GB/T 39575-2020 in English
VALIDTechnical requirements for security capability of mobile terminal with syncretic function
- Issued on:2020-12-14
- Implemented on:2021-07-01
- File Format:PDF
- Delivery:Via email within 1~3 business days
$214.00
| Standard No: | GB/T 39575-2020 |
| Document status: | VALID |
| Title in English: | Technical requirements for security capability of mobile terminal with syncretic function |
| Title in Chinese: | 具有融合功能的移动终端安全能力技术要求 |
| Language: | English |
| File Format: | Electronic (PDF) |
| Delivery: | Via email within 1~3 business days |
| Issued on: | 2020-12-14 |
| Implemented on: | 2021-07-01 |
| ICS Classification: | 33.050-Telecommunication terminal equipment |
| Chinese Classification: | M30-Communication equipment in general |
| Professional Classification: | GB-National Standard |
| Related Keywords: | security requirements
security capability security chips standard security dimension key 34976-2017 communication security encrypted transmission |
| Related Topics: | fusion
Functional organic compound Eight organic fusion terminal equipment function Energy Security Cooperation GBT39575 GB/T 39575-2020 mobile terminal function of atp synthase |
《GB/T 39575-2020具有融合功能的移动终端安全能力技术要求》由TC485(全国通信标准化技术委员会)归口,主管部门为工业和信息化部(通信)。
Introduction
Analysis of the core framework of the standard
| Security dimension | Key technical requirements | Protection objectives | Test method reference |
|---|---|---|---|
| Hardware security | Unique identification, anti-physical attack, encryption chip design | Prevent side channel attacks/data leakage | YD/T 2408 |
| Operating system security | Secure boot, integrity verification, permission control | Ensure the system trusted execution environment | GB/T 34976-2017 |
| Communication security | Encrypted transmission, interface control, and anti-DoS attack | Ensure data transmission reliability | YD/T 2674-2013 |
Technology evolution background
With the popularization of converged terminals such as in-vehicle terminals and wearable devices, the standard focuses on strengthening the frequent malicious charging and privacy leakage incidents between 2016 and 2020:
- Hardware layer: Encryption chips are required to support 128-bit random number generation
- Data layer: Financial payment data must be stored in ciphertext
- Audit layer: Operation logs must be recorded and cannot be tampered with for 6 months
Implementation recommendations for key clauses
5.1.3 Anti-physical attack
It is recommended to use security chips to achieve the following:
1. Non-invasive protection: electromagnetic shielding, clock jitter technology
2. Semi-invasive protection: optical sensor detects cover opening
3. Invasive protection: multi-layer wiring, active metal layer
5.4.4 Personal information transfer
Three-step implementation process:
1. Pre-processing: field-level desensitization according to YD/T 3082-2016
2. Transmission encryption: use SM4 national encryption algorithm
3. Post-audit: keep transmission logs for at least 180 days
Industry application cases
Smart medical terminal:
In the blood pressure monitoring function, through:
- Hardware-level biometric encryption module (comply with clause 5.1.2)
- Real-time data desensitization processing (meet the requirements of 5.4.3)
Realize the full process protection from medical data collection to cloud transmission
Limitations and development of the standard
The current version does not cover:
1. Security requirements in quantum communication scenarios
2. Collaborative protection of edge computing nodes
The revised version expected to be launched in 2023 will supplement the security assessment indicators of AIoT devices

Loading PDF document...
Error loading PDF. Please make sure the file is valid and try again.
We also recommend
-

GB/Z 41383-2022 in English
Technical requirements of M2M service communication protocol
2022-04-15 -

GB/T 39576-2020 in English
Test methods for security capability of mobile terminal with syncretic function
2020-12-14