Nota
L'accesso a questa pagina richiede l'autorizzazione. È possibile provare ad accedere o modificare le directory.
L'accesso a questa pagina richiede l'autorizzazione. È possibile provare a modificare le directory.
Note
Questo articolo si applica a Windows.
Per informazioni sulle ASP.NET Core, vedere ASP.NET Core Protezione dei dati.
.NET fornisce l'accesso all'API di protezione dei dati (DPAPI), che consente di crittografare i dati usando le informazioni dall'account utente o dal computer corrente. Quando si usa DPAPI, si evita il difficile problema di generare e archiviare in modo esplicito una chiave crittografica.
Usare la ProtectedData classe per crittografare una copia di una matrice di byte. È possibile specificare che solo lo stesso account utente può decrittografare i dati o che qualsiasi account nel computer può decrittografarlo. Per una descrizione dettagliata delle ProtectedData opzioni, vedere l'enumerazione DataProtectionScope .
Crittografare i dati in un file o in un flusso usando la protezione dei dati
Creare un'entropia casuale.
Chiamare il metodo statico Protect passando un array di byte da crittografare, l'entropia e l'ambito della protezione dei dati.
Scrivere i dati crittografati in un file o in un flusso.
Per decrittografare i dati da un file o da un flusso usando la protezione dei dati
Legge i dati crittografati da un file o da un flusso.
Chiamare il metodo statico Unprotect passando un array di byte da decrittografare e l'ambito di protezione dei dati.
Example
L'esempio di codice seguente illustra due forme di crittografia e decrittografia. Prima di tutto, il codice crittografa e quindi decrittografa una matrice in memoria di byte. Il codice crittografa quindi una copia di una matrice di byte, la salva in un file, carica i dati dal file e quindi decrittografa i dati. Nell'esempio vengono visualizzati i dati originali, i dati crittografati e i dati decrittografati.
Importante
ProtectedMemoryè disponibile solo per .NET Framework. ProtectedDataè disponibile in .NET e .NET Framework.
Questo esempio si compila e si esegue quando la destinazione è .NET su Windows. Per compilare l'esempio, aggiungere il System.Security.Cryptography.ProtectedData pacchetto NuGet.
using System.Security.Cryptography;
using System.Text;
try
{
// Data Encryption - ProtectedData
// Create the original data to be encrypted.
byte[] toEncrypt = Encoding.ASCII.GetBytes("This is some data of any length.");
// Create some random entropy.
byte[] entropy = CreateRandomEntropy();
Console.WriteLine();
Console.WriteLine($"Original data: {Encoding.ASCII.GetString(toEncrypt)}");
Console.WriteLine("Encrypting and writing to disk...");
int bytesWritten;
// Encrypt a copy of the data to the stream.
using (FileStream writeStream = new("Data.dat", FileMode.OpenOrCreate))
{
bytesWritten = EncryptDataToStream(toEncrypt, entropy, DataProtectionScope.CurrentUser, writeStream);
}
Console.WriteLine("Reading data from disk and decrypting...");
// Read from the stream and decrypt the data.
byte[] decryptData;
using (FileStream readStream = new("Data.dat", FileMode.Open))
{
decryptData = DecryptDataFromStream(entropy, DataProtectionScope.CurrentUser, readStream, bytesWritten);
}
Console.WriteLine($"Decrypted data: {Encoding.ASCII.GetString(decryptData)}");
}
catch (Exception e)
{
Console.WriteLine($"ERROR: {e.Message}");
}
static byte[] CreateRandomEntropy()
{
// Create a byte array to hold the random value and fill it with a random value.
byte[] entropy = new byte[16];
RandomNumberGenerator.Fill(entropy);
return entropy;
}
static int EncryptDataToStream(byte[] buffer, byte[] entropy, DataProtectionScope scope, Stream stream)
{
ArgumentNullException.ThrowIfNull(buffer);
ArgumentOutOfRangeException.ThrowIfZero(buffer.Length, nameof(buffer));
ArgumentNullException.ThrowIfNull(entropy);
ArgumentOutOfRangeException.ThrowIfZero(entropy.Length, nameof(entropy));
ArgumentNullException.ThrowIfNull(stream);
int length = 0;
// Encrypt the data and store the result in a new byte array. The original data remains unchanged.
