TCOS FlexCert Version 2.0 Release 2/SLC52

Webpage information

Certificate ID EUCC-3087-2026-0012
Product name TCOS FlexCert Version 2.0 Release 2/SLC52
Scheme 🇩🇪 DE
Assurance level high
Status active

Product Specification

Type Smartcards and similar devices
Description
The TOE is a smart card product according to the G2-COS specification from gematik and is implemented on the hardware platform Infineon Security Contr...
The TOE is a smart card product according to the G2-COS specification from gematik and is implemented on the hardware platform Infineon Security Controller IFX_CCI_000010h (SLC52GDA600A8 / SLC52GDA600A9) from Infineon Technologies AG. The TOE is intended to be used as a card operating system platform for cards of the card generation G2 in the framework of the German health care system.
Version Refer to Table 1 in the Certification Report
Package EAL4 augmented with ALC_DVS.2 , ATE_DPT.2 , AVA_VAN.5 , ALC_FLR.1

Certificate holder

Name Deutsche Telekom Security GmbH
Address Koblenzer Straße 87-93, 57072 Siegen
Contact information
Website https://www.telekom.com/en/company/data-privacy-and-security/hacking-and-testing

Certification body

Name BSI
NANDO ID 3087
Address Postfach 200363\n53133 Bonn, Bonn
Contact information [email protected] Phone: +49 228 99 9582-0

Standards & Compliance

CC Version CC:2022 Revision 1
CEM Version None
AVA_VAN level 5
Certification report reference None

Other

ITSEF SRC Security Research & Consulting GmbH
Responsible NCCA Bundesamt für Sicherheit in der Informationstechnik
Protection profile Common Criteria Protection Profile Card Operating System Generation 2 (PP COS G2), Version 2.1, 10 July 2019, BSI-CC-PP-0082-V4-2019, Bundesamt für Sicherheit in der Informationstechnik (BSI)
Certification date 03.07.2026
Archived date 03.07.2031

Certificate

Extracted keywords

Security level
EAL 2, EAL 4
Security Assurance Requirements (SAR)
ALC_FLR, ALC_DVS.2, ALC_FLR.1, ATE_DPT.2, AVA_VAN.5, AVA_VAN
Protection profiles
BSI-CC-PP-0082-V4-2019
Certificates
BSI-DSZ-CC-0904-V3-2026, EUCC-3087-2026-0012
Evaluation facilities
Deutsche Telekom Security, SRC Security Research & Consulting

Certification report

certification report could not be downloaded, no link is available.

Security target

Extracted keywords

Symmetric Algorithms
AES, AES128, AES-192, AES-256, DES, TDES, TDEA, CMAC, CBC-MAC
Asymmetric Algorithms
ECDH, ECDSA, ECC, DH, Diffie-Hellman
Hash functions
SHA-1, SHA-256, SHA-384, SHA-512, SHA512, SHA-2
Schemes
MAC, Key agreement, Key Agreement
Protocols
SSL, PACE
Randomness
TRNG, RND, RNG
Block cipher modes
ECB, CBC

Vendor
NXP Semiconductors, Infineon, Infineon Technologies AG, STMicroelectronics

