1.什么是密鑰庫(kù)系統(tǒng)?
利用 Android 密鑰庫(kù)系統(tǒng),您可以在容器中存儲(chǔ)加密密鑰,從而提高從設(shè)備中提取密鑰的難度。在密鑰進(jìn)入密鑰庫(kù)后,可以將它們用于加密操作,而密鑰材料仍不可導(dǎo)出。此外,它提供了密鑰使用的時(shí)間和方式限制措施,例如要求進(jìn)行用戶身份驗(yàn)證才能使用密鑰,或者限制為只能在某些加密模式中使用。
密鑰庫(kù)系統(tǒng)并不是讓程序直接進(jìn)行存儲(chǔ)程序的私密信息的,比如說用戶賬號(hào)密碼,其提供了一個(gè)密鑰安全容器,保護(hù)密鑰材料免遭未經(jīng)授權(quán)的使用,一個(gè)應(yīng)用程序可以在密鑰庫(kù)中存儲(chǔ)多個(gè)密鑰并且只允許應(yīng)用自身訪問,應(yīng)用程序可以在密鑰庫(kù)系統(tǒng)中生成,存儲(chǔ),獲取存儲(chǔ)其中的公鑰或者私鑰,因此可使用密鑰庫(kù)系統(tǒng)中的密鑰來進(jìn)行數(shù)據(jù)的加密。
密鑰庫(kù)系統(tǒng)由 KeyChain API 以及在 Android 4.3(API 級(jí)別 18)中引入的 Android 密鑰庫(kù)提供程序功能使用。
安卓系統(tǒng)提供了下面幾種KeyStore類型:

各種類型的詳細(xì)說明可以參考:https://developer.android.com/openjdk-redirect.html?v=8&path=/technotes/guides/security/StandardNames.html#KeyStore
下面操作都是基于AndroidKeyStore
2.密鑰庫(kù)的操作(生成密鑰,刪除密鑰,加密,解密)
先創(chuàng)建一個(gè)Activity,自定義布局從頁(yè)面上來實(shí)現(xiàn)幾種功能
<?xml version="1.0" encoding="utf-8"?>
<android.support.v4.widget.NestedScrollView xmlns:android="http://schemas.android.com/apk/res/android"
android:layout_width="match_parent"
android:layout_height="match_parent"
xmlns:tools="http://schemas.android.com/tools">
<LinearLayout
android:layout_width="match_parent"
android:layout_height="match_parent"
android:orientation="vertical"
tools:context=".MainActivity">
<android.support.v7.widget.AppCompatEditText
android:id="@+id/edit_text"
android:layout_width="match_parent"
android:layout_height="50dp"
android:layout_marginTop="5dp" />
<LinearLayout
android:layout_width="match_parent"
android:layout_height="wrap_content"
android:layout_marginTop="5dp"
android:gravity="center"
android:orientation="horizontal">
<Button
android:id="@+id/btn_add"
android:layout_width="0dp"
android:layout_height="wrap_content"
android:layout_weight="1"
android:onClick="onAddKey"
android:text="添加" />
<Button
android:id="@+id/btn_delete"
android:layout_width="0dp"
android:layout_height="wrap_content"
android:layout_weight="1"
android:onClick="onDeleteKey"
android:text="刪除" />
</LinearLayout>
<LinearLayout
android:layout_width="match_parent"
android:layout_height="wrap_content"
android:gravity="center"
android:orientation="horizontal">
<TextView
android:layout_width="wrap_content"
android:layout_height="wrap_content"
android:padding="5dp"
android:text="明文:" />
<TextView
android:layout_width="match_parent"
android:layout_height="wrap_content"
android:padding="5dp"
android:text="@string/plaintext" />
</LinearLayout>
<TextView
android:layout_width="match_parent"
android:layout_height="wrap_content"
android:padding="5dp"
android:text="加密/解密(Base64):" />
<TextView
android:id="@+id/tv_cipher"
android:layout_width="match_parent"
android:layout_height="wrap_content"
android:padding="5dp" />
<LinearLayout
android:layout_width="match_parent"
android:layout_height="wrap_content"
android:layout_marginTop="5dp"
android:gravity="center"
android:orientation="horizontal">
<Button
android:id="@+id/btn_encrypt"
android:layout_width="0dp"
android:layout_height="wrap_content"
android:layout_weight="1"
android:onClick="doEncrypt"
android:text="加密" />
<Button
android:id="@+id/btn_decrypt"
android:layout_width="0dp"
android:layout_height="wrap_content"
android:layout_weight="1"
