This page was not yet optimized for use on mobile devices.
eHealth Card Terminal with Touchscreen Display, ST-1506 AFxZ 5.0.0:4.0.0.
Certificate details
| Certificate ID | EUCC-3087-2026-0015 |
|---|---|
| Product name | eHealth Card Terminal with Touchscreen Display, ST-1506 AFxZ 5.0.0:4.0.0. |
| Scheme | 🇩🇪 DE |
| Assurance level | high |
| Status | active |
Product Specification
| Type | Smartcards and similar devices |
|---|---|
| Description |
The Target of Evaluation (TOE) is the eHealth Card Terminal with Touchscreen Display, ST-1506 AFxZ 5.0.0:4.0.0. The TOE has different certified varian...
The Target of Evaluation (TOE) is the eHealth Card Terminal with Touchscreen Display, ST-1506 AFxZ 5.0.0:4.0.0. The TOE has different certified variants, due to different housing color. The different variants can be identified by the part number of the TOE: the following variants of the TOE are certified TOE versions, ST-1506 AFHZ for white and ST-1506 AFEZ for black color. Both variants have the same TOE version. The TOE is the card terminal eHealth Terminal ST-1506 with 2 ID1 Slots (HPC and eGK) and 2 SMC Slots (SM-KT (supporting SMC-B and SMC-KT cards) and SMC-A), 720p touchscreen (also used for secure pin entry) and LAN interfaces for the use in the German healthcare system with HPC and eGK. It addresses the security services provided by this terminal:
|
| Version | 1 |
| Package | EAL3 augmented with ADV_FSP.4 , ADV_IMP.1 , ADV_TDS.3 , ALC_TAT.1 , AVA_VAN.4 |
Certificate holder
| Name | Cherry Digital Health GmbH |
|---|---|
| Address | Rosental 7 80331 München Germany |
| Contact information | [email protected] |
| Website | https://embedded.cherry.de/st-1506-security/ |
Certification body
| Name | BSI |
|---|---|
| NANDO ID | 3087 |
| Address | Postfach 200363\n53133 Bonn, Bonn |
| Contact information | [email protected] Phone: +49 228 99 9582-0 |
Standards & Compliance
| CC Version | CC:2022 Revision 1 |
|---|---|
| CEM Version | N/A |
| AVA_VAN level | 4 |
| Certification report reference | N/A |
Other
| ITSEF | TÜV Informationstechnik GmbH |
|---|---|
| Responsible NCCA | Bundesamt für Sicherheit in der Informationstechnik |
| Protection profile | Common Criteria Protection Profile Electronic Health Card Terminal (eHCT), BSI-CC-PP-0032-V3-2023 |
| Certification date | 17.08.2026 |
| Archived date | 17.08.2031 |
Certificate
certificate file processing did not finish successfully.
Show more...
Download pdf:
ERROR
Convert pdf to text:
OK
Extract keywords:
OK
Extracted keywords
Security level
EAL 3, EAL 2Security Assurance Requirements (SAR)
ADV_FSP.4, ADV_IMP.1, ADV_TDS.3, ALC_FLR, AVA_VAN.4, AVA_VANProtection profiles
BSI-CCPP-0032-V3-2023Certificates
BSI-DSZ-CC-1124-V4-2026, EUCC-3087-2026-0015Certification report
Extracted keywords
Symmetric Algorithms
AES-, AES, HPCAsymmetric Algorithms
ECDHE, ECDSA, ECC, Diffie-HellmanHash functions
SHA-256, SHA-384, SHA256, SHA-2Protocols
TLS 1.2, TLS, TLS v1.2Randomness
RNGBlock cipher modes
GCMSecurity level
EAL 2, EAL 3, EAL3+Claims
O.PROTECTIONSecurity Assurance Requirements (SAR)
ADV_FSP.4, ADV_IMP.1, ADV_TDS.3, ALC_FLR, ALC_TAT.1, ALC_DEL, ALC_DEL.1, ATE_IND, AVA_VAN.4, AVA_VANSecurity Functional Requirements (SFR)
FCS_CKM.1, FCS_COP.1, FIA_UAU.5Protection profiles
BSI-CC-PP-0032-V3-2023Certificates
BSI-DSZ-CC-1124-V4-2026, BSI-DSZ-CC-1124-V3-2023, EUCC-3087-2026-0015Evaluation facilities
TÜV InformationstechnikCertification process
3, 12.08.2026, EVALUATION TECHNICAL REPORT SUMMARY (ETR SUMMARY), TÜV Informationstechnik GmbH, (confidential document, ConfList] Configuration list for the TOE: [ALC_CMS_SW], [ALC_CMS_HW], [BOM] and [Bibliography] (confidential documents, Scope of Software Development ALC_CMS_SW, Version 3.1, 26.07.2026, Cherry Digital Health GmbH (confidential document, ALC_CMS_HW] ALC_CMS_HW_vx.y.z.xlsx, Version 1.1.1, 31.01.2023, Cherry Digital Health GmbH (confidential document, BOM] BOM_Package_v4.0.0_2023-02-01 Version 4.0.0, 01.02.2023, Cherry Digital Health GmbH (confidential document, ST-1506 Bibliography, Glossary and Acronyms, Version 6.3, 07.08.2026, Cherry Digital Health GmbH (confidential document, ALC_DEL] Common-Criteria-3.1 Dokument ALC_DEL.1, V1.1, 17.01.2023, Cherry Digital Health GmbH (confidential documentStandards
