cms.h 22 KB


  1. /*
  2. * Copyright 2014-2022 The GmSSL Project. All Rights Reserved.
  3. *
  4. * Licensed under the Apache License, Version 2.0 (the License); you may
  5. * not use this file except in compliance with the License.
  6. *
  7. * http://www.apache.org/licenses/LICENSE-2.0
  8. */
  9. /*
  10. References:
  11. 1. GM/T 0010-2012 SM2 Cryptography Message Syntax Specification
  12. 2. RFC 2315 PKCS #7 Cryptographic Message Syntax Version 1.5
  13. 3. RFC 5652 Cryptographic Message Syntax (CMS)
  14. */
  15. #ifndef GMSSL_CMS_H
  16. #define GMSSL_CMS_H
  17. #include <string.h>
  18. #include <stdint.h>
  19. #include <sys/types.h>
  20. #include <gmssl/x509.h>
  21. #ifdef __cplusplus
  22. extern "C" {
  23. #endif
  24. enum {
  25. CMS_version_v1 = 1,
  26. };
  27. /*
  28. ContentType:
  29. OID_cms_data
  30. OID_cms_signed_data
  31. OID_cms_enveloped_data
  32. OID_cms_signed_and_enveloped_data
  33. OID_cms_encrypted_data
  34. OID_cms_key_agreement_info
  35. */
  36. const char *cms_content_type_name(int oid);
  37. int cms_content_type_from_name(const char *name);
  38. int cms_content_type_to_der(int oid, uint8_t **out, size_t *outlen);
  39. int cms_content_type_from_der(int *oid, const uint8_t **in, size_t *inlen);
  40. /*
  41. ContentInfo ::= SEQUENCE {
  42. contentType OBJECT IDENTIFIER,
  43. content [0] EXPLICIT ANY OPTIONAL }
  44. */
  45. int cms_content_info_header_to_der(
  46. int content_type, size_t content_len,
  47. uint8_t **out, size_t *outlen);
  48. int cms_content_info_to_der(
  49. int content_type,
  50. const uint8_t *content, size_t content_len,
  51. uint8_t **out, size_t *outlen);
  52. int cms_content_info_from_der(
  53. int *content_type,
  54. const uint8_t **content, size_t *content_len, // 这里获得的是完整的TLV
  55. const uint8_t **in, size_t *inlen);
  56. int cms_content_info_print(FILE *fp, int fmt, int ind, const char *label, const uint8_t *d, size_t dlen);
  57. /*
  58. Data ::= OCTET STRING
  59. */
  60. #define cms_data_to_der(d,dlen,out,outlen) asn1_octet_string_to_der(d,dlen,out,outlen)
  61. #define cms_data_from_der(d,dlen,in,inlen) asn1_octet_string_from_der(d,dlen,in,inlen)
  62. #define cms_data_print(fp,fmt,ind,label,d,dlen) format_bytes(fp,fmt,ind,label,d,dlen)
  63. /*
  64. EncryptedContentInfo ::= SEQUENCE {
  65. contentType OBJECT IDENTIFIER,
  66. contentEncryptionAlgorithm AlgorithmIdentifier,
  67. encryptedContent [0] IMPLICIT OCTET STRING OPTIONAL,
  68. sharedInfo1 [1] IMPLICIT OCTET STRING OPTIONAL,
  69. sharedInfo2 [2] IMPLICIT OCTET STRING OPTIONAL }
  70. */
  71. int cms_enced_content_info_to_der(
  72. int content_type,
  73. int enc_algor, const uint8_t *enc_iv, size_t enc_iv_len,
  74. const uint8_t *enced_content, size_t enced_content_len,
  75. const uint8_t *shared_info1, size_t shared_info1_len,
  76. const uint8_t *shared_info2, size_t shared_info2_len,
  77. uint8_t **out, size_t *outlen);
  78. int cms_enced_content_info_from_der(
  79. int *content_type,
  80. int *enc_algor, const uint8_t **enc_iv, size_t *enc_iv_len,
  81. const uint8_t **enced_content, size_t *enced_content_len,
  82. const uint8_t **shared_info1, size_t *shared_info1_len,
  83. const uint8_t **shared_info2, size_t *shared_info2_len,
  84. const uint8_t **in, size_t *inlen);
  85. int cms_enced_content_info_print(FILE *fp, int fmt, int ind, const char *label, const uint8_t *d, size_t dlen);
  86. int cms_enced_content_info_encrypt_to_der(
  87. int enc_algor,
