You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

JavaScript WebCryptoAPI:为何不满足操作要求?如何修正密钥解包问题?

问题根源与修复方案

问题核心原因

你在decrypt和unwrapKey操作中传入的AES-GCM算法参数错误包含了length:256字段。Web Crypto API中,length仅在生成AES密钥(generateKey)时用来指定密钥长度,而在加密/解密、包装/解包密钥的操作中,算法参数不需要该字段。多余的length属性会导致API判定参数不符合要求,进而抛出DOMException: Data provided to an operation does not meet requirements错误。

修复步骤

只需要在decrypt和unwrapKey的算法配置中移除length字段即可。具体修改如下:

修正后的代码

(async() => {
  let exportFormat = "pkcs8";

  // 仅在生成密钥时包含length
  const keyWrappingAlgorithm = {
      name: "AES-GCM",
      length: 256,
  };
  let keyPairAlgorithm = {
      name: "RSA-OAEP",
      modulusLength: 4096,
      publicExponent: new Uint8Array([1, 0, 1]),
      hash: "SHA-256",
  };

  let kek = await window.crypto.subtle.generateKey(
      keyWrappingAlgorithm, 
      true, 
      ["decrypt", "wrapKey", "unwrapKey"]
  );

  let keyPair = await crypto.subtle.generateKey(
      keyPairAlgorithm, 
      true, 
      ["encrypt", "decrypt"]
  );

  const iv = crypto.getRandomValues(new Uint8Array(96/8));

  let wrappedPrivateKey = await crypto.subtle.wrapKey(
      exportFormat,
      keyPair.privateKey,
      kek,
      {
          name: "AES-GCM", // 仅保留必要的name和iv
          iv: iv,
      }
  );

  // 修正decrypt的算法参数
  let decryptedData = await crypto.subtle.decrypt(
      {
          name: "AES-GCM",
          iv: iv,
      },
      kek,
      wrappedPrivateKey,
  );
  console.log("done 1", decryptedData);
  await crypto.subtle.importKey(
      exportFormat,
      decryptedData,
      keyPairAlgorithm,
      true,
      ["encrypt", "decrypt"]
  ).then(() => {
      console.log("Success 1!");
  }).catch((error) => console.log("error 1", error));

  // 修正unwrapKey的算法参数
  let unwrappedKey = await crypto.subtle.unwrapKey(
      exportFormat,
      wrappedPrivateKey,
      kek,
      {
          name: "AES-GCM",
          iv: iv,
      },
      keyPairAlgorithm,
      true,
      ["encrypt", "decrypt"]
  ).then(() => {
      console.log("Success 2!");
  }).catch((error) => console.log("error 2", error));
})();

额外说明

  • 对于AES-GCM的算法参数,仅在generateKey时需要length字段,其他操作(加密、解密、包装、解包)只需指定name、iv,可选添加additionalData或tagLength(默认128位)。
  • 修正后,decrypt得到的decryptedData是正确的PKCS8格式私钥,importKey可正常导入;unwrapKey也能直接解包出可用的RSA私钥。

内容的提问来源于stack exchange,提问作者shilomig

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.19 13:30:19