GmController.php 16 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377378379380381382383384385386387388389390391392393394395396397398399400401402403404405406407408409410411412413414415416417418419420421422
  1. <?php
  2. /**
  3. * @Author: Marte
  4. * @Date: 2017-07-31 15:26:02
  5. * @Last Modified by: Marte
  6. * 1、getPostData 获取对方发过来的请求使用此方法对获取到的数据进行解密解签后得到数据
  7. * 2、runJson 返回数据给对方使用此方法对数据进行拼接加签加密后返回
  8. * 3、getToken 获取token方法,可以自行储存在文件内重复使用,过期后再次获取
  9. * 4、postJry 业务请求数据拼接,发送请求接口
  10. * 5、cityQuery 业务请求封装
  11. * 6、decryptByPublicKey rsa解密方法
  12. * 7、encryptByPrivateKey rsa加密方法
  13. * 8、decrypt aes解密方法
  14. * 9、encrypt aes加密方法
  15. */
  16. namespace app\api\controller;
  17. use app\api\controller\AuthController as Controller;
  18. class GmController extends Controller
  19. {
  20. //以下参数都需要金融云提供
  21. //AES偏移量
  22. protected $iv = 'abcdefghABCDEFGH';
  23. protected $appID = "96c8268e-cfa4-497f-9329-a5e3417f0825";
  24. protected $appSecretKey = "921b3c06-eaed-7b1c-e053-010000717745";
  25. protected $tokenUrl = "https://mouldai.com/apiSIT/tzyj/approveDev";//回归环境
  26. protected $token;
  27. //合作机构自有公钥
  28. const PUBLIC_KEY = "DE3w4DgjV+np0oHQzSDUgvlxGKPhi/gHBRp8dtjun+z6uqrRJE6B1qswZpaSCs3tp0tm98ZjjL9RTuNh4dyUuA==";
  29. //合作机构自有私钥
  30. const PRIVATE_KEY = "778NKKZgdS9IGm/crvajNPoq5CHJNEKXptciF/1SU3I=";
  31. //泰隆银行公钥
  32. const CGB_PUBLIC_KEY = "kZYtvaa+HIImu0xhONxte8wyXmMBe7HKKf1i1fqU7Wf8PrsmvAguPNClPXfOoxqW8gmy5qrFK9oX3tvmrq4r0A==";
  33. public function _initialize()
  34. {
  35. // 初始化加密扩展
  36. echo "--------php_crypto_init 初始化开始--------\n";
  37. $path = "/www/server/php/73/libcryptAPIsm_lnx64.so";
  38. php_crypto_init($path);
  39. echo "--------php_crypto_init 初始化结束-------\n";
  40. }
  41. public function string2hex($string)
  42. {
  43. $hex = '';
  44. for ($i = 0; $i < strlen($string); $i++) {
  45. $ch = dechex(ord($string[$i]));
  46. if (strlen($ch) == 1) {
  47. $ch = "0" . $ch;
  48. }
  49. $hex .= $ch;
  50. }
  51. return $hex;
  52. }
  53. //获取token
  54. public function getToken()
  55. {
  56. //获取6位数字符串
  57. $seqNO = (string)rand(100000, 999999);
  58. //获取16位随机字符串并md5 转大写 得到
  59. $key = strtoupper(md5($this->getKey()));
  60. //echo $this->string2hex(base64_decode(self::PRIVATE_KEY));
  61. echo $this->string2hex(base64_decode(self::PUBLIC_KEY));
  62. //初始化转换密钥信息
  63. php_HextoAsc($this->string2hex(base64_decode(self::PRIVATE_KEY)), $k1);
  64. php_HextoAsc($this->string2hex(base64_decode(self::PUBLIC_KEY)), $k2);
  65. php_HextoAsc($this->string2hex(base64_decode(self::CGB_PUBLIC_KEY)), $gf_k);
  66. //拼接参数数组
  67. $data = [
  68. 'appID' => $this->appID,
  69. 'seqNO' => $seqNO,
  70. 'random' => strtoupper(md5($seqNO)),
  71. 'sm2EncryptData' => $this->SM2Encrypt($key, $gf_k), //sm2加密key
  72. 'sm2Sign' => $this->SM2Sign($key, $k2, $k1), //sm2加密key
  73. ];
  74. //拼接签名参数,md5转大写
