An SM2 Digital Signature Method and System Resistant to Side-Channel Attacks

By combining random mask and diffusion error methods in the SM2 digital signature algorithm, the signature segments r and s are generated using the Montgomery point multiplication algorithm, which solves the problem that the SM2 digital signature algorithm cannot resist error injection attacks and grid attacks at the same time, achieving higher security and side channel attack protection.

CN114969836BActive Publication Date: 2025-07-04XINGTANG TELECOMM TECH CO LTD +2
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202110197626.6
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2021-02-22
Publication Date
2025-07-04
Estimated Expiration
2041-02-22

AI Technical Summary

Technical Problem

The existing SM2 digital signature algorithm cannot resist error injection attacks and grid attacks at the same time, which poses security risks.

Method used

The signature generation process is adopted that combines random mask and diffusion error methods. By generating the first signature segment r and the second signature segment s, the point multiplication operation is performed using the Montgomery point multiplication algorithm, the random number w is added as the mask of k and the nonlinear nature of point multiplication is used to diffusion errors to resist side channel attacks.

Benefits of technology

Effectively resist error injection attacks and grid attacks, improves the security of SM2 digital signature algorithm, enhances the protection ability of contralateral channel attacks, and is simple and easy to implement.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN114969836B_ABST
    Figure CN114969836B_ABST
Patent Text Reader

Abstract

The present invention relates to an SM2 digital signature method and system against side-channel attacks. The method includes: obtaining elliptic curve system parameters, a user public key, a user private key, and a message digest to be signed; the elliptic curve system parameters include the base point of the elliptic curve and the order n of the base point; generating a first random number and a second random number within the range of [1, n-1]; generating a first signature segment r by using a random masking method based on the elliptic curve system parameters, the user public key, the message digest to be signed, the first random number, and the second random number; if the first signature segment r passes the verification, generating a second signature segment s by using a diffusion error method based on the elliptic curve system parameters, the user private key, the user public key, the message digest to be signed, the first random number, the second random number, and the first signature segment r; if the second signature segment s passes the verification, outputting the signature (r, s) to complete the signature.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of digital signature technology, and in particular, to an SM2 digital signature method and system resistant to side-channel attacks. Background Art

[0002] The SM2 elliptic curve public key cryptography algorithm includes a digital signature algorithm, a key exchange protocol, and a public key encryption algorithm. Compared with the traditional and widely used RSA digital signature algorithm, the SM2 digital signature algorithm has a shorter key length and higher security strength, but it is still vulnerable to side-channel attacks, such as error injection attacks and lattice attacks.

[0003] An error injection attack means randomly injecting one-byte errors into the signature key each time, and information about the signature key can be obtained by analyzing the incorrect signatures; a lattice attack means that through laser attacks or other means, several high significant bits of the random numbers used in multiple signatures are the same, and a lattice is constructed using multiple signatures. When the lattice vector related to the signature key and the integer vector related to the signature meet certain conditions, the existing polynomial time algorithms for solving lattice problems can be used to solve the signature key.

[0004] Regarding the security protection of the SM2 digital signature algorithm, there is currently no side-channel attack resistant method that can resist both error injection attacks and lattice attacks. Summary of the Invention

[0005] In view of the above analysis, embodiments of the present invention aim to provide an SM2 digital signature method and system resistant to side-channel attacks to solve the problem that the existing SM2 digital signatures cannot resist both error injection attacks and lattice attacks.

[0006] On the one hand, embodiments of the present invention provide an SM2 digital signature method resistant to side-channel attacks, including the following steps:

[0007] Obtain elliptic curve system parameters, user public key P A , user private key d A and the message digest e to be signed; the elliptic curve system parameters include the base point G of the elliptic curve and the order n of the base point G;

[0008] Generate a first random number k and a second random number w within the range of [1, n - 1]; based on the elliptic curve system parameters, the user public key P A , the message digest e to be signed, the first random number k and the second random number w, use the method of random masking to generate a first signature segment r;

[0009] If the first signature segment r passes the verification, then based on the elliptic curve system parameters, the user private key d A , the user public key P A, using the method of diffusion error, generate the second signature segment s from the to-be-signed message digest e, the first random number k, the second random number w, and the first signature segment r;

[0010] If the second signature segment s passes the verification, output the signature (r, s) to complete the signature.

