US$879.00 ยท In stock Delivery: <= 6 days. True-PDF full-copy in English will be manually translated and delivered via email. GB/T 30272-2021: (Information Security Technology Public Key Infrastructure Standard Compliance Assessment) Status: Valid GB/T 30272: Evolution and historical versions
Standard ID | Contents [version] | USD | STEP2 | [PDF] delivered in | Standard Title (Description) | Status | PDF |
GB/T 30272-2021 | English | 879 |
Add to Cart
|
6 days [Need to translate]
|
(Information Security Technology Public Key Infrastructure Standard Compliance Assessment)
| Valid |
GB/T 30272-2021
|
GB/T 30272-2013 | English | RFQ |
ASK
|
7 days [Need to translate]
|
Information security technology -- Public Key Infrastructure -- Testing and evaluation guide on standard conformance
| Obsolete |
GB/T 30272-2013
|
PDF similar to GB/T 30272-2021
Basic data Standard ID | GB/T 30272-2021 (GB/T30272-2021) | Description (Translated English) | (Information Security Technology Public Key Infrastructure Standard Compliance Assessment) | Sector / Industry | National Standard (Recommended) | Classification of Chinese Standard | L80 | Word Count Estimation | 44,477 | Issuing agency(ies) | State Administration for Market Regulation, China National Standardization Administration |
GB/T 30272-2021: (Information Security Technology Public Key Infrastructure Standard Compliance Assessment) ---This is a DRAFT version for illustration, not a final translation. Full copy of true-PDF in English version (including equations, symbols, images, flow-chart, tables, and figures etc.) will be manually/carefully translated upon your order.
(Information Security Technology Public Key Infrastructure Standard Compliance Assessment)
ICS 35.030
CCSL80
National Standards of People's Republic of China
Replacing GB/T 30272-2013
Information Security Technology
Public Key Infrastructure Standard Compliance Assessment
Published on 2021-10-11
2022-05-01 Implementation
State Administration for Market Regulation
Released by the National Standardization Administration
directory
Preface III
Introduction IV
1 Scope 1
2 Normative references 1
3 Terms and Definitions 1
4 Abbreviations 1
5 Online Certificate Status Protocol Assessment 2
5.1 General 2
5.2 Security Considerations 4
6 Certificate Management Protocol Assessment 4
6.1 Required PKI management functions4
6.2 Transmission 7
6.3 Mandatory PKI management message structure 7
7 Component Minimum Interoperability Specification Evaluation 8
7.1 Component Specification 8
7.2 Data format 11
8 Digital Certificate Format Assessment 14
8.1 Data structure of the basic certificate field 14
8.2 TBSCertificate and its data structure 14
8.3 Certificate extensions 16
9 Time Stamp Specification Evaluation 21
9.1 Generation and issuance of timestamps 21
9.2 Management of Timestamps 23
9.3 Format of Timestamps 24
9.4 Security of time stamping systems 27
10 Electronic Signature Format Assessment 29
10.1 Basic Data Format 29
10.2 Validation data format 29
10.3 Signature Policy Requirements 30
11 Evaluation of reliable electronic signature generation and verification technology based on digital certificate 30
11.1 Requirements for data related to electronic signatures 30
11.2 Requirements for the Signature Generation Module 31
11.3 Electronic Signature Generation Process and Application Requirements 31
11.4 Electronic Signature Verification Process and Application Requirements 32
12 Comprehensive evaluation 33
Appendix A (Informative) General Table of Test Items 35
Appendix B (Informative) Example of a PKI Test Environment 38
Reference 39
foreword
This document is in accordance with the provisions of GB/T 1.1-2020 "Guidelines for Standardization Work Part 1.Structure and Drafting Rules of Standardization Documents"
drafted.
This document replaces GB/T 30272-2013 "Guidelines for Conformance Testing and Evaluation of Information Security Technology Public Key Infrastructure Standards", and
Compared with GB/T 30272-2013, in addition to editorial changes, the main technical changes are as follows.
--- Deleted "Specific Authority Management Center Technical Specification Evaluation" (see 4.5 of the.2013 edition);
--- Changed the relevant content in "Digital Certificate Format Evaluation" (see Chapter 8, 4.4 of the.2013 edition);
--- Added "evaluation of electronic signature format" (see Chapter 10);
--- Added "Reliable Electronic Signature Generation and Verification Technology Evaluation Based on Digital Certificates" (see Chapter 11).
Please note that some content of this document may be patented. The issuing agency of this document assumes no responsibility for identifying patents.
This document is proposed and managed by the National Information Security Standardization Technical Committee (SAC/TC260).
This document was drafted by. Shanghai Chenrui Information Technology Co., Ltd., the Third Research Institute of the Ministry of Public Security, the Research Institute of Data and Communication Protection of the Chinese Academy of Sciences
Education Center, Beijing Digital Certification Co., Ltd., Geer Software Co., Ltd., the 15th Research Institute of China Electronics Technology Group Corporation (Information
Information Industry Information Security Evaluation Center).
