RSA密码短语加密底层原理及.ssh私钥密码短语填充方式咨询
Let's start with the big picture: RSA itself is an asymmetric encryption algorithm, but storing your raw RSA private key as plaintext is a huge security risk. That's where passphrase encryption comes in—it wraps your private key with symmetric encryption (like the AES128-CBC you saw in your id_rsa file) to keep it safe when it's sitting on disk.
Here's the step-by-step breakdown:
- When you generate an RSA key pair with a passphrase, the system doesn't just use the passphrase directly as an encryption key (passphrases are usually too short or weak for that). Instead, it uses a key derivation function (KDF) to turn your passphrase into a strong, fixed-length symmetric key.
- The raw RSA private key (which includes components like the modulus, private exponent, and primes) is then encrypted using this symmetric key and the specified algorithm (AES128-CBC in your case), along with a random initialization vector (IV) to ensure identical plaintexts encrypt to different ciphertexts.
- All these pieces—encrypted private key, encryption algorithm, IV, salt (used in the KDF), and a message authentication code (MAC) for integrity checking—are bundled together and stored in your id_rsa file.
- When you enter your passphrase to use the key, the reverse happens: the KDF uses your passphrase and the stored salt to regenerate the same symmetric key, then AES128-CBC decrypts the encrypted private key using that key and the stored IV. The MAC verifies that the decrypted private key is valid (so you know you entered the right passphrase).
The key derivation function used here is almost always PBKDF2 (Password-Based Key Derivation Function 2), which adds computational cost (via iterative hashing) to make brute-force attacks on the passphrase much harder.
Let's clarify something first: your passphrase itself isn't "padded" for use in the decryption process. Instead, the passphrase is transformed into a valid AES key via PBKDF2, and the padding applies to the raw RSA private key data before it's encrypted. Here's the details:
Passphrase to Key Conversion:
- Your passphrase is first converted to a byte sequence using UTF-8 encoding (this is the standard in SSH).
- PBKDF2 takes this byte sequence, plus a random salt (stored in your id_rsa file—you might not have noticed it, but it's part of the file's structure), and runs multiple rounds of hashing (default is 1000 iterations in older SSH versions, more in newer ones) with a hash algorithm like SHA-1 or SHA-256. This outputs a fixed-length key exactly matching the requirements of your AES variant (16 bytes for AES128).
Private Key Padding for AES-CBC:
- AES-CBC is a block cipher, meaning it encrypts data in fixed-size blocks (16 bytes for AES). The raw RSA private key data might not be a multiple of this block size, so it needs padding before encryption.
- SSH uses PKCS#7 padding for this: if the plaintext is N bytes short of a full block, we add N bytes each with the value N. For example, if the last block is 13 bytes long (3 bytes short), we add three 0x03 bytes. When decrypting, the padding is stripped off by checking the last byte's value and removing that many bytes from the end.
So to recap: your passphrase doesn't get padded—instead, it's turned into a proper AES key via PBKDF2. The padding you're thinking about applies to the private key data before encryption, using PKCS#7 standards.
内容的提问来源于stack exchange,提问作者AznBoyStride

