python wrapper of GmSSL
Project description
gmssl_pyx
python wrapper of GmSSL
使用的版本是 GmSSL-3.1.0
支持 Python 3.7, 3.8, 3.9, 3.10
安装
pip install gmssl_pyx
SM2
加密和解密
from gmssl_pyx import sm2_key_generate, sm2_encrypt, sm2_decrypt
# 生成 SM2 公私钥
public_key, private_key = sm2_key_generate()
# 加密
plaintext = b"hello world"
ciphertext = sm2_encrypt(public_key, plaintext)
print("ciphertext", ciphertext)
# 解密
plaintext = sm2_decrypt(private_key, ciphertext)
print("plaintext", plaintext)
签名和验签
from gmssl_pyx import sm2_key_generate, sm2_sign, sm2_verify
# 生成 SM2 公私钥
public_key, private_key = sm2_key_generate()
# 没有 signer_id 和 SM3 杂凑值 z
# 签名
message = b"hello world"
signature = sm2_sign(private_key, public_key, message, signer_id=None)
print("signature", signature)
# 验证签名
verify = sm2_verify(private_key, public_key, message, signature, signer_id=None)
print("verify", verify)
# 默认 signer_id 和 SM3 杂凑值 z
signature = sm2_sign(private_key, public_key, message)
print("signature", signature)
# 验证签名
verify = sm2_verify(private_key, public_key, message, signature)
print("verify", verify)
# 自定义 signer_id 和 SM3 杂凑值 z
signer_id = b"signer_id"
signature = sm2_sign(private_key, public_key, message, signer_id=signer_id)
print("signature", signature)
# 验证签名
verify = sm2_verify(private_key, public_key, message, signature, signer_id=signer_id)
print("verify", verify)
ASN.1 DER 编码
加密和签名的结果都是 ASN.1 DER 编码,如果要得到原始的密文和签名,可以参考下面的例子
需要安装 pycryptodomex 库
pip install pycryptodomex
from Cryptodome.Util.asn1 import DerSequence, DerOctetString, DerInteger
from gmssl_pyx import sm2_key_generate, sm2_encrypt, sm2_decrypt
# 生成 SM2 公私钥
public_key, private_key = sm2_key_generate()
# 加密
plaintext = b"hello world"
ciphertext = sm2_encrypt(public_key, plaintext)
print("ciphertext", ciphertext)
seq_der = DerSequence()
decoded_ciphertext = seq_der.decode(ciphertext)
# ASN.1 DER 解码
# c1: point(x, y) 64bytes
# c2: ciphertext len(data)
# c3: hash 32bytes
# der order: c1x c1y hash ciphertext
c1x = decoded_ciphertext[0]
c1y = decoded_ciphertext[1]
c3 = DerOctetString().decode(decoded_ciphertext[2]).payload
c2 = DerOctetString().decode(decoded_ciphertext[3]).payload
# 模式为 C1C3C2
raw_ciphertext = c1x.to_bytes(32, "big") + c1y.to_bytes(32, "big") + c3 + c2
# 如果需要解密原始密文,需要先进行 ASN.1 DER 编码
seq_der = DerSequence()
c1x = raw_ciphertext[:32]
x = DerInteger(int.from_bytes(c1x, byteorder='big'))
seq_der.append(x)
c1y = raw_ciphertext[32:64]
y = DerInteger(int.from_bytes(c1y, byteorder='big'))
seq_der.append(y)
c3 = raw_ciphertext[64:64 + 32]
seq_der.append(DerOctetString(c3))
c2 = raw_ciphertext[64 +32:]
seq_der.append(DerOctetString(c2))
ciphertext = seq_der.encode()
plaintext = sm2_decrypt(private_key, ciphertext)
print("plaintext", plaintext)
# 签名
signature = sm2_sign(private_key, public_key, message)
seq_der = DerSequence()
decoded_sign = seq_der.decode(signature)
# ASN.1 DER 解码,两个 32 字节的整数
r = decoded_sign[0]
s = decoded_sign[1]
print('r', r)
print('s', s)
raw_signature = '%064x%064x' % (r, s)
