我创建了一个Encryption
类来加密/解密我的Android项目中的二进制数据,通过这个链接。
package com.my.package;
import java.security.SecureRandom;
import javax.crypto.Cipher;
import javax.crypto.KeyGenerator;
import javax.crypto.SecretKey;
import javax.crypto.spec.SecretKeySpec;
// TODO Incomplete class
public class Encryption {
private static final byte[] salt = { (byte) 0xA4, (byte) 0x0B, (byte) 0xC8,
(byte) 0x34, (byte) 0xD6, (byte) 0x95, (byte) 0xF3, (byte) 0x13 };
private static int BLOCKS = 128;
private static byte[] encrypt(byte[] raw, byte[] clear) throws Exception {
SecretKeySpec skeySpec = new SecretKeySpec(raw, "AES");
Cipher cipher = Cipher.getInstance("AES");
cipher.init(Cipher.ENCRYPT_MODE, skeySpec);
byte[] encrypted = cipher.doFinal(clear);
return encrypted;
}
private static byte[] decrypt(byte[] raw, byte[] encrypted)
throws Exception {
SecretKeySpec skeySpec = new SecretKeySpec(raw, "AES");
Cipher cipher = Cipher.getInstance("AES");
cipher.init(Cipher.DECRYPT_MODE, skeySpec);
byte[] decrypted = cipher.doFinal(encrypted);
return decrypted;
}
private static byte[] getKey() throws Exception {
byte[] keyStart = "this is a key".getBytes();
KeyGenerator kgen = KeyGenerator.getInstance("AES");
SecureRandom sr = SecureRandom.getInstance("SHA1PRNG");
sr.setSeed(keyStart);
kgen.init(128, sr); // 192 and 256 bits may not be available
SecretKey skey = kgen.generateKey();
byte[] key = skey.getEncoded();
return key;
}
public static void test() {
String test = "My Name Is Dragon Warrior";
byte[] e = null;
try {
e = encrypt(getKey(), test.getBytes());
} catch (Exception e1) {
// TODO Auto-generated catch block
e1.printStackTrace();
}
byte[] d = null;
try {
d = decrypt(getKey(), e);
} catch (Exception e1) {
// TODO Auto-generated catch block
e1.printStackTrace();
}
System.out.println(new String(d));
}
}
然后在主活动中运行代码:
public void onCreate(Bundle savedInstanceState) {
super.onCreate(savedInstanceState);
// ...
Encryption.test();
// ...
}
当以下代码在test()
中执行时,我得到一个BadPaddingException
:
try {
d = decrypt(getKey(), e);
} catch (Exception e1) {
// TODO Auto-generated catch block
e1.printStackTrace();
}
有趣的是,我创建了一个Java项目而不是Android项目。代码运行正常,没有任何异常。
我的代码有什么问题?
"SHA1PRNG" 不是密钥派生函数,不同的提供者的实现可能不同。请使用正确的KDF(例如PBKDF2)作为密码。"This is a key" 不是键,它是一个字符串。