The example in this article describes how PHP implements encryption and decryption based on mcrypt. Share it with everyone for your reference. The specific implementation method is as follows:
PHP comes with quite a few encryption methods. Here we take a look at how to use the mcrypt extension. I also need to use this thing to encrypt the value of the user's cookie at work, and I have studied this aspect seriously.
1. Introduction
Mcrypt is an extension of PHP that completes the encapsulation of commonly used encryption algorithms. In fact, this extension is an encapsulation of the mcrypt standard class library. mcrypt has completed quite a few commonly used encryption algorithms, such as DES, TripleDES, Blowfish (default), 3-WAY, SAFER-SK64, SAFER-SK128, TWOFISH, TEA, RC2 and GOST encryption algorithm and provides four block encryption models: CBC, OFB, CFB and ECB.
2. Installation and use
To use this extension, you must first install the mcrypt standard class library, which can be downloaded at http://mcrypt.sourceforge.net. The compilation and installation methods of this extension are the same as those of regular PHP extensions, so they will not be explained in detail.
3. Four block encryption models
Mcrypt supports four block encryption models, a brief description is as follows:
①. MCRYPT_MODE_ECB (electronic codebook) is suitable for encrypting small amounts of random data, such as encrypting user login passwords.
②. MCRYPT_MODE_CBC (cipher block chaining) is suitable for important file types with high encryption security level.
③. MCRYPT_MODE_CFB (cipher feedback) is suitable for situations where every byte of the data stream needs to be encrypted.
④. MCRYPT_MODE_OFB (output feedback, in 8bit) is compatible with CFB mode, but more secure than CFB mode. CFB mode will cause encryption errors to spread. If one byte is wrong, all subsequent bytes will be wrong. OFB mode does not have this problem. However, this mode is not very safe and is not recommended.
⑤. MCRYPT_MODE_NOFB (output feedback, in nbit) is compatible with OFB and has higher security due to the use of block operation algorithm.
⑥. MCRYPT_MODE_STREAM is an additional model provided for stream encryption algorithms such as WAKE or RC4.
NOFB and STREAM are only valid when the version number of mycrypt is greater than or equal to libmcrypt-2.4.x. (Basically all are larger than this version now, and the latest main version of libmcrypt has reached 4)
4. View supported algorithms and models
①. mcrypt_list_modes() lists the models supported by the current environment
②. mcrypt_list_algorithms() lists the algorithms supported by the current environment
Execute from command line:
5. How to use
Example 1:
The simplest method is shown in Example 1. This method indicates that $input is encrypted using the 3DES algorithm, and the encryption key is $key. However, the direct call method is no longer officially recommended. It is also recommended Please do not use this method during development. It may not be possible for this method to become unusable one day. When calling this method under PHP5, you will see a warning message, prompting "PHP Warning: attempt to use an empty IV, which is NOT recommend".
The officially recommended usage is shown in Example 2
Example 2:
The decryption process is basically the same as encryption. Just replace mcrypt_generic($td, $input) with mdecrypt_generic($td, $input). The other parts are exactly the same. Of course, for a symmetric encryption algorithm like 3des, the keys used for encryption and decryption must be exactly the same.
6. About IV
Not all models require IV. CFB and OFB must have IV, while CBC and EBC are optional. For the required IV mode, the values of the encrypted and decrypted IV must be exactly the same. CBC and EBC do not have this requirement. It can be the same or different, it doesn't matter.
7. A simple encryption and decryption class
I hope this article will be helpful to everyone’s PHP programming design.
In fact, you can use DES for decryption. There is an extension in php that can support the DES encryption algorithm. It is: extension=php_mcrypt.dll. Open this extension in the configuration file. It cannot be used in the windows environment. You need to add the PHP file. Copy the libmcrypt.dll in the folder to the system32 directory of the system. You can see through phpinfo that mcrypt means that this module can be tried normally.
Let me give you an example:
function do_mdecrypt($input, $key)
{
$input = str_replace(""n", "", $input);
$input = str_replace(""t", "", $input);
$input = str_replace(""r", "", $input);
$input = trim(chop(base64_decode($ input)));
$td = mcrypt_module_open('tripledes', '', 'ecb', '');
$key = substr(md5($key), 0, 24);
$iv = mcrypt_create_iv(mcrypt_enc_get_iv_size($td), MCRYPT_RAND);
mcrypt_generic_init($td, $key, $iv);
$decrypted_data = mdecrypt_generic($td, $input);
mcrypt_generic_deinit($td);
mcrypt_module_close($td);
return trim(chop($decrypted_data));
}
Then, you can implement the code using this method Decrypted!
1. The encryption algorithm is MCRYPT_RIJNDAEL_128. As for whether it is the AES you mentioned, it is hard to say. I personally think it shouldn't be. After all, the two don't look much alike.
2. There is no flaw in the code, but all encryption may be broken. The exhaustive method is just a time-consuming problem.
3. IV is used to initialize the algorithm. It also needs to be kept confidential.