You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

.NET 4.8中如何实现RSA OAEP-SHA256加密?

.NET 4.8中实现RSA OAEP-SHA256加解密方案

问题背景

你在.NET 8中使用的RSA加密代码依赖RSA.Create()和RSAEncryptionPadding.OaepSHA256,但移植到.NET 4.8时,原生RSACryptoServiceProvider仅支持OAEP-SHA1,使用第三方扩展类尝试SHA256填充时抛出Specified padding mode is not valid for this algorithm错误。

解决方案

方案1:使用.NET 4.8原生RSA基类实现

.NET 4.8中RSA基类已支持灵活的加密填充配置,默认实例为RSACng(基于Cryptography Next Generation),可直接支持OAEP-SHA256,无需依赖第三方库。

完整代码实现

首先定义KeyPair类(若未定义可补充):

public class KeyPair
{
    public string PublicKey { get; set; }
    public string PrivateKey { get; set; }
}

加解密及密钥生成方法:

using System;
using System.Security.Cryptography;
using System.Text;

public static class RsaOaepSha256Helper
{
    // 公钥加密(OAEP-SHA256)
    public static string EncryptWithPublicKey(string text, string publicKeyBase64)
    {
        using (RSA rsa = RSA.Create())
        {
            rsa.ImportRSAPublicKey(Convert.FromBase64String(publicKeyBase64), out _);
            byte[] dataBytes = Encoding.UTF8.GetBytes(text);
            byte[] encryptedBytes = rsa.Encrypt(dataBytes, RSAEncryptionPadding.OaepSHA256);
            return Convert.ToBase64String(encryptedBytes);
        }
    }

    // 私钥解密(OAEP-SHA256)
    public static string DecryptWithPrivateKey(string cipherTextBase64, string privateKeyBase64)
    {
        using (RSA rsa = RSA.Create())
        {
            rsa.ImportRSAPrivateKey(Convert.FromBase64String(privateKeyBase64), out _);
            byte[] encryptedBytes = Convert.FromBase64String(cipherTextBase64);
            byte[] decryptedBytes = rsa.Decrypt(encryptedBytes, RSAEncryptionPadding.OaepSHA256);
            return Encoding.UTF8.GetString(decryptedBytes);
        }
    }

    // 生成2048位RSA密钥对(兼容OAEP-SHA256)
    public static KeyPair GenerateKeyPair()
    {
        using (RSA rsa = RSA.Create(2048))
        {
            return new KeyPair
            {
                PublicKey = Convert.ToBase64String(rsa.ExportRSAPublicKey()),
                PrivateKey = Convert.ToBase64String(rsa.ExportRSAPrivateKey())
            };
        }
    }
}

方案2:使用Bouncy Castle库实现

若因环境限制无法使用RSACng,可通过Bouncy Castle库实现OAEP-SHA256加解密。

步骤1:安装NuGet包

安装BouncyCastle(推荐1.8.9及以上版本):

Install-Package BouncyCastle

步骤2:代码实现

using System;
using System.Text;
using Org.BouncyCastle.Crypto;
using Org.BouncyCastle.Crypto.Parameters;
using Org.BouncyCastle.Security;

public static class RsaBouncyCastleHelper
{
    // 公钥加密(OAEP-SHA256)
    public static string EncryptWithPublicKey(string text, string publicKeyBase64)
    {
        byte[] publicKeyBytes = Convert.FromBase64String(publicKeyBase64);
        AsymmetricKeyParameter publicKey = PublicKeyFactory.CreateKey(publicKeyBytes);
        
        IBufferedCipher cipher = CipherUtilities.GetCipher("RSA/NONE/OAEPWithSHA256AndMGF1Padding");
        cipher.Init(true, publicKey);
        
        byte[] dataBytes = Encoding.UTF8.GetBytes(text);
        byte[] encryptedBytes = cipher.DoFinal(dataBytes);
        return Convert.ToBase64String(encryptedBytes);
    }

    // 私钥解密(OAEP-SHA256)
    public static string DecryptWithPrivateKey(string cipherTextBase64, string privateKeyBase64)
    {
        byte[] privateKeyBytes = Convert.FromBase64String(privateKeyBase64);
        AsymmetricKeyParameter privateKey = PrivateKeyFactory.CreateKey(privateKeyBytes);
        
        IBufferedCipher cipher = CipherUtilities.GetCipher("RSA/NONE/OAEPWithSHA256AndMGF1Padding");
        cipher.Init(false, privateKey);
        
        byte[] encryptedBytes = Convert.FromBase64String(cipherTextBase64);
        byte[] decryptedBytes = cipher.DoFinal(encryptedBytes);
        return Encoding.UTF8.GetString(decryptedBytes);
    }

    // 生成RSA密钥对
    public static KeyPair GenerateKeyPair()
    {
        RsaKeyPairGenerator generator = new RsaKeyPairGenerator();
        generator.Init(new KeyGenerationParameters(new SecureRandom(), 2048));
        AsymmetricCipherKeyPair keyPair = generator.GenerateKeyPair();
        
        byte[] publicKeyBytes = SubjectPublicKeyInfoFactory.CreateSubjectPublicKeyInfo(keyPair.Public).GetEncoded();
        byte[] privateKeyBytes = PrivateKeyInfoFactory.CreatePrivateKeyInfo(keyPair.Private).GetEncoded();
        
        return new KeyPair
        {
            PublicKey = Convert.ToBase64String(publicKeyBytes),
            PrivateKey = Convert.ToBase64String(privateKeyBytes)
        };
    }
}

错误原因说明

你之前使用的扩展类基于RSACryptoServiceProvider,该类在.NET 4.8中底层依赖Windows CryptoAPI旧实现,仅支持SHA1的OAEP填充,因此无法识别OaepSHA256参数。改用RSA.Create()(默认返回RSACng实例)或Bouncy Castle即可避开这一限制。

内容的提问来源于stack exchange,提问作者cjsmith87

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.17 00:12:02