FIPS 197, FIPS PUB 180-2, FIPS PUB 180-4, FIPS 186-5, FIPS 180-4, PKCS#1, AIS 14, AIS 19, AIS 32, AIS 46, RFC 5246, RFC 4492, RFC 5289, RFC 8017, RFC 5639, RFC 4226, ISO/IEC 15408, ISO/IEC 18045, ISO/IEC 17065, X.509Frontpage
| Certificate ID | BSI-DSZ-CC-1124-V4-2026 |
|---|---|
| Certified item | CHERRY eHealth Terminal ST-1506, FW 5.0.0, HW 4.0.0 |
| Certification lab | BSI |
| Developer | Cherry Digital Health GmbH BSI - |
Security target
Extracted keywords
Symmetric Algorithms
AES, HPCAsymmetric Algorithms
ECDHE, ECDSA, ECCHash functions
SHA-256Protocols
TLS, VPNRandomness
PRNG, RNGBlock cipher modes
GCMTLS cipher suites
TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256, TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384, TLS_ECDHE_ECDSA_WITH_AES_128_GCM_SHA256, TLS_ECDHE_ECDSA_WITH_AES_256_GCM_SHA384Operating System name
JCOP 4Vendor
NXPSecurity level
EAL3+, EAL 3, EAL6+, EAL3, EAL3 augmented, EAL 3 augmentedClaims
O.ACCESS_CONTROL, O.PIN_ENTRY, O.MANAGEMENT, O.SECURE_CHANNEL, O.STATE, O.PROTECTION, T.COM, T.PIN, T.DATA, T.F-CONNECTOR, A.PUSH_SERVER, A.ENV, A.ADMIN, A.CONNECTOR, A.SM, OE.ENV, OE.ADMIN, OE.CONNECTOR, OE.SM, OE.PUSH_SERVER, OSP.PIN_ENTRYSecurity Assurance Requirements (SAR)
ADV_FSP.4, ADV_IMP.1, ADV_TDS.3, ADV_ARC.1, AGD_OPE.1, AGD_PRE.1, ALC_TAT.1, ALC_CMC.3, ALC_CMS.3, ALC_DEL.1, ALC_DVS.1, ALC_LCD.1, ATE_COV.2, ATE_DPT.1, ATE_FUN.1, ATE_IND.2, AVA_VAN.4, ASE_TSS, ASE_CCL.1, ASE_ECD.1, ASE_INT.1, ASE_OBJ.2, ASE_REQ.2, ASE_SPD.1, ASE_TSS.1Security Functional Requirements (SFR)
FCS_RNG, FCS_CKM.1, FCS_CKM.4, FCS_CKM.6, FCS_COP.1, FCS_RNG.1, FCS_CKM, FCS_COP, FCS_CKM.2, FCS_CKM.5, FCS_RBG.1, FCS_CKM.6.1, FCS_CKM.6.2, FCS_RNG.1.1, FCS_RNG.1.2, FDP_IFF.1, FDP_ACC, FDP_ACF, FDP_IFC, FDP_IFF, FDP_RIP.1, FDP_ITC.1, FDP_ITC.2, FDP_ACC.1, FDP_ACF.1, FDP_IFC.1, FDP_RIP.1.1, FIA_AFL.1, FIA_ATD.1, FIA_SOS.1, FIA_UAU.1, FIA_UAU.5, FIA_UAU.7, FIA_UID.1, FIA_AFL.1.1, FIA_AFL.1.2, FIA_UAU.1.1, FIA_ATD.1.1, FIA_SOS.1.1, FIA_UAU.1.2, FIA_UAU.5.2, FIA_UAU.5.1, FIA_UID.1.2, FIA_UAU.7.1, FIA_UID.1.1, FMT_SMF.1, FMT_MSA, FMT_MSA.2, FMT_SMR.1, FMT_MSA.3, FMT_MSA.1, FMT_MSA.2.1, FMT_SMF.1.1, FMT_SMR.1.1, FMT_SMR.1.2, FPT_PHP.3, FPT_TST.1, FPT_TST.1.1, FPT_FLS.1, FPT_ITT.1, FPT_PHP.1, FPT_FLS.1.1, FPT_ITT.1.1, FPT_PHP.1.1, FPT_PHP.1.2, FPT_PHP.3.1, FPT_TST.1.2, FPT_TST.1.3, FTA_TAB.1, FTA_TAB.1.1, FTA_TAB, FTP_ITC, FTP_TRP, FTP_ITC.1, FTP_TRP.1Protection profiles
BSI-CC-PP-0098-2020, BSI-CC-PP-0032-V3-2023, BSI-CC-PP-0098Certificates
NSCIB-CC-180212-CR2, NSCIB-CC-180212-CR5Side-channel analysis
physical tamperingAutomated analysis
Automated inference - use with caution
All attributes shown in this section (e.g., links between certificates, products, vendors, and known CVEs) are generated by automated heuristics and have not been reviewed by humans. These methods can produce false positives or false negatives and should not be treated as definitive without independent verification. If you want to know more about how this data is computed and how reliable it is, see our documentation on automated analysis. If you believe any information here is inaccurate or harmful, please submit feedback.Extracted SARs
ADV_ARC.1, ADV_FSP.4, ADV_IMP.1, ADV_TDS.3, AGD_OPE.1, AGD_PRE.1, ALC_CMC.3, ALC_CMS.3, ALC_DEL.1, ALC_DVS.1, ALC_LCD.1, ALC_TAT.1, ASE_CCL.1, ASE_ECD.1, ASE_INT.1, ASE_OBJ.2, ASE_REQ.2, ASE_SPD.1, ASE_TSS.1, ATE_COV.2, ATE_DPT.1, ATE_FUN.1, ATE_IND.2, AVA_VAN.4-
The certificate was first processed.
