Aore.CipherKit
1.1.1
Requires NuGet 4.3.0 or higher.
dotnet add package Aore.CipherKit --version 1.1.1
NuGet\Install-Package Aore.CipherKit -Version 1.1.1
<PackageReference Include="Aore.CipherKit" Version="1.1.1" />
<PackageVersion Include="Aore.CipherKit" Version="1.1.1" />
<PackageReference Include="Aore.CipherKit" />
paket add Aore.CipherKit --version 1.1.1
#r "nuget: Aore.CipherKit, 1.1.1"
#:package Aore.CipherKit@1.1.1
#addin nuget:?package=Aore.CipherKit&version=1.1.1
#tool nuget:?package=Aore.CipherKit&version=1.1.1
Aore.CipherKit
Aore.CipherKit 是一个面向 .NET 的生产级加密解密核心类库:一个 NuGet 包,覆盖常用加密、中国国密(SM2/SM3/SM4)、对称/非对称加密、哈希/KDF/口令哈希(bcrypt/scrypt/Argon2)、中文编码(GBK/GB2312/GB18030/Big5)与混淆脱敏。零外部依赖(全部算法为库内纯 C# 实现),API 高度统一,学会一个算法即会用所有算法。
- 目标框架:
netstandard2.0/net462/net472/net48/net8.0/net9.0/net10.0 - 质量红线:全 TFM 0 错误 0 警告、540 例单元测试 × 4 测试框架全绿、覆盖率门槛固化、标准向量(KAT)+ BouncyCastle/python 官方库互验;v1.1.1 完成全量代码安全审查(77 项发现,33 项已修复含全部 P0/P1,见 docs/05 §1.1 状态清单)
- 许可:MIT
安装
dotnet add package Aore.CipherKit
30 秒上手
using Aore.CipherKit;
// ── 对称加密:所有 16 个算法同一套签名,AORK 自描述容器(随机 IV 自动生成)──
string box = Cipher.Aes.Encrypt("机密数据", "任意长度字符串密钥"); // AES-256-GCM
string back = Cipher.Aes.Decrypt(box, "任意长度字符串密钥"); // "机密数据"
string sm4 = Cipher.Sm4.Encrypt("国密数据", "0123456789abcdef"); // 国密 SM4
// ── 摘要 ──
string sm3 = Hash.Sm3("文本"); // 国密 SM3
string sha = Hash.Sha256("文本"); // SHA-256
// ── 口令哈希(PHC 自描述,验证参数自适应)──
string hash = Cipher.Passwords.Argon2idHash("口令");
bool ok = Cipher.Passwords.Argon2idVerify("口令", hash); // true
// ── 一键口令加密(PBKDF2 六十万次派生 + AES-256-GCM)──
string box2 = Cipher.Protect("敏感信息", "强口令");
string open = Cipher.Unprotect(box2, "强口令"); // "敏感信息"
// ── 非对称(PEM/XML/Base64-DER/hex 自适应)──
var kp = Cipher.Rsa.GenerateKeyPair();
string enc = Cipher.Rsa.Encrypt("机密", kp.PublicKey);
string sig = Cipher.Rsa.Sign("报文", kp.PrivateKey);
bool valid = Cipher.Rsa.Verify("报文", Convert.FromBase64String(sig), kp.PublicKey);
// ── 编码 / 混淆 / 脱敏 ──
string gbk = Encode.ToGbkBase64("中文"); // 中文 → GBK → Base64
string id = Obfuscate.EncodeId(10086L); // Hashids ID 混淆
string morse = Obfuscate.Morse("SOS"); // "... --- ..."