android:onClick="doDecrypt"
android:text="解密" />
</LinearLayout>
<TextView
android:id="@+id/tv_current"
android:layout_width="match_parent"
android:layout_height="wrap_content"
android:background="#FFDBD9"
android:gravity="center|left"
android:padding="5dp"
android:text="@string/current_key"
android:textSize="12sp" />
<android.support.v7.widget.RecyclerView
android:id="@+id/recyclerview"
android:layout_width="match_parent"
android:layout_height="match_parent">
</android.support.v7.widget.RecyclerView>
</LinearLayout>
</android.support.v4.widget.NestedScrollView>
效果圖:


說明:
1.輸入框輸入要增加的密鑰的名稱,點(diǎn)擊添加按鈕進(jìn)行添加一個(gè)新密鑰;
2.輸入框輸入要?jiǎng)h除的密鑰的名稱,點(diǎn)擊刪除按鈕進(jìn)行刪除一個(gè)已存在的密鑰;
3.這里指定了數(shù)據(jù)明文,點(diǎn)擊密鑰列表中的item可選中指定的密鑰,用于使用密鑰進(jìn)行加密和解密,選中密鑰后,可點(diǎn)擊加密按鈕進(jìn)行加密,加密后可點(diǎn)擊解密按鈕進(jìn)行解密;
4.密鑰列表顯示當(dāng)前應(yīng)用在密鑰庫(kù)系統(tǒng)中生成了的密鑰,長(zhǎng)按可刪除密鑰;
MainActivity
package com.iigo.keystore;
import android.os.Bundle;
import android.support.annotation.NonNull;
import android.support.v7.app.AppCompatActivity;
import android.support.v7.widget.DividerItemDecoration;
import android.support.v7.widget.LinearLayoutManager;
import android.support.v7.widget.RecyclerView;
import android.text.TextUtils;
import android.util.Base64;
import android.view.View;
import android.view.ViewGroup;
import android.widget.EditText;
import android.widget.TextView;
import android.widget.Toast;
import java.util.ArrayList;
import java.util.Enumeration;
import java.util.List;
public class MainActivity extends AppCompatActivity {
private RecyclerView recyclerView;
private Adapter adapter;
private List<String> aliasList = new ArrayList<>();
private EditText editText;
private TextView tvKey;
private TextView tvCipher;
private String plainText; //明文
private String encryptData; //加密后字符串
private String currentSelectedKeyAlias;
@Override
protected void onCreate(Bundle savedInstanceState) {
super.onCreate(savedInstanceState);
setContentView(R.layout.activity_main);
initViews();
updateKeys();
//驗(yàn)證數(shù)據(jù)簽名
String data = "1234";
byte[] sign = KeyStoreUtil.get().sign(data.getBytes(), "qq");
System.out.println("verify: "+KeyStoreUtil.get().verify(data.getBytes(), sign, "qq"));
}
private void updateKeys() {
aliasList.clear();
Enumeration<String> aliases = KeyStoreUtil.get().getAliases();
if (aliases!= null){
while (aliases.hasMoreElements()){
aliasList.add(aliases.nextElement());
}
}
adapter.notifyDataSetChanged();
}
private void initViews() {
recyclerView = findViewById(R.id.recyclerview);
recyclerView.setLayoutManager(new LinearLayoutManager(getApplicationContext()));
recyclerView.addItemDecoration(new DividerItemDecoration(getBaseContext(), DividerItemDecoration.VERTICAL));
adapter = new Adapter();
adapter.setItemClickListener(itemClickListener);
recyclerView.setAdapter(adapter);
editText = findViewById(R.id.edit_text);
tvKey = findViewById(R.id.tv_current);
tvCipher = findViewById(R.id.tv_cipher);
tvKey.setText(getString(R.string.current_key, ""));
plainText = getString(R.string.plaintext);
}
@Override
protected void onPause() {
super.onPause();
if (isFinishing()){
aliasList.clear();
}
}
public void onAddKey(View view){
