天天看點

java密碼加鹽_如何使用Java中的BouncyCastle API對密碼進行加密和加鹽?

小編典典

我建議為此使用基于密碼的密鑰派生函數,而不是基本的哈希函數。像這樣:

// tuning parameters

// these sizes are relatively arbitrary

int seedBytes = 20;

int hashBytes = 20;

// increase iterations as high as your performance can tolerate

// since this increases computational cost of password guessing

// which should help security

int iterations = 1000;

// to save a new password:

SecureRandom rng = new SecureRandom();

byte[] salt = rng.generateSeed(seedBytes);

Pkcs5S2ParametersGenerator kdf = new Pkcs5S2ParametersGenerator();

kdf.init(passwordToSave.getBytes("UTF-8"), salt, iterations);

byte[] hash =

((KeyParameter) kdf.generateDerivedMacParameters(8*hashBytes)).getKey();

// now save salt and hash

// to check a password, given the known previous salt and hash:

kdf = new Pkcs5S2ParametersGenerator();

kdf.init(passwordToCheck.getBytes("UTF-8"), salt, iterations);

byte[] hashToCheck =

((KeyParameter) kdf.generateDerivedMacParameters(8*hashBytes)).getKey();

// if the bytes of hashToCheck don't match the bytes of hash

// that means the password is invalid

2020-10-20