zbb378@sohu.com
2024-11-04 b2bad51be3c8d3e78d7f81a19415faeac2d0297c
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
142
143
144
145
146
147
148
149
150
151
152
153
154
155
156
157
158
159
160
161
162
163
164
165
166
167
168
169
170
171
172
173
174
175
176
177
178
179
180
181
182
183
184
185
186
187
188
189
190
191
192
193
194
195
196
197
198
199
200
201
202
203
204
205
206
207
208
209
210
211
212
213
214
215
216
217
218
219
220
221
222
223
224
225
226
227
228
229
230
231
232
233
234
235
236
237
238
239
240
241
242
243
244
245
246
247
248
249
250
251
252
253
254
255
256
257
258
259
260
261
262
263
264
265
266
267
268
269
270
271
272
273
274
275
276
277
278
279
280
281
282
283
284
285
286
287
288
289
290
291
292
293
294
295
296
297
298
299
300
301
302
303
304
305
306
307
308
309
310
311
312
313
314
315
316
317
318
319
320
321
322
323
324
325
326
327
328
329
330
331
332
333
334
335
336
337
338
339
340
341
342
343
344
345
346
347
348
349
350
351
352
353
354
355
356
357
358
359
360
361
362
363
364
365
366
367
368
369
370
371
372
373
374
375
376
377
378
379
380
381
382
383
384
385
386
387
388
389
390
391
392
393
394
395
396
397
398
399
400
401
402
403
404
405
406
407
408
409
410
411
412
413
414
415
416
417
418
419
420
421
422
423
424
425
426
427
428
429
430
431
432
433
434
435
436
437
438
439
440
441
442
443
444
445
446
447
448
449
450
451
452
453
454
455
456
457
458
459
460
461
462
463
package com.nova.sankuai.domain.api.yixin;
 
 
import com.alibaba.fastjson.JSON;
import com.alibaba.fastjson.JSONObject;
import com.nova.sankuai.security.HexUtil;
 
import javax.crypto.Cipher;
import javax.crypto.spec.SecretKeySpec;
import java.nio.charset.Charset;
import java.nio.charset.StandardCharsets;
import java.security.*;
import java.time.LocalDateTime;
import java.time.format.DateTimeFormatter;
import java.util.*;
 
public class YXSignUtil {
 
    public static final String reqSysCode = "WHKJ";
 
    public static final String KEY_ALGORITHM = "RSA";
 
    //本地公钥
    public static final String LOCAL_PUBLIC_KEY = "MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQDPlqGyVfCliU1SmhdGKem9+p63rIb78bu3Yj9DWQv1c+fbFLV0OkfeMvyTAJi95PozH+JlDqt3gWWLyCXEb7M6pPNEJmUjGHX4+tCykUbooY55zr8En3DM4MMRvOz5hhkle7tosT4Iejhtuwsah9heWd4AuM84gw8C7LVA7XbOkQIDAQAB";
 
    //本地私钥
    public static final String LOCAL_PRIVATE_KEY = "MIICdgIBADANBgkqhkiG9w0BAQEFAASCAmAwggJcAgEAAoGBAM+WobJV8KWJTVKaF0Yp6b36nreshvvxu7diP0NZC/Vz59sUtXQ6R94y/JMAmL3k+jMf4mUOq3eBZYvIJcRvszqk80QmZSMYdfj60LKRRuihjnnOvwSfcMzgwxG87PmGGSV7u2ixPgh6OG27CxqH2F5Z3gC4zziDDwLstUDtds6RAgMBAAECgYAxZAya6tmz+SQdmC4bcpN7sSqcVv9S6KQaMNUOiBxRTT+IH7hArDE3S/hOXaD55YYmLdrm4oOnjnEDvh5GS7Ffv9U5i+7Dvf4u4rzvucBwj2gIWVVzQgjT2j2LXcBpExWLTEEE37WrJogXWJZk/iKFB6QpxnsFTi9bmFftO37S8QJBAPIIeHftqutrg55bjbM+NxAoa4oMNEnI7Ri3X7pmjWk7Zzjtl6c5nvAL5qbhXO3SdgF/+y7XtH2LUR6iRY2vuj0CQQDbkVA36O/dSQcq2LFf3J+kd1j2Z/j6BxC816Q7CchWvpvvXUm+9p+uiPX8LmCWTeVrkp3qr7mWwBDVyChJK27lAkA7JujSXqqkKL2dKUEDapQohchqj7sDwXB41vA1bTToYBVFK4Qh4Yo/npj7dh6xHPusOCwacatx92eW9g/LpgP9AkEAgW561EqLQ23uPLK6dOEQdpooJjEKUxFhK4EO/gJ5R7FbKNJcS6cEYJW6M+t+4nuO10f5sUPfal9UTUGNhfyFhQJAGNcLGWQvWuC2Si0vI5xKRhLYblb3MrwGKd/Mj6UdURq9qsHdjqvaW9rx0TjZ9uCb3YbCSGFO0nWavkkqJICO1Q==";
 
 
    /**
     * 构造合作方请求绿地报文
     *
     * @param bizMap     业务报文集
     * @param privateKey 合作方私钥
     * @param publicKey  绿地公钥
     * @return
     */
    public static String buildRequest(Map<String, Object> bizMap, PrivateKey privateKey, PublicKey publicKey, String funding) throws Exception {
        // 业务报文
        String params = JSON.toJSONString(bizMap);
        // 时间戳
        String timestamp = DateTimeFormatter.ofPattern("yyyyMMddHHmmss").format(LocalDateTime.now());
        // 构建签名
        SortedMap<String, String> map = new TreeMap<>();
        map.put("params", params);
        map.put("timestamp", timestamp);
 
        // 待签名明文
        String plain = toSortedString(map);
        // 做md5摘要处理
        String md5 = MD5.digest(plain, StandardCharsets.UTF_8);
        // 签名
        String sign = sign(md5, privateKey);
        map.put("sign", sign);
 
        // 生成16位AES密钥
        String aesKey = generateAesKey();
        // 对params进行AES加密, 并替换进map
        params = encrypt(params, aesKey);
        map.replace("params", params);
 
        // 对AES密钥进行RSA加密, 并将加密后的AES密钥加入map
        aesKey = encryptRSA(aesKey, publicKey);
        map.put("key", aesKey);
        map.put("reqSysCode", reqSysCode);
        map.put("funding", funding);
 
        return JSON.toJSONString(map);
    }
 
    /**
     * 绿地处理合作方发起的请求
     *
     * @param strReq     合作方请求到达绿地的json字符串请求报文
     * @param privateKey 绿地私钥
     * @param publicKey  合作方公钥
     * @return
     */
    public static Map<String, Object> parseRequest(String strReq, PrivateKey privateKey, PublicKey publicKey) throws Exception {
        JSONObject json = JSON.parseObject(strReq);
        String params = json.getString("params");
        String aesKey = json.getString("key");
        String sign = json.getString("sign");
        String timestamp = json.getString("timestamp");
 
        // 对AESkey进行RSA解密
        aesKey = decryptRSA(aesKey, privateKey);
        // 对params进行AES解密
        params = decrypt(params, aesKey);
 
        // 构建验签明文
        TreeMap<String, String> map = new TreeMap<>();
        map.put("params", params);
        map.put("timestamp", timestamp);
        String plain = toSortedString(map);
 
        // 做md5摘要
        String md5 = MD5.digest(plain, StandardCharsets.UTF_8);
 
        // 验签
        boolean passed = verify(sign, md5, publicKey);
        if (!passed) {
            throw new RuntimeException("验签失败");
        }
        return JSON.parseObject(params);
    }
 
    /**
     * 绿地处理合作方发起的请求
     *
     * @param strReq     合作方请求到达绿地的json字符串请求报文
     * @param privateKey 本地私钥
     * @param publicKey  绿地公钥
     * @return
     */
    public static Map<String, Object> parseLVDiRequest(Map<String, String> strReq, PrivateKey privateKey, PublicKey publicKey) throws Exception {
        String params = strReq.get("params");
        String aesKey = strReq.get("key");
        String signkeyIndex = strReq.get("signkeyIndex");
        String appId = strReq.get("appId");
        String version = strReq.get("version");
        String sign = strReq.get("sign");
        String timestamp = strReq.get("timestamp");
 
        // 对AESkey进行RSA解密
        aesKey = decryptRSA(aesKey, privateKey);
        // 对params进行AES解密
        params = decrypt(params, aesKey);
 
        // 构建验签明文
        Map<String, Object> map = new HashMap<>();
        map.put("params", params);
        map.put("timestamp", timestamp);
        map.put("signkeyIndex", signkeyIndex);
        map.put("appId", appId);
        map.put("version", version);
//        String plain = toSortedString(map);
 
        // 做md5摘要
//        String md5 = MD5.digest(plain, StandardCharsets.UTF_8);
 
        // 验签
//        boolean passed = verify(sign, md5, publicKey);
//        if (!passed) {
//            throw new RuntimeException("验签失败");
//        }
        return map;
    }
 
