Secret key recovery method of SM2 signature algorithm based on lattice attack and storage medium

By reducing the key recovery problem of the SM2 signature algorithm to the hidden number problem and further transforming it into the unique shortest vector problem, the filtering algorithm with enhanced linear predicate algorithm is used to solve the problem of low efficiency in the existing technology, and more efficient key recovery is achieved.

CN120200741APending Publication Date: 2025-06-24SHANGHAI HUAHONG INTEGRATED CIRCUIT
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510287781.5
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-03-12
Publication Date
2025-06-24

AI Technical Summary

Technical Problem

The prior art is difficult to efficiently recover the key of the SM2 signature algorithm under side channel attacks.

Method used

By constructing the hidden number problem (HNP), deducing it to the bounded distance decoding problem (BDD), and then further reducing it to the unique shortest vector problem (uSVP), a filtering algorithm with enhanced linear predicate algorithm is used to recover the hidden number and obtain the signature private key.

Benefits of technology

Improves the efficiency of SM2 signature key recovery and enhances security under side channel attacks.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120200741A_ABST
    Figure CN120200741A_ABST
Patent Text Reader

Abstract

The invention discloses a secret key recovery method of an SM2 signature algorithm based on lattice attack and a storage medium, and the secret key recovery method comprises the steps: S1, constructing a hidden number problem; s2, reducing the implicit number problem to a bounded distance decoding problem; s3, reducing a bounded distance decoding problem to a unique shortest vector problem; and S4, solving a unique shortest vector problem by adopting a screening algorithm with predicates, and recovering the implicit number to obtain a signature private key. According to the method, the problem of recovering a key d by an SM2 signature algorithm is reduced to a hidden number problem on the basis of bit information of the highest 1 (1 > = 2) bit of a random number obtained by side channel attack, then the hidden number problem is reduced to a bounded distance decoding problem, and the problem is further reduced to a unique shortest vector problem for solving through a Kannan embedding technology, so that the problem is solved; and finally, constructing a more efficient screening algorithm with predicates in combination with a small index test technology to solve a unique shortest vector problem, recovering implicit numbers, and obtaining a signature private key. According to the new method provided by the invention, the lattice attack overhead can be reduced, and the key recovery efficiency is improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of cryptography, and particularly to a method for recovering the key of the SM2 signature algorithm based on lattice attack. Background Art

[0002] Existing research shows that even if it is theoretically secure under traditional cryptanalysis, there may still be security problems with cryptographic algorithms in practical applications. When a cryptographic algorithm is run on a hardware device, an attacker can collect information such as the energy consumption and electromagnetic radiation on the circuit. Since this information is related to the operations or operands currently executed by the cryptographic algorithm, it may be possible to obtain secret information such as the key by analyzing this information. This attack method is called side-channel analysis.

[0003] Currently, scholars at home and abroad have conducted a large amount of research on the security of elliptic curve algorithms under side-channel attacks. For the signature algorithm of elliptic curves, the random number scalar is the secret information of the algorithm, and theoretically the complete value must be obtained to recover the key. However, with the continuous upgrading of the cryptographic algorithm protection scheme, it has become basically infeasible for an attacker to obtain the complete scalar value. For SPA attacks, the double-and-add-always method can be used to avoid the direct association between the algorithm execution order and the scalar value; for DPA attacks, methods such as randomization and masking can be used for defense. Therefore, researchers at home and abroad have been exploring how to recover the signature key using partial information of the scalar value in recent years. Howgrave-Graham et al. successfully attacked and obtained the key of the algorithm based on the lattice basis reduction LLL algorithm, only by obtaining partial bit information of the DSA signature random number. Since this attack method involves lattice operations, this attack method is called Lattice Attack.

[0004] In 1996, Boneh and Venkatesan proposed the Hidden Number Problem (HNP) as a number-theoretic problem to study the bit security of the Diffie-Hellman (DH) key exchange scheme. Later in 2002, their scheme was extended by Nguyen et al. to analyze the security of the Elliptic Curve Digital Signature Algorithm (ECDSA) with partial knowledge of the random number. That is, the adversary can obtain partial information about the random number used by ECDSA to generate signatures and then solve the Hidden Number Problem (HNP) to obtain the private key. There are mainly two algorithms for solving the Hidden Number Problem (HNP): lattice-based attacks and Fourier analysis-based attacks. Among them, lattice-based attacks are more efficient and require fewer samples when a sufficiently long random number bit information is known. In lattice-based attacks, the HNP can be transformed into the Bounded Distance Decoding (BDD) problem, which is a variant of the Closest Vector Problem (CVP), and then using the Kannan embedding technique, it can be further transformed into the Unique Shortest Vector Problem (uSVP). In 2021, Albrecht and Heninger improved the lattice attack ability by combining the Sieving with Predicate algorithm. They used the predicate algorithm to check the short vectors in the database of short vectors in the HNP lattice output by the sieving algorithm. For each short vector, they calculated whether [sk]G is equal to the public key to distinguish the target lattice vector. However, this method requires scalar multiplication operations on the elliptic curve for each short vector, resulting in a large time overhead. In 2023, Xu et al. proposed a more efficient Sieving with linear predicate algorithm, further improving the performance of the attack.

