A method and system for generating a certificate-based signature based on SM2 signature
Through the certificate signature generation method based on SM2 signature, combined with the advantages of traditional public key cryptography and identity cryptography, the security problems of certificate chain verification and key hosting in the existing technology are solved, and an efficient and secure digital signature solution is realized.
Patent Information
- Application Number
- CN202211150483.4
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2022-09-21
- Publication Date
- 2025-06-24
- Estimated Expiration
- 2042-09-21
AI Technical Summary
The existing technology has expensive certificate chain verification process and key hosting security problems in digital signatures, which is difficult to meet the new demand for signature functionality in the digital era.
The certificate signature generation method based on SM2 signature is adopted, combined with the advantages of traditional public key cryptography and identity cryptography, and the signature calculation and verification are realized through the master private key calculation of the certificate authority and the generation of the signer public key, avoiding the expensive certificate chain verification process.
It implements a signature process without expensive certificate chain verification, removes key hosting security issues, and provides an efficient and secure digital signature solution suitable for areas such as electronic voting and blockchain.
Smart Images

Figure CN115567217B_ABST
Abstract
Description
Technical Field
[0001] The present invention belongs to the technical field of information security, and particularly relates to a method and system for generating a certificate-based signature based on SM2 signature. Background Art
[0002] Traditional handwritten signature methods, such as letters, signing contracts, and payments, play an important role in daily life. In the Internet era, people pay fees and trade stocks through the Internet. To ensure the security of online business activities, a very important security mechanism, namely digital signature, is required. Digital signature plays an important role in information security, including authentication, data integrity, non-repudiation, etc., especially in key distribution, authentication in large-scale network security communications, and e-commerce systems.
[0003] The SM2 algorithm is a public key encryption standard released by the State Cryptography Administration on December 17, 2010. This standard became a cryptographic industry standard (GM / T 0003-2012) in 2012 and a national cryptographic standard of China (GB / T 32918-2016) in 2016. Among them, the second part of the SM2 elliptic curve public key cryptography algorithm is the digital signature algorithm. SM2 digital signature can replace foreign signature algorithms such as ECDSA and Schnorr, promoting the independent development of China's cryptographic technology. However, with the development of the digital era, new requirements for the functionality of signatures have emerged, and many new functional signature algorithms based on domestic commercial cryptography have emerged. The present invention discloses a method and system for generating a certificate-based signature based on SM2 signature. It is based on the signature structure of the national cryptographic algorithm SM2, combines the advantages of traditional public key cryptography and identity-based cryptography, does not require the use of an expensive certificate chain verification process, and removes the key escrow security problem.
[0004] In summary, this patent designs a method and system for generating a certificate-based signature based on SM2 signature. Summary of the Invention
[0005] The embodiments of the present invention provide a method and system for generating a certificate-based signature based on SM2 signature, which has non-forgeability and signs a message composed of an address and a tag. The significant feature of this solution is that the public key can be publicly extracted for the signatures on two different tags of the same address. Therefore, this solution is a means to prevent double signatures and can be applied in fields such as electronic voting and blockchain.
[0006] The embodiments of the present invention are implemented as follows. A method for generating a certificate-based signature based on SM2 signature includes the following steps:
[0007] Step S100, system initialization calculation. The certificate authority determines the master private key and calculates the master public key, and the signer selects a secret value to calculate the public key;
[0008] Step S200: Certificate authorization. The signer provides identity information, and the certificate issuing authority verifies it based on this information and the above key information. After the information passes the verification, it calculates and generates a certificate and feedbacks it to the signer.
[0009] Step S300: Signature calculation. Input the message to be signed, perform signature calculation, and output the signature value.
[0010] Step S400: Verification calculation. Perform verification calculation on the signature value output in the above step to judge its correctness.
