2016-11-03 34 views
1

我需要爲Ethereum構建一個私鑰加密,它應該與go-ethereum實現兼容(Ruby加密的密鑰也應與Ethereum實現一起使用) )。在Ruby中使用aes-128-ctr + scrypt加密私鑰

復仇採用了32位的私鑰,像這樣的,例如(十六進制編碼):

1234567890abcdef1234567890abcdef1234567890abcdef1234567890abcdef 

如果我導入此鍵go-ethereum實施和使用密碼加密來「密碼」,它生成的輸出:

{ 
    "address":"1be31a94361a391bbafb2a4ccd704f57dc04d4bb", 
    "crypto":{ 
     "cipher":"aes-128-ctr", 
     "ciphertext":"62bbf1a5a93b8ba8c66b70b3381f9f5badf44b35287614d309d760ebeec47139", 
     "cipherparams":{ 
      "iv":"a4a6638ea73872c07d62fa065f37f790" 
     }, 
     "kdf":"scrypt", 
     "kdfparams":{ 
      "dklen":32, 
      "n":262144, 
      "p":1, 
      "r":8, 
      "salt":"69ccd8c258bb50ac2effd65837e09e45b8bd9a747a1a1f3558b65a16e2f46f1a" 
     }, 
     "mac":"68ca6bc011d4d656e12a34cefd28005dbf76d9cfac15db2eaa83920eec5b38a9" 
    }, 
    "id":"9863070b-6c16-4aef-8188-2a34660192bf", 
    "version":3 
} 

因此,使用所有的KDF(密鑰導出函數)的參數,它生成的密文

62bbf1a5a93b8ba8c66b70b3381f9f5badf44b35287614d309d760ebeec47139 

我現在嘗試使用Ruby重現相同的密文,並查看Go實現。這是我的代碼:

# hard coded password 
password = "password" 

# hard coded test private key 
plain_private_key = "1234567890abcdef1234567890abcdef1234567890abcdef1234567890abcdef" 
puts "------------ Encryption input ------------ " 
puts "Clear private key = " + plain_private_key 

# Scrypt params, same as in Geth/Ethereum 
n = 262144 
r = 8 
p = 1 
dklen = 32 

# using same salt as Ethereum used 
salt = "69ccd8c258bb50ac2effd65837e09e45b8bd9a747a1a1f3558b65a16e2f46f1a" 
# using same iv as Ethereum used 
iv = "a4a6638ea73872c07d62fa065f37f790" 

puts "------------ Scrypt parameters ------------ " 
puts "Salt str = " + salt 
puts "Iv str = " + iv 
puts "n = " + n.to_s 
puts "r = " + r.to_s 
puts "p = " + p.to_s 
puts "dklen = " + dklen.to_s 

# Generate derived key 
derived_key = SCrypt::Engine.scrypt(password, salt, n, r, p, dklen) 
puts "------------ Scrypt output ------------ " 
puts "Derived key from password = " + derived_key.unpack("H*")[0] 

# Encrypt with derived key 
cipher_name = "aes-128-ctr" 
cipher = OpenSSL::Cipher.new cipher_name 
cipher.encrypt 
cipher.iv = iv 
cipher.key = derived_key 
encrypted = cipher.update([plain_private_key].pack("H*")) + cipher.final 
puts "------------ Encryption output ------------ " 
puts "Cipher text = " + encrypted.unpack("H*")[0] 

# Decrypt with derived key 
decipher = OpenSSL::Cipher.new cipher_name 
decipher.decrypt 
decipher.iv = iv 
decipher.key = derived_key 
decrypted = decipher.update(encrypted) + decipher.final 
decrypted_str = decrypted.unpack("H*")[0] 
puts "------------ Decryption output ------------ " 
puts "Decrypted: " + decrypted_str 
puts "Decryption worked: " + (plain_private_key == decrypted_str).to_s 

這是輸出:

------------ Encryption input ------------ 
Clear private key = 1234567890abcdef1234567890abcdef1234567890abcdef1234567890abcdef 
------------ Scrypt parameters ------------ 
Salt str = 69ccd8c258bb50ac2effd65837e09e45b8bd9a747a1a1f3558b65a16e2f46f1a 
Iv str = a4a6638ea73872c07d62fa065f37f790 
n = 262144 
r = 8 
p = 1 
dklen = 32 
------------ Scrypt output ------------ 
Derived key = b6e4410aa658f21213c7e55bacbbd8093e67f7f1738e7235335b58a2b690dcf5 
------------ Encryption output ------------ 
Cipher text = 6fddd3d2199edf65a17d9277d2328f5357e70a5be2e173d17681883ef5a3a27e 
------------ Decryption output ------------ 
Decrypted: 1234567890abcdef1234567890abcdef1234567890abcdef1234567890abcdef 
Decryption worked: true 

但密文是由什麼產生go-ethereum,使用相同的輸入和參數不同。

6fddd3d2199edf65a17d9277d2328f5357e70a5be2e173d17681883ef5a3a27e 

有人能幫我嗎?

回答

0

密鑰導出和加密都需要在四鹽從十六進制轉換爲二進制字符串,以同樣的方式爲你的私鑰做:

# using same salt as Ethereum used 
salt = ["69ccd8c258bb50ac2effd65837e09e45b8bd9a747a1a1f3558b65a16e2f46f1a"].pack('H*') 
# using same iv as Ethereum used 
iv = ["a4a6638ea73872c07d62fa065f37f790"].pack('H*') 

這給了相同的結果爲加密密鑰作爲去實現:

------------ Encryption output ------------ 
Cipher text = 62bbf1a5a93b8ba8c66b70b3381f9f5badf44b35287614d309d760ebeec47139 

別的東西,我注意到,這是不相關的立即解決問題:加密和解密只用前導出密鑰的16個字節。目前,Ruby OpenSSL綁定僅將關鍵字截斷爲正確的長度,因此目前正在運行,但這將會是change in future releases。這意味着您的代碼無法像升級後那樣運行。您需要提供正確的密鑰長度:

cipher.key = derived_key[0...16] 

,其餘16個字節的導出密鑰的被用作認證密鑰,使您可以檢查是否有任何已被篡改(你需要一個Ruby實現Keccak哈希函數來實現這一點)。