SecrecySwift is a wrapper library for CommonCrypto
and Security.framework
in Swift. It provides crpyto related functions.
- Digest and HMAC:
; - AES Encrypt and Decrypt:
; - RSA Encrypt/Decrypt and Sign/Verify with digest of
Carthage is a decentralized dependency manager that builds your dependencies and provides you with binary frameworks.
You can install Carthage with Homebrew using the following command:
$ brew update
$ brew install carthage
Buid for iOS
Create a Cartfile that lists the frameworks you’d like to use in your project.
git "" >= 0.3.4
carthage update
. This will fetch dependencies into a Carthage/Checkouts folder, then build each one. -
On your application targets’ “General” settings tab, in the “Linked Frameworks and Libraries” section, drag and drop each framework you want to use from the Carthage/Build folder on disk.
On your application targets’ “Build Phases” settings tab, click the “+” icon and choose “New Run Script Phase”. Create a Run Script with the following contents:
/usr/local/bin/carthage copy-frameworks
and add the paths to the frameworks you want to use under “Input Files”, e.g.:
Make sure that your project is in Git repository;
as submodule;git submodule
Drag and drop
to your project; -
On your application targets,
tab,Embedded Binaries
setting, click+
to addSecrecy.framework
. You will findSecrecy.framework
is also inBuild Phases
/Link Binary with Libraries
Copy following files in folder
to your project:- AES.swift
- Digest.swift
- HMAC.swift
- RSA.swift
- SecrecyExtension.swift
Crate a folder named
in your project and put
file:module CommonCrypto [system] { header "/Applications/" link "CommonCrypto" export * }
On your application targets
Build Settings
,Import Paths
setting, addCommonCrypto
. And add/usr/lib/system/
onLibrary Search Paths
; -
On your applicationtargets
Build Phases
tab,Link Binary with Linbrries
setting, addSecurity.framework
You should not import Secrecy
any more.
Digest.swift and HMAC.swift are forked from SwiftSSL:
Following alagorithms are available.
- MD2;
- MD4;
- MD5;
- SHA1;
- SHA224;
- SHA256;
- SHA384;
- SHA512;
Methods digestHex/digestBase64
in NSData
and String
could be used to digest it to Hex or Base64 Strings.
let raw = "abc123"
in NSData
and String
are signature methods to Hex and Base64 Strings.
let raw = "abc123"
print(raw.signHex(HMACAlgorithm.SHA1, key: "abc"))
print(raw.signBase64(HMACAlgorithm.SHA1, key: "abc"))
print(raw.signBase64(HMACAlgorithm.SHA1, key: "你好"))
It supports modes of:
- EBC;
- CBC:
Only PKCSPadding7 for AES is supported. Following encrypt alagorithms are supported depending on the length of KEY.
- AES128: 16;
- AES192: 24;
- AES256: 32;
: Encrypt in EBC Mode. -
Decrypt in EBC Mode from a Hex String. -
Decrypt in EBC Mode from a Base64 String.let key = "0000000000000000" let raw = "0123456789abcdef" let encrypt_1 = raw.aesEBCEncrypt(key) print(encrypt_1!.hexString) print(encrypt_1!.hexString.aesEBCDecryptFromHex(key)) print(encrypt_1!.base64String) print(encrypt_1!.base64String.aesEBCDecryptFromBase64(key))
CBC Mode can use IV, which will be filled with Zero if not specificed.
Encyrpt in CBC Mode; -
: Decrypt in CBC mode from a Hex String. -
: Decrypt in CBC mode from a Base64 String.let iv = "0000000000000000" let encrypt = raw.aesCBCEncrypt(key,iv: iv) print(encrypt!.hexString) print(encrypt!.hexString.aesCBCDecryptFromHex(key,iv: iv)) print(encrypt!.base64String) print(encrypt!.base64String.aesCBCDecryptFromBase64(key,iv: iv))
RSA in SecrecySwift supports file formats of .der
for public key and .p12
for private key. PKCS1Padding is used in RSA.
Generate certificates by OpenSSL
# Generate RSA Private Key
openssl genrsa -out private.pem 2048
# Get Public Key (pem file) from private key
openssl rsa -pubout -in private.pem -out public.pem
# Genrate Certificate Request from private key
openssl req -new -key private.pem -out cert.csr
# Generate Self-Signature Certificate from private key
openssl x509 -req -days 3650 -in cert.csr -signkey private.pem -out cert.crt
# Convert it to DER Format (Contains Public key)
openssl x509 -outform der -in cert.crt -out cert.der
# Export p12 file, with a password (Contains Private key)
openssl pkcs12 -export -inkey private.pem -in cert.crt -out cert.p12
Encrypt using Public Key
public func encrypt(data:NSData) -> NSData?
Decrypt usign Private Key
public func decrypt(data:NSData) -> NSData?
public func decrypt(fromHexString hexString:String) -> NSData?
public func decrypt(fromBase64String base64String:String) -> NSData?
let path_public = NSBundle.mainBundle().pathForResource("cert", ofType: "der")! let path_private = NSBundle.mainBundle().pathForResource("cert", ofType: "p12")! let raw = "0123456789abcdefg" let raw_data = raw.dataUsingEncoding(NSUTF8StringEncoding)! let rsa = RSA(filenameOfPulbicKey: path_public, filenameOfPrivateKey: path_private) guard let _rsa = rsa else { return } let encrypt_data = _rsa.encrypt(raw_data) let base64_string = encrypt_data!.base64String print(base64_string) let old_data = _rsa.decrypt(fromBase64String: base64_string) let old_string = String(data: old_data!, encoding: NSUTF8StringEncoding) print("old_string:\(old_string)")
You can use following alagorithms to sign:
- MD2;
- MD5;
- SHA1;
- SHA224;
- SHA256;
- SHA384;
- SHA512;
Sign using Private Key:
public func sign(algorithm:RSAAlgorithm,inputData:NSData) -> NSData?
Verify using Public Key:
public func verify(algorithm:RSAAlgorithm,inputData:NSData, signedData:NSData) -> Bool
let path_public = NSBundle.mainBundle().pathForResource("cert", ofType: "der")!
let path_private = NSBundle.mainBundle().pathForResource("cert", ofType: "p12")!
let rsa = RSA(filenameOfPulbicKey: path_public, filenameOfPrivateKey: path_private)
guard let _rsa = rsa else {
let raw = "0123456789abcdefg"
let raw_data = raw.dataUsingEncoding(NSUTF8StringEncoding)!
let sign_data = _rsa.sign(RSAAlgorithm.SHA1,inputData:raw_data)
// print(sign_data!.hexString)
let raw_test = "0123456789abcdefg"
let raw_test_data = raw_test.dataUsingEncoding(NSUTF8StringEncoding)!
let verified = _rsa.verify(RSAAlgorithm.SHA1,inputData: raw_test_data, signedData: sign_data!)
: Hex string; -
: Base64 String -
: Array of UInt8extension NSData { public var hexString : String public var base64String:String public func arrayOfBytes() -> [UInt8] }
: Get NSData from Hex String;extenstion String { func dataFromHexadecimalString() -> NSData? }
- Checkout how to impletment same functions in Python as SecrecySwift. SecrecyTestPy/