GM/T 0086-2020 in English
VALIDSpecification of key management system based on SM9 identity cryptography algorithm
- Issued on:2020-12-28
- Implemented on:2021-07-01
- File Format:PDF
- Delivery:Via email within 5 business days
Price(USD):
$430.00
$418.00
$418.00
| Standard No: | GM/T 0086-2020 |
| Document status: | VALID |
| Title in English: | Specification of key management system based on SM9 identity cryptography algorithm |
| Title in Chinese: | 基于SM9标识密码算法的密钥管理系统技术规范 |
| Language: | English |
| File Format: | Electronic (PDF) |
| Delivery: | Via email within 5 business days |
| Issued on: | 2020-12-28 |
| Implemented on: | 2021-07-01 |
| ICS Classification: | 35.040-Character sets and information coding |
| Chinese Classification: | L80-Data encryption |
| Related Keywords: | key management system
key management system core architecture key generation modulefunctionsecurity requirements private key generation system judicial key recovery |
| Related Topics: | password
algorithm key key management key management key pair private key key GM/T 38636-2020 sy/t 0086-2020 yy/t 0086-2020 yyt 0086-2020 |
本标准规定了基于SM9标识密码算法的密钥管理系统架构及其建设要求。该架构可作为基于标识密码应用的普适性基础标准,为其提供密钥生成、管理以及公开参数查询等服务。
本标准适用于指导基于SM9标识密码的标识密钥管理系统设计、建设和管理,也可以用于相关系统的检测。
Introduction
SM9 identification cryptographic algorithm key management system core architecture
According to the GM/T 0086-2020 standard, the system adopts a three-tier architecture design:
| Module | Function | Security requirements |
|---|---|---|
| Private Key Generation System (PKG) | Master key generation, user private key derivation | National Secret Authentication Password Device |
| Registration Service System (RA) | Identity verification, key distribution | Two-way identity authentication |
| Public Parameter Service (PPS) | Parameter release, status query | Digital signature protection |
Key life cycle management
Typical application scenario: Judicial key recovery
According to Article 8.8.3 of the standard, judicial recovery requires the establishment of an independent management system:
- Equipped with dedicated cryptographic equipment and audit modules
- Adopt m/n threshold mechanism to control operation permissions
- The whole process audit log is non-tamperable
Key technologies for security protection
| Protection level | Control measures | Standard terms |
|---|---|---|
| Master Key Security | Key Split Backup, Hardware Encrypted Storage | 11.2.4.2 |
| Transmission Security | SM4 Encrypted Channel + SM2 Signature | 8.3 |
| Terminal Security | Intelligent Password Key Carrier | 7.4.1 |
Implementation Suggestions
Note when deploying in a hierarchical manner:
- The upper-level KMS needs to sign the lower-level master public key (Appendix 13.4)
- The public parameter service adopts the master-slave synchronization mechanism (7.3.2)
- Cross-domain verification requires querying the other party's KMS certificate chain through PPS (13.6)
Sample only — not a preview of GM/T 0086-2020

Loading PDF document...
Error loading PDF. Please make sure the file is valid and try again.
We also recommend
-

GM/T 0044-2016 in English
SM9 identification cryptographic algorithm
2016-03-28