 6e 6e a9 c6
## [476] d7 e9 8a d5 8f 80 93 7d f5 f8 70 7a 39 9f ce d6 b6 ce 29 e9 c4 76 a0 bc 32
## [501] 29 14 56 1d 70 c8 c0 50 6a c1 2d 76 6a 41 09 3c 57 2c 09 0e 9d 6e 92 e8 73
## [526] 82 88 b5 2d 88 42 f7 73 db 40 dd 43 7a 42 13 67 9e 1d d8 fd e5 e5 1d 7b 5f
## [551] af b3 37 33 bf e3 f2 3e 26 10 64 49 36 0d 2d 5b e7 49 4f 23 ba 77 09 41 7a
## [576] fe f5 2f f1 69 bf 56 29 3c 41 5c 5f a1 61 35 97 10 23 21 5c 07 c2 b6 ee 6b
## [601] b0 26 b9 1f 01 9c ce 00 00 04 02 00 00 00 01 00 04 00 09 00 00 00 05 6e 61
## [626] 6d 65 73 00 00 00 10 00 00 00 04 00 04 00 09 00 00 00 02 69 76 00 04 00 09
## [651] 00 00 00 07 73 65 73 73 69 6f 6e 00 04 00 09 00 00 00 04 64 61 74 61 00 04
## [676] 00 09 00 00 00 09 73 69 67 6e 61 74 75 72 65 00 00 00 fe
which she can decrypt
## [1] "another message"
Chances are, you have an openssl keypair in your .ssh/
directory. If so, you would pass NULL
as the path for the
private (or less usefully, the public) key pair part. So to send a
message to Bob, we’d include the path to Bob’s public key.
This all skips over how Alice and Bob will exchange this secret information. Because the secret is bytes, it’s a bit odd to work with. Alice could save the secret to disk with
secret <- cyphr::encrypt_string("secret message", pair_a)
path_for_bob <- file.path(tempdir(), "for_bob_only")
writeBin(secret, path_for_bob)
And then send Bob the file for_bob_only
(over email or
any other insecure medium).
and bob could read the secret in with:
secret <- readBin(path_for_bob, raw(), file.size(path_for_bob))
cyphr::decrypt_string(secret, pair_b)
## [1] "secret message"
As an alternative, you can “base64 encode” the bytes into something that you can just email around:
## [1] "WAoAAAADAAQEAgADBQAAAAAFVVRGLTgAAAITAAAABAAAABgAAAAQIiDTzm9taZog8KXmg22GiAAAABgAAAEAcNs65zbV5cn+57Nx91r4EiArOFs+72OryxF1jZ2ekX1iEc4KGIzpEljW8NwQjWI8Bsda5s7qYjRwf5oQaeVGIJDdjjGK42SuM9Zpqtet5NKrkOQxZl6Dr+BpcgtAvqyI92Tj3tuLJBRvcwJohcbqTA53Ieipx8ixvd9GOSlK2eHGzLlec/gCyytKXkQ6zohl8yGcLA6IWM7yU4LmXOI8lwCwi0mD6jm7hchIqnU8rJXtlzxGjmqDXqSvwl41RRJOLkQxJF0ZvquLlwieNd2F0ilNCTByVRH/7ognAp5aDNdBBjFpHP2DvrOSYYogIMPeIW5/rWX4O2RhHEg9kFtwvQAAABgAAAAQrBhmiiVcetxjTID9LlNGZwAAABgAAAEAv6qUKwhwXBLuKt2i7IGqeRvjcTOko2XDiK/5I6pR1+c6DtccCGXLcUTS4EHRe2hgFWGuZxDjFzVB/3zx5HQQA9+gQ+RHzKvgOGNRmiZG+EZKO+7G7+8ABjC8XI9LFjakLz5c7LHodhoOJ2H59XFyKxM1H1u0AX36uOD6Ak4HVpOQsW9hADpvv7FJdHODXaYVzZr8OfVC+a2bPn+wa8T4A2AqpbvzaUDoADmci/LIp+3ZU/cdXM1wN6SlGb77ghYMDufuD37eGk5vrpaYDoN3K41XQg09jLdf+aPvmLS6G0A5ZuqyX9P4sVstoeb/CPhKXRccBk0MGhmXL2MqLERDzgAABAIAAAABAAQACQAAAAVuYW1lcwAAABAAAAAEAAQACQAAAAJpdgAEAAkAAAAHc2Vzc2lvbgAEAAkAAAAEZGF0YQAEAAkAAAAJc2lnbmF0dXJlAAAA/g=="
This can be converted back with
openssl::base64_decode
:
