GB/T 35287-2017 in English
VALIDInformation security technology—Guidelines of trusted identity technology for website
- Issued on:2017-12-29
- Implemented on:2018-07-01
- File Format:PDF
- Delivery:Via email within 5 business days
$359.00
| Standard No: | GB/T 35287-2017 |
| Document status: | VALID |
| Title in English: | Information security technology—Guidelines of trusted identity technology for website |
| Title in Chinese: | 信息安全技术 网站可信标识技术指南 |
| Language: | English |
| File Format: | Electronic (PDF) |
| Delivery: | Via email within 5 business days |
| Issued on: | 2017-12-29 |
| Implemented on: | 2018-07-01 |
| ICS Classification: | 35.040-Character sets and information coding |
| Chinese Classification: | L80-Data encryption |
| Professional Classification: | GB-National Standard |
| Related Topics: | beacon technology
beacon technology technology website Measurement Specifications Guideline credibility Technical standard identification Agent technical index iso indicator technique GBT35287 GB/T 35287-2017 AFG3102C technical specifications jb/zq4224 Industrial Standard Network Information NexION2000G ICPMS technical specifications Encore information |
《GB/T 35287-2017信息安全技术 网站可信标识技术指南》由TC260(全国网络安全标准化技术委员会)归口,主管部门为国家标准化管理委员会。
Introduction
Core Interpretation of Website Trusted Identification Technology Standard
GB/T 35287-2017 is my country's first national standard for website trusted identification technology, which builds a complete identity authentication system based on the SM2/SM3 domestic cryptographic algorithm. The standard defines a three-party framework including Identification Authority (IA), websites and Trusted Applications.
Trusted Identity Technical Architecture
| Components | Functions | Key Technologies |
|---|---|---|
| Identification Authority | Issuance/Management of Trusted Identity | SM2 Digital Signature |
| Website | Deployment of Identity File | Base64 Encoding |
| Trusted Application | Verification/Display of Identity | ASN.1 Parsing |
Typical Application Scenario
After a bank website applies for a trusted identity from an identification authority, it deploys the identity file in the root directory. When users access the system through a browser, the system automatically verifies the validity of the identification and displays the certified bank name and official website information, effectively preventing phishing websites.
The entire life cycle of identity management
- Application phase: The website submits qualification materials such as domain name/IP
- Generation phase: IA uses SM2 private key signature to generate ASN.1 DER encoded file
- Deployment phase: The website places the identity file in the root directory (such as site_trust_id.txt)
- Verification phase: The trusted application confirms the validity of the identity through 6 verification steps
Key technology implementation
1. Data format specification
| Field | Type | Example |
|---|---|---|
| SiteDomains | UTF8String sequence | *.abc.com |
| SignatureAlgorithm | OID | 1.2.156.10197.1.501 |
| Validity | UTCTime/GeneralizedTime | 20230704-20240704 |
2. Revocation Mechanism
It adopts the dual mechanisms of Identifier Revocation List (IRL) and real-time query, supports two publishing modes: full IRL and incremental IRL, and ensures timely synchronization of revocation status.
Recommendations for the implementation of the standard
- Identification authority: It must be certified by the State Cryptography Administration, and key management must comply with GM/T 0003 requirements
- Website deployment: It is recommended to use the HTTPS protocol to transmit identification files to prevent tampering by middlemen
- Application development: The verification module should support the SM2/SM3 algorithm suite and ASN.1 DER decoding
Technology evolution analysis
The standard innovatively combines the PKI system with website identification. Compared with the internationally used EV SSL certificate, it has the following advantages:
- The use of domestic cryptographic algorithms ensures independent control
- Lightweight deployment does not require modification of server configuration
- Support for domain name wildcards and IP segment verification

Loading PDF document...
Error loading PDF. Please make sure the file is valid and try again.
We also recommend
-

GB/T 45240-2025 in English
General requirements for device-independent quantum random number generators
2025-01-24 -

GB/T 15278-1994 in English
Information processing-Data encipherment-Physical layer interoperability requirements
1994-01-02 -

GB/T 39276-2020 in English
Information security technology—General security requirements of network products and services
2020-11-19 -

GB/Z 24294.1-2018 in English
Information security technology—Guide of implementation for internet-basede-government information security—Part 1:General
2018-03-15 -

GB/T 24363-2009 in English
Information security technology—Specifications of emergency response plan for information security
2009-09-30 -

GB/T 20009-2019 in English
Information security technology—Security evaluation criteria for database management system
2019-08-30