[0011] Based on a further improvement of the above method, based on the elliptic curve system parameters, the user public key P A , the to-be-signed message digest e, the first random number k, and the second random number w, use the method of random masking to generate the first signature segment r, including the following steps:

[0012] Calculate the first elliptic curve point Q1(x1, y1) according to the following formula:

[0013] Q1(x1, y1) = k·G + w·P A ;

[0014] Calculate the first signature segment r according to the following formula:

[0015] r = (x1 + e) mod n;

[0016] Where, mod n is the modulo n operation, and · is the dot product operation.

[0017] Further, based on the elliptic curve system parameters, the user private key d A , the user public key P A , the to-be-signed message digest e, the first random number k, the second random number w, and the first signature segment r, use the method of diffusion error to generate the second signature segment s, including the following steps:

[0018] Calculate the second elliptic curve point Q2(x2, y2) according to the following formula:

[0019] v = ((r - w) * d A + k) mod n;

[0020] Q2(x2, y2) = (2w - r)·P A + v·G;

[0021] Calculate the second signature segment s according to the following formula:

[0022] t = (x2 - (r - e)) mod n;

[0023] k' = k ⊕ t;

[0024] s = ((k' - v + k) / (1 + v / (w - r) - k / (w - r))) mod n; where v, t, and k' are all temporary parameters, mod n is the modulo n operation, ⊕ is the exclusive OR operation, · is the dot product operation, and * is the modular multiplication operation.

[0025] Further, the dot product operation adopts the Montgomery dot product algorithm, and the Montgomery dot product algorithm performs the dot product operation in the Lopez-Dahab projective coordinate system.

[0026] Further, the Montgomery dot product algorithm includes a loop operation of point addition operation and point doubling operation.

[0027] On the other hand, an embodiment of the present invention provides an SM2 digital signature system resistant to side-channel attacks, including:

[0028] A data acquisition module, configured to acquire elliptic curve system parameters, user public key P A , user private key d A and the message digest e to be signed; the elliptic curve system parameters include the base point G of the elliptic curve and the order n of the base point G;

[0029] A first signature segment generation module, configured to generate a first random number k and a second random number w within the range of [1, n - 1], and based on the elliptic curve system parameters, the user public key P A , the message digest e to be signed, the first random number k and the second random number w, generate a first signature segment r by using the method of random masking;

[0030] A second signature segment generation module, configured to, if the first signature segment r passes the verification, then based on the elliptic curve system parameters, the user private key d A , the user public key P A , the message digest e to be signed, the first random number k, the second random number w and the first signature segment r, generate a second signature segment s by using the method of diffusion error;

[0031] A signature result output module, if the second signature segment s passes the verification, then output the signature (r, s) to complete the signature.

[0032] Based on the further improvement of the above system, the first signature segment generation module generates the first signature segment r by performing the following steps:

[0033] Calculate the first elliptic curve Q1(x1, y1) according to the following formula:

[0034] Q1(x1, y1) = k · G + w · P A ;

[0035] The first signature segment r is calculated according to the following formula:

[0036] r = (x1 + e) mod n, where mod n is the modulo n operation, and · is the dot product operation.

[0037] Furthermore, the second signature segment generation module generates the second signature segment s by performing the following steps:

[0038] Calculate the second elliptic curve point Q2(x2, y2) according to the following formula:

[0039] v = ((r - w) * d A + k) mod n;

[0040] Q2(x2, y2) = (2w - r) · P A + v · G;

[0041] Calculate the second signature segment s according to the following formula:

[0042] t = (x2 - (r - e)) mod n;

[0043] k' = k ⊕ t;

[0044] s = ((k' - v + k) / (1 + v / (w - r) - k / (w - r))) mod n;

[0045] where v, t, and k' are all temporary parameters, mod n is the modulo n operation, ⊕ is the exclusive OR operation, · is the dot product operation, and * is the modular multiplication operation.

