1e41f4b71Sopenharmony_ci# Encryption and Decryption with an SM4 Symmetric Key (CBC Mode) (ArkTS)
2e41f4b71Sopenharmony_ci
3e41f4b71Sopenharmony_ci
4e41f4b71Sopenharmony_ciFor details about the algorithm specifications, see [SM4](crypto-sym-encrypt-decrypt-spec.md#sm4).
5e41f4b71Sopenharmony_ci
6e41f4b71Sopenharmony_ci**Encryption**
7e41f4b71Sopenharmony_ci
8e41f4b71Sopenharmony_ci
9e41f4b71Sopenharmony_ci1. Use [cryptoFramework.createSymKeyGenerator](../../reference/apis-crypto-architecture-kit/js-apis-cryptoFramework.md#cryptoframeworkcreatesymkeygenerator) and [SymKeyGenerator.generateSymKey](../../reference/apis-crypto-architecture-kit/js-apis-cryptoFramework.md#generatesymkey-1) to generate a 128-bit SM4 symmetric key (**SymKey**).
10e41f4b71Sopenharmony_ci   
11e41f4b71Sopenharmony_ci   In addition to the example in this topic, [SM4](crypto-sym-key-generation-conversion-spec.md#sm4) and [Randomly Generating a Symmetric Key](crypto-generate-sym-key-randomly.md) may help you better understand how to generate an SM4 symmetric key. Note that the input parameters in the reference documents may be different from those in the example below.
12e41f4b71Sopenharmony_ci
13e41f4b71Sopenharmony_ci2. Use [cryptoFramework.createCipher](../../reference/apis-crypto-architecture-kit/js-apis-cryptoFramework.md#cryptoframeworkcreatecipher) with the string parameter **'SM4_128|CBC|PKCS7'** to create a **Cipher** instance. The key type is **SM4_128**, block cipher mode is **CBC**, and the padding mode is **PKCS7**.
14e41f4b71Sopenharmony_ci
15e41f4b71Sopenharmony_ci3. Use [Cipher.init](../../reference/apis-crypto-architecture-kit/js-apis-cryptoFramework.md#init-1) to initialize the **Cipher** instance. In the **Cipher.init** API, set **opMode** to **CryptoMode.ENCRYPT_MODE** (encryption), **key** to **SymKey** (the key for encryption), and **params** to **IvParamsSpec** corresponding to the CBC mode.
16e41f4b71Sopenharmony_ci
17e41f4b71Sopenharmony_ci4. Use [Cipher.update](../../reference/apis-crypto-architecture-kit/js-apis-cryptoFramework.md#update-1) to pass in the data to be encrypted (plaintext).
18e41f4b71Sopenharmony_ci   
19e41f4b71Sopenharmony_ci   - If a small amount of data is to be encrypted, you can use **Cipher.doFinal** immediately after **Cipher.init**.
20e41f4b71Sopenharmony_ci   - If a large amount of data is to be encrypted, you can call **Cipher.update** multiple times to pass in the data by segment.
21e41f4b71Sopenharmony_ci
22e41f4b71Sopenharmony_ci5. Use [Cipher.doFinal](../../reference/apis-crypto-architecture-kit/js-apis-cryptoFramework.md#dofinal-1) to obtain the encrypted data.
23e41f4b71Sopenharmony_ci   
24e41f4b71Sopenharmony_ci   - If data has been passed in by **Cipher.update**, pass in **null** in the **data** parameter of **Cipher.doFinal**.
25e41f4b71Sopenharmony_ci   - The output of **Cipher.doFinal** may be **null**. To avoid exceptions, always check whether the result is **null** before accessing specific data.
