You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Erlang OTP 25下的RSA加解密及密钥对生成方案

Erlang OTP 25 下的RSA密钥生成与加解密实现

一、核心API变化说明

OTP 25 移除了 crypto 模块中旧的 rsa_private_encrypt/3、rsa_public_decrypt/3 等函数,统一使用 public_key 模块提供的标准API处理RSA操作。

二、生成RSA密钥对

1. 生成内存中的密钥对

直接生成2048位RSA密钥对(公钥指数用通用的65537):

% 生成私钥
{ok, PrivateKey} = public_key:generate_key({rsa, 2048, 65537}),
% 从私钥提取公钥
PublicKey = public_key:ssh_to_pubkey(public_key:private_key_to_ssh(PrivateKey)).

2. 保存密钥为PEM文件

将生成的密钥持久化到文件,方便后续复用:

% 保存私钥到PEM文件
PrivatePEM = public_key:pem_encode([public_key:pem_entry_encode('RSAPrivateKey', PrivateKey)]),
file:write_file("private_key.pem", PrivatePEM),

% 保存公钥到PEM文件
PublicPEM = public_key:pem_encode([public_key:pem_entry_encode('RSAPublicKey', PublicKey)]),
file:write_file("public_key.pem", PublicPEM).

三、从PEM文件加载密钥

替换旧的pem_to_der用法,使用标准PEM解析流程:

加载私钥

{ok, PrivatePEMBin} = file:read_file("private_key.pem"),
[{'RSAPrivateKey', PrivateDER, not_encrypted}] = public_key:pem_decode(PrivatePEMBin),
PrivateKey = public_key:der_decode('RSAPrivateKey', PrivateDER).

加载公钥

{ok, PublicPEMBin} = file:read_file("public_key.pem"),
[{'RSAPublicKey', PublicDER, not_encrypted}] = public_key:pem_decode(PublicPEMBin),
PublicKey = public_key:der_decode('RSAPublicKey', PublicDER).

四、RSA加解密与签名验签

1. 公钥加密+私钥解密(保密传输场景)

PlainText = <<"now is the time for all good men to come to the aid of their country">>,
% 公钥加密,PKCS#1 v1.5填充
Encrypted = public_key:encrypt_public(PlainText, PublicKey, [{rsa_pad, rsa_pkcs1_padding}]),
% 私钥解密
Decrypted = public_key:decrypt_private(Encrypted, PrivateKey, [{rsa_pad, rsa_pkcs1_padding}]),
% 验证结果
PlainText =:= Decrypted. % 返回true

2. 私钥签名+公钥验签(身份验证/防篡改场景)

旧代码中的rsa_private_encrypt实际是签名操作,对应新API的sign方法:

PlainText = <<"hello">>,
% 私钥签名,SHA-256哈希+PKCS#1 v1.5填充
Signature = public_key:sign(PlainText, sha256, PrivateKey),
% 公钥验签
Verified = public_key:verify(PlainText, sha256, Signature, PublicKey),
% 验证结果
Verified. % 返回true

五、适配你提供的旧代码(OTP25兼容版)

版本1:PEM加载+签名验签替换

% 加载PEM私钥
{ok, PrivatePEMBin} = file:read_file("./test_private_key"),
[{'RSAPrivateKey', PrivateDER, _}] = public_key:pem_decode(PrivatePEMBin),
PrivateKey = public_key:der_decode('RSAPrivateKey', PrivateDER),
% 提取公钥
PublicKey = public_key:ssh_to_pubkey(public_key:private_key_to_ssh(PrivateKey)),

PlainText = "now is the time for all good men to come to the aid of their country",
PlainTextBin = list_to_binary(PlainText),

% 替代旧的rsa_private_encrypt:私钥签名
Foo = public_key:sign(PlainTextBin, sha256, PrivateKey),
% 替代旧的rsa_public_decrypt:公钥验签
Bar = public_key:verify(PlainTextBin, sha256, Foo, PublicKey),
% 验证结果
Bar. % 返回true

版本2:直接用密钥参数构造密钥

如果要直接使用给定的指数、模数等参数:

% 构造私钥结构体
E = 257,
N = 77181119504409699204797322144340611322502523292227043692039327666381749008487,
D = 77131657261414365158890407156927969457179535804176721705182844017912686753873,
PrivateKey = #'RSAPrivateKey'{modulus = N, publicExponent = E, privateExponent = D},
% 构造公钥结构体
PublicKey = #'RSAPublicKey'{modulus = N, publicExponent = E},

PlainText = <<"hello">>,
% 签名
Enc = public_key:sign(PlainText, sha256, PrivateKey),
% 验签
DecResult = public_key:verify(PlainText, sha256, Enc, PublicKey),
% 编码为Base64
B64 = base64:encode(Enc).

注意:直接构造密钥结构体时,需确保所有参数符合RSA密钥的数学规范,否则会导致操作失败。

内容的提问来源于stack exchange,提问作者aniran mohammadpour

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.25 03:25:02