Aore.CipherKit 1.1.1

Requires NuGet 4.3.0 or higher.

dotnet add package Aore.CipherKit --version 1.1.1
                    
NuGet\Install-Package Aore.CipherKit -Version 1.1.1
                    
This command is intended to be used within the Package Manager Console in Visual Studio, as it uses the NuGet module's version of Install-Package.
<PackageReference Include="Aore.CipherKit" Version="1.1.1" />
                    
For projects that support PackageReference, copy this XML node into the project file to reference the package.
<PackageVersion Include="Aore.CipherKit" Version="1.1.1" />
                    
Directory.Packages.props
<PackageReference Include="Aore.CipherKit" />
                    
Project file
For projects that support Central Package Management (CPM), copy this XML node into the solution Directory.Packages.props file to version the package.
paket add Aore.CipherKit --version 1.1.1
                    
#r "nuget: Aore.CipherKit, 1.1.1"
                    
#r directive can be used in F# Interactive and Polyglot Notebooks. Copy this into the interactive tool or source code of the script to reference the package.
#:package Aore.CipherKit@1.1.1
                    
#:package directive can be used in C# file-based apps starting in .NET 10 preview 4. Copy this into a .cs file before any lines of code to reference the package.
#addin nuget:?package=Aore.CipherKit&version=1.1.1
                    
Install as a Cake Addin
#tool nuget:?package=Aore.CipherKit&version=1.1.1
                    
Install as a Cake Tool

Aore.CipherKit

Aore.CipherKit 是一个面向 .NET 的生产级加密解密核心类库:一个 NuGet 包,覆盖常用加密、中国国密(SM2/SM3/SM4)、对称/非对称加密、哈希/KDF/口令哈希(bcrypt/scrypt/Argon2)、中文编码(GBK/GB2312/GB18030/Big5)与混淆脱敏。零外部依赖(全部算法为库内纯 C# 实现),API 高度统一,学会一个算法即会用所有算法。

  • 目标框架:netstandard2.0 / net462 / net472 / net48 / net8.0 / net9.0 / net10.0
  • 质量红线:全 TFM 0 错误 0 警告、540 例单元测试 × 4 测试框架全绿、覆盖率门槛固化、标准向量(KAT)+ BouncyCastle/python 官方库互验;v1.1.1 完成全量代码安全审查(77 项发现,33 项已修复含全部 P0/P1,见 docs/05 §1.1 状态清单)
  • 许可:MIT

安装

dotnet add package Aore.CipherKit

30 秒上手

using Aore.CipherKit;

// ── 对称加密:所有 16 个算法同一套签名,AORK 自描述容器(随机 IV 自动生成)──
string box  = Cipher.Aes.Encrypt("机密数据", "任意长度字符串密钥");   // AES-256-GCM
string back = Cipher.Aes.Decrypt(box, "任意长度字符串密钥");          // "机密数据"
string sm4  = Cipher.Sm4.Encrypt("国密数据", "0123456789abcdef");    // 国密 SM4

// ── 摘要 ──
string sm3 = Hash.Sm3("文本");            // 国密 SM3
string sha = Hash.Sha256("文本");          // SHA-256

// ── 口令哈希(PHC 自描述,验证参数自适应)──
string hash = Cipher.Passwords.Argon2idHash("口令");
bool   ok   = Cipher.Passwords.Argon2idVerify("口令", hash);   // true

// ── 一键口令加密(PBKDF2 六十万次派生 + AES-256-GCM)──
string box2 = Cipher.Protect("敏感信息", "强口令");
string open = Cipher.Unprotect(box2, "强口令");                 // "敏感信息"

// ── 非对称(PEM/XML/Base64-DER/hex 自适应)──
var kp = Cipher.Rsa.GenerateKeyPair();
string enc   = Cipher.Rsa.Encrypt("机密", kp.PublicKey);
string sig   = Cipher.Rsa.Sign("报文", kp.PrivateKey);
bool   valid = Cipher.Rsa.Verify("报文", Convert.FromBase64String(sig), kp.PublicKey);

// ── 编码 / 混淆 / 脱敏 ──
string gbk   = Encode.ToGbkBase64("中文");            // 中文 → GBK → Base64
string id    = Obfuscate.EncodeId(10086L);           // Hashids ID 混淆
string morse = Obfuscate.Morse("SOS");               // "... --- ..."
string phone = Mask.Phone("13812345678");            // "138****5678"

API 清单(按门面)

