FIDO Universal Second Factor (U2F)

Web information ?

Status: active
Certification date: 2017-07-05
Scheme: 🇩🇪
Category: ICs, Smart Cards and Smart Card-Related Devices and Systems
Security level: AVA_VAN.5, EAL4+

Certification report ?

Extracted keywords

Schemes
MAC
Randomness
RNG

Security level
EAL 4, EAL 2, EAL4, EAL 4 augmented, ITSEC Evaluation
Security Assurance Requirements (SAR)
ALC_FLR, AVA_VAN.5, APE_INT.1, APE_CCL.1, APE_SPD.1, APE_OBJ.2, APE_ECD.1, APE_REQ.2
Protection profiles
BSI-CC-PP-0096-2017, BSI-CC-PP-0096

Certification process
2017, Evaluation Technical Report BSI-CC-PP-0096 Evaluation Assurance Level EAL4 Augmented, BSI (confidential document) [7] Protection Profile for the FIDO Universal Second Factor (U2F) Authenticator Version 1.0, 26

Standards
AIS 14, AIS 32, AIS 41, ISO/IEC 15408, ISO/IEC 18045, ISO/IEC 17065
Technical reports
BSI 7148

File metadata

Title Certification Report BSI-CC-PP-0096-2017
Subject FIDO Universal Second Faktor (U2F) Authenticator
Keywords "FIDO, Fast IDentity Online, Authenticator, Authentication Token, Common Criteria, Certification, Zertifizierung, Protection Profile, Schutzprofil"
Author Bundesamt für Sicherheit in der Informationstechnik
Creation date D:20170714101336+02'00'
Modification date D:20170714104242+02'00'
Pages 15
Creator Writer
Producer LibreOffice 5.2

Profile ?

Extracted keywords

Schemes
MAC
Protocols
TLS
Randomness
RNG

Vendor
NXP Semiconductors, Infineon Technologies AG, STMicroelectronics

Security level
EAL4, EAL4 augmented
Security Assurance Requirements (SAR)
ADV_ARC.1, ADV_FSP.4, ADV_TDS.3, ADV_IMP.1, AGD_OPE.1, AGD_PRE.1, ATE_DPT.1, ATE_DPT.2, AVA_VAN.5
Security Functional Requirements (SFR)
FCS_RNG, FCS_CKM.5, FCS_RNG.1, FCS_CKM.1, FCS_RNG.1.1, FCS_RNG.1.2, FCS_CKM, FCS_CKM.2, FCS_COP.1, FCS_CKM.4, FCS_CKM.5.1, FCS_COP, FDP_ITC.1, FDP_ITC.2, FDP_IFC, FDP_IFF.1, FDP_IFF, FDP_IFC.1.1, FDP_IFC.1, FDP_IFF.1.1, FDP_IFF.1.2, FDP_IFF.1.3, FDP_IFF.1.4, FDP_IFF.1.5, FDP_SDI.1, FDP_SDI.1.1, FDP_ACC.1, FIA_SOS.2, FIA_UAU.2, FIA_UAU.6, FIA_UAU.1, FIA_UID.1, FIA_UAU.2.1, FIA_UAU.6.1, FMT_MSA.3, FMT_MSA, FMT_SMF.1, FMT_SMF.1.1, FMT_SMR.1, FMT_SMR.1.1, FMT_SMR.1.2, FMT_MTD.1, FMT_MSA.1, FMT_MSA.3.2, FPR_ANO.1, FPR_ANO.1.1, FPT_EMS, FPT_EMS.1, FPT_EMS.1.1, FPT_EMS.1.2, FPT_PHP.3, FPT_PHP.3.1, FPT_TST.1, FPT_TST.1.1, FPT_TST.1.2, FPT_TST.1.3
Protection profiles
BSI-PP-CC-0096-2017, BSI-CC-PP-0096-2017, BSI-CC-PP-0084-2014

Side-channel analysis
physical probing, side channels, side channel, SPA, DPA, timing attacks, Physical tampering, physical tampering, fault injection, reverse engineering

Standards
CCMB-2012-09-001, CCMB-2012-09-002, CCMB-2012-09-003, CCMB-2012-09-004

File metadata

Title FIDO Universal Second Factor (U2F) Authenticator
Subject PP FIDO U2F
Keywords Common Criteria, Protection Profile, PP0096, FIDO, U2F, EAL4
Author Federal Agency for Information Security
Creation date D:20170713133046+02'00'
Modification date D:20170713182420+02'00'
Pages 40
Creator Writer
Producer LibreOffice 5.2

References ?

