Oberthur PIV EP v1 on ID-One Cosmo 64 v5 D

Certificate #668

Webpage information

Status historical
Historical reason RNG SP800-131A Revision 1 Transition
Validation dates 02.05.2006 , 27.07.2007 , 06.02.2014
Standard FIPS 140-2
Security level 2
Type Hardware
Embodiment Single Chip
Caveat None
Exceptions
  • Roles, Services, and Authentication: Level 3
  • Physical Security: Level 3
  • EMI/EMC: Level 3
  • Design Assurance: Level 3
Description The PIV EP v1 is a fully validated PIV-II « End Point » smart card to answer HSPD12. It offers Identity proofing (storage of personal data), User authentication, Card authentication, digital signature, encryption and secure post issuance management. To increase flexibility and customization capabilities, the card supports all PIV optional data containers from SP800-73-1, plus additional non-PIV containers and keys configurable during manufacturing. A built-in Card Single Sign-On application allows multiple on card applications to share the same Card Holder Verification Method (Global PIN).
Version (Hardware) HW P/N 77
Version (Firmware) FW Version E303-063684 with PIV Applet Suite v1 (PIV Applet v1.08 or v1.09 and SSO Applet v1.08
Vendor Oberthur Card Systems
References

This certificate's webpage directly references 0 certificates, transitively this expands into 0 certificates.

Security policy

Symmetric Algorithms
DES, TDES, KMAC
Asymmetric Algorithms
RSA1024, RSA-PSS
Hash functions
SHA-1
Schemes
MAC
Block cipher modes
ECB, CBC

JavaCard versions
Java Card 2.2, JC2.2, Global Platform 2.1.1
Vendor
Oberthur Card Systems, Oberthur, OBERTHUR

Security level
Level 2, Level 3
Side-channel analysis
SPA, DPA, Timing attacks, fault induction, Fault Induction, fault injection, reverse engineering, Bellcore attack
Certification process
More details about all the power-up self-tests and their implementation are provided in a separate confidential document. 7.3.2 Conditional Tests RSA Key generation: After generating an RSA key pair, the module performs, Integrity Mechanisms. The cryptographic key storage integrity mechanism is described in a separate confidential document called Self Test Description. 10.5.4 Destruction of Keys & PINs The Oberthur PIV EP destroys

File metadata

Title OCS PIV EP v1 Security Policy V1.01 _04-27-06_.doc
Author cgoyet
Creation date D:20060427143721-04'00'
Modification date D:20060427143721-04'00'
Pages 39
Creator PScript5.dll Version 5.2
Producer Acrobat Distiller 6.0 (Windows)

References

Outgoing
  • 548 - historical - ID-One Cosmo 64 v5

Heuristics

No heuristics are available for this certificate.

References

Loading...

Updates Feed

  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate was first processed.