Hash — 摘要与校验

API 说明
Hash.Sm3(text) 国密 SM3 → hex
Hash.Md5(text) / Md5_16(text) MD5 / 16 位短摘要(仅兼容用)
Hash.Sha1/Sha256/Sha384/Sha512(text) SHA 系列 → hex
Hash.Sha3_256(text) / Keccak256(bytes) SHA3-256 / Keccak-256
Hash.HmacSha256(key, text) / HmacSm3(key, bytes) HMAC 快捷方式
Hash.Crc32(bytes) CRC-32(另有 Crc16/Crc64 引擎类)
Blake2b / Blake2s / Ripemd160 引擎类:ComputeHash(...),1~64 字节可变输出

Cipher — 加密解密(对称 12 算法统一梯队)

门面 算法 密钥
Cipher.Aes AES-128/192/256(默认 GCM) 16/24/32 字节
Cipher.Sm4 国密 SM4 16 字节
Cipher.Des / TripleDes / Rc2 / Rc4 兼容旧系统 可变
Cipher.ChaCha20 / XChaCha20 / Salsa20 流密码 32 字节(Salsa20 支持 16)
Cipher.Xtea / Blowfish / Xxtea 轻量分组 可变(Blowfish 4~56 字节)
Cipher.Cast5 / Twofish / Serpent / Aria / Camellia 长尾分组(REQ-005 补齐) CAST5 5~16 字节,其余 16/24/32(128 位组默认 GCM)
Cipher.Zuc ZUC 祖冲之流密码(EEA3,16 字节 IV) 16 字节;另有 MacEia3 32 位完整性标签

统一方法梯队(以 Aes 为例,其余算法完全相同):

Cipher.Aes.Encrypt(string plain, string key)                     // → AORK 容器(Base64)
Cipher.Aes.Decrypt(string cipher, string key)
Cipher.Aes.EncryptBytes(byte[] data, byte[] key)                 // → AORK 容器(字节)
Cipher.Aes.EncryptBytes(byte[] data, CryptoOptions options)      // 指定模式/IV/关联数据
Cipher.Aes.EncryptStream(Stream in, Stream out, byte[] key)      // 64KB 分块恒定内存
Cipher.Aes.EncryptFile(string src, string dst, string key)
// Decrypt 同构。支持 ECB/CBC/CFB8/OFB/CTR/GCM + PKCS7 等填充。