Security level
EAL4, EAL5, EAL6, EAL 4, EAL4 augmented, EAL5 augmented, EAL6 augmented, EAL 4 augmented
Claims
O.RND, O.AES, O.PACE_CHIP, T.RND
Security Assurance Requirements (SAR)
ADV_IMP.2, ADV_INT.3, ADV_TDS.5, ADV_ARC.1, ADV_TDS.3, ADV_FUN.1, ADV_FSP.4, ADV_IMP.1, ADV_ARC, ADV_FSP, AGD_OPE.1, AGD_PRE.1, AGD_OPE, ALC_DVS.2, ALC_FLR.1, ALC_CMC.5, ALC_FLR.3, ALC_TAT.3, ALC_DEL, ALC_DVS, ALC_CMS, ALC_CMC.4, ALC_CMS.4, ALC_DEL.1, ALC_LCD.1, ALC_TAT.1, ATE_DPT.2, ATE_FUN.2, ATE_COV.3, ATE_DPT.1, ATE_COV, ATE_FUN, ATE_COV.2, ATE_FUN.1, AVA_VAN.5, AVA_VAN
Security Functional Requirements (SFR)
FAU_SAS, FAU_SAS.1, FAU_SAS.1.1, FCS_RNG, FCS_RNG.1, FCS_RNG.1.2, FCS_COP, FCS_CKM, FCS_CKM.6, FCS_CKM.4, FCS_RNG.1.1, FCS_CKM.1, FCS_COP.1, FCS_CKM.2, FCS_CKM.5, FCS_RBG.1, FCS_CKM.6.1, FCS_CKM.6.2, FDP_SDC, FDP_SDI, FDP_ITT, FDP_IFC, FDP_RIP.1, FDP_RIP, FDP_SDI.2, FDP_ACC, FDP_ACF, FDP_UCT, FDP_UIT, FDP_ITC.1, FDP_ITC.2, FDP_ACF.1, FDP_ACC.1, FDP_IFF.1, FDP_IFC.1, FDP_ITT.1, FDP_SDI.1, FDP_RIP.1.1, FDP_SDI.2.1, FDP_SDI.2.2, FDP_UCT.1, FDP_UIT.1, FDP_SDC.1, FIA_API, FIA_AFL, FIA_ATD.1, FIA_ATD, FIA_SOS.1, FIA_UAU.1, FIA_UAU, FIA_UAU.4, FIA_UAU.5, FIA_API.1, FIA_USB.1, FIA_USB, FIA_UID.1, FIA_UID, FIA_UAU.6, FIA_AFL.1, FIA_ATD.1.1, FIA_UAU.1.1, FIA_UAU.1.2, FIA_UAU.4.1, FIA_UAU.5.1, FIA_UAU.5.2, FIA_UAU.6.1, FIA_UID.1.1, FIA_UID.1.2, FIA_API.1.1, FIA_USB.1.1, FIA_USB.1.2, FIA_USB.1.3, FIA_SOS.1.1, FIA_SOS, FMT_LIM, FMT_SMR.1, FMT_MSA.3, FMT_MSA, FMT_SMF.1, FMT_SMR, FMT_MTD, FMT_SMF.1.1, FMT_SMR.1.1, FMT_SMR.1.2, FMT_MSA.1, FMT_MSA.3.1, FMT_MSA.3.2, FMT_MTD.1, FMT_LIM.2, FMT_LIM.1, FMT_SMF, FPT_ITE, FPT_EMS, FPT_ITE.1, FPT_ITE.2, FPT_ITE.1.1, FPT_ITE.1.2, FPT_ITE.2.1, FPT_ITE.2.2, FPT_FLS, FPT_PHP, FPT_ITT, FPT_FLS.1, FPT_EMS.1, FPT_TDC.1, FPT_TST.1, FPT_PHP.3, FPT_EMS.1.1, FPT_TDC.1.1, FPT_TDC.1.2, FPT_FLS.1.1, FPT_TST, FPT_ITT.1, FPT_TST.1.1, FPT_TST.1.2, FPT_TST.1.3, FPT_TST.2, FPT_TDC, FRU_FLT, FRU_FLT.2, FTP_ITC, FTP_TRP.1, FTP_ITC.1
Protection profiles
BSI-CC-PP-0082-V4-2019, BSI-CC-PP-0084-2014, BSI-CC-PP-0084-, BSI-CC-PP0082, BSI-CC-PP0084, BSI-CC-PP- 0035-2007, BSI-PP-0082, BSI-CC-PP- 0082-V4
Evaluation facilities
Deutsche Telekom Security

Side-channel analysis
Leak-Inherent, Physical Probing, physical probing, Physical probing, SPA, DPA, physical tampering, Malfunction, malfunction, DFA, Bleichenbacher attack

Heuristics

Automated inference - use with caution

All attributes shown in this section (e.g., links between certificates, products, vendors, and known CVEs) are generated by automated heuristics and have not been reviewed by humans. These methods can produce false positives or false negatives and should not be treated as definitive without independent verification. For details on our data sources and inference methods, see our methodology. If you believe any information here is inaccurate or harmful, please submit feedback.

Extracted SARs

ADV_ARC.1, ADV_FSP.4, ADV_FUN.1, ADV_IMP.2, ADV_INT.3, ADV_TDS.5, AGD_OPE.1, AGD_PRE.1, ALC_CMC.5, ALC_CMS.4, ALC_DEL.1, ALC_DVS.2, ALC_FLR.3, ALC_LCD.1, ALC_TAT.3, ATE_COV.3, ATE_DPT.2, ATE_FUN.2, AVA_VAN.5

Similar certificates

Name Certificate ID Actions
TCOS FlexCert Version 2.0 Release 2/SLC52 EUCC-3087-2026-0012 Compare

