GM/T 0070-2019 in English
VALIDTechnical requirement for applications of cryptography in electronic insurance policy
- Issued on:2019-07-12
- Implemented on:2019-07-12
- File Format:PDF
- Delivery:Via email within 1~3 business days
$136.00
| Standard No: | GM/T 0070-2019 |
| Document status: | VALID |
| Title in English: | Technical requirement for applications of cryptography in electronic insurance policy |
| Title in Chinese: | 电子保单密码应用技术要求 |
| Language: | English |
| File Format: | Electronic (PDF) |
| Delivery: | Via email within 1~3 business days |
| Issued on: | 2019-07-12 |
| Implemented on: | 2019-07-12 |
| Related Topics: | password
Application Technology Cryptography gm/t 0031 gm/t 0034 Single receipt gm t 0031 Technical specification requirements for electronic letter of guarantee system access |
Introduction
Interpretation of the core content of the standard
This standard systematically constructs the technical framework for the application of electronic insurance policy passwords for the first time, and explicitly requires the use of national secret algorithms such as SM2, SM3, and SM4 to achieve security protection for the entire process of insurance application, underwriting, insurance underwriting, and claims settlement. Among them, the technical requirements for digital signature verification and electronic signature are the key to ensuring the legal effectiveness of electronic insurance policies.
Comparison Table of Cryptographic Technology Applications
| Business Links | Cryptographic Technology | Implemented Functions | Compliance Requirements |
|---|---|---|---|
| Electronic Insurance | SM2 Digital Signature | Non-repudiation of Behavior | GB/T32918 |
| Policy Storage | SM4 Encryption | Data Confidentiality | GB/T32907 |
| Policy Verification | SM3 Hash Check | Integrity Protection | GB/T32905 |
Key Technology Implementation Points
1. Electronic Seal Implementation Plan
Article 7.1.2 of the standard explicitly requires the adoption of the GM/T0031 specification to implement electronic seals, which must include:
- Seal image data is consistent with the physical seal
- Signature certificate is issued by a legitimate CA
- Timestamp (in compliance with GB/T20520)
2. Key Management System
Article 8.3 stipulates that signature keys must be managed through approved devices such as server cryptographic machines, and implement:
- Key generation: completed in the encryption device
- Storage protection: HSM hardware isolation
- Usage audit: full life cycle log record
Industry application recommendations
- System transformation priority: Prioritize the SM2 signature verification function in the electronic policy issuance process
- CA selection requirements: Select a CA organization with electronic certification service qualifications, and the certificate format must comply with GB/T20518
- Compliance time node: Newly developed systems should directly comply with the standard, and existing systems must be transformed within 2 years
Technology evolution analysis
Compared with early industry practices, this standard has three major breakthroughs:
1) Algorithm localization: Fully adopt SM series algorithms to replace RSA/SHA1
2) Improvement of the chain of evidence: Requires the collection of multi-dimensional data such as signature handwriting and biometrics
3) Full process coverage: Password protection requirements are defined for each link from insurance application to expiration

Loading PDF document...
Error loading PDF. Please make sure the file is valid and try again.
We also recommend
-

GM/T 0039-2015 in English
Security Test Requirements for Cryptographic Modules
2015-04-01 -

GM/T 0027-2014 in English
Technique requirements for smart token
2014-02-13 -

GM/T 0031-2014 in English
Secure electronic seal cryptography technical specification
2014-02-13 -

GM/T 0107-2021 in English
Smart IC card key management system basic technical requirements
2021-10-18 -

GM/T 0030-2014 in English
Cryptographic server technical specification
2014-02-13 -

GM/T 0065-2019 in English
Specification for capability construction of production and guarantee for commercial-cryptographic products
2019-07-12 -

GM/T 0076-2019 in English
Cryptography technical requirements for banking card information systems
2019-07-12 -

GM/T 0035.2-2014 in English
Specifications of cryptographic application for RFID systems. Part 2: Specification of cryptographic application for RFID tag chip
2014-02-13 -

GM/T 0071-2019 in English
Guidance of cryptographic application for electronic records
2019-07-12 -

GM/T 0075-2019 in English
Cryptograhy technical requirements for credit banking information systems
2019-07-12