# 验证原始签名同样需要先进行 ASN.1 DER 编码
r = int(raw_signature[:64], base=16)
s = int(raw_signature[64:], base=16)
seq_der = DerSequence()
seq_der.append(DerInteger(r))
seq_der.append(DerInteger(s))
signature = seq_der.encode()
verify = sm2_verify(private_key, public_key, message, signature)
print('verify', verify)
公私钥的一些补充说明
公钥长度为 64 字节,是两个 32 字节的整数 x y 拼接而成。
如果公钥长度为 65 字节,那么第一个字节为 '\x04' ,表示后面的 64 字节就是公钥。
如果公钥长度为 33 字节,那么第一个字节为 '\x02' 或者 '\x03' , 这是一种压缩格式,后面的 32 字节为整数 x , y 可以根据 x 计算出来。
私钥长度为 32 字节,没有其他变化。
from gmssl_pyx import sm2_key_generate, normalize_sm2_public_key
raw_public_key, _ = sm2_key_generate()
k1 = normalize_sm2_public_key(raw_public_key)
assert k1 == raw_public_key
k1 = normalize_sm2_public_key(b'\x04' + raw_public_key)
assert k1 == raw_public_key
# 压缩版公钥
y = int.from_bytes(raw_public_key[32:], byteorder='big')
if y % 2 == 0:
# y 是偶数
compressed_public_key = b'\x02' +raw_public_key[:32]
else:
compressed_public_key = b'\x03' + raw_public_key[:32]
k1 = normalize_sm2_public_key(compressed_public_key)
assert k1 == raw_public_key
SM3
hash 计算
from gmssl_pyx import sm3_hash
message = b'hello world'
signature = sm3_hash(message)
print('message', message)
print('signature', signature.hex())
hmac 计算
import secrets
from gmssl_pyx import sm3_hmac
key = secrets.token_bytes(32)
message = b"sm3_hmac"
hmac_data = sm3_hmac(key, message)
print("message", message)
print("hmac_data", hmac_data)
kdf 计算
import secrets
from gmssl_pyx import sm3_kdf
key = secrets.token_bytes(32)
new_key = sm3_kdf(key, 32)
print('kdf new_key', new_key)
SM4
CBC 模式加密和解密
import secrets
from gmssl_pyx import (
sm4_cbc_padding_encrypt,
sm4_cbc_padding_decrypt,
SM4_KEY_SIZE,
SM4_BLOCK_SIZE,
)
key = secrets.token_bytes(SM4_KEY_SIZE)
iv = secrets.token_bytes(SM4_BLOCK_SIZE)
plaintext = b"hello world"
# 加密
ciphertext = sm4_cbc_padding_encrypt(key, iv, plaintext)
print("ciphertext", ciphertext.hex())
# 解密
decrypted = sm4_cbc_padding_decrypt(key, iv, ciphertext)
print("decrypted", decrypted)
CTR 模式加密和解密
import secrets
from gmssl_pyx import (
sm4_ctr_encrypt,
sm4_ctr_decrypt,
SM4_KEY_SIZE,
SM4_BLOCK_SIZE,
)
key = secrets.token_bytes(SM4_KEY_SIZE)
ctr = secrets.token_bytes(SM4_BLOCK_SIZE)
plaintext = b"hello world"
# 加密
ciphertext = sm4_ctr_encrypt(key, ctr, plaintext)
print("ciphertext", ciphertext.hex())
# 解密
decrypted = sm4_ctr_decrypt(key, ctr, ciphertext)
print("decrypted", decrypted)
GCM 模式加密和解密
import secrets
from gmssl_pyx import sm4_gcm_encrypt, sm4_gcm_decrypt, SM4_KEY_SIZE, SM4_BLOCK_SIZE
plaintext = b'hello world'
key = secrets.token_bytes(SM4_KEY_SIZE)
iv = secrets.token_bytes(SM4_BLOCK_SIZE)
aad = secrets.token_bytes(16)
# 加密
ciphertext, tag = sm4_gcm_encrypt(key, iv, aad, plaintext=plaintext)
print('ciphertext', ciphertext)
# 解密
plaintext = sm4_gcm_decrypt(key, iv=iv, aad=aad, ciphertext=ciphertext, tag=tag)
print('plaintext', plaintext)
Project details
Release history Release notifications | RSS feed
Download files
Download the file for your platform. If you're not sure which to choose, learn more about installing packages.
