GB/T 19771-2025Cybersecurity technology — Public key infrastructure — Specification for minimum interoperability for PKI components (English PDF)
网络安全技术 公钥基础设施 PKI组件最小互操作规范
Open the GB/T 19771-2025 preview as PDF
This is a limited preview
Buy now to download the full PDF (19 pages)
Issued by
SAMR; SAC
Level / Type
National · Recommended
Issue date
August 1, 2025
Implementation date
February 1, 2026
Scope
GB/T 19771-2025 is the English-translated version of 网络安全技术 公钥基础设施 PKI组件最小互操作规范.
GB/T 19771-2025 is the Chinese national standard covering the least a PKI component must do for another vendor's to interoperate with it — the basic functions of the CA system, the RA system, the certificate holder and the certificate verifier, the commercial cryptographic algorithms to be supported, the data formats of the registration request, the key update, the revocation request and the database access, and the test and evaluation methods that turn a claim of interoperability into something checkable. The test and evaluation methods of clause 7 are new: the 2005 edition set the requirements but not the way to check them. Issued on 1 August 2025, it has been in force since 1 February 2026, replacing GB/T 19771-2005.
Document preview — GB/T 19771-2025
National Standard of the People's Republic of China
- ICS
- 35.030
- Classification
- L 80
- Replacing
- GB/T 19771-2005
Issued by: State Administration for Market Regulation; Standardization Administration of the PRC
Contents
- PrefaceIII
- 1 Scope1
- 2 Normative references1
- 3 Terms and Definitions1
- 4 Abbreviations2
- 5 Minimum interoperability basic functional requirements3
- 5.1 Overview3
- 5.2 CA System3
- 5.3 RA System4
- 5.4 Certificate Holder5
- 5.5 Certificate Verifier5
- 5.6 Cryptographic Algorithms6
- 6 Interoperability Transaction Data Format Requirements6
- 6.1 General Requirements6
- 6.2 Registration Request6
- 6.3 Certificate Key Update10
- 6.4 Revocation Request1113
- 6.5 Accessing the Database13
- 7 Test and evaluation methods13
- 7.1 General test evaluation method13
- 7.2 Minimum interoperability basic function test evaluation method13
- 7.3 Interoperable Data Format Testing and Evaluation Methods15
Foreword
This document is in accordance with the provisions of GB/T 1.1-2020 "Guidelines for standardization work Part 1: Structure and drafting rules for standardization documents" Drafting.
This document replaces GB/T 19771-2005 "Information Technology Security Technology - Minimum Interoperability Specifications for Public Key Infrastructure (PKI) Components" Compared with GB/T 19771-2005, in addition to structural adjustments and editorial changes, the main technical changes are as follows.
a) The scope of the document has been changed, the standardization objects and the aspects covered have been redefined, and the applicable Use boundaries (see Chapter 1, Chapter 1 of the 2005 edition);
b) Changed the basic functional requirements of the four components of PKI (see Chapter 5, Chapter 5 of the 2005 edition), added BYOD request Functional requirements for certificates (see 5.3.2, 5.4.2), minimum steps for verifying certificates (see 5.2.2), and requirements for commercial Support for cryptographic algorithms (see 5.6);
c) Changed the requirements for the interoperability transaction data format, including the data structure of digital certificates, certificate extensions, and the format of certificate revocation lists.
The format requirements are modified to comply with GB/T 20518-2018 (see 6.1, 6.2, 6.3 of the 2005 edition); the PKI transaction message The requirements for the format and content have been modified to comply with GB/T 19714-2025 (see 6.1, 6.5 of the 2005 edition); the PKI transaction Message content (see Chapter 6, 6.6 of the 2005 edition);
d) Added test and evaluation methods for CA system, RA system, certificate holder and certificate verifier functions, and added interoperability data.
According to the format test evaluation method (see Chapter 7);
e) Deleted Normative Appendix A, Normative Appendix B, Normative Appendix C, Normative Appendix D (see Appendix A, Appendix D of the 2005 edition) B, Appendix C, Appendix D).
This document is proposed and coordinated by the National Cybersecurity Standardization Technical Committee (SAC/TC260).
This document was drafted by: University of Chinese Academy of Sciences, Beijing Digital Certification Co., Ltd., the Third Research Institute of the Ministry of Public Security, and the Software Research Institute of the Chinese Academy of Sciences.
