You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

使用CryptoPP解密Base64编码RSA密文时遇InvalidCiphertext异常求助

解决CryptoPP RSA解密抛出CryptoPP::InvalidCiphertext异常的问题

核心问题排查点

  • 加密解密的填充/哈希不匹配:你使用RSAES_OAEP_SHA_Decryptor(默认SHA-1哈希的OAEP填充),加密端必须对应使用RSAES_OAEP_SHA_Encryptor;如果加密用了SHA-256等其他哈希,解密端也要同步替换为RSAES_OAEP_SHA256_Decryptor。
  • 私钥传递风险:原代码中私钥以传值方式传入函数,可能导致私钥对象复制时损坏,改成传引用更安全。
  • Base64解码兼容性:默认Base64Decoder要求严格格式,若密文包含换行、空格等格式字符,需要关闭严格模式。
  • 密文完整性问题:确认密文是对应公钥加密的完整数据,无篡改、截断。

修正后的解密代码

const string RSA_Helpers::decrypt(const string& base64_cipher, const CryptoPP::RSA::PrivateKey& privateKey) const
{
    using namespace CryptoPP;

    string cipher;
    // 解码Base64,允许非严格格式(如带换行)
    StringSource(base64_cipher, true,
        new Base64Decoder(
            new StringSink(cipher),
            false // 关闭严格模式,兼容带格式的Base64密文
        )
    );

    string cleartext;
    AutoSeededRandomPool rng;
    // 确保与加密端的填充/哈希算法一致,此处为默认SHA-1的OAEP
    RSAES_OAEP_SHA_Decryptor decryptor(privateKey);
    
    try {
        StringSource(cipher, true,
            new PK_DecryptorFilter(rng, decryptor,
                new StringSink(cleartext)
            )
        );
    } catch(const CryptoPP::Exception& e) {
        cerr << "解密异常详情: " << e.what() << endl;
        throw; // 可根据需求选择处理或重新抛出异常
    }

    return cleartext;
}

额外验证步骤

  1. 核对密钥一致性:从私钥导出公钥,与加密用公钥对比参数(如模数n、公钥指数e),确保是同一密钥对:
    CryptoPP::RSA::PublicKey derivedPubKey(privateKey);
    // 对比derivedPubKey和加密端publicKey的n、e是否一致
    
  2. 检查密文长度:3072位RSA密钥加密后的密文长度应为384字节,Base64解码后可验证此长度,若不符则密文或解码过程有问题。
  3. 确认加密端实现:加密代码示例参考(确保与解密匹配):
    string encrypt(const string& plaintext, const CryptoPP::RSA::PublicKey& publicKey) {
        using namespace CryptoPP;
        string cipher;
        AutoSeededRandomPool rng;
        RSAES_OAEP_SHA_Encryptor encryptor(publicKey);
        StringSource(plaintext, true,
            new PK_EncryptorFilter(rng, encryptor,
                new StringSink(cipher)
            )
        );
        // 加密后Base64编码
        string base64Cipher;
        StringSource(cipher, true,
            new Base64Encoder(new StringSink(base64Cipher))
        );
        return base64Cipher;
    }
    

内容的提问来源于stack exchange,提问作者Anonymous_Codesman

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.14 04:27:38