Flutter使用flutter_cryptography验证Argon2id加密密码异常问题
Flutter离线认证:Argon2id哈希结果不匹配问题
需求
为Flutter应用实现离线认证功能,以应对Django后台系统离线的场景,必须使用flutter_cryptography包。
验证基准
通过命令行argon2工具,采用Django默认的Argon2id参数生成加密结果,已与在线Argon2生成器校验一致。命令行执行详情:
echo -n "password" | argon2 LymCzQ7tT4nyQ2HIdvXRxQ -id -l 32 -k 102400 -t 2 -p 8
命令行输出:
Type: Argon2id Iterations: 2 Memory: 102400 KiB Parallelism: 8 Hash: 4ec825ca2eb252c0122aa8404e948176013a1ae9767436e4ae587738bb8cda97 Encoded: $argon2id$v=19$m=102400,t=2,p=8$THltQ3pRN3RUNG55UTJISWR2WFJ4UQ$Tsglyi6yUsASKqhATpSBdgE6Gul2dDbkrlh3OLuM2pc 0.273 seconds
问题
使用flutter_cryptography包生成的哈希字节与命令行/在线生成的结果不匹配,怀疑是从CLI/Django生成的密码串中推导数值时出现错误,或存在其他疏漏。
测试代码
import 'dart:convert'; import 'dart:typed_data'; import 'package:cryptography/cryptography.dart'; Future<void> main() async { final Uint8List password = utf8.encode("password"); final List<int> salt = (await Sha256().hash(base64.decode("THltQ3pRN3RUNG55UTJISWR2WFJ4UQ=="))) .bytes; final List<int> hashedPWFroCLI = (await Sha256() .hash(base64.decode("Tsglyi6yUsASKqhATpSBdgE6Gul2dDbkrlh3OLuM2pc="))) .bytes; const int kdfIterations = 2; const int kdfParallelism = 8; const int kdfMemory = 102400; final Argon2id algorithm = Argon2id( parallelism: kdfParallelism, memory: kdfMemory, iterations: kdfIterations, hashLength: 32, ); final SecretKey newSecretKey = await algorithm.deriveKey(secretKey: SecretKey(password), nonce: salt); final List<int> newSecretKeyBytes = await newSecretKey.extractBytes(); print('hashed password : $newSecretKeyBytes'); print('hashed password from CLI: $hashedPWFroCLI'); }
运行结果
flutter: hashed password : [82, 74, 193, 248, 121, 184, 14, 2, 165, 86, 185, 44, 137, 11, 57, 112, 194, 140, 25, 143, 137, 241, 247, 151, 234, 38, 57, 181, 92, 21, 180, 1] flutter: hashed password from CLI: [180, 2, 251, 121, 218, 48, 41, 102, 201, 75, 45, 112, 130, 91, 108, 117, 204, 40, 146, 204, 168, 4, 80, 181, 137, 15, 103, 186, 144, 233, 199, 51]
内容的提问来源于stack exchange,提问作者leaningshelf
相关产品推荐
相关产品推荐

