RSA/AES algorithm

Refs: #2799, #2800

Change-Id: I6aeb1ea2d7b3431d4569fb5b2cc3ce214ee6fca3
diff --git a/AUTHORS.md b/AUTHORS.md
index 5831026..e68757f 100644
--- a/AUTHORS.md
+++ b/AUTHORS.md
@@ -4,6 +4,7 @@
 ## The primary authors are (and/or have been):
 
 * Yingdi Yu             <http://irl.cs.ucla.edu/~yingdi/>
+* Prashanth Swaminathan <prashanthsw@gmail.com>
 
 ## All project authors and contributors
 
diff --git a/src/algo/aes.cpp b/src/algo/aes.cpp
new file mode 100644
index 0000000..07cb788
--- /dev/null
+++ b/src/algo/aes.cpp
@@ -0,0 +1,111 @@
+/* -*- Mode:C++; c-file-style:"gnu"; indent-tabs-mode:nil; -*- */
+/**
+ * Copyright (c) 2014-2015,  Regents of the University of California
+ *
+ * This file is part of gep (Group-based Encryption Protocol for NDN).
+ * See AUTHORS.md for complete list of gep authors and contributors.
+ *
+ * gep is free software: you can redistribute it and/or modify it under the terms
+ * of the GNU General Public License as published by the Free Software Foundation,
+ * either version 3 of the License, or (at your option) any later version.
+ *
+ * gep is distributed in the hope that it will be useful, but WITHOUT ANY WARRANTY;
+ * without even the implied warranty of MERCHANTABILITY or FITNESS FOR A PARTICULAR
+ * PURPOSE.  See the GNU General Public License for more details.
+ *
+ * You should have received a copy of the GNU General Public License along with
+ * gep, e.g., in COPYING.md file.  If not, see <http://www.gnu.org/licenses/>.
+ */
+
+#include <ndn-cxx/encoding/buffer-stream.hpp>
+#include "aes.hpp"
+
+namespace ndn {
+namespace gep {
+namespace algo {
+
+using namespace CryptoPP;
+
+Buffer
+crypt(CipherModeBase* cipher, const Buffer& data);
+
+DecryptKey<Aes>
+Aes::generateKey(RandomNumberGenerator& rng, AesKeyParams& params)
+{
+  SecByteBlock key(0x00, params.getKeySize() >> 3);  // Converting key bit-size to byte-size.
+  rng.GenerateBlock(key.data(), key.size());
+
+  DecryptKey<Aes> decryptKey(std::move(Buffer(key.data(), key.size())));
+  return decryptKey;
+}
+
+EncryptKey<Aes>
+Aes::deriveEncryptKey(const Buffer& keyBits)
+{
+  Buffer copy = keyBits;
+  EncryptKey<Aes> encryptKey(std::move(copy));
+  return encryptKey;
+}
+
+Buffer
+Aes::decrypt(const Buffer& keyBits, const Buffer& encryptedData, const EncryptParams& params)
+{
+  switch (params.getEncryptMode()) {
+  case ENCRYPT_MODE_ECB_AES:
+    {
+      ECB_Mode<AES>::Decryption ecbDecryption(keyBits.get(), keyBits.size());
+      return crypt(&ecbDecryption, encryptedData);
+    }
+
+  case ENCRYPT_MODE_CBC_AES:
+    {
+      Buffer initVector = params.getIV();
+      if (initVector.size() != static_cast<size_t>(AES::BLOCKSIZE))
+        throw Error("incorrect initial vector size");
+
+      CBC_Mode<AES>::Decryption cbcDecryption(keyBits.get(), keyBits.size(), initVector.get());
+      return crypt(&cbcDecryption, encryptedData);
+    }
+
+  default:
+    throw Error("unsupported encryption mode");
+  }
+}
+
+Buffer
+Aes::encrypt(const Buffer& keyBits, const Buffer& plainData, const EncryptParams& params)
+{
+  switch (params.getEncryptMode()) {
+  case ENCRYPT_MODE_ECB_AES:
+    {
+      ECB_Mode<AES>::Encryption ecbEncryption(keyBits.get(), keyBits.size());
+      return crypt(&ecbEncryption, plainData);
+    }
+
+  case ENCRYPT_MODE_CBC_AES:
+    {
+      Buffer initVector = params.getIV();
+      if (initVector.size() != static_cast<size_t>(AES::BLOCKSIZE))
+        throw Error("incorrect initial vector size");
+
+      CBC_Mode<AES>::Encryption cbcEncryption(keyBits.get(), keyBits.size(), initVector.get());
+      return crypt(&cbcEncryption, plainData);
+    }
+
+  default:
+    throw Error("unsupported encryption mode");
+  }
+}
+
+Buffer
+crypt(CipherModeBase* cipher, const Buffer& data)
+{
+  OBufferStream obuf;
+  StringSource pipe(data.get(), data.size(), true,
+                    new StreamTransformationFilter(*cipher, new FileSink(obuf)));
+  return *(obuf.buf());
+}
+
+} // namespace algo
+} // namespace gep
+} // namespace ndn
diff --git a/src/algo/aes.hpp b/src/algo/aes.hpp
new file mode 100644
index 0000000..931b28d
--- /dev/null
+++ b/src/algo/aes.hpp
@@ -0,0 +1,56 @@
+/* -*- Mode:C++; c-file-style:"gnu"; indent-tabs-mode:nil; -*- */
+/**
+ * Copyright (c) 2014-2015,  Regents of the University of California
+ *
+ * This file is part of gep (Group-based Encryption Protocol for NDN).
+ * See AUTHORS.md for complete list of gep authors and contributors.
