Valid

GB/T 28455-2026Cybersecurity technology - Entity authentication involving a trusted third party and access architecture specification (English PDF)

网络安全技术 引入可信第三方的实体鉴别及接入架构规范

Open the GB/T 28455-2026 preview as PDF

Preview — first pages of GB/T 28455-2026 (full document: 84 pages)

This is a limited preview

Buy now to download the full PDF (84 pages)

Issued by

SAMR; SAC

Level / Type

National · Recommended

Issue date

May 25, 2026

Implementation date

December 1, 2026

Scope

GB/T 28455-2026 is the English-translated version of 网络安全技术 引入可信第三方的实体鉴别及接入架构规范.

GB/T 28455-2026 is the Chinese national standard covering authentication through a trusted third party - the architecture in which two entities that do not know each other are each vouched for by a party both trust, and the access control that follows from the result. At 24,000 words it replaces GB/T 28455-2012 after fourteen years. In force from 1 December 2026. It was issued on 25 May 2026 and takes effect on 1 December 2026, replacing GB/T 28455-2012. The document is under the responsibility of the Standardization Administration of China. This page is published from the official record of the 2026 edition; the clause text of a standard this recent is not yet in circulation, and the figures, limits and tables it contains are those of the document itself, delivered in full with the English translation.

Document preview — GB/T 28455-2026

National Standard of the People's Republic of China

ICS
35.030
Classification
L 80
Replacing
GB/T 28455-2012

Issued by: State Administration for Market Regulation; Standardization Administration of the PRC

Contents

  • 5 Overall Architecture
  • 5.3 System Roles and Port Technical Requirements
  • 5.3.2 Technical Requirements for Controlled and Uncontrolled Ports
  • 5.4 Port Access Entity
  • 5.4.5 TAEP Reuse Model
  • 5.4.6 End-to-end protocols
  • 6.3 Definition of each field in the TAEP grouping field
  • 7.6 Format of TAEPoLPDU
  • 7.6.6 Encapsulating Data Definitions in Content Fields

5 Overall Architecture

5.1 General Rules This chapter describes the structural framework, control functions, and devices employing this mechanism in an entity authentication and access system that introduces a trusted third party. The relationship between the various operations performed. The entity authentication and access system that introduces a trusted third party adopts a three-element peer-to-peer architecture (TePA), as shown in Figure 1, which sets the entities participating in the authentication to... In a peer-to-peer manner, a trusted third party (authentication server system) is introduced, and logical port control methods are used to complete the authentication and endpoint verification between the two parties. Authorization via authentication. Authentication between the requester system and the authentication access controller system can be achieved through an authentication server acting as an intermediary, using an authentication protocol. It runs on three entities. the requester system, the authentication access controller system, and the authentication server.

5.2 Access Control Requirements In an entity authentication and access architecture that introduces a trusted third party, the system port should provide a point of contact between the requester and the authentication access controller. Connections to the point. The requester and the authentication access controller, and the authentication access controller and the authentication server, perform entity authentication protocol interactions and, according to... The result of the protocol execution determines the port status of the requester and the authentication access controller, thereby implementing access control.

5.3 System Roles and Port Technical Requirements

5.3.1 System Role Requirements A system port is a channel for service access and provision. A port allows external systems to access the services provided by this system, and also allows internal systems to access the services provided by this system. The system provides services to the outside world through ports. A trusted third-party entity authentication and access architecture is introduced to ensure system port status by controlling the system's entity authentication and access architecture. Only authorized systems can access the services provided by this system, or access the services provided by authorized systems. The device's role should meet the requirements of the following three roles.

5.3.2 Technical Requirements for Controlled and Uncontrolled Ports

5.3.2.1 General Port Requirements The system introduces a trusted third-party entity authentication and access architecture. The connection point between the system and the link is a physical port or a logical port, and this port should provide... Provide one-to-one connections to other systems; two distinct access points should be established at the connection points between the system and the link. a controlled port and an uncontrolled end. The port should meet the following requirements.

a) The uncontrolled port and the controlled port are two parts of the same connection point, both receiving data frames from the physical connection point;

b) Uncontrolled ports, regardless of authorization status, allow uncontrolled exchange of data packets between systems on the link;

c) Controlled ports are only allowed to exchange data packets when they are in an authorized state.

