{"_id": "88e3c1202ae0f0fd", "_type": "sec_certs.sample.eucc.EUCCCertificate", "dgst": "88e3c1202ae0f0fd", "cert_id": "EUCC-3087-2026-0011", "category": "SMARTCARDS AND SIMILAR DEVICES", "name": "STARCOS 3.7 COS HBA-SMC", "status": "active", "manufacturer": "Giesecke+Devrient ePayments GmbH", "scheme": "DE", "security_level": {"_type": "Set", "elements": []}, "not_valid_before": "2026-06-17", "not_valid_after": "2031-06-17", "report_link": "https://certification.enisa.europa.eu/document/download/986b1328-abf8-438f-a553-5805097abdd7_en?filename=EUCC-3087-2026-0011%20Certification%20Report.pdf", "st_link": "https://certification.enisa.europa.eu/document/download/01f49505-5305-448c-924b-09b8904996ec_en?filename=EUCC-3087-2026-0011%20Security%20Target.pdf", "cert_link": "https://certification.enisa.europa.eu/document/download/1816b716-b06c-4989-9b42-0a7c915e2aa4_en?filename=EUCC-3087-2026-0011%20Certificate.pdf", "manufacturer_web": "https://www.gi-de.com/en/cybersecurity-information", "protection_profile_links": null, "state": {"_type": "sec_certs.sample.cc_eucc_common.InternalState", "report": {"_type": "sec_certs.sample.document_state.DocumentState", "download_ok": true, "convert_ok": true, "extract_ok": true, "source_hash": "517e2b9705ab9016ca985840cba21b034186a2a5e2c48205d1842f58020dee11", "txt_hash": "05376dc3314e753239585c14fadb5468622a527e2086b8782423850118da35cc", "json_hash": null}, "st": {"_type": "sec_certs.sample.document_state.DocumentState", "download_ok": true, "convert_ok": true, "extract_ok": true, "source_hash": "d76b738ba378d159a08ac02d3e93bcc14279b5bbaf1a0393322cd6e7718d666e", "txt_hash": "fa122615234a076d5146404f825329740373f05981dc4cf536604c919938d429", "json_hash": null}, "cert": {"_type": "sec_certs.sample.document_state.DocumentState", "download_ok": true, "convert_ok": true, "extract_ok": true, "source_hash": "3a152200634545304d684eb25e8287ef1b90868c68498176e4156f17f3d1d2bc", "txt_hash": "5952d52233ac572e4f8c4e485c9bf0880401d96eb257479c3cdc8a8efed90565", "json_hash": null}}, "pdf_data": {"_type": "sec_certs.sample.cc_eucc_common.PdfData", "report_metadata": {"pdf_file_size_bytes": 708967, "pdf_is_encrypted": false, "pdf_number_of_pages": 39, "/Subject": "STARCOS 3.7 COS HBA-SMC from G+D ePayments GmbH", "/Keywords": "Common Criteria, Certification, Zertifizierung, G2 COS, eHealth, gematik", "/CreationDate": "D:20260702102033+02'00'", "/Producer": "LibreOffice 5.3", "/Creator": "Writer", "/Title": "Certification Report EUCC-3087-jjjj-mm-nnnn; BSI-DSZ-CC-0976-V5", "pdf_hyperlinks": {"_type": "Set", "elements": ["https://www.iso.org/standard/72917.html", "https://www.iso.org/standard/72892.html", "https://www.commoncriteriaportal.org/", "https://www.iso.org/standard/72906.html", "https://www.iso.org/standard/72891.html", "http://www.commoncriteriaportal.org/", "https://www.gi-de.com/en/cybersecurity-information", "https://www.bsi.bund.de/zertifizierungsreporte", "https://www.bsi.bund.de/AIS", "https://www.iso.org/standard/72889.html", "https://certification.enisa.europa.eu/publications/eucc-state-art-documents_en", "https://eur-lex.europa.eu/eli/reg_impl/2025/2462/oj", "https://certification.enisa.europa.eu/", "https://www.bsi.bund.de/zertifizierung", "https://www.iso.org/standard/72913.html"]}}, "st_metadata": {"pdf_file_size_bytes": 