With the upgrade of PHP version, some functions have been abandoned, such as encryption and decryption functions. Before PHP7.1, decryption and encryption were implemented through mcrypt_decrypt() and mcrypt_encrypt(). After PHP7.1, decryption and encryption were implemented through openssl_decrypt() and openssl_encrypt. () to implement decryption and encryption. Here, through the encapsulation class, two implementation methods are implemented to implement
Two methods of encryption and decryption steps:
Return the original data (array) during decryption --->Encryption-->Encrypted string-->Decryption-->Original array|| JSON string-->Encryption-->Encrypted string-->Decryption-->Original JSON character String || String—->Encryption—->Encrypted string—->Decrypt—->Original string)
Used below PHP7.1
Class method
What needs to be noted in this class is the key: The key length corresponding to the algorithm: The length of the encryption key of AES-128, 192 and 256 is 16, 24 respectively. and 32-bit
<?php namespace aes; class AesT { private $_bit = MCRYPT_RIJNDAEL_256; private $_type = MCRYPT_MODE_CBC; private $_key = 'ThisIsYourAesKey'; // 密钥 必须16位 24位 32位 private $_use_base64 = true; private $_iv_size = null; private $_iv = null; /** * @param string $_key 密钥 * @param int $_bit 默认使用128字节 支持256、192、128 * @param string $_type 加密解密方式 默认为ecb 支持cfb、cbc、nofb、ofb、stream、ecb * @param boolean $_use_base64 默认使用base64二次加密 */ public function __construct($_key = '', $_bit = 128, $_type = 'ecb', $_use_base64 = true) { // 加密字节 if (192 === $_bit) { $this->_bit = MCRYPT_RIJNDAEL_192; } elseif (128 === $_bit) { $this->_bit = MCRYPT_RIJNDAEL_128; } else { $this->_bit = MCRYPT_RIJNDAEL_256; } // 加密方法 if ('cfb' === $_type) { $this->_type = MCRYPT_MODE_CFB; } elseif ('cbc' === $_type) { $this->_type = MCRYPT_MODE_CBC; } elseif ('nofb' === $_type) { $this->_type = MCRYPT_MODE_NOFB; } elseif ('ofb' === $_type) { $this->_type = MCRYPT_MODE_OFB; } elseif ('stream' === $_type) { $this->_type = MCRYPT_MODE_STREAM; } else { $this->_type = MCRYPT_MODE_ECB; } // 密钥 if (!empty($_key)) { $this->_key = $_key; } // 是否使用base64 $this->_use_base64 = $_use_base64; $this->_iv_size = mcrypt_get_iv_size($this->_bit, $this->_type); $this->_iv = mcrypt_create_iv($this->_iv_size, MCRYPT_RAND); } /** * 加密 * @param string $string 待加密字符串 * @return string */ public function encode($string) { // if (MCRYPT_MODE_ECB === $this->_type) { $encodeString = mcrypt_encrypt($this->_bit, $this->_key, json_encode($string), $this->_type); } else { $encodeString = mcrypt_encrypt($this->_bit, $this->_key, json_encode($string), $this->_type, $this->_iv); } if ($this->_use_base64) { $encodeString = base64_encode($encodeString); } return $encodeString; } /** * 解密 * @param string $string 待解密字符串 * @return string */ public function decode($string) { if ($this->_use_base64) { $string = base64_decode($string); } if (MCRYPT_MODE_ECB === $this->_type) { $decodeString = mcrypt_decrypt($this->_bit, $this->_key, $string, $this->_type); } else { $decodeString = mcrypt_decrypt($this->_bit, $this->_key, $string, $this->_type, $this->_iv); } return $decodeString; } }
Use
<?php use aes\AesT; class Test{ public function index() { $data1 = ['status' => '1', 'info' => 'success', 'data' => [['id' => 1, 'name' => '大房间', '2' => '小房间']]]; //$data2 = '{"status":"1","info":"success","data":[{"id":1,"name":"\u5927\u623f\u95f4","2":"\u5c0f\u623f\u95f4"}]}'; //$data3 = 'PHP AES cbc模式 pkcs7 128加密解密'; $objT = new AesT(); $resT = $objT->encode($data1);//加密数据 var_dump($resT); var_dump($objT->decode($resT));//解密 } }
PHP7.1 or above use
Class methods
AES-128-CBC, AES-192-CBC and AES-256-CBC The length of the encryption key is 16, 24 and 32 bits respectively
##Among the four parameters of openssl_encrypt(), you need to pay attention to the fourth parameter :
0: Automatically pad the plain text, and the returned data is base64 encoded.
1: OPENSSL_RAW_DATA, Automatically pad the plain text, But the returned result is not base64 encoded.
2 : OPENSSL_ZERO_PADDING, 自动对明文进行 0 填充, 返回的结果经过 base64 编码
<?php namespace aes; class Aes { public static $key = ''; public static $iv = ''; public static $method = ''; public function __construct() { //加密key self::$key = md5('AeSNJkBfhHmJqLzHL', true); //保证偏移量为16位 self::$iv = md5('HfgUdCliBjKjuRfa', true); //加密方式 # AES-128-CBC AES-192-CBC AES-256-CBC self::$method = 'AES-128-CBC'; } /** * @desc 加密 * @param $data * @return false|string */ public function aesEn($data) { return base64_encode(openssl_encrypt(json_encode($data), self::$method, self::$key, OPENSSL_RAW_DATA, self::$iv)); } /** * @desc 解密 * @param $data * @return false|string */ public function aesDe($data) { $tmpData = openssl_decrypt(base64_decode($data), self::$method, self::$key, OPENSSL_RAW_DATA, self::$iv); return is_null(json_decode($tmpData)) ? $tmpData : json_decode($tmpData, true); } }
使用
<?php use aes\Aes; class Test { public function aes() { $obj = new Aes(); $data = ['status' => '1', 'info' => 'success', 'data' => [['id' => 1, 'name' => '大房间', '2' => '小房间']]]; //$data = '{"status":"1","info":"success","data":[{"id":1,"name":"\u5927\u623f\u95f4","2":"\u5c0f\u623f\u95f4"}]}'; //$data = 'PHP AES cbc模式 pkcs7 128加密解密'; $res = $obj->aesEn($data);//加密数据 var_dump($res); var_dump($obj->aesDe($res));//解密 } }
使用该加密解密类时,如果将两个类整合到一个类中,需要通过PHP_VERSION获取当前PHP版本
The above is the detailed content of Data encryption and decryption. For more information, please follow other related articles on the PHP Chinese website!