  88. const uint8_t *key, size_t keylen,
  89. const uint8_t *iv, size_t ivlen,
  90. int content_type, const uint8_t *content, size_t content_len,
  91. const uint8_t *shared_info1, size_t shared_info1_len,
  92. const uint8_t *shared_info2, size_t shared_info2_len,
  93. uint8_t **out, size_t *outlen);
  94. int cms_enced_content_info_decrypt_from_der(
  95. int *enc_algor,
  96. const uint8_t *key, size_t keylen,
  97. int *content_type, uint8_t *content, size_t *content_len,
  98. const uint8_t **shared_info1, size_t *shared_info1_len,
  99. const uint8_t **shared_info2, size_t *shared_info2_len,
  100. const uint8_t **in, size_t *inlen);
  101. /*
  102. EncryptedData ::= SEQUENCE {
  103. version INTEGER (1),
  104. encryptedContentInfo EncryptedContentInfo }
  105. */
  106. int cms_encrypted_data_to_der(
  107. int version,
  108. int content_type,
  109. int enc_algor, const uint8_t *iv, size_t ivlen,
  110. const uint8_t *enced_content, size_t enced_content_len,
  111. const uint8_t *shared_info1, size_t shared_info1_len,
  112. const uint8_t *shared_info2, size_t shared_info2_len,
  113. uint8_t **out, size_t *outlen);
  114. int cms_encrypted_data_from_der(
  115. int *version,
  116. int *content_type,
  117. int *enc_algor, const uint8_t **iv, size_t *ivlen,
  118. const uint8_t **enced_content, size_t *enced_content_len,
  119. const uint8_t **shared_info1, size_t *shared_info1_len,
  120. const uint8_t **shared_info2, size_t *shared_info2_len,
  121. const uint8_t **in, size_t *inlen);
  122. int cms_encrypted_data_print(FILE *fp, int fmt, int ind, const char *label, const uint8_t *d, size_t dlen);
  123. int cms_encrypted_data_encrypt_to_der(
  124. int enc_algor,
  125. const uint8_t *key, size_t keylen,
  126. const uint8_t *iv, size_t ivlen,
  127. int content_type, const uint8_t *content, size_t content_len,
  128. const uint8_t *shared_info1, size_t shared_info1_len,
  129. const uint8_t *shared_info2, size_t shared_info2_len,
  130. uint8_t **out, size_t *outlen);
  131. int cms_encrypted_data_decrypt_from_der(
  132. int *enc_algor,
  133. const uint8_t *key, size_t keylen,
  134. int *content_type, uint8_t *content, size_t *content_len,
  135. const uint8_t **shared_info1, size_t *shared_info1_len,
  136. const uint8_t **shared_info2, size_t *shared_info2_len,
  137. const uint8_t **in, size_t *inlen);
  138. /*
  139. IssuerAndSerialNumber ::= SEQUENCE {
  140. isser Name,
  141. serialNumber INTEGER }
  142. */
  143. int cms_issuer_and_serial_number_to_der(
  144. const uint8_t *issuer, size_t issuer_len,
  145. const uint8_t *serial_number, size_t serial_number_len,
  146. uint8_t **out, size_t *outlen);
  147. int cms_issuer_and_serial_number_from_der(
  148. const uint8_t **issuer, size_t *issuer_len,
  149. const uint8_t **serial_number, size_t *serial_number_len,
  150. const uint8_t **in, size_t *inlen);
  151. int cms_issuer_and_serial_number_print(FILE *fp, int fmt, int ind, const char *label, const uint8_t *d, size_t dlen);
  152. /*
  153. SignerInfo ::= SEQUENCE {
  154. version INTEGER (1),
  155. issuerAndSerialNumber IssuerAndSerialNumber,
  156. digestAlgorithm AlgorithmIdentifier,
  157. authenticatedAttributes [0] IMPLICIT SET OF Attribute OPTINOAL,
  158. digestEncryptionAlgorithm AlgorithmIdentifier,
  159. encryptedDigest OCTET STRING,
  160. unauthenticatedAttributes [1] IMPLICIT SET OF Attribute OPTINOAL, }
  161. */
  162. int cms_signer_info_to_der(
  163. int version,