+ *
+ * gep is free software: you can redistribute it and/or modify it under the terms
+ * of the GNU General Public License as published by the Free Software Foundation,
+ * either version 3 of the License, or (at your option) any later version.
+ *
+ * gep is distributed in the hope that it will be useful, but WITHOUT ANY WARRANTY;
+ * without even the implied warranty of MERCHANTABILITY or FITNESS FOR A PARTICULAR
+ * PURPOSE.  See the GNU General Public License for more details.
+ *
+ * You should have received a copy of the GNU General Public License along with
+ * gep, e.g., in COPYING.md file.  If not, see <http://www.gnu.org/licenses/>.
+ */
+
+#ifndef NDN_GEP_ALGO_AES_HPP
+#define NDN_GEP_ALGO_AES_HPP
+
+#include <ndn-cxx/security/key-params.hpp>
+#include "random-number-generator.hpp"
+#include "algo/encrypt-params.hpp"
+#include "decrypt-key.hpp"
+#include "error.hpp"
+
+namespace ndn {
+namespace gep {
+namespace algo {
+
+class Aes
+{
+public:
+  static DecryptKey<Aes>
+  generateKey(RandomNumberGenerator& rng, AesKeyParams& params);
+
+  static EncryptKey<Aes>
+  deriveEncryptKey(const Buffer& keyBits);
+
+  static Buffer
+  decrypt(const Buffer& keyBits, const Buffer& encryptedData, const EncryptParams& params);
+
+  static Buffer
+  encrypt(const Buffer& keyBits, const Buffer& plainData, const EncryptParams& params);
+};
+
+typedef DecryptKey<Aes> AesEncryptKey;
+typedef EncryptKey<Aes> AesDecryptKey;
+
+} // namespace algo
+} // namespace gep
+} // namespace ndn
+
+#endif // NDN_GEP_ALGO_AES_ECB_HPP
diff --git a/src/algo/encrypt-params.cpp b/src/algo/encrypt-params.cpp
new file mode 100644
index 0000000..296cb22
--- /dev/null
+++ b/src/algo/encrypt-params.cpp
@@ -0,0 +1,76 @@
+/* -*- Mode:C++; c-file-style:"gnu"; indent-tabs-mode:nil; -*- */
+/**
+ * Copyright (c) 2014-2015,  Regents of the University of California
+ *
+ * This file is part of gep (Group-based Encryption Protocol for NDN).
+ * See AUTHORS.md for complete list of gep authors and contributors.
+ *
+ * gep is free software: you can redistribute it and/or modify it under the terms
+ * of the GNU General Public License as published by the Free Software Foundation,
+ * either version 3 of the License, or (at your option) any later version.
+ *
+ * gep is distributed in the hope that it will be useful, but WITHOUT ANY WARRANTY;
+ * without even the implied warranty of MERCHANTABILITY or FITNESS FOR A PARTICULAR
+ * PURPOSE.  See the GNU General Public License for more details.
+ *
+ * You should have received a copy of the GNU General Public License along with
+ * gep, e.g., in COPYING.md file.  If not, see <http://www.gnu.org/licenses/>.
+ */
+
+#include "random-number-generator.hpp"
+#include "encrypt-params.hpp"
+
+namespace ndn {
+namespace gep {
+namespace algo {
+
+EncryptParams::EncryptParams(EncryptionMode encryptMode, PaddingScheme paddingScheme, uint8_t ivLength = 0)
+  : m_encryptMode(encryptMode)
+  , m_paddingScheme(paddingScheme)
+{
+  if (ivLength != 0){
+    RandomNumberGenerator rng;
+    m_iv.resize(ivLength);
+    rng.GenerateBlock(m_iv.buf(), m_iv.size());
+  }
+}
+
+void
+EncryptParams::setIV(const Buffer& iv)
+{
+  m_iv = iv;
+}
+
+void
+EncryptParams::setEncryptMode(const EncryptionMode& encryptMode)
+{
+  m_encryptMode = encryptMode;
+}
+
+void
+EncryptParams::setPaddingScheme(const PaddingScheme& paddingScheme)
+{
+  m_paddingScheme = paddingScheme;
+}
+
+Buffer
+EncryptParams::getIV() const
+{
+  return m_iv;
+}
+
+EncryptionMode
+EncryptParams::getEncryptMode() const
+{
+  return m_encryptMode;
+}
+
+PaddingScheme
+EncryptParams::getPaddingScheme() const
+{
+  return m_paddingScheme;
+}
+
+} // namespace algo
+} // namespace gep
+} // namespace ndn
\ No newline at end of file
diff --git a/src/algo/encrypt-params.hpp b/src/algo/encrypt-params.hpp
new file mode 100644
index 0000000..2be5d99
--- /dev/null
+++ b/src/algo/encrypt-params.hpp
@@ -0,0 +1,61 @@
+#ifndef NDN_GEP_ENCRYPT_PARAMS_HPP
+#define NDN_GEP_ENCRYPT_PARAMS_HPP
+
+#include <ndn-cxx/encoding/buffer-stream.hpp>
+
+namespace ndn {
+namespace gep {
+
+enum EncryptionMode {
+  ENCRYPT_MODE_ECB_AES,
+  ENCRYPT_MODE_CBC_AES,
+  ENCRYPT_MODE_RSA
+};
+
+enum PaddingScheme {
+  PADDING_SCHEME_PKCS7,
+  PADDING_SCHEME_PKCS1v15,
+  PADDING_SCHEME_OAEP_SHA
+};
+
+namespace algo {
+
+class EncryptParams
+{
+public:
+  EncryptParams(EncryptionMode encryptMode, PaddingScheme paddingScheme, uint8_t ivLength);
+
+  virtual
+  ~EncryptParams()
+  {
+  }
+
+  void
+  setIV(const Buffer& iv);
+
+  void
+  setEncryptMode(const EncryptionMode& encryptMode);
+
+  void
+  setPaddingScheme(const PaddingScheme& paddingScheme);
+
+  Buffer
+  getIV() const;
+
+  EncryptionMode
+  getEncryptMode() const;
+
+  PaddingScheme
+  getPaddingScheme() const;
+
+private:
+  EncryptionMode m_encryptMode;
+  PaddingScheme m_paddingScheme;
+  Buffer m_iv;
+};
+
+} // namespace algo
+} // namespace gep
+} // namespace ndn
+
+#endif // NDN_GEP_ENCRYPT_PARAMS_HPP
diff --git a/src/algo/error.hpp b/src/algo/error.hpp
new file mode 100644
index 0000000..4cb46b1
--- /dev/null
+++ b/src/algo/error.hpp
@@ -0,0 +1,43 @@
+/* -*- Mode:C++; c-file-style:"gnu"; indent-tabs-mode:nil; -*- */
+/**
+ * Copyright (c) 2014-2015,  Regents of the University of California
+ *
+ * This file is part of gep (Group-based Encryption Protocol for NDN).
