Rfc2898DeriveBytes 建構函式
定義
重要
部分資訊涉及發行前產品,在發行之前可能會有大幅修改。 Microsoft 對此處提供的資訊,不做任何明確或隱含的瑕疵擔保。
初始化 Rfc2898DeriveBytes 類別的新執行個體。
多載
| 名稱 | Description |
|---|---|
| Rfc2898DeriveBytes(String, Byte[]) |
已淘汰.
已淘汰.
初始化一個新的類別實例 Rfc2898DeriveBytes ,使用密碼和鹽來推導金鑰。 |
| Rfc2898DeriveBytes(String, Int32) |
已淘汰.
已淘汰.
利用密碼和鹽大小初始化該類別的新實例 Rfc2898DeriveBytes 以推導金鑰。 |
| Rfc2898DeriveBytes(Byte[], Byte[], Int32) |
已淘汰.
已淘汰.
使用密碼、鹽值及迭代次數初始化該類別的新實例 Rfc2898DeriveBytes 以推導金鑰。 |
| Rfc2898DeriveBytes(String, Byte[], Int32) |
已淘汰.
已淘汰.
使用密碼、鹽值及迭代次數初始化該類別的新實例 Rfc2898DeriveBytes 以推導金鑰。 |
| Rfc2898DeriveBytes(String, Int32, Int32) |
已淘汰.
已淘汰.
使用密碼、鹽大小及迭代次數初始化該類別的新實例 Rfc2898DeriveBytes 以推導金鑰。 |
| Rfc2898DeriveBytes(Byte[], Byte[], Int32, HashAlgorithmName) |
已淘汰.
使用指定的密碼、鹽值、迭代次數及雜湊演算法名稱初始化該類別的新實例 Rfc2898DeriveBytes ,以推導出金鑰。 |
| Rfc2898DeriveBytes(String, Byte[], Int32, HashAlgorithmName) |
已淘汰.
使用指定的密碼、鹽值、迭代次數及雜湊演算法名稱初始化該類別的新實例 Rfc2898DeriveBytes ,以推導出金鑰。 |
| Rfc2898DeriveBytes(String, Int32, Int32, HashAlgorithmName) |
已淘汰.
使用指定的密碼、鹽大小、迭代次數及雜湊演算法名稱初始化該類別的新實例 Rfc2898DeriveBytes ,以推導金鑰。 |
Rfc2898DeriveBytes(String, Byte[])
警告
The constructors on Rfc2898DeriveBytes are obsolete. Use the static Pbkdf2 method instead.
警告
The default hash algorithm and iteration counts in Rfc2898DeriveBytes constructors are outdated and insecure. Use a constructor that accepts the hash algorithm and the number of iterations.
初始化一個新的類別實例 Rfc2898DeriveBytes ,使用密碼和鹽來推導金鑰。
public:
Rfc2898DeriveBytes(System::String ^ password, cli::array <System::Byte> ^ salt);
[System.Obsolete("The constructors on Rfc2898DeriveBytes are obsolete. Use the static Pbkdf2 method instead.", DiagnosticId="SYSLIB0060", UrlFormat="https://aka.ms/dotnet-warnings/{0}")]
public Rfc2898DeriveBytes(string password, byte[] salt);
public Rfc2898DeriveBytes(string password, byte[] salt);
[System.Obsolete("The default hash algorithm and iteration counts in Rfc2898DeriveBytes constructors are outdated and insecure. Use a constructor that accepts the hash algorithm and the number of iterations.", DiagnosticId="SYSLIB0041", UrlFormat="https://aka.ms/dotnet-warnings/{0}")]
public Rfc2898DeriveBytes(string password, byte[] salt);
[<System.Obsolete("The constructors on Rfc2898DeriveBytes are obsolete. Use the static Pbkdf2 method instead.", DiagnosticId="SYSLIB0060", UrlFormat="https://aka.ms/dotnet-warnings/{0}")>]
new System.Security.Cryptography.Rfc2898DeriveBytes : string * byte[] -> System.Security.Cryptography.Rfc2898DeriveBytes
new System.Security.Cryptography.Rfc2898DeriveBytes : string * byte[] -> System.Security.Cryptography.Rfc2898DeriveBytes
[<System.Obsolete("The default hash algorithm and iteration counts in Rfc2898DeriveBytes constructors are outdated and insecure. Use a constructor that accepts the hash algorithm and the number of iterations.", DiagnosticId="SYSLIB0041", UrlFormat="https://aka.ms/dotnet-warnings/{0}")>]
new System.Security.Cryptography.Rfc2898DeriveBytes : string * byte[] -> System.Security.Cryptography.Rfc2898DeriveBytes
Public Sub New (password As String, salt As Byte())
參數
- password
- String
用來推導金鑰的密碼。
- salt
- Byte[]
用來推導出鑰匙的 key salt。
- 屬性
例外狀況
指定的鹽大小小於 8 位元組,或迭代次數小於 1。
密碼或鹽是 null。
範例
以下程式碼範例利用該 Rfc2898DeriveBytes 類別來建立兩個相同的類別鍵 Aes 。 接著它會用金鑰加密和解密部分資料。
using System;
using System.IO;
using System.Text;
using System.Security.Cryptography;
public class rfc2898test
{
// Generate a key k1 with password pwd1 and salt salt1.
