Comparing certificates Experimental feature

You are comparing two certificates. By default, only differing attributes are shown. Use the button below to show/hide all attributes.

Showing only differing attributes.
STARCOS 3.7 COS GKV C2
BSI-DSZ-CC-1243-2024
STARCOS 3.7 COS GKV C2
BSI-DSZ-CC-0976-V3-2019
status active archived
not_valid_after 22.08.2029 21.11.2024
not_valid_before 22.08.2024 21.11.2019
cert_link https://www.commoncriteriaportal.org/nfs/ccpfiles/files/epfiles/1243c_pdf.pdf https://www.commoncriteriaportal.org/nfs/ccpfiles/files/epfiles/0976V3c_pdf.pdf
report_link https://www.commoncriteriaportal.org/nfs/ccpfiles/files/epfiles/1243a_pdf.pdf https://www.commoncriteriaportal.org/nfs/ccpfiles/files/epfiles/0976V3a_pdf.pdf
st_link https://www.commoncriteriaportal.org/nfs/ccpfiles/files/epfiles/1243b_pdf.pdf https://www.commoncriteriaportal.org/nfs/ccpfiles/files/epfiles/0976V3b_pdf.pdf
manufacturer Giesecke+Devrient ePayments GmbH G+D Mobile Security GmbH
manufacturer_web https://www.gi-de.com/de/ https://www.gi-de.com/de/de/mobile-security/
security_level AVA_VAN.5, ALC_DVS.2, EAL4+, ATE_DPT.2 AVA_VAN.5, ALC_DVS.1, EAL4+, ATE_DPT.2
dgst 7e00946c0c70e2a7 744d4ed202fc8a80
heuristics/cert_id BSI-DSZ-CC-1243-2024 BSI-DSZ-CC-0976-V3-2019
heuristics/extracted_sars ASE_INT.1, ALC_TAT.1, ATE_FUN.1, ADV_IMP.1, ALC_FLR.1, ASE_TSS.1, AGD_PRE.1, ASE_CCL.1, ALC_CMS.4, ALC_DVS.2, ATE_IND.2, AVA_VAN.5, ASE_SPD.1, ATE_DPT.2, ASE_OBJ.2, ADV_FSP.4, ATE_COV.2, ASE_REQ.2, ALC_CMC.4, ADV_ARC.1, ALC_DEL.1, AGD_OPE.1, ADV_TDS.3, ALC_LCD.1, ASE_ECD.1 ASE_INT.1, ALC_TAT.1, ATE_FUN.1, ALC_DVS.1, ADV_IMP.1, ALC_FLR.1, ASE_TSS.1, AGD_PRE.1, ASE_CCL.1, ALC_CMS.4, ATE_IND.2, AVA_VAN.5, ASE_SPD.1, ATE_DPT.2, ASE_OBJ.2, ADV_FSP.4, ATE_COV.2, ASE_REQ.2, ALC_CMC.4, ADV_ARC.1, ALC_DEL.1, AGD_OPE.1, ADV_TDS.3, ALC_LCD.1, ASE_ECD.1
heuristics/prev_certificates {} BSI-DSZ-CC-0976-2015, BSI-DSZ-CC-0976-V2-2018
heuristics/next_certificates {} BSI-DSZ-CC-0976-V4-2021
heuristics/report_references/directly_referenced_by {} BSI-DSZ-CC-1243-2024, BSI-DSZ-CC-0976-V4-2021
heuristics/report_references/directly_referencing BSI-DSZ-CC-0976-V3-2019, BSI-DSZ-CC-1110-V6-2023 BSI-DSZ-CC-1110-V2-2019, BSI-DSZ-CC-0976-V2-2018
heuristics/report_references/indirectly_referenced_by {} BSI-DSZ-CC-1243-2024, BSI-DSZ-CC-0976-V4-2021