No references are available for this protection profile.

Updates ?

  • 04.02.2025 The protection profile was first processed.
    New Protection Profile

    A new Protection Profile with the name FIDO Universal Second Factor (U2F) was processed.

Raw data

{
  "_id": "1e9ad5146d475d4f",
  "_type": "sec_certs.sample.protection_profile.ProtectionProfile",
  "dgst": "1e9ad5146d475d4f",
  "heuristics": {
    "_type": "sec_certs.sample.protection_profile.ProtectionProfile.Heuristics"
  },
  "pdf_data": {
    "_type": "sec_certs.sample.protection_profile.ProtectionProfile.PdfData",
    "pp_filename": "pp0096b_pdf.pdf",
    "pp_keywords": {
      "asymmetric_crypto": {},
      "cc_cert_id": {},
      "cc_claims": {},
      "cc_protection_profile_id": {
        "BSI": {
          "BSI-CC-PP-0084-2014": 1,
          "BSI-CC-PP-0096-2017": 1,
          "BSI-PP-CC-0096-2017": 1
        }
      },
      "cc_sar": {
        "ADV": {
          "ADV_ARC.1": 2,
          "ADV_FSP.4": 2,
          "ADV_IMP.1": 2,
          "ADV_TDS.3": 2
        },
        "AGD": {
          "AGD_OPE.1": 2,
          "AGD_PRE.1": 2
        },
        "ATE": {
          "ATE_DPT.1": 1,
          "ATE_DPT.2": 1
        },
        "AVA": {
          "AVA_VAN.5": 5
        }
      },
      "cc_security_level": {
        "EAL": {
          "EAL4": 12,
          "EAL4 augmented": 3
        }
      },
      "cc_sfr": {
        "FCS": {
          "FCS_CKM": 9,
          "FCS_CKM.1": 10,
          "FCS_CKM.2": 3,
          "FCS_CKM.4": 8,
          "FCS_CKM.5": 6,
          "FCS_CKM.5.1": 1,
          "FCS_COP": 5,
          "FCS_COP.1": 8,
          "FCS_RNG": 14,
          "FCS_RNG.1": 5,
          "FCS_RNG.1.1": 2,
          "FCS_RNG.1.2": 2
        },
        "FDP": {
          "FDP_ACC.1": 4,
          "FDP_IFC": 20,
          "FDP_IFC.1": 9,
          "FDP_IFC.1.1": 4,
          "FDP_IFF": 21,
          "FDP_IFF.1": 5,
          "FDP_IFF.1.1": 4,
          "FDP_IFF.1.2": 4,
          "FDP_IFF.1.3": 5,
          "FDP_IFF.1.4": 5,
          "FDP_IFF.1.5": 4,
          "FDP_ITC.1": 3,
          "FDP_ITC.2": 3,
          "FDP_SDI.1": 3,
          "FDP_SDI.1.1": 1
        },
        "FIA": {
          "FIA_SOS.2": 1,
          "FIA_UAU.1": 1,
          "FIA_UAU.2": 8,
          "FIA_UAU.2.1": 1,
          "FIA_UAU.6": 8,
          "FIA_UAU.6.1": 1,
          "FIA_UID.1": 2
        },
        "FMT": {
          "FMT_MSA": 24,
          "FMT_MSA.1": 5,
          "FMT_MSA.3": 5,
          "FMT_MSA.3.2": 4,
          "FMT_MTD.1": 6,
          "FMT_SMF.1": 12,
          "FMT_SMF.1.1": 1,
          "FMT_SMR.1": 21,
          "FMT_SMR.1.1": 1,
          "FMT_SMR.1.2": 1
        },
        "FPR": {
          "FPR_ANO.1": 3,
          "FPR_ANO.1.1": 1
        },
        "FPT": {
          "FPT_EMS": 5,
          "FPT_EMS.1": 7,
          "FPT_EMS.1.1": 3,
          "FPT_EMS.1.2": 3,
          "FPT_PHP.3": 3,
          "FPT_PHP.3.1": 1,
          "FPT_TST.1": 5,
          "FPT_TST.1.1": 1,
          "FPT_TST.1.2": 1,
          "FPT_TST.1.3": 1
        }
      },
      "certification_process": {},
      "cipher_mode": {},
      "cplc_data": {},
      "crypto_engine": {},
      "crypto_library": {},
      "crypto_protocol": {
        "TLS": {
          "TLS": {
            "TLS": 2
          }
        }
      },
      "crypto_scheme": {
        "MAC": {