[0046] Furthermore, the system includes a Montgomery dot product module for performing dot product operations using the Montgomery dot product algorithm; the first signature segment generation module and the second signature segment generation module call the Montgomery dot product module to perform dot product operations; the Montgomery dot product module performs dot product operations in the Lopez-Dahab projective coordinate system.

[0047] Furthermore, the Montgomery dot product module includes a point addition module and a point doubling module; the Montgomery dot product module performs dot product operations by repeatedly calling the point addition module and the point doubling module.

[0048] Compared with the prior art, the present invention can at least achieve one of the following beneficial effects:

[0049] 1. The present invention not only selects a random number k according to the standard SM2 digital signature algorithm, but also independently selects another random number w, and uses k · G and w · P A to perform point addition to achieve w * dA As a mask for k, so that the signature process can resist lattice attacks against different random numbers with several identical most significant bits, improving the security of the SM2 digital signature algorithm;

[0050] 2. Before generating the second signature segment s in the embodiments of the present invention, a dot product related to the user's private key d is added A Using the non-linear property of the dot product, the error introduced in d can be diffused in the second signature segment s, thereby effectively resisting error injection attacks and improving the security of the SM2 digital signature algorithm; A

[0051] 3. By adopting the means of combining the random mask method and the error diffusion method, it is possible to resist error injection attacks and lattice attacks in the signature process without changing the signature verification algorithm, thereby more comprehensively resisting side-channel attacks and improving the security of the SM2 digital signature algorithm;

[0052] 4. In the signature process, the Montgomery dot product algorithm is adopted. By performing cyclic operations of point addition and point doubling, since it has the same scale of operations for different scalar bits, the signature process can resist power consumption analysis attacks, and can more comprehensively and effectively improve the security protection ability of the signature process against side-channel attacks;

[0053] 5. By combining the Montgomery dot product algorithm, the random mask method and the error diffusion method, it is possible to resist power consumption analysis attacks, error injection attacks and lattice attacks in the signature process without changing the signature verification algorithm, thereby more comprehensively resisting side-channel attacks, improving the security of the SM2 digital signature algorithm, and the method is simple and easy to implement.

[0054] In the present invention, the above technical solutions can also be combined with each other to achieve more preferred combination schemes. Other features and advantages of the present invention will be described in the following description, and some advantages can be made obvious from the description, or understood by implementing the present invention. The purpose and other advantages of the present invention can be realized and obtained from the content specifically pointed out in the description and the drawings. BRIEF DESCRIPTION OF THE DRAWINGS

[0055] The drawings are only for the purpose of showing specific embodiments, and are not considered as a limitation to the present invention. Throughout the drawings, the same reference numerals represent the same components.

[0056] Figure 1 It is a flowchart of the SM2 digital signature method for resisting side-channel attacks according to an embodiment of the present invention;

[0057] Figure 2 ​This is the structural block diagram of the SM2 digital signature system against side-channel attacks according to the embodiments of the present invention. Detailed implementation manners

[0058] The preferred embodiments of the present invention will be specifically described below with reference to the accompanying drawings. The accompanying drawings form a part of this application and are used together with the embodiments of the present invention to explain the principles of the present invention, rather than to limit the scope of the present invention.

[0059] The SM2 digital signature algorithm is a digital signature algorithm based on elliptic curves. The parameters in the SM2 digital signature algorithm mainly include: the prime field Fp containing p elements; the elliptic curve parameters (p, a, b, G, n, h) on Fp, where a and b are elements in Fp, used to define an elliptic curve E on Fp, G is the base point, n is the order of G, and h is an optional cofactor; the public key P of user A A , and the private key d of user A A .

[0060] The main process of signature is as follows:

[0061] 1. Calculate the message digest e = HASH(M) to be signed, where M = Z A ||m, Z A is the digest value of user A, m is the message to be signed, and HASH can be the hash function of SM3;

[0062] 2. Randomly select k uniformly from [1, n - 1];

[0063] 3. Calculate the dot product k·G, whose coordinates are (x′, y′), and calculate the first part r of the signature as r = (e + x′) mod n;

[0064] 4. Check the first part of the signature. If r = 0 or r + k = n, execute step 2; otherwise, execute step 5;

[0065] 5. Calculate the second part s of the signature as s = (1 + d A ) -1 (k - r·d A ) mod n,

[0066] 6. Check the second part of the signature. If s = 0, execute step 2; otherwise, output (r, s).

