GM/T 0082-2020 in English
VALIDTrusted cryptography module protection profile
- Issued on:2020-12-28
- Implemented on:2021-07-01
- File Format:PDF
- Delivery:Via email within 5 business days
$476.00
| Standard No: | GM/T 0082-2020 |
| Document status: | VALID |
| Title in English: | Trusted cryptography module protection profile |
| Title in Chinese: | 可信密码模块保护轮廓 |
| Language: | English |
| File Format: | Electronic (PDF) |
| Delivery: | Via email within 5 business days |
| Issued on: | 2020-12-28 |
| Implemented on: | 2021-07-01 |
| ICS Classification: | 35.040-Character sets and information coding |
| Chinese Classification: | L80-Data encryption |
| Related Keywords: | key life cycle protection key generation
cryptography module protection algorithm key management sm2 algorithm protection profile trusted cryptographic module |
| Related Topics: | password
Module English upper contour set Protective spacer module Surface profiler maintenance GM/T 38636-2020 |
本文件以GB/T 29829和GB/T 18336为基础,构建可信密码模块的保护轮廓,对符合评估保障级第3级的TOE的定义、安全环境、安全目的、安全要求等进行了详细说明,并给出相应的基本原理说明。?
本文件适用于可信密码模块相关产品的生产、测评与应用开发。
Introduction
Analysis of the core content of the standard
Scope of application of the standard
This document builds the protection profile of the trusted cryptographic module based on GB/T 29829 and GB/T 18336, and explains in detail the definition, security environment, and security purpose of the TOE (object of evaluation) that meets the third level of the assessment assurance level. It is applicable to the production, evaluation, and application development of products related to the trusted cryptographic module.
Key technical requirements
| Security function | Implementation requirements | Corresponding algorithm |
|---|---|---|
| Key management | SM2 algorithm generates 256-bit keys, SM4 algorithm generates 128-bit keys | SM2/SM4 |
| Cryptographic operations | Support SM3 hashing, HMAC-SM3, SM2 signature/encryption, SM4 encryption/decryption | Full SM series |
| Physical protection | Anti-side channel attacks (energy analysis/timing analysis), physical tampering detection |
Decomposition of security function requirements
Typical application scenario: Key life cycle protection
- Key generation: Generate by SM2/SM4 algorithm specification according to FCS_CKM.1 requirement
- Key storage: Non-migratable keys are encrypted and protected by the storage master key
- Key destruction: FCS_CKM.4 requires the use of password erasure technology
Security assurance system
EAL3 enhanced level assurance requirements
| Assurance category | Key requirements |
|---|---|
| Configuration management | ACM_CAP.3 Authorization control, unique version identifier must be provided |
| Vulnerability assessment | AVA_VLA.1 Developers need to analyze and document obvious vulnerabilities |
| Test verification | ATE_IND.2 Requires third-party sampling test verification |
Implementation recommendations
Product development considerations
- Cryptographic algorithm implementation: Strictly follow the GM/T 0012 interface specification, the SM3 algorithm must implement a 256-bit hash value
- Security attribute management: Ensure that the security attributes of the key, such as TCM-KEY-FLAGS, are fully controlled
- Anti-physical attack: It is recommended to add temperature/voltage anomaly detection circuit
Evaluation points
- Verify the compliance of SM2 signature verification (GB/T 32918)
- Test the FDP_RIP.2 residual information clearing effect
- Check the FPT_PHP.1 physical tampering response mechanism

Loading PDF document...
Error loading PDF. Please make sure the file is valid and try again.
We also recommend
-

GM/T 0044-2016 in English
SM9 identification cryptographic algorithm
2016-03-28