引用本文:严都力,禹勇,李艳楠,李慧琳,赵艳琦,田爱奎.ECDSA签名方案的颠覆攻击与改进.软件学报,2023,34(6):2892-2905
【打印本页】   【下载PDF全文】   查看/发表评论  【EndNote】   【RefMan】   【BibTex】
←前一篇|后一篇→ 过刊浏览    高级检索
本文已被:浏览 1871次   下载 4157 本文二维码信息
码上扫一扫!
分享到: 微信 更多
ECDSA签名方案的颠覆攻击与改进
严都力1,2, 禹勇1,2, 李艳楠3, 李慧琳1, 赵艳琦1, 田爱奎4
1.陕西师范大学 计算机科学学院, 陕西 西安 710119;2.密码科学技术国家重点实验室, 北京 100878;3.School of Computer and Information Technology, University of Wollongong, Wollongong 2522, Australia;4.山东理工大学 计算机科学与技术学院, 山东 淄博 255049
摘要:
斯诺登事件揭露了某些密码体制的确存在被颠覆的事实.椭圆曲线数字签名算法(elliptic curve digital signature algorithm,ECDSA)在同等安全强度下,因其签名长度短而被广泛应用,如被用于比特币交易单的签名.ECDSA签名算法是否会被颠覆且存在修复方法仍是一个挑战.正面回答了这一问题:首先利用伪随机函数(pseudorandom function,PRF)计算$\widetilde k$替换ECDSA签名中使用的随机数k,实现了对ECDSA签名的颠覆,使得敌手只需获得至多3个连续签名就能够提取出签名私钥;然后,将签名私钥、签名消息与其他随机签名组件的哈希值作为签名算法的第2个随机数,对ECDSA签名进行了改进,提出了抗颠覆攻击的ECDSA签名,即使敌手替换新签名算法的某个组件,也无法提取签名私钥的任何信息;最后,对提出的算法与已有算法进行了效率测试,实验结果证明了提出的算法在计算复杂度与算法执行效率方面都具备优势.
关键词:  斯诺登事件  ECDSA签名  比特币  颠覆攻击  哈希函数
DOI:10.13328/j.cnki.jos.006516
分类号:TP309
基金项目:国家自然科学基金(61872229,U19B2021);教育部2020年度区块链核心技术战略研究项目(2020KJ010301);陕西省重点研发计划(2020ZDLGY09-06,2021ZDLGY06-04)
Subversion Attack and Improvement of ECDSA Signature Scheme
YAN Du-Li1,2, YU Yong1,2, LI Yan-Nan3, LI Hui-Lin1, ZHAO Yan-Qi1, TIAN Ai-Kui4
1.School of Computer Science, Shaanxi Normal University, Xi'an 710119, China;2.State Key Laboratory of Cryptology, Beijing 100878, China;3.School of Computer and Information Technology, University of Wollongong, Wollongong 2522, Australia;4.School of Computer Science and Technology, Shandong University of Technology, Zibo 255049, China
Abstract:
The Snowden incident revealed the fact that certain cryptosystems were indeed subverted. Elliptic curve digital signature algorithm (ECDSA) has been widely used due to its short signature length advantage under the same security level, for example, signing bitcoin transactions. However, whether the ECDSA can be subverted and how to resist this attack remain a challenge. This study answers this question positively. Firstly, it is shown that how to use a pseudorandom function (PRF) to calculate a random value to replace the randomness used in the ECDSA. The subverted ECDSA enables an adversary to extract signing private key by obtaining at most three consecutive signatures. Secondly, the hash value of private key, message, and the random signature component are used as the second random number to improve the ECDSA scheme, and as a result, the signature scheme against subversion-resistant attack is proposed. Even an adversary replaces the component of the new signature algorithm, it cannot extract any information of the signing key. Finally, the proposed algorithm and existing algorithm are implemented, and the implementation demonstrates that the proposed scheme has advantages in terms of computational complexity and efficiency.
Key words:  Snowden incident  ECDSA signature  bitcoin  subversion attack  hash function

引用本文:
【打印本页】   【下载PDF全文】   查看/发表评论  【EndNote】   【RefMan】   【BibTex】
←前一篇|后一篇→ 过刊浏览    高级检索
本文已被:浏览次   下载  
分享到: 微信 更多
摘要:
关键词:  
DOI:
分类号:
基金项目:
Abstract:
Key words: