Android中无填充(NO PADDING)RSA 512位使用及密钥生成求助
Hey there! Let's walk through solving your RSA NoPadding issue step by step—since you're new to this, I'll keep things clear and actionable.
First, a Critical Clarification
RSA keys themselves don't have a padding mode built into them. Padding is a parameter you specify when you perform encryption/decryption operations, not when generating keys. So your existing 512-bit keys are totally compatible with NoPadding—you just need to use the right configuration when setting up your encryption logic.
Step 1: Generate RSA Keys (No Changes Needed, But Here's the Standard Code)
Your generateKeys("RSA",512) method is fine, but here's a full, reusable snippet (Java example) for reference:
public KeyPair generateRSAKeys(int keySize) throws NoSuchAlgorithmException { KeyPairGenerator keyPairGenerator = KeyPairGenerator.getInstance("RSA"); keyPairGenerator.initialize(keySize); return keyPairGenerator.generateKeyPair(); }
This creates a valid 512-bit RSA key pair that works with any padding mode, including NoPadding.
Step 2: Encrypt an Integer with Your Private Key (NoPadding Mode)
Since you need to encrypt an integer with your private key, we need to handle two key things:
- Convert the integer to a byte array that's exactly 64 bytes long (512 bits = 64 bytes—required for RSA NoPadding, as plaintext length must match key length).
- Initialize the
Cipherclass with the full algorithm string"RSA/ECB/NoPadding".
Here's the code:
import java.math.BigInteger; import javax.crypto.Cipher; import android.util.Base64; // Assume you already have your private key from the KeyPair PrivateKey privateKey = yourKeyPair.getPrivate(); int yourInteger = 12345; // Replace with your target integer // 1. Convert integer to a 64-byte padded byte array BigInteger bigInt = BigInteger.valueOf(yourInteger); byte[] rawIntBytes = bigInt.toByteArray(); byte[] paddedPlaintext = new byte[64]; // 512 bits = 64 bytes // Copy the integer bytes to the end of the 64-byte array (pad with leading zeros) System.arraycopy(rawIntBytes, 0, paddedPlaintext, 64 - rawIntBytes.length, rawIntBytes.length); // 2. Initialize Cipher for NoPadding encryption Cipher cipher = Cipher.getInstance("RSA/ECB/NoPadding"); cipher.init(Cipher.ENCRYPT_MODE, privateKey); // 3. Perform encryption byte[] encryptedBytes = cipher.doFinal(paddedPlaintext); // Optional: Encode to Base64 for easy storage/transmission String encryptedBase64 = Base64.encodeToString(encryptedBytes, Base64.DEFAULT);
Important Note: Your integer must be smaller than
2^512 - 1(the maximum value a 512-bit RSA key can handle with NoPadding). If your integer is larger, you'll need a bigger key size (2048-bit is the modern minimum for security).
Step 3: Send Your Public Key to the Server
To send your public key to the server, convert it to a Base64-encoded string (easy to transmit over HTTP):
PublicKey publicKey = yourKeyPair.getPublic(); byte[] publicKeyBytes = publicKey.getEncoded(); // X.509 format String publicKeyBase64 = Base64.encodeToString(publicKeyBytes, Base64.DEFAULT); // Send publicKeyBase64 to your server via your preferred network method (Retrofit, OkHttp, etc.)
The server can then decode this Base64 string and reconstruct the public key to decrypt the encrypted integer.
Key Safety Notes
- 512-bit RSA is insecure: It's vulnerable to brute-force attacks. For production apps, use 2048-bit or 4096-bit keys instead.
- NoPadding is risky: It lacks randomization, making encrypted data susceptible to attacks. If possible, use
RSA/ECB/OAEPWithSHA-256AndMGF1Paddingfor secure encryption—only use NoPadding if your server strictly requires it. - Securely store your private key: Never hardcode it in your app. Use Android's
KeyStoreAPI to store keys securely, so they can't be extracted from the app.
内容的提问来源于stack exchange,提问作者Umaima Khurshid Ahmad