4100307, "pdf_is_encrypted": false, "pdf_number_of_pages": 168, "/Title": "G+D Security Target to BSI-PP-0082-V4", "/Author": "Giesecke+Devrient ePayments GmbH", "/Subject": "Security Target STARCOS 3.7 COS HBA-SMC", "/Keywords": "Version 2.2/23.04.2026", "/Creator": "Microsoft\u00ae Word f\u00fcr Microsoft 365", "/CreationDate": "D:20260423134806+02'00'", "/ModDate": "D:20260423134806+02'00'", "/Producer": "Microsoft\u00ae Word f\u00fcr Microsoft 365", "pdf_hyperlinks": {"_type": "Set", "elements": []}}, "cert_metadata": {"pdf_file_size_bytes": 125061, "pdf_is_encrypted": false, "pdf_number_of_pages": 2, "/Title": "KM_C300i26062206000", "/Creator": "KM_C300i", "/Producer": "KONICA MINOLTA bizhub C300i", "/CreationDate": "D:20260622060106+01'00'", "/ModDate": "D:20260622060106+01'00'", "pdf_hyperlinks": {"_type": "Set", "elements": []}}, "report_frontpage": {"DE": {"match_rules": ["(BSI-DSZ-CC-.+?) (?:for|For) (.+?) from (.*)"], "cert_id": "BSI-DSZ-CC-0976-V5-2026", "cert_item": "STARCOS 3.7 COS HBA-SMC", "developer": "Giesecke+Devrient ePayments GmbH", "cert_lab": "BSI"}}, "st_frontpage": null, "cert_frontpage": null, "report_keywords": {"cc_cert_id": {"DE": {"BSI-DSZ-CC-0976-V5-2026": 44, "BSI-DSZ-CC-0976-V4-2021": 2, "BSI-DSZ-CC-1110-": 1, "BSI-DSZ-CC-1110-V8-2025": 7, "BSI-DSZ-CC-S-0347-2026": 1, "EUCC-3087-2026-0011": 39}, "FR": {"ANSSI-CC-SITE-2025/05": 2, "ANSSI-CC-SITE-2025/03": 2}}, "cc_protection_profile_id": {"BSI": {"BSI-CC-PP-0082-V4-2019": 3}}, "cc_security_level": {"EAL": {"EAL 2": 2, "EAL 4": 1}}, "cc_sar": {"ADV": {"ADV_ARC": 1}, "ALC": {"ALC_FLR": 2, "ALC_DVS.2": 1, "ALC_FLR.1": 1}, "ATE": {"ATE_DPT.2": 1}, "AVA": {"AVA_VAN.5": 2}}, "cc_sfr": {"FCS": {"FCS_COP": 29, "FCS_CKM": 4, "FCS_RNG.1": 1, "FCS_RNG": 3}, "FIA": {"FIA_UAU": 2, "FIA_USB": 1}, "FPT": {"FPT_ITE.1": 1}, "FTP": {"FTP_ITC": 2}}, "cc_claims": {}, "vendor": {"Infineon": {"Infineon": 10, "Infineon Technologies AG": 6}, "GD": {"Giesecke+Devrient": 31, "G+D": 2}}, "eval_facility": {"TUV": {"T\u00dcV Informationstechnik": 1}, "SRC": {"SRC Security Research & Consulting": 6}}, "symmetric_crypto": {"AES_competition": {"AES": {"AES": 29}, "HPC": {"HPC": 4}}, "constructions": {"MAC": {"CMAC": 15}}}, "asymmetric_crypto": {"RSA": {"RSA-OAEP": 2}, "ECC": {"ECDH": {"ECDH": 3}, "ECDSA": {"ECDSA": 14}, "ECC": {"ECC": 8}}, "FF": {"DH": {"Diffie-Hellman": 1}}}, "pq_crypto": {}, "hash_function": {"SHA": {"SHA2": {"SHA-256": 3}}}, "crypto_scheme": {"MAC": {"MAC": 3}, "KA": {"Key Agreement": 1}}, "crypto_protocol": {"PACE": {"PACE": 11}}, "randomness": {"PRNG": {"PRNG": 1}, "RNG": {"RNG": 4}}, "cipher_mode": {"CBC": {"CBC": 10}}, "ecc_curve": {}, "crypto_engine": {}, "tls_cipher_suite": {}, "crypto_library": {}, "vulnerability": {}, "side_channel_analysis": {"SCA": {"side channel": 1, "DPA": 1, "SPA": 