Java Card MultiApp V4.2 platform in open configuration on IC IFX_CCI_000010h

Certificate details

Certificate ID EUCC-3090-2026-0060
Product name Java Card MultiApp V4.2 platform in open configuration on IC IFX_CCI_000010h
Scheme 🇫🇷 FR
Assurance level high
Status active

Product Specification

Type Smartcards and similar devices
Description
The product is designed to host and run one or more applications, referred to as applets in Java Card terminology. These applications may implement di...
The product is designed to host and run one or more applications, referred to as applets in Java Card terminology. These applications may implement different security features, depending on whether they are classified as “sensitive” or “basic”, and can be loaded and instantiated either before or after the product is issued.
Version 4.2.0.1
Package EAL5 augmented with ALC_DVS.2 , AVA_VAN.5

Certificate holder

Name THALES DIS FRANCE SAS
Address venue du Jujubier, ZI Athelia IV, 13705 La Ciotat Cedex
Contact information [email protected]
Website https://www.thalesgroup.com/en/search/public-security/civil-identity/thales-euc…

Certification body

Name ANSSI
NANDO ID 3090
Address Tour Mercure 31 Quai de Grenelle, 75015 Paris
Contact information [email protected] Phone: +33 (0)1 71 75 82 82

Standards & Compliance

CC Version CC:2022 Revision 1
CEM Version None
AVA_VAN level 5
Certification report reference None

Other

ITSEF Serma Safety and Security SAS
Responsible NCCA Agence nationale de la sécurité des systèmes d’information
Protection profile Java Card System Protection Profile - Open Configuration, version 3.0.5, BSI-PP-0099-2017.
Certification date 22.06.2026
Archived date 22.06.2031

Certificate

Extracted keywords

Security level
EAL5, EAL2
Security Assurance Requirements (SAR)
ALC_DVS.2, AVA_VAN.5
Protection profiles
BSI-PP-0099-2017
Certificates
EUCC-3090-2026-60
Evaluation facilities
SERMA

Certification report

certification report could not be downloaded, no link is available.

Security target

Extracted keywords

Symmetric Algorithms
AES, DES, TDEA, 3DES, TDES, Triple-DES, HMAC, KMAC, CMAC
Asymmetric Algorithms
ECDH, ECDSA, ECC, Diffie-Hellman, DH
Hash functions
SHA1, SHA-1, SHA-224, SHA224, SHA256, SHA384, SHA512, SHA-256, SHA-512, SHA-384
Schemes
MAC, Key Agreement, Key agreement
Protocols
PACE
Randomness
RNG, RND
Block cipher modes
CBC

JavaCard versions
Java Card 2.2.2, Java Card 3.0.5
JavaCard API constants
TYPE_ACCESS
JavaCard packages
java.lang, javacard.iasclassic, javacard.icao.nax, javacard.mspnp, javacard.fido, javacard.icao, javacard.security, javacard.framework, javacardx.gdp, javacardx.biometry, javacardx.crypto, com.gemalto.javacard.iasclassic, com.gemalto.javacard.icao.nax, com.gemalto.moc.server, com.gemalto.moc.api, com.gemalto.javacardx.gdp, com.gemalto.javacard.mspnp, com.gemalto.mpcos, com.gemalto.javacard.fido.u2f, com.gemalto.oath, com.gemalto.puredi, com.gemalto.tacho, com.gemalto.javacard.icao.lds2
CPLC
IC Fabricator
IC data groups
EF.DG1, EF.DG16
Vendor
Infineon, Infineon Technologies AG, Gemalto, Thales, Microsoft