[0067] Regarding the security protection of the SM2 digital signature algorithm, there is currently no side-channel attack resistance method that can resist both error injection attacks and lattice attacks.

[0068] In view of this, a specific embodiment of the present invention discloses an SM2 digital signature method against side-channel attacks, as Figure 1 shown, the signature includes the following steps:

[0069] S1. Obtain the elliptic curve system parameters, the user's public key P A , the user's private key d A and the message digest e to be signed; the elliptic curve system parameters include the base point G of the elliptic curve and the order n of the base point G.

[0070] In implementation, the elliptic curve system parameters adopt the elliptic curve parameters used in the standard SM2 signature algorithm, such as the prime field Fp containing p elements; two elements a and b on Fp are used to define an elliptic curve E on Fp; the base point G(x G , y G ) of the elliptic curve E; the order n of G.

[0071] In implementation, the message digest e to be signed can be calculated by the following formula: e = HASH(M), where M = Z A ||m, Z A is the digest value of user A, m is the message to be signed, HASH is a hash function, optionally the hash function of SM3; Z A ||m is the concatenation of Z A and m.

[0072] S2. Generate a first random number k and a second random number w within the range of [1, n - 1]; based on the elliptic curve system parameters, the user's public key P A , the message digest e to be signed, the first random number k and the second random number w, use the method of random masking to generate a first signature segment r. The first random number k and the second random number w are independently and uniformly randomly generated.

[0073] Specifically, the first signature segment r is calculated through the following steps:

[0074] Calculate the first elliptic curve point Q1(x1, y1) according to the following formula:

[0075] Q1(x1, y1) = k·G + w·P A ;

[0076] Calculate the first signature segment r according to the following formula:

[0077] r = (x1 + e) mod n;

[0078] where, mod n is the modulo n operation, and · is the dot product operation.

[0079] In an embodiment of the present invention, on the basis of the existing SM2 digital signature algorithm, by independently selecting another random number w, using k·G and w·P A for point addition, realizing w*d AAs a mask for k to resist lattice attacks against different random numbers with several identical most significant bits.

[0080] Specifically, to resist power analysis attacks, this embodiment adopts the Montgomery point multiplication algorithm when performing point multiplication operations. The Montgomery point multiplication algorithm can be carried out in different coordinate systems, such as the affine coordinate system, the Jacobi coordinate system, the affine-Jacobi hybrid coordinate system, and the Lopez-Dahab (LD) projective coordinate system. Preferably, an embodiment of the present invention performs point multiplication operations in the LD projective coordinate system.

[0081] Exemplarily, for a number k within the range of modulus n and a point Q3(x3, y3) in the affine coordinate system, performing Montgomery point multiplication to calculate k·Q3 includes the following steps:

[0082] S201. Set up a temporary point U and a temporary point V, initialize the temporary point U to the infinite point, that is, set the x-axis and z-axis of U to x u = 1, z u = 0; initialize the temporary point V to Q3, that is, set the x-axis and z-axis of V to x v = x3, z v = 1;

[0083] S202. For i from l - 1 to 0, loop and execute steps S203 to S205, where l is the bit length of k and i is a temporary variable;

[0084] S203. Increase the temporary variables x1′, z1′, x2′, z2′, and initialize them to x u , z u ,, x v , z v ;

[0085] S204. If the i-th bit of k is 1, then perform a point addition operation on U and V to obtain an updated U, and perform a point doubling operation on V to obtain an updated V, that is, calculate x u , z u , x v , z v are respectively

[0086] - 4b*z1′*z2′*(x1′*z2′ + x2′*z1′) + (x1′*x2′ - a*z1′*z2′)^2, x3*(x1′*z2′ - x2′*z1′)^2, (x2′^2 - a*z2′^2)^2 - 8b*x2′*z2′^3, 4z2′*(x2′^3 + a*x2′*z2′^2 + b*z2′^3);

[0087] S205. If the i-th bit of k is 0, perform point addition on U and V to obtain the updated V, and perform point doubling on U to obtain the updated U, that is, calculate x v , z v , x u , z u are respectively

[0088] -4b*z1′*z2′*(x1′*z2′+x2′*z1′)+(x1′*x2′-a*z1′*z2′)^2, x3*(x1′*z2′-x2′*z1′)^2, (x1′^2-a*z1′^2)^2-8b*x1′*z1′^3, 4z1′*(x1′^3+a*x1′*z1′^2+b*z1′^3);

[0089] S206. Convert the LD projection coordinates of U and V into affine coordinates, that is, calculate x u , x v , y u are respectively x u / z u ,, x v / z v , ((a + x3 * x u ) * (x3 + x u ) - x v * (x3 - x u )^2 + 2b) / 2y3, k·Q3 = (x u , y u ).

[0090] Where a and b are the parameters of the elliptic curve.

[0091] By converting the affine coordinate system to the Lopez - Dahab projection coordinate system, the number of modular inverse operations in the point multiplication process is reduced, thereby improving the efficiency of the point multiplication operation. The Montgomery point multiplication algorithm includes iterative operations of point addition and point doubling, and has the same scale of operations for different scalar bits, so that the signature process can resist power consumption analysis attacks and make the digital signature algorithm more secure.

[0092] S3. If the first signature segment r passes the verification, based on the elliptic curve system parameters, the user's private key d A , the user's public key P A , the message digest e to be signed, the first random number k, the second random number w, and the first signature segment r, use the method of diffusion error to generate the second signature segment s.

[0093] Specifically, the verification of the first signature segment r is the same as that of the existing SM2 digital signature algorithm. That is, if r = 0 or r + k = n, the verification fails and returns to step S2 to re - execute step S2; otherwise, the verification passes.

[0094] Specifically, when the first signature segment r passes the verification, the second signature segment s is generated according to the following steps:

[0095] Calculate the second elliptic curve point Q2(x2, y2) according to the following formula:

[0096] v = ((r - w) * d A + k) mod n;

[0097] Q2(x2, y2) = (2w - r)·P A + v·G;

[0098] Calculate the second signature segment s according to the following formula:

[0099] t = (x2 - (r - e)) mod n;

[0100] k’ = k ⊕ t;

[0101] s = ((k’ - v + k) / (1 + v / (w - r) - k / (w - r))) mod n;

[0102] Among them, v, t, and k’ are all temporary parameters, mod n is the modulo n operation, ⊕ is the exclusive - or operation, · is the dot - product operation, and * is the modular - multiplication operation. To resist power - consumption analysis attacks, the dot - product operation in the operation process adopts the Montgomery dot - product algorithm, that is, when calculating (2w - r)·P A and v·G, the Montgomery dot - product is used. The Montgomery dot - product algorithm is as described above.

[0103] To resist error - injection attacks, when generating the second signature segment s, a dot - product related to the signature key d A is added, that is, when calculating the second elliptic curve point Q2, using the non - linear property of the dot - product, when an error injection occurs, the error introduced in d A is diffused in s, thus resisting error - injection attacks.

[0104] At the same time, in order not to change the signature - verification algorithm in the standard SM2, when calculating the second signature segment s, by adding temporary parameters v, t, k’, when there is an error in d A the error information will be diffused in s, when there is an error in d AWhen there is no error normally, t = 0, k' = k, and the second signature segment s is the same as that without using the diffusion error method. Thus, by combining the random masking method and the diffusion error method, without changing the existing SM2 signature verification algorithm, it can resist lattice attacks and error injection attacks simultaneously, making the signature process more secure.

[0105] S4. If the second signature segment s passes the verification, output the signature (r, s) to complete the signature.

[0106] Specifically, the verification of the second signature segment s is the same as that in the standard SM2 signature algorithm. That is, if s = 0, the verification fails and return to step S2 to execute step S2 again; otherwise, the verification passes, output the digital signature (r, s) to complete the signature.

