QSslKeyingMaterial Class
描述了从 TLS 会话中导出的密钥材料。更多内容...
| 头文件: | #include <QSslKeyingMaterial> |
| CMake: | find_package(Qt6 REQUIRED COMPONENTS Network) target_link_libraries(mytarget PRIVATE Qt6::Network) |
| qmake: | QT += network |
| 自: | Qt 6.12 |
| 状态: | 技术预览 |
该类处于技术预览阶段,内容可能会有变动。
- 所有成员列表(包括继承的成员)
- QSslKeyingMaterial 属于网络编程 API 的一部分。
注意:该类中的所有函数均为可重入的。
QSslKeyingMaterial 比较
| 类别 | 可比较类型 |
|---|---|
| 相等 | QSslKeyingMaterial |
公共函数
| QSslKeyingMaterial() | |
| QSslKeyingMaterial(const QByteArray &label, qsizetype size) | |
| QSslKeyingMaterial(const QByteArray &label, qsizetype size, const QByteArray &context) | |
| QSslKeyingMaterial | clone() const |
| QByteArray | context() const |
| bool | isValid() const |
| QByteArray | label() const |
| qsizetype | requestedSize() const |
| void | swap(QSslKeyingMaterial &other) |
| QByteArray | value() const |
相关的非成员
| size_t | qHash(const QSslKeyingMaterial &key) |
| size_t | qHash(const QSslKeyingMaterial &key, size_t seed) |
| QDebug | operator<<(QDebug debug, const QSslKeyingMaterial &keying) |
详细说明
QSslKeyingMaterial 表示使用 TLS 导出机制从已建立的 TLS 连接中导出密钥材料的请求。
导出机制在 RFC 5705(适用于 TLS 1.2 及更早版本)和 RFC 8446(适用于 TLS 1.3)中进行了定义。它允许应用程序从 TLS 会话中导出加密上独立的密钥材料,而无需暴露会话的流量密钥。
每个 QSslKeyingMaterial 对象指定:
- 一个标识所导出密钥材料用途的导出器标签
- 一个可选的上下文值,用于将密钥材料与应用程序特定数据绑定
- 导出密钥材料的预期大小
实际的密钥材料由 TLS 后端在握手成功后推导出来,可通过 `value()` 读取。
通常在建立 TLS 连接之前,需通过QSslConfiguration::setKeyingMaterial() 配置 QSslKeyingMaterial 对象。
示例:客户端和服务器上的确定性导出
// Both client and server configure the same label and optional context
QSslKeyingMaterial keying("session-label", 32, "app-specific-context");
// After the TLS handshake completes get data from QSslConfiguration.
QByteArray derived = sslConfiguration().takeKeyingMaterial(keying)->value();
// Both client and server will obtain the same 'derived' bytes
// even though they each performed the derivation independently.
use(derived);安全注意事项
导出的密钥材料属于机密信息。QByteArray 是一个写时复制容器,因此每个持有该值的 QSslKeyingMaterial 对象都共享一个缓冲区,只要其中任何一个对象仍存在,该机密信息就会一直保存在内存中。如果应用程序需要确保自己持有唯一的剩余引用,则必须显式释放 Qt 内部的引用。
握手成功后,该值在 Qt 内部仅存在于一个位置:即套接字内部QSslConfiguration 中的 QSslKeyingMaterial 条目。QSslSocket::sslConfiguration() 返回的每个QSslConfiguration 都是该配置的独立副本,并与之共享该值的缓冲区。
QSslConfiguration::takeKeyingMaterial() 的两个重载方法均会将值传递出去而非共享:它们返回的对象持有对该值的唯一引用,而它们在被调用时所修改的配置中留下的条目则是无值的clones 。 使用value() 将值从返回的对象中复制出来,让对象本身超出作用域,然后将配置写回套接字:这会用无值的条目覆盖套接字的条目,从而释放 Qt 持有的最后一个引用。
QSslConfiguration config = socket->sslConfiguration();
// Copy the value out of the temporary that owns it, and let it die:
QByteArray secret = config.takeKeyingMaterial(request)->value();
// Overwrite the socket's copy with the entry left behind, which has no value:
socket->setSslConfiguration(config);以下复制操作不受套接字控制,必须单独处理:
- 应用程序仍持有的任何其他QSslConfiguration 副本,包括存储在QNetworkRequest 中或通过QSslConfiguration::setDefaultConfiguration()安装的副本。从一个副本中提取值不会影响其他副本。