  75. $data['sign'] = $this->SM3Crypt($data['random'] . $data['seqNO'] . $this->appSecretKey . $key);
  76. //发送post接口请求
  77. $res = $this->https_post($this->tokenUrl, $data);
  78. //解密返回token数据
  79. $token = $this->SM2Decrypt(base64_decode($res['sm2EncryptData']), $k1);
  80. $this->token = $token;
  81. //返回token
  82. return $token;
  83. }
  84. //业务请求数据
  85. public function postJry()
  86. {
  87. //创建模拟请求数据,必须包含head,body
  88. $data = [
  89. 'head' => [
  90. 'id' => 8989
  91. ],
  92. 'body' => [
  93. 'code' => "000000",
  94. 'msg' => "测试请求"
  95. ]
  96. ];
  97. $res = $this->scanPaymentCode($data);
  98. dump("返回结果");
  99. halt($res);
  100. }
  101. //业务请求封装
  102. public function scanPaymentCode($array = [])
  103. {
  104. //初始化转换密钥信息
  105. php_HextoAsc($this->string2hex(base64_decode(self::PRIVATE_KEY)), $k1);
  106. php_HextoAsc($this->string2hex(base64_decode(self::PUBLIC_KEY)), $k2);
  107. php_HextoAsc($this->string2hex(base64_decode(self::CGB_PUBLIC_KEY)), $gf_k);
  108. // $this->string2hex(base64_decode(self::PRIVATE_KEY));
  109. // $this->string2hex(base64_decode(self::PUBLIC_KEY));
  110. // $this->string2hex(base64_decode(self::CGB_PUBLIC_KEY));
  111. //数据转json
  112. $json = json_encode($array, JSON_UNESCAPED_UNICODE);
  113. //获取随机6位字符串数字
  114. $seqNO = (string)rand(100000, 999999);
  115. //获取随机字符串秘钥,md5 并转大写
  116. $key = strtoupper(md5($this->getKey()));
  117. //拼接请求数据
  118. $data = [
  119. 'appID' => $this->appID,
  120. 'seqNO' => $seqNO,
  121. 'signMethod' => "SM3",
  122. 'encryptMethod' => "SM4",
  123. 'appAccessToken' => $this->getToken(),//获取token
  124. 'sm2EncryptData' => $this->SM2Encrypt($key, $gf_k), //sm2加密key
  125. 'sm2Sign' => $this->SM2Sign($key, $k2, $k1), //sm2加密key
  126. ];
  127. //拼接签名参数,md5转大写
  128. $data['sign'] = $this->SM3Crypt($json . $data['seqNO'] . $this->appSecretKey . $key);
  129. //AES加密业务数据
  130. $data['reqData'] = $this->SM4Encrypt($json, $data['seqNO'] . $data['appAccessToken'] . $this->appSecretKey . $key);
  131. dump("业务数据json");
  132. dump($json);
  133. dump("请求数据");
  134. dump($data);
  135. $res = $this->https_post("https://mouldai.com/apiSIT/tzyj/scanPaymentCode", $data);
  136. //解密sm2密钥
  137. $sm2Key = $this->SM2Decrypt(base64_decode($res['sm2EncryptData']), $k1);
  138. dump("sm2解密数据:" . $sm2Key);
  139. //SM4解密数据
  140. $rspData = $this->SM4Decrypt($res['rspData'], $res['seqNO'] . $data['appAccessToken'] . $this->appSecretKey . $sm2Key);
  141. dump("sm4解密报文数据:" . $rspData);
  142. //sm3验签数据校验
  143. $sm3SignData = $this->SM3Crypt($rspData . $res['seqNO'] . $this->appSecretKey . $sm2Key);
  144. dump("sm3响应报文拼接加签:" . $sm3SignData);
  145. $signData = $res['sign'];
  146. dump("sm3响应报文签名:" . $signData);
  147. if ($sm3SignData == $signData) {
  148. dump("验签成功!");
  149. }
  150. dump($res);
  151. return $res;
  152. }
  153. //获取post数据并解密解签获得业务数据
