GM/T 0073-2019 in English
VALIDCryptography technical requirements for mobile banking information systems
- Issued on:2019-07-12
- Implemented on:2019-07-12
- File Format:PDF
- Delivery:Via email within 5 business days
$340.00
| Standard No: | GM/T 0073-2019 |
| Document status: | VALID |
| Title in English: | Cryptography technical requirements for mobile banking information systems |
| Title in Chinese: | 手机银行信息系统密码应用技术要求 |
| Language: | English |
| File Format: | Electronic (PDF) |
| Delivery: | Via email within 5 business days |
| Issued on: | 2019-07-12 |
| Implemented on: | 2019-07-12 |
| Related Keywords: | key management requirements
technical requirements requirements level mobile banking information systems introduction standard background mobile terminal security protection standard |
| Related Topics: | password
technology bank GM/T 0054 |
Introduction
Standard Background and Technical Evolution
As an important part of the series of standards for cryptographic applications in the financial industry, GM/T 0073-2019 fills the gap in cryptographic technical specifications in the field of mobile finance. This standard forms a technical complement to GM/T0054, and refines requirements for scenarios such as remote payment verification and mobile terminal security that are unique to mobile banking, reflecting the innovative application of commercial cryptography in my country's financial field.
Comparison of Core Security Frameworks
| Security Dimensions | Level 2 Requirements | Level 3 Requirements |
|---|---|---|
| Identity Authentication | Two-Factor Authentication (Recommended) | Mandatory Two-Factor + Biometrics |
| Data Transmission Encryption | TLS 1.0/SSL 3.0+ | Mandatory National Secret Algorithm SM2/SM3 |
| Cryptographic Module Level | GM/T0028 Level 2 | GM/T0028 Level 3 |
| Key management | Basic key split protection | Dual control + hardware encryption |
Key technology implementation points
1. Mobile terminal security protection
Standard 7.2.4.4 clearly requires: Mobile terminal applications must desensitize sensitive data (such as PAC/CVV) and prohibit plain text storage. Typical implementation plans include:
- Use Security Unit (SE) to store payment keys
- Use white box cryptography technology to protect the operating environment
- Implement code obfuscation to prevent reverse analysis
2. Dynamic password security
According to the requirements of 7.2.3.4, OTP generation must meet the following requirements:
- The random number generator complies with the GM/T0005 standard
- Single validity period ≤ 3 minutes
- Anti-replay attack mechanism
Key life cycle management
Chapter 8 of the standard specifies the key management requirements for the three-level system in detail:
- Generation: It must be generated using a tested hardware cryptographic machine
- Distribution: Use key envelope dual control (8.3.3.1)
- Storage: Encrypted storage in intelligent password key
- Destruction: Physical destruction requires supervision by a security auditor (8.3.3.5)
Compliance implementation recommendations
Institutional implementation path
Recommendations for different construction stages:
| Stage | Key tasks |
|---|---|
| Planning period | Conduct gap analysis against Appendix A |
| Construction period | Prioritize the deployment of cryptographic modules that comply with GM/T0028 |
| Operation and maintenance period | Establish a key rotation ledger (7.3.3.3) |
Avoidance of typical problems
- Avoid using non-national secret algorithms to encrypt sensitive data
- Prohibit sharing the same key across security domains
- Dynamic password systems must pass commercial password testing

Loading PDF document...
Error loading PDF. Please make sure the file is valid and try again.
We also recommend
-

GM/T 0065-2019 in English
Specification for capability construction of production and guarantee for commercial-cryptographic products
2019-07-12 -

GM/T 0107-2021 in English
Smart IC card key management system basic technical requirements
2021-10-18 -

GM/T 0027-2014 in English
Technique requirements for smart token
2014-02-13 -

GM/T 0032-2014 in English
Specifications for role based privilege management and access control
2014-02-13 -

GM/T 0039-2015 in English
Security Test Requirements for Cryptographic Modules
2015-04-01 -

GM/T 0042-2015 in English
Test specification for cryptography and security protocol in tri-element peer architecture
2015-04-01 -

GM/T 0035.5-2014 in English
Specifications of cryptographic application for RFID systems. Part 5: Specification for key management
2014-02-13 -

GM/T 0028-2014 in English
Security Requirements for Cryptographic Modules
2014-02-13 -

GM/T 0044.1-2016 in English
Identity-based cryptographic algorithms SM9 - Part 1: General
2016-03-28 -

GM/T 0040-2015 in English
Cipher test specification of radio frequency identification tag module
2015-04-01