SM2 cross-framework compatibility implementation method based on adapter mode
Through the adapter mode, the decryption failure problem caused by the differences in SM2 encryption structure between different departments is solved, and the automatic reconstruction of encrypted data across frameworks is realized, which simplifies development and deployment, and improves the success rate of decryption and system performance.
Patent Information
- Application Number
- CN202510603448.0
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-05-12
- Publication Date
- 2025-08-22
AI Technical Summary
Because the SM2 encryption system of different departments adopts different encryption structures, the electronic certificates need to be specially written and adapted when transmitting and identifying them between different departments, which increases the difficulty and cost of development.
Adapter mode is adopted to analyze, reconstruct and decrypt the encrypted data through the collaborative work of the data sender and the receiver to ensure the consistency of the data structure, including data encapsulation, disassembly, reconstruction and decryption processes, and use the standard encryption method and interface specifications of the SM2 algorithm for data transmission.
It realizes automatic reconstruction of encrypted data across frameworks, reduces development workload, improves decryption success rate, saves resources, simplifies the project deployment process, and improves system performance and decryption speed.
Smart Images

Figure CN120528637A_ABST
Abstract
Description
Technical Field
[0001] The invention discloses an SM2 cross-frame compatibility implementation method based on an adapter mode, and relates to the technical field of password management. Background Art
[0002] During the standardization process of the SM2 encryption algorithm, the differences between the two ciphertext structures (C1C2C3 and C1C3C2) stem from different stages of technical specification evolution. This is due to differences in SM2 encryption and decryption methods between the software libraries used by third-party systems and local systems, which can lead to issues. The different SM2 ciphertext structure standards mean that the encryption systems of various departments differ in their technical implementations. This requires specialized code development and system adaptation for each encryption structure to ensure the proper transmission and recognition of electronic certificates between different departments. This not only increases the development workload and difficulty, but also potentially requires increased human, material, and time costs. Summary of the Invention
[0003] In response to the problems of the prior art, the present invention provides an SM2 cross-framework compatibility implementation method based on the adapter mode, which is suitable for scenarios such as government service platforms and financial payment systems that need to simultaneously connect to multiple national encryption algorithm implementation libraries.
[0004] The specific scheme proposed by the present invention is:
[0005] The present invention provides a method for implementing SM2 cross-frame compatibility based on an adapter mode, comprising:
[0006] Step 1: The data sender encrypts the data to be transmitted based on the SM2 standard encryption method and sends the data to the receiver in accordance with the receiver's interface specification.
[0007] Step 2: After the receiver obtains the data sent by the sender, it first parses the data to obtain the encrypted data and determines whether the encrypted data is consistent with the structure used in the local SM2 algorithm. If it is consistent with the structure of the local SM2 algorithm, it directly decrypts it to obtain the plaintext.
[0008] If they are inconsistent, the encrypted data will be disassembled and reconstructed: replace the first two characters of the encrypted data with 04, then intercept the first segment of data as C1 according to the key length, intercept 64 characters of the data after intercepting C1 as C3, and use the remaining data as C2, and reconstruct the encrypted data in the order of C1C2C3.
[0009] Step 3: Decrypt the reconstructed data.
[0010] Furthermore, in step 1 of the method for implementing SM2 cross-frame compatibility based on the adapter pattern, the request header and request body format are encapsulated by the data sender, wherein the structure identifier of SM2 is encapsulated in the request header, and the encapsulation format in the request body is based on the specifications provided by the data receiver.
[0011] Furthermore, in step 1 of the method for implementing SM2 cross-frame compatibility based on the adapter mode, it is determined whether the data is sent successfully. If so, the receiver obtains the data; otherwise, the interface call fails and enters the exception handling process.
[0012] Furthermore, the first segment of data C1 intercepted in step 2 of the adapter-based SM2 cross-framework compatibility implementation method is used as the elliptic curve point coordinates, and the intercepted 64 characters are used as the hash value C3 generated by SM3, and C3 is used as the basis for the recipient to verify whether the data has been tampered with.
[0013] The present invention also provides an SM2 cross-frame compatibility implementation device based on the adapter mode, including an encryption module, a sending module, a parsing module, a judgment module, a reconstruction module and a decryption module.
[0014] The data sender encrypts the data to be transmitted based on the SM2 standard encryption method through the encryption module, and sends the data to the receiver through the sending module according to the receiver's interface specification.