[0011] As a preferred implementation of the present invention, the parameter selection of this method is consistent with the standard parameters of the SM2 signature algorithm. The specific symbol descriptions are as follows:
[0012] q: A large prime number;
[0013] The set of integers composed of 1, 2,..., q - 1;
[0014] G = (x G , y G ): A base point of the elliptic curve;
[0015] a, b: Parameters of the elliptic curve equation;
[0016] [k]P: The k - fold point of point P on the elliptic curve, where k is a positive integer;
[0017] H(·), H1(·), H2(·): Cryptographic functions derived from cryptographic hash functions, all of which are
[0018] S: Signer;
[0019] V: Verifier;
[0020] CA: Certificate issuing authority;
[0021] msk: The system master private key secretly held by CA;
[0022] mpk: The system master public key publicly announced by CA, and the calculation formula is mpk = (x mpk , y mpk ) = [msk]G;
[0023] IDInfo: Personal information of signer S;
[0024] upk: Public key of signer S;
[0025] Cert S : Certificate of signer S;
[0026] usk: The certificate-based private key of signer S;
[0027] usk1: The secret value of signer S;
[0028] M: The message to be signed;
[0029] σ = (r, s): The signature value;
[0030] mod q: Modulo q operation;
[0031] x||y: The concatenation of x and y, where x and y can be bit strings or byte strings.
[0032] As a preferred embodiment of the present invention, for the step S100, system initialization calculation, the certificate authority determines the master private key and calculates the master public key, and the detailed steps for the signer to select the secret value and calculate the public key are as follows: Where S represents the signer, V represents the verifier, and CA represents the certificate authority;
[0033] a) CA randomly selects as the master private key, and calculates the master public key mpk = (x mpk , y mpk ) = [msk]G;
[0034] b) The signer S randomly selects a secret value and calculates the public key upk = (x upk , y upk ) = [usk1]G.
[0035] As a preferred implementation solution of the present invention, for the step S200, certificate authorization, the signer provides identity information, and the certificate authority verifies based on this information and the above key information, and the detailed steps for calculating and generating a certificate and feeding it back to the signer after the information passes are as follows:
[0036] a) The signer S provides the information IDInfo to the CA, which includes his public key upk and any necessary additional identity information, such as her name;
[0037] b) The CA verifies the information;
[0038] c) If the verification passes, the CA calculates Z = H1(IDInfo||upk||a||b||x G ||y G ||x mpk ||y mpk );
[0039] d) Calculate λ = H2(x upk ||y upk ||Z);
[0040] e) The CA generates the certificate Cert s = λ·msk mod q and sends it to S.
[0041] As a preferred embodiment of the present invention, in step S300, signature calculation, the detailed steps of inputting the message to be signed, performing signature calculation, and outputting the signature value are as follows:
[0042] a) Input the message M, and the signer S calculates the private key usk=(usk1 + Cert S ) based on the certificate system;
[0043] b) Calculate Z = H1(IDInfo||upk||a||b||x G ||y G ||x mpk ||y mpk );
[0044] c) Calculate M′ = Z||M;
[0045] d) Calculate e = H(M′);
[0046] e) Randomly select
[0047] f) Calculate K = (x1, y1) = [k]G;
[0048] g) Calculate r = (e + x1) mod q;
[0049] h) Calculate s = ((1 + usk) -1 ·(k - r·usk)) mod q;
[0050] i) Output the signature σ = (r, s) of the message M.
[0051] As a preferred embodiment of the present invention, in step S400, verification calculation, the detailed steps of performing verification calculation on the signature value output in the above steps are as follows:
[0052] a) Calculate Z = H1(IDInfo||upk||a||b||x G ||y G ||x mpk ||y mpk );
[0053] b) Calculate λ = H2(x upk ||y upk ||Z);
[0054] c) Calculate R = upk + [λ]mpk;
[0055] d) Calculate M′ = Z||M;
[0056] e) Calculate e = H(M′);
[0057] f) Calculate t = (r + s) mod q;
[0058] g) Calculate K = (x1, y1) = [s]G + [t]R;
[0059] h) Calculate R = (e + x1) mod q;
[0060] i) Determine whether R = r holds. If it holds, the verification passes; otherwise, the verification fails.
