Method for implementing SM2 white-box digital signature based on residue number system

A residual system and digital signature technology, applied in the field of information security, can solve the problems of high use cost, inability to deal with white-box attack methods, poor versatility, etc., and achieve the effect of high practicability, expanding the scope of use, and reducing the cost of use.

CN106612182AActive Publication Date: 2017-05-03NO 30 INST OF CHINA ELECTRONIC TECH GRP CORP
2 Cites 21 Cited by

Patent Information

Authority / Receiving Office
CN · China
Current Assignee / Owner
Publication Date
2017-05-03

Smart Images

  • Figure 1
    Figure 1
  • Figure 2
    Figure 2
  • Figure 3
    Figure 3
Patent Text Reader

Abstract

The invention provides a method for implementing an SM2 white-box digital signature based on a residue number system. The method carries out research in allusion to problems that a key is unsafe in operation in an incredible environment and that a malicious attacker can acquire the key of the system through a means of white-box attacks. Splitting of a big number is realized through using the residue number system, so that the size of a key table is reduced; an intermediate result is ensured to be invisible to the attacker through using scrambling and confounding; and the uncertainty of a terminal key operation relation is ensured through using a random factor of the cloud, the safety of a signature private key in the terminal signature operation process is realized, and verification can be performed by using a standard SM2 signature verification algorithm at the same time. The method provided by the invention is small in required storage space, high in calculation efficiency, good in safety and high in practicability.
Need to check novelty before this filing date? Find Prior Art

Description

technical field

[0001] The invention relates to the technical field of information security, in particular to a method for realizing an SM2 white-box digital signature based on a remainder system. Background technique

[0002] In the existing software encryption algorithm, the key is directly in the memory of the computing platform, and the attacker can steal the key through malicious software, etc., which cannot deal with the existing white box attack method; the existing hardware encryption algorithm, It can better guarantee the security of key calculation, but the relative use cost is relatively high, and the versatility is poor, and it cannot be used for some application scenarios with relatively low security requirements; at the same time, some research institutions have proposed cloud-based Part of the key and the software encryption algorithm of the key decentralized storage strategy, but the cloud plus terminal strategy cannot resist the leakage of the local private ...

Examples

Embodiment Construction

[0031] The design idea of ​​the present invention is to conduct research on the problem that the key operation is not safe in an untrusted environment, and malicious attackers can obtain the system key through white-box attack means, and realize the splitting of large numbers by using the remainder system, thereby reducing The size of the key table; by using scrambling and obfuscation to ensure that the intermediate results are invisible to the attacker; by using the random factor in the cloud to ensure the unknownness of the terminal key calculation relationship, the security of the signature private key during the terminal signature calculation process is realized, and at the same time It can be verified using the standard SM2 signature verification algorithm.

[0032] The present invention is constructed based on the national commercial cryptographic algorithm SM2 digital signature algorithm. Please refer to the management standard issued by the National Commercial Cryptogra...