Raw data

{
  "_type": "sec_certs.sample.fips.FIPSCertificate",
  "cert_id": 668,
  "dgst": "6f81082badfd0073",
  "heuristics": {
    "_type": "sec_certs.sample.fips.FIPSCertificate.Heuristics",
    "algorithms": {
      "_type": "Set",
      "elements": [
        "CVL#204",
        "RSA#43",
        "RNG#94",
        "Triple-DES#232",
        "SHS#209",
        "Triple-DES MAC#232"
      ]
    },
    "cpe_matches": null,
    "direct_transitive_cves": null,
    "extracted_versions": {
      "_type": "Set",
      "elements": [
        "1.09",
        "1.08"
      ]
    },
    "indirect_transitive_cves": null,
    "module_processed_references": {
      "_type": "sec_certs.sample.certificate.References",
      "directly_referenced_by": null,
      "directly_referencing": null,
      "indirectly_referenced_by": null,
      "indirectly_referencing": null
    },
    "module_prunned_references": {
      "_type": "Set",
      "elements": []
    },
    "policy_processed_references": {
      "_type": "sec_certs.sample.certificate.References",
      "directly_referenced_by": null,
      "directly_referencing": {
        "_type": "Set",
        "elements": [
          "548"
        ]
      },
      "indirectly_referenced_by": null,
      "indirectly_referencing": {
        "_type": "Set",
        "elements": [
          "123",
          "112",
          "246",
          "548"
        ]
      }
    },
    "policy_prunned_references": {
      "_type": "Set",
      "elements": [
        "548"
      ]
    },
    "related_cves": null,
    "verified_cpe_matches": null
  },
  "pdf_data": {
    "_type": "sec_certs.sample.fips.FIPSCertificate.PdfData",
    "keywords": {
      "asymmetric_crypto": {
        "RSA": {
          "RSA-PSS": 1,
          "RSA1024": 1
        }
      },
      "certification_process": {
        "ConfidentialDocument": {
          "Integrity Mechanisms. The cryptographic key storage integrity mechanism is described in a separate confidential document called Self Test Description. 10.5.4 Destruction of Keys \u0026 PINs The Oberthur PIV EP destroys": 1,
          "More details about all the power-up self-tests and their implementation are provided in a separate confidential document. 7.3.2 Conditional Tests RSA Key generation: After generating an RSA key pair, the module performs": 1
        }
      },
      "cipher_mode": {
        "CBC": {
          "CBC": 8
        },
        "ECB": {
          "ECB": 6
        }
      },
      "cplc_data": {},
      "crypto_engine": {},
      "crypto_library": {},
      "crypto_protocol": {},
      "crypto_scheme": {
        "MAC": {
          "MAC": 7
        }
      },
      "device_model": {},
      "ecc_curve": {},
      "eval_facility": {},
      "fips_cert_id": {
        "Cert": {
          "#1": 1,
          "Certificate 548": 1
        }
      },
      "fips_certlike": {
        "Certlike": {
          "PKCS #1": 1,
          "PKCS#1": 1,
          "RSA PKCS #1": 1,
          "RSA PKCS#1": 1,
          "RSA1024": 1,
          "SHA-1": 1
        }
      },
      "fips_security_level": {
        "Level": {
          "Level 2": 5,
          "Level 3": 2
        }
      },
      "hash_function": {
        "SHA": {
          "SHA1": {
            "SHA-1": 1
          }
        }
      },
      "ic_data_group": {},
      "javacard_api_const": {},
      "javacard_packages": {},
      "javacard_version": {
        "GlobalPlatform": {
          "Global Platform 2.1.1": 1
        },
        "JavaCard": {
          "JC2.2": 1,
          "Java Card 2.2": 1
        }
      },
      "os_name": {},
      "pq_crypto": {},
      "randomness": {},
      "side_channel_analysis": {
        "FI": {
          "Fault Induction": 1,
          "fault induction": 1,
          "fault injection": 1
        },
        "SCA": {
          "DPA": 7,
          "SPA": 8,
          "Timing attacks": 1
        },
        "other": {
          "Bellcore attack": 1,
          "reverse engineering": 1
        }
      },
      "standard_id": {
        "FIPS": {
          "FIPS 140": 5,
          "FIPS 140-2": 14,
          "FIPS 186-2": 1,
          "FIPS 201": 4,
          "FIPS PUB 186-2": 1,
          "FIPS140-2": 3,
          "FIPS186-2": 1
        },
        "ICAO": {
          "ICAO": 1
        },
        "ISO": {
          "ISO/IEC 14443": 14,
          "ISO/IEC 14443-2": 1,
          "ISO/IEC 14443-3": 1,
          "ISO/IEC 14443-4": 1,