Scheme data

Cert Id EUCC-3087-2026-0012
Product TCOS FlexCert Version 2.0 Release 2/SLC52
Vendor Deutsche Telekom Security GmbH
Certification Date 03.07.2026
Category eHealth
Url https://www.bsi.bund.de/SharedDocs/Zertifikate_CC/CC/Gesundheitswesen_SmartCards/0904.html
Enhanced
Product TCOS FlexCert Version 2.0 Release 2/SLC52
Applicant Deutsche Telekom Security GmbH Neue Adresse: Koblenzer Straße 87-93 57072 Siegen Alte Adresse: Untere Industriestraße 20 57250 Netphen
Evaluation Facility SRC Security Research & Consulting GmbH
Assurance Level EAL4+,ALC_DVS.2,ATE_DPT.2,AVA_VAN.5,ALC_FLR.1
Protection Profile Card Operating System Generation 2 (PP COS G2), Version 2.1, 10 July 2019, BSI-CC-PP-0082-V4-2019
Certification Date 03.07.2026
Expiration Date 02.07.2031
Entries [frozendict({'id': 'EUCC-3087-2026-0012 / BSI-DSZ-CC-0904-V3-2026 (Ausstellungsdatum / Certification Date 03.07.2026, gültig bis / valid until 02.07.2031)', 'description': "The focus of this re-certification was on the transfer of the certification procedure to CC/CEM:2022 and to EUCC. Included is the update of the product life-cycle concerning the involved development and production sites, the underlying HW-certificate as well as the vulnerability analysis andvaluation of the TOE's (crypto) implementation. The certified product itself including its related guidance documentation did not change."}), frozendict({'id': 'BSI', 'description': 'The Partial ALC Re-Evaluation for BSI-DSZ-CC-0904-V2-2021 covers the update of the product life-cycle concerning the relocation of the involved development and production sites. The certified product itself did not change.'}), frozendict({'id': 'BSI-DSZ-CC-0904-V2-2021 (Ausstellungsdatum / Certification Date 24.06.2021, gültig bis / valid until 23.06.2026) Zertifizierungsreport / Certification Report Sicherheitsvorgaben / Security Target Zertifikat / Certificate Im Fokus der vorliegenden Re-Zertifizierung stand die Anpassung des Evaluierungsgegenstandes (EVG) an die aktuelle Version der G2.1 COS-Spezifikation der gematik und das zugehörige überarbeitete Schutzprofil PP-0082-V4. Dies war verbunden mit dem Wechsel des unterliegenden Halbleiters, Anpassungen im Lebenszyklusmodell, weiteren spezifischen Änderungen in der Embedded Software und einer entsprechenden Aktualisierung der zugehörigen Benutzerdokumentation. Insbesondere wurde die (Krypto-) Implementierung des EVG überarbeitet, re-evaluiert und neu bewertet.', 'description': 'Software'}), frozendict({'id': 'BSI', 'description': 'The maintenance procedure addresses the change of the production site.'}), frozendict({'id': 'BSI', 'description': 'Maintenance Report'}), frozendict({'id': 'BSI', 'description': 'Security Target'})]
Description The Target of Evaluation (TOE) is the product TCOS FlexCert 2.0 Release 1/SLE78CLX1440P developed by T-Systems International GmbH. The TOE is a smart card product according to the G2 Card Operating System specification from gematik. The TOE is intended to be used as a card operating system platform for different card types and applications of the card generation G2 in the framework of the German health care system. The TOE implements from the PP-0082-V2 the base part and the packages Crypto Box, Logical Channel and Contactless.
Subcategory Smartcards

Updates Feed

  • The certificate was first processed.

