STARCOS 3.7 ID eAT BAC C1, STARCOS 3.7 ID ePass BAC C1
CSV information ?
Status | active |
---|---|
Valid from | 18.08.2020 |
Valid until | 18.08.2025 |
Scheme | 🇩🇪 DE |
Manufacturer | G+D Mobile Security GmbH |
Category | ICs, Smart Cards and Smart Card-Related Devices and Systems |
Security level | EAL4+, ALC_DVS.2 |
Heuristics summary ?
Certificate ?
Extracted keywords
Operating System name
STARCOS 3Vendor
Giesecke+DevrientSecurity level
EAL 4, EAL 5, EAL 2, EAL 4 augmentedSecurity Assurance Requirements (SAR)
ALC_DVS.2Protection profiles
BSI-CC-PP- 0055-2009Certificates
BSI-DSZ-CC-1076-2020Standards
ISO/IEC 15408, ISO/IEC 18045, ICAOFile metadata
Title | Certificate BSI-DSZ-CC-1076-2020 |
---|---|
Subject | STARCOS 3.7 ID eAT BAC C1, STARCOS 3.7 ID ePass BAC C1 |
Keywords | Common Criteria, Certification, Zertifizierung, STARCOS 3.7, BAC, MRTD |
Author | Bundesamt für Sicherheit in der Informationstechnik |
Creation date | D:20200821064941+02'00' |
Modification date | D:20200821065058+02'00' |
Pages | 1 |
Creator | Writer |
Producer | LibreOffice 6.2 |
Certification report ?
Extracted keywords
Symmetric Algorithms
AES, DES, 3DES, TDES, CMACAsymmetric Algorithms
ECDH, ECIES, ECC, Diffie-HellmanHash functions
SHA-1Schemes
MAC, Key AgreementProtocols
PACERandomness
RNGBlock cipher modes
CBCOperating System name
STARCOS 3Vendor
Infineon, Infineon Technologies AG, Giesecke+DevrientSecurity level
EAL 4, EAL 5, EAL 2, EAL 1, EAL 2+, EAL5+, EAL6, EAL 5+, EAL 6, EAL 4 augmentedClaims
A.USecurity Assurance Requirements (SAR)
ADV_ARC, ALC_DVS.2, ALC_FLR, ALC_CMC.4, ALC_CMS.4, ALC_DEL.1, ALC_LCD.1, ALC_TAT.1Security Functional Requirements (SFR)
FCS_COP, FCS_CKM.1, FCS_RND.1, FDP_UIT.1, FIA_UAU.4, FIA_AFL.1Protection profiles
BSI-CC-PP- 0055-2009, BSI-PP-0055-2009, BSI-PP-0055-Certificates
BSI-DSZ-CC-1076-2020, BSI-DSZ-CC-1077, BSI-DSZ-CC-1110-V3-, BSI-DSZ-CC-1110-V3-2020, BSI-DSZ-CC-S-0132-2019, BSI-DSZ-CC-S-0152-2020, BSI-DSZ-CC-S-0150-2020, BSI-DSZ-CC-S-0143-2019Evaluation facilities
TÃœV Informationstechnik, SRC Security Research & ConsultingSide-channel analysis
side channel, physical tampering, malfunction, fault injection, JILCertification process
being maintained, is not given any longer. In particular, prior to the dissemination of confidential documentation and information related to the TOE or resulting from the evaluation and certification, STARCOS 3.7 ID ePass BAC C1, Version 1.5, 12 August 2020, Giesecke+Devrient Mobile Security GmbH (confidential document) [7] Security Target Lite BSI-DSZ-CC-1076-2020, Security Target Lite STARCOS 3.7 ID eAT BAC C1, STARCOS 3.7 ID ePass BAC C1, Version 1.2, 13 August 2020, SRC Security Research & Consulting GmbH (confidential document) [10] Configuration List BSI-DSZ-CC-1076-2020, Configuration List STARCOS 3.7 ID eAT BAC C1, 3.7 ID ePass BAC C1, Version 0.2, 12 August 2020, Giesecke+Devrient Mobile Security GmbH (confidential document) [11] Guidance Documentation STARCOS 3.7 ID C1 – Main Document, Version 1.01, 21 July 2020, H13, Revision 3.3, 22 April 2020, Infineon Technologies AG, BSI-DSZ-CC-1110-V3- 2020 (confidential document) Security Target Lite of the underlying hardware platform, Common Criteria Public Security Target, procedure BSI-DSZ-CC-1110-V3-2020, Version 1, 23 April 2020, TÜV Informationstechnik GmbH (confidential document) [19] Technical Guideline BSI TR-03110: Advanced Security Mechanisms for Machine Readable TravelStandards
FIPS46-3, FIPS197, FIPS180, FIPS PUB 46-3, FIPS PUB 180-4, FIPS PUB 197, AIS 34, AIS 36, AIS 37, AIS 26, AIS 25, AIS 20, AIS 31, AIS 46, AIS 35, AIS 1, AIS 14, AIS 19, AIS 23, AIS 32, AIS 38, AIS20, AIS31, ISO/IEC 15408, ISO/IEC 18045, ISO/IEC 17065, ISO/IEC 18031:2005, ICAOTechnical reports
BSI TR-03116, BSI TR-03110, BSI TR-03116-2, BSI TR-02102-1, BSI 7148File metadata
Title | Certification Report BSI-DSZ-CC-1076-2020 |
---|---|
Subject | STARCOS 3.7 ID eAT BAC C1, STARCOS 3.7 ID ePass BAC C1 |
Keywords | "Common Criteria, Certification, Zertifizierung, STARCOS 3.7, BAC, MRTD" |
Author | Bundesamt für Sicherheit in der Informationstechnik |
Creation date | D:20200821063851+02'00' |
Modification date | D:20200821131000+02'00' |
Pages | 33 |
Creator | Writer |
Producer | LibreOffice 6.2 |
Frontpage
Certificate ID | BSI-DSZ-CC-1076-2020 |
---|---|
Certified item | STARCOS 3.7 ID eAT BAC C1, STARCOS 3.7 ID ePass BAC C1 |
Certification lab | BSI |
Developer | Giesecke+Devrient Mobile Security GmbH |
References
Outgoing- BSI-DSZ-CC-1110-V3-2020 - active - Infineon Security Controller IFX_CCI_000003h, 000005h, 000008h, 00000Ch, 000013h, 000014h, 000015h, 00001Ch, 00001Dh, 000021h, 000022h in the design step H13 and including optional software libraries and dedicated firmware in several versions
Security target ?
