GB/T 36968-2018 in English
VALIDInformation security technology—Technical specification for IPSec VPN
- Issued on:2018-12-28
- Implemented on:2019-07-01
- File Format:PDF
- Delivery:Via email within 5 business days
$670.00
| Standard No: | GB/T 36968-2018 |
| Document status: | VALID |
| Title in English: | Information security technology—Technical specification for IPSec VPN |
| Title in Chinese: | 信息安全技术 IPSec VPN技术规范 |
| Language: | English |
| File Format: | Electronic (PDF) |
| Delivery: | Via email within 5 business days |
| Issued on: | 2018-12-28 |
| Implemented on: | 2019-07-01 |
| ICS Classification: | 35.040-Character sets and information coding |
| Chinese Classification: | L80-Data encryption |
| Professional Classification: | GB-National Standard |
| Related Topics: | Holographic technology
Holographic technology Information security technology ipsec-based ip storage network security technical requirements ipsec+vpn technical specification+ GBT36968 GB/T 36968-2018 Safety Technical Specification Arbutin Full text of technical specifications made public gb/t 36968-2018 |
《GB/T 36968-2018信息安全技术 IPSec VPN技术规范》由TC260(全国网络安全标准化技术委员会)归口,主管部门为国家标准化管理委员会。
Introduction
Analysis of the Standard Core Framework
| Technical Modules | Core Requirements | Support for National Encryption Algorithms |
|---|---|---|
| Cryptographic Algorithms | Must Support SM2/SM3/SM4 Algorithm Suites | Mandatory Default Configuration |
| Key Exchange | Two-Phase Negotiation (Main Mode + Quick Mode) | SM2 is used for digital envelope |
| Message Encapsulation | Nested Use of AH and ESP | SM4-CBC Encryption Mode |
Cryptographic algorithm configuration specification
Chapter 5 of the standard clearly stipulates:
- Asymmetric algorithm: The SM2 elliptic curve algorithm is mandatory for entity authentication and digital signature (in accordance with GB/T 32918)
- Symmetric algorithm: The SM4 block cipher (CBC mode) with a key length of 128 bits must be supported (in accordance with GB/T 32907)
- Hash algorithm: The SM3 algorithm is used for integrity verification (in accordance with GB/T 32905)
Typical configuration example
A government VPN device uses the following algorithm combination:
Phase 1: SM2 signature + SM4 encryption working key second stage: SM4 session key (1428-byte frame encryption and decryption throughput ≥ 1Gbps)
Security Association Establishment Process
| Phase | Number of messages | Key operations |
|---|---|---|
| Main mode | 6 messages | Certificate authentication, working key generation |
| Quick mode | 3 messages | Session key derivation, SPI negotiation |
Special note: NAT traversal must comply with RFC 3947 specifications and is implemented in UDP 4500 port implements ESP encapsulation
Key indicators for product testing
- Functional testing: Random number generation must pass the 16 tests of GB/T 32915
- Performance parameters:
- Encryption and decryption delay: 1428-byte frame ≤200μs
- Key update cycle: working key ≤24h, session key ≤1h
- Security management: Device keys must be stored in hardware cryptographic modules
Implementation suggestions
- Preferably adopt tunnel mode deployment to ensure internal IP header encryption
- Gateway devices should be configured with an anti-replay window (64 bits by default)
- Log records must include SA lifecycle events and abnormal decryption records

Loading PDF document...
Error loading PDF. Please make sure the file is valid and try again.
We also recommend
-

GB/T 24363-2009 in English
Information security technology—Specifications of emergency response plan for information security
2009-09-30 -

GB/T 20009-2019 in English
Information security technology—Security evaluation criteria for database management system
2019-08-30 -

GB/T 17901.1-2020 in English
Information technology—Security techniques—Key management—Part 1: Framework
2020-03-06 -

GB/T 45240-2025 in English
General requirements for device-independent quantum random number generators
2025-01-24 -

GB/T 27422-2019 in English
Conformity assessment -- Requirements for bodies providing audit and certification of business continuity management systems
2019-12-10 -

GB/T 32905-2016 in English
Information security technology SM3 cryptographic hash algorithm
2016-08-29 -

GB/T 15278-1994 in English
Information processing-Data encipherment-Physical layer interoperability requirements
1994-01-02 -

GB/T 41266-2022 in English
Security testing methods for critical network devices—Switch
2022-03-09 -

GB/Z 29830.2-2013 in English
Information Technology - Security Technology - A Framework for IT Security Assurance - Part 2: Assurance Methods
2013-11-12 -

GB/T 36323-2018 in English
Information security technology--Security management fundamental requirements for industrial control systems
2018-06-07