{
"_type": "sec_certs.sample.eucc.EUCCCertificate",
"category": "SMARTCARDS AND SIMILAR DEVICES",
"cert_id": "EUCC-3087-2026-0015",
"cert_link": "https://certification.enisa.europa.eu/document/download/8a523e49-89d2-45ff-adf1-877981ca6cb4_en?filename=EUCC-3087-2026-0015_Certificate.pdf",
"dgst": "a6f6b2b3e9dfb92a",
"heuristics": {
"_type": "sec_certs.sample.cc_eucc_common.Heuristics",
"annotated_references": null,
"cert_id": "EUCC-3087-2026-15",
"cert_lab": [
"BSI"
],
"cpe_matches": null,
"direct_transitive_cves": null,
"eal": "EAL3",
"extracted_sars": {
"_type": "Set",
"elements": [
{
"_type": "sec_certs.sample.sar.SAR",
"family": "ASE_ECD",
"level": 1
},
{
"_type": "sec_certs.sample.sar.SAR",
"family": "ALC_TAT",
"level": 1
},
{
"_type": "sec_certs.sample.sar.SAR",
"family": "ASE_SPD",
"level": 1
},
{
"_type": "sec_certs.sample.sar.SAR",
"family": "ALC_DEL",
"level": 1
},
{
"_type": "sec_certs.sample.sar.SAR",
"family": "ALC_DVS",
"level": 1
},
{
"_type": "sec_certs.sample.sar.SAR",
"family": "ALC_CMS",
"level": 3
},
{
"_type": "sec_certs.sample.sar.SAR",
"family": "ATE_IND",
"level": 2
},
{
"_type": "sec_certs.sample.sar.SAR",
"family": "ATE_FUN",
"level": 1
},
{
"_type": "sec_certs.sample.sar.SAR",
"family": "ADV_IMP",
"level": 1
},
{
"_type": "sec_certs.sample.sar.SAR",
"family": "ASE_CCL",
"level": 1
},
{
"_type": "sec_certs.sample.sar.SAR",
"family": "AGD_PRE",
"level": 1
},
{
"_type": "sec_certs.sample.sar.SAR",
"family": "ASE_OBJ",
"level": 2
},
{
"_type": "sec_certs.sample.sar.SAR",
"family": "ALC_LCD",
"level": 1
},
{
"_type": "sec_certs.sample.sar.SAR",
"family": "ADV_ARC",
"level": 1
},
{
"_type": "sec_certs.sample.sar.SAR",
"family": "AGD_OPE",
"level": 1
},
{
"_type": "sec_certs.sample.sar.SAR",
"family": "ALC_CMC",
"level": 3
},
{
"_type": "sec_certs.sample.sar.SAR",
"family": "ASE_REQ",
"level": 2
},
{
"_type": "sec_certs.sample.sar.SAR",
"family": "ADV_FSP",
"level": 4
},
{
"_type": "sec_certs.sample.sar.SAR",
"family": "AVA_VAN",
"level": 4
},
{
"_type": "sec_certs.sample.sar.SAR",
"family": "ASE_INT",
"level": 1
},
{
"_type": "sec_certs.sample.sar.SAR",
"family": "ATE_COV",
"level": 2
},
{
"_type": "sec_certs.sample.sar.SAR",
"family": "ATE_DPT",
"level": 1
},
{
"_type": "sec_certs.sample.sar.SAR",
"family": "ADV_TDS",
"level": 3
},
{
"_type": "sec_certs.sample.sar.SAR",
"family": "ASE_TSS",
"level": 1
}
]
},
"extracted_versions": {
"_type": "Set",
"elements": [
"5.0.0",
"4.0.0"
]
},
"indirect_transitive_cves": null,
"next_certificates": null,
"prev_certificates": null,
"protection_profiles": null,
"related_cves": null,
"report_references": {
"_type": "sec_certs.sample.certificate.References",
"directly_referenced_by": null,
"directly_referencing": null,
"indirectly_referenced_by": null,
"indirectly_referencing": null
},
"scheme_data": null,
"st_references": {
"_type": "sec_certs.sample.certificate.References",
"directly_referenced_by": null,
"directly_referencing": null,
"indirectly_referenced_by": null,
"indirectly_referencing": null
},
"verified_cpe_matches": null
},
"manufacturer": "Cherry Digital Health GmbH",