Extracted keywords
Symmetric Algorithms
AES, DES, Triple-DES, KMACAsymmetric Algorithms
ECDSAHash functions
SHA-1Schemes
MACRandomness
RND, RNGBlock cipher modes
CBCOperating System name
STARCOS 3IC data groups
EF.DG1, EF.DG2, EF.DG3, EF.DG4, EF.DG5, EF.DG16, EF.DG13, EF.DG14, EF.DG15, EF.COM, EF.SODVendor
Infineon, Infineon Technologies AG, Giesecke+DevrientSecurity level
EAL6, EAL4, EAL 4, EAL 6, EAL4 augmentedClaims
O.RND, O.MEM_ACCESS, T.RNDSecurity Assurance Requirements (SAR)
ADV_ARC.1, ALC_DVS.2, ALC_DVS, ALC_FLR.1Security Functional Requirements (SFR)
FAU_SAS, FAU_GEN, FAU_SAS.1, FAU_SAS.1.1, FAU_UAU.4, FCS_RND, FCS_RND.1, FCS_CKM.1, FCS_RND.1.1, FCS_CKM.2, FCS_COP.1, FCS_CKM.4, FCS_CKM.1.1, FCS_CKM.4.1, FCS_COP, FCS_RNG.1, FCS_FLS.1, FDP_ACF, FDP_ITC.1, FDP_ITC.2, FDP_ACC.1, FDP_ACF.1, FDP_ACC.1.1, FDP_ACF.1.1, FDP_ACF.1.2, FDP_ACF.1.3, FDP_ACF.1.4, FDP_UCT.1, FDP_UIT.1, FDP_IFC.1, FDP_UCT.1.1, FDP_UIT.1.1, FDP_UIT.1.2, FDP_ITC, FDP_ITT.1, FDP_SDI.1, FDP_SDI.2, FDP_ACC, FIA_SOS.2, FIA_UAU.5.2, FIA_UAU.4, FIA_UAU.6, FIA_UID.1, FIA_UID.1.1, FIA_UID.1.2, FIA_UAU.1, FIA_UAU.1.1, FIA_UAU.1.2, FIA_UAU.4.1, FIA_UAU.5, FIA_UAU.5.1, FIA_UAU.6.1, FIA_AFL.1, FIA_AFL.1.1, FIA_AFL.1.2, FIA_API.1, FMT_LIM, FMT_LIM.1, FMT_LIM.2, FMT_LIM.1.1, FMT_LIM.2.1, FMT_MTD.1, FMT_MSA.3, FMT_SMF.1, FMT_SMR.1, FMT_SMF.1.1, FMT_SMR.1.1, FMT_SMR.1.2, FMT_MTD, FMT_MSA.1, FPT_FLS.1, FPT_TST.1, FPT_PHP.3, FPT_FLS.1.1, FPT_TST, FPT_TST.1.1, FPT_TST.1.2, FPT_TST.1.3, FPT_PHP.3.1, FPT_RVM.1, FPT_SEP.1, FPT_TST.2, FPT_ITT.1, FRU_FLT.2, FTP_ITC.1, FTP_TRP.1Protection profiles
BSI-PP-0002-2001, BSI-PP- 0035-2007, BSI-CC-PP-0056-2009Certificates
BSI-DSZ-CC-1110-V3-2020Side-channel analysis
Leak-Inherent, physical probing, DPA, SPA, timing attacks, Physical Tampering, physical tampering, Physical tampering, Malfunction, malfunction, fault injection, reverse engineeringStandards
FIPS 180-415, FIPS 46-3, FIPS 180-2, FIPS 197, FIPS PUB 46-3, FIPS PUB 186-2, AIS20, AIS 20, AIS 31, AIS 32, RFC3369, ISO/IEC 7816-2, ISO/IEC 14443, ISO/IEC 7816-4, ICAO, CCMB-2017-04-001, CCMB-2017-04-002, CCMB-2017-04-003, CCMB-2017-04-004File metadata
Title | Security Target Lite |
---|---|
Subject | Target of Evaluation = STARCOS 3.7 ID eAT BAC C1, STARCOS 3.7 ID ePass BAC C1 |
Keywords | smartcard programmed on a contactless chip for machine readable travel documents (MRTD) based on the requirements and recommendations of the International Civil Aviation Organization (ICAO). It addresses the advanced security methods Basic Access Control in the ‘ICAO Doc 9303’. Version 1.5/Status 12.08.2020 |
Author | Ulrich Stutenbäumer, Giesecke + Devrient Mobile Security GmbH |
Creation date | D:20200813110600+02'00' |
Modification date | D:20200813111747+02'00' |
Pages | 88 |
Creator | Microsoft® Word für Office 365 |
Producer | Microsoft® Word für Office 365 |
References
Outgoing- BSI-DSZ-CC-1110-V3-2020 - active - Infineon Security Controller IFX_CCI_000003h, 000005h, 000008h, 00000Ch, 000013h, 000014h, 000015h, 00001Ch, 00001Dh, 000021h, 000022h in the design step H13 and including optional software libraries and dedicated firmware in several versions
Heuristics ?
Extracted SARs
ALC_DEL.1, ALC_CMC.4, ALC_LCD.1, ALC_DVS.2, ALC_FLR.1, ALC_CMS.4, ALC_TAT.1, ADV_ARC.1Similar certificates
Name | Certificate ID | |
---|---|---|
STARCOS 3.7 ID ePA C1, STARCOS 3.7 ID eAT C1, STARCOS 3.7 ID ePass C1 | BSI-DSZ-CC-1077-2020 | Compare |
STARCOS 3.7 ID ePA C2, STARCOS 3.7 ID eAT C2, STARCOS 3.7 ID ePass C2 | BSI-DSZ-CC-1077-V2-2024 | Compare |
Scheme data ?
Cert Id | BSI-DSZ-CC-0916-2015 | |
---|---|---|
Product | STARCOS 3.6 COS C1 | |
Vendor | Giesecke & Devrient GmbH seit 1. Juli 2017 Giesecke+Devrient Mobile Security GmbH | |
Certification Date | 07.08.2015 | |
Category | eHealth | |
Url | https://www.bsi.bund.de/SharedDocs/Zertifikate_CC/CC/Gesundheitswesen_SmartCards/0916.html | |
Enhanced | ||
Product | STARCOS 3.6 COS C1 | |
Applicant | Giesecke & Devrient GmbH seit 1. Juli 2017 Giesecke+Devrient Mobile Security GmbH Prinzregentenstr. 159 81677 München | |
Evaluation Facility | SRC Security Research & Consulting GmbH | |
Assurance Level | EAL4+,ALC_DVS.2,ATE_DPT.2,AVA_VAN.5 | |
Protection Profile | Card Operating System Generation 2 (PP COS G2), Version 1.9, 18 November 2014, BSI-CC-PP-0082-V2-2014 | |
Certification Date | 07.08.2015 | |
Expiration Date | 06.08.2020 | |
Entries | [frozendict({'id': 'BSI-DSZ-CC-0916-2015-MA-02', 'description': 'The changes are related to an update and reevaluation of the product life-cycle caused by changes in the development and porduction sites. The certified product itself did not change.'}), frozendict({'id': 'BSI-DSZ-CC-0916-2015-MA-01', 'description': 'Maintenance Report'}), frozendict({'id': 'BSI-DSZ-CC-0916-2015', 'description': 'Security Target'})] | |
Report Link | https://www.bsi.bund.de/SharedDocs/Downloads/DE/BSI/Zertifizierung/Reporte/Reporte09/0916a_pdf.pdf?__blob=publicationFile&v=1 | |
Target Link | https://www.bsi.bund.de/SharedDocs/Downloads/DE/BSI/Zertifizierung/Reporte/Reporte09/0916b_pdf.pdf?__blob=publicationFile&v=1 | |
Description | The Target of Evaluation (TOE) is the product STARCOS 3.6 COS C1 developed by Giesecke & Devrient GmbH. The TOE is a smart card product according to the G2 Card Operating System specification from gematik. The TOE is intended to be used as a card operating system platform for different card types and applications of the card generation G2 in the framework of the German health care system. The TOE implements from the PP-0082-V2 the base part and the packages Crypto Box, Logical Channel and Contactless. | |
Subcategory | Smartcards |
References ?
Updates ?
-
09.11.2024 The certificate data changed.
Certificate changed
The computed heuristics were updated.
- The scheme_data property was set to
{'cert_id': 'BSI-DSZ-CC-0916-2015', 'product': 'STARCOS 3.6 COS C1', 'vendor': 'Giesecke & Devrient GmbH seit 1. Juli 2017 Giesecke+Devrient Mobile Security GmbH', 'certification_date': '2015-08-07', 'category': 'eHealth', 'url': 'https://www.bsi.bund.de/SharedDocs/Zertifikate_CC/CC/Gesundheitswesen_SmartCards/0916.html', 'enhanced': {'product': 'STARCOS 3.6 COS C1', 'applicant': 'Giesecke & Devrient GmbH seit 1. Juli 2017 Giesecke+Devrient Mobile Security GmbH Prinzregentenstr. 159 81677 München', 'evaluation_facility': 'SRC Security Research & Consulting GmbH', 'assurance_level': 'EAL4+,ALC_DVS.2,ATE_DPT.2,AVA_VAN.5', 'protection_profile': 'Card Operating System Generation 2 (PP COS G2), Version 1.9, 18 November 2014, BSI-CC-PP-0082-V2-2014', 'certification_date': '2015-08-07', 'expiration_date': '2020-08-06', 'entries': [{'id': 'BSI-DSZ-CC-0916-2015-MA-02', 'description': 'The changes are related to an update and reevaluation of the product life-cycle caused by changes in the development and porduction sites. The certified product itself did not change.'}, {'id': 'BSI-DSZ-CC-0916-2015-MA-01', 'description': 'Maintenance Report'}, {'id': 'BSI-DSZ-CC-0916-2015', 'description': 'Security Target'}], 'report_link': 'https://www.bsi.bund.de/SharedDocs/Downloads/DE/BSI/Zertifizierung/Reporte/Reporte09/0916a_pdf.pdf?__blob=publicationFile&v=1', 'target_link': 'https://www.bsi.bund.de/SharedDocs/Downloads/DE/BSI/Zertifizierung/Reporte/Reporte09/0916b_pdf.pdf?__blob=publicationFile&v=1', 'description': 'The Target of Evaluation (TOE) is the product STARCOS 3.6 COS C1 developed by Giesecke & Devrient GmbH. The TOE is a smart card product according to the G2 Card Operating System specification from gematik. The TOE is intended to be used as a card operating system platform for different card types and applications of the card generation G2 in the framework of the German health care system. The TOE implements from the PP-0082-V2 the base part and the packages Crypto Box, Logical Channel and Contactless.'}, 'subcategory': 'Smartcards'}
.
- The scheme_data property was set to
-
22.08.2024 The certificate data changed.
Certificate changed
The state of the certificate object was updated.
