java使用bouncycastle加解密

jdk默认带了一些常见的加解密方式,当我们常见的加解密不能满足时,就需要用到一些第三方的库了,bouncycastle就是其中一种。

但是bouncycastle文档比较少。简单介绍一下写法

1.导入依赖

   <dependency>
            <groupId>org.bouncycastle</groupId>
            <artifactId>bcprov-jdk15on</artifactId>
            <version>1.69</version>
        </dependency>

2.写代码

常见的有两种方式,一种使用BouncyCastleProvider,另一种使用BlockCipherEngine

BouncyCastleProvider使用方式跟原生jdk类似,多数getInstance的地方指定一下provider就行

BouncyCastleProvider方式DES加解密代码如下

package com.vvvtimes.demo.util.endecrypt;

import lombok.extern.slf4j.Slf4j;
import org.bouncycastle.jce.provider.BouncyCastleProvider;

import javax.crypto.Cipher;
import javax.crypto.KeyGenerator;
import javax.crypto.SecretKey;
import javax.crypto.SecretKeyFactory;
import javax.crypto.spec.DESKeySpec;
import javax.crypto.spec.IvParameterSpec;
import java.security.Key;
import java.security.NoSuchAlgorithmException;

@Slf4j
public class BcDesUtil {

    private static final BouncyCastleProvider provider;

    //BouncyCastle与JDK加解密类区别
    //KeyFactory.getInstance("RSA"); +provider-->KeyFactory.getInstance("RSA", provider)
    //Cipher.getInstance("RSA");  +provider-->Cipher.getInstance("RSA", provider)
    //Signature.getInstance("SHA1withRSA"); +provider-->Signature.getInstance("SHA1withRSA", provider);
    //KeyGenerator.getInstance("DES") ; +provider-->KeyGenerator.getInstance("DES", provider); 或者KeyGenerator.getInstance("DES","BC")

    /**
     * 偏移变量,固定占8位字节
     */
    private final static String IV_PARAMETER = "12345678";

    /*
     * 生成key
     */
    public byte[] generateKey() {
        KeyGenerator keyGenerator = null;
        try {
            keyGenerator = KeyGenerator.getInstance("DES",provider);
            keyGenerator.init(56);
            SecretKey secretKey = keyGenerator.generateKey();
            byte[] encoded = secretKey.getEncoded();
            return encoded;
        } catch (NoSuchAlgorithmException e) {
            e.printStackTrace();
        }
        return null;
    }


    /**
     * 生成key
     *
     * @param password 密钥字符串
     * @return 密钥对象
     * @throws Exception
     */
    private static Key convertKey(byte[] password) throws Exception {
        DESKeySpec dks = new DESKeySpec(password);
        SecretKeyFactory keyFactory = SecretKeyFactory.getInstance("DES",provider);
        return keyFactory.generateSecret(dks);
    }

    /**
     * DES加密
     */
    public static byte[] encrypt(byte[] data, byte[] password) {
        if (password == null || password.length < 8) {
            throw new RuntimeException("加密失败,key不能小于8位");
        }
        if (data == null)
            return null;
        try {
            Key secretKey = convertKey(password);
            Cipher cipher = Cipher.getInstance("DES/CBC/PKCS5Padding",provider);
            IvParameterSpec iv = new IvParameterSpec(IV_PARAMETER.getBytes("utf-8"));
            cipher.init(Cipher.ENCRYPT_MODE, secretKey, iv);
            byte[] bytes = cipher.doFinal(data);
            return bytes;
        } catch (Exception e) {
            e.printStackTrace();
            return data;
        }
    }

