JAVA加密解密之DH(Diffie-Hellman)算法

x33g5p2x  于2021-12-25 转载在 其他  
字(10.6k)|赞(0)|评价(0)|浏览(530)

DH算法简介

Diffie-Hellman算法(D-H算法),密钥一致协议。是由公开密钥密码体制的奠基人Diffie和Hellman所提出的一种思想。简单的说就是允许两名用户在公开媒体上交换信息以生成”一致”的、可以共享的密钥。换句话说,就是由甲方产出一对密钥(公钥、私钥),乙方依照甲方公钥产生乙方密钥对(公钥、私钥)。以此为基线,作为数据传输保密基础,同时双方使用同一种对称加密算法构建本地密钥(SecretKey)对数据加密。这样,在互通了本地密钥(SecretKey)算法后,甲乙双方公开自己的公钥,使用对方的公钥和刚才产生的私钥加密数据,同时可以使用对方的公钥和自己的私钥对数据解密。不单单是甲乙双方两方,可以扩展为多方共享数据通讯,这样就完成了网络交互数据的安全通讯!该算法源于中国的同余定理——中国馀数定理。

  1. 甲方构建密钥对儿,将公钥公布给乙方,将私钥保留;双方约定数据加密算法;乙方通过甲方公钥构建密钥对儿,将公钥公布给甲方,将私钥保留。
  2. 甲方使用私钥、乙方公钥、约定数据加密算法构建本地密钥,然后通过本地密钥加密数据,发送给乙方加密后的数据;乙方使用私钥、甲方公钥、约定数据加密算法构建本地密钥,然后通过本地密钥对数据解密。
  3. 乙方使用私钥、甲方公钥、约定数据加密算法构建本地密钥,然后通过本地密钥加密数据,发送给甲方加密后的数据;甲方使用私钥、乙方公钥、约定数据加密算法构建本地密钥,然后通过本地密钥对数据解密。

DH算法实现

  1. package com.jianggujin.codec;
  2. import java.io.InputStream;
  3. import java.io.OutputStream;
  4. import java.security.Key;
  5. import java.security.KeyFactory;
  6. import java.security.KeyPair;
  7. import java.security.KeyPairGenerator;
  8. import java.security.NoSuchAlgorithmException;
  9. import java.security.PublicKey;
  10. import java.security.spec.PKCS8EncodedKeySpec;
  11. import java.security.spec.X509EncodedKeySpec;
  12. import javax.crypto.Cipher;
  13. import javax.crypto.KeyAgreement;
  14. import javax.crypto.SecretKey;
  15. import javax.crypto.interfaces.DHPublicKey;
  16. import javax.crypto.spec.DHParameterSpec;
  17. import com.jianggujin.codec.util.JCipherInputStream;
  18. import com.jianggujin.codec.util.JCipherOutputStream;
  19. import com.jianggujin.codec.util.JCodecException;
  20. /** * Diffie-Hellman算法(D-H算法),密钥一致协议。是由公开密钥密码体制的奠基人Diffie和Hellman所提出的一种思想。 * 简单的说就是允许两名用户在公开媒体上交换信息以生成"一致"的、可以共享的密钥。换句话说,就是由甲方产出一对密钥(公钥、私钥), * 乙方依照甲方公钥产生乙方密钥对(公钥、私钥)。以此为基线,作为数据传输保密基础,同时双方使用同一种对称加密算法构建本地密钥(SecretKey)对数据加密 * 。这样,在互通了本地密钥(SecretKey)算法后,甲乙双方公开自己的公钥,使用对方的公钥和刚才产生的私钥加密数据, * 同时可以使用对方的公钥和自己的私钥对数据解密。不单单是甲乙双方两方,可以扩展为多方共享数据通讯,这样就完成了网络交互数据的安全通讯! * 该算法源于中国的同余定理——中国馀数定理 * <ol> * <li>甲方构建密钥对儿,将公钥公布给乙方,将私钥保留;双方约定数据加密算法;乙方通过甲方公钥构建密钥对儿,将公钥公布给甲方,将私钥保留。</li> * <li>甲方使用私钥、乙方公钥、约定数据加密算法构建本地密钥,然后通过本地密钥加密数据,发送给乙方加密后的数据;乙方使用私钥、甲方公钥、 * 约定数据加密算法构建本地密钥,然后通过本地密钥对数据解密。</li> * <li>乙方使用私钥、甲方公钥、约定数据加密算法构建本地密钥,然后通过本地密钥加密数据,发送给甲方加密后的数据;甲方使用私钥、乙方公钥、 * 约定数据加密算法构建本地密钥,然后通过本地密钥对数据解密。</li> * </ol> * * @author jianggujin * */
  21. public class JDH {
  22. private final static String ALGORITHM = "DH";
  23. /** * 对称算法 * * @author jianggujin * */
  24. public static enum JDHSymmetricalAlgorithm {
  25. DES, DESede;
  26. public String getName() {
  27. return this.name();
  28. }
  29. }
  30. /** * 初始化甲方密钥 * * @return */
  31. public static KeyPair initPartyAKey() {
  32. return initPartyAKey(1024);
  33. }
  34. /** * 初始化甲方密钥 * * @param keySize * @return */
  35. public static KeyPair initPartyAKey(int keySize) {
  36. try {
  37. KeyPairGenerator keyPairGen = KeyPairGenerator.getInstance(ALGORITHM);
  38. keyPairGen.initialize(keySize);
  39. return keyPairGen.generateKeyPair();
  40. } catch (NoSuchAlgorithmException e) {
  41. throw new JCodecException(e);
  42. }
  43. }
  44. /** * 初始化乙方密钥 * * @param partyAPublicKey * 甲方公钥 * @return */
  45. public static KeyPair initPartyBKey(byte[] partyAPublicKey) {
  46. try {
  47. X509EncodedKeySpec x509KeySpec = new X509EncodedKeySpec(partyAPublicKey);
  48. KeyFactory keyFactory = KeyFactory.getInstance(ALGORITHM);
  49. PublicKey pubKey = keyFactory.generatePublic(x509KeySpec);
  50. // 由甲方公钥构建乙方密钥
  51. DHParameterSpec dhParamSpec = ((DHPublicKey) pubKey).getParams();
  52. KeyPairGenerator keyPairGenerator = KeyPairGenerator.getInstance(keyFactory.getAlgorithm());
  53. keyPairGenerator.initialize(dhParamSpec);
  54. return keyPairGenerator.generateKeyPair();
  55. } catch (Exception e) {
  56. throw new JCodecException(e);
  57. }
  58. }
  59. /** * 加密 * * @param data * 加密数据 * @param privateKey * 己方私钥 * @param publicKey * 对方公钥 * @param algorithm * 对称算法 * @return */
  60. public static byte[] encrypt(byte[] data, byte[] privateKey, byte[] publicKey, String algorithm) {
  61. // 数据加密