[0107] For the signature verification part of the digital signature, use the existing standard SM2 signature verification algorithm.

[0108] Compared with the prior art, the SM2 digital signature method against side-channel attacks provided by this embodiment has the following beneficial effects:

[0109] 1. In this embodiment, not only a random number k is selected according to the standard SM2 digital signature algorithm, but also another random number w is independently selected. Use k·G and w·P A to perform point addition to implement w*d A as the mask of k, so that the signature process can resist lattice attacks on different random numbers with several identical most significant bits, improving the security of the SM2 digital signature algorithm.

[0110] 2. Before generating the second signature segment s in the embodiment of the present invention, add a point multiplication related to the user's private key d A Using the non-linear property of point multiplication, the error introduced in d A can be diffused in the second signature segment s, thus effectively resisting error injection attacks and improving the security of the SM2 digital signature algorithm.

[0111] 3. By using the method of combining the random masking method and the diffusion error method, without changing the signature verification algorithm, it can resist error injection attacks and lattice attacks in the signature process simultaneously, thus more comprehensively resisting side-channel attacks and improving the security of the SM2 digital signature algorithm. The method is simple and easy to implement.

[0112] 4. In the signature process, use the Montgomery point multiplication algorithm. By performing cyclic operations of point addition and point doubling, since it has the same scale of operations for different scalar bits, the signature process can resist power consumption analysis attacks, and can more comprehensively and effectively improve the security protection ability of the signature process against side-channel attacks.

[0113] 5. By combining the Montgomery point multiplication algorithm, the random masking method, and the diffusion error method, it is possible to resist power analysis attacks, error injection attacks, and lattice attacks during the signature process without changing the signature verification algorithm, thereby more comprehensively resisting side-channel attacks, improving the security of the SM2 digital signature algorithm, and being simple and easy to implement.

[0114] Another specific embodiment of the present invention discloses an SM2 digital signature system resistant to side-channel attacks, as Figure 2 shown, including:

[0115] A data acquisition module for acquiring elliptic curve system parameters, user public key P A , user private key d A and the message digest e to be signed; the elliptic curve system parameters include the base point G of the elliptic curve and the order n of the base point G;

[0116] A first signature segment generation module for generating a first random number k and a second random number w within the range of [1, n - 1], and based on the elliptic curve system parameters, the user public key P A , the message digest e to be signed, the first random number k, and the second random number w, using the random masking method to generate a first signature segment r;

[0117] Specifically, the first signature segment generation module generates the first signature segment r by performing the following steps:

[0118] Calculate the first elliptic curve point Q1(x1, y1) according to the following formula:

[0119] Q1(x1, y1) = k·G + w·P A ;

[0120] Calculate the first signature segment r according to the following formula:

[0121] r = (x1 + e) mod n, where mod n is the modulo n operation, and · is the point multiplication operation.

[0122] The first signature segment generation module independently selects another random number w and performs point addition using k·G and w·P A to implement using w*d A as a mask for k, thereby resisting lattice attacks against different random numbers with several identical most significant bits.

[0123] A second signature segment generation module for, if the first signature segment r passes the verification, based on the elliptic curve system parameters, the user private key d A , the user public key P AUsing the method of diffusion error, generate the second signature segment s from the to-be-signed message digest e, the first random number k, the second random number w, and the first signature segment r.

[0124] During implementation, the verification of the first signature segment r is the same as that of the existing SM2 digital signature algorithm. That is, if r = 0 or r + k = n, the verification fails, and the first signature segment generation module is re-executed to generate the first signature segment r; otherwise, the verification passes.

[0125] Specifically, when the first signature segment r passes the verification, the second signature segment generation module generates the second signature segment s by performing the following steps:

[0126] Calculate the second elliptic curve point Q2(x2, y2) according to the following formula:

[0127] v = ((r - w) * d A + k) mod n;

[0128] Q2(x2, y2) = (2w - r) · P A + v · G;

[0129] Calculate the second signature segment s according to the following formula:

[0130] t = (x2 - (r - e)) mod n;

[0131] k' = k ⊕ t;

[0132] s = ((k' - v + k) / (1 + v / (w - r) - k / (w - r))) mod n;

[0133] Among them, v, t, and k' are all temporary parameters, mod n is the modulo n operation, ⊕ is the exclusive OR operation, · is the dot product operation, and * is the modular multiplication operation.