String alias = editText.getText().toString();
if (!TextUtils.isEmpty(alias)){
KeyStoreUtil.get().generateKey(getBaseContext(), alias);
updateKeys();
}
}
public void onDeleteKey(View view){
deleteKey(editText.getText().toString());
}
private void deleteKey(String alias){
if (!TextUtils.isEmpty(alias)){
KeyStoreUtil.get().deleteKey(alias);
updateKeys();
}
}
private OnItemClickListener itemClickListener = new OnItemClickListener() {
@Override
public void onItemClick(View view, int position) {
currentSelectedKeyAlias = aliasList.get(position);
tvKey.setText(getString(R.string.current_key, currentSelectedKeyAlias));
}
@Override
public boolean onItemLongClick(View view, int position) {
deleteKey(aliasList.get(position));
return true;
}
};
public void doEncrypt(View view) {
if (currentSelectedKeyAlias == null){
Toast.makeText(getApplicationContext(), "請(qǐng)先選取alias", Toast.LENGTH_SHORT).show();
return;
}
byte[] data = KeyStoreUtil.get().encrypt(plainText.getBytes(), currentSelectedKeyAlias);
if (data != null){
encryptData = Base64.encodeToString(data, Base64.DEFAULT);
tvCipher.setText(getString(R.string.encrypt_content, encryptData));
}
}
public void doDecrypt(View view) {
if (currentSelectedKeyAlias == null){
Toast.makeText(getApplicationContext(), "請(qǐng)先選取alias", Toast.LENGTH_SHORT).show();
return;
}
byte[] data = KeyStoreUtil.get().decrypt(Base64.decode(encryptData, Base64.DEFAULT), currentSelectedKeyAlias);
if (data != null){
tvCipher.setText(getString(R.string.decrypt_content, new String(data)));
}
}
private class ViewHolder extends RecyclerView.ViewHolder{
TextView textView;
public ViewHolder(View itemView) {
super(itemView);
textView = itemView.findViewById(R.id.tv_name);
}
}
private class Adapter extends RecyclerView.Adapter<ViewHolder> {
private OnItemClickListener itemClickListener;
@NonNull
@Override
public ViewHolder onCreateViewHolder(@NonNull ViewGroup parent, int viewType) {
View view = getLayoutInflater().inflate(R.layout.layout_item, parent, false);
return new ViewHolder(view);
}
@Override
public void onBindViewHolder(@NonNull ViewHolder holder, final int position) {
holder.textView.setText(aliasList.get(position));
holder.itemView.setOnClickListener(new View.OnClickListener() {
@Override
public void onClick(View v) {
if (itemClickListener != null){
itemClickListener.onItemClick(v, position);
}
}
});
holder.itemView.setOnLongClickListener(new View.OnLongClickListener() {
@Override
public boolean onLongClick(View v) {
if (itemClickListener != null){
return itemClickListener.onItemLongClick(v, position);
}
return false;
}
});
}
@Override
public int getItemCount() {
return aliasList.size();
}
public void setItemClickListener(OnItemClickListener itemClickListener){
this.itemClickListener = itemClickListener;
}
}
public interface OnItemClickListener{
void onItemClick(View view, int position);
boolean onItemLongClick(View view, int position);
}
}
密鑰庫(kù)系統(tǒng)工具類
package com.iigo.keystore;
import android.content.Context;
import android.security.KeyPairGeneratorSpec;
import android.text.TextUtils;
import java.io.IOException;
import java.math.BigInteger;
import java.security.InvalidAlgorithmParameterException;
