search
HomeBackend DevelopmentPHP TutorialAES/RSA encryption mechanism

AES/RSA encryption mechanism

Apr 04, 2017 pm 02:36 PM

During HTTP communication between the server and the terminal device, packets are often captured by the network. , decompilation (Android APK decompilation tool) and other technologies to obtain the HTTP communication interface address and parameters. In order to ensure the security of the information, we use the AES+RSA combination. Method to encrypt and decrypt interface parameters.

1. Regarding the RSA encryption mechanism: the public key is used to encrypt the data, and the private key is used to decrypt the data. The public key and the private key are generated at the same time. , one-to-one correspondence. For example: A has a public key, and B has a public key and a private key. After A encrypts the data with the public key, B can decrypt it with the private key and public key.

#2. AES encryption is also called symmetric encryption: After A uses the password to AES encrypt the data, B uses the same password to AES decrypt the ciphertext



Specific operation method. :

1. Use openssl mode to enter the relevant

attributes of the key (company name, email, etc.) in the terminal, and then generate the public key and private key under the current address of the terminal. There are 7 files in total (see the expanded link in the appendix for how to use the 7 files)

2. At this time, it is assumed that the Android client has the public key Public

Key, and the server has the public key. PublicKey and private key PrivateKey.

3. Android sends a request to the server: Android randomly generates a Byte[] random password, assuming RandomKey="123456", and uses the AES algorithm to

Json data Use encryption.

4. But at this moment, the server does not know what the client's RandomKey is, so it needs to pass the Randomkey to the server at the same time, otherwise the server cannot decrypt the Json data through AES. But if the request is sent directly, The RandomKey will be exposed, so the RandomKey must be irreversibly encrypted with RSA.

5. Android will use Randomkey for AES encryption and RandomKey for RSA encryption to send the data to the server through HTTP. The request is completed.

6. The server receives the AES-encrypted Json data and the Rsa-encrypted RandomKey data.

7. The server decrypts the encrypted RandomKey using the private key. Get the original RandomKey generated by Android.

8. Use the original RandomKey to perform AES symmetric decryption of the encrypted Json data. At this point, the original Json data sent from the Android side has been obtained. Perform regular server business operations, and then encrypt the returned data with AES through RandomKey on the Android side, and then the Response is returned.

9. After the Android terminal receives the Response data, it can directly perform AES decryption using the RandomKey generated locally.

You can view the detailed flow chart below.


AES/RSA encryption mechanism

Client-server HTTPS data transmission flow chart

Notes:

1. During the actual development process, it was found that RSA and AES have different ciphertext generation standards and are incompatible with IOS. IOS requires a different public key in the RSA algorithm than JAVA. For detailed solutions, please see:

2. AES encryption cannot use KEYs exceeding 128Byte, because versions above jdk1.7 do not support KEYs exceeding 128Byte.

Summary: From a performance perspective, the entire client from sending encrypted data to decrypting and getting the original data returned does not exceed

300ms (Iphone4 and Centos Java server transmission test). This plan does not use TOKEN, but it may be used in the future. How to update the public key also needs to continue to be improved.


The above is the detailed content of AES/RSA encryption mechanism. For more information, please follow other related articles on the PHP Chinese website!

Statement
The content of this article is voluntarily contributed by netizens, and the copyright belongs to the original author. This site does not assume corresponding legal responsibility. If you find any content suspected of plagiarism or infringement, please contact admin@php.cn
PHP vs. Python: Understanding the DifferencesPHP vs. Python: Understanding the DifferencesApr 11, 2025 am 12:15 AM

PHP and Python each have their own advantages, and the choice should be based on project requirements. 1.PHP is suitable for web development, with simple syntax and high execution efficiency. 2. Python is suitable for data science and machine learning, with concise syntax and rich libraries.

PHP: Is It Dying or Simply Adapting?PHP: Is It Dying or Simply Adapting?Apr 11, 2025 am 12:13 AM

PHP is not dying, but constantly adapting and evolving. 1) PHP has undergone multiple version iterations since 1994 to adapt to new technology trends. 2) It is currently widely used in e-commerce, content management systems and other fields. 3) PHP8 introduces JIT compiler and other functions to improve performance and modernization. 4) Use OPcache and follow PSR-12 standards to optimize performance and code quality.

