GB/T 36639-2018 in English
VALIDInformation security technology—Trusted computing specification—Trusted support platform for server
- Issued on:2018-09-17
- Implemented on:2019-04-01
- File Format:PDF
- Delivery:Via email within 1~3 business days
$243.00
| Standard No: | GB/T 36639-2018 |
| Document status: | VALID |
| Title in English: | Information security technology—Trusted computing specification—Trusted support platform for server |
| Title in Chinese: | 信息安全技术 可信计算规范 服务器可信支撑平台 |
| Language: | English |
| File Format: | Electronic (PDF) |
| Delivery: | Via email within 1~3 business days |
| Issued on: | 2018-09-17 |
| Implemented on: | 2019-04-01 |
| ICS Classification: | 35.040-Character sets and information coding |
| Chinese Classification: | L80-Data encryption |
| Professional Classification: | GB-National Standard |
| Related Topics: | Technical support platform
support platform support platform GB/T 36639-2018 GBT36639 GB/T 36639-2018 Platform level adjustment calculation Encore information |
《GB/T 36639-2018信息安全技术 可信计算规范 服务器可信支撑平台》由TC260(全国网络安全标准化技术委员会)归口,主管部门为国家标准化管理委员会。
Introduction
GB/T 36639—2018 Standard Overview
The National Standard of the People's Republic of China GB/T 36639—2018 "Information Security Technology Trusted Computing Specification Server Trusted Support Platform" is a standardized document formulated around the design, production, integration, management and testing of the server trusted support platform. This standard aims to build a secure environment under the trusted computing system and ensure the trust chain transmission of the server hardware system and operating system.
Comparison of Standard Core Frameworks
| Dimensions | Physical Root of Trust Requirements | Virtual Root of Trust Requirements | Trusted Infrastructure Component Requirements |
|---|---|---|---|
| Functional Requirements | Integrity Measurement, Secure Storage, and Reporting | Virtual Machine Integrity Measurement Starting Point | Physical Root of Trust Matching Function |
| Implementation Method | Hardware or Firmware Module | Software or Virtualization Environment Component | TCM Service Module, etc. |
| Application Scenarios | Non-virtualized Server System | Virtualized Server Environment | Bridge between Operating System and Hardware |
Standard Development Background and Technology Evolution Analysis
With the widespread application of cloud computing and virtualization technologies, the security threats faced by server systems are becoming increasingly complex. The formulation of the GB/T 36639-2018 standard fills an important gap in the field of trusted computing. By introducing the concepts of physical root of trust and virtual root of trust, it ensures the complete trust chain transmission from hardware to operating system.
Technology Evolution Analysis
- Extending from hardware trust chain to support virtualized environment
- Introducing virtual trusted components to adapt to cloud server requirements
- Implementing a cross-platform trusted migration mechanism
Implementation Recommendations and Best Practices
In actual applications, it is recommended to follow the following principles:
- Ensure the hardware compliance of the physical root of trust
- Prioritize the deployment of virtual trusted components in a virtualized environment
- Perform integrity measurement and remote attestation verification regularly
- Maintain the security of the virtual root of trust manager and keys

Loading PDF document...
Error loading PDF. Please make sure the file is valid and try again.
We also recommend
-

GB/T 22186-2016 in English
Information security techniques―Security technical requirements for IC card chip with CPU
2016-08-29 -

GB/T 45240-2025 in English
General requirements for device-independent quantum random number generators
2025-01-24 -

GB/T 27422-2019 in English
Conformity assessment -- Requirements for bodies providing audit and certification of business continuity management systems
2019-12-10 -

GB/Z 24294.1-2018 in English
Information security technology—Guide of implementation for internet-basede-government information security—Part 1:General
2018-03-15 -

GB/T 20261-2020 in English
Information security technology—System security engineering—Capability maturity model
2020-11-19 -

GB/T 36618-2018 in English
Information security technology—Specification for financial information service security
2018-09-17 -

GB/T 15278-1994 in English
Information processing-Data encipherment-Physical layer interoperability requirements
1994-01-02