RSA 2048 前端 jsencrypt 公钥加密 后端 java私钥解密

加密流程:

1.客户端GET请求java 后端Controller
2.java 后端 Controller读取公钥内容发送到前端
3.前端获取到公钥使用JSEncrypt加密
4.将加密以后的数据发送到后端
5.后端通过私钥解密字段

需要的工具:

前端加密JSEncrypt 下载:
https://github.com/travist/jsencrypt

后端需要 code

    <dependency>
       <groupId>org.bouncycastle</groupId>
       <artifactId>bcprov-jdk15on</artifactId>
       <version>1.66</version>
    </dependency>

前端代码

<html lang="en" xmlns:th="http://www.thymeleaf.org">
<head>
    <meta http-equiv="Content-Type" content="text/html; charset=utf-8" />
    <title>登录</title>
    <script th:src="@{/jsencrypt.js}" type="text/javascript"></script>
    <script th:src="@{/jquery.js}" type="text/javascript"></script>
    <script type="text/javascript" th:inline="javascript">
        $(function() {
            $('#testme').click(function() {
                var pubkey = [[${publicKey}]];
                console.log(pubkey);
                var encrypt = new JSEncrypt();
                encrypt.setPublicKey(pubkey);
                var encrypted = encrypt.encrypt($('#input').val());
                console.log(encrypted);
                $.post("/page/logins", {"payload":encrypted} );
            });
        });
    </script>
</head>
<body>
<label for="input">Text to encrypt:</label><br/>
<textarea id="input" name="input" type="text" rows=4 cols=70>This is a test!</textarea><br/>
<input id="testme" type="button" value="Test Me!!!" /><br/>

</body>
</html>

后端代码

Controller 接收代码

package org.lbyang.controller.page;

import org.kong.controller.util.RSAUtils;
import org.springframework.stereotype.Controller;
import org.springframework.web.bind.annotation.GetMapping;
import org.springframework.web.bind.annotation.PostMapping;
import org.springframework.web.bind.annotation.RequestMapping;
import org.springframework.web.servlet.ModelAndView;
import sun.misc.BASE64Encoder;

import java.security.PrivateKey;

/**
 * @Author: libo
 * @Date: 2020/8/6
 */
@Controller
@RequestMapping("/page")
public class PageController {
    @GetMapping("/login")
    public ModelAndView login(){
        ModelAndView modelAndView = new ModelAndView("loginpage2");
        String publicKeyFileName =getClass().getResource("/rsaPublicKey.txt").getFile();
        //String publicKeyFileNameCer =getClass().getResource("/sso-form-qat-pubic.cer").getFile();
        try{
            //byte[] encoded=RSAUtils.getPublicKeyFromCer(publicKeyFileName).getEncoded();
            //BASE64Encoder base64ecoder = new BASE64Encoder();
            //modelAndView.addObject("publicKey",RSAUtils.base64ecoder.encode(encoded));
            modelAndView.addObject("publicKey",RSAUtils.readRSAKeyPem(publicKeyFileName));
        }catch (Exception ex){
            ex.printStackTrace();
        }

        return modelAndView;
    }

    @PostMapping("/logins")
    public String postlogin(String payload) throws Exception {
        System.out.println(payload);
        RSAUtils(payload);
        return "loginpage2";
    }

    private void RSAUtils(String payload) throws Exception {
        String privateKeyFileName =getClass().getResource("/rsaPrivateKey.txt").getFile();
        PrivateKey privateKeyFromPem = RSAUtils.getPrivateKeyFromPem(privateKeyFileName);
        BASE64Encoder base64ecoder = new BASE64Encoder();
        String decrypt = RSAUtils.decrypt(payload, base64ecoder.encode(privateKeyFromPem.getEncoded()));
        System.out.println(decrypt);
    }
}


RSA 工具类

package org.lbyang.util;

import javax.crypto.Cipher;
import java.io.BufferedReader;
import java.io.FileInputStream;
import java.io.FileReader;
import java.security.*;
import java.security.cert.CertificateFactory;
import java.security.cert.X509Certificate;
import java.security.interfaces.RSAPrivateKey;
import java.security.interfaces.RSAPublicKey;
import java.security.spec.PKCS8EncodedKeySpec;
import java.security.spec.X509EncodedKeySpec;
import sun.misc.BASE64Decoder;
import sun.misc.BASE64Encoder;

