You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

无法解密react-native-rsa加密消息,解密时出现OAEP解码错误

问题描述

我实现了一个后端RSA加解密工具类,单独在后端进行字符串加解密完全正常,但使用react-native-rsa-native库在前端加密消息后,后端用该工具类解密时抛出错误:

error:02000079:rsa routines::oaep decoding error

后端工具类代码:

import crypto from 'crypto';

interface KeyPair {
    publicKey: string;
    privateKey: string;
}

export class RSAController {
    static async generateKeys(): Promise<KeyPair> {
        return new Promise((res, rej) => {
            crypto.generateKeyPair(
                'rsa',
                {
                    modulusLength: 2048,
                },
                (err, publicKeyObject, privateKeyObject) => {
                    if (err) rej(err);

                    const publicKey = publicKeyObject.export({
                        type: 'pkcs1',
                        format: 'pem',
                    });
                    const privateKey = privateKeyObject.export({
                        type: 'pkcs1',
                        format: 'pem',
                    });

                    res({
                        publicKey: publicKey as string,
                        privateKey: privateKey as string,
                    });
                },
            );
        });
    }

    static encrypt({ data, publicKey }: { data: string; publicKey: string }) {
        const encryptedData = crypto.publicEncrypt(
            {
                key: publicKey,
                padding: crypto.constants.RSA_PKCS1_OAEP_PADDING,
                oaepHash: 'sha256',
            },
            Buffer.from(data),
        );

        return encryptedData.toString('base64');
    }

    static decrypt({ encryptedData, privateKey }: { encryptedData: string; privateKey: string }) {
        const decryptedData = crypto.privateDecrypt(
            {
                key: privateKey,
                padding: crypto.constants.RSA_PKCS1_OAEP_PADDING,
                oaepHash: 'sha256',
            },
            Buffer.from(encryptedData, 'base64'),
        );

        return decryptedData.toString();
    }
}

后端单独测试正常的代码:

const { privateKey, publicKey } = await RSAController.generateKeys();
const encryptedData = await RSAController.encrypt({ data: 'hello world', publicKey });
console.log('encryptedData', encryptedData);
const decryptedData = await RSAController.decrypt({ encryptedData, privateKey });
console.log('decryptedData', decryptedData); // 正常输出"hello world"
问题原因及解决办法
  • 密钥格式不匹配:后端生成的是PKCS#1格式密钥,而react-native-rsa-native默认通常使用PKCS#8格式,两者不兼容导致解密失败。解决方式:
    统一密钥格式为PKCS#8(通用标准),修改后端generateKeys方法的导出配置:

    const publicKey = publicKeyObject.export({
        type: 'spki', // PKCS#8公钥格式
        format: 'pem',
    });
    const privateKey = privateKeyObject.export({
        type: 'pkcs8', // PKCS#8私钥格式
        format: 'pem',
    });
    
  • 加密参数不一致:后端使用的是RSA_PKCS1_OAEP_PADDING填充方式和sha256哈希算法,前端加密时需指定完全相同的参数。前端加密示例:

    // 确保传入的公钥是后端生成的PKCS#8格式PEM字符串
    const encryptedData = await RSA.encrypt('需要加密的内容', publicKey, {
      padding: 'OAEP',
      hash: 'SHA256'
    });
    

    注:不同版本的react-native-rsa-native参数命名可能有差异,请以官方文档为准。

  • 编码一致性:确认前端加密后的输出是Base64编码(后端解密时按Base64解码),若前端输出为其他编码(如hex),需调整后端解密时的Buffer解码方式。

内容的提问来源于stack exchange,提问作者Mike K

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.19 17:42:41