## [1] TRUE
Or, less compactly but also suitable for email, you might just convert the bytes into their hex representation:
## [1] "580a000000030004040200030500000000055554462d38000002130000000400000018000000102220d3ce6f6d699a20f0a5e6836d8688000000180000010070db3ae736d5e5c9fee7b371f75af812202b385b3eef63abcb11758d9d9e917d6211ce0a188ce91258d6f0dc108d623c06c75ae6ceea6234707f9a1069e5462090dd8e318ae364ae33d669aad7ade4d2ab90e431665e83afe069720b40beac88f764e3dedb8b24146f73026885c6ea4c0e7721e8a9c7c8b1bddf4639294ad9e1c6ccb95e73f802cb2b4a5e443ace8865f3219c2c0e8858cef25382e65ce23c9700b08b4983ea39bb85c848aa753cac95ed973c468e6a835ea4afc25e3545124e2e4431245d19beab8b97089e35dd85d2294d0930725511ffee8827029e5a0cd7410631691cfd83beb392618a2020c3de216e7fad65f83b64611c483d905b70bd0000001800000010ac18668a255c7adc634c80fd2e5346670000001800000100bfaa942b08705c12ee2adda2ec81aa791be37133a4a365c388aff923aa51d7e73a0ed71c0865cb7144d2e041d17b68601561ae6710e3173541ff7cf1e4741003dfa043e447ccabe03863519a2646f8464a3beec6efef000630bc5c8f4b1636a42f3e5cecb1e8761a0e2761f9f571722b13351f5bb4017dfab8e0fa024e07569390b16f61003a6fbfb1497473835da615cd9afc39f542f9ad9b3e7fb06bc4f803602aa5bbf36940e800399c8bf2c8a7edd953f71d5ccd7037a4a519befb82160c0ee7ee0f7ede1a4e6fae96980e83772b8d57420d3d8cb75ff9a3ef98b4ba1b403966eab25fd3f8b15b2da1e6ff08f84a5d171c064d0c1a19972f632a2c4443ce000004020000000100040009000000056e616d6573000000100000000400040009000000026976000400090000000773657373696f6e00040009000000046461746100040009000000097369676e6174757265000000fe"
and the reverse with sodium::hex2bin
:
## [1] TRUE
(this is somewhat less space efficient than base64 encoding.
As a final option, you can just save the secret with
saveRDS
and read it in with readRDS
like any
other option. This will be the best route if the secret is saved into a
more complicated R object (e.g., a list or data.frame
).
See the other cyphr vignette
(vignette("data", package = "cyphr")
) for a suggested
workflow for exchanging secrets within a team, and the wrapper functions
below for more convenient ways of working with encrypted data.
Do you already have an ssh keypair? To find out, run
One of three things will happen:
you will be prompted for your password to decrypt your private
key, and then after entering it an object
<cyphr_keypair: openssl>
will be returned - you’re
good to go!
you were not prompted for your password, but got a
<cyphr_keypair: openssl>
object. You should consider
whether this is appropriate and consider generating a new keypair with
the private key encrypted. If you don’t then anyone who can read your
private key can decrypt any message intended for you.
you get an error like
Did not find default ssh public key at ~/.ssh/id_rsa.pub
.
You need to create a keypair.