- The st property was updated, with the
{'download_ok': True, 'convert_ok': True, 'extract_ok': True, 'pdf_hash': '970d564f830c6d0266fa2d16e6d89a8f74d69ed3a9f057bd70d14e3e61d4a454', 'txt_hash': '5e76dfce19dbdb02ed52b63a9dedd9dcbc3162893ef9b9194f56ccc4c3f48e01'}
data. - The cert property was updated, with the
{'download_ok': True, 'convert_ok': True, 'extract_ok': True, 'pdf_hash': '720a97a349d8c6cac309ad5b10cd1fce597a84202f082647a119608330642c16', 'txt_hash': '5a05b94f237b46707fcbec4948fe9aab8285f6476185941f036b6df918df9921'}
data.
The PDF extraction data was updated.
- The st_metadata property was set to
{'pdf_file_size_bytes': 976160, 'pdf_is_encrypted': False, 'pdf_number_of_pages': 88, '/Author': 'Ulrich Stutenbäumer, Giesecke + Devrient Mobile Security GmbH', '/CreationDate': "D:20200813110600+02'00'", '/Creator': 'Microsoft® Word für Office 365', '/Keywords': 'smartcard programmed on a contactless chip for machine readable travel documents (MRTD) based on the requirements and recommendations of the International Civil Aviation Organization (ICAO). It addresses the advanced security methods Basic Access Control in the ‘ICAO Doc 9303’. Version 1.5/Status 12.08.2020', '/ModDate': "D:20200813111747+02'00'", '/Producer': 'Microsoft® Word für Office 365', '/Subject': 'Target of Evaluation = STARCOS 3.7 ID eAT BAC C1, STARCOS 3.7 ID ePass BAC C1', '/Title': 'Security Target Lite', 'pdf_hyperlinks': {'_type': 'Set', 'elements': []}}
. - The cert_metadata property was set to
{'pdf_file_size_bytes': 298425, 'pdf_is_encrypted': False, 'pdf_number_of_pages': 1, '/Author': 'Bundesamt für Sicherheit in der Informationstechnik', '/CreationDate': "D:20200821064941+02'00'", '/Creator': 'Writer', '/Keywords': 'Common Criteria, Certification, Zertifizierung, STARCOS 3.7, BAC, MRTD', '/ModDate': "D:20200821065058+02'00'", '/Producer': 'LibreOffice 6.2', '/Subject': 'STARCOS 3.7 ID eAT BAC C1, STARCOS 3.7 ID ePass BAC C1', '/Title': 'Certificate BSI-DSZ-CC-1076-2020', 'pdf_hyperlinks': {'_type': 'Set', 'elements': []}}
. - The st_keywords property was set to
{'cc_cert_id': {'DE': {'BSI-DSZ-CC-1110-V3-2020': 1}}, 'cc_protection_profile_id': {'BSI': {'BSI-PP-0002-2001': 1, 'BSI-PP- 0035-2007': 1, 'BSI-CC-PP-0056-2009': 1}}, 'cc_security_level': {'EAL': {'EAL6': 1, 'EAL4': 8, 'EAL 4': 2, 'EAL 6': 2, 'EAL4 augmented': 2}}, 'cc_sar': {'ADV': {'ADV_ARC.1': 2}, 'ALC': {'ALC_DVS.2': 6, 'ALC_DVS': 1, 'ALC_FLR.1': 1}}, 'cc_sfr': {'FAU': {'FAU_SAS': 5, 'FAU_GEN': 1, 'FAU_SAS.1': 16, 'FAU_SAS.1.1': 2, 'FAU_UAU.4': 1}, 'FCS': {'FCS_RND': 5, 'FCS_RND.1': 16, 'FCS_CKM.1': 25, 'FCS_RND.1.1': 2, 'FCS_CKM.2': 1, 'FCS_COP.1': 18, 'FCS_CKM.4': 21, 'FCS_CKM.1.1': 1, 'FCS_CKM.4.1': 1, 'FCS_COP': 36, 'FCS_RNG.1': 3, 'FCS_FLS.1': 1}, 'FDP': {'FDP_ACF': 2, 'FDP_ITC.1': 10, 'FDP_ITC.2': 10, 'FDP_ACC.1': 19, 'FDP_ACF.1': 12, 'FDP_ACC.1.1': 1, 'FDP_ACF.1.1': 1, 'FDP_ACF.1.2': 2, 'FDP_ACF.1.3': 1, 'FDP_ACF.1.4': 2, 'FDP_UCT.1': 10, 'FDP_UIT.1': 8, 'FDP_IFC.1': 5, 'FDP_UCT.1.1': 1, 'FDP_UIT.1.1': 1, 'FDP_UIT.1.2': 1, 'FDP_ITC': 2, 'FDP_ITT.1': 1, 'FDP_SDI.1': 1, 'FDP_SDI.2': 1, 'FDP_ACC': 1}, 'FIA': {'FIA_SOS.2': 1, 'FIA_UAU.5.2': 4, 'FIA_UAU.4': 14, 'FIA_UAU.6': 10, 'FIA_UID.1': 11, 'FIA_UID.1.1': 1, 'FIA_UID.1.2': 1, 'FIA_UAU.1': 9, 'FIA_UAU.1.1': 1, 'FIA_UAU.1.2': 1, 'FIA_UAU.4.1': 1, 'FIA_UAU.5': 10, 'FIA_UAU.5.1': 1, 'FIA_UAU.6.1': 1, 'FIA_AFL.1': 7, 'FIA_AFL.1.1': 1, 'FIA_AFL.1.2': 1, 'FIA_API.1': 1}, 'FMT': {'FMT_LIM': 12, 'FMT_LIM.1': 26, 'FMT_LIM.2': 22, 'FMT_LIM.1.1': 3, 'FMT_LIM.2.1': 4, 'FMT_MTD.1': 7, 'FMT_MSA.3': 4, 'FMT_SMF.1': 22, 'FMT_SMR.1': 21, 'FMT_SMF.1.1': 1, 'FMT_SMR.1.1': 1, 'FMT_SMR.1.2': 1, 'FMT_MTD': 22, 'FMT_MSA.1': 2}, 'FPT': {'FPT_FLS.1': 17, 'FPT_TST.1': 12, 'FPT_PHP.3': 15, 'FPT_FLS.1.1': 1, 'FPT_TST': 1, 'FPT_TST.1.1': 1, 'FPT_TST.1.2': 1, 'FPT_TST.1.3': 2, 'FPT_PHP.3.1': 1, 'FPT_RVM.1': 1, 'FPT_SEP.1': 1, 'FPT_TST.2': 4, 'FPT_ITT.1': 1}, 'FRU': {'FRU_FLT.2': 3}, 'FTP': {'FTP_ITC.1': 6, 'FTP_TRP.1': 5}}, 'cc_claims': {'O': {'O.RND': 3, 'O.MEM_ACCESS': 1}, 'T': {'T.RND': 3}}, 'vendor': {'Infineon': {'Infineon': 2, 'Infineon Technologies AG': 1}, 'GD': {'Giesecke+Devrient': 8}}, 'eval_facility': {}, 'symmetric_crypto': {'AES_competition': {'AES': {'AES': 8}}, 'DES': {'DES': {'DES': 5}, '3DES': {'Triple-DES': 10}}, 'constructions': {'MAC': {'KMAC': 1}}}, 'asymmetric_crypto': {'ECC': {'ECDSA': {'ECDSA': 1}}}, 'pq_crypto': {}, 'hash_function': {'SHA': {'SHA1': {'SHA-1': 3}}}, 'crypto_scheme': {'MAC': {'MAC': 4}}, 'crypto_protocol': {}, 'randomness': {'RNG': {'RND': 7, 'RNG': 8}}, 'cipher_mode': {'CBC': {'CBC': 1}}, 'ecc_curve': {}, 'crypto_engine': {}, 'tls_cipher_suite': {}, 'crypto_library': {}, 'vulnerability': {}, 'side_channel_analysis': {'SCA': {'Leak-Inherent': 6, 'physical probing': 3, 'DPA': 2, 'SPA': 1, 'timing attacks': 1}, 'FI': {'Physical Tampering': 5, 'physical tampering': 6, 'Physical tampering': 1, 'Malfunction': 13, 'malfunction': 6, 'fault injection': 1}, 'other': {'reverse engineering': 1}}, 'technical_report_id': {}, 'device_model': {}, 'tee_name': {}, 'os_name': {'STARCOS': {'STARCOS 3': 190}}, 'cplc_data': {}, 'ic_data_group': {'EF': {'EF.DG1': 33, 'EF.DG2': 11, 'EF.DG3': 11, 'EF.DG4': 10, 'EF.DG5': 9, 'EF.DG16': 32, 'EF.DG13': 3, 'EF.DG14': 3, 'EF.DG15': 1, 'EF.COM': 12, 'EF.SOD': 12}}, 'standard_id': {'FIPS': {'FIPS 180-415': 1, 'FIPS 46-3': 2, 'FIPS 180-2': 1, 'FIPS 197': 2, 'FIPS PUB 46-3': 1, 'FIPS PUB 186-2': 1}, 'BSI': {'AIS20': 1, 'AIS 20': 1, 'AIS 31': 1, 'AIS 32': 1}, 'RFC': {'RFC3369': 1}, 'ISO': {'ISO/IEC 7816-2': 1, 'ISO/IEC 14443': 2, 'ISO/IEC 7816-4': 1}, 'ICAO': {'ICAO': 14}, 'CC': {'CCMB-2017-04-001': 2, 'CCMB-2017-04-002': 2, 'CCMB-2017-04-003': 2, 'CCMB-2017-04-004': 2}}, 'javacard_version': {}, 'javacard_api_const': {}, 'javacard_packages': {}, 'certification_process': {}}
. - The cert_keywords property was set to
{'cc_cert_id': {'DE': {'BSI-DSZ-CC-1076-2020': 1}}, 'cc_protection_profile_id': {'BSI': {'BSI-CC-PP- 0055-2009': 1}}, 'cc_security_level': {'EAL': {'EAL 4': 1, 'EAL 5': 1, 'EAL 2': 1, 'EAL 4 augmented': 1}}, 'cc_sar': {'ALC': {'ALC_DVS.2': 1}}, 'cc_sfr': {}, 'cc_claims': {}, 'vendor': {'GD': {'Giesecke+Devrient': 1}}, 'eval_facility': {}, 'symmetric_crypto': {}, 'asymmetric_crypto': {}, 'pq_crypto': {}, 'hash_function': {}, 'crypto_scheme': {}, 'crypto_protocol': {}, 'randomness': {}, 'cipher_mode': {}, 'ecc_curve': {}, 'crypto_engine': {}, 'tls_cipher_suite': {}, 'crypto_library': {}, 'vulnerability': {}, 'side_channel_analysis': {}, 'technical_report_id': {}, 'device_model': {}, 'tee_name': {}, 'os_name': {'STARCOS': {'STARCOS 3': 2}}, 'cplc_data': {}, 'ic_data_group': {}, 'standard_id': {'ISO': {'ISO/IEC 15408': 2, 'ISO/IEC 18045': 2}, 'ICAO': {'ICAO': 1}}, 'javacard_version': {}, 'javacard_api_const': {}, 'javacard_packages': {}, 'certification_process': {}}
. - The st_filename property was set to
1076b_pdf.pdf
. - The cert_filename property was set to
1076c_pdf.pdf
.
