Visual Basic与CryptoJS生成HMACSHA256结果不一致问题排查
Fixing HMACSHA256 Mismatch in Visual Basic
It sounds like you're hitting a common snag when generating HMACSHA256 in VB: your output matches the jsSHA test result (f701ea7028f20df11a52bee297a336de212655a8bad01d848eeaa87d0f76ee5e) but not the expected value from CryptoJS/Python (330c55857e5ff197a407a9dcd41bbf03a2e8de0b351aba9a405139919b3cae57). This almost always comes down to incorrect encoding handling or misprocessing your hexadecimal secret key.
Let's Break Down the Root Causes
- Secret Key Misinterpretation: Your secret is a hexadecimal string, not plain text. If you pass it directly to
HMACSHA256as a string (via standard encoding), you're converting each character to bytes instead of decoding the hex values into raw bytes. - Input String Encoding: VB uses UTF-16 (Unicode) as the default string encoding, while CryptoJS and Python default to UTF-8 for string-to-byte conversions. Using the wrong encoding alters the input bytes and produces a different hash.
- Line Endings: Your input data has line breaks—make sure you're using the correct line ending (
\nvs\r\n) that matches what CryptoJS/Python used to generate the expected result.
Correct Visual Basic Implementation
Here's a complete solution that fixes all these issues:
Imports System.Security.Cryptography Imports System.Text Public Class HmacSha256Utility Public Shared Function CalculateHmac(hexSecret As String, inputText As String) As String ' Step 1: Convert hexadecimal secret to raw byte array Dim secretBytes As Byte() = ConvertHexToBytes(hexSecret) ' Step 2: Encode input text using UTF-8 (matches CryptoJS/Python default) Dim inputBytes As Byte() = Encoding.UTF8.GetBytes(inputText) ' Step 3: Compute HMACSHA256 hash Using hmac As New HMACSHA256(secretBytes) Dim hashBytes As Byte() = hmac.ComputeHash(inputBytes) ' Convert hash bytes to lowercase hex string Return ConvertBytesToHex(hashBytes) End Using End Function ' Helper: Convert hex string to byte array Private Shared Function ConvertHexToBytes(hex As String) As Byte() Dim byteCount As Integer = hex.Length \ 2 Dim byteArray As Byte() = New Byte(byteCount - 1) {} For i As Integer = 0 To hex.Length - 1 Step 2 byteArray(i \ 2) = Convert.ToByte(hex.Substring(i, 2), 16) Next Return byteArray End Function ' Helper: Convert byte array to hex string Private Shared Function ConvertBytesToHex(bytes As Byte()) As String Dim sb As New StringBuilder(bytes.Length * 2) For Each b As Byte In bytes sb.Append(b.ToString("x2")) Next Return sb.ToString() End Function End Class ' Example Usage Sub Main() ' Replace vbLf with vbCrLf if your original input uses CRLF line endings Dim inputData As String = "Test" & vbLf & "Test" & vbLf & "Test" Dim secretKey As String = "c39ff802b43a01c08ea759750c41d7d4bac6b1b884b3864d640b577cf1dca21a" Dim result As String = HmacSha256Utility.CalculateHmac(secretKey, inputData) Console.WriteLine(result) ' Output should match: 330c55857e5ff197a407a9dcd41bbf03a2e8de0b351aba9a405139919b3cae57 End Sub
Key Checks to Ensure Success
- Secret Handling: Never encode the hex secret as a regular string—always decode it directly to bytes. This is the most critical fix here.
- Encoding: Using
Encoding.UTF8ensures your input bytes align with what CryptoJS/Python process by default. - Line Endings: Double-check if your original input uses
\n(LF) or\r\n(CRLF). Adjust thevbLf/vbCrLfin the example to match your actual input data.
Run this code, and you should get the exact HMAC value you expect from CryptoJS and Python.
内容的提问来源于stack exchange,提问作者Philipp
相关产品推荐
相关产品推荐