Raw data

{
  "_type": "sec_certs.sample.eucc.EUCCCertificate",
  "category": "SMARTCARDS AND SIMILAR DEVICES",
  "cert_id": "EUCC-3087-2026-0012",
  "cert_link": "https://certification.enisa.europa.eu/document/download/0e312e99-9cb1-4f06-9ae6-6ea8eb1e27d1_en?filename=EUCC-3087-2026-0012%20Certificate.pdf",
  "dgst": "d64e39fcf832abcb",
  "heuristics": {
    "_type": "sec_certs.sample.cc_eucc_common.Heuristics",
    "annotated_references": null,
    "cert_id": "EUCC-3087-2026-12",
    "cert_lab": null,
    "cpe_matches": null,
    "direct_transitive_cves": null,
    "eal": null,
    "extracted_sars": {
      "_type": "Set",
      "elements": [
        {
          "_type": "sec_certs.sample.sar.SAR",
          "family": "AGD_OPE",
          "level": 1
        },
        {
          "_type": "sec_certs.sample.sar.SAR",
          "family": "ADV_TDS",
          "level": 5
        },
        {
          "_type": "sec_certs.sample.sar.SAR",
          "family": "ALC_CMS",
          "level": 4
        },
        {
          "_type": "sec_certs.sample.sar.SAR",
          "family": "ADV_IMP",
          "level": 2
        },
        {
          "_type": "sec_certs.sample.sar.SAR",
          "family": "ATE_DPT",
          "level": 2
        },
        {
          "_type": "sec_certs.sample.sar.SAR",
          "family": "ADV_ARC",
          "level": 1
        },
        {
          "_type": "sec_certs.sample.sar.SAR",
          "family": "ALC_DVS",
          "level": 2
        },
        {
          "_type": "sec_certs.sample.sar.SAR",
          "family": "ALC_DEL",
          "level": 1
        },
        {
          "_type": "sec_certs.sample.sar.SAR",
          "family": "ADV_FUN",
          "level": 1
        },
        {
          "_type": "sec_certs.sample.sar.SAR",
          "family": "ALC_LCD",
          "level": 1
        },
        {
          "_type": "sec_certs.sample.sar.SAR",
          "family": "AVA_VAN",
          "level": 5
        },
        {
          "_type": "sec_certs.sample.sar.SAR",
          "family": "ADV_FSP",
          "level": 4
        },
        {
          "_type": "sec_certs.sample.sar.SAR",
          "family": "ATE_COV",
          "level": 3
        },
        {
          "_type": "sec_certs.sample.sar.SAR",
          "family": "ALC_CMC",
          "level": 5
        },
        {
          "_type": "sec_certs.sample.sar.SAR",
          "family": "ALC_FLR",
          "level": 3
        },
        {
          "_type": "sec_certs.sample.sar.SAR",
          "family": "ATE_FUN",
          "level": 2
        },
        {
          "_type": "sec_certs.sample.sar.SAR",
          "family": "ADV_INT",
          "level": 3
        },
        {
          "_type": "sec_certs.sample.sar.SAR",
          "family": "AGD_PRE",
          "level": 1
        },
        {
          "_type": "sec_certs.sample.sar.SAR",
          "family": "ALC_TAT",
          "level": 3
        }
      ]
    },
    "extracted_versions": {
      "_type": "Set",
      "elements": [
        "2.0"
      ]
    },
    "indirect_transitive_cves": null,
    "next_certificates": null,
    "prev_certificates": null,
    "protection_profiles": null,
    "related_cves": null,
    "report_references": {
      "_type": "sec_certs.sample.certificate.References",
      "directly_referenced_by": null,
      "directly_referencing": null,
      "indirectly_referenced_by": null,
      "indirectly_referencing": null
    },
    "scheme_data": {
      "category": "eHealth",
      "cert_id": "EUCC-3087-2026-0012",
      "certification_date": "2026-07-03",
      "enhanced": {
        "applicant": "Deutsche Telekom Security GmbH Neue Adresse: Koblenzer Stra\u00dfe 87-93 57072 Siegen Alte Adresse: Untere Industriestra\u00dfe 20 57250 Netphen",
        "assurance_level": "EAL4+,ALC_DVS.2,ATE_DPT.2,AVA_VAN.5,ALC_FLR.1",
        "certification_date": "2026-07-03",
        "description": "The Target of Evaluation (TOE) is the product TCOS FlexCert 2.0 Release 1/SLE78CLX1440P developed by T-Systems International GmbH. The TOE is a smart card product according to the G2 Card Operating System specification from gematik. The TOE is intended to be used as a card operating system platform for different card types and applications of the card generation G2 in the framework of the German health care system. The TOE implements from the PP-0082-V2 the base part and the packages Crypto Box, Logical Channel and Contactless.",
        "entries": [
          {
            "description": "The focus of this re-certification was on the transfer of the certification procedure to CC/CEM:2022 and to EUCC. Included is the update of the product life-cycle concerning the involved development and production sites, the underlying HW-certificate as well as the vulnerability analysis andvaluation of the TOE\u0027s (crypto) implementation. The certified product itself including its related guidance documentation did not change.",