heuristics/report_references/indirectly_referencing BSI-DSZ-CC-0945-V3-2018, BSI-DSZ-CC-0945-V2-2018, BSI-DSZ-CC-0945-2017, BSI-DSZ-CC-1110-V4-2021, BSI-DSZ-CC-0916-2015, BSI-DSZ-CC-1110-V2-2019, BSI-DSZ-CC-0782-2012, BSI-DSZ-CC-1110-V6-2023, BSI-DSZ-CC-0782-V2-2015, BSI-DSZ-CC-1110-2019, BSI-DSZ-CC-0891-2015, BSI-DSZ-CC-1110-V3-2020, BSI-DSZ-CC-0976-V3-2019, BSI-DSZ-CC-0976-2015, BSI-DSZ-CC-0976-V2-2018, BSI-DSZ-CC-0891-V2-2016, BSI-DSZ-CC-1110-V5-2022, BSI-DSZ-CC-0879-2014 BSI-DSZ-CC-0945-V3-2018, BSI-DSZ-CC-0945-V2-2018, BSI-DSZ-CC-0945-2017, BSI-DSZ-CC-0916-2015, BSI-DSZ-CC-1110-V2-2019, BSI-DSZ-CC-0782-2012, BSI-DSZ-CC-0782-V2-2015, BSI-DSZ-CC-1110-2019, BSI-DSZ-CC-0891-2015, BSI-DSZ-CC-0976-V2-2018, BSI-DSZ-CC-0976-2015, BSI-DSZ-CC-0891-V2-2016, BSI-DSZ-CC-0879-2014
heuristics/scheme_data
  • category: eHealth
  • cert_id: BSI-DSZ-CC-1243-2024
  • certification_date: 22.08.2024
  • enhanced:
    • applicant: Giesecke+Devrient ePayments GmbH Prinzregentenstr. 161 81677 München
    • assurance_level: EAL4+,ALC_DVS.2,ATE_DPT.2,AVA_VAN.5
    • cert_link: https://www.bsi.bund.de/SharedDocs/Downloads/DE/BSI/Zertifizierung/Reporte/Reporte1200/1243c_pdf.pdf?__blob=publicationFile&v=2
    • certification_date: 22.08.2024
    • description: The Target of Evaluation (TOE) is the product STARCOS 3.7 COS GKV C2 developed by Giesecke+Devrient ePayments GmbH. The TOE is a smart card product according to the G2 Card Operating System (G2-COS) specification from gematik. The TOE is intended to be used as a card operating system platform for the electronic Health Card (eHC) of the card generation G2.1 in the framework of the German health care system, and therefore implements the mandatory part of the G2-COS specification with the base functionality of the operating system platform and additionally the functional packages "RSA Key Generation" and "Contactless Interface". The TOE uses from the Protection Profile PP-0082-V4 the base part together with the corresponding optional packages. This certification procedure was carried out as a re-evaluation based on the certificate BSI-DSZ-CC-0976-V3-2019 including subsequent maintenance procedures BSI-DSZ-CC-0976-V3-2019-MA-01 and BSI-DSZ-CC-0976-V3-2019-MA-02. The TOE and its implementation itself did not change. The focus of this re-evaluation was on the change of the TOE’s life-cycle model regards production sites including renewal of corresponding site certificates, the update of the underlying HW certificate, and the renewal of the TOE’s vulnerability analysis and assessment including penetration testing of the TOE’s (crypto) implementation.