import java.security.InvalidKeyException;
import java.security.KeyPair;
import java.security.KeyPairGenerator;
import java.security.KeyStore;
import java.security.KeyStoreException;
import java.security.NoSuchAlgorithmException;
import java.security.NoSuchProviderException;
import java.security.PrivateKey;
import java.security.Signature;
import java.security.SignatureException;
import java.security.UnrecoverableEntryException;
import java.security.cert.CertificateException;
import java.security.interfaces.RSAPublicKey;
import java.util.Calendar;
import java.util.Enumeration;
import javax.crypto.BadPaddingException;
import javax.crypto.Cipher;
import javax.crypto.IllegalBlockSizeException;
import javax.crypto.NoSuchPaddingException;
import javax.security.auth.x500.X500Principal;
/**
* @author SamLeung
* @Emial 729717222@qq.com
* @date 2018/6/14 0014 12:15
*/
public class KeyStoreUtil {
private static KeyStoreUtil INSTANCE;
private static Object LOCK = new Object();
private KeyStore keyStore;
private X500Principal x500Principal; //自簽署證書
private static final String CIPHER_TRANSFORMATION = "RSA/ECB/PKCS1Padding";
private KeyStoreUtil(){
init();
}
private void init() {
try {
keyStore = KeyStore.getInstance("AndroidKeyStore");
keyStore.load(null);
/**
* CN commonName
* O organizationName
* OU organizationalUnitName
* C countryName
* */
x500Principal = new X500Principal("CN=Duke, OU=JavaSoft, O=Sun Microsystems, C=US");
} catch (KeyStoreException e) {
e.printStackTrace();
} catch (CertificateException e) {
e.printStackTrace();
} catch (NoSuchAlgorithmException e) {
e.printStackTrace();
} catch (IOException e) {
e.printStackTrace();
}
}
public static KeyStoreUtil get(){
if (INSTANCE == null){
synchronized (LOCK){
if (INSTANCE == null){
INSTANCE = new KeyStoreUtil();
}
}
}
return INSTANCE;
}
/**
* 獲取當(dāng)前應(yīng)用密鑰庫(kù)中的條目
*
* @return
* */
public Enumeration<String> getAliases(){
if (keyStore == null) {
return null;
}
try {
return keyStore.aliases();
} catch (KeyStoreException e) {
e.printStackTrace();
}
return null;
}
/**
* 先判斷是否存在該別名
* */
public boolean containsAlias(String alias) {
if (keyStore == null || TextUtils.isEmpty(alias)){
return false;
}
boolean contains = false;
try{
contains = keyStore.containsAlias(alias);
}catch (Exception e){
e.printStackTrace();
}
return contains;
}
/**
* 生成新的密鑰
*
* @param context
* @param alias 存儲(chǔ)在KeyStore中的別名
* */
public KeyPair generateKey(Context context, String alias){
if (containsAlias(alias)){
return null;
}
try {
Calendar endDate = Calendar.getInstance();
endDate.add(Calendar.YEAR, 10);
KeyPairGeneratorSpec spec = new KeyPairGeneratorSpec.Builder(context.getApplicationContext())
.setAlias(alias)
.setSubject(x500Principal)
.setSerialNumber(BigInteger.ONE)
.setStartDate(Calendar.getInstance().getTime())
.setEndDate(endDate.getTime())
.build();
KeyPairGenerator generator = KeyPairGenerator.getInstance("RSA", "AndroidKeyStore");
generator.initialize(spec);
return generator.generateKeyPair();
} catch (NoSuchAlgorithmException e) {
e.printStackTrace();
} catch (NoSuchProviderException e) {
e.printStackTrace();
} catch (InvalidAlgorithmParameterException e) {
e.printStackTrace();
