You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

azure-sdk-for-js无法解包Key Vault API单独包装的密钥

问题原因与解决方案

核心问题

你直接用Buffer.from(wrappedDEK)处理Azure Key Vault API返回的wrappedDEK是错误的——Azure Key Vault的wrapKey API返回的是Base64编码字符串,而Buffer.from(字符串)默认会按UTF-8编码转成Buffer,这会导致传入unwrapKey的二进制数据和实际加密后的密文不匹配,从而抛出解密错误。

你观察到的字节差异也能佐证这点:342字符的Base64字符串解码后,刚好是256字节(和库生成的wrappedDEKLib.result一致),因为Base64编码会让数据体积膨胀约1/3。

修复代码

只需要将Buffer.from(wrappedDEK)改为Base64解码的方式:

const { CryptographyClient } = require('@azure/keyvault-keys');
    
const cryptographyClient = new CryptographyClient(masterKey, azureCredential, {
                serviceVersion: keyVaultApiVersion
            });
// 关键修改:指定Base64编码解码
const unwrappedDEK = await cryptographyClient.unwrapKey(
                'RSA1_5', Buffer.from(wrappedDEK, 'base64'));

补充验证

你可以先手动验证解码后的字节数,确认和库生成的密文字节数一致:

console.log(Buffer.from(wrappedDEK, 'base64').length); // 应输出256

内容的提问来源于stack exchange,提问作者Snehasish Karmakar

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.23 21:50:03