Server definition
- Hash
- sha256:95df8bff26442cf7ea46de7c3458a1d53dcf41703274459a25afe252fe426a80
- What it is
- What a remote MCP server returned when asked what it offers: 55 tools
The blob, as servednamed by its sha256
{
"instructions": null,
"tools": [
{
"description": "[structured_message] 解剖任意 ASN.1/BER 字节的 TLV 结构,给出逐节点拆解树与 DER 判定(X.690)。\n【算法】ASN.1 显微镜:定长(§8.1.3.3-5)/不定长 BER(§8.1.3.6,0x80+EOC)/\n分段八位串(§8.7)/高 tag 号(§8.1.2.4)均容忍;要求单根逐字节闭合。\n【参数】\n- asn1_in_hex:ASN.1/BER 字节的十六进制字符串(1B~128KB)\n【输出】der_conformant、ber_features(walker 检出的 BER 特征清单)、\nnode_count、total_length、structure_tree(offset/header_len/total_len/\ntag_hex/tag_number/class/constructed/length_form/value_hint/rfc_note)、\ntruncated、warnings。\n【注意】der_conformant 是 walker 口径的近似(特征清单为空即判真),\n非完整 X.690 DER 校验器;BER 特征是识别 AWS KMS 回包等非规范编码的卖点。",
"inputSchema": {
"properties": {
"asn1_in_hex": {
"default": "",
"description": "ASN.1/BER 字节的十六进制字符串(1B~128KB,单根且逐字节闭合;BER 不定长/分段八位串/高 tag 号均容忍)",
"title": "Asn1 In Hex",
"type": "string"
}
},
"title": "Asn1ParseRequest",
"type": "object"
},
"name": "asn1_parse",
"outputSchema": null
},
{
"description": "[symmetric_cipher] 分组密码 CBC 模式加解密。\n【算法】AES128(key=16B) / AES256(key=32B) / SM4(key=16B)。\n【参数】\n- algorithm:算法名\n- process_type:Encrypt 或 Decrypt\n- input_data_in_hex:明文或密文 Hex(1B~16MB)\n- key_in_hex:密钥 Hex\n- iv_in_hex:初始向量 Hex(固定 16 字节 = 32 hex 字符)\n【自动行为】加密自动 PKCS7 填充,解密自动去填充。\n【输出】output_data_in_hex、output_length、output_sha256、algorithm。\n【注意】解密时密文长度必须为 16 字节整数倍。",
"inputSchema": {
"properties": {
"algorithm": {
"default": "AES256",
"description": "密码算法名称(具体可选值因工具而异,见工具描述)",
"enum": [
"AES128",
"AES256",
"SM4"
],
"title": "Algorithm",
"type": "string"
},
"input_data_in_hex": {
"default": "",
"description": "输入数据的十六进制字符串(加密时为明文,解密时为密文,1B~16MB)",
"title": "Input Data In Hex",
"type": "string"
},
"iv_in_hex": {
"default": "",
"description": "初始向量的十六进制字符串,固定 32 个 hex 字符(16 字节)",
"title": "Iv In Hex",
"type": "string"
},
"key_in_hex": {
"default": "",
"description": "密钥的十六进制字符串。长度取决于算法:AES256=64 字符(32B),AES128/SM4=32 字符(16B)",
"title": "Key In Hex",
"type": "string"
},
"process_type": {
"default": "Encrypt",
"description": "操作类型,可选值:Encrypt / Decrypt",
"enum": [
"Encrypt",
"Decrypt"
],
"title": "Process Type",
"type": "string"
}
},
"title": "BlockCipherRequest",
"type": "object"
},
"name": "block_cipher",
"outputSchema": null
},
{
"description": "[structured_message] 把 CBOR 字节流解码为 JSON,并给出逐字段结构拆解树(RFC 8949)。\n【算法】CBOR 解码,定长(§3.2.1)与不定长(§3.2.2)均容忍;\n要求单数据项且逐字节闭合(尾随字节即拒绝)。\n【参数】\n- cbor_in_hex:CBOR 字节的十六进制字符串(1B~128KB)\n【输出】decoded_json(bytes→{\"hex\":…}、tag→{\"tag\",\"value\"}、\n语义 tag→date_time/uuid 等标注形式)、decoded_type、decoded_length、\nstructure_tree(offset/header_len/total_len/major_type/length_form/rfc_note)、truncated、warnings。\n【注意】structure_tree 超过 20000 节点或深度超 64 会截断并置 truncated=true;cbor2 对 tag 0/1/2/3 等有内置语义解码,wire 层形态以 structure_tree 为准。",
"inputSchema": {
"properties": {
"cbor_in_hex": {
"default": "",
"description": "CBOR 字节的十六进制字符串(1B~128KB,单数据项且逐字节闭合)",
"title": "Cbor In Hex",
"type": "string"
}
},
"title": "CborDecodeRequest",
"type": "object"
},
"name": "cbor_decode",
"outputSchema": null
},
{
"description": "[structured_message] 把 JSON 载荷编码为 CBOR 字节流(RFC 8949)。\n【算法】CBOR 规范编码(RFC 8949 §4.2.1)或不定长教学编码(§3.2.2)。\n【参数】\n- json_payload:待编码的 JSON 文本(≤65536 字符),支持两类教学标记:\n {\"$bytes\": \"<hex>\"} 渲染为 byte string(major type 2);\n {\"$tag\": <n>, \"value\": …} 渲染为 tagged value(major type 6)\n- canonical:True=规范形式(定长最短,map 键按长度+字节序排序)\n- prefer_indefinite:True=字符串/数组/map 用不定长编码(0x5f/0x7f/0x9f/0xbf + 0xff break)\n- coerce_integer_keys:True 时形如 \"-35\"/\"0\" 的十进制字符串键转整数键(复刻 Nitro attestation 的 protected 头 {1:-35})\n【输出】encoded_in_hex、encoded_length、canonical、structure_tree(逐字段拆解树)、truncated、warnings。\n【注意】canonical 与 prefer_indefinite 互斥;JSON 对象键天然是字符串,需要整数键时用 coerce_integer_keys=true。",
"inputSchema": {
"description": "json_payload 中的教学标记:\n- {\"$bytes\": \"<hex>\"} 渲染为 byte string(major type 2)\n- {\"$tag\": <n>, \"value\": …} 渲染为 tagged value(major type 6)\ncoerce_integer_keys=True 时,形如 \"-35\"/\"0\" 的十进制字符串键渲染为整数键\n(复刻 Nitro attestation 的 protected 头 {1:-35} 与 pcrs map)。",
"properties": {
"canonical": {
"default": true,
"description": "True=RFC 8949 §4.2.1 规范编码(定长最短、map 键排序);与 prefer_indefinite 互斥",
"title": "Canonical",
"type": "boolean"
},
"coerce_integer_keys": {
"default": false,
"description": "True 时形如 \"-35\"/\"0\" 的十进制字符串键渲染为 CBOR 整数键(如 Nitro protected 头 {1:-35})",
"title": "Coerce Integer Keys",
"type": "boolean"
},
"json_payload": {
"default": "",
"description": "待编码的结构化消息 JSON 文本(≤65536 字符)。CBOR:{\"$bytes\":\"<hex>\"} 渲染 byte string、{\"$tag\":n,\"value\":…} 渲染 tagged value;DER:ASN.1 节点 DSL(一节点一主键,如 {\"sequence\":[{\"oid\":\"1.2…\"}]},形态清单见 der_encode 工具描述)",
"title": "Json Payload",
"type": "string"
},
"prefer_indefinite": {
"default": false,
"description": "True=不定长教学编码(字符串/数组/map 用 0x5f/0x7f/0x9f/0xbf + 0xff break)",
"title": "Prefer Indefinite",
"type": "boolean"
}
},
"title": "CborEncodeRequest",
"type": "object"
},
"name": "cbor_encode",
"outputSchema": null
},
{
"description": "[cert] [x509_certificate] 解析 X.509 证书(国际 / 国密 GM SM2 双路径)。输入 PEM 证书(≤10KB),返回:证书类型(X.509 (international) / X.509 (GM SM2),按签名算法 OID 是否落在国密分支 1.2.156.10197 自动判定)、版本、序列号 hex、签名算法及 OID、颁发者/主体 DN(dict 与 RFC4514 串)、有效期(UTC ISO-8601)与当前状态(valid/expired/not_yet_valid,仅信息展示)、是否自签、公钥类型与位数、SAN、扩展清单、SHA-256 与 SM3 双指纹。GM 证书额外返回主体 SM2 公钥:sm2_public_key_hex(裸坐标 X||Y,128 hex 字符)与 sm2_public_key_hex_uncompressed(未压缩点 04||X||Y,130 hex 字符,与 gmssl certparse 的 ECPoint 输出一致)。国际路径 cryptography 实现,SM2 公钥点位走 GmSSL C 库。解析失败(非法 PEM/DER)返回错误码 'Certificate parse failed'。",
"inputSchema": {
"properties": {
"certificate_in_pem": {
"default": "",
"description": "终端实体证书的 PEM 文本(含 BEGIN/END CERTIFICATE 头尾,≤10KB)",
"title": "Certificate In Pem",
"type": "string"
}
},
"title": "CertParseRequest",
"type": "object"
},
"name": "cert_parse",
"outputSchema": null
},
{
"description": "[cert] [x509_certificate] 用 CA 证书验证终端实体证书(单级直接签发验证)。语义:颁发者 DN 与 CA 主体 DN 匹配 + 签名可由 CA 公钥验证;不做链构建、不做吊销检查。有效期不参与 verified 判定,仅以 time_status 字段(valid/expired/not_yet_valid)信息性回显。GM 证书(签名 OID 落在 1.2.156.10197 国密分支)走 GmSSL C 的 x509_cert_verify_by_ca_cert(SM2withSM3,与 gmssl certverify CLI 同一函数),sm2_id 为签名者 ID(默认 '1234567812345678',与 GmSSL SM2_DEFAULT_ID 同源,GM/T 0009 默认值,1~64 字节);国际证书走 cryptography 的 verify_directly_issued_by(RSA/EC/Ed25519 等)。verified=false 是成功响应(附 reason 分类:DN 不匹配 / 签名验证失败),仅输入格式非法才返回错误码 'Certificate verify failed'。",
"inputSchema": {
"properties": {
"ca_certificate_in_pem": {
"default": "",
"description": "CA 证书的 PEM 文本(含 BEGIN/END CERTIFICATE 头尾,≤10KB)",
"title": "Ca Certificate In Pem",
"type": "string"
},
"certificate_in_pem": {
"default": "",
"description": "终端实体证书的 PEM 文本(含 BEGIN/END CERTIFICATE 头尾,≤10KB)",
"title": "Certificate In Pem",
"type": "string"
},
"sm2_id": {
"default": "1234567812345678",
"description": "SM2 签名者 ID(仅 GM 证书验证使用;默认 '1234567812345678',GM/T 0009 与 GmSSL 同源默认值,1~64 字节)",
"title": "Sm2 Id",
"type": "string"
}
},
"title": "CertVerifyRequest",
"type": "object"
},
"name": "cert_verify",
"outputSchema": null
},
{
"description": "[cms_enveloped] 解密 CMS EnvelopedData(RFC 5652 §6)/ authEnvelopedData(RFC 5083),\nBER/DER 输入均容忍。\n【算法】按消息声明还原算法:rsaesOaep 参数(hashFunc/MGF1/pSource,\nRFC 3560)重建 OAEP padding,内容算法按 OID 分派(CBC 去 PKCS#7\n填充 / GCM 取独立 mac 字段验 AEAD,长度必须等于声明的 aes-ICVlen,\nauthAttrs 存在时以 universal SET OF DER 作 AAD——RFC 5083 §3;\nEnvelopedData 下的 GCM 无定义,直接 reason 拒绝)。\n【参数】\n- cms_in_hex:信封 DER/BER 的十六进制(≤16MB)\n- recipient_private_key_in_pem:收件人 RSA 私钥 PEM(可选;不给则\n 仅做结构拆解)\n- recipient_private_key_password:私钥口令(未加密则留空)\n【输出】decrypted(bool)、reason、plain_data_in_hex、version、\nwrap/CEA(从消息声明还原)、recipients、ber_features(不定长容器/\n分段八位串/非最短长度等 BER 特征清单)、structure_tree。\n【注意】结构性解析成功即 success——解密失败落 decrypted=false +\nreason,树照常返回;AWS KMS 回包这类 BER 信封可直接喂入。",
"inputSchema": {
"description": "结构性解析成功即 success(树总返回);解密失败落 decrypted=false + reason。\npadding / 内容算法从消息声明还原,不收客户端多余输入。",
"properties": {
"cms_in_hex": {
"default": "",
"description": "CMS 信封 DER/BER 编码的十六进制字符串(≤16MB;KMS 回包这类 BER 不定长编码可直接输入)",
"title": "Cms In Hex",
"type": "string"
},
"recipient_private_key_in_pem": {
"default": "",
"description": "收件人 RSA 私钥的 PEM 文本(含 BEGIN/END 头尾)",
"title": "Recipient Private Key In Pem",
"type": "string"
},
"recipient_private_key_password": {
"default": "",
"description": "收件人私钥的加密密码(原始字符串,未加密则留空)",
"title": "Recipient Private Key Password",
"type": "string"
}
},
"title": "CmsEnvelopedDecryptRequest",
"type": "object"
},
"name": "cms_enveloped_decrypt",
"outputSchema": null
},
{
"description": "[cms_enveloped] 构造 CMS EnvelopedData 信封(RFC 5652 §6,KeyTransRecipientInfo)。\n【算法】密钥封装 RSAES-OAEP(RFC 8017 / RFC 3560 参数:hashFunc +\nMGF1 同哈希 + 空 pSource)或 RSAES-PKCS1-v1_5;内容加密 AES-128/256-CBC\n(RFC 3565,PKCS#7 填充)或 AES-128/256-GCM(RFC 5084 只为\nauthEnvelopedData 定义 GCM:RFC 5083 形态,version 恒 0、tag 独立\n放 mac 字段、nonce 12B、aes-ICVlen 声明在参数里)。\n【参数】\n- recipient_certificate_in_pem:收件人 RSA 证书 PEM\n- key_wrap_algorithm:RSAES_OAEP_SHA_256(默认)/ SHA_1 / SHA_224 /\n SHA_384 / SHA_512 / RSAES_PKCS1_V1_5\n- content_encryption_algorithm:AES256_CBC(默认)/ AES128_CBC /\n AES256_GCM / AES128_GCM\n- plain_data_in_hex:明文(1B~16MB)\n【输出】cms_in_hex(DER 定长编码)、version、wrap/CEA 的 OID、\nrecipients 摘要(rid 类型/SKI 或 issuer+serial)、der_note、\nstructure_tree(ASN.1 TLV 拆解树)。\n【注意】CEK 与 IV 服务端 CSPRNG 生成、永不回显;证书带 SKI 扩展时\nrid=SKI、version=2(与 AWS KMS 回包同构),否则 issuerAndSerial、\nversion=0。",
"inputSchema": {
"properties": {
"content_encryption_algorithm": {
"default": "AES256_CBC",
"description": "内容加密算法,可选值:AES256_CBC / AES128_CBC(RFC 3565)/ AES256_GCM / AES128_GCM(RFC 5084,产出 authEnvelopedData 形态 RFC 5083)",
"enum": [
"AES256_CBC",
"AES128_CBC",
"AES256_GCM",
"AES128_GCM"
],
"title": "Content Encryption Algorithm",
"type": "string"
},
"key_wrap_algorithm": {
"default": "RSAES_OAEP_SHA_256",
"description": "密钥封装算法,可选值:RSAES_OAEP_SHA_256 / RSAES_OAEP_SHA_1 / RSAES_OAEP_SHA_224 / RSAES_OAEP_SHA_384 / RSAES_OAEP_SHA_512 / RSAES_PKCS1_V1_5",
"enum": [
"RSAES_OAEP_SHA_256",
"RSAES_OAEP_SHA_1",
"RSAES_OAEP_SHA_224",
"RSAES_OAEP_SHA_384",
"RSAES_OAEP_SHA_512",
"RSAES_PKCS1_V1_5"
],
"title": "Key Wrap Algorithm",
"type": "string"
},
"plain_data_in_hex": {
"default": "",
"description": "明文的十六进制字符串",
"title": "Plain Data In Hex",
"type": "string"
},
"recipient_certificate_in_pem": {
"default": "",
"description": "收件人 RSA 证书的 PEM 文本(含 BEGIN/END CERTIFICATE 头尾)",
"title": "Recipient Certificate In Pem",
"type": "string"
}
},
"title": "CmsEnvelopedEncryptRequest",
"type": "object"
},
"name": "cms_enveloped_encrypt",
"outputSchema": null
},
{
"description": "[cms_enveloped] 纯拆解 CMS EnvelopedData(RFC 5652 §6)/ authEnvelopedData(RFC 5083),\n不解密。\n【算法】自写 ASN.1 TLV walker(X.690 BER 容忍)出结构树 +\nasn1crypto 出结构化字段,两层对照。\n【参数】\n- cms_in_hex:信封 DER/BER 的十六进制(≤16MB)\n【输出】content_type_oid(envelopedData = 1.2.840.113549.1.7.3 /\nauthEnvelopedData = 1.2.840.113549.1.9.16.1.23)、\nversion、recipients(rid 类型 / wrap 算法+OID / encryptedKey 字节数)、\ncontent_encryption_iv_hex(IV 本就是公开字段)、\nrecipient_info_supported(非 KeyTrans 收件人置 False)、\nber_features、structure_tree(含 offset/length_form/rfc_note)。\n【注意】KARI/KEKRI/PWRI/ORI 收件人(RFC 5652 §6.2.2-6.2.6)可拆解\n标注,但本族不做其解密。",
"inputSchema": {
"properties": {
"cms_in_hex": {
"default": "",
"description": "CMS 信封 DER/BER 编码的十六进制字符串(≤16MB;KMS 回包这类 BER 不定长编码可直接输入)",
"title": "Cms In Hex",
"type": "string"
}
},
"title": "CmsEnvelopedParseRequest",
"type": "object"
},
"name": "cms_enveloped_parse",
"outputSchema": null
},
{
"description": "[cms_signed] 构造 CMS SignedData 签名消息(RFC 5652 §5)。\n【算法】RSA PKCS#1 v1.5 或 ECDSA × SHA224/256/384/512;\nauthenticatedAttributes 自动携带 contentType + messageDigest +\nsigningTime + SMIMECapabilities,签名按 §5.4 计算在 signedAttrs\n的 EXPLICIT SET OF(0x31)DER 重编码上(untag 规则)。\n【参数】\n- signer_certificate_in_pem:签名者证书 PEM(嵌入 certificates 集,\n 验签方可按 sid 定位)\n- signer_private_key_in_pem / signer_private_key_password:签名\n 私钥与口令(未加密留空)\n- hash_algorithm:Sha256(默认)/ Sha384 / Sha512 / Sha224 / Sha1\n- detached:True 时 eContent 缺省(§5.2,载荷带外,验签必填\n 外部内容);默认 False(attached,内容嵌消息)\n- data_in_hex:待签原文(1B~16MB)\n【输出】cms_in_hex(DER 定长)、version(=1)、digest/signature\n算法与 OID、signer_sid、certificates_embedded、detached、\nstructure_tree(ASN.1 TLV 拆解树)。\n【注意】Ed25519 与 SHA1 签名被上游 PKCS7SignatureBuilder 拒绝\n(add_signer 只收 RSA/EC × SHA224-512),返回签名失败错误码,\n验签侧照常支持;RSA-PSS 构建未暴露——openssl cms -sign\n-keyopt rsa_padding_mode:pss 的产物可用 cms_signed_verify 验。",
"inputSchema": {
"properties": {
"data_in_hex": {
"default": "",
"description": "数据的十六进制字符串。RAW 模式为消息原文 Hex,DIGEST 模式为哈希摘要 Hex",
"title": "Data In Hex",
"type": "string"
},
"detached": {
"default": false,
"description": "True 时载荷带外(COSE payload 置 null / CMS eContent 缺省),验签必须提供外部内容;默认 False",
"title": "Detached",
"type": "boolean"
},
"hash_algorithm": {
"default": "Sha256",
"description": "哈希算法名称,可选值:Sha1 / Sha224 / Sha256 / Sha384 / Sha512(ECC 不支持 Sm3)",
"enum": [
"Sha256",
"Sha384",
"Sha512",
"Sha224",
"Sha1"
],
"title": "Hash Algorithm",
"type": "string"
},
"signer_certificate_in_pem": {
"default": "",
"description": "签名者证书的 PEM 文本(嵌入 certificates 集,验签方可按 sid 定位)",
"title": "Signer Certificate In Pem",
"type": "string"
},
"signer_private_key_in_pem": {
"default": "",
"description": "签名者私钥的 PEM 文本(含 BEGIN/END 头尾)",
"title": "Signer Private Key In Pem",
"type": "string"
},
"signer_private_key_password": {
"default": "",
"description": "签名者私钥的加密密码(原始字符串,未加密则留空)",
"title": "Signer Private Key Password",
"type": "string"
}
},
"title": "CmsSignedSignRequest",
"type": "object"
},
"name": "cms_signed_sign",
"outputSchema": null
},
{
"description": "[cms_signed] 验签 CMS SignedData(RFC 5652 §5),BER/DER 输入均容忍。\n【算法】按消息声明还原 digestAlgorithm / signatureAlgorithm:\nRSA PKCS#1 v1.5、ECDSA、Ed25519、SHA1 消息均可验;rsassa_pss\n按 RFC 8017 A.2.3 参数(hashFunc / MGF1 / saltLength)重建\npadding;signedAttrs 验签体是 EXPLICIT SET OF DER 重编码(§5.4),\nBER 消息先规范形重编码再验。\n【参数】\n- cms_in_hex:SignedData DER/BER 的十六进制(≤16MB)\n- data_in_hex:外部内容(仅 detached 消息必填;attached 消息\n 以消息内嵌内容为准,忽略此字段)\n- signer_certificate_in_pem:签名者证书 PEM(可选;留空则从\n 消息 certificates 集按 sid 定位——KMS 验 Nitro 证明文档同思路)\n【输出】verified(bool)、reason、key_source(provided_pem /\nembedded_certificates)、detached、content_in_hex(attached 时\n回显 eContent)、content_matches(外部内容与 messageDigest 一致)、\ndigest/signature 算法与 OID、ber_features、structure_tree。\n【注意】验签语义 = 签名可验证 + messageDigest 与内容一致;证书\n链有效性属 cert_verify 职责(warnings 注明);验签失败不返回\n错误码,而是 verified=false + reason。",
"inputSchema": {
"description": "证书留空则从消息 certificates 集提取(KMS 验 Nitro 文档同思路);\ndetached 消息必须给 data_in_hex(外部内容)。",
"properties": {
"cms_in_hex": {
"default": "",
"description": "CMS 信封 DER/BER 编码的十六进制字符串(≤16MB;KMS 回包这类 BER 不定长编码可直接输入)",
"title": "Cms In Hex",
"type": "string"
},
"data_in_hex": {
"default": "",
"description": "数据的十六进制字符串。RAW 模式为消息原文 Hex,DIGEST 模式为哈希摘要 Hex",
"title": "Data In Hex",
"type": "string"
},
"signer_certificate_in_pem": {
"default": "",
"description": "签名者证书的 PEM 文本(嵌入 certificates 集,验签方可按 sid 定位)",
"title": "Signer Certificate In Pem",
"type": "string"
}
},
"title": "CmsSignedVerifyRequest",
"type": "object"
},
"name": "cms_signed_verify",
"outputSchema": null
},
{
"description": "[cose_sign1] 纯拆解 COSE_Sign1 消息,不验签(RFC 9052 §4.2)。\n【算法】CBOR 四元素数组 [protected, unprotected, payload, signature]\n逐字段拆解;protected 头解码出 alg;payload 尝试嵌套 CBOR 解码。\n【参数】\n- cose_sign1_in_hex:COSE_Sign1 消息(≤128KB,hex)\n【输出】protected_in_hex、protected_header、unprotected_header、\npayload_in_hex、payload_json、payload_decoded、signature_raw_in_hex、\nsignature_format_note(裸 r||s 语义说明)、structure_tree。\n【注意】structure_tree 与 cbor_decode 同构(offset/major_type/length_form/ \nrfc_note),四元素数组在树中可见 [protected, {}, payload, sig] 布局。",
"inputSchema": {
"properties": {
"cose_sign1_in_hex": {
"default": "",
"description": "COSE_Sign1 消息的十六进制字符串(≤128KB,4 元素数组)",
"title": "Cose Sign1 In Hex",
"type": "string"
}
},
"title": "CoseSign1ParseRequest",
"type": "object"
},
"name": "cose_sign1_parse",
"outputSchema": null
},
{
"description": "[cose_sign1] 构造并签名 COSE_Sign1 消息(RFC 9052 §4.2,算法 RFC 9053)。\n【算法】ES256(-7, P-256+SHA-256) / ES384(-35, P-384+SHA-384) /\nES512(-36, P-521+SHA-512) / EdDSA(-8, Ed25519)。ES 系签名为裸 r||s\n(坐标左补零到曲线宽度,ES512 坐标 66 字节、r||s 共 132 字节)。\n【参数】\n- algorithm:ES256 / ES384 / ES512 / EdDSA\n- ecc_private_key_in_pem:EC 或 Ed25519 私钥 PEM(须与算法曲线匹配)\n- ecc_private_key_password:私钥口令(未加密则留空)\n- payload_in_hex:待签 payload(1B~256KB)\n- external_aad_in_hex:外部 AAD(可选,默认空串)\n【输出】cose_sign1_in_hex(完整 COSE_Sign1)、protected_in_hex、\nsig_structure_in_hex(Sig_structure 待签字节,RFC 9052 §4.4,可直送\nopenssl dgst 交叉)、signature_raw_in_hex(裸 r||s)、\nsignature_der_in_hex / r_in_hex / s_in_hex(EdDSA 无此形态)、structure_tree。\n【注意】签名真正覆盖的是 Sig_structure = [\"Signature1\", protected, \nexternal_aad, payload] 的规范编码,不是 payload 本身。",
"inputSchema": {
"properties": {
"algorithm": {
"default": "ES384",
"description": "密码算法名称(具体可选值因工具而异,见工具描述)",
"enum": [
"ES256",
"ES384",
"ES512",
"EdDSA"
],
"title": "Algorithm",
"type": "string"
},
"detached": {
"default": false,
"description": "True 时载荷带外(COSE payload 置 null / CMS eContent 缺省),验签必须提供外部内容;默认 False",
"title": "Detached",
"type": "boolean"
},
"ecc_private_key_in_pem": {
"default": "",
"description": "ECC 私钥的 PEM 文本(含 BEGIN/END 头尾的 Base64 编码文本)",
"title": "Ecc Private Key In Pem",
"type": "string"
},
"ecc_private_key_password": {
"default": "",
"description": "ECC 私钥的加密密码(原始字符串,非编码格式)",
"title": "Ecc Private Key Password",
"type": "string"
},
"external_aad_in_hex": {
"default": "",
"description": "外部 AAD 的十六进制字符串(可选;参与 Sig_structure 但不出现在消息里)",
"title": "External Aad In Hex",
"type": "string"
},
"payload_in_hex": {
"default": "",
"description": "COSE Sign1 待签 payload 的十六进制字符串(1B~256KB)",
"title": "Payload In Hex",
"type": "string"
}
},
"title": "CoseSign1SignRequest",
"type": "object"
},
"name": "cose_sign1_sign",
"outputSchema": null
},
{
"description": "[cose_sign1] 验证 COSE_Sign1 签名(RFC 9052 §4.4 Sig_structure 重构验签)。\n【算法】按 protected 头 alg 声明分派:-7/-35/-36(ES,裸 r||s → DER)\n与 -8(Ed25519)。\n【参数】\n- cose_sign1_in_hex:COSE_Sign1 消息(≤128KB,hex)\n- ecc_public_key_in_pem:验签公钥 PEM。留空时从 payload 的 certificate\n 字段提取公钥(复刻 KMS 验 Nitro attestation 文档方式)\n- external_aad_in_hex:与签名时一致的外部 AAD(可选)\n【输出】verified(bool)、reason、key_source(provided_pem 或 \npayload_certificate)、protected_header、payload_in_hex、payload_json、\npayload_certificate_in_pem、sig_structure_in_hex、structure_tree。\n【注意】verified=false 是成功响应(附 reason);仅消息无法解析为\n4 元素 COSE_Sign1 数组才返回错误码。",
"inputSchema": {
"description": "ecc_public_key_in_pem 留空时从 payload 的 certificate 字段提取公钥\n(复刻 KMS 验 Nitro attestation 文档的方式);key_source 回显实际来源。\n验签失败是 success + verified=false + reason(cert_verify 先例),\n仅消息本身无法解析为 COSE_Sign1 数组才返回错误码。",
"properties": {
"cose_sign1_in_hex": {
"default": "",
"description": "COSE_Sign1 消息的十六进制字符串(≤128KB,4 元素数组)",
"title": "Cose Sign1 In Hex",
"type": "string"
},
"detached_payload_in_hex": {
"default": "",
"description": "detached 消息的外部载荷十六进制字符串(消息 payload 为 null 时验签必填,1B~256KB)",
"title": "Detached Payload In Hex",
"type": "string"
},
"ecc_public_key_in_pem": {
"default": "",
"description": "ECC 公钥的 PEM 文本(含 BEGIN/END 头尾的 Base64 编码文本)",
"title": "Ecc Public Key In Pem",
"type": "string"
},
"external_aad_in_hex": {
"default": "",
"description": "外部 AAD 的十六进制字符串(可选;参与 Sig_structure 但不出现在消息里)",
"title": "External Aad In Hex",
"type": "string"
}
},
"title": "CoseSign1VerifyRequest",
"type": "object"
},
"name": "cose_sign1_verify",
"outputSchema": null
},
{
"description": "[symmetric_cipher] [symmetric_cipher] CTR 计数器模式加解密(AES-256-CTR / SM4-CTR)。CTR 是把块密码转成密钥流的模式:加解密为同一操作(密钥流 XOR),无填充,密文长度与明文等长,任意长度输入(1B ~ 16MB)。algorithm 可选 AES256CTR(key 32B,cryptography 实现)或 SM4CTR(key 16B,GmSSL C 库实现,与 eet 的 sm4-ctr 同源)。iv_in_hex 为 16 字节初始计数器块(32 hex 字符),同 key/iv 下加解密互为逆操作。注意:CTR 不提供认证(无 MAC/tag)——需要防篡改时优先用 stream_cipher 的 AEAD 模式(AES-GCM/ChaCha20-Poly1305/SM4-GCM),CTR 仅适合已有独立认证层或互操作对数场景。返回字段:output_data_in_hex、output_length、output_sha256、algorithm。",
"inputSchema": {
"properties": {
"algorithm": {
"default": "AES256CTR",
"description": "密码算法名称(具体可选值因工具而异,见工具描述)",
"enum": [
"AES256CTR",
"SM4CTR"
],
"title": "Algorithm",
"type": "string"
},
"input_data_in_hex": {
"default": "",
"description": "输入数据的十六进制字符串(加密时为明文,解密时为密文,1B~16MB)",
"title": "Input Data In Hex",
"type": "string"
},
"iv_in_hex": {
"default": "",
"description": "初始向量的十六进制字符串,固定 32 个 hex 字符(16 字节)",
"title": "Iv In Hex",
"type": "string"
},
"key_in_hex": {
"default": "",
"description": "密钥的十六进制字符串。长度取决于算法:AES256=64 字符(32B),AES128/SM4=32 字符(16B)",
"title": "Key In Hex",
"type": "string"
}
},
"title": "CtrCipherRequest",
"type": "object"
},
"name": "ctr_cipher",
"outputSchema": null
},
{
"description": "[symmetric_cipher] PKCS7 填充/去填充工具。\n【参数】\n- padding_action:DoPadding(填充到 16 字节对齐)或 UnPadding(去填充)\n- data_in_hex:待处理数据 Hex\n【输出】output_data_in_hex、output_length。\n【说明】块大小固定 16 字节(AES/SM4 块大小)。通常无需单独调用此工具,block_cipher 内部已自动处理填充。",
"inputSchema": {
"properties": {
"data_in_hex": {
"description": "数据的十六进制字符串。RAW 模式为消息原文 Hex,DIGEST 模式为哈希摘要 Hex",
"title": "Data In Hex",
"type": "string"
},
"padding_action": {
"default": "DoPadding",
"description": "填充操作,可选值:DoPadding(填充到 16 字节对齐)/ UnPadding(去填充)",
"enum": [
"DoPadding",
"UnPadding"
],
"title": "Padding Action",
"type": "string"
}
},
"required": [
"data_in_hex"
],
"title": "DataPaddingRequest",
"type": "object"
},
"name": "data_padding",
"outputSchema": null
},
{
"description": "[structured_message] 把 JSON 节点 DSL 编码为 DER 字节(X.690)。\n【算法】DER 规范编码(定长最短 + SET OF 排序);或教学 BER 不定长\n(构造容器 0x80 + EOC,复刻 AWS KMS 回包形态)。\n【参数】\n- json_payload:节点 DSL(≤65536 字符),一节点一主键:\n {\"integer\": n}/{\"enumerated\": n}/{\"boolean\": true}/{\"null\": true};\n {\"oid\": \"1.2.840…\"}(首弧 0/1 时次弧≤39);\n {\"octet_string\": \"<hex>\"}/{\"bit_string\": {\"hex\",\"unused_bits\":0..7}};\n {\"utf8_string\"|\"printable_string\"|\"ia5_string\"|\"numeric_string\": s};\n {\"utc_time\": \"YYMMDDHHMMSSZ\"}/{\"generalized_time\": \"YYYYMMDDHHMMSS[.f]Z\"};\n {\"sequence\": [节点]}/{\"set\": [节点]};\n {\"context\"|\"application\"|\"private\": {\"number\": n,\n \"children\": [节点]|\"primitive_hex\": \"<hex>\"}}(children=[单节点] 即\n EXPLICIT、[内层孩子们] 即 IMPLICIT-constructed);\n {\"raw\": {\"tag_hex\", \"content_hex\"}}(逃生舱)\n- der:True=规范 DER(SET OF 按 X.690 §11.6 完整子 TLV 字节排序)\n- ber_indefinite:True=构造容器不定长 BER(原语保持定长,§8.1.3.4)\n【输出】encoded_in_hex、encoded_length、der、der_conformant、ber_features、\nstructure_tree(编码输出回剖的免费拆解树)、truncated、warnings。\n【注意】der 与 ber_indefinite 互斥;两者皆 false 为定长 + SET OF 作者序的\n教学 BER 态;时间只收线上原格式(不做 ISO 便捷转换)。",
"inputSchema": {
"description": "json_payload 中的节点形态(一主键一节点,未知/多主键拒绝):\n- {\"integer\": n} / {\"enumerated\": n} / {\"boolean\": true} / {\"null\": true}\n- {\"oid\": \"1.2.840...\"}(首弧 0/1 时次弧 ≤39)\n- {\"octet_string\": \"<hex>\"} / {\"bit_string\": {\"hex\": ..., \"unused_bits\": 0..7}}\n- {\"utf8_string\"|\"printable_string\"|\"ia5_string\"|\"numeric_string\": s}\n- {\"utc_time\": \"YYMMDDHHMMSSZ\"} / {\"generalized_time\": \"YYYYMMDDHHMMSS[.f]Z\"}\n- {\"sequence\": [...]} / {\"set\": [...]}(SET OF 在 der 态按 X.690 §11.6 排序)\n- {\"context\"|\"application\"|\"private\": {\"number\": n, \"children\"| \"primitive_hex\": …}}\n- {\"raw\": {\"tag_hex\": ..., \"content_hex\": ...}}(逃生舱)\nder=True 规范 DER;ber_indefinite=True 构造容器不定长 BER(AWS KMS 回包\n同款特征);两者皆 false 为定长 + SET OF 作者序的教学 BER 态。",
"properties": {
"ber_indefinite": {
"default": false,
"description": "True=构造容器不定长 BER(0x80 + 两字节 EOC 递归,原语保持定长;AWS KMS 回包同款形态)",
"title": "Ber Indefinite",
"type": "boolean"
},
"der": {
"default": true,
"description": "True=规范 DER(X.690 §10 定长最短 + SET OF 按 §11.6 排序);与 ber_indefinite 互斥",
"title": "Der",
"type": "boolean"
},
"json_payload": {
"default": "",
"description": "待编码的结构化消息 JSON 文本(≤65536 字符)。CBOR:{\"$bytes\":\"<hex>\"} 渲染 byte string、{\"$tag\":n,\"value\":…} 渲染 tagged value;DER:ASN.1 节点 DSL(一节点一主键,如 {\"sequence\":[{\"oid\":\"1.2…\"}]},形态清单见 der_encode 工具描述)",
"title": "Json Payload",
"type": "string"
}
},
"title": "DerEncodeRequest",
"type": "object"
},
"name": "der_encode",
"outputSchema": null
},
{
"description": "[ecc] ECDH + HKDF 密钥协商,双方各用私钥+对方公钥派生相同对称密钥。\n【参数】\n- alice_ecc_private_key_in_pem:己方私钥 PEM\n- bob_ecc_public_key_in_pem:对方公钥 PEM\n- hash_algorithm:HKDF 底层哈希(Sha256/Sha384/Sha512 等,不支持 Sm3)\n- salt:HKDF salt Hex(可选)\n- additional_info:HKDF info Hex(可选)\n- derived_key_length:派生密钥长度 16~1024 字节\n- alice_ecc_private_key_password:若私钥加密则传入\n【输出】derived_key_in_hex、derived_key_length。\n【曲线限制】Ed25519 不可用,X25519 可用。",
"inputSchema": {
"properties": {
"additional_info": {
"default": "536572696f75732043727970746f6772617068790a20202020437265617469766520536f6c7574696f6e730a202020204d617070696e67204469676974616c205472757374",
"description": "HKDF info 的十六进制字符串(可选)",
"title": "Additional Info",
"type": "string"
},
"alice_ecc_private_key_in_pem": {
"default": "",
"description": "Alice 侧 ECC 私钥的 PEM 文本",
"title": "Alice Ecc Private Key In Pem",
"type": "string"
},
"alice_ecc_private_key_password": {
"default": "",
"description": "Alice 侧 ECC 私钥的加密密码(原始字符串,非编码格式)",
"title": "Alice Ecc Private Key Password",
"type": "string"
},
"bob_ecc_public_key_in_pem": {
"default": "",
"description": "Bob 侧 ECC 公钥的 PEM 文本",
"title": "Bob Ecc Public Key In Pem",
"type": "string"
},
"derived_key_length": {
"default": 32,
"description": "HKDF/KDF 派生密钥长度(整数,16~1024 字节;KDF Pbkdf2Sm3 上限 256)",
"title": "Derived Key Length",
"type": "integer"
},
"hash_algorithm": {
"default": "Sha512",
"description": "哈希算法名称,可选值:Sha1 / Sha224 / Sha256 / Sha384 / Sha512(ECC 不支持 Sm3)",
"enum": [
"Sha1",
"Sha224",
"Sha256",
"Sha384",
"Sha512"
],
"title": "Hash Algorithm",
"type": "string"
},
"salt": {
"default": "e5af86e7a081e5ada6e4babae38090436970686572485542e38091",
"description": "HKDF salt 的十六进制字符串(可选)",
"title": "Salt",
"type": "string"
}
},
"title": "EccKeyExchangeRequest",
"type": "object"
},
"name": "ecc_key_exchange",
"outputSchema": null
},
{
"description": "[ecc] ECC 私钥签名(SECP* 用 ECDSA,ED25519 用 EdDSA)。\n【参数】\n- ecc_private_key_in_pem:PEM 私钥\n- data_in_hex:待签数据 Hex\n- sign_raw_data_mode:True=对原文签名(内部先哈希),False=data_in_hex 已是摘要\n- hash_algorithm:Sha256/Sha384/Sha512 等(EdDSA 忽略此参数)\n- ecc_private_key_password:若私钥加密则传入\n【输出】signature_in_hex、signature_length、curve_name。\n【曲线限制】X25519 不可用于签名。",
"inputSchema": {
"properties": {
"data_in_hex": {
"default": "",
"description": "数据的十六进制字符串。RAW 模式为消息原文 Hex,DIGEST 模式为哈希摘要 Hex",
"title": "Data In Hex",
"type": "string"
},
"ecc_private_key_in_pem": {
"default": "",
"description": "ECC 私钥的 PEM 文本(含 BEGIN/END 头尾的 Base64 编码文本)",
"title": "Ecc Private Key In Pem",
"type": "string"
},
"ecc_private_key_password": {
"default": "",
"description": "ECC 私钥的加密密码(原始字符串,非编码格式)",
"title": "Ecc Private Key Password",
"type": "string"
},
"hash_algorithm": {
"default": "Sha512",
"description": "哈希算法名称,可选值:Sha1 / Sha224 / Sha256 / Sha384 / Sha512(ECC 不支持 Sm3)",
"enum": [
"Sha1",
"Sha224",
"Sha256",
"Sha384",
"Sha512"
],
"title": "Hash Algorithm",
"type": "string"
},
"sign_raw_data_mode": {
"default": true,
"description": "True=对原文签名(服务端内部先哈希),False=data_in_hex 已是哈希摘要的 Hex",
"title": "Sign Raw Data Mode",
"type": "boolean"
}
},
"title": "EccSignRequest",
"type": "object"
},
"name": "ecc_key_sign",
"outputSchema": null
},
{
"description": "[ecc] ECC 公钥验签(SECP* 用 ECDSA,ED25519 用 EdDSA)。\n【参数】\n- ecc_public_key_in_pem:PEM 公钥\n- data_in_hex:原始数据 Hex\n- signature_in_hex:签名 Hex\n- sign_raw_data_mode:必须与签名时一致\n- hash_algorithm:必须与签名时一致\n【输出】verified(bool,True=验签通过)、curve_name。\n【曲线限制】X25519 不可用于验签。",
"inputSchema": {
"properties": {
"data_in_hex": {
"default": "",
"description": "数据的十六进制字符串。RAW 模式为消息原文 Hex,DIGEST 模式为哈希摘要 Hex",
"title": "Data In Hex",
"type": "string"
},
"ecc_public_key_in_pem": {
"default": "",
"description": "ECC 公钥的 PEM 文本(含 BEGIN/END 头尾的 Base64 编码文本)",
"title": "Ecc Public Key In Pem",
"type": "string"
},
"hash_algorithm": {
"default": "Sha512",
"description": "哈希算法名称,可选值:Sha1 / Sha224 / Sha256 / Sha384 / Sha512(ECC 不支持 Sm3)",
"enum": [
"Sha1",
"Sha224",
"Sha256",
"Sha384",
"Sha512"
],
"title": "Hash Algorithm",
"type": "string"
},
"sign_raw_data_mode": {
"default": true,
"description": "True=对原文签名(服务端内部先哈希),False=data_in_hex 已是哈希摘要的 Hex",
"title": "Sign Raw Data Mode",
"type": "boolean"
},
"signature_in_hex": {
"default": "",
"description": "签名的十六进制字符串",
"title": "Signature In Hex",
"type": "string"
}
},
"title": "EccVerifyRequest",
"type": "object"
},
"name": "ecc_key_verify",
"outputSchema": null
},
{
"description": "[ecc] 生成 ECC 密钥对。\n【曲线】ECC_SECP_256R1 / ECC_SECP_384R1 / ECC_SECP_521R1 / ECC_SECP256K1 / ECC_ED25519(仅签名)/ ECC_X25519(仅 ECDH)。\n【参数】\n- curve:曲线名\n- private_key_password:可选,私钥 PEM 加密保护\n【输出】public_key_in_pem、private_key_in_pem、curve。\n【能力矩阵】\n- SECP* / SECP256K1 → 签名 + 验签 + ECDH\n- ED25519 → 仅签名/验签(EdDSA)\n- X25519 → 仅 ECDH 密钥协商",
"inputSchema": {
"properties": {
"curve": {
"default": "ECC_SECP_256R1",
"description": "ECC 曲线名,可选值:ECC_SECP_256R1 / ECC_SECP_384R1 / ECC_SECP_521R1 / ECC_SECP256K1 / ECC_ED25519 / ECC_X25519",
"enum": [
"ECC_SECP_256R1",
"ECC_SECP_384R1",
"ECC_SECP_521R1",
"ECC_SECP256K1",
"ECC_ED25519",
"ECC_X25519"
],
"title": "Curve",
"type": "string"
},
"private_key_password": {
"default": "",
"description": "私钥的加密密码(原始字符串,非编码格式),可选",
"title": "Private Key Password",
"type": "string"
}
},
"title": "GenerateECCRequest",
"type": "object"
},
"name": "generate_ecc",
"outputSchema": null
},
{
"description": "[random] 使用操作系统 CSPRNG 生成安全随机字节。data_length 指定字节数(1-128),返回 data_in_hex 十六进制字符串。返回字段:data_in_hex(随机数据 Hex 编码)、data_length(实际字节数)。",
"inputSchema": {
"properties": {
"data_length": {
"description": "随机数据字节数(整数,1~128)",
"title": "Data Length",
"type": "integer"
}
},
"required": [
"data_length"
],
"title": "GenerateRandomDataRequest",
"type": "object"
},
"name": "generate_random_data",
"outputSchema": null
},
{
"description": "[rsa] 生成 RSA 密钥对。\n【参数】\n- key_size:2048 / 3072 / 4096(位)\n- private_key_password:可选,设置后私钥 PEM 用 AES-256-CBC 加密保护\n【输出】public_key_in_pem、private_key_in_pem、key_size。\n【后续操作】公钥用于 rsa_encryption / rsa_verify,私钥用于 rsa_decryption / rsa_sign。",
"inputSchema": {
"properties": {
"key_size": {
"default": 2048,
"description": "RSA 密钥位数,可选值:2048 / 3072 / 4096",
"enum": [
"2048",
"3072",
"4096"
],
"title": "Key Size",
"type": "integer"
},
"private_key_password": {
"default": "",
"description": "私钥的加密密码(原始字符串,非编码格式),可选",
"title": "Private Key Password",
"type": "string"
}
},
"title": "GenerateRSARequest",
"type": "object"
},
"name": "generate_rsa",
"outputSchema": null
},
{
"description": "[sm2] 生成 SM2(SM2P256V1 / 国密曲线)密钥对。\n【参数】\n- private_key_password:必填,私钥 PEM 加密口令(1-64 字节;私钥只有加密 PEM 一种导出形态)\n【输出】public_key_in_pem、private_key_in_pem、z_in_hex、point_x_in_hex、point_y_in_hex、public_key_in_hex、private_key_in_hex。\n【后续操作】公钥用于 sm2_encryption / sm2_verify,私钥用于 sm2_decryption / sm2_sign。",
"inputSchema": {
"properties": {
"private_key_password": {
"default": "",
"description": "私钥的加密密码(原始字符串,非编码格式),可选",
"title": "Private Key Password",
"type": "string"
}
},
"title": "GenerateSM2Request",
"type": "object"
},
"name": "generate_sm2",
"outputSchema": null
},
{
"description": "[sm9_ibc] [sm9_ibc] 生成 SM9 标识密码主密钥(GM/T 0044,GmSSL C 实现)。key_kind='Sign' 生成签名主密钥(验签方持主公钥),'Enc' 生成加密主密钥(加密方持主公钥),默认 Enc。输出:master_public_key_in_pem(明文主公钥,分发给所有用户)与 master_private_key_in_pem(ENCRYPTED 口令加密主私钥,KGC 自留)。private_key_password 必填,1-32 UTF-8 字节。SM9 私钥 PEM 只有加密形态(无明文导出)。",
"inputSchema": {
"properties": {
"key_kind": {
"default": "Enc",
"description": "SM9 主密钥类型,可选值:Sign(签名主密钥)/ Enc(加密主密钥)",
"enum": [
"Sign",
"Enc"
],
"title": "Key Kind",
"type": "string"
},
"private_key_password": {
"default": "",
"description": "私钥的加密密码(原始字符串,非编码格式),可选",
"title": "Private Key Password",
"type": "string"
}
},
"title": "GenerateSM9Request",
"type": "object"
},
"name": "generate_sm9",
"outputSchema": null
},
{
"description": "[hash_digest] 计算消息摘要(支持多算法批量计算)。\n【支持算法】Sha1 / Sha224 / Sha256 / Sha384 / Sha512 / Sm3 / Shake128 / Shake256。\n【参数】\n- plain_in_hex:明文 Hex 字符串(原始数据 1B ~ 16MB)\n- required_hash_modes:字符串数组,指定需要计算的算法列表,默认计算全部算法\n- shake_output_length:SHAKE 系列的输出字节长度(32~256,默认 64),仅在 required_hash_modes 包含 Shake128 或 Shake256 时生效\n【输出】Results 字典,每个算法对应 hash_sum_in_hex(摘要 Hex)和 hash_length(字节数)。\n【SHAKE 说明】SHAKE128/256 是 XOF(可扩展输出函数),输出长度可变,适合需要自定义长度密钥派生的场景。",
"inputSchema": {
"properties": {
"plain_in_hex": {
"default": "",
"description": "原始数据的十六进制字符串(1B~16MB,即 2~33554432 个 hex 字符)",
"title": "Plain In Hex",
"type": "string"
},
"required_hash_modes": {
"default": [
"Sha256",
"Sha384",
"Sha512",
"Sha1",
"Sha224",
"Sm3",
"Shake128",
"Shake256"
],
"description": "哈希算法名称数组,指定需要计算的算法列表,可选值:Sha1 / Sha224 / Sha256 / Sha384 / Sha512 / Sm3 / Shake128 / Shake256(HMAC 不支持 Shake 系列)",
"enum": [
"Sha1",
"Sha224",
"Sha256",
"Sha384",
"Sha512",
"Sm3",
"Shake128",
"Shake256"
],
"items": {
"type": "string"
},
"title": "Required Hash Modes",
"type": "array"
},
"shake_output_length": {
"default": 64,
"description": "SHAKE 系列输出字节长度(整数,32~256,默认 64)",
"title": "Shake Output Length",
"type": "integer"
}
},
"title": "HashSumRequest",
"type": "object"
},
"name": "hash_sum",
"outputSchema": null
},
{
"description": "[utility] 健康检查 / 回显接口。客户端传入 client_msg 字符串,服务端原样回显并附加 server_msg,用于验证 MCP 通道连通性。返回字段:client_msg(回显)、server_msg(服务端附加消息)。",
"inputSchema": {
"properties": {
"client_msg": {
"description": "任意字符串,服务端原样回显(原始字符串,非编码格式)",
"title": "Client Msg",
"type": "string"
}
},
"required": [
"client_msg"
],
"title": "HelloRequest",
"type": "object"
},
"name": "hello",
"outputSchema": null
},
{
"description": "[hash_digest] 计算 HMAC(基于哈希的消息认证码)。\n【支持算法】Sha1 / Sha224 / Sha256 / Sha384 / Sha512 / Sm3(不支持 SHAKE 系列,因 SHAKE 为 XOF 非固定长度哈希)。\n【参数】\n- key_in_hex:密钥 Hex。SHA 系按 RFC 2104 支持 16~256 字节(超块大小会先哈希);若算法列表含 Sm3,上限为 64 字节(SM3 块大小,即 32~128 个 hex 字符)。\n- plain_in_hex:待认证数据 Hex(1B ~ 16MB)\n- required_hash_modes:字符串数组,指定 HMAC 底层哈希算法列表,默认计算全部 6 种算法\n【输出】Results 字典,每个算法对应 hmac_sum_in_hex(HMAC Hex 编码)和 hmac_length(字节数)。\n【典型用途】消息完整性验证、API 签名、密钥确认。",
"inputSchema": {
"properties": {
"key_in_hex": {