} catch (NullPointerException e){
e.printStackTrace();
}
return null;
}
public void deleteKey(final String alias){
try{
keyStore.deleteEntry(alias);
} catch (Exception e) {
e.printStackTrace();
}
}
/**
* 加密
*
* @param data 要加密的數(shù)據(jù)
* @param alias KeyStore中的別名
* */
public byte[] encrypt(byte[] data, String alias){
try {
//取出密鑰
KeyStore.PrivateKeyEntry privateKeyEntry = (KeyStore.PrivateKeyEntry)keyStore.getEntry(alias, null);
RSAPublicKey publicKey = (RSAPublicKey) privateKeyEntry.getCertificate().getPublicKey();
Cipher cipher = Cipher.getInstance(CIPHER_TRANSFORMATION);
cipher.init(Cipher.ENCRYPT_MODE, publicKey);
return cipher.doFinal(data);
} catch (NoSuchAlgorithmException e) {
e.printStackTrace();
} catch (InvalidKeyException e) {
e.printStackTrace();
} catch (UnrecoverableEntryException e) {
e.printStackTrace();
} catch (NoSuchPaddingException e) {
e.printStackTrace();
} catch (KeyStoreException e) {
e.printStackTrace();
} catch (BadPaddingException e) {
e.printStackTrace();
} catch (IllegalBlockSizeException e) {
e.printStackTrace();
}
return null;
}
/**
* 解密
*
* @param data 要解密的數(shù)據(jù)
* @param alias KeyStore中的別名
* */
public byte[] decrypt(byte[] data, String alias){
try {
//取出密鑰
KeyStore.PrivateKeyEntry privateKeyEntry = (KeyStore.PrivateKeyEntry)keyStore.getEntry(alias, null);
PrivateKey privateKey = privateKeyEntry.getPrivateKey();
Cipher cipher = Cipher.getInstance(CIPHER_TRANSFORMATION);
cipher.init(Cipher.DECRYPT_MODE, privateKey);
return cipher.doFinal(data);
} catch (NoSuchAlgorithmException e) {
e.printStackTrace();
} catch (InvalidKeyException e) {
e.printStackTrace();
} catch (UnrecoverableEntryException e) {
e.printStackTrace();
} catch (NoSuchPaddingException e) {
e.printStackTrace();
} catch (KeyStoreException e) {
e.printStackTrace();
} catch (BadPaddingException e) {
e.printStackTrace();
} catch (IllegalBlockSizeException e) {
e.printStackTrace();
}
return null;
}
/**
* 對(duì)數(shù)據(jù)進(jìn)行簽名
*
* @param data
* @param alias
* */
public byte[] sign(byte[] data, String alias){
try{
//取出密鑰
KeyStore.PrivateKeyEntry privateKeyEntry = (KeyStore.PrivateKeyEntry)keyStore.getEntry(alias, null);
Signature s = Signature.getInstance("SHA1withRSA");
s.initSign(privateKeyEntry.getPrivateKey());
s.update(data);
return s.sign();
} catch (NoSuchAlgorithmException e) {
e.printStackTrace();
} catch (KeyStoreException e) {
e.printStackTrace();
} catch (UnrecoverableEntryException e) {
e.printStackTrace();
} catch (SignatureException e) {
e.printStackTrace();
} catch (InvalidKeyException e) {
e.printStackTrace();
}
return null;
}
/**
* 驗(yàn)證數(shù)據(jù)簽名
*
* @param data 原始數(shù)據(jù)
* @param signatureData 簽署的數(shù)據(jù)
* @param alias
* */
public boolean verify (byte[] data, byte[] signatureData, String alias){
try{
//取出密鑰
KeyStore.PrivateKeyEntry privateKeyEntry = (KeyStore.PrivateKeyEntry)keyStore.getEntry(alias, null);
Signature s = Signature.getInstance("SHA1withRSA");
s.initVerify(privateKeyEntry.getCertificate());
s.update(data);
return s.verify(signatureData);
} catch (NoSuchAlgorithmException e) {
e.printStackTrace();
} catch (InvalidKeyException e) {
e.printStackTrace();
