当passwordFormat =加密和解密= AES

时间:2016-06-11 21:03:43

标签: asp.net aes asp.net-identity asp.net-membership asp.net-identity-2


如果您发现自己处于类似情况,那么您可能会遇到这个问题helpful post from microsoft,它为您提供了很好的指导和脚本,可以将数据库转换为新架构,包括密码。



int passwordformat = 1;

用于散列密码。我需要的是能够使用System.Web / MachineKey配置元素的decryptionKey来处理我的场景的加密密码。


1 个答案:

答案 0 :(得分:6)

首先,让我们快速谈谈SqlMembershipProvider正在做什么。提供程序通过将两者连接在一起,将转换为byte []的salt与编码为unicode字节数组的密码组合成一个更大的字节数组。非常直截了当。然后它通过抽象(MembershipAdapter)将其传递给MachineKeySection,在那里完成实际工作。


public class SQLPasswordHasher : PasswordHasher
    public override string HashPassword(string password)
        return base.HashPassword(password);

    public override PasswordVerificationResult VerifyHashedPassword(string hashedPassword, string providedPassword)
        string[] passwordProperties = hashedPassword.Split('|');
        if (passwordProperties.Length != 3)
            return base.VerifyHashedPassword(hashedPassword, providedPassword);
            string passwordHash = passwordProperties[0];
            int passwordformat = int.Parse(passwordProperties[1]);
            string salt = passwordProperties[2];

            if (String.Equals(EncryptPassword(providedPassword, passwordformat, salt), passwordHash, StringComparison.CurrentCultureIgnoreCase))
                return PasswordVerificationResult.SuccessRehashNeeded;
                return PasswordVerificationResult.Failed;


    //This is copied from the existing SQL providers and is provided only for back-compat.
    private string EncryptPassword(string pass, int passwordFormat, string salt)
        if (passwordFormat == 0) // MembershipPasswordFormat.Clear
            return pass;

        byte[] bIn = Encoding.Unicode.GetBytes(pass);
        byte[] bSalt = Convert.FromBase64String(salt);
        byte[] bRet = null;

        if (passwordFormat == 1)
        { // MembershipPasswordFormat.Hashed 
            HashAlgorithm hm = HashAlgorithm.Create("SHA1");
            if (hm is KeyedHashAlgorithm)
                KeyedHashAlgorithm kha = (KeyedHashAlgorithm)hm;
                if (kha.Key.Length == bSalt.Length)
                    kha.Key = bSalt;
                else if (kha.Key.Length < bSalt.Length)
                    byte[] bKey = new byte[kha.Key.Length];
                    Buffer.BlockCopy(bSalt, 0, bKey, 0, bKey.Length);
                    kha.Key = bKey;
                    byte[] bKey = new byte[kha.Key.Length];
                    for (int iter = 0; iter < bKey.Length;)
                        int len = Math.Min(bSalt.Length, bKey.Length - iter);
                        Buffer.BlockCopy(bSalt, 0, bKey, iter, len);
                        iter += len;
                    kha.Key = bKey;
                bRet = kha.ComputeHash(bIn);
                byte[] bAll = new byte[bSalt.Length + bIn.Length];
                Buffer.BlockCopy(bSalt, 0, bAll, 0, bSalt.Length);
                Buffer.BlockCopy(bIn, 0, bAll, bSalt.Length, bIn.Length);
                bRet = hm.ComputeHash(bAll);
        else //MembershipPasswordFormat.Encrypted, aka 2
            byte[] bEncrypt = new byte[bSalt.Length + bIn.Length];
            Buffer.BlockCopy(bSalt, 0, bEncrypt, 0, bSalt.Length);
            Buffer.BlockCopy(bIn, 0, bEncrypt, bSalt.Length, bIn.Length);

            // Distilled from MachineKeyConfigSection EncryptOrDecryptData function, assuming AES algo and paswordCompatMode=Framework20 (the default)
            MemoryStream stream = new MemoryStream();
            var aes = new AesCryptoServiceProvider();
            aes.Key = HexStringToByteArray(MachineKey.DecryptionKey);
            aes.IV = new byte[aes.IV.Length];
            ICryptoTransform transform = aes.CreateEncryptor(); 

            CryptoStream stream2 = new CryptoStream(stream, transform, CryptoStreamMode.Write);

            stream2.Write(bEncrypt, 0, bEncrypt.Length);

            bRet = stream.ToArray();

        return Convert.ToBase64String(bRet);

    public static byte[] HexStringToByteArray(String hex)
        int NumberChars = hex.Length;
        byte[] bytes = new byte[NumberChars / 2];
        for (int i = 0; i < NumberChars; i += 2)
            bytes[i / 2] = Convert.ToByte(hex.Substring(i, 2), 16);
        return bytes;

    private static MachineKeySection MachineKey
            //Get encryption and decryption key information from the configuration.
            System.Configuration.Configuration cfg = WebConfigurationManager.OpenWebConfiguration(System.Web.Hosting.HostingEnvironment.ApplicationVirtualPath);
            return cfg.GetSection("system.web/machineKey") as MachineKeySection;