  62. Cipher cipher = getEncryptCipher(privateKey, publicKey, algorithm);
  63. try {
  64. return cipher.doFinal(data);
  65. } catch (Exception e) {
  66. throw new JCodecException(e);
  67. }
  68. }
  69. /** * 包裹输出流,包裹后的输出流为加密输出流 * * @param out * @param privateKey * @param publicKey * @param algorithm * @return */
  70. public static OutputStream wrap(OutputStream out, byte[] privateKey, byte[] publicKey, String algorithm) {
  71. // 数据加密
  72. Cipher cipher = getEncryptCipher(privateKey, publicKey, algorithm);
  73. return new JCipherOutputStream(cipher, out);
  74. }
  75. /** * 获得加密模式的{@link Cipher} * * @param privateKey * @param publicKey * @param algorithm * @return */
  76. public static Cipher getEncryptCipher(byte[] privateKey, byte[] publicKey, String algorithm) {
  77. return getCipher(privateKey, publicKey, algorithm, Cipher.ENCRYPT_MODE);
  78. }
  79. /** * 解密 * * @param data * 解密数据 * @param privateKey * 己方私钥 * @param publicKey * 对方公钥 * @param algorithm * 对称算法 * @return */
  80. public static byte[] decrypt(byte[] data, byte[] privateKey, byte[] publicKey, String algorithm) {
  81. // 数据解密
  82. Cipher cipher = getDecryptCipher(privateKey, publicKey, algorithm);
  83. try {
  84. return cipher.doFinal(data);
  85. } catch (Exception e) {
  86. throw new JCodecException(e);
  87. }
  88. }
  89. /** * 包裹输入流,原输入流为加密数据输入流 * * @param in * @param privateKey * @param publicKey * @param algorithm * @return */
  90. public static InputStream wrap(InputStream in, byte[] privateKey, byte[] publicKey, String algorithm) {
  91. // 数据解密
  92. Cipher cipher = getDecryptCipher(privateKey, publicKey, algorithm);
  93. return new JCipherInputStream(cipher, in);
  94. }
  95. /** * 获得解密模式的{@link Cipher} * * @param privateKey * @param publicKey * @param algorithm * @return */
  96. public static Cipher getDecryptCipher(byte[] privateKey, byte[] publicKey, String algorithm) {
  97. return getCipher(privateKey, publicKey, algorithm, Cipher.DECRYPT_MODE);
  98. }
  99. private static Cipher getCipher(byte[] privateKey, byte[] publicKey, String algorithm, int opmode) {
  100. // 生成本地密钥
  101. SecretKey secretKey = getSecretKey(privateKey, publicKey, algorithm);
  102. try {
  103. // 数据加密
  104. Cipher cipher = Cipher.getInstance(secretKey.getAlgorithm());
  105. cipher.init(opmode, secretKey);
  106. return cipher;
  107. } catch (Exception e) {
  108. throw new JCodecException(e);
  109. }
  110. }
  111. /** * 获得密钥 * * @param privateKey * 己方私钥 * @param publicKey * 对方公钥 * @param algorithm * 对称算法 * @return */
  112. private static SecretKey getSecretKey(byte[] privateKey, byte[] publicKey, String algorithm) {
  113. try {
  114. KeyFactory keyFactory = KeyFactory.getInstance(ALGORITHM);
  115. X509EncodedKeySpec x509KeySpec = new X509EncodedKeySpec(publicKey);
  116. PublicKey pubKey = keyFactory.generatePublic(x509KeySpec);
  117. PKCS8EncodedKeySpec pkcs8KeySpec = new PKCS8EncodedKeySpec(privateKey);
  118. Key priKey = keyFactory.generatePrivate(pkcs8KeySpec);
  119. KeyAgreement keyAgree = KeyAgreement.getInstance(keyFactory.getAlgorithm());
  120. keyAgree.init(priKey);
  121. keyAgree.doPhase(pubKey, true);
  122. // 生成本地密钥
  123. return keyAgree.generateSecret(algorithm);
  124. } catch (Exception e) {
  125. throw new JCodecException(e);
  126. }
  127. }
  128. }

