GB/T 39720-2020 in English
VALIDInformation security technology—Security technical requirements and test evaluation approaches for smart mobile terminal
- Issued on:2020-12-14
- Implemented on:2021-07-01
- File Format:PDF
- Delivery:Via email within 1~3 business days
$243.00
《GB/T 39720-2020信息安全技术 移动智能终端安全技术要求及测试评价方法》由TC260(全国网络安全标准化技术委员会)归口,主管部门为国家标准化管理委员会。
Introduction
Analysis of the standard technical framework
GB/T 39720-2020 has built a security technology system covering five core areas of mobile smart terminals:
- Hardware security: chip interface protection and physical security
- System security: 7 mechanisms such as signature verification, permission control, and security isolation
- Application software security: 4 requirements such as code signing and minimum permissions
- Communication connection security: network access authentication and data transmission encryption
- User data security: full process specifications for collection, storage, transmission, and deletion
Comparison of key technical requirements
| Security dimension | GB/T 39720-2020 requirements | International benchmark (ISO/IEC 15408) | Implementation difficulties |
|---|---|---|---|
| Hardware security | Disable hidden debug interface | ALC_FLR.3 fault detection | Chip-level security verification |
| System signature verification | Mandatory digital signature authentication | FPT_TST.1 Integrity test | Key management system construction |
| User data protection | Explicit consent + encrypted storage | FDP_UCT.1 Data transmission encryption | Data flow tracking |
Implementation points analysis
Hardware security practice
Article 6.1 of the standard requires chip manufacturers to:
- Close all debugging interfaces before mass production
- Use Physically Unclonable Function (PUF) technology to prevent hardware cloning
- Typical case: A certain brand of smartphone permanently disables the JTAG interface through a fuse mechanism
Permission control optimization
The principle of minimizing permissions stipulated in Article 6.2.4 of the standard:
- Dynamic application for permissions at runtime (such as iOS's ATT framework)
- Permission usage scenario description (Android permission usage prompts)
- Background permission automatic recovery mechanism
Testing Method Innovation
The three-level testing system proposed in Chapter 7 of the standard:
| Test Type | Technical Means | Sample Tool |
|---|---|---|
| Static Analysis | Reverse Engineering Detection | IDA Pro, Jadx |
| Dynamic Monitoring | API Call Tracking | Frida, Xposed |
| Pension Testing | Vulnerability Exploitation Verification | Metasploit |
Standard Evolution Trend
Main upgrades compared to GB/T 32927-2016:
- Added special protection requirements for biometric data (Article 6.5.2)
- Detailed communication interface security management (Article 6.4.2)
- Strengthen supply chain security management (Chapter 7 Test Scope)
It is expected that the next version will add: AI algorithm security assessment, 5G slice security, IoT linkage protection and other requirements.

Loading PDF document...
Error loading PDF. Please make sure the file is valid and try again.
We also recommend
-

GB/T 45240-2025 in English
General requirements for device-independent quantum random number generators
2025-01-24 -

GB/T 39680-2020 in English
Information security technology—Technique requirements and evaluation criteria for server security
2020-12-14 -

GB/T 24363-2009 in English
Information security technology—Specifications of emergency response plan for information security
2009-09-30 -

GB/Z 24294.1-2018 in English
Information security technology—Guide of implementation for internet-basede-government information security—Part 1:General
2018-03-15 -

GB/T 32905-2016 in English
Information security technology SM3 cryptographic hash algorithm
2016-08-29 -

GB/T 39276-2020 in English
Information security technology—General security requirements of network products and services
2020-11-19 -

GB/T 22186-2016 in English
Information security techniques―Security technical requirements for IC card chip with CPU
2016-08-29 -

GB/T 20009-2019 in English
Information security technology—Security evaluation criteria for database management system
2019-08-30 -

GB/T 32213-2015 in English
Information security technology―Public key infrastructure―Specification for remote password authentication and key establishment
2015-12-10 -

GB/T 17901.1-2020 in English
Information technology—Security techniques—Key management—Part 1: Framework
2020-03-06