[0005] In recent years, lattice attacks have become one of the most effective attack methods for side-channel analysis of elliptic curve public key cryptography algorithms. However, current domestic and foreign research in this direction basically focuses on the ECDSA algorithm, and there is less research on the SM2 algorithm. Summary of the Invention

[0006] A series of simplified concepts are introduced in the Summary of the Invention section. These simplified concepts are simplified from the prior art in this field and will be further described in detail in the Detailed Implementation section. The Summary of the Invention section of the present invention does not mean to attempt to define the key features and essential technical features of the claimed technical solution, nor does it mean to attempt to determine the protection scope of the claimed technical solution.

[0007] The technical problem to be solved by the present invention is to provide a method for efficiently recovering the SM2 signature key based on lattice attack compared with the prior art.

[0008] To solve the above technical problems, the key recovery method of the SM2 signature algorithm based on lattice attack provided by the present invention includes the following steps:

[0009] S1. Construct a hidden number problem (HNP):

[0010] r and s are signatures corresponding to random numbers, d is the private key, corresponding to the hidden number α in the constructed hidden number problem, t is obtained by taking the integer part of (s + r) divided by n, and k l is the bit information of the highest l bits of the random number k, l≥2, a is obtained by multiplying k l by n, dividing by 2 l and taking the integer part and then taking the modulus n. n is the order of the elliptic curve, and i represents the signature number;

[0011] S2. Reduce the hidden number problem (HNP) to a bounded distance decoding problem (BDD);

[0012] S3. Reduce the bounded distance decoding problem (BDD) to a unique shortest vector problem (uSVP);

[0013] S4. Use a sieving algorithm with an enhanced linear predicate algorithm to solve the unique shortest vector problem (uSVP) and recover the hidden number to obtain the signature private key d.

[0014] Optionally, further improve the key recovery method of the SM2 signature algorithm based on lattice attack. The implementation of step S1 includes the following sub-steps:

[0015] s = ((1 + d) -1 ·(k - r·d)) mod n Formula (1);

[0016] u = (s + r)d - k l ·n / 2 l mod n Formula (2);

[0017] r and s are SM2 signatures corresponding to random numbers, u = k - k l ·n / 2 l where u is a non-negative integer and u is less than n / 2 l ;

[0018] Define Simplify Formula (2) to u = dt - a mod n, and t and a can be calculated through public parameters;

[0019] Then holds;

[0020] For m groups of signature results (r i s i)For each group of signatures corresponding to (t i , a i ) all satisfy formula (3).

[0021] Optionally, further improve the key recovery method of the SM2 signature algorithm based on lattice attack. The implementation step S2 includes the following sub-steps:

[0022] Derive from formula (3) that there exists an integer C i such that the following formula (4) holds;

[0023] |dt i -a i +c i n| ≤ n / 2 l Formula (4);

[0024] Construct a (d + 1)-dimensional lattice L(B), which is generated by the matrix B,

[0025] Obtain the hidden vector and the target vector;

[0026] When the distance between the hidden vector and the target vector is shorter than the distance between other vectors in the lattice and the target vector, the key can be solved.