The computed heuristics were updated.
- The st_references property was updated, with the
{'directly_referencing': {'_type': 'Set', 'elements': ['BSI-DSZ-CC-1110-V3-2020']}, 'indirectly_referencing': {'_type': 'Set', 'elements': ['BSI-DSZ-CC-1110-V3-2020']}}
data. - The report_references property was updated, with the
{'indirectly_referencing': {'__add__': {'_type': 'Set', 'elements': ['BSI-DSZ-CC-0782-2012', 'BSI-DSZ-CC-0891-V2-2016', 'BSI-DSZ-CC-1110-2019', 'BSI-DSZ-CC-0945-2017', 'BSI-DSZ-CC-0945-V3-2018', 'BSI-DSZ-CC-1110-V2-2019', 'BSI-DSZ-CC-0945-V2-2018', 'BSI-DSZ-CC-0891-2015']}}}
data. - The extracted_sars property was updated, with the
{'_type': 'Set', 'elements': [{'_type': 'sec_certs.sample.sar.SAR', 'family': 'ALC_FLR', 'level': 1}, {'_type': 'sec_certs.sample.sar.SAR', 'family': 'ADV_ARC', 'level': 1}]}
values added.
- The st property was updated, with the
-
19.08.2024 The certificate data changed.
Certificate changed
The computed heuristics were updated.
- The report_references property was updated, with the
{'directly_referencing': {'_type': 'Set', 'elements': ['BSI-DSZ-CC-1110-V3-2020']}, 'indirectly_referencing': {'_type': 'Set', 'elements': ['BSI-DSZ-CC-1110-V3-2020']}}
data.
- The report_references property was updated, with the
-
17.08.2024 The certificate data changed.
Certificate changed
The report_link was updated.
- The new value is
https://www.commoncriteriaportal.org/nfs/ccpfiles/files/epfiles/1076a_pdf.pdf
.
The st_link was updated.
- The new value is
https://www.commoncriteriaportal.org/nfs/ccpfiles/files/epfiles/1076b_pdf.pdf
.
The state of the certificate object was updated.
- The report property was updated, with the
{'download_ok': True, 'convert_ok': True, 'extract_ok': True, 'pdf_hash': '7f12b09dee42fb29a9cfb85f6619b1992e689767a5e1f983f875c3dade6ccb85', 'txt_hash': '79b30fa5296033604c81414b86fbb22f48a1ca6f0a8f42c8aeca87800942afee'}
data. - The st property was updated, with the
{'download_ok': False, 'convert_ok': False, 'extract_ok': False, 'pdf_hash': None, 'txt_hash': None}
data. - The cert property was updated, with the
{'download_ok': False, 'convert_ok': False, 'extract_ok': False, 'pdf_hash': None, 'txt_hash': None}
data.
The PDF extraction data was updated.
- The report_metadata property was set to
{'pdf_file_size_bytes': 476034, 'pdf_is_encrypted': False, 'pdf_number_of_pages': 33, '/Author': 'Bundesamt für Sicherheit in der Informationstechnik', '/CreationDate': "D:20200821063851+02'00'", '/Creator': 'Writer', '/Keywords': '"Common Criteria, Certification, Zertifizierung, STARCOS 3.7, BAC, MRTD"', '/ModDate': "D:20200821131000+02'00'", '/Producer': 'LibreOffice 6.2', '/Subject': 'STARCOS 3.7 ID eAT BAC C1, STARCOS 3.7 ID ePass BAC C1', '/Title': 'Certification Report BSI-DSZ-CC-1076-2020', 'pdf_hyperlinks': {'_type': 'Set', 'elements': ['https://www.bsi.bund.de/', 'http://www.commoncriteriaportal.org/cc/', 'https://www.bsi.bund.de/zertifizierung', 'http://www.commoncriteriaportal.org/', 'https://www.bsi.bund.de/AIS', 'https://www.bsi.bund.de/zertifizierungsreporte', 'https://www.sogis.eu/']}}
. - The st_metadata property was set to
None
. - The cert_metadata property was set to
None
. - The report_frontpage property was set to
{'DE': {'match_rules': ['(BSI-DSZ-CC-.+?) (?:for|For) (.+?) from (.*)'], 'cert_id': 'BSI-DSZ-CC-1076-2020', 'cert_item': 'STARCOS 3.7 ID eAT BAC C1, STARCOS 3.7 ID ePass BAC C1', 'developer': 'Giesecke+Devrient Mobile Security GmbH', 'cert_lab': 'BSI', 'ref_protection_profiles': 'Common Criteria Protection Profile Machine Readable Travel Document with "ICAO Application" Basic Access Control, Version 1.10, 25 March 2009, BSI-CC-PP- 0055-2009', 'cc_version': 'PP conformant Common Criteria Part 2 extended', 'cc_security_level': 'Common Criteria Part 3 conformant EAL 4 augmented by ALC_DVS.2'}}
. - The report_keywords property was set to
{'cc_cert_id': {'DE': {'BSI-DSZ-CC-1076-2020': 22, 'BSI-DSZ-CC-1077': 5, 'BSI-DSZ-CC-1110-V3-': 3, 'BSI-DSZ-CC-1110-V3-2020': 5, 'BSI-DSZ-CC-S-0132-2019': 1, 'BSI-DSZ-CC-S-0152-2020': 1, 'BSI-DSZ-CC-S-0150-2020': 2, 'BSI-DSZ-CC-S-0143-2019': 2}}, 'cc_protection_profile_id': {'BSI': {'BSI-CC-PP- 0055-2009': 1, 'BSI-PP-0055-2009': 1, 'BSI-PP-0055-': 1}}, 'cc_security_level': {'EAL': {'EAL 4': 5, 'EAL 5': 4, 'EAL 2': 2, 'EAL 1': 1, 'EAL 2+': 1, 'EAL5+': 1, 'EAL6': 1, 'EAL 5+': 1, 'EAL 6': 1, 'EAL 4 augmented': 3}}, 'cc_sar': {'ADV': {'ADV_ARC': 1}, 'ALC': {'ALC_DVS.2': 5, 'ALC_FLR': 2, 'ALC_CMC.4': 1, 'ALC_CMS.4': 1, 'ALC_DEL.1': 1, 'ALC_LCD.1': 1, 'ALC_TAT.1': 1}}, 'cc_sfr': {'FCS': {'FCS_COP': 8, 'FCS_CKM.1': 1, 'FCS_RND.1': 1}, 'FDP': {'FDP_UIT.1': 1}, 'FIA': {'FIA_UAU.4': 1, 'FIA_AFL.1': 1}}, 'cc_claims': {'A': {'A.U': 2}}, 'vendor': {'Infineon': {'Infineon': 9, 'Infineon Technologies AG': 7}, 'GD': {'Giesecke+Devrient': 24}}, 'eval_facility': {'TUV': {'TÜV Informationstechnik': 1}, 'SRC': {'SRC Security Research & Consulting': 3}}, 'symmetric_crypto': {'AES_competition': {'AES': {'AES': 5}}, 'DES': {'DES': {'DES': 4}, '3DES': {'3DES': 4, 'TDES': 2}}, 'constructions': {'MAC': {'CMAC': 1}}}, 