// Generate a key k2 with password pwd1 and salt salt1.
// Encrypt data1 with key k1 using symmetric encryption, creating edata1.
// Decrypt edata1 with key k2 using symmetric decryption, creating data2.
// data2 should equal data1.
private const string usageText = "Usage: RFC2898 <password>\nYou must specify the password for encryption.\n";
public static void Main(string[] passwordargs)
{
//If no file name is specified, write usage text.
if (passwordargs.Length == 0)
{
Console.WriteLine(usageText);
}
else
{
string pwd1 = passwordargs[0];
// Create a byte array to hold the random value.
byte[] salt1 = new byte[8];
using (RandomNumberGenerator rng = RandomNumberGenerator.Create())
{
// Fill the array with a random value.
rng.GetBytes(salt1);
}
//data1 can be a string or contents of a file.
string data1 = "Some test data";
//The legacy default iteration count is 1000 so the two methods use the same iteration count.
int myIterations = 1000;
try
{
Rfc2898DeriveBytes k1 = new Rfc2898DeriveBytes(pwd1, salt1,
myIterations);
Rfc2898DeriveBytes k2 = new Rfc2898DeriveBytes(pwd1, salt1);
// Encrypt the data.
Aes encAlg = Aes.Create();
encAlg.Key = k1.GetBytes(16);
MemoryStream encryptionStream = new MemoryStream();
CryptoStream encrypt = new CryptoStream(encryptionStream,
encAlg.CreateEncryptor(), CryptoStreamMode.Write);
byte[] utfD1 = new System.Text.UTF8Encoding(false).GetBytes(
data1);
encrypt.Write(utfD1, 0, utfD1.Length);
encrypt.FlushFinalBlock();
encrypt.Close();
byte[] edata1 = encryptionStream.ToArray();
k1.Reset();
// Try to decrypt, thus showing it can be round-tripped.
Aes decAlg = Aes.Create();
decAlg.Key = k2.GetBytes(16);
decAlg.IV = encAlg.IV;
MemoryStream decryptionStreamBacking = new MemoryStream();
CryptoStream decrypt = new CryptoStream(
decryptionStreamBacking, decAlg.CreateDecryptor(), CryptoStreamMode.Write);
decrypt.Write(edata1, 0, edata1.Length);
decrypt.Flush();
decrypt.Close();
k2.Reset();
string data2 = new UTF8Encoding(false).GetString(
decryptionStreamBacking.ToArray());
if (!data1.Equals(data2))
{
Console.WriteLine("Error: The two values are not equal.");
}
else
{
Console.WriteLine("The two values are equal.");
Console.WriteLine("k1 iterations: {0}", k1.IterationCount);
Console.WriteLine("k2 iterations: {0}", k2.IterationCount);
}
}
catch (Exception e)
{
Console.WriteLine("Error: {0}", e);
}
}
}
}
Imports System.IO
Imports System.Text
Imports System.Security.Cryptography
Public Class rfc2898test
' Generate a key k1 with password pwd1 and salt salt1.
' Generate a key k2 with password pwd1 and salt salt1.
' Encrypt data1 with key k1 using symmetric encryption, creating edata1.
' Decrypt edata1 with key k2 using symmetric decryption, creating data2.
' data2 should equal data1.
Private Const usageText As String = "Usage: RFC2898 <password>" + vbLf + "You must specify the password for encryption." + vbLf
Public Shared Sub Main(ByVal passwordargs() As String)
'If no file name is specified, write usage text.
If passwordargs.Length = 0 Then
Console.WriteLine(usageText)
Else
Dim pwd1 As String = passwordargs(0)
Dim salt1(8) As Byte
Using rng As RandomNumberGenerator = RandomNumberGenerator.Create()
rng.GetBytes(salt1)
End Using
'data1 can be a string or contents of a file.
Dim data1 As String = "Some test data"
'The legacy default iteration count is 1000 so the two methods use the same iteration count.
Dim myIterations As Integer = 1000
Try
Dim k1 As New Rfc2898DeriveBytes(pwd1, salt1, myIterations)
Dim k2 As New Rfc2898DeriveBytes(pwd1, salt1)
' Encrypt the data.
Dim encAlg As Aes = Aes.Create()
encAlg.Key = k1.GetBytes(16)
Dim encryptionStream As New MemoryStream()
Dim encrypt As New CryptoStream(encryptionStream, encAlg.CreateEncryptor(), CryptoStreamMode.Write)
Dim utfD1 As Byte() = New System.Text.UTF8Encoding(False).GetBytes(data1)
encrypt.Write(utfD1, 0, utfD1.Length)
encrypt.FlushFinalBlock()
encrypt.Close()
Dim edata1 As Byte() = encryptionStream.ToArray()
k1.Reset()
' Try to decrypt, thus showing it can be round-tripped.
