語言

Rfc2898DeriveBytes 建構函式

定義

初始化 Rfc2898DeriveBytes 類別的新執行個體。

多載

名稱 Description
Rfc2898DeriveBytes(String, Byte[])
已淘汰.
已淘汰.

初始化一個新的類別實例 Rfc2898DeriveBytes ,使用密碼和鹽來推導金鑰。

Rfc2898DeriveBytes(String, Int32)
已淘汰.
已淘汰.

利用密碼和鹽大小初始化該類別的新實例 Rfc2898DeriveBytes 以推導金鑰。

Rfc2898DeriveBytes(Byte[], Byte[], Int32)
已淘汰.
已淘汰.

使用密碼、鹽值及迭代次數初始化該類別的新實例 Rfc2898DeriveBytes 以推導金鑰。

Rfc2898DeriveBytes(String, Byte[], Int32)
已淘汰.
已淘汰.

使用密碼、鹽值及迭代次數初始化該類別的新實例 Rfc2898DeriveBytes 以推導金鑰。

Rfc2898DeriveBytes(String, Int32, Int32)
已淘汰.
已淘汰.

使用密碼、鹽大小及迭代次數初始化該類別的新實例 Rfc2898DeriveBytes 以推導金鑰。

Rfc2898DeriveBytes(Byte[], Byte[], Int32, HashAlgorithmName)
已淘汰.

使用指定的密碼、鹽值、迭代次數及雜湊演算法名稱初始化該類別的新實例 Rfc2898DeriveBytes ,以推導出金鑰。

Rfc2898DeriveBytes(String, Byte[], Int32, HashAlgorithmName)
已淘汰.

使用指定的密碼、鹽值、迭代次數及雜湊演算法名稱初始化該類別的新實例 Rfc2898DeriveBytes ,以推導出金鑰。

Rfc2898DeriveBytes(String, Int32, Int32, HashAlgorithmName)
已淘汰.

使用指定的密碼、鹽大小、迭代次數及雜湊演算法名稱初始化該類別的新實例 Rfc2898DeriveBytes ,以推導金鑰。

Rfc2898DeriveBytes(String, Byte[])

來源:
Rfc2898DeriveBytes.cs
來源:
Rfc2898DeriveBytes.cs
來源:
Rfc2898DeriveBytes.cs
來源:
Rfc2898DeriveBytes.cs
來源:
Rfc2898DeriveBytes.cs

警告

The constructors on Rfc2898DeriveBytes are obsolete. Use the static Pbkdf2 method instead.

警告

The default hash algorithm and iteration counts in Rfc2898DeriveBytes constructors are outdated and insecure. Use a constructor that accepts the hash algorithm and the number of iterations.

初始化一個新的類別實例 Rfc2898DeriveBytes ,使用密碼和鹽來推導金鑰。

public:
 Rfc2898DeriveBytes(System::String ^ password, cli::array <System::Byte> ^ salt);
[System.Obsolete("The constructors on Rfc2898DeriveBytes are obsolete. Use the static Pbkdf2 method instead.", DiagnosticId="SYSLIB0060", UrlFormat="https://aka.ms/dotnet-warnings/{0}")]
public Rfc2898DeriveBytes(string password, byte[] salt);
public Rfc2898DeriveBytes(string password, byte[] salt);
[System.Obsolete("The default hash algorithm and iteration counts in Rfc2898DeriveBytes constructors are outdated and insecure. Use a constructor that accepts the hash algorithm and the number of iterations.", DiagnosticId="SYSLIB0041", UrlFormat="https://aka.ms/dotnet-warnings/{0}")]
public Rfc2898DeriveBytes(string password, byte[] salt);
[<System.Obsolete("The constructors on Rfc2898DeriveBytes are obsolete. Use the static Pbkdf2 method instead.", DiagnosticId="SYSLIB0060", UrlFormat="https://aka.ms/dotnet-warnings/{0}")>]
new System.Security.Cryptography.Rfc2898DeriveBytes : string * byte[] -> System.Security.Cryptography.Rfc2898DeriveBytes
new System.Security.Cryptography.Rfc2898DeriveBytes : string * byte[] -> System.Security.Cryptography.Rfc2898DeriveBytes
[<System.Obsolete("The default hash algorithm and iteration counts in Rfc2898DeriveBytes constructors are outdated and insecure. Use a constructor that accepts the hash algorithm and the number of iterations.", DiagnosticId="SYSLIB0041", UrlFormat="https://aka.ms/dotnet-warnings/{0}")>]
new System.Security.Cryptography.Rfc2898DeriveBytes : string * byte[] -> System.Security.Cryptography.Rfc2898DeriveBytes
Public Sub New (password As String, salt As Byte())

參數

password
String

用來推導金鑰的密碼。

salt
Byte[]

用來推導出鑰匙的 key salt。

屬性

例外狀況

指定的鹽大小小於 8 位元組,或迭代次數小於 1。

密碼或鹽是 null。

範例

以下程式碼範例利用該 Rfc2898DeriveBytes 類別來建立兩個相同的類別鍵 Aes 。 接著它會用金鑰加密和解密部分資料。

using System;
using System.IO;
using System.Text;
using System.Security.Cryptography;

public class rfc2898test
{
    // Generate a key k1 with password pwd1 and salt salt1.
    // Generate a key k2 with password pwd1 and salt salt1.
    // Encrypt data1 with key k1 using symmetric encryption, creating edata1.
    // Decrypt edata1 with key k2 using symmetric decryption, creating data2.
    // data2 should equal data1.