"default": "",
"description": "密钥的十六进制字符串。长度取决于算法:AES256=64 字符(32B),AES128/SM4=32 字符(16B)",
"title": "Key In Hex",
"type": "string"
},
"plain_in_hex": {
"default": "",
"description": "原始数据的十六进制字符串(1B~16MB,即 2~33554432 个 hex 字符)",
"title": "Plain In Hex",
"type": "string"
},
"required_hash_modes": {
"default": [
"Sha256",
"Sha384",
"Sha512",
"Sha1",
"Sha224",
"Sm3"
],
"description": "哈希算法名称数组,指定需要计算的算法列表,可选值:Sha1 / Sha224 / Sha256 / Sha384 / Sha512 / Sm3 / Shake128 / Shake256(HMAC 不支持 Shake 系列)",
"enum": [
"Sha1",
"Sha224",
"Sha256",
"Sha384",
"Sha512",
"Sm3"
],
"items": {
"type": "string"
},
"title": "Required Hash Modes",
"type": "array"
}
},
"title": "HmacSumRequest",
"type": "object"
},
"name": "hmac_sum",
"outputSchema": null
},
{
"description": "[pqc_kem] 执行 X25519 + ML-KEM-768 混合密钥交换全流程演示。\n【设计灵感】参考 IETF X-Wing 草案(draft-connolly-cfrg-xwing-kem)的思路,本工具实现的是通用拼接组合器(ecdh_ss || ml_kem_ss → HKDF-SHA256),并非 X-Wing 规范本身的组合器。\n【参数】所有密钥参数均可选:\n- alice_x25519_private_key_pem / bob_x25519_private_key_pem:X25519 PEM 私钥\n- alice_ml_kem_public_key_base64 / bob_ml_kem_public_key_base64:ML-KEM-768 公钥,支持 raw 或 SPKI DER Base64\n- alice_ml_kem_secret_key_base64 / bob_ml_kem_secret_key_base64:ML-KEM-768 私钥,支持 raw 或 PKCS#8 DER Base64\n- ML-KEM 公钥和私钥必须同时提供;留空则服务端使用 CSPRNG 随机生成 raw keypair\n【流程】\n1. Alice 和 Bob 各持有 X25519 + ML-KEM-768 密钥对\n2. Alice 用 Bob 公钥做 X25519 ECDH + ML-KEM Encap\n3. Bob 用自己私钥做 X25519 ECDH + ML-KEM Decap\n4. 双方将 ecdh_ss || ml_kem_ss 通过 HKDF-SHA256 派生 32 字节最终密钥\n【输出】双方中间值 + 最终密钥 + keys_match(bool)验证一致性。\n【安全等级】组合后达到 NIST Level 3(ML-KEM-768)+ Level 1(X25519),抵抗经典和量子攻击。",
"inputSchema": {
"description": "X25519 + ML-KEM-768 混合密钥交换请求。\n\n所有密钥字段均可选:\n- 若留空,服务端随机生成\n- 若传入,服务端使用传入的密钥对进行协商\n\nAlice 侧字段:\n- alice_x25519_private_key_pem: Alice X25519 私钥 (PEM)\n- alice_x25519_public_key_pem: Alice X25519 公钥 (PEM,仅展示/回填)\n- alice_ml_kem_public_key_base64: Alice ML-KEM 公钥 (raw 或 SPKI DER Base64)\n- alice_ml_kem_secret_key_base64: Alice ML-KEM 私钥 (raw 或 PKCS#8 DER Base64)\n\nBob 侧字段同理。若传入 ML-KEM key,公钥和私钥必须同时提供;响应保持 raw key Base64 以兼容演示流程。",
"properties": {
"alice_ml_kem_public_key_base64": {
"default": "",
"description": "Alice 侧 ML-KEM 公钥的 Base64 字符串(raw 或 SPKI DER)",
"title": "Alice Ml Kem Public Key Base64",
"type": "string"
},
"alice_ml_kem_secret_key_base64": {
"default": "",
"description": "Alice 侧 ML-KEM 私钥的 Base64 字符串(raw 或 PKCS#8 DER)",
"title": "Alice Ml Kem Secret Key Base64",
"type": "string"
},
"alice_x25519_private_key_pem": {
"default": "",
"description": "Alice 侧 X25519 私钥的 PEM 文本",
"title": "Alice X25519 Private Key Pem",
"type": "string"
},
"alice_x25519_public_key_pem": {
"default": "",
"title": "Alice X25519 Public Key Pem",
"type": "string"
},
"bob_ml_kem_public_key_base64": {
"default": "",
"description": "Bob 侧 ML-KEM 公钥的 Base64 字符串(raw 或 SPKI DER)",
"title": "Bob Ml Kem Public Key Base64",
"type": "string"
},
"bob_ml_kem_secret_key_base64": {
"default": "",
"description": "Bob 侧 ML-KEM 私钥的 Base64 字符串(raw 或 PKCS#8 DER)",
"title": "Bob Ml Kem Secret Key Base64",
"type": "string"
},
"bob_x25519_private_key_pem": {
"default": "",
"description": "Bob 侧 X25519 私钥的 PEM 文本",
"title": "Bob X25519 Private Key Pem",
"type": "string"
},
"bob_x25519_public_key_pem": {
"default": "",
"title": "Bob X25519 Public Key Pem",
"type": "string"
}
},
"title": "HybridKEXRequest",
"type": "object"
},
"name": "hybrid_kex",
"outputSchema": null
},
{
"description": "[kdf] 执行密钥派生(KDF),从高熵秘密或口令派生对称密钥材料。\n【支持算法】\n- HKDF(默认):RFC 5869 extract-then-expand,底层哈希 Sha256(默认)/ Sha384 / Sha512\n- Sm3Kdf:GB/T 32918 密钥派生,SM3(Z ∥ be32(ct)),ct 从 1 起,适合对 SM2 ECDH 共享秘密派生密钥\n- Pbkdf2Sm3:RFC 8018 PBKDF2,PRF 为 HMAC-SM3,用于口令拉伸\n【参数】(按算法适用,错配会被拒)\n- algorithm:HKDF / Sm3Kdf / Pbkdf2Sm3,默认 HKDF\n- hash_algorithm:仅 HKDF,默认 Sha256\n- input_in_hex:HKDF 的 IKM / Sm3Kdf 的共享秘密 Z,Hex(1B~16MB),与 password 二选一\n- password:仅 Pbkdf2Sm3,口令原文 utf-8(1~1024B)\n- salt_in_hex:HKDF/Pbkdf2Sm3 可选盐 Hex(≤256B)。HKDF 空=未提供(RFC 5869 补 HashLen 零);Pbkdf2Sm3 空=服务端生成 16B 随机盐并在响应回显\n- info_in_hex:仅 HKDF,可选上下文信息 Hex(≤256B)\n- iterations:仅 Pbkdf2Sm3,10000~4000000(默认 10000;受 8s 网关约束,eet CLI 上限为 16777216,互通测试建议取 ≤100 万区间)\n- derived_key_length:派生长度,16~1024B(默认 32;Pbkdf2Sm3 上限 256B)\n【输出】derived_key_in_hex、derived_key_in_base64、salt_used_in_hex(实际使用的盐,Pbkdf2Sm3 未提供盐时回显服务端随机盐)、salt_generated、algorithm、hash_algorithm、iterations、derived_key_length、input_bytes。\n【典型用途】ECDH 共享秘密到会话密钥的收口、口令到加密密钥的拉伸、多上下文密钥隔离(HKDF info)。",
"inputSchema": {
"properties": {
"algorithm": {
"default": "HKDF",
"description": "密码算法名称(具体可选值因工具而异,见工具描述)",
"enum": [
"HKDF",
"Sm3Kdf",
"Pbkdf2Sm3"
],
"title": "Algorithm",
"type": "string"
},
"derived_key_length": {
"default": 32,
"description": "HKDF/KDF 派生密钥长度(整数,16~1024 字节;KDF Pbkdf2Sm3 上限 256)",
"title": "Derived Key Length",
"type": "integer"
},
"hash_algorithm": {
"default": "Sha256",
"description": "哈希算法名称,可选值:Sha1 / Sha224 / Sha256 / Sha384 / Sha512(ECC 不支持 Sm3)",
"enum": [
"Sha256",
"Sha384",
"Sha512"
],
"title": "Hash Algorithm",
"type": "string"
},
"info_in_hex": {
"default": "",
"description": "HKDF 上下文信息的十六进制字符串(可选,≤256B)",
"title": "Info In Hex",
"type": "string"
},
"input_in_hex": {
"default": "",
"description": "输入秘密的十六进制字符串(KDF:HKDF 的 IKM / Sm3Kdf 的共享秘密 Z,1B~16MB)",
"title": "Input In Hex",
"type": "string"
},
"iterations": {
"default": 10000,
"description": "PBKDF2 迭代次数(整数;KDF Pbkdf2Sm3 范围 10000~4000000,默认 10000)",
"title": "Iterations",
"type": "integer"
},
"password": {
"default": "",
"description": "密码(原始字符串,非编码格式;私钥工具为私钥加密密码,KDF Pbkdf2Sm3 为待拉伸口令)",
"title": "Password",
"type": "string"
},
"salt_in_hex": {
"default": "",
"description": "盐的十六进制字符串(KDF,可选 ≤256B;Pbkdf2Sm3 留空则服务端生成 16B 随机盐并回显)",
"title": "Salt In Hex",
"type": "string"
}
},
"title": "KeyDerivationRequest",
"type": "object"
},
"name": "key_derivation",
"outputSchema": null
},
{
"description": "[pqc_signature] 独立计算 ML-DSA 的 64 字节 mu 值(FIPS 204 Section 6.2)。\n【用途】用于验证或调试 EXTERNAL_MU 模式的中间值,或与 AWS KMS EXTERNAL_MU 签名流程对接。\n【计算公式】\n- tr = SHAKE-256(raw_pk, 64)\n- M' = 0x00 || len(ctx) || ctx || message\n- mu = SHAKE-256(tr || M', 64)\n【参数】\n- public_key_spki_in_hex:公钥 hex(SPKI DER 或裸公钥均可),并校验 OID/长度与 algorithm 一致\n- message_in_hex:原始消息 hex(最大 2048 字节,空字符串表示空消息)\n- context_in_hex:可选上下文 hex(最大 255 字节)\n- algorithm:ML-DSA-44 / ML-DSA-65(默认)/ ML-DSA-87\n【输出】tr_in_hex、mu_in_hex、raw_pk_in_hex、algorithm、message_bytes。",
"inputSchema": {
"properties": {
"algorithm": {
"default": "ML-DSA-65",
"description": "密码算法名称(具体可选值因工具而异,见工具描述)",
"enum": [
"ML-DSA-44",
"ML-DSA-65",
"ML-DSA-87"
],
"title": "Algorithm",
"type": "string"
},
"context_in_hex": {
"default": "",
"description": "ML-DSA 上下文的十六进制字符串(可选,最大 255 字节)",
"title": "Context In Hex",
"type": "string"
},
"message_in_hex": {
"default": "",
"description": "消息的十六进制字符串(空字符串表示空消息)",
"title": "Message In Hex",
"type": "string"
},
"public_key_spki_in_hex": {
"default": "",
"description": "ML-DSA 公钥的十六进制字符串(SPKI DER 或裸公钥均可)",
"title": "Public Key Spki In Hex",
"type": "string"
}
},
"title": "MLDSAComputeMURequest",
"type": "object"
},
"name": "ml_dsa_compute_mu",
"outputSchema": null
},
{
"description": "[pqc_signature] 生成 ML-DSA 密钥对(FIPS 204,后量子数字签名标准)。\n【算法选择】algorithm 支持 ML-DSA-44(NIST Level 2)/ ML-DSA-65(Level 3,默认)/ ML-DSA-87(Level 5)。\n【安全等级参考】ML-DSA-44 ≈ AES-128 / ML-DSA-65 ≈ AES-192 / ML-DSA-87 ≈ AES-256。\n【输出】public_key_in_hex(SPKI DER hex)、public_key_in_base64、private_key_in_hex(PKCS#8 DER hex)、private_key_in_base64、algorithm、nist_level、public_key_bytes、private_key_bytes。\n【典型用途】生成密钥对后,私钥用于 ml_dsa_sign 签名,公钥用于 ml_dsa_verify 验签。",
"inputSchema": {
"properties": {
"algorithm": {
"default": "ML-DSA-65",
"description": "密码算法名称(具体可选值因工具而异,见工具描述)",
"enum": [
"ML-DSA-44",
"ML-DSA-65",
"ML-DSA-87"
],
"title": "Algorithm",
"type": "string"
}
},
"title": "MLDSAKeyGenRequest",
"type": "object"
},
"name": "ml_dsa_keygen",
"outputSchema": null
},
{
"description": "[pqc_signature] 使用 ML-DSA 私钥对消息签名(FIPS 204)。\n【双模式】sign_mode 支持 RAW(默认)和 EXTERNAL_MU 两种模式。\n- RAW 模式:直接签名原始消息(liboqs,最大 256 字节)\n- EXTERNAL_MU 模式:先计算 mu = SHAKE-256(tr||M', 64),再通过 OpenSSL 3.5+ mu 模式签名(最大 2048 字节),与 AWS KMS ML-DSA EXTERNAL_MU 语义等价\n【消息长度策略】\n- RAW:最大 256 字节,空消息合法\n- EXTERNAL_MU:最大 2048 字节,空消息合法\n- > 256 且 <= 2048 字节:使用 EXTERNAL_MU\n- > 2048 字节:拒绝\n【算法】algorithm 支持 ML-DSA-44 / ML-DSA-65(默认)/ ML-DSA-87。\n【参数】\n- private_key_in_hex:ml_dsa_keygen 返回的私钥 hex\n- public_key_spki_in_hex:EXTERNAL_MU 模式必填,ml_dsa_keygen 返回的公钥 hex(SPKI DER)\n- message_in_hex:待签消息 hex\n- context_in_hex:可选上下文 hex(最大 255 字节)\n- sign_mode:RAW 或 EXTERNAL_MU(默认 RAW)\n【输出】signature_in_hex、signature_in_base64、algorithm、message_bytes、signature_bytes。",