    /**
     * DES解密解密字符串
     */
    public static byte[] decrypt(byte[] data, byte[] password) {
        if (password == null || password.length < 8) {
            throw new RuntimeException("加密失败,key不能小于8位");
        }
        if (data == null)
            return null;
        try {
            Key secretKey = convertKey(password);
            Cipher cipher = Cipher.getInstance("DES/CBC/PKCS5Padding",provider);
            IvParameterSpec iv = new IvParameterSpec(IV_PARAMETER.getBytes("utf-8"));
            cipher.init(Cipher.DECRYPT_MODE, secretKey, iv);
            byte[] bytes = cipher.doFinal(data);
            return bytes;
        } catch (Exception e) {
            e.printStackTrace();
            return data;
        }
    }

    /**
     * byte数组转十六进制
     *
     * @param bytes
     * @return
     */
    public static String byte2HexString(byte[] bytes) {
        StringBuilder hex = new StringBuilder();
        if (bytes != null) {
            for (Byte b : bytes) {
                hex.append(String.format("%02X", b.intValue() & 0xFF));
            }
        }
        return hex.toString();
    }

    //测试
    public static void main(String[] args) throws Exception {
        String source = "admin测试信息1234!@#$%^&*()_+";
        System.out.println("原  文: " + source);
        String password = "lw112190@2023";
        byte[] encryptDataBytes = encrypt(source.getBytes("utf-8"), password.getBytes("utf-8"));
        String encryptData = byte2HexString(encryptDataBytes);
        System.out.println("加密后: " + encryptData);
        byte[] decryptDataBytes = decrypt(encryptDataBytes, password.getBytes("utf-8"));
        String decryptData = new String(decryptDataBytes, "utf-8");
        ;
        System.out.println("解密后: " + decryptData);
    }

    static {
        provider = new BouncyCastleProvider();
    }
}

BlockCipherEngine方式的DES加解密代码如下

package com.vvvtimes.demo.util.endecrypt;

import org.bouncycastle.crypto.BlockCipher;
import org.bouncycastle.crypto.BufferedBlockCipher;
import org.bouncycastle.crypto.InvalidCipherTextException;
import org.bouncycastle.crypto.engines.DESEngine;
import org.bouncycastle.crypto.modes.CBCBlockCipher;
import org.bouncycastle.crypto.paddings.PKCS7Padding;
import org.bouncycastle.crypto.paddings.PaddedBufferedBlockCipher;
import org.bouncycastle.crypto.params.DESParameters;
import org.bouncycastle.crypto.params.ParametersWithIV;
import org.bouncycastle.jce.provider.BouncyCastleProvider;

import javax.crypto.SecretKey;
import javax.crypto.SecretKeyFactory;
import javax.crypto.spec.DESKeySpec;
import java.io.UnsupportedEncodingException;
import java.security.InvalidKeyException;
import java.security.NoSuchAlgorithmException;
import java.security.spec.InvalidKeySpecException;

public class BcDesEngineUtil {

    private final static BlockCipher engine;
    private static final BouncyCastleProvider provider;

    /**
     * 偏移变量,固定占8位字节
     */
    private final static String IV_PARAMETER = "12345678";

    /**
     * 生成key
     *
     * @param password 密钥字符串
     * @return 密钥对象
     * @throws Exception
     */
    private static byte[] convertKeyEncoded(byte[] password) {
        byte[] result = null;
        try {
            DESKeySpec dks  = new DESKeySpec(password);
            SecretKeyFactory keyFactory = SecretKeyFactory.getInstance("DES",provider);
            SecretKey secretKey = keyFactory.generateSecret(dks);
            return secretKey.getEncoded();
        } catch (InvalidKeyException e) {
            e.printStackTrace();
        } catch (NoSuchAlgorithmException e) {
            e.printStackTrace();
        } catch (InvalidKeySpecException e) {
            e.printStackTrace();
        }
        return result;

