Sign In |Help & Support
ALL SECTORS
  • ALL SECTORS
  • GB(National Standard)
  • CB(Shipping)
  • CECS(Engineering Construction)
  • CJ(Urban Construction)
  • CY(News and Publication)
  • DB(Provincial Standard)
  • DL(Electricity & Power)
  • DZ(Geology & Mineralogy)
  • FZ(Spinning & Textile)
  • GA(Public Security)
  • HB(Aviation)
  • HG(Chemical Industry)
  • HJ(Environmental Protection)
  • JB(Machinery)
  • JC(Building Materials)
  • JG(Building & Construction)
  • JJ(Metering)
  • JT(Highway & Transportation)
  • LY(Forestry)
  • MT(Coal)
  • NB(Energy)
  • NY(Agriculture)
  • QB(Light Industry)
  • QC(Automobile & Vehicle)
  • QJ(Aerospace)
  • SH(Petrochemical)
  • SJ(Electronics)
  • SL(Water Resources)
  • SN(Commodity Inspection)
  • SY(Oil & Gas)
  • TB(Railway & Train)
  • YB(Ferrous Metallurgy)
  • YC(Tobacco)
  • YD(Telecommunication)
  • YY(Medical Device)
Database: 365,228(8 Aug 2026)
civil aviation mobile applications core security requirements security civil aviation administration civil aviation introduction standard background mobile application program description units wavelength primary standard flame smelting furnaces
MH/T 0068-2018 in English

MH/T 0068-2018 in English

VALID

Security testing guide for mobile application program of civil aviation

  • Issued on:2018-12-14
  • Implemented on:2019-04-01
  • File Format:PDF
  • Delivery:Via email within 1~3 business days
Price(USD): $250.00
$243.00
Standard No: MH/T 0068-2018
Document status: VALID
Title in English: Security testing guide for mobile application program of civil aviation
Title in Chinese: 民用航空移动应用程序安全测评指南
Language: English
File Format: Electronic (PDF)
Delivery: Via email within 1~3 business days
Issued on: 2018-12-14
Implemented on: 2019-04-01
Professional Classification: MH-Civil Aviation
Related Keywords: civil aviation mobile applications
core security requirements security
civil aviation administration
civil aviation introduction standard background
mobile application program
Related Topics: evaluation
application
Safety Evaluation
Evaluation Standards
Immigrate to outer space
immigration space
mh/t 4049-2018
Mobile Application Security
The whole program is blank
Mobile air conditioner safety
t/csee0068-2018
t/cwan 0068
t/cpcif 0068


Introduction

Standard Background and Scope of Application

MH/T 0068-2018 was proposed by the Civil Aviation Administration of China to establish a standardized framework for the safety assessment of civil aviation mobile applications. The standard applies to civil aviation mobile applications classified as Level 2 and Level 3 by GB/T 22240, covering typical scenarios such as air travel services and airport operations.


Analysis of core security requirements

Security domain Key control points Evaluation method
Identity authentication Two-factor authentication, login failure lock, forced modification of initial password Manual inspection + penetration testing
Access control Principle of least privilege, separation of privileges, protection against unauthorized access Permission matrix review + interface testing
Data security Transmission encryption, storage encryption, residual information removal Traffic packet capture analysis + storage detection

Typical implementation case

Case:During the penetration test of a certain airline check-in APP, it was found that:
1. The unencrypted passenger ID number field was intercepted using Burp Suite
2. Unauthorized viewing of other people’s itineraries was achieved by modifying HTTP parameters
Corrective measures:Use the national secret SM4 algorithm to encrypt sensitive fields and increase the server-side permission verification layer


Evaluation implementation process

  1. Preparation stage:Determine the scope of the evaluation (it is recommended to include ≥3 typical business modules)
  2. Tool selection:It is recommended to use a combination of MobSF static scanning + OWASP ZAP dynamic testing
  3. Risk control:The test data must use desensitized simulated data
  4. Report output:It must include the vulnerability CVSS score and repair priority recommendations

Technology Evolution Trends

As civil aviation mobile applications develop towards mini-programs, subsequent versions of the standard need to supplement:
1. Security detection items for cross-platform frameworks (such as Flutter)
2. Application specifications for biometric authentication in check-in scenarios
3. Communication security requirements in 5G network environments

Sample only — not a preview of MH/T 0068-2018
Page: 1 / 0
100%

Loading PDF document...

Error loading PDF. Please make sure the file is valid and try again.

We also recommend