    private const string usageText = "Usage: RFC2898 <password>\nYou must specify the password for encryption.\n";
    public static void Main(string[] passwordargs)
    {
        //If no file name is specified, write usage text.
        if (passwordargs.Length == 0)
        {
            Console.WriteLine(usageText);
        }
        else
        {
            string pwd1 = passwordargs[0];
            // Create a byte array to hold the random value.
            byte[] salt1 = new byte[8];
            using (RandomNumberGenerator rng = RandomNumberGenerator.Create())
            {
                // Fill the array with a random value.
                rng.GetBytes(salt1);
            }

            //data1 can be a string or contents of a file.
            string data1 = "Some test data";
            //The legacy default iteration count is 1000 so the two methods use the same iteration count.
            int myIterations = 1000;
            try
            {
                Rfc2898DeriveBytes k1 = new Rfc2898DeriveBytes(pwd1, salt1,
myIterations);
                Rfc2898DeriveBytes k2 = new Rfc2898DeriveBytes(pwd1, salt1);
                // Encrypt the data.
                Aes encAlg = Aes.Create();
                encAlg.Key = k1.GetBytes(16);
                MemoryStream encryptionStream = new MemoryStream();
                CryptoStream encrypt = new CryptoStream(encryptionStream,
encAlg.CreateEncryptor(), CryptoStreamMode.Write);
                byte[] utfD1 = new System.Text.UTF8Encoding(false).GetBytes(
data1);

                encrypt.Write(utfD1, 0, utfD1.Length);
                encrypt.FlushFinalBlock();
                encrypt.Close();
                byte[] edata1 = encryptionStream.ToArray();
                k1.Reset();

                // Try to decrypt, thus showing it can be round-tripped.
                Aes decAlg = Aes.Create();
                decAlg.Key = k2.GetBytes(16);
                decAlg.IV = encAlg.IV;
                MemoryStream decryptionStreamBacking = new MemoryStream();
                CryptoStream decrypt = new CryptoStream(
decryptionStreamBacking, decAlg.CreateDecryptor(), CryptoStreamMode.Write);
                decrypt.Write(edata1, 0, edata1.Length);
                decrypt.Flush();
                decrypt.Close();
                k2.Reset();
                string data2 = new UTF8Encoding(false).GetString(
decryptionStreamBacking.ToArray());

                if (!data1.Equals(data2))
                {
                    Console.WriteLine("Error: The two values are not equal.");
                }
                else
                {
                    Console.WriteLine("The two values are equal.");
                    Console.WriteLine("k1 iterations: {0}", k1.IterationCount);
                    Console.WriteLine("k2 iterations: {0}", k2.IterationCount);
                }
            }
            catch (Exception e)
            {
                Console.WriteLine("Error: {0}", e);
            }
        }
    }
}
Imports System.IO
Imports System.Text
Imports System.Security.Cryptography



Public Class rfc2898test
    ' Generate a key k1 with password pwd1 and salt salt1.
    ' Generate a key k2 with password pwd1 and salt salt1.
    ' Encrypt data1 with key k1 using symmetric encryption, creating edata1.
    ' Decrypt edata1 with key k2 using symmetric decryption, creating data2.
    ' data2 should equal data1.
    Private Const usageText As String = "Usage: RFC2898 <password>" + vbLf + "You must specify the password for encryption." + vbLf

    Public Shared Sub Main(ByVal passwordargs() As String)
        'If no file name is specified, write usage text.
        If passwordargs.Length = 0 Then
            Console.WriteLine(usageText)
        Else
            Dim pwd1 As String = passwordargs(0)

            Dim salt1(8) As Byte
            Using rng As RandomNumberGenerator = RandomNumberGenerator.Create()
                rng.GetBytes(salt1)
            End Using
            'data1 can be a string or contents of a file.
            Dim data1 As String = "Some test data"
            'The legacy default iteration count is 1000 so the two methods use the same iteration count.
            Dim myIterations As Integer = 1000
            Try
                Dim k1 As New Rfc2898DeriveBytes(pwd1, salt1, myIterations)
                Dim k2 As New Rfc2898DeriveBytes(pwd1, salt1)
                ' Encrypt the data.
                Dim encAlg As Aes = Aes.Create()
                encAlg.Key = k1.GetBytes(16)
                Dim encryptionStream As New MemoryStream()
                Dim encrypt As New CryptoStream(encryptionStream, encAlg.CreateEncryptor(), CryptoStreamMode.Write)
                Dim utfD1 As Byte() = New System.Text.UTF8Encoding(False).GetBytes(data1)
                encrypt.Write(utfD1, 0, utfD1.Length)
                encrypt.FlushFinalBlock()
                encrypt.Close()
                Dim edata1 As Byte() = encryptionStream.ToArray()
                k1.Reset()

                ' Try to decrypt, thus showing it can be round-tripped.
                Dim decAlg As Aes = Aes.Create()
                decAlg.Key = k2.GetBytes(16)
                decAlg.IV = encAlg.IV
                Dim decryptionStreamBacking As New MemoryStream()
                Dim decrypt As New CryptoStream(decryptionStreamBacking, decAlg.CreateDecryptor(), CryptoStreamMode.Write)
                decrypt.Write(edata1, 0, edata1.Length)
                decrypt.Flush()
                decrypt.Close()
                k2.Reset()
                Dim data2 As String = New UTF8Encoding(False).GetString(decryptionStreamBacking.ToArray())