[0027] Optionally, further improve the key recovery method of the SM2 signature algorithm based on lattice attack. When implementing step S3, it includes the following steps:

[0028] Construct a (d + 2)-dimensional lattice L(F), which is generated by the matrix F,

[0029] The target vector

[0030] is the embedding factor, which is the upper limit of u i ;

[0031] Use the Recentering Technique, let w = n / 2 l+1 Obtain a shorter target vector

[0032]

[0033] Adopt the Elimination Method, let the hidden number then

[0034] The hidden number changes from d to u0 - w, and the target vector is whose upper bound is

[0035] Optionally, further improve the key recovery method of the SM2 signature algorithm based on lattice attack, and use a screening algorithm with an enhanced linear predicate algorithm to solve the unique shortest vector problem (uSVP), including the following sub-steps;

[0036] Define a variable r to store the currently found shortest vector, with an initial value of empty or set to a vector of a specified length, and the specified length is determined according to the requirements of the unique shortest vector problem (uSVP);

[0037] Run a screening algorithm on the lattice L(B) to generate a database L containing short vectors;

[0038] Traverse each vector v in the database L output by the screening algorithm;

[0039] For each vector v in the database L, perform the following operations:

[0040] Use the predicate algorithm f() to verify whether the vector v satisfies the conditions:

[0041] Detect the legality of the vector. If any one of conditions 1) to 3) holds, feedback failure;

[0042] 1) Whether the penultimate coordinate v of the vector v m-1 is 0, |v m-1 | = 0;

[0043] 2) Whether the absolute value of the penultimate coordinate v of the vector v m-1 exceeds n / 2 l+1 , |v m-1 | ≥ n / 2 l+1 ;

[0044] 3) The last coordinate v of the vector v m is not equal to the embedding factor

[0045] Calculate the candidate value α;

[0046] If

[0047] Randomly select a set of decimals θ1, θ2,..., θ m-1 ∈ [1, 2 x

[0048] If then feedback failure;

[0049] If

[0050] Randomly select a set of decimals θ1, θ2,..., θ​m-1 ∈[1, 2 x

[0051] If then the feedback fails;

[0052] If v satisfies the condition and f(v) = 1, then further check whether the length ||v|| of the vector v is less than the length ||r|| of the currently stored shortest vector r:

[0053] If ||v|| < ||r|| or r is empty, then update r to the current vector v:

[0054] After the traversal is completed, return the vector stored in the variable r, which is the shortest vector that satisfies the condition. The shortest vector v contains the hidden number related to the signature private key and can be used to obtain the signature private key d.

[0055] The present invention also provides a computer-readable storage medium, which stores a computer program internally. When the computer program is executed, it is used to implement the steps of the key recovery method of the SM2 signature algorithm based on lattice attack described in any one of the above.

[0056] The present invention first obtains the highest l (l≥2) consecutive bit information of the random number based on side-channel attack, reduces the problem of recovering the key d to the hidden number problem (HNP), and the key d becomes the hidden number in the HNP. Therefore, solving the HNP can recover the key d; then reduces the hidden number problem (HNP) to the bounded distance decoding problem (BDD), and through the use of Kannan embedding technology, it can be further reduced to the unique shortest vector problem (uSVP) for solution. Then, a more efficient filtering algorithm with predicates is constructed to solve the unique shortest vector problem (uSVP), recover the hidden number α, and finally obtain the signature private key d, thereby improving the solution efficiency and also improving the key recovery efficiency. BRIEF DESCRIPTION OF THE DRAWINGS

[0057] The drawings of the present invention are intended to illustrate the general characteristics of the methods, structures, and / or materials used in specific exemplary embodiments of the present invention to supplement the description in the specification. However, the drawings of the present invention are schematic diagrams not drawn to scale and may not be able to accurately reflect the precise structure or performance characteristics of any given embodiment. The drawings of the present invention should not be construed as limiting or restricting the scope of the numerical values or properties covered by the exemplary embodiments according to the present invention. The present invention will be further described in detail below in conjunction with the drawings and specific embodiments:

[0058] Figure 1 It is a schematic flowchart of the present invention. DETAILED DESCRIPTION OF THE EMBODIMENTS

[0059] ​The following describes the implementation manners of the present invention through specific embodiments. Those skilled in the art can fully understand other advantages and technical effects of the present invention from the content disclosed in this specification. The present invention can also be implemented or applied through different specific implementation manners. The details in this specification can also be applied based on different viewpoints, and various modifications or changes can be made without departing from the overall design concept of the invention. It should be noted that, without conflict, the following embodiments and the features in the embodiments can be combined with each other. The following exemplary embodiments of the present invention can be implemented in many different forms and should not be construed as being limited only to the specific embodiments described herein. It should be understood that these embodiments are provided to make the disclosure of the present invention thorough and complete, and to fully convey the technical solutions of these exemplary specific embodiments to those skilled in the art.