} catch (SignatureException e) {
e.printStackTrace();
} catch (UnrecoverableEntryException e) {
e.printStackTrace();
} catch (KeyStoreException e) {
e.printStackTrace();
}
return false;
}
}
生成新密鑰
生成密鑰時(shí)使用X500Principal指定了自簽署證書,參數(shù)分別代表
CN:通用名稱
O:組織
OU:組織單元
C:國(guó)家
并且指定密鑰的有效時(shí)間,并且指定了用于生成密鑰對(duì)的自簽名證書的序列號(hào)。
這里指定了通過密鑰庫(kù)系統(tǒng)生成RSA密鑰。
/**
* CN commonName
* O organizationName
* OU organizationalUnitName
* C countryName
* */
x500Principal = new X500Principal("CN=Duke, OU=JavaSoft, O=Sun Microsystems, C=US");
Calendar endDate = Calendar.getInstance();
endDate.add(Calendar.YEAR, 10);
KeyPairGeneratorSpec spec = new KeyPairGeneratorSpec.Builder(context.getApplicationContext())
.setAlias(alias)
.setSubject(x500Principal)
.setSerialNumber(BigInteger.ONE)
.setStartDate(Calendar.getInstance().getTime())
.setEndDate(endDate.getTime())
.build();
KeyPairGenerator generator = KeyPairGenerator.getInstance("RSA", "AndroidKeyStore");
generator.initialize(spec);
return generator.generateKeyPair();
刪除密鑰
keyStore.deleteEntry(alias);
使用密鑰加密
先從密鑰庫(kù)中取出密鑰,使用公鑰進(jìn)行加密
KeyStore.PrivateKeyEntry privateKeyEntry = (KeyStore.PrivateKeyEntry)keyStore.getEntry(alias, null);
RSAPublicKey publicKey = (RSAPublicKey) privateKeyEntry.getCertificate().getPublicKey();
Cipher cipher = Cipher.getInstance(CIPHER_TRANSFORMATION);
cipher.init(Cipher.ENCRYPT_MODE, publicKey);
return cipher.doFinal(data);
使用密鑰解密
先從密鑰庫(kù)中取出密鑰,使用私鑰進(jìn)行解密
KeyStore.PrivateKeyEntry privateKeyEntry = (KeyStore.PrivateKeyEntry)keyStore.getEntry(alias, null);
PrivateKey privateKey = privateKeyEntry.getPrivateKey();
Cipher cipher = Cipher.getInstance(CIPHER_TRANSFORMATION);
cipher.init(Cipher.DECRYPT_MODE, privateKey);
return cipher.doFinal(data);
使用密鑰對(duì)數(shù)據(jù)簽名
使用密鑰對(duì)數(shù)據(jù)簽名,簽名算法須與秘鑰算法保持一致。
public byte[] sign(byte[] data, String alias){
try{
//取出密鑰
KeyStore.PrivateKeyEntry privateKeyEntry = (KeyStore.PrivateKeyEntry)keyStore.getEntry(alias, null);
Signature s = Signature.getInstance("SHA1withRSA");
s.initSign(privateKeyEntry.getPrivateKey());
s.update(data);
return s.sign();
} catch (NoSuchAlgorithmException e) {
e.printStackTrace();
} catch (KeyStoreException e) {
e.printStackTrace();
} catch (UnrecoverableEntryException e) {
e.printStackTrace();
} catch (SignatureException e) {
e.printStackTrace();
} catch (InvalidKeyException e) {
e.printStackTrace();
}
return null;
}
數(shù)據(jù)簽名認(rèn)證
使用密鑰對(duì)數(shù)據(jù)進(jìn)行簽名認(rèn)證,簽名算法須與秘鑰算法保持一致。
public boolean verify (byte[] data, byte[] signatureData, String alias){
try{
//取出密鑰
KeyStore.PrivateKeyEntry privateKeyEntry = (KeyStore.PrivateKeyEntry)keyStore.getEntry(alias, null);
Signature s = Signature.getInstance("SHA1withRSA");
s.initVerify(privateKeyEntry.getCertificate());
s.update(data);
return s.verify(signatureData);
} catch (NoSuchAlgorithmException e) {
e.printStackTrace();
} catch (InvalidKeyException e) {
e.printStackTrace();
} catch (SignatureException e) {
e.printStackTrace();
} catch (UnrecoverableEntryException e) {
e.printStackTrace();
} catch (KeyStoreException e) {
e.printStackTrace();
}
return false;
}
密鑰庫(kù)支持的算法可參考:https://developer.android.com/training/articles/keystore