Apache NiFi脚本处理器中PyCryptodome的纯Python替代方案咨询
NiFi Script Processor AES Encryption/Decryption: Alternatives to PyCryptodome
Since NiFi's Python Script Processor relies on Jython (which doesn’t support C-extended modules like PyCryptodome or pycrypto), here are two reliable, compatible ways to implement AES functionality:
1. Use pyaes (Pure Python AES Implementation)
pyaes is a fully pure-Python AES library with zero C dependencies, making it a perfect fit for Jython environments like NiFi. It supports all common AES modes (CBC, CTR, ECB, etc.) and padding schemes.
Setup Steps:
- Grab the
pyaessource code (it’s a lightweight package) and place thepyaesdirectory or core.pyfiles in a location accessible to NiFi’s Script Processor. You can either add this path to NiFi’s Python classpath or bundle the files directly with your script.
Example Code Snippet:
import pyaes import os # Generate 256-bit (32-byte) key and 16-byte IV key = os.urandom(32) iv = os.urandom(16) # Encryption aes_encrypt = pyaes.AESModeOfOperationCBC(key, iv=iv) plaintext = b"Your sensitive data here" # Apply PKCS7-style padding to reach 16-byte blocks padding_length = 16 - len(plaintext) % 16 padded_plaintext = plaintext + (bytes([padding_length]) * padding_length) ciphertext = aes_encrypt.encrypt(padded_plaintext) # Decryption aes_decrypt = pyaes.AESModeOfOperationCBC(key, iv=iv) decrypted_padded = aes_decrypt.decrypt(ciphertext) # Remove padding padding_length = decrypted_padded[-1] decrypted = decrypted_padded[:-padding_length]
2. Call Java's Cryptography API Directly (Recommended)
Since NiFi is a Java application, Jython seamlessly integrates with Java’s built-in crypto tools. Using the javax.crypto package is the most robust, dependency-free approach—no external Python libraries required.
Example Code Snippet:
from javax.crypto import Cipher from javax.crypto.spec import SecretKeySpec, IvParameterSpec import os # Generate AES-256 key (32 bytes) and IV (16 bytes) key_bytes = os.urandom(32) iv_bytes = os.urandom(16) # Initialize encryption cipher (CBC mode with PKCS5 padding) encrypt_cipher = Cipher.getInstance("AES/CBC/PKCS5Padding") secret_key = SecretKeySpec(key_bytes, "AES") iv_spec = IvParameterSpec(iv_bytes) encrypt_cipher.init(Cipher.ENCRYPT_MODE, secret_key, iv_spec) # Encrypt data plaintext = "Your sensitive data here" ciphertext = encrypt_cipher.doFinal(plaintext.getBytes("UTF-8")) # Initialize decryption cipher decrypt_cipher = Cipher.getInstance("AES/CBC/PKCS5Padding") decrypt_cipher.init(Cipher.DECRYPT_MODE, secret_key, iv_spec) # Decrypt data decrypted_bytes = decrypt_cipher.doFinal(ciphertext) decrypted_text = decrypted_bytes.toString("UTF-8")
Key Notes:
- Avoid insecure modes like ECB—stick to CBC or GCM (for authenticated encryption). For GCM, use the cipher string
"AES/GCM/NoPadding"and handle authentication tags. - Ensure your key length matches the AES variant: 128-bit = 16 bytes, 192-bit = 24 bytes, 256-bit = 32 bytes.
内容的提问来源于stack exchange,提问作者jordi
相关产品推荐
相关产品推荐