+ * See AUTHORS.md for complete list of gep authors and contributors.
+ *
+ * gep is free software: you can redistribute it and/or modify it under the terms
+ * of the GNU General Public License as published by the Free Software Foundation,
+ * either version 3 of the License, or (at your option) any later version.
+ *
+ * gep is distributed in the hope that it will be useful, but WITHOUT ANY WARRANTY;
+ * without even the implied warranty of MERCHANTABILITY or FITNESS FOR A PARTICULAR
+ * PURPOSE.  See the GNU General Public License for more details.
+ *
+ * You should have received a copy of the GNU General Public License along with
+ * gep, e.g., in COPYING.md file.  If not, see <http://www.gnu.org/licenses/>.
+ */
+
+#ifndef NDN_GEP_ALGO_ERROR_HPP
+#define NDN_GEP_ALGO_ERROR_HPP
+
+#include <stdexcept>
+
+namespace ndn {
+namespace gep {
+namespace algo {
+
+class Error : public std::runtime_error
+{
+public:
+  explicit
+  Error(const std::string& what)
+    : std::runtime_error(what)
+  {
+  }
+};
+
+} // namespace algo
+} // namespace gep
+} // namespace ndn
+
+#endif // NDN_GEP_ALGO_ERROR_HPP
diff --git a/src/algo/rsa.cpp b/src/algo/rsa.cpp
new file mode 100644
index 0000000..66361fb
--- /dev/null
+++ b/src/algo/rsa.cpp
@@ -0,0 +1,135 @@
+/* -*- Mode:C++; c-file-style:"gnu"; indent-tabs-mode:nil; -*- */
+/**
+ * Copyright (c) 2014-2015,  Regents of the University of California
+ *
+ * This file is part of gep (Group-based Encryption Protocol for NDN).
+ * See AUTHORS.md for complete list of gep authors and contributors.
+ *
+ * gep is free software: you can redistribute it and/or modify it under the terms
+ * of the GNU General Public License as published by the Free Software Foundation,
+ * either version 3 of the License, or (at your option) any later version.
+ *
+ * gep is distributed in the hope that it will be useful, but WITHOUT ANY WARRANTY;
+ * without even the implied warranty of MERCHANTABILITY or FITNESS FOR A PARTICULAR
+ * PURPOSE.  See the GNU General Public License for more details.
+ *
+ * You should have received a copy of the GNU General Public License along with
+ * gep, e.g., in COPYING.md file.  If not, see <http://www.gnu.org/licenses/>.
+ */
+
+#include <ndn-cxx/encoding/buffer-stream.hpp>
+#include "rsa.hpp"
+
+namespace ndn {
+namespace gep {
+namespace algo {
+
+using namespace CryptoPP;
+
+Buffer
+crypt(SimpleProxyFilter* filter, const Buffer& data);
+
+DecryptKey<Rsa>
+Rsa::generateKey(RandomNumberGenerator& rng, RsaKeyParams& params)
+{
+  RSA::PrivateKey privateKey;
+  privateKey.GenerateRandomWithKeySize(rng, params.getKeySize());
+
+  OBufferStream obuf;
+  privateKey.Save(FileSink(obuf).Ref());
+
+  DecryptKey<Rsa> decryptKey(std::move(*obuf.buf()));
+  return decryptKey;
+}
+
+EncryptKey<Rsa>
+Rsa::deriveEncryptKey(const Buffer& keyBits)
+{
+  RSA::PrivateKey privateKey;
+
+  ByteQueue keyQueue;
+  keyQueue.LazyPut(keyBits.get(), keyBits.size());
+  privateKey.Load(keyQueue);
+
+  RSA::PublicKey publicKey(privateKey);
+
+  OBufferStream obuf;
+  publicKey.Save(FileSink(obuf).Ref());
+
+  EncryptKey<Rsa> encryptKey(std::move(*obuf.buf()));
+  return encryptKey;
+}
+
+Buffer
+Rsa::decrypt(const Buffer& keyBits, const Buffer& encryptedData, const EncryptParams& params)
+{
+  AutoSeededRandomPool rng;
+  RSA::PrivateKey privateKey;
+
+  ByteQueue keyQueue;
+  keyQueue.LazyPut(keyBits.data(), keyBits.size());
+  privateKey.Load(keyQueue);
+
+  switch (params.getPaddingScheme()) {
+  case PADDING_SCHEME_PKCS1v15:
+    {
+      RSAES_PKCS1v15_Decryptor decryptor_pkcs1v15(privateKey);
+      PK_DecryptorFilter* filter_pkcs1v15 = new PK_DecryptorFilter(rng, decryptor_pkcs1v15);
+      return crypt(filter_pkcs1v15, encryptedData);
+    }
+
+  case PADDING_SCHEME_OAEP_SHA:
+    {
+      RSAES_OAEP_SHA_Decryptor decryptor_oaep_sha(privateKey);
+      PK_DecryptorFilter* filter_oaep_sha = new PK_DecryptorFilter(rng, decryptor_oaep_sha);
+      return crypt(filter_oaep_sha, encryptedData);
+    }
+
+  default:
+    throw Error("unsupported padding scheme");
+  }
+}
+
+Buffer