1}, "FI": {"malfunction": 1, "DFA": 1, "fault injection": 1}, "other": {"JIL": 2}}, "technical_report_id": {"BSI": {"BSI TR-03116-1": 1, "BSI TR-03144": 10, "BSI TR-03143": 5}}, "device_model": {}, "tee_name": {}, "os_name": {"STARCOS": {"STARCOS 3": 37}}, "cplc_data": {}, "ic_data_group": {}, "standard_id": {"FIPS": {"FIPS 180-4": 9, "FIPS 197": 12, "FIPS PUB 180-4": 1, "FIPS PUB 197": 1}, "PKCS": {"PKCS#1": 5}, "BSI": {"AIS 20": 5, "AIS 31": 4, "AIS 37": 2, "AIS 46": 2, "AIS 38": 2, "AIS 1": 2, "AIS 25": 2, "AIS 32": 2, "AIS 14": 1, "AIS 19": 1, "AIS 26": 1}, "RFC": {"RFC 5639": 15}, "ISO": {"ISO/IEC 15408": 2, "ISO/IEC 18045": 2, "ISO/IEC 17065": 2, "ISO/IEC 18031:2005": 1}}, "javacard_version": {}, "javacard_api_const": {}, "javacard_packages": {}, "certification_process": {"ConfidentialDocument": {"for STARCOS 3.7 COS HBA-SMC, Version 3.2, 24 May 2026, SRC Security Research & Consulting GmbH (confidential document) [ConfList] Configuration List BSI-DSZ-CC-0976-V5-2026, Configuration List STARCOS 3.7 COS HBA-SMC": 1, "1.0, 21 May 2026, Giesecke+Devrient ePayments GmbH (confidential document) 6 specifically \u2022 AIS 1, Version 14, Durchf\u00fchrung der Ortsbesichtigung in der Entwicklungsumgebung": 1, "design step H13, Version 6.2, 26 June 2025, Infineon Technologies AG, BSI-DSZ-CC-1110-V8-2025 (confidential document) Security Target Lite of the underlying hardware platform, Security Target IFX_CCI_000003h": 1, "procedure BSI-DSZ-CC-1110-V8-2025, Version 2, 25 July 2025, T\u00dcV Informationstechnik GmbH (confidential document) [Spec G2 COS] Einf\u00fchrung der Gesundheitskarte, Spezifikation des Card Operating System (COS": 1}}}, "st_keywords": {"cc_cert_id": {"DE": {"BSI-DSZ-CC-1110-V8-2025": 1}}, "cc_protection_profile_id": {"BSI": {"BSI-PP-0084-2014": 8, "BSI-CC-PP-0084-2014": 51, "BSI-CC-PP- 0084-2014": 6, "BSI-CC-PP-0082-V4": 32, "BSI-CC-PP-0084-2007": 1, "BSI-CC-PP- 0082-V4": 1, "BSI-CC-PP-0084-": 4, "BSI-PP-0084-": 2, "BSI-CC-PP-0035-2007": 1}}, "cc_security_level": {"EAL": {"EAL4": 14, "EAL 4": 2, "EAL5": 1, "EAL6": 1, "EAL 5": 1, "EAL4 augmented": 4, "EAL5 augmented": 1, "EAL6 augmented": 1}}, "cc_sar": {"ADV": {"ADV_ARC.1": 9, "ADV_FSP.4": 6, "ADV_IMP.1": 6, "ADV_TDS.3": 3, "ADV_ARC": 2, "ADV_FSP": 2, "ADV_IMP": 2, "ADV_IMP.2": 1, "ADV_INT.3": 1, "ADV_TDS.5": 1}, "AGD": {"AGD_OPE.1": 6, "AGD_PRE.1": 2, "AGD_OPE": 2, "AGD_PRE": 2}, "ALC": {"ALC_FLR.1": 11, "ALC_DVS.2": 13, "ALC_CMC.4": 1, "ALC_CMS.4": 1, "ALC_DEL.1": 1, "ALC_LCD.1": 1, "ALC_TAT.1": 1, "ALC_DEL": 2, "ALC_DVS": 2, "ALC_CMS": 2, "ALC_CMC": 2, "ALC_CMC.5": 1, "ALC_TAT.3": 1}, "ATE": {"ATE_FUN.1": 6, "ATE_IND.2": 5, "ATE_DPT.2": 11, "ATE_COV.2": 1, "ATE_COV": 2, "ATE_DPT.1": 1, "ATE_FUN.2": 1, "ATE_COV.3": 1}, "AVA": {"AVA_VAN.5": 11, "AVA_VAN": 2}, "ASE": {"ASE_CCL.1": 1, "ASE_ECD.1": 1, "ASE_INT.1": 1, "ASE_OBJ.2": 1, "ASE_REQ.2": 1, "ASE_SPD.1": 1, "ASE_TSS.1": 1, "ASE_ECD": 1}}, "cc_sfr": {"FAU": {"FAU_SAS": 8, "FAU_SAS.1": 3}, "FCS": {"FCS_RNG": 35, "FCS_COP": 191, "FCS_CKM": 84, "FCS_RNG.1": 32, "FCS_CKM.6": 65, "FCS_RNG.1.1": 3, "FCS_RNG.1.2": 2, "FCS_CKM.1": 40, "FCS_CKM.5": 42, "FCS_COP.1": 23, "FCS_CKM.2": 9, "FCS_CKM.3": 1, "FCS_RBG.1": 9, "FCS_COP.1.1": 1, "FCS_CKM.6.1": 2, "FCS_CKM.6.2": 1}, "FDP": {"FDP_ITT": 7, "FDP_IFC": 7, "FDP_SDC": 8, "FDP_SDI": 7, "FDP_RIP.1": 14, "FDP_SDI.2": 11, "FDP_ACC": 123, "FDP_ACF": 110, "FDP_SDC.1": 3, "FDP_ITT.1": 3, "FDP_IFC.1": 16, "FDP_RIP.1.1": 1, "FDP_SDI.1": 1, "FDP_SDI.2.1": 1, "FDP_SDI.2.2": 1, "FDP_ACF.1": 41, "FDP_ACC.1": 44, "FDP_ITC.1": 35, "FDP_ITC.2": 35, "FDP_RIP": 9, "FDP_UCT": 7, "FDP_UCT.1": 1, "FDP_UIT": 8, "FDP_UIT.1": 2}, "FIA": {"FIA_API": 10, "FIA_AFL": 22, "FIA_ATD.1": 20, "FIA_SOS.1": 8, "FIA_UAU.1": 20, "FIA_UAU.4": 12, "FIA_UAU.5": 17, "FIA_UAU.6": 12, "FIA_API.1": 16, "FIA_USB.1": 30, "FIA_USB": 32, "FIA_UAU": 50, "FIA_UID.1": 19, "FIA_SOS.1.1": 1, "FIA_AFL.1": 4, "FIA_ATD.1.1": 1, "FIA_UAU.1.1": 1, "FIA_UAU.1.2": 1, "FIA_UAU.4.1": 1, "FIA_UAU.5.1": 1, "FIA_UAU.5.2": 1, "FIA_UAU.6.1": 1, "FIA_UID.1.1": 1, "FIA_UID.1.2": 1, "FIA_API.1.1": 1, "FIA_USB.1.1": 1, "FIA_USB.1.2": 1, "FIA_USB.1.3": 2, "FIA_UID": 14, "FIA_ATD": 10, "FIA_ACF": 1, "FIA_ACC": 1}, "FMT": {"FMT_LIM": 15, "FMT_SMR.1": 41, "FMT_MSA.3": 39, "FMT_SMF.1": 51, "FMT_MSA": 68, "FMT_MTD": 38, "FMT_LIM.1": 3, "FMT_LIM.2": 2, "FMT_SMR.1.1": 1, "FMT_SMR.1.2": 1, "FMT_SMF.1.1": 1, "FMT_MSA.1": 8, "FMT_MSA.3.1": 1, "FMT_MSA.3.2": 1, "FMT_MTD.1": 4, "FMT_SMR": 9, "FMT_SRM": 1}, "FPT": {"FPT_FLS": 7, "FPT_PHP": 7, "FPT_ITT": 7, "FPT_EMS": 15, "FPT_ITE": 11, "FPT_FLS.1": 18, "FPT_EMS.1": 12, "FPT_TDC.1": 10, "FPT_ITE.1": 11, "FPT_ITE.2": 13, "FPT_TST.1": 11, "FPT_PHP.3": 4, "FPT_ITT.1": 3, "FPT_FLS.1.1": 1, "FPT_TST": 2, "FPT_EMS.1.1": 1, "FPT_TDC.1.1": 1, "FPT_TDC.1.2": 1, "FPT_ITE.1.1": 1, "FPT_ITE.1.2": 1, "FPT_ITE.2.1": 5, "FPT_ITE.2.2": 1, "FPT_TST.1.1": 1, "FPT_TST.1.2": 1, "FPT_TST.1.3": 1}, "FRU": {"FRU_FLT": 7, "FRU_FLT.2": 3}, "FTP": {"FTP_ITC": 22, "FTP_ITE": 1, "FTP_ITC.1": 12, "FTP_TRP.1": 5}}, "cc_claims": {"O": {"O.RND": 8, "O.AES": 7, "O.PACE_CHIP": 2}, "T": {"T.RND": 5}}, "vendor": {"NXP": {"NXP Semiconductors": 1}, "Infineon": {"Infineon": 2, "Infineon Technologies AG": 2}, "STMicroelectronics": {"STMicroelectronics": 1}, "GD": {"G+D": 1, "Giesecke+Devrient": 10}}, "eval_facility": {}, "symmetric_crypto": {"AES_competition": {"AES": {"AES": 81}, "HPC": {"HPC": 1}}, "constructions": {"MAC": {"CMAC": 43}}}, "asymmetric_crypto": {"ECC": {"ECDH": {"ECDH": 6}, "ECDSA": {"ECDSA": 38}, "ECC": {"ECC": 16}}, "FF": {"DH": {"Diffie-Hellman": 1, "DH": 13}, "DSA": {"DSA": 1}}}, "pq_crypto": {}, "hash_function": {"SHA": {"SHA1": {"SHA-1": 3}, "SHA2": {"SHA-224": 2, "SHA-384": 6, "SHA-256": 11, "SHA-512": 3}}}, "crypto_scheme": {"MAC": {"MAC": 33}, "KA": {"Key agreement": 1, "Key Agreement": 1}}, "crypto_protocol": {"TLS": {"SSL": {"SSL": 1}}, "PACE": {"PACE": 125}}, "randomness": {"RNG": {"RND": 15, "RNG": 36}}, "cipher_mode": {"CBC": {"CBC": 4}}, "ecc_curve": {"Brainpool": {"brainpoolP256r1": 4, "brainpoolP384r1": 4, "brainpoolP512r1": 4}}, "crypto_engine": {}, "tls_cipher_suite": {}, "crypto_library": {}, "vulnerability": {}, "side_channel_analysis": {"SCA": {"Leak-Inherent": 15, "Physical Probing": 2, "side channel": 1, "SPA": 1, "DPA": 1}, "FI": {"physical tampering": 3, "Malfunction": 17, "malfunction": 1, "DFA": 1}, "other": {"Bleichenbacher attack": 1, "JIL": 1}}, "technical_report_id": {"BSI": {"BSI TR-03143": 2, "BSI TR-03111": 3}}, "device_model": {}, "tee_name": {"IBM": {"SE": 1}}, "os_name": {"STARCOS": {"STARCOS 3": 181}}, "cplc_data": {}, "ic_data_group": {}, "standard_id": {"FIPS": {"FIPS 180-4": 1, "FIPS 197": 4, "FIPS PUB 197": 1, "FIPS PUB 180-4": 1}, "NIST": {"NIST SP 800-38B": 1}, "PKCS": {"PKCS #1": 2}, "BSI": {"AIS31": 1, "AIS20": 2}, "RFC": {"RFC5639": 3, "RFC 5639": 1}, "ISO": {"ISO/IEC 7816": 2}, "CC": {"CCMB-2022-11-003": 2, "CCMB-2022-11-001": 1, "CCMB-2022-11-002": 1, "CCMB-2022-11-004": 2}}, "javacard_version": {}, "javacard_api_const": {}, "javacard_packages": {}, "certification_process": {"OutOfScope": {"out of scope": 1, "and cryptographic key sizes 2048 bits and 3072 bits modulus length for RSA private key operation is out of scope for the TOE. 378 The TOE shall meet the requirement \u201cCryptographic operation \u2013 CB ECC (FCS_COP.1/CB": 1}}}, "cert_keywords": {"cc_cert_id": {"DE": {"BSI-DSZ-CC-0976-V5-2026": 1, "EUCC-3087-2026-0011": 1}}, "cc_protection_profile_id": {}, "cc_security_level": {"EAL": {"EAL 2": 1, "EAL 4": 1}}, "cc_sar": {"ALC": {"ALC_FLR": 1, "ALC_DVS.2": 1, "ALC_FLR.1": 1}, "ATE": {"ATE_DPT.2": 1}, "AVA": {"AVA_VAN.5": 2, "AVA_VAN": 1}}, "cc_sfr": {}, "cc_claims": {}, "vendor": {"GD": {"Giesecke+Devrient": 1}}, "eval_facility": {"SRC": {"SRC Security Research & Consulting": 1}}, "symmetric_crypto": {}, "asymmetric_crypto": {}, "pq_crypto": {}, "hash_function": {}, "crypto_scheme": {}, "crypto_protocol": {}, "randomness": {}, "cipher_mode": {}, "ecc_curve": {}, "crypto_engine": {}, "tls_cipher_suite": {}, "crypto_library": {}, "vulnerability": {}, "side_channel_analysis": {}, "technical_report_id": {}, "device_model": {}, "tee_name": {}, "os_name": {"STARCOS": {"STARCOS 3": 1}}, "cplc_data": {}, "ic_data_group": {}, "standard_id": {"ISO": {"ISO/IEC 15408": 2, "ISO/IEC 18045": 2}}, "javacard_version": {}, "javacard_api_const": {}, "javacard_packages": {}, "certification_process": {}}, "report_filename": "986b1328-abf8-438f-a553-5805097abdd7_en", "st_filename": "01f49505-5305-448c-924b-09b8904996ec_en", "cert_filename": "1816b716-b06c-4989-9b42-0a7c915e2aa4_en"}, "heuristics": {"_type": "sec_certs.sample.cc_eucc_common.Heuristics", "extracted_versions": {"_type": "Set", "elements": ["3.7"]}, "cpe_matches": null, "verified_cpe_matches": null, "related_cves": null, "cert_lab": ["BSI"], "cert_id": "EUCC-3087-2026-11", "prev_certificates": null, "next_certificates": null, "st_references": {"_type": "sec_certs.sample.certificate.References", "directly_referenced_by": null, "indirectly_referenced_by": null, "directly_referencing": null, "indirectly_referencing": null}, "report_references": {"_type": "sec_certs.sample.certificate.References", "directly_referenced_by": null, "indirectly_referenced_by": null, "directly_referencing": null, "indirectly_referencing": null}, "annotated_references": null, "extracted_sars": {"_type": "Set", "elements": [{"_type": "sec_certs.sample.sar.SAR", "family": "ASE_INT", "level": 1}, {"_type": "sec_certs.sample.sar.SAR", "family": "ASE_CCL", "level": 1}, {"_type": "sec_certs.sample.sar.SAR", "family": "AGD_OPE", "level": 1}, {"_type": "sec_certs.sample.sar.SAR", "family": "ALC_FLR", "level": 1}, {"_type": "sec_certs.sample.sar.SAR", "family": "ADV_TDS", "level": 5}, {"_type": "sec_certs.sample.sar.SAR", "family": "ALC_CMS", "level": 4}, {"_type": "sec_certs.sample.sar.SAR", "family": "ADV_IMP", "level": 2}, {"_type": "sec_certs.sample.sar.SAR", "family": "ATE_DPT", "level": 2}, {"_type": "sec_certs.sample.sar.SAR", "family": "ADV_ARC", "level": 1}, {"_type": "sec_certs.sample.sar.SAR", "family": "ALC_DVS", "level": 2}, {"_type": "sec_certs.sample.sar.SAR", "family": "ALC_DEL", "level": 1}, {"_type": "sec_certs.sample.sar.SAR", "family": "ALC_LCD", "level": 1}, {"_type": "sec_certs.sample.sar.SAR", "family": "AVA_VAN", "level": 5}, {"_type": "sec_certs.sample.sar.SAR", "family": "ADV_FSP", "level": 4}, {"_type": "sec_certs.sample.sar.SAR", "family": "ATE_COV", "level": 3}, {"_type": "sec_certs.sample.sar.SAR", "family": "ATE_IND", "level": 2}, {"_type": "sec_certs.sample.sar.SAR", "family": "ASE_OBJ", "level": 2}, {"_type": "sec_certs.sample.sar.SAR", "family": "ALC_CMC", "level": 5}, {"_type": "sec_certs.sample.sar.SAR", "family": "ASE_SPD", "level": 1}, {"_type": "sec_certs.sample.sar.SAR", "family": "ASE_REQ", "level": 2}, {"_type": "sec_certs.sample.sar.SAR", "family": "ATE_FUN", "level": 2}, {"_type": "sec_certs.sample.sar.SAR", "family": "ADV_INT", "level": 3}, {"_type": "sec_certs.sample.sar.SAR", "family": "ASE_ECD", "level": 1}, {"_type": "sec_certs.sample.sar.SAR", "family": "AGD_PRE", "level": 1}, {"_type": "sec_certs.sample.sar.SAR", "family": "ASE_TSS", "level": 1}, {"_type": "sec_certs.sample.sar.SAR", "family": "ALC_TAT", "level": 3}]}, "direct_transitive_cves": null, "indirect_transitive_cves": null, "scheme_data": {"cert_id": "EUCC-3087-2026-0011", "product": "STARCOS 3.7 COS HBA-SMC", "vendor": "Giesecke & Devrient GmbH seit 1. Juli 2017 Giesecke+Devrient Mobile Security GmbH seit 1. Juli 2023 Giesecke+Devrient ePayments GmbH", "certification_date": "2026-06-17", "category": "eHealth", "url": "https://www.bsi.bund.de/SharedDocs/Zertifikate_CC/CC/Gesundheitswesen_SmartCards/0976.html", "enhanced": {"product": "STARCOS 3.7 COS HBA-SMC", "applicant": "Giesecke & Devrient GmbH seit 1. Juli 2017 Giesecke+Devrient Mobile Security GmbH seit 1. Juli 2023 Giesecke+Devrient ePayments GmbH Prinzregentenstr. 