Java Cryptography की मूल बातें
In this page:
Cryptography Overview
Java Cryptography Architecture (JCA) sensitive data को encrypt और decrypt करने के लिए classes और provider interfaces का एक standard, pluggable set प्रदान करता है, आपके application code को वैसा ही रहने देते हुए भले ही underlying cryptographic algorithm implementation बदल जाए।
उदाहरण: Cryptography Overview
import javax.crypto.Cipher;
public class Main {
public static void main(String[] args) throws Exception {
Cipher cipher = Cipher.getInstance("AES/GCM/NoPadding"); // pluggable provider, same code regardless of implementation
System.out.println(cipher.getAlgorithm());
}
}
Login to try C/C++/Java/PHP code in the editor
Generating Keys
KeyGenerator class AES जैसे symmetric encryption algorithms के लिए सुरक्षित, cryptographically random keys produce करता है। किसी hand-rolled random source के बजाय एक proper KeyGenerator उपयोग करना मायने रखता है, क्योंकि कमज़ोर या predictable keys किसी मज़बूत encryption algorithm की security को भी कमज़ोर कर देती हैं।
उदाहरण: Generating Keys
import javax.crypto.KeyGenerator;
import javax.crypto.SecretKey;
public class Main {
public static void main(String[] args) throws Exception {
KeyGenerator keyGen = KeyGenerator.getInstance("AES");
keyGen.init(128);
SecretKey key = keyGen.generateKey(); // cryptographically random, not hand-rolled
System.out.println(key.getAlgorithm() + " key generated");
}
}
Login to try C/C++/Java/PHP code in the editor
Symmetric Encryption with AES
AES से data encrypt करने के लिए, आप अपनी secret key के साथ एक Cipher object को ENCRYPT_MODE में initialize करते हैं, फिर ciphertext वापस पाने के लिए अपने plaintext byte array पर doFinal() call करते हैं -- process को उल्टा करने के लिए decrypting side पर वही key और mode pairing चाहिए।
उदाहरण: Symmetric Encryption with AES
// Import javax.crypto.* so it can be used by its short name
import javax.crypto.*;
// Define the class Main
public class Main {
// Program entry point: the JVM starts running here
public static void main(String[] args) throws Exception {
KeyGenerator keyGen = KeyGenerator.getInstance("AES");
keyGen.init(128);
SecretKey key = keyGen.generateKey();
Cipher cipher = Cipher.getInstance("AES/ECB/PKCS5Padding");
cipher.init(Cipher.ENCRYPT_MODE, key);
byte[] ciphertext = cipher.doFinal("secret data".getBytes());
// Print a line to the console
System.out.println("Encrypted length: " + ciphertext.length);
}
}
Login to try C/C++/Java/PHP code in the editor
Symmetric Decryption with AES
AES-encrypted data को decrypt करने के लिए, आप Cipher object को DECRYPT_MODE में बिल्कुल उसी secret key का उपयोग करते हुए initialize करते हैं जो इसे encrypt करने के लिए उपयोग हुई थी, फिर original plaintext bytes वापस पाने के लिए encrypted byte array पर doFinal() call करते हैं।
उदाहरण: Symmetric Decryption with AES
import javax.crypto.*;
public class Main {
public static void main(String[] args) throws Exception {
KeyGenerator keyGen = KeyGenerator.getInstance("AES");
keyGen.init(128);
SecretKey key = keyGen.generateKey();
Cipher encryptCipher = Cipher.getInstance("AES/ECB/PKCS5Padding");
encryptCipher.init(Cipher.ENCRYPT_MODE, key);
byte[] ciphertext = encryptCipher.doFinal("secret data".getBytes());
Cipher decryptCipher = Cipher.getInstance("AES/ECB/PKCS5Padding");
decryptCipher.init(Cipher.DECRYPT_MODE, key); // same key, DECRYPT_MODE
byte[] plaintext = decryptCipher.doFinal(ciphertext);
System.out.println(new String(plaintext));
}
}
Login to try C/C++/Java/PHP code in the editor
Cipher Modes and Padding
किसी JCA provider की default settings पर निर्भर रहने के बजाय हमेशा explicit cipher modes और padding schemes (जैसे 'AES/GCM/NoPadding') specify करें, क्योंकि कुछ historically default combinations (जैसे ECB mode) में known weaknesses हैं जो plaintext के बारे में जानकारी leak कर सकते हैं।
उदाहरण: Cipher Modes and Padding
import javax.crypto.*;
public class Main {
public static void main(String[] args) throws Exception {
Cipher cipher = Cipher.getInstance("AES/GCM/NoPadding"); // explicit mode, not a weak default like ECB
System.out.println(cipher.getAlgorithm());
}
}
Login to try C/C++/Java/PHP code in the editor
Cipher.getInstance("AES")का उपयोग करना, जो default रूप से ECB mode उपयोग करता है और सुरक्षित नहीं है;AES/GCM/NoPaddingजैसा एक mode specify करें।- GCM में एक ही key के साथ एक ही IV (nonce) को फिर से उपयोग करना, जो इसकी security तोड़ देता है।
- IV को ciphertext के साथ save न करना, जिससे data बाद में decrypt नहीं हो सकता।
Chapter Quiz — Complete all 19 topics to unlock
0/19 topics done
Complete these topics first:
- Java Reflection API
- Java Annotations Advanced
- Java Garbage Collection
- Java Memory Management
- Java Performance Optimization
- Java Advanced Interview Questions
- Java CompletableFuture
- Java Atomic Classes
- Java Locks & Semaphores
- Java Concurrent Collections
- Java Cryptography Basics
- Java Hashing (MD5, SHA)
- Java SSL & HTTPS
- Java Logging (Log4j/SLF4J)
- Java Serialization Advanced
- Java Interview Questions Advanced
- Java Connection Pooling
- Java Test Driven Development
- Java Integration Testing