如何将加密的字符串保存到数据库?

时间:2020-03-06 14:51:31  来源:igfitidea点击:

我在VB.net"加密"中具有此功能(请参见下文)

Private key() As Byte = {1, 2, 3, 4, 5, 6, 7, 8, 9, 10, 11, 12, 13, 14, 15, 16, 17, 18, 19, 20, 21, 22, 23, 24}
Private iv() As Byte = {65, 110, 68, 26, 69, 178, 200, 219}

Public Function Encrypt(ByVal plainText As String) As Byte()
    ' Declare a UTF8Encoding object so we may use the GetByte 
    ' method to transform the plainText into a Byte array. 
    Dim utf8encoder As UTF8Encoding = New UTF8Encoding()
    Dim inputInBytes() As Byte = utf8encoder.GetBytes(plainText)

    ' Create a new TripleDES service provider 
    Dim tdesProvider As TripleDESCryptoServiceProvider = New TripleDESCryptoServiceProvider()

    ' The ICryptTransform interface uses the TripleDES 
    ' crypt provider along with encryption key and init vector 
    ' information 
    Dim cryptoTransform As ICryptoTransform = tdesProvider.CreateEncryptor(Me.key, Me.iv)

    ' All cryptographic functions need a stream to output the 
    ' encrypted information. Here we declare a memory stream 
    ' for this purpose. 
    Dim encryptedStream As MemoryStream = New MemoryStream()
    Dim cryptStream As CryptoStream = New CryptoStream(encryptedStream, cryptoTransform, CryptoStreamMode.Write)

    ' Write the encrypted information to the stream. Flush the information 
    ' when done to ensure everything is out of the buffer. 
    cryptStream.Write(inputInBytes, 0, inputInBytes.Length)
    cryptStream.FlushFinalBlock()
    encryptedStream.Position = 0

    ' Read the stream back into a Byte array and return it to the calling method. 
    Dim result(encryptedStream.Length - 1) As Byte
    encryptedStream.Read(result, 0, encryptedStream.Length)
    cryptStream.Close()
    Return result
End Function

我想将加密的字符串保存在SQL数据库中。我该怎么做?

解决方案

将字节数组编码为字符串。 0x00可以为" 00",0xFF可以为" FF"。或者我们可以看一下Base64.

加密字符串应与任何二进制数据都没有不同。

如果我们知道结果将很小,则可以对其进行编码并将其保存在文本字段中。

只需将其存储在二进制列中即可。 (大多数操作是从内存中完成的,欢迎进行更正!)

CREATE TABLE [Test]
(
    [Id] NOT NULL IDENTITY(1,1) PRIMARY KEY,
    [Username] NOT NULL VARCHAR(500),
    [Password] NOT NULL VARBINARY(500)
)

然后插入:

Dim conn As SqlConnection

Try
    conn = New SqlConnection("<connectionstring>")
    Dim command As New SqlCommand("INSERT INTO [Test] ([Username], [Password]) VALUES (@Username, @Password)", conn)

    Dim usernameParameter = New SqlParameter("@Username", SqlDbType.VarChar)
    usernameParameter.Value = username
    command.Parameters.Add(usernameParameter)

    Dim passwordParameter = New SqlParameter("@Password", SqlDbType.VarBinary)
    passwordParameter.Value = password
    command.Parameters.Add(passwordParameter)

    command.ExecuteNonQuery()

Finally
    If (Not (conn Is Nothing)) Then
        conn.Close()
    End If
End Try