GM/T 0098-2020 in English
VALIDCryptographic technical specifications for encrypted voice communication based on IP network
- Issued on:2020-12-28
- Implemented on:2021-07-01
- File Format:PDF
- Delivery:Via email within 5 business days
Price(USD):
$670.00
$650.00
$650.00
| Standard No: | GM/T 0098-2020 |
| Document status: | VALID |
| Title in English: | Cryptographic technical specifications for encrypted voice communication based on IP network |
| Title in Chinese: | 基于IP网络的加密语音通信密码技术规范 |
| Language: | English |
| File Format: | Electronic (PDF) |
| Delivery: | Via email within 5 business days |
| Issued on: | 2020-12-28 |
| Implemented on: | 2021-07-01 |
| ICS Classification: | 35.040-Character sets and information coding |
| Chinese Classification: | L80-Data encryption |
| Related Keywords: | encrypted voice communication
cryptographic machine user key encrypted voice communication systems public key key management certificate cryptographic system |
| Related Topics: | password
Cryptography gm t gm/t t.gm encryption network encryption gm/t 0030 Regulations of the Ministry of Industry and Information Technology on Online Sacrifice GM/T 38636-2020 Network decoder technology Crypto gateway industry Channel encryption |
本文件定义了基于IP网络的加密语音通信系统、密钥管理、安全协议、密码模块、安全要求和产品检测基本要求。?
本文件适用于指导基于IP网络的加密语音通信系统应用中密码安全方案设计、产品研制,也可用于指导基于IP网络的加密语音通信系统产品的检测。
Introduction
Analysis of the core content of the standard
GM/T 0098-2020 specifies the technical requirements for encrypted voice communication systems based on IP networks, mainly including:
- Cryptographic system using national secret algorithms such as SM2/SM4/SM9
- Two-way identity authentication mechanism between terminal and server
- Dynamic generation principle of one conversation, one secret for session keys
- End-to-end encrypted transmission specification for voice data
Comparison of cryptographic technology systems
| Technical elements | PKI system (SM2) | Identification cryptographic system (SM9) |
|---|---|---|
| Identity credentials | Digital certificate | User identity is directly used as the public key |
| Key management | Certificate issued by CA | Private key distributed by key generation center |
| Typical applications | Enterprise-level communication system | Mobile terminal rapid deployment scenario |
Key technology implementation
1. Key management mechanism
The standard defines a three-level key system:
- Root key: SM2/SM9 master key stored in the server cryptographic machine
- User key: an asymmetric key pair held by the terminal
- Session key: a symmetric key dynamically generated by SM4/ZUC
2. Security protocol process
Implemented by extending the SIP protocol:
INVITE sip:[email protected] SIP/2.0 Authorization: Capability algorithm="SM4/CBC:SM9" version="1"
Implementation suggestions
Key points of system deployment
- The terminal password module must comply with the GB/T 37092 security level 1 requirements
- The server should use the GM/T 0030 authentication password machine
- The key distribution response time is controlled within ≤1s (WiFi/4G environment)
Test acceptance standards
According to the requirements of Chapter 10 of the standard:
- Functional testing: including 6 major items such as session establishment and key negotiation
- Performance indicators: number of concurrent sessions ≥500 (10M bandwidth)
- Security testing: the cryptographic module interface complies with GB/T 35291
Sample only — not a preview of GM/T 0098-2020

Loading PDF document...
Error loading PDF. Please make sure the file is valid and try again.
We also recommend
-

GM/T 0044-2016 in English
SM9 identification cryptographic algorithm
2016-03-28