GB/T 39576-2020 in English
VALIDTest methods for security capability of mobile terminal with syncretic function
- Issued on:2020-12-14
- Implemented on:2021-07-01
- File Format:PDF
- Delivery:Via email within 5 business days
$301.00
《GB/T 39576-2020具有融合功能的移动终端安全能力测试方法》由TC485(全国通信标准化技术委员会)归口,主管部门为工业和信息化部(通信)。
Introduction
Core content architecture of the standard
| Security field | Number of test items | Key technical indicators |
|---|---|---|
| Hardware security | 3 | Unique identification, physical protection, chip security |
| System software security | 11 | Secure boot, permission control, vulnerability protection |
| Communication connection security | 5 | Encrypted transmission, interface control, data integrity |
| Personal information security | 5 | Collection authorization, storage encryption, desensitization processing |
Key points of key technology testing
1. Hardware security test
The standard requires three key tests for convergent function terminals:
- Identification uniqueness verification: Verify the non-tamperability of hardware identifiers such as IMEI through rewrite tests
- Chip security design: Evaluate key management mechanisms and physical interface protection capabilities
- Physical attack protection: Including resistance tests to side channel attacks (power consumption analysis, electromagnetic analysis) and error injection attacks (voltage glitches, clock glitches)
2. System security test
Typical test case: permission control test
The test requires the development of a test application that attempts to call sensitive APIs (such as location, address book access, etc.) to verify whether the system:
- Provides a clear permission control strategy
- Implements a user authorization mechanism before calling
- Blocks unauthorized access
The test results show that terminals that meet the requirements should achieve a 100% sensitive API call interception rate.
Recommendations for the implementation of the standard
Enterprise compliance path
| Implementation phase | Key tasks | Acceptance indicators |
|---|---|---|
| Design phase | Security architecture design, chip selection | Pass 4.2.2 design security test |
| Development phase | Security coding, permission model implementation | Pass 4.3.6 Permission control test |
| Testing phase | Penetration test, vulnerability scanning | Meet 4.3.9 system security requirements |
Technology evolution direction
With the development of intelligent connected devices, the standard may need to:
- Increase test requirements for 5G slice security capabilities
- Improve special protection tests for biometric data
- Supplement security verification in edge computing scenarios

Loading PDF document...
Error loading PDF. Please make sure the file is valid and try again.
We also recommend
-

GB/Z 41383-2022 in English
Technical requirements of M2M service communication protocol
2022-04-15 -

GB/T 39575-2020 in English
Technical requirements for security capability of mobile terminal with syncretic function
2020-12-14