    /**
     * 绿地给合作方的同步响应报文构建
     *
     * @param bizMap     业务报文
     * @param privateKey 绿地私钥
     * @param publicKey  合作方公钥
     * @return
     */
    public static String buildResponse(Map<String, Object> bizMap, PrivateKey privateKey, PublicKey publicKey) throws Exception {
        JSONObject json = new JSONObject();
        TreeMap<String, String> map = new TreeMap<>();
        String params = JSON.toJSONString(bizMap);
        map.put("params", params);
 
        // 处理签名
        String plain = toSortedString(map);
        String md5 = MD5.digest(plain, StandardCharsets.UTF_8);
        String sign = sign(md5, privateKey);
        map.put("sign", sign);
        // 处理加密
        String aesKey = generateAesKey();
        params = encrypt(params, aesKey);
        map.replace("params", params);
        map.put("key", encryptRSA(aesKey, publicKey));
        map.put("encrypt", "true");
        return JSON.toJSONString(map);
    }
 
 
    /**
     * 绿地回调请求合作方报文构建
     *
     * @param bizMap     业务报文
     * @param privateKey 绿地私钥
     * @param publicKey  合作方公钥
     * @return
     */
    public static String buildCallbackRequest(Map<String, Object> bizMap, PrivateKey privateKey, PublicKey publicKey) throws Exception {
 
        // 参数
        String params = JSON.toJSONString(bizMap);
        // 签名
        TreeMap<String, String> map = new TreeMap<>();
        map.put("params", params);
        map.put("timestamp", DateTimeFormatter.ofPattern("yyyyMMddHHmmss").format(LocalDateTime.now()));
        map.put("appId", "");// 固定,待合作方分配
        map.put("version", "1.0");// 固定,由具体接口文档定
 
        String plain = toSortedString(map);
        // MD5
        String md5 = MD5.digest(plain, StandardCharsets.UTF_8);
        // 签名
        String sign = sign(md5, privateKey);
        map.put("sign", sign);
 
        // AES密钥
        String aesKey = generateAesKey();
        // 加密
        map.replace("params", encrypt(params, aesKey));
        map.put("key", encryptRSA(aesKey, publicKey));
 
        map.put("signType", "");// 具体由接口文档定
        map.put("signkeyIndex", "");// 固定,由合作方分配
 
        return JSON.toJSONString(map);
    }
 
    /**
     * 绿地处理合作方的回调响应
     *
     * @param strResp
     * @param privateKey
     * @param publicKey
     * @return
     */
    public static String parseCallbackResponse(String strResp, PrivateKey privateKey, PublicKey publicKey) throws Exception {
        JSONObject json = JSON.parseObject(strResp);
        String sign = (String) json.remove("gsSign");
        TreeMap<String, String> map = new TreeMap<>();
        json.forEach((k, v) -> map.put(k, v.toString()));
        String plain = toSortedString(map);
        String md5 = MD5.digest(plain, StandardCharsets.UTF_8);
        boolean verify = verify(sign, md5, publicKey);
        if (!verify) {
            throw new RuntimeException("验签失败");
        }
        String params = json.getString("params");
        Boolean encrypted = json.getBoolean("encrypt");
        if (encrypted != null && encrypted) {
            String aesKey = json.getString("key");
            aesKey = decryptRSA(aesKey, privateKey);
            params = decrypt(params, aesKey);
        }
 
        return params;
    }
 
 
    /**
     * RSA签名
     *
     * @param data
     * @param privateKey
     * @return
     */
    public static String sign(String data, PrivateKey privateKey) throws Exception {
        Signature signature = Signature.getInstance("SHA1WithRSA");
        signature.initSign(privateKey);
        signature.update(data.getBytes(StandardCharsets.UTF_8));
        return Base64.getEncoder().encodeToString(signature.sign());
    }
 
    /**
     * 验签
     *
     * @param sign
     * @param md5
     * @param publicKey
     * @return
     */
    public static boolean verify(String sign, String md5, PublicKey publicKey) throws Exception {
        byte[] signBytes = Base64.getDecoder().decode(sign);
        Signature signature = Signature.getInstance("SHA1WithRSA");
        signature.initVerify(publicKey);
        signature.update(md5.getBytes(StandardCharsets.UTF_8));
        return signature.verify(signBytes);
    }
 
 
    /**
     * 将需要加签的数据拼接为'='和'&'拼接的格式
     *
     * @param map
     * @return
     */
    private static String toSortedString(SortedMap<String, String> map) {
        StringBuilder sb = new StringBuilder();
        Iterator<Map.Entry<String, String>> it = map.entrySet().iterator();
        while (true) {
            Map.Entry<String, String> entry = it.next();
            sb.append(entry.getKey()).append('=').append(entry.getValue());
            if (it.hasNext()) {
                sb.append('&');
            } else {
                break;
            }
        }
        return sb.toString();
    }
 
