GM/T 0044.2-2016 in English
VALIDIdentity-based cryptographic algorithms SM9 - Part 2: Digital signature algorithm
- Issued on:2016-03-28
- Implemented on:2016-03-28
- File Format:PDF
- Delivery:Via email within 1~3 business days
$136.00
| Standard No: | GM/T 0044.2-2016 |
| Document status: | VALID |
| Title in English: | Identity-based cryptographic algorithms SM9 - Part 2: Digital signature algorithm |
| Title in Chinese: | SM9标识密码算法 第2部分:数字签名算法 |
| Language: | English |
| File Format: | Electronic (PDF) |
| Delivery: | Via email within 1~3 business days |
| Issued on: | 2016-03-28 |
| Implemented on: | 2016-03-28 |
| Related Keywords: | digital signature algorithm
sm9 digital signature algorithm gm/t digital signature electronic signature system core algorithm parameters parameterdescriptionmathematical representation signature master keysystem |
| Related Topics: | algorithm
gm t gm/t sm9 identifies the digital signature algorithm digital signature Algorithm gm/t0045-2016 sign double log algorithm Calculate digital estimate National standard analysis method name |
Introduction
Technical Analysis of SM9 Digital Signature Algorithm
GM/T 0044.2-2016 standard defines a digital signature algorithm based on an identity cryptographic system, using elliptic curve pairs to achieve natural binding of identity and key. The algorithm distributes signature private keys through a key generation center (KGC), eliminating the certificate management burden of the traditional PKI system.
Core algorithm parameters
| Parameter | Description | Mathematical representation |
|---|---|---|
| Signature master key | System top-level key pair | (Ppub-s, s) |
| User signature key | Derived from the identifier ID | ds=[1/(s+H(ID))]P |
| Bilinear pairing | Core operation function | e: G1×G2→GT |
Signature generation process
Typical application scenario: In the government electronic signature system, after using the SM3 hash algorithm to process the document to be signed:
- Generate a random number r∈[1,N-1]
- Calculate w=e(g,g)r
- Generate a hash value h through H2(M||w,N)
- Output signature (h, [rh]ds)
Innovation of verification algorithm
The verification process realizes certificateless verification through the bilinear pairing property:
e(S', P) · e([h]P1 + Ppub-s, P2)-1 = e(g,g)rh · e(g,g)h = w
This design allows the verifier to complete the verification only by knowing the signer's ID, without the need to exchange public key certificates in advance.
Implementation Recommendations
- Key Management:KGC should use a hardware cryptographic module to protect the master private key
- Parameter Selection:It is recommended to use the BN curve to achieve 256-bit security strength
- System Integration:Implemented in conjunction with the general provisions of GM/T 0044.1

Loading PDF document...
Error loading PDF. Please make sure the file is valid and try again.
We also recommend
-

GM/T 0107-2021 in English
Smart IC card key management system basic technical requirements
2021-10-18 -

GM/T 0065-2019 in English
Specification for capability construction of production and guarantee for commercial-cryptographic products
2019-07-12 -

GM/T 0027-2014 in English
Technique requirements for smart token
2014-02-13 -

GM/T 0039-2015 in English
Security Test Requirements for Cryptographic Modules
2015-04-01 -

GM/T 0076-2019 in English
Cryptography technical requirements for banking card information systems
2019-07-12 -

GM/T 0042-2015 in English
Test specification for cryptography and security protocol in tri-element peer architecture
2015-04-01 -

GM/T 0077-2019 in English
Cryptography tecyhnical requirements for core banking systems
2019-07-12 -

GM/T 0074-2019 in English
Technical requirements on cryptographic application for internet banking
2019-07-12 -

GM/T 0071-2019 in English
Guidance of cryptographic application for electronic records
2019-07-12 -

GM/T 0044.3-2016 in English
Identity-based cryptographic algorithms SM9 - Part 3: Key exchange protocol
2016-03-28