161 81677 M\u00fcnchen", "evaluation_facility": "SRC Security Research & Consulting GmbH", "assurance_level": "EAL4+,ALC_DVS.2,ATE_DPT.2,AVA_VAN.5,ALC_FLR.1", "protection_profile": "Card Operating System Generation 2 (PP COS G2), Version 2.1, 10 July 2019, BSI-CC-PP-0082-V4-2019", "certification_date": "2026-06-17", "expiration_date": "2031-06-16", "entries": [{"id": "EUCC-3087-2026-0011 / BSI-DSZ-CC-0976-V5-2026 (Ausstellungsdatum / Certification Date 17.06.2026, g\u00fcltig bis / valid until 16.06.2031)", "description": "The focus of this re-certification was on the transfer of the certification procedure to CC/CEM:2022 and to EUCC. Included is the update of the product life-cycle concerning the involved development and production sites, the underlying HW-certificate as well as the vulnerability analysis and valuation of the TOE's (crypto) implementation. The certified product itself including its related guidance documentation did not change."}, {"id": "BSI", "description": "The maintenance procedure for BSI-DSZ-CC-0976-V4-2021 covers the update of the product life-cycle concerning the involved development and production sites and additionally addresses the update of the Security Target (ST) and user guidance documentation regards the TOE's random number generation functionality. The certified product itself did not change."}, {"id": "BSI", "description": "The partial ALC re-evaluation for procedure 0976-V4 covers the update of the product life-cycle concerning the involved development and production sites. The certified product itself did not change."}, {"id": "BSI", "description": "The focus of this re-certification was on the adaptation of the Target of Evaluation (TOE) to the current version of the G2.1 COS-specification from gematik and the corresponding Protection Profile PP-0082-V4. This was related to the re-certification of the underlying Integrated Circuit (IC), to adaptations in the life-cycle model, to the integration of the functional packages Crypto Box and Logical Channel, to further specific changes in the Embedded Software as well as a corresponding update of the associated user guidance documentation. In particular, the TOE\u2019s (crypto) implementation was revised, re-evaluated and re-assessed."}, {"id": "BSI", "description": "The partial ALC re-evaluation for procedure 0976-V3 covers the update of the product life-cycle concerning the involved development and production sites. The certified product itself did not change."}, {"id": "BSI", "description": "The partial ALC re-evaluation for procedure 0976-V3 covers the update of the product life-cycle concerning the involved development and production sites. The certified product itself did not change."}, {"id": "BSI", "description": "Software"}, {"id": "BSI-DSZ-CC-0976-V2-2018 (Ausstellungsdatum / Certification Date 20.09.2018, g\u00fcltig bis / valid until 19.09.2023) Zertifizierungsreport / Certification Report Sicherheitsvorgaben / Security Target Zertifikate / Certificate Im Fokus der vorliegenden Re-Zertifizierung stand die Anpassung des Evaluierungsgegenstandes (EVG) an die aktuelle Version der G2.1 COS-Spezifikation der gematik und das zugeh\u00f6rige \u00fcberarbeitete Schutzprofil PP-0082-V3. Dies war verbunden mit einem Wechsel des unterliegenden Halbleiters, Anpassungen im Lebenszyklusmodell sowie spezifischen \u00c4nderungen in der Embedded Software und einer entsprechenden Aktualisierung der zugeh\u00f6rigen Benutzerdokumentation.", "description": "Software"}, {"id": "BSI", "description": "The changes are related to an update and reevaluation of the product life-cycle caused by changes in the development and porduction sites. The certified product itself did not change."