"inputSchema": {
"properties": {
"algorithm": {
"default": "ML-DSA-65",
"description": "密码算法名称(具体可选值因工具而异,见工具描述)",
"enum": [
"ML-DSA-44",
"ML-DSA-65",
"ML-DSA-87"
],
"title": "Algorithm",
"type": "string"
},
"context_in_hex": {
"default": "",
"description": "ML-DSA 上下文的十六进制字符串(可选,最大 255 字节)",
"title": "Context In Hex",
"type": "string"
},
"message_in_hex": {
"default": "",
"description": "消息的十六进制字符串(空字符串表示空消息)",
"title": "Message In Hex",
"type": "string"
},
"private_key_in_hex": {
"default": "",
"description": "ML-DSA 私钥的十六进制字符串(PKCS#8 DER 编码)",
"title": "Private Key In Hex",
"type": "string"
},
"public_key_spki_in_hex": {
"default": "",
"description": "ML-DSA 公钥的十六进制字符串(SPKI DER 或裸公钥均可)",
"title": "Public Key Spki In Hex",
"type": "string"
},
"sign_mode": {
"default": "RAW",
"description": "ML-DSA 签名模式,可选值:RAW(默认,直接签名原文)/ EXTERNAL_MU(先计算 mu 再签名,与 AWS KMS 语义等价)",
"enum": [
"RAW",
"EXTERNAL_MU"
],
"title": "Sign Mode",
"type": "string"
}
},
"title": "MLDSASignRequest",
"type": "object"
},
"name": "ml_dsa_sign",
"outputSchema": null
},
{
"description": "[pqc_signature] 使用 ML-DSA 公钥验证签名(FIPS 204)。\n【双模式】sign_mode 支持 RAW(默认)和 EXTERNAL_MU 两种模式,必须与签名时使用的模式一致。\n- RAW 模式:直接验证原始消息签名(liboqs,最大 256 字节,空消息合法)\n- EXTERNAL_MU 模式:先计算 mu,再通过 OpenSSL 3.5+ mu 模式验签,可验证 AWS KMS EXTERNAL_MU 签名(最大 2048 字节,空消息合法)\n【算法】algorithm 支持 ML-DSA-44 / ML-DSA-65(默认)/ ML-DSA-87。\n【参数】\n- public_key_spki_in_hex:公钥 hex(SPKI DER 或裸公钥均可),并校验 OID/长度与 algorithm 一致\n- message_in_hex:原始消息 hex,空字符串表示空消息\n- signature_in_hex:签名 hex\n- context_in_hex:签名时使用的 context(必须一致)\n- sign_mode:RAW 或 EXTERNAL_MU(默认 RAW)\n【输出】verified(bool,True=验签通过)、algorithm、message_bytes。",
"inputSchema": {
"properties": {
"algorithm": {
"default": "ML-DSA-65",
"description": "密码算法名称(具体可选值因工具而异,见工具描述)",
"enum": [
"ML-DSA-44",
"ML-DSA-65",
"ML-DSA-87"
],
"title": "Algorithm",
"type": "string"
},
"context_in_hex": {
"default": "",
"description": "ML-DSA 上下文的十六进制字符串(可选,最大 255 字节)",
"title": "Context In Hex",
"type": "string"
},
"message_in_hex": {
"default": "",
"description": "消息的十六进制字符串(空字符串表示空消息)",
"title": "Message In Hex",
"type": "string"
},
"public_key_spki_in_hex": {
"default": "",
"description": "ML-DSA 公钥的十六进制字符串(SPKI DER 或裸公钥均可)",
"title": "Public Key Spki In Hex",
"type": "string"
},
"sign_mode": {
"default": "RAW",
"description": "ML-DSA 签名模式,可选值:RAW(默认,直接签名原文)/ EXTERNAL_MU(先计算 mu 再签名,与 AWS KMS 语义等价)",
"enum": [
"RAW",
"EXTERNAL_MU"
],
"title": "Sign Mode",
"type": "string"
},
"signature_in_hex": {
"default": "",
"description": "签名的十六进制字符串",
"title": "Signature In Hex",
"type": "string"
}
},
"title": "MLDSAVerifyRequest",
"type": "object"
},
"name": "ml_dsa_verify",
"outputSchema": null
},
{
"description": "[pqc_kem] 使用 ML-KEM 私钥执行密钥解封装(FIPS 203)。\n【算法】ML-KEM-512 / ML-KEM-768 / ML-KEM-1024。\n【参数】\n- algorithm:必须与 keygen/encap 一致\n- secret_key_in_hex:ml_kem_keygen 返回的私钥 hex\n- ciphertext_in_hex:ml_kem_encap 返回的密文 hex\n【输出】shared_secret_in_hex、shared_secret_in_base64、shared_secret_sha256、shared_secret_bytes、algorithm。\n【安全特性】若密文被篡改,ML-KEM Implicit Rejection 不抛异常,返回确定性伪随机值(IND-CCA2 安全),不泄露私钥信息。\n【完整流程】keygen → encap(pub) → decap(sk, ct) → 双方 shared_secret 一致",
"inputSchema": {
"properties": {
"algorithm": {
"default": "ML-KEM-768",
"description": "密码算法名称(具体可选值因工具而异,见工具描述)",
"enum": [
"ML-KEM-512",
"ML-KEM-768",
"ML-KEM-1024"
],
"title": "Algorithm",
"type": "string"
},
"ciphertext_in_hex": {
"default": "",
"description": "ML-KEM 密文的十六进制字符串",
"title": "Ciphertext In Hex",
"type": "string"
},
"secret_key_in_hex": {
"default": "",
"description": "ML-KEM 私钥的十六进制字符串",
"title": "Secret Key In Hex",
"type": "string"
}
},
"title": "MLKEMDecapRequest",
"type": "object"
},
"name": "ml_kem_decap",
"outputSchema": null
},
{
"description": "[pqc_kem] 使用 ML-KEM 公钥执行密钥封装(FIPS 203)。\n【算法】ML-KEM-512 / ML-KEM-768 / ML-KEM-1024。\n【参数】\n- algorithm:必须与 keygen 时一致\n- public_key_in_hex:ml_kem_keygen 返回的公钥 hex\n【输出】ciphertext_in_hex、ciphertext_in_base64、shared_secret_in_hex、shared_secret_in_base64、shared_secret_sha256、ciphertext_bytes、shared_secret_bytes、algorithm。\n【说明】每次 encap 产生不同密文(随机化),共享密钥始终 32 字节。发送 ciphertext 给密钥持有方,对方用 ml_kem_decap 恢复相同的 shared_secret。",
"inputSchema": {
"properties": {
"algorithm": {
"default": "ML-KEM-768",
"description": "密码算法名称(具体可选值因工具而异,见工具描述)",
"enum": [
"ML-KEM-512",
"ML-KEM-768",
"ML-KEM-1024"
],
"title": "Algorithm",
"type": "string"
},
"public_key_in_hex": {
"default": "",
"description": "公钥的十六进制字符串(裸密钥或 DER 编码,取决于算法)",
"title": "Public Key In Hex",
"type": "string"
}
},
"title": "MLKEMEncapRequest",
"type": "object"
},
"name": "ml_kem_encap",
"outputSchema": null
},
{
"description": "[pqc_kem] 生成 ML-KEM 密钥对(FIPS 203,后量子密钥封装标准)。\n【算法选择】ML-KEM-512(NIST Level 1)/ ML-KEM-768(Level 3,推荐)/ ML-KEM-1024(Level 5)。\n【参数】\n- algorithm:算法名\n- seed_in_hex:64 字节种子 hex(128 字符),确定性生成\n- use_random_seed:True 时忽略 seed_in_hex,使用 CSPRNG\n【输出】public_key_in_hex、public_key_in_base64、secret_key_in_hex、secret_key_in_base64、seed_in_hex、algorithm、nist_level、public_key_bytes、secret_key_bytes。\n【后续操作】公钥用于 ml_kem_encap,私钥用于 ml_kem_decap。",
"inputSchema": {
"properties": {
"algorithm": {
"default": "ML-KEM-768",
"description": "密码算法名称(具体可选值因工具而异,见工具描述)",
"enum": [
"ML-KEM-512",
"ML-KEM-768",
"ML-KEM-1024"
],
"title": "Algorithm",
"type": "string"
},
"seed_in_hex": {
"default": "30313233343536373839303132333435363738393031323334353637383930313233343536373839303132333435363738393031323334353637383930313233",
"description": "ML-KEM 密钥生成种子的十六进制字符串,固定 128 个 hex 字符(64 字节)",
"title": "Seed In Hex",
"type": "string"
},
"use_random_seed": {
"default": false,
"description": "True 时忽略 seed_in_hex,使用 CSPRNG 随机生成种子",
"title": "Use Random Seed",
"type": "boolean"
}
},
"title": "MLKEMKeyGenRequest",
"type": "object"
},
"name": "ml_kem_keygen",
"outputSchema": null
},
{
"description": "[rsa] RSA 私钥解密。\n【参数】\n- rsa_private_key_in_pem:PEM 格式私钥\n- cipher_data_in_hex:密文 Hex(长度 = key_size/8 字节)\n- rsa_padding_mode:必须与加密时一致\n- password:若私钥有密码保护则传入\n【输出】plain_data_in_hex、plain_length。",
"inputSchema": {
"properties": {
"cipher_data_in_hex": {
"default": "",
"description": "密文的十六进制字符串",
"title": "Cipher Data In Hex",
"type": "string"
},
"password": {
"default": "",
"description": "密码(原始字符串,非编码格式;私钥工具为私钥加密密码,KDF Pbkdf2Sm3 为待拉伸口令)",
"title": "Password",
"type": "string"
},
"rsa_padding_mode": {
"default": "",
"description": "RSA 加密填充模式,可选值:RSAES_PKCS1_V1_5 / RSAES_OAEP_SHA_1 / RSAES_OAEP_SHA_224 / RSAES_OAEP_SHA_256 / RSAES_OAEP_SHA_384 / RSAES_OAEP_SHA_512",
"enum": [
"RSAES_PKCS1_V1_5",
"RSAES_OAEP_SHA_1",
"RSAES_OAEP_SHA_224",
"RSAES_OAEP_SHA_256",
"RSAES_OAEP_SHA_384",
"RSAES_OAEP_SHA_512"
],
"title": "Rsa Padding Mode",
"type": "string"
},
"rsa_private_key_in_pem": {
"default": "",
"description": "RSA 私钥的 PEM 文本(含 BEGIN/END 头尾的 Base64 编码文本)",
"title": "Rsa Private Key In Pem",
"type": "string"
}
},
"title": "RSADecryptionRequest",
"type": "object"
},
"name": "rsa_decryption",
"outputSchema": null
},
{
"description": "[rsa] RSA 公钥加密。\n【参数】\n- rsa_public_key_in_pem:PEM 格式公钥\n- plain_data_in_hex:明文 Hex\n- rsa_padding_mode:RSAES_PKCS1_V1_5 / RSAES_OAEP_SHA_1 / RSAES_OAEP_SHA_224 / RSAES_OAEP_SHA_256 / RSAES_OAEP_SHA_384 / RSAES_OAEP_SHA_512\n【明文长度限制】受 key_size 和 padding 约束:PKCS1v1.5 上限 = 模长字节 − 11;OAEP 上限 = 模长字节 − 2×哈希输出 − 2(RSA-4096 + OAEP-SHA256 = 446 字节,OAEP-SHA512 = 382 字节)。\n【输出】cipher_data_in_hex、cipher_length。\n【安全建议】推荐使用 OAEP 而非 PKCS1v1.5。",
"inputSchema": {
"properties": {
"plain_data_in_hex": {
"default": "",
"description": "明文的十六进制字符串",
"title": "Plain Data In Hex",
"type": "string"
},
"rsa_padding_mode": {
"default": "",
"description": "RSA 加密填充模式,可选值:RSAES_PKCS1_V1_5 / RSAES_OAEP_SHA_1 / RSAES_OAEP_SHA_224 / RSAES_OAEP_SHA_256 / RSAES_OAEP_SHA_384 / RSAES_OAEP_SHA_512",
"enum": [
"RSAES_PKCS1_V1_5",
"RSAES_OAEP_SHA_1",
"RSAES_OAEP_SHA_224",
"RSAES_OAEP_SHA_256",
"RSAES_OAEP_SHA_384",
"RSAES_OAEP_SHA_512"
],
"title": "Rsa Padding Mode",
"type": "string"
},
"rsa_public_key_in_pem": {
"default": "",
"description": "RSA 公钥的 PEM 文本(含 BEGIN/END 头尾的 Base64 编码文本)",
"title": "Rsa Public Key In Pem",
"type": "string"
}
},
"title": "RSAEncryptionRequest",
"type": "object"
},
"name": "rsa_encryption",
"outputSchema": null
},
{
"description": "[rsa] RSA 私钥签名。\n【参数】\n- rsa_private_key_in_pem:PEM 格式私钥\n- data_in_hex:待签数据 Hex\n- rsa_sign_padding_mode:RSA_SIGN_PKCS1_V1_5_SHA{1,224,256,384,512} 或 RSA_SIGN_PSS_SHA{1,224,256,384,512}\n- rsa_sign_raw_data_mode:True=对原文签名(内部先哈希),False=data_in_hex 已是摘要值\n- password:若私钥有密码保护则传入\n【输出】signature_in_hex、signature_length。\n【安全建议】推荐 PSS 而非 PKCS1v1.5。",
