GB/T 36644-2018 in English
VALIDInformation security technology—Methods for obtaining security attestations for digital signature applications
- Issued on:2018-09-17
- Implemented on:2019-04-01
- File Format:PDF
- Delivery:Via email within 5 business days
$388.00
《GB/T 36644-2018信息安全技术 数字签名应用安全证明获取方法》由TC260(全国网络安全标准化技术委员会)归口,主管部门为国家标准化管理委员会。
Introduction
Analysis of the core content of the standard
This standard builds a complete digital signature security proof system framework, covering the three core modules of private key ownership attributes, public key validity and signature time proof. The technical route is compatible with the international standard NIST SP 800-89/102, and is adapted to my country's cryptographic algorithm specifications.
Private Key Possession Attribute Proof Model
| Time Model | Key Parameters | Proof Level Change | Applicable Scenarios |
|---|---|---|---|
| Proof Time Determination | tA,a,b,c | High→Medium→Low Gradient Attenuation | Precise Time Source Scenarios |
| Proof Time Uncertainty | t1,t2,d | Dynamic Credibility Assessment | Scenarios with Large Network Latency |
Typical application:In the electronic contract signing scenario, the TTSA timestamp is used to determine the certification time tA, and a=1h, b=24h, and c=7d are set to ensure that a high level of security certification is maintained within 24 hours after the contract is signed.
Public key validity verification process
According to Appendix A of the standard, the SM2 algorithm public key verification must be strictly implemented:
- Elliptic curve parameter verification (GB/T 32918.1)
- Public key point coordinate validity check
- Base point multiplication operation verification
Notes:When using TTP escrow keys, the security strength of the escrow agreement must be additionally verified.
Comparison of Time Proof Acquisition Solutions
| Solution Type | Accuracy | Relying Party | Typical Latency |
|---|---|---|---|
| TTSA Single Timestamp | Seconds | Two-way Trust | 500ms-2s |
| Dual Timestamp | Milliseconds | Multi-TTSA Collaboration | 1-5s |
| Nonce Verification | Minutes | One-way Trust | Real-time |
Implementation Recommendations
1. Key management: Give priority to the proof signature method of standard 5.2.3.2 to avoid performance loss caused by key regeneration
2. Time source selection: Financial-level applications are recommended to deploy the Trusted Timestamp Service that complies with GB/T 20520
3. Parameter configuration: Dynamically adjust the time model parameters according to business security requirements:
- Highly sensitive scenarios: a≥4h, b≥48h, c≤3d
- General scenarios: a≥1h, b≥24h, c≤7d

Loading PDF document...
Error loading PDF. Please make sure the file is valid and try again.
We also recommend
-

GB/T 22186-2016 in English
Information security techniques―Security technical requirements for IC card chip with CPU
2016-08-29 -

GB/T 45240-2025 in English
General requirements for device-independent quantum random number generators
2025-01-24 -

GB/T 17901.1-2020 in English
Information technology—Security techniques—Key management—Part 1: Framework
2020-03-06 -

GB/Z 24294.1-2018 in English
Information security technology—Guide of implementation for internet-basede-government information security—Part 1:General
2018-03-15 -

GB/T 37931-2019 in English
Information security technology—Security technology requirements and testing and evaluation approaches for Web application security detection system
2019-08-30 -

GB/T 15278-1994 in English
Information processing-Data encipherment-Physical layer interoperability requirements
1994-01-02 -

GB/T 20518-2018 in English
Information security technology—Public key infrastructure—Digital certificate format
2018-06-07 -

GB/T 27422-2019 in English
Conformity assessment -- Requirements for bodies providing audit and certification of business continuity management systems
2019-12-10