Alex Rivera | Logout

How do I encrypt a string and get a equal length encrypted string?

Asked 2009-06-12T09:31:49.190
14

My problem is the following:

In an existing database I want to encrypt data in a couple of columns. The columns contains strings of different lengths.

I don't want to change the size of the columns so the encryption need to produce an equal length text representation of the input text.

The strength of the encryption algorithm is of secondary interest but of course I want it to be as strong as it can be. Otherwise I wouldn't need to encrypt the data. But the most important thing is the size of the output.

Is this possible? If so how would I do it?

I'm interested in doing it in .NET. No database-level encryption.

Edit
Report

3 Answers

22

Within your constrants, I would use AES in CFB mode, which turns it into a stream cipher and the output length will be the same as the input length. Unless you're storing the strings in blobs, you'll need to hex or base64 encode the output to make it char friendly, which will be a 100% or 33% increase in length.

One .NET implementation is here.

answered 2009-06-19T02:33:02.273
2

Secure encryption requires that the ciphertext be larger than the plaintext; otherwise identical plaintext always results in identical ciphertext, and there's no such thing as an invalid ciphertext, which are both weaknesses.

However, if you really can't expand the data you're encrypting, the best you can do is a tweakable block mode. Look up XTS and CMC modes which are used for disk encryption.

answered 2009-09-23T12:24:05.540
1

This is usually impossible, because (in a naïve way) you would expect the encrypted string to hold more information than the plain text.

Vague ideas for solving your problem:
- Map your number onto a shorter text string: two digits could map into one character.
- Can you avoid encrypting the first x digits?
- What are the possibilities for encrypting it as an integer rather than text?

answered 2009-06-12T09:36:10.770

Your Answer