"; // var_dump($json); $json_content = json_encode($json); //随机生成aes密钥 $aes_key = $this->randomKeys(16); //商户RSA私钥 if( empty($config['merRsaPrivateKey']) ){ $private_rsa_key = file_get_contents($this->getPath() . $config['agencyId'] . '/' . $config['agencyId']. '.pem'); }else{ $private_rsa_key = $config['merRsaPrivateKey']; } //我司平台RSA公钥 if( empty($config['rootRsaPublicKey']) ){ $public_rsa_key = file_get_contents($this->getPath() . $config['agencyId'] . '/' . 'GHT_ROOT.pem'); }else{ $public_rsa_key = $config['rootRsaPublicKey']; } //用上面随机生成的aes密钥加密请求报文 $data['encryptData'] = $this->aesEncode($json_content, $aes_key); //用我司平台rsa公钥加密上面随机生成的aes密钥 $data['encryptKey'] = $this->rsaEncode($aes_key, $public_rsa_key); //用商户ras私钥签名 $data['signData'] = $this->rsaSign($json_content, $private_rsa_key); $data['agencyId'] = $config['agencyId']; $data_content = json_encode($data); //发送请求 $request_result = $this->httpPost($data_content, $config['url']); // var_dump($request_result);exit; //解密返回报文 $result_json = json_decode($request_result,true); //用商户私钥解密aes密钥(是由平台随机生成的) $result_aes_key = $this->rsaDecode($result_json['encryptKey'], $private_rsa_key); //用aes密钥解密报文 $decode_content = $this->aesDecode($result_json['encryptData'],$result_aes_key); // var_dump($decode_content);exit; //用平台公钥验签 if($this->verifySign($decode_content, $result_json['signData'], $public_rsa_key)){ $res = json_decode($decode_content,true); // var_dump($res);exit; return $res; } else { //验签失败 throw new \Exception("SICPAY 验签失败"); } } private function aesEncode($data, $aes_key){ $encrypt_data = openssl_encrypt($this->pad($data), "aes-128-ecb", $aes_key, OPENSSL_RAW_DATA | OPENSSL_NO_PADDING); return base64_encode($encrypt_data); } public function aesDecode($data,$aes_key){ $data = base64_decode($data); return openssl_decrypt($data, "aes-128-ecb", $aes_key, OPENSSL_RAW_DATA); } private function rsaEncode($data, $public_rsa_key){ $ret = false; // if (!self::_checkPadding(OPENSSL_PKCS1_PADDING, 'en')){ // return 'padding error'; // } $key = openssl_get_publickey($public_rsa_key); if (openssl_public_encrypt($data,$result,$key,OPENSSL_PKCS1_PADDING)){ $ret = base64_encode($result); } return $ret; } private function rsaDecode($data, $private_rsa_key){ $ret = false; $data = base64_decode($data); if ($data !== false){ if (openssl_private_decrypt($data, $result, $private_rsa_key, OPENSSL_PKCS1_PADDING)){ $ret = $result; } } return $ret; } private function rsaSign($data, $private_rsa_key) { $res = openssl_get_privatekey ($private_rsa_key); openssl_sign($data,$sign, $res); openssl_free_key($res); $sign = base64_encode($sign); return $sign; } private function verifySign($data, $signData, $public_rsa_key){ $signData =base64_decode($signData); $res = openssl_get_publickey($public_rsa_key); $result = openssl_verify($data, $signData, $res); openssl_free_key($res); if($result === 1){ return true; } else { return false; } } private function httpPost($data,$url){ $ch = curl_init(); curl_setopt($ch, CURLOPT_HTTPHEADER, array('Content-type: application/json')); curl_setopt($ch,CURLOPT_TIMEOUT,600); curl_setopt($ch,CURLOPT_URL,$url); curl_setopt($ch,CURLOPT_POST,true); curl_setopt($ch,CURLOPT_POSTFIELDS,$data); curl_setopt($ch,CURLOPT_RETURNTRANSFER,true); if (strpos($url, 'https') !== false) { curl_setopt($ch, CURLOPT_SSL_VERIFYHOST, 2); curl_setopt($ch, CURLOPT_SSL_VERIFYPEER, 0); curl_setopt($ch, CURLOPT_SSLVERSION, 1); } $ret_data = trim(curl_exec($ch)); curl_close($ch); return $ret_data; } //获取当前绝对路径 private function getPath(){ return dirname(__FILE__).'/'; } private function randomKeys($length) { $key = ''; $pattern = '1234567890abcdefghijklmnopqrstuvwxyzABCDEFGHIJKLOMNOPQRSTUVWXYZ'; for($i=0;$i<$length;$i++) { $key .= $pattern[mt_rand(0,35)]; //生成php随机数 } return $key; } private function pad($data, $blocksize = 16) { $pad = $blocksize - (strlen($data) % $blocksize); return $data . str_repeat(chr($pad), $pad); } // 异步解压 //1. 将encryptKey做base64解密,然后使⽤merRsaPrivateKey进⾏RSA解密,得到rootAesKey //2. 将encryptData做base64解密,然后使⽤rootAesKey进⾏AES解密,得到业务报⽂ //3. 将signData做base64解密,然后与rootRsaPublicKey、业务报⽂共同进⾏SHA1WithRSA验签 public function notifyDecodeData($config,$result_json){ //用商户私钥解密aes密钥(是由平台随机生成的) $result_aes_key = $this->rsaDecode($result_json['encryptKey'], $config['merRsaPrivateKey']); //用aes密钥解密报文 $decode_content = $this->aesDecode($result_json['encryptData'],$result_aes_key); //用平台公钥验签 if($this->verifySign($decode_content, $result_json['signData'], $config['rootRsaPublicKey'])){ return json_decode($decode_content,true); } else { //验签失败 throw new \Exception("SICPAY 验签失败"); } } }