之前寫過一篇PHP7的AES資料加密function教學
//AES 資料加密
function encryptdecode($var="",$types="",$key=""){
//製作SHA384-KEY
$hash_string = $key;
$hash = hash('SHA384', $hash_string, true);
$app_cc_aes_key = substr($hash, 0, 32);
$app_cc_aes_iv = substr($hash, 32, 16);
//加密
if($types==encrypt){
$data = $var;
$padding = 16 - (strlen($data) % 16);
$data .= str_repeat(chr($padding), $padding);
$encrypt = mcrypt_encrypt(MCRYPT_RIJNDAEL_128, $app_cc_aes_key, $data, MCRYPT_MODE_CBC, $app_cc_aes_iv);
$encrypt_text = base64_encode($encrypt);
$returnvar=$encrypt_text;
}
//解密
if($types==decryption){
$encrypt =base64_decode($var);
$data = mcrypt_decrypt(MCRYPT_RIJNDAEL_128, $app_cc_aes_key, $encrypt, MCRYPT_MODE_CBC, $app_cc_aes_iv);
$padding = ord($data[strlen($data) - 1]);
$decrypt_text = substr($data, 0, -$padding);
$returnvar=$decrypt_text;
}
return $returnvar;
}
但因為php7.1之取消了Mcrypt加密套件,所以原本的方法就不能使用了,必須改用OpenSSL來加密資料,以下為吧Mcrypt加密function替換為OpenSSL加密function的方法,只需要更動function內容即可,在模組中引入的function及傳入值參都不須更動。
原本的Mcrypt加密function
function encryptdecode($var="",$types="",$key=""){
//製作SHA384-KEY
$hash_string = $key;
$hash = hash('SHA384', $hash_string, true);
$app_cc_aes_key = substr($hash, 0, 32);
$app_cc_aes_iv = substr($hash, 32, 16);
//加密
if($types==encrypt){
$data = $var;
$padding = 16 - (strlen($data) % 16);
$data .= str_repeat(chr($padding), $padding);
$encrypt = mcrypt_encrypt(MCRYPT_RIJNDAEL_128, $app_cc_aes_key, $data, MCRYPT_MODE_CBC, $app_cc_aes_iv);
$encrypt_text = base64_encode($encrypt);
$returnvar=$encrypt_text;
}
//解密
if($types==decryption){
$encrypt =base64_decode($var);
$data = mcrypt_decrypt(MCRYPT_RIJNDAEL_128, $app_cc_aes_key, $encrypt, MCRYPT_MODE_CBC, $app_cc_aes_iv);
$padding = ord($data[strlen($data) - 1]);
$decrypt_text = substr($data, 0, -$padding);
$returnvar=$decrypt_text;
}
return $returnvar;
}
直接替換成以下的OpenSSL加密function
//openssl資料加密
function encryptdecode($var="",$types="",$key=""){
//加密
if($types=="encrypt"){
$id=serialize($var);//加密資料
$data['iv']=base64_encode(substr('fdakinel;injajdji',0,16));
$data['value']=openssl_encrypt($id, 'AES-256-CBC',$key,0,base64_decode($data['iv']));
$encrypt=base64_encode(json_encode($data));
$returnvar=$encrypt;
}
//解密
if($types=="decryption"){
$encrypt=$var; //解密資料
$encrypt = json_decode(base64_decode($encrypt), true);
$iv = base64_decode($encrypt['iv']);
$decrypt = openssl_decrypt($encrypt['value'], 'AES-256-CBC', $key, 0, $iv);
$id = unserialize($decrypt);
if(!empty($id)) $returnvar= $id;
}
return $returnvar;
}
使用方法跟原本的Mcrypt加密function一樣
$var為加密解密資料傳入值
$key為加密解密key值(必須一樣)
$types為選擇function加密或解密
//資料加密
echo encryptdecode($var="Good day, 201852",$types="encrypt",$key=test123);
輸出加密字串:dO7N6jPnOhfWpBHnefP9w0GHVrnvpkZQGmkXcCnxXFg=
//資料解密
echo encryptdecode($var="dO7N6jPnOhfWpBHnefP9w0GHVrnvpkZQGmkXcCnxXFg=",$types="decryption",$key=test123);
輸出解密字串:Good day, 201852
echo encryptdecode($var="Good day, 201852",$types="encrypt",$key=test123);
輸出加密字串:dO7N6jPnOhfWpBHnefP9w0GHVrnvpkZQGmkXcCnxXFg=
//資料解密
echo encryptdecode($var="dO7N6jPnOhfWpBHnefP9w0GHVrnvpkZQGmkXcCnxXFg=",$types="decryption",$key=test123);
輸出解密字串:Good day, 201852
教學撰寫:徐嘉裕 Neil hsu
依照您所依照您所提供的OpenSSL替代方案, 所得到的結果與您在網頁上顯示的不同
回覆刪除是不是用法不正確阿~要吧輸出加密字串的值用在解密的$var
刪除例如
//加密
$encrypt=encryptdecode($var='KK16819804',$types="encrypt",$key=XOOPS_LICENSE_KEY);
//解密
$encrypt=encryptdecode($var=$encrypt,$types="decryption",$key=XOOPS_LICENSE_KEY);
ECHO $encrypt 輸出 KK16819804 我剛剛測試過了沒問題的!