[JavaScript] 纯文本查看 复制代码 const EC = require('elliptic').ec; // 依赖 elliptic 库,需先安装:npm install elliptic
const sm3 = require('sm3'); // SM3 哈希库,需安装:npm install sm3
// SM2 椭圆曲线参数(国家标准)
const sm2Params = {
name: 'sm2',
curve: 'sm2p256v1',
p: 'FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF00000000FFFFFFFFFFFFFFFF',
a: 'FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF00000000FFFFFFFFFFFFFFFC',
b: '28E9FA9E9D9F5E344D5A9E4BCF6509A7F39789F515AB8F92DDBCBD414D940E93',
gx: '32C4AE2C1F1981195F9904466A39C9948FE30BBFF2660BE1715A4589334C74C7',
gy: 'BC3736A2F4F6779C59BDCEE36B692153D0A9877CC62A474002DF32E52139F0A0',
n: 'FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF00000000FFFFFFFFFFFFFFFFBCE6FAADA7179E84F3B9CAC2FC632551',
};
// 生成 SM2 密钥对
function generateKeyPair() {
const ec = new EC(sm2Params.curve, sm2Params);
const keyPair = ec.genKeyPair();
const privateKey = keyPair.getPrivate().toHex();
const publicKey = keyPair.getPublic().encode('hex', true); // 压缩公钥格式
return { privateKey, publicKey };
}
// SM2 加密(C1C3C2 顺序)
function sm2Encrypt(publicKey, plaintext) {
const ec = new EC(sm2Params.curve, sm2Params);
const pubKey = ec.keyFromPublic(publicKey, 'hex', true); // 解析压缩公钥
// 生成随机数 k
const k = ec.genKeyPair().getPrivate();
const C1 = pubKey.curve.pointFromScalar(k).encode('hex', true); // 压缩格式 C1
// 计算椭圆曲线点 S = k * PB(PB 是公钥点)
const PB = pubKey.getPublic();
const S = k.mul(PB);
if (S.isInfinity()) throw new Error('加密失败:S 为无穷远点');
// 计算会话密钥 kdf(S.x, S.y)
const z = sm3(sm2Params.gx + sm2Params.gy + publicKey + privateKey, { output: 'hex' }); // 实际需按标准处理 ZA
const t = kdf(S.x.toHex(), S.y.toHex(), plaintext.length * 8); // 密钥派生函数
if (t.length === 0) throw new Error('密钥派生失败');
// 明文加密(此处示例为异或,实际需用对称算法如 SM4)
const C2 = xorEncrypt(plaintext, t);
// 计算 C3 = SM3(C1 || 明文 || C2)
const dataForC3 = C1 + plaintext + C2;
const C3 = sm3(dataForC3, { output: 'hex' });
// 组合密文:C1 + C3 + C2(16进制字符串)
return C1 + C3 + C2;
}
// 密钥派生函数(简化实现,实际需按 GM/T 0009 标准)
function kdf(x, y, bitLen) {
let k = '';
const Z = x + y;
const tLen = Math.ceil(bitLen / 32);
for (let i = 1; i <= tLen; i++) {
const hash = sm3(Z + i.toString(16).padStart(8, '0'), { output: 'hex' });
k += hash;
}
return k.substr(0, bitLen / 4); // 截取指定长度
}
// 异或加密(示例,实际需用 SM4 等对称算法)
function xorEncrypt(plaintext, key) {
let ciphertext = '';
for (let i = 0; i < plaintext.length; i++) {
ciphertext += String.fromCharCode(plaintext.charCodeAt(i) ^ key.charCodeAt(i % key.length));
}
return ciphertext;
}
// 示例用法
const { publicKey, privateKey } = generateKeyPair();
const plaintext = 'Hello, SM2!';
const ciphertext = sm2Encrypt(publicKey, plaintext);
console.log('密文(C1C3C2):', ciphertext); |