Skip to main navigation Skip to search Skip to main content

Security on SM2 and GOST signatures against related key attacks

Research output: Chapter in Book/Report/Conference proceedingConference PaperResearchpeer-review

Abstract

The US Standard (EC)DSA is currently almost the most popular digital signature scheme. Chinese and Russian governments also proposed their counterparts: SM2 and GOST R 34.10 (GOST). Nowadays, there are already many industrial applications supporting SM2 and GOST digital signatures. Unfortunately, the existing analyses for SM2 and GOST are rather limited when compared to ECDSA. This paper focuses on the security of SM2 and GOST from the viewpoints of RKA security (related-key attack) and sKRKA security (strong known related key attack). RKA captures the real attacks of tampering and fault injection in hardware-stored secret keys. sKRKA, a recently proposed security model modified from RKA, captures the real attacks in the BIP-32 HD wallet and the stealth address used in Monero. It was proved that ECDSA is insecure in the RKA model (ICISC 2015) and but secure in the sKRKA model (NSS 2019). In this work, we proved that GOST is insecure in both RKA and skRKA models, but SM2 is secure in both RKA and sKRKA models. This result well differentiates the security of ECDSA, SM2 and GOST, and demonstrates that Chinese SM2 is capable to construct secure cryptocurrency systems using BIP-32 HD wallet or stealth address, as secure as ECDSA, but outperforms ECDSA in resisting tampering or fault injection attacks.

Original languageEnglish
Title of host publicationProceedings - 2021 IEEE 20th International Conference on Trust, Security and Privacy in Computing and Communications, TrustCom 2021
EditorsLiang Zhao, Neeraj Kumar, Robert C. Hsu, Deqing Zou
Place of PublicationPiscataway NJ USA
PublisherIEEE, Institute of Electrical and Electronics Engineers
Pages155-163
Number of pages9
ISBN (Electronic)9781665416580
ISBN (Print)9781665416597
DOIs
Publication statusPublished - 2021
Externally publishedYes
EventIEEE International Conference on Trust, Security and Privacy in Computing and Communications (TrustCom) 2021 - Shenyang, China
Duration: 20 Oct 202122 Oct 2021
Conference number: 20th

Conference

ConferenceIEEE International Conference on Trust, Security and Privacy in Computing and Communications (TrustCom) 2021
Abbreviated titleTrustCom 2021
Country/TerritoryChina
CityShenyang
Period20/10/2122/10/21

Keywords

  • GOST
  • related-key attack
  • SM2
  • strong known related key attack

Cite this