SM2Signer.cs 7.4 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246
  1. #if !BESTHTTP_DISABLE_ALTERNATE_SSL && (!UNITY_WEBGL || UNITY_EDITOR)
  2. #pragma warning disable
  3. using System;
  4. using BestHTTP.SecureProtocol.Org.BouncyCastle.Crypto.Digests;
  5. using BestHTTP.SecureProtocol.Org.BouncyCastle.Crypto.Parameters;
  6. using BestHTTP.SecureProtocol.Org.BouncyCastle.Math;
  7. using BestHTTP.SecureProtocol.Org.BouncyCastle.Math.EC;
  8. using BestHTTP.SecureProtocol.Org.BouncyCastle.Math.EC.Multiplier;
  9. using BestHTTP.SecureProtocol.Org.BouncyCastle.Security;
  10. using BestHTTP.SecureProtocol.Org.BouncyCastle.Utilities.Encoders;
  11. namespace BestHTTP.SecureProtocol.Org.BouncyCastle.Crypto.Signers
  12. {
  13. /// <summary>The SM2 Digital Signature algorithm.</summary>
  14. public class SM2Signer
  15. : ISigner
  16. {
  17. private readonly IDsaKCalculator kCalculator = new RandomDsaKCalculator();
  18. private readonly SM3Digest digest = new SM3Digest();
  19. private readonly IDsaEncoding encoding;
  20. private ECDomainParameters ecParams;
  21. private ECPoint pubPoint;
  22. private ECKeyParameters ecKey;
  23. private byte[] z;
  24. public SM2Signer()
  25. {
  26. this.encoding = StandardDsaEncoding.Instance;
  27. }
  28. public SM2Signer(IDsaEncoding encoding)
  29. {
  30. this.encoding = encoding;
  31. }
  32. public virtual string AlgorithmName
  33. {
  34. get { return "SM2Sign"; }
  35. }
  36. public virtual void Init(bool forSigning, ICipherParameters parameters)
  37. {
  38. ICipherParameters baseParam;
  39. byte[] userID;
  40. if (parameters is ParametersWithID)
  41. {
  42. baseParam = ((ParametersWithID)parameters).Parameters;
  43. userID = ((ParametersWithID)parameters).GetID();
  44. }
  45. else
  46. {
  47. baseParam = parameters;
  48. userID = Hex.Decode("31323334353637383132333435363738"); // the default value (ASCII "1234567812345678")
  49. }
  50. if (forSigning)
  51. {
  52. if (baseParam is ParametersWithRandom)
  53. {
  54. ParametersWithRandom rParam = (ParametersWithRandom)baseParam;
  55. ecKey = (ECKeyParameters)rParam.Parameters;
  56. ecParams = ecKey.Parameters;
  57. kCalculator.Init(ecParams.N, rParam.Random);
  58. }
  59. else
  60. {
  61. ecKey = (ECKeyParameters)baseParam;
  62. ecParams = ecKey.Parameters;
  63. kCalculator.Init(ecParams.N, new SecureRandom());
  64. }
  65. pubPoint = CreateBasePointMultiplier().Multiply(ecParams.G, ((ECPrivateKeyParameters)ecKey).D).Normalize();
  66. }
  67. else
  68. {
  69. ecKey = (ECKeyParameters)baseParam;
  70. ecParams = ecKey.Parameters;
  71. pubPoint = ((ECPublicKeyParameters)ecKey).Q;
  72. }
  73. digest.Reset();
  74. z = GetZ(userID);
  75. digest.BlockUpdate(z, 0, z.Length);
  76. }
  77. public virtual void Update(byte b)
  78. {
  79. digest.Update(b);
  80. }
  81. public virtual void BlockUpdate(byte[] buf, int off, int len)
  82. {
  83. digest.BlockUpdate(buf, off, len);
  84. }
  85. public virtual bool VerifySignature(byte[] signature)
  86. {
  87. try
  88. {
  89. BigInteger[] rs = encoding.Decode(ecParams.N, signature);
  90. return VerifySignature(rs[0], rs[1]);
  91. }
  92. catch (Exception)
  93. {
  94. }
  95. return false;
  96. }
  97. public virtual void Reset()
  98. {
  99. if (z != null)
  100. {
  101. digest.Reset();
  102. digest.BlockUpdate(z, 0, z.Length);
  103. }
  104. }
  105. public virtual byte[] GenerateSignature()
  106. {
  107. byte[] eHash = DigestUtilities.DoFinal(digest);
  108. BigInteger n = ecParams.N;
  109. BigInteger e = CalculateE(eHash);
  110. BigInteger d = ((ECPrivateKeyParameters)ecKey).D;
  111. BigInteger r, s;
  112. ECMultiplier basePointMultiplier = CreateBasePointMultiplier();
  113. // 5.2.1 Draft RFC: SM2 Public Key Algorithms
  114. do // generate s
  115. {
  116. BigInteger k;
  117. do // generate r
  118. {
  119. // A3
  120. k = kCalculator.NextK();
  121. // A4
  122. ECPoint p = basePointMultiplier.Multiply(ecParams.G, k).Normalize();
  123. // A5
  124. r = e.Add(p.AffineXCoord.ToBigInteger()).Mod(n);
  125. }
  126. while (r.SignValue == 0 || r.Add(k).Equals(n));
  127. // A6
  128. BigInteger dPlus1ModN = d.Add(BigInteger.One).ModInverse(n);
  129. s = k.Subtract(r.Multiply(d)).Mod(n);
  130. s = dPlus1ModN.Multiply(s).Mod(n);
  131. }
  132. while (s.SignValue == 0);
  133. // A7
  134. try
  135. {
  136. return encoding.Encode(ecParams.N, r, s);
  137. }
  138. catch (Exception ex)
  139. {
  140. throw new CryptoException("unable to encode signature: " + ex.Message, ex);
  141. }
  142. }
  143. private bool VerifySignature(BigInteger r, BigInteger s)
  144. {
  145. BigInteger n = ecParams.N;
  146. // 5.3.1 Draft RFC: SM2 Public Key Algorithms
  147. // B1
  148. if (r.CompareTo(BigInteger.One) < 0 || r.CompareTo(n) >= 0)
  149. return false;
  150. // B2
  151. if (s.CompareTo(BigInteger.One) < 0 || s.CompareTo(n) >= 0)
  152. return false;
  153. // B3
  154. byte[] eHash = DigestUtilities.DoFinal(digest);
  155. // B4
  156. BigInteger e = CalculateE(eHash);
  157. // B5
  158. BigInteger t = r.Add(s).Mod(n);
  159. if (t.SignValue == 0)
  160. return false;
  161. // B6
  162. ECPoint q = ((ECPublicKeyParameters)ecKey).Q;
  163. ECPoint x1y1 = ECAlgorithms.SumOfTwoMultiplies(ecParams.G, s, q, t).Normalize();
  164. if (x1y1.IsInfinity)
  165. return false;
  166. // B7
  167. return r.Equals(e.Add(x1y1.AffineXCoord.ToBigInteger()).Mod(n));
  168. }
  169. private byte[] GetZ(byte[] userID)
  170. {
  171. AddUserID(digest, userID);
  172. AddFieldElement(digest, ecParams.Curve.A);
  173. AddFieldElement(digest, ecParams.Curve.B);
  174. AddFieldElement(digest, ecParams.G.AffineXCoord);
  175. AddFieldElement(digest, ecParams.G.AffineYCoord);
  176. AddFieldElement(digest, pubPoint.AffineXCoord);
  177. AddFieldElement(digest, pubPoint.AffineYCoord);
  178. return DigestUtilities.DoFinal(digest);
  179. }
  180. private void AddUserID(IDigest digest, byte[] userID)
  181. {
  182. int len = userID.Length * 8;
  183. digest.Update((byte)(len >> 8));
  184. digest.Update((byte)len);
  185. digest.BlockUpdate(userID, 0, userID.Length);
  186. }
  187. private void AddFieldElement(IDigest digest, ECFieldElement v)
  188. {
  189. byte[] p = v.GetEncoded();
  190. digest.BlockUpdate(p, 0, p.Length);
  191. }
  192. protected virtual BigInteger CalculateE(byte[] message)
  193. {
  194. return new BigInteger(1, message);
  195. }
  196. protected virtual ECMultiplier CreateBasePointMultiplier()
  197. {
  198. return new FixedPointCombMultiplier();
  199. }
  200. }
  201. }
  202. #pragma warning restore
  203. #endif