Skip to content

sm2: reject point at infinity in signature verification - #1946

Merged
tarcieri merged 2 commits into
RustCrypto:masterfrom
kriss39:fix/sm2-verify-identity
Oct 2, 2026
Merged

tarcieri merged 2 commits into
RustCrypto:masterfrom
kriss39:fix/sm2-verify-identity

Conversation

@kriss39

@kriss39 kriss39 commented Oct 2, 2026

Copy link
Copy Markdown
Contributor

In verify_prehash, step B6 computes [s']G + [t]PA and goes straight to .to_affine().x(). draft-shen-sm2-ecdsa 5.3.1 (and GB/T 32918.2) say verification fails if that point is the point at infinity, but here the identity's x is just 0, so B7 turns into r == e and passes.

Producing such a signature needs the private key (r = e, s = -r*d / (1 + d)), so it's a conformance issue rather than a forgery, but other implementations reject it and this one shouldn't accept it either.

This adds the identity check before taking x, plus a test in tests/sm2dsa.rs that builds that signature and fails on master.

Step B6 of the verification algorithm fails if [s']G + [t]PA is the point at infinity. Without the check its x coordinate is taken as 0 and a signature with r = e passes B7.
Comment thread sm2/src/dsa/verifying.rs Outdated

@tarcieri tarcieri left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Thanks, good catch!

@tarcieri
tarcieri merged commit b37ef18 into RustCrypto:master Oct 2, 2026
13 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants