【问题标题】:InvalidKeyException in Android app when trying to encrypt with RSA private key尝试使用 RSA 私钥加密时,Android 应用中出现 InvalidKeyException
【发布时间】:2017-02-28 09:49:04
【问题描述】:

我正在尝试使用硬件支持的密钥库中生成的密钥对在我的 Android 应用程序中进行加密/解密。这是我的密钥生成代码:

public void createKeys() {
    Context ctx = getApplicationContext();
    Calendar start = new GregorianCalendar();
    Calendar end = new GregorianCalendar();
    end.add(Calendar.YEAR, 1);
    try {
        KeyPairGenerator kpGenerator = KeyPairGenerator.getInstance("RSA", "AndroidKeyStore");
        AlgorithmParameterSpec spec = null;

        if (Build.VERSION.SDK_INT > Build.VERSION_CODES.JELLY_BEAN_MR1 && Build.VERSION.SDK_INT < Build.VERSION_CODES.M) {
            spec = new KeyPairGeneratorSpec.Builder(ctx)
                    .setAlias(mAlias)
                    .setSubject(new X500Principal("CN=" + mAlias))
                    .setSerialNumber(BigInteger.valueOf(1337))
                    .setStartDate(start.getTime())
                    .setEndDate(end.getTime())
                    .build();
        } else if (Build.VERSION.SDK_INT >= Build.VERSION_CODES.M) {
            spec = new KeyGenParameterSpec.Builder(mAlias,
                    KeyProperties.PURPOSE_ENCRYPT | KeyProperties.PURPOSE_DECRYPT)
                    .setDigests(KeyProperties.DIGEST_SHA256, KeyProperties.DIGEST_SHA512)
                    .setEncryptionPaddings(KeyProperties.ENCRYPTION_PADDING_RSA_PKCS1)
                    .build();
        }
        kpGenerator.initialize(spec);
        KeyPair kp = kpGenerator.generateKeyPair();
    } catch (NoSuchAlgorithmException e) {
        Log.w(TAG, "RSA not supported", e);
    } catch (NoSuchProviderException e) {
        Log.w(TAG, "No such provider: AndroidKeyStore");
    } catch (InvalidAlgorithmParameterException e) {
        Log.w(TAG, "No such provider: AndroidKeyStore");
    }
}

这是我的加密代码:

public String encrypt(String challenge) {
    try {
        KeyStore mKeyStore = KeyStore.getInstance("AndroidKeyStore");
        mKeyStore.load(null);
        KeyStore.PrivateKeyEntry entry = (KeyStore.PrivateKeyEntry) mKeyStore.getEntry(mAlias, null);
        Cipher cip = null;
        cip = Cipher.getInstance("RSA/ECB/PKCS1Padding");
        cip.init(Cipher.ENCRYPT_MODE, entry.getPrivateKey());
        byte[] encryptBytes = cip.doFinal(challenge.getBytes());
        String encryptedStr64 = Base64.encodeToString(encryptBytes, Base64.NO_WRAP);
        return encryptedStr64;
    } catch (NoSuchAlgorithmException e) {
        Log.w(TAG, "No Such Algorithm Exception");
        e.printStackTrace();
    } catch (UnrecoverableEntryException e) {
        Log.w(TAG, "Unrecoverable Entry Exception");
        e.printStackTrace();
    } catch (KeyStoreException e) {
        Log.w(TAG, "KeyStore Exception");
        e.printStackTrace();
    } catch (InvalidKeyException e) {
        Log.w(TAG, "Invalid Key Exception");
        e.printStackTrace();
    } catch (NoSuchPaddingException e) {
        Log.w(TAG, "No Such Padding Exception");
        e.printStackTrace();
    } catch (BadPaddingException e) {
        Log.w(TAG, "Bad Padding Exception");
        e.printStackTrace();
    } catch (IllegalBlockSizeException e) {
        Log.w(TAG, "Illegal Block Size Exception");
        e.printStackTrace();
    } catch (CertificateException e) {
        Log.w(TAG, "Certificate Exception");
    } catch (IOException e) {
        Log.w(TAG, "IO Exception", e);
    }
    return null;
}

密钥生成成功完成。我还使用 KeyInfo.isInsideSecureHardware() 验证它是否有硬件支持。但是,我在 encrypt() 的 cip.init(Cipher.ENCRYPT_MODE, entry.getPrivateKey()) 行上不断收到 InvalidKeyException。确切的例外是

java.security.InvalidKeyException: Keystore operation failed

有人知道为什么吗?

【问题讨论】:

    标签: android encryption keystore android-keystore key-pair


    【解决方案1】:

    只有使用公钥时,加密才有意义。如果您使用私钥“加密”,那么您实际上是在创建签名。 Java/Android 有一个单独的类。

    【讨论】:

    • 好的,所以我尝试使用私钥签名,但我仍然收到 Invalid Key Exception: Keystore operation failed。 Android中是否有RSA签名/验证的示例代码?
    • 那么,你解决了吗?您可以使用一些代码添加自己的答案。
    • 哦,是的,我做到了。你的答案是正确的。我的印象是我可以用私钥加密,因为 github 中有一个示例代码可以做到这一点。显然它不起作用。
    猜你喜欢
    • 1970-01-01
    • 1970-01-01
    • 2016-02-23
    • 1970-01-01
    • 1970-01-01
    • 2013-05-07
    • 2015-12-25
    • 1970-01-01
    • 2011-03-20
    相关资源
    最近更新 更多