/**
 * @Author: lbyang
 * @Date: 2020/8/10
 */
public class RSAUtils {
    private static final String KEY_ALGORITHM = "RSA";

    public static final String SIGNATURE_ALGORITHM = "MD5withRSA";

    private static final String UTF_8="UTF-8";

    public static final Provider provider = new org.bouncycastle.jce.provider.BouncyCastleProvider();
    private static BASE64Decoder base64decoder = new BASE64Decoder();
    private static BASE64Encoder base64ecoder = new BASE64Encoder();
    static {
        Security.addProvider(provider);
    }

    public static String readRSAKeyPem(String keypath) throws Exception{
        BufferedReader br = new BufferedReader(new FileReader(keypath));
        String s = br.readLine();
        String str = "";
        s = br.readLine();
        while (s.charAt(0) != '-') {
            str += s + "\r";
            s = br.readLine();
        }

        return str;
    }

    public static PrivateKey getPrivateKeyFromPem(String privateKeyPath) throws Exception {
        byte[] b = base64decoder.decodeBuffer(readRSAKeyPem(privateKeyPath));
        KeyFactory kf = KeyFactory.getInstance(KEY_ALGORITHM);
        PKCS8EncodedKeySpec keySpec = new PKCS8EncodedKeySpec(b);
        return kf.generatePrivate(keySpec);
    }

    public static PublicKey getPublicKeyFromCer(String cerPath) throws Exception{
        CertificateFactory certificatefactory = CertificateFactory.getInstance("X.509");
        FileInputStream fis = new FileInputStream(cerPath);
        X509Certificate Cert = (X509Certificate) certificatefactory.generateCertificate(fis);
        return  Cert.getPublicKey();
    }

    public static PublicKey getPublicKeyFromPem(String publicKeyPath) throws Exception{
        byte[] b = base64decoder.decodeBuffer(readRSAKeyPem(publicKeyPath));
        KeyFactory kf = KeyFactory.getInstance(KEY_ALGORITHM);
        X509EncodedKeySpec keySpec = new X509EncodedKeySpec(b);
        return kf.generatePublic(keySpec);
    }

    public static String encrypt(String str, String publicKey) throws Exception{
        byte[] decoded=base64decoder.decodeBuffer(publicKey);
        RSAPublicKey pubKey = (RSAPublicKey) KeyFactory.getInstance(KEY_ALGORITHM).generatePublic(new X509EncodedKeySpec(decoded));
        Cipher cipher = Cipher.getInstance(KEY_ALGORITHM);
        cipher.init(Cipher.ENCRYPT_MODE, pubKey);
        return base64ecoder.encode(cipher.doFinal(str.getBytes(UTF_8)));
    }

    public static String decrypt(String str, String privateKey) throws Exception{
        byte[] inputByte = base64decoder.decodeBuffer(str);
        byte[] decoded= base64decoder.decodeBuffer(privateKey);

        RSAPrivateKey priKey = (RSAPrivateKey) KeyFactory.getInstance(KEY_ALGORITHM).generatePrivate(new PKCS8EncodedKeySpec(decoded));
        Cipher cipher = Cipher.getInstance(KEY_ALGORITHM);
        cipher.init(Cipher.DECRYPT_MODE, priKey);
        return new String(cipher.doFinal(inputByte));
    }


    public static void genKeyPair() throws Exception {
        KeyPairGenerator keyPairGen = KeyPairGenerator.getInstance(KEY_ALGORITHM);
        keyPairGen.initialize(1024);
        KeyPair keyPair = keyPairGen.generateKeyPair();
        RSAPublicKey publicKey = (RSAPublicKey) keyPair.getPublic();
        RSAPrivateKey privateKey = (RSAPrivateKey) keyPair.getPrivate();
        System.out.println("public key:"+new String(publicKey.getEncoded(),UTF_8));
        System.out.println("private key:"+new String(privateKey.getEncoded(),UTF_8));
    }

