ios java 加密,使用Apples CryptoKit在iOS和Kotlin/Java之间进行跨平台AES加密

I want to send encrypted data form a server running a kotlin application to an iOS App using Apples CryptoKit.

I have problems to initialize a AES.GCM.SealedBox and decrypt the data. In general I don't understand what Sealboxstag is for.

So first Kotlin side:

fun ByteArray.aesEncrypt(key: ByteArray, iv: ByteArray? = null): ByteArray {

return aes(this, Cipher.ENCRYPT_MODE, key, iv)

}

private fun aes(self: ByteArray, mode: Int, key: ByteArray, iv: ByteArray?): ByteArray{

val skey = SecretKeySpec(key, "AES")

val cipher = Cipher.getInstance("AES/GCM/PKCS5Padding")

println("MODE: ${cipher.algorithm}")

iv?.let {

cipher.init(mode, skey, GCMParameterSpec(128, iv))

}?: run{

cipher.init(mode, skey)

}

val cipherText = ByteArray(cipher.getOutputSize(self.size))

var ctLength = cipher.update(self, 0, self.size, cipherText, 0)

ctLength += cipher.doFinal(cipherText, ctLength)

return cipherText

}

iOS:

static private let privateKey = SymmetricKey(size: SymmetricKeySize.bits128)

static private let nonce = AES.GCM.Nonce()

static func decrypt(_ data: Data) -> Data {

print("Encrypted data \(data.bytes)")

print("Private key: \(privateKey.data.bytes)")

print("Nonce: \(Array(nonce))")

let boxToDecrypt = try! AES.GCM.SealedBox(combined: data)

let plainData = try! AES.GCM.open(boxToDecrypt, using: privateKey)

return plainData

}

Of cause both sides have the same key and iv/nonce. The error message I'm running into is:

CryptoKit.CryptoKitError.incorrectParameterSize

in line:

let boxToDecrypt = try! AES.GCM.SealedBox(combined: data)

EDIT I:

Additional payload info:

Server(Kotlin):

Not encrypted: 0,0,0,0,0,0,0,1

Key: 169,152,60,154,77,50,10,63,60,166,48,129,1,68,219,250

IV: 134,191,34,26,111,146,17,54,31,212,74,14

Encrypted: 158,154,213,95,227,42,155,199,169,183,166,67,139,154,198,172,229,82,34,30,40,188,41,73

Client(iOS):

Encrypted data [158, 154, 213, 95, 227, 42, 155, 199, 169, 183, 166, 67, 139, 154, 198, 172, 229, 82, 34, 30, 40, 188, 41, 73]

Nonce: [134, 191, 34, 26, 111, 146, 17, 54, 31, 212, 74, 14]

Private key: [169, 152, 60, 154, 77, 50, 10, 63, 60, 166, 48, 129, 1, 68, 219, 250]

解决方案

could you try this (or something like it) with your setup. From what I undestand

you need to prefix data with nonce, because data from kotlin/java contains the cipher text plus the tag at the end. CryptoKit needs nonce || ciphertext || tag.

func decrypt(data: Data) -> String {

// need to prefix data with nonce, because data from kotlin/java contains the cipher text plus the tag at the end.

// we want nonce || ciphertext || tag for CryptoKit to be happy

let combine = nonce + data

if let myNewSealedBox = try? AES.GCM.SealedBox(combined: combine),

let res = try? AES.GCM.open(myNewSealedBox, using: mykey),

let myText = try? String(decoding: res, as: UTF8.self) {

return myText

}

return ""

}

  • 0
    点赞
  • 0
    收藏
    觉得还不错? 一键收藏
  • 0
    评论
评论
添加红包

请填写红包祝福语或标题

红包个数最小为10个

红包金额最低5元

当前余额3.43前往充值 >
需支付:10.00
成就一亿技术人!
领取后你会自动成为博主和红包主的粉丝 规则
hope_wisdom
发出的红包
实付
使用余额支付
点击重新获取
扫码支付
钱包余额 0

抵扣说明:

1.余额是钱包充值的虚拟货币,按照1:1的比例进行支付金额的抵扣。
2.余额无法直接购买下载,可以购买VIP、付费专栏及课程。

余额充值