[0015] After the receiver obtains the data sent by the data sender through the parsing module, it first parses the data to obtain the encrypted data, and then uses the judgment module to determine whether the encrypted data is consistent with the structure used in the local SM2 algorithm. If it is consistent with the local SM2 algorithm structure, it will directly decrypt and obtain the plaintext.
[0016] If they are inconsistent, the reconstruction module will disassemble and reconstruct the encrypted data: replace the first two characters of the encrypted data with 04, then intercept the first segment of data as C1 according to the key length, intercept 64 characters of the data after intercepting C1 as C3, and use the remaining data as C2, and reconstruct the encrypted data in the order of C1C2C3.
[0017] The decryption module decrypts the reconstructed data.
[0018] Furthermore, the data sender of the SM2 cross-frame compatibility implementation device based on the adapter mode encapsulates the request header and request body format through an encryption module, wherein the request header encapsulates the SM2 structure identifier, and the encapsulation format in the request body is based on the specifications provided by the data receiver.
[0019] Furthermore, the sending module of the SM2 cross-frame compatibility implementation device based on the adapter mode determines whether the data is sent successfully. If so, the receiver obtains the data; otherwise, the interface call fails and enters the exception handling process.
[0020] Furthermore, the reconstruction module of the SM2 cross-framework compatibility implementation device based on the adapter mode intercepts the first segment of data C1 as the coordinates of the elliptic curve point, and the intercepted 64 characters are used as the hash value C3 generated by SM3, and C3 is used as the basis for the recipient to verify whether the data has been tampered with.
[0021] The benefits of the present invention are:
[0022] The SM2 encrypted data reconstruction process of the present invention can automatically select whether to reconstruct the encrypted data according to different encryption structures, effectively solving the problem of decryption failure caused by docking different platforms in the service field, mainly due to the following beneficial effects:
[0023] The encrypted data reconstruction method is simple to use and has a high decryption success rate. In actual use, the corresponding reconstruction operation can be completed by simply calling the relevant modules, which can reduce the workload of developers.
[0024] Compared with the method of using middleware to decrypt data with structural conflicts, the reconstruction method used in this paper does not require the use of additional server resources and decrypts the data directly in the original program, reducing the waste of resources and decryption failures caused by network fluctuations and other reasons, and improving the success rate of decryption.
[0025] During the actual application of the service platform, projects in different regions need to be connected with different third parties. During the connection process, they need to use the software libraries provided by the third party for encryption and decryption. A large part of the code in some of these software libraries is repeated, which leads to the bloated program and increases the difficulty of deploying projects in different regions. The method provided by this patent reduces the need to add software libraries provided by third parties during the connection process, which is conducive to the project deployment system.
[0026] The reconstruction method based on ciphertext strings has a fast processing speed, saves the time required in large-scale concurrent calls, and improves the overall performance of the system. BRIEF DESCRIPTION OF THE DRAWINGS
[0027] Figure 1 It is a schematic flow chart of the method of the present invention.
[0028] Figure 2 It is a schematic diagram of the reconstruction process. DETAILED DESCRIPTION
[0029] The present invention will be further described below with reference to the accompanying drawings and specific embodiments so that those skilled in the art can better understand the present invention and implement it. However, the embodiments are not intended to limit the present invention.
[0030] Example 1
[0031] The present invention provides a method for implementing SM2 cross-frame compatibility based on an adapter mode, comprising:
[0032] Step 1: The data sender encrypts the data to be transmitted based on the standard encryption method of SM2 and sends the data to the receiver in accordance with the receiver's interface specification.
[0033] In step 1, the data sender encapsulates the request header and the request body format, wherein the request header encapsulates the structure identifier of SM2, and the encapsulation format in the request body is based on the specification provided by the data receiver.
[0034] In addition, it is determined whether the data is sent successfully. If so, the receiver obtains the data. Otherwise, the interface call fails and enters the exception handling process.
[0035] Step 2: After the receiver obtains the data sent by the sender, it first parses the data to obtain the encrypted data and determines whether the encrypted data is consistent with the structure used in the local SM2 algorithm. If it is consistent with the structure of the local SM2 algorithm, it directly decrypts it to obtain the plaintext.
