这个错误通常发生在使用Apache Nifi进行解密时,加密算法不匹配导致解密失败。解决方法是确保使用正确的加密算法进行解密。
以下是一个示例代码片段,展示如何使用AES/GCM/NoPadding算法进行加密和解密:
import javax.crypto.Cipher;
import javax.crypto.spec.GCMParameterSpec;
import javax.crypto.spec.SecretKeySpec;
import java.nio.charset.StandardCharsets;
import java.util.Base64;
public class EncryptionUtils {
private static final String ALGORITHM = "AES/GCM/NoPadding";
private static final int TAG_LENGTH_BIT = 128;
private static final int IV_LENGTH_BYTE = 12;
public static String encrypt(String plaintext, String key) throws Exception {
byte[] iv = generateIV();
byte[] cipherText;
byte[] keyBytes = key.getBytes(StandardCharsets.UTF_8);
SecretKeySpec secretKeySpec = new SecretKeySpec(keyBytes, "AES");
Cipher cipher = Cipher.getInstance(ALGORITHM);
GCMParameterSpec gcmParameterSpec = new GCMParameterSpec(TAG_LENGTH_BIT, iv);
cipher.init(Cipher.ENCRYPT_MODE, secretKeySpec, gcmParameterSpec);
cipherText = cipher.doFinal(plaintext.getBytes(StandardCharsets.UTF_8));
byte[] encrypted = new byte[iv.length + cipherText.length];
System.arraycopy(iv, 0, encrypted, 0, iv.length);
System.arraycopy(cipherText, 0, encrypted, iv.length, cipherText.length);
return Base64.getEncoder().encodeToString(encrypted);
}
public static String decrypt(String encryptedText, String key) throws Exception {
byte[] decoded = Base64.getDecoder().decode(encryptedText);
byte[] iv = new byte[IV_LENGTH_BYTE];
byte[] cipherText = new byte[decoded.length - IV_LENGTH_BYTE];
System.arraycopy(decoded, 0, iv, 0, iv.length);
System.arraycopy(decoded, iv.length, cipherText, 0, cipherText.length);
byte[] keyBytes = key.getBytes(StandardCharsets.UTF_8);
SecretKeySpec secretKeySpec = new SecretKeySpec(keyBytes, "AES");
Cipher cipher = Cipher.getInstance(ALGORITHM);
GCMParameterSpec gcmParameterSpec = new GCMParameterSpec(TAG_LENGTH_BIT, iv);
cipher.init(Cipher.DECRYPT_MODE, secretKeySpec, gcmParameterSpec);
byte[] decryptedText = cipher.doFinal(cipherText);
return new String(decryptedText, StandardCharsets.UTF_8);
}
private static byte[] generateIV() {
byte[] iv = new byte[IV_LENGTH_BYTE];
// Generate random IV
// You should use a secure random generator
for (int i = 0; i < IV_LENGTH_BYTE; ++i) {
iv[i] = (byte) (Math.random() * 0xFF);
}
return iv;
}
}
使用上述代码,你可以调用encrypt
方法对明文进行加密,然后将返回的密文存储或传输。在需要解密时,调用decrypt
方法将密文解密为原始明文。
确保在调用加密和解密方法时使用相同的密钥,这样才能成功解密。