Örnek C Programı: CryptProtectData Kullanma

Note

DPAPI kapsamı ve sınırlamaları:

  • Varsayılan olarak, CryptProtectData yalnızca aynı makinedekiaynı kullanıcı hesabının şifresini çözebilmesi için verileri şifreler. Makinedeki CRYPTPROTECT_LOCAL_MACHINE herhangi bir kullanıcının şifresini çözmesine izin vermek için bayrağını kullanın.
  • DPAPI, aktarım sırasında veya makineler arasında verileri korumaz. Makineler arası veya çok kullanıcılı senaryolar için DPAPI-NG (NCryptProtectSecret/NCryptUnprotectSecret) veya CNG'yi açık anahtar yönetimiyle kullanın.
  • Kullanıcının parolası bir yönetici tarafından sıfırlanırsa (kullanıcı tarafından değiştirilmek yerine), kurtarma aracısı veya DPAPI yedekleme anahtarı olmadığı sürece önceden korunan veriler kurtarılamaz hale gelebilir.

Aşağıdaki örnek, CryptProtectData ve CryptUnprotectDatakullanarak BLOBverileri şifreler ve şifresini çözer.

Bu örnekte aşağıdaki görevler ve CryptoAPI işlevleri gösterilmektedir:

Bu örnekte MyHandleErrorişlevinikullanılır. Bu işlevin kodu örneğe dahil edilir. Bu ve diğer yardımcı işlevlerin kodu da Genel Amaçlı İşlevleraltında listelenir.

Aşağıdaki örnekte verilerin korunması gösterilmektedir.

#pragma comment(lib, "crypt32.lib")

#include <stdio.h>
#include <windows.h>
#include <Wincrypt.h>
#define MY_ENCODING_TYPE  (PKCS_7_ASN_ENCODING | X509_ASN_ENCODING)
void MyHandleError(char *s);

void main()
{

// Copyright (C) Microsoft.  All rights reserved.
// Encrypt data from DATA_BLOB DataIn to DATA_BLOB DataOut.
// Then decrypt to DATA_BLOB DataVerify.

//-------------------------------------------------------------------
// Declare and initialize variables.

DATA_BLOB DataIn;
DATA_BLOB DataOut;
DATA_BLOB DataVerify;
BYTE *pbDataInput =(BYTE *)"Hello world of data protection.";
DWORD cbDataInput = strlen((char *)pbDataInput)+1;
DataIn.pbData = pbDataInput;    
DataIn.cbData = cbDataInput;
CRYPTPROTECT_PROMPTSTRUCT PromptStruct;
LPWSTR pDescrOut = NULL;

//-------------------------------------------------------------------
//  Begin processing.

printf("The data to be encrypted is: %s\n",pbDataInput);

//-------------------------------------------------------------------
//  Initialize PromptStruct.

ZeroMemory(&PromptStruct, sizeof(PromptStruct));
PromptStruct.cbSize = sizeof(PromptStruct);
PromptStruct.dwPromptFlags = CRYPTPROTECT_PROMPT_ON_PROTECT;
PromptStruct.szPrompt = L"This is a user prompt.";

//-------------------------------------------------------------------
//  Begin protect phase.

if(CryptProtectData(
     &DataIn,
     L"This is the description string.", // A description string. 
     NULL,                               // Optional entropy
                                         // not used.
     NULL,                               // Reserved.
     &PromptStruct,                      // Pass a PromptStruct.
     0,
     &DataOut))
{
     printf("The encryption phase worked. \n");
}
else
{
    MyHandleError("Encryption error!");
}
//-------------------------------------------------------------------
//   Begin unprotect phase.

if (CryptUnprotectData(
        &DataOut,
        &pDescrOut,
        NULL,                 // Optional entropy
        NULL,                 // Reserved
        &PromptStruct,        // Optional PromptStruct
        0,
        &DataVerify))
{
     printf("The decrypted data is: %s\n", DataVerify.pbData);
     printf("The description of the data was: %S\n",pDescrOut);
}
else
{
    MyHandleError("Decryption error!");
}
//-------------------------------------------------------------------
// At this point, memcmp could be used to compare DataIn.pbData and 
// DataVerify.pbDate for equality. If the two functions worked
// correctly, the two byte strings are identical. 

//-------------------------------------------------------------------
//  Clean up.

LocalFree(pDescrOut);
LocalFree(DataOut.pbData);
LocalFree(DataVerify.pbData);
} // End of main

//-------------------------------------------------------------------
//  This example uses the function MyHandleError, a simple error
//  handling function, to print an error message to the  
//  standard error (stderr) file and exit the program. 
//  For most applications, replace this function with one 
//  that does more extensive error reporting.

void MyHandleError(char *s)
{
    fprintf(stderr,"An error occurred in running the program. \n");
    fprintf(stderr,"%s\n",s);
    fprintf(stderr, "Error number %x.\n", GetLastError());
    fprintf(stderr, "Program terminating. \n");
    exit(1);
} // End of MyHandleError