GM/T 0097-2020 in English
VALIDSecurity technical specifications for unified name resolution service of RFID
- Issued on:2020-12-28
- Implemented on:2021-07-01
- File Format:PDF
- Delivery:Via email within 5 business days
$321.00
| Standard No: | GM/T 0097-2020 |
| Document status: | VALID |
| Title in English: | Security technical specifications for unified name resolution service of RFID |
| Title in Chinese: | 射频识别电子标签统一名称解析服务安全技术规范 |
| Language: | English |
| File Format: | Electronic (PDF) |
| Delivery: | Via email within 5 business days |
| Issued on: | 2020-12-28 |
| Implemented on: | 2021-07-01 |
| ICS Classification: | 35.040-Character sets and information coding |
| Chinese Classification: | L80-Data encryption |
| Related Topics: | Radio Frequency Identification
gm t gm/t Electronic tags Electronic label industry GM/T 38636-2020 |
本标准规定了射频识别电子标签统一名称解析服务的系统架构、关键业务流程和安全性要求,定义了名称解析服务器的注册流程、产品电子代码的安全查询流程及相应消息报文格式。本标准适用于射频识别电子标签统一名称解析服务系统的开发和使用。
Introduction
Standard Background and Significance
With the development of Internet of Things technology, the security issues of name resolution services of RFID electronic tags as digital identity carriers of items are becoming increasingly prominent. This standard is issued by the Cryptography Administration and specifies the security requirements for the entire link from tag encoding to resolution services.
System Architecture Analysis
| Components | Security Functions | Cryptographic Technology |
|---|---|---|
| Local ONS Server | Session Key Agreement | SM2/SM4 |
| Infrastructure Server | Level 3 Key Distribution | SM3 Derived Key |
| EPCIS Server | Data Source Authentication | Digital Certificate |
Key Technical Requirements
1. Cryptographic Algorithm System
Adopt National Secret Algorithm Suite:
- Asymmetric encryption: SM2 elliptic curve algorithm (GB/T 32918)
- Symmetric encryption: SM4 block cipher (GB/T 32907)
- Hash algorithm: SM3 cryptographic hash (GB/T 32905)
2. Key management system
Typical three-layer key structure:
- Device key layer: SM2 certificate protection identity authentication
- Session key layer: 24 hours validity period, SM4 protection communication
- Working key layer: 1 hour validity period, dynamic derivation
Key life cycle management strictly follows the GB/T 17901.1 framework requirements.
Implementation Suggestions
1. Key Points of System Deployment
It is recommended to adopt a hierarchical deployment mode:
- Level 1 node: responsible for root certificate and top-level key distribution
- Level 2 node: regional key management
- Level 3 node: terminal device access authentication
2. Security Audit Requirements
The following key logs need to be recorded:
- Key generation/update timestamp
- MAC verification result of ONS query
- Certificate validity verification record
3. Compatibility Considerations
Note the integration with existing RFID systems:
- Encoding rule conversion (Appendix A)
- Certificate injection of traditional readers
- EPCIS interface adaptation

Loading PDF document...
Error loading PDF. Please make sure the file is valid and try again.
We also recommend
-

GM/T 0044-2016 in English
SM9 identification cryptographic algorithm
2016-03-28