  154. public function getPostData()
  155. {
  156. //获取post数据
  157. $arr = input("post.");
  158. //模拟post获取数据
  159. $arr = '{"sign":"1CA0926A5C8BC2E2347E57016650E731","signMethod":"MD5","rsaEncryptData":"xs8lNVCj4ZCsAbXoJHI+AmRPqDJk01dlt3q7Jb9Vox4SNvvx6F+DclM2v1FdnDxAsNgXBERLXCc3SOFnqtrcMdYxc2GKyF+YTLJKjX0NmlGkXlO2oipIzhIL94la\/NGEzlT+JL4I8KF5vZvE+4gudkg0mZ+jC6jPWc+qyM6RROdwbgYPCiOpVTaQ+jtIxwz4rCY\/a2z\/fAFazzApUbyRxsCTVRESJ+3dU8V9zYxE7VzrV+IlOCwJdAIAfGPcwjq5wd3p\/3yEeFDBbZz0N6jnIEIlkCH99NsNFWIYY2mH0K2z+ccpJlBejoNq+FaxusS2DvZfJhp8xa3dav8itVyiSw==","encryptMethod":"AES","reqData":"QbYx9PwqKwy30K1SSgiorq9Sg9taSxImEw6qwY93N0QhsRb1UHqBghS+WmbBRZxrBTCMYNGBsG1GFvUdJxIrdXaQ4qBU\/PTpIjLlD+bvRyE27OYgHrSpQ6umylxWXSTYUIO0qbdTjNTR8UwRKPlHjuUJ149E5eH+s\/oyE6zZi9KNzx8BwjeZ\/Qeo\/CQF7fMuu3uJF7XOOIDqLidXvevQEr8hHLUyT40a\/NZsOAoqQSoNppazy+tDuttATH7gFWjFKNzRtt89wDdbjWNtK95tc\/uUBojfjg5HKcctSmqQ7jW6HvA2J5k3WnC6mxsTdaU9WPjtKbnqGUTkoM9YbJs1VghcnnQLSH49wAY7kB5SwWwTaPkHZy5kvytfMvLjwgjUioW0qYSpZyaBww4dSXJ0bQ1Mb+TArunrCpIzl2T4ZkzWT3\/j0m4bJoq7le4l03NVAn8iA3ju2asrBbrySTWzQ9vXDQbq1q+S5uh9YTXrVq0dM6CMNV8KquOCEC0UyaTKxCK2+cAS9LDQD4APXRTuNhkR57LKox2CfvN+CTDlWw8QfFfYKdNpmt\/OHklrUez0LcfMluc08ce1fvoDCuOqMN51y5qhV+d3utWa5rBjvzhE8de5qi54l3qW4EV03sQRdvN7R433fxOVt33N1mZ3NOwx1xjnJ4ivdVuhZ1XbGHd\/B7NGGafQbx3RChEIT250Kl3vih\/P2yF1ozQC8MY6sAHgOxAufmos8DoOwwWy9L59lNqN2sAnVpPalvjM4UCa8pkSrToDaoU4Sc44JOBghQ==","appAccessToken":"","seqNO":"127600","appID":"a539d3d7-3d4b-454b-9c49-7fb83fb8b611"}';//正式获取数据删除这里
  160. $arr = json_decode($arr, true); //正式获取数据删除这里
  161. //检验字段是否缺失
  162. if (!isset($arr['rsaEncryptData']) || !isset($arr['seqNO']) || !isset($arr['signMethod']) || !isset($arr['sign']) || !isset($arr['encryptMethod']) || !isset($arr['reqData']) || !isset($arr['appID'])) {
  163. return $this->runJson("1000001", "缺少参数");
  164. }
  165. dump("获取到的post数据");
  166. dump($arr);
  167. //rsa解密秘钥字段rsaEncryptData
  168. $rasKey = $this->decryptByPublicKey($arr['rsaEncryptData']);
  169. dump("解密后的秘钥");
  170. dump($rasKey);
  171. //拼接秘钥
  172. $key = $arr['seqNO'] . $this->token . $this->appSecretKey . $rasKey;
  173. //秘钥转md5 转大写
  174. $key = strtoupper(md5($key));
  175. //aes解密
  176. $res = $this->decrypt($arr['reqData'], $key);
  177. $res = json_decode($res, true);
  178. dump("数据结果");
  179. halt($res);
  180. }
  181. //SM2Encrypt
  182. function SM2Encrypt($data, $pubkey)
  183. {
  184. //sm2加密
  185. $recode = php_SM2Encrypt($data, $cipher, $pubkey);
  186. echo "<br/>recode:$recode \n";
  187. //php_SM2Encrypt接口返回的密文值是c1c3c2格式,以下示例转DER编码
  188. $recode = php_SM2FormatConvert(102, $cipher, $der);
  189. echo "<br/>recode:$recode \n";
  190. //SM2加密字符串转base64编码
  191. $sm2encrypted = base64_encode($der);
  192. echo "<br/>sm2加密字符串base64:$sm2encrypted \n";
  193. return $sm2encrypted;
  194. }
  195. //SM2Decrypt
  196. function SM2Decrypt($data, $privkey)
  197. {
