GM/T 0107-2021 in English
VALIDSmart IC card key management system basic technical requirements
- Issued on:2021-10-18
- Implemented on:2022-05-01
- File Format:PDF
- Delivery:Via email within 1~3 business days
$243.00
| Standard No: | GM/T 0107-2021 |
| Document status: | VALID |
| Title in English: | Smart IC card key management system basic technical requirements |
| Title in Chinese: | 智能IC卡密钥管理系统基本技术要求 |
| Language: | English |
| File Format: | Electronic (PDF) |
| Delivery: | Via email within 1~3 business days |
| Issued on: | 2021-10-18 |
| Implemented on: | 2022-05-01 |
| Related Topics: | key
key management key management key pair tube system private key Basic requirements of the test system key |
Introduction
Analysis of the core content of the standard
| Technical dimension | Symmetric key system | Asymmetric key system |
|---|---|---|
| Key type | Management key/transaction key | Root key/issuing institution key/card key |
| Typical algorithm | SM4 | SM2/SM9 |
| Distribution level | Support multi-level dispersion (root key→institution key→card key) | Three-level certificate system (root certificate→institution certificate→card certificate) |
Detailed explanation of key technical requirements
1. Key dispersion mechanism
Use SM4 algorithm to achieve key dispersion:
- Dispersion factor: institution code (superior→subordinate), PAN+serial number (institution→card)
- Calculation process: master key+dispersion factor→SM4 encryption→subkey generation
2. Secure transmission mechanism
The standard recommends two secure delivery methods:
- Key master card+authentication card dual-factor authentication
- Password envelope+KEK encrypted transmission
Implementation suggestions
Financial IC card system construction case
A bank adopts Financial Data Cryptography Machine (GM/T 0045 compliant) implements:
- The consumer root key generates the terminal PSAM card key through three-level dispersion
- The transaction MAC key adopts the SM3-SM4 combined algorithm
- The audit log uses the SM2 digital signature to prevent tampering
Standard Evolution Analysis
Compared with earlier versions, the 2021 version has the following major enhancements:
- Added support for SM9 identification cryptographic algorithm
- Refine key archiving management requirements (at least 2 component storage)
- Strengthen cryptographic module testing and certification requirements

Loading PDF document...
Error loading PDF. Please make sure the file is valid and try again.
We also recommend
-

GM/T 0027-2014 in English
Technique requirements for smart token
2014-02-13 -

GM/T 0075-2019 in English
Cryptograhy technical requirements for credit banking information systems
2019-07-12 -

GM/T 0065-2019 in English
Specification for capability construction of production and guarantee for commercial-cryptographic products
2019-07-12 -

GM/T 0035.4-2014 in English
Specifications of cryptographic application for RFID systems. Part 4: Specification of cryptographic application for communication between RFID tag and reader
2014-02-13 -

GM/T 0039-2015 in English
Security Test Requirements for Cryptographic Modules
2015-04-01 -

GM/T 0030-2014 in English
Cryptographic server technical specification
2014-02-13 -

GM/T 0044.3-2016 in English
Identity-based cryptographic algorithms SM9 - Part 3: Key exchange protocol
2016-03-28 -

GM/T 0048-2016 in English
Cryptography test specification for cryptographic smart token
2016-12-23 -

GM/T 0049-2016 in English
Cryptography test specification for EPP
2016-12-23 -

GM/T 0035.1-2014 in English
Specifications of cryptographic application for RFID systems. Part 1: Cryptographic protection framework and security levels
2014-02-13