            "id": "EUCC-3087-2026-0012 / BSI-DSZ-CC-0904-V3-2026 (Ausstellungsdatum / Certification Date 03.07.2026, g\u00fcltig bis / valid until 02.07.2031)"
          },
          {
            "description": "The Partial ALC Re-Evaluation for BSI-DSZ-CC-0904-V2-2021 covers the update of the product life-cycle concerning the relocation of the involved development and production sites. The certified product itself did not change.",
            "id": "BSI"
          },
          {
            "description": "Software",
            "id": "BSI-DSZ-CC-0904-V2-2021 (Ausstellungsdatum / Certification Date 24.06.2021, g\u00fcltig bis / valid until 23.06.2026) Zertifizierungsreport / Certification Report Sicherheitsvorgaben / Security Target Zertifikat / Certificate Im Fokus der vorliegenden Re-Zertifizierung stand die Anpassung des Evaluierungsgegenstandes (EVG) an die aktuelle Version der G2.1 COS-Spezifikation der gematik und das zugeh\u00f6rige \u00fcberarbeitete Schutzprofil PP-0082-V4. Dies war verbunden mit dem Wechsel des unterliegenden Halbleiters, Anpassungen im Lebenszyklusmodell, weiteren spezifischen \u00c4nderungen in der Embedded Software und einer entsprechenden Aktualisierung der zugeh\u00f6rigen Benutzerdokumentation. Insbesondere wurde die (Krypto-) Implementierung des EVG \u00fcberarbeitet, re-evaluiert und neu bewertet."
          },
          {
            "description": "The maintenance procedure addresses the change of the production site.",
            "id": "BSI"
          },
          {
            "description": "Maintenance Report",
            "id": "BSI"
          },
          {
            "description": "Security Target",
            "id": "BSI"
          }
        ],
        "evaluation_facility": "SRC Security Research \u0026 Consulting GmbH",
        "expiration_date": "2031-07-02",
        "product": "TCOS FlexCert Version 2.0 Release 2/SLC52",
        "protection_profile": "Card Operating System Generation 2 (PP COS G2), Version 2.1, 10 July 2019, BSI-CC-PP-0082-V4-2019"
      },
      "product": "TCOS FlexCert Version 2.0 Release 2/SLC52",
      "subcategory": "Smartcards",
      "url": "https://www.bsi.bund.de/SharedDocs/Zertifikate_CC/CC/Gesundheitswesen_SmartCards/0904.html",
      "vendor": "Deutsche Telekom Security GmbH"
    },
    "st_references": {
      "_type": "sec_certs.sample.certificate.References",
      "directly_referenced_by": null,
      "directly_referencing": null,
      "indirectly_referenced_by": null,
      "indirectly_referencing": null
    },
    "verified_cpe_matches": null
  },
  "manufacturer": "Deutsche Telekom Security GmbH",
  "manufacturer_web": "https://www.telekom.com/en/company/data-privacy-and-security/hacking-and-testing",
  "name": "TCOS FlexCert Version 2.0 Release 2/SLC52",
  "not_valid_after": "2031-07-03",
  "not_valid_before": "2026-07-03",
  "other_metadata": {
    "_type": "sec_certs.sample.eucc.EUCCCertificate.EnisaMetadata",
    "assurance_level": "High",
    "ava_van_level": "5",
    "cc_version": "CC:2022 Revision 1",
    "cem_version": null,
    "certificate_id": "EUCC-3087-2026-0012",
    "certificate_yearly_number": null,
    "certification_body": "BSI",
    "certification_body_address": "Postfach 200363\\n53133 Bonn, Bonn",
    "certification_body_contact": "[email protected] Phone: +49 228 99 9582-0",
    "holder_address": "Koblenzer Stra\u00dfe 87-93, 57072 Siegen",
    "holder_contact": null,
    "holder_name": "Deutsche Telekom Security GmbH",
    "holder_website": "https://www.telekom.com/en/company/data-privacy-and-security/hacking-and-testing",
    "issuance_date_full": "03/07/2026",
    "issuance_month": "7",
    "issuance_year": "2026",
    "itsef": "SRC Security Research \u0026 Consulting GmbH",
    "modification_or_reassurance": null,
    "nando_id": "3087",
    "package": {
      "EAL4": [
        "ALC_DVS.2",
        "ATE_DPT.2",
        "AVA_VAN.5",
        "ALC_FLR.1"
      ]
    },
    "product_description": "The TOE is a smart card product according to the G2-COS specification from gematik and is implemented on the hardware platform Infineon Security Controller IFX_CCI_000010h (SLC52GDA600A8 / SLC52GDA600A9) from Infineon Technologies AG. The TOE is intended to be used as a card operating system platform for cards of the card generation G2 in the framework of the German health care system.",
    "product_name": "TCOS FlexCert Version 2.0 Release 2/SLC52",
    "product_type": "Smartcards and similar devices",
    "product_version": "Refer to Table 1 in the Certification Report",
    "protection_profile": "Common Criteria Protection Profile Card Operating System Generation 2 (PP COS G2), Version 2.1, 10 July 2019, BSI-CC-PP-0082-V4-2019, Bundesamt f\u00fcr Sicherheit in der Informationstechnik (BSI)",