+Rsa::encrypt(const Buffer& keyBits, const Buffer& plainData, const EncryptParams& params)
+{
+  AutoSeededRandomPool rng;
+  RSA::PublicKey publicKey;
+
+  ByteQueue keyQueue;
+  keyQueue.LazyPut(keyBits.data(), keyBits.size());
+  publicKey.Load(keyQueue);
+
+  switch (params.getPaddingScheme()) {
+  case PADDING_SCHEME_PKCS1v15:
+    {
+      RSAES_PKCS1v15_Encryptor encryptor_pkcs1v15(publicKey);
+      PK_EncryptorFilter* filter_pkcs1v15 = new PK_EncryptorFilter(rng, encryptor_pkcs1v15);
+      return crypt(filter_pkcs1v15, plainData);
+    }
+
+  case PADDING_SCHEME_OAEP_SHA:
+    {
+      RSAES_OAEP_SHA_Encryptor encryptor_oaep_sha(publicKey);
+      PK_EncryptorFilter* filter_oaep_sha = new PK_EncryptorFilter(rng, encryptor_oaep_sha);
+      return crypt(filter_oaep_sha, plainData);
+    }
+
+  default:
+    throw Error("unsupported padding scheme");
+  }
+}
+
+Buffer
+crypt(SimpleProxyFilter* filter, const Buffer& data)
+{
+  OBufferStream obuf;
+  filter->Attach(new FileSink(obuf));
+
+  StringSource pipe(data.get(), data.size(), true, filter);
+  return *(obuf.buf());
+}
+
+} // namespace algo
+} // namespace gep
+} // namespace ndn
diff --git a/src/algo/rsa.hpp b/src/algo/rsa.hpp
new file mode 100644
index 0000000..7d4567b
--- /dev/null
+++ b/src/algo/rsa.hpp
@@ -0,0 +1,57 @@
+/* -*- Mode:C++; c-file-style:"gnu"; indent-tabs-mode:nil; -*- */
+/**
+ * Copyright (c) 2014-2015,  Regents of the University of California
+ *
+ * This file is part of gep (Group-based Encryption Protocol for NDN).
+ * See AUTHORS.md for complete list of gep authors and contributors.
+ *
+ * gep is free software: you can redistribute it and/or modify it under the terms
+ * of the GNU General Public License as published by the Free Software Foundation,
+ * either version 3 of the License, or (at your option) any later version.
+ *
+ * gep is distributed in the hope that it will be useful, but WITHOUT ANY WARRANTY;
+ * without even the implied warranty of MERCHANTABILITY or FITNESS FOR A PARTICULAR
+ * PURPOSE.  See the GNU General Public License for more details.
+ *
+ * You should have received a copy of the GNU General Public License along with
+ * gep, e.g., in COPYING.md file.  If not, see <http://www.gnu.org/licenses/>.
+ */
+
+#ifndef NDN_GEP_ALGO_RSA_HPP
+#define NDN_GEP_ALGO_RSA_HPP
+
+#include <ndn-cxx/security/key-params.hpp>
+
+#include "random-number-generator.hpp"
+#include "algo/encrypt-params.hpp"
+#include "decrypt-key.hpp"
+#include "error.hpp"
+
+namespace ndn {
+namespace gep {
+namespace algo {
+
+class Rsa
+{
+public:
+  static DecryptKey<Rsa>
+  generateKey(RandomNumberGenerator& rng, RsaKeyParams& params);
+
+  static EncryptKey<Rsa>
+  deriveEncryptKey(const Buffer& keyBits);
+
+  static Buffer
+  decrypt(const Buffer& keyBits, const Buffer& encryptedData, const EncryptParams& params);
+
+  static Buffer
+  encrypt(const Buffer& keyBits, const Buffer& plainData, const EncryptParams& params);
+};
+
+typedef DecryptKey<Rsa> RsaPrivateKey;
+typedef EncryptKey<Rsa> RsaPublicKey;
+
+} // namespace algo
+} // namespace gep
+} // namespace ndn
+
+#endif // NDN_GEP_ALGO_RSA_HPP
diff --git a/src/cryptopp.hpp b/src/cryptopp.hpp
new file mode 100644
index 0000000..a7a1ae8
--- /dev/null
+++ b/src/cryptopp.hpp
@@ -0,0 +1,44 @@
+/* -*- Mode:C++; c-file-style:"gnu"; indent-tabs-mode:nil; -*- */
+/**
+ * Copyright (c) 2014-2015,  Regents of the University of California
+ *
+ * This file is part of ndn-group-encrypt (Group-based Encryption Protocol for NDN).
+ * See AUTHORS.md for complete list of ndn-group-encrypt authors and contributors.
+ *
+ * ndn-group-encrypt is free software: you can redistribute it and/or modify it under
+ * the terms of the GNU General Public License as published by the Free Software
+ * Foundation, either version 3 of the License, or (at your option) any later version.
+ *
+ * ndn-group-encrypt is distributed in the hope that it will be useful, but WITHOUT
+ * ANY WARRANTY; without even the implied warranty of MERCHANTABILITY or FITNESS FOR
+ * A PARTICULAR PURPOSE.  See the GNU General Public License for more details.