Security level
EAL5+, EAL5, EAL6, EAL 6+, EAL5 augmented, EAL6 augmented
Claims
D.APP_CODE, D.APP_C_DATA, D.APP_I_DATA, D.PIN, D.BIO, D.API_DATA, D.CRYPTO, D.JCS_CODE, D.JCS_DATA, D.SEC_DATA, O.SID, O.FIREWALL, O.GLOBAL_ARRAYS_CONFID, O.GLOBAL_ARRAYS_INTEG, O.NATIVE, O.OPERATE, O.REALLOCATION, O.RESOURCES, O.ALARM, O.CIPHER, O.RNG, O.KEY-MNGT, O.PIN-MNGT, O.TRANSACTION, O.BIO-MNGT, O.OBJ-DELETION, O.DELETION, O.LOAD, O.INSTALL, O.SCP, O.CARD-MANAGEMENT, O.PIN_MNGT, O.KEY_MNGT, O.CARD_MANAGEMENT, O.PIN-, O.RND, O.TDES, O.AES, O.APPLET, O.CODE_PKG, O.JAVAOBJECT, O.CODE_PCKG, O.OBJ_DELETION, T.CONFID-APPLI-DATA, T.CONFID-JCS-CODE, T.CONFID-JCS-DATA, T.INTEG-APPLI-CODE, T.INTEG-APPLI-DATA, T.INTEG-JCS-CODE, T.INTEG-JCS-DATA, T.SID, T.EXE-CODE, T.NATIVE, T.RESOURCES, T.DELETION, T.INSTALL, T.OBJ-DELETION, T.PHYSICAL, A.APPLET, A.DELETION, A.VERIFICATION, R.JAVA, OT.X, OP.ARRAY_ACCESS, OP.ARRAY_LENGTH, OP.ARRAY_AASTORE, OP.CREATE, OP.DELETE_APPLET, OP.DELETE_PCKG, OP.DELETE_PCKG_APPLET, OP.INSTANCE_FIELD, OP.INVK_VIRTUAL, OP.INVK_INTERFACE, OP.JAVA, OP.THROW, OP.TYPE_ACCESS, OP.PUT, OP.PUTFIELD, OP.PUTSTATIC, OE.APPLET, OE.VERIFICATION, OE.CODE-EVIDENCE, OE.CODE_EVIDENCE, OE.CARD-MANAGEMENT, OE.SCP, OE.NATIVE, OSP.VERIFICATION, OSP.RNG, OSP.RND
Security Assurance Requirements (SAR)
ADV_IMP.2, ADV_INT.3, ADV_TDS.5, ADV_ARC.1, ADV_TDS.1, ADV_TDS.4, ADV_IMP.1, ADV_TDS.3, ADV_INT.2, ADV_FSP.5, ADV_FSP.1, ADV_FSP.2, ADV_FSP.4, ADV_ARC, ADV_FSP, ADV_IMP, ADV_TDS, AGD_PRE, AGD_OPE, AGD_OPE.1, AGD_PRE.1, ALC_DVS.2, ALC_CMC.5, ALC_FLR.3, ALC_TAT.3, ALC_TAT.1, ALC_TAT.2, ALC_CMC.4, ALC_DVS.1, ALC_LCD.1, ALC_DEL.1, ALC_CMS.5, ATE_FUN.2, ATE_COV.3, ATE_COV.2, ATE_FUN.1, ATE_COV.1, ATE_IND.2, ATE_DPT.1, ATE_DPT.3, AVA_VAN.5
Security Functional Requirements (SFR)
FAU_ARP.1, FAU_ARP.1.1, FAU_SAA.1, FAU_SAS.1, FCO_NRO, FCO_NRO.2, FCS_CKM, FCS_COP, FCS_RNG.1, FCS_CKM.4, FCS_CKM.6, FCS_CKM.1, FCS_CKM.1.1, FCS_CKM.6.1, FCS_CKM.6.2, FCS_COP.1, FCS_COP.1.1, FCS_RNG, FCS_RNG.1.1, FCS_RNG.1.2, FCS_CKM.2, FCS_CKM.5, FCS_RBG.1, FCS_CMK, FDP_ACC, FDP_ACC.2, FDP_ACF, FDP_ACF.1, FDP_IFC, FDP_IFC.1, FDP_IFF, FDP_IFF.1, FDP_RIP, FDP_RIP.1, FDP_ROL.1, FDP_ROL, FDP_SDI, FDP_SDI.2, FDP_ITC, FDP_ITC.2, FDP_IFC.2, FDP_UIT, FDP_UIT.1, FDP_ACC.1, FDP_ITC.1, FDP_RIP.1.1, FDP_ITT.1, FDP_SDC.1, FDP_UCT.1, FIA_AFL, FIA_ATD, FIA_ATD.1, FIA_UID, FIA_UID.2, FIA_USB, FIA_USB.1, FIA_UAU, FIA_UAU.1, FIA_UID.1, FIA_UAU.4, FIA_AFL.1.1, FIA_AFL.1.2, FIA_UID.1.1, FIA_UID.1.2, FIA_UAU.1.1, FIA_UAU.1.2, FIA_UAU.4.1, FIA_UAU.5.1, FIA_UAU.5.2, FIA_UAU.6.1, FIA_API.1, FMT_LIM.1, FMT_LIM.2, FMT_MSA, FMT_MSA.1, FMT_MSA.2, FMT_MSA.3, FMT_SMR, FMT_SMR.1, FMT_SMF, FMT_SMF.1, FMT_MTD, FMT_MTD.1, FMT_MTD.3, FMT_SMF.1.1, FMT_SMR.1.1, FMT_SMR.1.2, FMT_LIM, FMT_LIM.1.1, FMT_LIM.2.1, FPR_UNO.1, FPR_UNO.1.1, FPR_UNO, FPT_EMS.1, FPT_TST, FPT_TST.1, FPT_FLS, FPT_FLS.1, FPT_TDC.1, FPT_TDC.1.1, FPT_TDC.1.2, FPT_RCV, FPT_RCV.3, FPT_FLS.1.1, FPT_PHP, FPT_PHP.3, FPT_RCV.4, FPT_ITT, FPT_ITT.1, FPT_EMS.1.1, FPT_TST.1.1, FPT_TST.1.2, FPT_TST.1.3, FPT_PHP.3.1, FPT_TST.2, FRU_FLT.2, FTP_ITC, FTP_ITC.1, FTP_ITC.1.1, FTP_ITC.1.2, FTP_ITC.1.3, FTP_TRP.1
Protection profiles
BSI-CC-PP-0084-2014, BSI-CC-PP-0099-2017, BSI-CC-PP- 0068-V2-2011-MA-01, BSI-PP- 0055-2009
Certificates
BSI-DSZ-CC-1079-V6-2025, EUCC-3087-2025-12-0001, CC-3, CC-1, CC-2, CC-4, CC-5
Evaluation facilities
Serma Safety & Security