"manufacturer_web": "https://embedded.cherry.de/st-1506-security/",
"name": "eHealth Card Terminal with Touchscreen Display, ST-1506 AFxZ 5.0.0:4.0.0.",
"not_valid_after": "2031-08-17",
"not_valid_before": "2026-08-17",
"other_metadata": {
"_type": "sec_certs.sample.eucc.EUCCCertificate.EnisaMetadata",
"assurance_level": "High",
"ava_van_level": "4",
"cc_version": "CC:2022 Revision 1",
"cem_version": null,
"certificate_id": "EUCC-3087-2026-0015",
"certificate_yearly_number": null,
"certification_body": "BSI",
"certification_body_address": "Postfach 200363\\n53133 Bonn, Bonn",
"certification_body_contact": "[email protected] Phone: +49 228 99 9582-0",
"holder_address": "Rosental 7 80331 M\u00fcnchen Germany",
"holder_contact": "[email protected]",
"holder_name": "Cherry Digital Health GmbH",
"holder_website": "https://embedded.cherry.de/st-1506-security/",
"issuance_date_full": "17/08/2026",
"issuance_month": "8",
"issuance_year": "2026",
"itsef": "T\u00dcV Informationstechnik GmbH",
"modification_or_reassurance": null,
"nando_id": "3087",
"package": {
"EAL3": [
"ADV_FSP.4",
"ADV_IMP.1",
"ADV_TDS.3",
"ALC_TAT.1",
"AVA_VAN.4"
]
},
"product_description": "The Target of Evaluation (TOE) is the eHealth Card Terminal with Touchscreen Display, ST-1506 AFxZ 5.0.0:4.0.0. The TOE has different certified variants, due to different housing color. The different variants can be identified by the part number of the TOE: the following variants of the TOE are certified TOE versions, ST-1506 AFHZ for white and ST-1506 AFEZ for black color. Both variants have the same TOE version. The TOE is the card terminal eHealth Terminal ST-1506 with 2 ID1 Slots (HPC and eGK) and 2 SMC Slots (SM-KT (supporting SMC-B and SMC-KT cards) and SMC-A), 720p touchscreen (also used for secure pin entry) and LAN interfaces for the use in the German healthcare system with HPC and eGK. It addresses the security services provided by this terminal:",
"product_name": "eHealth Card Terminal with Touchscreen Display, ST-1506 AFxZ 5.0.0:4.0.0.",
"product_type": "Smartcards and similar devices",
"product_version": "1",
"protection_profile": "Common Criteria Protection Profile Electronic Health Card Terminal (eHCT), BSI-CC-PP-0032-V3-2023",
"report_reference": null,
"responsible_ncca": "Bundesamt f\u00fcr Sicherheit in der Informationstechnik",
"scheme": "(UE) 2024/482 - EUCC",
"validity_period_years": "5 years"
},
"pdf_data": {
"_type": "sec_certs.sample.cc_eucc_common.PdfData",
"cert_filename": "8a523e49-89d2-45ff-adf1-877981ca6cb4_en",
"cert_frontpage": null,
"cert_keywords": {
"asymmetric_crypto": {},
"cc_cert_id": {
"DE": {
"BSI-DSZ-CC-1124-V4-2026": 1,
"EUCC-3087-2026-0015": 1
}
},
"cc_claims": {},
"cc_protection_profile_id": {
"BSI": {
"BSI-CCPP-0032-V3-2023": 1
}
},
"cc_sar": {
"ADV": {
"ADV_FSP.4": 1,
"ADV_IMP.1": 1,
"ADV_TDS.3": 1
},
"ALC": {
"ALC_FLR": 1
},
"AVA": {
"AVA_VAN": 1,
"AVA_VAN.4": 1
}
},
"cc_security_level": {
"EAL": {
"EAL 2": 1,
"EAL 3": 1
}
},
"cc_sfr": {},
"certification_process": {},
"cipher_mode": {},
"cplc_data": {},
"crypto_engine": {},
"crypto_library": {},
"crypto_protocol": {},