    "report_reference": null,
    "responsible_ncca": "Bundesamt f\u00fcr Sicherheit in der Informationstechnik",
    "scheme": "(UE) 2024/482 - EUCC",
    "validity_period_years": "5 years"
  },
  "pdf_data": {
    "_type": "sec_certs.sample.cc_eucc_common.PdfData",
    "cert_filename": "0e312e99-9cb1-4f06-9ae6-6ea8eb1e27d1_en",
    "cert_frontpage": null,
    "cert_keywords": {
      "asymmetric_crypto": {},
      "cc_cert_id": {
        "DE": {
          "BSI-DSZ-CC-0904-V3-2026": 1,
          "EUCC-3087-2026-0012": 1
        }
      },
      "cc_claims": {},
      "cc_protection_profile_id": {
        "BSI": {
          "BSI-CC-PP-0082-V4-2019": 1
        }
      },
      "cc_sar": {
        "ALC": {
          "ALC_DVS.2": 1,
          "ALC_FLR": 1,
          "ALC_FLR.1": 1
        },
        "ATE": {
          "ATE_DPT.2": 1
        },
        "AVA": {
          "AVA_VAN": 1,
          "AVA_VAN.5": 2
        }
      },
      "cc_security_level": {
        "EAL": {
          "EAL 2": 1,
          "EAL 4": 1
        }
      },
      "cc_sfr": {},
      "certification_process": {},
      "cipher_mode": {},
      "cplc_data": {},
      "crypto_engine": {},
      "crypto_library": {},
      "crypto_protocol": {},
      "crypto_scheme": {},
      "device_model": {},
      "ecc_curve": {},
      "eval_facility": {
        "DeutscheTelekom": {
          "Deutsche Telekom Security": 1
        },
        "SRC": {
          "SRC Security Research \u0026 Consulting": 1
        }
      },
      "hash_function": {},
      "ic_data_group": {},
      "javacard_api_const": {},
      "javacard_packages": {},
      "javacard_version": {},
      "os_name": {},
      "pq_crypto": {},
      "randomness": {},
      "side_channel_analysis": {},
      "standard_id": {
        "ISO": {
          "ISO/IEC 15408": 2,
          "ISO/IEC 18045": 2
        }
      },
      "symmetric_crypto": {},
      "technical_report_id": {},
      "tee_name": {},
      "tls_cipher_suite": {},
      "vendor": {},
      "vulnerability": {}
    },
    "cert_metadata": {
      "/CreationDate": "D:20260713051950+01\u002700\u0027",
      "/Creator": "KM_C300i",
      "/ModDate": "D:20260713051950+01\u002700\u0027",
      "/Producer": "KONICA MINOLTA bizhub C300i",
      "/Title": "KM_C300i26071305190",
      "pdf_file_size_bytes": 118556,
      "pdf_hyperlinks": {
        "_type": "Set",
        "elements": []
      },
      "pdf_is_encrypted": false,
      "pdf_number_of_pages": 2
    },
    "report_filename": null,
    "report_frontpage": null,
    "report_keywords": null,
    "report_metadata": null,
    "st_filename": "ac407808-1505-45cc-beb7-bc6a9b935aef_en",
    "st_frontpage": null,
    "st_keywords": {
      "asymmetric_crypto": {
        "ECC": {
          "ECC": {
            "ECC": 10
          },
          "ECDH": {
            "ECDH": 5
          },
          "ECDSA": {
            "ECDSA": 26
          }
        },
        "FF": {
          "DH": {
            "DH": 4,
            "Diffie-Hellman": 2
          }
        }
      },
      "cc_cert_id": {},
      "cc_claims": {
        "O": {
          "O.AES": 1,
          "O.PACE_CHIP": 9,
          "O.RND": 3
        },
        "T": {
          "T.RND": 4
        }
      },
      "cc_protection_profile_id": {
        "BSI": {
          "BSI-CC-PP- 0035-2007": 1,
          "BSI-CC-PP- 0082-V4": 1,
          "BSI-CC-PP-0082-V4-2019": 2,
          "BSI-CC-PP-0084-": 1,
          "BSI-CC-PP-0084-2014": 21,
          "BSI-CC-PP0082": 4,
          "BSI-CC-PP0084": 2,
          "BSI-PP-0082": 1
        }
      },
      "cc_sar": {
        "ADV": {
          "ADV_ARC": 1,
          "ADV_ARC.1": 4,
          "ADV_FSP": 1,
          "ADV_FSP.4": 2,
          "ADV_FUN.1": 1,
          "ADV_IMP.1": 2,
          "ADV_IMP.2": 2,
          "ADV_INT.3": 2,
          "ADV_TDS.3": 3,
          "ADV_TDS.5": 2
        },
        "AGD": {
          "AGD_OPE": 1,
          "AGD_OPE.1": 2,
          "AGD_PRE.1": 2
        },
        "ALC": {
          "ALC_CMC.4": 1,
          "ALC_CMC.5": 2,
          "ALC_CMS": 1,
          "ALC_CMS.4": 1,
          "ALC_DEL": 1,
          "ALC_DEL.1": 1,
          "ALC_DVS": 1,
          "ALC_DVS.2": 9,
          "ALC_FLR.1": 6,
          "ALC_FLR.3": 4,
          "ALC_LCD.1": 1,
          "ALC_TAT.1": 1,
          "ALC_TAT.3": 2
        },
        "ATE": {
          "ATE_COV": 1,
          "ATE_COV.2": 1,
          "ATE_COV.3": 2,
          "ATE_DPT.1": 1,
          "ATE_DPT.2": 7,
          "ATE_FUN": 1,
          "ATE_FUN.1": 1,
          "ATE_FUN.2": 2
        },
        "AVA": {
          "AVA_VAN": 1,
          "AVA_VAN.5": 10
        }
      },
      "cc_security_level": {
        "EAL": {
          "EAL 4": 1,
          "EAL 4 augmented": 1,