'asymmetric_crypto': {'ECC': {'ECDH': {'ECDH': 1}, 'ECIES': {'ECIES': 2}, 'ECC': {'ECC': 1}}, 'FF': {'DH': {'Diffie-Hellman': 1}}}, 'pq_crypto': {}, 'hash_function': {'SHA': {'SHA1': {'SHA-1': 3}}}, 'crypto_scheme': {'MAC': {'MAC': 2}, 'KA': {'Key Agreement': 1}}, 'crypto_protocol': {'PACE': {'PACE': 3}}, 'randomness': {'RNG': {'RNG': 2}}, 'cipher_mode': {'CBC': {'CBC': 5}}, 'ecc_curve': {}, 'crypto_engine': {}, 'tls_cipher_suite': {}, 'crypto_library': {}, 'vulnerability': {}, 'side_channel_analysis': {'SCA': {'side channel': 1}, 'FI': {'physical tampering': 1, 'malfunction': 1, 'fault injection': 1}, 'other': {'JIL': 5}}, 'technical_report_id': {'BSI': {'BSI TR-03116': 4, 'BSI TR-03110': 1, 'BSI TR-03116-2': 2, 'BSI TR-02102-1': 1, 'BSI 7148': 1}}, 'device_model': {}, 'tee_name': {}, 'os_name': {'STARCOS': {'STARCOS 3': 56}}, 'cplc_data': {}, 'ic_data_group': {}, 'standard_id': {'FIPS': {'FIPS46-3': 4, 'FIPS197': 2, 'FIPS180': 3, 'FIPS PUB 46-3': 1, 'FIPS PUB 180-4': 1, 'FIPS PUB 197': 1}, 'BSI': {'AIS 34': 4, 'AIS 36': 3, 'AIS 37': 2, 'AIS 26': 4, 'AIS 25': 4, 'AIS 20': 3, 'AIS 31': 3, 'AIS 46': 2, 'AIS 35': 2, 'AIS 1': 1, 'AIS 14': 1, 'AIS 19': 1, 'AIS 23': 1, 'AIS 32': 1, 'AIS 38': 1, 'AIS20': 2, 'AIS31': 2}, 'ISO': {'ISO/IEC 15408': 4, 'ISO/IEC 18045': 4, 'ISO/IEC 17065': 2, 'ISO/IEC 18031:2005': 1}, 'ICAO': {'ICAO': 19}}, 'javacard_version': {}, 'javacard_api_const': {}, 'javacard_packages': {}, 'certification_process': {'ConfidentialDocument': {'being maintained, is not given any longer. In particular, prior to the dissemination of confidential documentation and information related to the TOE or resulting from the evaluation and certification': 1, 'STARCOS 3.7 ID ePass BAC C1, Version 1.5, 12 August 2020, Giesecke+Devrient Mobile Security GmbH (confidential document) [7] Security Target Lite BSI-DSZ-CC-1076-2020, Security Target Lite STARCOS 3.7 ID eAT BAC C1': 1, 'STARCOS 3.7 ID ePass BAC C1, Version 1.2, 13 August 2020, SRC Security Research & Consulting GmbH (confidential document) [10] Configuration List BSI-DSZ-CC-1076-2020, Configuration List STARCOS 3.7 ID eAT BAC C1': 1, '3.7 ID ePass BAC C1, Version 0.2, 12 August 2020, Giesecke+Devrient Mobile Security GmbH (confidential document) [11] Guidance Documentation STARCOS 3.7 ID C1 – Main Document, Version 1.01, 21 July 2020': 1, 'H13, Revision 3.3, 22 April 2020, Infineon Technologies AG, BSI-DSZ-CC-1110-V3- 2020 (confidential document) Security Target Lite of the underlying hardware platform, Common Criteria Public Security Target': 1, 'procedure BSI-DSZ-CC-1110-V3-2020, Version 1, 23 April 2020, TÜV Informationstechnik GmbH (confidential document) [19] Technical Guideline BSI TR-03110: Advanced Security Mechanisms for Machine Readable Travel': 1}}}
. - The st_keywords property was set to
None
. - The cert_keywords property was set to
None
. - The report_filename property was set to
1076a_pdf.pdf
. - The st_filename property was set to
None
. - The cert_filename property was set to
None
.
The computed heuristics were updated.
- The cert_lab property was set to
['BSI']
. - The st_references property was updated, with the
{'directly_referencing': None, 'indirectly_referencing': None}
data. - The extracted_sars property was updated, with the
{'_type': 'Set', 'elements': [{'_type': 'sec_certs.sample.sar.SAR', 'family': 'ALC_DEL', 'level': 1}, {'_type': 'sec_certs.sample.sar.SAR', 'family': 'ALC_CMC', 'level': 4}, {'_type': 'sec_certs.sample.sar.SAR', 'family': 'ALC_LCD', 'level': 1}, {'_type': 'sec_certs.sample.sar.SAR', 'family': 'ALC_CMS', 'level': 4}, {'_type': 'sec_certs.sample.sar.SAR', 'family': 'ALC_TAT', 'level': 1}]}
values added.
- The new value is
-
12.08.2024 The certificate data changed.
Certificate changed
The state of the certificate object was updated.
- The report property was updated, with the
{'download_ok': False, 'convert_ok': False, 'extract_ok': False, 'pdf_hash': None, 'txt_hash': None}
data.
The PDF extraction data was updated.
- The report_metadata property was set to
None
. - The report_frontpage property was set to
None
. - The report_keywords property was set to
None
. - The report_filename property was set to
None
.
The computed heuristics were updated.
- The cert_lab property was set to
None
. - The report_references property was updated, with the
{'directly_referencing': None, 'indirectly_referencing': None}
data. - The extracted_sars property was updated, with the
{'_type': 'Set', 'elements': [{'_type': 'sec_certs.sample.sar.SAR', 'family': 'ALC_DEL', 'level': 1}, {'_type': 'sec_certs.sample.sar.SAR', 'family': 'ALC_CMC', 'level': 4}, {'_type': 'sec_certs.sample.sar.SAR', 'family': 'ALC_LCD', 'level': 1}, {'_type': 'sec_certs.sample.sar.SAR', 'family': 'ALC_CMS', 'level': 4}, {'_type': 'sec_certs.sample.sar.SAR', 'family': 'ALC_TAT', 'level': 1}]}
values discarded.
- The report property was updated, with the
-
23.07.2024 The certificate was first processed.
New certificate
A new Common Criteria certificate with the product name STARCOS 3.7 ID eAT BAC C1, STARCOS 3.7 ID ePass BAC C1 was processed.
Raw data
{
"_type": "sec_certs.sample.cc.CCCertificate",
"category": "ICs, Smart Cards and Smart Card-Related Devices and Systems",
"cert_link": "https://www.commoncriteriaportal.org/nfs/ccpfiles/files/epfiles/1076c_pdf.pdf",
"dgst": "bf65789ff15eff6f",
"heuristics": {
"_type": "sec_certs.sample.cc.CCCertificate.Heuristics",
"annotated_references": null,
"cert_id": "BSI-DSZ-CC-1076-2020",
"cert_lab": [
"BSI"
],
"cpe_matches": null,
"direct_transitive_cves": null,
"extracted_sars": {
"_type": "Set",
"elements": [
{
"_type": "sec_certs.sample.sar.SAR",
"family": "ALC_FLR",
"level": 1
},
{
"_type": "sec_certs.sample.sar.SAR",
"family": "ALC_DVS",
"level": 2
},
{
"_type": "sec_certs.sample.sar.SAR",
"family": "ALC_CMS",
"level": 4
},
{
"_type": "sec_certs.sample.sar.SAR",
"family": "ALC_TAT",
"level": 1
},
{
"_type": "sec_certs.sample.sar.SAR",
"family": "ALC_LCD",
"level": 1
},
{
"_type": "sec_certs.sample.sar.SAR",
"family": "ALC_CMC",
"level": 4
},
{
"_type": "sec_certs.sample.sar.SAR",
"family": "ADV_ARC",
"level": 1
},
{
"_type": "sec_certs.sample.sar.SAR",
"family": "ALC_DEL",
"level": 1
}
]
},
"extracted_versions": {
"_type": "Set",
"elements": [
"3.7"
]
},
"indirect_transitive_cves": null,
"related_cves": null,
"report_references": {
"_type": "sec_certs.sample.certificate.References",
"directly_referenced_by": null,
"directly_referencing": {
"_type": "Set",
"elements": [
"BSI-DSZ-CC-1110-V3-2020"
]
},
"indirectly_referenced_by": null,
"indirectly_referencing": {
"_type": "Set",
"elements": [
"BSI-DSZ-CC-0891-V2-2016",
"BSI-DSZ-CC-0945-2017",
"BSI-DSZ-CC-0891-2015",
"BSI-DSZ-CC-1110-V3-2020",
"BSI-DSZ-CC-0782-2012",
"BSI-DSZ-CC-0945-V2-2018",
"BSI-DSZ-CC-1110-V2-2019",
"BSI-DSZ-CC-1110-2019",
"BSI-DSZ-CC-0945-V3-2018"
]
}
},
"scheme_data": {
"category": "eHealth",
"cert_id": "BSI-DSZ-CC-0916-2015",
"certification_date": "2015-08-07",
"enhanced": {
"applicant": "Giesecke \u0026 Devrient GmbH seit 1. Juli 2017 Giesecke+Devrient Mobile Security GmbH Prinzregentenstr. 159 81677 M\u00fcnchen",
"assurance_level": "EAL4+,ALC_DVS.2,ATE_DPT.2,AVA_VAN.5",
"certification_date": "2015-08-07",
"description": "The Target of Evaluation (TOE) is the product STARCOS 3.6 COS C1 developed by Giesecke \u0026 Devrient GmbH. The TOE is a smart card product according to the G2 Card Operating System specification from gematik. The TOE is intended to be used as a card operating system platform for different card types and applications of the card generation G2 in the framework of the German health care system. The TOE implements from the PP-0082-V2 the base part and the packages Crypto Box, Logical Channel and Contactless.",
"entries": [
{
"description": "The changes are related to an update and reevaluation of the product life-cycle caused by changes in the development and porduction sites. The certified product itself did not change.",
"id": "BSI-DSZ-CC-0916-2015-MA-02"
},
{
"description": "Maintenance Report",
"id": "BSI-DSZ-CC-0916-2015-MA-01"
},
{
"description": "Security Target",
"id": "BSI-DSZ-CC-0916-2015"
}
],
"evaluation_facility": "SRC Security Research \u0026 Consulting GmbH",
"expiration_date": "2020-08-06",
"product": "STARCOS 3.6 COS C1",
"protection_profile": "Card Operating System Generation 2 (PP COS G2), Version 1.9, 18 November 2014, BSI-CC-PP-0082-V2-2014",
"report_link": "https://www.bsi.bund.de/SharedDocs/Downloads/DE/BSI/Zertifizierung/Reporte/Reporte09/0916a_pdf.pdf?__blob=publicationFile\u0026v=1",
"target_link": "https://www.bsi.bund.de/SharedDocs/Downloads/DE/BSI/Zertifizierung/Reporte/Reporte09/0916b_pdf.pdf?__blob=publicationFile\u0026v=1"
},
"product": "STARCOS 3.6 COS C1",
"subcategory": "Smartcards",
"url": "https://www.bsi.bund.de/SharedDocs/Zertifikate_CC/CC/Gesundheitswesen_SmartCards/0916.html",
"vendor": "Giesecke \u0026 Devrient GmbH seit 1. Juli 2017 Giesecke+Devrient Mobile Security GmbH"
},
"st_references": {
"_type": "sec_certs.sample.certificate.References",
"directly_referenced_by": null,
"directly_referencing": {
"_type": "Set",
"elements": [
"BSI-DSZ-CC-1110-V3-2020"
]
},
"indirectly_referenced_by": null,
"indirectly_referencing": {
"_type": "Set",
"elements": [
"BSI-DSZ-CC-1110-V3-2020"
]
}
},
"verified_cpe_matches": null
},
"maintenance_updates": {
"_type": "Set",
"elements": []
},
"manufacturer": "G+D Mobile Security GmbH",
"manufacturer_web": "https://www.gi-de.com/de/de/mobile-security/",
"name": "STARCOS 3.7 ID eAT BAC C1, STARCOS 3.7 ID ePass BAC C1",
"not_valid_after": "2025-08-18",
"not_valid_before": "2020-08-18",
"pdf_data": {
"_type": "sec_certs.sample.cc.CCCertificate.PdfData",
"cert_filename": "1076c_pdf.pdf",
"cert_frontpage": null,
"cert_keywords": {
"asymmetric_crypto": {},
"cc_cert_id": {
"DE": {
"BSI-DSZ-CC-1076-2020": 1
}
},
"cc_claims": {},
"cc_protection_profile_id": {
"BSI": {
"BSI-CC-PP- 0055-2009": 1
}
},
"cc_sar": {
"ALC": {
"ALC_DVS.2": 1
}
},
"cc_security_level": {
"EAL": {
"EAL 2": 1,
"EAL 4": 1,
"EAL 4 augmented": 1,
"EAL 5": 1
}
},
"cc_sfr": {},
"certification_process": {},
"cipher_mode": {},
"cplc_data": {},
"crypto_engine": {},
"crypto_library": {},
"crypto_protocol": {},
"crypto_scheme": {},
"device_model": {},
"ecc_curve": {},
"eval_facility": {},
"hash_function": {},
"ic_data_group": {},
"javacard_api_const": {},
"javacard_packages": {},
"javacard_version": {},
"os_name": {
"STARCOS": {
"STARCOS 3": 2
}
},
"pq_crypto": {},
"randomness": {},
"side_channel_analysis": {},
"standard_id": {
"ICAO": {
"ICAO": 1
},
"ISO": {
"ISO/IEC 15408": 2,
"ISO/IEC 18045": 2
}
},
"symmetric_crypto": {},
"technical_report_id": {},
"tee_name": {},
"tls_cipher_suite": {},
"vendor": {
"GD": {
"Giesecke+Devrient": 1
}
},
"vulnerability": {}
},
"cert_metadata": {
"/Author": "Bundesamt f\u00fcr Sicherheit in der Informationstechnik",
"/CreationDate": "D:20200821064941+02\u002700\u0027",
"/Creator": "Writer",
"/Keywords": "Common Criteria, Certification, Zertifizierung, STARCOS 3.7, BAC, MRTD",
"/ModDate": "D:20200821065058+02\u002700\u0027",
"/Producer": "LibreOffice 6.2",
"/Subject": "STARCOS 3.7 ID eAT BAC C1, STARCOS 3.7 ID ePass BAC C1",
"/Title": "Certificate BSI-DSZ-CC-1076-2020",
"pdf_file_size_bytes": 298425,
