标准解读

《gm/t 0025-2023 SSL VPN 网关产品规范》与《gm/t 0025-2014 SSL VPN网关产品规范》相比,在多个方面进行了更新和调整,以适应技术发展及安全需求的变化。主要变化包括但不限于:

  1. 安全性要求提升:新标准强化了对SSL/TLS协议版本的要求,推荐使用更安全的TLS 1.2及以上版本,并明确禁止使用已被证明存在安全隐患的老版本协议。

  2. 密码套件更新:随着加密算法的进步,《gm/t 0025-2023》增加了对新型强加密算法的支持,同时淘汰了一些被认为不够安全的旧式密码套件,确保数据传输过程中的高安全性。

  3. 身份验证机制增强:新版标准细化并加强了用户认证流程的安全性规定,比如增加了多因素认证(MFA)作为可选项之一,提高了抵御未授权访问的能力。

  4. 日志记录与审计功能改进:为了更好地支持网络安全管理,《gm/t 0025-2023》对日志记录内容、格式以及存储时间等方面提出了更为具体的要求,有助于提高事后追踪分析效率。

  5. 性能指标明确化:针对不同应用场景下的性能需求,新标准给出了更加详细且量化的性能测试方法及合格标准,帮助企业或机构根据自身情况选择合适的产品。

  6. 兼容性和互操作性考虑:考虑到实际部署环境中可能存在多种设备和服务共存的情况,《gm/t 0025-2023》特别强调了产品之间的兼容性和互操作性,旨在促进不同厂商之间产品的无缝对接。

这些调整反映了近年来信息技术领域尤其是网络安全方面的最新进展,旨在为用户提供更加可靠、高效的服务保障。


如需获取更多详尽信息,请直接参考下方经官方授权发布的权威标准文档。

....

查看全部

  • 现行
  • 正在执行有效
  • 2023-12-04 颁布
  • 2024-06-01 实施
©正版授权
GM/T 0025-2023SSL VPN 网关产品规范_第1页
GM/T 0025-2023SSL VPN 网关产品规范_第2页
GM/T 0025-2023SSL VPN 网关产品规范_第3页
GM/T 0025-2023SSL VPN 网关产品规范_第4页
GM/T 0025-2023SSL VPN 网关产品规范_第5页
免费预览已结束,剩余15页可下载查看

下载本文档

GM/T 0025-2023SSL VPN 网关产品规范-免费下载试读页

文档简介

ICS35.030

CCSL80

中华人民共和国密码行业标准

GM/T0025—2023

代替GM/T0025—2014

SSLVPN网关产品规范

SSLVPNgatewayproductspecification

2023⁃12⁃04发布2024⁃06⁃01实施

国家密码管理局发布

GM/T0025—2023

目次

前言··························································································································Ⅲ

1范围·······················································································································1

2规范性引用文件········································································································1

3术语和定义··············································································································1

4缩略语····················································································································1

5密码算法和密钥种类··································································································2

5.1算法要求···········································································································2

5.2密钥种类···········································································································2

6SSLVPN网关产品要求·····························································································2

6.1产品功能要求·····································································································2

6.2产品性能参数·····································································································4

6.3产品安全性要求··································································································4

6.4产品管理要求·····································································································5

6.5产品硬件要求·····································································································7

6.6过程保护········································································································7

6.7参数可配置能力要求····························································································7

7SSLVPN网关产品检测要求·······················································································7

7.1检测说明···········································································································7

7.2外观和结构的检查·······························································································8

7.3提交文档的检查··································································································8

7.4产品功能检测·····································································································8

7.5产品性能检测·····································································································9

7.6安全管理检测·····································································································9

7.7硬件检测··········································································································11

8判定规则···············································································································11

GM/T0025—2023

前言

本文件按照GB/T1.1—2020《标准化工作导则第1部分:标准化文件的结构和起草规则》的规

定起草。

本文件代替GM/T0025—2014《SSLVPN网关产品规范》,与GM/T0025—2014相比,除结构调

整和编辑性改动外,主要技术变化如下:

a)增加了GB/T25069(见第2章)、GM/T0016(见6.3.1)、GM/T0028(见6.3.2.2,6.3.2.3和

6.3.2.4)、GM/T0050(见6.4.1)、GM/T0062(见6.4.2.3.3)和GM/Z4001(见第2章),删除

了GB/T17964和GM/T0014(见2014年版的第2章);

