Sign In |Help & Support
ALL SECTORS
  • ALL SECTORS
  • GB(National Standard)
  • CB(Shipping)
  • CECS(Engineering Construction)
  • CJ(Urban Construction)
  • CY(News and Publication)
  • DB(Provincial Standard)
  • DL(Electricity & Power)
  • DZ(Geology & Mineralogy)
  • FZ(Spinning & Textile)
  • GA(Public Security)
  • HB(Aviation)
  • HG(Chemical Industry)
  • HJ(Environmental Protection)
  • JB(Machinery)
  • JC(Building Materials)
  • JG(Building & Construction)
  • JJ(Metering)
  • JT(Highway & Transportation)
  • LY(Forestry)
  • MT(Coal)
  • NB(Energy)
  • NY(Agriculture)
  • QB(Light Industry)
  • QC(Automobile & Vehicle)
  • QJ(Aerospace)
  • SH(Petrochemical)
  • SJ(Electronics)
  • SL(Water Resources)
  • SN(Commodity Inspection)
  • SY(Oil & Gas)
  • TB(Railway & Train)
  • YB(Ferrous Metallurgy)
  • YC(Tobacco)
  • YD(Telecommunication)
  • YY(Medical Device)
Database: 365,228(8 Aug 2026)
quality plan their accessories scopethis standard reproduction/fertility effects
GB/T 35281-2017 in English

GB/T 35281-2017 in English

VALID

Information security technology—Security technique requirements for application servers in mobile internet

  • Issued on:2017-12-29
  • Implemented on:2018-07-01
  • File Format:PDF
  • Delivery:Via email within 1~3 business days
Price(USD): $220.00
$214.00
Standard No: GB/T 35281-2017
Document status: VALID
Title in English: Information security technology—Security technique requirements for application servers in mobile internet
Title in Chinese: 信息安全技术 移动互联网应用服务器安全技术要求
Language: English
File Format: Electronic (PDF)
Delivery: Via email within 1~3 business days
Issued on: 2017-12-29
Implemented on: 2018-07-01
ICS Classification: 35.040-Character sets and information coding
Professional Classification: GB-National Standard
Related Topics: "Information Security Technology Web Application Security Scanning Product Security Technical Requirements"
Security Requirements for Mobile Devices
Information Security Technology Mobile Internet Application Server Security Technical Requirements
mobile internet technology
Information security technology web application security scanning product security technical requirements
The Ten Commandments of Mobile Security
Mobile Internet Application Server Security
GBT35281
GB/T 35281-2017
Data Security Technical Requirements for Internet of Vehicles Information Service
Mobile Internet Security Audit
Provisions on the Administration of Mobile Internet Application Information Services
Information technology service service security requirements GB/T 39770-2021
Sterilization technology + Internet
Security protection technical requirements for power distribution Internet of Things applications
GB/T 39770-2021 Information technology service security requirements
Telecom network and Internet application program interface data security technical requirements and testing methods
Safety technical requirements for the use of sulfuric acid

《GB/T 35281-2017信息安全技术 移动互联网应用服务器安全技术要求》由TC260(全国网络安全标准化技术委员会)归口,主管部门为国家标准化管理委员会。


Introduction

Interpretation of the National Standard of the People's Republic of China GB/T 35281—2017

Core Framework of Security Technical Requirements for Mobile Internet Application Servers

Dimensions Key Requirements Implementation Focus
Data Security User Data Integrity, Confidentiality and Anonymization Encrypted Storage, Regular Backup, Principle of Least Privileges
Business Security Security Specifications for Payment, Push, Advertising and Instant Messaging Prevent SQL Injection and XSS Attacks, and Ensure Encrypted Transmission of Payment Information
System Security Security configuration of operating system, middleware and database Update patches in time, close non-essential ports, and strengthen access control

Implementation suggestions and best practices

1. Three-layer protection strategy for data security:

  • At the storage level: Use encryption algorithms to protect sensitive data, such as AES-256.
  • At the transmission level: Ensure the security of data in the network through the HTTPS protocol.
  • At the processing level: Adopt the principle of minimization and only process necessary user information.

2. Multi-dimensional guarantee of business security:

  • Payment business: Follow the JR/T0095-2012 standard to ensure that payment information is not leaked or abused.
  • Ad push: Review the security of third-party links to avoid malicious website targeting.
  • Instant messaging: Real-time security scanning of files and messages to prevent the spread of malicious code.

3. Layered protection of system security:

  • Operating system level: Disable non-essential accounts and services, and strengthen access control policies.
  • Middleware level: Regularly update software versions, close default components and ports.
  • Database level: Limit database access rights to prevent unauthorized queries.

Sample only — not a preview of GB/T 35281-2017
Page: 1 / 0
100%

Loading PDF document...

Error loading PDF. Please make sure the file is valid and try again.