[0036] If there is any inconsistency, the encrypted data is disassembled and reconstructed: the first two characters of the encrypted data are replaced with 04, and then the first segment of data is intercepted as C1 according to the key length. After intercepting C1, 64 characters are intercepted as C3, and the remaining data is used as C2. The encrypted data is reconstructed in the order of C1C2C3. For the obtained encrypted string data, the intercepted first segment of data C1 is used as the coordinates of the elliptic curve point, and the intercepted 64 characters are used as the hash value C3 generated by SM3. C3 is used as the basis for the recipient to verify whether the data has been tampered with. The remaining data is used as the encrypted data C2, and its length is the same as the length of the string in the plaintext. After determining the structure that needs to be converted, C1, C2 and C3 are reconstructed in sequence, and the reassembled encrypted data is converted into a byte array and then decrypted.
[0037] Step 3: Decrypt the reconstructed data.
[0038] The present invention solves the problem of data message decryption failure caused by different encryption structures when using the SM2 algorithm for data encryption in different framework systems. The data of C1C3C2 is reconstructed into C1C2C3 by parsing and reconstructing the encrypted data.
[0039] This method can adaptively switch the encryption structure: the structure of the encrypted data is determined by the identifier carried by the Content-Type field, and adaptive structure conversion is performed based on this;
[0040] De-library processing: Directly operate on ciphertext strings and byte streams without adding dependent libraries used by third-party systems. This reduces system startup failures or data decryption failures caused by dependency conflicts, and further alleviates the problem of code bloat caused by too many dependencies in the overall system.
[0041] Resource Conservation: No need to redeploy the middleware system to provide the decryption interface, reducing server resource waste, performance loss during interface calls, and related issues caused by network fluctuations.
[0042] Seamless processing: During the docking process, the docking technicians do not need to perform any other operations. The module automatically parses and reconstructs the encrypted data. The user does not need to perform any other operations, and it is transparent to the user.
[0043] Example 2
[0044] The present invention also provides an SM2 cross-frame compatibility implementation device based on the adapter mode, including an encryption module, a sending module, a parsing module, a judgment module, a reconstruction module and a decryption module.
[0045] The data sender encrypts the data to be transmitted based on the SM2 standard encryption method through the encryption module, and sends the data to the receiver through the sending module according to the receiver's interface specification.
[0046] After the receiver obtains the data sent by the data sender through the parsing module, it first parses the data to obtain the encrypted data, and then uses the judgment module to determine whether the encrypted data is consistent with the structure used in the local SM2 algorithm. If it is consistent with the local SM2 algorithm structure, it will directly decrypt and obtain the plaintext.
[0047] If they are inconsistent, the reconstruction module will disassemble and reconstruct the encrypted data: replace the first two characters of the encrypted data with 04, then intercept the first segment of data as C1 according to the key length, intercept 64 characters of the data after intercepting C1 as C3, and use the remaining data as C2, and reconstruct the encrypted data in the order of C1C2C3.
[0048] The decryption module decrypts the reconstructed data.
[0049] Since the information interaction, execution process and other contents between the modules in the above-mentioned device are based on the same concept as the embodiment of the method of the present invention, the specific contents can be found in the description of the embodiment of the method of the present invention and will not be repeated here.
[0050] Similarly, the device of the present invention can automatically select whether to reconstruct the encrypted data according to different encryption structures, effectively solving the problem of decryption failure caused by docking different platforms in the service field, mainly due to the following beneficial effects:
[0051] The encrypted data reconstruction method is simple to use and has a high decryption success rate. In actual use, the corresponding reconstruction operation can be completed by simply calling the relevant modules, which can reduce the workload of developers.
[0052] Compared with the method of using middleware to decrypt data with structural conflicts, the reconstruction method used in this paper does not require the use of additional server resources and decrypts the data directly in the original program, reducing the waste of resources and decryption failures caused by network fluctuations and other reasons, and improving the success rate of decryption.
[0053] During the actual application of the service platform, projects in different regions need to be connected with different third parties. During the connection process, they need to use the software libraries provided by the third party for encryption and decryption. A large part of the code in some of these software libraries is repeated, which leads to the bloated program and increases the difficulty of deploying projects in different regions. The method provided by this patent reduces the need to add software libraries provided by third parties during the connection process, which is conducive to the project deployment system.
[0054] The reconstruction method based on ciphertext strings has a fast processing speed, saves the time required in large-scale concurrent calls, and improves the overall performance of the system.