"inputSchema": {
"properties": {
"data_in_hex": {
"default": "",
"description": "数据的十六进制字符串。RAW 模式为消息原文 Hex,DIGEST 模式为哈希摘要 Hex",
"title": "Data In Hex",
"type": "string"
},
"password": {
"default": "",
"description": "密码(原始字符串,非编码格式;私钥工具为私钥加密密码,KDF Pbkdf2Sm3 为待拉伸口令)",
"title": "Password",
"type": "string"
},
"rsa_private_key_in_pem": {
"default": "",
"description": "RSA 私钥的 PEM 文本(含 BEGIN/END 头尾的 Base64 编码文本)",
"title": "Rsa Private Key In Pem",
"type": "string"
},
"rsa_sign_padding_mode": {
"default": "",
"description": "RSA 签名填充模式,可选值:RSA_SIGN_PKCS1_V1_5_SHA1 / SHA224 / SHA256 / SHA384 / SHA512 或 RSA_SIGN_PSS_SHA1 / SHA224 / SHA256 / SHA384 / SHA512",
"enum": [
"RSA_SIGN_PKCS1_V1_5_SHA1",
"RSA_SIGN_PKCS1_V1_5_SHA224",
"RSA_SIGN_PKCS1_V1_5_SHA256",
"RSA_SIGN_PKCS1_V1_5_SHA384",
"RSA_SIGN_PKCS1_V1_5_SHA512",
"RSA_SIGN_PSS_SHA1",
"RSA_SIGN_PSS_SHA224",
"RSA_SIGN_PSS_SHA256",
"RSA_SIGN_PSS_SHA384",
"RSA_SIGN_PSS_SHA512"
],
"title": "Rsa Sign Padding Mode",
"type": "string"
},
"rsa_sign_raw_data_mode": {
"default": true,
"description": "True=对原文签名(服务端内部先哈希),False=data_in_hex 已是哈希摘要的 Hex",
"title": "Rsa Sign Raw Data Mode",
"type": "boolean"
}
},
"title": "RSASignRequest",
"type": "object"
},
"name": "rsa_sign",
"outputSchema": null
},
{
"description": "[rsa] RSA 公钥验签。\n【参数】\n- rsa_public_key_in_pem:PEM 格式公钥\n- data_in_hex:原始数据 Hex\n- signature_in_hex:签名 Hex\n- rsa_sign_padding_mode:必须与签名时一致\n- rsa_sign_raw_data_mode:必须与签名时一致\n【输出】verified(bool,True=验签通过)。",
"inputSchema": {
"properties": {
"data_in_hex": {
"default": "",
"description": "数据的十六进制字符串。RAW 模式为消息原文 Hex,DIGEST 模式为哈希摘要 Hex",
"title": "Data In Hex",
"type": "string"
},
"rsa_public_key_in_pem": {
"default": "",
"description": "RSA 公钥的 PEM 文本(含 BEGIN/END 头尾的 Base64 编码文本)",
"title": "Rsa Public Key In Pem",
"type": "string"
},
"rsa_sign_padding_mode": {
"default": "",
"description": "RSA 签名填充模式,可选值:RSA_SIGN_PKCS1_V1_5_SHA1 / SHA224 / SHA256 / SHA384 / SHA512 或 RSA_SIGN_PSS_SHA1 / SHA224 / SHA256 / SHA384 / SHA512",
"enum": [
"RSA_SIGN_PKCS1_V1_5_SHA1",
"RSA_SIGN_PKCS1_V1_5_SHA224",
"RSA_SIGN_PKCS1_V1_5_SHA256",
"RSA_SIGN_PKCS1_V1_5_SHA384",
"RSA_SIGN_PKCS1_V1_5_SHA512",
"RSA_SIGN_PSS_SHA1",
"RSA_SIGN_PSS_SHA224",
"RSA_SIGN_PSS_SHA256",
"RSA_SIGN_PSS_SHA384",
"RSA_SIGN_PSS_SHA512"
],
"title": "Rsa Sign Padding Mode",
"type": "string"
},
"rsa_sign_raw_data_mode": {
"default": true,
"description": "True=对原文签名(服务端内部先哈希),False=data_in_hex 已是哈希摘要的 Hex",
"title": "Rsa Sign Raw Data Mode",
"type": "boolean"
},
"signature_in_hex": {
"default": "",
"description": "签名的十六进制字符串",
"title": "Signature In Hex",
"type": "string"
}
},
"title": "RSAVerifyRequest",
"type": "object"
},
"name": "rsa_verify",
"outputSchema": null
},
{
"description": "[sm2] SM2 私钥解密。\n【参数】\n- sm2_private_key_in_pem:PEM 格式私钥\n- cipher_data_in_hex:密文 Hex\n- cipher_format:必须指定 C1C3C2_ASN1 / C1C2C3_ASN1 / C1C3C2 / C1C2C3\n- sm2_private_key_password:若私钥加密则传入\n【输出】plain_data_in_hex、plain_length。\n【注意】cipher_format 必须与加密时的格式对应,否则解密失败。",
"inputSchema": {
"properties": {
"cipher_data_in_hex": {
"default": "",
"description": "密文的十六进制字符串",
"title": "Cipher Data In Hex",
"type": "string"
},
"cipher_format": {
"default": "",
"description": "SM2 密文编码格式,可选值:C1C3C2_ASN1 / C1C2C3_ASN1 / C1C3C2 / C1C2C3",
"enum": [
"C1C3C2_ASN1",
"C1C2C3_ASN1",
"C1C3C2",
"C1C2C3"
],
"title": "Cipher Format",
"type": "string"
},
"sm2_private_key_in_pem": {
"default": "",
"description": "SM2 加密私钥的 PEM 文本(含 BEGIN/END ENCRYPTED PRIVATE KEY 头尾)",
"title": "Sm2 Private Key In Pem",
"type": "string"
},
"sm2_private_key_password": {
"default": "",
"description": "SM2 私钥的加密密码(原始字符串,非编码格式)",
"title": "Sm2 Private Key Password",
"type": "string"
}
},
"title": "SM2DecryptionRequest",
"type": "object"
},
"name": "sm2_decryption",
"outputSchema": null
},
{
"description": "[sm2] SM2 公钥加密。\n【参数】\n- sm2_public_key_in_pem:PEM 格式公钥\n- plain_data_in_hex:明文 Hex\n【输出】cipher_in_hex_with_format 字典,同时返回四种编码格式:\n- C1C3C2_ASN1:ASN.1 DER 编码(推荐,国标 GM/T 0009)\n- C1C2C3_ASN1:ASN.1 DER 旧格式\n- C1C3C2:原始拼接格式\n- C1C2C3:原始拼接旧格式\n【注意】每次加密因随机 k 不同,密文不同,这是正常行为。",
"inputSchema": {
"properties": {
"plain_data_in_hex": {
"default": "",
"description": "明文的十六进制字符串",
"title": "Plain Data In Hex",
"type": "string"
},
"sm2_public_key_in_pem": {
"default": "",
"description": "SM2 公钥的 PEM 文本(含 BEGIN/END 头尾的 Base64 编码文本)",
"title": "Sm2 Public Key In Pem",
"type": "string"
}
},
"title": "SM2EncryptionRequest",
"type": "object"
},
"name": "sm2_encryption",
"outputSchema": null
},
{
"description": "[sm2] 解析 SM2 加密私钥(ENCRYPTED PRIVATE KEY PEM)结构,返回 ASN.1 内部字段的 JSON 视图。用于调试与教学,不会解出私钥值。返回字段:structure(ASN.1 结构 JSON,含加密算法 OID、盐、迭代次数等)。",
"inputSchema": {
"properties": {
"private_key_in_pem": {
"default": "",
"description": "SM2 加密私钥的 PEM 文本(含 BEGIN/END ENCRYPTED PRIVATE KEY 头尾)",
"title": "Private Key In Pem",
"type": "string"
}
},
"title": "SM2PrivateKeyStructureParseRequest",
"type": "object"
},
"name": "sm2_private_key_structure_parse",
"outputSchema": null
},
{
"description": "[sm2] 将 SM2 PEM 公钥转换为裸 Hex 编码(未压缩点,04 || X || Y)。返回字段:public_key_in_hex(130 个 hex 字符,65 字节)。",
"inputSchema": {
"properties": {
"public_key_in_pem": {
"default": "",
"description": "SM2 公钥的 PEM 文本(含 BEGIN/END PUBLIC KEY 头尾)",
"title": "Public Key In Pem",
"type": "string"
}
},
"title": "SM2PublicKeyToHexRequest",
"type": "object"
},
"name": "sm2_public_key_to_hex",
"outputSchema": null
},
{
"description": "[sm2] SM2 私钥签名。\n【参数】\n- sm2_private_key_in_pem:PEM 格式私钥\n- data_in_hex:待签数据 Hex。\n · RAW 模式(sign_raw_data_mode=True):消息原文 Hex,服务端走标准 SM2 流程,内部计算 e = SM3(ZA || M) 后签名。\n · DIGEST 模式(sign_raw_data_mode=False):必须传 32 字节 SM3 摘要 e 的 Hex(64 个 hex 字符),服务端不再做任何隐式 SM3,直接对 e 做裸 SM2 签名,与 KMS / ECC / RSA 的 DIGEST 模式语义一致。\n- sign_raw_data_mode:True=RAW(原文),False=DIGEST(32 字节摘要)\n- sm2_private_key_password:若私钥加密则传入\n【输出】signature_in_hex_with_format 字典:\n- RS:r||s 原始拼接(各 32 字节,共 64 字节)\n- RS_ASN1:ASN.1 DER 编码(推荐用于验签)\n【验签时需使用 RS_ASN1 格式的签名,且 sign_raw_data_mode 必须与签名时一致】",
"inputSchema": {
"properties": {
"data_in_hex": {
"default": "",
"description": "数据的十六进制字符串。RAW 模式为消息原文 Hex,DIGEST 模式为哈希摘要 Hex",
"title": "Data In Hex",
"type": "string"
},
"sign_raw_data_mode": {
"default": true,
"description": "True=对原文签名(服务端内部先哈希),False=data_in_hex 已是哈希摘要的 Hex",
"title": "Sign Raw Data Mode",
"type": "boolean"
},
"sm2_private_key_in_pem": {
"default": "",
"description": "SM2 加密私钥的 PEM 文本(含 BEGIN/END ENCRYPTED PRIVATE KEY 头尾)",
"title": "Sm2 Private Key In Pem",
"type": "string"
},
"sm2_private_key_password": {
"default": "",
"description": "SM2 私钥的加密密码(原始字符串,非编码格式)",
"title": "Sm2 Private Key Password",
"type": "string"
}
},
"title": "SM2SignRequest",
"type": "object"
},
"name": "sm2_sign",
"outputSchema": null
},
{
"description": "[sm2] SM2 公钥验签。\n【参数】\n- sm2_public_key_in_pem:PEM 格式公钥\n- data_in_hex:待验签数据 Hex。\n · RAW 模式(sign_raw_data_mode=True):消息原文 Hex,服务端走标准 SM2 流程,内部计算 e = SM3(ZA || M) 后验签。\n · DIGEST 模式(sign_raw_data_mode=False):必须传 32 字节 SM3 摘要 e 的 Hex(64 个 hex 字符),服务端不再做任何隐式 SM3,直接对 e 做裸 SM2 验签,与 KMS / ECC / RSA 的 DIGEST 模式语义一致。\n- signature_in_hex:签名 Hex(必须为 RS_ASN1 格式)\n- signature_format:固定为 RS_ASN1\n- sign_raw_data_mode:必须与签名时一致;True=RAW,False=DIGEST\n【输出】verified(bool,True=验签通过)。\n【完整流程】generate_sm2 → sm2_sign → sm2_verify",
"inputSchema": {
"properties": {
"data_in_hex": {
"default": "",
"description": "数据的十六进制字符串。RAW 模式为消息原文 Hex,DIGEST 模式为哈希摘要 Hex",
"title": "Data In Hex",
"type": "string"
},
"sign_raw_data_mode": {
"default": true,
"description": "True=对原文签名(服务端内部先哈希),False=data_in_hex 已是哈希摘要的 Hex",
"title": "Sign Raw Data Mode",
"type": "boolean"
},
"signature_format": {
"default": "RS_ASN1",
"description": "SM2 签名编码格式,固定值:RS_ASN1(ASN.1 DER 编码)",
"enum": [
"RS_ASN1"
],
"title": "Signature Format",
"type": "string"
},
"signature_in_hex": {
"default": "",
"description": "签名的十六进制字符串",
"title": "Signature In Hex",
"type": "string"
},
"sm2_public_key_in_pem": {
"default": "",
"description": "SM2 公钥的 PEM 文本(含 BEGIN/END 头尾的 Base64 编码文本)",
"title": "Sm2 Public Key In Pem",
"type": "string"
}
},
"title": "SM2VerifyRequest",
"type": "object"
},
"name": "sm2_verify",
"outputSchema": null
},
{
"description": "[sm9_ibc] [sm9_ibc] SM9 标识解密(GM/T 0044)。接收方用 KGC 派发的用户钥解密:输入 user_private_key_in_pem(SM9ExtractKey key_kind=Enc 输出)、private_key_password(用户钥口令,与提取时一致)、identity(接收方标识,必须与加密时一致)、cipher_data_in_hex(DER 密文,≤367 字节)。输出:plain_data_in_hex、plain_length。口令错或标识不符返回 'SM9 decrypt failed'。",