Side-channel analysis
Leak-Inherent, physical probing, DPA, physical tampering, Physical Tampering, malfunction, Malfunction, fault induction
Certification process
out of scope, SHA512, SHA1 (1) RNG according to AIS 31 1 Signature generation and verification based ECDSA is out of scope MultiApp V4.2: JCS Security Target © Copyright Thales NOT EXPORT-CONTROLLED Page 21 / 152 ▪ The, a timeout policy that prevent them from being blocked should a card fails to answer. That point is out of scope of this Security Target, though. Finally, the objectives O.SCP.RECOVERY and O.SCP.SUPPORT are

Standards
FIPS180-2, FIPS197, FIPS 140-2, FIPS 46-3, FIPS 197, SP 800-67, PKCS#1, PKCS#5, AIS31, AIS 31, ISO/IEC 7816-2, ICAO, SCP01, SCP02, SCP03, CCMB-2022-11-001, CCMB-2022-11-002, CCMB-2022-11-003, CCMB-2022-11-004, CCMB-2022-11-005, CCMB-2022-11-006

Automated analysis

Automated inference - use with caution

All attributes shown in this section (e.g., links between certificates, products, vendors, and known CVEs) are generated by automated heuristics and have not been reviewed by humans. These methods can produce false positives or false negatives and should not be treated as definitive without independent verification. If you want to know more about how this data is computed and how reliable it is, see our documentation on automated analysis. If you believe any information here is inaccurate or harmful, please submit feedback.

Extracted SARs

ADV_ARC.1, ADV_FSP.5, ADV_IMP.2, ADV_INT.3, ADV_TDS.5, AGD_OPE.1, AGD_PRE.1, ALC_CMC.5, ALC_CMS.5, ALC_DEL.1, ALC_DVS.2, ALC_FLR.3, ALC_LCD.1, ALC_TAT.3, ATE_COV.3, ATE_DPT.3, ATE_FUN.2, ATE_IND.2, AVA_VAN.5

Similar certificates

Processing updates

Feed
  • The certificate was first processed.