          "MAC": 17
        }
      },
      "device_model": {},
      "ecc_curve": {},
      "eval_facility": {},
      "hash_function": {},
      "ic_data_group": {},
      "javacard_api_const": {},
      "javacard_packages": {},
      "javacard_version": {},
      "os_name": {},
      "pq_crypto": {},
      "randomness": {
        "RNG": {
          "RNG": 13
        }
      },
      "side_channel_analysis": {
        "FI": {
          "Physical tampering": 1,
          "fault injection": 1,
          "physical tampering": 1
        },
        "SCA": {
          "DPA": 1,
          "SPA": 1,
          "physical probing": 1,
          "side channel": 4,
          "side channels": 1,
          "timing attacks": 1
        },
        "other": {
          "reverse engineering": 1
        }
      },
      "standard_id": {
        "CC": {
          "CCMB-2012-09-001": 2,
          "CCMB-2012-09-002": 2,
          "CCMB-2012-09-003": 2,
          "CCMB-2012-09-004": 1
        }
      },
      "symmetric_crypto": {},
      "technical_report_id": {},
      "tee_name": {},
      "tls_cipher_suite": {},
      "vendor": {
        "Infineon": {
          "Infineon Technologies AG": 1
        },
        "NXP": {
          "NXP Semiconductors": 1
        },
        "STMicroelectronics": {
          "STMicroelectronics": 1
        }
      },
      "vulnerability": {}
    },
    "pp_metadata": {
      "/Author": "Federal Agency for Information Security",
      "/CreationDate": "D:20170713133046+02\u002700\u0027",
      "/Creator": "Writer",
      "/Keywords": "Common Criteria, Protection Profile, PP0096, FIDO, U2F, EAL4",
      "/ModDate": "D:20170713182420+02\u002700\u0027",
      "/Producer": "LibreOffice 5.2",
      "/Subject": "PP FIDO U2F",
      "/Title": "FIDO Universal Second Factor (U2F) Authenticator",
      "pdf_file_size_bytes": 1336107,
      "pdf_hyperlinks": {
        "_type": "Set",
        "elements": []
      },
      "pdf_is_encrypted": false,
      "pdf_number_of_pages": 40
    },
    "report_filename": "pp0096a_pdf.pdf",
    "report_keywords": {
      "asymmetric_crypto": {},
      "cc_cert_id": {},
      "cc_claims": {},
      "cc_protection_profile_id": {
        "BSI": {
          "BSI-CC-PP-0096": 1,
          "BSI-CC-PP-0096-2017": 7
        }
      },
      "cc_sar": {
        "ALC": {
          "ALC_FLR": 1
        },
        "APE": {
          "APE_CCL.1": 1,
          "APE_ECD.1": 1,
          "APE_INT.1": 1,
          "APE_OBJ.2": 1,
          "APE_REQ.2": 1,
          "APE_SPD.1": 1
        },
        "AVA": {
          "AVA_VAN.5": 2
        }
      },
      "cc_security_level": {
        "EAL": {
          "EAL 2": 1,
          "EAL 4": 4,
          "EAL 4 augmented": 2,
          "EAL4": 1
        },
        "ITSEC": {
          "ITSEC Evaluation": 1
        }
      },
      "cc_sfr": {},
      "certification_process": {
        "ConfidentialDocument": {
          "2017, Evaluation Technical Report BSI-CC-PP-0096 Evaluation Assurance Level EAL4 Augmented, BSI (confidential document) [7] Protection Profile for the FIDO Universal Second Factor (U2F) Authenticator Version 1.0, 26": 1
        }
      },
      "cipher_mode": {},
      "cplc_data": {},
      "crypto_engine": {},
      "crypto_library": {},
      "crypto_protocol": {},
      "crypto_scheme": {
        "MAC": {
          "MAC": 1