    public static String sign(byte[] data, String privateKey) throws Exception {
        byte[] keyBytes = base64decoder.decodeBuffer(privateKey);
        PKCS8EncodedKeySpec pkcs8KeySpec = new PKCS8EncodedKeySpec(keyBytes);
        KeyFactory keyFactory = KeyFactory.getInstance(KEY_ALGORITHM);
        PrivateKey privateK = keyFactory.generatePrivate(pkcs8KeySpec);
        Signature signature = Signature.getInstance(SIGNATURE_ALGORITHM);
        signature.initSign(privateK);
        signature.update(data);
        return base64ecoder.encode(signature.sign());
    }

    public static boolean verify(byte[] data, String publicKey, String sign)
            throws Exception {
        byte[] keyBytes = base64decoder.decodeBuffer(publicKey);
        X509EncodedKeySpec keySpec = new X509EncodedKeySpec(keyBytes);
        KeyFactory keyFactory = KeyFactory.getInstance(KEY_ALGORITHM);
        PublicKey publicK = keyFactory.generatePublic(keySpec);
        Signature signature = Signature.getInstance(SIGNATURE_ALGORITHM);
        signature.initVerify(publicK);
        signature.update(data);
        return signature.verify(base64decoder.decodeBuffer(sign));
    }

    public static void main(String[] args) {
        try{
//            String privateKeyFileName = "/Users/mac/Documents/javawork/kong-gateway/kong-controller/src/main/resources/rsaPrivateKey.txt";
//            String publicKeyFileName = "/Users/mac/Documents/javawork/kong-gateway/kong-controller/src/main/resources/rsaPublicKey.txt";
//
//            PublicKey publicKey = getPublicKeyFromPem(publicKeyFileName);
//            PrivateKey privateKeyFromPem = getPrivateKeyFromPem(privateKeyFileName);
//            String encrypt = encrypt("zhangsan", base64ecoder.encode(publicKey.getEncoded()));
//            String decrypt = decrypt(encrypt, base64ecoder.encode(privateKeyFromPem.getEncoded()));
//            System.out.println(encrypt);
//            System.out.println(decrypt);

            String privateKeyFileName = "/Users/mac/Documents/javawork/kong-gateway/kong-controller/src/main/resources/sso_form_qat-private.key";
            String publicKeyFileName = "/Users/mac/Documents/javawork/kong-gateway/kong-controller/src/main/resources/sso-form-qat-pubic.cer";

            PublicKey publicKey = getPublicKeyFromCer(publicKeyFileName);
            PrivateKey privateKeyFromPem = getPrivateKeyFromPem(privateKeyFileName);
            String encrypt = encrypt("zhangsan", base64ecoder.encode(publicKey.getEncoded()));
            String decrypt = decrypt(encrypt, base64ecoder.encode(privateKeyFromPem.getEncoded()));
            System.out.println(encrypt);
            System.out.println(decrypt);
        }catch (Exception ex){
            ex.printStackTrace();
        }

    }
}

公钥

-----BEGIN PUBLIC KEY-----
MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAleOgtAqdr5l4PRT0s5QB
3YIozBwk1koFOs8pNSYzWqtld8Y6hEaQaT8o7ilohTg46EhBWwER1fn3P/28iZ5w
KnMrfYYdP8U/BtBW580NiKwn8I7qfKZ30SY0KjbtviwbixA3+pi85jMguYMA0nMY
JjYkmkOhuWfvUeV4D/mTJFPsM9gXpnxkAfUyS+Ndwsl5UE2UbEfa84h7aWM1JG+t
hkeqD3EBCaAVP/G+8zZWycFE2lnljBznFcC/knPZlvdiOJFTBXaVOMiwqIl8/RuD
tSyU2Ur0klT0EtqFDRu0PiyZhWiK+zH7YbGMrUx5DbQea+EWJrcgtSdC6LVWns1Z
ZQIDAQAB
-----END PUBLIC KEY-----