Note. Although data packets can be obtained on both controlled and uncontrolled ports, a protocol entity can only be associated with one port at a time.

5.3.2.2 Port Control Technical Requirements Controlled and uncontrolled ports are logical concepts that categorize data flows. Management and control flows can be managed through uncontrolled ports. The information flow is controlled through a controlled port without affecting the system's communication management. The controlled port status parameter (AuthControledPortStatus) and the results of LAC control are shown in Figure

2.In System 1 of Figure 2... In System 1, because the LAC to the link connection point is operable, both controlled and uncontrolled ports can access the link; while in System 2, because... The LAC at the link connection point is inoperable; neither controlled nor uncontrolled ports can access the link. This inoperability of the LAC also leads to This causes the controlled port status of the system to be unauthorized.

5.3.2.3 Control Parameter Requirements for Controlled Ports In addition to the controlled port status parameters, administrators use the controlled port control parameter (AuthControledPortControl) to control... The port's authorization status. Controlled port control parameters have three possible values. Force Authorized, Auto, and Force Not Authorized. The authorization setting (ForceUnauthorized) defaults to automatic. The relationship between controlled port status parameters and controlled port control parameters should meet the following requirements. The following requirements must be met.

a) When the controlled port control parameter value is "forced authorization", the authentication access controller or requester state machine will change the controlled port state. The value of the state parameter is set to authorized; that is, the controlled port is unconditionally set to authorized.

b) When the controlled port control parameter is set to automatic, the authentication access controller and requester state machine determine the requester and authentication access controller based on the requester and the authentication access controller. The result of the authentication exchange between the controller and the authentication server determines the value of the controlled port status parameter;

c) When the controlled port control parameter value is forced unauthorized, the authentication access controller or requester state machine will control the controlled port. The status parameter is set to unauthorized, meaning the controlled port is unconditionally set to unauthorized. In the three cases described above, the value of the controlled port state parameter directly reflects the port state in the authentication access controller and the requester state machine. The value of the (portStatus) variable.

5.3.2.4 Port Status Variable Requirements The value of the port status variable is affected by the following three factors, and the port status change should meet the following requirements.

a) Identify the authorized state of the access controller state machine. if no state machine is implemented on the port, it is considered "authorized".

b) Authorization state of the requester's state machine. If the port does not implement a state machine, it is considered "authorized".

5.4 Port Access Entity

5.4.1 Overview The Port Access Entity (PAE) operates on the protocols defined in Chapter

8.For systems that support port access control, regardless of... Whether the system acts as a requester or an authentication access controller, a PAE exists on each port.

a) The PAE that plays the role of the requester in the authentication exchange is called the requester PAE.

b) The PAE that plays the role of authentication access controller is called authentication access controller PAE. Both PAE roles control the authorized/unauthorized status of the controlled port based on the results of the authentication process.

5.4.2 Identifying Access Controller Role Requirements The authentication access controller should meet the following requirements.

a) The authentication access controller (PAE) should be responsible for authenticating requesting PAEs connecting to its controlled ports and for authenticating the controlled ports. The authorization status is controlled accordingly;

b) During the authentication process, the Authentication Access Controller (PAE) can use the authentication server;

c) The authentication server may be in the same system as the authentication access controller, or in a system that can be accessed via remote communication mechanisms, LAN, or other means. Other systems that access via other mechanisms;

d) Communication between the requester PAE and the authentication access controller PAE, and communication between the authentication access controller PAE and the authentication server (when authentication...). When the authentication server and the authentication access controller are not in the same system, communication should preferably be conducted through the procedures described in Chapter 8. Finish.

5.4.3 Requester Role Requirements The requester should meet the following requirements.

a) The requester PAE is responsible for sending the requester's authentication credentials to the authentication access controller PAE, as a confirmation of the authentication access control. The response to the PAE request;

b) The requesting PAE shall control the authorization of the controlled port based on the result of the authentication exchange with the authentication access controller PAE. state;

c) The requester PAE can initiate an authentication exchange to complete a specific deregistration exchange.

