值错误:使用AES256解密时填充字节无效

2024-10-03 17:28:08 发布

您现在位置:Python中文网/ 问答频道 /正文

我试图使用cryptography库重写this解决方案,但在解密过程中,我得到了填充错误,即ValueError: Invalid padding bytes.以下是我目前拥有的密码类:

import os
import base64

from cryptography.hazmat.primitives import hashes
from cryptography.hazmat.primitives import padding
from cryptography.hazmat.backends import default_backend
from cryptography.hazmat.primitives.ciphers import modes
from cryptography.hazmat.primitives.ciphers import Cipher
from cryptography.hazmat.primitives.ciphers import algorithms
from cryptography.hazmat.primitives.kdf.pbkdf2 import PBKDF2HMAC

class AES256Cipher:

    def __init__(self, password, salt):
        self.password = password.encode('utf-8')
        self.salt = salt.encode('utf-8')

        self.backend = default_backend()
        self.key = self.pbkdf2()

    def encrypt(self, plaintext):
        iv = os.urandom(16)
        cipher = Cipher(
            algorithms.AES(self.key),
            modes.CBC(iv),
            backend=self.backend
        )

        encryptor = cipher.encryptor()
        padder = padding.PKCS7(256).padder()
        plaintext = plaintext.rstrip().encode('utf-8')
        padded = padder.update(plaintext) + padder.finalize()
        ciphertext = encryptor.update(padded) + encryptor.finalize()
        return base64.b64encode(ciphertext)

    def decrypt(self, ciphertext):
        ciphertext = base64.b64decode(ciphertext.rstrip())
        iv = ciphertext[:16]
        cipher = Cipher(
            algorithms.AES(self.key),
            modes.CBC(iv),
            backend=self.backend
        )

        decryptor = cipher.decryptor()
        unpadder = padding.PKCS7(256).unpadder()
        plaintext = decryptor.update(ciphertext) + decryptor.finalize()
        unpadded = unpadder.update(plaintext) + unpadder.finalize()
        return unpadded.decode('utf-8')

    def pbkdf2(self):
        kdf = PBKDF2HMAC(
            algorithm=hashes.SHA256(),
            length=32, salt=self.salt,
            iterations=100000,
            backend=self.backend
        )
        return kdf.derive(self.password)

当代码到达decrypt方法中的unpadded = unpadder.update(plaintext) + unpadder.finalize()时引发异常。为什么填充物不起作用?E、 g.:

^{pr2}$

Tags: fromimportselfbackenddefupdatesaltcryptography
1条回答
网友
1楼 · 发布于 2024-10-03 17:28:08

您的解密方法是提取密码的前16个字节作为IV,但是您的encrypt方法从未将其放在那里。修复方法是在base64编码之前,encrypt将IV放在密文前面。在

return base64.b64encode(iv + ciphertext)

在解密端,必须正确删除它:

^{pr2}$

相关问题 更多 >