tkuehn

tkuehn

AES256 CBC encryption returning empty string

Hi everyone.
I’m currently looking into AES256 CBC and how to encrypt/decrypt plaintext using Elixir. The Erlang crypto module provides the crypto_one_time/5 function which seems like the right function to use.

The code I used:

iv = :crypto.strong_rand_bytes(16)
key = :crypto.strong_rand_bytes(32)
data_to_encrypt = "the_plaintext"
:crypto.crypto_one_time(:aes_256_cbc, key, iv, data_to_encrypt, true)

The problem I’m facing is that the crypto_one_time/5 function returns an empty string.

crypto.info/1 returns:

:crypto.info
%{
  otp_crypto_version: ~c"5.5.1",
  compile_type: :normal,
  link_type: :dynamic,
  cryptolib_version_compiled: ~c"OpenSSL 3.3.2 3 Sep 2024",
  cryptolib_version_linked: ~c"OpenSSL 3.4.0 22 Oct 2024",
  fips_provider_available: false
}

aec_256_cbc gets listed when using :crypto.supports()

:crypto.supports[:ciphers]
[:chacha20, :aes_256_ofb, :aes_192_ofb, :aes_128_ofb, :sm4_ctr, :sm4_ofb,
 :sm4_cfb, :sm4_ecb, :sm4_cbc, :blowfish_ecb, :blowfish_ofb64, :blowfish_cfb64,
 :blowfish_cbc, :des_ede3_cfb, :des_ecb, :des_cfb, :des_cbc, :rc4, :rc2_cbc,
 :aes_128_cbc, :aes_192_cbc, :aes_256_cbc, :aes_128_cfb128, :aes_192_cfb128,
 :aes_256_cfb128, :aes_128_cfb8, :aes_192_cfb8, :aes_256_cfb8, :aes_128_ecb,
 :aes_192_ecb, :aes_256_ecb, :sm4_gcm, :sm4_ccm, :chacha20_poly1305,
 :aes_256_gcm, :aes_256_ccm, :aes_192_gcm, :aes_192_ccm, :aes_128_gcm,
 :aes_128_ccm, :aes_256_ctr, :aes_192_ctr, :aes_128_ctr, :des_ede3_cbc,
 :aes_cbc, :aes_ccm, :aes_cfb128, :aes_cfb8, :aes_ctr, :aes_ecb, ...]

Any help would be greatly appreciated.

Marked As Solved

al2o3cr

al2o3cr

Further review turns up the padding option, which mentions this important fact:

This option handles padding in the last block. If not set, no padding is done and any bytes in the last unfilled block is silently discarded.

You can see this happening with a longer-than-16-byte string:

iex(28)> data_to_encrypt = "the_plaintext1234"
"the_plaintext1234"

iex(29)> byte_size(data_to_encrypt)
17

iex(30)> :crypto.crypto_one_time(:aes_256_cbc, key, iv, data_to_encrypt, true)
<<112, 120, 31, 19, 167, 197, 128, 142, 183, 99, 178, 94, 193, 254, 84, 224>>

iex(31)> byte_size(v(30))
16

The last byte is silently dropped because the block wasn’t full.

Explicitly passing a value for padding solves the original issue:

iex(26)> data_to_encrypt = "the_plaintext"
"the_plaintext"
iex(27)> :crypto.crypto_one_time(:aes_256_cbc, key, iv, data_to_encrypt, encrypt: true, padding: :pkcs_padding)
<<128, 42, 49, 230, 33, 26, 157, 34, 189, 47, 164, 21, 246, 50, 96, 230>>

Also Liked

tkuehn

tkuehn

Thank you for your quick response.
It’s the data which should get encrypted.
I’ll edit the question to make more clear.

al2o3cr

al2o3cr

There’s something going on here with the length of the input - making the plaintext longer eventually gives a non-empty result, at exactly 16 bytes :thinking:

iex(19)> data_to_encrypt = "the_plaintext1"
"the_plaintext1"

iex(20)> :crypto.crypto_one_time(:aes_256_cbc, key, iv, data_to_encrypt, true)
""

iex(21)> data_to_encrypt = "the_plaintext12"
"the_plaintext12"

iex(22)> :crypto.crypto_one_time(:aes_256_cbc, key, iv, data_to_encrypt, true)
""

iex(23)> data_to_encrypt = "the_plaintext123"
"the_plaintext123"

iex(24)> :crypto.crypto_one_time(:aes_256_cbc, key, iv, data_to_encrypt, true)
<<112, 120, 31, 19, 167, 197, 128, 142, 183, 99, 178, 94, 193, 254, 84, 224>>

iex(25)> byte_size(data_to_encrypt)
16
garrison

garrison

16 bytes (128 bits) is the block size of AES, so perhaps you are expected to pad the input yourself? (I don’t know much about cryptography)

Last Post!

garrison

garrison

I see, if it’s something that’s standardized that makes a lot more sense.

Where Next?

Popular in Questions Top

skosch
To my knowledge, put_in, Map.update etc. all have the one limitation of not automatically creating intermediate keys when needed (for exa...
New
nsuchy
Hi. I’ve noticed that Windows Powershell has it’s own IEX command and you cannot access Elixir’s IEX due to the conflict. This isn’t a cr...
New
jay1
Why is it that the mnesia database isn’t the most preferred database for use in Elixir/Phoenix?
New
komlanvi
Hi everyone, I was playing with phoenix liveView but I run into an issue. I have a form and want to validate each input text when the te...
New
vrod
I am using the Starship cross-shell prompt – it seems pretty nice, but I get some errors: [WARN] - (starship::utils): Executing command ...
New
Patoshizzle
After calling mix ecto.create I get this error: 17:00:32.162 [error] GenServer #PID&lt;0.412.0&gt; terminating ** (Postgrex.Error) FATAL...
New
JorisKok
I have a server on AWS, and was running a load test using artillery. When looking at the Phoenix dashboard I see the Ports going to 100% ...
New

Other popular topics Top

hariharasudhan94
Lets say I have map like this fetching from my database %{"_id" =&gt; #BSON.ObjectId&lt;58eb1a7a9ad169198c3dXXXX&gt;, "email" =&gt; ...
New
aadeshere1
I have a another noob question about loop. Since elixir is immutable, while loop is not directly possible. total = 10 while total != 0 ...
New
axelson
This post is a wiki (feel free to hit the edit button near the bottom right of this post to add your own changes!) This post collects co...
239 49134 226
New
sergio_101
I am VERY much an elixir newbie. I have taken one elixir course and one phoenix course on Udemy. During that course, I saw the instructor...
New
Patoshizzle
After calling mix ecto.create I get this error: 17:00:32.162 [error] GenServer #PID&lt;0.412.0&gt; terminating ** (Postgrex.Error) FATAL...
New
sergio
Kind of like when jquery came out, it was super necessary. Existing drag and drop libraries have a bunch of baggage to support old browse...
New

We're in Beta

About us Mission Statement