私钥

-----BEGIN PRIVATE KEY-----
MIIEvQIBADANBgkqhkiG9w0BAQEFAASCBKcwggSjAgEAAoIBAQCV46C0Cp2vmXg9
FPSzlAHdgijMHCTWSgU6zyk1JjNaq2V3xjqERpBpPyjuKWiFODjoSEFbARHV+fc/
/byJnnAqcyt9hh0/xT8G0FbnzQ2IrCfwjup8pnfRJjQqNu2+LBuLEDf6mLzmMyC5
gwDScxgmNiSaQ6G5Z+9R5XgP+ZMkU+wz2BemfGQB9TJL413CyXlQTZRsR9rziHtp
YzUkb62GR6oPcQEJoBU/8b7zNlbJwUTaWeWMHOcVwL+Sc9mW92I4kVMFdpU4yLCo
iXz9G4O1LJTZSvSSVPQS2oUNG7Q+LJmFaIr7MfthsYytTHkNtB5r4RYmtyC1J0Lo
tVaezVllAgMBAAECggEAHMMxc1sWJzwr9oyu6EbelMMFUSWVbAmIN2DJZ4mNETkS
n4lKcVeZHpkgIZOQmv/O68PxxqTN52GwMHdgVogwvfSbw9qYgkQ3c/dGtfSDRFbE
00SZepH3LAtIt1ETDgsovea+1ze4B/SHsxGQdtHfMHXzUCbqQcnQAscl4urhcXbe
DR4LaKgArF9Ogp7hkZEsDsKyeFe7zuhaawoOAd+yVe2/FPUKTLdmPEQqGhD47PNn
eSKFW1w++L3oem5a50LWmJJ3QO90s7/+yE0WBay1O/zn4J+pf9Uht1qK7eyfSEOK
AI+11KoR8WVOY3H5o/SZ66iGAy+Oef28C6oBbGWlgQKBgQDGa3JAdz8fsG5Zr2FA
HfOg0yfKvQOtetFzGoflBv3vaBm7B9PrpR5lrChQejHDfZ3AU+9p2g+nAErorJ+H
bUQoc9MyqcNF0QqtHfqRA7bWpYcDKRsXZNmvbPP3EH/JzviPWRvlTpKftJ0BAIWC
RwQrtZmFI5PSOQ0idL1WZ1zuGwKBgQDBYtvlYQB/LloA9Xo2trFqZ1nf7uVQgw16
j0ESpAFKYUWbmHdRSRz8Csf/xVT2WjfyWzhbKy3viNJQNsodnGRzL2NCfMkEbdW9
BW5izGQg1U2NLcDrhMwCmkBmuv1bWk0SjsnpVK+CM3JZ/YsYM9UfAH1F3OrtO11s
ebVKq+VOfwKBgQC3isaqCWST3LGHNqtAEzS9DPZfHM8dF2JOFjmkyv31CpfaoZgP
/7KJnGHCZ/ZGfpmBQmNRyEv4UFX6u0vqi1GkFdhEojKnD4LPts6EfCoSjhXA/7I2
xqxzENbwMQv0UwcsGuKqEC+jmgAt4Byf8S9Te23icZGYwft7Zv+JwJ1/BwKBgHbH
PqLTgpebI6LlI4yJh8z/777QH77kz5mQdXp6i2Rg/H0GF3swugHAqXjafkXVwfk0
uBefHNa8Jdko3dl0Hmp1F7VVqa3zvE0eEd/TBEj6Wmi1SoIeDaQnlBjFDypV+3LD
ixaqciY5bSoCxbU22Nby2P7ZIt5VERu4YXacv/oHAoGAerZP4/CHVAwg1VDUJpPV
PvSAOASSbIvhjR3WLLvr8LsVBo3+XLVTVyRPAZDZBYyELG8bBymIVUqIIhkEqOWP
YEPM9QNesuXVZAJ40dlKmj5xqSQUxeS8y+qUonOLC3uOSvq3KsO/SmUMoSxfKj2E
uu6bZOJvBkMmjeLCjwoLpcc=
-----END PRIVATE KEY-----

