rsa.py 1.7 KB

12345678910111213141516171819202122232425262728293031323334353637383940414243444546474849505152535455565758
  1. # -*- coding:utf-8 -*-
  2. import hashlib
  3. from Crypto.Cipher import PKCS1_OAEP
  4. from Crypto.PublicKey import RSA
  5. from extensions.ext_redis import redis_client
  6. from extensions.ext_storage import storage
  7. # TODO: PKCS1_OAEP is no longer recommended for new systems and protocols. It is recommended to migrate to PKCS1_PSS.
  8. def generate_key_pair(tenant_id):
  9. private_key = RSA.generate(2048)
  10. public_key = private_key.publickey()
  11. pem_private = private_key.export_key()
  12. pem_public = public_key.export_key()
  13. filepath = "privkeys/{tenant_id}".format(tenant_id=tenant_id) + "/private.pem"
  14. storage.save(filepath, pem_private)
  15. return pem_public.decode()
  16. def encrypt(text, public_key):
  17. if isinstance(public_key, str):
  18. public_key = public_key.encode()
  19. rsa_key = RSA.import_key(public_key)
  20. cipher = PKCS1_OAEP.new(rsa_key)
  21. encrypted_text = cipher.encrypt(text.encode())
  22. return encrypted_text
  23. def decrypt(encrypted_text, tenant_id):
  24. filepath = "privkeys/{tenant_id}".format(tenant_id=tenant_id) + "/private.pem"
  25. cache_key = 'tenant_privkey:{hash}'.format(hash=hashlib.sha3_256(filepath.encode()).hexdigest())
  26. private_key = redis_client.get(cache_key)
  27. if not private_key:
  28. try:
  29. private_key = storage.load(filepath)
  30. except FileNotFoundError:
  31. raise PrivkeyNotFoundError("Private key not found, tenant_id: {tenant_id}".format(tenant_id=tenant_id))
  32. redis_client.setex(cache_key, 120, private_key)
  33. rsa_key = RSA.import_key(private_key)
  34. cipher = PKCS1_OAEP.new(rsa_key)
  35. decrypted_text = cipher.decrypt(encrypted_text)
  36. return decrypted_text.decode()
  37. class PrivkeyNotFoundError(Exception):
  38. pass