string phone = Mask.Phone("13812345678"); // "138****5678"
API 清单(按门面)
Hash — 摘要与校验
| API | 说明 |
|---|---|
Hash.Sm3(text) |
国密 SM3 → hex |
Hash.Md5(text) / Md5_16(text) |
MD5 / 16 位短摘要(仅兼容用) |
Hash.Sha1/Sha256/Sha384/Sha512(text) |
SHA 系列 → hex |
Hash.Sha3_256(text) / Keccak256(bytes) |
SHA3-256 / Keccak-256 |
Hash.HmacSha256(key, text) / HmacSm3(key, bytes) |
HMAC 快捷方式 |
Hash.Crc32(bytes) |
CRC-32(另有 Crc16/Crc64 引擎类) |
Blake2b / Blake2s / Ripemd160 |
引擎类:ComputeHash(...),1~64 字节可变输出 |
Cipher — 加密解密(对称 12 算法统一梯队)
| 门面 | 算法 | 密钥 |
|---|---|---|
Cipher.Aes |
AES-128/192/256(默认 GCM) | 16/24/32 字节 |
Cipher.Sm4 |
国密 SM4 | 16 字节 |
Cipher.Des / TripleDes / Rc2 / Rc4 |
兼容旧系统 | 可变 |
Cipher.ChaCha20 / XChaCha20 / Salsa20 |
流密码 | 32 字节(Salsa20 支持 16) |
Cipher.Xtea / Blowfish / Xxtea |
轻量分组 | 可变(Blowfish 4~56 字节) |
Cipher.Cast5 / Twofish / Serpent / Aria / Camellia |
长尾分组(REQ-005 补齐) | CAST5 5~16 字节,其余 16/24/32(128 位组默认 GCM) |
Cipher.Zuc |
ZUC 祖冲之流密码(EEA3,16 字节 IV) | 16 字节;另有 MacEia3 32 位完整性标签 |
统一方法梯队(以 Aes 为例,其余算法完全相同):
Cipher.Aes.Encrypt(string plain, string key) // → AORK 容器(Base64)
Cipher.Aes.Decrypt(string cipher, string key)
Cipher.Aes.EncryptBytes(byte[] data, byte[] key) // → AORK 容器(字节)
Cipher.Aes.EncryptBytes(byte[] data, CryptoOptions options) // 指定模式/IV/关联数据
Cipher.Aes.EncryptStream(Stream in, Stream out, byte[] key) // 64KB 分块恒定内存
Cipher.Aes.EncryptFile(string src, string dst, string key)
// Decrypt 同构。支持 ECB/CBC/CFB8/OFB/CTR/GCM + PKCS7 等填充。
新补齐算法用法完全相同(切换算法只需替换类名):
```csharp
string box = Cipher.Camellia.Encrypt("机密文本", "myKey"); // Camellia-GCM 容器(Twofish/Serpent/Aria 同构)
string cast5 = Cipher.Cast5.Encrypt("旧系统文本", "myKey"); // CAST5-CBC 容器(64 位分组)
string zuc = Cipher.Zuc.Encrypt("国密流加密", "myKey"); // ZUC-EEA3 容器(16 字节 IV)
byte[] mac = Cipher.Zuc.MacEia3(data, key16, iv16); // EIA3 完整性标签(4 字节)
Cipher — 非对称与证书
| 门面 | 算法 | 核心方法 |
|---|---|---|
Cipher.Rsa |
RSA 1024~16384 | GenerateKeyPair / Encrypt / Decrypt / Sign / Verify(OAEP/PSS 可选) |
Cipher.Sm2 |
国密 SM2 | GenerateKeyPair / Encrypt / Decrypt / Sign / Verify;Sm2.KeyExchange(SM2DH,GB/T 32918.3,可选确认) |
Cipher.Ecdsa |
ECDSA P-256/384/521 | GenerateKeyPair / Sign / Verify |
Cipher.Ecdh |
ECDH | GenerateKeyPair / DeriveSharedKey |
Cipher.Dsa |
DSA 1024~3072 | GenerateKeyPair / SignBytes / Verify |
Cipher.Ed25519 |
Ed25519 | GenerateKeyPair / Sign / Verify(64 字节签名) |
Cipher.X25519 |
X25519 | GenerateKeyPair / DeriveSharedKey |
Cipher.ElGamal |
ElGamal 1024~4096 | GenerateKeyPair / Encrypt / Decrypt |
Cipher.Certificate |
X.509(SM2/RSA) | Load / LoadFile / Verify(自签与指定签发者链式) |
Cipher.Sm9 |
国密 SM9 标识密码(GM/T 0044) | KGC:GenerateSignatureMasterKey / GenerateEncryptionMasterKey;Sm9Ops.Encrypt/Decrypt/Sign/Verify/Exchange(配对 + IBE) |
SM2 密钥交换与 SM9 标识密码(v1.1 补齐):
// SM2DH:双方各自生成交换材料并派生一致密钥
var alice = Cipher.Sm2.KeyExchange.Generate("ALICE123@YAHOO.COM");
var bob = Cipher.Sm2.KeyExchange.Generate("BILL456@YAHOO.COM");
