信息网络安全 ›› 2021, Vol. 21 ›› Issue (8): 17-25.doi: 10.3969/j.issn.1671-1122.2021.08.003

• 技术研究 • 上一篇    下一篇

密钥管理服务系统下的多方协同SM4加/解密方案

杨伊1, 何德彪1(), 文义红2, 罗敏1   

  1. 1.武汉大学国家网络安全学院,武汉 430072
    2.中国电子科技集团有限公司第五十四研究所,石家庄 050000
  • 收稿日期:2021-05-11 出版日期:2021-08-10 发布日期:2021-09-01
  • 通讯作者: 何德彪 E-mail:hedebiao@163.com
  • 作者简介:杨伊(1993—),女,湖北,博士研究生,主要研究方向为数字签名和安全多方计算|何德彪(1980—),男,湖北,教授,博士,主要研究方向为密码协议、信息安全、区块链技术与应用|文义红(1977—),男,湖北,高级工程师,博士,主要研究方向为航天区块链、模拟仿真训练|罗敏(1974—),男,湖北,副教授,博士,主要研究方向为密码协议、信息安全、区块链技术与应用
  • 基金资助:
    国家重点研发计划(2018YFC1604000);国家自然科学基金(61932016);国家自然科学基金(61972294)

Multi-party Collaborative SM4 Encryption/Decryption Scheme in Key Management Service

YANG Yi1, HE Debiao1(), WEN Yihong2, LUO Min1   

  1. 1. School of Cyber Science and Engineering, Wuhan University, Wuhan 430072, China
    2. The 54th Research Institute of CETC, Shijiazhuang 050000, China
  • Received:2021-05-11 Online:2021-08-10 Published:2021-09-01
  • Contact: HE Debiao E-mail:hedebiao@163.com

摘要:

随着密码国产化与密钥保护需求的不断增加,商用密码算法与密钥安全管理的复合应用成为专家和学者关注的焦点之一。为解决加 / 解密方案中私钥易泄露的问题,针对密钥管理服务系统,文章提出一种安全高效的多方协同SM4加/ 解密方案。该方案利用一次一密且可以预计算的Beaver乘法三元组构成安全两方乘加转换器,保证多方S盒协同计算,从而实现安全高效的多方协同SM4加/解密,有效降低了在线交互过程中的计算开销与通信开销。安全性分析表明,文章方案在恶意模型下是安全的;其他性能分析详细统计了方案的计算开销与通信开销,表明方案是高效且适用于密钥管理服务系统的。

关键词: 密钥管理服务, SM4, 多方协同, Beaver乘法三元组

Abstract:

With the increasing demand for cryptograph localization and key protection, the composite application of commercial cryptographic algorithm and key security management has become one of the focuses of experts and scholars. In order to solve the problem of easy key disclosure in encryption/decryption scheme, this paper proposes a secure and efficient multi-party collaborative SM4 encryption/decryption scheme for key management service (KMS) system. The scheme uses the Beaver’s triple, which can be calculated predicatively and once, to construct a secure two-party multiplication and addition converter to ensure multi-party S-box collaborative computing, so as to realize the secure and efficient multi-party collaborative SM4 encryption/decryption and effectively reduce the computation and communication costs in the process of online interaction. Security analysis shows that the proposed scheme is secure under the malicious model and the other performance analysis details the computation and communication costs of the proposed scheme, which show that the proposed scheme is efficient and suitable for KMS system.

Key words: key management service, SM4, multi-party collaborate, Beaver’s triple

中图分类号: