Skip to content

Additional security mechanism that use cryptographic methods to protect the payload of a JSON message

License

Notifications You must be signed in to change notification settings

tiagomistral/SecJSON

Folders and files

NameName
Last commit message
Last commit date

Latest commit

 

History

59 Commits
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 

Repository files navigation

NPM version Build status Dependency Status License Downloads

Secure JSON implementation for node.js. SecJSON allow encrypt/decrypt a message or a specific value of an JSON object.

Usage

npm install secjson

encrypt

var secjson = require('secjson');

var options = {
	rsa_pub: fs.readFileSync(__dirname + '/test-auth0_rsa.pub'),
	pem: fs.readFileSync(__dirname + '/test-auth0.pem'),
	encryptionAlgorithm: 'http://tiagomistral.github.io/SecJSON#aes128-cbc',
	keyEncryptionAlgorighm: 'http://tiagomistral.github.io/SecJSON#rsa-oaep-mgf1p'
};

secjson.encrypt('content to encrypt', options, function(err, result) { 
	console.log(result);
});

Result:

{
    "EncryptedData":{
        "EncryptionMethod":{
            "Algorithm":"http://tiagomistral.github.io/SecJSON#aes128-cbc"
        },
        "KeyInfo":{
            "EncryptedKey":{
                "EncryptionMethod":{
                    "Algorithm":"http://tiagomistral.github.io/SecJSON#rsa-oaep-mgf1p",
                    "DigestMethod":{
                        "Algorithm":"http://tiagomistral.github.io/SecJSON#sha1"
                    }
                },
                "KeyInfo": {
                   "RetrievalMethod": "MIIEDzCCAveg...[base64 cert]...q3uaLvlAUo="
                },
                "CipherData":{
                    "CipherValue":"Ad/F7DvLVc...[encrypted symmetric key]...0bb2VrjXcTZxQ=="
                }
            }
        },
        "CipherData":{
            "CipherValue":"g5HaGPWeQZ...[encrypted content]...4qYHVr5/pUQgjwVd"
        }
    }
}

decrypt

var decryptOptions = {
  key: fs.readFileSync(__dirname + '/test-auth0.key')
};

       
secjson.decrypt(encryptResult, decryptOptions, function(err, dec) { 
  console.log(dec);
});

Result:

content to encrypt

JSON encrypt

Encrypt the second book (Sword of Honour) of the object "obj".

var options = {
      rsa_pub: fs.readFileSync(__dirname + '/test-auth0_rsa.pub'),
      pem: fs.readFileSync(__dirname + '/test-auth0.pem'),
      encryptionAlgorithm: 'http://tiagomistral.github.io/SecJSON#aes128-cbc',
      keyEncryptionAlgorighm: 'http://tiagomistral.github.io/SecJSON#rsa-oaep-mgf1p'
    };

    var obj = {
    "store": {
      "book": [
        {
          "category": "reference",
          "author": "Nigel Rees",
          "title": "Sayings of the Century",
          "price": 8.95
        },
        {
          "category": "fiction",
          "author": "Evelyn Waugh",
          "title": "Sword of Honour",
          "price": 12.99
        },
        {
          "category": "fiction",
          "author": "Herman Melville",
          "title": "Moby Dick",
          "isbn": "0-553-21311-3",
          "price": 8.99
        },
        {
          "category": "fiction",
          "author": "J. R. R. Tolkien",
          "title": "The Lord of the Rings",
          "isbn": "0-395-19395-8",
          "price": 22.99
        }
      ],
      "bicycle": {
        "color": "red",
        "price": 19.95
      }
        }
      };

secjson.jsonEncrypt(obj, 'store.book[1]', options, function(err, encryptJsonObject) { 
	console.log(JSON.stringify(encryptJsonObject));
});

Result:

{
    "store":{
        "book":[
            {
                "category":"reference",
                "author":"Nigel Rees",
                "title":"Sayings of the Century",
                "price":8.95
            },
            {
                "EncryptedData":{
                    "EncryptionMethod":{
                        "Algorithm":"http://tiagomistral.github.io/SecJSON#aes128-cbc"
                    },
                    "KeyInfo":{
                        "EncryptedKey":{
                            "EncryptionMethod":{
                                "Algorithm":"http://tiagomistral.github.io/SecJSON#rsa-oaep-mgf1p",
                                "DigestMethod":{
                                    "Algorithm":"http://tiagomistral.github.io/SecJSON#sha1"
                                }
                            },
                            "KeyInfo": {
                                "RetrievalMethod": "MIIEDzCCAveg...[base64 cert]...q3uaLvlAUo="
                            },
                            "CipherData":{
                                "CipherValue":"nBZdvu0Go+Qp...[encrypted symmetric key]...hoCJR5NVxOdgdJcGClg=="
                            }
                        }
                    },
                    "CipherData":{
                        "CipherValue":"1GV6RbZcWRAe...[encrypted content]...IjcyW6sGKAC8IqMsBBesw=="
                    }
                }
            },
            {
                "category":"fiction",
                "author":"Herman Melville",
                "title":"Moby Dick",
                "isbn":"0-553-21311-3",
                "price":8.99
            },
            {
                "category":"fiction",
                "author":"J. R. R. Tolkien",
                "title":"The Lord of the Rings",
                "isbn":"0-395-19395-8",
                "price":22.99
            }
        ],
        "bicycle":{
            "color":"red",
            "price":19.95
        }
    }
}

JSON decrypt

var decryptOptions = {
	key: fs.readFileSync(__dirname + '/test-auth0.key')
};

secjson.jsonDecrypt(encryptJsonObject, 'store.book[1]', decryptOptions, function(err, dec) {
	console.log(JSON.stringify(dec));
});

Result:

{
   "store":{
      "book":[
         {
            "category":"reference",
            "author":"Nigel Rees",
            "title":"Sayings of the Century",
            "price":8.95
         },
         {
            "category":"fiction",
            "author":"Evelyn Waugh",
            "title":"Sword of Honour",
            "price":12.99
         },
         {
            "category":"fiction",
            "author":"Herman Melville",
            "title":"Moby Dick",
            "isbn":"0-553-21311-3",
            "price":8.99
         },
         {
            "category":"fiction",
            "author":"J. R. R. Tolkien",
            "title":"The Lord of the Rings",
            "isbn":"0-395-19395-8",
            "price":22.99
         }
      ],
      "bicycle":{
         "color":"red",
         "price":19.95
      }
   }
}

Supported algorithms

Currently the library supports:

However, you can fork and implement your own algorithm. The code supports adding more algorithms easily

Issue Reporting

If you have found a bug or if you have a feature request, please report them at this repository issues section. Please do not report security vulnerabilities on the public GitHub issue tracker. The Responsible Disclosure Program details the procedure for disclosing security issues.

License

MIT

About

Additional security mechanism that use cryptographic methods to protect the payload of a JSON message

Resources

License

Stars

Watchers

Forks

Releases

No releases published

Packages

No packages published