Dim decAlg As Aes = Aes.Create()
decAlg.Key = k2.GetBytes(16)
decAlg.IV = encAlg.IV
Dim decryptionStreamBacking As New MemoryStream()
Dim decrypt As New CryptoStream(decryptionStreamBacking, decAlg.CreateDecryptor(), CryptoStreamMode.Write)
decrypt.Write(edata1, 0, edata1.Length)
decrypt.Flush()
decrypt.Close()
k2.Reset()
Dim data2 As String = New UTF8Encoding(False).GetString(decryptionStreamBacking.ToArray())
If Not data1.Equals(data2) Then
Console.WriteLine("Error: The two values are not equal.")
Else
Console.WriteLine("The two values are equal.")
Console.WriteLine("k1 iterations: {0}", k1.IterationCount)
Console.WriteLine("k2 iterations: {0}", k2.IterationCount)
End If
Catch e As Exception
Console.WriteLine("Error: ", e)
End Try
End If
End Sub
End Class
備註
鹽的大小必須是 8 位元組或以上。
RFC 2898 包含從密碼與鹽建立金鑰與初始化向量(IV)的方法。 你可以使用 PBKDF2,一種基於密碼的金鑰推導函式,透過偽隨機函式推導金鑰,該函式允許產生幾乎無限長度的金鑰。 此 Rfc2898DeriveBytes 類別可用於從基礎鍵及其他參數產生導出金鑰。 在基於密碼的金鑰導出函式中,基鍵是密碼,其他參數則是鹽值和迭代次數。
欲了解更多關於 PBKDF2 的資訊,請參閱 RFC 2898,標題為「PKCS #5:Password-Based 密碼學規範版本 2.0」。 完整詳情請參見第5.2節「PBKDF2」。
Important
千萬不要在原始碼裡硬寫密碼。 硬編碼密碼可透過 Ildasm.exe(IL 反組譯器)、十六進位編輯器,或直接在文字編輯器(如 Notepad.exe)中開啟組合語言來取得。
另請參閱
適用於
Rfc2898DeriveBytes(String, Int32)
警告
The constructors on Rfc2898DeriveBytes are obsolete. Use the static Pbkdf2 method instead.
警告
The default hash algorithm and iteration counts in Rfc2898DeriveBytes constructors are outdated and insecure. Use a constructor that accepts the hash algorithm and the number of iterations.
利用密碼和鹽大小初始化該類別的新實例 Rfc2898DeriveBytes 以推導金鑰。
public:
Rfc2898DeriveBytes(System::String ^ password, int saltSize);
[System.Obsolete("The constructors on Rfc2898DeriveBytes are obsolete. Use the static Pbkdf2 method instead.", DiagnosticId="SYSLIB0060", UrlFormat="https://aka.ms/dotnet-warnings/{0}")]
public Rfc2898DeriveBytes(string password, int saltSize);
public Rfc2898DeriveBytes(string password, int saltSize);
[System.Obsolete("The default hash algorithm and iteration counts in Rfc2898DeriveBytes constructors are outdated and insecure. Use a constructor that accepts the hash algorithm and the number of iterations.", DiagnosticId="SYSLIB0041", UrlFormat="https://aka.ms/dotnet-warnings/{0}")]
public Rfc2898DeriveBytes(string password, int saltSize);
[<System.Obsolete("The constructors on Rfc2898DeriveBytes are obsolete. Use the static Pbkdf2 method instead.", DiagnosticId="SYSLIB0060", UrlFormat="https://aka.ms/dotnet-warnings/{0}")>]
new System.Security.Cryptography.Rfc2898DeriveBytes : string * int -> System.Security.Cryptography.Rfc2898DeriveBytes
new System.Security.Cryptography.Rfc2898DeriveBytes : string * int -> System.Security.Cryptography.Rfc2898DeriveBytes
[<System.Obsolete("The default hash algorithm and iteration counts in Rfc2898DeriveBytes constructors are outdated and insecure. Use a constructor that accepts the hash algorithm and the number of iterations.", DiagnosticId="SYSLIB0041", UrlFormat="https://aka.ms/dotnet-warnings/{0}")>]
new System.Security.Cryptography.Rfc2898DeriveBytes : string * int -> System.Security.Cryptography.Rfc2898DeriveBytes
Public Sub New (password As String, saltSize As Integer)
參數
- password
- String
用來推導金鑰的密碼。
- saltSize
- Int32
你想讓類別產生的隨機鹽值大小。
- 屬性
例外狀況
指定的鹽大小小於 8 位元組。
密碼或鹽是 null。
備註
鹽的大小必須是 8 位元組或以上。
RFC 2898 包含從密碼與鹽建立金鑰與初始化向量(IV)的方法。 你可以使用 PBKDF2,一種基於密碼的金鑰推導函式,透過偽隨機函式推導金鑰,該函式允許產生幾乎無限長度的金鑰。 此 Rfc2898DeriveBytes 類別可用於從基礎鍵及其他參數產生導出金鑰。 在基於密碼的金鑰導出函式中,基鍵是密碼,其他參數則是鹽值和迭代次數。
欲了解更多關於 PBKDF2 的資訊,請參閱 RFC 2898,標題為「PKCS #5:Password-Based 密碼學規範版本 2.0」。 完整詳情請參見第5.2節「PBKDF2」。
Important
千萬不要在原始碼裡硬寫密碼。 硬編碼密碼可透過 Ildasm.exe(IL 反組譯器)、十六進位編輯器,或直接在文字編輯器(如 Notepad.exe)中開啟組合語言來取得。
另請參閱
適用於
Rfc2898DeriveBytes(Byte[], Byte[], Int32)
警告
The constructors on Rfc2898DeriveBytes are obsolete. Use the static Pbkdf2 method instead.