Raw data

{
  "_type": "sec_certs.sample.eucc.EUCCCertificate",
  "category": "SMARTCARDS AND SIMILAR DEVICES",
  "cert_id": "EUCC-3090-2026-0060",
  "cert_link": "https://certification.enisa.europa.eu/document/download/9335a0ae-3c7a-4a27-8d98-660718319665_en?filename=EUCC-3090-2026-60-certificat.pdf",
  "dgst": "15893e37a7f97721",
  "heuristics": {
    "_type": "sec_certs.sample.cc_eucc_common.Heuristics",
    "annotated_references": null,
    "cert_id": "EUCC-3090-2026-60",
    "cert_lab": null,
    "cpe_matches": null,
    "direct_transitive_cves": null,
    "eal": "EAL5",
    "extracted_sars": {
      "_type": "Set",
      "elements": [
        {
          "_type": "sec_certs.sample.sar.SAR",
          "family": "AGD_OPE",
          "level": 1
        },
        {
          "_type": "sec_certs.sample.sar.SAR",
          "family": "ADV_TDS",
          "level": 5
        },
        {
          "_type": "sec_certs.sample.sar.SAR",
          "family": "ATE_DPT",
          "level": 3
        },
        {
          "_type": "sec_certs.sample.sar.SAR",
          "family": "ADV_IMP",
          "level": 2
        },
        {
          "_type": "sec_certs.sample.sar.SAR",
          "family": "ADV_ARC",
          "level": 1
        },
        {
          "_type": "sec_certs.sample.sar.SAR",
          "family": "ADV_FSP",
          "level": 5
        },
        {
          "_type": "sec_certs.sample.sar.SAR",
          "family": "ALC_DVS",
          "level": 2
        },
        {
          "_type": "sec_certs.sample.sar.SAR",
          "family": "ALC_DEL",
          "level": 1
        },
        {
          "_type": "sec_certs.sample.sar.SAR",
          "family": "ALC_LCD",
          "level": 1
        },
        {
          "_type": "sec_certs.sample.sar.SAR",
          "family": "AVA_VAN",
          "level": 5
        },
        {
          "_type": "sec_certs.sample.sar.SAR",
          "family": "ATE_COV",
          "level": 3
        },
        {
          "_type": "sec_certs.sample.sar.SAR",
          "family": "ALC_CMS",
          "level": 5
        },
        {
          "_type": "sec_certs.sample.sar.SAR",
          "family": "ATE_IND",
          "level": 2
        },
        {
          "_type": "sec_certs.sample.sar.SAR",
          "family": "ALC_CMC",
          "level": 5
        },
        {
          "_type": "sec_certs.sample.sar.SAR",
          "family": "ALC_FLR",
          "level": 3
        },
        {
          "_type": "sec_certs.sample.sar.SAR",
          "family": "ATE_FUN",
          "level": 2
        },
        {
          "_type": "sec_certs.sample.sar.SAR",
          "family": "ADV_INT",
          "level": 3
        },
        {
          "_type": "sec_certs.sample.sar.SAR",
          "family": "AGD_PRE",
          "level": 1
        },
        {
          "_type": "sec_certs.sample.sar.SAR",
          "family": "ALC_TAT",
          "level": 3
        }
      ]
    },
    "extracted_versions": {
      "_type": "Set",
      "elements": [
        "4.2"
      ]
    },
    "indirect_transitive_cves": null,
    "next_certificates": null,
    "prev_certificates": null,
    "protection_profiles": null,
    "related_cves": null,
    "report_references": {
      "_type": "sec_certs.sample.certificate.References",
      "directly_referenced_by": null,
      "directly_referencing": null,
      "indirectly_referenced_by": null,
      "indirectly_referencing": null
    },
    "scheme_data": null,
    "st_references": {
      "_type": "sec_certs.sample.certificate.References",
      "directly_referenced_by": null,
      "directly_referencing": null,
      "indirectly_referenced_by": null,
      "indirectly_referencing": null
    },
    "verified_cpe_matches": null
  },
  "manufacturer": "THALES DIS FRANCE SAS",
  "manufacturer_web": "https://www.thalesgroup.com/en/search/public-security/civil-identity/thales-euc",
  "name": "Java Card MultiApp V4.2 platform in open configuration on IC IFX_CCI_000010h",
  "not_valid_after": "2031-06-22",
  "not_valid_before": "2026-06-22",
  "other_metadata": {
    "_type": "sec_certs.sample.eucc.EUCCCertificate.EnisaMetadata",
    "assurance_level": "High",
    "ava_van_level": "5",
    "cc_version": "CC:2022 Revision 1",
    "cem_version": null,
    "certificate_id": "EUCC-3090-2026-0060",
    "certificate_yearly_number": null,
    "certification_body": "ANSSI",
    "certification_body_address": "Tour Mercure 31 Quai de Grenelle, 75015 Paris",
    "certification_body_contact": "[email protected] Phone: +33 (0)1 71 75 82 82",
    "holder_address": "venue du Jujubier, ZI Athelia IV, 13705 La Ciotat Cedex",
    "holder_contact": "[email protected]",
    "holder_name": "THALES DIS FRANCE SAS",
    "holder_website": "https://www.thalesgroup.com/en/search/public-security/civil-identity/thales-euc\u2026",
    "issuance_date_full": "22/06/2026",
    "issuance_month": "6",
    "issuance_year": "2026",
    "itsef": "Serma Safety and Security SAS",