新补齐算法用法完全相同(切换算法只需替换类名):

```csharp
string box = Cipher.Camellia.Encrypt("机密文本", "myKey");   // Camellia-GCM 容器(Twofish/Serpent/Aria 同构)
string cast5 = Cipher.Cast5.Encrypt("旧系统文本", "myKey");  // CAST5-CBC 容器(64 位分组)
string zuc = Cipher.Zuc.Encrypt("国密流加密", "myKey");       // ZUC-EEA3 容器(16 字节 IV)
byte[] mac = Cipher.Zuc.MacEia3(data, key16, iv16);          // EIA3 完整性标签(4 字节)

Cipher — 非对称与证书

门面 算法 核心方法
Cipher.Rsa RSA 1024~16384 GenerateKeyPair / Encrypt / Decrypt / Sign / Verify(OAEP/PSS 可选)
Cipher.Sm2 国密 SM2 GenerateKeyPair / Encrypt / Decrypt / Sign / Verify;Sm2.KeyExchange(SM2DH,GB/T 32918.3,可选确认)
Cipher.Ecdsa ECDSA P-256/384/521 GenerateKeyPair / Sign / Verify
Cipher.Ecdh ECDH GenerateKeyPair / DeriveSharedKey
Cipher.Dsa DSA 1024~3072 GenerateKeyPair / SignBytes / Verify
Cipher.Ed25519 Ed25519 GenerateKeyPair / Sign / Verify(64 字节签名)
Cipher.X25519 X25519 GenerateKeyPair / DeriveSharedKey
Cipher.ElGamal ElGamal 1024~4096 GenerateKeyPair / Encrypt / Decrypt
Cipher.Certificate X.509(SM2/RSA) Load / LoadFile / Verify(自签与指定签发者链式)
Cipher.Sm9 国密 SM9 标识密码(GM/T 0044) KGC:GenerateSignatureMasterKey / GenerateEncryptionMasterKey;Sm9Ops.Encrypt/Decrypt/Sign/Verify/Exchange(配对 + IBE)

SM2 密钥交换与 SM9 标识密码(v1.1 补齐):

// SM2DH:双方各自生成交换材料并派生一致密钥
var alice = Cipher.Sm2.KeyExchange.Generate("ALICE123@YAHOO.COM");
var bob = Cipher.Sm2.KeyExchange.Generate("BILL456@YAHOO.COM");
byte[] keyA = Cipher.Sm2.KeyExchange.Agree(alice, bob.StaticPublicKeyHex,
    bob.EphemeralPublicKeyHex, "BILL456@YAHOO.COM", 16, selfIsInitiator: true);
byte[] keyB = Cipher.Sm2.KeyExchange.Agree(bob, alice.StaticPublicKeyHex,
    alice.EphemeralPublicKeyHex, "ALICE123@YAHOO.COM", 16, selfIsInitiator: false);
// keyA == keyB

// SM9:KGC 派生用户密钥 → 标识加解密/签名(无需交换证书)
var encMaster = Cipher.Sm9.GenerateEncryptionMasterKey();
var sigMaster = Cipher.Sm9.GenerateSignatureMasterKey();
var decKey = encMaster.GenerateUserKey("Bob");
string box = Cipher.Sm9Ops.Encrypt("Hello, SM9!", encMaster.MasterPublicKeyHex, "Bob");
string plain = Cipher.Sm9Ops.Decrypt(box, decKey);
var signKey = sigMaster.GenerateUserKey("Alice");
string sig = Cipher.Sm9Ops.Sign("Hello, SM9!", signKey);
bool ok = Cipher.Sm9Ops.Verify("Hello, SM9!", sig, sigMaster, "Alice");

Cipher.Passwords — 口令哈希

API 默认参数
BcryptHash(text, cost=12) / BcryptVerify $2b$12$…(OpenBSD 语义,验证兼容 2a/2b/2y/x)
ScryptHash(text, N=32768, r=8, p=1) / ScryptVerify $scrypt$n=…
Argon2idHash(text, m=64MB, t=3, p=4) / Argon2idVerify $argon2id$v=19$m=…
Scrypt/Argon2id(口令, 盐, 长度, …) 裸 KDF 用法

Cipher.Protect — 一键口令加密

Cipher.Protect(plain, password) / Unprotect(box, password)      // 文本
Cipher.ProtectBytes(data, password) / UnprotectBytes(box, password)  // 字节

Encode / Encoders — 编码

API 说明
Base64.Encode/Decode(+EncodeUrlSafe)、Hex.Encode/Decode(+EncodeUpper) 基础编码
Base32(+Crockford)、Base58(+EncodeCheck/双 SHA256)、Base62(+EncodeNumber)、Base85、Base91 进制系
QuotedPrintable RFC 2045
Encode.ToGbkBase64/FromGbkBase64(另有 GB2312/GB18030/Big5) 中文 → 码表字节 → Base64
Encode.ToTelecode/FromTelecode 中文电码:汉字 ↔ 4 位电码(11470 收录字,签证/电报用途;数据源混入的 73 条 "0000" 非法码条目已剔除并报「未收录」)
ChineseEncoding.EncodeGbk/DecodeGbk/… 四种中文编解码直通(net48 走系统 NLS,其余内嵌码表,输出一致)

Obfuscate — 混淆

API 说明
Xor/XorDecode、XorRolling/XorRollingDecode XOR(repeating-key / 滚动密钥链式),Base64 输出
Rot13 / RotN(text, n) / Caesar(text, shift=3) / Atbash 字母变换(自反)
Vigenere/VigenereDecode(text, key, autokey) 维吉尼亚(标准 + autokey)
RailFence/RailFenceDecode(text, rails) 栅栏 W 形
Bacon/BaconDecode 培根(经典 24 字母表,I/J、U/V 归并)
Morse/MorseDecode 摩斯电码(国际标准表)
EncodeId/DecodeId/EncodeIds/DecodeIds、Hashids 类 Hashids ID 混淆(盐/最小长度/自定义字母表/批量)

Mask — 脱敏

Phone(保前3后4)、IdCard(保前6后4)、Name(保姓)、Email(保域名)、BankCard(保尾4)、Ip(保前2段)、Custom(text, keepStart, keepEnd, maskChar)。