警告
The default hash algorithm and iteration counts in Rfc2898DeriveBytes constructors are outdated and insecure. Use a constructor that accepts the hash algorithm and the number of iterations.
使用密碼、鹽值及迭代次數初始化該類別的新實例 Rfc2898DeriveBytes 以推導金鑰。
public:
Rfc2898DeriveBytes(cli::array <System::Byte> ^ password, cli::array <System::Byte> ^ salt, int iterations);
[System.Obsolete("The constructors on Rfc2898DeriveBytes are obsolete. Use the static Pbkdf2 method instead.", DiagnosticId="SYSLIB0060", UrlFormat="https://aka.ms/dotnet-warnings/{0}")]
public Rfc2898DeriveBytes(byte[] password, byte[] salt, int iterations);
public Rfc2898DeriveBytes(byte[] password, byte[] salt, int iterations);
[System.Obsolete("The default hash algorithm and iteration counts in Rfc2898DeriveBytes constructors are outdated and insecure. Use a constructor that accepts the hash algorithm and the number of iterations.", DiagnosticId="SYSLIB0041", UrlFormat="https://aka.ms/dotnet-warnings/{0}")]
public Rfc2898DeriveBytes(byte[] password, byte[] salt, int iterations);
[<System.Obsolete("The constructors on Rfc2898DeriveBytes are obsolete. Use the static Pbkdf2 method instead.", DiagnosticId="SYSLIB0060", UrlFormat="https://aka.ms/dotnet-warnings/{0}")>]
new System.Security.Cryptography.Rfc2898DeriveBytes : byte[] * byte[] * int -> System.Security.Cryptography.Rfc2898DeriveBytes
new System.Security.Cryptography.Rfc2898DeriveBytes : byte[] * byte[] * int -> System.Security.Cryptography.Rfc2898DeriveBytes
[<System.Obsolete("The default hash algorithm and iteration counts in Rfc2898DeriveBytes constructors are outdated and insecure. Use a constructor that accepts the hash algorithm and the number of iterations.", DiagnosticId="SYSLIB0041", UrlFormat="https://aka.ms/dotnet-warnings/{0}")>]
new System.Security.Cryptography.Rfc2898DeriveBytes : byte[] * byte[] * int -> System.Security.Cryptography.Rfc2898DeriveBytes
Public Sub New (password As Byte(), salt As Byte(), iterations As Integer)
參數
- password
- Byte[]
用來推導金鑰的密碼。
- salt
- Byte[]
用來推導出鑰匙的 key salt。
- iterations
- Int32
運算的迭代次數。
- 屬性
例外狀況
指定的鹽大小小於 8 位元組,或迭代次數小於 1。
密碼或鹽是 null。
備註
鹽的大小必須是 8 位元組或以上,且迭代次數必須大於零。
RFC 2898 包含從密碼與鹽建立金鑰與初始化向量(IV)的方法。 你可以使用 PBKDF2,一種基於密碼的金鑰推導函式,透過偽隨機函式推導金鑰,該函式允許產生幾乎無限長度的金鑰。 此 Rfc2898DeriveBytes 類別可用於從基礎鍵及其他參數產生導出金鑰。 在基於密碼的金鑰導出函式中,基鍵是密碼,其他參數則是鹽值和迭代次數。
欲了解更多關於 PBKDF2 的資訊,請參閱 RFC 2898,標題為「PKCS #5:Password-Based 密碼學規範版本 2.0」。 完整詳情請參見第5.2節「PBKDF2」。
Important
千萬不要在原始碼裡硬寫密碼。 硬編碼密碼可透過 Ildasm.exe(IL 反組譯器)、十六進位編輯器,或直接在文字編輯器(如 Notepad.exe)中開啟組合語言來取得。
適用於
Rfc2898DeriveBytes(String, Byte[], Int32)
警告
The constructors on Rfc2898DeriveBytes are obsolete. Use the static Pbkdf2 method instead.
警告
The default hash algorithm and iteration counts in Rfc2898DeriveBytes constructors are outdated and insecure. Use a constructor that accepts the hash algorithm and the number of iterations.
