Converting Python RSA Decryption Script to C#, Output is only last 16B instead of 128B

I come to you today, hat in hand, after pounding my head against the brick wall that is encryption.

Here's the premise: I have a python script that generates a ASN.1 encoded DER key. I then have another python script that takes that DER private key and uses it to decrypt a base64 encoded string. I'm currently attempting to convert that second script into its C# alternative, and I've got it working--to a point.

When using the original python scripts, the decrypted output is 127 bytes long, while the C# code I have is 16 bytes long. At this point I thought the C# code I had was completely wrong, until I noticed that the last 16 bytes of both the python output and the C# output are the exact same. WAT?

Here's the code I have for prosterity (obv no error checking, etc.)

Input DER Private Key (Base64 encoded for web)


Input Encypted String (Base64 encoded)


Python RSA Script using (PyCrypt) to decode Encrypted String

//removed python code to convert base64 encoded DER key to ASN.1 and then to RSA key tuple for pycrypto, the following is the hex data within the tuple:
key = ['0x0:0xcc:0x25:0x7:0x33:0x71:0xaa:0x6:0x7a:0x96:0x48:0x3d:0xc4:0xc6:0x24:0x1e:0x40:0x7d:0x20:0x45:0xaa:0x10:0xad:0xe4:0x1f:0x87:0x46:0x96:0x94:0xa2:0xc6:0x73:0x2:0x1a:0x28:0x96:0x3c:0x4a:0xae:0x54:0x5d:0xde:0x82:0xf0:0xc3:0x6a:0x6a:0xca:0x3c:0x86:0x97:0xd6:0xea:0xac:0xa8:0x5a:0x46:0xe0:0x8f:0x68:0x48:0x3f:0x44:0x76:0x2f:0xa9:0x3d:0xe0:0x12:0x3b:0x56:0xf5:0x7a:0xc5:0xdd:0xa6:0xec:0x30:0xfd:0xa2:0x86:0x9f:0x92:0x80:0xe4:0xe7:0x45:0xa4:0xb:0x94:0xae:0xd6:0xca:0x1d:0x90:0x53:0x85:0xca:0x4d:0xdd:0xf:0xca:0x3b:0xfe:0x9d:0x84:0xcc:0xdd:0x1d:0x4b:0x46:0xf7:0x8d:0xd9:0x81:0x20:0xf9:0xd5:0x94:0x78:0x6a:0x86:0x26:0xe3:0x6c:0xf4:0xd0:0x2b:0xab',

// from
// from Crypto.PublicKey import RSA

rsa = RSA.construct(key)
plain_text = RSA.decrypt(cipher_text.decode('base64'))

Python Script Output


C# RSA Decryption Script

static void Main(string[] args)
    var derContent = Convert.FromBase64String(base64DerContent); //base64DerContent is the "Input DER Private Key" above
    var rsa = DecodeRSAPrivateKey(derContent);
    Byte[] cipher_text_data = Convert.FromBase64String("e1algxNK5vfiLQmN42bQf9CHJnRGH06w13P+ObHx5U7XJWbCsh9HKclXX88b2peEG4U3K4WC+dSNGLEPe8d3bPwxlBOYXVgsAHKLrgD7gXJDOG+gMawUsUlVx+hWPESITHXDscbcM6zASUuIWGtPkJw3r00MwJy9ZzYqfr2OiJg=");

    Byte[] raw = rsa.Decrypt(cipher_text_data, false);
        string hex = BitConverter.ToString(raw);
        System.Console.WriteLine("Decrypted: " + hex);
//the following code taken from
//------- Parses binary ans.1 RSA private key; returns RSACryptoServiceProvider  ---
    public static RSACryptoServiceProvider DecodeRSAPrivateKey(byte[] privkey)
        byte[] MODULUS, E, D, P, Q, DP, DQ, IQ;

        // ---------  Set up stream to decode the asn.1 encoded RSA private key  ------
        MemoryStream mem = new MemoryStream(privkey);
        BinaryReader binr = new BinaryReader(mem);    //wrap Memory Stream with BinaryReader for easy reading
        byte bt = 0;
        ushort twobytes = 0;
        int elems = 0;
            twobytes = binr.ReadUInt16();
            if (twobytes == 0x8130) //data read as little endian order (actual data order for Sequence is 30 81)
                binr.ReadByte();        //advance 1 byte
            else if (twobytes == 0x8230)
                binr.ReadInt16();       //advance 2 bytes
                return null;

            twobytes = binr.ReadUInt16();
            if (twobytes != 0x0102) //version number
                return null;
            bt = binr.ReadByte();
            if (bt != 0x00)
                return null;

