金融交易系统中若干密码国家标准的应用实践
The Application Practice of Some National Cryptographic Standards for Financial Trading Systems
郑强 1叶枫 1孔庆强 2黄福飞 1彭玲西1
作者信息
- 1. 格尔软件股份有限公司
- 2. 北京格尔国信科技有限公司
- 折叠
摘要
为尽快落实商用密码在证券期货领域的全面应用,以期货行业交易系统中的安全加固改造为典型案例,阐述了GB/T 37092-2018《信息安全技术 密码模块安全要求》、GB/T 38636-2020《信息安全技术 传输层密码协议(TLCP)》等密码国家标准应用实践分析,包括标准的应用模式和标准的应用效果,以及所带来的社会效益.基于商用密码算法的底层安全通讯技术、密钥分割技术,实现了商用密码算法与业务的高效融合.该案例主要应用在证券/期货等金融网上交易系统的业务场景,促进了应用领域的自主可控、安全稳定发展.
Abstract
To quickly implement the comprehensive application of cryptography in the field of securities and futures taking the security reinforcement and renovation of the securities/futures trading system as a typical case,this paper elaborates on the practical application of national cryptographic standards such as GB/T 37092-2018"Information security technology-Security requirements for cryptographic modules"and GB/T 38636-2020"Information security technology-Transport layer cryptography protocol(TLCP)",including standard application modes,and standard application effects,as well as the economic/social benefits it brings.Based on the underlying secure communication technology and key segmentation technology of commercial cryptographic algorithms,efficient integration of commercial cryptographic algorithms and business has been achieved.This case is not only mainly applied in business scenarios of financial online trading systems such as securities/futures and mobile offices in the government.It has effectively promoted the independent,controllable,secure and stable development of application fields.
关键词
密码模块/传输层密码协议/协同签名/密钥Key words
cryptographic modules/TLCP/cooperative signing/key引用本文复制引用
出版年
2024