The Future of PHP: Adaptations and InnovationsThe Future of PHP: Adaptations and InnovationsApr 11, 2025 am 12:01 AM

The future of PHP will be achieved by adapting to new technology trends and introducing innovative features: 1) Adapting to cloud computing, containerization and microservice architectures, supporting Docker and Kubernetes; 2) introducing JIT compilers and enumeration types to improve performance and data processing efficiency; 3) Continuously optimize performance and promote best practices.

When would you use a trait versus an abstract class or interface in PHP?When would you use a trait versus an abstract class or interface in PHP?Apr 10, 2025 am 09:39 AM

In PHP, trait is suitable for situations where method reuse is required but not suitable for inheritance. 1) Trait allows multiplexing methods in classes to avoid multiple inheritance complexity. 2) When using trait, you need to pay attention to method conflicts, which can be resolved through the alternative and as keywords. 3) Overuse of trait should be avoided and its single responsibility should be maintained to optimize performance and improve code maintainability.

What is a Dependency Injection Container (DIC) and why use one in PHP?What is a Dependency Injection Container (DIC) and why use one in PHP?Apr 10, 2025 am 09:38 AM

Dependency Injection Container (DIC) is a tool that manages and provides object dependencies for use in PHP projects. The main benefits of DIC include: 1. Decoupling, making components independent, and the code is easy to maintain and test; 2. Flexibility, easy to replace or modify dependencies; 3. Testability, convenient for injecting mock objects for unit testing.

Explain the SPL SplFixedArray and its performance characteristics compared to regular PHP arrays.Explain the SPL SplFixedArray and its performance characteristics compared to regular PHP arrays.Apr 10, 2025 am 09:37 AM

SplFixedArray is a fixed-size array in PHP, suitable for scenarios where high performance and low memory usage are required. 1) It needs to specify the size when creating to avoid the overhead caused by dynamic adjustment. 2) Based on C language array, directly operates memory and fast access speed. 3) Suitable for large-scale data processing and memory-sensitive environments, but it needs to be used with caution because its size is fixed.

How does PHP handle file uploads securely?How does PHP handle file uploads securely?Apr 10, 2025 am 09:37 AM

PHP handles file uploads through the $\_FILES variable. The methods to ensure security include: 1. Check upload errors, 2. Verify file type and size, 3. Prevent file overwriting, 4. Move files to a permanent storage location.

What is the Null Coalescing Operator (??) and Null Coalescing Assignment Operator (??=)?What is the Null Coalescing Operator (??) and Null Coalescing Assignment Operator (??=)?Apr 10, 2025 am 09:33 AM

In JavaScript, you can use NullCoalescingOperator(??) and NullCoalescingAssignmentOperator(??=). 1.??Returns the first non-null or non-undefined operand. 2.??= Assign the variable to the value of the right operand, but only if the variable is null or undefined. These operators simplify code logic, improve readability and performance.

See all articles

Hot AI Tools

Undresser.AI Undress

Undresser.AI Undress

AI-powered app for creating realistic nude photos

AI Clothes Remover

AI Clothes Remover

Online AI tool for removing clothes from photos.

Undress AI Tool

Undress AI Tool

Undress images for free

Clothoff.io

Clothoff.io

AI clothes remover

AI Hentai Generator

AI Hentai Generator

Generate AI Hentai for free.

Hot Article

R.E.P.O. Energy Crystals Explained and What They Do (Yellow Crystal)
3 weeks agoBy尊渡假赌尊渡假赌尊渡假赌
R.E.P.O. Best Graphic Settings
3 weeks agoBy尊渡假赌尊渡假赌尊渡假赌
R.E.P.O. How to Fix Audio if You Can't Hear Anyone
3 weeks agoBy尊渡假赌尊渡假赌尊渡假赌
WWE 2K25: How To Unlock Everything In MyRise
3 weeks agoBy尊渡假赌尊渡假赌尊渡假赌

Hot Tools

Notepad++7.3.1

Notepad++7.3.1

Easy-to-use and free code editor

MantisBT

MantisBT

Mantis is an easy-to-deploy web-based defect tracking tool designed to aid in product defect tracking. It requires PHP, MySQL and a web server. Check out our demo and hosting services.

ZendStudio 13.5.1 Mac

ZendStudio 13.5.1 Mac

Powerful PHP integrated development environment

SublimeText3 Chinese version

SublimeText3 Chinese version

Chinese version, very easy to use

Atom editor mac version download

Atom editor mac version download

The most popular open source editor