+ *
+ * You should have received a copy of the GNU General Public License along with
+ * ndn-group-encrypt, e.g., in COPYING.md file.  If not, see <http://www.gnu.org/licenses/>.
+ */
+
+#ifndef NDN_GEP_CRYPTOPP_HPP
+#define NDN_GEP_CRYPTOPP_HPP
+
+// suppress CryptoPP warnings
+#pragma GCC system_header
+#pragma clang system_header
+
+#include <cryptopp/asn.h>
+#include <cryptopp/base64.h>
+#include <cryptopp/des.h>
+#include <cryptopp/files.h>
+#include <cryptopp/filters.h>
+#include <cryptopp/hex.h>
+#include <cryptopp/modes.h>
+#include <cryptopp/osrng.h>
+#include <cryptopp/pssr.h>
+#include <cryptopp/pwdbased.h>
+#include <cryptopp/rsa.h>
+#include <cryptopp/sha.h>
+#include <cryptopp/eccrypto.h>
+#include <cryptopp/oids.h>
+#include <cryptopp/dsa.h>
+#include <cryptopp/cryptlib.h>
+
+#endif // NDN_GEP_CRYPTOPP_HPP
diff --git a/src/decrypt-key.hpp b/src/decrypt-key.hpp
new file mode 100644
index 0000000..fdccea7
--- /dev/null
+++ b/src/decrypt-key.hpp
@@ -0,0 +1,62 @@
+/* -*- Mode:C++; c-file-style:"gnu"; indent-tabs-mode:nil; -*- */
+/**
+ * Copyright (c) 2014-2015,  Regents of the University of California
+ *
+ * This file is part of ndn-group-encrypt (Group-based Encryption Protocol for NDN).
+ * See AUTHORS.md for complete list of ndn-group-encrypt authors and contributors.
+ *
+ * ndn-group-encrypt is free software: you can redistribute it and/or modify it under
+ * the terms of the GNU General Public License as published by the Free Software
+ * Foundation, either version 3 of the License, or (at your option) any later version.
+ *
+ * ndn-group-encrypt is distributed in the hope that it will be useful, but WITHOUT
+ * ANY WARRANTY; without even the implied warranty of MERCHANTABILITY or FITNESS FOR
+ * A PARTICULAR PURPOSE.  See the GNU General Public License for more details.
+ *
+ * You should have received a copy of the GNU General Public License along with
+ * ndn-group-encrypt, e.g., in COPYING.md file.  If not, see <http://www.gnu.org/licenses/>.
+ */
+
+#ifndef NDN_GEP_DECRYPT_KEY_HPP
+#define NDN_GEP_DECRYPT_KEY_HPP
+
+#include "encrypt-key.hpp"
+
+namespace ndn {
+namespace gep {
+
+template<class Algorithm>
+class DecryptKey
+{
+public:
+  DecryptKey(Buffer&& keyBits)
+    : m_keyBits(keyBits)
+  {
+  }
+
+  EncryptKey<Algorithm>
+  deriveEncryptKey()
+  {
+    return Algorithm::deriveEncryptKey(m_keyBits);
+  }
+
+  Buffer
+  decrypt(const Buffer& encryptedData)
+  {
+    return Algorithm::decrypt(m_keyBits, encryptedData);
+  }
+
+  const Buffer&
+  getKeyBits()
+  {
+    return m_keyBits;
+  }
+
+private:
+  Buffer m_keyBits;
+};
+
+} // namespace gep
+} // namespace ndn
+
+#endif // NDN_GEP_DECRYPT_KEY_HPP
diff --git a/src/encrypt-key.hpp b/src/encrypt-key.hpp
new file mode 100644
index 0000000..ba0d778
--- /dev/null
+++ b/src/encrypt-key.hpp
@@ -0,0 +1,56 @@
+/* -*- Mode:C++; c-file-style:"gnu"; indent-tabs-mode:nil; -*- */
+/**
+ * Copyright (c) 2014-2015,  Regents of the University of California
+ *
+ * This file is part of ndn-group-encrypt (Group-based Encryption Protocol for NDN).
+ * See AUTHORS.md for complete list of ndn-group-encrypt authors and contributors.
+ *
+ * ndn-group-encrypt is free software: you can redistribute it and/or modify it under
+ * the terms of the GNU General Public License as published by the Free Software
+ * Foundation, either version 3 of the License, or (at your option) any later version.
+ *
+ * ndn-group-encrypt is distributed in the hope that it will be useful, but WITHOUT
+ * ANY WARRANTY; without even the implied warranty of MERCHANTABILITY or FITNESS FOR
+ * A PARTICULAR PURPOSE.  See the GNU General Public License for more details.
+ *
+ * You should have received a copy of the GNU General Public License along with
+ * ndn-group-encrypt, e.g., in COPYING.md file.  If not, see <http://www.gnu.org/licenses/>.
+ */
+
+#ifndef NDN_GEP_ENCRYPT_KEY_HPP
+#define NDN_GEP_ENCRYPT_KEY_HPP
+
+#include "common.hpp"
+
+namespace ndn {
+namespace gep {
+
+template<class Algorithm>
+class EncryptKey
+{
+public:
+  EncryptKey(Buffer&& keyBits)
+    : m_keyBits(keyBits)
+  {
+  }
+
+  Buffer
+  encrypt(const Buffer& plainData)
+  {
+    return Algorithm::encrypt(m_keyBits, plainData);
+  }
+
+  const Buffer&
+  getKeyBits() const
+  {
+    return m_keyBits;
+  }
+
+private:
+  Buffer m_keyBits;
+};
+
+} // namespace gep
+} // namespace ndn
+
+#endif // NDN_GEP_ENCRYPT_KEY_HPP
diff --git a/src/random-number-generator.hpp b/src/random-number-generator.hpp
new file mode 100644
index 0000000..0d74f47
--- /dev/null
+++ b/src/random-number-generator.hpp
@@ -0,0 +1,33 @@
+/* -*- Mode:C++; c-file-style:"gnu"; indent-tabs-mode:nil; -*- */
+/**
+ * Copyright (c) 2014-2015,  Regents of the University of California
+ *
+ * This file is part of ndn-group-encrypt (Group-based Encryption Protocol for NDN).