[0134] When generating the second signature segment s, the second signature segment generation module adds a dot product related to the signature key d A That is, calculate the second elliptic curve point Q2. Using the non-linear property of the dot product, when an error injection occurs, the error introduced in d A is diffused in s, thereby resisting error injection attacks.

[0135] At the same time, in order not to change the signature verification algorithm in the standard SM2, when generating the second signature segment s, the second signature segment generation module adds temporary parameters v, t, and k', so that when there is an error in d A the error information will be diffused in s. When there is an error in d AWhen there is no error normally, t = 0, k' = k, and the second signature segment s is the same as when the error diffusion method is not adopted, so the signature verification algorithm remains unchanged. Through the mutual cooperation of the first signature segment generation module and the second signature segment generation module, the random masking method and the error diffusion method are combined. Without changing the existing SM2 signature verification algorithm, it can resist lattice attacks and error injection attacks simultaneously, making the signature process more secure, and the system structure is simple and easy to implement.

[0136] Signature result output module. If the second signature segment s passes the verification, it outputs the signature (r, s) to complete the signature.

[0137] Specifically, the verification of the second signature segment s is the same as that in the standard SM2 signature algorithm, that is, if s = 0, the verification fails and it returns to the first signature segment generation module to regenerate the digital signature; otherwise, the verification passes, outputs the digital signature (r, s), and completes the signature.

[0138] To improve the security protection ability of the digital signature process and resist power analysis attacks, the system also includes a Montgomery point multiplication module for performing point multiplication operations using the Montgomery point multiplication algorithm. When the first signature segment generation module and the second signature segment generation module perform point multiplication operations, they call the Montgomery point multiplication module to perform point multiplication operations.

[0139] Specifically, the Montgomery point multiplication module includes a point addition module and a double point module; the Montgomery point multiplication module performs point multiplication operations by circularly calling the point addition module and the double point module. For different scalar bits, there are operations of the same scale, so that the signature process can resist power analysis attacks.

[0140] Preferably, the Montgomery point multiplication module performs point multiplication operations in the Lopez-Dahab projective coordinate system, reducing the number of modular inverse operations, thereby improving the efficiency of point multiplication operations.

[0141] Those skilled in the art can understand that all or part of the processes of implementing the above embodiment methods can be completed by instructing relevant hardware through a computer program, and the program can be stored in a computer-readable storage medium. Among them, the computer-readable storage medium is a disk, an optical disk, a read-only memory, or a random access memory, etc.

[0142] The above is only a preferred specific embodiment of the present invention, but the protection scope of the present invention is not limited thereto. Any changes or substitutions that can be easily thought of by those skilled in the art within the technical scope disclosed by the present invention should be covered within the protection scope of the present invention.

Claims

1. An SM2 digital signature method against side-channel attacks, characterized in that, It includes the following steps: Obtain the elliptic curve system parameters, the user's public key P A , the user's private key d A and the message digest e to be signed; the elliptic curve system parameters include the base point G of the elliptic curve and the order n of the base point G; Generate a first random number k and a second random number w within the range of [1, n-1]; based on the elliptic curve system parameters, the user public key P A , the message digest e to be signed, the first random number k and the second random number w, use the method of random masking to generate a first signature segment r; If the first signature segment r passes the verification, based on the elliptic curve system parameters, the user's private key d A , the user's public key P A , the message digest e to be signed, the first random number k, the second random number w, and the first signature segment r, use the method of diffusion error to generate the second signature segment s; If the second signature segment s passes the verification, output the signature (r, s) to complete the signature; Based on the elliptic curve system parameters, the user's public key P A , the message digest e to be signed, the first random number k, and the second random number w, a first signature segment r is generated by using the method of random masking, including the following steps: Calculate the first elliptic curve point Q1(x1, y1) according to the following formula: Q1(x1,y1) = k·G + w·P A ; Calculate the first signature segment r according to the following formula: r = (x1 + e) mod n; Where, mod n is the modulo n operation, and · is the point multiplication operation; Based on the elliptic curve system parameters and the user's private key d A , the user's public key P A , the message digest e to be signed, the first random number k, the second random number w, and the first signature segment r, using the method of diffusion error, generate the second signature segment s, including the following steps: Calculate the second elliptic curve point Q2(x2, y2) according to the following formula: v = ((r - w) * d A + k) mod n; Q2(x2,y2) = (2w - r)·P A + v·G; Calculate the second signature segment s according to the following formula: t = (x2 - (r - e)) mod n; k' = k ⊕ t; s = ((k' - v + k) / (1 + v / (w - r) - k / (w - r))) mod n; Where, v, t, and k' are all temporary parameters; mod n is the modulo n operation, ⊕ is the exclusive OR operation, · is the point multiplication operation, and * is the modular multiplication operation.