byte[] encryptedData = ProtectedData.Protect(buffer, entropy, scope);
// Write the encrypted data to a stream.
if (stream.CanWrite)
{
stream.Write(encryptedData, 0, encryptedData.Length);
length = encryptedData.Length;
}
// Return the length that was written to the stream.
return length;
}
static byte[] DecryptDataFromStream(byte[] entropy, DataProtectionScope scope, Stream stream, int length)
{
ArgumentNullException.ThrowIfNull(stream);
ArgumentOutOfRangeException.ThrowIfZero(length, nameof(length));
ArgumentNullException.ThrowIfNull(entropy);
ArgumentOutOfRangeException.ThrowIfZero(entropy.Length, nameof(entropy));
if (!stream.CanRead)
throw new IOException("Could not read the stream.");
byte[] inBuffer = new byte[length];
stream.ReadExactly(inBuffer, 0, length);
// Return the decrypted data.
return ProtectedData.Unprotect(inBuffer, entropy, scope);
}
Imports System.IO
Imports System.Security.Cryptography
Imports System.Text
Public Module DataProtectionSample
Sub Main()
Try
' Data Encryption - ProtectedData
' Create the original data to be encrypted.
Dim toEncrypt As Byte() = Encoding.ASCII.GetBytes("This is some data of any length.")
' Create some random entropy.
Dim entropy As Byte() = CreateRandomEntropy()
Console.WriteLine()
Console.WriteLine($"Original data: {Encoding.ASCII.GetString(toEncrypt)}")
Console.WriteLine("Encrypting and writing to disk...")
Dim bytesWritten As Integer
' Encrypt a copy of the data to the stream.
Using writeStream As New FileStream("Data.dat", FileMode.OpenOrCreate)
bytesWritten = EncryptDataToStream(toEncrypt, entropy, DataProtectionScope.CurrentUser, writeStream)
End Using
Console.WriteLine("Reading data from disk and decrypting...")
' Read from the stream and decrypt the data.
Dim decryptData As Byte()
Using readStream As New FileStream("Data.dat", FileMode.Open)
decryptData = DecryptDataFromStream(entropy, DataProtectionScope.CurrentUser, readStream, bytesWritten)
End Using
Console.WriteLine($"Decrypted data: {Encoding.ASCII.GetString(decryptData)}")
Catch e As Exception
Console.WriteLine($"ERROR: {e.Message}")
End Try
End Sub
Function CreateRandomEntropy() As Byte()
' Create a byte array to hold the random value and fill it with a random value.
Dim entropy(15) As Byte
RandomNumberGenerator.Fill(entropy)
Return entropy
End Function
Function EncryptDataToStream(buffer As Byte(), entropy As Byte(), scope As DataProtectionScope, stream As Stream) As Integer
ArgumentNullException.ThrowIfNull(buffer)
ArgumentOutOfRangeException.ThrowIfZero(buffer.Length, NameOf(buffer))
ArgumentNullException.ThrowIfNull(entropy)
ArgumentOutOfRangeException.ThrowIfZero(entropy.Length, NameOf(entropy))
ArgumentNullException.ThrowIfNull(stream)
Dim length As Integer = 0
' Encrypt the data and store the result in a new byte array. The original data remains unchanged.
Dim encryptedData As Byte() = ProtectedData.Protect(buffer, entropy, scope)
' Write the encrypted data to a stream.
If stream.CanWrite Then
stream.Write(encryptedData, 0, encryptedData.Length)
length = encryptedData.Length
End If
' Return the length that was written to the stream.
Return length
End Function
Function DecryptDataFromStream(entropy As Byte(), scope As DataProtectionScope, stream As Stream, length As Integer) As Byte()
ArgumentNullException.ThrowIfNull(stream)
ArgumentOutOfRangeException.ThrowIfZero(length, NameOf(length))
ArgumentNullException.ThrowIfNull(entropy)
ArgumentOutOfRangeException.ThrowIfZero(entropy.Length, NameOf(entropy))
If Not stream.CanRead Then
Throw New IOException("Could not read the stream.")
End If
Dim inBuffer(length - 1) As Byte
stream.ReadExactly(inBuffer, 0, length)
' Return the decrypted data.
Return ProtectedData.Unprotect(inBuffer, entropy, scope)
End Function
End Module