GM/T 0076-2019 in English
VALIDCryptography technical requirements for banking card information systems
- Issued on:2019-07-12
- Implemented on:2019-07-12
- File Format:PDF
- Delivery:Via email within 5 business days
$476.00
| Standard No: | GM/T 0076-2019 |
| Document status: | VALID |
| Title in English: | Cryptography technical requirements for banking card information systems |
| Title in Chinese: | 银行卡信息系统密码应用技术要求 |
| Language: | English |
| File Format: | Electronic (PDF) |
| Delivery: | Via email within 5 business days |
| Issued on: | 2019-07-12 |
| Implemented on: | 2019-07-12 |
| Related Keywords: | core security technical requirements security dimensions security requirements level
card information systems introduction standard background information security level protection technical requirements security protection requirements |
| Related Topics: | password
Application Technology silver Cryptography gm t gm/t gm request gm/t 0028 gm/t 0036 gm request Leica Information Bank card GM/T 0054 password card gm/t 0024 |
Introduction
Standard Background and Scope of Application
This standard, as a supporting specification for the application of cryptographic technology in the banking industry under the information security level protection, constitutes a technical system together with GM/T0054-2018. It is applicable to the application guidance of commercial cryptography in bank card inter-bank payment systems and systems within issuing banks, covering security protection requirements from level 2 to level 4.
Core Security Technical Requirements
| Security Dimensions | Security Requirements Level 2 | Level 3 Enhancement | Level 4 Enhancement |
|---|---|---|---|
| Physical Environment | Basic Hardware Protection | Access Control System Integrity Verification | Biometric Identification + Anti-Reentry Control |
| Network Communication | SSL/TLS Encrypted Transmission | Two-Factor Authentication | Anti-Repudiation Evidence Retention |
| Key Management | Random Number Generation | Hardware Noise Source | Anti-electromagnetic leakage environment |
Key points for implementing cryptographic technology
Typical application scenario: POS terminal
1. The Password keyboard must meet the following requirements:
- The transaction amount and PIN input are physically separated
- The display only displays an asterisk mask
- The key storage complies with the requirements of the GM/T0028 Level 3 module
2. The application ciphertext generation must include: minimum data sets such as transaction amount, currency code, and application interaction features
Key life cycle management
- Generation: Use hardware physical noise sources approved by the state
- Storage: Encrypted and stored in dedicated hardware, level 4 requires electromagnetic leakage prevention
- Distribution: Dual control principle, key components are kept by different people
- Destruction: Physical coverage + audit records, level 4 requires medium incineration
Implementation suggestions
1. It is recommended that level 3 and above systems deploy a level 3 cryptographic module that complies with GM/T0028
2. Sensitive fields (such as CVN2, PIN) must be encrypted using the national secret algorithm
3. The key administrator and security auditor positions must be separated

Loading PDF document...
Error loading PDF. Please make sure the file is valid and try again.
We also recommend
-

GM/T 0074-2019 in English
Technical requirements on cryptographic application for internet banking
2019-07-12 -

GM/T 0072-2019 in English
Technical requirements for the applying of cryptography in remote mobile payment
2019-07-12 -

GM/T 0107-2021 in English
Smart IC card key management system basic technical requirements
2021-10-18 -

GM/T 0065-2019 in English
Specification for capability construction of production and guarantee for commercial-cryptographic products
2019-07-12 -

GM/T 0044.3-2016 in English
Identity-based cryptographic algorithms SM9 - Part 3: Key exchange protocol
2016-03-28 -

GM/T 0039-2015 in English
Security Test Requirements for Cryptographic Modules
2015-04-01 -

GM/T 0027-2014 in English
Technique requirements for smart token
2014-02-13 -

GM/T 0031-2014 in English
Secure electronic seal cryptography technical specification
2014-02-13 -

GM/T 0044.2-2016 in English
Identity-based cryptographic algorithms SM9 - Part 2: Digital signature algorithm
2016-03-28 -

GM/T 0044.4-2016 in English
Identity-based cryptographic algorithms SM9 - Part 4: Key encapsulation mechanism and public key encryption alogorithm
2016-03-28