GM/T 0075-2019 in English
VALIDCryptograhy technical requirements for credit banking information systems
- Issued on:2019-07-12
- Implemented on:2019-07-12
- File Format:PDF
- Delivery:Via email within 5 business days
$379.00
| Standard No: | GM/T 0075-2019 |
| Document status: | VALID |
| Title in English: | Cryptograhy technical requirements for credit banking information systems |
| Title in Chinese: | 银行信贷信息系统密码应用技术要求 |
| Language: | English |
| File Format: | Electronic (PDF) |
| Delivery: | Via email within 5 business days |
| Issued on: | 2019-07-12 |
| Implemented on: | 2019-07-12 |
| Related Keywords: | key technical requirements
technical requirements specific technical requirements technical field core requirements bank credit information systems |
| Related Topics: | Application Technology
jy/t 0075 |
Introduction
Standard Overview
GM/T 0075-2019 is a cryptographic industry standard issued by the State Cryptography Administration, which puts forward specific technical requirements for the application of cryptography in bank credit information systems. The standard forms a technical system with GM/T 0054-2018, etc., and focuses on regulating:
| Technical field | Core requirements | Corresponding chapters |
|---|---|---|
| Key management | Full life cycle management (generation, storage, distribution, update, destruction) | 7.3 |
| Encryption protocol | SSL/TLS, VPN and other secure transmission requirements | 7.2.4 |
| Access control | Biometric identification, multi-factor authentication mechanism | 7.2.3 |
Key Technical Requirements
1. Key Management System
The standard requires the use of Trusted Cryptographic Module (TCM) to implement:
- Key generation: Comply with GM/T 0005 algorithm standard
- Storage protection: Hardware-level secure storage, anti-side channel attack
- Distribution mechanism: Key negotiation based on SM2/SM9
2. Data transmission encryption
Explicit requirements:
- SSL/TLS 1.2+ or IPSec VPN must be enabled on the communication link
- Sensitive fields (such as PIN code) must be encrypted separately
- Weak algorithms such as RC4 and DES are prohibited
Implementation suggestions
Typical application scenarios
In the credit approval system:
- Customer identity authentication uses OTP dynamic password encrypted by SM4
- Contract documents use SM2 digital signatures
- Database field-level encryption uses SM3 hash protection
Key points for compliance inspection
| Inspection items | Detection methods | Reference clauses |
|---|---|---|
| Key rotation period | Audit key update log | 7.3.2.3 |
| Encryption protocol version | Network Packet Capture Analysis | 8.2.4.2 |

Loading PDF document...
Error loading PDF. Please make sure the file is valid and try again.
We also recommend
-

GM/T 0027-2014 in English
Technique requirements for smart token
2014-02-13 -

GM/T 0044.3-2016 in English
Identity-based cryptographic algorithms SM9 - Part 3: Key exchange protocol
2016-03-28 -

GM/T 0035.1-2014 in English
Specifications of cryptographic application for RFID systems. Part 1: Cryptographic protection framework and security levels
2014-02-13 -

GM/T 0032-2014 in English
Specifications for role based privilege management and access control
2014-02-13 -

GM/T 0065-2019 in English
Specification for capability construction of production and guarantee for commercial-cryptographic products
2019-07-12 -

GM/T 0045-2016 in English
Specifications of financial cryptographic server
2016-03-28 -

GM/T 0077-2019 in English
Cryptography tecyhnical requirements for core banking systems
2019-07-12 -

GM/T 0030-2014 in English
Cryptographic server technical specification
2014-02-13 -

GM/T 0051-2016 in English
Cryptography device management - Specifications of symmetric key management technology
2016-12-23 -

GM/T 0039-2015 in English
Security Test Requirements for Cryptographic Modules
2015-04-01