+ * See AUTHORS.md for complete list of ndn-group-encrypt authors and contributors.
+ *
+ * ndn-group-encrypt is free software: you can redistribute it and/or modify it under
+ * the terms of the GNU General Public License as published by the Free Software
+ * Foundation, either version 3 of the License, or (at your option) any later version.
+ *
+ * ndn-group-encrypt is distributed in the hope that it will be useful, but WITHOUT
+ * ANY WARRANTY; without even the implied warranty of MERCHANTABILITY or FITNESS FOR
+ * A PARTICULAR PURPOSE.  See the GNU General Public License for more details.
+ *
+ * You should have received a copy of the GNU General Public License along with
+ * ndn-group-encrypt, e.g., in COPYING.md file.  If not, see <http://www.gnu.org/licenses/>.
+ */
+
+#ifndef NDN_GEP_RANDOM_NUMBER_GENERATOR_HPP
+#define NDN_GEP_RANDOM_NUMBER_GENERATOR_HPP
+
+#include "cryptopp.hpp"
+
+namespace ndn {
+namespace gep {
+
+typedef CryptoPP::AutoSeededRandomPool RandomNumberGenerator;
+
+} // namespace gep
+} // namespace ndn
+
+#endif // NDN_GEP_RANDOM_NUMBER_GENERATOR_HPP
diff --git a/tests/unit-tests/aes.t.cpp b/tests/unit-tests/aes.t.cpp
new file mode 100644
index 0000000..46787cc
--- /dev/null
+++ b/tests/unit-tests/aes.t.cpp
@@ -0,0 +1,115 @@
+/* -*- Mode:C++; c-file-style:"gnu"; indent-tabs-mode:nil; -*- */
+/**
+ * Copyright (c) 2014-2015,  Regents of the University of California
+ *
+ * This file is part of ndn-group-encrypt (Group-based Encryption Protocol for NDN).
+ * See AUTHORS.md for complete list of ndn-group-encrypt authors and contributors.
+ *
+ * ndn-group-encrypt is free software: you can redistribute it and/or modify it under the terms
+ * of the GNU General Public License as published by the Free Software Foundation,
+ * either version 3 of the License, or (at your option) any later version.
+ *
+ * ndn-group-encrypt is distributed in the hope that it will be useful, but WITHOUT ANY WARRANTY;
+ * without even the implied warranty of MERCHANTABILITY or FITNESS FOR A PARTICULAR
+ * PURPOSE.  See the GNU General Public License for more details.
+ *
+ * You should have received a copy of the GNU General Public License along with
+ * ndn-group-encrypt, e.g., in COPYING.md file.  If not, see <http://www.gnu.org/licenses/>.
+ */
+
+#include "algo/aes.hpp"
+
+#include "boost-test.hpp"
+#include <algorithm>
+
+namespace ndn {
+namespace gep {
+namespace algo {
+namespace tests {
+
+const uint8_t key[] = {
+  0xdd, 0x60, 0x77, 0xec, 0xa9, 0x6b, 0x23, 0x1b,
+  0x40, 0x6b, 0x5a, 0xf8, 0x7d, 0x3d, 0x55, 0x32
+};
+
+const uint8_t plaintext[] = { // plaintext: AES-Encrypt-Test
+  0x41, 0x45, 0x53, 0x2d, 0x45, 0x6e, 0x63, 0x72,
+  0x79, 0x70, 0x74, 0x2d, 0x54, 0x65, 0x73, 0x74
+};
+
+const uint8_t ciphertext_ecb[] = {
+  0xcb, 0xe5, 0x6a, 0x80, 0x41, 0x24, 0x58, 0x23,
+  0x84, 0x14, 0x15, 0x61, 0x80, 0xb9, 0x5e, 0xbd,
+  0xce, 0x32, 0xb4, 0xbe, 0xbc, 0x91, 0x31, 0xd6,
+  0x19, 0x00, 0x80, 0x8b, 0xfa, 0x00, 0x05, 0x9c
+};
+
+const uint8_t initvector[] = {
+  0x6f, 0x53, 0x7a, 0x65, 0x58, 0x6c, 0x65, 0x75,
+  0x44, 0x4c, 0x77, 0x35, 0x58, 0x63, 0x78, 0x6e
+};
+
+const uint8_t ciphertext_cbc_iv[] = {
+  0xb7, 0x19, 0x5a, 0xbb, 0x23, 0xbf, 0x92, 0xb0,
+  0x95, 0xae, 0x74, 0xe9, 0xad, 0x72, 0x7c, 0x28,
+  0x6e, 0xc6, 0x73, 0xb5, 0x0b, 0x1a, 0x9e, 0xb9,
+  0x4d, 0xc5, 0xbd, 0x8b, 0x47, 0x1f, 0x43, 0x00
+};
+
+BOOST_AUTO_TEST_SUITE(TestAesAlgorithm)
+
+BOOST_AUTO_TEST_CASE(EncryptionDecryption)
+{
+  RandomNumberGenerator rng;
+  AesKeyParams params;
+
+  EncryptParams eparams(ENCRYPT_MODE_ECB_AES, PADDING_SCHEME_PKCS7, 16);
+
+  DecryptKey<Aes> decryptKey(std::move(Buffer(key, sizeof(key))));
+  EncryptKey<Aes> encryptKey = Aes::deriveEncryptKey(decryptKey.getKeyBits());
