GB/T 38644-2020 in English
VALIDInformation security technology—Trusted computing—Testing method of trusted connect
- Issued on:2020-04-28
- Implemented on:2020-11-01
- File Format:PDF
- Delivery:Via email within 5 business days
$359.00
《GB/T 38644-2020信息安全技术 可信计算 可信连接测试方法》由TC260(全国网络安全标准化技术委员会)归口,主管部门为国家标准化管理委员会。
Introduction
Interpretation of the core content of the standard
GB/T38644-2020, as a supporting test standard for GB/T29828-2013, has established a complete trusted connection test system. The standard innovatively adopts the ternary peer-to-peer architecture (TePA) as the technical basis, and ensures the security of trusted connections through the dual dimensions of protocol interaction mechanism testing and cryptographic algorithm verification.
Test Framework Comparison
| Test Dimensions | AR Device Test | AC Device Test | PM Device Test |
|---|---|---|---|
| Test Topology | AR+AC+PM Combination | AC+AR+PM Combination | PM+AC/AR Combination |
| Core Test Items | Port Status Control, Platform Integrity Verification | Access Decision Logic, Protocol Encapsulation | Certificate Verification, Policy Management |
| Typical Scenarios | Terminal Access Control | Border protection equipment | Centralized control platform |
Key technology implementation points
1. Port control test
Article 7.1 of the standard specifies in detail the three state transition mechanisms of the controlled port:
- Authorized state: the platform certificate is legal and the integrity complies with the policy
- Isolated state: the platform has repairable integrity anomalies
- Blocked state: the certificate is illegal or has irreparable integrity issues
2. Cryptographic algorithm verification
Chapter 8 explicitly requires the use of the national secret algorithm system:
- SM4 is used for data encryption (GB/T32907)
- SM2 is used for signature/key exchange (GB/T32918)
- SM3 is used for hash operation (GB/T32905)
Standard Evolution Analysis
Main improvements of this standard compared with GM/T0042-2015:
- Added Platform Integrity Assessment test process (Appendix A)
- Refine cryptographic algorithm performance test indicators (Appendix B)
- Clear mandatory use requirements for TCP/UDP port 5111
Implementation Suggestions
Note for enterprise deployment:
- The test equipment needs to support TAEPoL encapsulation (Ethernet type 0x891b)
- The cryptographic module should pass the commercial cryptographic testing and certification
- Integrity measurement value collection needs to cover key components such as BIOS and OS

Loading PDF document...
Error loading PDF. Please make sure the file is valid and try again.
We also recommend
-

GB/T 15278-1994 in English
Information processing-Data encipherment-Physical layer interoperability requirements
1994-01-02 -

GB/T 45240-2025 in English
General requirements for device-independent quantum random number generators
2025-01-24 -

GB/T 28449-2018 in English
Information security technology-Testing and evaluation process guide for classified protection of cybersecurity
2018-12-28 -

GB/T 25056-2018 in English
Information security technology—Specifications of cryptograph and related security technology for certificate authentication system
2018-06-07 -

GB/T 41266-2022 in English
Security testing methods for critical network devices—Switch
2022-03-09 -

GB/T 37931-2019 in English
Information security technology—Security technology requirements and testing and evaluation approaches for Web application security detection system
2019-08-30 -

GB/Z 24294.1-2018 in English
Information security technology—Guide of implementation for internet-basede-government information security—Part 1:General
2018-03-15 -

GB/T 36323-2018 in English
Information security technology--Security management fundamental requirements for industrial control systems
2018-06-07