信息网络安全 ›› 2023, Vol. 23 ›› Issue (11): 9-16.doi: 10.3969/j.issn.1671-1122.2023.11.002

• 技术研究 • 上一篇    下一篇

基于国密SM2算法的证书透明日志系统设计

陈立全1(), 薛雨欣1, 江英华1,2, 朱雅晴1   

  1. 1.东南大学网络空间安全学院,南京 211189
    2.西藏民族大学信息工程学院,咸阳 712082
  • 收稿日期:2023-06-18 出版日期:2023-11-10 发布日期:2023-11-10
  • 通讯作者: 陈立全 lqchen@seu.edu.cn
  • 作者简介:陈立全(1976—),男,广西,教授,博士,CCF会员,主要研究方向为网络与信息安全|薛雨欣(2002—),女,山东,本科,主要研究方向为物联网安全、密码应用技术|江英华(1989—),男,重庆,讲师,硕士,主要研究方向为密码学、量子密码学|朱雅晴(1997—),女,河南,硕士研究生,主要研究方向为物联网安全技术
  • 基金资助:
    国家自然科学基金(U22B2026)

Design of Certificate Transparency Log System Based on SM2 Algorithm

CHEN Liquan1(), XUE Yuxin1, JIANG Yinghua1,2, ZHU Yaqing1   

  1. 1. School of Cyber Science and Engineering, Southeast University, Nanjing 211189, China
    2. College of Information Engineering, Xizang Minzu University, Xianyang 712082, China
  • Received:2023-06-18 Online:2023-11-10 Published:2023-11-10

摘要:

证书透明日志系统具有广泛应用前景,但当前的证书透明日志系统多采用存在一定局限性的RSA算法和ECC算法,且无法识别基于国密算法的SSL证书。文章提出了一种基于国密SM2算法的证书透明日志系统设计方法,采用SM2算法生成日志系统签名密钥和数字签名证书透明日志数据,采用SM3算法作为系统的摘要算法来计算日志签名数据的哈希值,实现支持国密SSL证书的证书透明日志系统,用于保障国密SSL证书的安全可信。

关键词: 证书透明日志系统, 国密SSL证书, 国密HTTPS加密, SM2算法

Abstract:

The certificate transparency log system is an important mechanism for ensuring the security of digital certificates and addressing malicious issuances. The local encryption algorithm, SM2, which is independently developed in our country and has become an international standard, has a wide range of potential applications in the field of digital certificates. However, the current certificate transparency log systems mostly rely on RSA, ECC and they cannot recognize SSL certificates based on the SM2 algorithm. In this paper, a design method for a certificate transparency log system based on the SM2 algorithm is proposed. The system utilized the SM2 algorithm to generate the log system's signature key and to digitally sign the certificate transparency log data and the SM3 algorithm was used as the digest algorithm required by the system to calculate the hash value. This implementation enables the support of SM2 SSL certificates in the certificate transparency log system, thereby ensuring the security and trustworthiness of these SM2 SSL certificates.

Key words: certificate transparency log system, SM2 SSL Certificate, SM2 HTTPS encryption, SM2 algorithm

中图分类号: