SecureFile is a web-based cybersecurity application that allows users to securely encrypt and decrypt files using modern cryptographic techniques.
The application uses AES-256-GCM encryption and PBKDF2-HMAC-SHA256 for secure password-based key derivation.
Users can encrypt a file with a password, download the encrypted file, and later decrypt it using the same password.
- Upload any supported file.
- Enter a password.
- Encrypt the file using AES-256-GCM.
- Download the encrypted file.
- The original file remains unchanged.
- Upload an encrypted
.encfile. - Enter the original password.
- Decrypt the file.
- Download the original file.
- AES-256-GCM authenticated encryption.
- PBKDF2-HMAC-SHA256 for password-based key derivation.
- Random salt for every encryption operation.
- Random IV/nonce for every encryption operation.
- Passwords are never stored.
- Uploaded files are not permanently stored.
- Modified or corrupted encrypted files are rejected.
SecureFile prevents users from encrypting an already encrypted SecureFile file.
document.pdf
↓
Encrypt
↓
document.pdf.enc
Trying to encrypt the .enc file again will result in:
❌ File is already encrypted
Original File
↓
User Password
↓
PBKDF2-HMAC-SHA256
↓
Encryption Key
↓
AES-256-GCM
↓
Encrypted File (.enc)
Encrypted File (.enc)
↓
User Password
↓
PBKDF2-HMAC-SHA256
↓
Encryption Key
↓
AES-256-GCM
↓
Original File
AES (Advanced Encryption Standard) is a widely used symmetric encryption algorithm.
SecureFile uses AES-256-GCM because it provides:
- Strong encryption
- Confidentiality
- Integrity protection
- Authentication of encrypted data
GCM also helps detect if an encrypted file has been modified or corrupted.
The user's password is not directly used as the AES encryption key.
Instead:
Password
+
Random Salt
↓
PBKDF2-HMAC-SHA256
↓
256-bit Encryption Key
This makes password-based encryption significantly stronger than directly using the password as an encryption key.
The password is never stored by the application.
SecureFile stores the required cryptographic information inside the encrypted file.
Conceptually:
┌──────────────────────┐
│ SecureFile Header │
├──────────────────────┤
│ Version │
├──────────────────────┤
│ Random Salt │
├──────────────────────┤
│ Random IV / Nonce │
├──────────────────────┤
│ Encrypted File Data │
├──────────────────────┤
│ Authentication Tag │
└──────────────────────┘
The password is not stored inside the file.
Without the correct password, the encrypted file cannot be successfully decrypted.
- Open SecureFile.
- Select Encrypt.
- Choose a file.
- Enter a password.
- Click Encrypt File.
- Download the
.encfile.
- Select Decrypt.
- Choose the encrypted
.encfile. - Enter the same password used during encryption.
- Click Decrypt File.
- Download the restored file.
SecureFile prevents common invalid operations.
document.pdf.enc
↓
Encrypt
↓
❌ Already encrypted
Encrypted File
↓
Wrong Password
↓
❌ Decryption Failed
If the encrypted file is modified after encryption:
Encrypted File
↓
Modified / Corrupted
↓
AES-GCM Verification
↓
❌ Integrity Check Failed
- Java
- Spring Boot
- Spring Web
- Java Cryptography Architecture (JCA)
- AES-256-GCM
- PBKDF2-HMAC-SHA256
- SecureRandom
- HTML5
- CSS3
- JavaScript
- Docker
- GitHub
- Cloud deployment
SecureFile/
│
├── src/
│ └── main/
│ ├── java/
│ │ └── com/
│ │ └── securefile/
│ │ ├── controller/
│ │ ├── service/
│ │ ├── security/
│ │ ├── config/
│ │ └── SecureFileApplication.java
│ │
│ └── resources/
│ ├── static/
│ │ ├── index.html
│ │ ├── css/
│ │ └── js/
│ │
│ └── application.properties
│
├── Dockerfile
├── .gitignore
├── pom.xml
└── README.md
Make sure you have:
- Java 17 or later
- Maven
- Git
git clone <YOUR-GITHUB-REPOSITORY>cd SecureFilemvn spring-boot:runThe application will start locally.
Open:
http://localhost:8080
Build the Docker image:
docker build -t securefile .Run the container:
docker run -p 8080:8080 securefileThen open:
http://localhost:8080
SecureFile can be deployed as a public web application.
Recommended architecture:
GitHub
↓
Docker
↓
Cloud Platform
↓
Public URL
↓
Anyone can access SecureFile
No account or login is required.
Users only need a web browser.
SecureFile is designed as an educational cybersecurity project and follows important security principles:
- Strong authenticated encryption
- Random cryptographic salt
- Random IV/nonce
- Password-based key derivation
- No password storage
- No permanent file storage
- File validation
- Protection against repeated encryption
- Integrity verification using AES-GCM
- Safe error handling
- No sensitive information in error responses
The security of the encrypted file ultimately depends on the strength of the password chosen by the user.
Users should use strong, unique passwords.
The main objectives of SecureFile are:
- Demonstrate practical use of cryptography.
- Understand symmetric encryption.
- Learn how AES works in real applications.
- Understand password-based key derivation.
- Demonstrate file confidentiality.
- Demonstrate file integrity verification.
- Build a practical cybersecurity application.
- Provide a simple interface that non-technical users can understand.
SecureFile can be used as a college cybersecurity project to demonstrate concepts such as:
- Cryptography
- Symmetric encryption
- AES
- Password-based encryption
- Key derivation
- Authentication
- Data confidentiality
- Data integrity
- Secure file handling
Possible future improvements include:
- Multiple file encryption
- Folder encryption
- Password strength meter
- Secure file sharing
- Expiring download links
- Client-side encryption
- Cloud storage integration
- User accounts
- File integrity verification
- Encryption history
- QR-based secure file sharing
Godson Suresh
Cybersecurity / Computer Science Project
This project is intended primarily for educational and academic purposes.
Add an appropriate open-source license if you plan to distribute the project publicly.