[0061] As a preferred embodiment of the present invention, for the step S400, the algorithm for judging its correctness is as follows:
[0062] s = ((1 + usk) -1 ·(k - r·usk))
[0063] = (1 + usk1 + λ·msk) -1 ·(k - (r·usk1 + r·λ·msk))
[0064] K = [s]G + [t]R
[0065] = [s]G + [(r + s)·usk1]G + [(r + s)·λ·msk]G
[0066] = [s]G + [s·usk1]G + [r·usk1]G + [r·λ·msk]G + [s·λ·msk]G
[0067] = [s·(1 + usk1 + λ·msk)]G + [r·usk1]G + [r·λ·msk]G
[0068] = [(1 + usk1 + λ·msk) -1 ·(k - (r·usk1 + r·λ·msk))·(1 + usk1 + λ·msk)]G + [r·usk1]G + [r·λ·msk]G
[0069] = [k - (r·usk1 + r·λ·msk)]G + [r·usk1]G + [r·λ·msk]G
[0070] = [k]G.
[0071] A certificate - based signature generation system based on SM2 signature, comprising:
[0072] An initialization unit, which is used to perform system initialization calculations;
[0073] A certificate authorization unit, which is used to perform certificate authorization calculation;
[0074] A signature calculation unit, which is used to calculate the signature value for the entire surgical certificate;
[0075] A verification calculation unit, which is used to complete the verification algorithm.
[0076] As a preferred embodiment of the present invention, the parameter selection in this system is consistent with the standard parameters of the SM2 signature algorithm.
[0077] The beneficial effects of the present invention: This solution is based on the signature structure of SM2, combines the advantages of traditional public key cryptography and identity-based cryptography, does not require the use of expensive certificate chain verification processes, and removes the key escrow security problem. Description of the Drawings
[0078] Figure 1 It is a method step diagram of a certificate signature generation method based on SM2 signature of the present invention;
[0079] Figure 2 It is a schematic diagram of a certificate signature generation method based on SM2 signature of the present invention;
[0080] Figure 3 It is a structural block diagram of a certificate signature generation system based on SM2 signature of the present invention. Detailed Embodiments
[0081] In order to make the objectives, technical solutions and advantages of the present invention clearer, the present invention will be further described in detail below with reference to the drawings and embodiments. It should be understood that the specific embodiments described herein are only used to explain the present invention and are not used to limit the present invention.
[0082] The present invention is based on the signature structure of SM2, combines the advantages of traditional public key cryptography and identity-based cryptography, does not require the use of expensive certificate chain verification processes, and removes the key escrow security problem.
[0083] The embodiments of the present invention are implemented as follows. A certificate signature generation method based on SM2 signature includes the following steps:
[0084] Step S100, system initialization calculation, the certificate issuing authority determines the master private key and calculates the master public key, and the signer selects a secret value to calculate the public key;
[0085] Step S200, certificate authorization, the signer provides identity information, and the certificate issuing authority verifies according to this information and the above key information. After the information passes, it calculates and generates a certificate and feeds it back to the signer;
[0086] Step S300, signature calculation: Input the message to be signed, perform signature calculation, and output the signature value.
[0087] Step S400, verification calculation: Perform verification calculation on the signature value output in the above step to judge its correctness.
[0088] Furthermore, the parameter selection of this method is consistent with the standard parameters of the SM2 signature algorithm. The specific symbol descriptions are as follows:
[0089] q: A large prime number;
[0090] The set of integers composed of 1, 2,..., q - 1;
[0091] G = (x G , y G ): A base point of the elliptic curve;
[0092] a, b: Parameters of the elliptic curve equation;
[0093] [k]P: The k - multiple point of point P on the elliptic curve, where k is a positive integer;
[0094] H(·), H1(·), H2(·): Cryptographic functions derived from cryptographic hash functions, all of which are
[0095] S: Signer;
[0096] V: Verifier;
[0097] CA: Certificate Authority;
[0098] msk: The system master private key secretly held by CA;
[0099] mpk: The system master public key publicly announced by CA, and the calculation formula is mpk = (x mpk , y mpk ) = [msk]G;
[0100] IDInfo: Personal information of signer S;
[0101] upk: Public key of signer S;
[0102] Cert S : Certificate of signer S;
[0103] usk: Private key of signer S based on the certificate system;
[0104] usk1: Secret value of signer S;
[0105] M: Message to be signed;
[0106] σ=(r, s): Signature value;
[0107] mod q: Modulo q operation;
[0108] x||y: Concatenation of x and y, where x and y can be bit strings or byte strings.
[0109] Furthermore, for the step S100, system initialization calculation, the certificate authority determines the master private key and calculates the master public key. The detailed steps for the signer to select a secret value and calculate the public key are as follows: Where S represents the signer, V represents the verifier, and CA represents the certificate authority;
[0110] a) CA randomly selects as the master private key and calculates the master public key mpk=(x mpk , y mpk )=[msk]G;
[0111] b) The signer S randomly selects a secret value and calculates the public key upk=(x upk , y upk )=[usk1]G.
[0112] As a preferred implementation solution of the present invention, for the step S200, certificate authorization, the signer provides identity information, and the certificate authority verifies based on this information and the above key information. After the information passes, the detailed steps for calculating and generating a certificate and feedbacking it to the signer are as follows:
[0113] a) The signer S provides the information IDInfo to CA, which includes his public key upk and any necessary additional identity information, such as her name;
[0114] b) CA verifies the information;
[0115] c) If the verification passes, CA calculates Z = H1(IDInfo||upk||a||b||x G ||y G ||x mpk ||y mpk );
[0116] d) Calculate λ = H2(x upk ||y upk ||Z);
[0117] e) CA generates the certificate Cert S = λ·msk mod q and sends it to S.
[0118] Further, for the step S300, signature calculation, the detailed steps of inputting the message to be signed and performing signature calculation and outputting the signature value are as follows:
[0119] a) Input the message M. The signer S calculates the private key usk=(usk1 + Cert S ) based on the certificate system;
[0120] b) Calculate Z = H1(IDInfo||upk||a||b||x G ||y G ||x mpk ||y mpk );
[0121] c) Calculate M' = Z||M;
[0122] d) Calculate e = H(M');
[0123] e) Randomly select
[0124] f) Calculate K=(x1, y1)=[k]G;
[0125] g) Calculate r=(e + x1) mod q;
[0126] h) Calculate s = ((1 + usk) -1 ·(k - r·usk)) mod q;
[0127] i) Output the signature σ=(r, s) of the message M.
[0128] Further, for the step S400, verification calculation, the detailed steps of performing verification calculation on the signature value output in the above step are as follows:
[0129] a) Calculate Z = H1(IDInfo||upk||a||b||x G ||y G ||x mpk ||y mpk );
[0130] b) Calculate λ = H2(x upk ||y upk ||Z);
[0131] c) Calculate R = upk + [λ]mpk;
[0132] d) Calculate M' = Z||M;
[0133] e) Calculate e = H(M');
[0134] f) Calculate t = (r + s) mod q;
[0135] g) Calculate \(K=(x_1,y_1)=[s]G + [t]R\);
[0136] h) Calculate \(R=(e + x_1)\bmod q\);
[0137] i) Determine whether \(R = r\) holds. If it holds, the verification passes; otherwise, the verification fails.