To create a keypair, you can use the cyphr::ssh_keygen()
function as
This will create the keypair as ~/.ssh/id_rsa
and
~/.ssh/id_rsa.pub
, which is where cyphr
will
look for your keys by default. See ?ssh_keygen
for more
information. (On Linux and macOS you might use the
ssh-keygen
command line utility. On windows, PuTTY` has a
utility for creating keys.)
sodium
With sodium
, things are largely the same with the
exception that there is no standard format for saving sodium keys. The
bits below use an in-memory key (which is just a collection of bytes)
but these can also be filenames, each of which contains the contents of
the key written out with writeBin
.
First, generate keys for Alice:
the public key is derived from the private key, and Alice can share that with Bob. We next generate Bob’s keys
Bob would now share is public key with Alice.
If Alice wants to send a message to Bob she again uses her private key and Bob’s public key:
As above, she can now send a message:
## [1] 9b d0 9e 36 3c 18 a7 ef d1 b4 77 36 fc 75 62 6e 90 dd 71 91 99 bd 4d a6 38
## [26] 42 e1 25 af c1 c3 a9 d8 27 fb ec ca d3 8e 7a af 14 96 44 a9 9b f6 80 57 48
## [51] 6a 8b ec ae
Note how this line is identical to the one in the
openssl
section.
To decrypt this message, Bob would use Alice’s public key and his private key:
## [1] "secret message"
Above, we used cyphr::encrypt_string
and
cyphr::decrypt_string
to encrypt and decrypt a string.
There are several such functions in the package that encrypt and
decrypt
encrypt_object
/ decrypt_object
(using serialization and deserialization)encrypt_string
/
decrypt_string
encrypt_data
/
decrypt_data
encrypt_file
/ decrypt_file
For this section we will just use a sodium symmetric encryption key
For the examples below, in the case of asymmetric encryption (using
either cyphr::keypair_openssl
or
cyphr::keypair_sodium
) the sender would use their private
key and the recipient’s public key and the recipient would use the
complementary key pair.
Here’s an object to encrypt:
This creates a bunch of raw bytes corresponding to the data (it’s not really possible to print this as anything nicer than bytes).
## [1] 4c 80 e0 60 cc e2 9f 04 5f a4 3b b4 49 a2 05 cc e6 ac 47 0b 95 b9 6e d4 5b
## [26] e7 d4 52 40 a2 04 08 e9 30 66 f3 b6 1e 96 37 d3 a4 f6 e6 37 cf d3 03 b6 5e
## [51] 54 bc 6e 4b 4e 10 86 36 07 a5 2c a2 dc 65 b9 59 c1 ef f4 fb 95 9e cd 30 c4
## [76] a6 7d a2 cc 93 b1 0e 6a f1 15 4b 01 29 3a fc 41 8c b5 55 35 1e e4 0e 5f 59
## [101] ed 50 e5 bf b0 a6 2b 0a 0a 8f e4 6a 78 ab 81 c2 7b 75 aa 24 17 00 9a 6e e6
## [126] bc c0 7a 52 62 f5 93 cb b5 3e d5 b2 34 2e eb 83 b3 ab 2a f3 14 3f f1 4c 18
## [151] 57 cc f9 bc 0a b6 45 c6 da 5e b1 02 fa 1e 8c 1e eb 4b bd 4b df 18 e6 49 24
## [176] a8 bd ba c4 8e 27 24 51 79 cd 62 ef 7f 81 8a 3f c1 16 05 86 4f 95 8d 86 e1
## [201] f1 af d3 0a 97 c4 ef 55 5f 7c 96 a4 c7 fb d2 0e d2 f2 17 fe a3 4b b2 8d b3
## [226] 1a 15 84 6b a9 4f 79 13 4e c9 32 51 42 b6 06 1f 42 29 3a c9 11 e9 f0 ac 08
## [251] da 82 1e 5a
The data can be decrypted with the decrypt_object
function:
## $x
## [1] 1 2 3 4 5 6 7 8 9 10
##
## $y
## [1] "secret"
Optionally, this process can go via a file, using a third argument to the functions (note that temporary files are used here for compliance with CRAN policies - any path may be used in practice).
