跳到主要内容

附录 2

签名验证

步骤 1:导入所需的包

import java.security.KeyFactory;
import java.security.PublicKey;
import java.security.Signature;

步骤 2:从公钥字节创建 PublicKey 对象

KeyFactory keyFactory = KeyFactory.getInstance("RSA");
PublicKey publicKey = keyFactory.generatePublic(new X509EncodedKeySpec(publicKeyBytes));

步骤 3:创建 Signature 对象并用公钥初始化

Signature signature = Signature.getInstance("SHA256withRSA");
signature.initVerify(publicKey);

步骤 4:将除了 signedMessage 之外的所有参数转换为字节数组

response.setACQ("FNX");
response.setDeviceBrandModel("SB-001");
response.setDeviceID("SB000000001");
response.setLang("EN");
response.setTrxRefNo("FNX202302170100000000000000001");
response.setTrxCurr("MYR");
response.setTrxAmt("100.00");
response.setTrxDateTms("20230217121212236");
response.setTrxPymtBrand("PN");
response.setMID("000010000010440");
response.setTID("60003614");
Gson gson = new Gson();
String jsonStr = gson.toJson(response);
byte[] messageBytes = jsonStr.getBytes();

步骤 5:使用消息字节更新 signature

signature.update(messageBytes);

步骤 6:将 signedMessage 转换为字节数组并进行验证

boolean verified = signature.verify(signedMessageBytes);