Golang RSA 加密解密和签名验证库
package crypto
import ( 'crypto' 'crypto/rand' 'crypto/rsa' 'crypto/x509' 'encoding/base64' 'encoding/pem' 'errors' 'github.com/containous/traefik/v2/pkg/log' )
type pkcsClient struct { privateKey *rsa.PrivateKey publicKey *rsa.PublicKey } type Type int64
const ( PKCS1 Type = iota PKCS8 )
func (this *pkcsClient) Encrypt(plaintext []byte) ([]byte, error) { return rsa.EncryptPKCS1v15(rand.Reader, this.publicKey, plaintext) } func (this *pkcsClient) Decrypt(ciphertext []byte) ([]byte, error) { return rsa.DecryptPKCS1v15(rand.Reader, this.privateKey, ciphertext) }
func (this *pkcsClient) Sign(src []byte, hash crypto.Hash) ([]byte, error) { h := hash.New() h.Write(src) hashed := h.Sum(nil) return rsa.SignPKCS1v15(rand.Reader, this.privateKey, hash, hashed) }
func (this *pkcsClient) Verify(src []byte, sign []byte, hash crypto.Hash) error { h := hash.New() h.Write(src) hashed := h.Sum(nil) return rsa.VerifyPKCS1v15(this.publicKey, hash, hashed, sign) }
type Cipher interface { Encrypt(plaintext []byte) ([]byte, error) Decrypt(ciphertext []byte) ([]byte, error) Sign(src []byte, hash crypto.Hash) ([]byte, error) Verify(src []byte, sign []byte, hash crypto.Hash) error }
//默认客户端,pkcs8私钥格式,pem编码 func NewDefault(privateKey, publicKey string) (Cipher, error) { blockPri, _ := pem.Decode([]byte(privateKey)) if blockPri == nil { return nil, errors.New('private key error') } blockPub, _ := pem.Decode([]byte(publicKey)) if blockPub == nil { return nil, errors.New('public key error') } return NewRsa(blockPri.Bytes, blockPub.Bytes, PKCS8) }
func NewRsa(privateKey, publicKey []byte, privateKeyType Type) (Cipher, error) {
priKey, err := genPriKey(privateKey, privateKeyType)
if err != nil {
return nil, err
}
pubKey, err := genPubKey(publicKey)
if err != nil {
return nil, err
}
return &pkcsClient{privateKey: priKey, publicKey: pubKey}, nil
}
func genPubKey(publicKey []byte) (*rsa.PublicKey, error) { pub, err := x509.ParsePKIXPublicKey(publicKey) if err != nil { return nil, err } return pub.(*rsa.PublicKey), nil }
func genPriKey(privateKey []byte, privateKeyType Type) (*rsa.PrivateKey, error) { var priKey *rsa.PrivateKey var err error switch privateKeyType { case PKCS1: { priKey, err = x509.ParsePKCS1PrivateKey([]byte(privateKey)) if err != nil { return nil, err } } case PKCS8: { prkI, err := x509.ParsePKCS8PrivateKey([]byte(privateKey)) if err != nil { return nil, err } priKey = prkI.(*rsa.PrivateKey) } default: { return nil, errors.New('unsupport private key type') } } return priKey, nil }
func KeyPair() (priKey, pubKey string, err error) { privateKey, err := rsa.GenerateKey(rand.Reader, 2048) if err != nil { log.WithoutContext().Errorln(err) return } priKey = base64.StdEncoding.EncodeToString(x509.MarshalPKCS1PrivateKey(privateKey))
// 生成公钥文件
publicKey := &privateKey.PublicKey
derPkix, err := x509.MarshalPKIXPublicKey(publicKey)
if err != nil {
log.WithoutContext().Errorln(err)
return
}
pubKey = base64.StdEncoding.EncodeToString(derPkix)
return
} func KeyPairPem() (priKey, pubKey string, err error) { privateKey, err := rsa.GenerateKey(rand.Reader, 2048) if err != nil { return '', '', err } var pemPrivateBlock = &pem.Block{ Type: 'RSA PRIVATE KEY', Bytes: x509.MarshalPKCS1PrivateKey(privateKey), } priKey = string(pem.EncodeToMemory(pemPrivateBlock))
// 生成公钥文件
publicKey := &privateKey.PublicKey
derPkix, err := x509.MarshalPKIXPublicKey(publicKey)
if err != nil {
return '', '', err
}
block := &pem.Block{
Type: 'RSA PRIVATE KEY',
Bytes: derPkix,
}
pubKey = string(pem.EncodeToMemory(block))
return priKey, pubKey, nil
}
转为java内容:package crypto;
import java.nio.charset.StandardCharsets; import java.security.KeyPair; import java.security.KeyPairGenerator; import java.security.PrivateKey; import java.security.PublicKey; import java.security.Signature; import java.util.Base64;
public class RsaCipher implements Cipher {
private PrivateKey privateKey;
private PublicKey publicKey;
public RsaCipher(PrivateKey privateKey, PublicKey publicKey) {
this.privateKey = privateKey;
this.publicKey = publicKey;
}
@Override
public byte[] encrypt(byte[] plaintext) throws Exception {
// RSA encryption
Cipher cipher = Cipher.getInstance('RSA');
cipher.init(Cipher.ENCRYPT_MODE, publicKey);
return cipher.doFinal(plaintext);
}
@Override
public byte[] decrypt(byte[] ciphertext) throws Exception {
// RSA decryption
Cipher cipher = Cipher.getInstance('RSA');
cipher.init(Cipher.DECRYPT_MODE, privateKey);
return cipher.doFinal(ciphertext);
}
@Override
public byte[] sign(byte[] src) throws Exception {
// RSA signature
Signature signature = Signature.getInstance('SHA256withRSA');
signature.initSign(privateKey);
signature.update(src);
return signature.sign();
}
@Override
public boolean verify(byte[] src, byte[] sign) throws Exception {
// RSA signature verification
Signature signature = Signature.getInstance('SHA256withRSA');
signature.initVerify(publicKey);
signature.update(src);
return signature.verify(sign);
}
public static RsaCipher generateKeyPair() throws Exception {
// Generate RSA key pair
KeyPairGenerator keyPairGen = KeyPairGenerator.getInstance('RSA');
keyPairGen.initialize(2048);
KeyPair keyPair = keyPairGen.generateKeyPair();
return new RsaCipher(keyPair.getPrivate(), keyPair.getPublic());
}
public static void main(String[] args) throws Exception {
RsaCipher rsaCipher = RsaCipher.generateKeyPair();
String plaintext = 'Hello, World!';
byte[] ciphertext = rsaCipher.encrypt(plaintext.getBytes(StandardCharsets.UTF_8));
byte[] decrypted = rsaCipher.decrypt(ciphertext);
String sign = Base64.getEncoder().encodeToString(rsaCipher.sign(plaintext.getBytes(StandardCharsets.UTF_8)));
boolean verified = rsaCipher.verify(plaintext.getBytes(StandardCharsets.UTF_8), Base64.getDecoder().decode(sign));
System.out.println('Plaintext: ' + plaintext);
System.out.println('Ciphertext: ' + Base64.getEncoder().encodeToString(ciphertext));
System.out.println('Decrypted: ' + new String(decrypted, StandardCharsets.UTF_8));
System.out.println('Signature: ' + sign);
System.out.println('Verified: ' + verified);
}
}
原文地址: http://www.cveoy.top/t/topic/phbn 著作权归作者所有。请勿转载和采集!