0Pricing
Node.js Backend Development Bootcamp · 课时

数据加密与哈希

学习加密静态和传输中的敏感数据,并使用恰当的哈希技术保护用户密码

数据加密与哈希 是 CoddyKit 上的免费 Node.js Backend Development Bootcamp 课时。 这是第 3 节课,共 4 节。 你可以在下方免费阅读本课时的完整内容 — 然后在浏览器中使用内置代码编辑器和全天候 AI 导师进行实践。 这是 Node.js Backend Development Bootcamp 学习路径的一部分,你的进度在网页和 CoddyKit 应用中同步。 Node.js Backend Development Bootcamp 课程共包含 4 节课。

本课时的部分内容尚未翻译,以英文显示。

Data Security Essentials

Welcome to Data Encryption & Hashing! In today's digital world, protecting sensitive information is paramount. Whether it's user passwords, personal data, or financial details, securing this data is a core responsibility for any developer.

This lesson will equip you with the knowledge and tools to implement robust data protection strategies in your Node.js applications.

数据加密与哈希 — 插图 1

Encryption vs. Hashing

Before diving into techniques, let's understand two fundamental concepts:

  • Encryption: A two-way process that transforms data (plaintext) into an unreadable format (ciphertext) using a key. It's reversible, meaning the ciphertext can be converted back to plaintext with the correct key.
  • Hashing: A one-way process that transforms data of any size into a fixed-size string of characters (a hash value or digest). It's irreversible; you cannot get the original data back from its hash.

They serve different purposes!

Symmetric Encryption

Symmetric encryption uses the same secret key for both encrypting and decrypting data. It's fast and efficient, making it suitable for encrypting large amounts of data.

Common algorithms include AES (Advanced Encryption Standard). The key must be kept secret and securely exchanged between parties.

Node.js Symmetric Encryption

Node.js's built-in crypto module allows us to perform symmetric encryption. Here's an example using AES-256-CBC, a strong symmetric algorithm.

Note: In a real application, the encryption key should be securely generated and stored (e.g., in environment variables) and the IV should be random for each encryption.

const crypto = require('crypto');

// IMPORTANT: In production, generate this key securely and store it safely!
const ENCRYPTION_KEY = 'averysecretkeyforencryption123456'; // Must be 32 bytes for AES-256
const IV_LENGTH = 16; // For AES-256-CBC, IV is 16 bytes

function encrypt(text) {
  const iv = crypto.randomBytes(IV_LENGTH);
  const cipher = crypto.createCipheriv(
    'aes-256-cbc',
    Buffer.from(ENCRYPTION_KEY, 'utf8'),
    iv
  );
  let encrypted = cipher.update(text, 'utf8', 'hex');
  encrypted += cipher.final('hex');
  // Store IV with encrypted data (e.g., as 'iv:encryptedData')
  return iv.toString('hex') + ':' + encrypted;
}

function decrypt(text) {
  const textParts = text.split(':');
  const iv = Buffer.from(textParts.shift(), 'hex');
  const encryptedText = textParts.join(':');
  const decipher = crypto.createDecipheriv(
    'aes-256-cbc',
    Buffer.from(ENCRYPTION_KEY, 'utf8'),
    iv
  );
  let decrypted = decipher.update(encryptedText, 'hex', 'utf8');
  decrypted += decipher.final('utf8');
  return decrypted;
}

const message = 'Sensitive data for storage.';
console.log('Original:', message);

const encryptedMessage = encrypt(message);
console.log('Encrypted:', encryptedMessage);

const decryptedMessage = decrypt(encryptedMessage);
console.log('Decrypted:', decryptedMessage);

Asymmetric Encryption

Asymmetric encryption, also known as public-key cryptography, uses a pair of keys: a public key and a private key.

  • Public key: Can be shared with anyone. Used for encryption.
  • Private key: Must be kept secret. Used for decryption.

If you encrypt data with someone's public key, only they can decrypt it with their private key. This is slower than symmetric encryption but crucial for secure communication and digital signatures.

Hashing for Passwords

When storing user passwords, NEVER encrypt them. Instead, always hash them. If an attacker gains access to your database, they would ideally only find irreversible hashes, not decryptable passwords.

