1 //----------------------------------------------------------------------
3 // Copyright (c) Microsoft Corporation.
4 // All rights reserved.
6 // This code is licensed under the MIT License.
8 // Permission is hereby granted, free of charge, to any person obtaining a copy
9 // of this software and associated documentation files(the "Software"), to deal
10 // in the Software without restriction, including without limitation the rights
11 // to use, copy, modify, merge, publish, distribute, sublicense, and / or sell
12 // copies of the Software, and to permit persons to whom the Software is
13 // furnished to do so, subject to the following conditions :
15 // The above copyright notice and this permission notice shall be included in
16 // all copies or substantial portions of the Software.
18 // THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS OR
19 // IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY,
20 // FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT.IN NO EVENT SHALL THE
21 // AUTHORS OR COPYRIGHT HOLDERS BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER
22 // LIABILITY, WHETHER IN AN ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING FROM,
23 // OUT OF OR IN CONNECTION WITH THE SOFTWARE OR THE USE OR OTHER DEALINGS IN
26 //------------------------------------------------------------------------------
29 using System.Runtime.InteropServices.WindowsRuntime;
30 using System.Threading.Tasks;
31 using Windows.Security.Cryptography;
32 using Windows.Security.Cryptography.DataProtection;
33 using Windows.Storage.Streams;
35 namespace Microsoft.IdentityModel.Clients.ActiveDirectory
37 internal static class CryptographyHelper
39 // This descriptor does not require the enterprise authentication capability.
40 private const string ProtectionDescriptor = "LOCAL=user";
42 public static string Encrypt(string message)
44 if (string.IsNullOrEmpty(message))
49 DataProtectionProvider dataProtectionProvider = new DataProtectionProvider(ProtectionDescriptor);
50 IBuffer messageBuffer = CryptographicBuffer.ConvertStringToBinary(message, BinaryStringEncoding.Utf8);
51 IBuffer protectedBuffer = RunAsyncTaskAndWait(dataProtectionProvider.ProtectAsync(messageBuffer).AsTask());
52 return Convert.ToBase64String(protectedBuffer.ToArray(0, (int)protectedBuffer.Length));
55 public static string Decrypt(string encryptedMessage)
57 if (string.IsNullOrEmpty(encryptedMessage))
59 return encryptedMessage;
62 DataProtectionProvider dataProtectionProvider = new DataProtectionProvider(ProtectionDescriptor);
63 IBuffer messageBuffer = Convert.FromBase64String(encryptedMessage).AsBuffer();
64 IBuffer unprotectedBuffer = RunAsyncTaskAndWait(dataProtectionProvider.UnprotectAsync(messageBuffer).AsTask());
65 return CryptographicBuffer.ConvertBinaryToString(BinaryStringEncoding.Utf8, unprotectedBuffer);
68 public static byte[] Encrypt(byte[] message)
75 DataProtectionProvider dataProtectionProvider = new DataProtectionProvider(ProtectionDescriptor);
76 IBuffer protectedBuffer = RunAsyncTaskAndWait(dataProtectionProvider.ProtectAsync(message.AsBuffer()).AsTask());
77 return protectedBuffer.ToArray(0, (int)protectedBuffer.Length);
80 public static byte[] Decrypt(byte[] encryptedMessage)
82 if (encryptedMessage == null)
87 DataProtectionProvider dataProtectionProvider = new DataProtectionProvider(ProtectionDescriptor);
88 IBuffer buffer = RunAsyncTaskAndWait(dataProtectionProvider.UnprotectAsync(encryptedMessage.AsBuffer()).AsTask());
89 return buffer.ToArray(0, (int)buffer.Length);
92 private static T RunAsyncTaskAndWait<T>(Task<T> task)
96 Task.Run(async () => await task.ConfigureAwait(false)).Wait();
99 catch (AggregateException ae)
101 // Any exception thrown as a result of running task will cause AggregateException to be thrown with
102 // actual exception as inner.
103 throw ae.InnerExceptions[0];