  164. const uint8_t *issuer, size_t issuer_len,
  165. const uint8_t *serial_number, size_t serial_number_len,
  166. int digest_algor,
  167. const uint8_t *authed_attrs, size_t authed_attrs_len,
  168. int signature_algor,
  169. const uint8_t *enced_digest, size_t enced_digest_len,
  170. const uint8_t *unauthed_attrs, size_t unauthed_attrs_len,
  171. uint8_t **out, size_t *outlen);
  172. int cms_signer_info_from_der(
  173. int *version,
  174. const uint8_t **issuer, size_t *issuer_len,
  175. const uint8_t **serial_number, size_t *serial_number_len,
  176. int *digest_algor,
  177. const uint8_t **authed_attrs, size_t *authed_attrs_len,
  178. int *signature_algor,
  179. const uint8_t **enced_digest, size_t *enced_digest_len,
  180. const uint8_t **unauthed_attrs, size_t *unauthed_attrs_len,
  181. const uint8_t **in, size_t *inlen);
  182. int cms_signer_info_print(FILE *fp, int fmt, int ind, const char *label, const uint8_t *d, size_t dlen);
  183. int cms_signer_info_sign_to_der(
  184. const SM3_CTX *sm3_ctx, const SM2_KEY *sm2_key,
  185. const uint8_t *issuer, size_t issuer_len,
  186. const uint8_t *serial_number, size_t serial_number_len,
  187. const uint8_t *authed_attrs, size_t authed_attrs_len,
  188. const uint8_t *unauthed_attrs, size_t unauthed_attrs_len,
  189. uint8_t **out, size_t *outlen);
  190. int cms_signer_info_verify_from_der(
  191. const SM3_CTX *sm3_ctx, const uint8_t *certs, size_t certslen,
  192. const uint8_t **cert, size_t *certlen,
  193. const uint8_t **issuer, size_t *issuer_len,
  194. const uint8_t **serial, size_t *serial_len,
  195. const uint8_t **authed_attrs, size_t *authed_attrs_len,
  196. const uint8_t **unauthed_attrs, size_t *unauthed_attrs_len,
  197. const uint8_t **in, size_t *inlen);
  198. /*
  199. SignerInfos ::= SET OF SignerInfo;
  200. */
  201. int cms_signer_infos_add_signer_info(
  202. uint8_t *d, size_t *dlen, size_t maxlen,
  203. const SM3_CTX *sm3_ctx, const SM2_KEY *sign_key,
  204. const uint8_t *issuer, size_t issuer_len,
  205. const uint8_t *serial_number, size_t serial_number_len,
  206. const uint8_t *authed_attrs, size_t authed_attrs_len,
  207. const uint8_t *unauthed_attrs, size_t unauthed_attrs_len);
  208. #define cms_signer_infos_to_der(d,dlen,out,outlen) asn1_set_to_der(d,dlen,out,outlen)
  209. #define cms_signer_infos_from_der(d,dlen,in,inlen) asn1_set_from_der(d,dlen,in,inlen)
  210. int cms_signer_infos_print(FILE *fp, int fmt, int ind, const char *label, const uint8_t *d, size_t dlen);
  211. int cms_digest_algors_to_der(const int *digest_algors, size_t digest_algors_cnt, uint8_t **out, size_t *outlen);
  212. int cms_digest_algors_from_der(int *digest_algors, size_t *digest_algors_cnt, size_t max_digest_algors,
  213. const uint8_t **in, size_t *inlen);
  214. int cms_digest_algors_print(FILE *fp, int fmt, int ind, const char *label, const uint8_t *d, size_t dlen);
  215. /*
  216. SignedData ::= SEQUENCE {
  217. version INTEGER (1),
  218. digestAlgorithms SET OF AlgorithmIdentifier,
  219. contentInfo ContentInfo,
  220. certificates [0] IMPLICIT SET OF Certificate OPTIONAL,
  221. crls [1] IMPLICIT SET OF CertificateRevocationList OPTIONAL,
  222. signerInfos SET OF SignerInfo }
  223. */
  224. int cms_signed_data_to_der(
  225. int version,
  226. const int *digest_algors, size_t digest_algors_cnt,
  227. const int content_type, const uint8_t *content, const size_t content_len,
  228. const uint8_t *certs, size_t certs_len,
  229. const uint8_t *crls, const size_t crls_len,