A good hashing algorithm for passwords should be:

  • One-way: Impossible to reverse.
  • Collision-resistant: Extremely unlikely for two different inputs to produce the same hash.
  • Slow: Deliberately designed to be computationally intensive to deter brute-force attacks.

Salting Passwords

To further enhance password security, we use salts. A salt is a unique, random string added to a password before it's hashed.

Why use salts?

  • Prevents Rainbow Table Attacks: Without salts, attackers could pre-compute hashes for common passwords (rainbow tables).
  • Unique Hashes: Even if two users have the same password, their salted hashes will be different.

The salt is usually stored alongside the hash.

Bcrypt for Password Hashing

bcrypt is a widely recommended library for hashing passwords in Node.js because it's designed to be slow and integrates salting automatically.

It handles generating a unique salt and performing multiple rounds of hashing (controlled by saltRounds, a work factor) to make brute-force attacks more difficult.

const bcrypt = require('bcrypt');

async function runBcryptExample() {
  const password = 'mySecretPassword123';
  const saltRounds = 10; // A higher number means more processing time

  console.log('Original Password:', password);

  // Hash the password with a generated salt
  const hashedPassword = await bcrypt.hash(password, saltRounds);
  console.log('Hashed Password:', hashedPassword);

  // Compare a candidate password with the stored hash
  const isMatch = await bcrypt.compare(password, hashedPassword);
  console.log('Password Match (correct):', isMatch);

  const wrongPassword = 'wrongPassword';
  const isWrongMatch = await bcrypt.compare(wrongPassword, hashedPassword);
  console.log('Password Match (wrong):', isWrongMatch);
}

runBcryptExample();

Securing Data in Transit (TLS/SSL)

While encryption and hashing protect data at rest (stored in a database), it's equally important to protect data while it's moving between systems (data in transit).

TLS/SSL (Transport Layer Security/Secure Sockets Layer) protocols provide encryption for network communication. When you visit a website using HTTPS, your browser and the server use TLS/SSL to encrypt all data exchanged, preventing eavesdropping and tampering.

Check Your Understanding

Which of the following statements about encryption and hashing are TRUE?

Recap: Data Protection

Great job! You've learned the fundamentals of data encryption and hashing:

  • Encryption protects sensitive data, making it reversible with a key.
  • Hashing provides one-way transformation, ideal for password storage and data integrity.
  • Symmetric encryption uses a single key, while asymmetric encryption uses public/private key pairs.
  • Always use strong, salted hashing (like bcrypt) for passwords.
  • TLS/SSL secures data in transit over networks.

Implementing these practices is vital for building secure Node.js applications!

常见问题解答

「数据加密与哈希」课时是免费的吗?

是的 — 「数据加密与哈希」的完整文本可在网页上免费阅读。要进行交互式练习(内置代码编辑器和全天候 AI 导师)并解锁 Node.js Backend Development Bootcamp 课程的其余内容,请升级到 CoddyKit PRO。 Node.js Backend Development Bootcamp 课程共包含 4 节课。

「数据加密与哈希」这节课中我会学到什么?

学习加密静态和传输中的敏感数据,并使用恰当的哈希技术保护用户密码 你通过在浏览器中直接运行的动手代码来练习 Node.js Backend Development Bootcamp,全天候 AI 导师会在你学习这节课的过程中回答你的问题。

学习 Node.js Backend Development Bootcamp 需要有经验吗?

无需任何先前经验。CoddyKit 上的 Node.js Backend Development Bootcamp 课程适合初学者到高级学习者,你可以从这里开始或从头开始,按照自己的节奏学习。 这是第 3 节课,共 4 节。

「数据加密与哈希」课时需要多长时间?

大多数 CoddyKit 课程大约需要 5–10 分钟。每节课都很精短且互动,所以你能稳步进步,并在网页和应用中从离开的地方继续。

我能在这节 Node.js Backend Development Bootcamp 课中编写并运行代码吗?

能。每节 Node.js Backend Development Bootcamp 课都包含内置代码编辑器,你可以在浏览器中直接编写并运行真实代码,并获得即时 AI 反馈 — 无需本地设置。

此课程中的所有课时

  1. 理解 OWASP Top 10
  2. Node.js 安全编码实践
  3. 数据加密与哈希
  4. 速率限制与暴力破解防护
← 返回 Node.js Backend Development Bootcamp