[0138] Furthermore, for the step S400, the algorithm for judging its correctness is as follows:
[0139] \(s = ((1 + usk) -1 \cdot(k - r\cdot usk))
[0140] =(1 + usk1+\lambda\cdot msk) -1 \cdot(k-(r\cdot usk1 + r\cdot\lambda\cdot msk))
[0141] \(K = [s]G + [t]R
[0142] =[s]G + [(r + s)\cdot usk1]G + [(r + s)\cdot\lambda\cdot msk]G
[0143] =[s]G + [s\cdot usk1]G + [r\cdot usk1]G + [r\cdot\lambda\cdot msk]G + [s\cdot\lambda\cdot msk]G
[0144] =[s\cdot(1 + usk1+\lambda\cdot msk)]G + [r\cdot usk1]G + [r\cdot\lambda\cdot msk]G
[0145] =[(1 + usk1+\lambda\cdot msk) -1 \cdot(k-(r\cdot usk1 + r\cdot\lambda\cdot msk))\cdot(1 + usk1+\lambda\cdot msk)]G + [r\cdot usk1]G + [r\cdot\lambda\cdot msk]G
[0146] =[k-(r\cdot usk1 + r\cdot\lambda\cdot msk)]G + [r\cdot usk1]G + [r\cdot\lambda\cdot msk]G
[0147] =[k]G.
[0148] A certificate - based signature generation system based on SM2 signature, including:
[0149] An initialization unit, which is used to perform system initialization calculations;
[0150] A certificate authorization unit, which is used to perform certificate authorization calculations;
[0151] A signature calculation unit, which is used to calculate the signature value for the entire certificate;
[0152] A verification calculation unit, which is used to complete a verification algorithm.
[0153] Furthermore, the parameter selection in this system is consistent with the standard parameters of the SM2 signature algorithm.
[0154] Embodiment 1
[0155] Refer to Figures 1-3 , the present invention proposes a certificate signature generation method based on SM2 signature. The following is a specific description. The national cryptography SM2 algorithm currently used in our country is improved on the basis of elliptic curve cryptography theory, and its encryption strength is higher than that of the RSA algorithm (2048 bits). With stronger security performance as the core algorithm of traditional SSL certificates, although the RSA algorithm still occupies the mainstream position in the SSL certificate market, with the development of computer technology and the improvement of factorization, attacks on low-bit keys have become possible, and traditional SSL certificates also face more unknown risks. The SM2 algorithm based on the ECC elliptic curve algorithm generally uses a 256-bit key length, and its unit security strength is relatively high, which is relatively difficult to implement in engineering applications, and the difficulty of breaking or solving is basically exponential. Therefore, the SM2 algorithm can provide higher security strength than the RSA algorithm with less computing power, while the required key length is much lower than that of the RSA algorithm.
[0156] The specific scheme process is as follows: S represents the signer, V represents the verifier, and CA represents the certificate authority.
[0157] 1) Initialization
[0158] a) The CA randomly selects as the master private key, and calculates the master public key mpk=(x mpk , y mpk )=[msk]G.
[0159] b) The signer S randomly selects a secret value and calculates the public key upk=(x upk , y upk )=[usk1]G
[0160] 2) Certificate authorization algorithm
[0161] a) The signer S provides the information IDInfo to the CA, which includes his public key upk and any necessary additional identity information, such as her name.
[0162] b) The CA verifies the information.
[0163] c) If the verification passes, the CA calculates Z = H1(IDInfo||upk||a||b||x G||y G ||x mpk ||y mpk )。
[0164] d) Calculate λ = H2(x upk ||y upk ||Z).
[0165] e) CA generates the certificate Cert S = λ · msk mod q, and sends it to S.
[0166] 3) Signature algorithm
[0167] a) Given the message M, the signer S calculates the private key usk = (usk1 + Cert S ).
[0168] b) Calculate Z = H1(IDInfo || upk || a || b || x G ||y G ||x mpk ||y mpk ).
[0169] c) Calculate M′ = Z || M.
[0170] d) Calculate e = H(M′).
[0171] e) Randomly select
[0172] f) Calculate K = (x1, y1) = [k]G.
[0173] g) Calculate r = (e + x1) mod q.
[0174] h) Calculate s = ((1 + usk) -1 ·(k - r · usk)) mod q.
[0175] i) Output the signature σ = (r, s) of the message M.