26e41f4b71Sopenharmony_ci
27e41f4b71Sopenharmony_ci
28e41f4b71Sopenharmony_ci**Decryption**
29e41f4b71Sopenharmony_ci
30e41f4b71Sopenharmony_ci
31e41f4b71Sopenharmony_ci1. Use [Cipher.init](../../reference/apis-crypto-architecture-kit/js-apis-cryptoFramework.md#init-1) to initialize the **Cipher** instance. In the **Cipher.init** API, set **opMode** to **CryptoMode.DECRYPT_MODE** (decryption), **key** to **SymKey** (the key for decryption), and **params** to **IvParamsSpec** corresponding to the CBC mode.
32e41f4b71Sopenharmony_ci
33e41f4b71Sopenharmony_ci2. Use [Cipher.update](../../reference/apis-crypto-architecture-kit/js-apis-cryptoFramework.md#update-1) to pass in the data to be decrypted (ciphertext).
34e41f4b71Sopenharmony_ci
35e41f4b71Sopenharmony_ci3. Use [Cipher.doFinal](../../reference/apis-crypto-architecture-kit/js-apis-cryptoFramework.md#dofinal-1) to obtain the decrypted data.
36e41f4b71Sopenharmony_ci
37e41f4b71Sopenharmony_ci
38e41f4b71Sopenharmony_ci- Example (using asynchronous APIs):
39e41f4b71Sopenharmony_ci
40e41f4b71Sopenharmony_ci  ```ts
41e41f4b71Sopenharmony_ci  import { cryptoFramework } from '@kit.CryptoArchitectureKit';
42e41f4b71Sopenharmony_ci  import { buffer } from '@kit.ArkTS';
43e41f4b71Sopenharmony_ci
44e41f4b71Sopenharmony_ci  function genIvParamsSpec() {
45e41f4b71Sopenharmony_ci    let arr = [0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0]; // 16 bytes
46e41f4b71Sopenharmony_ci    let dataIv = new Uint8Array(arr);
47e41f4b71Sopenharmony_ci    let ivBlob: cryptoFramework.DataBlob = { data: dataIv };
48e41f4b71Sopenharmony_ci    let ivParamsSpec: cryptoFramework.IvParamsSpec = {
49e41f4b71Sopenharmony_ci      algName: "IvParamsSpec",
50e41f4b71Sopenharmony_ci      iv: ivBlob
51e41f4b71Sopenharmony_ci    };
52e41f4b71Sopenharmony_ci    return ivParamsSpec;
53e41f4b71Sopenharmony_ci  }
54e41f4b71Sopenharmony_ci  // Encrypt the message.
55e41f4b71Sopenharmony_ci  async function encryptMessagePromise(symKey: cryptoFramework.SymKey, plainText: cryptoFramework.DataBlob) {
56e41f4b71Sopenharmony_ci    let cipher = cryptoFramework.createCipher('SM4_128|CBC|PKCS7');
57e41f4b71Sopenharmony_ci    let iv = genIvParamsSpec();
58e41f4b71Sopenharmony_ci    await cipher.init(cryptoFramework.CryptoMode.ENCRYPT_MODE, symKey, iv);
59e41f4b71Sopenharmony_ci    let encryptData = await cipher.doFinal(plainText);
60e41f4b71Sopenharmony_ci    return encryptData;
61e41f4b71Sopenharmony_ci  }
62e41f4b71Sopenharmony_ci  // Decrypt the message.
63e41f4b71Sopenharmony_ci  async function decryptMessagePromise(symKey: cryptoFramework.SymKey, cipherText: cryptoFramework.DataBlob) {
64e41f4b71Sopenharmony_ci    let decoder = cryptoFramework.createCipher('SM4_128|CBC|PKCS7');
65e41f4b71Sopenharmony_ci    let iv = genIvParamsSpec();
66e41f4b71Sopenharmony_ci    await decoder.init(cryptoFramework.CryptoMode.DECRYPT_MODE, symKey, iv);
67e41f4b71Sopenharmony_ci    let decryptData = await decoder.doFinal(cipherText);
68e41f4b71Sopenharmony_ci    return decryptData;
69e41f4b71Sopenharmony_ci  }
70e41f4b71Sopenharmony_ci  async function genSymKeyByData(symKeyData: Uint8Array) {
71e41f4b71Sopenharmony_ci    let symKeyBlob: cryptoFramework.DataBlob = { data: symKeyData };
72e41f4b71Sopenharmony_ci    let symGenerator = cryptoFramework.createSymKeyGenerator('SM4_128');
73e41f4b71Sopenharmony_ci    let symKey = await symGenerator.convertKey(symKeyBlob);
74e41f4b71Sopenharmony_ci    console.info('convertKey success');
75e41f4b71Sopenharmony_ci    return symKey;
76e41f4b71Sopenharmony_ci  }
77e41f4b71Sopenharmony_ci  async function main() {
78e41f4b71Sopenharmony_ci    try {
79e41f4b71Sopenharmony_ci      let keyData = new Uint8Array([7, 154, 52, 176, 4, 236, 150, 43, 237, 9, 145, 166, 141, 174, 224, 131]);
80e41f4b71Sopenharmony_ci      let symKey = await genSymKeyByData(keyData);
81e41f4b71Sopenharmony_ci      let message = "This is a test";
82e41f4b71Sopenharmony_ci      let plainText: cryptoFramework.DataBlob = { data: new Uint8Array(buffer.from(message, 'utf-8').buffer) };
83e41f4b71Sopenharmony_ci      let encryptText = await encryptMessagePromise(symKey, plainText);
84e41f4b71Sopenharmony_ci      let decryptText = await decryptMessagePromise(symKey, encryptText);
85e41f4b71Sopenharmony_ci      if (plainText.data.toString() === decryptText.data.toString()) {
86e41f4b71Sopenharmony_ci        console.info('decrypt ok');
87e41f4b71Sopenharmony_ci        console.info('decrypt plainText: ' + buffer.from(decryptText.data).toString('utf-8'));
88e41f4b71Sopenharmony_ci      } else {
89e41f4b71Sopenharmony_ci        console.error('decrypt failed');
90e41f4b71Sopenharmony_ci      }
91e41f4b71Sopenharmony_ci    } catch (error) {
92e41f4b71Sopenharmony_ci      console.error(`SM4 "${error}", error code: ${error.code}`);
93e41f4b71Sopenharmony_ci    }
94e41f4b71Sopenharmony_ci  }
95e41f4b71Sopenharmony_ci  ```
96e41f4b71Sopenharmony_ci
97e41f4b71Sopenharmony_ci- Example (using synchronous APIs):
98e41f4b71Sopenharmony_ci
99e41f4b71Sopenharmony_ci  ```ts
100e41f4b71Sopenharmony_ci  import { cryptoFramework } from '@kit.CryptoArchitectureKit';
101e41f4b71Sopenharmony_ci  import { buffer } from '@kit.ArkTS';
102e41f4b71Sopenharmony_ci
103e41f4b71Sopenharmony_ci  function genIvParamsSpec() {
104e41f4b71Sopenharmony_ci    let arr = [0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0]; // 16 bytes
105e41f4b71Sopenharmony_ci    let dataIv = new Uint8Array(arr);
106e41f4b71Sopenharmony_ci    let ivBlob: cryptoFramework.DataBlob = { data: dataIv };
107e41f4b71Sopenharmony_ci    let ivParamsSpec: cryptoFramework.IvParamsSpec = {
108e41f4b71Sopenharmony_ci      algName: "IvParamsSpec",
109e41f4b71Sopenharmony_ci      iv: ivBlob
110e41f4b71Sopenharmony_ci    };
111e41f4b71Sopenharmony_ci    return ivParamsSpec;
112e41f4b71Sopenharmony_ci  }
113e41f4b71Sopenharmony_ci  // Encrypt the message.
