You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

基于Botan C++库加载RSA私钥实现license.ini签名验证问询

使用Botan C++库实现license.ini的RSA-PKCS#1 v1.5签名与验证

我基于你提到的需求,整理了一套完整的实现方案,包含文件内容读取、RSA签名生成以及签名验证的全流程,每一步都做了详细注释,方便你参考:

完整代码实现

#include <Botan/RSA.h>
#include <Botan/PK_Signer.h>
#include <Botan/PK_Verifier.h>
#include <Botan/auto_rng.h>
#include <Botan/hex.h>
#include <fstream>
#include <string>
#include <vector>

// 读取文件内容的辅助函数
std::string readFileContent(const std::string& filePath) {
    std::ifstream file(filePath, std::ios::binary);
    if (!file.is_open()) {
        throw std::runtime_error("Failed to open file: " + filePath);
    }
    return std::string((std::istreambuf_iterator<char>(file)), std::istreambuf_iterator<char>());
}

int main(int argc, char* argv[]) {
    if (argc < 2) {
        std::cerr << "Usage: " << argv[0] << " <path_to_license.ini>" << std::endl;
        return 1;
    }

    try {
        // -------------------------- 签名流程 --------------------------
        // 1. 读取待签名的license文件内容
        std::string licensePath = argv[1];
        std::string fileContents = readFileContent(licensePath);

        // 2. 加载RSA私钥(注意:实际项目中请勿硬编码私钥,建议从加密文件/密钥管理系统读取)
        const uint8_t private_key[] = "你的RSA私钥内容(PEM格式)";
        Botan::DataSource_Memory priv_key_src(private_key, sizeof(private_key) - 1);
        std::unique_ptr<Botan::Private_Key> rsa_priv_key(Botan::PKCS8::load_key(priv_key_src));

        // 3. 初始化签名器:采用RSA+PKCS#1 v1.5填充,搭配SHA-256哈希算法
        Botan::AutoSeeded_RNG rng;
        Botan::PK_Signer signer(*rsa_priv_key, rng, "SHA-256/PKCS1v15");

        // 4. 对文件内容进行签名
        signer.update(reinterpret_cast<const uint8_t*>(fileContents.data()), fileContents.size());
        Botan::secure_vector<uint8_t> signature = signer.signature(rng);

        // 可选:将签名转换为十六进制字符串方便存储/传输
        std::string signature_hex = Botan::hex_encode(signature);
        std::cout << "Generated signature (hex): " << signature_hex << std::endl;

        // -------------------------- 验证流程 --------------------------
        // 1. 加载RSA公钥(同样建议从安全渠道读取,而非硬编码)
        const uint8_t public_key[] = "你的RSA公钥内容(PEM格式)";
        Botan::DataSource_Memory pub_key_src(public_key, sizeof(public_key) - 1);
        std::unique_ptr<Botan::Public_Key> rsa_pub_key(Botan::X509::load_key(pub_key_src));

        // 2. 初始化验证器:与签名流程使用相同的哈希算法和填充方式
        Botan::PK_Verifier verifier(*rsa_pub_key, "SHA-256/PKCS1v15");

        // 3. 验证签名
        verifier.update(reinterpret_cast<const uint8_t*>(fileContents.data()), fileContents.size());
        bool is_valid = verifier.check_signature(signature);

        if (is_valid) {
            std::cout << "Signature verification passed! License is authentic." << std::endl;
        } else {
            std::cerr << "Signature verification failed! License may be tampered." << std::endl;
        }
    } catch (const std::exception& e) {
        std::cerr << "Error: " << e.what() << std::endl;
        return 1;
    }

    return 0;
}

关键注意事项

  • 密钥安全:绝对不要在代码中硬编码私钥,实际项目中建议使用加密的密钥文件,或者借助专业的密钥管理服务来加载密钥,防止私钥泄露。
  • 哈希算法选择:示例中使用SHA-256,这是当前安全性较高的选择;如果必须兼容旧系统,可替换为SHA-1,但SHA-1已被证实存在安全漏洞,不推荐。
  • 填充方式匹配:签名和验证必须使用完全一致的填充方式和哈希算法,否则验证一定会失败。这里我们明确指定SHA-256/PKCS1v15,确保两端配置统一。
  • 异常处理:Botan库在操作失败时会抛出异常,务必做好异常捕获和处理,避免程序崩溃。

内容的提问来源于stack exchange,提问作者Petar Mijović

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.22 10:02:41