GB/T 20279-2024Cybersecurity technology - Technical specification for network and terminal separation products (English PDF)
网络安全技术 网络和终端隔离产品技术规范
Open the GB/T 20279-2024 preview as PDF
This is a limited preview
Buy now to download the full PDF (39 pages)
Issued by
SAMR; SAC
Level / Type
National · Recommended
Issue date
September 29, 2024
Implementation date
April 1, 2025
Scope
GB/T 20279-2024 is the English-translated version of 网络安全技术 网络和终端隔离产品技术规范.
GB/T 20279-2024 covers network and terminal separation products, setting out how they are classified, how their requirements are graded, what they have to do and how a laboratory checks it. Two families are recognised: terminal separation products, that is isolation cards and isolation computers, and network separation products, the latter split into protocol conversion products, gaps and network unilateral transmission products. The document applies to the design, development and testing of such products. Requirements are organised in four blocks, security functions, self-security, performance and security assurance, and each block is divided into a basic grade and an enhanced grade, the enhanced grade adding or strengthening items. Clause 7 mirrors clause 6 with an evaluation method for every requirement, each written as evaluation content, expected result and rule of judgement. Annex A maps the requirements to the two grades for each of the four product families, and Annex B does the same for the evaluation methods. The document replaces GB/T 20279-2015 and GB/T 20277-2015, merging a requirements standard and a test method standard into a single text, and was issued on 29 September 2024 for implementation on 1 April 2025.
Document preview — GB/T 20279-2024
National Standard of the People's Republic of China
- ICS
- 35.030
- Classification
- L 80
- Replacing
- GB/T 20279-2015, GB/T 20277-2015
Issued by: State Administration for Market Regulation; Standardization Administration of the PRC
Contents
- 1 Scope1
- 2 Normative references1
- 3 Terms and definitions1
- 4 Abbreviations2
- 5 General3
- 6 Security technical requirements5
- 6.1 Security function requirements5
- 6.2 Self-security requirements9
- 6.3 Performance requirements10
- 6.4 Security assurance requirements11
- 7 Evaluation methods13
- 7.1 Security function evaluation13
- 7.2 Self-security evaluation23
- 7.3 Performance evaluation26
- 7.4 Security assurance evaluation26
- Annex A (normative) Classification of network and terminal separation products and grading of security technical requirements33
- Annex B (normative) Classification of network and terminal separation products and grading of evaluation methods39
3 Terms and definitions
3.2 Physical disconnection is defined as the technique of using physical means to make sure that different security domains cannot be connected either directly or indirectly. The note adds that physical disconnection is applied both to physical conduction and to physical storage.
3.3 Protocol conversion is the technique of stripping the application data out of a public network protocol and encapsulating it in a private protocol proprietary to the system for transmission.
3.4 Information ferry is the data transmission technique in which information travels from the security domain of the source to an intermediate buffer area and then from that buffer area to the security domain of the destination. At any instant the buffer area is connected to one side only.
3.5 A unilateral transmission unit is a matched pair of independent sending and receiving parts, the sending part providing only a sending function and the receiving part only a receiving function; the note states that these functions are determined by physical characteristics.
3.6 to 3.10 define terminal separation products, network separation products, protocol conversion products, the gap, and network unilateral transmission products.
5 General
Network and terminal separation products fall into two families. Terminal separation products are isolation cards or isolation computers. Network separation products are divided by form and function into protocol conversion products, gaps and network unilateral transmission products; protocol conversion products and gaps are also commonly called security isolation and information exchange systems or products.
The functional aim of the whole family is to set a controlled point between different network security domains and to offer access-controlled services between them. The assets protected are the network services and resources covered by the security policy, and the product itself together with the important information held inside it.
A terminal separation product is normally an isolation card fitted into a host. An electronic switch connects, in mutually exclusive fashion, either security domain A with its hard disk 1 or security domain B with its hard disk 2, which is how the physical disconnection of the two domains is obtained. The card can also be integrated into the host so that the product takes the form of an isolation computer. This family achieves physical disconnection only by controlling the switching of the card.