"pdf_hyperlinks": {
"_type": "Set",
"elements": []
},
"pdf_is_encrypted": false,
"pdf_number_of_pages": 1
},
"report_filename": "1076a_pdf.pdf",
"report_frontpage": {
"DE": {
"cc_security_level": "Common Criteria Part 3 conformant EAL 4 augmented by ALC_DVS.2",
"cc_version": "PP conformant Common Criteria Part 2 extended",
"cert_id": "BSI-DSZ-CC-1076-2020",
"cert_item": "STARCOS 3.7 ID eAT BAC C1, STARCOS 3.7 ID ePass BAC C1",
"cert_lab": "BSI",
"developer": "Giesecke+Devrient Mobile Security GmbH",
"match_rules": [
"(BSI-DSZ-CC-.+?) (?:for|For) (.+?) from (.*)"
],
"ref_protection_profiles": "Common Criteria Protection Profile Machine Readable Travel Document with \"ICAO Application\" Basic Access Control, Version 1.10, 25 March 2009, BSI-CC-PP- 0055-2009"
}
},
"report_keywords": {
"asymmetric_crypto": {
"ECC": {
"ECC": {
"ECC": 1
},
"ECDH": {
"ECDH": 1
},
"ECIES": {
"ECIES": 2
}
},
"FF": {
"DH": {
"Diffie-Hellman": 1
}
}
},
"cc_cert_id": {
"DE": {
"BSI-DSZ-CC-1076-2020": 22,
"BSI-DSZ-CC-1077": 5,
"BSI-DSZ-CC-1110-V3-": 3,
"BSI-DSZ-CC-1110-V3-2020": 5,
"BSI-DSZ-CC-S-0132-2019": 1,
"BSI-DSZ-CC-S-0143-2019": 2,
"BSI-DSZ-CC-S-0150-2020": 2,
"BSI-DSZ-CC-S-0152-2020": 1
}
},
"cc_claims": {
"A": {
"A.U": 2
}
},
"cc_protection_profile_id": {
"BSI": {
"BSI-CC-PP- 0055-2009": 1,
"BSI-PP-0055-": 1,
"BSI-PP-0055-2009": 1
}
},
"cc_sar": {
"ADV": {
"ADV_ARC": 1
},
"ALC": {
"ALC_CMC.4": 1,
"ALC_CMS.4": 1,
"ALC_DEL.1": 1,
"ALC_DVS.2": 5,
"ALC_FLR": 2,
"ALC_LCD.1": 1,
"ALC_TAT.1": 1
}
},
"cc_security_level": {
"EAL": {
"EAL 1": 1,
"EAL 2": 2,
"EAL 2+": 1,
"EAL 4": 5,
"EAL 4 augmented": 3,
"EAL 5": 4,
"EAL 5+": 1,
"EAL 6": 1,
"EAL5+": 1,
"EAL6": 1
}
},
"cc_sfr": {
"FCS": {
"FCS_CKM.1": 1,
"FCS_COP": 8,
"FCS_RND.1": 1
},
"FDP": {
"FDP_UIT.1": 1
},
"FIA": {
"FIA_AFL.1": 1,
"FIA_UAU.4": 1
}
},
"certification_process": {
"ConfidentialDocument": {
"3.7 ID ePass BAC C1, Version 0.2, 12 August 2020, Giesecke+Devrient Mobile Security GmbH (confidential document) [11] Guidance Documentation STARCOS 3.7 ID C1 \u2013 Main Document, Version 1.01, 21 July 2020": 1,
"H13, Revision 3.3, 22 April 2020, Infineon Technologies AG, BSI-DSZ-CC-1110-V3- 2020 (confidential document) Security Target Lite of the underlying hardware platform, Common Criteria Public Security Target": 1,
"STARCOS 3.7 ID ePass BAC C1, Version 1.2, 13 August 2020, SRC Security Research \u0026 Consulting GmbH (confidential document) [10] Configuration List BSI-DSZ-CC-1076-2020, Configuration List STARCOS 3.7 ID eAT BAC C1": 1,
"STARCOS 3.7 ID ePass BAC C1, Version 1.5, 12 August 2020, Giesecke+Devrient Mobile Security GmbH (confidential document) [7] Security Target Lite BSI-DSZ-CC-1076-2020, Security Target Lite STARCOS 3.7 ID eAT BAC C1": 1,
"being maintained, is not given any longer. In particular, prior to the dissemination of confidential documentation and information related to the TOE or resulting from the evaluation and certification": 1,
"procedure BSI-DSZ-CC-1110-V3-2020, Version 1, 23 April 2020, T\u00dcV Informationstechnik GmbH (confidential document) [19] Technical Guideline BSI TR-03110: Advanced Security Mechanisms for Machine Readable Travel": 1
}
},
"cipher_mode": {
"CBC": {
"CBC": 5
}
},
"cplc_data": {},
"crypto_engine": {},
"crypto_library": {},
"crypto_protocol": {
"PACE": {
"PACE": 3
}
},
"crypto_scheme": {
"KA": {
"Key Agreement": 1
},
"MAC": {
"MAC": 2
}
},
"device_model": {},
"ecc_curve": {},
"eval_facility": {
"SRC": {
"SRC Security Research \u0026 Consulting": 3
},
"TUV": {
"T\u00dcV Informationstechnik": 1
}
},
"hash_function": {
"SHA": {
"SHA1": {
"SHA-1": 3
}
}
},
"ic_data_group": {},
"javacard_api_const": {},
"javacard_packages": {},
"javacard_version": {},
"os_name": {
"STARCOS": {
"STARCOS 3": 56
}
},
"pq_crypto": {},
"randomness": {
"RNG": {
"RNG": 2
}
},
"side_channel_analysis": {
"FI": {
"fault injection": 1,
"malfunction": 1,
"physical tampering": 1
},
"SCA": {
"side channel": 1
},
"other": {
"JIL": 5
}
},
"standard_id": {
"BSI": {
"AIS 1": 1,
"AIS 14": 1,
"AIS 19": 1,
"AIS 20": 3,
"AIS 23": 1,
"AIS 25": 4,
"AIS 26": 4,
"AIS 31": 3,
"AIS 32": 1,
"AIS 34": 4,
"AIS 35": 2,
"AIS 36": 3,
"AIS 37": 2,
"AIS 38": 1,
"AIS 46": 2,
"AIS20": 2,
"AIS31": 2
},
"FIPS": {
"FIPS PUB 180-4": 1,
"FIPS PUB 197": 1,
"FIPS PUB 46-3": 1,
"FIPS180": 3,
"FIPS197": 2,
"FIPS46-3": 4
},
"ICAO": {
"ICAO": 19
},
"ISO": {
"ISO/IEC 15408": 4,
"ISO/IEC 17065": 2,
"ISO/IEC 18031:2005": 1,
"ISO/IEC 18045": 4
}
},
"symmetric_crypto": {
"AES_competition": {
"AES": {
"AES": 5
}
},
"DES": {
"3DES": {
"3DES": 4,
"TDES": 2
},
"DES": {
"DES": 4
}
},
"constructions": {
"MAC": {
"CMAC": 1
}
}
},
"technical_report_id": {
"BSI": {
"BSI 7148": 1,
"BSI TR-02102-1": 1,
"BSI TR-03110": 1,
"BSI TR-03116": 4,
"BSI TR-03116-2": 2
}
},
"tee_name": {},
"tls_cipher_suite": {},
"vendor": {
"GD": {
"Giesecke+Devrient": 24
},
"Infineon": {
"Infineon": 9,
"Infineon Technologies AG": 7
}
},
"vulnerability": {}
},
"report_metadata": {
"/Author": "Bundesamt f\u00fcr Sicherheit in der Informationstechnik",
"/CreationDate": "D:20200821063851+02\u002700\u0027",
"/Creator": "Writer",
"/Keywords": "\"Common Criteria, Certification, Zertifizierung, STARCOS 3.7, BAC, MRTD\"",
"/ModDate": "D:20200821131000+02\u002700\u0027",
"/Producer": "LibreOffice 6.2",
"/Subject": "STARCOS 3.7 ID eAT BAC C1, STARCOS 3.7 ID ePass BAC C1",
"/Title": "Certification Report BSI-DSZ-CC-1076-2020",
"pdf_file_size_bytes": 476034,
"pdf_hyperlinks": {
"_type": "Set",
"elements": [
"https://www.bsi.bund.de/AIS",
"https://www.bsi.bund.de/zertifizierungsreporte",
"https://www.bsi.bund.de/zertifizierung",
"http://www.commoncriteriaportal.org/cc/",
"https://www.bsi.bund.de/",
"https://www.sogis.eu/",
"http://www.commoncriteriaportal.org/"
]
},
"pdf_is_encrypted": false,
"pdf_number_of_pages": 33
},
"st_filename": "1076b_pdf.pdf",
"st_frontpage": null,
"st_keywords": {
"asymmetric_crypto": {
"ECC": {
"ECDSA": {
"ECDSA": 1
}
}
},
"cc_cert_id": {
"DE": {
"BSI-DSZ-CC-1110-V3-2020": 1
}
},
"cc_claims": {
"O": {
"O.MEM_ACCESS": 1,
"O.RND": 3
},
"T": {
"T.RND": 3
}
},
"cc_protection_profile_id": {
"BSI": {
"BSI-CC-PP-0056-2009": 1,
"BSI-PP- 0035-2007": 1,
"BSI-PP-0002-2001": 1
