You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Spring Boot 4如何通过高级API实现跨服务确定性字符串加密?

实现Spring Boot 4中的确定性字符串加密(无需底层Cipher操作)

问题背景

当前使用Spring Security的Encryptors.text()实现加密,但该方法默认使用随机初始化向量(IV),导致相同明文每次加密结果不同,无法满足卡号场景的UNIQUE约束和基于加密卡号的查询需求。需要一种仅通过高级API(不直接使用javax.crypto.Cipher)实现的跨服务器运行的确定性加密方案。

解决方案

方案一:基于Spring Security构建确定性TextEncryptor

通过Spring Security提供的AesBytesEncryptor自定义加密器,指定固定IV来实现确定性加密,全程无需接触底层Cipher类。

  1. 修改Spring Security配置类,替换原有TextEncryptor Bean:
import com.example.em_card_service.data.properties.EncryptionProperties;
import lombok.RequiredArgsConstructor;
import org.springframework.context.annotation.Bean;
import org.springframework.context.annotation.Configuration;
import org.springframework.security.crypto.encrypt.AesBytesEncryptor;
import org.springframework.security.crypto.encrypt.TextEncryptor;
import org.springframework.security.crypto.encrypt.Encryptors;

@Configuration
@RequiredArgsConstructor
public class SecurityConfig {

    private final EncryptionProperties encryptionProperties;

    @Bean
    public TextEncryptor deterministicTextEncryptor() {
        // 从配置中读取固定IV(需为16字节的十六进制字符串)
        String fixedIv = encryptionProperties.getFixedIv();
        
        // 创建AES字节加密器,指定固定IV与GCM算法(兼顾安全与效率)
        AesBytesEncryptor bytesEncryptor = new AesBytesEncryptor(
                encryptionProperties.getPassword(),
                encryptionProperties.getSalt(),
                AesBytesEncryptor.CipherAlgorithm.GCM,
                fixedIv
        );
        
        // 封装为TextEncryptor,自动处理字符串编解码
        return Encryptors.text(bytesEncryptor);
    }
}
  1. 在配置文件中添加固定IV参数(示例为application.properties):
encryption.password=your-32-byte-strong-hex-password
encryption.salt=your-16-byte-hex-salt
encryption.fixed-iv=your-16-byte-hex-fixed-iv

方案二:使用Jasypt Spring Boot Starter(极简配置)

Jasypt提供开箱即用的高级加密API,通过简单配置即可实现确定性加密,完全无需底层操作。

  1. 添加Maven依赖(适配Spring Boot 4的版本):
<dependency>
    <groupId>com.github.ulisesbocchio</groupId>
    <artifactId>jasypt-spring-boot-starter</artifactId>
    <version>3.0.5</version>
</dependency>
  1. 配置application.properties:
# 加密密钥
jasypt.encryptor.password=your-strong-encryption-password
# 使用安全的AES算法
jasypt.encryptor.algorithm=PBEWithHMACSHA512AndAES_256
# 禁用随机IV,实现确定性加密
jasypt.encryptor.iv-generator-classname=org.jasypt.iv.NoIvGenerator
# 密文输出格式为十六进制
jasypt.encryptor.string-output-type=hexadecimal
  1. 注入StringEncryptor直接使用:
import org.jasypt.encryption.StringEncryptor;
import org.springframework.stereotype.Service;

@Service
public class CardEncryptionService {

    private final StringEncryptor encryptor;

    public CardEncryptionService(StringEncryptor encryptor) {
        this.encryptor = encryptor;
    }

    // 加密卡号
    public String encryptCardNumber(String cardNumber) {
        return encryptor.encrypt(cardNumber);
    }

    // 解密卡号
    public String decryptCardNumber(String encryptedCardNumber) {
        return encryptor.decrypt(encryptedCardNumber);
    }
}

注意事项

  • 固定IV仅适用于需要确定性加密的场景(如卡号),需确保密钥、盐、IV的安全性,避免泄露。
  • GCM算法是推荐的安全选择,相比ECB模式更安全,同时支持确定性加密。
  • Jasypt方案配置更简洁,适合快速实现;Spring Security方案则更贴合现有Spring生态。

内容的提问来源于stack exchange,提问作者Sergey Zolotarev

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.02 02:24:54