    /**
     * 生成16位不重复的随机数,含数字+大小写
     * 作为AES密钥使用
     */
    private static String generateAesKey() {
        StringBuilder uid = new StringBuilder();
        //产生16位的强随机数
        Random rd = new SecureRandom();
        for (int i = 0; i < 16; i++) {
            int type = rd.nextInt(3);
            switch (type) {
                case 0:
                    uid.append(rd.nextInt(10));
                    break;
                case 1:
                    uid.append((char) (rd.nextInt(25) + 65));
                    break;
                case 2:
                    uid.append((char) (rd.nextInt(25) + 97));
                    break;
                default:
                    break;
            }
        }
        return uid.toString();
    }
 
    /**
     * AES加密
     *
     * @param content 需要加密的内容
     * @param strKey  加密秘钥
     * @return 加密后的比特流
     */
    private static String encrypt(String content, String strKey) throws Exception {
        SecretKeySpec key = new SecretKeySpec(strKey.getBytes(), "AES"); //NOSONAR
        Cipher cipher = Cipher.getInstance("AES");
        byte[] byteContent = content.getBytes(StandardCharsets.UTF_8);
        cipher.init(Cipher.ENCRYPT_MODE, key);
        return byte2hex(cipher.doFinal(byteContent));
    }
 
    /**
     * AES解密
     *
     * @param content 待解密内容
     * @param strKey  解密密钥
     * @return 解密后的
     */
    private static String decrypt(String content, String strKey) throws Exception {
        SecretKeySpec key = new SecretKeySpec(strKey.getBytes(), "AES");
        Cipher cipher = Cipher.getInstance("AES");
        cipher.init(Cipher.DECRYPT_MODE, key);
        return new String(cipher.doFinal(hex2byte(content)));
    }
 
    /**
     * RSA加密
     *
     * @param data
     * @param publicKey
     * @return
     */
    public static String encryptRSA(String data, PublicKey publicKey) throws Exception {
        // 对数据加密
        Cipher cipher = Cipher.getInstance("RSA");
        cipher.init(Cipher.ENCRYPT_MODE, publicKey);
        return byte2hex(cipher.doFinal(data.getBytes()));
    }
 
    /**
     * RSA解密
     *
     * @param message
     * @param privateKey
     * @return
     */
    public static String decryptRSA(String message, PrivateKey privateKey) throws Exception {
        byte[] bytes = hex2byte(message);
        Cipher cipher = Cipher.getInstance("RSA");
        cipher.init(2, privateKey);
        byte[] result = cipher.doFinal(bytes);
        return new String(result);
    }
 
    /**
     * 16进制string转byte[]
     *
     * @param str
     * @return
     */
    private static byte[] hex2byte(final String str) {
        if (str == null) {
            return new byte[]{};
        }
        String newStr = str.trim();
        int len = newStr.length();
        if (len <= 0 || len % 2 != 0) {
            return new byte[]{};
        }
        byte[] b = new byte[len / 2];
        try {
            for (int i = 0; i < newStr.length(); i += 2) {
                b[i / 2] = (byte) Integer.decode("0x" + newStr.substring(i, i + 2)).intValue();
            }
            return b;
        } catch (Exception e) { //NOSONAR
            return new byte[]{};
        }
    }
 
    /**
     * byte[]转16进制string
     *
     * @param b
     * @return
     */
    private static String byte2hex(byte[] b) {
        StringBuilder hs = new StringBuilder();
        for (byte bi : b) {
            String temp = Integer.toHexString(bi & 0XFF);
            if (temp.length() == 1) {
                hs.append("0");
            }
            hs.append(temp);
        }
        return hs.toString().toUpperCase();
    }
 
 
    /**
     * MD5工具类
     */
    private static class MD5 {
        private static ThreadLocal threadLocal = new ThreadLocal() {
            @Override
            protected synchronized Object initialValue() {
                MessageDigest messagedigest = null;
 
                try {
                    messagedigest = MessageDigest.getInstance("MD5");
                } catch (NoSuchAlgorithmException var3) {
 
                }
 
                return messagedigest;
            }
        };
 
        public MD5() {
        }
 
        public static MessageDigest getMessageDigest() {
            return (MessageDigest) threadLocal.get();
        }
 
        public static String digest(String s, Charset charset) {
            getMessageDigest().update(s.getBytes(charset));
            return HexUtil.bytes2Hexstr(getMessageDigest().digest());
        }
    }
 
 
}