Back to Insights
SSL CertificatesData securityComplianceChinese cryptographic algorithms 2024-09-30

How TLS Supports Industrial Data Security in China

SSL/TLS certificates can support secure data transmission within a wider compliance program for China’s industrial and information technology sectors.

Industrial and information technology systems are important parts of the digital economy. Data leakage, alteration or destruction can have serious consequences. In China, organizations processing such data must consider the Data Security Law, Cybersecurity Law, the trial measures for data security management in the industrial and information technology sectors, relevant protection requirements and other applicable policies and standards.

SSL certificates, used with correctly configured TLS, support the protection of data in transit. They are one technical component of a broader data security program, not a substitute for all legal, organizational and operational requirements.

Certificates supporting data security

The original September 2024 article discussed the Data Security Compliance Guidelines for the Industrial and Information Technology Sectors (Draft for Comments), jointly prepared by the China Institute of Communications and 16 other organizations. The document was a consultation draft in the context of that article; it should not be presented as a new, universally binding rule. Its discussion of data transmission within lifecycle protection included the following principles:

  • Divide enterprise networks into appropriate security domains based on business processes, responsibilities, deployment and risk. Distinguish transmission within and between domains. Depending on the data type, classification and use case, define security policies, implement safeguards and establish secure transmission channels.
  • For important and core data, use appropriate commercial cryptographic techniques to protect confidentiality and integrity in transit. The draft referenced message authentication codes based on symmetric or hash algorithms, public-key digital signatures, symmetric encryption and decryption, and public-key digital envelopes.

Certificates using supported public-key algorithms, such as RSA or SM2, can contribute to this design by enabling authenticated secure connections. Modern HTTPS uses TLS, rather than the obsolete SSL protocol. The connection combines authentication, key establishment and traffic protection; the certificate itself does not encrypt all transmitted data.

Secure transmission using certificates

  1. Confidentiality in transit. HTTPS establishes an encrypted channel between compatible endpoints. With appropriate protocol configuration and protected keys, it helps prevent unauthorized parties on the network from reading the transmitted content. It does not protect data after a compromised endpoint has decrypted it.
  2. Integrity in transit. TLS record protection detects unauthorized modification of protected traffic. Certificate signatures help authenticate the handshake, while negotiated traffic-protection algorithms protect application data; these are related but distinct functions.
  3. Authenticating the server. Certificate validation checks the issuing chain, validity and the identity required for the connection, such as the server hostname. The level of organization identity validation depends on the certificate type. A standard server certificate does not, by itself, authenticate every client or prevent unauthorized users from accessing an application; client authentication and access controls require additional design.

Together, these capabilities help protect data exchanged by industrial websites, applications and systems. Whether an implementation meets a particular compliance obligation depends on the applicable requirements and the complete system, including cryptographic configuration, identity and access management, monitoring and operational controls.

The original article introduced Racent’s portfolio of more than ten certificate brands, including RSA-based products, SM2 SSL certificates and dual SM2/RSA certificate solutions intended to address compatible domestic and international clients. That product-count statement describes the 2024 article, not a current inventory guarantee.

For current product information or to discuss a deployment, contact us. International service inquiries are handled through NicSRS; requirements for SM2 products should be confirmed through consultation.