The present invention discloses a security protection method based on the SM9 signature
algorithm. The method determines the
operation time according to the value of a random number. The
operation time is random. In addition, the point multiplication
operation time is also random, which can
resist timing attacks. A key
mask operation is performed on the user's private key. At the same time, the point multiplication operands are randomized in the point multiplication operation. The NAF point multiplication
algorithm is used. The private key is not leaked during the signature
algorithm. At the same time, the intermediate process is fully masked, so that
power consumption, electromagnetic and key information are unrelated, and the method can
resist energy consumption and electromagnetic attacks. By comparing the hash operation at the beginning of the algorithm and before the point multiplication operation, it can detect whether the relevant parameter variables have been tampered with or whether there is error injection. In addition, after the signature is completed, a
verification operation is performed on the signature value. It can detect whether all parameter variables and intermediate variables in the full
process operation have been tampered with or whether there is error injection, which can
resist fault attacks.