5.4.4 Port Access Restrictions Authentication is triggered during system initialization or when the requesting system connects to the authentication access controller system's port. Authentication is performed on each end. Ports are configured, and in some configurations, authentication of specific ports is not required. Port access should meet the following requirements.

5.4.5 TAEP Reuse Model

5.4.5.1 General Requirements The TAEP reuse model should conform to the requirements in Figure

4.The dashed line in Figure 4 indicates an optional part; whether this part is effective during operation is determined by... The TAEP identification method is determined.

5.4.5.2 Lower Layer and Transport Layer The underlying and transport layers are responsible for transmitting and receiving TAEP packets between the requester, the authentication access controller, and the authentication server. The layer is a logical concept, indicating that this layer and the adjacent lower layer are not the same technology.

5.4.5.3 TAEP Layer The TAEP layer should transmit and receive TAEP packets through the lower layers to achieve duplicate packet detection and retransmission, and to authenticate access at the peer layer. Messages are transmitted between controller layers.

5.4.5.4 TAEP Peer Layer and Authentication Access Controller Layer The TAEP layer should parse the received TAEP packet according to the value of the encoding field in the TAEP packet and then transmit it to the TAEP peer layer. Alternatively, use TAEP to authenticate access to the controller layer.

5.4.5.5 TAEP Identification Method Messages are transmitted through the TAEP peer layer and the TAEP authentication access controller layer, and the TAEP authentication method layer implements the authentication algorithm. Since fragmentation is not implemented at the TAEP layer, the TAEP identification method layer should implement fragmentation functionality.

5.4.6 End-to-end protocols

5.4.6.1 General Rules TAEP is an end-to-end protocol, referring to the operation of the TAEP protocol between a peer and an authentication access controller. Therefore, one Both ends of the link can simultaneously act as authentication access controllers and peers. In this case, TAEP authentication access control is implemented at both ends. Device layer and TAEP equivalent layer. In the presence of an authentication server, i.e., the TAEP authentication method requires the existence of an authentication server to implement the authentication access controller function. One end of the device can communicate with the authentication server without restriction. 6.TAEP packaging requirements

6.1 Overview The PAE includes two functions. authentication and control, and mutual communication. The authentication and control function realizes the state transition of the PAE; the communication function transmits... Authentication messages between two PAEs. The TAEP protocol supports authentication between the access controller PAE and the requesting PAE, and authentication of access control... Communication functionality between the device PAE and the authentication server.

6.2 TAEP Grouping Format The TAEP grouping format should conform to the requirements of Figure 5.

6.3 Definition of each field in the TAEP grouping field

6.3.1 Request and Response Packets The request and response packet formats should conform to the requirements of Figure 6. 7.TAEP packaging requirements on the link

7.1 Overview This chapter defines the encapsulation requirements for the payload TAEP packet between the requester PAE and the authentication access controller PAE. This encapsulation is called... TAEP on the link, or TAEPoL. The encapsulation methods may differ across different types of links, but their function is similar. to be able to transmit TAEP data packets. And the session between the requester PAE and the authentication access controller PAE. This document defines TAEPoL conforming to the packaging requirements of GB/T 15629.2-2008 and GB/T 15629.3-2014. The TAEPoL protocol used in other network forms is not within the scope of this document.

7.2 Transmission and Identification of Octaves The transmission and identification of the TAEPoLPDU octet should meet the following requirements.

a) All TAEPoLPDUs contain an integer number of octets, numbered starting from 1 according to their position in the MAC. The order of the bits increases sequentially. The bit numbers in each octet range from 1 to 8, with 1 being the least significant bit.

b) When a binary number is represented by consecutive octets, the lower-numbered octet is the higher-numbered octet in the binary number.

c) When the encoding (elements) of a TAEPoLPDU uses the graphical representation from Chapter 6, the representation rules should meet the following requirements. 1) Octave group 1 is displayed at the very top of the page, and the highest-numbered octave group is displayed at the bottom; 2) If multiple octets appear in a row, the lowest-numbered octet is on the far left, and the highest-numbered octet is on the far right. right; 3) In an octet, bit 8 is on the left and bit 1 is on the right.

