Valid

GB/T 19714-2025Cybersecurity technology — Public key infrastructure — Certificate management protocol (English PDF)

网络安全技术 公钥基础设施 证书管理协议

Open the GB/T 19714-2025 preview as PDF

Preview — first pages of GB/T 19714-2025 (full document: 49 pages)

This is a limited preview

Buy now to download the full PDF (49 pages)

Issued by

SAMR; SAC

Level / Type

National · Recommended

Issue date

August 1, 2025

Implementation date

February 1, 2026

Scope

GB/T 19714-2025 is the English-translated version of 网络安全技术 公钥基础设施 证书管理协议.

GB/T 19714-2025 is the Chinese national standard covering the messages exchanged when a certificate is issued, updated or withdrawn — the flows between terminal, registration authority, certification authority, key management system and database, the structures for initial registration, certificate request, key update, and certificate freeze and thaw, the proof of possession that stops a requester claiming a private key it does not hold, and the SM2 enveloped key that carries every encrypted field. At 29,500 words. Issued on 1 August 2025, it has been in force since 1 February 2026, replacing GB/T 19714-2005.

Document preview — GB/T 19714-2025

National Standard of the People's Republic of China

ICS
35.030
Classification
L 80
Replacing
GB/T 19714-2005

Issued by: State Administration for Market Regulation; Standardization Administration of the PRC

Contents

  • PrefaceIII
  • 1 Scope1
  • 2 Normative references1
  • 3 Terms and Definitions1
  • 4 Abbreviations2
  • 5 General Principles2
  • 6 Process and Message Structure3
  • 6.1 Protocol between terminal and RA system3
  • 6.2 Protocol between RA system and CA system4
  • 6.3 Agreement between CA system and KM system6
  • 6.4 Protocol between CA system and database12
  • 6.5 Protocol between terminal and database14
  • Appendix A (Normative) Mandatory Certificate Management Message Structure22
  • A.1 Overview22
  • A.2 General Rules for Interpreting Message Structures22
  • A.3 Algorithm using parameters22
  • A.4 Proof of Ownership Message Structure23
  • A.5 Initial Registration/Authentication (Basic Authentication Scheme)23
  • A.6 Certificate Request28
  • A.7 Key Update Request28
  • Appendix B (Informative) Optional Certificate Management Message Structure29
  • B.1 Overview29
  • B.2 General Rules for Structural Interpretation29
  • B.3 Algorithm Parameters29
  • B.4 PKI Information Request/Response29
  • B.5 Initialization using external identity certificates30
  • Appendix C (Normative) PKI Message Data Structure32
  • C.1 PKI Message Overview32
  • C.2 Common Data Structures36
  • C.3 Specific Operation Data Structure41
  • Appendix D (Informative) Version Negotiation47
  • D.1 General Principles47
  • D.2 Clients that communicate with the GB/T 19714-2005 server47
  • D.3 Server receiving GB/T 19714-2005 version message47
  • Appendix E (Informative) Using a “Passphrase”48
  • Appendix F (Informative) Certificate Management Protocol ASN.1 Description49
  • Reference57

Foreword

This document is in accordance with the provisions of GB/T 1.1-2020 "Guidelines for standardization work Part 1: Structure and drafting rules for standardization documents" Drafting.

This document replaces GB/T 19714-2005 "Information Technology Security Technology Public Key Infrastructure Certificate Management Protocol".

Compared with GB/T 19714-2005, in addition to structural adjustments and editorial changes, the main technical changes are as follows.

a) The scope of the standard has been changed (see Chapter 1, Chapter 1 of the 2005 edition);

b) Deleted the PKI management overview (see Chapter 5 of the 2005 edition);

c) Deleted the content related to proof of possession of encryption key and private key (see 6.3.2 and 7.2.8 of the 2005 edition) and proof of possession of negotiation key and private key.