    }

    private static byte[] encrypt( byte[] ptBytes,byte[] key) throws InvalidCipherTextException, UnsupportedEncodingException {
        BufferedBlockCipher cipher = new PaddedBufferedBlockCipher(new CBCBlockCipher(engine), new PKCS7Padding());
        cipher.init(true, new ParametersWithIV(new DESParameters(key), IV_PARAMETER.getBytes("utf-8")));
        byte[] rv = new byte[cipher.getOutputSize(ptBytes.length)];
        int tam = cipher.processBytes(ptBytes, 0, ptBytes.length, rv, 0);

        cipher.doFinal(rv, tam);
        return rv;
    }


    private static byte[] decrypt( byte[] cipherText,byte[] key) throws InvalidCipherTextException, UnsupportedEncodingException {
        BufferedBlockCipher cipher = new PaddedBufferedBlockCipher(new CBCBlockCipher(engine), new PKCS7Padding());
        cipher.init(false, new ParametersWithIV(new DESParameters( key),IV_PARAMETER.getBytes("utf-8")));
        byte[] rv = new byte[cipher.getOutputSize(cipherText.length)];
        int tam = cipher.processBytes(cipherText, 0, cipherText.length, rv, 0);
        cipher.doFinal(rv, tam);
        return rv;
    }

    /**
     * byte数组转十六进制
     *
     * @param bytes
     * @return
     */
    public static String byte2HexString(byte[] bytes) {
        StringBuilder hex = new StringBuilder();
        if (bytes != null) {
            for (Byte b : bytes) {
                hex.append(String.format("%02X", b.intValue() & 0xFF));
            }
        }
        return hex.toString();
    }

    //测试
    public static void main(String[] args) throws Exception {
        String source = "admin测试信息1234!@#$%^&*()_+";
        System.out.println("原  文: " + source);
        String password = "lw112190@2023";
        //String password ="geffzhan";
        //String password ="lw112190";
        byte[] keyEncoded = convertKeyEncoded(password.getBytes("utf-8"));

        byte[] encryptDataBytes = encrypt(source.getBytes("utf-8"), keyEncoded);
        String encryptData = byte2HexString(encryptDataBytes);
        System.out.println("加密后: " + encryptData);
        byte[] decryptDataBytes = decrypt(encryptDataBytes, keyEncoded);
        String decryptData = new String(decryptDataBytes, "utf-8");
        ;
        System.out.println("解密后: " + decryptData);
        /*
         *原  文: admin测试信息1234!@#$%^&*()_+
        加密后: 1D5C21B694A9085A69BE7EA37C197D1632239545298613B944C3AC272750A519F66FB43EFEC55C89
        解密后: admin测试信息1234!@#$%^&*()_+
         */
    }

    static {
        engine = new DESEngine();
        provider = new BouncyCastleProvider();
    }

}

3.其他示例

AES加解密

package com.vvvtimes.demo.util.endecrypt;

import lombok.extern.slf4j.Slf4j;
import org.bouncycastle.jce.provider.BouncyCastleProvider;

import javax.crypto.Cipher;
import javax.crypto.KeyGenerator;
import javax.crypto.SecretKey;
import javax.crypto.SecretKeyFactory;
import javax.crypto.spec.DESKeySpec;
import javax.crypto.spec.IvParameterSpec;
import javax.crypto.spec.SecretKeySpec;
import java.security.AlgorithmParameters;
import java.security.Key;
import java.security.NoSuchAlgorithmException;
import java.security.spec.InvalidParameterSpecException;

@Slf4j
public class BcAesUtil {

    private static final BouncyCastleProvider provider;

    /**
     * 偏移变量,固定占8位字节
     */
    private final static String IV_PARAMETER = "1234567890123456";

    /**
     * AES加密
     */
    public static byte[] encrypt(byte[] data, byte[] password, byte[] iv) {
        if (data == null)
            return null;
        try {
            Key secretKey = new SecretKeySpec(password,"AES");
            Cipher cipher = Cipher.getInstance("AES/CBC/PKCS7Padding",provider);
            AlgorithmParameters generateIV = generateIV(iv);
            cipher.init(Cipher.ENCRYPT_MODE, secretKey, generateIV);
            byte[] bytes = cipher.doFinal(data);
            return bytes;
        } catch (Exception e) {
            e.printStackTrace();
            return data;
        }
    }

