GB/T 42589-2023Information security technology - Specification for electronic credential service security (English PDF)
信息安全技术 电子凭据服务安全规范
Open the GB/T 42589-2023 preview as PDF
This is a limited preview
Buy now to download the full PDF (32 pages)
Issued by
SAMR; SAC
Level / Type
National · Recommended
Issue date
May 23, 2023
Implementation date
December 1, 2023
Scope
GB/T 42589-2023 is the English-translated version of 信息安全技术 电子凭据服务安全规范.
GB/T 42589-2023 is about the security of electronic credentials - the digital equivalents of the receipt, the invoice, the certificate, the ticket, documents whose whole value lies in being hard to forge and possible to check later. Moving them out of paper removes the physical cues that made forgery difficult and replaces them with a service, and that service becomes the thing that has to be trusted. This document specifies the security requirements for that service across the credential's life: issuance and the granting of authority to issue, delivery to the holder, storage, approval, inspection and verification, and the management of the credential's status when it is used, cancelled or expires. For each it gives the corresponding evaluation method, so the requirements can be tested. It sets out the service framework and the basic security services underneath it, then the general and external-service security requirements built on top. It applies to the design, deployment, provision and evaluation of electronic credential services, and is written to be usable as a reference by the bodies that supervise them. Under ICS 35.030 and CCS L80, its audience is credential platform operators, the enterprises relying on them, and evaluation agencies.
Document preview — GB/T 42589-2023
National Standard of the People's Republic of China
- ICS
- 35.030
- Classification
- L80
Issued by: State Administration for Market Regulation; Standardization Administration of the PRC
Contents
- 1 Scope1
- 2 Normative references1
- 3 Terms and Definitions1
- 4 Abbreviations3
- 2 Basic Security Services4
- 3 Internal Service Security Requirements9
- 5 Safety management education and training system requirements10
- 22 Reference28
Foreword
This document is in accordance with the provisions of GB/T 1:1-2020 "Guidelines for Standardization Work Part 1: Structure and Drafting Rules for Standardization Documents" drafting: Please note that some contents of this document may refer to patents: The issuing agency of this document assumes no responsibility for identifying patents: This document is proposed and managed by the National Information Security Standardization Technical Committee (SAC/TC260): This document was drafted by: Xidian University, Institute of Information Engineering, Chinese Academy of Sciences, Aerospace Information Corporation, Beijing Lisichen New Technology Co:, Ltd:, China Electronics Standardization Institute, Shanghai Jiaotong University, Elephant Huiyun Information Technology Co:, Ltd:, Guoxin Electronic Bill Platform Information Service Co:, Ltd:, Beijing Haitai Fangyuan Technology Co:, Ltd: The main drafters of this document: Li Hui, Li Fenghua, Zhao Xingwen, Wang Zhu, Li Shaowei, Hou Haibo, Wang Huili, Qiu Weidong, Zhu Yanchao, Yue Qiang, Geng Kui, Zhou Shuguang, Zhu Hui, Fang Liang, Luo Yurong, Jia Baogang, Cao Jin, Kou Wenlong, Song Qipeng: Information Security Technology Electronic Credential Service Security Specification
1 Scope
GB/T 42589-2023 is about the security of electronic credentials - the digital equivalents of the receipt, the invoice, the certificate, the ticket, documents whose whole value lies in being hard to forge and possible to check later. Moving them out of paper removes the physical cues that made forgery difficult and replaces them with a service, and that service becomes the thing that has to be trusted. This document specifies the security requirements for that service across the credential's life: issuance and the granting of authority to issue, delivery to the holder, storage, approval, inspection and verification, and the management of the credential's status when it is used, cancelled or expires. For each it gives the corresponding evaluation method, so the requirements can be tested. It sets out the service framework and the basic security services underneath it, then the general and external-service security requirements built on top. It applies to the design, deployment, provision and evaluation of electronic credential services, and is written to be usable as a reference by the bodies that supervise them. Under ICS 35.030 and CCS L80, its audience is credential platform operators, the enterprises relying on them, and evaluation agencies.
This document specifies the security requirements and evaluation of services such as electronic credential issuance, issuance, delivery, storage, approval, inspection, and status management: method: This document is applicable to the design, deployment, provision and evaluation of electronic credential services, and can also provide reference for the supervision of electronic credential services:
2 Normative references
The contents of the following documents constitute the essential provisions of this document through normative references in the text: Among them, dated references For documents, only the version corresponding to the date is applicable to this document; for undated reference documents, the latest version (including all amendments) is applicable to this document:
GB/T 22239-2019 Basic Requirements for Network Security Level Protection of Information Security Technology
GB/T 25069-2022 Information Security Technical Terminology
GB/T 28449-2018 Information Security Technology Network Security Classified Protection Evaluation Process Guide
GB/T 32924-2016 Information Security Technology Network Security Early Warning Guidelines
GB/T 35273-2020 Personal Information Security Specifications for Information Security Technology
GB/T 36635-2018 Basic Requirements and Implementation Guidelines for Network Security Monitoring of Information Security Technology
GB/T 37092-2018 Security requirements for cryptographic modules of information security technology GM/T 0031-2014 Technical Specifications for Secure Electronic Signature Password
3 Terms and Definitions
The following terms and definitions defined in GB/T 25069-2022 apply to this document: 3:1 electronic credential electroniccredential Electronic data records that record activities such as economic transactions: Examples: Electronic invoices, passenger tickets, financial settlement notes for public institutions, administrative fee receipts, bank receipts, etc: 3:
2 Business processes related to electronic credentials provided by service recipients:
Note: Electronic credential services include issuance, issuance, delivery, inspection, status management, etc: 3:
3 Entity entity Any concrete or abstract thing that exists or may exist, including the relationship between these things: Examples: person, object, event, idea, process: NOTE: The existence of an entity is independent of the availability of data related to it: [Source: GB/T 5271:17-2010,17:02:05]
......
This preview omits tables, figures, formulas and parts of the technical clauses. The complete document — 32 pages — is available in the English PDF.
Referenced standards
Normative references
- GB/T 22239-2019Information security technology - Baseline for classified protection of cybersecurity
- GB/T 25069-2022Information security techniques—Terminology
- GB/T 28449-2018Information security technology—Testing and evaluation process guide for classified protection of cybersecurity
- GB/T 32924-2016Information security technology—Guideline for cyber security warning
- GB/T 35273-2020Information security technology—Personal information security specification
- GB/T 36635-2018Information security technology-Basic requirements and implementation guide of network security monitoring
Similar standards
GB 38031-2025|GB/T42589-2023|GB/T 1|GB/T 22239-2019|GB/T 25069-2022|GB/T 28449-2018|GB/T 32924-2016|GB/T 35273-2020
How to Buy GB/T 42589-2023
- 1Add to cart. Click the "Buy GB/T 42589-2023" button on this page. You can add more standards before checkout.
- 2Checkout. Enter your email and billing details. Payment is processed securely by Stripe (cards, Apple Pay, Google Pay supported).
- 3Instant delivery (0–9 sec). Delivery is automatic: within seconds of payment you'll receive an email with a secure download link. The link stays valid for 72 hours.
- 4Invoice included. A tax invoice is attached to the confirmation email. Need a custom invoice? Contact us.
Related Standards
GB/T 22239-2019 — Information security technology - Baseline for classified protection of cybersecurity
GB/T 25069-2022 — Information security techniques—Terminology
GB/T 28449-2018 — Information security technology—Testing and evaluation process guide for classified protection of cybersecurity
Secure payment via Stripe
Payments accepted
GB/T 42589-2023
$545.00