from cryptography.fernet import Fernet key = Fernet.generate_key() fernet = Fernet(key) plaintext = "secret".encode() token = fernet.encrypt(plaintext) print(token) decrypted_text = fernet.decrypt(token) print(decrypted_text)
Fernet.generate_key() method can generate a symmetric key securely. One should keep the generated key secret and store it in a safe place.
Using the Fernet(key) method, we can initialize a Fernet. After that, we can use Fernet.encrypt() method to encrypt plaintext. Please note that Fernet.encrypt() method takes bytes as input. So, we are encoding the plaintext to generate bytes. Fernet.encrypt() method generates a token that has the format as mentioned earlier.
We can use Fernet.decrypt() method to decrypt a token. After decryption, the decrypted text will be the same as the plaintext.
How to encrypt and decrypt data using MultiFernet in Python?
Let’s say an employee has access to a secret key using which some tokens were generated. Now, the employee leaves the company. So, the company needs to discard the earlier key and re-encrypt all the data. Using MultiFernet, one can do so very easily. MultiFernet takes a list of Fernets as input and uses the first Fernet in the list to encrypt data. At the time of decryption, MultiFernet tries all the Fernets in the list to decrypt the data. And, we can rotate a token in a MultiFernet so that the token is decrypted and encrypted again with a different Fernet from the list.
Let’s look at an example.
from cryptography.fernet import Fernet, MultiFernet key1 = Fernet.generate_key() key2 = Fernet.generate_key() fernet1 = Fernet(key1) fernet2 = Fernet(key2) plaintext = "Secret".encode() multi_fernet = MultiFernet([fernet1, fernet2]) token = multi_fernet.encrypt(plaintext) print(token) decrypted_text1 = multi_fernet.decrypt(token) print(decrypted_text1) key3 = Fernet.generate_key() fernet3 = Fernet(key3) multi_fernet2 = MultiFernet([fernet3, fernet1, fernet2]) rotated_token = multi_fernet2.rotate(token) print(rotated_token) decrypted_text2 = multi_fernet2.decrypt(rotated_token) print(decrypted_text2) multi_fernet3 = MultiFernet([fernet3, fernet2]) decrypted_text3 = multi_fernet3.decrypt(rotated_token) print(decrypted_text3)
Firstly, we have generated two secret keys securely using Fernet.generate_key() method. After that, we have initialized two Fernets fernet1 and fernet2 using the generated keys.
Then, we have initialized a MultiFernet that has taken a list of Fernets as input.
Now, if we encrypt a text using the MultiFernet, it will encrypt the text using fernet1. At the time of decryption, the MultiFernet will try both the Fernets for decryption.
Now, let’s say we want to discard fernet1. So, we initialized another Fernet fernet3 and created another MultiFernet with fernet3 at the front of the list of the Fernets. So, if we encrypt any data now, the MultiFernet will use fernet3 for encryption.
But, earlier we used fernet1 for generating tokens. So, we have used MultiFernet.rotate(token) method to decrypt the earlier generated token using fernet1 and then encrypt it using fernet3. Now, we can discard fernet1 safely.
So, we have created another MultiFernet with fernet3 and fernet2 and decrypted the rotated token using the new MultiFernet.
I hope this helps. However, readers who want to know more about how different cryptographic algorithms work and how they are used in various secure network protocols can refer to the book “Cryptography And Public Key Infrastructure.”










































0 Comments