"crypto_scheme": {},
"device_model": {},
"ecc_curve": {},
"eval_facility": {},
"hash_function": {},
"ic_data_group": {},
"javacard_api_const": {},
"javacard_packages": {},
"javacard_version": {},
"os_name": {},
"pq_crypto": {},
"randomness": {},
"side_channel_analysis": {},
"standard_id": {
"ISO": {
"ISO/IEC 15408": 2,
"ISO/IEC 18045": 2
}
},
"symmetric_crypto": {},
"technical_report_id": {},
"tee_name": {},
"tls_cipher_suite": {},
"vendor": {},
"vulnerability": {}
},
"cert_metadata": {
"/CreationDate": "D:20260820090231+01\u002700\u0027",
"/Creator": "KM_C300i",
"/ModDate": "D:20260820090231+01\u002700\u0027",
"/Producer": "KONICA MINOLTA bizhub C300i",
"/Title": "KM_C300i26082009020",
"pdf_file_size_bytes": 118700,
"pdf_hyperlinks": {
"_type": "Set",
"elements": []
},
"pdf_is_encrypted": false,
"pdf_number_of_pages": 2
},
"report_filename": "557b1874-d144-4b07-9811-c38f82c6529a_en",
"report_frontpage": {
"DE": {
"cert_id": "BSI-DSZ-CC-1124-V4-2026",
"cert_item": "CHERRY eHealth Terminal ST-1506, FW 5.0.0, HW 4.0.0",
"cert_lab": "BSI",
"developer": "Cherry Digital Health GmbH BSI -",
"match_rules": [
"(BSI-DSZ-CC-.+?) (?:for|For) (.+?) from (.*)"
]
}
},
"report_keywords": {
"asymmetric_crypto": {
"ECC": {
"ECC": {
"ECC": 2
},
"ECDH": {
"ECDHE": 8
},
"ECDSA": {
"ECDSA": 12
}
},
"FF": {
"DH": {
"Diffie-Hellman": 2
}
}
},
"cc_cert_id": {
"DE": {
"BSI-DSZ-CC-1124-V3-2023": 2,
"BSI-DSZ-CC-1124-V4-2026": 23,
"EUCC-3087-2026-0015": 22
}
},
"cc_claims": {
"O": {
"O.PROTECTION": 1
}
},
"cc_protection_profile_id": {
"BSI": {
"BSI-CC-PP-0032-V3-2023": 3
}
},
"cc_sar": {
"ADV": {
"ADV_FSP.4": 1,
"ADV_IMP.1": 1,
"ADV_TDS.3": 1
},
"ALC": {
"ALC_DEL": 3,
"ALC_DEL.1": 1,
"ALC_FLR": 2,
"ALC_TAT.1": 1
},
"ATE": {
"ATE_IND": 2
},
"AVA": {
"AVA_VAN": 2,
"AVA_VAN.4": 2
}
},
"cc_security_level": {
"EAL": {
"EAL 2": 2,
"EAL 3": 1,
"EAL3+": 1
}
},
"cc_sfr": {
"FCS": {
"FCS_CKM.1": 2,
"FCS_COP.1": 4
},
"FIA": {
"FIA_UAU.5": 2
}
},
"certification_process": {
"ConfidentialDocument": {
"3, 12.08.2026, EVALUATION TECHNICAL REPORT SUMMARY (ETR SUMMARY), T\u00dcV Informationstechnik GmbH, (confidential document": 1,
"ALC_CMS_HW] ALC_CMS_HW_vx.y.z.xlsx, Version 1.1.1, 31.01.2023, Cherry Digital Health GmbH (confidential document": 1,
"ALC_DEL] Common-Criteria-3.1 Dokument ALC_DEL.1, V1.1, 17.01.2023, Cherry Digital Health GmbH (confidential document": 1,
"BOM] BOM_Package_v4.0.0_2023-02-01 Version 4.0.0, 01.02.2023, Cherry Digital Health GmbH (confidential document": 1,
"ConfList] Configuration list for the TOE: [ALC_CMS_SW], [ALC_CMS_HW], [BOM] and [Bibliography] (confidential documents": 1,
"ST-1506 Bibliography, Glossary and Acronyms, Version 6.3, 07.08.2026, Cherry Digital Health GmbH (confidential document": 1,
"Scope of Software Development ALC_CMS_SW, Version 3.1, 26.07.2026, Cherry Digital Health GmbH (confidential document": 1
}
},
"cipher_mode": {
"GCM": {
"GCM": 2
}
},
"cplc_data": {},
"crypto_engine": {},
"crypto_library": {},
"crypto_protocol": {
"TLS": {
"TLS": {
"TLS": 4,
"TLS 1.2": 2,
"TLS v1.2": 1
}
}
},
"crypto_scheme": {},
"device_model": {},
"ecc_curve": {
"Brainpool": {
