2013-12-09 263 views
1

我正在尝试使用模数和指数为RSA生成公钥的应用程序。但是,有一个问题,模数和指数都可能是十六进制值。这是我用于生成密钥的代码,标记为 - <的行是错误发生的位置。错误:RSA密钥长度必须至少为512位?

RSAPublicKeySpec spec = new RSAPublicKeySpec(new BigInteger(1,hexToByte(rsaJSON.publickey_exp)),new BigInteger(1,hexToByte(rsaJSON.publickey_mod))); 
KeyFactory factory = KeyFactory.getInstance("RSA"); 
PublicKey pub = factory.generatePublic(spec); <--- 
Cipher cipher = cipher = Cipher.getInstance("RSA/None/OAEPWithSHA1AndMGF1Padding", "BC"); 
cipher.init(Cipher.ENCRYPT_MODE, pub); 
..... 
String HEXES = "ABCDEF"; 
public static String byteToHex(byte [] raw) { 
    if (raw == null) { 
     return null; 
    } 
    final StringBuilder hex = new StringBuilder(2 * raw.length); 
    for (final byte b : raw) { 
     hex.append(HEXES.charAt((b & 0xF0) >> 4)) 
     .append(HEXES.charAt((b & 0x0F))); 
    } 
    return hex.toString(); 
} 

public static byte[] hexToByte(String hexString){ 
    int len = hexString.length(); 
    byte[] ba = new byte[len/2]; 
    for (int i = 0; i < len; i += 2) { 
     ba[i/2] = (byte) ((Character.digit(hexString.charAt(i), 16) << 4) + Character.digit(hexString.charAt(i+1), 16)); 
    } 
    return ba; 
} 

一个例子模数和指数将被投入这如下:

modulus:"B31F9097CA38B4548D7300A0768F262C58D92B190355E382DACA4B79DA52226758FD8EB23CE29F404433411AC90308BEEED093BA157E03982E587496A15BB47A371C32C6B665FF75D6E900CF28CF679E871FB06FF0E90431E829DBE8EBDF7D5024A2D32F8B0D50C0D592E5D31046DE275F81B106088EBECA434493458DBF2B804BC46EC973E8F47408CC454F03F24933A5B100001B47239B44A52CF6A40670CED35060EB84BD6D0829DF8EC84EC49D784CA8583F353086071604DB2F43FA243A05F031033FFB179D8CB281A814B01F8CCC2EC29196BB136905104E23832FA923185743E18924C4E9772ED094D98643C677DE99EF1E598452728A7AC3DF5A1AB9" 

exponent:"010001"

堆栈跟踪,在大多数情况下:

java.security.spec.InvalidKeySpecException: java.security.InvalidKeyException: RSA keys must be at least 512 bits long 
at sun.security.rsa.RSAKeyFactory.engineGeneratePublic(Unknown Source) 
at java.security.KeyFactory.generatePublic(Unknown Source) 
    ..... 

我不会假装我知道为什么这个错误发生,因为我的知识才智h RSA加密是有限的。如果有人能帮我弄清楚为什么这个错误会持续出现,那将非常有帮助:)

回答

0

没有什么要“生成”。

(modulus, exponent)元组是公钥。

例如,我对谷歌的Web服务器的一个证书,如果我跑openssl x509 -in certfile.pem -text,这是输出的一部分:

Subject Public Key Info: 
     Public Key Algorithm: rsaEncryption 
     RSA Public Key: (1024 bit) 
      Modulus (1024 bit): 
       00:a7:4b:85:b2:80:e5:94:03:6f:ca:4a:e5:6c:a9: 
       71:80:a1:67:f7:b9:46:e8:26:b5:e9:bd:59:4f:7b: 
       dd:1a:50:68:c7:3a:df:73:15:ce:a8:69:00:d4:27: 
       09:a9:cd:e1:d1:6e:2d:c6:a3:e9:3b:d6:aa:94:63: 
       83:1a:64:27:bf:fe:87:90:d4:e6:b8:e4:89:a8:76: 
       23:15:13:e0:27:6b:38:0a:fa:1f:b1:ec:71:0a:ec: 
       34:ff:0d:9c:1c:a7:d6:47:0f:ec:70:6c:2a:6b:89: 
       90:f5:de:58:e9:4e:ae:4d:6f:f0:f1:ca:7d:72:c0: 
       7a:79:94:28:fe:85:01:58:c9 
      Exponent: 65537 (0x10001) 

就是这样。 RSA公钥是模数和指数。我认为你有你需要的东西。

+0

那么,*然后*什么*导致异常? – user2864740

+0

对于初学者来说编写不佳的API。 ;-) – mpontillo

+1

(注意,我并没有试图直接回答这个问题;相反,我试图解决OP对RSA公钥的理解;另一方面,当你已经“生成”公钥时看起来反直觉,这是由于API调用创建一个公钥对象,而不是一行代码)。 – mpontillo

相关问题