    /**
     * AES解密解密字符串
     */
    public static byte[] decrypt(byte[] data, byte[] password, byte[] iv) {
        if (data == null)
            return null;
        try {
            Key secretKey = new SecretKeySpec(password,"AES");
            Cipher cipher = Cipher.getInstance("AES/CBC/PKCS7Padding",provider);
            AlgorithmParameters generateIV = generateIV(iv);
            cipher.init(Cipher.DECRYPT_MODE, secretKey, generateIV);
            byte[] bytes = cipher.doFinal(data);
            return bytes;
        } catch (Exception e) {
            e.printStackTrace();
            return data;
        }
    }

   public static AlgorithmParameters generateIV(byte[] iv){
       AlgorithmParameters params = null;
       try {
           params = AlgorithmParameters.getInstance("AES");
           params.init(new IvParameterSpec(iv));
       } catch (NoSuchAlgorithmException | InvalidParameterSpecException e) {
           e.printStackTrace();
       }
       return params;

    }

    /**
     * byte数组转十六进制
     *
     * @param bytes
     * @return
     */
    public static String byte2HexString(byte[] bytes) {
        StringBuilder hex = new StringBuilder();
        if (bytes != null) {
            for (Byte b : bytes) {
                hex.append(String.format("%02X", b.intValue() & 0xFF));
            }
        }
        return hex.toString();
    }

    //测试
    public static void main(String[] args) throws Exception {
        String source = "admin测试信息1234!@#$%^&*()_+";
        System.out.println("原  文: " + source);
        String password = "passwordpassword";
        byte[] encryptDataBytes = encrypt(source.getBytes("utf-8"), password.getBytes("utf-8"),IV_PARAMETER.getBytes("utf-8"));
        String encryptData = byte2HexString(encryptDataBytes);
        System.out.println("加密后: " + encryptData);
        byte[] decryptDataBytes = decrypt(encryptDataBytes, password.getBytes("utf-8"),IV_PARAMETER.getBytes("utf-8"));
        String decryptData = new String(decryptDataBytes, "utf-8");
        System.out.println("解密后: " + decryptData);
    }

    static {
        provider = new BouncyCastleProvider();
    }
}

RSA私钥解密 签名

package com.vvvtimes.demo.util.endecrypt;

import cn.hutool.core.codec.Base64;
import org.bouncycastle.jce.provider.BouncyCastleProvider;

import javax.crypto.BadPaddingException;
import javax.crypto.Cipher;
import javax.crypto.IllegalBlockSizeException;
import javax.crypto.NoSuchPaddingException;
import java.nio.charset.Charset;
import java.security.*;
import java.security.spec.PKCS8EncodedKeySpec;

public class BcRsaUtil {
    private static final BouncyCastleProvider provider;




    private static PrivateKey getPrivateKey(String pkcs8Key) {

        byte[] pkcs8Keybytes = Base64.decode(pkcs8Key.getBytes(Charset.forName("UTF-8")));
        final PKCS8EncodedKeySpec pkcs8EncodedKeySpec = new PKCS8EncodedKeySpec(pkcs8Keybytes);
        try {
            return KeyFactory.getInstance("RSA", provider).generatePrivate(pkcs8EncodedKeySpec);
        } catch (Exception ex) {
            ex.printStackTrace();
            return null;
        }
    }

    /**
     * RSA私钥解密
     *
     * @param inputByte 待解密字节数组
     * @param pkcs8Key  私钥
     * @return 明文
     */
    public static byte[] decrypt(byte[] inputByte, String pkcs8Key) {
        byte[] outputeByte = null;
        try {
            PrivateKey privateKey = getPrivateKey(pkcs8Key);
            //RSA解密
            Cipher cipher = Cipher.getInstance("RSA", provider);
            cipher.init(Cipher.DECRYPT_MODE, privateKey);
            outputeByte = cipher.doFinal(inputByte);