使用密碼、鹽值及迭代次數初始化該類別的新實例 Rfc2898DeriveBytes 以推導金鑰。
public:
Rfc2898DeriveBytes(System::String ^ password, cli::array <System::Byte> ^ salt, int iterations);
[System.Obsolete("The constructors on Rfc2898DeriveBytes are obsolete. Use the static Pbkdf2 method instead.", DiagnosticId="SYSLIB0060", UrlFormat="https://aka.ms/dotnet-warnings/{0}")]
public Rfc2898DeriveBytes(string password, byte[] salt, int iterations);
public Rfc2898DeriveBytes(string password, byte[] salt, int iterations);
[System.Obsolete("The default hash algorithm and iteration counts in Rfc2898DeriveBytes constructors are outdated and insecure. Use a constructor that accepts the hash algorithm and the number of iterations.", DiagnosticId="SYSLIB0041", UrlFormat="https://aka.ms/dotnet-warnings/{0}")]
public Rfc2898DeriveBytes(string password, byte[] salt, int iterations);
[<System.Obsolete("The constructors on Rfc2898DeriveBytes are obsolete. Use the static Pbkdf2 method instead.", DiagnosticId="SYSLIB0060", UrlFormat="https://aka.ms/dotnet-warnings/{0}")>]
new System.Security.Cryptography.Rfc2898DeriveBytes : string * byte[] * int -> System.Security.Cryptography.Rfc2898DeriveBytes
new System.Security.Cryptography.Rfc2898DeriveBytes : string * byte[] * int -> System.Security.Cryptography.Rfc2898DeriveBytes
[<System.Obsolete("The default hash algorithm and iteration counts in Rfc2898DeriveBytes constructors are outdated and insecure. Use a constructor that accepts the hash algorithm and the number of iterations.", DiagnosticId="SYSLIB0041", UrlFormat="https://aka.ms/dotnet-warnings/{0}")>]
new System.Security.Cryptography.Rfc2898DeriveBytes : string * byte[] * int -> System.Security.Cryptography.Rfc2898DeriveBytes
Public Sub New (password As String, salt As Byte(), iterations As Integer)
參數
- password
- String
用來推導金鑰的密碼。
- salt
- Byte[]
用來推導出鑰匙的 key salt。
- iterations
- Int32
運算的迭代次數。
- 屬性
例外狀況
指定的鹽大小小於 8 位元組,或迭代次數小於 1。
密碼或鹽是 null。
範例
以下程式碼範例利用該 Rfc2898DeriveBytes 類別來建立兩個相同的類別鍵 Aes 。 接著它會用金鑰加密和解密部分資料。
using System;
using System.IO;
using System.Text;
using System.Security.Cryptography;
public class rfc2898test
{
// Generate a key k1 with password pwd1 and salt salt1.
// Generate a key k2 with password pwd1 and salt salt1.
// Encrypt data1 with key k1 using symmetric encryption, creating edata1.
// Decrypt edata1 with key k2 using symmetric decryption, creating data2.
// data2 should equal data1.
private const string usageText = "Usage: RFC2898 <password>\nYou must specify the password for encryption.\n";
public static void Main(string[] passwordargs)
{
//If no file name is specified, write usage text.
if (passwordargs.Length == 0)
{
Console.WriteLine(usageText);
}
else
{
string pwd1 = passwordargs[0];
// Create a byte array to hold the random value.
byte[] salt1 = new byte[8];
using (RandomNumberGenerator rng = RandomNumberGenerator.Create())
{
// Fill the array with a random value.
rng.GetBytes(salt1);
}
//data1 can be a string or contents of a file.
string data1 = "Some test data";
//The legacy default iteration count is 1000 so the two methods use the same iteration count.
int myIterations = 1000;
try
{
Rfc2898DeriveBytes k1 = new Rfc2898DeriveBytes(pwd1, salt1,
myIterations);
Rfc2898DeriveBytes k2 = new Rfc2898DeriveBytes(pwd1, salt1);
// Encrypt the data.
Aes encAlg = Aes.Create();
encAlg.Key = k1.GetBytes(16);
MemoryStream encryptionStream = new MemoryStream();
CryptoStream encrypt = new CryptoStream(encryptionStream,
encAlg.CreateEncryptor(), CryptoStreamMode.Write);
byte[] utfD1 = new System.Text.UTF8Encoding(false).GetBytes(
data1);
encrypt.Write(utfD1, 0, utfD1.Length);
encrypt.FlushFinalBlock();
encrypt.Close();
byte[] edata1 = encryptionStream.ToArray();
k1.Reset();
// Try to decrypt, thus showing it can be round-tripped.
