You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

技术咨询:能否提取/导出navigator.credentials.create生成的本地/私钥?

能否提取/导出navigator.credentials.create生成的私钥?
  • 核心结论:默认情况下不能直接提取或导出WebAuthn生成的私钥,这是WebAuthn API的安全设计决定的。浏览器会将私钥存储在安全隔离环境(如TPM、安全元件或浏览器专属安全存储)中,禁止直接访问原始私钥数据。

  • 例外情况:仅当创建凭证时显式设置extractable: true参数,且你的设备和浏览器支持该配置时,才有可能导出私钥。但需注意:

    • 依赖硬件安全模块(如TPM)的设备通常不允许私钥提取,会直接拒绝extractable: true的配置请求。
    • 即使导出成功,你得到的是PKCS#8格式的封装密钥材料,而非原始裸私钥,且必须通过SubtleCrypto.exportKey()方法完成导出。
  • 可提取私钥的示例代码(仅在兼容环境下生效):

    async function createAndExportCredential() {
      const publicKeyOpts = {
        rp: { name: "Your Service" },
        user: {
          id: new Uint8Array(16),
          name: "user@your-service.com",
          displayName: "Your User"
        },
        pubKeyCredParams: [{ type: "public-key", alg: -7 }], // ES256算法
        authenticatorSelection: {
          authenticatorAttachment: "platform",
          requireResidentKey: false
        },
        // 关键配置:允许私钥提取
        extractable: true,
        attestation: "none",
        timeout: 60000
      };
    
      const cred = await navigator.credentials.create({ publicKey: publicKeyOpts });
      const keyHandle = cred.response.getPublicKey();
      
      try {
        const exportedPk = await window.crypto.subtle.exportKey("pkcs8", keyHandle);
        console.log("导出的私钥(PKCS#8格式):", exportedPk);
      } catch (err) {
        console.error("导出失败:", err.message);
      }
    }
    
  • 注意:大多数现代浏览器和安全设备会优先拒绝可提取私钥的请求,因为这会大幅降低WebAuthn的安全性。如果你的设备不支持,上述代码会抛出"Operation not allowed"类的错误。

内容的提问来源于stack exchange,提问作者olfek

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.17 07:04:59