+
+  Buffer plainBuf(plaintext, sizeof(plaintext));
+
+  Buffer cipherBuf = Aes::encrypt(encryptKey.getKeyBits(), plainBuf, eparams);
+  BOOST_CHECK_EQUAL_COLLECTIONS(cipherBuf.begin(),
+                                cipherBuf.end(),
+                                ciphertext_ecb,
+                                ciphertext_ecb + sizeof(ciphertext_ecb));
+
+  Buffer recvBuf = Aes::decrypt(decryptKey.getKeyBits(), cipherBuf, eparams);
+  BOOST_CHECK_EQUAL_COLLECTIONS(recvBuf.begin(),
+                                recvBuf.end(),
+                                plaintext,
+                                plaintext + sizeof(plaintext));
+
+  eparams.setEncryptMode(ENCRYPT_MODE_CBC_AES);
+
+  cipherBuf = Aes::encrypt(encryptKey.getKeyBits(), plainBuf, eparams);
+  recvBuf = Aes::decrypt(decryptKey.getKeyBits(), cipherBuf, eparams);
+  BOOST_CHECK_EQUAL_COLLECTIONS(recvBuf.begin(),
+                                recvBuf.end(),
+                                plaintext,
+                                plaintext + sizeof(plaintext));
+
+  Buffer iv(initvector, 16);
+  eparams.setIV(iv);
+
+  cipherBuf = Aes::encrypt(encryptKey.getKeyBits(), plainBuf, eparams);
+  BOOST_CHECK_EQUAL_COLLECTIONS(cipherBuf.begin(),
+                                cipherBuf.end(),
+                                ciphertext_cbc_iv,
+                                ciphertext_cbc_iv + sizeof(ciphertext_cbc_iv));
+
+  recvBuf = Aes::decrypt(decryptKey.getKeyBits(), cipherBuf, eparams);
+  BOOST_CHECK_EQUAL_COLLECTIONS(recvBuf.begin(),
+                                recvBuf.end(),
+                                plaintext,
+                                plaintext + sizeof(plaintext));
+}
+
+BOOST_AUTO_TEST_SUITE_END()
+
+} // namespace tests
+} // namespace algo
+} // namespace gep
+} // namespace ndn
diff --git a/tests/unit-tests/rsa.t.cpp b/tests/unit-tests/rsa.t.cpp
new file mode 100644
index 0000000..502a352
--- /dev/null
+++ b/tests/unit-tests/rsa.t.cpp
@@ -0,0 +1,127 @@
+/* -*- Mode:C++; c-file-style:"gnu"; indent-tabs-mode:nil; -*- */
+/**
+ * Copyright (c) 2014-2015,  Regents of the University of California
+ *
+ * This file is part of ndn-group-encrypt (Group-based Encryption Protocol for NDN).
+ * See AUTHORS.md for complete list of ndn-group-encrypt authors and contributors.
+ *
+ * ndn-group-encrypt is free software: you can redistribute it and/or modify it under the terms
+ * of the GNU General Public License as published by the Free Software Foundation,
+ * either version 3 of the License, or (at your option) any later version.
+ *
+ * ndn-group-encrypt is distributed in the hope that it will be useful, but WITHOUT ANY WARRANTY;
+ * without even the implied warranty of MERCHANTABILITY or FITNESS FOR A PARTICULAR
+ * PURPOSE.  See the GNU General Public License for more details.
+ *
+ * You should have received a copy of the GNU General Public License along with
+ * ndn-group-encrypt, e.g., in COPYING.md file.  If not, see <http://www.gnu.org/licenses/>.
+ */
+
+#include <ndn-cxx/encoding/buffer-stream.hpp>
+#include "algo/encrypt-params.hpp"
+#include "algo/rsa.hpp"
+
+#include "boost-test.hpp"
+#include <algorithm>
+#include <string>
+
+using namespace CryptoPP;
+
+namespace ndn {
+namespace gep {
+namespace algo {
+namespace tests {
+
+const std::string privateKey = {
+  "MIICdwIBADANBgkqhkiG9w0BAQEFAASCAmEwggJdAgEAAoGBAMLY2w1PmsuZNvZ4"
+  "rJs1pESLrxF1Xlk9Zg4Sc0r2HIEn/eme8f7cOxXq8OtxIjowEfjceHGvfc7YG1Nw"
+  "LDh+ka4Jh6QtYqPEL9GHfrBeufynd0g2PAPVXySBvOJr/Isk+4/Fsj5ihrIPgrQ5"
+  "wTBBuLYjDgwPppC/+vddsr5wu5bbAgMBAAECgYBYmRLB8riIa5q6aBTUXofbQ0jP"
+  "v3avTWPicjFKnK5JbE3gtQ2Evc+AH9x8smzF2KXTayy5RPsH2uxR/GefKK5EkWbB"
+  "mLwWDJ5/QPlLK1STxPs8B/89mp8sZkZ1AxnSHhV/a3dRcK1rVamVcqPMdFyM5PfX"
