GM/T 0044.3-2016 in English
VALIDIdentity-based cryptographic algorithms SM9 - Part 3: Key exchange protocol
- Issued on:2016-03-28
- Implemented on:2016-03-28
- File Format:PDF
- Delivery:Via email within 1~3 business days
$136.00
| Standard No: | GM/T 0044.3-2016 |
| Document status: | VALID |
| Title in English: | Identity-based cryptographic algorithms SM9 - Part 3: Key exchange protocol |
| Title in Chinese: | SM9标识密码算法 第3部分:密钥交换协议 |
| Language: | English |
| File Format: | Electronic (PDF) |
| Delivery: | Via email within 1~3 business days |
| Issued on: | 2016-03-28 |
| Implemented on: | 2016-03-28 |
| Related Keywords: | sm9 key exchange protocol gm/t
key exchange protocol introduction technical analysis key negotiation private key key negotiation mechanism |
| Related Topics: | password
algorithm key gm t gm/t sm9 identifies the digital signature algorithm key exchange private key key exchange key |
Introduction
Technical Analysis of SM9 Key Exchange Protocol
GM/T 0044.3-2016 standard defines the key negotiation mechanism in the identity-based cryptography system, the core of which uses elliptic curve pairs to implement bilinear mapping. The protocol allows the communicating parties to establish a shared key in 2-3 interactions through the identity and private key, which is suitable for secure session key generation.
Core parameters of the protocol
| Parameter | Description | Mathematical representation |
|---|---|---|
| System master key | Top-level key pair generated by KGC | (s, Ppub=[s]P1) |
| User private key | Calculated by identifier hid | dA=[H1(ID‖hid)+s]-1P2 |
| Temporary key | Session random number | rA, rB∈[1,N-1] |
Protocol Execution Flow
- Calculate QB=[H1(IDB)](P1)+Ppub
- Generate random number rA
- Send RA=[rA]QB
- Calculate bilinear pairing: g1=e(RA,dB), g2=e(Ppub,P2)rB
- Derived key: SK=KDF(ID‖RA‖RB‖g1‖g2)
Security enhancement mechanism
- Key confirmation: Two-way verification is achieved through Hash(0x82‖g1‖Hash(g2‖g3‖ID‖R))
- Anti-man-in-the-middle attack: Relies on the elliptic curve discrete logarithm problem (ECDLP) and the bilinear Diffie-Hellman assumption
- Forward security: Single-use property of temporary key rA/rB
Implementation suggestions
Typical application scenario: In the government security communication system, the SM9 protocol is used to implement:
- Terminal devices are registered using a unified identifier
- KGC centrally distributes private keys
- Session key negotiation takes <200ms (based on a 256-bit curve)
Compatibility considerations: Ensure that all participants:
- Use the same elliptic curve parameters (defined in GM/T 0044.5)
- Implement SM3 hash algorithm (GM/T 0004)
- Use certified random number generator

Loading PDF document...
Error loading PDF. Please make sure the file is valid and try again.
We also recommend
-

GM/T 0044.4-2016 in English
Identity-based cryptographic algorithms SM9 - Part 4: Key encapsulation mechanism and public key encryption alogorithm
2016-03-28 -

GM/T 0039-2015 in English
Security Test Requirements for Cryptographic Modules
2015-04-01 -

GM/T 0065-2019 in English
Specification for capability construction of production and guarantee for commercial-cryptographic products
2019-07-12 -

GM/T 0027-2014 in English
Technique requirements for smart token
2014-02-13 -

GM/T 0107-2021 in English
Smart IC card key management system basic technical requirements
2021-10-18 -

GM/T 0066-2019 in English
Implementation guide to capability construction criteria of production and guarantee for commercial cryptographic products
2019-07-12 -

GM/T 0071-2019 in English
Guidance of cryptographic application for electronic records
2019-07-12 -

GM/T 0040-2015 in English
Cipher test specification of radio frequency identification tag module
2015-04-01 -

GM/T 0070-2019 in English
Technical requirement for applications of cryptography in electronic insurance policy
2019-07-12 -

GM/T 0068-2019 in English
Open third party resource authorization protocol framework
2019-07-12