          "ISO/IEC 7816": 6,
          "ISO/IEC 7816-2": 1,
          "ISO/IEC 7816-3": 6,
          "ISO/IEC 7816-4": 2,
          "ISO/IEC 7816-5": 2,
          "ISO/IEC 9796-2": 1,
          "ISO/IEC 9797-1": 1,
          "ISO/IEC14443": 2,
          "ISO/IEC7816": 2
        },
        "PKCS": {
          "PKCS #1": 1,
          "PKCS#1": 1
        },
        "SCP": {
          "SCP01": 1
        }
      },
      "symmetric_crypto": {
        "DES": {
          "3DES": {
            "TDES": 28
          },
          "DES": {
            "DES": 8
          }
        },
        "constructions": {
          "MAC": {
            "KMAC": 1
          }
        }
      },
      "tee_name": {},
      "tls_cipher_suite": {},
      "vendor": {
        "Oberthur": {
          "OBERTHUR": 2,
          "Oberthur": 51,
          "Oberthur Card Systems": 47
        }
      },
      "vulnerability": {}
    },
    "policy_metadata": {
      "/Author": "cgoyet",
      "/CreationDate": "D:20060427143721-04\u002700\u0027",
      "/Creator": "PScript5.dll Version 5.2",
      "/ModDate": "D:20060427143721-04\u002700\u0027",
      "/Producer": "Acrobat Distiller 6.0 (Windows)",
      "/Title": "OCS PIV EP v1 Security Policy V1.01 _04-27-06_.doc",
      "pdf_file_size_bytes": 277690,
      "pdf_hyperlinks": {
        "_type": "Set",
        "elements": []
      },
      "pdf_is_encrypted": false,
      "pdf_number_of_pages": 39
    }
  },
  "state": {
    "_type": "sec_certs.sample.fips.InternalState",
    "module": {
      "_type": "sec_certs.sample.document_state.DocumentState",
      "convert_ok": true,
      "download_ok": true,
      "extract_ok": true,
      "json_hash": null,
      "source_hash": null,
      "txt_hash": null
    },
    "policy": {
      "_type": "sec_certs.sample.document_state.DocumentState",
      "convert_ok": true,
      "download_ok": true,
      "extract_ok": true,
      "json_hash": null,
      "source_hash": "736bcc5b7aa10dda6780bbd520aa901a8acdeb7b009abdd89a79959caa962d3d",
      "txt_hash": "4bc9a12a2942a605398f149aa02a32777edb421e5d7b64c449d6ef61b43ec0cd"
    }
  },
  "web_data": {
    "_type": "sec_certs.sample.fips.FIPSCertificate.WebData",
    "caveat": "None",
    "certificate_pdf_url": "https://csrc.nist.gov/CSRC/media/projects/cryptographic-module-validation-program/documents/certificates/140crt668.pdf",
    "date_sunset": null,
    "description": "The PIV EP v1 is a fully validated PIV-II \u00ab End Point \u00bb smart card to answer HSPD12. It offers Identity proofing (storage of personal data), User authentication, Card authentication, digital signature, encryption and secure post issuance management. To increase flexibility and customization capabilities, the card supports all PIV optional data containers from SP800-73-1, plus additional non-PIV containers and keys configurable during manufacturing. A built-in Card Single Sign-On application allows multiple on card applications to share the same Card Holder Verification Method (Global PIN).",
    "embodiment": "Single Chip",
    "exceptions": [
      "Roles, Services, and Authentication: Level 3",
      "Physical Security: Level 3",
      "EMI/EMC: Level 3",
      "Design Assurance: Level 3"
    ],
    "fw_versions": "FW Version E303-063684 with PIV Applet Suite v1 (PIV Applet v1.08 or v1.09 and SSO Applet v1.08",
    "historical_reason": "RNG SP800-131A Revision 1 Transition",
    "hw_versions": "HW P/N 77",
    "level": 2,
    "mentioned_certs": {},
    "module_name": "Oberthur PIV EP v1 on ID-One Cosmo 64 v5 D",
    "module_type": "Hardware",
    "revoked_link": null,
    "revoked_reason": null,
    "standard": "FIPS 140-2",
    "status": "historical",
    "sw_versions": null,
    "tested_conf": null,
    "validation_history": [
      {
        "_type": "sec_certs.sample.fips.FIPSCertificate.ValidationHistoryEntry",
        "date": "2006-05-02",
        "lab": "UL Verification Services, Inc.",
        "validation_type": "Initial"
      },
      {
        "_type": "sec_certs.sample.fips.FIPSCertificate.ValidationHistoryEntry",
        "date": "2007-07-27",
        "lab": "",
        "validation_type": "Update"
      },
      {
        "_type": "sec_certs.sample.fips.FIPSCertificate.ValidationHistoryEntry",
        "date": "2014-02-06",
        "lab": "",
        "validation_type": "Update"
      }
    ],
    "vendor": "Oberthur Card Systems",
    "vendor_url": "http://www.oberthurusa.com"
  }
}