          "EAL4": 10,
          "EAL4 augmented": 2,
          "EAL5": 2,
          "EAL5 augmented": 2,
          "EAL6": 2,
          "EAL6 augmented": 2
        }
      },
      "cc_sfr": {
        "FAU": {
          "FAU_SAS": 10,
          "FAU_SAS.1": 7,
          "FAU_SAS.1.1": 1
        },
        "FCS": {
          "FCS_CKM": 61,
          "FCS_CKM.1": 29,
          "FCS_CKM.2": 4,
          "FCS_CKM.4": 26,
          "FCS_CKM.5": 6,
          "FCS_CKM.6": 42,
          "FCS_CKM.6.1": 3,
          "FCS_CKM.6.2": 2,
          "FCS_COP": 141,
          "FCS_COP.1": 20,
          "FCS_RBG.1": 4,
          "FCS_RNG": 32,
          "FCS_RNG.1": 31,
          "FCS_RNG.1.1": 3,
          "FCS_RNG.1.2": 2
        },
        "FDP": {
          "FDP_ACC": 64,
          "FDP_ACC.1": 39,
          "FDP_ACF": 76,
          "FDP_ACF.1": 38,
          "FDP_IFC": 5,
          "FDP_IFC.1": 10,
          "FDP_IFF.1": 1,
          "FDP_ITC.1": 19,
          "FDP_ITC.2": 17,
          "FDP_ITT": 5,
          "FDP_ITT.1": 3,
          "FDP_RIP": 6,
          "FDP_RIP.1": 9,
          "FDP_RIP.1.1": 1,
          "FDP_SDC": 9,
          "FDP_SDC.1": 1,
          "FDP_SDI": 8,
          "FDP_SDI.1": 2,
          "FDP_SDI.2": 6,
          "FDP_SDI.2.1": 1,
          "FDP_SDI.2.2": 1,
          "FDP_UCT": 6,
          "FDP_UCT.1": 1,
          "FDP_UIT": 6,
          "FDP_UIT.1": 2
        },
        "FIA": {
          "FIA_AFL": 19,
          "FIA_AFL.1": 4,
          "FIA_API": 9,
          "FIA_API.1": 13,
          "FIA_API.1.1": 1,
          "FIA_ATD": 6,
          "FIA_ATD.1": 12,
          "FIA_ATD.1.1": 1,
          "FIA_SOS": 1,
          "FIA_SOS.1": 6,
          "FIA_SOS.1.1": 1,
          "FIA_UAU": 38,
          "FIA_UAU.1": 12,
          "FIA_UAU.1.1": 1,
          "FIA_UAU.1.2": 1,
          "FIA_UAU.4": 12,
          "FIA_UAU.4.1": 1,
          "FIA_UAU.5": 15,
          "FIA_UAU.5.1": 1,
          "FIA_UAU.5.2": 1,
          "FIA_UAU.6": 9,
          "FIA_UAU.6.1": 1,
          "FIA_UID": 7,
          "FIA_UID.1": 14,
          "FIA_UID.1.1": 1,
          "FIA_UID.1.2": 1,
          "FIA_USB": 29,
          "FIA_USB.1": 29,
          "FIA_USB.1.1": 1,
          "FIA_USB.1.2": 1,
          "FIA_USB.1.3": 2
        },
        "FMT": {
          "FMT_LIM": 14,
          "FMT_LIM.1": 8,
          "FMT_LIM.2": 8,
          "FMT_MSA": 52,
          "FMT_MSA.1": 7,
          "FMT_MSA.3": 25,
          "FMT_MSA.3.1": 1,
          "FMT_MSA.3.2": 1,
          "FMT_MTD": 27,
          "FMT_MTD.1": 4,
          "FMT_SMF": 1,
          "FMT_SMF.1": 34,
          "FMT_SMF.1.1": 1,
          "FMT_SMR": 6,
          "FMT_SMR.1": 22,
          "FMT_SMR.1.1": 1,
          "FMT_SMR.1.2": 1
        },
        "FPT": {
          "FPT_EMS": 8,
          "FPT_EMS.1": 10,
          "FPT_EMS.1.1": 1,
          "FPT_FLS": 7,
          "FPT_FLS.1": 17,
          "FPT_FLS.1.1": 2,
          "FPT_ITE": 16,
          "FPT_ITE.1": 12,
          "FPT_ITE.1.1": 2,
          "FPT_ITE.1.2": 2,
          "FPT_ITE.2": 12,
          "FPT_ITE.2.1": 6,
          "FPT_ITE.2.2": 2,
          "FPT_ITT": 5,
          "FPT_ITT.1": 2,
          "FPT_PHP": 5,
          "FPT_PHP.3": 7,
          "FPT_TDC": 1,
          "FPT_TDC.1": 5,
          "FPT_TDC.1.1": 1,
          "FPT_TDC.1.2": 1,
          "FPT_TST": 3,
          "FPT_TST.1": 7,
          "FPT_TST.1.1": 1,
          "FPT_TST.1.2": 1,
          "FPT_TST.1.3": 1,
          "FPT_TST.2": 1
        },
        "FRU": {
          "FRU_FLT": 6,
          "FRU_FLT.2": 3
        },
        "FTP": {
          "FTP_ITC": 12,
          "FTP_ITC.1": 6,
          "FTP_TRP.1": 2
        }
      },
      "certification_process": {},
      "cipher_mode": {
        "CBC": {
          "CBC": 5
        },
        "ECB": {
          "ECB": 2
        }
      },
      "cplc_data": {},
      "crypto_engine": {},
      "crypto_library": {},
      "crypto_protocol": {
        "PACE": {
          "PACE": 99
        },
        "TLS": {
          "SSL": {
            "SSL": 1
          }
        }
      },
      "crypto_scheme": {
        "KA": {
          "Key Agreement": 1,
          "Key agreement": 1
        },
        "MAC": {
          "MAC": 27
        }
      },
      "device_model": {},
      "ecc_curve": {
        "Brainpool": {
          "brainpoolP256r1": 3,
          "brainpoolP384r1": 3,
          "brainpoolP512r1": 2
        },
        "NIST": {
          "NIST P-256": 1,
          "P-256": 3,
          "P-384": 2
        }
      },
      "eval_facility": {
        "DeutscheTelekom": {
          "Deutsche Telekom Security": 135
        }
      },
      "hash_function": {
        "SHA": {
          "SHA1": {
            "SHA-1": 5
          },
          "SHA2": {
            "SHA-2": 2,
            "SHA-256": 12,
            "SHA-384": 7,