Aes decAlg = Aes.Create();
decAlg.Key = k2.GetBytes(16);
decAlg.IV = encAlg.IV;
MemoryStream decryptionStreamBacking = new MemoryStream();
CryptoStream decrypt = new CryptoStream(
decryptionStreamBacking, decAlg.CreateDecryptor(), CryptoStreamMode.Write);
decrypt.Write(edata1, 0, edata1.Length);
decrypt.Flush();
decrypt.Close();
k2.Reset();
string data2 = new UTF8Encoding(false).GetString(
decryptionStreamBacking.ToArray());
if (!data1.Equals(data2))
{
Console.WriteLine("Error: The two values are not equal.");
}
else
{
Console.WriteLine("The two values are equal.");
Console.WriteLine("k1 iterations: {0}", k1.IterationCount);
Console.WriteLine("k2 iterations: {0}", k2.IterationCount);
}
}
catch (Exception e)
{
Console.WriteLine("Error: {0}", e);
}
}
}
}
Imports System.IO
Imports System.Text
Imports System.Security.Cryptography
Public Class rfc2898test
' Generate a key k1 with password pwd1 and salt salt1.
' Generate a key k2 with password pwd1 and salt salt1.
' Encrypt data1 with key k1 using symmetric encryption, creating edata1.
' Decrypt edata1 with key k2 using symmetric decryption, creating data2.
' data2 should equal data1.
Private Const usageText As String = "Usage: RFC2898 <password>" + vbLf + "You must specify the password for encryption." + vbLf
Public Shared Sub Main(ByVal passwordargs() As String)
'If no file name is specified, write usage text.
If passwordargs.Length = 0 Then
Console.WriteLine(usageText)
Else
Dim pwd1 As String = passwordargs(0)
Dim salt1(8) As Byte
Using rng As RandomNumberGenerator = RandomNumberGenerator.Create()
rng.GetBytes(salt1)
End Using
'data1 can be a string or contents of a file.
Dim data1 As String = "Some test data"
'The legacy default iteration count is 1000 so the two methods use the same iteration count.
Dim myIterations As Integer = 1000
Try
Dim k1 As New Rfc2898DeriveBytes(pwd1, salt1, myIterations)
Dim k2 As New Rfc2898DeriveBytes(pwd1, salt1)
' Encrypt the data.
Dim encAlg As Aes = Aes.Create()
encAlg.Key = k1.GetBytes(16)
Dim encryptionStream As New MemoryStream()
Dim encrypt As New CryptoStream(encryptionStream, encAlg.CreateEncryptor(), CryptoStreamMode.Write)
Dim utfD1 As Byte() = New System.Text.UTF8Encoding(False).GetBytes(data1)
encrypt.Write(utfD1, 0, utfD1.Length)
encrypt.FlushFinalBlock()
encrypt.Close()
Dim edata1 As Byte() = encryptionStream.ToArray()
k1.Reset()
' Try to decrypt, thus showing it can be round-tripped.
Dim decAlg As Aes = Aes.Create()
decAlg.Key = k2.GetBytes(16)
decAlg.IV = encAlg.IV
Dim decryptionStreamBacking As New MemoryStream()
Dim decrypt As New CryptoStream(decryptionStreamBacking, decAlg.CreateDecryptor(), CryptoStreamMode.Write)
decrypt.Write(edata1, 0, edata1.Length)
decrypt.Flush()
decrypt.Close()
k2.Reset()
Dim data2 As String = New UTF8Encoding(False).GetString(decryptionStreamBacking.ToArray())
If Not data1.Equals(data2) Then
Console.WriteLine("Error: The two values are not equal.")
Else
Console.WriteLine("The two values are equal.")
Console.WriteLine("k1 iterations: {0}", k1.IterationCount)
Console.WriteLine("k2 iterations: {0}", k2.IterationCount)
End If
Catch e As Exception
Console.WriteLine("Error: ", e)
End Try
End If
End Sub
End Class
備註
鹽的大小必須是 8 位元組或以上,且迭代次數必須大於零。
RFC 2898 包含從密碼與鹽建立金鑰與初始化向量(IV)的方法。 你可以使用 PBKDF2,一種基於密碼的金鑰推導函式,透過偽隨機函式推導金鑰,該函式允許產生幾乎無限長度的金鑰。 此 Rfc2898DeriveBytes 類別可用於從基礎鍵及其他參數產生導出金鑰。 在基於密碼的金鑰導出函式中,基鍵是密碼,其他參數則是鹽值和迭代次數。
欲了解更多關於 PBKDF2 的資訊,請參閱 RFC 2898,標題為「PKCS #5:Password-Based 密碼學規範版本 2.0」。 完整詳情請參見第5.2節「PBKDF2」。
Important
千萬不要在原始碼裡硬寫密碼。 硬編碼密碼可透過 Ildasm.exe(IL 反組譯器)、十六進位編輯器,或直接在文字編輯器(如 Notepad.exe)中開啟組合語言來取得。
另請參閱
適用於
Rfc2898DeriveBytes(String, Int32, Int32)
警告
The constructors on Rfc2898DeriveBytes are obsolete. Use the static Pbkdf2 method instead.
警告
The default hash algorithm and iteration counts in Rfc2898DeriveBytes constructors are outdated and insecure. Use a constructor that accepts the hash algorithm and the number of iterations.
