引用本文:唐长虹,赵艳琦,杨晓艺,冯琦,禹勇.加权门限SM2签名方案.软件学报,2025,36(8):3883-3895
【打印本页】   【下载PDF全文】   查看/发表评论  【EndNote】   【RefMan】   【BibTex】
←前一篇|后一篇→ 过刊浏览    高级检索
本文已被:浏览 988次   下载 1777 本文二维码信息
码上扫一扫!
分享到: 微信 更多
加权门限SM2签名方案
唐长虹1, 赵艳琦1, 杨晓艺1, 冯琦2, 禹勇3
1.西安邮电大学 网络空间安全学院, 陕西 西安 710121;2.武汉大学 国家网络安全学院, 湖北 武汉 430072;3.陕西师范大学 计算机科学学院, 陕西 西安 710119
摘要:
随着物联网和移动互联网技术的发展, 各类移动终端设备被接入互联网中. 当对移动终端设备进行识别和认证时, 通常需要验证其提交的数字签名. 但移动终端设备本身的计算能力受限, 往往采用软件模块来保存密钥至本地或者智能芯片中, 增加了密钥泄露的风险. 现实应用中多采用门限数字签名来抵抗这一攻击, 借助多方合作来分散风险, 提升设备可用性. SM2数字签名算法是我国自主研发的椭圆曲线公钥密码算法, 于2016年成为国家密码标准, 被广泛应用于政府部门、金融机构、电子认证服务提供商等领域. 设计高可用的门限SM2数字签名备受关注, 但这类方案的构造依旧较少, 同时也缺乏对参与者权重的考量. 因此, 提出更加灵活的加权门限SM2数字签名方案. 在加权门限SM2数字签名中签名者分配不同权重, 之后多个签名者共同生成一个有效的签名. 在方法上, 基于中国剩余定理的加权门限秘密共享将SM2数字签名的秘钥进行分割. 参与者不只是单一的达到门限值就可以得到签名密钥, 而需要通过计算参与者权重之和, 并达到相应的秘密门限值t和重构门限T, 才能了解到密钥的部分信息或者恢复出签名密钥. 在秘密分割时, 对SM2数字签名算法的签名私钥进行变形, 以完成签名阶段对SM2密钥进行求逆的这一操作. 最后, 将所提方案与门限SM2签名以及联合SM2签名等已有工作进行分析比较, 该算法在提升SM2签名方案功能性的同时进一步降低了计算开销.
关键词:  SM2  加权门限  中国剩余定理  秘密共享
DOI:10.13328/j.cnki.jos.007255
分类号:
基金项目:国家重点研发计划(2022YFB2701500); 国家自然科学基金(61872229, U19B2021, 62202375, 62202339); 陕西省杰出青年基金(2022JC-47); 陕西省科学技术协会青年人才托举计划(20220134); 陕西省重点研发计划重点产业创新链(群)(2024GX-ZDCYL-01-09, 2024GX-ZDCYL-01-15); 陕西省教育厅科学研究项目(22JK0557)
Weighted Threshold SM2 Signature Scheme
TANG Chang-Hong1, ZHAO Yan-Qi1, YANG Xiao-Yi1, FENG Qi2, YU Yong3
1.School of Cyberspace Security, Xi’an University of Posts and Telecommunications, Xi’an 710121, China;2.School of Cyber Science and Engineering, Wuhan University, Wuhan 430072, China;3.School of Computer Science, Shaanxi Normal University, Xi’an 710119, China
Abstract:
As the Internet of Things and mobile Internet technologies continue to advance, a wide range of mobile devices are connected to the Internet. To identify and authenticate these devices, it is necessary to verify the digital signatures they submit. However, many mobile devices have limited computing power and typically use software modules to store keys locally or on smart chips, which increases the risk of key exposure. To avoid this risk, threshold signatures are commonly employed in real-world applications. These signatures rely on multi-party cooperation to decentralize risks and enhance device availability. The SM2 digital signature algorithm, an elliptic curve public key cryptographic algorithm developed independently by China, was adopted as the national cryptography standard in 2016. It finds extensive use in various sectors including government agencies, financial institutions, and electronic authentication service providers. While there has been interest in constructing SM2 threshold signatures with high availability, there are still limited schemes available, and participant weights have not been adequately considered. This study proposes a flexible SM2 weighted threshold signature scheme. In this scheme, signers are assigned different weights, and multiple signers collaborate to generate a valid signature. The key of the SM2 digital signature is divided based on the weighted threshold secret sharing of the Chinese remainder theorem. Participants do not acquire a signing key only by meeting the threshold value. They have to meet the corresponding secret threshold t and the reconstruction threshold T by calculating the sum of the weights of participants to obtain part of the key information or recover the signing key. During secret segmentation, the private signing key of the SM2 digital signature algorithm is transformed to complete the inversion of the SM2 key during the signing stage. Finally, the proposed scheme is compared with other schemes such as SM2 threshold signatures and joint SM2 signatures. The proposed scheme not only reduces computational overhead but also enhances the functionality of the SM2 signature.
Key words:  SM2  weighted threshold  Chinese remainder theorem (CRT)  secret sharing

引用本文:
【打印本页】   【下载PDF全文】   查看/发表评论  【EndNote】   【RefMan】   【BibTex】
←前一篇|后一篇→ 过刊浏览    高级检索
本文已被:浏览次   下载  
分享到: 微信 更多
摘要:
关键词:  
DOI:
分类号:
基金项目:
Abstract:
Key words: