.NET 4.8中如何实现RSA OAEP-SHA256加密?
.NET 4.8中实现RSA OAEP-SHA256加解密方案
问题背景
你在.NET 8中使用的RSA加密代码依赖RSA.Create()和RSAEncryptionPadding.OaepSHA256,但移植到.NET 4.8时,原生RSACryptoServiceProvider仅支持OAEP-SHA1,使用第三方扩展类尝试SHA256填充时抛出Specified padding mode is not valid for this algorithm错误。
解决方案
方案1:使用.NET 4.8原生RSA基类实现
.NET 4.8中RSA基类已支持灵活的加密填充配置,默认实例为RSACng(基于Cryptography Next Generation),可直接支持OAEP-SHA256,无需依赖第三方库。
完整代码实现
首先定义KeyPair类(若未定义可补充):
public class KeyPair { public string PublicKey { get; set; } public string PrivateKey { get; set; } }
加解密及密钥生成方法:
using System; using System.Security.Cryptography; using System.Text; public static class RsaOaepSha256Helper { // 公钥加密(OAEP-SHA256) public static string EncryptWithPublicKey(string text, string publicKeyBase64) { using (RSA rsa = RSA.Create()) { rsa.ImportRSAPublicKey(Convert.FromBase64String(publicKeyBase64), out _); byte[] dataBytes = Encoding.UTF8.GetBytes(text); byte[] encryptedBytes = rsa.Encrypt(dataBytes, RSAEncryptionPadding.OaepSHA256); return Convert.ToBase64String(encryptedBytes); } } // 私钥解密(OAEP-SHA256) public static string DecryptWithPrivateKey(string cipherTextBase64, string privateKeyBase64) { using (RSA rsa = RSA.Create()) { rsa.ImportRSAPrivateKey(Convert.FromBase64String(privateKeyBase64), out _); byte[] encryptedBytes = Convert.FromBase64String(cipherTextBase64); byte[] decryptedBytes = rsa.Decrypt(encryptedBytes, RSAEncryptionPadding.OaepSHA256); return Encoding.UTF8.GetString(decryptedBytes); } } // 生成2048位RSA密钥对(兼容OAEP-SHA256) public static KeyPair GenerateKeyPair() { using (RSA rsa = RSA.Create(2048)) { return new KeyPair { PublicKey = Convert.ToBase64String(rsa.ExportRSAPublicKey()), PrivateKey = Convert.ToBase64String(rsa.ExportRSAPrivateKey()) }; } } }
方案2:使用Bouncy Castle库实现
若因环境限制无法使用RSACng,可通过Bouncy Castle库实现OAEP-SHA256加解密。
步骤1:安装NuGet包
安装BouncyCastle(推荐1.8.9及以上版本):
Install-Package BouncyCastle
步骤2:代码实现
using System; using System.Text; using Org.BouncyCastle.Crypto; using Org.BouncyCastle.Crypto.Parameters; using Org.BouncyCastle.Security; public static class RsaBouncyCastleHelper { // 公钥加密(OAEP-SHA256) public static string EncryptWithPublicKey(string text, string publicKeyBase64) { byte[] publicKeyBytes = Convert.FromBase64String(publicKeyBase64); AsymmetricKeyParameter publicKey = PublicKeyFactory.CreateKey(publicKeyBytes); IBufferedCipher cipher = CipherUtilities.GetCipher("RSA/NONE/OAEPWithSHA256AndMGF1Padding"); cipher.Init(true, publicKey); byte[] dataBytes = Encoding.UTF8.GetBytes(text); byte[] encryptedBytes = cipher.DoFinal(dataBytes); return Convert.ToBase64String(encryptedBytes); } // 私钥解密(OAEP-SHA256) public static string DecryptWithPrivateKey(string cipherTextBase64, string privateKeyBase64) { byte[] privateKeyBytes = Convert.FromBase64String(privateKeyBase64); AsymmetricKeyParameter privateKey = PrivateKeyFactory.CreateKey(privateKeyBytes); IBufferedCipher cipher = CipherUtilities.GetCipher("RSA/NONE/OAEPWithSHA256AndMGF1Padding"); cipher.Init(false, privateKey); byte[] encryptedBytes = Convert.FromBase64String(cipherTextBase64); byte[] decryptedBytes = cipher.DoFinal(encryptedBytes); return Encoding.UTF8.GetString(decryptedBytes); } // 生成RSA密钥对 public static KeyPair GenerateKeyPair() { RsaKeyPairGenerator generator = new RsaKeyPairGenerator(); generator.Init(new KeyGenerationParameters(new SecureRandom(), 2048)); AsymmetricCipherKeyPair keyPair = generator.GenerateKeyPair(); byte[] publicKeyBytes = SubjectPublicKeyInfoFactory.CreateSubjectPublicKeyInfo(keyPair.Public).GetEncoded(); byte[] privateKeyBytes = PrivateKeyInfoFactory.CreatePrivateKeyInfo(keyPair.Private).GetEncoded(); return new KeyPair { PublicKey = Convert.ToBase64String(publicKeyBytes), PrivateKey = Convert.ToBase64String(privateKeyBytes) }; } }
错误原因说明
你之前使用的扩展类基于RSACryptoServiceProvider,该类在.NET 4.8中底层依赖Windows CryptoAPI旧实现,仅支持SHA1的OAEP填充,因此无法识别OaepSHA256参数。改用RSA.Create()(默认返回RSACng实例)或Bouncy Castle即可避开这一限制。
内容的提问来源于stack exchange,提问作者cjsmith87
相关产品推荐
相关产品推荐