A protocol conversion product is normally built as a double host: an internal processing unit, an external processing unit and a private protocol communication medium joining the two. That medium is the only physical channel trusted between the two security domains; it strips off TCP/IP and other public network protocols and carries a private protocol instead. The product provides application proxy service, protocol conversion, access control, information filtering and data exchange.
A gap is built in the same way but adds a dedicated isolation component acting as the intermediate buffer area: an isolation exchange board built around a dedicated isolation chip that contains an electronic switch and has the information ferry control logic fixed in it. The product provides application proxy service, information ferry, access control, information filtering and data exchange.
A network unilateral transmission product is a double host plus a unilateral transmission unit: a data sending processing unit, a data receiving processing unit and the unit itself. The sending unit connects to sending domain A and the receiving unit to receiving domain B, and information flows one way only, with no feedback signal of any kind. The one-way physical transmission characteristic is fixed and cannot be altered; no software configuration or physical jumper can change the characteristic or the direction.
Network separation products may also appear as a front-end server, a protocol conversion product or gap or network unilateral transmission product, and a back-end server. The front and back servers mainly provide application proxy, access control and attack protection, while the middle element provides network isolation and data exchange.
Security function, self-security, performance and security assurance requirements are each divided into a basic grade and an enhanced grade. The strength of the security functions and of the self-security, together with the level of the assurance requirements, are the criteria for the division; compared with the basic grade the enhanced grade adds or strengthens items. The requirements applicable to each product family and their grading are given in Annex A, and the evaluation methods and their grading in Annex B.
6.1 Security function requirements
6.1.1.1 Information flow control policy: when switching the isolated computer information resources the product makes the user enter a switching password; before business data is transmitted the accessing user or device is authenticated, either by password, digital certificate or biometric information, or by a combination of two or more factors.
6.1.1.2 Information flow control function: the product cuts the internal and external domains apart in physical transmission so that the outside cannot enter the inside over a network connection and inside information cannot leak outward. In physical storage the two network environments are also cut apart: volatile parts such as memory and registers are zeroed on switching, non-volatile devices such as hard disks and memory cards keep internal and external information on separate storage devices, and for removable media such as optical discs, floppy disks and USB storage the user is prompted to intervene, or the device is forbidden, before the domain is switched. Access control policy elements include IP address, port and protocol type, TCP, UDP and application layer protocols among them, and by default the product refuses all data transmission. Further items cover data synchronisation tasks, proxy reception, timed periodic transmission, protocol conversion with a private protocol carrying a consistency check, physical time-division switching of the internal and external links so that both networks are never connected to the dedicated isolation component at once, and construction by physical means of the single one-way channel with no reverse transmission or feedback.
6.1.1.3 to 6.1.1.8 add illegal external connection detection with alarm, consistency of the switching signal, detection and alarm on illegal swapping of the hard disks, physical isolation of memory and of all USB ports where the product is a whole-machine isolation system, non-bypassability of the security policy check, and object reuse, under which a newly allocated resource carries no content from any earlier connection.
6.1.2 Application and protocol support: at least two of each type are supported, drawn from file transfer protocols such as HTTP, FTP and SMB, mail protocols such as SMTP and POP3, database protocols, audio and video protocols such as SIP and RTSP, industrial control protocols such as Modbus and OPC, internet of things protocols such as MQTT and JMS, service invocation protocols such as API and Web services, and encrypted protocols such as HTTPS and FTPS. Which of these apply depends on the product family and its field of use.
6.1.3 Information filtering is specified per protocol family: command filtering, keyword filtering of the transmitted content, file type filtering, and, for image files, recognition and filtering of non-image data hidden inside them; for mail, protocol conformance checking and keyword filtering of subject and attachments plus attachment type filtering; for databases, command filtering, keyword filtering and, as a recommendation, masking of table field content; for audio and video, signalling filtering and, as a recommendation, filtering by media coding format; and matching provisions for industrial control, internet of things, service invocation and encrypted protocols.