                If Not data1.Equals(data2) Then
                    Console.WriteLine("Error: The two values are not equal.")
                Else
                    Console.WriteLine("The two values are equal.")
                    Console.WriteLine("k1 iterations: {0}", k1.IterationCount)
                    Console.WriteLine("k2 iterations: {0}", k2.IterationCount)
                End If
            Catch e As Exception
                Console.WriteLine("Error: ", e)
            End Try
        End If

    End Sub
End Class

備註

鹽的大小必須是 8 位元組或以上。

RFC 2898 包含從密碼與鹽建立金鑰與初始化向量(IV)的方法。 你可以使用 PBKDF2,一種基於密碼的金鑰推導函式,透過偽隨機函式推導金鑰,該函式允許產生幾乎無限長度的金鑰。 此 Rfc2898DeriveBytes 類別可用於從基礎鍵及其他參數產生導出金鑰。 在基於密碼的金鑰導出函式中,基鍵是密碼,其他參數則是鹽值和迭代次數。

欲了解更多關於 PBKDF2 的資訊,請參閱 RFC 2898,標題為「PKCS #5:Password-Based 密碼學規範版本 2.0」。 完整詳情請參見第5.2節「PBKDF2」。

Important

千萬不要在原始碼裡硬寫密碼。 硬編碼密碼可透過 Ildasm.exe(IL 反組譯器)、十六進位編輯器,或直接在文字編輯器(如 Notepad.exe)中開啟組合語言來取得。

另請參閱

適用於

Rfc2898DeriveBytes(String, Int32)

來源:
Rfc2898DeriveBytes.cs
來源:
Rfc2898DeriveBytes.cs
來源:
Rfc2898DeriveBytes.cs
來源:
Rfc2898DeriveBytes.cs
來源:
Rfc2898DeriveBytes.cs

警告

The constructors on Rfc2898DeriveBytes are obsolete. Use the static Pbkdf2 method instead.

警告

The default hash algorithm and iteration counts in Rfc2898DeriveBytes constructors are outdated and insecure. Use a constructor that accepts the hash algorithm and the number of iterations.

利用密碼和鹽大小初始化該類別的新實例 Rfc2898DeriveBytes 以推導金鑰。

public:
 Rfc2898DeriveBytes(System::String ^ password, int saltSize);
[System.Obsolete("The constructors on Rfc2898DeriveBytes are obsolete. Use the static Pbkdf2 method instead.", DiagnosticId="SYSLIB0060", UrlFormat="https://aka.ms/dotnet-warnings/{0}")]
public Rfc2898DeriveBytes(string password, int saltSize);
public Rfc2898DeriveBytes(string password, int saltSize);
[System.Obsolete("The default hash algorithm and iteration counts in Rfc2898DeriveBytes constructors are outdated and insecure. Use a constructor that accepts the hash algorithm and the number of iterations.", DiagnosticId="SYSLIB0041", UrlFormat="https://aka.ms/dotnet-warnings/{0}")]
public Rfc2898DeriveBytes(string password, int saltSize);
[<System.Obsolete("The constructors on Rfc2898DeriveBytes are obsolete. Use the static Pbkdf2 method instead.", DiagnosticId="SYSLIB0060", UrlFormat="https://aka.ms/dotnet-warnings/{0}")>]
new System.Security.Cryptography.Rfc2898DeriveBytes : string * int -> System.Security.Cryptography.Rfc2898DeriveBytes
new System.Security.Cryptography.Rfc2898DeriveBytes : string * int -> System.Security.Cryptography.Rfc2898DeriveBytes
[<System.Obsolete("The default hash algorithm and iteration counts in Rfc2898DeriveBytes constructors are outdated and insecure. Use a constructor that accepts the hash algorithm and the number of iterations.", DiagnosticId="SYSLIB0041", UrlFormat="https://aka.ms/dotnet-warnings/{0}")>]
new System.Security.Cryptography.Rfc2898DeriveBytes : string * int -> System.Security.Cryptography.Rfc2898DeriveBytes
Public Sub New (password As String, saltSize As Integer)

參數

password
String

用來推導金鑰的密碼。

saltSize
Int32

你想讓類別產生的隨機鹽值大小。

屬性

例外狀況

指定的鹽大小小於 8 位元組。

密碼或鹽是 null。

備註

鹽的大小必須是 8 位元組或以上。

RFC 2898 包含從密碼與鹽建立金鑰與初始化向量(IV)的方法。 你可以使用 PBKDF2,一種基於密碼的金鑰推導函式,透過偽隨機函式推導金鑰,該函式允許產生幾乎無限長度的金鑰。 此 Rfc2898DeriveBytes 類別可用於從基礎鍵及其他參數產生導出金鑰。 在基於密碼的金鑰導出函式中,基鍵是密碼,其他參數則是鹽值和迭代次數。

欲了解更多關於 PBKDF2 的資訊,請參閱 RFC 2898,標題為「PKCS #5:Password-Based 密碼學規範版本 2.0」。 完整詳情請參見第5.2節「PBKDF2」。

Important

千萬不要在原始碼裡硬寫密碼。 硬編碼密碼可透過 Ildasm.exe(IL 反組譯器)、十六進位編輯器,或直接在文字編輯器(如 Notepad.exe)中開啟組合語言來取得。

另請參閱

適用於

Rfc2898DeriveBytes(Byte[], Byte[], Int32)

來源:
Rfc2898DeriveBytes.cs
來源:
Rfc2898DeriveBytes.cs
來源:
Rfc2898DeriveBytes.cs
來源:
Rfc2898DeriveBytes.cs
來源:
Rfc2898DeriveBytes.cs

警告

The constructors on Rfc2898DeriveBytes are obsolete. Use the static Pbkdf2 method instead.