[0055] It should be noted that not all steps and modules in the above-mentioned processes and device structures are required, and certain steps or modules can be omitted according to actual needs. The execution order of each step is not fixed and can be adjusted as needed. The system structure described in the above-mentioned embodiments can be a physical structure or a logical structure, that is, some modules may be implemented by the same physical entity, or some modules may be implemented by multiple physical entities, or may be implemented by certain components in multiple independent devices.
[0056] The above embodiments are merely preferred embodiments for the purpose of fully illustrating the present invention, and the scope of protection of the present invention is not limited thereto. Equivalent substitutions or modifications made by those skilled in the art based on the present invention are within the scope of protection of the present invention. The scope of protection of the present invention shall be subject to the claims.
Claims
1. A method for implementing SM2 cross-frame compatibility based on adapter mode, characterized by: include: Step 1: The data sender encrypts the data to be transmitted based on the SM2 standard encryption method and sends the data to the receiver in accordance with the receiver's interface specification. Step 2: After the receiver obtains the data sent by the sender, it first parses the data to obtain the encrypted data and determines whether the encrypted data is consistent with the structure used in the local SM2 algorithm. If it is consistent with the structure of the local SM2 algorithm, it directly decrypts it to obtain the plaintext. If they are inconsistent, the encrypted data will be disassembled and reconstructed: replace the first two characters of the encrypted data with 04, then intercept the first segment of data as C1 according to the key length, intercept 64 characters of the data after intercepting C1 as C3, and use the remaining data as C2, and reconstruct the encrypted data in the order of C1C2C3. Step 3: Decrypt the reconstructed data.
2. According to the method for implementing SM2 cross-frame compatibility based on the adapter mode in claim 1, it is characterized in that in step 1, the request header and request body format are encapsulated by the data sender, wherein the request header encapsulates the SM2 structure identifier, and the encapsulation format in the request body is based on the specifications provided by the data receiver.
3. The method for implementing SM2 cross-frame compatibility based on the adapter mode according to claim 1, characterized in that In step 1, it is determined whether the data is sent successfully. If so, the receiver obtains the data. Otherwise, the interface call fails and enters the exception handling process.
4. The method for implementing SM2 cross-frame compatibility based on the adapter mode according to claim 1, characterized in that The first segment of data C1 intercepted in step 2 is used as the coordinates of the elliptic curve point, and the intercepted 64 characters are used as the hash value C3 generated by SM3. C3 is used as the basis for the recipient to verify whether the data has been tampered with.
5. An SM2 cross-frame compatibility implementation device based on adapter mode, characterized by Including encryption module, sending module, parsing module, judgment module, reconstruction module and decryption module, The data sender encrypts the data to be transmitted based on the SM2 standard encryption method through the encryption module, and sends the data to the receiver through the sending module according to the receiver's interface specification. After the receiver obtains the data sent by the data sender through the parsing module, it first parses the data to obtain the encrypted data, and then uses the judgment module to determine whether the encrypted data is consistent with the structure used in the local SM2 algorithm. If it is consistent with the local SM2 algorithm structure, it will directly decrypt and obtain the plaintext. If they are inconsistent, the reconstruction module will disassemble and reconstruct the encrypted data: replace the first two characters of the encrypted data with 04, then intercept the first segment of data as C1 according to the key length, intercept 64 characters of the data after intercepting C1 as C3, and use the remaining data as C2, and reconstruct the encrypted data in the order of C1C2C3. The decryption module decrypts the reconstructed data.
6. The device for realizing SM2 cross-frame compatibility based on adapter mode according to claim 5, characterized in that The data sender encapsulates the request header and request body format through the encryption module, where the request header encapsulates the SM2 structure identifier, and the encapsulation format in the request body is based on the specifications provided by the data receiver.
7. The device for realizing SM2 cross-frame compatibility based on adapter mode according to claim 5, characterized in that The sending module determines whether the data is sent successfully. If so, the receiver obtains the data. Otherwise, the interface call fails and enters the exception handling process.
8. The device for realizing SM2 cross-frame compatibility based on adapter mode according to claim 5, characterized in that The reconstruction module intercepts the first segment of data C1 as the coordinates of the elliptic curve point, and the intercepted 64 characters are used as the hash value C3 generated by SM3. C3 is used as the basis for the receiver to verify whether the data has been tampered with.
Citation Information
Patent Citations
Communication method capable of being decrypted by sender, receiver and supervisor
CN117527226A