6.1.4 to 6.1.8 cover sensitivity labels with mandatory access control, denial of service attack protection against ICMP flood, SYN flood, UDP flood and ping of death, malicious code protection with a signature library, security isolation split into domain isolation and label isolation, high availability split into a main and standby failover mode and a cluster mode, and data integrity in storage and in transmission.
6.1.9 Security audit and analysis: the recorded event types are access requests matched by the policy, access requests blocked by the policy, and detected attacks. Log content includes the date and time, the subject, object and description, with packet logs carrying protocol type, source and destination address and source and destination port, and a description of the attack. Logs are reachable by the authorised administrator only, can be queried by date, time, subject and object, are held on non-volatile storage for not less than six months, raise an alarm to the administrator when the storage threshold is reached, and can be backed up automatically to other storage. Alarms merge repeated identical events to avoid an alarm storm and are delivered by sound and light, screen prompt, mail or short message, carrying subject, object, description, level, date and time. Statistics are shown on a graphical interface by IP, time span and application type, by attack event type, IP and time span, and by processor, memory and disk occupancy, with report output.
6.1.10 to 6.1.12 add an interconnection interface for sharing information with other security devices, operation in an IPv6 environment and in a dual IPv4 and IPv6 stack environment, and, where the internal or external host supports it, deployment in a virtualised environment with unified platform management and elastic resource adjustment.
6.2 Self-security requirements
6.2.1 Identification and authentication: user identities are uniquely identified; authentication information is protected in storage and transmission by cryptographic means; login failure handling limits consecutive illegal attempts; a session that times out is closed automatically; the mechanism resists replay. Where passwords are used, complexity is checked and periodic change can be set, the stated complexity being a combination of at least three of upper case letters, lower case letters, digits and special characters, longer than eight positions. Default passwords prompt the user to change them, with forced change or password setting at first management of the product. Authorised administrators are authenticated by two or more combined techniques.
6.2.2 Management capability: setting and modification of security management parameters, setting, query and modification of security policies, management of audit logs, updating of the product software and of its signature libraries with the upgrade secured, synchronisation of logs to a log server by protocols such as SYSLOG, time synchronisation with an external time server, allocation of accounts and privileges with administrator roles that constrain one another, and a check on the effectiveness of the security policy.
6.2.3 Management audit: logging of account login and logout, system start, configuration change, addition, deletion or modification of administrators, and saving or clearing of audit logs; alarms on abnormal states of the product and its components such as excessive processor or memory occupancy or abnormal internal communication; log records carrying date and time, event type, subject and result; storage on non-volatile media for not less than six months; and protection of the logs against unexpected deletion, modification, overwriting or loss.
6.2.4 Management mode: local management, for example through a console port; separate management of the internal and external hosts connected to the different security domains; restriction of the source IP address for remote management over a network interface; confidentiality and integrity of the remote management traffic; and separation of the management interface from the business interface.
6.2.5 Supporting system security: no superfluous components or network services; no loss of security policy or log information on restart; and no publicly disclosed vulnerability of medium risk or above, the risk grading being referred to the national guide on classification and grading of network security vulnerabilities such as GB/T 30279.
6.3 Performance requirements
6.3.1 Throughput at network layer differs with the rate class of the product. For a 1518 byte packet, a 100 megabit product reaches not less than 100 Mb/s, a gigabit product not less than 1 Gb/s, and a high performance product not less than 8 Gb/s.
6.3.2 Latency likewise differs with the rate class. The introductory sentence states that, with no packet loss, a 100 megabit product does not exceed 10 ms and gigabit and 10 gigabit products do not exceed 5 ms. The lettered items that follow read: for a 1518 byte packet the average latency of a 100 megabit product is not greater than 10 ms, and that of gigabit and high performance products not greater than 5 ms.
