Sign In |Help & Support
ALL SECTORS
  • ALL SECTORS
  • GB(National Standard)
  • CB(Shipping)
  • CECS(Engineering Construction)
  • CJ(Urban Construction)
  • CY(News and Publication)
  • DB(Provincial Standard)
  • DL(Electricity & Power)
  • DZ(Geology & Mineralogy)
  • FZ(Spinning & Textile)
  • GA(Public Security)
  • HB(Aviation)
  • HG(Chemical Industry)
  • HJ(Environmental Protection)
  • JB(Machinery)
  • JC(Building Materials)
  • JG(Building & Construction)
  • JJ(Metering)
  • JT(Highway & Transportation)
  • LY(Forestry)
  • MT(Coal)
  • NB(Energy)
  • NY(Agriculture)
  • QB(Light Industry)
  • QC(Automobile & Vehicle)
  • QJ(Aerospace)
  • SH(Petrochemical)
  • SJ(Electronics)
  • SL(Water Resources)
  • SN(Commodity Inspection)
  • SY(Oil & Gas)
  • TB(Railway & Train)
  • YB(Ferrous Metallurgy)
  • YC(Tobacco)
  • YD(Telecommunication)
  • YY(Medical Device)
Database: 365,228(8 Aug 2026)
% aluminium phosphide oil port non-diaphragm electrolyzer
GB/T 36968-2018 in English

GB/T 36968-2018 in English

VALID

Information security technology—Technical specification for IPSec VPN

  • Issued on:2018-12-28
  • Implemented on:2019-07-01
  • File Format:PDF
  • Delivery:Via email within 5 business days
Price(USD): $690.00
$670.00
Standard No: GB/T 36968-2018
Document status: VALID
Title in English: Information security technology—Technical specification for IPSec VPN
Title in Chinese: 信息安全技术 IPSec VPN技术规范
Language: English
File Format: Electronic (PDF)
Delivery: Via email within 5 business days
Issued on: 2018-12-28
Implemented on: 2019-07-01
ICS Classification: 35.040-Character sets and information coding
Chinese Classification: L80-Data encryption
Professional Classification: GB-National Standard
Related Topics: Holographic technology
Holographic technology
Information security technology ipsec-based ip storage network security technical requirements
ipsec+vpn technical specification+
GBT36968
GB/T 36968-2018
Safety Technical Specification Arbutin
Full text of technical specifications made public
gb/t 36968-2018

《GB/T 36968-2018信息安全技术 IPSec VPN技术规范》由TC260(全国网络安全标准化技术委员会)归口,主管部门为国家标准化管理委员会。


Introduction

Analysis of the Standard Core Framework

Technical Modules Core Requirements Support for National Encryption Algorithms
Cryptographic Algorithms Must Support SM2/SM3/SM4 Algorithm Suites Mandatory Default Configuration
Key Exchange Two-Phase Negotiation (Main Mode + Quick Mode) SM2 is used for digital envelope
Message Encapsulation Nested Use of AH and ESP SM4-CBC Encryption Mode

Cryptographic algorithm configuration specification

Chapter 5 of the standard clearly stipulates:

  • Asymmetric algorithm: The SM2 elliptic curve algorithm is mandatory for entity authentication and digital signature (in accordance with GB/T 32918)
  • Symmetric algorithm: The SM4 block cipher (CBC mode) with a key length of 128 bits must be supported (in accordance with GB/T 32907)
  • Hash algorithm: The SM3 algorithm is used for integrity verification (in accordance with GB/T 32905)

Typical configuration example

A government VPN device uses the following algorithm combination:

Phase 1: SM2 signature + SM4 encryption working key second stage: SM4 session key (1428-byte frame encryption and decryption throughput ≥ 1Gbps) 

Security Association Establishment Process

Phase Number of messages Key operations
Main mode 6 messages Certificate authentication, working key generation
Quick mode 3 messages Session key derivation, SPI negotiation

Special note: NAT traversal must comply with RFC 3947 specifications and is implemented in UDP 4500 port implements ESP encapsulation


Key indicators for product testing

  • Functional testing: Random number generation must pass the 16 tests of GB/T 32915
  • Performance parameters:
    • Encryption and decryption delay: 1428-byte frame ≤200μs
    • Key update cycle: working key ≤24h, session key ≤1h
  • Security management: Device keys must be stored in hardware cryptographic modules

Implementation suggestions

  1. Preferably adopt tunnel mode deployment to ensure internal IP header encryption
  2. Gateway devices should be configured with an anti-replay window (64 bits by default)
  3. Log records must include SA lifecycle events and abnormal decryption records

Sample only — not a preview of GB/T 36968-2018
Page: 1 / 0
100%

Loading PDF document...

Error loading PDF. Please make sure the file is valid and try again.

We also recommend