摘要
针对移动终端易丢失且安全防护等级较低、存储于终端的SM2私钥安全性较低等问题,设计了基于SM2的协作签名算法提高私钥安全性,并对其安全性进行证明。结合SM2协作签名算法和英特尔软件保护扩展(software guard extension,SGX)技术,提出一种与云计算技术结合的协作签名应用部署方案。该方案解决了目前协作签名应用使用专用密码机的硬件部署弊端,使协作签名应用在享受云计算优势的同时,确保机密数据的安全性。针对功能正确性测试1000次,验证签名通过1000次,通过率为100%;通过安全性测试分析表明,该方案以合理的开销,显著地提高了协作签名应用在云服务中的安全性,具有较高的实用价值。
With the popularization and development of mobile devices,mobile terminals are widely used to deal with sensitive applications such as mobile payment and electronic wallet.SM2 digital signature algorithm can effectively protect the authenticity and integrity of confidential data in sensitive applications.Aiming at the problems that mobile terminals are easy to lose and the security protection level is low,and the security of SM2 private key stored in terminals is low,we propose a cooperative signature algorithm based on SM2 to improve the security of private key,and its security is proved.Based on SM2 collaborative signature algorithm and SGX technology,a collaborative signature application deployment scheme combined with cloud computing technology is proposed.The scheme solves the disadvantages of the current collaborative signature applications,such as the use of special cryptography machine,and ensures the security of confidential data while enjoying the advantages of cloud computing.The performance analysis shows that the execution time of this algorithm is about 15%—25%longer than that of other collaborative signature algorithms.For the function correctness test 1000 times,the verification signature passes 1000 times,and the pass rate is 100%.Through security testing and analysis,this scheme can significantly improve the security of collaborative signature application in cloud services with reasonable cost,and has high practical value.
作者
马莉媛
黄勃
MA Liyuan;HUANG Bo(College of Electronic and Electrical Engineering,Shanghai University of Engineering Science,Shanghai 201600,P.R.China)
出处
《重庆邮电大学学报(自然科学版)》
CSCD
北大核心
2022年第6期1065-1070,共6页
Journal of Chongqing University of Posts and Telecommunications(Natural Science Edition)
基金
国家自然科学青年基金(61802251)。
关键词
SM2签名算法
两方协作签名
云计算
软件保护扩展技术
数据安全
SM2 signature algorithm
two-party collaborative signature
cloud computing
software guard extension technology
data security