byte[] keyA = Cipher.Sm2.KeyExchange.Agree(alice, bob.StaticPublicKeyHex,
bob.EphemeralPublicKeyHex, "BILL456@YAHOO.COM", 16, selfIsInitiator: true);
byte[] keyB = Cipher.Sm2.KeyExchange.Agree(bob, alice.StaticPublicKeyHex,
alice.EphemeralPublicKeyHex, "ALICE123@YAHOO.COM", 16, selfIsInitiator: false);
// keyA == keyB
// SM9:KGC 派生用户密钥 → 标识加解密/签名(无需交换证书)
var encMaster = Cipher.Sm9.GenerateEncryptionMasterKey();
var sigMaster = Cipher.Sm9.GenerateSignatureMasterKey();
var decKey = encMaster.GenerateUserKey("Bob");
string box = Cipher.Sm9Ops.Encrypt("Hello, SM9!", encMaster.MasterPublicKeyHex, "Bob");
string plain = Cipher.Sm9Ops.Decrypt(box, decKey);
var signKey = sigMaster.GenerateUserKey("Alice");
string sig = Cipher.Sm9Ops.Sign("Hello, SM9!", signKey);
bool ok = Cipher.Sm9Ops.Verify("Hello, SM9!", sig, sigMaster, "Alice");
Cipher.Passwords — 口令哈希
| API | 默认参数 |
|---|---|
BcryptHash(text, cost=12) / BcryptVerify |
$2b$12$…(OpenBSD 语义,验证兼容 2a/2b/2y/x) |
ScryptHash(text, N=32768, r=8, p=1) / ScryptVerify |
$scrypt$n=… |
Argon2idHash(text, m=64MB, t=3, p=4) / Argon2idVerify |
$argon2id$v=19$m=… |
Scrypt/Argon2id(口令, 盐, 长度, …) |
裸 KDF 用法 |
Cipher.Protect — 一键口令加密
Cipher.Protect(plain, password) / Unprotect(box, password) // 文本
Cipher.ProtectBytes(data, password) / UnprotectBytes(box, password) // 字节
Encode / Encoders — 编码
| API | 说明 |
|---|---|
Base64.Encode/Decode(+EncodeUrlSafe)、Hex.Encode/Decode(+EncodeUpper) |
基础编码 |
Base32(+Crockford)、Base58(+EncodeCheck/双 SHA256)、Base62(+EncodeNumber)、Base85、Base91 |
进制系 |
QuotedPrintable |
RFC 2045 |
Encode.ToGbkBase64/FromGbkBase64(另有 GB2312/GB18030/Big5) |
中文 → 码表字节 → Base64 |
Encode.ToTelecode/FromTelecode |
中文电码:汉字 ↔ 4 位电码(11470 收录字,签证/电报用途;数据源混入的 73 条 "0000" 非法码条目已剔除并报「未收录」) |
ChineseEncoding.EncodeGbk/DecodeGbk/… |
四种中文编解码直通(net48 走系统 NLS,其余内嵌码表,输出一致) |
Obfuscate — 混淆
| API | 说明 |
|---|---|
Xor/XorDecode、XorRolling/XorRollingDecode |
XOR(repeating-key / 滚动密钥链式),Base64 输出 |
Rot13 / RotN(text, n) / Caesar(text, shift=3) / Atbash |
字母变换(自反) |
Vigenere/VigenereDecode(text, key, autokey) |
维吉尼亚(标准 + autokey) |
RailFence/RailFenceDecode(text, rails) |
栅栏 W 形 |
Bacon/BaconDecode |
培根(经典 24 字母表,I/J、U/V 归并) |
Morse/MorseDecode |
摩斯电码(国际标准表) |
EncodeId/DecodeId/EncodeIds/DecodeIds、Hashids 类 |
Hashids ID 混淆(盐/最小长度/自定义字母表/批量) |
Mask — 脱敏
Phone(保前3后4)、IdCard(保前6后4)、Name(保姓)、Email(保域名)、BankCard(保尾4)、Ip(保前2段)、Custom(text, keepStart, keepEnd, maskChar)。
基础设施(Aore.CipherKit.Security / Abstractions)
SecureRandom.GetBytes(n)(CSPRNG)、ConstantTime.Equals/Zeroize(恒时比较/清零)、Keys.Normalize/ParseIv(密钥规整)、CryptoOptions(模式/填充/IV/关联数据)。
特性总览
| 分类 | 能力 |
|---|---|
| 对称加密 | AES(ECB/CBC/CFB8/OFB/CTR/GCM)、DES、3DES、RC2、RC4、SM4、ChaCha20(+Poly1305)、XChaCha20、Salsa20、XTEA/XXTEA、Blowfish、CAST5、Twofish、Serpent、ARIA、Camellia、ZUC(EEA3/EIA3);全部支持流式/文件加密与一键口令加密 Protect |
| 非对称加密 | RSA、ECDSA、ECDH、DSA、SM2(加解密/签名/密钥交换 SM2DH)、Ed25519/X25519、ElGamal、SM9(标识加密/签名/密钥交换/KGC)、X.509 证书解析与验签(SM2/RSA) |
