You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Apache NiFi脚本处理器中PyCryptodome的纯Python替代方案咨询

NiFi Script Processor AES Encryption/Decryption: Alternatives to PyCryptodome

Since NiFi's Python Script Processor relies on Jython (which doesn’t support C-extended modules like PyCryptodome or pycrypto), here are two reliable, compatible ways to implement AES functionality:

1. Use pyaes (Pure Python AES Implementation)

pyaes is a fully pure-Python AES library with zero C dependencies, making it a perfect fit for Jython environments like NiFi. It supports all common AES modes (CBC, CTR, ECB, etc.) and padding schemes.

Setup Steps:

  • Grab the pyaes source code (it’s a lightweight package) and place the pyaes directory or core .py files in a location accessible to NiFi’s Script Processor. You can either add this path to NiFi’s Python classpath or bundle the files directly with your script.

Example Code Snippet:

import pyaes
import os

# Generate 256-bit (32-byte) key and 16-byte IV
key = os.urandom(32)
iv = os.urandom(16)

# Encryption
aes_encrypt = pyaes.AESModeOfOperationCBC(key, iv=iv)
plaintext = b"Your sensitive data here"
# Apply PKCS7-style padding to reach 16-byte blocks
padding_length = 16 - len(plaintext) % 16
padded_plaintext = plaintext + (bytes([padding_length]) * padding_length)
ciphertext = aes_encrypt.encrypt(padded_plaintext)

# Decryption
aes_decrypt = pyaes.AESModeOfOperationCBC(key, iv=iv)
decrypted_padded = aes_decrypt.decrypt(ciphertext)
# Remove padding
padding_length = decrypted_padded[-1]
decrypted = decrypted_padded[:-padding_length]

Since NiFi is a Java application, Jython seamlessly integrates with Java’s built-in crypto tools. Using the javax.crypto package is the most robust, dependency-free approach—no external Python libraries required.

Example Code Snippet:

from javax.crypto import Cipher
from javax.crypto.spec import SecretKeySpec, IvParameterSpec
import os

# Generate AES-256 key (32 bytes) and IV (16 bytes)
key_bytes = os.urandom(32)
iv_bytes = os.urandom(16)

# Initialize encryption cipher (CBC mode with PKCS5 padding)
encrypt_cipher = Cipher.getInstance("AES/CBC/PKCS5Padding")
secret_key = SecretKeySpec(key_bytes, "AES")
iv_spec = IvParameterSpec(iv_bytes)
encrypt_cipher.init(Cipher.ENCRYPT_MODE, secret_key, iv_spec)

# Encrypt data
plaintext = "Your sensitive data here"
ciphertext = encrypt_cipher.doFinal(plaintext.getBytes("UTF-8"))

# Initialize decryption cipher
decrypt_cipher = Cipher.getInstance("AES/CBC/PKCS5Padding")
decrypt_cipher.init(Cipher.DECRYPT_MODE, secret_key, iv_spec)

# Decrypt data
decrypted_bytes = decrypt_cipher.doFinal(ciphertext)
decrypted_text = decrypted_bytes.toString("UTF-8")

Key Notes:

  • Avoid insecure modes like ECB—stick to CBC or GCM (for authenticated encryption). For GCM, use the cipher string "AES/GCM/NoPadding" and handle authentication tags.
  • Ensure your key length matches the AES variant: 128-bit = 16 bytes, 192-bit = 24 bytes, 256-bit = 32 bytes.

内容的提问来源于stack exchange,提问作者jordi

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.12 03:56:27