Sign In |Help & Support
ALL SECTORS
  • ALL SECTORS
  • GB(National Standard)
  • CB(Shipping)
  • CECS(Engineering Construction)
  • CJ(Urban Construction)
  • CY(News and Publication)
  • DB(Provincial Standard)
  • DL(Electricity & Power)
  • DZ(Geology & Mineralogy)
  • FZ(Spinning & Textile)
  • GA(Public Security)
  • HB(Aviation)
  • HG(Chemical Industry)
  • HJ(Environmental Protection)
  • JB(Machinery)
  • JC(Building Materials)
  • JG(Building & Construction)
  • JJ(Metering)
  • JT(Highway & Transportation)
  • LY(Forestry)
  • MT(Coal)
  • NB(Energy)
  • NY(Agriculture)
  • QB(Light Industry)
  • QC(Automobile & Vehicle)
  • QJ(Aerospace)
  • SH(Petrochemical)
  • SJ(Electronics)
  • SL(Water Resources)
  • SN(Commodity Inspection)
  • SY(Oil & Gas)
  • TB(Railway & Train)
  • YB(Ferrous Metallurgy)
  • YC(Tobacco)
  • YD(Telecommunication)
  • YY(Medical Device)
Database: 365,228(8 Aug 2026)
complete digital signature security proof system framework signature time proof digital signature applications introduction analysis information security technology methods proof signature method crab net enclosure culture control points drm system integration engineering purposes measurement
GB/T 36644-2018 in English

GB/T 36644-2018 in English

VALID

Information security technology—Methods for obtaining security attestations for digital signature applications

  • Issued on:2018-09-17
  • Implemented on:2019-04-01
  • File Format:PDF
  • Delivery:Via email within 5 business days
Price(USD): $400.00
$388.00
Standard No: GB/T 36644-2018
Document status: VALID
Title in English: Information security technology—Methods for obtaining security attestations for digital signature applications
Title in Chinese: 信息安全技术 数字签名应用安全证明获取方法
Language: English
File Format: Electronic (PDF)
Delivery: Via email within 5 business days
Issued on: 2018-09-17
Implemented on: 2019-04-01
ICS Classification: 35.040-Character sets and information coding
Chinese Classification: L80-Data encryption
Professional Classification: GB-National Standard
Related Keywords: complete digital signature security proof system framework
signature time proof
digital signature applications introduction analysis
information security technology methods
proof signature method
Related Topics: Information access technology does not include
digital signature
Technical Application Proof
Information acquisition techniques include
Equipment Safety Certificate
Information Access Technology
What technology does information access technology not include
Proof of application
Proof of Technology Use
GBT36644
GB/T 36644-2018
How to obtain junction temperature

《GB/T 36644-2018信息安全技术 数字签名应用安全证明获取方法》由TC260(全国网络安全标准化技术委员会)归口,主管部门为国家标准化管理委员会。


Introduction

Analysis of the core content of the standard

This standard builds a complete digital signature security proof system framework, covering the three core modules of private key ownership attributes, public key validity and signature time proof. The technical route is compatible with the international standard NIST SP 800-89/102, and is adapted to my country's cryptographic algorithm specifications.


Private Key Possession Attribute Proof Model

Time Model Key Parameters Proof Level Change Applicable Scenarios
Proof Time Determination tA,a,b,c High→Medium→Low Gradient Attenuation Precise Time Source Scenarios
Proof Time Uncertainty t1,t2,d Dynamic Credibility Assessment Scenarios with Large Network Latency

Typical application:In the electronic contract signing scenario, the TTSA timestamp is used to determine the certification time tA, and a=1h, b=24h, and c=7d are set to ensure that a high level of security certification is maintained within 24 hours after the contract is signed.


Public key validity verification process

According to Appendix A of the standard, the SM2 algorithm public key verification must be strictly implemented:

  1. Elliptic curve parameter verification (GB/T 32918.1)
  2. Public key point coordinate validity check
  3. Base point multiplication operation verification

Notes:When using TTP escrow keys, the security strength of the escrow agreement must be additionally verified.


Comparison of Time Proof Acquisition Solutions

Solution Type Accuracy Relying Party Typical Latency
TTSA Single Timestamp Seconds Two-way Trust 500ms-2s
Dual Timestamp Milliseconds Multi-TTSA Collaboration 1-5s
Nonce Verification Minutes One-way Trust Real-time

Implementation Recommendations

1. Key management: Give priority to the proof signature method of standard 5.2.3.2 to avoid performance loss caused by key regeneration

2. Time source selection: Financial-level applications are recommended to deploy the Trusted Timestamp Service that complies with GB/T 20520

3. Parameter configuration: Dynamically adjust the time model parameters according to business security requirements:

  • Highly sensitive scenarios: a≥4h, b≥48h, c≤3d
  • General scenarios: a≥1h, b≥24h, c≤7d

Sample only — not a preview of GB/T 36644-2018
Page: 1 / 0
100%

Loading PDF document...

Error loading PDF. Please make sure the file is valid and try again.

We also recommend

  • GB/T 22186-2016 in English

    GB/T 22186-2016 in English

    Information security techniques―Security technical requirements for IC card chip with CPU

    2016-08-29
  • GB/T 45240-2025 in English

    GB/T 45240-2025 in English

    General requirements for device-independent quantum random number generators

    2025-01-24
  • GB/T 17901.1-2020 in English

    GB/T 17901.1-2020 in English

    Information technology—Security techniques—Key management—Part 1: Framework

    2020-03-06
  • GB/Z 24294.1-2018 in English

    GB/Z 24294.1-2018 in English

    Information security technology—Guide of implementation for internet-basede-government information security—Part 1:General

    2018-03-15
  • GB/T 37931-2019 in English

    GB/T 37931-2019 in English

    Information security technology—Security technology requirements and testing and evaluation approaches for Web application security detection system

    2019-08-30
  • GB/T 15278-1994 in English

    GB/T 15278-1994 in English

    Information processing-Data encipherment-Physical layer interoperability requirements

    1994-01-02
  • GB/T 20518-2018 in English

    GB/T 20518-2018 in English

    Information security technology—Public key infrastructure—Digital certificate format

    2018-06-07
  • GB/T 27422-2019 in English

    GB/T 27422-2019 in English

    Conformity assessment -- Requirements for bodies providing audit and certification of business continuity management systems

    2019-12-10