Content (see 6.3.3 of the 2005 edition);

d) Deleted the content related to root CA updates (see 6.4 and 8.2 of the 2005 edition);

e) Deleted the prerequisites and restrictions related to terminal entity initialization and initial registration/authentication (see Chapter 6 of the 2005 edition);

f) Added "Process and Message Structure" to describe the process and message structure of certificate management between PKI components (see Chapter 6);

g) Added national standard algorithms and algorithm OIDs supported by the protocol (see Table A.1 in Appendix A);

h) Added the description of "transactionID" (see C.1.2.1 of Appendix C);

i) Added the setting of the protocol version field value (see C.1.2.1);

j) Added the "implicit confirmation" data structure (see C.1.2.2) and the "confirmation waiting time" data structure (see C.1.2.3);

k) Added support for the certificate template identifier "certTemplateID" field in the generalInfo extension of PKIHead (see C.1.2.4);

l) Added descriptions on “multiple protection” (see C.1.4);

m) The encrypted value data structure has been changed to "SM2EnvelopedKey" (see C.2.2, 7.2.2 of the 2005 edition), and the protocol has been added Encrypted data is uniformly changed to use "SM2EnvelopedKey" (see C.3.2, 6.2.2, 7.3.2, Appendix E of the 2005 edition);

n) Added content related to certificate confirmation (see C.1.3, C.3.15);

o) Added "Polling Request and Response" data structures (see C.3.19);

p) Added content related to certificate freeze and certificate thawing requests and responses (see C.1.3, C.3.20, and C.3.21);

q) added more information on failure conditions (see C.2.3);

r) Added support for applying for multiple certificates using CertReqMessages and for requesting multiple certificates using CertRepMessage There are multiple implementation options for response, clarifying that there are multiple options for implementation (see C.3.1 and C.3.2), clarifying a Common implementation methods (see A.5);

s) Deleted the content related to cross-certification (see 7.3.11, 7.3.12, and 8.6 of the 2005 edition);

t) Deleted the PKI management functions related to CA initialization and terminal entity initialization (see Chapter 8 of the 2005 edition);

u) Deleted the transmission-related content of the CMP protocol (see Chapter 9 and Appendix G of the 2005 edition);

v) Deleted "Request Message Behavior Description" (see Appendix D of the 2005 edition) and incorporated its main content into Appendix C (see C.2.8, C.3.1);

w) The certificate management protocol OID has been changed (see Appendix F of the 2005 edition).

Please note that some of the contents of this document may involve patents. The issuing organization of this document does not assume the responsibility for identifying patents.

This document is proposed and coordinated by the National Cybersecurity Standardization Technical Committee (SAC/TC260).

This document was drafted by: Beijing Digital Certification Co., Ltd., China Electronics Technology Standardization Institute, Xi'an Xidian Jietong Wireless Network Network Communications Co., Ltd., Boya Zhongke (Beijing) Information Technology Co., Ltd., Changchun Jida Zhengyuan Information Technology Co., Ltd., Shanghai Municipal Digital Certificate Certification Center Co., Ltd., Huawei Technologies Co., Ltd., Wuhan University, the First Research Institute of the Ministry of Public Security, and Asiasoft Information Technology (Shanghai) Co., Ltd., Changyang Technology (Beijing) Co., Ltd., Shenzhen E-Commerce Security Certificate Management Co., Ltd., Shaanxi Provincial Information Engineering Research Institute, Jiangnan Xinan (Beijing) Technology Co., Ltd., Zhengzhou Xindajiean Information Technology Co., Ltd., Tsinghua University, Geer Software Co., Ltd.

Co., Ltd., Guangdong Electronic Commerce Certification Co., Ltd., Tongzhi Weiye Software Co., Ltd., Beijing Times Newway Information Technology Co., Ltd.

Beijing Zhongguancun Laboratory, Zhejiang Dahua Technology Co., Ltd., and the Cybersecurity Industry Development Center of the Ministry of Industry and Information Technology (MIIT).

Information Center of the Ministry of Information Technology), Gongxintong (Beijing) Information Technology Co., Ltd., the Sixth Research Institute of China Electronics Information Industry Group Co., Ltd., State Grid Blockchain Technology (Beijing) Co., Ltd., China Science and Technology Information Security Common Technology National Engineering Research Center Co., Ltd., Digital Security Times Technology Co., Ltd.