[0060] The first embodiment;

[0061] Refer to Figure 1 As shown, the present invention provides a key recovery method for the SM2 signature algorithm based on lattice attack, including the following steps:

[0062] S1. Construct a Hidden Number Problem (HNP):

[0063] If s is the signature corresponding to the random number k, then s = ((1 + d) -1 - (k - r·d)) mod n;

[0064] Assume that the highest l (l≥2) bits of the random number k are known as k1, then u = k - k1·n*2 l , u is an integer not less than 0 and u is less than n / 2 l , and substitute it into formula (1);

[0065] s = ((1 + d) -1 ·(k - r·d)) mod n Formula (1);

[0066] Obtain formula (2);

[0067] u = (s + r)d - k l ·n / 2 l mod n Formula (2);

[0068] Define Simplify formula (2) to u = dt - a mod n, and t and a can be calculated through public parameters;

[0069] Then holds;

[0070] Therefore, for m groups of signature results (r i , s i ), for each group of signatures corresponding to (ti , a i ) all satisfy formula (3);

[0071]

[0072] r and s are the signatures corresponding to random numbers, d is the private key, corresponding to constructing the hidden number α in the hidden number problem, t is obtained by adding s and r, dividing by n, and taking the integer part, k l is the bit information of the highest l bits of the random number k, l ≥ 2, a is obtained by multiplying k l by n, dividing by 2 l and taking the integer part and then taking the modulus n, n is the order of the elliptic curve, and i represents the serial number of the signature;

[0073] According to the definition of the hidden number problem (HNP), if a i is known, the problem of recovering the key is in the same form as the hidden number problem (HNP); therefore, the problem of recovering the private key of the SM2 signature algorithm is reduced to the hidden number problem (HNP), and then reducing it to solving the difficult problem on the lattice can recover the key;

[0074] S2, reduce the hidden number problem (HNP) to the bounded distance decoding problem (BDD);

[0075] There exists an integer c i such that the inequality |dt i - a i + c i n| ≤ n / 2 l holds;

[0076] Construct a (d + 1)-dimensional lattice L(B), which is generated by the matrix B,

[0077] The lattice vector v = (dt0 + c0n,..., dt m-1 + c m-1 n, d / 2 l ) belongs to L(B), which is obtained by multiplying the last row by m and adding the other rows multiplied by c i n, and the last coordinate of the lattice vector exposes the hidden number α = d, then v is called the hidden vector, and the distance between the hidden vector and the target vector v = (a0, a1,..., a m-1 , 0) is very close;

[0078] When it is shorter than the distance between other vectors in the lattice and the target vector, the key can be recovered by solving the bounded distance decoding problem (BDD), and it is transformed into the unique shortest vector problem (uSVP) for solution using Kannan embedding;

[0079] S3, reduce the bounded distance decoding problem (BDD) to the unique shortest vector problem (uSVP);

[0080] Construct a (d + 2)-dimensional lattice L(F) generated by the matrix F,

[0081] Target vector

[0082] For the embedding factor being u i The upper limit, that is At this time Use the re-centralization technique. Since 0 ≤ u i <n / 2 l , let w = n / 2 l+1 , obtain a new and shorter target vector:

[0083]

[0084] In the original hidden number problem (HNP), there is a i +u i =t i α. Use the elimination method to make the hidden number Then The hidden number changes from d to u0 - w, and the target vector is Its upper limit is

[0085] S4, use the sieving algorithm with predicate to solve the unique shortest vector problem (uSVP), and recover the hidden number to obtain the signature private key d.

[0086] When implementing step S4, there are the following two implementation methods;

[0087] First, use the sieving algorithm with predicate to solve the unique shortest vector problem (uSVP). Albrecht and Heninger proposed the sieving with predicate algorithm. The sieving algorithm will output a database of lattice vectors shorter than . After obtaining the database, use the predicate algorithm to detect whether each short vector in the database meets the conditions. Specifically, it includes the following sub-steps;

[0088] Define a variable r to store the currently found shortest vector, with the initial value being empty or set to a vector of a specified length, and the specified length is determined according to the requirements of the unique shortest vector problem (uSVP);

[0089] Run the sieving algorithm on the lattice L(B) to generate a database L containing short vectors;

[0090] Traverse each vector v in the database L output by the screening algorithm;

[0091] For each vector v in the database L, perform the following operations:

[0092] Use the predicate algorithm f() to verify whether the vector v satisfies the condition:

[0093] If f(v) = 1, then further check whether the length ||v|| of the vector v is less than the length ||r|| of the currently stored shortest vector r:

[0094] If ||v|| < ||r|| or r is empty, then update r to the current vector v:

[0095] After the traversal is completed, return the vector stored in the variable r, which is the shortest vector that satisfies the condition. The shortest vector v contains the hidden number related to the key, and the signature private key d is obtained.

