RSA随机密钥加密

 前端加密用户名和密码,后端代码获取参数后解密得到真实用户名再查询用户

package com.guiyang.education.utils;

import org.apache.commons.codec.binary.Base64;
import javax.crypto.Cipher;
import java.security.KeyFactory;
import java.security.KeyPair;
import java.security.KeyPairGenerator;
import java.security.NoSuchAlgorithmException;
import java.security.SecureRandom;
import java.security.interfaces.RSAPrivateKey;
import java.security.interfaces.RSAPublicKey;
import java.security.spec.PKCS8EncodedKeySpec;
import java.security.spec.X509EncodedKeySpec;
import java.util.HashMap;
import java.util.Map;

public class RSAEncryptUtil {

    private static Map keyMap = new HashMap();  //用于封装随机产生的公钥与私钥

    /**
     * 随机生成密钥对
     * @throws NoSuchAlgorithmException
     */
    public static Map genKeyPair(){
        try {
            keyMap = new HashMap();
            // KeyPairGenerator类用于生成公钥和私钥对,基于RSA算法生成对象
            KeyPairGenerator keyPairGen = KeyPairGenerator.getInstance("RSA");
            // 初始化密钥对生成器,密钥大小为96-1024位
            keyPairGen.initialize(1024, new SecureRandom());
            // 生成一个密钥对,保存在keyPair中
            KeyPair keyPair = keyPairGen.generateKeyPair();
            RSAPrivateKey privateKey = (RSAPrivateKey) keyPair.getPrivate();   // 得到私钥
            RSAPublicKey publicKey = (RSAPublicKey) keyPair.getPublic();  // 得到公钥
            String publicKeyString = new String(Base64.encodeBase64(publicKey.getEncoded()));
            // 得到私钥字符串
            String privateKeyString = new String(Base64.encodeBase64((privateKey.getEncoded())));
            // 将公钥和私钥保存到Map
            keyMap.put(0, publicKeyString);  //0表示公钥
            keyMap.put(1, privateKeyString);  //1表示私钥
        }catch (Exception e){
            e.printStackTrace();
        }
        return keyMap;
    }
    /**
     * RSA公钥加密
     *
     * @param str
     *            加密字符串
     * @param publicKey
     *            公钥
     * @return 密文
     * @throws Exception
     *             加密过程中的异常信息
     */
    public static String encrypt( String str, String publicKey ) throws Exception{
        //base64编码的公钥
        byte[] decoded = Base64.decodeBase64(publicKey);
        RSAPublicKey pubKey = (RSAPublicKey) KeyFactory.getInstance("RSA").generatePublic(new X509EncodedKeySpec(decoded));
        //RSA加密
        Cipher cipher = Cipher.getInstance("RSA");
        cipher.init(Cipher.ENCRYPT_MODE, pubKey);
        String outStr = Base64.encodeBase64String(cipher.doFinal(str.getBytes("UTF-8")));
        return outStr;
    }

    /**
     * RSA私钥解密
     *
     * @param str
     *            加密字符串
     * @param privateKey
     *            私钥
     * @return 铭文
     * @throws Exception
     *             解密过程中的异常信息
     */
    public static String decrypt(String str, String privateKey) throws Exception{
        //64位解码加密后的字符串
        byte[] inputByte = Base64.decodeBase64(str.getBytes("UTF-8"));
        //base64编码的私钥
        byte[] decoded = Base64.decodeBase64(privateKey);
        RSAPrivateKey priKey = (RSAPrivateKey) KeyFactory.getInstance("RSA").generatePrivate(new PKCS8EncodedKeySpec(decoded));
        //RSA解密
        Cipher cipher = Cipher.getInstance("RSA");
        cipher.init(Cipher.DECRYPT_MODE, priKey);
        String outStr = new String(cipher.doFinal(inputByte));
        return outStr;
    }

}

//登录
$(".login").on('click',".ok_submit",function(){
    var login_name = $.trim($("#login_name").val());
    if(login_name != '' && login_name != null){
        var password = $.trim($("#password").val());
        if(password != '' && password != null){
            var loginName="";
            var pwd="";
            $.ajax({
                type: "POST",
                url: "${resource}loginEncrypt",
                data: {"login_name":login_name,"password":$.md5(password)},
                dataType: "json",
                async: false,
                success: function(data){
                    loginName=data.login_name;
                    pwd=data.password;
                }
            });

            $.ajax({
                type: "POST",
                url: "${resource}doLogin",
                data: {"login_name":loginName,"password":pwd},
                dataType: "json",
                success: function(data){
                    if(data.status==0){
                        loginStatus=1;
                        setUser();
                        $(".login").hide();
                        $(".logined").show();
                        location.href='${resource}';
                    }else{
                        layer.msg(data.result);
                        return false;
                    }
                }
            });
        }else{
            layer.open({
                content : "请输入密码",
                btn : [ "确定" ],
                shadeClose : false,
                yes : function(index) {
                    layer.close(index);
                }
            });
            return false;
        }
    }else{
        layer.open({
            content : "请输入用户名",
            btn : [ "确定" ],
            shadeClose : false,
            yes : function(index) {
                layer.close(index);
            }
        });
        return false;
    }
})

你可能感兴趣的:(Java,安全,RSA加密)