Procedura dettagliata: Crittografia e decrittografia di stringhe in Visual Basic

Questa procedura dettagliata illustra come usare la TripleDES classe per crittografare e decrittografare le stringhe usando l'algoritmo Triple Data Encryption Standard (3DES). Il primo passaggio consiste nel creare una classe wrapper semplice che incapsula l'algoritmo 3DES e archivia i dati crittografati come stringa con codifica base 64. Il wrapper viene quindi usato per archiviare in modo sicuro i dati utente privati in un file di testo accessibile pubblicamente.

È possibile usare la crittografia per proteggere i segreti utente (ad esempio, le password) e rendere le credenziali illeggibili da utenti non autorizzati. Questo può proteggere l'identità di un utente autorizzato dal furto, salvaguardando gli asset dell'utente e fornendo non ripudiabilità. La crittografia può anche proteggere i dati di un utente dall'accesso da parte di utenti non autorizzati.

Per altre informazioni, vedere Servizi di crittografia.

Importante

Gli algoritmi Rijndael (ora definiti Advanced Encryption Standard [AES]) e Triple Data Encryption Standard (3DES) offrono maggiore sicurezza rispetto a DES perché richiedono un uso più intensivo del calcolo. Per altre informazioni, vedere DES e Rijndael.

Per creare il wrapper di crittografia

  1. Creare la Simple3Des classe per incapsulare i metodi di crittografia e decrittografia.

    Public NotInheritable Class Simple3Des
    End Class
    
  2. Aggiungere un'importazione dello spazio dei nomi di crittografia all'inizio del file contenente la classe Simple3Des.

    Imports System.Security.Cryptography
    
  3. Nella classe Simple3Des, aggiungere campi privati per memorizzare il provider di servizi crittografici 3DES, la chiave specificata, la versione del formato, la dimensione del salt e il numero di iterazioni.

    Private TripleDes As TripleDES = TripleDES.Create()
    
    Private Const FormatVersion As Byte = 1
    Private Const SaltSize As Integer = 16
    Private Const Iterations As Integer = 600000
    Private ReadOnly Key As String
    
  4. Aggiungere un metodo privato che crea un array di byte a partire dalla chiave specificata e da un sale.

    Private Function DeriveKey(ByVal salt() As Byte) As Byte()
        ' Derive a key from the specified key and the salt.
        Using kdf As New Rfc2898DeriveBytes(
            Key, salt, Iterations, HashAlgorithmName.SHA256)
    
            Return kdf.GetBytes(TripleDes.KeySize \ 8)
        End Using
    End Function
    
  5. Aggiungere un costruttore che archivia la chiave specificata.

    Il key parametro controlla i EncryptData metodi e DecryptData .

    Sub New(ByVal key As String)
        ' Store the key. The encryption key and IV are created per message.
        Me.Key = key
    End Sub
    
  6. Aggiungere un metodo pubblico che crittografa una stringa.

    Public Function EncryptData( 
        ByVal plaintext As String) As String
    
        ' Create a new salt and initialization vector for this message.
        Dim salt(SaltSize - 1) As Byte
        Using rng As RandomNumberGenerator = RandomNumberGenerator.Create()
            rng.GetBytes(salt)
        End Using
    
        TripleDes.Key = DeriveKey(salt)
        TripleDes.GenerateIV()
    
        ' Convert the plaintext string to a byte array.
        Dim plaintextBytes() As Byte = 
            System.Text.Encoding.Unicode.GetBytes(plaintext)
    
        ' Create the stream.
        Dim ms As New System.IO.MemoryStream
        ' Write the format version, salt, and initialization vector in front of
        ' the cipher text. The version identifies the salt length and iteration count.
        ms.WriteByte(FormatVersion)
        ms.Write(salt, 0, salt.Length)
        ms.Write(TripleDes.IV, 0, TripleDes.IV.Length)
    
        ' Create the encoder to write to the stream.
        Dim encStream As New CryptoStream(ms, 
            TripleDes.CreateEncryptor(), 
            System.Security.Cryptography.CryptoStreamMode.Write)
    
        ' Use the crypto stream to write the byte array to the stream.
        encStream.Write(plaintextBytes, 0, plaintextBytes.Length)
        encStream.FlushFinalBlock()
    
        ' Convert the encrypted stream to a printable string.
        Return Convert.ToBase64String(ms.ToArray)
    End Function
    
  7. Aggiungere un metodo pubblico che decrittografa una stringa.

    Public Function DecryptData( 
        ByVal encryptedtext As String) As String
    
        ' Convert the encrypted text string to a byte array.
        Dim encryptedBytes() As Byte = Convert.FromBase64String(encryptedtext)
    
        ' Read the header that precedes the cipher text. Only one format
        ' version exists, so reject anything else.
        Dim ivSize As Integer = TripleDes.BlockSize \ 8
        Dim headerSize As Integer = 1 + SaltSize + ivSize
        If encryptedBytes.Length < headerSize OrElse
            encryptedBytes(0) <> FormatVersion Then
    
            Throw New CryptographicException(
                "The encrypted data is not in the expected format.")
        End If
    
        Dim salt(SaltSize - 1) As Byte
        Dim iv(ivSize - 1) As Byte
        Array.Copy(encryptedBytes, 1, salt, 0, SaltSize)
        Array.Copy(encryptedBytes, 1 + SaltSize, iv, 0, ivSize)
    
        TripleDes.Key = DeriveKey(salt)
        TripleDes.IV = iv
    
        ' Create the stream.
        Dim ms As New System.IO.MemoryStream
        ' Create the decoder to write to the stream.
        Dim decStream As New CryptoStream(ms, 
            TripleDes.CreateDecryptor(), 
            System.Security.Cryptography.CryptoStreamMode.Write)
    
        ' Use the crypto stream to write the byte array to the stream.
        decStream.Write(encryptedBytes, headerSize, 
            encryptedBytes.Length - headerSize)
        decStream.FlushFinalBlock()
    
        ' Convert the plaintext stream to a string.
        Return System.Text.Encoding.Unicode.GetString(ms.ToArray)
    End Function
    

    La classe wrapper può ora essere usata per proteggere gli asset utente. In questo esempio viene usato per archiviare in modo sicuro i dati utente privati in un file di testo accessibile pubblicamente.

Per testare il wrapper di crittografia

  1. In una classe separata aggiungere un metodo che usa il metodo del EncryptData wrapper per crittografare una stringa e scriverla nella cartella Documenti dell'utente.

    Sub TestEncoding()
        Dim plainText As String = InputBox("Enter the plain text:")
        Dim password As String = InputBox("Enter the password:")
    
        Dim wrapper As New Simple3Des(password)
        Dim cipherText As String = wrapper.EncryptData(plainText)
    
        MsgBox("The cipher text is: " & cipherText)
        My.Computer.FileSystem.WriteAllText( 
            My.Computer.FileSystem.SpecialDirectories.MyDocuments & 
            "\cipherText.txt", cipherText, False)
    End Sub
    
  2. Aggiungere un metodo che legge la stringa crittografata dalla cartella Documenti dell'utente e decrittografa la stringa con il metodo del DecryptData wrapper.

    Sub TestDecoding()
        Dim cipherText As String = My.Computer.FileSystem.ReadAllText( 
            My.Computer.FileSystem.SpecialDirectories.MyDocuments & 
                "\cipherText.txt")
        Dim password As String = InputBox("Enter the password:")
        Dim wrapper As New Simple3Des(password)
    
        ' DecryptData throws if the wrong password is used.
        Try
            Dim plainText As String = wrapper.DecryptData(cipherText)
            MsgBox("The plain text is: " & plainText)
        Catch ex As System.Security.Cryptography.CryptographicException
            MsgBox("The data could not be decrypted with the password.")
        End Try
    End Sub
    
  3. Aggiungere il codice dell'interfaccia utente per chiamare i metodi TestEncoding e TestDecoding.

  4. Eseguire l'applicazione.

    Quando si testa l'applicazione, si noti che non decrittograferà i dati se si specifica la password errata.

Vedere anche