There is now a file called secret.rds
in the temporary
directory:
## [1] TRUE
though it is not actually an rds file:
## Error in readRDS(path_secret): unknown input format
When passed a filename (as opposed to a raw vector),
cyphr::decrypt_object
will read the object in before
decrypting it
## $x
## [1] 1 2 3 4 5 6 7 8 9 10
##
## $y
## [1] "secret"
For the case of strings we can do this in a slightly more lightweight
way (the above function routes through serialize
/
deserialize
which can be slow and will create larger
objects than using charToRaw
/ rawToChar
)
## [1] aa c8 c3 cc a6 58 49 50 11 a6 5b 39 0f 39 91 8d d1 3b 9a 00 cd 88 1f a7 7d
## [26] ca cb 11 60 cd 4b f6 ac 53 b9 c5 66 30 4f ed c4 a9 eb f0 db 85
and decrypt:
## [1] "secret"
If these are not enough for you, you can work directly with raw
objects (bunches of bytes) by using encrypt_data
:
## [1] d7 aa 43 30 89 a4 b1 ea 59 1e cf 36 48 be 4e ac 9d bc f6 b2 2c f8 59 e8 1c
## [26] 33 42 e7 16 b0 66 ed f6 9c e9 a6 d1 de 23 df b5 5b 84 f7 bb da 8b c0 a6 7e
## [51] c5 08 d2 0a 9c da 14 ff 08 11 cf eb 56 93 60 e8 33 6a 78 0f 7a 72 d3 25 96
## [76] 2f 3e 9e aa c6 09 be a8 01 00 06 21 a5 56 fa 5e 89 54 f7 07 7b ac 4c 8a 1c
## [1] 09 8e 12 70 0d e8 9b 1e dc 67 2a a0 17 5a 7c 6d ca 57 5b eb 56 f5 79 a1 2b
## [26] 5b 21 20 c6 2a c7 ef 30 5b 20 50 1f 95 67 6b ac ff 1e 4f 64 a3 d6 5c 90 73
## [51] 3c 79 00 68 c0 11 33 c2 80 94 e1 67 16 a2 db 63 9c 3b 53 d8 41 1c 9a 5a d2
## [76] 42 0b 80 53 13 5d e6 35 8c bb a0 54 d2 19 64 57 87 6f d0 e1 a2 06 6a 51 cf
## [101] bc 19 e9 84 1b a0 9a 01 98 f9 c9 36 23 d1 9d 0a 55 66 17 c2 8c 49 93 da 68
## [126] 8e e3 82 54 42 3c 03 c8 34 28 ce 64 ec bc 3f
Decrypted data is the same as a the original data
## [1] TRUE
Suppose we have written a file that we want to encrypt to send to someone (in a temporary directory for compliance with CRAN policies)
You can encrypt that file with
path_data_enc <- file.path(tempdir(), "iris.csv.enc")
cyphr::encrypt_file(path_data_csv, key, path_data_enc)
This encrypted file can then be decrypted with
path_data_decrypted <- file.path(tempdir(), "idis2.csv")
cyphr::decrypt_file(path_data_enc, key, path_data_decrypted)
Which is identical to the original:
## /tmp/RtmpWWimol/iris.csv /tmp/RtmpWWimol/idis2.csv
## "5fe92fe6a2c1928ef5a67b8939fdaf8d" "5fe92fe6a2c1928ef5a67b8939fdaf8d"
This is the most user-friendly way of using the package when the aim
is to encrypt and decrypt files. The package provides a pair of
functions cyphr::encrypt
and cyphr::decrypt
that wrap file writing and file reading functions. In general you would
use encrypt
when writing a file and decrypt
when reading one. They’re designed to be used like so:
Suppose you have a super-secret object that you want to share privately
If you save x
to disk with saveRDS
it will
be readable by everyone until it is deleted. But if you encrypted the
file that saveRDS
produced it would be protected and only
people with the key can read it:
(see below for some more details on how this works).