        } catch (NoSuchPaddingException | InvalidKeyException | IllegalBlockSizeException | BadPaddingException | NoSuchAlgorithmException e) {
            e.printStackTrace();
        }
        return outputeByte;
    }

    public static byte[] sign(final byte[] array, String pkcs8Key) {
        try {
            PrivateKey privateKey = getPrivateKey(pkcs8Key);
            final Signature instance = Signature.getInstance("SHA1withRSA", provider);
            instance.initSign(privateKey);
            instance.update(array);
            return instance.sign();
        } catch (GeneralSecurityException ex) {
            throw new RuntimeException("License Server installation error 0000000F2", ex);
        }
    }

    static {
        provider = new BouncyCastleProvider();
    }
}

实际上bouncycastle还支持部分国密算法,这一部分不用自己写实现了。

  • 1
    点赞
  • 5
    收藏
    觉得还不错? 一键收藏
  • 0
    评论
BouncyCastle 是一个流行的开源加密库,提供了多种加密算法和安全协议的实现。.NET Core 也可以使用 BouncyCastle 库来实现加密和解密的功能。 在 .NET Core 中使用 BouncyCastle 库,需要先安装 BouncyCastle NuGet 包。可以通过 Visual Studio 中的 NuGet 包管理器搜索并安装,也可以通过命令行使用 dotnet 命令进行安装: ``` dotnet add package BouncyCastle ``` 安装完成后,就可以在代码中使用 BouncyCastle 库提供的加密和解密方法了。以下是一个使用 BouncyCastle 库进行 AES 加密和解密的示例代码: ```csharp using Org.BouncyCastle.Crypto; using Org.BouncyCastle.Crypto.Engines; using Org.BouncyCastle.Crypto.Modes; using Org.BouncyCastle.Crypto.Parameters; using Org.BouncyCastle.Security; public class AesCipher { private readonly byte[] _key; private readonly byte[] _iv; public AesCipher(byte[] key, byte[] iv) { _key = key; _iv = iv; } public byte[] Encrypt(byte[] data) { IBufferedCipher cipher = CipherUtilities.GetCipher("AES/CBC/PKCS7Padding"); cipher.Init(true, new ParametersWithIV(new KeyParameter(_key), _iv)); return cipher.DoFinal(data); } public byte[] Decrypt(byte[] data) { IBufferedCipher cipher = CipherUtilities.GetCipher("AES/CBC/PKCS7Padding"); cipher.Init(false, new ParametersWithIV(new KeyParameter(_key), _iv)); return cipher.DoFinal(data); } } ``` 在上面的示例代码中,我们使用BouncyCastle 库提供的 `IBufferedCipher` 接口来进行加密和解密。`CipherUtilities.GetCipher` 方法可以根据指定的算法名称获取对应的 `IBufferedCipher` 实例。在初始化 `IBufferedCipher` 实例时,我们需要传入加密/解密的模式、密钥和初始化向量等参数。在加密/解密时,我们调用 `DoFinal` 方法来执行加密/解密操作,并返回加密/解密后的结果。

“相关推荐”对你有帮助么?

  • 非常没帮助
  • 没帮助
  • 一般
  • 有帮助
  • 非常有帮助
提交
评论
添加红包

请填写红包祝福语或标题

红包个数最小为10个

红包金额最低5元

当前余额3.43前往充值 >
需支付:10.00
成就一亿技术人!
领取后你会自动成为博主和红包主的粉丝 规则
hope_wisdom
发出的红包
实付
使用余额支付
点击重新获取
扫码支付
钱包余额 0

抵扣说明:

1.余额是钱包充值的虚拟货币,按照1:1的比例进行支付金额的抵扣。
2.余额无法直接购买下载,可以购买VIP、付费专栏及课程。

余额充值