Lenguaje
Nota:
El acceso a esta página requiere autorización. Puede intentar iniciar sesión o cambiar directorios.
El acceso a esta página requiere autorización. Puede intentar cambiar los directorios.
Note
Este artículo se aplica a Windows.
Para obtener información sobre ASP.NET Core, consulte ASP.NET Core Protección de datos.
.NET proporciona acceso a la API de protección de datos (DPAPI), que permite cifrar los datos mediante la información de la cuenta de usuario o el equipo actual. Cuando se usa DPAPI, se evita el problema difícil de generar y almacenar explícitamente una clave criptográfica.
Use la ProtectedData clase para cifrar una copia de una matriz de bytes. Puede especificar que solo la misma cuenta de usuario pueda descifrar los datos o que cualquier cuenta del equipo pueda descifrarlos. Para obtener una descripción detallada de las ProtectedData opciones, consulte la DataProtectionScope enumeración .
Cifrado de datos en un archivo o flujo mediante la protección de datos
Cree una entropía aleatoria.
Llame al método Protect estático mientras pasa la matriz de bytes que se vaya a cifrar, la entropía y el ámbito de la protección de datos.
Escriba los datos cifrados en un archivo o secuencia.
Para descifrar datos de un archivo o flujo mediante la protección de datos
Lea los datos cifrados de un archivo o secuencia.
Llame al método Unprotect estático mientras pasa la matriz de bytes que se vaya a descifrar y el ámbito de la protección de datos.
Example
En el ejemplo de código siguiente se muestran dos formas de cifrado y descifrado. En primer lugar, el código cifra y, a continuación, descifra una matriz en memoria de bytes. A continuación, el código cifra una copia de una matriz de bytes, la guarda en un archivo, carga los datos del archivo y, a continuación, descifra los datos. En el ejemplo se muestran los datos originales, los datos cifrados y los datos descifrados.
Important
ProtectedMemorysolo está disponible para .NET Framework. ProtectedDataestá disponible en .NET y .NET Framework.
Este ejemplo compila y se ejecuta si el destino es .NET en Windows. Para compilar el ejemplo, agregue el System.Security.Cryptography.ProtectedData paquete NuGet.
using System.Security.Cryptography;
using System.Text;
try
{
// Data Encryption - ProtectedData
// Create the original data to be encrypted.
byte[] toEncrypt = Encoding.ASCII.GetBytes("This is some data of any length.");
// Create some random entropy.
byte[] entropy = CreateRandomEntropy();
Console.WriteLine();
Console.WriteLine($"Original data: {Encoding.ASCII.GetString(toEncrypt)}");
Console.WriteLine("Encrypting and writing to disk...");
int bytesWritten;
// Encrypt a copy of the data to the stream.
using (FileStream writeStream = new("Data.dat", FileMode.OpenOrCreate))
{
bytesWritten = EncryptDataToStream(toEncrypt, entropy, DataProtectionScope.CurrentUser, writeStream);
}
Console.WriteLine("Reading data from disk and decrypting...");
// Read from the stream and decrypt the data.
byte[] decryptData;
using (FileStream readStream = new("Data.dat", FileMode.Open))
{
decryptData = DecryptDataFromStream(entropy, DataProtectionScope.CurrentUser, readStream, bytesWritten);
}
Console.WriteLine($"Decrypted data: {Encoding.ASCII.GetString(decryptData)}");
}
catch (Exception e)
{
Console.WriteLine($"ERROR: {e.Message}");
}
static byte[] CreateRandomEntropy()
{
// Create a byte array to hold the random value and fill it with a random value.
byte[] entropy = new byte[16];
RandomNumberGenerator.Fill(entropy);
return entropy;
}
static int EncryptDataToStream(byte[] buffer, byte[] entropy, DataProtectionScope scope, Stream stream)
{
ArgumentNullException.ThrowIfNull(buffer);
ArgumentOutOfRangeException.ThrowIfZero(buffer.Length, nameof(buffer));
ArgumentNullException.ThrowIfNull(entropy);
ArgumentOutOfRangeException.ThrowIfZero(entropy.Length, nameof(entropy));
ArgumentNullException.ThrowIfNull(stream);
int length = 0;
// Encrypt the data and store the result in a new byte array. The original data remains unchanged.
