【问题标题】:How to create a function the encrypts/encrypts JSON data into AES-128-CBC algorithm?如何创建将 JSON 数据加密/加密为 AES-128-CBC 算法的函数?
【发布时间】:2019-10-28 04:59:02
【问题描述】:

你能帮我解决我的问题吗?我在 AES-128-CBC 加密中找不到任何好的示例或教程 AES 表示高级加密标准,我是新手。我有一个 JSON 格式的数据。我需要做的就是为我的表单数据创建一个加密和解密函数。使用 AES-128-CBC 算法。知道怎么做吗?或者可以帮助我解决问题的示例或任何链接?提前致谢。 :) 顺便说一句,我在这个链接中有一个参考,但我不知道我的数据是否在 AES-128-CBC 算法中加密。 http://www.php.net/manual/en/function.mcrypt-encrypt.php这是代码:

<?php
    # --- ENCRYPTION ---

    # the key should be random binary, use scrypt, bcrypt or PBKDF2 to
    # convert a string into a key
    # key is specified using hexadecimal
    $key = pack('H*', "bcb04b7e103a0cd8b54763051cef08bc55abe029fdebae5e1d417e2ffb2a00a3");

    # show key size use either 16, 24 or 32 byte keys for AES-128, 192
    # and 256 respectively
    $key_size =  strlen($key);
    echo "Key size: " . $key_size . "\n";

    $plaintext = "This string was AES-256 / CBC / ZeroBytePadding encrypted.";

    # create a random IV to use with CBC encoding
    $iv_size = mcrypt_get_iv_size(MCRYPT_RIJNDAEL_128, MCRYPT_MODE_CBC);
    $iv = mcrypt_create_iv($iv_size, MCRYPT_RAND);

    # creates a cipher text compatible with AES (Rijndael block size = 128)
    # to keep the text confidential 
    # only suitable for encoded input that never ends with value 00h
    # (because of default zero padding)
    $ciphertext = mcrypt_encrypt(MCRYPT_RIJNDAEL_128, $key,
                                 $plaintext, MCRYPT_MODE_CBC, $iv);

    # prepend the IV for it to be available for decryption
    $ciphertext = $iv . $ciphertext;

    # encode the resulting cipher text so it can be represented by a string
    $ciphertext_base64 = base64_encode($ciphertext);

    echo  $ciphertext_base64 . "\n";

    # === WARNING ===

    # Resulting cipher text has no integrity or authenticity added
    # and is not protected against padding oracle attacks.

    # --- DECRYPTION ---

    $ciphertext_dec = base64_decode($ciphertext_base64);

    # retrieves the IV, iv_size should be created using mcrypt_get_iv_size()
    $iv_dec = substr($ciphertext_dec, 0, $iv_size);

    # retrieves the cipher text (everything except the $iv_size in the front)
    $ciphertext_dec = substr($ciphertext_dec, $iv_size);

    # may remove 00h valued characters from end of plain text
    $plaintext_dec = mcrypt_decrypt(MCRYPT_RIJNDAEL_128, $key,
                                    $ciphertext_dec, MCRYPT_MODE_CBC, $iv_dec);

    echo  $plaintext_dec . "\n";
?>

输出是

Key size: 32
ENJW8mS2KaJoNB5E5CoSAAu0xARgsR1bdzFWpEn+poYw45q+73az5kYi4j+0haevext1dGrcW8Qi59txfCBV8BBj3bzRP3dFCp3CPQSJ8eU=
This string was AES-256 / CBC / ZeroBytePadding encrypted.

但是在 AES-256 CBC 中。如何创建 AES 128 CBC 格式的加密?

【问题讨论】:

  • 查看mcrypt() 的文档。该页面甚至有一个特定的代码示例,用于使用 CBC 模式进行 AES 128 加密。
  • 好的,我会检查的,谢谢
  • github.com/defuse/php-encryption - json_encode() 然后 Crypto::encrypt()。解密时: Crypto::decrypt() 然后 json_decode()。真的很简单。

标签: php algorithm encryption cryptography


【解决方案1】:

你可能是don't want to use CBC mode in practice

相反,well-studied PHP encryption library(最好是doesn't use mcrypt)结合 JSON 函数应该可以完全解决您的问题。

最简单的是defuse/php-encryption:

<?php
use Defuse\Crypto\Crypto;
use Defuse\Crypto\Key;

/**
 * @param array|object $encrypted
 * @param Key $key
 * @return string
 */
function encryptJson($arrayOrObject, Key $key)
{
    $encoded = json_encode($arrayOrObject);
    return Crypto::encrypt($encoded, $key);
}

/**
 * @param string $encrypted
 * @param Key $key
 * @param bool $assoc
 * @return array|object
 */
function decryptJson($encrypted, Key $key, $assoc = false)
{
    $decrypted = Crypto::decrypt($encrypted, $key);
    return json_encode($decrypted, $assoc);
}

【讨论】:

    猜你喜欢
    • 2019-08-17
    • 2020-04-15
    • 2013-08-11
    • 2021-06-25
    • 1970-01-01
    • 1970-01-01
    • 2020-11-29
    • 1970-01-01
    • 1970-01-01
    相关资源
    最近更新 更多