警告

The default hash algorithm and iteration counts in Rfc2898DeriveBytes constructors are outdated and insecure. Use a constructor that accepts the hash algorithm and the number of iterations.

使用密碼、鹽值及迭代次數初始化該類別的新實例 Rfc2898DeriveBytes 以推導金鑰。

public:
 Rfc2898DeriveBytes(cli::array <System::Byte> ^ password, cli::array <System::Byte> ^ salt, int iterations);
[System.Obsolete("The constructors on Rfc2898DeriveBytes are obsolete. Use the static Pbkdf2 method instead.", DiagnosticId="SYSLIB0060", UrlFormat="https://aka.ms/dotnet-warnings/{0}")]
public Rfc2898DeriveBytes(byte[] password, byte[] salt, int iterations);
public Rfc2898DeriveBytes(byte[] password, byte[] salt, int iterations);
[System.Obsolete("The default hash algorithm and iteration counts in Rfc2898DeriveBytes constructors are outdated and insecure. Use a constructor that accepts the hash algorithm and the number of iterations.", DiagnosticId="SYSLIB0041", UrlFormat="https://aka.ms/dotnet-warnings/{0}")]
public Rfc2898DeriveBytes(byte[] password, byte[] salt, int iterations);
[<System.Obsolete("The constructors on Rfc2898DeriveBytes are obsolete. Use the static Pbkdf2 method instead.", DiagnosticId="SYSLIB0060", UrlFormat="https://aka.ms/dotnet-warnings/{0}")>]
new System.Security.Cryptography.Rfc2898DeriveBytes : byte[] * byte[] * int -> System.Security.Cryptography.Rfc2898DeriveBytes
new System.Security.Cryptography.Rfc2898DeriveBytes : byte[] * byte[] * int -> System.Security.Cryptography.Rfc2898DeriveBytes
[<System.Obsolete("The default hash algorithm and iteration counts in Rfc2898DeriveBytes constructors are outdated and insecure. Use a constructor that accepts the hash algorithm and the number of iterations.", DiagnosticId="SYSLIB0041", UrlFormat="https://aka.ms/dotnet-warnings/{0}")>]
new System.Security.Cryptography.Rfc2898DeriveBytes : byte[] * byte[] * int -> System.Security.Cryptography.Rfc2898DeriveBytes
Public Sub New (password As Byte(), salt As Byte(), iterations As Integer)

參數

password
Byte[]

用來推導金鑰的密碼。

salt
Byte[]

用來推導出鑰匙的 key salt。

iterations
Int32

運算的迭代次數。

屬性

例外狀況

指定的鹽大小小於 8 位元組,或迭代次數小於 1。

密碼或鹽是 null。

備註

鹽的大小必須是 8 位元組或以上,且迭代次數必須大於零。

RFC 2898 包含從密碼與鹽建立金鑰與初始化向量(IV)的方法。 你可以使用 PBKDF2,一種基於密碼的金鑰推導函式,透過偽隨機函式推導金鑰,該函式允許產生幾乎無限長度的金鑰。 此 Rfc2898DeriveBytes 類別可用於從基礎鍵及其他參數產生導出金鑰。 在基於密碼的金鑰導出函式中,基鍵是密碼,其他參數則是鹽值和迭代次數。

欲了解更多關於 PBKDF2 的資訊,請參閱 RFC 2898,標題為「PKCS #5:Password-Based 密碼學規範版本 2.0」。 完整詳情請參見第5.2節「PBKDF2」。

Important

千萬不要在原始碼裡硬寫密碼。 硬編碼密碼可透過 Ildasm.exe(IL 反組譯器)、十六進位編輯器,或直接在文字編輯器(如 Notepad.exe)中開啟組合語言來取得。

適用於

Rfc2898DeriveBytes(String, Byte[], Int32)

來源:
Rfc2898DeriveBytes.cs
來源:
Rfc2898DeriveBytes.cs
來源:
Rfc2898DeriveBytes.cs
來源:
Rfc2898DeriveBytes.cs
來源:
Rfc2898DeriveBytes.cs

警告

The constructors on Rfc2898DeriveBytes are obsolete. Use the static Pbkdf2 method instead.

警告

The default hash algorithm and iteration counts in Rfc2898DeriveBytes constructors are outdated and insecure. Use a constructor that accepts the hash algorithm and the number of iterations.

