openssl_encrypt加密数组值无法解密及continue语句执行异常咨询
问题根因与修复方案
1. 相同明文加密结果不一致、无法解密的问题
根因为变量名冲突:代码顶部定义的加密密钥变量名为$key,但内层遍历二维数组列的foreach语句将列名赋值给了$key变量,导致加密时实际传入的密钥并非预定义的有效密钥,而是当前列的键名字符串,因此加密结果错误无法解密。
修复方案:将遍历列使用的变量重命名,避免和密钥变量重名,这里统一将密钥变量重命名为$encryption_key规避冲突。
2. 不加密[0]、[1]列的逻辑不生效的问题
根因为判断条件错误:现有判断条件if ($items < 2)中的$items是当前行的完整数组,并非当前列的序号,且数组的列键是带方括号的字符串格式(如"[0]"),无法直接和数字比较。
修复方案:先提取列键中的数字再做判断,修改判断逻辑即可实现跳过前两列加密。
修正后的完整代码
<?php header( 'Content-Type: text/html; charset=utf-8' ); echo "Below is a 3-row, 2-dimensional array displaying sections, fields and values"; $bgyaa = array ( '[0]' => array ( '[0]' => '2', '[1]' => 'bgyaa.ZBRDE5aTZsUGZmWQ', '[2]' => '12346', '[3]' => 'John Citizen', '[4]' => 'noy-pic-1.jpg', '[5]' => 'noy-pic-2.jpg', '[6]' => 'RESIDENT', '[7]' => '777 Sarangani Street', '[8]' => '03/27/84', '[9]' => 'B', '[10]' => '287-865-194', '[11]' =>' '), '[1]' => array ( '[0]' => '3', '[1]' => 'bgyaa.ZMTEtpTC5qVGNTUQ', '[2]' => '12347', '[3]' => 'Dominador Pridas', '[4]' => 'domeng-pic-1.jpg', '[5]' => 'domeng-pic-2.jpg', '[6]' => 'TENANT', '[7]' => '321 Mango Drive', '[8]' => '03/27/84', '[9]' => 'B', '[10]' => '287-865-194', '[11]' =>' ' ), '[2]' => array ( '[0]' => '4', '[1]' => 'bgyaa.ZpcEpteDJOZlBVQQ', '[2]' => '12348', '[3]' => 'Taylor Swift', '[4]' => 'taylorswift-pic-1.jpg', '[5]' => 'taylorswift-pic-2.jpg', '[6]' => 'TENANT', '[7]' => '826 Anonas Street', '[8]' => '03/27/84', '[9]' => 'B', '[10]' => '287-865-194', '[11]' =>' ' ), ); echo "<pre>"; foreach ($bgyaa as $section => $items) { foreach ($items as $col_key => $value) { echo "$section:\t$col_key:\t$value<br/>"; } } $encryption_key="c871754451c2b89d4cdb1b14705be457b7fabe967af6a559f3d20c79ded5b5ff18675e56fa77d75fdcd47c34271bb74e372d6d04652f7aa6f529a838ca4aa6bd"; $iv= "f1e64276d153ad8a"; // this iv value is 16 bytes of hex characters $cipher = "aes-256-cbc-hmac-sha256"; if (in_array($cipher, openssl_get_cipher_methods())) { $ivlen = openssl_cipher_iv_length($cipher); $plain_text = 'John Citizen'; $encrypted = openssl_encrypt($plain_text, $cipher, $encryption_key, $options=0, $iv); echo "<br/><br/><br/>Bellw are from direct encrytion of the plain text name<br/>"; echo "plain text is John Citizen " . "<br/>"; echo "encrypted text is " . $encrypted . "<br/><br/><br/>"; } echo "And then below are openssl_encrypt (cipher aes-256-cbc) encrypted array codes beside their plain text original values<br/>"; foreach ($bgyaa as $section => $items) // section is the sub array (starts from 0) // items are rows { foreach ($items as $col_key => $value) //key represents field or column //value represents the values of row { $col_index = trim($col_key, '[]'); if ($col_index < 2) { continue; //跳过前两列不加密 } $encrypted = ''; if (in_array($cipher, openssl_get_cipher_methods())) { $ivlen = openssl_cipher_iv_length($cipher); $encrypted = openssl_encrypt($value, $cipher, $encryption_key, $options=0, $iv); } echo $col_key . " : " . $encrypted . " : " . $value . "<br/>"; } } echo "</pre>"; ?>
生产环境使用注意:加密IV不要固定写死,需要为每条加密数据生成独立随机IV,和密文一起存储,降低安全风险。
内容的提问来源于stack exchange,提问作者osarte2021
相关产品推荐
相关产品推荐

