  1 对称加密


  cipher.init(mode, key);模式有以下四种:





// 可以一直调用cipher.update(),进行加密


  int blockSize = cipher.getBlockSize();

  byte[] inBytes = new byte[blockSize];

  ... // read inBytes

  int outputSize = cipher.getOutputSize(blockSize);

  byte[] outBytes = new byte[outputSize];

  int outLength = cipher.update(inBytes, 0, outputSize, outBytes);

  ... // write outBytes



  outBytes = cipher.doFinal(inBytes, 0, inLength);


  outBytes = cipher.doFinal();




  doFinal调用时必要的,因为它会对最后的数据块进行填充,常用填充方案是RSA Security公司在公共秘钥密码标准#5(Public Key Cryptography Standard, PKCS)中描述的方案


  2 秘钥生成


  1). 为加密算法获取KeyGenerator

  2). 用随机源来初始化秘钥发生器。如果密码长度是可变的,还需要指定期望的密码块长度

  3). 调用generateKey方法



KeyGenerator keygen = KeyGenerator.getInstance("AES");


  SecureRandom random = new SecureRandom();


  SecretKey key = keygen.generateKey();




  byte[] keyData = ...; // 16 byte for AES

  SecretKey key = new SecretKeySpec(keyData, "AES");


  SecureRandom类产生的随机数,远比由Random类产生的那些随机数字安全得多。也可以由我们提供种子。由setSeed(byre[] b)方法传递给它。


!注意: 这个算法仍然被人为是安全的。而且,在过去,依靠对诸如硬盘访问之间的类的其他计算机组件进行计时的算法, 后来也被证明不也是完全随机的。

  3 密码流


  API javax.crypto.CipherInputStream 1.4

CipherInputStream(InputStream in, Cipher cipher)


  int read()

  int read(byte[] b, int off, int len)


CipherOutputSream(OutputStream out, Cipher cipher)


  void write(int ch)

  void write(byte b, int off, int len)


  void flush()




  4 工具类


import javax.crypto.*;


  import javax.crypto.spec.IvParameterSpec;

  import javax.crypto.spec.SecretKeySpec;

  import java.io.*;

  import java.nio.charset.Charset;

  import java.nio.charset.StandardCharsets;

  import java.nio.file.Files;

  import java.security.*;

  import java.security.spec.AlgorithmParameterSpec;

  import java.util.Base64;

  import java.util.Objects;

   * 加解密字符串、文件工具类

   * @author YYang 13047

   * @version 2022/10/25 12:10

  public class AESUtils {

   public static final String AES = "AES";

   //PKCS: Public Key Cryptographic Standard

   public static final String AES_ECB = "AES/ECB/PKCS5Padding";

   public static final String AES_CBC = "AES/CBC/PKCS5Padding";

   public static final String AES_CFB = "AES/CFB/PKCS5Padding";

   public static final int KEY_SIZE = 128;

   public static final int BUFFER_SIZE = 512;

   public static String encodeToString(byte[] unEncoded) {

   return Base64.getEncoder().encodeToString(unEncoded);

   public static byte[] decode(String encoded) {

   return Base64.getDecoder().decode(encoded);

   public static String generateAESKey() throws NoSuchAlgorithmException {

   return generateAESKey(KEY_SIZE, null);

   * @param keySize keySize must be equal to 128, 192 or 256;

   * @param seed 随机数种子

   * @see #generateAESKey0()

   public static String generateAESKey(int keySize, String seed) throws NoSuchAlgorithmException {

   KeyGenerator keyGen = KeyGenerator.getInstance(AES);

   SecureRandom random = (seed == null seed.length() == 0) ?

   new SecureRandom() : new SecureRandom(seed.getBytes(StandardCharsets.UTF_8));

   //如果不初始化,SunJCE默认使用new SecureRandom()

   keyGen.init(keySize, random);

   SecretKey secretKey = keyGen.generateKey();

   return encodeToString(secretKey.getEncoded());

   * @return 密钥,不初始化,使用默认的

   public static String generateAESKey0() throws NoSuchAlgorithmException {

   return encodeToString(KeyGenerator.getInstance(AES).generateKey().getEncoded());

   * @param algorithm 算法名

   * @return 返回一个当前算法BlockSize大小的随机数组,然后Base64转码

   * @see #generateAESIv()

   public static String generateAESIv(String algorithm) throws NoSuchAlgorithmException, NoSuchPaddingException {

   Cipher cipher = Cipher.getInstance(algorithm);

   int blockSize = cipher.getBlockSize();

   byte[] ivByte = new byte[blockSize];

   new SecureRandom().nextBytes(ivByte);

   return encodeToString(ivByte);

   public static String generateAESIv() {

   //AES blockSize == 16

   byte[] bytes = new byte[16];

   new SecureRandom().nextBytes(bytes);

   return encodeToString(bytes);

   public static AlgorithmParameterSpec getIv(String ivStr) {

   if (ivStr == null ivStr.length() 1) return null;

   return new IvParameterSpec(decode(ivStr));

   * @return 指定秘钥和算法,返回Key对象

   public static Key getKey(String keyStr, String algorithm) {

   return new SecretKeySpec(decode(keyStr), algorithm);

   public static Cipher initCipher(String algorithm, int cipherMode, Key key, AlgorithmParameterSpec param)

   throws NoSuchPaddingException, NoSuchAlgorithmException, InvalidKeyException, InvalidAlgorithmParameterException {

   Cipher cipher = Cipher.getInstance(algorithm);

   if (param == null) {

   cipher.init(cipherMode, key);

   } else {

   cipher.init(cipherMode, key, param);

   return cipher;

   public static String encrypt(String algorithm, String keyStr, String ivStr, String unencryptedStr) throws Exception {

   return encrypt(algorithm, keyStr, ivStr, unencryptedStr, StandardCharsets.UTF_8);

   public static String encrypt(String algorithm, String keyStr, String ivStr, String unencryptedStr, Charset charset) throws Exception {

   Cipher cipher = initCipher(algorithm, Cipher.ENCRYPT_MODE, getKey(keyStr, AES), getIv(ivStr));

   byte[] encrypted = cipher.doFinal(unencryptedStr.getBytes(charset));

   return encodeToString(encrypted);

   public static String decrypt(String algorithm, String keyStr, String ivStr, String encryptedStr) throws Exception {

   return decrypt(algorithm, keyStr, ivStr, encryptedStr, StandardCharsets.UTF_8);

   public static String decrypt(String algorithm, String keyStr, String ivStr, String encryptedStr, Charset charset) throws Exception {

   Cipher cipher = initCipher(algorithm, Cipher.DECRYPT_MODE, getKey(keyStr, AES), getIv(ivStr));

   byte[] decrypted = cipher.doFinal(decode(encryptedStr));

   return new String(decrypted, charset);

   * 解密文件

   public static void encryptFile(String algorithm, String keyStr, String ivStr, File source, File target) throws Exception {

   checkPath(source, target);

   Cipher cipher = initCipher(algorithm, Cipher.ENCRYPT_MODE, getKey(keyStr, AES), getIv(ivStr));

   try (FileOutputStream fos = new FileOutputStream(target);

   CipherInputStream cis = new CipherInputStream(new FileInputStream(source), cipher)) {

   byte[] buffer = new byte[BUFFER_SIZE];

   int len;

   while ((len = cis.read(buffer)) != -1) {

   fos.write(buffer, 0, len);


   * 加密文件

   public static void decryptFile(String algorithm, String keyStr, String ivStr, File source, File target) throws Exception {

   checkPath(source, target);

   Cipher cipher = initCipher(algorithm, Cipher.DECRYPT_MODE, getKey(keyStr, AES), getIv(ivStr));

   try (FileInputStream fis = new FileInputStream(source);

   CipherOutputStream cos = new CipherOutputStream(new FileOutputStream(target), cipher)) {

   byte[] buffer = new byte[BUFFER_SIZE];

   int len;

   while ((len = fis.read(buffer)) != -1) {

   cos.write(buffer, 0, len);


   public static void checkPath(File source, File target) throws IOException {



   if (source.isDirectory() !source.exists()) {

   throw new FileNotFoundException(source.toString());

   if (Objects.equals(source.getCanonicalPath(), target.getCanonicalPath())) {

   throw new IllegalArgumentException("sourceFile equals targetFile");

   File parentDirectory = target.getParentFile();

   if (parentDirectory != null !parentDirectory.exists()) {


   public static void main(String[] args) throws Exception {



   String keyStr = "dN2VIV86Z2ShT47pEC1XwQ==";

   String ivStr = "00hDTDhCxa9t11TrQSso3w==";

   String encrypted = encrypt(AES_CBC, keyStr, ivStr, "中国深圳");

   System.out.println("encrypted:" + encrypted);

   System.out.println(decrypt(AES_CBC, keyStr, ivStr, encrypted));

   File source = new File("README.md");

   File encryptedFile = new File("out/README1.md");

   File decryptedFile = new File("out/README2.md");

   encryptFile(AES_CBC, keyStr, ivStr, source, encryptedFile);

   decryptFile(AES_CBC, keyStr, ivStr, encryptedFile, decryptedFile);