This file cannot be read with readRDS
:
## Error in readRDS(path_object): unknown input format
but if we wrap the call with decrypt
and pass in the
config object it can be decrypted and read:
## $a
## [1] 1 2 3 4 5 6 7 8 9 10
##
## $b
## [1] "don't tell anyone else"
What happens in the call above is cyphr
uses “non
standard evaluation” to rewrite the call above so that it becomes
(approximately)
cyphr::decrypt_file
to decrypt “secret.rds” as a
temporary filereadRDS
on that temporary fileThis non-standard evaluation breaks referential integrity (so may not
be suitable for programming). You can always do this manually with
encrypt_file
/ decrypt_file
so long as you
make sure to clean up after yourself.
The encrypt
function inspects the call in the first
argument passed to it and works out for the function provided
(saveRDS
) which argument corresponds to the filename (here
"secret.rds"
). It then rewrites the call to write out to a
temporary file (using tempfile()
). Then it calls
encrypt_file
(see below) on this temporary file to create
the file asked for ("secret.rds"
). Then it deletes the
temporary file, though this will also happen in case of an error in any
of the above.
The decrypt
function works similarly. It inspects the
call and detects that the first argument represents the filename. It
decrypts that file to create a temporary file, and then runs
readRDS
on that file. Again it will delete the temporary
file on exit.
The functions supported via this interface are:
readLines
/ writeLines
readRDS
/ writeRDS
read
/ save
read.table
/ write.table
read.csv
/ read.csv2
/
write.csv
read.delim
/ read.delim2
But new functions can be added with the rewrite_register
function. For example, to support the excellent rio package, whose
import
and export
functions take the filename
file
you could use:
now you can read and write tabular data into and out of a great many different file formats with encryption with calls like
The functions above use non
standard evaluation and so may not be suitable for programming or
use in packages. An “escape hatch” is provided via encrypt_
and decrypt_
where the first argument is a quoted
expression.
cyphr::encrypt_(quote(saveRDS(x, path_object)), key)
cyphr::decrypt_(quote(readRDS(path_object)), key)
## $a
## [1] 1 2 3 4 5 6 7 8 9 10
##
## $b
## [1] "don't tell anyone else"
When using key_openssl
, keypair_openssl
,
key_sodium
, or keypair_sodium
we generate
something that can decrypt data. The objects that are returned by these
functions can encrypt and decrypt data and so it is reasonable to be
concerned that if these objects were themselves saved to disk your data
would be compromised.
To avoid this, cyphr
does not store private or symmetric
keys directly in these objects but instead encrypts the sensitive keys
with a cyphr
-specific session key that is regenerated each
time the package is loaded. This means that the objects are practically
only useful within one session, and if saved with
save.image
(perhaps automatically at the end of a session)
the keys cannot be used to decrypt data.
To manually invalidate all keys you can use the
cyphr::session_key_refresh
function. For example, here is a
symmetric key:
which we can use to encrypt a secret string
and decrypt it:
## [1] "my secret"
If we refresh the session key we invalidate the key
object
and after this point the key cannot be used any further
## Error: Failed to decrypt key as session key has changed
This approach works because the package holds the session key within
its environment (in cyphr:::session$key
) which R will not
serialize. As noted above - this approach does not prevent an attacker
with the ability to snoop on your R session from discovering your
private keys or sensitive data but it does prevent accidentally saving
keys in a way that would be useful for an attacker to use in a
subsequent session.
openssl
(vignette(package = "openssl")
) and sodium
(vignette(package = "openssl")
) packages have explanations
of how the tools used in cyphr
work and interface with
R.Confused? Need help? Found a bug?
cyphr
issue
tracker