1
  2
  3
  4
  5
  6
  7
  8
  9
 10
 11
 12
 13
 14
 15
 16
 17
 18
 19
 20
 21
 22
 23
 24
 25
 26
 27
 28
 29
 30
 31
 32
 33
 34
 35
 36
 37
 38
 39
 40
 41
 42
 43
 44
 45
 46
 47
 48
 49
 50
 51
 52
 53
 54
 55
 56
 57
 58
 59
 60
 61
 62
 63
 64
 65
 66
 67
 68
 69
 70
 71
 72
 73
 74
 75
 76
 77
 78
 79
 80
 81
 82
 83
 84
 85
 86
 87
 88
 89
 90
 91
 92
 93
 94
 95
 96
 97
 98
 99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
142
143
144
// Copyright 2020 WeDPR Lab Project Authors. Licensed under Apache-2.0.

//! SM2 signature functions.

#[allow(unused_imports)]
#[macro_use]
extern crate wedpr_l_macros;
#[macro_use]
extern crate lazy_static;

use wedpr_l_utils::{error::WedprError, traits::Signature};

use wedpr_l_libsm::sm2::signature::{SigCtx, Signature as sm2Signature};

lazy_static! {
    // Shared sm2 instance initialized for all functions.
    static ref SM2_CTX: SigCtx = SigCtx::new();
}

/// Implements FISCO-BCOS-compatible SM2 as a Signature instance.
#[derive(Default, Debug, Clone)]
pub struct WedprSm2p256v1 {}

impl Signature for WedprSm2p256v1 {
    fn sign<T: ?Sized + AsRef<[u8]>>(
        &self,
        private_key: &T,
        msg_hash: &T,
    ) -> Result<Vec<u8>, WedprError> {
        let secret_key = match SM2_CTX.load_seckey(&private_key.as_ref()) {
            Ok(v) => v,
            Err(_) => {
                return Err(WedprError::FormatError);
            },
        };
        let derived_public_key = SM2_CTX.pk_from_sk(&secret_key);
        let signature =
            SM2_CTX.sign(&msg_hash.as_ref(), &secret_key, &derived_public_key);
        Ok(signature.bytes_encode().to_vec())
    }

    fn verify<T: ?Sized + AsRef<[u8]>>(
        &self,
        public_key: &T,
        msg_hash: &T,
        signature: &T,
    ) -> bool {
        let public_key_point = match SM2_CTX.load_pubkey(&public_key.as_ref()) {
            Ok(v) => v,
            Err(_) => {
                return false;
            },
        };

        let parsed_sig = match sm2Signature::bytes_decode(signature.as_ref()) {
            Ok(v) => v,
            Err(_) => {
                return false;
            },
        };
        SM2_CTX.verify(&msg_hash.as_ref(), &public_key_point, &parsed_sig)
    }

    fn generate_keypair(&self) -> (Vec<u8>, Vec<u8>) {
        let (public_key, secret_key) = SM2_CTX.new_keypair();
        (
            SM2_CTX.serialize_pubkey(&public_key, false),
            SM2_CTX.serialize_seckey(&secret_key),
        )
    }
}

impl WedprSm2p256v1 {
    /// Signes a message hash faster with both the private and public keys.
    pub fn sign_fast<T: ?Sized + AsRef<[u8]>>(
        &self,
        private_key: &T,
        public_key: &T,
        msg_hash: &T,
    ) -> Result<Vec<u8>, WedprError> {
        let secret_key = match SM2_CTX.load_seckey(&private_key.as_ref()) {
            Ok(v) => v,
            Err(_) => {
                return Err(WedprError::FormatError);
            },
        };
        let public_key_point = match SM2_CTX.load_pubkey(&public_key.as_ref()) {
            Ok(v) => v,
            Err(_) => {
                return Err(WedprError::FormatError);
            },
        };
        let signature =
            SM2_CTX.sign(&msg_hash.as_ref(), &secret_key, &public_key_point);
        Ok(signature.bytes_encode().to_vec())
    }

    /// Derives public key from private key.
    pub fn derive_public_key<T: ?Sized + AsRef<[u8]>>(&self, private_key: &T) -> Result<Vec<u8>, WedprError> {
        let secret_key = match SM2_CTX.load_seckey(&private_key.as_ref()) {
            Ok(v) => v,
            Err(_) => {
                return Err(WedprError::FormatError);
            },
        };
        let public_key = SM2_CTX.pk_from_sk(&secret_key);
        Ok(SM2_CTX.serialize_pubkey(&public_key, false))
    }
}

#[cfg(test)]
mod tests {
    use super::*;
    use wedpr_l_utils::constant::tests::BASE64_ENCODED_TEST_MESSAGE;

    #[test]
    fn test_sm2() {
        let sm2_sign = WedprSm2p256v1::default();

        // The message hash (NOT the original message) is required for
        // generating a valid signature.
        let msg_hash = BASE64_ENCODED_TEST_MESSAGE;

        let (public_key, private_key) = sm2_sign.generate_keypair();

        let public_key_derive = sm2_sign.derive_public_key(&private_key).unwrap();
        assert_eq!(public_key, public_key_derive);

        let signature_normal =
            sm2_sign.sign(&private_key, &msg_hash.to_vec()).unwrap();
        assert_eq!(
            true,
            sm2_sign.verify(&public_key_derive, &msg_hash.to_vec(), &signature_normal)
        );

        let signature_fast = sm2_sign
            .sign_fast(&private_key, &public_key, &msg_hash.to_vec())
            .unwrap();
        assert_eq!(
            true,
            sm2_sign.verify(&public_key, &msg_hash.to_vec(), &signature_fast)
        );
    }
}