  230. const uint8_t *signer_infos, size_t signer_infos_len,
  231. uint8_t **out, size_t *outlen);
  232. int cms_signed_data_from_der(
  233. int *version,
  234. int *digest_algors, size_t *digest_algors_cnt, size_t max_digest_algors,
  235. int *content_type, const uint8_t **content, size_t *content_len,
  236. const uint8_t **certs, size_t *certs_len,
  237. const uint8_t **crls, size_t *crls_len,
  238. const uint8_t **signer_infos, size_t *signer_infos_len,
  239. const uint8_t **in, size_t *inlen);
  240. int cms_signed_data_print(FILE *fp, int fmt, int ind, const char *label, const uint8_t *d, size_t dlen);
  241. typedef struct {
  242. uint8_t *certs;
  243. size_t certs_len;
  244. SM2_KEY *sign_key;
  245. } CMS_CERTS_AND_KEY;
  246. int cms_signed_data_sign_to_der(
  247. const CMS_CERTS_AND_KEY *signers, size_t signers_cnt,
  248. int content_type, const uint8_t *data, size_t datalen, // 当OID_cms_data时为raw data
  249. const uint8_t *crls, size_t crls_len, // 可以为空
  250. uint8_t **out, size_t *outlen);
  251. int cms_signed_data_verify_from_der(
  252. const uint8_t *extra_certs, size_t extra_certs_len,
  253. const uint8_t *extra_crls, size_t extra_crls_len,
  254. int *content_type, const uint8_t **content, size_t *content_len, // 是否应该返回raw data呢?
  255. const uint8_t **certs, size_t *certs_len,
  256. const uint8_t **crls, size_t *crls_len,
  257. const uint8_t **signer_infos, size_t *signer_infos_len,
  258. const uint8_t **in, size_t *inlen);
  259. /*
  260. RecipientInfo ::= SEQUENCE {
  261. version INTEGER (1),
  262. issuerAndSerialNumber IssuerAndSerialNumber,
  263. keyEncryptionAlgorithm AlgorithmIdentifier,
  264. encryptedKey OCTET STRING -- DER-encoding of SM2Cipher
  265. }
  266. 由于encryptedKey的类型为SM2Cipher, 而SM2Cipher中有2个INTEGER,因此长度是不固定的。
  267. 因此不能预先确定输出长度
  268. */
  269. int cms_recipient_info_to_der(
  270. int version,
  271. const uint8_t *issuer, size_t issuer_len,
  272. const uint8_t *serial_number, size_t serial_number_len,
  273. int public_key_enc_algor,
  274. const uint8_t *enced_key, size_t enced_key_len,
  275. uint8_t **out, size_t *outlen);
  276. int cms_recipient_info_from_der(
  277. int *version,
  278. const uint8_t **issuer, size_t *issuer_len,
  279. const uint8_t **serial_number, size_t *serial_number_len,
  280. int *pke_algor, const uint8_t **params, size_t *params_len,// SM2加密只使用SM3,没有默认参数,但是ECIES可能有
  281. const uint8_t **enced_key, size_t *enced_key_len,
  282. const uint8_t **in, size_t *inlen);
  283. int cms_recipient_info_print(FILE *fp, int fmt, int ind, const char *label, const uint8_t *d, size_t dlen);
  284. int cms_recipient_info_encrypt_to_der(
  285. const SM2_KEY *public_key,
  286. const uint8_t *issuer, size_t issuer_len,
  287. const uint8_t *serial, size_t serial_len,
  288. const uint8_t *in, size_t inlen,
  289. uint8_t **out, size_t *outlen);
  290. int cms_recipient_info_decrypt_from_der(
  291. const SM2_KEY *sm2_key,
  292. const uint8_t *rcpt_issuer, size_t rcpt_issuer_len,
  293. const uint8_t *rcpt_serial, size_t rcpt_serial_len,
  294. uint8_t *out, size_t *outlen, size_t maxlen,
  295. const uint8_t **in, size_t *inlen);
  296. int cms_recipient_infos_add_recipient_info(
  297. uint8_t *d, size_t *dlen, size_t maxlen,
  298. const SM2_KEY *public_key,
  299. const uint8_t *issuer, size_t issuer_len,
  300. const uint8_t *serial, size_t serial_len,
  301. const uint8_t *in, size_t inlen);
