Skip to main content

Appendix 2

Signature Verification

Step 1 : Import the required packages

import java.security.KeyFactory;
import java.security.PublicKey;
import java.security.Signature;

Step 2 : Create a PublicKey object from the public key bytes

KeyFactory keyFactory = KeyFactory.getInstance("RSA");
PublicKey publicKey = keyFactory.generatePublic(new X509EncodedKeySpec(publicKeyBytes));

Step 3 : Create a Signature object and initialize it with the public key

Signature signature = Signature.getInstance("SHA256withRSA");
signature.initVerify(publicKey);

Step 4 : Convert all parameters into bytes except signedMessage

response.setACQ("FNX");
response.setDeviceBrandModel("SB-001");
response.setDeviceID("SB000000001");
response.setLang("EN");
response.setTrxRefNo("FNX202302170100000000000000001");
response.setTrxCurr("MYR");
response.setTrxAmt("100.00");
response.setTrxDateTms("20230217121212236");
response.setTrxPymtBrand("PN");
response.setMID("000010000010440");
response.setTID("60003614");
Gson gson = new Gson();
String jsonStr = gson.toJson(response);
byte[] messageBytes = jsonStr.getBytes();

Step 5 : Update the signature with the message bytes

signature.update(messageBytes);

Step 6 : Convert signedMessage to bytes and verify

boolean verified = signature.verify(signedMessageBytes);