6.4 Security assurance requirements
6.4.1 Development covers four deliverables. The security architecture description matches the scope of the security function description in the design document and fully describes the self-protection and non-bypass mechanisms. The functional specification describes the security functions defined in 6.1 and 6.2 for the product type, identifies and describes the purpose, method of use and parameters of every security function interface, describes all behaviour associated with those interfaces during enforcement, and describes all direct error messages that an interface call can raise. The product design describes the structure through subsystems and their interactions, maps subsystems to security function interfaces, describes the security functions through implementation modules with their purpose, interfaces and return values, and maps implementation modules to subsystems. The implementation representation defines the security functions in detail through instances such as software code and design data and is mapped to the design description.
6.4.2 Guidance documents are the operational user guidance, which describes the functions and privileges each user role can reach with suitable warnings, the user operation method for the security functions and interfaces including safe values for configuration parameters, all possible operating states including failures and operational errors, and the security policies that have to be enforced to meet the security objectives; and the preparative procedures, which describe every step needed for secure acceptance of the delivered product and for secure installation of the product and its operating environment.
6.4.3 Life cycle support covers configuration management capability, from unique identification of versions and of configuration items through to an automated configuration management system and a configuration management plan; configuration management scope, requiring a configuration item list that names the developer and covers the product, the assurance evaluation evidence, the product parts, the implementation representation and the security flaw reports with their resolution status; delivery procedures documented for each version; development security, documenting the physical, procedural, personnel and other measures protecting the confidentiality and integrity of design and implementation; life cycle definition; and tools and techniques, with tool documentation that defines the meaning of every statement and of every implementation-dependent option without ambiguity.
6.4.4 Testing covers test coverage, showing the correspondence between the tests identified in the test documentation and the security functions described in the functional specification and that all security function interfaces have been tested; test depth, showing consistency with the security function subsystems and implementation modules of the design and that all of them have been tested; functional testing, with a test plan, expected results and a comparison with the actual results; and independent testing, for which the developer supplies resources equivalent to those used for its own testing so that the security functions can be sample tested.
6.4.5 Vulnerability assessment: on the basis of the potential vulnerabilities identified, the product resists attackers with basic attack potential and attackers with moderate attack potential.
7 Evaluation methods
Clause 7 mirrors clause 6 item by item. Every subclause is written in the same three parts: evaluation content, expected result, and result determination, the last of which reads that where the actual evaluation result agrees with the relevant expected result the item is judged to conform, and in all other cases not to conform.
7.1 Security function evaluation follows the numbering of 6.1, from information flow control policy and function through illegal external connection, switching signal consistency, hard disk swapping, memory and USB port isolation, non-bypassability and object reuse, then application and protocol support, information filtering, labels and mandatory access control, attack protection, security isolation, high availability, data integrity, security audit and analysis, interconnection, IPv6 support and virtualised deployment. The filtering tests name concrete rules to configure, such as filtering the GET and PUT commands of FTP, filtering insert and delete in a database protocol, filtering invite, bye and register in signalling, filtering H264 and H265 stream coding formats, register read and write operations for industrial control, and correct recognition of files whose extension has been changed.
7.2 Self-security evaluation follows 6.2: unique user identification, protection of authentication information, triggering of login failure handling, automatic logout on timeout, replay of a previously accepted credential, password complexity checking with weak passwords such as empty or all-digit refused, forced change of a default password at first login, and two-factor management; then management capability, management audit, management mode and supporting system security.
7.3 Performance evaluation connects a performance tester to the product interfaces and measures, for 1518 byte UDP packets, the network layer throughput reached without packet loss and the latency at maximum throughput without packet loss, recording the number of ports used and the values obtained for each rate class.
7.4 Security assurance evaluation examines the developer's evidence for each item of 6.4 and includes on-site checks, for the configuration management system, the development environment and the life cycle model among others; the expected result in each case is that the information supplied meets the corresponding requirement of clause 6.
