Sign In |Help & Support
ALL SECTORS
  • ALL SECTORS
  • GB(National Standard)
  • CB(Shipping)
  • CECS(Engineering Construction)
  • CJ(Urban Construction)
  • CY(News and Publication)
  • DB(Provincial Standard)
  • DL(Electricity & Power)
  • DZ(Geology & Mineralogy)
  • FZ(Spinning & Textile)
  • GA(Public Security)
  • HB(Aviation)
  • HG(Chemical Industry)
  • HJ(Environmental Protection)
  • JB(Machinery)
  • JC(Building Materials)
  • JG(Building & Construction)
  • JJ(Metering)
  • JT(Highway & Transportation)
  • LY(Forestry)
  • MT(Coal)
  • NB(Energy)
  • NY(Agriculture)
  • QB(Light Industry)
  • QC(Automobile & Vehicle)
  • QJ(Aerospace)
  • SH(Petrochemical)
  • SJ(Electronics)
  • SL(Water Resources)
  • SN(Commodity Inspection)
  • SY(Oil & Gas)
  • TB(Railway & Train)
  • YB(Ferrous Metallurgy)
  • YC(Tobacco)
  • YD(Telecommunication)
  • YY(Medical Device)
Database: 365,228(8 Aug 2026)
core security technical requirements security dimensions security requirements level card information systems introduction standard background information security level protection technical requirements security protection requirements military information flywheel energy storage unit iot identification resolution
GM/T 0076-2019 in English

GM/T 0076-2019 in English

VALID

Cryptography technical requirements for banking card information systems

  • Issued on:2019-07-12
  • Implemented on:2019-07-12
  • File Format:PDF
  • Delivery:Via email within 5 business days
Price(USD): $490.00
$476.00
Standard No: GM/T 0076-2019
Document status: VALID
Title in English: Cryptography technical requirements for banking card information systems
Title in Chinese: 银行卡信息系统密码应用技术要求
Language: English
File Format: Electronic (PDF)
Delivery: Via email within 5 business days
Issued on: 2019-07-12
Implemented on: 2019-07-12
Related Keywords: core security technical requirements security dimensions security requirements level
card information systems introduction standard background
information security level protection
technical requirements
security protection requirements
Related Topics: password
Application Technology
silver
Cryptography
gm t
gm/t
gm request
gm/t 0028
gm/t 0036
gm request
Leica Information
Bank card
GM/T 0054
password card
gm/t 0024


Introduction

Standard Background and Scope of Application

This standard, as a supporting specification for the application of cryptographic technology in the banking industry under the information security level protection, constitutes a technical system together with GM/T0054-2018. It is applicable to the application guidance of commercial cryptography in bank card inter-bank payment systems and systems within issuing banks, covering security protection requirements from level 2 to level 4.


Core Security Technical Requirements

Security Dimensions Security Requirements Level 2 Level 3 Enhancement Level 4 Enhancement
Physical Environment Basic Hardware Protection Access Control System Integrity Verification Biometric Identification + Anti-Reentry Control
Network Communication SSL/TLS Encrypted Transmission Two-Factor Authentication Anti-Repudiation Evidence Retention
Key Management Random Number Generation Hardware Noise Source Anti-electromagnetic leakage environment

Key points for implementing cryptographic technology

Typical application scenario: POS terminal

1. The Password keyboard must meet the following requirements:

  • The transaction amount and PIN input are physically separated
  • The display only displays an asterisk mask
  • The key storage complies with the requirements of the GM/T0028 Level 3 module

2. The application ciphertext generation must include: minimum data sets such as transaction amount, currency code, and application interaction features


Key life cycle management

  1. Generation: Use hardware physical noise sources approved by the state
  2. Storage: Encrypted and stored in dedicated hardware, level 4 requires electromagnetic leakage prevention
  3. Distribution: Dual control principle, key components are kept by different people
  4. Destruction: Physical coverage + audit records, level 4 requires medium incineration

Implementation suggestions

1. It is recommended that level 3 and above systems deploy a level 3 cryptographic module that complies with GM/T0028
2. Sensitive fields (such as CVN2, PIN) must be encrypted using the national secret algorithm
3. The key administrator and security auditor positions must be separated

Sample only — not a preview of GM/T 0076-2019
Page: 1 / 0
100%

Loading PDF document...

Error loading PDF. Please make sure the file is valid and try again.

We also recommend