Effective methods to prevent session fixed attacks include: 1. Regenerate the session ID after the user logs in; 2. Use a secure session ID generation algorithm; 3. Implement the session timeout mechanism; 4. Encrypt session data using HTTPS. These measures can ensure that the application is indestructible when facing session fixed attacks.

Implementing session-free authentication can be achieved by using JSONWebTokens (JWT), a token-based authentication system where all necessary information is stored in the token without server-side session storage. 1) Use JWT to generate and verify tokens, 2) Ensure that HTTPS is used to prevent tokens from being intercepted, 3) Securely store tokens on the client side, 4) Verify tokens on the server side to prevent tampering, 5) Implement token revocation mechanisms, such as using short-term access tokens and long-term refresh tokens.

The security risks of PHP sessions mainly include session hijacking, session fixation, session prediction and session poisoning. 1. Session hijacking can be prevented by using HTTPS and protecting cookies. 2. Session fixation can be avoided by regenerating the session ID before the user logs in. 3. Session prediction needs to ensure the randomness and unpredictability of session IDs. 4. Session poisoning can be prevented by verifying and filtering session data.

To destroy a PHP session, you need to start the session first, then clear the data and destroy the session file. 1. Use session_start() to start the session. 2. Use session_unset() to clear the session data. 3. Finally, use session_destroy() to destroy the session file to ensure data security and resource release.

How to change the default session saving path of PHP? It can be achieved through the following steps: use session_save_path('/var/www/sessions');session_start(); in PHP scripts to set the session saving path. Set session.save_path="/var/www/sessions" in the php.ini file to change the session saving path globally. Use Memcached or Redis to store session data, such as ini_set('session.save_handler','memcached'); ini_set(

TomodifydatainaPHPsession,startthesessionwithsession_start(),thenuse$_SESSIONtoset,modify,orremovevariables.1)Startthesession.2)Setormodifysessionvariablesusing$_SESSION.3)Removevariableswithunset().4)Clearallvariableswithsession_unset().5)Destroythe

Arrays can be stored in PHP sessions. 1. Start the session and use session_start(). 2. Create an array and store it in $_SESSION. 3. Retrieve the array through $_SESSION. 4. Optimize session data to improve performance.

PHP session garbage collection is triggered through a probability mechanism to clean up expired session data. 1) Set the trigger probability and session life cycle in the configuration file; 2) You can use cron tasks to optimize high-load applications; 3) You need to balance the garbage collection frequency and performance to avoid data loss.


Hot AI Tools

Undresser.AI Undress
AI-powered app for creating realistic nude photos

AI Clothes Remover
Online AI tool for removing clothes from photos.

Undress AI Tool
Undress images for free

Clothoff.io
AI clothes remover

Video Face Swap
Swap faces in any video effortlessly with our completely free AI face swap tool!

Hot Article

Hot Tools

mPDF
mPDF is a PHP library that can generate PDF files from UTF-8 encoded HTML. The original author, Ian Back, wrote mPDF to output PDF files "on the fly" from his website and handle different languages. It is slower than original scripts like HTML2FPDF and produces larger files when using Unicode fonts, but supports CSS styles etc. and has a lot of enhancements. Supports almost all languages, including RTL (Arabic and Hebrew) and CJK (Chinese, Japanese and Korean). Supports nested block-level elements (such as P, DIV),

WebStorm Mac version
Useful JavaScript development tools

SAP NetWeaver Server Adapter for Eclipse
Integrate Eclipse with SAP NetWeaver application server.

Notepad++7.3.1
Easy-to-use and free code editor

VSCode Windows 64-bit Download
A free and powerful IDE editor launched by Microsoft