The main drafters of this document. Qiu Zihua, Chen Yan, Li Qian, Liu Limin, Lu Na, Zheng Qiang, Fu Dapeng, Wang Luhan, Shao Xudong, Chen Jiaming, Gu Liu,
Zhao Xinyi, Yuan Quan, Liu Zhong, Xu Jun, Liu Jian.
The previous versions of this document and its superseded documents are as follows.
---First published in.2013 as GB/T 30272-2013;
---This is the first revision.
Introduction
This document is used to guide test evaluators to test and evaluate whether public key infrastructure meets the requirements of national standards.
This document is based on seven public key infrastructure standards that have been promulgated and implemented by the country, namely.
---GB/T 19713-2005 Information Technology Security Technology Public Key Infrastructure Online Certificate Status Protocol
---GB/T 19714-2005 Information Technology Security Technology Public Key Infrastructure Certificate Management Protocol
---GB/T 19771-2005 Information Technology Security Technology Public Key Infrastructure PKI Components Minimum Interoperability Specification
---GB/T 20518-2018 Information Security Technology Public Key Infrastructure Digital Certificate Format
---GB/T 20520-2006 Information Security Technology Public Key Infrastructure Timestamp Specification
---GB/T 25064-2010 Information Security Technology Public Key Infrastructure Electronic Signature Format Specification
---GB/T 35285-2017 Information security technology public key infrastructure based on digital certificate-based reliable electronic signature generation and
Verify technical requirements
These seven criteria describe the corresponding evaluation test methods in detail.
Information Security Technology
Public Key Infrastructure Standard Compliance Assessment
1 Scope
This document describes the testing and evaluation methods of related components of public key infrastructure, including CA, RA, timestamp subsystem, online certificate status
Status query subsystem, electronic signature and verification subsystem, client and other components.
This document applies to national standards GB/T 19713-2005, GB/T 19714-2005, GB/T 19771-2005,
GB/T 20518-2018, GB/T 20520-2006, GB/T 25064-2010, GB/T 35285-2017
Testing and evaluation of related components of category public key infrastructure.
2 Normative references
The contents of the following documents constitute essential provisions of this document through normative references in the text. Among them, dated citations
documents, only the version corresponding to that date applies to this document; for undated references, the latest edition (including all amendments) applies to
this document.
GB/T 19713-2005 Information Technology Security Technology Public Key Infrastructure Online Certificate Status Protocol
GB/T 19714-2005 Information Technology Security Technology Public Key Infrastructure Certificate Management Protocol
GB/T 19771-2005 Information Technology Security Technology Public Key Infrastructure PKI Components Minimum Interoperability Specification
GB/T 20518-2018 Information Security Technology Public Key Infrastructure Digital Certificate Format
GB/T 20520-2006 Information Security Technology Public Key Infrastructure Timestamp Specification
GB/T 25064-2010 Information Security Technology Public Key Infrastructure Electronic Signature Format Specification
GB/T 25069-2010 Information Security Technical Terminology
GB/T 35275-2017 Information Security Technology SM2 Cryptographic Algorithm Encrypted Signature Message Syntax Specification
GB/T 35285-2017 Information Security Technology Public Key Infrastructure Reliable Electronic Signature Generation and Verification Technology Based on Digital Certificate
technical requirements
3 Terms and Definitions
GB/T 19713-2005, GB/T 19714-2005, GB/T 19771-2005, GB/T 20518-2018, GB/T 20520-
Terms and definitions defined in.2006, GB/T 25064-2010, GB/T 35285-2017, GB/T 25069-2010 apply to this document.
4 Abbreviations
The following abbreviations apply to this document.
Tips & Frequently Asked Questions:Question 1: How long will the true-PDF of GB/T 30272-2021_English be delivered?Answer: Upon your order, we will start to translate GB/T 30272-2021_English as soon as possible, and keep you informed of the progress. The lead time is typically 4 ~ 6 working days. The lengthier the document the longer the lead time. Question 2: Can I share the purchased PDF of GB/T 30272-2021_English with my colleagues?Answer: Yes. The purchased PDF of GB/T 30272-2021_English will be deemed to be sold to your employer/organization who actually pays for it, including your colleagues and your employer's intranet. Question 3: Does the price include tax/VAT?Answer: Yes. Our tax invoice, downloaded/delivered in 9 seconds, includes all tax/VAT and complies with 100+ countries' tax regulations (tax exempted in 100+ countries) -- See Avoidance of Double Taxation Agreements (DTAs): List of DTAs signed between Singapore and 100+ countriesQuestion 4: Do you accept my currency other than USD?Answer: Yes. If you need your currency to be printed on the invoice, please write an email to [email protected]. In 2 working-hours, we will create a special link for you to pay in any currencies. Otherwise, follow the normal steps: Add to Cart -- Checkout -- Select your currency to pay. Question 5: Should I purchase the latest version GB/T 30272-2021?Answer: Yes. Unless special scenarios such as technical constraints or academic study, you should always prioritize to purchase the latest version GB/T 30272-2021 even if the enforcement date is in future. Complying with the latest version means that, by default, it also complies with all the earlier versions, technically.
|