    • evaluation_facility: SRC Security Research & Consulting GmbH
    • expiration_date: 21.08.2029
    • product: STARCOS 3.7 COS GKV C2
    • protection_profile: Card Operating System Generation 2 (PP COS G2), Version 2.1, 10 July 2019, BSI-CC-PP-0082-V4-2019
    • report_link: https://www.bsi.bund.de/SharedDocs/Downloads/DE/BSI/Zertifizierung/Reporte/Reporte1200/1243a_pdf.pdf?__blob=publicationFile&v=2
    • target_link: https://www.bsi.bund.de/SharedDocs/Downloads/DE/BSI/Zertifizierung/Reporte/Reporte1200/1243b_pdf.pdf?__blob=publicationFile&v=2
  • product: STARCOS 3.7 COS GKV C2
  • subcategory: Smartcards
  • url: https://www.bsi.bund.de/SharedDocs/Zertifikate_CC/CC/Gesundheitswesen_SmartCards/1243.html
  • vendor: Giesecke+Devrient ePayments GmbH
heuristics/st_references/directly_referencing BSI-DSZ-CC-1110-V6-2023 BSI-DSZ-CC-1110-V2-2019
heuristics/st_references/indirectly_referencing BSI-DSZ-CC-1110-V6-2023 BSI-DSZ-CC-1110-V2-2019
maintenance_updates
protection_profiles
pdf_data/cert_filename 1243c_pdf.pdf 0976V3c_pdf.pdf
pdf_data/cert_keywords/cc_cert_id
  • DE:
    • BSI-DSZ-CC-1243-2024: 1
  • DE:
    • BSI-DSZ-CC-0976-V3-2019: 1
pdf_data/cert_metadata
  • /Author: Bundesamt für Sicherheit in der Informationstechnik
  • /Keywords: "Common Criteria, Certification, Zertifizierung, PP-0082-V4, G+D, STARCOS 3.7, eHealth"
  • /Subject: Common Criteria, Certification, Zertifizierung, PP-0082-V4, G+D, STARCOS 3.7, eHealth
  • /Title: Certification Report BSI-DSZ-CC-1243-2024
  • pdf_file_size_bytes: 233610
  • pdf_hyperlinks: {}
  • pdf_is_encrypted: False
  • pdf_number_of_pages: 1
  • /Author: Bundesamt für Sicherheit in der Informationstechnik
  • /CreationDate: D:20191128152454+01'00'
  • /Creator: Writer
  • /Keywords: Common Criteria, Certification, Zertifizierung, PP-0082-V4, G+D, STARCOS 3.7, eHealth
  • /ModDate: D:20191128152705+01'00'
  • /Producer: LibreOffice 6.2
  • /Subject: STARCOS 3.7 COS GKV C2
  • /Title: Certificate BSI-DSZ-CC-0976-V3-2019
  • pdf_file_size_bytes: 294740
  • pdf_hyperlinks: {}
  • pdf_is_encrypted: False
  • pdf_number_of_pages: 1
pdf_data/report_filename 1243a_pdf.pdf 0976V3a_pdf.pdf
pdf_data/report_frontpage
  • DE:
    • cc_security_level: Common Criteria Part 3 conformant EAL 4 augmented by ALC_DVS.2, ATE_DPT.2 and AVA_VAN.5 valid until: 21 August 2029
    • cc_version: PP conformant Common Criteria Part 2 extended
    • cert_id: BSI-DSZ-CC-1243-2024
    • cert_item: STARCOS 3.7 COS GKV C2
    • cert_lab: BSI
    • developer: Giesecke+Devrient ePayments GmbH
    • match_rules: ['(BSI-DSZ-CC-.+?) (?:for|For) (.+?) from (.*)']
    • ref_protection_profiles: Card Operating System Generation 2 (PP COS G2), Version 2.1, 10 July 2019, BSI-CC-PP-0082-V4- 2019
  • DE:
    • cc_security_level: Common Criteria Part 3 conformant EAL 4 augmented by ALC_DVS.2, ATE_DPT.2 and AVA_VAN.5
    • cc_version: PP conformant Common Criteria Part 2 extended
    • cert_id: BSI-DSZ-CC-0976-V3-2019
