LD/T 02.2-2022 in English
VALIDSpecifications for human resources and social security electronic authentication system-Part 2: Technology specification for electronic authentication system
- Issued on:2022-06-01
- Implemented on:2022-07-01
- File Format:PDF
- Delivery:Via email within 5 business days
$534.00
本文件给出了人力资源社会保障电子认证系统的系统构成,规定了电子认证系统各单元的结构和本文件给出了人力资源社会保障电子认证系统的系统构成,规定了电子认证系统各单元的结构和
基本功能、密码算法、密码设备及接口、基础安全防护措施、业务流程及相关协议。
本文件适用于各级人力资源社会保障部门建设基于PKI技术的电子认证系统。
Introduction
Analysis of the core content of the standard
| Core module | 2009 version | Main changes in the 2022 version |
|---|---|---|
| Cryptographic algorithm | No domestic algorithm specified | SM2/SM3/SM4 algorithms are mandatory |
| System architecture | 6 major subsystems | Optimized as certificate authentication + key management dual facilities |
| Certificate management | CRL query only | Added OCSP real-time verification |
Key technical requirements
1. Cryptographic algorithm system
Chapter 8 of the standard clearly stipulates:
- Asymmetric algorithm: SM2 (digital signature/key exchange)
- Hash algorithm: SM3 (message digest)
- Symmetric algorithm: SM1/SM4 (data encryption)
All cryptographic devices must be certified by the National Cryptography Administration, and key storage must meet the security requirements of Level 2 or above of GB/T 37092-2018.
2. Dual certificate mechanism
Standard 6.1.1 stipulates that the system must implement:
Encryption certificate: used for data encryption, supporting key recovery
Typical case: The social security card holder certificate must contain both certificates
Implementation suggestions
Provincial system construction plan
According to Appendix A/B two modes:
| Comparison dimensions | Mode 1 (centralized) | Mode 2 (distributed) |
|---|---|---|
| CA deployment | Provincial centralized CA | Provincial sub-CA + ministerial root CA |
| Number of cryptographic machines | 2 | 3 (independent KMC) |
| Applicable scenarios | Provinces with medium business volume | Provinces with high concurrent business |
Key points of operation and maintenance
- Key management facilities need to achieve hot standby + remote disaster recovery
- OCSP service response time should be controlled within 500ms
- Regularly perform GM/T 0014-2012 protocol compliance testing

Loading PDF document...
Error loading PDF. Please make sure the file is valid and try again.
We also recommend
-

LD/T 04-2022 in English
Specification for human resources and social security network security monitoring and emergency disposal
2022-06-01 -

LD/T 02.4-2022 in English
Specifications for human resources and social security electronic authentication system - Part 4: Specification for certificate application interface
2022-06-01 -

LD/T 03-2022 in English
Specification for human resources and social security electronic certification service management
2022-06-01 -

LD/T 07-2022 in English
Specification for human resources social security data center and network system operation monitoring
2022-09-30 -

LD/T 01.3-2022 in English
Human Resources and Social Security Electronic Seal System Part 3:Technical Specification of the Seal Signature
2022-03-23 -

LD/T 01.4-2022 in English
Human Resources and Social Security Electronic Seal System Part 4:System Interface Specification
2022-03-23 -

LD/T 01.2-2022 in English
Human Resources and Social Security Electronic Seal System Part 2:Technical Specification of the Seal
2022-03-23 -

LD/T 02.3-2022 in English
Specifications for human resources and social security electronic authentication system-Part 3: Format specifications for digital certificate
2022-06-01 -

LD/T 02.1-2022 in English
Specifications for human resources and social security electronic authentication system-Part 1: Architecture specification
2022-06-01 -

LD/T 09-2022 in English
Specification for human resources and social security information system operation and maintenance platform construction
2022-09-30