    "modification_or_reassurance": null,
    "nando_id": "3090",
    "package": {
      "EAL5": [
        "ALC_DVS.2",
        "AVA_VAN.5"
      ]
    },
    "product_description": "The product is designed to host and run one or more applications, referred to as applets in Java Card terminology. These applications may implement different security features, depending on whether they are classified as \u201csensitive\u201d or \u201cbasic\u201d, and can be loaded and instantiated either before or after the product is issued.",
    "product_name": "Java Card MultiApp V4.2 platform in open configuration on IC IFX_CCI_000010h",
    "product_type": "Smartcards and similar devices",
    "product_version": "4.2.0.1",
    "protection_profile": "Java Card System Protection Profile - Open Configuration, version 3.0.5, BSI-PP-0099-2017.",
    "report_reference": null,
    "responsible_ncca": "Agence nationale de la s\u00e9curit\u00e9 des syst\u00e8mes d\u2019information",
    "scheme": "(UE) 2024/482 - EUCC",
    "validity_period_years": "5 years"
  },
  "pdf_data": {
    "_type": "sec_certs.sample.cc_eucc_common.PdfData",
    "cert_filename": "9335a0ae-3c7a-4a27-8d98-660718319665_en",
    "cert_frontpage": null,
    "cert_keywords": {
      "asymmetric_crypto": {},
      "cc_cert_id": {
        "FR": {
          "EUCC-3090-2026-60": 2
        }
      },
      "cc_claims": {},
      "cc_protection_profile_id": {
        "BSI": {
          "BSI-PP-0099-2017": 1
        }
      },
      "cc_sar": {
        "ALC": {
          "ALC_DVS.2": 1
        },
        "AVA": {
          "AVA_VAN.5": 1
        }
      },
      "cc_security_level": {
        "EAL": {
          "EAL2": 1,
          "EAL5": 1
        }
      },
      "cc_sfr": {},
      "certification_process": {},
      "cipher_mode": {},
      "cplc_data": {},
      "crypto_engine": {},
      "crypto_library": {},
      "crypto_protocol": {},
      "crypto_scheme": {},
      "device_model": {},
      "ecc_curve": {},
      "eval_facility": {
        "Serma": {
          "SERMA": 2
        }
      },
      "hash_function": {},
      "ic_data_group": {},
      "javacard_api_const": {},
      "javacard_packages": {},
      "javacard_version": {},
      "os_name": {},
      "pq_crypto": {},
      "randomness": {},
      "side_channel_analysis": {},
      "standard_id": {
        "ISO": {
          "ISO/IEC 15408:2022": 2,
          "ISO/IEC 18045:2022": 2
        }
      },
      "symmetric_crypto": {},
      "technical_report_id": {},
      "tee_name": {},
      "tls_cipher_suite": {},
      "vendor": {},
      "vulnerability": {}
    },
    "cert_metadata": {
      "/CreationDate": "D:20260618103736+02\u002700\u0027",
      "/Creator": "Acrobat PDFMaker 26 pour Word",
      "/ModDate": "D:20260623143835+00\u002700\u0027",
      "/Producer": "Docusign DMv10",
      "pdf_file_size_bytes": 414869,
      "pdf_hyperlinks": {
        "_type": "Set",
        "elements": [
          "https://cyber.gouv.fr/",
          "https://cyber.gouv.fr/cybersecurity-act",
          "mailto:[email protected]",
          "https://www.thalesgroup.com/en/global/group/psirt",
          "https://www.thalesgroup.com/en/search/public-security/civil-identity/thales-eucc-certification-civil-identity"
        ]
      },
      "pdf_is_encrypted": false,
      "pdf_number_of_pages": 2
    },
    "report_filename": null,
    "report_frontpage": null,
    "report_keywords": null,
    "report_metadata": null,
    "st_filename": "162a9e83-485e-4d91-bee6-c0c644499856_en",
    "st_frontpage": null,
    "st_keywords": {
      "asymmetric_crypto": {
        "ECC": {
          "ECC": {
            "ECC": 7
          },
          "ECDH": {
            "ECDH": 6
          },
          "ECDSA": {
            "ECDSA": 2
          }
        },
        "FF": {
          "DH": {
            "DH": 8,
            "Diffie-Hellman": 4
          }
        }
      },
      "cc_cert_id": {
        "DE": {
          "BSI-DSZ-CC-1079-V6-2025": 1,
          "EUCC-3087-2025-12-0001": 1
        },
        "NL": {
          "CC-1": 2,
          "CC-2": 14,
          "CC-3": 4,
          "CC-4": 2,
          "CC-5": 3
        }
      },
      "cc_claims": {
        "A": {
          "A.APPLET": 5,
          "A.DELETION": 4,
          "A.VERIFICATION": 4
        },
        "D": {
          "D.API_DATA": 3,
          "D.APP_CODE": 6,
          "D.APP_C_DATA": 3,
          "D.APP_I_DATA": 5,
          "D.BIO": 1,
          "D.CRYPTO": 5,
          "D.JCS_CODE": 3,
          "D.JCS_DATA": 5,
          "D.PIN": 4,
          "D.SEC_DATA": 7
        },
        "O": {
          "O.AES": 1,
          "O.ALARM": 14,
          "O.APPLET": 28,
          "O.BIO-MNGT": 6,
          "O.CARD-MANAGEMENT": 3,
          "O.CARD_MANAGEMENT": 16,
          "O.CIPHER": 10,
          "O.CODE_PCKG": 16,
          "O.CODE_PKG": 7,
          "O.DELETION": 5,
          "O.FIREWALL": 12,
          "O.GLOBAL_ARRAYS_CONFID": 8,