        }
      },
      "device_model": {},
      "ecc_curve": {},
      "eval_facility": {},
      "hash_function": {},
      "ic_data_group": {},
      "javacard_api_const": {},
      "javacard_packages": {},
      "javacard_version": {},
      "os_name": {},
      "pq_crypto": {},
      "randomness": {
        "RNG": {
          "RNG": 1
        }
      },
      "side_channel_analysis": {},
      "standard_id": {
        "BSI": {
          "AIS 14": 1,
          "AIS 32": 1,
          "AIS 41": 1
        },
        "ISO": {
          "ISO/IEC 15408": 4,
          "ISO/IEC 17065": 2,
          "ISO/IEC 18045": 4
        }
      },
      "symmetric_crypto": {},
      "technical_report_id": {
        "BSI": {
          "BSI 7148": 1
        }
      },
      "tee_name": {},
      "tls_cipher_suite": {},
      "vendor": {},
      "vulnerability": {}
    },
    "report_metadata": {
      "/Author": "Bundesamt f\u00fcr Sicherheit in der Informationstechnik",
      "/CreationDate": "D:20170714101336+02\u002700\u0027",
      "/Creator": "Writer",
      "/Keywords": "\"FIDO, Fast IDentity Online, Authenticator, Authentication Token, Common Criteria, Certification, Zertifizierung, Protection Profile, Schutzprofil\"",
      "/ModDate": "D:20170714104242+02\u002700\u0027",
      "/Producer": "LibreOffice 5.2",
      "/Subject": "FIDO Universal Second Faktor (U2F) Authenticator",
      "/Title": "Certification Report BSI-CC-PP-0096-2017",
      "pdf_file_size_bytes": 436971,
      "pdf_hyperlinks": {
        "_type": "Set",
        "elements": [
          "http://www.commoncriteriaportal.org/",
          "http://www.sogisportal.eu/",
          "https://www.bsi.bund.de/"
        ]
      },
      "pdf_is_encrypted": false,
      "pdf_number_of_pages": 15
    }
  },
  "state": {
    "_type": "sec_certs.sample.protection_profile.ProtectionProfile.InternalState",
    "pp": {
      "_type": "sec_certs.sample.document_state.DocumentState",
      "convert_garbage": false,
      "convert_ok": true,
      "download_ok": true,
      "extract_ok": true,
      "pdf_hash": "cb7ca8beaf3e3860404cb41d8ea6c1b1258ff0723c447186fcd5054f9f60242e",
      "txt_hash": "a5fc5eec96b644d1bd882d2a312a0a1d91cf6bfaff25d376afb941d20dbeeecc"
    },
    "report": {
      "_type": "sec_certs.sample.document_state.DocumentState",
      "convert_garbage": false,
      "convert_ok": true,
      "download_ok": true,
      "extract_ok": true,
      "pdf_hash": "f47c22bcd7b2fd99b3f0e1def829c33f654b1cb005421adf54df829c70f6a946",
      "txt_hash": "30b012db77d8e67e693b816be96c859445f35d94a58f3036e90bb40128b899da"
    }
  },
  "web_data": {
    "_type": "sec_certs.sample.protection_profile.ProtectionProfile.WebData",
    "category": "ICs, Smart Cards and Smart Card-Related Devices and Systems",
    "is_collaborative": false,
    "maintenances": [],
    "name": "FIDO Universal Second Factor (U2F)",
    "not_valid_after": null,
    "not_valid_before": "2017-07-05",
    "pp_link": "https://www.commoncriteriaportal.org/nfs/ccpfiles/files/ppfiles/pp0096b_pdf.pdf",
    "report_link": "https://www.commoncriteriaportal.org/nfs/ccpfiles/files/ppfiles/pp0096a_pdf.pdf",
    "scheme": "DE",
    "security_level": {
      "_type": "Set",
      "elements": [
        "AVA_VAN.5",
        "EAL4+"
      ]
    },
    "status": "active",
    "version": "Version 1.0"
  }
}