Compute HMAC sha-512 in NodeJS and Java
我正在尝试将sha-512计算从Java迁移到节点JS,我似乎无法获得相同的结果...
Java代码(根据我在网上看到的代码看起来很标准):
1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 | public class Test { private static String get_SecurePassword(String passwordToHash, String salt, String algo) throws NoSuchAlgorithmException { String generatedPassword = null; MessageDigest md = MessageDigest.getInstance(algo); md.update(salt.getBytes()); byte[] bytes = md.digest(passwordToHash.getBytes()); StringBuilder sb = new StringBuilder(); for (int i = 0; i< bytes.length; i++) { sb.append(Integer.toString((bytes[i] & 0xff) + 0x100, 16).substring(1)); } generatedPassword = sb.toString(); return generatedPassword; } public static void main(String[] args) throws NoSuchAlgorithmException { String res = get_SecurePassword("test","test","SHA-512"); System.out.println(res); } } |
输出:
1 | 125d6d03b32c84d492747f79cf0bf6e179d287f341384eb5d6d3197525ad6be8e6df0116032935698f99a09e265073d1d6c32c274591bf1d0a20ad67cba921bc |
NodeJS:
1 2 3 4 5 6 7 8 9 10 11 12 13 | const crypto = require('crypto'); function getSecurePassword(password, salt, algo) { const algoFormatted = algo.toLowerCase().replace('-', ''); const hash = crypto.createHmac(algoFormatted, salt); hash.update(password); const res = hash.digest('hex'); return res; } console.log(getSecurePassword('test', 'test', 'SHA-512')); |
输出:
1 | 9ba1f63365a6caf66e46348f43cdef956015bea997adeb06e69007ee3ff517df10fc5eb860da3d43b82c2a040c931119d2dfc6d08e253742293a868cc2d82015 |
我究竟做错了什么?
注意:我正在使用Java 8和Node 10.13
如果有人希望借助@DavidConrad来感谢我对Node JS的修复,这里是:
1 2 3 4 5 6 7 8 9 10 11 | const crypto = require('crypto'); function getSecurePassword(password, salt, algo) { const algoFormatted = algo.toLowerCase().replace('-', ''); const hash = crypto.createHash(algoFormatted); hash.update(salt + password); return hash.digest('hex'); } console.log(getSecurePassword('test', 'test', 'SHA-512')); |
输出:
1 | 125d6d03b32c84d492747f79cf0bf6e179d287f341384eb5d6d3197525ad6be8e6df0116032935698f99a09e265073d1d6c32c274591bf1d0a20ad67cba921bc |
在Node中,您使用的是HMAC-SHA-512,但是在Java中,您仅使用的是SHA-512,并将键和纯文本连接在一起。 这不是HMAC的工作方式。 您还需要在Java中使用HMAC-SHA-512:
1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 | import static java.nio.charset.StandardCharsets.*; import java.math.BigInteger; import java.security.InvalidKeyException; import java.security.NoSuchAlgorithmException; import javax.crypto.Mac; import javax.crypto.spec.SecretKeySpec; public class Test { private static String getSecurePassword(String password, String salt, String algo) throws NoSuchAlgorithmException, InvalidKeyException { SecretKeySpec secretKeySpec = new SecretKeySpec(salt.getBytes(UTF_8), algo); Mac mac = Mac.getInstance(algo); mac.init(secretKeySpec); byte[] bytes = mac.doFinal(password.getBytes(UTF_8)); return new BigInteger(1, bytes).toString(16); } public static void main(String[] args) throws NoSuchAlgorithmException, InvalidKeyException { System.out.println(getSecurePassword("test","test","HmacSHA512")); } } |
输出:
1 | 9ba1f63365a6caf66e46348f43cdef956015bea997adeb06e69007ee3ff517df10fc5eb860da3d43b82c2a040c931119d2dfc6d08e253742293a868cc2d82015 |
对于NodeJS,您可以将键附加数据以获取Java等效散列。
1 | require('crypto').createHash(algo).update(data + key).digest() |