Annex A Classification of products and grading of security technical requirements
A.1 The annex lists the grading of the security technical requirements separately for terminal separation products, protocol conversion products, gaps and network unilateral transmission products. Each table has three columns: the requirement, the subclause number applicable at the basic grade, and the subclause number applicable at the enhanced grade, with a dash meaning not applicable.
A.2 Table A.1, terminal separation products, applies at the basic grade only the parts of information flow control that concern switching and physical separation, and leaves illegal external connection, illegal hard disk swapping, implementation representation, development security, life cycle definition, tools and techniques and test depth to the enhanced grade alone.
A.3 Table A.2, protocol conversion products, adds application and protocol support, information filtering, domain isolation, security audit, interconnection, IPv6 support and virtualised deployment at the basic grade, and reserves object reuse, labels and mandatory access control, malicious code protection, label isolation, fault tolerance, alarm and statistics for the enhanced grade.
A.4 Table A.3, gaps, is close to Table A.2 but adds object reuse and fault tolerance at the basic grade, adds clustering at the enhanced grade, and brings the throughput and latency performance requirements in at both grades. Application and protocol support at the basic grade is any one of the eight protocol families, and at the enhanced grade the file, mail and database families or any one of the remaining five.
A.5 Table A.4, network unilateral transmission products, requires malicious code protection at the basic grade as well as the enhanced one, requires the one-way construction item of the information flow control function at both grades, and places the performance requirements at the enhanced grade only.
Annex B Classification of products and grading of evaluation methods
B.1 The annex sets out, for the same four product families and following the requirement grading of Annex A, which subclause of clause 7 applies at the basic grade and which at the enhanced grade, again with a dash for not applicable.
B.2 to B.5 give one table per family, Table B.1 for terminal separation products, Table B.2 for protocol conversion products, Table B.3 for gaps and Table B.4 for network unilateral transmission products, each running from security function evaluation through self-security evaluation and, where the family has them, performance evaluation, to security assurance evaluation.
......
This preview omits tables, figures, formulas and parts of the technical clauses. The complete document — 39 pages — is available in the English PDF.
Referenced standards
Cited by
- GB/T 46364-2025Technical requirements for boundary security interaction system for video surveillance for public security
- GB/T 46739-2025Baseline for information system security of urban rail transit networks
- GB/T 35282-2023Information security technology - Security technology specifications of mobile e-government system
Editions of GB/T 20279
| Edition | Title | Revision | Status |
|---|---|---|---|
| GB/T 20279-2024 | Cybersecurity technology - Technical specification for network and terminal separation products | current edition | Current |
| GB/T 20279-2015, GB/T 20277-2015 | Cybersecurity technology - Technical specification for network and terminal separation products | previous edition | In force until 2025-04-01 |
This page sells the current edition, GB/T 20279-2024. Earlier editions are listed for reference only.
How to Buy GB/T 20279-2024
- 1Add to cart. Click the "Buy GB/T 20279-2024" button on this page. You can add more standards before checkout.
- 2Checkout. Enter your email and billing details. Payment is processed securely by Stripe (cards, Apple Pay, Google Pay supported).
- 3Instant delivery (0–9 sec). Delivery is automatic: within seconds of payment you'll receive an email with a secure download link. The link stays valid for 72 hours.
- 4Invoice included. A tax invoice is attached to the confirmation email. Need a custom invoice? Contact us.
Related Standards
GB/T 47310-2026 — Determination of total silicon, aluminium, iron, potassium, sodium, calcium, magnesium, manganese, phosphorus, titanium and sulfur in soil - Monochromatic excitation energy dispersive X-ray fluorescence spectrometry
GB/T 47321-2026 — Specification for the warning data exchange of the national emergency early warning dissemination system
GB/T 47293-2026 — Determination of available mercury in soil
Secure payment via Stripe
Payments accepted
GB/T 20279-2024
$725.00