[0176] 4) Verification algorithm
[0177] a) Calculate Z = H1(IDInfo || upk || a || b || x G ||y G ||x mpk ||y mpk ).
[0178] b) Calculate λ = H2(x upk ||y upk ||Z).
[0179] c) Calculate \(R = u_{pk}+[\lambda]m_{pk}\).
[0180] d) Calculate \(M' = Z||M\).
[0181] e) Calculate \(e = H(M')\).
[0182] f) Calculate \(t=(r + s)\bmod q\).
[0183] g) Calculate \(K=(x_1,y_1)=[s]G+[t]R\).
[0184] h) Calculate \(R=(e + x_1)\bmod q\).
[0185] i) Judge whether \(R = r\) holds. If it holds, the verification passes; otherwise, the verification fails.
[0186] Correctness:
[0187] \(s = ((1 + usk) -1 \(\cdot(k - r\cdot usk))
[0188] =(1 + usk1+\lambda\cdot msk) -1 \(\cdot(k-(r\cdot usk1 + r\cdot\lambda\cdot msk))
[0189] \(K = [s]G+[t]R
[0190] =[s]G+[(r + s)\cdot usk1]G+[(r + s)\cdot\lambda\cdot msk]G
[0191] =[s]G+[s\cdot usk1]G+[r\cdot usk1]G+[r\cdot\lambda\cdot msk]G+[s\cdot\lambda\cdot msk]G
[0192] =[s\cdot(1 + usk1+\lambda\cdot msk)]G+[r\cdot usk1]G+[r\cdot\lambda\cdot msk]G
[0193] =[(1 + usk1+\lambda\cdot msk) -1 \(\cdot(k-(r\cdot usk1 + r\cdot\lambda\cdot msk))\cdot(1 + usk1+\lambda\cdot msk)]G+[r\cdot usk1]G+[r\cdot\lambda\cdot msk]G
[0194] =[k-(r\cdot usk1 + r\cdot\lambda\cdot msk)]G+[r\cdot usk1]G+[r\cdot\lambda\cdot msk]G
[0195] =[k]G
[0196] Example 2
[0197] Please refer to Figure 3, the present invention also provides a certificate signature generation system based on SM2 signature. When in use, first, the initialization unit performs system initialization calculations; then the certificate authorization unit performs certificate authorization calculations based on the initialization calculation data; then the signature calculation unit calculates the signature value based on the certificate authorization content, and finally the verification calculation unit is used to complete the verification algorithm for verification.
[0198] Furthermore, the parameter selection in this system is consistent with the standard parameters of the SM2 signature algorithm.
[0199] In summary, the signature structure of the present invention based on SM2 combines the advantages of traditional public key cryptography and identity-based cryptography, eliminates the need for an expensive certificate chain verification process, and removes the key escrow security issue.
[0200] It should be understood that although the steps in the flowcharts of the embodiments of the present invention are shown in sequence according to the arrows, these steps do not necessarily have to be executed in the order indicated by the arrows. Unless clearly stated in this article, there is no strict order restriction for the execution of these steps, and these steps can be executed in other orders. Moreover, at least some of the steps in each embodiment may include multiple sub-steps or multiple stages. These sub-steps or stages do not necessarily have to be completed at the same moment, but can be executed at different moments. The execution order of these sub-steps or stages does not necessarily have to be sequential, but can be executed alternately or in turn with at least a part of other steps or sub-steps or stages of other steps.
[0201] The technical features of the above-described embodiments can be combined arbitrarily. For the sake of brevity of description, not all possible combinations of the technical features in the above-described embodiments are described. However, as long as there is no contradiction in the combination of these technical features, it should be considered to be within the scope described in this specification.
[0202] The above-described embodiments only represent several implementation manners of the present invention, and their descriptions are relatively specific and detailed, but they should not be construed as limiting the scope of the invention patent. It should be noted that for those of ordinary skill in the art, without departing from the concept of the present invention, several modifications and improvements can still be made, and these all belong to the protection scope of the present invention. Therefore, the protection scope of the invention patent should be subject to the appended claims.