"inputSchema": {
"properties": {
"cipher_data_in_hex": {
"default": "",
"description": "密文的十六进制字符串",
"title": "Cipher Data In Hex",
"type": "string"
},
"identity": {
"default": "",
"description": "SM9 用户标识(原始字符串,如邮箱/账号,1-63 UTF-8 字节;签名/加密/解密均与该标识绑定)",
"title": "Identity",
"type": "string"
},
"private_key_password": {
"default": "",
"description": "私钥的加密密码(原始字符串,非编码格式),可选",
"title": "Private Key Password",
"type": "string"
},
"user_private_key_in_pem": {
"default": "",
"description": "SM9 加密用户私钥的 PEM 文本(含 BEGIN ENCRYPTED SM9 ... PRIVATE KEY 头尾,由 SM9ExtractKey 派发)",
"title": "User Private Key In Pem",
"type": "string"
}
},
"title": "SM9DecryptionRequest",
"type": "object"
},
"name": "sm9_decryption",
"outputSchema": null
},
{
"description": "[sm9_ibc] [sm9_ibc] SM9 标识加密(GM/T 0044)。任何人持主公钥即可加密:输入 master_public_key_in_pem(key_kind=Enc 的主公钥)、identity(接收方标识,密文与标识绑定)、plain_data_in_hex(明文 hex,1-255 字节,SM9 单次加密上限受 KDF 块计数器约束)。输出:cipher_in_hex / cipher_in_base64(DER 编码密文,C1/C3/C2 结构,≤367 字节)。",
"inputSchema": {
"properties": {
"identity": {
"default": "",
"description": "SM9 用户标识(原始字符串,如邮箱/账号,1-63 UTF-8 字节;签名/加密/解密均与该标识绑定)",
"title": "Identity",
"type": "string"
},
"master_public_key_in_pem": {
"default": "",
"description": "SM9 主公钥的 PEM 文本(明文形态,验签/加密侧使用;Sign/Enc 两类主密钥的公钥标签不同)",
"title": "Master Public Key In Pem",
"type": "string"
},
"plain_data_in_hex": {
"default": "",
"description": "明文的十六进制字符串",
"title": "Plain Data In Hex",
"type": "string"
}
},
"title": "SM9EncryptionRequest",
"type": "object"
},
"name": "sm9_encryption",
"outputSchema": null
},
{
"description": "[sm9_ibc] [sm9_ibc] KGC 按标识提取 SM9 用户私钥(GM/T 0044)。输入:key_kind(Sign/Enc)、master_private_key_in_pem(GenerateSm9 输出的加密主私钥)、private_key_password(主私钥口令,提取的用户钥也以同一口令加密)、identity(被派发方标识,如邮箱/账号,1-63 UTF-8 字节)。内置 N-1 探针:GmSSL 加密 PEM 导入无口令校验,错口令可能静默解出垃圾主密钥,因此派生后当场完成一次签名验回/加解密往返(probe_verified=true)才输出。输出:user_private_key_in_pem。错口令返回 'SM9 extract user key failed'。",
"inputSchema": {
"properties": {
"identity": {
"default": "",
"description": "SM9 用户标识(原始字符串,如邮箱/账号,1-63 UTF-8 字节;签名/加密/解密均与该标识绑定)",
"title": "Identity",
"type": "string"
},
"key_kind": {
"default": "Enc",
"description": "SM9 主密钥类型,可选值:Sign(签名主密钥)/ Enc(加密主密钥)",
"enum": [
"Sign",
"Enc"
],
"title": "Key Kind",
"type": "string"
},
"master_private_key_in_pem": {
"default": "",
"description": "SM9 加密主私钥的 PEM 文本(含 BEGIN ENCRYPTED SM9 ... MASTER KEY 头尾,KGC 自留)",
"title": "Master Private Key In Pem",
"type": "string"
},
"private_key_password": {
"default": "",
"description": "私钥的加密密码(原始字符串,非编码格式),可选",
"title": "Private Key Password",
"type": "string"
}
},
"title": "SM9ExtractKeyRequest",
"type": "object"
},
"name": "sm9_extract_key",
"outputSchema": null
},
{
"description": "[sm9_ibc] [sm9_ibc] SM9 标识签名(GM/T 0044)。签名者用 KGC 派发的用户钥签名:输入 user_private_key_in_pem(SM9ExtractKey key_kind=Sign 输出)、private_key_password(用户钥口令)、data_in_hex(消息原文 hex,签名前内部先算 SM3 摘要,流式处理,仅支持原文模式)。输出:signature_in_hex / signature_in_base64(DER 编码签名,固定 104 字节)。",
"inputSchema": {
"properties": {
"data_in_hex": {
"default": "",
"description": "数据的十六进制字符串。RAW 模式为消息原文 Hex,DIGEST 模式为哈希摘要 Hex",
"title": "Data In Hex",
"type": "string"
},
"private_key_password": {
"default": "",
"description": "私钥的加密密码(原始字符串,非编码格式),可选",
"title": "Private Key Password",
"type": "string"
},
"user_private_key_in_pem": {
"default": "",
"description": "SM9 加密用户私钥的 PEM 文本(含 BEGIN ENCRYPTED SM9 ... PRIVATE KEY 头尾,由 SM9ExtractKey 派发)",
"title": "User Private Key In Pem",
"type": "string"
}
},
"title": "SM9SignRequest",
"type": "object"
},
"name": "sm9_sign",
"outputSchema": null
},
{
"description": "[sm9_ibc] [sm9_ibc] SM9 标识验签(GM/T 0044)。验签方只需主公钥与签名者标识:输入 master_public_key_in_pem(key_kind=Sign 的主公钥)、identity(签名者标识)、data_in_hex(消息原文 hex)、signature_in_hex(DER 签名,恰 104 字节 = 208 hex 字符)。verified=false 是成功响应(签名或标识不匹配),仅输入格式非法才返回错误码 'SM9 verify failed'。",
"inputSchema": {
"properties": {
"data_in_hex": {
"default": "",
"description": "数据的十六进制字符串。RAW 模式为消息原文 Hex,DIGEST 模式为哈希摘要 Hex",
"title": "Data In Hex",
"type": "string"
},
"identity": {
"default": "",
"description": "SM9 用户标识(原始字符串,如邮箱/账号,1-63 UTF-8 字节;签名/加密/解密均与该标识绑定)",
"title": "Identity",
"type": "string"
},
"master_public_key_in_pem": {
"default": "",
"description": "SM9 主公钥的 PEM 文本(明文形态,验签/加密侧使用;Sign/Enc 两类主密钥的公钥标签不同)",
"title": "Master Public Key In Pem",
"type": "string"
},
"signature_in_hex": {
"default": "",
"description": "签名的十六进制字符串",
"title": "Signature In Hex",
"type": "string"
}
},
"title": "SM9VerifyRequest",
"type": "object"
},
"name": "sm9_verify",
"outputSchema": null
},
{
"description": "[symmetric_cipher] AEAD 流式加解密(认证加密)。\n【算法】AES256GCM(key=32B) / ChaCha20Poly1305(key=32B) / SM4GCM(key=16B)。\n【参数】\n- algorithm:算法名\n- process_type:Encrypt 或 Decrypt\n- input_data_in_hex:明文或密文 Hex(1B~16MB)\n- key_in_hex:密钥 Hex\n- nonce_in_hex:随机数 Hex(固定 12 字节 = 24 hex 字符)\n- associated_data_in_hex:可选附加认证数据(参与 MAC 但不加密)\n【输出】output_data_in_hex、output_length、output_sha256、algorithm。\n【注意】加密输出包含 16 字节 auth tag;解密失败(篡改检测)会报错。",
"inputSchema": {
"properties": {
"algorithm": {
"default": "AES256GCM",
"description": "密码算法名称(具体可选值因工具而异,见工具描述)",
"enum": [
"AES256GCM",
"ChaCha20Poly1305",
"SM4GCM"
],
"title": "Algorithm",
"type": "string"
},
"associated_data_in_hex": {
"default": "",
"description": "附加认证数据的十六进制字符串(参与 MAC 计算但不加密,可选)",
"title": "Associated Data In Hex",
"type": "string"
},
"input_data_in_hex": {
"default": "",
"description": "输入数据的十六进制字符串(加密时为明文,解密时为密文,1B~16MB)",
"title": "Input Data In Hex",
"type": "string"
},
"key_in_hex": {
"default": "",
"description": "密钥的十六进制字符串。长度取决于算法:AES256=64 字符(32B),AES128/SM4=32 字符(16B)",
"title": "Key In Hex",
"type": "string"
},
"nonce_in_hex": {
"default": "",
"description": "随机数的十六进制字符串,固定 24 个 hex 字符(12 字节)",
"title": "Nonce In Hex",
"type": "string"
},
"process_type": {
"default": "Encrypt",
"description": "操作类型,可选值:Encrypt / Decrypt",
"enum": [
"Encrypt",
"Decrypt"
],
"title": "Process Type",
"type": "string"
}
},
"title": "StreamCipherRequest",
"type": "object"
},
"name": "stream_cipher",
"outputSchema": null
},
{
"description": "[other] [symmetric_cipher] AES-XTS 可调窄分组模式加解密(IEEE 1619 / NIST SP 800-38E)。algorithm 可选 AES128XTS(key 32B = 数据密钥 16B + 调组密钥 16B)或 AES256XTS(key 64B = 32B + 32B)。tweak_in_hex 为 16 字节调整值,编码数据单元编号/扇区地址,密文与数据单元位置绑定。process_type 可选 Encrypt / Decrypt(两个变换不同,须显式声明)。输入 16B ~ 16MB,无填充,密文与明文等长;非 16 倍数的尾部自动走密文窃取(ciphertext stealing)。模式特点:各数据单元独立加密,支持并行与随机访问,同一数据单元加解密自同步;同一密钥下 tweak 严禁重复使用(否则两个数据单元明文相同会直接暴露相等关系);XTS 只提供保密性、可塑性攻击下无认证,需要防篡改时在外层叠加 AEAD 或签名。典型使用场景:BitLocker / LUKS2 / FileVault 全盘加密,AMD SEV-SNP 以 AES-256-XTS + VEK 加密 guest 内存(tweak 按物理地址派生,每页唯一),Intel TDX 内存加密同族。返回字段:output_data_in_hex、output_length、output_sha256、algorithm。",
"inputSchema": {
"properties": {
"algorithm": {
"default": "AES256XTS",
"description": "密码算法名称(具体可选值因工具而异,见工具描述)",
"enum": [
"AES128XTS",
"AES256XTS"
],
"title": "Algorithm",
"type": "string"
},
"input_data_in_hex": {
"default": "",
"description": "输入数据的十六进制字符串(加密时为明文,解密时为密文,1B~16MB)",
"title": "Input Data In Hex",
"type": "string"
},
"key_in_hex": {
"default": "",
"description": "密钥的十六进制字符串。长度取决于算法:AES256=64 字符(32B),AES128/SM4=32 字符(16B)",
"title": "Key In Hex",
"type": "string"
},
"process_type": {
"default": "Encrypt",
"description": "操作类型,可选值:Encrypt / Decrypt",
"enum": [
"Encrypt",
"Decrypt"
],
"title": "Process Type",
"type": "string"
},
"tweak_in_hex": {
"default": "",
"title": "Tweak In Hex",
"type": "string"
}
},
"title": "XtsCipherRequest",
"type": "object"
},
"name": "xts_cipher",
"outputSchema": null
},
{
"description": "[symmetric_cipher] ZUC-128 流密码(中国商密算法)。由于 ZUC 是对称流密码,加解密为同一操作,传入明文即输出密文,反之亦然。key_in_hex 固定 16 字节(32 hex 字符),iv_in_hex 固定 16 字节(32 hex 字符),input_data_in_hex 原始数据长度 1B ~ 16MB。返回字段:output_data_in_hex(输出 Hex)、output_length(字节数)。",
"inputSchema": {
"properties": {
"input_data_in_hex": {
"default": "",
"description": "输入数据的十六进制字符串(加密时为明文,解密时为密文,1B~16MB)",
"title": "Input Data In Hex",
"type": "string"
},
"iv_in_hex": {
"default": "",
"description": "初始向量的十六进制字符串,固定 32 个 hex 字符(16 字节)",
"title": "Iv In Hex",
"type": "string"
},
"key_in_hex": {
"default": "",
"description": "密钥的十六进制字符串。长度取决于算法:AES256=64 字符(32B),AES128/SM4=32 字符(16B)",
"title": "Key In Hex",
"type": "string"
}
},
"title": "ZUCCipherRequest",
"type": "object"
},
"name": "zuc_cipher",
"outputSchema": null
}
]
}Verify it yourself
curl -s https://api.teppi.xyz/v1/evidence/sha256:95df8bff26442cf7ea46de7c3458a1d53dcf41703274459a25afe252fe426a80 | sha256sum