"brainpoolP256r1": 2,
"brainpoolP384r1": 4
},
"NIST": {
"P-256": 6,
"P-384": 6
}
},
"eval_facility": {
"TUV": {
"T\u00dcV Informationstechnik": 6
}
},
"hash_function": {
"SHA": {
"SHA2": {
"SHA-2": 1,
"SHA-256": 7,
"SHA-384": 3,
"SHA256": 2
}
}
},
"ic_data_group": {},
"javacard_api_const": {},
"javacard_packages": {},
"javacard_version": {},
"os_name": {},
"pq_crypto": {},
"randomness": {
"RNG": {
"RNG": 1
}
},
"side_channel_analysis": {},
"standard_id": {
"BSI": {
"AIS 14": 1,
"AIS 19": 1,
"AIS 32": 1,
"AIS 46": 1
},
"FIPS": {
"FIPS 180-4": 4,
"FIPS 186-5": 1,
"FIPS 197": 2,
"FIPS PUB 180-2": 1,
"FIPS PUB 180-4": 1
},
"ISO": {
"ISO/IEC 15408": 2,
"ISO/IEC 17065": 2,
"ISO/IEC 18045": 2
},
"PKCS": {
"PKCS#1": 2
},
"RFC": {
"RFC 4226": 1,
"RFC 4492": 2,
"RFC 5246": 2,
"RFC 5289": 2,
"RFC 5639": 2,
"RFC 8017": 2
},
"X509": {
"X.509": 1
}
},
"symmetric_crypto": {
"AES_competition": {
"AES": {
"AES": 2,
"AES-": 2
},
"HPC": {
"HPC": 2
}
}
},
"technical_report_id": {},
"tee_name": {},
"tls_cipher_suite": {},
"vendor": {},
"vulnerability": {}
},
"report_metadata": {
"/CreationDate": "D:20260901150245+02\u002700\u0027",
"/Creator": "Writer",
"/Keywords": "Common Criteria, Certification, Zertifizierung, EUCC",
"/Producer": "LibreOffice 5.3",
"/Subject": "CHERRY eHealth Terminal ST-1506, FW 5.0.0, HW 4.0.0; Common Criteria Protection Profile Electronic Health Card Terminal (eHCT), BSI-CC-PP-0032-V3-2023",
"/Title": "Certification Report EUCC-3087-2026-0015 ;BSI-DSZ-CC-1124-V4-2026",
"pdf_file_size_bytes": 410622,
"pdf_hyperlinks": {
"_type": "Set",
"elements": [
"https://www.iso.org/standard/72889.html",
"http://www.commoncriteriaportal.org/",
"https://www.iso.org/standard/72917.html",
"https://www.iso.org/standard/72891.html",
"https://certification.enisa.europa.eu/publications/eucc-state-art-documents_en",
"https://www.iso.org/standard/72892.html",
"https://www.bsi.bund.de/zertifizierungsreporte",
"https://www.bsi.bund.de/zertifizierung",
"https://www.iso.org/standard/72906.html",
"https://www.commoncriteriaportal.org/",
"https://www.iso.org/standard/72913.html",
"https://eur-lex.europa.eu/eli/reg_impl/2025/2462/oj",
"https://www.bsi.bund.de/AIS"
]
},
"pdf_is_encrypted": false,
"pdf_number_of_pages": 22
},
"st_filename": "1adf65b4-8329-426c-a919-054c639461f1_en",
"st_frontpage": null,
"st_keywords": {
"asymmetric_crypto": {
"ECC": {
"ECC": {
"ECC": 7
},
"ECDH": {
"ECDHE": 4
},
"ECDSA": {
"ECDSA": 6
}
}
},
"cc_cert_id": {
"NL": {
"NSCIB-CC-180212-CR2": 2,
"NSCIB-CC-180212-CR5": 2
}
},
"cc_claims": {
"A": {
"A.ADMIN": 3,
"A.CONNECTOR": 3,
"A.ENV": 7,
"A.PUSH_SERVER": 4,
"A.SM": 4
},
"O": {
"O.ACCESS_CONTROL": 9,
"O.MANAGEMENT": 7,
"O.PIN_ENTRY": 6,
"O.PROTECTION": 9,
"O.SECURE_CHANNEL": 4,
"O.STATE": 7
},
"OE": {
"OE.ADMIN": 4,
"OE.CONNECTOR": 6,
"OE.ENV": 11,
"OE.PUSH_SERVER": 4,
"OE.SM": 2
},
"OSP": {
"OSP.PIN_ENTRY": 5
},
"T": {
"T.COM": 3,
"T.DATA": 3,
"T.F-CONNECTOR": 4,
"T.PIN": 6
}
},
"cc_protection_profile_id": {
"BSI": {
"BSI-CC-PP-0032-V3-2023": 4,
"BSI-CC-PP-0098": 1,
"BSI-CC-PP-0098-2020": 1
}
},
"cc_sar": {
"ADV": {
"ADV_ARC.1": 1,
"ADV_FSP.4": 5,