b)删除了术语“密码算法”(见2014年版的3.1.1)、“密码杂凑算法”(见2014年版的3.1.2)、“非

对称密码算法/公钥密码算法”(见2014年版的3.1.3)、“对称密码算法”(见2014年版的

3.1.4)、“分组密码算法”(见2014年版的3.1.5)、“密文分组链接工作模式”(见2014年版的

3.1.6)、“初始化向量/值”(见2014年版的3.1.7)、“数字证书”(见2014年版的3.1.8)、“SSL

协议”(见2014年版的3.1.9)、“虚拟专用网络”(见2014年版的3.1.10)和“SM2算法”(见

2014年版的3.1.11);

c)增加了缩略语“GCM”和“TLCP”(见第4章);

d)增加了GCM模式(见5.1);

e)增加了对随机数生成的描述(见6.1.1);

f)更改了产品性能参数要求的描述(见6.2,2014年版的5.2);

g)更改了密钥安全的描述(见6.3.1,2014年版的5.3.1);

h)增加了敏感参数配置安全(见6.3.2.2);

i)增加了应符合GM/T0028对硬件模块物理安全规定的描述(见6.3.2.3);

j)增加了应符合GM/T0028对软件/固件安全的规定和软件升级相关要求的描述(见

6.3.2.4);

k)增加了远程管理(见6.4.1);

l)增加了一些管理员口令量化的指标(见6.4.2.2);

m)增加了设备管理中注册和监控(6.4.2.3.2);

n)更改了“随机数发生器”的要求(见6.5.3,2014年版的5.4.4.3);

o)更改了“加密部件”的描述(6.5.2,2014年版的5.4.4.2);

p)增加了“检测说明”“外观和结构检查”和“提交文档的检查”(见7.1,7.2和7.3);

q)增加了安全管理检测的检测方法的描述(见7.6);

r)增加了敏感参数配置安全检测的描述(见7.6.1.3);

s)增加了远程管理检测的描述(见7.6.2.4);

t)增加了硬件要求的检测方法的描述(见7.7);

u)更改了判定规则(见第8章,2014年版的第7章)。

请注意本文件的某些内容可能涉及专利。本文件的发布机构不承担识别专利的责任。

本文件由密码行业标准化技术委员会提出并归口。

本文件起草单位:格尔软件股份有限公司、无锡江南信息安全工程技术中心、山东得安信息技术有

限公司、北京信安世纪科技股份有限公司、飞天诚信股份有限公司、广东省电子商务认证有限公司、北

京国脉信安科技有限公司、中电信量子信息科技集团有限公司、山东渔翁信息技术股份有限公司、天融

GM/T0025—2023

信科技集团股份有限公司、上海数字证书认证中心有限公司、智巡密码(上海)检测技术有限公司、山东

大学、兴唐通信科技有限公司、中电科网络安全科技股份有限公司、北京数字认证股份有限公司。

本文件主要起草人:郑强、谭武征、孔凡玉、胡金山、李元正、汪宗斌、朱鹏飞、梁宁宁、药乐、王鹏、

罗俊、安高峰、刘承、韩玮、李述胜、王丽娜、邱媛、韩琳、董明富。

本文件所代替文件的历次版本发布情况为:

——2014年首次发布为GM/T0025—2014;

——本次为第一次修订。

GM/T0025—2023

SSLVPN网关产品规范

1范围

本文件规定了SSLVPN网关产品的功能要求、硬件要求、软件要求、安全性要求和检测要求。

本文件适用于SSLVPN网关产品的研发、检测和管理。

2规范性引用文件

下列文件中的内容通过文中的规范性引用而构成本文件必不可少的条款。其中,注日期的引用文

件,仅该日期对应的版本适用于本文件;不注日期的引用文件,其最新版本(包括所有的修改单)适用于

本文件。

GB/T9813.3计算机通用规范第3部分:服务器

温馨提示

  • 1. 本站所提供的标准文本仅供个人学习、研究之用,未经授权,严禁复制、发行、汇编、翻译或网络传播等,侵权必究。
  • 2. 本站所提供的标准均为PDF格式电子版文本(可阅读打印),因数字商品的特殊性,一经售出,不提供退换货服务。
  • 3. 标准文档要求电子版与印刷版保持一致,所以下载的文档中可能包含空白页,非文档质量问题。

评论

0/150

提交评论