          "O.GLOBAL_ARRAYS_INTEG": 5,
          "O.INSTALL": 8,
          "O.JAVAOBJECT": 66,
          "O.KEY-MNGT": 7,
          "O.KEY_MNGT": 1,
          "O.LOAD": 9,
          "O.NATIVE": 11,
          "O.OBJ-DELETION": 4,
          "O.OBJ_DELETION": 2,
          "O.OPERATE": 15,
          "O.PIN-": 1,
          "O.PIN-MNGT": 6,
          "O.PIN_MNGT": 1,
          "O.REALLOCATION": 5,
          "O.RESOURCES": 8,
          "O.RND": 3,
          "O.RNG": 9,
          "O.SCP": 35,
          "O.SID": 12,
          "O.TDES": 1,
          "O.TRANSACTION": 7
        },
        "OE": {
          "OE.APPLET": 4,
          "OE.CARD-MANAGEMENT": 2,
          "OE.CODE-EVIDENCE": 10,
          "OE.CODE_EVIDENCE": 1,
          "OE.NATIVE": 1,
          "OE.SCP": 6,
          "OE.VERIFICATION": 25
        },
        "OP": {
          "OP.ARRAY_AASTORE": 3,
          "OP.ARRAY_ACCESS": 7,
          "OP.ARRAY_LENGTH": 3,
          "OP.CREATE": 11,
          "OP.DELETE_APPLET": 6,
          "OP.DELETE_PCKG": 4,
          "OP.DELETE_PCKG_APPLET": 4,
          "OP.INSTANCE_FIELD": 6,
          "OP.INVK_INTERFACE": 10,
          "OP.INVK_VIRTUAL": 8,
          "OP.JAVA": 8,
          "OP.PUT": 8,
          "OP.PUTFIELD": 1,
          "OP.PUTSTATIC": 1,
          "OP.THROW": 7,
          "OP.TYPE_ACCESS": 7
        },
        "OSP": {
          "OSP.RND": 3,
          "OSP.RNG": 1,
          "OSP.VERIFICATION": 4
        },
        "OT": {
          "OT.X": 1
        },
        "R": {
          "R.JAVA": 10
        },
        "T": {
          "T.CONFID-APPLI-DATA": 4,
          "T.CONFID-JCS-CODE": 4,
          "T.CONFID-JCS-DATA": 4,
          "T.DELETION": 3,
          "T.EXE-CODE": 8,
          "T.INSTALL": 4,
          "T.INTEG-APPLI-CODE": 7,
          "T.INTEG-APPLI-DATA": 8,
          "T.INTEG-JCS-CODE": 3,
          "T.INTEG-JCS-DATA": 4,
          "T.NATIVE": 4,
          "T.OBJ-DELETION": 4,
          "T.PHYSICAL": 4,
          "T.RESOURCES": 3,
          "T.SID": 8
        }
      },
      "cc_protection_profile_id": {
        "BSI": {
          "BSI-CC-PP- 0068-V2-2011-MA-01": 1,
          "BSI-CC-PP-0084-2014": 1,
          "BSI-CC-PP-0099-2017": 1,
          "BSI-PP- 0055-2009": 1
        }
      },
      "cc_sar": {
        "ADV": {
          "ADV_ARC": 2,
          "ADV_ARC.1": 9,
          "ADV_FSP": 1,
          "ADV_FSP.1": 1,
          "ADV_FSP.2": 2,
          "ADV_FSP.4": 2,
          "ADV_FSP.5": 6,
          "ADV_IMP": 1,
          "ADV_IMP.1": 9,
          "ADV_IMP.2": 1,
          "ADV_INT.2": 3,
          "ADV_INT.3": 1,
          "ADV_TDS": 1,
          "ADV_TDS.1": 2,
          "ADV_TDS.3": 4,
          "ADV_TDS.4": 8,
          "ADV_TDS.5": 1
        },
        "AGD": {
          "AGD_OPE": 2,
          "AGD_OPE.1": 9,
          "AGD_PRE": 3,
          "AGD_PRE.1": 7
        },
        "ALC": {
          "ALC_CMC.4": 3,
          "ALC_CMC.5": 1,
          "ALC_CMS.5": 2,
          "ALC_DEL.1": 3,
          "ALC_DVS.1": 2,
          "ALC_DVS.2": 10,
          "ALC_FLR.3": 2,
          "ALC_LCD.1": 5,
          "ALC_TAT.1": 2,
          "ALC_TAT.2": 5,
          "ALC_TAT.3": 1
        },
        "ATE": {
          "ATE_COV.1": 2,
          "ATE_COV.2": 4,
          "ATE_COV.3": 1,
          "ATE_DPT.1": 2,
          "ATE_DPT.3": 3,
          "ATE_FUN.1": 9,
          "ATE_FUN.2": 1,
          "ATE_IND.2": 4
        },
        "AVA": {
          "AVA_VAN.5": 10
        }
      },
      "cc_security_level": {
        "EAL": {
          "EAL 6+": 1,
          "EAL5": 7,
          "EAL5 augmented": 3,
          "EAL5+": 2,
          "EAL6": 1,
          "EAL6 augmented": 1
        }
      },
      "cc_sfr": {
        "FAU": {
          "FAU_ARP.1": 17,
          "FAU_ARP.1.1": 1,
          "FAU_SAA.1": 2,
          "FAU_SAS.1": 2
        },
        "FCO": {
          "FCO_NRO": 6,
          "FCO_NRO.2": 3
        },
        "FCS": {
          "FCS_CKM": 69,
          "FCS_CKM.1": 30,
          "FCS_CKM.1.1": 3,
          "FCS_CKM.2": 5,
          "FCS_CKM.4": 3,
          "FCS_CKM.5": 15,
          "FCS_CKM.6": 27,
          "FCS_CKM.6.1": 2,
          "FCS_CKM.6.2": 1,
          "FCS_CMK": 2,
          "FCS_COP": 66,
          "FCS_COP.1": 26,
          "FCS_COP.1.1": 5,
          "FCS_RBG.1": 4,
          "FCS_RNG": 25,
          "FCS_RNG.1": 20,
          "FCS_RNG.1.1": 2,
          "FCS_RNG.1.2": 2
        },
        "FDP": {
          "FDP_ACC": 40,
          "FDP_ACC.1": 21,
          "FDP_ACC.2": 6,
          "FDP_ACF": 34,
          "FDP_ACF.1": 18,
          "FDP_IFC": 23,
          "FDP_IFC.1": 14,
          "FDP_IFC.2": 2,
          "FDP_IFF": 15,
          "FDP_IFF.1": 17,
          "FDP_ITC": 11,
          "FDP_ITC.1": 11,
          "FDP_ITC.2": 16,
          "FDP_ITT.1": 2,
          "FDP_RIP": 110,
          "FDP_RIP.1": 11,
          "FDP_RIP.1.1": 1,
          "FDP_ROL": 15,
          "FDP_ROL.1": 5,
          "FDP_SDC.1": 2,
          "FDP_SDI": 8,