使用密碼、鹽大小及迭代次數初始化該類別的新實例 Rfc2898DeriveBytes 以推導金鑰。
public:
Rfc2898DeriveBytes(System::String ^ password, int saltSize, int iterations);
[System.Obsolete("The constructors on Rfc2898DeriveBytes are obsolete. Use the static Pbkdf2 method instead.", DiagnosticId="SYSLIB0060", UrlFormat="https://aka.ms/dotnet-warnings/{0}")]
public Rfc2898DeriveBytes(string password, int saltSize, int iterations);
public Rfc2898DeriveBytes(string password, int saltSize, int iterations);
[System.Obsolete("The default hash algorithm and iteration counts in Rfc2898DeriveBytes constructors are outdated and insecure. Use a constructor that accepts the hash algorithm and the number of iterations.", DiagnosticId="SYSLIB0041", UrlFormat="https://aka.ms/dotnet-warnings/{0}")]
public Rfc2898DeriveBytes(string password, int saltSize, int iterations);
[<System.Obsolete("The constructors on Rfc2898DeriveBytes are obsolete. Use the static Pbkdf2 method instead.", DiagnosticId="SYSLIB0060", UrlFormat="https://aka.ms/dotnet-warnings/{0}")>]
new System.Security.Cryptography.Rfc2898DeriveBytes : string * int * int -> System.Security.Cryptography.Rfc2898DeriveBytes
new System.Security.Cryptography.Rfc2898DeriveBytes : string * int * int -> System.Security.Cryptography.Rfc2898DeriveBytes
[<System.Obsolete("The default hash algorithm and iteration counts in Rfc2898DeriveBytes constructors are outdated and insecure. Use a constructor that accepts the hash algorithm and the number of iterations.", DiagnosticId="SYSLIB0041", UrlFormat="https://aka.ms/dotnet-warnings/{0}")>]
new System.Security.Cryptography.Rfc2898DeriveBytes : string * int * int -> System.Security.Cryptography.Rfc2898DeriveBytes
Public Sub New (password As String, saltSize As Integer, iterations As Integer)
參數
- password
- String
用來推導金鑰的密碼。
- saltSize
- Int32
你想讓類別產生的隨機鹽值大小。
- iterations
- Int32
運算的迭代次數。
- 屬性
例外狀況
指定的鹽大小小於 8 位元組,或迭代次數小於 1。
密碼或鹽是 null。
iterations 超出射程範圍。 此參數需要非負數值。
備註
鹽的大小必須是 8 位元組或以上,且迭代次數必須大於零。
RFC 2898 包含從密碼與鹽建立金鑰與初始化向量(IV)的方法。 你可以使用 PBKDF2,一種基於密碼的金鑰推導函式,透過偽隨機函式推導金鑰,該函式允許產生幾乎無限長度的金鑰。 此 Rfc2898DeriveBytes 類別可用於從基礎鍵及其他參數產生導出金鑰。 在基於密碼的金鑰導出函式中,基鍵是密碼,其他參數則是鹽值和迭代次數。
欲了解更多關於 PBKDF2 的資訊,請參閱 RFC 2898,標題為「PKCS #5:Password-Based 密碼學規範版本 2.0」。 完整詳情請參見第5.2節「PBKDF2」。
Important
千萬不要在原始碼裡硬寫密碼。 硬編碼密碼可透過 Ildasm.exe(IL 反組譯器)、十六進位編輯器,或直接在文字編輯器(如 Notepad.exe)中開啟組合語言來取得。
另請參閱
適用於
Rfc2898DeriveBytes(Byte[], Byte[], Int32, HashAlgorithmName)
警告
The constructors on Rfc2898DeriveBytes are obsolete. Use the static Pbkdf2 method instead.
使用指定的密碼、鹽值、迭代次數及雜湊演算法名稱初始化該類別的新實例 Rfc2898DeriveBytes ,以推導出金鑰。
public:
Rfc2898DeriveBytes(cli::array <System::Byte> ^ password, cli::array <System::Byte> ^ salt, int iterations, System::Security::Cryptography::HashAlgorithmName hashAlgorithm);
[System.Obsolete("The constructors on Rfc2898DeriveBytes are obsolete. Use the static Pbkdf2 method instead.", DiagnosticId="SYSLIB0060", UrlFormat="https://aka.ms/dotnet-warnings/{0}")]
public Rfc2898DeriveBytes(byte[] password, byte[] salt, int iterations, System.Security.Cryptography.HashAlgorithmName hashAlgorithm);
public Rfc2898DeriveBytes(byte[] password, byte[] salt, int iterations, System.Security.Cryptography.HashAlgorithmName hashAlgorithm);
[<System.Obsolete("The constructors on Rfc2898DeriveBytes are obsolete. Use the static Pbkdf2 method instead.", DiagnosticId="SYSLIB0060", UrlFormat="https://aka.ms/dotnet-warnings/{0}")>]
new System.Security.Cryptography.Rfc2898DeriveBytes : byte[] * byte[] * int * System.Security.Cryptography.HashAlgorithmName -> System.Security.Cryptography.Rfc2898DeriveBytes
new System.Security.Cryptography.Rfc2898DeriveBytes : byte[] * byte[] * int * System.Security.Cryptography.HashAlgorithmName -> System.Security.Cryptography.Rfc2898DeriveBytes
Public Sub New (password As Byte(), salt As Byte(), iterations As Integer, hashAlgorithm As HashAlgorithmName)
參數
- password
- Byte[]
用來推導金鑰的密碼。
- salt
- Byte[]
用來推導金鑰的 key salt。
- iterations
- Int32
運算的迭代次數。
- hashAlgorithm
- HashAlgorithmName
用來推導金鑰的雜湊演算法。
- 屬性
例外狀況
雜湊演算法名稱無效。
適用於
Rfc2898DeriveBytes(String, Byte[], Int32, HashAlgorithmName)
警告
The constructors on Rfc2898DeriveBytes are obsolete. Use the static Pbkdf2 method instead.
