4

我有以下 Clojure 代码:

(ns myproject.hmac-sha256
    (:import (javax.crypto Mac)
             (javax.crypto.spec SecretKeySpec)))

(defn secretKeyInst [key mac]
    (SecretKeySpec. (.getBytes key) (.getAlgorithm mac)))

(defn toString [bytes]
    "Convert bytes to a String"
    (String. bytes "UTF-8"))

(defn sign [key string]
    "Returns the signature of a string with a given 
    key, using a SHA-256 HMAC."
    (let [mac (Mac/getInstance "HMACSHA256")
          secretKey (secretKeyInst key mac)]
          (-> (doto mac
                (.init secretKey)
                (.update (.getBytes "UTF-8")))
              .doFinal
              toString)))

当我sign在 REPL 中使用该函数时,会输出奇怪的字形:

(sign "key" "The quick brown fox jumps over the lazy dog")
"*��`��n�S�F�|�؏�o�r���"

而我期望f7bc83f430538424b13298e6aa6fb143ef4d59a14946175997479dbc2d1a3cd8按照https://en.wikipedia.org/wiki/Hash-based_message_authentication_code#Examples_of_HMAC_.28MD5.2C_SHA1.2C_SHA256.29

这无疑是一个字符串编码问题,但我对编码知之甚少。任何人都可以帮忙吗?

4

1 回答 1

8

要将输出转换为可以与示例进行比较的格式,请不要调用上面定义的 toString,而是将 .doFinal 的结果视为字节数组并以十六进制打印。上面的例子是对字符串“UTF-8”而不是输入字符串进行签名:

 (defn sign [key string]
  "Returns the signature of a string with a given
    key, using a SHA-256 HMAC."
  (let [mac (Mac/getInstance "HMACSHA256")
        secretKey (secretKeyInst key mac)]
    (-> (doto mac
          (.init secretKey)
          (.update (.getBytes string)))
        .doFinal)))

myproject.hmac-sha256>  (apply str (map #(format "%x" %) (sign "key" "The quick brown fox jumps over the lazy dog")))
"f7bc83f430538424b13298e6aa6fb143ef4d59a14946175997479dbc2d1a3cd8"

然后,您可以将 toString 函数编写为:

(defn toHexString [bytes]
  "Convert bytes to a String"
  (apply str (map #(format "%x" %) bytes)))
于 2013-03-16T00:14:18.310 回答