The application is suitable for the field of
information security technology, and provides a
certificate signature scheme based on an SM9 signature
algorithm, which comprises the following steps: S100,
system initialization calculation, a
certificate authority generates a random number as a private key and calculates a public key, then randomly selects a signer private key and performs public key calculation to produce a signer private key pair; S200,
certificate authorization, a signer provides identity information to the
certificate authority, the
certificate authority verifies the information according to the information and the key information, and calculates and generates a certificate after the information passes, and feeds back the certificate to the signer; and S300, signature calculation and the like. The application is based on the signature structure of the SM9 national secret
algorithm, combines the advantages of traditional
public key cryptography and identity-based
encryption technology, and solves the problems of complex certificate management and
key escrow. The scheme can
resist attacks of Type 1 and Type 2 enemies at the same time.