Page 328 - 《软件学报》2026年第6期
P. 328
软件学报 ISSN 1000-9825, CODEN RUXUEW E-mail: jos@iscas.ac.cn
2026,37(6):2647−2657 [doi: 10.13328/j.cnki.jos.007469] [CSTR: 32375.14.jos.007469] http://www.jos.org.cn
©中国科学院软件研究所版权所有. Tel: +86-10-62562563
*
基于国密 SM9 的密钥隔离签名
高 睿 1,2 , 丁 昀 1 , 高 欣 1 , 王化群 1,2
1
(南京邮电大学 计算机学院、软件学院、网络空间安全学院, 江苏 南京 210023)
2
(江苏省密码技术工程研究中心, 江苏 南京 210023)
通信作者: 王化群, E-mail: wanghuaqun@aliyun.com
摘 要: 签名计算通常在移动电话或小型物联网设备等不安全的物理设备上进行, 这可能导致私钥暴露, 从而引发
整个密码系统的崩溃. 密钥隔离签名方案是减轻私钥暴露造成的损害的一种方法. 在密钥隔离密码系统中, 公钥在
整个时间周期内保持不变, 固定私钥被存储在物理安全设备上. 在每个离散的时间段开始时, 不安全设备通过与存
储固定私钥的物理安全设备的交互以获得当前时间片的临时私钥. 一个安全的基于身份的密钥隔离签名方案需要
满足签名不可伪造性和密钥隔离性. 密钥隔离性保证了即使一个攻击者获得了多个时间段的临时私钥, 它也无法
伪造其他时间段的签名. SM9 是我国自主设计的商用标识密码算法. 将密钥隔离方法应用于 SM9 基于身份的签名
方案中, 解决原方案中存在的私钥暴露问题. 首先给出基于身份的密钥隔离签名的安全模型. 然后构造一个基于身
份的 SM9 密钥隔离签名方案. 最后给出详细的安全性证明和实验分析.
关键词: 国密 SM9; 基于身份的签名; 前向-后向安全; 安全性分析
中图法分类号: TP309
中文引用格式: 高睿, 丁昀, 高欣, 王化群. 基于国密SM9的密钥隔离签名. 软件学报, 2026, 37(6): 2647–2657. http://www.jos.org.cn/
1000-9825/7469.htm
英文引用格式: Gao R, Ding Y, Gao X, Wang HQ. Key-isolated Signature Based on SM9. Ruan Jian Xue Bao/Journal of Software,
2026, 37(6): 2647–2657 (in Chinese). http://www.jos.org.cn/1000-9825/7469.htm
Key-isolated Signature Based on SM9
1,2
1
1
GAO Rui , DING Yun , GAO Xin , WANG Hua-Qun 1,2
1
(School of Computer Science, Nanjing University of Posts and Telecommunications, Nanjing 210023, China)
2
(Jiangsu Cryptographic Technology Engineering Research Center, Nanjing 210023, China)
Abstract: The computation of signatures is typically performed on physically insecure devices such as mobile phones or small IoT
devices, which may lead to private key exposure and subsequently compromise the entire cryptographic system. Key-insulated signature
schemes serve as a method to mitigate the damage caused by private key exposure. In a key-insulated cryptosystem, the public key
remains constant throughout the entire time period, and the fixed private key is stored on a physically secure device. At the beginning of
each time period, the insecure device interacts with the physically secure device storing the fixed private key to obtain the temporary
private key for the current time slice. A secure identity-based key-insulated signature scheme must satisfy both unforgeability and key
insulation. Key insulation ensures that even if an adversary obtains temporary private keys for multiple time periods, they cannot forge
signatures for other periods. SM9 is a commercial identity-based cryptographic standard independently developed by China. This study
applies the key-insulated method to the SM9 identity-based signature scheme to resolve the private key exposure issue present in the
original scheme. First, a security model for identity-based key-insulated signatures is presented. Then, an identity-based key-insulated
signature scheme based on SM9 is constructed. Finally, detailed security proofs and experimental analysis are provided.
Key words: SM9; identity-based signature; forward-backward security; security analysis
* 基金项目: 国家自然科学基金 (U23B2002); 江苏省研究生科研创新计划 (KYCX25_1146, KYCX25_1159)
收稿时间: 2024-12-03; 修改时间: 2025-03-17; 采用时间: 2025-05-12; jos 在线出版时间: 2025-09-10
CNKI 网络首发时间: 2025-09-11