[0096] More specifically, it is described as:

[0097]

[0098] Second, to reduce the computational overhead, a more efficient predicate algorithm is proposed by combining the small exponent test technique. The screening algorithm with the enhanced predicate algorithm is used to solve the unique shortest vector problem (uSVP), which includes the following sub-steps;

[0099] Define a variable r to store the currently found shortest vector, with an initial value of empty or set to a vector of a specified length, and the specified length is determined according to the requirements of the unique shortest vector problem (uSVP);

[0100] Run the screening algorithm on the lattice L(B) to generate a database L containing short vectors

[0101] Traverse each vector v in the database L output by the screening algorithm

[0102] For each vector v in the database L, perform the following operations:

[0103] Use the enhanced predicate algorithm f() to verify whether the vector v satisfies the condition:

[0104] Detect the legality of the vector. If any one of conditions 1) to 3) holds, then feedback failure;

[0105] 1) The second-to-last coordinate v of the vector v m-1 Whether it is 0, |v m-1 | = 0;

[0106] 2) The absolute value of the second-to-last coordinate v of the vector v m-1 Whether it exceeds n / 2l+1 , |v m-1 | ≥ n / 2 l+1 ;

[0107] 3) The last coordinate v of the vector v m is not equal to the embedding factor

[0108] Calculate the candidate value α;

[0109] If

[0110] Randomly select a set of decimal numbers θ1, θ2, …, θ m-1 ∈ [1, 2 x

[0111] If then feedback failure;

[0112] If

[0113] Randomly select a set of decimal numbers θ1, θ2, …, θ m-1 ∈ [1, 2 x

[0114] If then feedback failure;

[0115] If v satisfies the condition and f(v) = 1, then further check whether the length ||v|| of the vector v is less than the length ||r|| of the currently stored shortest vector r:

[0116] If ||v|| < ||r|| or r is empty, then update r to the current vector v:

[0117] After the traversal is completed, return the vector stored in the variable r, which is the shortest vector that satisfies the condition. The shortest vector v contains the hidden number related to the signature private key and can be used to obtain the signature private key d.

[0118] More specifically, the enhanced predicate algorithm is described as:

[0119]

[0120]

[0121] The second embodiment;

[0122] The present invention provides a computer-readable storage medium, which internally stores a computer program. When the computer program is executed, it is used to implement the steps of the key recovery method of the SM2 signature algorithm based on lattice attack described in the above embodiment.

[0123] ​​The computer-readable medium includes both permanent and non-permanent, removable and non-removable media and can implement information storage by any method or technology. The information can be computer-readable instructions, data structures, program modules, or other data. Examples of computer storage media include, but are not limited to, phase change memory (PRAM), static random access memory (SRAM), dynamic random access memory (DRAM), other types of random access memory (RAM), read-only memory (ROM), electrically erasable programmable read-only memory (EEPROM), flash memory or other memory technologies, compact disc read-only memory (CD-ROM), digital versatile disc (DVD) or other optical storage, magnetic cassettes, magnetic tape disk storage or other magnetic storage devices, or any other non-transitory medium that can be used to store information accessible by a computing device. As defined herein, computer-readable media does not include transitory media such as modulated data signals and carrier waves.

[0124] Unless otherwise defined, all terms used herein (including technical and scientific terms) have the same meaning as commonly understood by one of ordinary skill in the art to which this invention belongs. It will also be understood that terms, such as those defined in a general dictionary, should be interpreted as having a meaning consistent with their meaning in the context of the relevant art and not be interpreted in an idealized or overly formal sense unless expressly so defined herein.

[0125] The present invention has been described in detail above through specific embodiments and examples, but these do not constitute a limitation to the present invention. Without departing from the principle of the present invention, those skilled in the art can also make many variations and improvements, which should also be regarded as the protection scope of the present invention.

Claims

1. A key recovery method for SM2 signature algorithm based on lattice attack, characterized in that: The following steps are involved: S1, construct the hidden number problem (HNP): r, s are the signatures corresponding to the random numbers, d is the private key, and the hidden number α in the hidden number problem is constructed. t is obtained by adding s to r and dividing it by n and taking the integer part, k ι is the highest l bits of random number k, l ≥ 2, a is calculated by ι Multiply by n and divide by 2 l And take the integer part and then modulo n to get it, n is the order of the elliptic curve, i represents the serial number of the signature; S2, reducing the Hidden Number Problem (HNP) problem to the Bounded Distance Decoding Problem (BDD); S3, reducing the bounded distance decoding problem (BDD) to the unique shortest vector problem (uSVP); S4, uses the screening algorithm with enhanced linear predicate algorithm to solve the unique shortest vector problem (uSVP), recovers the hidden number and obtains the signature private key d.