}
},
"cc_sar": {
"ADV": {
"ADV_ARC.1": 2
},
"ALC": {
"ALC_DVS": 1,
"ALC_DVS.2": 6,
"ALC_FLR.1": 1
}
},
"cc_security_level": {
"EAL": {
"EAL 4": 2,
"EAL 6": 2,
"EAL4": 8,
"EAL4 augmented": 2,
"EAL6": 1
}
},
"cc_sfr": {
"FAU": {
"FAU_GEN": 1,
"FAU_SAS": 5,
"FAU_SAS.1": 16,
"FAU_SAS.1.1": 2,
"FAU_UAU.4": 1
},
"FCS": {
"FCS_CKM.1": 25,
"FCS_CKM.1.1": 1,
"FCS_CKM.2": 1,
"FCS_CKM.4": 21,
"FCS_CKM.4.1": 1,
"FCS_COP": 36,
"FCS_COP.1": 18,
"FCS_FLS.1": 1,
"FCS_RND": 5,
"FCS_RND.1": 16,
"FCS_RND.1.1": 2,
"FCS_RNG.1": 3
},
"FDP": {
"FDP_ACC": 1,
"FDP_ACC.1": 19,
"FDP_ACC.1.1": 1,
"FDP_ACF": 2,
"FDP_ACF.1": 12,
"FDP_ACF.1.1": 1,
"FDP_ACF.1.2": 2,
"FDP_ACF.1.3": 1,
"FDP_ACF.1.4": 2,
"FDP_IFC.1": 5,
"FDP_ITC": 2,
"FDP_ITC.1": 10,
"FDP_ITC.2": 10,
"FDP_ITT.1": 1,
"FDP_SDI.1": 1,
"FDP_SDI.2": 1,
"FDP_UCT.1": 10,
"FDP_UCT.1.1": 1,
"FDP_UIT.1": 8,
"FDP_UIT.1.1": 1,
"FDP_UIT.1.2": 1
},
"FIA": {
"FIA_AFL.1": 7,
"FIA_AFL.1.1": 1,
"FIA_AFL.1.2": 1,
"FIA_API.1": 1,
"FIA_SOS.2": 1,
"FIA_UAU.1": 9,
"FIA_UAU.1.1": 1,
"FIA_UAU.1.2": 1,
"FIA_UAU.4": 14,
"FIA_UAU.4.1": 1,
"FIA_UAU.5": 10,
"FIA_UAU.5.1": 1,
"FIA_UAU.5.2": 4,
"FIA_UAU.6": 10,
"FIA_UAU.6.1": 1,
"FIA_UID.1": 11,
"FIA_UID.1.1": 1,
"FIA_UID.1.2": 1
},
"FMT": {
"FMT_LIM": 12,
"FMT_LIM.1": 26,
"FMT_LIM.1.1": 3,
"FMT_LIM.2": 22,
"FMT_LIM.2.1": 4,
"FMT_MSA.1": 2,
"FMT_MSA.3": 4,
"FMT_MTD": 22,
"FMT_MTD.1": 7,
"FMT_SMF.1": 22,
"FMT_SMF.1.1": 1,
"FMT_SMR.1": 21,
"FMT_SMR.1.1": 1,
"FMT_SMR.1.2": 1
},
"FPT": {
"FPT_FLS.1": 17,
"FPT_FLS.1.1": 1,
"FPT_ITT.1": 1,
"FPT_PHP.3": 15,
"FPT_PHP.3.1": 1,
"FPT_RVM.1": 1,
"FPT_SEP.1": 1,
"FPT_TST": 1,
"FPT_TST.1": 12,
"FPT_TST.1.1": 1,
"FPT_TST.1.2": 1,
"FPT_TST.1.3": 2,
"FPT_TST.2": 4
},
"FRU": {
"FRU_FLT.2": 3
},
"FTP": {
"FTP_ITC.1": 6,
"FTP_TRP.1": 5
}
},
"certification_process": {},
"cipher_mode": {
"CBC": {
"CBC": 1
}
},
"cplc_data": {},
"crypto_engine": {},
"crypto_library": {},
"crypto_protocol": {},
"crypto_scheme": {
"MAC": {
"MAC": 4
}
},
"device_model": {},
"ecc_curve": {},
"eval_facility": {},
"hash_function": {
"SHA": {
"SHA1": {
"SHA-1": 3
}
}
},
"ic_data_group": {
"EF": {
"EF.COM": 12,
"EF.DG1": 33,
"EF.DG13": 3,
"EF.DG14": 3,
"EF.DG15": 1,
"EF.DG16": 32,
"EF.DG2": 11,
"EF.DG3": 11,
"EF.DG4": 10,
"EF.DG5": 9,
"EF.SOD": 12
}
},
"javacard_api_const": {},
"javacard_packages": {},
"javacard_version": {},
"os_name": {
"STARCOS": {
"STARCOS 3": 190
}
},
"pq_crypto": {},
"randomness": {
"RNG": {
"RND": 7,
"RNG": 8
}
},
"side_channel_analysis": {
"FI": {
"Malfunction": 13,
"Physical Tampering": 5,
"Physical tampering": 1,
"fault injection": 1,
"malfunction": 6,
"physical tampering": 6
},
"SCA": {
"DPA": 2,
"Leak-Inherent": 6,
"SPA": 1,
"physical probing": 3,
"timing attacks": 1
},
"other": {
"reverse engineering": 1
}
},
"standard_id": {
"BSI": {
"AIS 20": 1,
"AIS 31": 1,
"AIS 32": 1,
"AIS20": 1
},
"CC": {
"CCMB-2017-04-001": 2,
"CCMB-2017-04-002": 2,
"CCMB-2017-04-003": 2,
"CCMB-2017-04-004": 2
},
"FIPS": {
"FIPS 180-2": 1,
"FIPS 180-415": 1,
"FIPS 197": 2,
"FIPS 46-3": 2,
"FIPS PUB 186-2": 1,
"FIPS PUB 46-3": 1
},
"ICAO": {
"ICAO": 14
},
"ISO": {
"ISO/IEC 14443": 2,
"ISO/IEC 7816-2": 1,
"ISO/IEC 7816-4": 1
},
"RFC": {
"RFC3369": 1
}
},
"symmetric_crypto": {
"AES_competition": {
"AES": {
"AES": 8
}
},
"DES": {
"3DES": {
"Triple-DES": 10
},
"DES": {
"DES": 5
}
},
"constructions": {
"MAC": {
"KMAC": 1
}
}
},
"technical_report_id": {},
"tee_name": {},
"tls_cipher_suite": {},
"vendor": {
"GD": {
"Giesecke+Devrient": 8
},
"Infineon": {
"Infineon": 2,
"Infineon Technologies AG": 1
}
},
"vulnerability": {}
},
"st_metadata": {
"/Author": "Ulrich Stutenb\u00e4umer, Giesecke + Devrient Mobile Security GmbH",
"/CreationDate": "D:20200813110600+02\u002700\u0027",
"/Creator": "Microsoft\u00ae Word f\u00fcr Office 365",
"/Keywords": "smartcard programmed on a contactless chip for machine readable travel documents (MRTD) based on the requirements and recommendations of the International Civil Aviation Organization (ICAO). It addresses the advanced security methods Basic Access Control in the \u2018ICAO Doc 9303\u2019. Version 1.5/Status 12.08.2020",
"/ModDate": "D:20200813111747+02\u002700\u0027",
"/Producer": "Microsoft\u00ae Word f\u00fcr Office 365",
"/Subject": "Target of Evaluation = STARCOS 3.7 ID eAT BAC C1, STARCOS 3.7 ID ePass BAC C1",
"/Title": "Security Target Lite",
"pdf_file_size_bytes": 976160,
"pdf_hyperlinks": {
"_type": "Set",
"elements": []
},
"pdf_is_encrypted": false,
"pdf_number_of_pages": 88
}
},
"protection_profiles": {
"_type": "Set",
"elements": [
{
"_type": "sec_certs.sample.protection_profile.ProtectionProfile",
"pp_eal": null,
"pp_ids": null,
"pp_link": "https://www.commoncriteriaportal.org/nfs/ccpfiles/files/ppfiles/pp0055b.pdf",
"pp_name": "Protection Profile for Machine Readable Travel Document with \u0027ICAO Application\u0027, Basic Acce..."
}
]
},
"report_link": "https://www.commoncriteriaportal.org/nfs/ccpfiles/files/epfiles/1076a_pdf.pdf",
"scheme": "DE",
"security_level": {
"_type": "Set",
"elements": [
"ALC_DVS.2",
"EAL4+"
]
},
"st_link": "https://www.commoncriteriaportal.org/nfs/ccpfiles/files/epfiles/1076b_pdf.pdf",
"state": {
"_type": "sec_certs.sample.cc.CCCertificate.InternalState",
"cert": {
"_type": "sec_certs.sample.cc.CCCertificate.DocumentState",
"convert_garbage": false,
"convert_ok": true,
"download_ok": true,
"extract_ok": true,
"pdf_hash": "720a97a349d8c6cac309ad5b10cd1fce597a84202f082647a119608330642c16",
"txt_hash": "5a05b94f237b46707fcbec4948fe9aab8285f6476185941f036b6df918df9921"
},
"report": {
"_type": "sec_certs.sample.cc.CCCertificate.DocumentState",
"convert_garbage": false,
"convert_ok": true,
"download_ok": true,
"extract_ok": true,
"pdf_hash": "7f12b09dee42fb29a9cfb85f6619b1992e689767a5e1f983f875c3dade6ccb85",
"txt_hash": "79b30fa5296033604c81414b86fbb22f48a1ca6f0a8f42c8aeca87800942afee"
},
"st": {
"_type": "sec_certs.sample.cc.CCCertificate.DocumentState",
"convert_garbage": false,
"convert_ok": true,
"download_ok": true,
"extract_ok": true,
"pdf_hash": "970d564f830c6d0266fa2d16e6d89a8f74d69ed3a9f057bd70d14e3e61d4a454",
"txt_hash": "5e76dfce19dbdb02ed52b63a9dedd9dcbc3162893ef9b9194f56ccc4c3f48e01"
}
},
"status": "active"
}