- 从未写回套接字的配置。从QSslConfiguration 中取出值只会清除该配置副本;套接字会保留自己的副本,直到收到无值的条目为止。
- 应用程序自行创建的任何 QSslKeyingMaterial 副本。当需要请求的副本但不包含其值时,请使用clone()。
当套接字开始新的握手过程时,其条目会被重置为无值的副本,此时套接字也会丢弃这些值;此外,当套接字被销毁时同样会丢弃这些值。对于持续运行的套接字,上述两种情况均不能替代前文所述的显式操作步骤。
成员函数文档
QSslKeyingMaterial::QSslKeyingMaterial()
默认构造一个 QSslKeyingMaterial 实例。
默认实例永远无效。
另请参阅 isValid()。
[explicit] QSslKeyingMaterial::QSslKeyingMaterial(const QByteArray &label, qsizetype size)
[explicit] QSslKeyingMaterial::QSslKeyingMaterial(const QByteArray &label, qsizetype size, const QByteArray &context)
使用给定的导出器label 、输出size 以及可选的context ,构建一个QSslKeyingMaterial 对象。
label 用于标识所导出密钥材料的用途,且必须为非空。size 指定要从 TLS 导出器中派生的字节数。
可选的context 是应用程序定义的数据,将其混入密钥派生过程中以实现域分离。
在 TLS 握手成功完成之前,密钥材料本身不会被生成。
注意:在 TLS 1.2(RFC 5705)下 ,空上下文和非空上下文会生成不同的密钥材料:当不存在上下文时,上下文长度字段会被完全省略,从而产生不同的 PRF 输入。 在 TLS 1.3(RFC 8446)中,未指定上下文和空上下文被定义为等效,且会生成相同的密钥材料。请使用QByteArray::isNull() 来区分它们。
另请参见 isValid()、label()、context() 和value()。
QSslKeyingMaterial QSslKeyingMaterial::clone() const
返回此密钥材料请求的副本,但不包含其value()。
返回的对象包含 exporterlabel()、context() 和requestedSize(),因此可用于再次请求相同的密钥材料,但其value() 为空。使用它来初始化一个副本,或重置一个条目,而不会携带该值。
另请参阅 value()。
QByteArray QSslKeyingMaterial::context() const
返回用于推导密钥材料的可选上下文值。
上下文值将导出的密钥生成材料与应用程序特定数据绑定,并有助于防止在不同用途中意外重复使用相同的密钥。
如果未指定上下文,则返回一个 null/空的QByteArray (参见QSslKeyingMaterial::QSslKeyingMaterial())。
[noexcept] bool QSslKeyingMaterial::isValid() const
如果该QSslKeyingMaterial 对象描述了一个有效的导出请求,则返回true。
如果QSslKeyingMaterial 对象具有非空的导出器标签和正的输出大小,则被视为有效。
QByteArray QSslKeyingMaterial::label() const
返回用于推导密钥材料的导出器标签。
该标签用于标识导出密钥材料的用途,并将原样包含在 TLS 导出器推导过程中。
[noexcept] qsizetype QSslKeyingMaterial::requestedSize() const
密钥材料的期望大小。
所需大小是指握手协议被要求生成的字节数,该字节数用于实现所请求密钥素材的label()和context()所描述的目的。
另请参阅 value()。
[noexcept] void QSslKeyingMaterial::swap(QSslKeyingMaterial &other)
将此密钥材料与other 进行交换。此操作速度极快,且从未失败。
QByteArray QSslKeyingMaterial::value() const
返回导出的密钥材料。
返回的QByteArray 包含使用配置的导出器标签和上下文从TLS会话中派生的密钥材料。
如果 TLS 握手未成功完成,或者 TLS 后端不支持密钥导出器,则该函数返回空值。
注意: 返回的密钥材料内容涉及安全敏感信息,必须谨慎处理。有关如何确保返回的 `QByteArray ` 是其唯一副本,请参阅Security Considerations 。
另请参阅 label()、context() 和requestedSize()。
相关的非成员
[noexcept] size_t qHash(const QSslKeyingMaterial &key)
[noexcept] size_t qHash(const QSslKeyingMaterial &key, size_t seed)
返回key 的哈希值,并使用seed 作为计算的种子。
QDebug operator<<(QDebug debug, const QSslKeyingMaterial &keying)
将密钥材料keying 的文本表示写入调试对象debug 。
另请参阅 《调试技术》。
© 2026 The Qt Company Ltd. Documentation contributions included herein are the copyrights of their respective owners. The documentation provided herein is licensed under the terms of the GNU Free Documentation License version 1.3 as published by the Free Software Foundation. Qt and respective logos are trademarks of The Qt Company Ltd. in Finland and/or other countries worldwide. All other trademarks are property of their respective owners.