Android中SHA1+RSA加密的UWP等价实现异常求助
Fixing UWP Equivalent of Android's SHA1 + RSA Private Key Encryption
Let's break down why your current UWP code isn't matching the Android behavior, then fix it step by step.
What Your Android Code Actually Does
Your Android code follows this exact flow:
- Compute a raw SHA1 hash of the input plain text
- Encrypt this raw 20-byte SHA1 hash directly using an RSA private key with PKCS1 padding
- Base64-encode the encrypted result to return as a string
Why Your UWP Code Fails
Your UWP code uses RsaSignPkcs1Sha1, which is an RSA signature algorithm—not a raw encryption algorithm. This is the core mismatch:
- The signature algorithm automatically wraps the SHA1 hash in a PKCS#1 standard
DigestInfoASN.1 structure (adding extra bytes that identify the hash algorithm) before applying PKCS1 padding. - Your Android code skips this wrapping entirely and encrypts the raw hash directly.
Corrected UWP Implementation
This code matches the exact behavior of your Android snippet:
using Windows.Security.Cryptography; using Windows.Security.Cryptography.Core; using System.Text; public string EncryptSha1WithRsaPrivateKey(string plainText, string privateKeyPkcs8Base64) { // 1. Calculate raw SHA1 hash of the plain text (matches Android's MessageDigest.digest) IBuffer plainTextBuffer = CryptographicBuffer.ConvertStringToBinary(plainText, BinaryStringEncoding.Utf8); HashAlgorithmProvider sha1Provider = HashAlgorithmProvider.OpenAlgorithm(HashAlgorithmNames.Sha1); IBuffer rawSha1Hash = sha1Provider.HashData(plainTextBuffer); // 2. Import your RSA private key (assuming it's in PKCS#8 Base64 format) IBuffer privateKeyBuffer = CryptographicBuffer.DecodeFromBase64String(privateKeyPkcs8Base64); AsymmetricKeyAlgorithmProvider rsaProvider = AsymmetricKeyAlgorithmProvider.OpenAlgorithm(AsymmetricAlgorithmNames.RsaPkcs1); // Import PKCS#8 private key (ignore the unused parameters output) CryptographicKey privateKey = rsaProvider.ImportPkcs8PrivateKey(privateKeyBuffer, out _); // 3. Encrypt the raw SHA1 hash with RSA private key + PKCS1 padding (matches Android's cipher.doFinal) IBuffer encryptedHash = CryptographicEngine.Encrypt(privateKey, rawSha1Hash, null); // 4. Convert encrypted data to Base64 string return CryptographicBuffer.EncodeToBase64String(encryptedHash); }
Key Adjustments Made
- Switched to
RsaPkcs1algorithm: This skips the ASN.1 wrapping and applies PKCS1 padding directly to the raw SHA1 hash, perfectly matching Android'sRSA/ECB/PKCS1Paddingbehavior. - Proper private key import: Used
ImportPkcs8PrivateKey(the standard format for RSA private keys exported from Android KeyStore). If yourkeyPairStringuses a different format (like PKCS#1), convert it to PKCS#8 first—you can do this in Android when exporting the key, or use a library like BouncyCastle. - Replaced signature logic: Swapped
CryptographicEngine.SignHashedDatawithCryptographicEngine.Encryptto perform raw private key encryption instead of standard signature generation.
Verification Tips
- Confirm both Android and UWP use the same RSA key length (e.g., 2048 bits)
- Validate the raw SHA1 hash first: Print the Base64 of
rawSha1Hashin UWP and compare it with Android'smessageDigestBase64 output to ensure they match - Double-check that your private key is in PKCS#8 format (Android's
KeyStorecan export keys in this format with proper export flags)
内容的提问来源于stack exchange,提问作者Trikutam Gargeya Sai Nikhil
相关产品推荐
相关产品推荐

