JR/T 0184-2020 in English
VALIDFinancial distributed ledger technology security
- Issued on:2020-02-05
- Implemented on:2020-02-05
- File Format:PDF
- Delivery:Via email within 1~3 business days
$476.00
| Standard No: | JR/T 0184-2020 |
| Document status: | VALID |
| Title in English: | Financial distributed ledger technology security |
| Title in Chinese: | 金融分布式账本技术安全规范 |
| Language: | English |
| File Format: | Electronic (PDF) |
| Delivery: | Via email within 1~3 business days |
| Issued on: | 2020-02-05 |
| Implemented on: | 2020-02-05 |
| Professional Classification: | JR-Finance |
| Related Keywords: | security requirements
smart contract security specifications chapter technology security introduction standard core framework security system security template generation deployment phase |
| Related Topics: | finance
distributed Paradigm Distributed+ JR/t |
Introduction
Standard core framework and security requirements
This standard constructs a security system with 12 dimensions including basic hardware, cryptographic algorithms, smart contracts, etc., which is suitable for the construction of distributed ledger systems of financial institutions such as banks and securities. The main features include:
| Technical field | Core requirements | Compliance benchmark |
|---|---|---|
| Basic hardware | Node heterogeneous deployment, encryption machine complies with GM/T 0045 | GB/T 22239 Level 3+ |
| Cryptographic algorithm | Mandatory national secret algorithm (SM2/3/4) | GM/T series standards |
| Smart contract | Atomicity/version control/formal verification | Chapter 12 special requirements |
Key points for implementing cryptographic algorithms
Chapter 8 of the standard explicitly requires the use of the national secret algorithm system:
- Confidentiality: SM4 encrypts data for transmission, and session keys require dynamic negotiation
- Integrity: SM3 hash algorithm ensures data tamper-proof
- Authenticity: SM2 digital signature achieves two-way identity authentication
Smart Contract Security Specifications
Chapter 12 of the standard proposes full life cycle management requirements:
- Development phase: complexity limit (number of lines of code ≤5000), security template generation
- Deployment phase: multi-party joint review mechanism, mandatory version number identification
- Operation phase: atomicity guarantee (automatic rollback on errors), resource isolation
Regulatory compliance implementation recommendations
According to the requirements of Chapter 15, the following measures are recommended:
| Regulatory requirements | Technical implementation | Audit requirements |
|---|---|---|
| Penetrating supervision | Supervisory nodes are directly connected to the underlying data | Log retention ≥ 6 months |
| Transaction intervention | Multi-signature governance contract | Operation track on the chain |

Loading PDF document...
Error loading PDF. Please make sure the file is valid and try again.
We also recommend
-

JR/T 0221-2021 in English
Evaluation specification of artificial intelligence algorithm in financial application
2021-03-26 -

JR/T 0213-2021 in English
Financial cyber security General specification for security testing of Web application services
2021-02-10 -

JR/T 0055.1-2009 in English
Technical specifications on bankcard interoperability - Part 1: Transaction processing
2009-06-01 -

JR/T 0025.2-2010 in English
China Financial Integrated Circuit Card Specifications-Part 2:Electronic Purse/Electronic Deposit Application Specification
2010-04-30 -

JR/T 0004-2013 in English
Commemorative Coin Made from Precious Metal - Gold
2013-06-27 -

JR/T 0069-2012 in English
Code for Business of Credit Enhancement Organization
2012-08-21 -

JR/T 0035-2007 in English
Criterion of Code and Coding for Insurance Institutions
2007-12-27 -

JR/T 0099-2012 in English
Specification for Operation, Maintenance and Management of Information System in Securities and Futures Industry
2013-01-31 -

JR/T 0061-2011 in English
Terms for Bankcard
2011-06-10 -

JR/T 0071.6-2020 in English
Implementation guidelines for classified protection of cybersecurity of financialindustryPart 6: Guidelines for audit work
2020-11-11