114e41f4b71Sopenharmony_ci  function encryptMessage(symKey: cryptoFramework.SymKey, plainText: cryptoFramework.DataBlob) {
115e41f4b71Sopenharmony_ci    let cipher = cryptoFramework.createCipher('SM4_128|CBC|PKCS7');
116e41f4b71Sopenharmony_ci    let iv = genIvParamsSpec();
117e41f4b71Sopenharmony_ci    cipher.initSync(cryptoFramework.CryptoMode.ENCRYPT_MODE, symKey, iv);
118e41f4b71Sopenharmony_ci    let encryptData = cipher.doFinalSync(plainText);
119e41f4b71Sopenharmony_ci    return encryptData;
120e41f4b71Sopenharmony_ci  }
121e41f4b71Sopenharmony_ci  // Decrypt the message.
122e41f4b71Sopenharmony_ci  function decryptMessage(symKey: cryptoFramework.SymKey, cipherText: cryptoFramework.DataBlob) {
123e41f4b71Sopenharmony_ci    let decoder = cryptoFramework.createCipher('SM4_128|CBC|PKCS7');
124e41f4b71Sopenharmony_ci    let iv = genIvParamsSpec();
125e41f4b71Sopenharmony_ci    decoder.initSync(cryptoFramework.CryptoMode.DECRYPT_MODE, symKey, iv);
126e41f4b71Sopenharmony_ci    let decryptData = decoder.doFinalSync(cipherText);
127e41f4b71Sopenharmony_ci    return decryptData;
128e41f4b71Sopenharmony_ci  }
129e41f4b71Sopenharmony_ci  async function genSymKeyByData(symKeyData: Uint8Array) {
130e41f4b71Sopenharmony_ci    let symKeyBlob: cryptoFramework.DataBlob = { data: symKeyData };
131e41f4b71Sopenharmony_ci    let symGenerator = cryptoFramework.createSymKeyGenerator('SM4_128');
132e41f4b71Sopenharmony_ci    let symKey = symGenerator.convertKey(symKeyBlob);
133e41f4b71Sopenharmony_ci    console.info('convertKey success');
134e41f4b71Sopenharmony_ci    return symKey;
135e41f4b71Sopenharmony_ci  }
136e41f4b71Sopenharmony_ci  async function main() {
137e41f4b71Sopenharmony_ci    try {
138e41f4b71Sopenharmony_ci      let keyData = new Uint8Array([7, 154, 52, 176, 4, 236, 150, 43, 237, 9, 145, 166, 141, 174, 224, 131]);
139e41f4b71Sopenharmony_ci      let symKey = await genSymKeyByData(keyData);
140e41f4b71Sopenharmony_ci      let message = "This is a test";
141e41f4b71Sopenharmony_ci      let plainText: cryptoFramework.DataBlob = { data: new Uint8Array(buffer.from(message, 'utf-8').buffer) };
142e41f4b71Sopenharmony_ci      let encryptText = encryptMessage(symKey, plainText);
143e41f4b71Sopenharmony_ci      let decryptText = decryptMessage(symKey, encryptText);
144e41f4b71Sopenharmony_ci      if (plainText.data.toString() === decryptText.data.toString()) {
145e41f4b71Sopenharmony_ci        console.info('decrypt ok');
146e41f4b71Sopenharmony_ci        console.info('decrypt plainText: ' + buffer.from(decryptText.data).toString('utf-8'));
147e41f4b71Sopenharmony_ci      } else {
148e41f4b71Sopenharmony_ci        console.error('decrypt failed');
149e41f4b71Sopenharmony_ci      }
150e41f4b71Sopenharmony_ci    } catch (error) {
151e41f4b71Sopenharmony_ci      console.error(`SM4 "${error}", error code: ${error.code}`);
152e41f4b71Sopenharmony_ci    }
153e41f4b71Sopenharmony_ci  }
154e41f4b71Sopenharmony_ci  ```
155