This project is a memory-safe command-line application for secure file encryption and decryption on UNIX-like systems. Written in C++, it demonstrates that robust security can be achieved even in traditionally unsafe languages by combining modern cryptographic primitives, memory-safe compilation, and secure programming practices.
The system encrypts files individually using AEAD (AES-GCM) and supports password-based authentication via Argon2id. Optional features like Shamir's Secret Sharing (SSS) for key splitting are planned for future releases.
- File encryption and decryption with per-file unique keys and nonces
- Secure memory management using Fil-C and OpenSSL secure buffers
- User authentication without storing persistent passwords
- Input validation and basic logging
- Anti-debugging measures to hinder reverse engineering
- Secure file deletion routines
- Clone the repository:
git clone https://github.com/yourusername/secure-file-encrypt.git cd secure-file-encrypt - Build:
Notes on the building:
./build.sh
-
The building process use "git pull" to complete the CI/CD pipeline with the fil-c compiler. Since both are an in development project doesn't exists any official pipeline and this is the fastest, simpler and universal solution found. A more robust way will be provided after a consist in a more mature phase of the project.
-
The building process could take some time, the reason for this are:
- Dependecy download and build: all the dependecies are builded as part of the project to allow fil-c to achieve full compability and overall memory control.
- Constant time encryption: to achieve constant time encryption to cryptographic sensitive libraries (OpenSSL) are needed to the compiler additional steps
- Fil-C security checks: fil-c introduces several security checks in the building phase and they take time.
-
- Application initialization:
To initialize the application run:./encrypt-it init
- Encryption/Decryption:
To encrypt or decrypt a file run:./encrypt-it encrypt --with-psw <filename> ./encrypt-it decrypt --with-psw <filename>
- Delete:
To securly delete a file run:./encrypt-it delete <filename>
- [Planned] Encryption/Decryption with SSS:
To encrypt or decrypt a file run:./encrypt-it encrypt --with-sss <filename> ./encrypt-it decrypt --with-sss <filename>