Source Distribution
gmssl_pyx-1.0.1.tar.gz
(18.0 kB
view hashes)
Built Distributions
Close
Hashes for gmssl_pyx-1.0.1-cp310-cp310-win_amd64.whl
Algorithm | Hash digest | |
---|---|---|
SHA256 | 0f995d3d4062fd5f4cba0ad4d65caa5e9effc06c359d4a1a04e507d03f0e06d3 |
|
MD5 | 8785bdaf6a2d260b0e969150d2fcac37 |
|
BLAKE2b-256 | 2f96b3fdf7cb61df51c238e90364f44d1a949c5b26da4e5391d60e5a3cf6e4ed |
Close
Hashes for gmssl_pyx-1.0.1-cp310-cp310-manylinux_2_17_x86_64.manylinux2014_x86_64.whl
Algorithm | Hash digest | |
---|---|---|
SHA256 | 73433c9f01758a147b3e577090317733a802e1823f5887e58f9be0f9488336fd |
|
MD5 | a7074c4e66fa4771b9c3d14d8fba1feb |
|
BLAKE2b-256 | ae4db7dda1176c72de711363a1be975e071b0d289da25618c7f6627410173561 |
Close
Hashes for gmssl_pyx-1.0.1-cp310-cp310-macosx_10_9_x86_64.whl
Algorithm | Hash digest | |
---|---|---|
SHA256 | cb6b8a304eeb74dd83e34938f63176e748ed13c1f464ad450f58dfe90bd94d32 |
|
MD5 | 9809e422a2dc7c8f6ab3cda2fb46e4f5 |
|
BLAKE2b-256 | 293500bd41186d0b7f1879f3a35c37ca81f66d235ecb4159a9b8f5c3552b9fbd |
Close
Hashes for gmssl_pyx-1.0.1-cp39-cp39-win_amd64.whl
Algorithm | Hash digest | |
---|---|---|
SHA256 | c3ef8a483c3348c2bd25ac685dc9602d1c2c3b05c7011961c5d26ef750d132a2 |
|
MD5 | 14f08feedf914e2fb32b4ced1a624825 |
|
BLAKE2b-256 | 3b63ee5e1b89e6b645a951e48d7951ac284602061d91a47f4e4e9f7223fdba7f |
Close
Hashes for gmssl_pyx-1.0.1-cp39-cp39-manylinux_2_17_x86_64.manylinux2014_x86_64.whl
Algorithm | Hash digest | |
---|---|---|
SHA256 | b7f37d706353a94f8396e36d980e1298062c693add3ae4f56b962074f519ac7c |
|
MD5 | a8ce7e29ca6e84fd452b2bcff8134f49 |
|
BLAKE2b-256 | 88bab8db99e9631af8124333e0f54c313a1772c32a2ea7ebb4784e42e483497e |
Close
Hashes for gmssl_pyx-1.0.1-cp39-cp39-macosx_10_9_x86_64.whl
Algorithm | Hash digest | |
---|---|---|
SHA256 | f0fb07af16e582824e81a1d21f52bf81c49f2c2385a6c989fd2f5322aec6bc5b |
|
MD5 | 24ac8892a334f25cb16f7f3ac5e7ce35 |
|
BLAKE2b-256 | a3027fefda5f7e0fba3b433ddd6f4d21ec7e16a5b790ba7e8a4460b792e0a31d |
Close
Hashes for gmssl_pyx-1.0.1-cp38-cp38-win_amd64.whl
Algorithm | Hash digest | |
---|---|---|
SHA256 | 35d1ce50958879915d107483f41f0f379d49271ce22f822e9531bddf34b0d0cb |
|
MD5 | 55e30dd396d3cc2fa63ad71e5546e730 |
|
BLAKE2b-256 | 25a3de5009bb67725ee33f007ca6402f4814dbf3a53961aeaa10fe1653b419de |
Close
Hashes for gmssl_pyx-1.0.1-cp38-cp38-manylinux_2_17_x86_64.manylinux2014_x86_64.whl
Algorithm | Hash digest | |
---|---|---|
SHA256 | 0b4de2278f7c773c15b308311aa0b2e24ee5bc1870950a1516beff7925fbbb74 |
|
MD5 | fb75808323f36f6eaf29ed57bfb85a96 |
|
BLAKE2b-256 | 48c8676baad442f57ac5f351878ad205c985138fa636a9afa1a891a2eb90c95d |
Close
Hashes for gmssl_pyx-1.0.1-cp38-cp38-macosx_10_9_x86_64.whl
Algorithm | Hash digest | |
---|---|---|
SHA256 | 2c860755a6ebfe7a41f63395f530721b946f67ded89838996b4e6a8ce3aa638e |
|
MD5 | cdf7bd6b401808330ae08f40f2624d6c |
|
BLAKE2b-256 | bcc29389fee0943183eccbf9c81cb40e9a5cb5d57af412b5ea61aa45b813552e |
Close
Hashes for gmssl_pyx-1.0.1-cp37-cp37m-win_amd64.whl
Algorithm | Hash digest | |
---|---|---|
SHA256 | fbc814f3fd545dacf1a470fea867338f5734baa74089755c4044a15e78f05071 |
|
MD5 | a0e925f80d0663a895e440f4ba68c9b2 |
|
BLAKE2b-256 | c969facefb85ee7e543b7228a74c6fba968c240330a3d5d24b7f8b92a003104b |
Close
Hashes for gmssl_pyx-1.0.1-cp37-cp37m-manylinux_2_17_x86_64.manylinux2014_x86_64.whl
Algorithm | Hash digest | |
---|---|---|
SHA256 | 489f9526766da4a47969351f5eae62d6744c81c75d83bf1151887ae8b2d06c7d |
|
MD5 | 59d7ea6f4a94ba0543fc966d90b18f86 |
|
BLAKE2b-256 | 97881492cfe1e1e3b00c27ac52f45517c3364315d4b78f1784e8680d43842623 |
Close
Hashes for gmssl_pyx-1.0.1-cp37-cp37m-macosx_10_9_x86_64.whl
Algorithm | Hash digest | |
---|---|---|
SHA256 | 97c622367f0ea55cff529bf22465360e584d9be8892579a539616ef2118b78c0 |
|
MD5 | ef2fdcec893322bd7afc0807a5acb972 |
|
BLAKE2b-256 | 1f481d804da1630878689b6536f6935b934be34fa3c27b02261ef95dfe454c78 |