Software Research Institute, Changchun Jida Zhengyuan Information Technology Co., Ltd., Anhui Xinke Gongchuang Information Security Evaluation Co., Ltd., Tsinghua University, Guangdong Provincial Electronic Commerce Certification Co., Ltd., Shenzhen Electronic Commerce Security Certificate Management Co., Ltd., Asia Information Technology (Shanghai) Co., Ltd., China Science Information Security Common Technology National Engineering Research Center Co., Ltd., China Unicom Online Information Technology Co., Ltd., Beijing Zhongguancun Laboratory, Qi'anxin Wangshen Information Technology (Beijing) Co., Ltd., Shaanxi Information Engineering Research Institute, National Information Technology Security Research Center, Zhongfu Information Co., Ltd., Hangzhou Hikvision Digital Technology Co., Ltd., China Electronics Information Industry Group Co., Ltd. Sixth Research Institute Research Institute, Changyang Technology (Beijing) Co., Ltd.
The main drafters of this document are: Feng Dengguo, Jing Jiwu, Liu Limin, Zheng Yajie, Chen Yan, Ding Zhaowei, Zhang Jianguo, Kou Chunjing, Zhang Liwu, Jia Keting, Zhang Yan, Qin Lingyue, Li Qiang, Chen Shule, Zheng Huitao, Wei Yicai, Hu Jianxun, Liang Bin, Zhao Boxin, Meng Jiaying, An Jincheng, Zhao Xiaorong, Liang Li, Chen Teng, Wang Bin, Wang Long, and Zhao Hua.
The previous versions of this document and the documents it replaces are as follows.
— First published in 2005 as GB/T 19771-2005;
— This is the first revision.
Cybersecurity Technology Public Key Infrastructure Minimum Interoperability Specifications for PKI Components
1 Scope
This document specifies the minimum interoperability requirements and data format requirements for public key infrastructure components, and describes the test and evaluation method.
This document applies to the design, development, testing and application of PKI in activities such as electronic signatures, electronic seals, and identity management.
2 Normative references
GB/T 15852.2
GB/T 19714-2025
GB/T 20518-2018
GB/T 25056-2018
GB/T 32905
GB/T 32907
GB/T 32918.2
GB/T 37092
GB/T 43694
3 Terms and Definitions
The terms and definitions defined in GB/T 25056-2018, GM/Z0001-2013 and the following apply to this document.
3.1
An element of the PKI system that is used to carry out certificate-related activities.
3.2 digital certificatedigitalcertificate
The certificate authority confirms the user's public key and identity information and signs the data with the private key.
Note. Also called public key certificate.
3.3 signaturecertificate
A digital certificate used to authenticate the signing public key. [Source. GM/Z0001-2013, 2.90]
......
This preview omits tables, figures, formulas and parts of the technical clauses. The complete document — 19 pages — is available in the English PDF.
Referenced standards
Normative references
- GB/T 19714-2025Cybersecurity technology — Public key infrastructure — Certificate management protocol
- GB/T 20518-2018Information security technology—Public key infrastructure—Digital certificate format
- GB/T 25056-2018Information security technology—Specifications of cryptograph and related security technology for certificate authentication system
- GB/T 32905Information security techniques - SM3 cryptographic hash algorithm
- GB/T 32907Information security technology - SM4 block cipher algorithm
- GB/T 32918.2Information security technology—Public key cryptographic algorithm SM2 based on elliptic curves—Part 2: Digital signature algorithm
GB/T 15852.2
Editions of GB/T 19771
| Edition | Title | Revision | Status |
|---|---|---|---|
| GB/T 19771-2025 | Cybersecurity technology - Public key infrastructure - Specification for minimum interoperability for PKI components | current edition | Current |
| GB/T 19771-2005 | Information technology -- Security technology -- Public key infrastructure -- Minimum interoperability specification for PKI components | previous edition | In force |
This page sells the current edition, GB/T 19771-2025. Earlier editions are listed for reference only.
How to Buy GB/T 19771-2025
- 1Add to cart. Click the "Buy GB/T 19771-2025" button on this page. You can add more standards before checkout.
- 2Checkout. Enter your email and billing details. Payment is processed securely by Stripe (cards, Apple Pay, Google Pay supported).
- 3Instant delivery (0–9 sec). Delivery is automatic: within seconds of payment you'll receive an email with a secure download link. The link stays valid for 72 hours.
- 4Invoice included. A tax invoice is attached to the confirmation email. Need a custom invoice? Contact us.
Related Standards
GB/T 19714-2025 — Cybersecurity technology — Public key infrastructure — Certificate management protocol
GB/T 20518-2018 — Information security technology—Public key infrastructure—Digital certificate format
GB/T 25056-2018 — Information security technology—Specifications of cryptograph and related security technology for certificate authentication system
Secure payment via Stripe
Payments accepted
GB/T 19771-2025
$335.00