2. The key recovery method of the SM2 signature algorithm based on lattice attack as claimed in claim 1, characterized in that: The implementation step S1 includes the following sub-steps: s=((1+d) -1 ·(kr·d))mod n Formula (1); u=(s+r)dk ι n / 2 l mod n formula (2); r,s is the SM2 signature corresponding to the random number, u=kk ι n / 2 l , where u is an integer not less than 0 and u is less than n / 2 l of; definition The simplified formula (2) is u = dt-a mod n, and t and a can be calculated through public parameters; but Established; Give m groups of signature results (r i ,s i )For each set of signatures corresponding to (t i , a i ) all satisfy formula (3).

3. The key recovery method of the SM2 signature algorithm based on lattice attack as claimed in claim 2, characterized in that: The implementation step S2 includes the following sub-steps: Based on formula (3), it is deduced that there exists an integer C i So that the following formula (4) is established; |dt i -a i +c i n|≤n / 2 l Formula (4); Construct a (d+1)-dimensional lattice L(B), generated by the matrix B, Get the hidden vector and target vector; When the distance between the hidden vector and the target vector When the distance between the target vector and other vectors in the lattice is shorter, the key can be solved.

4. The key recovery method of the SM2 signature algorithm based on lattice attack as claimed in claim 3 is characterized in that: The implementation of step S3 includes the following steps: Construct a (d+2)-dimensional lattice L(F) generated by the matrix F, Target vector v = ±(dt0-a1+c0n, ..., dt m-1 -a m +c m-1 n,d / 2 l , t j )=±(u0,u1,…,u m-1 , d / 2 l , -t j ) t j is the embedding factor, which is u i The upper limit of Use the Recentering Technique and set w = n / 2 l+1 Get a shorter target vector v=(u0-w,u1-w,…,u m-1 -w,d / 2 l ,-t j ); Using the Elimination Method, let the implicit number but The implicit number changes from d to u0-w, and the target vector is v = ±(u1-w, ..., u m-1 -w,u0–w,-t j ), whose upper bound is 5. The key recovery method of the SM2 signature algorithm based on lattice attack as claimed in claim 4, characterized in that: The unique shortest vector problem (uSVP) is solved using the sieving algorithm with enhanced linear predicate algorithm, which includes the following sub-steps; Define a variable r to store the shortest vector currently found. The initial value is empty or set to a vector of a specified length. The specified length is determined according to the requirements of the unique shortest vector problem (uSVP). Run the screening algorithm on the lattice L(B) to generate a database L containing short vectors; Traverse each vector v in the database L output by the screening algorithm; For each vector v in the database L, do the following: Use the predicate algorithm f() to verify whether the vector v satisfies the condition: Check the legitimacy of the vector. If any of the conditions 1) to 3) is met, the feedback fails. 1) The penultimate coordinate v of the vector v m-1 Is it 0,|v m-1 |=0; 2) The penultimate coordinate v of vector v m-1 Whether the absolute value exceeds n / 2 l+1 ,|v m-1 |≥n / 2 l+1 ; 3) The last coordinate v of vector v m Not equal to the embedding factor t j ,|v m |≠t j ; Calculate candidate value α; if Randomly select a set of small numbers θ1, θ2, ..., θ m-1 ∈[1,2 x ] if The feedback fails; if Randomly select a set of small numbers θ1, θ2, ..., θ m-1 ∈[1,2 x ] if The feedback fails; If v satisfies the condition, f(v) = 1, then further check whether the length of vector v ||v|| is less than the length of the shortest vector r currently stored ||r||: If ||v||<||r|| or r is empty, update r to the current vector v: After the traversal is completed, the vector stored in the variable r is returned. This vector is the shortest vector that meets the conditions. The shortest vector v contains the hidden number related to the signature private key, which is used to obtain the signature private key d.

6. A computer-readable storage medium, characterized in that: A computer program is stored therein, and when the computer program is executed, it is used to implement the steps of the key recovery method of the SM2 signature algorithm based on lattice attack as described in any one of claims 1-5.