In scenarios involving the transmission of sensitive information, the information sender can provide identity proof through asymmetric signature verification. The specific operation flow is as follows:
2. The information sender generates a signature for the data to be transmitted using the created user private key. For details, see Signature. 3. The information sender transmits the signature and data to the information recipient.
4. After obtaining the signature and data, the information recipient verifies the signature. There are two methods for performing this verification.
4.1 Call the KMS signature verification API to perform the verification. For details, see Verify Signature. 4.2 Download the KMS asymmetric key public key and verify it locally using methods such as gmssl, openssl, cryptographic libraries, or the KMS SM Encryption SDK.
Note:
Asymmetric signature verification currently supports SM2/RSA/ECC signature algorithms.