使用指定的密碼、鹽值、迭代次數及雜湊演算法名稱初始化該類別的新實例 Rfc2898DeriveBytes ,以推導出金鑰。
public:
Rfc2898DeriveBytes(System::String ^ password, cli::array <System::Byte> ^ salt, int iterations, System::Security::Cryptography::HashAlgorithmName hashAlgorithm);
[System.Obsolete("The constructors on Rfc2898DeriveBytes are obsolete. Use the static Pbkdf2 method instead.", DiagnosticId="SYSLIB0060", UrlFormat="https://aka.ms/dotnet-warnings/{0}")]
public Rfc2898DeriveBytes(string password, byte[] salt, int iterations, System.Security.Cryptography.HashAlgorithmName hashAlgorithm);
public Rfc2898DeriveBytes(string password, byte[] salt, int iterations, System.Security.Cryptography.HashAlgorithmName hashAlgorithm);
[<System.Obsolete("The constructors on Rfc2898DeriveBytes are obsolete. Use the static Pbkdf2 method instead.", DiagnosticId="SYSLIB0060", UrlFormat="https://aka.ms/dotnet-warnings/{0}")>]
new System.Security.Cryptography.Rfc2898DeriveBytes : string * byte[] * int * System.Security.Cryptography.HashAlgorithmName -> System.Security.Cryptography.Rfc2898DeriveBytes
new System.Security.Cryptography.Rfc2898DeriveBytes : string * byte[] * int * System.Security.Cryptography.HashAlgorithmName -> System.Security.Cryptography.Rfc2898DeriveBytes
Public Sub New (password As String, salt As Byte(), iterations As Integer, hashAlgorithm As HashAlgorithmName)
參數
- password
- String
用來推導金鑰的密碼。
- salt
- Byte[]
用來推導金鑰的 key salt。
- iterations
- Int32
運算的迭代次數。
- hashAlgorithm
- HashAlgorithmName
用來推導金鑰的雜湊演算法。
- 屬性
例外狀況
雜湊演算法名稱無效。
適用於
Rfc2898DeriveBytes(String, Int32, Int32, HashAlgorithmName)
警告
The constructors on Rfc2898DeriveBytes are obsolete. Use the static Pbkdf2 method instead.
使用指定的密碼、鹽大小、迭代次數及雜湊演算法名稱初始化該類別的新實例 Rfc2898DeriveBytes ,以推導金鑰。
public:
Rfc2898DeriveBytes(System::String ^ password, int saltSize, int iterations, System::Security::Cryptography::HashAlgorithmName hashAlgorithm);
[System.Obsolete("The constructors on Rfc2898DeriveBytes are obsolete. Use the static Pbkdf2 method instead.", DiagnosticId="SYSLIB0060", UrlFormat="https://aka.ms/dotnet-warnings/{0}")]
public Rfc2898DeriveBytes(string password, int saltSize, int iterations, System.Security.Cryptography.HashAlgorithmName hashAlgorithm);
public Rfc2898DeriveBytes(string password, int saltSize, int iterations, System.Security.Cryptography.HashAlgorithmName hashAlgorithm);
[<System.Obsolete("The constructors on Rfc2898DeriveBytes are obsolete. Use the static Pbkdf2 method instead.", DiagnosticId="SYSLIB0060", UrlFormat="https://aka.ms/dotnet-warnings/{0}")>]
new System.Security.Cryptography.Rfc2898DeriveBytes : string * int * int * System.Security.Cryptography.HashAlgorithmName -> System.Security.Cryptography.Rfc2898DeriveBytes
new System.Security.Cryptography.Rfc2898DeriveBytes : string * int * int * System.Security.Cryptography.HashAlgorithmName -> System.Security.Cryptography.Rfc2898DeriveBytes
Public Sub New (password As String, saltSize As Integer, iterations As Integer, hashAlgorithm As HashAlgorithmName)
參數
- password
- String
用來推導金鑰的密碼。
- saltSize
- Int32
你想讓類別產生的隨機鹽值大小。
- iterations
- Int32
運算的迭代次數。
- hashAlgorithm
- HashAlgorithmName
用來推導金鑰的雜湊演算法。
- 屬性
例外狀況
saltSize 小於零。
雜湊演算法名稱無效。