            //------  all private key components are Integer sequences ----
            elems = GetIntegerSize(binr);
            MODULUS = binr.ReadBytes(elems);

            elems = GetIntegerSize(binr);
            E = binr.ReadBytes(elems);

            elems = GetIntegerSize(binr);
            D = binr.ReadBytes(elems);

            elems = GetIntegerSize(binr);
            P = binr.ReadBytes(elems);

            elems = GetIntegerSize(binr);
            Q = binr.ReadBytes(elems);

            elems = GetIntegerSize(binr);
            DP = binr.ReadBytes(elems);

            elems = GetIntegerSize(binr);
            DQ = binr.ReadBytes(elems);

            elems = GetIntegerSize(binr);
            IQ = binr.ReadBytes(elems);

            System.Console.WriteLine("showing components ..");
            if (true)
                System.Console.WriteLine("\nModulus", MODULUS);
                System.Console.WriteLine("\nExponent", E);
                System.Console.WriteLine("\nD", D);
                System.Console.WriteLine("\nP", P);
                System.Console.WriteLine("\nQ", Q);
                System.Console.WriteLine("\nDP", DP);
                System.Console.WriteLine("\nDQ", DQ);
                System.Console.WriteLine("\nIQ", IQ);

            // ------- create RSACryptoServiceProvider instance and initialize with public key -----
            RSACryptoServiceProvider RSA = new RSACryptoServiceProvider();
            RSAParameters RSAparams = new RSAParameters();
            RSAparams.Modulus = MODULUS;
            RSAparams.Exponent = E;
            RSAparams.D = D;
            RSAparams.P = P;
            RSAparams.Q = Q;
            RSAparams.DP = DP;
            RSAparams.DQ = DQ;
            RSAparams.InverseQ = IQ;
            return RSA;
        catch (Exception)
            return null;
    private static int GetIntegerSize(BinaryReader binr)
        byte bt = 0;
        byte lowbyte = 0x00;
        byte highbyte = 0x00;
        int count = 0;
        bt = binr.ReadByte();
        if (bt != 0x02)     //expect integer
            return 0;
        bt = binr.ReadByte();

        if (bt == 0x81)
            count = binr.ReadByte();    // data size in next byte
            if (bt == 0x82)
                highbyte = binr.ReadByte(); // data size in next 2 bytes
                lowbyte = binr.ReadByte();
                byte[] modint = { lowbyte, highbyte, 0x00, 0x00 };
                count = BitConverter.ToInt32(modint, 0);
                count = bt;     // we already have the data size

        while (binr.ReadByte() == 0x00)
        {   //remove high order zeros in data
            count -= 1;
        binr.BaseStream.Seek(-1, SeekOrigin.Current);       //last ReadByte wasn't a removed zero, so back up a byte
        return count;

C# Script Output


As you can see the output of the C# code is only 16 bytes long, however it directly matches the last 16 bytes of the python script. I'm not sure exactly what is going on, and my (basic) understanding of RSA tells me it should be an all or nothing function--the whole text gets decrypted, or I get gibberish.


  • The issue here is padding. RSA operations require that the message be padded with a secure padding scheme before encryption. Otherwise, certain attacks exist that could recover the private key. Here's a good article explaining why.

    For some reason, the Python crypto library is not removing the padding for you, but the C# library is. So you'll have to remove the padding manually in the Python code.

    Lucky for you, from the data you give, it looks like the padding scheme being used here is PKCS#1.5. That's a relatively simple padding scheme that will be easy to handle. The full specs are in RFC 3447, but it boils down to this:

    EM = 0x00 || 0x02 || PS || 0x00 || M.

    where EM is the padded message before encryption, PS is the padding, and M is the original, unpadded message.

    Here's a Python function that should do the job for you:

    def RemovePKCS15Padding( padded_msg ):
        if len(padded_msg) < 2 or padded_msg[0]!='\x02':
            raise PaddingError # or whatever
        p = padded_msg.find('\x00')
        if p < 0:
            raise PaddingError # or whatever
        return padded_msg[p+1:]