2. The SM2 digital signature method against side-channel attacks according to claim 1, wherein The point multiplication operation adopts the Montgomery point multiplication algorithm; the Montgomery point multiplication algorithm performs the point multiplication operation in the Lopez-Dahab projective coordinate system.

3. The SM2 digital signature method against side-channel attacks according to claim 2, characterized in that, The Montgomery point multiplication algorithm includes a loop operation of point addition operation and double point operation.

4. An SM2 digital signature system resistant to side-channel attacks, characterized in that, It includes: A data acquisition module, which is used to acquire elliptic curve system parameters, a user public key P A , a user private key d A and a message digest e to be signed; the elliptic curve system parameters include a base point G of the elliptic curve and an order n of the base point G; The first signature segment generation module is used to generate a first random number k and a second random number w within the range of [1, n - 1], and based on the elliptic curve system parameters, the user public key P A , the message digest e of the message to be signed, the first random number k and the second random number w, and use the method of random masking to generate a first signature segment r; The second signature segment generation module is used to, if the first signature segment r passes the verification, generate a second signature segment s by using a diffusion error method based on the elliptic curve system parameters, the user's private key d A , the user's public key P A , the message digest e to be signed, the first random number k, the second random number w, and the first signature segment r A signature result output module, if the second signature segment s passes the verification, output the signature (r, s) to complete the signature; The first signature segment generation module generates the first signature segment r by performing the following steps: Calculate the first elliptic curve Q1(x1, y1) according to the following formula: Q1(x1,y1) = k·G + w·P A ; Calculate the first signature segment r according to the following formula: r = (x1 + e) mod n; Where, mod n is the modulo n operation, and · is the point multiplication operation; The second signature segment generation module generates the second signature segment s by performing the following steps: Calculate the second elliptic curve point Q2(x2, y2) according to the following formula: v = ((r - w) * d A + k) mod n; Q2(x2,y2) = (2w - r)·P A + v·G; Calculate the second signature segment s according to the following formula: t = (x2 - (r - e)) mod n; k' = k ⊕ t; s = ((k' - v + k) / (1 + v / (w - r) - k / (w - r))) mod n; Where, v, t, and k' are all temporary parameters, mod n is the modulo n operation, ⊕ is the exclusive OR operation, · is the point multiplication operation, and * is the modular multiplication operation.

5. The SM2 digital signature system against side-channel attacks according to claim 4, characterized in that, It further includes a Montgomery point multiplication module for performing the point multiplication operation using the Montgomery point multiplication algorithm; the first signature segment generation module and the second signature segment generation module call the Montgomery point multiplication module to perform the point multiplication operation; the Montgomery point multiplication module performs the point multiplication operation in the Lopez-Dahab projective coordinate system.

6. The SM2 digital signature system against side-channel attacks according to claim 5, characterized in that The Montgomery point multiplication module includes a point addition module and a double point module; the Montgomery point multiplication module performs the point multiplication operation by circularly calling the point addition module and the double point module.

Citation Information

Patent Citations

  • SM2 signature algorithm protection method for resisting error attack based on lattice

    CN104852805A

  • Multi-party collaborative signature method and system based on SM2

    CN111147246A