[0203] The above is only the preferred embodiment of the present invention and is not intended to limit the present invention. Any modifications, equivalent replacements, and improvements made within the spirit and principle of the present invention should be included in the protection scope of the present invention.
Claims
1. A certificate-based signature generation method based on SM2 signature, characterized in that, It includes the following steps: Step S100, system initialization calculation. The certificate authority determines the master private key and calculates the master public key. The signer selects a secret value to calculate the public key; Step S200, certificate authorization. The signer provides identity information. The certificate authority verifies based on this information and the key information. After the information passes, it calculates and generates a certificate and feedbacks it to the signer; Step S300, signature calculation. Input the message to be signed, and perform signature calculation and output the signature value; Step S400, verification calculation. Perform verification calculation on the signature value output in the above step to judge its correctness; The parameter selection of this method is consistent with the standard parameters of the SM2 signature algorithm. The specific symbol descriptions are as follows: : A large prime number; : The integer set composed of ; : A base point of an elliptic curve; Elliptic curve equation parameters; : Point on the elliptic curve of multiple points, where is a positive integer; : Password functions derived from cryptographic hash functions are all ; : Signer; : Verifier; : Certificate Issuing Authority; : Consisting of The system master private key held secretly; : The public system master key disclosed by ; : Personal information of the signatory ; : Signer 's public key; : Signer 's certificate; : Signer 's private key based on the certificate system; : The signer 's secret value; : The message to be signed; : Signature value; : modulus operation; : concatenation of and where can be a bit string or a byte string; a) Randomly select as the master private key and calculate the master public key ; b) Signer Randomly select a secret value , and calculate the public key ; For the detailed steps of step S100, system initialization calculation, where the certificate authority determines the master private key and calculates the master public key, and the signer selects a secret value to calculate the public key: Among them, S represents the signer, V represents the verifier, and CA represents the certificate authority; a) Signer Provide information to , including his public key and any necessary additional identity information, such as her name; b) Verification information; c) If the verification passes, Calculate d) Calculation e) Generate a certificate and send it to ; For the detailed steps of step S200, certificate authorization, where the signer provides identity information, and the certificate authority verifies based on this information and the above key information, and after the information passes, calculates and generates a certificate and feedbacks it to the signer: a) Input message , the signer calculates a private key based on the certificate system ; b) Calculation ; c) Calculate ; d) Calculation ; e) Random selection ; f) Calculate ; g) Calculation ; h) Calculate ; i) Signature of the output message . 2. The method for generating a certificate-based signature based on SM2 signature according to claim 1, characterized in that, For the detailed steps of step S300, signature calculation, where the message to be signed is input, and signature calculation is performed and the signature value is output: a) Calculate ; b) Calculation ; c) Calculate ; d) Calculation ; e) Calculate ; f) Calculation ; g) Calculate ; h) Calculate ; i) Judge Whether it holds. If it holds, the verification passes; otherwise, the verification fails.
3. The method for generating a certificate-based signature based on SM2 signature according to claim 2, wherein, For the detailed steps of step S400, verification calculation, where verification calculation is performed on the signature value output in the above step: = 。 4. A certificate-based signature generation system based on SM2 signature, characterized in that, For step S400, the algorithm for judging its correctness is as follows: The system is used to execute a certificate signature generation method based on SM2 signature according to any one of claims 1-3, and it includes: An initialization unit, which is used to execute system initialization calculation; A certificate authorization unit, which is used to execute certificate authorization calculation; A signature calculation unit, which is used to calculate the signature value with the full certificate of the operation; 5. The certificate signature generation system based on SM2 signature according to claim 4, wherein A verification calculation unit, which is used to complete the verification algorithm. The parameter selection in this system is consistent with the standard parameters of the SM2 signature algorithm.
Citation Information
Patent Citations
Digital signature method and system based on SM2-based identity base
CN108809658A
Certificate-free signature method based on national secret SM2
CN109274506A