Co., Ltd., Qi'anxin Wangshen Information Technology (Beijing) Co., Ltd., and China Electronics Technology Group Corporation Network Security Technology Co., Ltd.

The main drafters of this document are: Gao Wenhua, Gao Wenju, Li Yanfeng, Li Qin, Wang Bingxin, Ding Zhaowei, Wang Yulin, Zeng Guang, He Debiao, Hu Guangjun, Lin Xueyan, Xia Luning, Xia Bingbing, Li Xiangfeng, Fu Dapeng, Liu Zhong, Wang Yuehui, Zhang Guoqiang, Li Zhiyong, Tian Yucun, Li Liang, Guo Yanfei, Ding Beijing, Deng Chen, Liu Bin, Zhao Jing, Zhang Ziwei, Wei Yicai, Zhao Hua, Shen Zhichun, Zhang Xin, Su Jinyan, Wang Zhihui, Zheng Huitao, Zhao Xiaorong, Xu Jiannan, Wang Tong, Wang Haiyang, Liu Weihua, Jia Keting, Zheng Qiang, Chen Shule, Jiao Zhengkun, Yu Zhengchen, Zhu Weiru, Zhao Boxin, Zhang Jianqing, Chen Zixiong, Wang Jin, Wang Bin, Wang Long, Yang Ke, Gao Zhenpeng, Du Zhiqiang, An Jincheng, and Kou Jianbo.

The previous versions of this document and the documents it replaces are as follows.

— First published in 2005 as GB/T 19714-2005;

— This is the first revision.

Cybersecurity Technology Public Key Infrastructure Certificate Management Protocol

1 Scope

This document provides the structure and content of the certificate management protocol in the public key infrastructure (PKI), and specifies the requirements for certificate generation and management. The protocol message format.

This document is applicable to the research and development of public key infrastructure related products, and is used to guide the design, development and manage.

2 Normative references

GB/T 19713

GB/T 20518-2018

GB/T 25056

GB/T 25069-2022

GB/T 33560

GB/T 35276-2017

3 Terms and Definitions

The terms and definitions defined in GB/T 25069-2022 and the following apply to this document.

3.1 digital signature

The receiver of the data unit is used to confirm the source and integrity of the data unit to protect the data and prevent it from being forged.

Some data on a data unit, or a cryptographic transformation of a data unit.

[Source. GB/T 25069-2022, 3.576, modified]

3.2 hash-algorithm

A cryptographic algorithm based on a hash function.

3.3

The terminal is used to securely store certificates and private keys.

3.4 proof of possession; POP

The terminal uses this to prove that it owns (i.e. can use) the private key corresponding to the public key for which it applies for the certificate.

......
This preview omits tables, figures, formulas and parts of the technical clauses. The complete document — 49 pages — is available in the English PDF.

Referenced standards

Editions of GB/T 19714

EditionTitleRevisionStatus
GB/T 19714-2025Cybersecurity technology - Public key infrastructure - Certificate management protocolcurrent editionCurrent
GB/T 19714-2005Information technology -- Security technology -- Internet public key infrastructure -- Certificate management protocolprevious editionIn force

This page sells the current edition, GB/T 19714-2025. Earlier editions are listed for reference only.

How to Buy GB/T 19714-2025

  1. 1Add to cart. Click the "Buy GB/T 19714-2025" button on this page. You can add more standards before checkout.
  2. 2Checkout. Enter your email and billing details. Payment is processed securely by Stripe (cards, Apple Pay, Google Pay supported).
  3. 3Instant delivery (0–9 sec). Delivery is automatic: within seconds of payment you'll receive an email with a secure download link. The link stays valid for 72 hours.
  4. 4Invoice included. A tax invoice is attached to the confirmation email. Need a custom invoice? Contact us.

Related Standards

English PDF
49 pages
Instant delivery (0–9 sec)
Invoice included
View Cart

Secure payment via Stripe

Payments accepted

VisaMastercardAmerican ExpressApple PayGoogle PayStripe

GB/T 19714-2025

$875.00

$745.00for partners