GM/T 0100-2020 in English
VALIDCryptographic application technical requirements for manually confirmed signing
- Issued on:2020-12-28
- Implemented on:2021-07-01
- File Format:PDF
- Delivery:Via email within 5 business days
Price(USD):
$430.00
$418.00
$418.00
| Standard No: | GM/T 0100-2020 |
| Document status: | VALID |
| Title in English: | Cryptographic application technical requirements for manually confirmed signing |
| Title in Chinese: | 人工确权型数字签名密码应用技术要求 |
| Language: | English |
| File Format: | Electronic (PDF) |
| Delivery: | Via email within 5 business days |
| Issued on: | 2020-12-28 |
| Implemented on: | 2021-07-01 |
| ICS Classification: | 35.040-Character sets and information coding |
| Chinese Classification: | L80-Data encryption |
| Related Topics: | Application Technology
gm request digital signature confirmation Technical requirements for manual digital signature cryptographic applications GM/T 38636-2020 HR digital human application |
本文件规定了人工确权型数字签名的总体要求、应用接口以及使用专用签名密钥对的人工确权型数字签名相关要求。?
本文件适用于人工确权型数字签名应用、人工确权型数字签名系统以及人工确权型数字签名设备的设计和开发,也可用于指导上述应用、系统及设备的测试。
Introduction
Analysis of the core content of the standard
| Technical elements | Manual confirmation signature | General digital signature |
|---|---|---|
| Signature trigger mechanism | Need to meet the triggering characteristics + manual confirmation | Direct generation |
| Security level | GB/T 37092 Level 2 or above | Basic level |
| Typical applications | Financial transactions, identity authentication | Ordinary electronic signature |
Key technology implementation
1. Three-stage signature process
The signature process specified by the standard is divided into: Trigger check → Manual interaction → Signature generation:
- Visual button type smart password key needs to have a built-in transaction message parsing engine
- Review type signature timeout ≥ 60 seconds
- Interaction features need to be anti-counterfeiting (such as dedicated key pairs)
2. Equipment security requirements
Case:Online banking USB Key needs to meet the following requirements:
- With display screen and physical buttons
- Transaction data analysis and display consistency
- Anti-remote hijacking design
Typical application scenarios
| Industry | Application model | Compliance basis |
|---|---|---|
| Online banking | Transfer transaction review | JR/T0068-2012 |
| Identity authentication | FIDO2 protocol | W3C WebAuthn |
Implementation suggestions
1. Key management solution
It is recommended to adopt the Dedicated signature key pair solution in Chapter 7 of the standard:
- Maintain at least two pairs of keys (dedicated + common)
- Container isolation storage (dedicated container does not store other keys together)
- Certificate policy distinction (dedicated sub-CA)
2. Anti-fraud measures
Risk case: XML/JSON message parsing vulnerability may lead to "what you see is not what you sign"
Solution:
- Strictly define the trigger feature judgment rules
- Implement a double verification mechanism for signature results
- Use the message format specification in Appendix B
Sample only — not a preview of GM/T 0100-2020

Loading PDF document...
Error loading PDF. Please make sure the file is valid and try again.
We also recommend
-

GM/T 0044-2016 in English
SM9 identification cryptographic algorithm
2016-03-28