7.3 Format of TAEPoLMPDU in GB/T 15629.2-2008 Logical Link Control The TAEPoLMPDU in GB/T 15629.2-2008 Logical Link Control (LLC) format should conform to the requirements of Figure 13. According to GB/T 15629.2-2008 MPDU, starting from the Length/Type field, Figure 13 excludes the SNAP-encoded Ethernet type word. Fields other than segments should conform to the definition in 7.6.

7.4 Format of TAEPoLMPDU in GB/T 15629.3-2014 The format of TAEPoLMPDU in GB/T 15629.3-2014 should conform to the requirements of Figure

14.Figure 14, except for PAE Ethernet... Fields other than the type field should conform to the definition in 7.6. Figure

14.Format of TAEPoLMPDU in GB/T 15629.3-2014 The PAE Ethernet type field is two octets long and represents the Ethernet type value to be used by PAE, which should conform to the definition in Table 6.

7.5 Label TAEPoLMPDU The TAEpoLMPDU sent by PAE should not be labeled with a virtual LAN, but a priority label may be added. All PAEs Both should be able to accept TAEPoLMPDUs with and without priority labels.

7.6 Format of TAEPoLPDU

7.6.1 General Rules The format of the TAEPoLPDU field should conform to the requirements of Figure 15, and the definitions of each field should conform to 7.6.2, 7.6.3, and

7.6.4 respectively. Definition of 7.6.5. Protocol version

7.6.2 This field is one octet long and is represented by an unsigned number. Its value indicates the number of frames supported by the sender of the TAEPoL frame. TAEPoL protocol version. This field value should be 00000001 if conforming to this document.

7.6.3 Type This field is one octet long, represented by an unsigned number. Its value identifies the type of frame being sent, and its definition should conform to the following... The following requirements are made.

a) TAEP-Packet. A value of 00000000 indicates that the frame contains a TAEP packet;

b) TAEPoL-Start. A value of 00000001 indicates that the frame is a TAEPoL-Start frame;

c) TAEPoL-Logoff. A value of 00000010 indicates that the frame is a TAEPoL-Logoff request frame;

d) TAEPoL-Key. A value of 00000011 indicates that the frame is a TAEPoL-Key frame;

e) TAEPoL-Encapsulated-Alert. The value 00000100 indicates the frame carrier TAEPoL-Encapsulated-Alert. All other values besides the five mentioned above are reserved for future extensions of this agreement.

7.6.6 Encapsulating Data Definitions in Content Fields

7.6.6.1 Key Descriptor 7.6.6.1.1 Key Descriptor Format The format of the key descriptor should conform to Figure 16, and the definitions of each field should conform to 7.6.6.1.2, 7.6.6.1.3, 7.6.6.1.4, and 7.6.6.1.5 respectively. Requirements of 7.6.6.1.6, 7.6.6.1.7, and 7.6.6.1.8. 7.6.6.1.2 Length Field The length field is a two-octet integer representing all fields in the Key descriptor, including the length field. Eight-bit group number.

......
This preview omits tables, figures, formulas and parts of the technical clauses. The complete document — 84 pages — is available in the English PDF.

Referenced standards

Editions of GB/T 28455

EditionTitleRevisionStatus
GB/T 28455-2026Cybersecurity technology - Entity authentication involving a trusted third party and access architecture specificationcurrent editionCurrent
GB/T 28455-2012Cybersecurity technology - Entity authentication involving a trusted third party and access architecture specificationprevious editionIn force until 1 December 2026

This page sells the current edition, GB/T 28455-2026. Earlier editions are listed for reference only.

How to Buy GB/T 28455-2026

  1. 1Add to cart. Click the "Buy GB/T 28455-2026" button on this page. You can add more standards before checkout.
  2. 2Checkout. Enter your email and billing details. Payment is processed securely by Stripe (cards, Apple Pay, Google Pay supported).
  3. 3Instant delivery (0–9 sec). Delivery is automatic: within seconds of payment you'll receive an email with a secure download link. The link stays valid for 72 hours.
  4. 4Invoice included. A tax invoice is attached to the confirmation email. Need a custom invoice? Contact us.

Related Standards

English PDF
84 pages
Instant delivery (0–9 sec)
Invoice included
View Cart

Secure payment via Stripe

Payments accepted

VisaMastercardAmerican ExpressApple PayGoogle PayStripe

GB/T 28455-2026

$710.00

$605.00for partners