}, {"id": "BSI", "description": "Security Target"}, {"id": "BSI", "description": "Security Target"}], "description": "The Target of Evaluation (TOE) is the product STARCOS 3.6 COSGKV C1 developed by Giesecke & Devrient GmbH. The TOE is a smart card product according to the G2 Card Operating System (G2-COS) specification from gematik. The TOE is intended to be used as a card operating system platform for specific card types and applications of the card generation G2 in the framework of the German health care system, and therefore implements the mandatory part of the G2-COS specification with the base functionality of the operating system platform only. The TOE implements from the PP-0082-V2 the base part without any of the optional packages."}, "subcategory": "Smartcards"}, "protection_profiles": null, "eal": null}, "other_metadata": {"_type": "sec_certs.sample.eucc.EUCCCertificate.EnisaMetadata", "certificate_id": "EUCC-3087-2026-0011", "product_name": "STARCOS 3.7 COS HBA-SMC", "product_type": "Smartcards and similar devices", "product_version": "47 44 00 B7 04 01 01", "product_description": "The TOE is a smart card product according to the G2-COS specification from gematik and is implemented on the hardware platform Infineon Security Controller IFX_CCI_000005h from Infineon Technologies AG. The TOE is intended to be used as a card operating system platform for cards of the card generation G2 in the framework of the German health care system.", "holder_name": "Giesecke+Devrient ePayments GmbH", "holder_address": "Prinzregentenstra\u00dfe 161, 81677 M\u00fcnchen", "holder_contact": null, "holder_website": "https://www.gi-de.com/en/cybersecurity-information", "certification_body": "BSI", "nando_id": "3087", "certification_body_address": "Postfach 200363\\n53133 Bonn, Bonn", "certification_body_contact": "zertdokus@bsi.bund.de Phone: +49 228 99 9582-0", "itsef": "SRC Security Research & Consulting GmbH", "responsible_ncca": "Bundesamt f\u00fcr Sicherheit in der Informationstechnik", "scheme": "(UE) 2024/482 - EUCC", "report_reference": "EUCC-3087-2026-0011 Certificate Report", "assurance_level": "High", "cc_version": "CC:2022 Revision 1", "cem_version": "CEM:2022 Revision 1", "ava_van_level": "5", "package": {"EAL4": ["ALC_DVS.2", "ATE_DPT.2", "AVA_VAN.5", "ALC_FLR.1"]}, "protection_profile": "Common Criteria Protection Profile Card Operating System Generation 2 (PP COS G2), Version 2.1, 10 July 2019, BSI-CC-PP-0082-V4-2019, Bundesamt f\u00fcr Sicherheit in der Informationstechnik (BSI)", "issuance_year": "2026", "issuance_month": "6", "issuance_date_full": "17/06/2026", "certificate_yearly_number": "EUCC-3087-2026-000011-I-00", "modification_or_reassurance": null, "validity_period_years": "5 years"}}