GM/T 0102-2020 in English
VALIDCryptographic device application interface test specification
- Issued on:2020-12-28
- Implemented on:2021-07-01
- File Format:PDF
- Delivery:Via email within 5 business days
$670.00
| Standard No: | GM/T 0102-2020 |
| Document status: | VALID |
| Title in English: | Cryptographic device application interface test specification |
| Title in Chinese: | 密码设备应用接口符合性检测规范 |
| Language: | English |
| File Format: | Electronic (PDF) |
| Delivery: | Via email within 5 business days |
| Issued on: | 2020-12-28 |
| Implemented on: | 2021-07-01 |
| ICS Classification: | 35.040-Character sets and information coding |
| Chinese Classification: | L80-Data encryption |
| Related Topics: | password
gm t gm/t compliance sex test Testing specification Testing equipment application code device code detection code GM/T 38636-2020 Crypto device application interface Air tightness testing equipment acceptance gm/t 0024 Temperature calibration equipment application |
本文件规定了GB/T 36322—2018的符合性检测要求和检测方法。?
本文件适用于按照GB/T 36322—2018实现的密码设备应用接口的检测,也可用于指导基于该接口规范的密码设备、模块、固件和软件产品的研制和应用开发。
Introduction
Analysis of the core framework of the standard
| Test category | Core indicator | Reference standard |
|---|---|---|
| Device management category | Session establishment/destruction success rate ≥ 99.99% | GB/T 36322-2018 Chapter 6 |
| Key management category | SM2/SM4 key generation speed ≥ 100 times/second | GB/T 32918.5-2017 |
| Algorithm operation class | SM3 hash value calculation accuracy 100% | GB/T 32905-2016 |
Key technical requirements
1. Device management interface
Specification requirements for device handle management to implement:
- Session timeout mechanism: Automatically released after 300 seconds of no operation by default
- Concurrency control: Support ≥16 parallel sessions
- Exception handling: When communication is interrupted, the error code 0x00000101 should be returned
Typical application scenarios
In the deployment of financial encryption machines, the session established through SDF_OpenSession must cooperate with the HSM hardware isolation mechanism to ensure the isolation of key storage for different tenants.
2. Key Lifecycle Management
The specification clearly defines the key lifecycle processing flow:
- Generation: Support SM2(256bit)/RSA(2048bit) key pairs
- Storage: Internal key index value range 1-32
- Destruction: The memory must be cleared after calling
SDF_DestroyKey
| Key Type | Encryption Mode | Compliance Requirements |
|---|---|---|
| Session Key | ECB/CBC | Compliant with GB/T 32907 |
| KEK | SM4-Wrap | Index 1-8 is reserved |
Implementation suggestions
Test environment construction
The following topology is recommended:
[Test console] ←SSL→ [Test server] ←TCP/IP→ [Crypto device]
Note: Network latency should be controlled within ≤50ms
Frequently asked questions
- Error 0x00000303: Check whether SM2 signature preprocessing performs GB/T 35276 ZA calculation
- Random number detection failed: Use NIST SP800-22 test suite for verification

Loading PDF document...
Error loading PDF. Please make sure the file is valid and try again.
We also recommend
-

GM/T 0044-2016 in English
SM9 identification cryptographic algorithm
2016-03-28