Android Keystore多用途密钥生成

问题描述 投票:0回答:1

我正在尝试为此目的生成RSA密钥对:

val purposes = PURPOSE_DECRYPT or PURPOSE_ENCRYPT or PURPOSE_SIGN or PURPOSE_VERIFY

这是我的密钥生成代码:

val generator = KeyPairGenerator.getInstance(
                KEY_ALGORITHM,
                ANDROID_KEY_STORE
            )
generator?.initialize(
                    KeyGenParameterSpec.Builder(
                        alias,
                        purposes
                    )
                        .setDigests(KeyProperties.DIGEST_SHA256)
                        .setEncryptionPaddings(KeyProperties.ENCRYPTION_PADDING_RSA_PKCS1)
                        .setSignaturePaddings(KeyProperties.SIGNATURE_PADDING_RSA_PKCS1)
                        .build()
                )
generator?.generateKeyPair()

但是,当我使用此目的时,解密不起作用并引发异常:

InvalidKeyException: "keystore operation  failed. Incompatible purpose."

但是当我尝试仅进行加密和解密时,密钥库确实进行了加密,而且解密也完美。这就是我用于的目的:

val purposes = PURPOSE_DECRYPT or PURPOSE_ENCRYPT

这些是加密和解密的方法:

private fun decrypt(cipherText: String, alias: String): String? {
        return try {
            val privateKeyEntry = getGeneratedPrivateKey(alias)

            val output = Cipher.getInstance(
                "$KEY_ALGORITHM_RSA/$BLOCK_MODE_ECB/$ENCRYPTION_PADDING_RSA_PKCS1"
//                ANDROID_OPEN_SSL
            )
            output.init(Cipher.DECRYPT_MODE, privateKeyEntry?.privateKey)

            val inputStream = ByteArrayInputStream(
                android.util.Base64.decode(
                    cipherText,
                    android.util.Base64.NO_WRAP
                )
            )

            val res = String(CipherInputStream(inputStream, output).readBytes(), Charsets.UTF_8)
            res
        } catch (e: Exception) {
            e.printStackTrace()
            null
        }
    }

private fun encrypt(plainText: String, alias: String): String? {
        return try {
            val publicKey = getGeneratedPublicKey(alias) ?: setupKeyPair(
                alias,
                PURPOSE_ENCRYPT or PURPOSE_DECRYPT
            )?.public
            val cipher = Cipher.getInstance(
                "$KEY_ALGORITHM_RSA/$BLOCK_MODE_ECB/$ENCRYPTION_PADDING_RSA_PKCS1"
//                ANDROID_OPEN_SSL
            )
            cipher.init(Cipher.ENCRYPT_MODE, publicKey)

            val outputStream = ByteArrayOutputStream()
            val cipherOutputStream = CipherOutputStream(outputStream, cipher)
            cipherOutputStream.write(plainText.toByteArray(charset("UTF-8")))
            cipherOutputStream.close()

            val encryptedText = outputStream.toByteArray()
            outputStream.close()
            val res = android.util.Base64.encodeToString(encryptedText, android.util.Base64.NO_WRAP)
            res
        } catch (e: Exception) {
            e.printStackTrace()
            null
        }
    }

那是什么问题?如何在Android密钥库中制作多用途密钥对?

android encryption rsa android-keystore
1个回答
0
投票
可能您有自己的purpose keys自定义变量

您应在此行中使用KeyProperties

val purposes = PURPOSE_DECRYPT or PURPOSE_ENCRYPT or PURPOSE_SIGN or PURPOSE_VERIFY

像这样:

val purposes = KeyProperties.PURPOSE_ENCRYPT or KeyProperties.PURPOSE_DECRYPT or KeyProperties.PURPOSE_SIGN or KeyProperties.PURPOSE_VERIFY

© www.soinside.com 2019 - 2024. All rights reserved.