"ADV_IMP.1": 6,
"ADV_TDS.3": 5
},
"AGD": {
"AGD_OPE.1": 1,
"AGD_PRE.1": 1
},
"ALC": {
"ALC_CMC.3": 1,
"ALC_CMS.3": 1,
"ALC_DEL.1": 1,
"ALC_DVS.1": 1,
"ALC_LCD.1": 1,
"ALC_TAT.1": 5
},
"ASE": {
"ASE_CCL.1": 1,
"ASE_ECD.1": 1,
"ASE_INT.1": 1,
"ASE_OBJ.2": 1,
"ASE_REQ.2": 1,
"ASE_SPD.1": 1,
"ASE_TSS": 3,
"ASE_TSS.1": 1
},
"ATE": {
"ATE_COV.2": 1,
"ATE_DPT.1": 1,
"ATE_FUN.1": 1,
"ATE_IND.2": 1
},
"AVA": {
"AVA_VAN.4": 5
}
},
"cc_security_level": {
"EAL": {
"EAL 3": 3,
"EAL 3 augmented": 2,
"EAL3": 1,
"EAL3 augmented": 1,
"EAL3+": 1,
"EAL6+": 1
}
},
"cc_sfr": {
"FCS": {
"FCS_CKM": 26,
"FCS_CKM.1": 16,
"FCS_CKM.2": 4,
"FCS_CKM.4": 2,
"FCS_CKM.5": 16,
"FCS_CKM.6": 35,
"FCS_CKM.6.1": 2,
"FCS_CKM.6.2": 1,
"FCS_COP": 58,
"FCS_COP.1": 12,
"FCS_RBG.1": 4,
"FCS_RNG": 1,
"FCS_RNG.1": 18,
"FCS_RNG.1.1": 1,
"FCS_RNG.1.2": 1
},
"FDP": {
"FDP_ACC": 27,
"FDP_ACC.1": 13,
"FDP_ACF": 26,
"FDP_ACF.1": 14,
"FDP_IFC": 21,
"FDP_IFC.1": 13,
"FDP_IFF": 22,
"FDP_IFF.1": 16,
"FDP_ITC.1": 15,
"FDP_ITC.2": 12,
"FDP_RIP.1": 9,
"FDP_RIP.1.1": 1
},
"FIA": {
"FIA_AFL.1": 8,
"FIA_AFL.1.1": 1,
"FIA_AFL.1.2": 2,
"FIA_ATD.1": 8,
"FIA_ATD.1.1": 1,
"FIA_SOS.1": 8,
"FIA_SOS.1.1": 1,
"FIA_UAU.1": 11,
"FIA_UAU.1.1": 1,
"FIA_UAU.1.2": 1,
"FIA_UAU.5": 8,
"FIA_UAU.5.1": 1,
"FIA_UAU.5.2": 1,
"FIA_UAU.7": 8,
"FIA_UAU.7.1": 1,
"FIA_UID.1": 13,
"FIA_UID.1.1": 1,
"FIA_UID.1.2": 1
},
"FMT": {
"FMT_MSA": 41,
"FMT_MSA.1": 8,
"FMT_MSA.2": 10,
"FMT_MSA.2.1": 1,
"FMT_MSA.3": 15,
"FMT_SMF.1": 15,
"FMT_SMF.1.1": 1,
"FMT_SMR.1": 24,
"FMT_SMR.1.1": 1,
"FMT_SMR.1.2": 1
},
"FPT": {
"FPT_FLS.1": 8,
"FPT_FLS.1.1": 1,
"FPT_ITT.1": 8,
"FPT_ITT.1.1": 1,
"FPT_PHP.1": 10,
"FPT_PHP.1.1": 1,
"FPT_PHP.1.2": 1,
"FPT_PHP.3": 11,
"FPT_PHP.3.1": 1,
"FPT_TST.1": 12,
"FPT_TST.1.1": 2,
"FPT_TST.1.2": 1,
"FPT_TST.1.3": 1
},
"FTA": {
"FTA_TAB": 7,
"FTA_TAB.1": 3,
"FTA_TAB.1.1": 1
},
"FTP": {
"FTP_ITC": 7,
"FTP_ITC.1": 4,
"FTP_TRP": 8,
"FTP_TRP.1": 3
}
},
"certification_process": {},
"cipher_mode": {
"GCM": {
"GCM": 1
}
},
"cplc_data": {},
"crypto_engine": {},
"crypto_library": {},
"crypto_protocol": {
"TLS": {
"TLS": {
"TLS": 27
}
},
"VPN": {
"VPN": 12
}
},
"crypto_scheme": {},
"device_model": {},
"ecc_curve": {
"Brainpool": {
"brainpoolP256r1": 5,
"brainpoolP384r1": 7
},
"NIST": {
"P-256": 4,
"P-384": 8
}
},
"eval_facility": {},
"hash_function": {
"SHA": {
"SHA2": {
"SHA-256": 1
}
}
},
"ic_data_group": {},
"javacard_api_const": {},
"javacard_packages": {},
"javacard_version": {},
"os_name": {
"JCOP": {
"JCOP 4": 2
}
},
"pq_crypto": {},
"randomness": {
"PRNG": {
"PRNG": 2
},
"RNG": {
"RNG": 5
}
},
"side_channel_analysis": {
"FI": {
"physical tampering": 7
}
},
"standard_id": {
"BSI": {
"AIS 20": 1,
"AIS 31": 1,
"AIS20": 5
},
"CC": {
"CCMB-2022-11-001": 3,
"CCMB-2022-11-002": 2,
"CCMB-2022-11-006": 1
},
"FIPS": {
"FIPS 197": 1
},
"ISO": {
"ISO/IEC 14443": 2
},
"PKCS": {
"PKCS#1": 1
},
"RFC": {
"RFC 5246": 2,
"RFC 5289": 1,
"RFC 8017": 1,
"RFC 8422": 1
},
"X509": {
"X.509": 5
}
},
"symmetric_crypto": {
"AES_competition": {
"AES": {
"AES": 5
},
"HPC": {
"HPC": 11
}
}
},
"technical_report_id": {
"BSI": {
"BSI TR-03111": 1
}
},
"tee_name": {},
