GB/T 35278-2017 in English
VALIDInformation security technology―Technical requirements for mobile terminal security protection
- Issued on:2017-12-29
- Implemented on:2018-07-01
- File Format:PDF
- Delivery:Via email within 5 business days
$418.00
《GB/T 35278-2017信息安全技术 移动终端安全保护技术要求》由TC260(全国网络安全标准化技术委员会)归口,主管部门为国家标准化管理委员会。
Introduction
Standard Overview and Technical Background
As an important specification in the field of mobile Internet security, this standard is based on the GB/T 18336 evaluation criteria framework and builds a complete technical system including security objectives, functional requirements and assurance requirements for five typical threats faced by mobile smart terminals, such as data theft and malware. The standard was formulated by the Ministry of Industry and Information Technology's Telecommunication Research Institute and reflects the cutting-edge security technology requirements in 2017.
Analysis of core security function requirements
| Functional category | Key requirements | Technical implementation |
|---|---|---|
| Cryptographic support (FCS) | Key full life cycle management | Requires hardware-protected REK key system, DEK/KEK layered encrypted storage, in compliance with national encryption algorithm standards |
| User Data Protection (FDP) | Static data encryption | Mandatory full disk encryption, support for 4 secure transmission protocols such as IPSec/TLS |
| Security Audit (FAU) | Event Recording and Protection | 18 types of security events need to be recorded, and an overwriting or blocking strategy will be adopted when the audit storage is full |
Key Technical Innovations
1. Trusted Communication Mechanism
Article 7.9 of the standard requires the establishment of a trusted channel based on TLS 1.2/IPSec, which is implemented in a wireless network environment:
- Two-way certificate authentication (FIA_X509_EXT series)
- End-to-end encryption (FCS_TLSC_EXT.2)
- Anti-man-in-the-middle attacks (FTP_ITC_EXT.1)
2. Defense in Depth
Multi-level protection is used to deal with the risk of physical loss:
- Hardware level: Anti-chip debugging interface (FPT_KST_EXT.3)
- System level: ASLR memory protection (FPT_AEX_EXT.1)
- Application level: Sandbox isolation (FDP_ACF_EXT.1)
Implementation recommendations
Key points for development compliance
Referring to the security requirements in Chapter 8, it is recommended to adopt:
- Secure development lifecycle (ALC_TSU_EXT)
- Third-party component security management (ALC_CMS.2)
- Vulnerability response mechanism (AVA_VAN.1)
Typical application scenarios
The key points for government mobile office terminals are:
- FDP_DAR_EXT.1 Full Disk Encryption
- FIA_PMG_EXT.1 Six-digit Complex Password
- FMT_SMF_EXT.1 Application Whitelist Control
Technology Evolution Comparison
| Version | Security Requirements | New Content |
|---|---|---|
| YD/T 2407-2013 | Basic Capability Requirements | Missing Key Management System |
| GB/T 35278-2017 | Full Lifecycle Protection | Added FCS_CKM_EXT key chain specification |
| Level 2.0 Security Protection | Extended Control Items | Integrated FPT_TUD Trusted Update |

Loading PDF document...
Error loading PDF. Please make sure the file is valid and try again.
We also recommend
-

GB/T 15278-1994 in English
Information processing-Data encipherment-Physical layer interoperability requirements
1994-01-02 -

GB/T 45240-2025 in English
General requirements for device-independent quantum random number generators
2025-01-24 -

GB/T 20009-2019 in English
Information security technology—Security evaluation criteria for database management system
2019-08-30 -

GB/T 25056-2018 in English
Information security technology—Specifications of cryptograph and related security technology for certificate authentication system
2018-06-07 -

GB/T 20261-2020 in English
Information security technology—System security engineering—Capability maturity model
2020-11-19 -

GB/T 24363-2009 in English
Information security technology—Specifications of emergency response plan for information security
2009-09-30 -

GB/T 37931-2019 in English
Information security technology—Security technology requirements and testing and evaluation approaches for Web application security detection system
2019-08-30 -

GB/T 17901.1-2020 in English
Information technology—Security techniques—Key management—Part 1: Framework
2020-03-06 -

GB/T 40018-2021 in English
Information security technology—Certificate request and application protocol based on multiple channels
2021-04-30 -

GB/T 36323-2018 in English
Information security technology--Security management fundamental requirements for industrial control systems
2018-06-07