          "FDP_SDI.2": 6,
          "FDP_UCT.1": 2,
          "FDP_UIT": 7,
          "FDP_UIT.1": 4
        },
        "FIA": {
          "FIA_AFL": 25,
          "FIA_AFL.1.1": 2,
          "FIA_AFL.1.2": 2,
          "FIA_API.1": 2,
          "FIA_ATD": 8,
          "FIA_ATD.1": 2,
          "FIA_UAU": 67,
          "FIA_UAU.1": 6,
          "FIA_UAU.1.1": 2,
          "FIA_UAU.1.2": 2,
          "FIA_UAU.4": 1,
          "FIA_UAU.4.1": 1,
          "FIA_UAU.5.1": 1,
          "FIA_UAU.5.2": 1,
          "FIA_UAU.6.1": 1,
          "FIA_UID": 43,
          "FIA_UID.1": 18,
          "FIA_UID.1.1": 2,
          "FIA_UID.1.2": 2,
          "FIA_UID.2": 1,
          "FIA_USB": 7,
          "FIA_USB.1": 3
        },
        "FMT": {
          "FMT_LIM": 36,
          "FMT_LIM.1": 9,
          "FMT_LIM.1.1": 2,
          "FMT_LIM.2": 9,
          "FMT_LIM.2.1": 2,
          "FMT_MSA": 94,
          "FMT_MSA.1": 13,
          "FMT_MSA.2": 2,
          "FMT_MSA.3": 19,
          "FMT_MTD": 39,
          "FMT_MTD.1": 9,
          "FMT_MTD.3": 1,
          "FMT_SMF": 63,
          "FMT_SMF.1": 21,
          "FMT_SMF.1.1": 2,
          "FMT_SMR": 70,
          "FMT_SMR.1": 29,
          "FMT_SMR.1.1": 2,
          "FMT_SMR.1.2": 2
        },
        "FPR": {
          "FPR_UNO": 6,
          "FPR_UNO.1": 11,
          "FPR_UNO.1.1": 1
        },
        "FPT": {
          "FPT_EMS.1": 15,
          "FPT_EMS.1.1": 1,
          "FPT_FLS": 44,
          "FPT_FLS.1": 19,
          "FPT_FLS.1.1": 2,
          "FPT_ITT": 7,
          "FPT_ITT.1": 2,
          "FPT_PHP": 8,
          "FPT_PHP.3": 18,
          "FPT_PHP.3.1": 1,
          "FPT_RCV": 14,
          "FPT_RCV.3": 7,
          "FPT_RCV.4": 2,
          "FPT_TDC.1": 8,
          "FPT_TDC.1.1": 1,
          "FPT_TDC.1.2": 1,
          "FPT_TST": 10,
          "FPT_TST.1": 17,
          "FPT_TST.1.1": 1,
          "FPT_TST.1.2": 1,
          "FPT_TST.1.3": 1,
          "FPT_TST.2": 1
        },
        "FRU": {
          "FRU_FLT.2": 2
        },
        "FTP": {
          "FTP_ITC": 19,
          "FTP_ITC.1": 7,
          "FTP_ITC.1.1": 1,
          "FTP_ITC.1.2": 1,
          "FTP_ITC.1.3": 1,
          "FTP_TRP.1": 2
        }
      },
      "certification_process": {
        "OutOfScope": {
          "SHA512, SHA1 (1) RNG according to AIS 31 1 Signature generation and verification based ECDSA is out of scope MultiApp V4.2: JCS Security Target \u00a9 Copyright Thales NOT EXPORT-CONTROLLED Page 21 / 152 \u25aa The": 1,
          "a timeout policy that prevent them from being blocked should a card fails to answer. That point is out of scope of this Security Target, though. Finally, the objectives O.SCP.RECOVERY and O.SCP.SUPPORT are": 1,
          "out of scope": 2
        }
      },
      "cipher_mode": {
        "CBC": {
          "CBC": 2
        }
      },
      "cplc_data": {
        "ICFab": {
          "IC Fabricator": 1
        }
      },
      "crypto_engine": {},
      "crypto_library": {},
      "crypto_protocol": {
        "PACE": {
          "PACE": 185
        }
      },
      "crypto_scheme": {
        "KA": {
          "Key Agreement": 3,
          "Key agreement": 2
        },
        "MAC": {
          "MAC": 15
        }
      },
      "device_model": {},
      "ecc_curve": {},
      "eval_facility": {
        "Serma": {
          "Serma Safety \u0026 Security": 1
        }
      },
      "hash_function": {
        "SHA": {
          "SHA1": {
            "SHA-1": 4,
            "SHA1": 2
          },
          "SHA2": {
            "SHA-224": 4,
            "SHA-256": 4,
            "SHA-384": 2,
            "SHA-512": 4,
            "SHA224": 3,
            "SHA256": 1,
            "SHA384": 1,
            "SHA512": 1
          }
        }
      },
      "ic_data_group": {
        "EF": {
          "EF.DG1": 6,
          "EF.DG16": 6
        }
      },
      "javacard_api_const": {
        "misc": {
          "TYPE_ACCESS": 7
        }
      },
      "javacard_packages": {
        "com": {
          "com.gemalto.javacard.fido.u2f": 1,
          "com.gemalto.javacard.iasclassic": 1,
          "com.gemalto.javacard.icao.lds2": 1,
          "com.gemalto.javacard.icao.nax": 1,
          "com.gemalto.javacard.mspnp": 1,
          "com.gemalto.javacardx.gdp": 1,
          "com.gemalto.moc.api": 1,
          "com.gemalto.moc.server": 1,
          "com.gemalto.mpcos": 1,
          "com.gemalto.oath": 1,
          "com.gemalto.puredi": 1,
          "com.gemalto.tacho": 1
        },
        "java": {
          "java.lang": 1
        },
        "javacard": {
          "javacard.fido": 1,
          "javacard.framework": 3,
          "javacard.iasclassic": 1,
          "javacard.icao": 1,
          "javacard.icao.nax": 1,
          "javacard.mspnp": 1,
          "javacard.security": 3
        },
        "javacardx": {
          "javacardx.biometry": 1,
          "javacardx.crypto": 2,
          "javacardx.gdp": 1
        }
      },