  198. //php_SM2Decrypt 接收密文值是c1c3c2格式,若对方给的密文值是DER格式 则通过如下方式转换,然后再传入接口解密
  199. $recode = php_SM2FormatConvert(101, $data, $c1c3c2);
  200. echo "<br/>recode:$recode \n";
  201. //解密
  202. $recode = php_SM2Decrypt($c1c3c2, $plain, $privkey);
  203. echo "<br/>recode:$recode \n";
  204. echo "<br/>解密数据plain: $plain\n";
  205. return $plain;
  206. }
  207. //SM2Sign
  208. function SM2Sign($data, $pubkey, $privkey)
  209. {
  210. //签名
  211. $recode = php_SM2Sign($data, $redata, $privkey, $pubkey);
  212. echo "<br/>recode:$recode \n";
  213. //php_SM2Sign接口返回的签名值是RS格式,以下示例转DER编码
  214. $php_func = 'php_SM2FormatConvert';
  215. $recode = $php_func(202, $redata, $der);
  216. echo "<br/>recode:$recode \n";
  217. echo "<br/>data: " . $data . " len:" . strlen($data) . " \n";
  218. echo "<br/>signValue DER: " . base64_encode($der) . " len:" . strlen($der) . " \n";
  219. //加签数据base64返回
  220. $sm2SignData = base64_encode($der);
  221. return $sm2SignData;
  222. }
  223. //SM3Crypt
  224. function SM3Crypt($data)
  225. {
  226. $recode = php_SM3Crypt($data, $sm3hash);
  227. echo "<br/>recode:$recode \n";
  228. //加签数据base64返回
  229. return strtoupper($this->string2hex($sm3hash));
  230. }
  231. //16进制转换为二进制
  232. function hex2String($hexdata)
  233. {
  234. $bindata = "";
  235. for ($i = 0; $i < strlen($hexdata); $i += 2) {
  236. $bindata .= chr(hexdec(substr($hexdata, $i, 2)));
  237. }
  238. return $bindata;
  239. }
  240. //SM4Encrypt
  241. function SM4Encrypt($data, $password)
  242. {
  243. //加密密码做特殊处理 先MD5转换大写 从第8位开始截取16个字符串
  244. $password = substr(strtoupper(md5($password)), 8, 16);
  245. echo "<br/>【SM4】MD5加密密码=======" . $password;
  246. //接口是密文key,将明文key加密后再传入php_SM4CBCCrypt进行数据加密
  247. //不必要每次都加密key,建议手工加密一次,将key密文保存使用,key明文保存至安全的地方
  248. //若是会话级别的key则自行定策略
  249. $recode = php_CryptKey(0, $password, $key);
  250. echo "<br/>recode:$recode \n";
  251. //加密
  252. $recode = php_SM4CBCCrypt(0, $data, $redata, $key, $this->iv);
  253. echo "<br/>recode:$recode \n";
  254. echo "<br/>redata: " . base64_encode($redata) . " \n";
  255. $SM4Encryptdata = base64_encode($redata);
  256. return $SM4Encryptdata;
  257. }
  258. //SM4Encrypt
  259. function SM4Decrypt($data, $password)
  260. {
  261. echo "<br/>SM4解密数据=======" . $data;
  262. //加密密码做特殊处理
  263. $password = substr(strtoupper(md5($password)), 8, 16);
  264. echo "<br/>MD5密码=======" . $password;
  265. //接口是密文key,将明文key加密后再传入php_SM4CBCCrypt进行数据加密
  266. //不必要每次都加密key,建议手工加密一次,将key密文保存使用,key明文保存至安全的地方
  267. //若是会话级别的key则自行定策略
  268. $recode = php_CryptKey(0, $password, $key);
  269. echo "<br/>recode:$recode \n";
  270. //解密
  271. $recode = php_SM4CBCCrypt(1, base64_decode($data), $dedata, $key, $this->iv);
  272. echo "<br/>sm4[解密]recode:$recode \n";
  273. return $dedata;
  274. }
  275. /**
  276. * 公钥解密
  277. * @param 密文数据 $data
  278. * @return 原文结果 string