            "SHA-512": 5,
            "SHA512": 1
          }
        }
      },
      "ic_data_group": {},
      "javacard_api_const": {},
      "javacard_packages": {},
      "javacard_version": {},
      "os_name": {},
      "pq_crypto": {},
      "randomness": {
        "RNG": {
          "RND": 7,
          "RNG": 46
        },
        "TRNG": {
          "TRNG": 1
        }
      },
      "side_channel_analysis": {
        "FI": {
          "DFA": 1,
          "Malfunction": 7,
          "malfunction": 6,
          "physical tampering": 1
        },
        "SCA": {
          "DPA": 1,
          "Leak-Inherent": 8,
          "Physical Probing": 2,
          "Physical probing": 1,
          "SPA": 1,
          "physical probing": 1
        },
        "other": {
          "Bleichenbacher attack": 1
        }
      },
      "standard_id": {
        "BSI": {
          "AIS 31": 1,
          "AIS 36": 1,
          "AIS31": 5,
          "AIS36": 4
        },
        "CC": {
          "CCMB-2022-11-006": 2
        },
        "FIPS": {
          "FIPS 180-4": 1,
          "FIPS 197": 4,
          "FIPS PUB 180-4": 1,
          "FIPS PUB 186-4": 1,
          "FIPS180": 2,
          "FIPS186": 5,
          "FIPS197": 8
        },
        "ICAO": {
          "ICAO": 2
        },
        "ISO": {
          "ISO/IEC 18033-3": 3,
          "ISO/IEC 9797-1": 2
        },
        "NIST": {
          "NIST SP 800-38B": 1,
          "SP 800-38A": 3
        },
        "PKCS": {
          "PKCS#3": 3,
          "PKCS1": 3
        },
        "RFC": {
          "RFC 3447": 1,
          "RFC 5639": 1,
          "RFC3447": 7,
          "RFC5639": 8
        }
      },
      "symmetric_crypto": {
        "AES_competition": {
          "AES": {
            "AES": 50,
            "AES-192": 1,
            "AES-256": 1,
            "AES128": 2
          }
        },
        "DES": {
          "3DES": {
            "TDEA": 1,
            "TDES": 1
          },
          "DES": {
            "DES": 2
          }
        },
        "constructions": {
          "MAC": {
            "CBC-MAC": 1,
            "CMAC": 36
          }
        }
      },
      "technical_report_id": {},
      "tee_name": {},
      "tls_cipher_suite": {},
      "vendor": {
        "Infineon": {
          "Infineon": 1,
          "Infineon Technologies AG": 2
        },
        "NXP": {
          "NXP Semiconductors": 1
        },
        "STMicroelectronics": {
          "STMicroelectronics": 1
        }
      },
      "vulnerability": {}
    },
    "st_metadata": {
      "/Author": "Deutsche Telekom Security GmbH",
      "/CreationDate": "D:20260611093646+02\u002700\u0027",
      "/Creator": "Microsoft\u00ae Word f\u00fcr Microsoft 365",
      "/Keywords": "\"TCOS FlexCert, Generation 2\", Gesundheitskarte, electronic health card, TCOS",
      "/ModDate": "D:20260611093646+02\u002700\u0027",
      "/Producer": "Microsoft\u00ae Word f\u00fcr Microsoft 365",
      "/Subject": "TCOS FlexCert Version 2.0 Release 2",
      "/Title": "Security Target TCOS FlexCert Version 2.0 Release 2",
      "pdf_file_size_bytes": 3188796,
      "pdf_hyperlinks": {
        "_type": "Set",
        "elements": [
          "http://www.phy.duke.edu/~rgb/General/dieharder/dieharder-3.31.0.tgz",
          "http://csrc.nist.gov/groups/ST/toolkit/rng/documents/sts-2.1.1.zip"
        ]
      },
      "pdf_is_encrypted": false,
      "pdf_number_of_pages": 129
    }
  },
  "protection_profile_links": null,
  "report_link": null,
  "scheme": "DE",
  "security_level": {
    "_type": "Set",
    "elements": []
  },
  "st_link": "https://certification.enisa.europa.eu/document/download/ac407808-1505-45cc-beb7-bc6a9b935aef_en?filename=EUCC-3087-2026-0012%20Security%20Target.pdf",
  "state": {
    "_type": "sec_certs.sample.cc_eucc_common.InternalState",
    "cert": {
      "_type": "sec_certs.sample.document_state.DocumentState",
      "convert_ok": true,
      "download_ok": true,
      "extract_ok": true,
      "json_hash": null,
      "source_hash": "eecaa07d6eec3ed2678127c6722345e04c861a6eb9e9589500dc82e801334fe3",
      "txt_hash": "4ebdf238828d5f770f746bf4612d6c52f29764c92e996a32396336bd93b29394"
    },
    "report": {
      "_type": "sec_certs.sample.document_state.DocumentState",
      "convert_ok": false,
      "download_ok": false,
      "extract_ok": false,
      "json_hash": null,
      "source_hash": null,
      "txt_hash": null
    },
    "st": {
      "_type": "sec_certs.sample.document_state.DocumentState",
      "convert_ok": true,
      "download_ok": true,
      "extract_ok": true,
      "json_hash": null,
      "source_hash": "405d50c87b9f0e6c752b0dcbc2ae462259b51ed46fea923dea20f5923661367c",
      "txt_hash": "9c0995033cd2a7062c96ce52a0a752995754e4e2c53c57ff4bbe05523aeb769d"
    }
  },
  "status": "active"
}