【问题标题】:Validating in objective c Password encrypted in Java using PBKDF2WithHmacSHA1 algorithm在目标 c 中验证使用 PBKDF2WithHmacSHA1 算法在 Java 中加密的密码
【发布时间】:2014-10-06 10:56:09
【问题描述】:

用户路径: 一个在我的安卓应用中注册,然后决定通过iphone应用登录。

服务器向我发送加密密码,我需要与刚刚在密码字段中输入的用户进行比较。

这是加密字符串的Java方法:

public static String encrypt(String password)  {
        int iterations = 1000;
        char[] chars = password.toCharArray();
        byte[] salt = getSalt().getBytes();

        PBEKeySpec spec = new PBEKeySpec(chars, salt, iterations, 256);
        SecretKeyFactory skf = SecretKeyFactory.getInstance("PBKDF2WithHmacSHA1");
        byte[] hash = skf.generateSecret(spec).getEncoded();
        return toHex(hash);
}

到目前为止我所拥有的:

- (BOOL)isPasswordValid 
{   
  NSString * saltString = @"5b42406231323062343030";
  NSString * storedPasswordString = @"90bd42e6f15ccd2d3ec3386d031758898bb7bc08f476a3d7afe6fe1cfbc372e6";

  NSData * hashData = [storedPasswordString dataFromHexString]; 

  unsigned char out[256];

  //converting saltstring into char array
  //
  NSMutableArray * saltArray = [NSMutableArray array];
  for (NSInteger idx = 0; idx < saltString.length; idx++) {
   [saltArray addObject:[NSString stringWithFormat:@"%C", [saltString characterAtIndex:idx]]];
  }

  unsigned char * buffer = (unsigned char *)calloc([saltArray count],
                                              sizeof(unsigned char));

  for (int i = 0; i < [saltArray count]; i++)
    buffer[i] = (char)[saltArray objectAtIndex:i];

  PKCS5_PBKDF2_HMAC_SHA1("password", strlen("password"), buffer, sizeof(buffer), ITERATION, 256, out);

  NSMutableString * hashTestString = [NSMutableString new];
  for (NSInteger idx = 0; idx < sizeof(out); idx++) {
    [hashTestString appendString:[NSString stringWithFormat:@"%02x", out[idx]]];
  }

  NSData * hashDataTest = [hashTestString dataFromHexString];

  const char *hashBytes = [hashData bytes];
  const char *hashBytesTest = [hashDataTest bytes];

  int diff = hashData.length ^ hashDataTest.length;
  for (int i = 0; i < hashData.length && i < hashDataTest.length; i++) {
    diff |= hashBytes[i] ^ hashBytesTest[i];
  }

  free(buffer);
  return diff == 0;
}

Method PKCS5_PBKDF2_HMAC_SHA1 不幸的是,它总是为测试用例返回 -1。

想法:

接收到的十六进制字符串中的盐,这可能是问题所在。所以我尝试将十六进制@"5b42406231323062343030"转换为字符串@"[B@b120b400",然后将其转换为char数组,但仍然没有结果。

更新: 如果我使用 unsigned char salt[] = {'[','B','@','b','1','2','0','b','4','0','0'};' instead ofbuffer` 变量,它工作正常。所以,我的十六进制字符串转换为 char 数组很糟糕。

【问题讨论】:

  • 密码验证应该都是服务器端的。比较存储密码和输入密码的加密值。
  • 不管怎样,我需要正确加密它。

标签: java android objective-c c encryption


【解决方案1】:

您使用calloc 为buffer 保留空间:

unsigned char * buffer = (unsigned char *)calloc([saltArray count],

这里:

PKCS5_PBKDF2_HMAC_SHA1("password", strlen("password"), buffer, sizeof(buffer), ..

sizeof(buffer) 返回sizeof(unsigned char *),使用strlen((char *)buffer)

【讨论】:

  • *警告:passing 'unsigned char *' to parameter of type 'const char * converts between pointers to integer types with different types'
  • 是的,有一个转换警告,使用强制转换:strlen((char *) buffer)
  • 对不起,我无法在我的机器上编译你的代码来检查这个:(
  • 如果我使用 unsigned char salt[] = {'[','B','@','b','1','2','0','b','4','0','0'}; 而不是缓冲区变量,它可以正常工作。所以,我的十六进制字符串转换为 char 数组很糟糕。
【解决方案2】:

反复测试,我的解决方案奏效了。正如我上面评论的, 如果我使用 unsigned char salt[] = {'[','B','@','b','1','2','0','b','4','0','0'}; 而不是 buffer 变量它工作正常。所以,我注意到我的十六进制字符串转换为 char 数组很糟糕。

NSString 实例具有 - (const char *)UTF8String 方法,该方法返回一个以 null 结尾的 UTF8 表示。

另外,我将我从服务器接收到的 hex-salt 转换为 NSString,最后得到以下 sn-p:

- (BOOL)isPasswordValid 
{
    NSString * saltString = @"[B@b120b400";
    NSString * storedPasswordString = @"90bd42e6f15ccd2d3ec3386d031758898bb7bc08f476a3d7afe6fe1cfbc372e6";

    NSData * hashData = [storedPasswordString dataFromHexString];

    unsigned char out[[hashData length]];

    PKCS5_PBKDF2_HMAC_SHA1("password", strlen("password"), 
                          (const unsigned char *)[saltString UTF8String], 
                          strlen([saltString UTF8String]), 1000, 
                                  [hashData length], out);

    NSMutableString * hashTestString = [NSMutableString new];
    for (NSInteger idx = 0; idx < sizeof(out); idx++) {
      [hashTestString appendString:[NSString stringWithFormat:@"%02x", out[idx]]];
    }

    NSData * hashDataTest = [hashTestString dataFromHexString];

    const char * hashBytes = [hashData bytes];
    const char * hashBytesTest = [hashDataTest bytes];

    int diff = hashData.length ^ hashDataTest.length;
    for (int i = 0; i < hashData.length && i < hashDataTest.length; i++) {
        diff |= hashBytes[i] ^ hashBytesTest[i];
    }

    return diff == 0;
}

【讨论】:

    猜你喜欢
    • 2015-01-14
    • 1970-01-01
    • 2016-06-22
    • 2011-08-29
    • 1970-01-01
    • 2015-12-07
    • 2016-03-31
    • 2013-11-20
    • 2021-08-10
    相关资源
    最近更新 更多