      "javacard_version": {
        "JavaCard": {
          "Java Card 2.2.2": 3,
          "Java Card 3.0.5": 5
        }
      },
      "os_name": {},
      "pq_crypto": {},
      "randomness": {
        "RNG": {
          "RND": 10,
          "RNG": 32
        }
      },
      "side_channel_analysis": {
        "FI": {
          "Malfunction": 9,
          "Physical Tampering": 3,
          "fault induction": 2,
          "malfunction": 8,
          "physical tampering": 1
        },
        "SCA": {
          "DPA": 1,
          "Leak-Inherent": 5,
          "physical probing": 6
        }
      },
      "standard_id": {
        "BSI": {
          "AIS 31": 1,
          "AIS31": 6
        },
        "CC": {
          "CCMB-2022-11-001": 1,
          "CCMB-2022-11-002": 1,
          "CCMB-2022-11-003": 1,
          "CCMB-2022-11-004": 1,
          "CCMB-2022-11-005": 1,
          "CCMB-2022-11-006": 1
        },
        "FIPS": {
          "FIPS 140-2": 3,
          "FIPS 197": 1,
          "FIPS 46-3": 1,
          "FIPS180-2": 1,
          "FIPS197": 5
        },
        "ICAO": {
          "ICAO": 1
        },
        "ISO": {
          "ISO/IEC 7816-2": 1
        },
        "NIST": {
          "SP 800-67": 1
        },
        "PKCS": {
          "PKCS#1": 8,
          "PKCS#5": 5
        },
        "SCP": {
          "SCP01": 6,
          "SCP02": 6,
          "SCP03": 5
        }
      },
      "symmetric_crypto": {
        "AES_competition": {
          "AES": {
            "AES": 30
          }
        },
        "DES": {
          "3DES": {
            "3DES": 2,
            "TDEA": 1,
            "TDES": 16,
            "Triple-DES": 3
          },
          "DES": {
            "DES": 20
          }
        },
        "constructions": {
          "MAC": {
            "CMAC": 2,
            "HMAC": 2,
            "KMAC": 2
          }
        }
      },
      "technical_report_id": {},
      "tee_name": {},
      "tls_cipher_suite": {},
      "vendor": {
        "Gemalto": {
          "Gemalto": 2
        },
        "Infineon": {
          "Infineon": 15,
          "Infineon Technologies AG": 1
        },
        "Microsoft": {
          "Microsoft": 2
        },
        "Thales": {
          "Thales": 179
        }
      },
      "vulnerability": {}
    },
    "st_metadata": {
      "/Author": "D1487827",
      "/CreationDate": "D:20260320194210+01\u002700\u0027",
      "/Creator": "Microsoft\u00ae Word for Microsoft 365",
      "/Keywords": "04-05-2021",
      "/MSIP_Label_cf20372f-9ab3-4551-9149-9f9b12e2c27e_ActionId": "d5d43b89-d83d-4146-bdce-5ee95cd15237",
      "/MSIP_Label_cf20372f-9ab3-4551-9149-9f9b12e2c27e_ContentBits": "0",
      "/MSIP_Label_cf20372f-9ab3-4551-9149-9f9b12e2c27e_Enabled": "true",
      "/MSIP_Label_cf20372f-9ab3-4551-9149-9f9b12e2c27e_Method": "Privileged",
      "/MSIP_Label_cf20372f-9ab3-4551-9149-9f9b12e2c27e_Name": "DIS OPEN",
      "/MSIP_Label_cf20372f-9ab3-4551-9149-9f9b12e2c27e_SetDate": "2026-03-20T13:45:19Z",
      "/MSIP_Label_cf20372f-9ab3-4551-9149-9f9b12e2c27e_SiteId": "6e603289-5e46-4e26-ac7c-03a85420a9a5",
      "/MSIP_Label_cf20372f-9ab3-4551-9149-9f9b12e2c27e_Tag": "10, 0, 1, 1",
      "/ModDate": "D:20260320194210+01\u002700\u0027",
      "/Producer": "Microsoft\u00ae Word for Microsoft 365",
      "/Subject": "1.18",
      "/Title": "MultiApp V4.2: JCS Security Target",
      "pdf_file_size_bytes": 3164116,
      "pdf_hyperlinks": {
        "_type": "Set",
        "elements": []
      },
      "pdf_is_encrypted": false,
      "pdf_number_of_pages": 152
    }
  },
  "protection_profile_links": null,
  "report_link": null,
  "scheme": "FR",
  "security_level": {
    "_type": "Set",
    "elements": [
      "EAL5"
    ]
  },
  "st_link": "https://certification.enisa.europa.eu/document/download/162a9e83-485e-4d91-bee6-c0c644499856_en?filename=EUCC-3090-2026-60-cible.pdf",
  "state": {
    "_type": "sec_certs.sample.cc_eucc_common.InternalState",
    "cert": {
      "_type": "sec_certs.sample.document_state.DocumentState",
      "convert_ok": true,
      "download_ok": true,
      "extract_ok": true,
      "json_hash": null,
      "source_hash": "fc7a08b100516f82a3c7726d78ea014f8b86f7291a6db8f349103ba270cd9e31",
      "txt_hash": "10b435ab9554911e4c5b0b743314e0aadaaad80339a5d7517673408166fae67f"
    },
    "report": {
      "_type": "sec_certs.sample.document_state.DocumentState",
      "convert_ok": false,
      "download_ok": false,
      "extract_ok": false,
      "json_hash": null,
      "source_hash": null,
      "txt_hash": null
    },
    "st": {
      "_type": "sec_certs.sample.document_state.DocumentState",
      "convert_ok": true,
      "download_ok": true,
      "extract_ok": true,
      "json_hash": null,
      "source_hash": "5c7673c2acc237c05c32a73ea1f8493c9554c892b42f0b3d518c9c82aa4e17b8",
      "txt_hash": "c1b6eed8f99dbcaee5a219396a0836e957a56d6ad8707fda50ac1306a462ab2a"
    }
  },
  "status": "active"
}