GB/T 35275-2017 in English
VALIDInformation security technology―SM2 cryptographic algorithm encrypted signature message syntax specification
- Issued on:2017-12-29
- Implemented on:2018-07-01
- File Format:PDF
- Delivery:Via email within 1~3 business days
$214.00
《GB/T 35275-2017信息安全技术 SM2密码算法加密签名消息语法规范》由TC260(全国网络安全标准化技术委员会)归口,主管部门为国家标准化管理委员会。
Introduction
1. Standard Background and Overview
GB/T 35275—2017 is a national standard of the People's Republic of China, which specifies the syntax of encrypted signature messages using the SM2 cryptographic algorithm. This standard was proposed and managed by the National Information Security Standardization Technical Committee, and the main drafting units include Shanghai Geer Software Co., Ltd., Beijing Digital Certification Center and many other companies and research institutions.
The SM2 cryptographic algorithm is an elliptic curve public key cryptographic algorithm with high security and efficiency, and is widely used in electronic signatures, data encryption and other fields. The purpose of this standard is to unify the message syntax format based on the SM2 algorithm to ensure interoperability between different systems.
2. Comparison of standard frameworks
| Key modules | Functional description | Main features |
|---|---|---|
| Signature data type (signedData) | Supports signatures of any type of data and allows multiple signers to sign. | Implements digital signatures based on the SM2 algorithm, providing high security. |
| The signature structure includes content summary, signature certificate chain and revocation list. | Complies with the PKCS standard extended syntax and supports flexible configuration. | |
| Digital envelope data type (envelopedData) | Encrypts and encapsulates sensitive data. | Combined with SM2 public key encryption technology, data privacy protection is achieved. |
| Supports key negotiation and encryption for multiple recipients. | Based on the elliptic curve encryption mechanism, ensure the secure transmission of keys. | |
| Digital envelopes can embed signature information to achieve the combination of signature and encryption. | Provide dual security: data integrity and confidentiality. | |
| Comparison: Compared with the traditional RSA algorithm, the signature and encryption functions implemented by the SM2 algorithm have significant advantages in security and computational efficiency. In particular, it reflects technical innovation in the selection of elliptic curve parameters and key negotiation mechanism. | ||
3. Practical application cases
Case: Application of SM2 algorithm in electronic signature system
An e-commerce platform adopts GB/T 35275-2017 standard to standardize its electronic contract signature process:
- After the user submits the order, the system generates JSON data containing the order details.
- The data is signed using the SM2 private key and a signature certificate chain is generated.
- The signed data is encapsulated in the message syntax format of the signedData type.
- The signature data is transmitted to a third-party custodian through the HTTPS protocol.
Key points:In this case, the digital signature function of the SM2 algorithm ensures the integrity and immutability of the electronic contract. At the same time, the certificate management mechanism in the standard is followed to ensure the authenticity of the signature.
4. Implementation Advice
4.1 System Integration Advice
- Ensure that the underlying layer supports elliptic curve operations of the SM2 algorithm.
- Use the object identifier (OID) defined in the standard for certificate and key management.
- Implement the encapsulation and parsing functions of core data types such as signedData and envelopedData.
4.2 Security Advice
- Update the SM2 key pair regularly to avoid using the same private key for a long time.
- Configure the Certificate Revocation List (CRL) or Online Certificate Status Protocol (OCSP) to prevent the abuse of revoked certificates.
- Embed the shared information field in the digital envelope to enhance the security of data transmission.
4.3 Recommended development tools
- OpenSSL: An open source encryption library that supports the SM2 algorithm.
- Bouncy Castle: An advanced encryption function implementation library on the Java platform.
- National Encryption GMT-SM2: A development kit optimized for national encryption standards.
5. Analysis of standard technology evolution
From the perspective of technological development, GB/T 35275—2017 embodies important innovations in the following aspects:
- Algorithm optimization: Compared with RSA, the SM2 algorithm has a shorter key length and higher computational efficiency at the same security strength.
- Protocol compatibility: Complies with the international PKCS standard extended syntax and supports seamless integration with the existing CA certification system.
- Application scenario expansion: Extended from traditional digital signatures to mobile payments, IoT devices and other fields, demonstrating wide applicability.

Loading PDF document...
Error loading PDF. Please make sure the file is valid and try again.
We also recommend
-

GB/Z 24294.1-2018 in English
Information security technology—Guide of implementation for internet-basede-government information security—Part 1:General
2018-03-15 -

GB/T 20979-2019 in English
Information security technology—Technical requirements for iris recognition system
2019-08-30 -

GB/T 45240-2025 in English
General requirements for device-independent quantum random number generators
2025-01-24 -

GB/T 27422-2019 in English
Conformity assessment -- Requirements for bodies providing audit and certification of business continuity management systems
2019-12-10 -

GB/T 45409-2025 in English
Cybersecurity technology—Technical specifications for operation and maintenance security management products
2025-03-28 -

GB/T 15278-1994 in English
Information processing-Data encipherment-Physical layer interoperability requirements
1994-01-02 -

GB/T 15843.1-2017 in English
Information technology―Security techniques―Entity authentication―Part 1:General
2017-12-29 -

GB/T 24363-2009 in English
Information security technology—Specifications of emergency response plan for information security
2009-09-30 -

GB/T 37931-2019 in English
Information security technology—Security technology requirements and testing and evaluation approaches for Web application security detection system
2019-08-30 -

GB/T 20009-2019 in English
Information security technology—Security evaluation criteria for database management system
2019-08-30