使用密碼、鹽值及迭代次數初始化該類別的新實例 Rfc2898DeriveBytes 以推導金鑰。

public:
 Rfc2898DeriveBytes(System::String ^ password, cli::array <System::Byte> ^ salt, int iterations);
[System.Obsolete("The constructors on Rfc2898DeriveBytes are obsolete. Use the static Pbkdf2 method instead.", DiagnosticId="SYSLIB0060", UrlFormat="https://aka.ms/dotnet-warnings/{0}")]
public Rfc2898DeriveBytes(string password, byte[] salt, int iterations);
public Rfc2898DeriveBytes(string password, byte[] salt, int iterations);
[System.Obsolete("The default hash algorithm and iteration counts in Rfc2898DeriveBytes constructors are outdated and insecure. Use a constructor that accepts the hash algorithm and the number of iterations.", DiagnosticId="SYSLIB0041", UrlFormat="https://aka.ms/dotnet-warnings/{0}")]
public Rfc2898DeriveBytes(string password, byte[] salt, int iterations);
[<System.Obsolete("The constructors on Rfc2898DeriveBytes are obsolete. Use the static Pbkdf2 method instead.", DiagnosticId="SYSLIB0060", UrlFormat="https://aka.ms/dotnet-warnings/{0}")>]
new System.Security.Cryptography.Rfc2898DeriveBytes : string * byte[] * int -> System.Security.Cryptography.Rfc2898DeriveBytes
new System.Security.Cryptography.Rfc2898DeriveBytes : string * byte[] * int -> System.Security.Cryptography.Rfc2898DeriveBytes
[<System.Obsolete("The default hash algorithm and iteration counts in Rfc2898DeriveBytes constructors are outdated and insecure. Use a constructor that accepts the hash algorithm and the number of iterations.", DiagnosticId="SYSLIB0041", UrlFormat="https://aka.ms/dotnet-warnings/{0}")>]
new System.Security.Cryptography.Rfc2898DeriveBytes : string * byte[] * int -> System.Security.Cryptography.Rfc2898DeriveBytes
Public Sub New (password As String, salt As Byte(), iterations As Integer)

參數

password
String

用來推導金鑰的密碼。

salt
Byte[]

用來推導出鑰匙的 key salt。

iterations
Int32

運算的迭代次數。

屬性

例外狀況

指定的鹽大小小於 8 位元組,或迭代次數小於 1。

密碼或鹽是 null。

範例

以下程式碼範例利用該 Rfc2898DeriveBytes 類別來建立兩個相同的類別鍵 Aes 。 接著它會用金鑰加密和解密部分資料。

using System;
using System.IO;
using System.Text;
using System.Security.Cryptography;

public class rfc2898test
{
    // Generate a key k1 with password pwd1 and salt salt1.
    // Generate a key k2 with password pwd1 and salt salt1.
    // Encrypt data1 with key k1 using symmetric encryption, creating edata1.
    // Decrypt edata1 with key k2 using symmetric decryption, creating data2.
    // data2 should equal data1.

    private const string usageText = "Usage: RFC2898 <password>\nYou must specify the password for encryption.\n";
    public static void Main(string[] passwordargs)
    {
        //If no file name is specified, write usage text.
        if (passwordargs.Length == 0)
        {
            Console.WriteLine(usageText);
        }
        else
        {
            string pwd1 = passwordargs[0];
            // Create a byte array to hold the random value.
            byte[] salt1 = new byte[8];
            using (RandomNumberGenerator rng = RandomNumberGenerator.Create())
            {
                // Fill the array with a random value.
                rng.GetBytes(salt1);
            }

            //data1 can be a string or contents of a file.
            string data1 = "Some test data";
            //The legacy default iteration count is 1000 so the two methods use the same iteration count.
            int myIterations = 1000;
            try
            {
                Rfc2898DeriveBytes k1 = new Rfc2898DeriveBytes(pwd1, salt1,
myIterations);
                Rfc2898DeriveBytes k2 = new Rfc2898DeriveBytes(pwd1, salt1);
                // Encrypt the data.
                Aes encAlg = Aes.Create();
                encAlg.Key = k1.GetBytes(16);
                MemoryStream encryptionStream = new MemoryStream();
                CryptoStream encrypt = new CryptoStream(encryptionStream,
encAlg.CreateEncryptor(), CryptoStreamMode.Write);
                byte[] utfD1 = new System.Text.UTF8Encoding(false).GetBytes(
data1);

                encrypt.Write(utfD1, 0, utfD1.Length);
                encrypt.FlushFinalBlock();
                encrypt.Close();
                byte[] edata1 = encryptionStream.ToArray();
                k1.Reset();

                // Try to decrypt, thus showing it can be round-tripped.
                Aes decAlg = Aes.Create();
                decAlg.Key = k2.GetBytes(16);
                decAlg.IV = encAlg.IV;
                MemoryStream decryptionStreamBacking = new MemoryStream();
                CryptoStream decrypt = new CryptoStream(
decryptionStreamBacking, decAlg.CreateDecryptor(), CryptoStreamMode.Write);
                decrypt.Write(edata1, 0, edata1.Length);
                decrypt.Flush();
                decrypt.Close();
                k2.Reset();
                string data2 = new UTF8Encoding(false).GetString(
decryptionStreamBacking.ToArray());

                if (!data1.Equals(data2))
                {
                    Console.WriteLine("Error: The two values are not equal.");
                }
                else
                {
                    Console.WriteLine("The two values are equal.");
                    Console.WriteLine("k1 iterations: {0}", k1.IterationCount);
                    Console.WriteLine("k2 iterations: {0}", k2.IterationCount);
                }
            }
            catch (Exception e)
            {
                Console.WriteLine("Error: {0}", e);
            }
        }
    }
}
Imports System.IO
Imports System.Text
Imports System.Security.Cryptography



Public Class rfc2898test
    ' Generate a key k1 with password pwd1 and salt salt1.
    ' Generate a key k2 with password pwd1 and salt salt1.
    ' Encrypt data1 with key k1 using symmetric encryption, creating edata1.
    ' Decrypt edata1 with key k2 using symmetric decryption, creating data2.
    ' data2 should equal data1.
    Private Const usageText As String = "Usage: RFC2898 <password>" + vbLf + "You must specify the password for encryption." + vbLf

    Public Shared Sub Main(ByVal passwordargs() As String)
        'If no file name is specified, write usage text.
        If passwordargs.Length = 0 Then
            Console.WriteLine(usageText)
        Else
            Dim pwd1 As String = passwordargs(0)

            Dim salt1(8) As Byte
            Using rng As RandomNumberGenerator = RandomNumberGenerator.Create()
                rng.GetBytes(salt1)
            End Using
            'data1 can be a string or contents of a file.
            Dim data1 As String = "Some test data"
            'The legacy default iteration count is 1000 so the two methods use the same iteration count.
            Dim myIterations As Integer = 1000
            Try
                Dim k1 As New Rfc2898DeriveBytes(pwd1, salt1, myIterations)
                Dim k2 As New Rfc2898DeriveBytes(pwd1, salt1)
                ' Encrypt the data.
                Dim encAlg As Aes = Aes.Create()
                encAlg.Key = k1.GetBytes(16)
                Dim encryptionStream As New MemoryStream()
                Dim encrypt As New CryptoStream(encryptionStream, encAlg.CreateEncryptor(), CryptoStreamMode.Write)
                Dim utfD1 As Byte() = New System.Text.UTF8Encoding(False).GetBytes(data1)
                encrypt.Write(utfD1, 0, utfD1.Length)
                encrypt.FlushFinalBlock()
                encrypt.Close()
                Dim edata1 As Byte() = encryptionStream.ToArray()
                k1.Reset()

                ' Try to decrypt, thus showing it can be round-tripped.
                Dim decAlg As Aes = Aes.Create()
                decAlg.Key = k2.GetBytes(16)
                decAlg.IV = encAlg.IV
                Dim decryptionStreamBacking As New MemoryStream()
                Dim decrypt As New CryptoStream(decryptionStreamBacking, decAlg.CreateDecryptor(), CryptoStreamMode.Write)
                decrypt.Write(edata1, 0, edata1.Length)
                decrypt.Flush()
                decrypt.Close()
                k2.Reset()
                Dim data2 As String = New UTF8Encoding(False).GetString(decryptionStreamBacking.ToArray())

                If Not data1.Equals(data2) Then
                    Console.WriteLine("Error: The two values are not equal.")
                Else
                    Console.WriteLine("The two values are equal.")
                    Console.WriteLine("k1 iterations: {0}", k1.IterationCount)
                    Console.WriteLine("k2 iterations: {0}", k2.IterationCount)
                End If
            Catch e As Exception
                Console.WriteLine("Error: ", e)
            End Try
        End If

    End Sub
End Class

備註

鹽的大小必須是 8 位元組或以上,且迭代次數必須大於零。

RFC 2898 包含從密碼與鹽建立金鑰與初始化向量(IV)的方法。 你可以使用 PBKDF2,一種基於密碼的金鑰推導函式,透過偽隨機函式推導金鑰,該函式允許產生幾乎無限長度的金鑰。 此 Rfc2898DeriveBytes 類別可用於從基礎鍵及其他參數產生導出金鑰。 在基於密碼的金鑰導出函式中,基鍵是密碼,其他參數則是鹽值和迭代次數。

欲了解更多關於 PBKDF2 的資訊,請參閱 RFC 2898,標題為「PKCS #5:Password-Based 密碼學規範版本 2.0」。 完整詳情請參見第5.2節「PBKDF2」。

Important

千萬不要在原始碼裡硬寫密碼。 硬編碼密碼可透過 Ildasm.exe(IL 反組譯器)、十六進位編輯器,或直接在文字編輯器(如 Notepad.exe)中開啟組合語言來取得。

另請參閱

適用於

Rfc2898DeriveBytes(String, Int32, Int32)

來源:
Rfc2898DeriveBytes.cs
來源:
Rfc2898DeriveBytes.cs
來源:
Rfc2898DeriveBytes.cs
來源:
Rfc2898DeriveBytes.cs
來源:
Rfc2898DeriveBytes.cs

警告

The constructors on Rfc2898DeriveBytes are obsolete. Use the static Pbkdf2 method instead.

警告

The default hash algorithm and iteration counts in Rfc2898DeriveBytes constructors are outdated and insecure. Use a constructor that accepts the hash algorithm and the number of iterations.

使用密碼、鹽大小及迭代次數初始化該類別的新實例 Rfc2898DeriveBytes 以推導金鑰。

public:
 Rfc2898DeriveBytes(System::String ^ password, int saltSize, int iterations);
[System.Obsolete("The constructors on Rfc2898DeriveBytes are obsolete. Use the static Pbkdf2 method instead.", DiagnosticId="SYSLIB0060", UrlFormat="https://aka.ms/dotnet-warnings/{0}")]
public Rfc2898DeriveBytes(string password, int saltSize, int iterations);
public Rfc2898DeriveBytes(string password, int saltSize, int iterations);
[System.Obsolete("The default hash algorithm and iteration counts in Rfc2898DeriveBytes constructors are outdated and insecure. Use a constructor that accepts the hash algorithm and the number of iterations.", DiagnosticId="SYSLIB0041", UrlFormat="https://aka.ms/dotnet-warnings/{0}")]
public Rfc2898DeriveBytes(string password, int saltSize, int iterations);
[<System.Obsolete("The constructors on Rfc2898DeriveBytes are obsolete. Use the static Pbkdf2 method instead.", DiagnosticId="SYSLIB0060", UrlFormat="https://aka.ms/dotnet-warnings/{0}")>]
new System.Security.Cryptography.Rfc2898DeriveBytes : string * int * int -> System.Security.Cryptography.Rfc2898DeriveBytes
new System.Security.Cryptography.Rfc2898DeriveBytes : string * int * int -> System.Security.Cryptography.Rfc2898DeriveBytes
[<System.Obsolete("The default hash algorithm and iteration counts in Rfc2898DeriveBytes constructors are outdated and insecure. Use a constructor that accepts the hash algorithm and the number of iterations.", DiagnosticId="SYSLIB0041", UrlFormat="https://aka.ms/dotnet-warnings/{0}")>]
new System.Security.Cryptography.Rfc2898DeriveBytes : string * int * int -> System.Security.Cryptography.Rfc2898DeriveBytes
Public Sub New (password As String, saltSize As Integer, iterations As Integer)

參數

password
String

用來推導金鑰的密碼。

saltSize
Int32

你想讓類別產生的隨機鹽值大小。

iterations
Int32

運算的迭代次數。

屬性

例外狀況

指定的鹽大小小於 8 位元組,或迭代次數小於 1。

密碼或鹽是 null。

iterations 超出射程範圍。 此參數需要非負數值。

備註

鹽的大小必須是 8 位元組或以上,且迭代次數必須大於零。

RFC 2898 包含從密碼與鹽建立金鑰與初始化向量(IV)的方法。 你可以使用 PBKDF2,一種基於密碼的金鑰推導函式,透過偽隨機函式推導金鑰,該函式允許產生幾乎無限長度的金鑰。 此 Rfc2898DeriveBytes 類別可用於從基礎鍵及其他參數產生導出金鑰。 在基於密碼的金鑰導出函式中,基鍵是密碼,其他參數則是鹽值和迭代次數。

欲了解更多關於 PBKDF2 的資訊,請參閱 RFC 2898,標題為「PKCS #5:Password-Based 密碼學規範版本 2.0」。 完整詳情請參見第5.2節「PBKDF2」。

Important

千萬不要在原始碼裡硬寫密碼。 硬編碼密碼可透過 Ildasm.exe(IL 反組譯器)、十六進位編輯器,或直接在文字編輯器(如 Notepad.exe)中開啟組合語言來取得。

另請參閱

適用於

Rfc2898DeriveBytes(Byte[], Byte[], Int32, HashAlgorithmName)

來源:
Rfc2898DeriveBytes.cs
來源:
Rfc2898DeriveBytes.cs
來源:
Rfc2898DeriveBytes.cs
來源:
Rfc2898DeriveBytes.cs
來源:
Rfc2898DeriveBytes.cs

警告

The constructors on Rfc2898DeriveBytes are obsolete. Use the static Pbkdf2 method instead.

使用指定的密碼、鹽值、迭代次數及雜湊演算法名稱初始化該類別的新實例 Rfc2898DeriveBytes ,以推導出金鑰。

public:
 Rfc2898DeriveBytes(cli::array <System::Byte> ^ password, cli::array <System::Byte> ^ salt, int iterations, System::Security::Cryptography::HashAlgorithmName hashAlgorithm);
[System.Obsolete("The constructors on Rfc2898DeriveBytes are obsolete. Use the static Pbkdf2 method instead.", DiagnosticId="SYSLIB0060", UrlFormat="https://aka.ms/dotnet-warnings/{0}")]
public Rfc2898DeriveBytes(byte[] password, byte[] salt, int iterations, System.Security.Cryptography.HashAlgorithmName hashAlgorithm);
public Rfc2898DeriveBytes(byte[] password, byte[] salt, int iterations, System.Security.Cryptography.HashAlgorithmName hashAlgorithm);
[<System.Obsolete("The constructors on Rfc2898DeriveBytes are obsolete. Use the static Pbkdf2 method instead.", DiagnosticId="SYSLIB0060", UrlFormat="https://aka.ms/dotnet-warnings/{0}")>]
new System.Security.Cryptography.Rfc2898DeriveBytes : byte[] * byte[] * int * System.Security.Cryptography.HashAlgorithmName -> System.Security.Cryptography.Rfc2898DeriveBytes
new System.Security.Cryptography.Rfc2898DeriveBytes : byte[] * byte[] * int * System.Security.Cryptography.HashAlgorithmName -> System.Security.Cryptography.Rfc2898DeriveBytes
Public Sub New (password As Byte(), salt As Byte(), iterations As Integer, hashAlgorithm As HashAlgorithmName)

參數

password
Byte[]

用來推導金鑰的密碼。

salt
Byte[]

用來推導金鑰的 key salt。

iterations
Int32

運算的迭代次數。

hashAlgorithm
HashAlgorithmName

用來推導金鑰的雜湊演算法。

屬性

例外狀況

Name的hashAlgorithm性質為nullEmpty或為。

雜湊演算法名稱無效。

適用於

Rfc2898DeriveBytes(String, Byte[], Int32, HashAlgorithmName)

來源:
Rfc2898DeriveBytes.cs
來源:
Rfc2898DeriveBytes.cs
來源:
Rfc2898DeriveBytes.cs
來源:
Rfc2898DeriveBytes.cs
來源:
Rfc2898DeriveBytes.cs

警告

The constructors on Rfc2898DeriveBytes are obsolete. Use the static Pbkdf2 method instead.

使用指定的密碼、鹽值、迭代次數及雜湊演算法名稱初始化該類別的新實例 Rfc2898DeriveBytes ,以推導出金鑰。

public:
 Rfc2898DeriveBytes(System::String ^ password, cli::array <System::Byte> ^ salt, int iterations, System::Security::Cryptography::HashAlgorithmName hashAlgorithm);
[System.Obsolete("The constructors on Rfc2898DeriveBytes are obsolete. Use the static Pbkdf2 method instead.", DiagnosticId="SYSLIB0060", UrlFormat="https://aka.ms/dotnet-warnings/{0}")]
public Rfc2898DeriveBytes(string password, byte[] salt, int iterations, System.Security.Cryptography.HashAlgorithmName hashAlgorithm);
public Rfc2898DeriveBytes(string password, byte[] salt, int iterations, System.Security.Cryptography.HashAlgorithmName hashAlgorithm);
[<System.Obsolete("The constructors on Rfc2898DeriveBytes are obsolete. Use the static Pbkdf2 method instead.", DiagnosticId="SYSLIB0060", UrlFormat="https://aka.ms/dotnet-warnings/{0}")>]
new System.Security.Cryptography.Rfc2898DeriveBytes : string * byte[] * int * System.Security.Cryptography.HashAlgorithmName -> System.Security.Cryptography.Rfc2898DeriveBytes
new System.Security.Cryptography.Rfc2898DeriveBytes : string * byte[] * int * System.Security.Cryptography.HashAlgorithmName -> System.Security.Cryptography.Rfc2898DeriveBytes
Public Sub New (password As String, salt As Byte(), iterations As Integer, hashAlgorithm As HashAlgorithmName)

參數

password
String

用來推導金鑰的密碼。

salt
Byte[]

用來推導金鑰的 key salt。

iterations
Int32

運算的迭代次數。

hashAlgorithm
HashAlgorithmName

用來推導金鑰的雜湊演算法。

屬性

例外狀況

Name的hashAlgorithm性質為nullEmpty或為。

雜湊演算法名稱無效。

適用於

Rfc2898DeriveBytes(String, Int32, Int32, HashAlgorithmName)

來源:
Rfc2898DeriveBytes.cs
來源:
Rfc2898DeriveBytes.cs
來源:
Rfc2898DeriveBytes.cs
來源:
Rfc2898DeriveBytes.cs
來源:
Rfc2898DeriveBytes.cs

警告

The constructors on Rfc2898DeriveBytes are obsolete. Use the static Pbkdf2 method instead.

使用指定的密碼、鹽大小、迭代次數及雜湊演算法名稱初始化該類別的新實例 Rfc2898DeriveBytes ,以推導金鑰。

public:
 Rfc2898DeriveBytes(System::String ^ password, int saltSize, int iterations, System::Security::Cryptography::HashAlgorithmName hashAlgorithm);
[System.Obsolete("The constructors on Rfc2898DeriveBytes are obsolete. Use the static Pbkdf2 method instead.", DiagnosticId="SYSLIB0060", UrlFormat="https://aka.ms/dotnet-warnings/{0}")]
public Rfc2898DeriveBytes(string password, int saltSize, int iterations, System.Security.Cryptography.HashAlgorithmName hashAlgorithm);
public Rfc2898DeriveBytes(string password, int saltSize, int iterations, System.Security.Cryptography.HashAlgorithmName hashAlgorithm);
[<System.Obsolete("The constructors on Rfc2898DeriveBytes are obsolete. Use the static Pbkdf2 method instead.", DiagnosticId="SYSLIB0060", UrlFormat="https://aka.ms/dotnet-warnings/{0}")>]
new System.Security.Cryptography.Rfc2898DeriveBytes : string * int * int * System.Security.Cryptography.HashAlgorithmName -> System.Security.Cryptography.Rfc2898DeriveBytes
new System.Security.Cryptography.Rfc2898DeriveBytes : string * int * int * System.Security.Cryptography.HashAlgorithmName -> System.Security.Cryptography.Rfc2898DeriveBytes
Public Sub New (password As String, saltSize As Integer, iterations As Integer, hashAlgorithm As HashAlgorithmName)

參數

password
String

用來推導金鑰的密碼。

saltSize
Int32

你想讓類別產生的隨機鹽值大小。

iterations
Int32

運算的迭代次數。

hashAlgorithm
HashAlgorithmName

用來推導金鑰的雜湊演算法。

屬性

例外狀況

saltSize 小於零。

Name的hashAlgorithm性質為nullEmpty或為。

雜湊演算法名稱無效。

適用於