| 哈希 / MAC / KDF | MD5、SHA1/SHA2、SHA3、Keccak-256、SM3、BLAKE2b/s、RIPEMD160、CRC16/32/64、HMAC、AES-CMAC、Poly1305、PBKDF2、HKDF |
| 口令哈希 | bcrypt(OpenBSD 语义)、scrypt(RFC 7914)、Argon2(RFC 9106,d/i/id)——PHC 自描述、参数自适应 |
| 完整性 | EIA3(ZUC 完整性算法,32 位 MAC) |
| 编码 | Hex、Base64/64Url、Base32、Base58/58Check、Base62、Base85、Base91、Quoted-Printable、GBK/GB2312/GB18030/Big5(内嵌码表,零依赖)、中文电码(11470 收录字) |
| 混淆 / 脱敏 | XOR(repeating/滚动)、ROT13/ROT-N、凯撒、Atbash、维吉尼亚、栅栏、培根、摩斯、Hashids 数字 ID 混淆、手机号/身份证/姓名/邮箱/银行卡/IP/自定义脱敏 |
许可
MIT © 2026 WEI.ZHOU (Willis)
| Product | Versions Compatible and additional computed target framework versions. |
|---|---|
| .NET | net5.0 was computed. net5.0-windows was computed. net6.0 was computed. net6.0-android was computed. net6.0-ios was computed. net6.0-maccatalyst was computed. net6.0-macos was computed. net6.0-tvos was computed. net6.0-windows was computed. net7.0 was computed. net7.0-android was computed. net7.0-ios was computed. net7.0-maccatalyst was computed. net7.0-macos was computed. net7.0-tvos was computed. net7.0-windows was computed. net8.0 is compatible. net8.0-android was computed. net8.0-browser was computed. net8.0-ios was computed. net8.0-maccatalyst was computed. net8.0-macos was computed. net8.0-tvos was computed. net8.0-windows was computed. net9.0 is compatible. net9.0-android was computed. net9.0-browser was computed. net9.0-ios was computed. net9.0-maccatalyst was computed. net9.0-macos was computed. net9.0-tvos was computed. net9.0-windows was computed. net10.0 is compatible. net10.0-android was computed. net10.0-browser was computed. net10.0-ios was computed. net10.0-maccatalyst was computed. net10.0-macos was computed. net10.0-tvos was computed. net10.0-windows was computed. |
| .NET Core | netcoreapp2.0 was computed. netcoreapp2.1 was computed. netcoreapp2.2 was computed. netcoreapp3.0 was computed. netcoreapp3.1 was computed. |
| .NET Standard | netstandard2.0 is compatible. netstandard2.1 was computed. |
| .NET Framework | net461 was computed. net462 is compatible. net463 was computed. net47 was computed. net471 was computed. net472 is compatible. net48 is compatible. net481 was computed. |
| MonoAndroid | monoandroid was computed. |
| MonoMac | monomac was computed. |
| MonoTouch | monotouch was computed. |
| Tizen | tizen40 was computed. tizen60 was computed. |
| Xamarin.iOS | xamarinios was computed. |
| Xamarin.Mac | xamarinmac was computed. |
| Xamarin.TVOS | xamarintvos was computed. |
| Xamarin.WatchOS | xamarinwatchos was computed. |
-
.NETFramework 4.6.2
- No dependencies.
-
.NETFramework 4.7.2
- No dependencies.
-
.NETFramework 4.8
- No dependencies.
-
.NETStandard 2.0
- No dependencies.
-
net10.0
- No dependencies.
-
net8.0
- No dependencies.
-
net9.0
- No dependencies.
NuGet packages
This package is not used by any NuGet packages.
GitHub repositories
This package is not used by any popular GitHub repositories.
首个版本:统一通用 API 契约 + 90+ 加解密能力项(常用/国密/对称/非对称/哈希/口令/编码/混淆)。详见 CHANGELOG.md。