测试代码:

  1. package com.jianggujin.codec.test;
  2. import java.io.File;
  3. import java.io.FileInputStream;
  4. import java.io.FileOutputStream;
  5. import java.io.InputStream;
  6. import java.io.OutputStream;
  7. import java.security.KeyPair;
  8. import org.junit.Test;
  9. import com.jianggujin.codec.JBase64;
  10. import com.jianggujin.codec.JBase64.JEncoder;
  11. import com.jianggujin.codec.JDH;
  12. import com.jianggujin.codec.JDH.JDHSymmetricalAlgorithm;
  13. public class DHTest {
  14. String str = "jianggujin";
  15. File file = new File(getClass().getSimpleName() + ".dat");
  16. @Test
  17. public void test() throws Exception {
  18. System.out.println("原串:" + str);
  19. JEncoder encoder = JBase64.getEncoder();
  20. KeyPair keyPairA = JDH.initPartyAKey();
  21. byte[] keyPairAPrivate = keyPairA.getPrivate().getEncoded();
  22. byte[] keyPairAPublic = keyPairA.getPublic().getEncoded();
  23. System.out.println("甲方私钥:" + encoder.encodeToString(keyPairAPrivate, "UTF-8"));
  24. System.out.println("甲方公钥:" + encoder.encodeToString(keyPairAPublic, "UTF-8"));
  25. KeyPair keyPairB = JDH.initPartyBKey(keyPairAPublic);
  26. byte[] keyPairBPrivate = keyPairB.getPrivate().getEncoded();
  27. byte[] keyPairBPublic = keyPairB.getPublic().getEncoded();
  28. System.out.println("乙方私钥:" + encoder.encodeToString(keyPairBPrivate, "UTF-8"));
  29. System.out.println("乙方公钥:" + encoder.encodeToString(keyPairBPublic, "UTF-8"));
  30. for (JDHSymmetricalAlgorithm algorithm : JDHSymmetricalAlgorithm.values()) {
  31. System.out.println("-----------------------------------------");
  32. System.out.println("对称算法:" + algorithm.getName());
  33. byte[] encrypt = JDH.encrypt(str.getBytes(), keyPairAPrivate, keyPairBPublic, algorithm.getName());
  34. System.out.println("加密:" + encoder.encodeToString(encrypt, "UTF-8"));
  35. System.out
  36. .println("解密:" + new String(JDH.decrypt(encrypt, keyPairBPrivate, keyPairAPublic, algorithm.getName())));
  37. System.out.print("输出流加密:" + file.getAbsolutePath());
  38. OutputStream out = JDH.wrap(new FileOutputStream(file), keyPairAPrivate, keyPairBPublic, algorithm.getName());
  39. out.write(str.getBytes());
  40. out.flush();
  41. out.close();
  42. System.out.println();
  43. System.out.print("输入流解密:");
  44. InputStream in = JDH.wrap(new FileInputStream(file), keyPairBPrivate, keyPairAPublic, algorithm.getName());
  45. byte[] buffer = new byte[1024];
  46. int len = in.read(buffer);
  47. System.out.println(new String(buffer, 0, len));
  48. }
  49. }
  50. }

