GB/T 38646-2020 in English
VALIDInformation security technology—Technical requirements of mobile signature service
- Issued on:2020-04-28
- Implemented on:2020-11-01
- File Format:PDF
- Delivery:Via email within 1~3 business days
$243.00
| Standard No: | GB/T 38646-2020 |
| Document status: | VALID |
| Title in English: | Information security technology—Technical requirements of mobile signature service |
| Title in Chinese: | 信息安全技术 移动签名服务技术要求 |
| Language: | English |
| File Format: | Electronic (PDF) |
| Delivery: | Via email within 1~3 business days |
| Issued on: | 2020-04-28 |
| Implemented on: | 2020-11-01 |
| ICS Classification: | 35.040-Character sets and information coding |
| Chinese Classification: | L80-Data encryption |
| Professional Classification: | GB-National Standard |
| Related Topics: | technical standard
german mobile technology Information Security Technology Mobile Internet Application Server Security Technical Requirements Technical English Technical English sign sign China Mobile Information Technology GBT38646 GB/T 38646-2020 technology Information technology service service security requirements GB/T 39770-2021 GB/T 39770-2021 Information technology service security requirements information security |
《GB/T 38646-2020信息安全技术 移动签名服务技术要求》由TC260(全国网络安全标准化技术委员会)归口,主管部门为国家标准化管理委员会。
Introduction
Interpretation of the core content of the standard
This standard defines an electronic signature technology system based on the Mobile Signature Device (MSD), and realizes secure signature services in a mobile environment through the collaboration of five entities (users, MSD, application providers, CA certification authorities, and mobile signature service platforms).
Technical Framework Comparison
| Dimensions | Traditional Signature | Mobile Signature |
|---|---|---|
| Hardware Dependence | Dedicated USB Key | Mobile phone/tablet built-in MSD module |
| Certificate Management | Single Business Single Certificate | Coexistence of Multiple Business Certificates (≤5 CA Institutions) |
| Signature Process | Client installation required | No client dependency (Chapter 6.1 of the standard) |
Analysis of key processes
1. Certificate lifecycle management
Chapter 6.2 of the standard specifies the complete certificate management process:
- Application phase: Double identity authentication must be completed (offline branch review + authorization code)
- Update mechanism: Supports CA active triggering (validity warning) and MSSP passive request
- Revocation scenarios: Covers three categories: user active, AP business abnormality, and MSSP security policy
2. Signature security protection
Chapter 9 of the standard requires:
MSD module must implement:
- PIN code/biometric verification (≤5 incorrect attempts)
- Keys do not leave the domain (in compliance with GM/T 0028-2014)
- What you see is what you sign (anti-interface hijacking)
Implementation suggestions
Development precautions
| Components | Compliance points |
|---|---|
| MSSP platform | It is necessary to deploy the national secret SM4 encryption machine to process the key, and the audit log is retained for ≥6 months |
| MSD module | PIN code needs to be stored using the PBKDF2 algorithm, and the signature response time is ≤500ms |
Typical application scenarios
Financial transaction scenario: After a bank APP integrates mobile signature service:
- Large amount transfers complete secondary verification through MSD
- Certificate renewal rate increased by 40% (standard 6.2.3 process optimization)
- Transaction dispute rate decreased by 62%

Loading PDF document...
Error loading PDF. Please make sure the file is valid and try again.
We also recommend
-

GB/T 15278-1994 in English
Information processing-Data encipherment-Physical layer interoperability requirements
1994-01-02 -

GB/Z 24294.1-2018 in English
Information security technology—Guide of implementation for internet-basede-government information security—Part 1:General
2018-03-15 -

GB/T 45240-2025 in English
General requirements for device-independent quantum random number generators
2025-01-24 -

GB/T 20518-2018 in English
Information security technology—Public key infrastructure—Digital certificate format
2018-06-07 -

GB/T 25056-2018 in English
Information security technology—Specifications of cryptograph and related security technology for certificate authentication system
2018-06-07 -

GB/T 15843.1-2017 in English
Information technology―Security techniques―Entity authentication―Part 1:General
2017-12-29 -

GB/T 29767-2013 in English
Information security techniques—Public key infrastructure—Bridge Certification Authority leveled certificate specification
2013-09-18 -

GB/T 29241-2012 in English
Information security technology—Public key infrastructure—PKI interoperability evaluation criteria
2012-12-31