.NET 中的 RSA 密钥指数有限制吗?

人气:574 发布:2022-10-16 标签: c# cryptography rsa exponent system.security

问题描述

使用 C# 我无法导入指数为 {1, 0, 0, 0, 15} 的公共 RSA 密钥:有一个例外:

Using C# I cannot import a public RSA key with an exponent of {1, 0, 0, 0, 15}: There is an exception:

System.Security.Cryptography.CryptographicException was caught
  HResult=-2146893819
  Message=Bad Data.

  Source=mscorlib
  StackTrace:
       at System.Security.Cryptography.CryptographicException.ThrowCryptographicException(Int32 hr)
       at System.Security.Cryptography.Utils._ImportKey(SafeProvHandle hCSP, Int32 keyNumber, CspProviderFlags flags, Object cspObject, SafeKeyHandle& hKey)
       at System.Security.Cryptography.RSACryptoServiceProvider.ImportParameters(RSAParameters parameters)
       at TestRSA.Form1.buttonTest_Click(Object sender, EventArgs e) in c:UsersThomasDocumentsVisual Studio 2010ProjectsModulesTestRSAForm1.cs:line 32

使用代码:

RSACryptoServiceProvider rsaAlg = new RSACryptoServiceProvider();
RSAParameters key = new RSAParameters();
key.Exponent = new byte[5] { 1, 0, 0, 0, 15 };
key.Modulus = GetModulus(); // byte Array with length 256...
rsaAlg.ImportParameters(key); // <<== this call will throw the exception

.NET 中的 RSA 密钥指数有限制吗?(使用 Exponent == { 1, 0, 1 } 导入将成功.

Is there a limit for RSA key exponents in .NET? (With Exponent == { 1, 0, 1 } the import will succeed.

问候托马斯

推荐答案

微软默认提供者只支持特定大小的公钥指数,CodesInChaos 认为:

The default provider by Microsoft only supports public key exponents of a specific size, as CodesInChaos mused:

CNG 在 RSA 密钥对方面更加灵活.例如,CNG 支持长度大于 32 位的公共指数,并且支持 p 和 q 长度不同的密钥.

CNG is more flexible with regard to RSA key pairs. For example, CNG supports public exponents larger than 32-bits in length, and it supports keys in which p and q are different lengths.

请注意,4 字节指数的限制仅适用于 MS CSP.如果使用第三方 CSP,CryptoAPI 应该能够使用 5 字节指数.

Please, note that the restriction of 4 byte exponents are for MS CSPs only. CryptoAPI should be able to work with 5 byte exponents if using a third-party CSP.

来源:

http://blogs.msdn.com/b/alejacma/archive/2010/07/28/cryptoapi-and-5-bytes-exponent-public-keys.aspx来源:http://msdn.microsoft.com/en-us/library/bb204778%28VS.85%29.aspx

933