基础设施(Aore.CipherKit.Security / Abstractions)

SecureRandom.GetBytes(n)(CSPRNG)、ConstantTime.Equals/Zeroize(恒时比较/清零)、Keys.Normalize/ParseIv(密钥规整)、CryptoOptions(模式/填充/IV/关联数据)。

特性总览

分类 能力
对称加密 AES(ECB/CBC/CFB8/OFB/CTR/GCM)、DES、3DES、RC2、RC4、SM4、ChaCha20(+Poly1305)、XChaCha20、Salsa20、XTEA/XXTEA、Blowfish、CAST5、Twofish、Serpent、ARIA、Camellia、ZUC(EEA3/EIA3);全部支持流式/文件加密与一键口令加密 Protect
非对称加密 RSA、ECDSA、ECDH、DSA、SM2(加解密/签名/密钥交换 SM2DH)、Ed25519/X25519、ElGamal、SM9(标识加密/签名/密钥交换/KGC)、X.509 证书解析与验签(SM2/RSA)
哈希 / MAC / KDF MD5、SHA1/SHA2、SHA3、Keccak-256、SM3、BLAKE2b/s、RIPEMD160、CRC16/32/64、HMAC、AES-CMAC、Poly1305、PBKDF2、HKDF
口令哈希 bcrypt(OpenBSD 语义)、scrypt(RFC 7914)、Argon2(RFC 9106,d/i/id)——PHC 自描述、参数自适应
完整性 EIA3(ZUC 完整性算法,32 位 MAC)
编码 Hex、Base64/64Url、Base32、Base58/58Check、Base62、Base85、Base91、Quoted-Printable、GBK/GB2312/GB18030/Big5(内嵌码表,零依赖)、中文电码(11470 收录字)
混淆 / 脱敏 XOR(repeating/滚动)、ROT13/ROT-N、凯撒、Atbash、维吉尼亚、栅栏、培根、摩斯、Hashids 数字 ID 混淆、手机号/身份证/姓名/邮箱/银行卡/IP/自定义脱敏

许可

MIT © 2026 WEI.ZHOU (Willis)

Product Compatible and additional computed target framework versions.
.NET net5.0 was computed.  net5.0-windows was computed.  net6.0 was computed.  net6.0-android was computed.  net6.0-ios was computed.  net6.0-maccatalyst was computed.  net6.0-macos was computed.  net6.0-tvos was computed.  net6.0-windows was computed.  net7.0 was computed.  net7.0-android was computed.  net7.0-ios was computed.  net7.0-maccatalyst was computed.  net7.0-macos was computed.  net7.0-tvos was computed.  net7.0-windows was computed.  net8.0 is compatible.  net8.0-android was computed.  net8.0-browser was computed.  net8.0-ios was computed.  net8.0-maccatalyst was computed.  net8.0-macos was computed.  net8.0-tvos was computed.  net8.0-windows was computed.  net9.0 is compatible.  net9.0-android was computed.  net9.0-browser was computed.  net9.0-ios was computed.  net9.0-maccatalyst was computed.  net9.0-macos was computed.  net9.0-tvos was computed.  net9.0-windows was computed.  net10.0 is compatible.  net10.0-android was computed.  net10.0-browser was computed.  net10.0-ios was computed.  net10.0-maccatalyst was computed.  net10.0-macos was computed.  net10.0-tvos was computed.  net10.0-windows was computed. 
.NET Core netcoreapp2.0 was computed.  netcoreapp2.1 was computed.  netcoreapp2.2 was computed.  netcoreapp3.0 was computed.  netcoreapp3.1 was computed. 
.NET Standard netstandard2.0 is compatible.  netstandard2.1 was computed. 
.NET Framework net461 was computed.  net462 is compatible.  net463 was computed.  net47 was computed.  net471 was computed.  net472 is compatible.  net48 is compatible.  net481 was computed. 
MonoAndroid monoandroid was computed. 
MonoMac monomac was computed. 
MonoTouch monotouch was computed. 
Tizen tizen40 was computed.  tizen60 was computed. 
Xamarin.iOS xamarinios was computed. 
Xamarin.Mac xamarinmac was computed. 
Xamarin.TVOS xamarintvos was computed. 
Xamarin.WatchOS xamarinwatchos was computed. 
Compatible target framework(s)
Included target framework(s) (in package)
Learn more about Target Frameworks and .NET Standard.
  • .NETFramework 4.6.2

    • No dependencies.
  • .NETFramework 4.7.2

    • No dependencies.
  • .NETFramework 4.8

    • No dependencies.
  • .NETStandard 2.0

    • No dependencies.
  • net10.0

    • No dependencies.
  • net8.0

    • No dependencies.
  • net9.0

    • No dependencies.

NuGet packages

This package is not used by any NuGet packages.

GitHub repositories

This package is not used by any popular GitHub repositories.

Version Downloads Last Updated
1.1.1 79 9/27/2026
1.1.0 85 9/27/2026
1.0.0 81 9/27/2026

首个版本:统一通用 API 契约 + 90+ 加解密能力项(常用/国密/对称/非对称/哈希/口令/编码/混淆)。详见 CHANGELOG.md。