测试结果:
原串:jianggujin
甲方私钥:MIIBZwIBADCCARsGCSqGSIb3DQEDATCCAQwCgYEA/X9TgR11EilS30qcLuzk5/YRt1I870QAwx4/gLZRJmlFXUAiUftZPY1Y+r/F9bow9subVWzXgTuAHTRv8mZgt2uZUKWkn5/oBHsQIsJPu6nX/rfGG/g7V+fGqKYVDwT7g/bTxR7DAjVUE1oWkTL2dfOuK2HXKu/yIgMZndFIAccCgYEA9+GghdabPd7LvKtcNrhXuXmUr7v6OuqC+VdMCz0HgmdRWVeOutRZT+ZxBxCBgLRJFnEj6EwoFhO3zwkyjMim4TwWeotUfI0o4KOuHiuzpnWRbqN/C/ohNWLx+2J6ASQ7zKTxvqhRkImog9/hWuWfBpKLZl6Ae1UlZAFMO/7PSSoCAgIABEMCQQCKZ/IM4bTS0YkWGsMGFY6NAAICuvHpvhSBaPZ3Le4PS/owyrEnsiS3AXig5OYYko/fVvIBz1kOaKTl/0tsQLtt
甲方公钥:MIIBpzCCARsGCSqGSIb3DQEDATCCAQwCgYEA/X9TgR11EilS30qcLuzk5/YRt1I870QAwx4/gLZRJmlFXUAiUftZPY1Y+r/F9bow9subVWzXgTuAHTRv8mZgt2uZUKWkn5/oBHsQIsJPu6nX/rfGG/g7V+fGqKYVDwT7g/bTxR7DAjVUE1oWkTL2dfOuK2HXKu/yIgMZndFIAccCgYEA9+GghdabPd7LvKtcNrhXuXmUr7v6OuqC+VdMCz0HgmdRWVeOutRZT+ZxBxCBgLRJFnEj6EwoFhO3zwkyjMim4TwWeotUfI0o4KOuHiuzpnWRbqN/C/ohNWLx+2J6ASQ7zKTxvqhRkImog9/hWuWfBpKLZl6Ae1UlZAFMO/7PSSoCAgIAA4GFAAKBgQClQTWNc/3DBQQvs/KHwJ6CC9lYT2Cr2NdSHBUFiCuAUhQ7vpEgzL14IrhqJqixtMuOKOAOUOFBipavJTwhXNnviRNHQ0TJ1l+2ZNQaXHLQdpkBSl5E0fR7DRigbHUeNso52ZrNkDpyR0d7a6XQQRw9Ffig1ZujtO2+D7Ka2F8EJg==
乙方私钥:MIIBZwIBADCCARsGCSqGSIb3DQEDATCCAQwCgYEA/X9TgR11EilS30qcLuzk5/YRt1I870QAwx4/gLZRJmlFXUAiUftZPY1Y+r/F9bow9subVWzXgTuAHTRv8mZgt2uZUKWkn5/oBHsQIsJPu6nX/rfGG/g7V+fGqKYVDwT7g/bTxR7DAjVUE1oWkTL2dfOuK2HXKu/yIgMZndFIAccCgYEA9+GghdabPd7LvKtcNrhXuXmUr7v6OuqC+VdMCz0HgmdRWVeOutRZT+ZxBxCBgLRJFnEj6EwoFhO3zwkyjMim4TwWeotUfI0o4KOuHiuzpnWRbqN/C/ohNWLx+2J6ASQ7zKTxvqhRkImog9/hWuWfBpKLZl6Ae1UlZAFMO/7PSSoCAgIABEMCQQDfg2OOQ+Rz4eRaatC0AKhNtA5i7KIrss7uM7Vtv2ls7zRCKWwXP5nRdbZAlO96tS1vF9AIZsYI82e8fQSBVfbX
乙方公钥:MIIBpjCCARsGCSqGSIb3DQEDATCCAQwCgYEA/X9TgR11EilS30qcLuzk5/YRt1I870QAwx4/gLZRJmlFXUAiUftZPY1Y+r/F9bow9subVWzXgTuAHTRv8mZgt2uZUKWkn5/oBHsQIsJPu6nX/rfGG/g7V+fGqKYVDwT7g/bTxR7DAjVUE1oWkTL2dfOuK2HXKu/yIgMZndFIAccCgYEA9+GghdabPd7LvKtcNrhXuXmUr7v6OuqC+VdMCz0HgmdRWVeOutRZT+ZxBxCBgLRJFnEj6EwoFhO3zwkyjMim4TwWeotUfI0o4KOuHiuzpnWRbqN/C/ohNWLx+2J6ASQ7zKTxvqhRkImog9/hWuWfBpKLZl6Ae1UlZAFMO/7PSSoCAgIAA4GEAAKBgDtzbZB/0vIobewwv7mUGGS54TBuNGf6wl3lLsAfTKylvzD2//qPqTJVXBGy9ZInHMYOwLb5nn85l8oULoXsp0uwZe2cFpmgJfRFpRD2FH+ZahBbtb7zgdsB30t0y42Qed+bL/o8znzv5yE1E6/z2iQdKhCRc52254hWgUVDkrH5
—————————————–
对称算法:DES
加密:zBJhlhWDFme0qIlClaBUQw==
解密:jianggujin
输出流加密:F:\workspace\java\eclipse\JCodec\DHTest.dat
输入流解密:jianggujin
—————————————–
对称算法:DESede
加密:0TFsnTdcA3JuJH2ZYn1ZcQ==
解密:jianggujin
输出流加密:F:\workspace\java\eclipse\JCodec\DHTest.dat
输入流解密:jianggujin

相关文章