  279. */
  280. private function decryptByPublicKey($data)
  281. {
  282. $data = base64_decode($data);
  283. openssl_public_decrypt($data, $decrypted, $this->publicKey, OPENSSL_PKCS1_PADDING);//公钥解密
  284. return $decrypted;
  285. }
  286. /**
  287. * 私钥加密
  288. * @param 原始数据 $data
  289. * @return 密文结果 string
  290. */
  291. private function encryptByPrivateKey($data)
  292. {
  293. openssl_private_encrypt($data, $encrypted, $this->privateKey, OPENSSL_PKCS1_PADDING);//私钥加密
  294. $encrypted = base64_encode($encrypted);//加密后的内容通常含有特殊字符,需要编码转换下,在网络间通过url传输时要注意base64编码是否是url安全的
  295. return $encrypted;
  296. }
  297. //封装返回数据
  298. private function runJson($code = "000000", $msg = "完成")
  299. {
  300. return json(['code' => $code, 'message' => $msg]);
  301. //以下加密信息返回,暂时不用使用
  302. // $data = [
  303. // 'signMethod' => 'MD5',
  304. // 'encryptMethod' => 'AES',
  305. // 'appID' => $this->appID,
  306. // 'seqNO' => (string)rand(100000,999999),
  307. // 'appAccessToken' => ''
  308. // ];
  309. // $json = json_encode(['code'=>$code, 'message'=>$msg]);
  310. // $key = strtoupper(md5(getKey()));//随机秘钥
  311. // $data['rsaEncryptData'] = $this->encryptByPrivateKey($key);
  312. // $data['reqData'] = $this->encrypt($json, $key);
  313. // $data['sign'] = strtoupper(md5($data['reqData'] . $data['seqNO'] . $this->appSecretKey . $key ));
  314. // return json($data);
  315. }
  316. // curl post请求
  317. private function https_post($url, $data = null)
  318. {
  319. $data = json_encode($data, JSON_UNESCAPED_SLASHES);
  320. $header [] = 'Content-Type:application/x-www-form-urlencoded';
  321. $ch = curl_init();
  322. curl_setopt($ch, CURLOPT_HTTPHEADER, $header);
  323. curl_setopt($ch, CURLOPT_URL, $url);
  324. curl_setopt($ch, CURLOPT_CUSTOMREQUEST, "POST");
  325. curl_setopt($ch, CURLOPT_SSL_VERIFYPEER, FALSE);
  326. curl_setopt($ch, CURLOPT_SSL_VERIFYHOST, FALSE);
  327. curl_setopt($ch, CURLOPT_USERAGENT, 'Mozilla/5.0 (compatible; MSIE 5.01; Windows NT 5.0)');
  328. @curl_setopt($ch, CURLOPT_FOLLOWLOCATION, true);
  329. curl_setopt($ch, CURLOPT_AUTOREFERER, 1);
  330. curl_setopt($ch, CURLOPT_POSTFIELDS, $data);
  331. curl_setopt($ch, CURLOPT_RETURNTRANSFER, true);
  332. $tmpInfo = curl_exec($ch);
  333. curl_close($ch);
  334. $tmpInfo1 = json_decode($tmpInfo, true);
  335. return $tmpInfo1;
  336. }
  337. /**
  338. * 获得随机字符串
  339. **/
  340. private function getKey($length = 16)
  341. {
  342. // 密码字符集,可任意添加你需要的字符
  343. $chars = 'abcdefghijklmnopqrstuvwxyzABCDEFGHIJKLMNOPQRSTUVWXYZ2345678';
  344. $key = '';
  345. for ($i = 0; $i < $length; $i++) {
  346. // 这里提供两种字符获取方式
  347. // 第一种是使用 substr 截取$chars中的任意一位字符;
  348. // 第二种是取字符数组 $chars 的任意元素
  349. // $key .= substr($chars, mt_rand(0, strlen($chars) – 1), 1);
  350. $key .= $chars[mt_rand(0, strlen($chars) - 1)];
  351. }
  352. return $key;
  353. }
  354. }