The invention discloses an MPC threshold signature method and
system suitable for HSM, and relates to the technical field of
information security and
cryptography, and the method comprises the steps: a management module manages a plurality of hardware security modules HSM, coordinates a
key generation module of each HSM to execute a distributed
key generation protocol DKG, and enables a private key fragment to be directly generated in each HSM and to be encrypted and stored; the MPC threshold signature module receives a to-be-signed message of an application APP and user
certificate information, calls the management module to perform identity
verification on the user
certificate information, and obtains a target HSM node
list associated with a user passing
verification; the MPC threshold signature module schedules a threshold signature module with at least a threshold value of t HSM nodes according to the target HSM node
list, and MPC threshold signature operation is executed in each HSM based on private key fragments; and the MPC threshold signature module receives partial signatures returned by each HSM, and aggregates the partial signatures into a standard
digital signature for realizing efficient, compliant and single-point fault resistant
digital signature operation on the premise of ensuring absolute security of the private key.