    • cert_item: STARCOS 3.7 COS GKV C2
    • cert_lab: BSI
    • developer: Giesecke+Devrient Mobile Security GmbH
    • match_rules: ['(BSI-DSZ-CC-.+?) (?:for|For) (.+?) from (.*)']
    • ref_protection_profiles: Card Operating System Generation 2 (PP COS G2), Version 2.1, 10 July 2019, BSI-CC-PP-0082-V4- 2019
pdf_data/report_keywords/cc_cert_id
  • DE:
    • BSI-DSZ-CC-0976-V3-: 2
    • BSI-DSZ-CC-0976-V3-2019: 3
    • BSI-DSZ-CC-0976-V3-2019-MA-01: 2
    • BSI-DSZ-CC-1110-V6-2023: 7
    • BSI-DSZ-CC-1243: 4
    • BSI-DSZ-CC-1243-2024: 21
    • BSI-DSZ-CC-S-0260-2023: 2
  • DE:
    • BSI-DSZ-CC-0976-V2-2018: 3
    • BSI-DSZ-CC-0976-V3-2019: 25
    • BSI-DSZ-CC-1110-: 1
    • BSI-DSZ-CC-1110-V2-2019: 7
    • BSI-DSZ-CC-S-0095-2018: 2
    • BSI-DSZ-CC-S-0132-2019: 1
pdf_data/report_keywords/cc_security_level
  • EAL:
    • EAL 1: 1
    • EAL 2: 3
    • EAL 4: 5
    • EAL 4 augmented: 3
    • EAL 5: 4
    • EAL 5+: 2
    • EAL 6: 2
  • EAL:
    • EAL 1: 1
    • EAL 2: 2
    • EAL 2+: 1
    • EAL 4: 5
    • EAL 4 augmented: 3
    • EAL 5: 4
    • EAL 5+: 1
    • EAL 6: 1
    • EAL5+: 1
    • EAL6: 1
pdf_data/report_keywords/vendor
  • GD:
    • Giesecke+Devrient: 33
  • Infineon:
    • Infineon: 12
    • Infineon Technologies AG: 6
  • GD:
    • Giesecke & Devrient: 2
    • Giesecke+Devrient: 28
  • Infineon:
    • Infineon: 11
    • Infineon Technologies AG: 7
pdf_data/report_keywords/symmetric_crypto
  • AES_competition:
    • AES:
      • AES: 21
    • HPC:
      • HPC: 1
  • constructions:
    • MAC:
      • CMAC: 9
  • AES_competition:
    • AES:
      • AES: 20
    • HPC:
      • HPC: 1
  • constructions:
    • MAC:
      • CMAC: 9
pdf_data/report_keywords/hash_function
  • SHA:
    • SHA2:
      • SHA-256: 3
  • SHA:
    • SHA2:
      • SHA-256: 2
pdf_data/report_keywords/crypto_protocol
  • PACE:
    • PACE: 18
  • PACE:
    • PACE: 13
pdf_data/report_keywords/standard_id
  • BSI:
    • AIS 1: 1
    • AIS 14: 1
    • AIS 19: 1
    • AIS 20: 5
    • AIS 25: 4
    • AIS 26: 4
    • AIS 31: 4
    • AIS 32: 1
    • AIS 34: 4
    • AIS 35: 2
    • AIS 36: 5
    • AIS 37: 3
    • AIS 38: 1
    • AIS 46: 3
  • FIPS:
    • FIPS PUB 180-4: 1
    • FIPS PUB 197: 1
  • ISO:
    • ISO/IEC 15408: 4
    • ISO/IEC 17065: 2
    • ISO/IEC 18031:2005: 1
    • ISO/IEC 18045: 4
  • RFC:
    • RFC 5639: 1
  • BSI:
    • AIS 1: 1
    • AIS 14: 1
    • AIS 19: 1
    • AIS 20: 5
    • AIS 23: 1
    • AIS 25: 4
    • AIS 26: 4
    • AIS 31: 4
    • AIS 32: 1
    • AIS 34: 4
    • AIS 35: 2
    • AIS 36: 5
    • AIS 37: 2
    • AIS 38: 1
    • AIS 46: 2
  • FIPS:
    • FIPS PUB 180-4: 1
    • FIPS PUB 186-4: 1
    • FIPS PUB 197: 1
  • ISO:
    • ISO/IEC 15408: 4
    • ISO/IEC 17065: 2
    • ISO/IEC 18031:2005: 1
    • ISO/IEC 18045: 4
  • RFC:
    • RFC 5639: 1
pdf_data/report_keywords/certification_process
  • ConfidentialDocument:
    • H13, Revision 4.4, 30 November 2023, Infineon Technologies AG, BSI-DSZ-CC- 1110-V6-2023 (confidential document) Security Target Lite of the underlying hardware platform, Common Criteria Public Security Target: 1
    • July 2024, Giesecke+Devrient ePayments GmbH (confidential document) [11] Guidance Documentation STARCOS 3.7 COS GKV C2 – Main Document, Version 1.5, 5 June 2024: 1
    • Target STARCOS 3.7 COS GKV C2, Version 1.6, 10 June 2024, Giesecke+Devrient ePayments GmbH (confidential document) [7] Security Target Lite BSI-DSZ-CC-1243, Security Target Lite STARCOS 3.7 COS GKV C2, Version 1.6: 1
    • being maintained, is not given any longer. In particular, prior to the dissemination of confidential documentation and information related to the TOE or resulting from the evaluation and certification: 1
    • for STARCOS 3.7 COS GKV C2, Version 1.1, 1 August 2024, SRC Security Research & Consulting GmbH (confidential document) [10] Configuration List BSI-DSZ-CC-1243, Configuration List STARCOS 3.7 COS GKV C2, Version 1.2: 1
    • procedure BSI-DSZ-CC-1110-V6-2023, Version 3, 01 December 2023, TÜV Informationstechnik GmbH (confidential document) [21] Einführung der Gesundheitskarte, Spezifikation des Card Operating System (COS), Elektrische: 1
  • ConfidentialDocument:
    • 000021h, 000022h H13, Revision 2.9, 13 May 2019, Infineon Technologies AG, BSI-DSZ-CC-1110-V2-2019 (confidential document) Security Target Lite of the underlying hardware platform, Security Target IFX_CCI_000003h, 000005h: 1
    • 1.5, 14 November 2019, Giesecke+Devrient Mobile Security GmbH (confidential document) [11] Guidance Documentation STARCOS 3.7 – Main Document, Version 1.4, 23 August 2019: 1
    • STARCOS 3.7 COS GKV C2, Version 1.4, 12 September 2019, Giesecke+Devrient Mobile Security GmbH (confidential document) [7] Security Target Lite BSI-DSZ-CC-0976-V3-2019, Security Target Lite STARCOS 3.7 COS GKV C2: 1
    • being maintained, is not given any longer. In particular, prior to the dissemination of confidential documentation and information related to the TOE or resulting from the evaluation and certification: 1
    • for STARCOS 3.7 COS GKV C2, Version 2.6, 14 November 2019, SRC Security Research & Consulting GmbH (confidential document) [10] Configuration List BSI-DSZ-CC-0976-V3-2019, Configuration List STARCOS 3.7 COS GKV C2: 1
    • procedure BSI-DSZ-CC-1110-V2-2019, Version 2, 14 June 2019, TÜV Informationstechnik GmbH (confidential document) [21] Einführung der Gesundheitskarte, Spezifikation des Card Operating System (COS), Elektrische: 1
pdf_data/report_metadata
pdf_data/st_filename 1243b_pdf.pdf 0976V3b_pdf.pdf
pdf_data/st_keywords/cc_cert_id
  • DE:
    • BSI-DSZ-CC-1110-V6-2023: 1
  • DE:
    • BSI-DSZ-CC-1110-V2-2019: 2
pdf_data/st_keywords/cc_protection_profile_id
  • BSI:
    • BSI-CC-PP- 0082-V4: 1
    • BSI-CC-PP- 0084-2014: 8
    • BSI-CC-PP- 16: 1
    • BSI-CC-PP-0035-2007: 1
    • BSI-CC-PP-0082-: 1
    • BSI-CC-PP-0082-V4: 24
    • BSI-CC-PP-0084-: 4
    • BSI-CC-PP-0084-2007: 1
    • BSI-CC-PP-0084-2014: 54
    • BSI-PP-0082-V4: 147
    • BSI-PP-0084-: 2
    • BSI-PP-0084-2014: 8
  • BSI:
    • BSI-CC-PP- 0082-V3: 1
    • BSI-CC-PP- 0084-2014: 9
    • BSI-CC-PP- 15: 1
    • BSI-CC-PP-0035-2007: 1
    • BSI-CC-PP-0082-: 1
    • BSI-CC-PP-0082-V3: 21
    • BSI-CC-PP-0082-V4: 3
    • BSI-CC-PP-0084-: 4
    • BSI-CC-PP-0084-2007: 1
    • BSI-CC-PP-0084-2014: 53
    • BSI-PP-0084-: 2
    • BSI-PP-0084-2014: 8
pdf_data/st_keywords/vendor
  • GD:
    • G+D: 147
    • Giesecke+Devrient: 13
  • Infineon:
    • Infineon: 2
    • Infineon Technologies: 1
    • Infineon Technologies AG: 1
  • NXP:
    • NXP Semiconductors: 1
  • STMicroelectronics:
    • STMicroelectronics: 1
  • GD:
    • Giesecke+Devrient: 14
  • Infineon:
    • Infineon: 2
    • Infineon Technologies AG: 2
  • NXP:
    • NXP Semiconductors: 1
  • STMicroelectronics:
    • STMicroelectronics: 1
pdf_data/st_keywords/hash_function
  • SHA:
    • SHA1:
      • SHA-1: 3
    • SHA2:
      • SHA-224: 2
      • SHA-256: 11
      • SHA-384: 6
      • SHA-512: 3
  • SHA:
    • SHA1:
      • SHA-1: 3
    • SHA2:
      • SHA-224: 2
      • SHA-256: 11
      • SHA-384: 6
      • SHA-512: 4
pdf_data/st_keywords/os_name
  • STARCOS:
    • STARCOS 3: 16
  • STARCOS:
    • STARCOS 3: 162
pdf_data/st_keywords/standard_id
  • BSI:
    • AIS20: 2
    • AIS31: 1
  • CC:
    • CCMB-2017-04-001: 1
    • CCMB-2017-04-002: 1
    • CCMB-2017-04-003: 1
    • CCMB-2017-04-004: 1
    • CCMB-2017-05-001: 1
  • FIPS:
    • FIPS 180-4: 1
    • FIPS 197: 3
    • FIPS PUB 180-4: 1
  • ISO:
    • ISO/IEC 7816: 2
  • NIST:
    • NIST SP 800-38B: 1
  • PKCS:
    • PKCS #1: 1
  • RFC:
    • RFC 5639: 1
    • RFC5639: 3
  • BSI:
    • AIS20: 2
    • AIS31: 1
  • CC:
    • CCMB-2017-04-001: 1
    • CCMB-2017-04-002: 1
    • CCMB-2017-04-003: 1
    • CCMB-2017-04-004: 1
    • CCMB-2017-05-001: 1
  • FIPS:
    • FIPS 180-4: 1
    • FIPS 197: 3
    • FIPS PUB 180-4: 1
    • FIPS PUB 197: 1
  • ISO:
    • ISO/IEC 7816: 2
  • NIST:
    • NIST SP 800-38B: 1
  • PKCS:
    • PKCS #1: 1
  • RFC:
    • RFC 5639: 1
    • RFC5639: 3
pdf_data/st_metadata
  • /Author: wallhaek
  • /Keywords:
  • /Subject:
  • /Title: ASE_STA37_COSGKV_C2_Lite
  • pdf_file_size_bytes: 1178896
  • pdf_hyperlinks: {}
  • pdf_is_encrypted: False
  • pdf_number_of_pages: 149
  • /Author: Giesecke+Devrient Mobile Security GmbH
  • /CreationDate: D:20191202161357+01'00'
  • /Creator: Microsoft® Word 2010
  • /Keywords: Version 1.4/12.09.2019
  • /ModDate: D:20191202161357+01'00'
  • /Producer: Microsoft® Word 2010
  • /Subject: Security Target STARCOS 3.7 COS GKV C2
  • /Title: G+D MS Security Target to BSI-PP-0082-V4
  • pdf_file_size_bytes: 2514997
  • pdf_hyperlinks: {}
  • pdf_is_encrypted: False
  • pdf_number_of_pages: 148
state/cert/pdf_hash Different Different
state/cert/txt_hash Different Different
state/report/pdf_hash Different Different
state/report/txt_hash Different Different
state/st/pdf_hash Different Different
state/st/txt_hash Different Different