最后编辑于
©著作权归作者所有,转载或内容合作请联系作者
禁止转载,如需转载请通过简信或评论联系作者。
  • 序言:七十年代末,一起剥皮案震惊了整个滨河市,随后出现的几起案子,更是在滨河造成了极大的恐慌,老刑警刘岩,带你破解...
    沈念sama阅读 194,457评论 5 459
  • 序言:滨河连续发生了三起死亡事件,死亡现场离奇诡异,居然都是意外死亡,警方通过查阅死者的电脑和手机,发现死者居然都...
    沈念sama阅读 81,837评论 2 371
  • 文/潘晓璐 我一进店门,熙熙楼的掌柜王于贵愁眉苦脸地迎上来,“玉大人,你说我怎么就摊上这事。” “怎么了?”我有些...
    开封第一讲书人阅读 141,696评论 0 319
  • 文/不坏的土叔 我叫张陵,是天一观的道长。 经常有香客问我,道长,这世上最难降的妖魔是什么? 我笑而不...
    开封第一讲书人阅读 52,183评论 1 263
  • 正文 为了忘掉前任,我火速办了婚礼,结果婚礼上,老公的妹妹穿的比我还像新娘。我一直安慰自己,他们只是感情好,可当我...
    茶点故事阅读 61,057评论 4 355
  • 文/花漫 我一把揭开白布。 她就那样静静地躺着,像睡着了一般。 火红的嫁衣衬着肌肤如雪。 梳的纹丝不乱的头发上,一...
    开封第一讲书人阅读 46,105评论 1 272
  • 那天,我揣着相机与录音,去河边找鬼。 笑死,一个胖子当着我的面吹牛,可吹牛的内容都是我干的。 我是一名探鬼主播,决...
    沈念sama阅读 36,520评论 3 381
  • 文/苍兰香墨 我猛地睁开眼,长吁一口气:“原来是场噩梦啊……” “哼!你这毒妇竟也来了?” 一声冷哼从身侧响起,我...
    开封第一讲书人阅读 35,211评论 0 253
  • 序言:老挝万荣一对情侣失踪,失踪者是张志新(化名)和其女友刘颖,没想到半个月后,有当地人在树林里发现了一具尸体,经...
    沈念sama阅读 39,482评论 1 290
  • 正文 独居荒郊野岭守林人离奇死亡,尸身上长有42处带血的脓包…… 初始之章·张勋 以下内容为张勋视角 年9月15日...
    茶点故事阅读 34,574评论 2 309
  • 正文 我和宋清朗相恋三年,在试婚纱的时候发现自己被绿了。 大学时的朋友给我发了我未婚夫和他白月光在一起吃饭的照片。...
    茶点故事阅读 36,353评论 1 326
  • 序言:一个原本活蹦乱跳的男人离奇死亡,死状恐怖,灵堂内的尸体忽然破棺而出,到底是诈尸还是另有隐情,我是刑警宁泽,带...
    沈念sama阅读 32,213评论 3 312
  • 正文 年R本政府宣布,位于F岛的核电站,受9级特大地震影响,放射性物质发生泄漏。R本人自食恶果不足惜,却给世界环境...
    茶点故事阅读 37,576评论 3 298
  • 文/蒙蒙 一、第九天 我趴在偏房一处隐蔽的房顶上张望。 院中可真热闹,春花似锦、人声如沸。这庄子的主人今日做“春日...
    开封第一讲书人阅读 28,897评论 0 17
  • 文/苍兰香墨 我抬头看了看天上的太阳。三九已至,却和暖如春,着一层夹袄步出监牢的瞬间,已是汗流浃背。 一阵脚步声响...
    开封第一讲书人阅读 30,174评论 1 250
  • 我被黑心中介骗来泰国打工, 没想到刚下飞机就差点儿被人妖公主榨干…… 1. 我叫王不留,地道东北人。 一个月前我还...
    沈念sama阅读 41,489评论 2 341
  • 正文 我出身青楼,却偏偏与公主长得像,于是被迫代替她去往敌国和亲。 传闻我的和亲对象是个残疾皇子,可洞房花烛夜当晚...
    茶点故事阅读 40,683评论 2 335