byte[] encryptedData = ProtectedData.Protect(buffer, entropy, scope);
// Write the encrypted data to a stream.
if (stream.CanWrite)
{
stream.Write(encryptedData, 0, encryptedData.Length);
length = encryptedData.Length;
}
// Return the length that was written to the stream.
return length;
}
static byte[] DecryptDataFromStream(byte[] entropy, DataProtectionScope scope, Stream stream, int length)
{
ArgumentNullException.ThrowIfNull(stream);
ArgumentOutOfRangeException.ThrowIfZero(length, nameof(length));
ArgumentNullException.ThrowIfNull(entropy);
ArgumentOutOfRangeException.ThrowIfZero(entropy.Length, nameof(entropy));
if (!stream.CanRead)
throw new IOException("Could not read the stream.");
byte[] inBuffer = new byte[length];
stream.ReadExactly(inBuffer, 0, length);
// Return the decrypted data.
return ProtectedData.Unprotect(inBuffer, entropy, scope);
}
Imports System.IO
Imports System.Security.Cryptography
Imports System.Text
Public Module DataProtectionSample
Sub Main()
Try
' Data Encryption - ProtectedData
' Create the original data to be encrypted.
Dim toEncrypt As Byte() = Encoding.ASCII.GetBytes("This is some data of any length.")
' Create some random entropy.
Dim entropy As Byte() = CreateRandomEntropy()
Console.WriteLine()
Console.WriteLine($"Original data: {Encoding.ASCII.GetString(toEncrypt)}")
Console.WriteLine("Encrypting and writing to disk...")
Dim bytesWritten As Integer
' Encrypt a copy of the data to the stream.
Using writeStream As New FileStream("Data.dat", FileMode.OpenOrCreate)
bytesWritten = EncryptDataToStream(toEncrypt, entropy, DataProtectionScope.CurrentUser, writeStream)
End Using
Console.WriteLine("Reading data from disk and decrypting...")
' Read from the stream and decrypt the data.
Dim decryptData As Byte()
Using readStream As New FileStream("Data.dat", FileMode.Open)
decryptData = DecryptDataFromStream(entropy, DataProtectionScope.CurrentUser, readStream, bytesWritten)
End Using
Console.WriteLine($"Decrypted data: {Encoding.ASCII.GetString(decryptData)}")
Catch e As Exception
Console.WriteLine($"ERROR: {e.Message}")
End Try
End Sub
Function CreateRandomEntropy() As Byte()
' Create a byte array to hold the random value and fill it with a random value.
Dim entropy(15) As Byte
RandomNumberGenerator.Fill(entropy)
Return entropy
End Function
Function EncryptDataToStream(buffer As Byte(), entropy As Byte(), scope As DataProtectionScope, stream As Stream) As Integer
ArgumentNullException.ThrowIfNull(buffer)
ArgumentOutOfRangeException.ThrowIfZero(buffer.Length, NameOf(buffer))
ArgumentNullException.ThrowIfNull(entropy)
ArgumentOutOfRangeException.ThrowIfZero(entropy.Length, NameOf(entropy))
ArgumentNullException.ThrowIfNull(stream)
Dim length As Integer = 0
' Encrypt the data and store the result in a new byte array. The original data remains unchanged.
Dim encryptedData As Byte() = ProtectedData.Protect(buffer, entropy, scope)
' Write the encrypted data to a stream.
If stream.CanWrite Then
stream.Write(encryptedData, 0, encryptedData.Length)
length = encryptedData.Length
End If
' Return the length that was written to the stream.
Return length
End Function
Function DecryptDataFromStream(entropy As Byte(), scope As DataProtectionScope, stream As Stream, length As Integer) As Byte()
ArgumentNullException.ThrowIfNull(stream)
ArgumentOutOfRangeException.ThrowIfZero(length, NameOf(length))
ArgumentNullException.ThrowIfNull(entropy)
ArgumentOutOfRangeException.ThrowIfZero(entropy.Length, NameOf(entropy))
If Not stream.CanRead Then
Throw New IOException("Could not read the stream.")
End If
Dim inBuffer(length - 1) As Byte
stream.ReadExactly(inBuffer, 0, length)
' Return the decrypted data.
Return ProtectedData.Unprotect(inBuffer, entropy, scope)
End Function
End Module