"tls_cipher_suite": {
"TLS": {
"TLS_ECDHE_ECDSA_WITH_AES_128_GCM_SHA256": 4,
"TLS_ECDHE_ECDSA_WITH_AES_256_GCM_SHA384": 4,
"TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256": 4,
"TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384": 4
}
},
"vendor": {
"NXP": {
"NXP": 1
}
},
"vulnerability": {}
},
"st_metadata": {
"/Author": "[email protected]",
"/CreationDate": "D:20260811091435+02\u002700\u0027",
"/Creator": "Microsoft\u00ae Word f\u00fcr Microsoft 365",
"/MSIP_Label_38947aad-632d-4fb2-b863-0b57b309f586_ActionId": "9ed53ba9-c371-4cfe-aa76-810ce900ab52",
"/MSIP_Label_38947aad-632d-4fb2-b863-0b57b309f586_ContentBits": "0",
"/MSIP_Label_38947aad-632d-4fb2-b863-0b57b309f586_Enabled": "true",
"/MSIP_Label_38947aad-632d-4fb2-b863-0b57b309f586_Method": "Standard",
"/MSIP_Label_38947aad-632d-4fb2-b863-0b57b309f586_Name": "defa4170-0d19-0005-0004-bc88714345d2",
"/MSIP_Label_38947aad-632d-4fb2-b863-0b57b309f586_SetDate": "2026-07-24T14:31:14Z",
"/MSIP_Label_38947aad-632d-4fb2-b863-0b57b309f586_SiteId": "5e0e1b52-21b5-4e7b-83bb-514ec460677e",
"/MSIP_Label_38947aad-632d-4fb2-b863-0b57b309f586_Tag": "10, 3, 0, 1",
"/ModDate": "D:20260811091435+02\u002700\u0027",
"/Producer": "Microsoft\u00ae Word f\u00fcr Microsoft 365",
"/Subject": "CC-Evaluierung EAL3 augmented",
"pdf_file_size_bytes": 1186888,
"pdf_hyperlinks": {
"_type": "Set",
"elements": [
"http://www.cherry.de/"
]
},
"pdf_is_encrypted": false,
"pdf_number_of_pages": 85
}
},
"protection_profile_links": null,
"report_link": "https://certification.enisa.europa.eu/document/download/557b1874-d144-4b07-9811-c38f82c6529a_en?filename=EUCC-3087-2026-0015_Report.pdf",
"scheme": "DE",
"security_level": {
"_type": "Set",
"elements": [
"EAL3"
]
},
"st_link": "https://certification.enisa.europa.eu/document/download/1adf65b4-8329-426c-a919-054c639461f1_en?filename=EUCC-3087-2026-0015_Security_Target_6_5.pdf",
"state": {
"_type": "sec_certs.sample.cc_eucc_common.InternalState",
"cert": {
"_type": "sec_certs.sample.document_state.DocumentState",
"convert_ok": true,
"download_ok": false,
"extract_ok": true,
"json_hash": "625783a6b04a1f5583114dc8e241f6a6ef11627ebb906948dfc0afcb73a19434",
"source_hash": "1c495b4bf09239d7682cbb6a92167bccc05d533ad16b8fa6e0f2b322cead234d",
"txt_hash": "62c37efecd53485adae50dda2d69281367113ecad9dca75e4e20f030ad3935b8"
},
"report": {
"_type": "sec_certs.sample.document_state.DocumentState",
"convert_ok": true,
"download_ok": true,
"extract_ok": true,
"json_hash": "a330011b99851624e943f4c9f67acc0e7e026d9ab9b247e316bd58874617449b",
"source_hash": "ccb3c725f591e9e305e841d0aee30fbb8c5f1295804a5f784db6d34e1e23a41b",
"txt_hash": "8866048b8edf73184f8d72d323c1a597c3396a76a05f49a9aea4d91f72e7ae07"
},
"st": {
"_type": "sec_certs.sample.document_state.DocumentState",
"convert_ok": true,
"download_ok": true,
"extract_ok": true,
"json_hash": "0f9ace951415fc4dcedf2b53b0a63ea6c0bf778bde57c0526696c8058750660b",
"source_hash": "c596e08ec9500a1af27f6fff8de66903410990be81fd0e64c9a13cfbc0253b8b",
"txt_hash": "396d5ec7ff42bbe597721a0c1e2fa0a1698320d627c8ef92026955266ee7b61f"
}
},
"status": "active"
}