Page 328 - 《软件学报》2026年第6期
P. 328

软件学报 ISSN 1000-9825, CODEN RUXUEW                                        E-mail: jos@iscas.ac.cn
                 2026,37(6):2647−2657 [doi: 10.13328/j.cnki.jos.007469] [CSTR: 32375.14.jos.007469]  http://www.jos.org.cn
                 ©中国科学院软件研究所版权所有.                                                          Tel: +86-10-62562563



                                                       *
                 基于国密        SM9   的密钥隔离签名

                 高    睿  1,2 ,    丁    昀  1 ,    高    欣  1 ,    王化群  1,2


                 1
                  (南京邮电大学 计算机学院、软件学院、网络空间安全学院, 江苏 南京 210023)
                 2
                  (江苏省密码技术工程研究中心, 江苏 南京 210023)
                 通信作者: 王化群, E-mail: wanghuaqun@aliyun.com

                 摘 要: 签名计算通常在移动电话或小型物联网设备等不安全的物理设备上进行, 这可能导致私钥暴露, 从而引发
                 整个密码系统的崩溃. 密钥隔离签名方案是减轻私钥暴露造成的损害的一种方法. 在密钥隔离密码系统中, 公钥在
                 整个时间周期内保持不变, 固定私钥被存储在物理安全设备上. 在每个离散的时间段开始时, 不安全设备通过与存
                 储固定私钥的物理安全设备的交互以获得当前时间片的临时私钥. 一个安全的基于身份的密钥隔离签名方案需要
                 满足签名不可伪造性和密钥隔离性. 密钥隔离性保证了即使一个攻击者获得了多个时间段的临时私钥, 它也无法
                 伪造其他时间段的签名. SM9        是我国自主设计的商用标识密码算法. 将密钥隔离方法应用于                    SM9  基于身份的签名
                 方案中, 解决原方案中存在的私钥暴露问题. 首先给出基于身份的密钥隔离签名的安全模型. 然后构造一个基于身
                 份的  SM9  密钥隔离签名方案. 最后给出详细的安全性证明和实验分析.
                 关键词: 国密   SM9; 基于身份的签名; 前向-后向安全; 安全性分析
                 中图法分类号: TP309

                 中文引用格式: 高睿, 丁昀, 高欣, 王化群. 基于国密SM9的密钥隔离签名. 软件学报, 2026, 37(6): 2647–2657. http://www.jos.org.cn/
                 1000-9825/7469.htm
                 英文引用格式: Gao R, Ding Y, Gao X, Wang HQ. Key-isolated Signature Based on SM9. Ruan Jian Xue Bao/Journal of Software,
                 2026, 37(6): 2647–2657 (in Chinese). http://www.jos.org.cn/1000-9825/7469.htm

                 Key-isolated Signature Based on SM9
                        1,2
                                  1
                                           1
                 GAO Rui , DING Yun , GAO Xin , WANG Hua-Qun 1,2
                 1
                 (School of Computer Science, Nanjing University of Posts and Telecommunications, Nanjing 210023, China)
                 2
                 (Jiangsu Cryptographic Technology Engineering Research Center, Nanjing 210023, China)
                 Abstract:  The  computation  of  signatures  is  typically  performed  on  physically  insecure  devices  such  as  mobile  phones  or  small  IoT
                 devices,  which  may  lead  to  private  key  exposure  and  subsequently  compromise  the  entire  cryptographic  system.  Key-insulated  signature
                 schemes  serve  as  a  method  to  mitigate  the  damage  caused  by  private  key  exposure.  In  a  key-insulated  cryptosystem,  the  public  key
                 remains  constant  throughout  the  entire  time  period,  and  the  fixed  private  key  is  stored  on  a  physically  secure  device.  At  the  beginning  of
                 each  time  period,  the  insecure  device  interacts  with  the  physically  secure  device  storing  the  fixed  private  key  to  obtain  the  temporary
                 private  key  for  the  current  time  slice.  A  secure  identity-based  key-insulated  signature  scheme  must  satisfy  both  unforgeability  and  key
                 insulation.  Key  insulation  ensures  that  even  if  an  adversary  obtains  temporary  private  keys  for  multiple  time  periods,  they  cannot  forge
                 signatures  for  other  periods.  SM9  is  a  commercial  identity-based  cryptographic  standard  independently  developed  by  China.  This  study
                 applies  the  key-insulated  method  to  the  SM9  identity-based  signature  scheme  to  resolve  the  private  key  exposure  issue  present  in  the
                 original  scheme.  First,  a  security  model  for  identity-based  key-insulated  signatures  is  presented.  Then,  an  identity-based  key-insulated
                 signature scheme based on SM9 is constructed. Finally, detailed security proofs and experimental analysis are provided.
                 Key words:  SM9; identity-based signature; forward-backward security; security analysis


                 *    基金项目: 国家自然科学基金  (U23B2002); 江苏省研究生科研创新计划 (KYCX25_1146, KYCX25_1159)
                  收稿时间: 2024-12-03; 修改时间: 2025-03-17; 采用时间: 2025-05-12; jos 在线出版时间: 2025-09-10
                  CNKI 网络首发时间: 2025-09-11
   323   324   325   326   327   328   329   330   331   332   333