【发布时间】:2015-05-19 18:22:45
【问题描述】:
我在网上搜索过,但没有找到任何解决我的问题的方法。
我正在使用以前编写的方法使用 Rijndael 类对文本进行加密和加密。
我使用这些函数来加密和解密我一直在开发的 Web 应用程序的用户名和电子邮件。
加密/解密工作完美,但每隔一段时间我就会收到此错误:
System.Security.Cryptography.CryptographicException: Length of the data to decrypt is invalid.
目前,我使用特定的电子邮件地址收到此错误,即使我替换了电子邮件中的某些字母,我也无法重现该错误。
这里是加密/解密函数。 IV 和 Key 被定义为只读字符串。
static public string Encrypting(string Source)
{
byte[] bytIn = System.Text.ASCIIEncoding.ASCII.GetBytes(Source);
// create a MemoryStream so that the process can be done without I/O files
System.IO.MemoryStream ms = new System.IO.MemoryStream();
byte[] IVBytes = Encoding.ASCII.GetBytes(IV);
byte[] KEYBytes = Encoding.ASCII.GetBytes(KEY);
Rijndael rijndael = Rijndael.Create();
rijndael.IV = IVBytes;
rijndael.Key = KEYBytes;
// create Crypto Stream that transforms a stream using the encryption
CryptoStream cs = new CryptoStream(ms, rijndael.CreateEncryptor(), CryptoStreamMode.Write);
// write out encrypted content into MemoryStream
cs.Write(bytIn, 0, bytIn.Length);
cs.FlushFinalBlock();
// get the output and trim the '\0' bytes
byte[] bytOut = ms.GetBuffer();
int i = 0;
for (i = 0; i < bytOut.Length; i++)
if (bytOut[i] == 0)
break;
// convert into Base64 so that the result can be used in xml
return System.Convert.ToBase64String(bytOut, 0, i);
}
static public string Decrypting(string Source)
{
// convert from Base64 to binary
byte[] bytIn = System.Convert.FromBase64String(Source);
// create a MemoryStream with the input
System.IO.MemoryStream ms = new System.IO.MemoryStream(bytIn, 0, bytIn.Length);
byte[] IVBytes = Encoding.ASCII.GetBytes(IV);
byte[] KEYBytes = Encoding.ASCII.GetBytes(KEY);
Rijndael rijndael = Rijndael.Create();
rijndael.IV = IVBytes;
rijndael.Key = KEYBytes;
// create Crypto Stream that transforms a stream using the decryption
CryptoStream cs = new CryptoStream(ms, rijndael.CreateDecryptor(), CryptoStreamMode.Read);
// read out the result from the Crypto Stream
System.IO.StreamReader sr = new System.IO.StreamReader(cs);
return sr.ReadToEnd();
}
仅供参考 - 我对密码学和安全性非常陌生。
是否可以修复这些函数以避免导致错误的特殊情况,或者我应该废弃这些函数并使用RijndaelManaged 类?
我发现使用 RijndaelManaged 的网站: SeeSharp
【问题讨论】:
-
pastebin.com/BNHLU1Tc 试试这个并说是否会发生同样的错误。我看到的问题与要解密的数据的无效填充有关。或者解密数据填充的设置无效,因此该方法无法计算正确的无填充的纯加密字节大小。
-
您是否已验证您尝试解密的值是否使用相同的文本编码进行了加密?
-
@Kosmos - 谢谢,我会解决这个问题的。
-
@CamBruce - 是的,我确定。所有代码都在上面,并确保我有一个可以加密和解密文本的文本应用程序。问题在于算法以及某些字符串如何导致它抛出该错误。
标签: c# exception encryption cryptography