基于国密SM9的密钥隔离签名
CSTR:
作者:
作者单位:

作者简介:

通讯作者:

中图分类号:

TP309

基金项目:

国家自然科学基金(U23B2002); 江苏省研究生科研创新计划 (KYCX25_1146, KYCX25_1159)


Key-isolated Signature Based on SM9
Author:
Affiliation:

Fund Project:

  • 摘要
  • |
  • 图/表
  • |
  • 访问统计
  • |
  • 参考文献
  • |
  • 相似文献
  • |
  • 引证文献
  • |
  • 资源附件
  • |
  • 文章评论
    摘要:

    签名计算通常在移动电话或小型物联网设备等不安全的物理设备上进行, 这可能导致私钥暴露, 从而引发整个密码系统的崩溃. 密钥隔离签名方案是减轻私钥暴露造成的损害的一种方法. 在密钥隔离密码系统中, 公钥在整个时间周期内保持不变, 固定私钥被存储在物理安全设备上. 在每个离散的时间段开始时, 不安全设备通过与存储固定私钥的物理安全设备的交互以获得当前时间片的临时私钥. 一个安全的基于身份的密钥隔离签名方案需要满足签名不可伪造性和密钥隔离性. 密钥隔离性保证了即使一个攻击者获得了多个时间段的临时私钥, 它也无法伪造其他时间段的签名. SM9是我国自主设计的商用标识密码算法. 将密钥隔离方法应用于SM9基于身份的签名方案中, 解决原方案中存在的私钥暴露问题. 首先给出基于身份的密钥隔离签名的安全模型. 然后构造一个基于身份的SM9密钥隔离签名方案. 最后给出详细的安全性证明和实验分析.

    Abstract:

    The computation of signatures is typically performed on physically insecure devices such as mobile phones or small IoT devices, which may lead to private key exposure and subsequently compromise the entire cryptographic system. Key-insulated signature schemes serve as a method to mitigate the damage caused by private key exposure. In a key-insulated cryptosystem, the public key remains constant throughout the entire time period, and the fixed private key is stored on a physically secure device. At the beginning of each time period, the insecure device interacts with the physically secure device storing the fixed private key to obtain the temporary private key for the current time slice. A secure identity-based key-insulated signature scheme must satisfy both unforgeability and key insulation. Key insulation ensures that even if an adversary obtains temporary private keys for multiple time periods, they cannot forge signatures for other periods. SM9 is a commercial identity-based cryptographic standard independently developed by China. This study applies the key-insulated method to the SM9 identity-based signature scheme to resolve the private key exposure issue present in the original scheme. First, a security model for identity-based key-insulated signatures is presented. Then, an identity-based key-insulated signature scheme based on SM9 is constructed. Finally, detailed security proofs and experimental analysis are provided.

    参考文献
    相似文献
    引证文献
引用本文

高睿,丁昀,高欣,王化群.基于国密SM9的密钥隔离签名.软件学报,,():1-11

复制
相关视频

分享
文章指标
  • 点击次数:
  • 下载次数:
  • HTML阅读次数:
  • 引用次数:
历史
  • 收稿日期:2024-12-03
  • 最后修改日期:2025-03-17
  • 录用日期:
  • 在线发布日期: 2025-09-10
  • 出版日期:
文章二维码
您是第位访问者
版权所有:中国科学院软件研究所 京ICP备05046678号-3
地址:北京市海淀区中关村南四街4号,邮政编码:100190
电话:010-62562563 传真:010-62562533 Email:jos@iscas.ac.cn
技术支持:北京勤云科技发展有限公司

京公网安备 11040202500063号