You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何在Python中生成跨平台硬件派生的唯一特定持久化ID

跨平台生成固定主机唯一ID以派生主密钥

要实现跨平台(Windows/macOS/Linux)生成固定的主机唯一标识,进而派生主密钥,核心是获取每个系统上不会随程序运行变化、仅与主机绑定的硬件/系统标识,再通过密码学手段转换为密钥。以下是具体实现方案:

各平台固定标识获取方法

Windows

Windows系统可以通过wmic csproduct get UUID获取主板UUID,这个值在系统生命周期内固定不变:

import subprocess

def get_windows_id():
    try:
        # 调用wmic命令获取UUID
        output = subprocess.check_output(["wmic", "csproduct", "get", "UUID"], text=True)
        # 提取有效UUID行(跳过表头)
        return output.strip().split('\n')[1].strip()
    except Exception as e:
        raise RuntimeError(f"获取Windows UUID失败: {e}")

Linux

Linux系统的/etc/machine-id或/var/lib/dbus/machine-id文件存储了系统安装时生成的唯一ID,除非重装系统否则不会改变:

def get_linux_id():
    # 优先读取/etc/machine-id,不存在则尝试dbus路径
    paths = ["/etc/machine-id", "/var/lib/dbus/machine-id"]
    for path in paths:
        try:
            with open(path, 'r') as f:
                return f.read().strip()
        except FileNotFoundError:
            continue
    raise RuntimeError("Linux系统未找到machine-id文件")

macOS

macOS可以通过ioreg命令获取系统的IOPlatformUUID,这是与主机绑定的固定标识:

def get_macos_id():
    try:
        output = subprocess.check_output(["ioreg", "-rd1", "-c", "IOPlatformExpertDevice"], text=True)
        # 从输出中提取UUID
        for line in output.split('\n'):
            if "IOPlatformUUID" in line:
                return line.split('=')[1].strip().strip('"')
        raise RuntimeError("macOS系统未找到IOPlatformUUID")
    except Exception as e:
        raise RuntimeError(f"获取macOS UUID失败: {e}")

跨平台统一封装

通过platform.system()判断当前系统,调用对应平台的获取函数:

import platform

def get_host_unique_id():
    system = platform.system()
    if system == "Windows":
        return get_windows_id()
    elif system == "Linux":
        return get_linux_id()
    elif system == "Darwin":  # macOS的系统标识为Darwin
        return get_macos_id()
    else:
        raise RuntimeError(f"不支持的操作系统: {system}")

从主机ID派生主密钥与子密钥

直接使用主机ID作为密钥不安全,需通过密码学哈希或密钥派生函数(KDF)转换为符合要求的密钥:

import hashlib
from cryptography.hazmat.primitives.kdf.hkdf import HKDF
from cryptography.hazmat.primitives import hashes
from cryptography.hazmat.backends import default_backend

def derive_master_key(host_id):
    # 用SHA-256哈希主机ID,生成32字节的主密钥
    return hashlib.sha256(host_id.encode('utf-8')).digest()

def derive_subkey(master_key, salt, info):
    # 使用HKDF派生子密钥,salt和info可根据子密钥用途自定义
    hkdf = HKDF(
        algorithm=hashes.SHA256(),
        length=32,
        salt=salt,
        info=info,
        backend=default_backend()
    )
    return hkdf.derive(master_key)

# 使用示例
if __name__ == "__main__":
    host_id = get_host_unique_id()
    master_key = derive_master_key(host_id)
    # 派生用于存储加密的子密钥
    storage_subkey = derive_subkey(master_key, b"storage_salt_123", b"encryption_key_for_local_storage")

关键注意事项

  • 主机ID会在**系统重装、核心硬件更换(如主板)**时改变,此时之前派生的密钥会失效,需提前告知用户。
  • 确保程序具备基础权限:Windows调用wmic、Linux读取machine-id、macOS调用ioreg均无需管理员权限。
  • 禁止直接使用原始主机ID作为密钥,必须经过哈希/KDF处理,避免泄露主机标识同时提升密钥安全性。

内容的提问来源于stack exchange,提问作者Ray

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.08.13 07:31:06