+  "/apL3MlL6bsq2FipAQJBAOp7EJuEs/qAjh8hgyV2acLdsokUEwXH4gCK6+KQW8XS"
+  "xFWAG4IbbLfq1HwEpHC2hJSzifCQGoPAxYBRgSK+h6sCQQDUuqF04o06+Qpe4A/W"
+  "pWCBGE33+CD4lBtaeoIagsAs/lgcFmXiJZ4+4PhyIORmwFgql9ZDFHSpl8rAYsfk"
+  "dz2RAkEAtUKpFe/BybYzJ3Galg0xuMf0ye7QvblExjKeIqiBqS1DRO0hVrSomIxZ"
+  "8f0MuWz+lI0t5t8fABa3FnjrINa0vQJBAJeZKNaTXPJZ5/oU0zS0RkG5gFbmjRiY"
+  "86VXCMC7zRhDaacajyDKjithR6yNpDdVe39fFWJYgYsakXLo8mruTwECQGqywoy9"
+  "epf1flKx4YCCrw+qRKmbkcXWcpFV32EG2K2D1GsxkuXv/b3qO67Uxx1Arxp9o8dl"
+  "k34WfzApRjNjho0="
+};
+
+const std::string publicKey = {
+  "MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQDC2NsNT5rLmTb2eKybNaREi68R"
+  "dV5ZPWYOEnNK9hyBJ/3pnvH+3DsV6vDrcSI6MBH43Hhxr33O2BtTcCw4fpGuCYek"
+  "LWKjxC/Rh36wXrn8p3dINjwD1V8kgbzia/yLJPuPxbI+YoayD4K0OcEwQbi2Iw4M"
+  "D6aQv/r3XbK+cLuW2wIDAQAB"
+};
+
+const uint8_t plaintext[] = { // plaintext: RSA-Encrypt-Test
+  0x52, 0x53, 0x41, 0x2d, 0x45, 0x6e, 0x63, 0x72,
+  0x79, 0x70, 0x74, 0x2d, 0x54, 0x65, 0x73, 0x74
+};
+
+const uint8_t ciphertext[] = {
+  0x33, 0xfb, 0x32, 0xd4, 0x2d, 0x45, 0x75, 0x3f, 0x34, 0xde, 0x3b,
+  0xaa, 0x80, 0x5f, 0x74, 0x6f, 0xf0, 0x3f, 0x01, 0x31, 0xdd, 0x2b,
+  0x85, 0x02, 0x1b, 0xed, 0x2d, 0x16, 0x1b, 0x96, 0xe5, 0x77, 0xde,
+  0xcd, 0x44, 0xe5, 0x3c, 0x32, 0xb6, 0x9a, 0xa9, 0x5d, 0xaa, 0x4b,
+  0x94, 0xe2, 0xac, 0x4a, 0x4e, 0xf5, 0x35, 0x21, 0xd0, 0x03, 0x4a,
+  0xa7, 0x53, 0xae, 0x13, 0x08, 0x63, 0x38, 0x2c, 0x92, 0xe3, 0x44,
+  0x64, 0xbf, 0x33, 0x84, 0x8e, 0x51, 0x9d, 0xb9, 0x85, 0x83, 0xf6,
+  0x8e, 0x09, 0xc1, 0x72, 0xb9, 0x90, 0x5d, 0x48, 0x63, 0xec, 0xd0,
+  0xcc, 0xfa, 0xab, 0x44, 0x2b, 0xaa, 0xa6, 0xb6, 0xca, 0xec, 0x2b,
+  0x5f, 0xbe, 0x77, 0xa5, 0x52, 0xeb, 0x0a, 0xaa, 0xf2, 0x2a, 0x19,
+  0x62, 0x80, 0x14, 0x87, 0x42, 0x35, 0xd0, 0xb6, 0xa3, 0x47, 0x4e,
+  0xb6, 0x1a, 0x88, 0xa3, 0x16, 0xb2, 0x19
+};
+
+BOOST_AUTO_TEST_SUITE(TestRsaAlgorithm)
+
+BOOST_AUTO_TEST_CASE(EncryptionDecryption)
+{
+  RandomNumberGenerator rng;
+  RsaKeyParams params;
+  EncryptParams eparams(ENCRYPT_MODE_RSA, PADDING_SCHEME_OAEP_SHA, 0);
+
+  OBufferStream privateKeyBuffer, publicKeyBuffer;
+  StringSource privPipe(privateKey, true,
+                        new Base64Decoder(new FileSink(privateKeyBuffer)));
+  StringSource publPipe(publicKey, true,
+                        new Base64Decoder(new FileSink(publicKeyBuffer)));
+
+  DecryptKey<Rsa> decryptKey(std::move(*(privateKeyBuffer.buf())));
+  EncryptKey<Rsa> encryptKey = Rsa::deriveEncryptKey(decryptKey.getKeyBits());
+
+  Buffer encodedPublic = *(publicKeyBuffer.buf());
+  Buffer derivedPublicKey = encryptKey.getKeyBits();
+
+  BOOST_CHECK_EQUAL_COLLECTIONS(encodedPublic.begin(),
+                                encodedPublic.end(),
+                                derivedPublicKey.begin(),
+                                derivedPublicKey.end());
+
+  Buffer plainBuf(plaintext, sizeof(plaintext));
+  Buffer encryptBuf = Rsa::encrypt(encryptKey.getKeyBits(), plainBuf, eparams);
+  Buffer recvBuf = Rsa::decrypt(decryptKey.getKeyBits(), encryptBuf, eparams);
+
+  BOOST_CHECK_EQUAL_COLLECTIONS(plaintext,
+                                plaintext + sizeof(plaintext),
+                                recvBuf.begin(),
+                                recvBuf.end());
+
+  Buffer cipherBuf(ciphertext, sizeof(ciphertext));
+  Buffer convBuf = Rsa::decrypt(decryptKey.getKeyBits(), cipherBuf, eparams);
+
+  BOOST_CHECK_EQUAL_COLLECTIONS(plaintext,
+                                plaintext + sizeof(plaintext),
+                                convBuf.begin(),
+                                convBuf.end());
+}
+
+BOOST_AUTO_TEST_SUITE_END()
+
+} // namespace tests
+} // namespace algo
+} // namespace gep
+} // namespace ndn