← Back to Advanced Java Course | Chapter 11: Advanced & Security | Lesson 11 of 19

Java Cryptography की मूल बातें

Cryptography जानकारी को इस तरह उलझाना है कि सिर्फ सही व्यक्ति उसे पढ़ सके, जैसे एक key वाला secret code। Java में keys बनाने, messages lock और unlock करने के tools हैं।

Cryptography Overview

Java Cryptography Architecture (JCA) sensitive data को encrypt और decrypt करने के लिए classes और provider interfaces का एक standard, pluggable set प्रदान करता है, आपके application code को वैसा ही रहने देते हुए भले ही underlying cryptographic algorithm implementation बदल जाए।

उदाहरण: Cryptography Overview

java
import javax.crypto.Cipher;
public class Main {
	public static void main(String[] args) throws Exception {
		Cipher cipher = Cipher.getInstance("AES/GCM/NoPadding"); // pluggable provider, same code regardless of implementation
		System.out.println(cipher.getAlgorithm());
	}
}

Generating Keys

KeyGenerator class AES जैसे symmetric encryption algorithms के लिए सुरक्षित, cryptographically random keys produce करता है। किसी hand-rolled random source के बजाय एक proper KeyGenerator उपयोग करना मायने रखता है, क्योंकि कमज़ोर या predictable keys किसी मज़बूत encryption algorithm की security को भी कमज़ोर कर देती हैं।

उदाहरण: Generating Keys

java
import javax.crypto.KeyGenerator;
import javax.crypto.SecretKey;
public class Main {
	public static void main(String[] args) throws Exception {
		KeyGenerator keyGen = KeyGenerator.getInstance("AES");
		keyGen.init(128);
		SecretKey key = keyGen.generateKey(); // cryptographically random, not hand-rolled
		System.out.println(key.getAlgorithm() + " key generated");
	}
}

Symmetric Encryption with AES

AES से data encrypt करने के लिए, आप अपनी secret key के साथ एक Cipher object को ENCRYPT_MODE में initialize करते हैं, फिर ciphertext वापस पाने के लिए अपने plaintext byte array पर doFinal() call करते हैं -- process को उल्टा करने के लिए decrypting side पर वही key और mode pairing चाहिए।

उदाहरण: Symmetric Encryption with AES

java
// Import javax.crypto.* so it can be used by its short name
import javax.crypto.*;
// Define the class Main
public class Main {
	// Program entry point: the JVM starts running here
	public static void main(String[] args) throws Exception {
		KeyGenerator keyGen = KeyGenerator.getInstance("AES");
		keyGen.init(128);
		SecretKey key = keyGen.generateKey();
		Cipher cipher = Cipher.getInstance("AES/ECB/PKCS5Padding");
		cipher.init(Cipher.ENCRYPT_MODE, key);
		byte[] ciphertext = cipher.doFinal("secret data".getBytes());
		// Print a line to the console
		System.out.println("Encrypted length: " + ciphertext.length);
	}
}

Symmetric Decryption with AES

AES-encrypted data को decrypt करने के लिए, आप Cipher object को DECRYPT_MODE में बिल्कुल उसी secret key का उपयोग करते हुए initialize करते हैं जो इसे encrypt करने के लिए उपयोग हुई थी, फिर original plaintext bytes वापस पाने के लिए encrypted byte array पर doFinal() call करते हैं।

उदाहरण: Symmetric Decryption with AES

java
import javax.crypto.*;
public class Main {
	public static void main(String[] args) throws Exception {
		KeyGenerator keyGen = KeyGenerator.getInstance("AES");
		keyGen.init(128);
		SecretKey key = keyGen.generateKey();
		Cipher encryptCipher = Cipher.getInstance("AES/ECB/PKCS5Padding");
		encryptCipher.init(Cipher.ENCRYPT_MODE, key);
		byte[] ciphertext = encryptCipher.doFinal("secret data".getBytes());
		Cipher decryptCipher = Cipher.getInstance("AES/ECB/PKCS5Padding");
		decryptCipher.init(Cipher.DECRYPT_MODE, key); // same key, DECRYPT_MODE
		byte[] plaintext = decryptCipher.doFinal(ciphertext);
		System.out.println(new String(plaintext));
	}
}

Cipher Modes and Padding

किसी JCA provider की default settings पर निर्भर रहने के बजाय हमेशा explicit cipher modes और padding schemes (जैसे 'AES/GCM/NoPadding') specify करें, क्योंकि कुछ historically default combinations (जैसे ECB mode) में known weaknesses हैं जो plaintext के बारे में जानकारी leak कर सकते हैं।

उदाहरण: Cipher Modes and Padding

java
import javax.crypto.*;
public class Main {
	public static void main(String[] args) throws Exception {
		Cipher cipher = Cipher.getInstance("AES/GCM/NoPadding"); // explicit mode, not a weak default like ECB
		System.out.println(cipher.getAlgorithm());
	}
}
Related Topics
{# common_mistakes/chapter_summary/browser_support: on Hindi pages the view already swaps in the hi_ translation fields (or blanks these out if untranslated), so this renders correctly for both languages without a lang_code check here. #}
आम गलतियां
  1. Cipher.getInstance("AES") का उपयोग करना, जो default रूप से ECB mode उपयोग करता है और सुरक्षित नहीं है; AES/GCM/NoPadding जैसा एक mode specify करें।
  2. GCM में एक ही key के साथ एक ही IV (nonce) को फिर से उपयोग करना, जो इसकी security तोड़ देता है।
  3. IV को ciphertext के साथ save न करना, जिससे data बाद में decrypt नहीं हो सकता।

Login to run this code

C/C++/Java/PHP execution requires a free account. Your code is saved — you'll land right back in the editor after logging in.