  302. #define cms_recipient_infos_to_der(d,dlen,out,outlen) asn1_set_to_der(d,dlen,out,outlen)
  303. #define cms_recipient_infos_from_der(d,dlen,in,inlen) asn1_set_from_der(d,dlen,in,inlen)
  304. int cms_recipient_infos_print(FILE *fp, int fmt, int ind, const char *label, const uint8_t *d, size_t dlen);
  305. /*
  306. EnvelopedData ::= SEQUENCE {
  307. version Version,
  308. recipientInfos SET OF RecipientInfo,
  309. encryptedContentInfo EncryptedContentInfo }
  310. */
  311. int cms_enveloped_data_to_der(
  312. int version,
  313. const uint8_t *rcpt_infos, size_t rcpt_infos_len,
  314. int content_type,
  315. int enc_algor, const uint8_t *enc_iv, size_t enc_iv_len,
  316. const uint8_t *enced_content, size_t enced_content_len,
  317. const uint8_t *shared_info1, size_t shared_info1_len,
  318. const uint8_t *shared_info2, size_t shared_info2_len,
  319. uint8_t **out, size_t *outlen);
  320. int cms_enveloped_data_from_der(
  321. int *version,
  322. const uint8_t **rcpt_infos, size_t *rcpt_infos_len,
  323. const uint8_t **enced_content_info, size_t *enced_content_info_len,
  324. const uint8_t **in, size_t *inlen);
  325. int cms_enveloped_data_print(FILE *fp, int fmt, int ind, const char *label, const uint8_t *d, size_t dlen);
  326. int cms_enveloped_data_encrypt_to_der(
  327. const uint8_t *rcpt_certs, size_t rcpt_certs_len,
  328. int enc_algor, const uint8_t *key, size_t keylen, const uint8_t *iv, size_t ivlen,
  329. int content_type, const uint8_t *content, size_t content_len,
  330. const uint8_t *shared_info1, size_t shared_info1_len,
  331. const uint8_t *shared_info2, size_t shared_info2_len,
  332. uint8_t **out, size_t *outlen);
  333. int cms_enveloped_data_decrypt_from_der(
  334. const SM2_KEY *sm2_key,
  335. const uint8_t *issuer, size_t issuer_len,
  336. const uint8_t *serial_number, size_t serial_number_len,
  337. int *content_type, uint8_t *content, size_t *content_len,
  338. const uint8_t **rcpt_infos, size_t *rcpt_infos_len,
  339. const uint8_t **shared_info1, size_t *shared_info1_len,
  340. const uint8_t **shared_info2, size_t *shared_info2_len,
  341. const uint8_t **in, size_t *inlen);
  342. /*
  343. SignedAndEnvelopedData ::= SEQUENCE {
  344. version INTEGER (1),
  345. recipientInfos SET OF RecipientInfo,
  346. digestAlgorithms SET OF AlgorithmIdentifier,
  347. encryptedContentInfo EncryptedContentInfo,
  348. certificates [0] IMPLICIT SET OF Certificate OPTIONAL,
  349. crls [1] IMPLICIT SET OF CertificateRevocationList OPTIONAL,
  350. signerInfos SET OF SignerInfo }
  351. */
  352. int cms_signed_and_enveloped_data_to_der(
  353. int version,
  354. const uint8_t *rcpt_infos, size_t rcpt_infos_len,
  355. const int *digest_algors, size_t digest_algors_cnt,
  356. int content_type,
  357. int enc_algor, const uint8_t *iv, size_t ivlen,
  358. const uint8_t *enced_content, size_t enced_content_len,
  359. const uint8_t *shared_info1, size_t shared_info1_len,
  360. const uint8_t *shared_info2, size_t shared_info2_len,
  361. const uint8_t *certs, size_t certs_len,
  362. const uint8_t *crls, size_t crls_len,
  363. const uint8_t *signer_infos, size_t signer_infos_len,
  364. uint8_t **out, size_t *outlen);
  365. int cms_signed_and_enveloped_data_from_der(
  366. int *version,
  367. const uint8_t **rcpt_infos, size_t *rcpt_infos_len,
  368. int *digest_algors, size_t *digest_algors_cnt, size_t max_digest_algors,
  369. const uint8_t **enced_content_info, size_t *enced_content_info_len,
  370. const uint8_t **certs, size_t *certs_len,
  371. const uint8_t **crls, size_t *crls_len,
  372. const uint8_t **signer_infos, size_t *signer_infos_len,
  373. const uint8_t **in, size_t *inlen);
  374. int cms_signed_and_enveloped_data_print(FILE *fp, int fmt, int ind, const char *label, const uint8_t *d, size_t dlen);
  375. int cms_signed_and_enveloped_data_encipher_to_der(
  376. const CMS_CERTS_AND_KEY *signers, size_t signers_cnt,
  377. const uint8_t *rcpt_certs, size_t rcpt_certs_len,
  378. int enc_algor, const uint8_t *key, size_t keylen, const uint8_t *iv, size_t ivlen,
  379. int content_type, const uint8_t *content, size_t content_len,
  380. const uint8_t *signers_crls, size_t signers_crls_len,
  381. const uint8_t *shared_info1, size_t shared_info1_len,
  382. const uint8_t *shared_info2, size_t shared_info2_len,
  383. uint8_t **out, size_t *outlen);
  384. int cms_signed_and_enveloped_data_decipher_from_der(
  385. const SM2_KEY *rcpt_key,
  386. const uint8_t *rcpt_issuer, size_t rcpt_issuer_len,
  387. const uint8_t *rcpt_serial, size_t rcpt_serial_len,
  388. int *content_type, uint8_t *content, size_t *content_len,
  389. const uint8_t **prcpt_infos, size_t *prcpt_infos_len,
  390. const uint8_t **shared_info1, size_t *shared_info1_len,
  391. const uint8_t **shared_info2, size_t *shared_info2_len,
  392. const uint8_t **certs, size_t *certs_len,
  393. const uint8_t **crls, size_t *crls_len,
  394. const uint8_t **psigner_infos, size_t *psigner_infos_len,
  395. const uint8_t *extra_certs, size_t extra_certs_len,
  396. const uint8_t *extra_crls, size_t extra_crls_len,
  397. const uint8_t **in, size_t *inlen);
  398. /*
  399. KeyAgreementInfo ::= SEQUENCE {
  400. version INTEGER (1),
  401. tempPublicKeyR SM2PublicKey,
  402. userCertificate Certificate,
  403. userID OCTET STRING }
  404. */
  405. int cms_key_agreement_info_to_der(
  406. int version,
  407. const SM2_KEY *temp_public_key_r,
  408. const uint8_t *user_cert, size_t user_cert_len,
  409. const uint8_t *user_id, size_t user_id_len,
  410. uint8_t **out, size_t *outlen);
  411. int cms_key_agreement_info_from_der(
  412. int *version,
  413. SM2_KEY *temp_public_key_r,
  414. const uint8_t **user_cert, size_t *user_cert_len,
  415. const uint8_t **user_id, size_t *user_id_len,
  416. const uint8_t **in, size_t *inlen);
  417. int cms_key_agreement_info_print(FILE *fp, int fmt, int ind, const char *label, const uint8_t *d, size_t dlen);
  418. // 下面是公开API
  419. // 公开API的设计考虑:
  420. // 1. 不需要调用其他函数
  421. // 2. 在逻辑上容易理解
  422. // 3. 将cms,cmslen看做对象
  423. // 生成ContentInfo, type == data
  424. int cms_set_data(uint8_t *cms, size_t *cmslen,
  425. const uint8_t *d, size_t dlen);
  426. int cms_encrypt(
  427. uint8_t *cms, size_t *cmslen, // 输出的ContentInfo (type encryptedData)
  428. int enc_algor, const uint8_t *key, size_t keylen, const uint8_t *iv, size_t ivlen, // 对称加密算法、密钥和IV
  429. int content_type, const uint8_t *content, size_t content_len, // 待加密的输入数据
  430. const uint8_t *shared_info1, size_t shared_info1_len, // 附加信息
  431. const uint8_t *shared_info2, size_t shared_info2_len);
  432. int cms_decrypt(
  433. const uint8_t *cms, size_t cmslen, // 输入的ContentInfo (type encryptedData)
  434. int *enc_algor, const uint8_t *key, size_t keylen, // 解密密钥(我们不知道解密算法)
  435. int *content_type, uint8_t *content, size_t *content_len, // 输出的解密数据类型及数据
  436. const uint8_t **shared_info1, size_t *shared_info1_len, // 附加信息
  437. const uint8_t **shared_info2, size_t *shared_info2_len);
