You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

RSA加密时出现‘句柄无效’问题求助

解决RSA加密时"The handle is not valid"错误

这个错误我之前也碰到过,核心问题就是你的RSAParameters没有被正确初始化——手动把PEM格式的密钥转成RSAParameters很容易踩坑:要么是没处理好PEM的头部尾部/换行符,要么是漏掉了Modulus、Exponent这类核心参数,甚至是字节顺序搞错了。下面给你两种靠谱的解决办法:

方法1:用.NET内置方法直接解析PEM(推荐)

从.NET Core 3.0+ / .NET 5+开始,框架已经原生支持PEM格式密钥的解析,完全不用手动折腾RSAParameters,代码简洁还不容易错:

解析公钥并加密

using System.Security.Cryptography;

// 你的PEM格式公钥字符串
string publicKeyPem = "-----BEGIN PUBLIC KEY-----\r\nMIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAsG5sBbnH7gXkrExzNOeK\r\nE...";

using RSA rsa = RSA.Create();
rsa.ImportFromPem(publicKeyPem);

// 加密文本
string plainText = "要加密的内容";
byte[] plainBytes = System.Text.Encoding.UTF8.GetBytes(plainText);
byte[] encryptedBytes = rsa.Encrypt(plainBytes, RSAEncryptionPadding.OaepSHA256);

// 转成Base64方便存储/传输
string encryptedText = Convert.ToBase64String(encryptedBytes);

解析私钥并解密

string privateKeyPem = "-----BEGIN PRIVATE KEY-----\r\n...";

using RSA rsa = RSA.Create();
rsa.ImportFromPem(privateKeyPem);

byte[] encryptedBytes = Convert.FromBase64String(encryptedText);
byte[] decryptedBytes = rsa.Decrypt(encryptedBytes, RSAEncryptionPadding.OaepSHA256);
string decryptedText = System.Text.Encoding.UTF8.GetString(decryptedBytes);

方法2:手动处理RSAParameters(适配旧版.NET)

如果你的项目还在用.NET Framework或者更早的版本,就得手动处理PEM的解析,但也别自己硬填RSAParameters字段,用框架的导入方法更稳妥:

  1. 先写个工具方法清理PEM格式,提取纯Base64内容:
private static byte[] ExtractKeyBytesFromPem(string pemString, string header, string footer)
{
    // 定位头部尾部,截取中间的Base64内容
    int startIndex = pemString.IndexOf(header) + header.Length;
    int endIndex = pemString.IndexOf(footer, startIndex);
    string cleanBase64 = pemString.Substring(startIndex, endIndex - startIndex)
                                  .Replace("\r", "")
                                  .Replace("\n", "");
    return Convert.FromBase64String(cleanBase64);
}
  1. 解析公钥(X.509格式)到RSAParameters:
byte[] publicKeyBytes = ExtractKeyBytesFromPem(_strPublicKey, "-----BEGIN PUBLIC KEY-----", "-----END PUBLIC KEY-----");
using RSA rsa = RSA.Create();
rsa.ImportSubjectPublicKeyInfo(publicKeyBytes, out _);
_publicKey = rsa.ExportParameters(false); // 导出公钥参数
  1. 解析私钥(PKCS#8格式)到RSAParameters:
byte[] privateKeyBytes = ExtractKeyBytesFromPem(_strPrivateKey, "-----BEGIN PRIVATE KEY-----", "-----END PRIVATE KEY-----");
using RSA rsa = RSA.Create();
rsa.ImportPkcs8PrivateKey(privateKeyBytes, out _);
_privateKey = rsa.ExportParameters(true); // 导出私钥参数

几个关键注意点

  • 别手动填充RSAParameters的各个字段!比如Modulus和Exponent要求是Big-Endian字节序,手动处理很容易搞反。
  • 确认密钥格式:如果私钥是BEGIN RSA PRIVATE KEY(PKCS#1格式),要改用ImportRSAPrivateKey方法,而不是ImportPkcs8PrivateKey。
  • 加密和解密必须用相同的填充模式,比如两边都用RSAEncryptionPadding.OaepSHA256,不然会解密失败。

内容的提问来源于stack exchange,提问作者Vivek Jeeva Kumar

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.21 08:31:35