  438. int cms_sign(
  439. uint8_t *cms, size_t *cms_len,
  440. const CMS_CERTS_AND_KEY *signers, size_t signers_cnt, // 签名者的签名私钥和证书
  441. int content_type, const uint8_t *content, size_t content_len, // 待签名的输入数据
  442. const uint8_t *crls, size_t crls_len);
  443. int cms_verify(
  444. const uint8_t *cms, size_t cms_len,
  445. const uint8_t *extra_certs, size_t extra_certs_len,
  446. const uint8_t *extra_crls, size_t extra_crls_len,
  447. int *content_type, const uint8_t **content, size_t *content_len,
  448. const uint8_t **certs, size_t *certs_len,
  449. const uint8_t **crls, size_t *crls_len,
  450. const uint8_t **signer_infos, size_t *signer_infos_len);
  451. int cms_envelop(
  452. uint8_t *cms, size_t *cms_len,
  453. const uint8_t *rcpt_certs, size_t rcpt_certs_len, // 接收方证书,注意这个参数的类型可以容纳多个证书,但是只有在一个接受者时对调用方最方便
  454. int enc_algor, const uint8_t *key, size_t keylen, const uint8_t *iv, size_t ivlen, // 对称加密算法及参数
  455. int content_type, const uint8_t *content, size_t content_len, // 待加密的输入数据
  456. const uint8_t *shared_info1, size_t shared_info1_len, // 附加输入信息
  457. const uint8_t *shared_info2, size_t shared_info2_len);
  458. int cms_deenvelop(
  459. const uint8_t *cms, size_t cms_len,
  460. const SM2_KEY *rcpt_key, const uint8_t *rcpt_cert, size_t rcpt_cert_len, // 接收方的解密私钥和对应的证书,注意只需要一个解密方
  461. int *content_type, uint8_t *content, size_t *content_len,
  462. const uint8_t **rcpt_infos, size_t *rcpt_infos_len, // 解析得到,用于显示
  463. const uint8_t **shared_info1, size_t *shared_info1_len,
  464. const uint8_t **shared_info2, size_t *shared_info2_len);
  465. int cms_sign_and_envelop(
  466. uint8_t *cms, size_t *cms_len,
  467. const CMS_CERTS_AND_KEY *signers, size_t signers_cnt,
  468. const uint8_t *rcpt_certs, size_t rcpt_certs_len,
  469. int enc_algor, const uint8_t *key, size_t keylen, const uint8_t *iv, size_t ivlen,
  470. int content_type, const uint8_t *content, size_t content_len,
  471. const uint8_t *signers_crls, size_t signers_crls_len,
  472. const uint8_t *shared_info1, size_t shared_info1_len,
  473. const uint8_t *shared_info2, size_t shared_info2_len);
  474. int cms_deenvelop_and_verify(
  475. const uint8_t *cms, size_t cms_len,
  476. const SM2_KEY *rcpt_key, const uint8_t *rcpt_cert, size_t rcpt_cert_len,
  477. const uint8_t *extra_signer_certs, size_t extra_signer_certs_len,
  478. const uint8_t *extra_signer_crls, size_t extra_signer_crls_len,
  479. int *content_type, uint8_t *content, size_t *content_len,
  480. const uint8_t **rcpt_infos, size_t *rcpt_infos_len,
  481. const uint8_t **signer_infos, size_t *signer_infos_len,
  482. const uint8_t **signer_certs, size_t *signer_certs_len,
  483. const uint8_t **signer_crls, size_t *signer_crls_len,
  484. const uint8_t **shared_info1, size_t *shared_info1_len,
  485. const uint8_t **shared_info2, size_t *shared_info2_len);
  486. // 生成ContentInfo, type == keyAgreementInfo
  487. int cms_set_key_agreement_info(
  488. uint8_t *cms, size_t *cms_len,
  489. const SM2_KEY *temp_public_key_r,
  490. const uint8_t *user_cert, size_t user_cert_len,
  491. const uint8_t *user_id, size_t user_id_len);
  492. #define PEM_CMS "CMS"
  493. int cms_to_pem(const uint8_t *cms, size_t cms_len, FILE *fp);
  494. int cms_from_pem(uint8_t *cms, size_t *cms_len, size_t maxlen, FILE *fp);
  495. int cms_print(FILE *fp, int fmt, int ind, const char *label, const uint8_t *a, size_t alen);
  496. #ifdef __cplusplus
  497. }
  498. #endif
  499. #endif