Schutzprofile fur die elektronische Gesundheitskarte (eGK), Version 2.0

Web information

Status archived
Valid from 15.02.2007
Valid until 15.11.2012
Scheme 🇩🇪 DE
Category ICs, Smart Cards and Smart Card-Related Devices and Systems
Security level EAL4+

Certification report

Extracted keywords

Symmetric Algorithms
HPC, DES
Schemes
MAC

Security level
EAL 4, EAL4, EAL 4 augmented
Security Assurance Requirements (SAR)
ADV_IMP.2, AVA_MSU.3, AVA_VLA.4, APE_DES.1, APE_ENV.1, APE_INT.1, APE_OBJ.1, APE_REQ.1, APE_SRE.1
Security Functional Requirements (SFR)
FCS_CKM, FCS_CKM.4, FCS_COP, FCS_RND.1, FDP_ACC.2, FDP_ACF.1, FDP_RIP.1, FDP_SDI.2, FDP_UCT.1, FDP_UIT.1, FIA_AFL, FIA_ATD.1, FIA_UID.1, FIA_UAU.1, FIA_UAU.4, FMT_SMF.1, FMT_SMR.1, FMT_MTD, FMT_LIM.1, FMT_LIM.2, FPT_FLS.1, FPT_PHP.3, FPT_TST.1, FPT_RVM.1, FPT_SEP.1, FTP_ITC.1
Protection profiles
BSI-PP-0020-V2-2007, BSI-PP-0005-2002T, BSI-PP-0006-2002T

Side-channel analysis
Physical Tampering
Certification process
Health Card (eHC) – elektronische Gesundheitskarte (eGK), BSI-PP-0020-V2-2007, T-Systems GEI GmbH (confidential document) [7] Common Criteria Protection Profile electronic Health Card (eHC) – elektronische

Standards
ISO/IEC 15408, X.509
Technical reports
BSI 7125, BSI 7148, BSI 7149

File metadata

Title PP Certification Report BSI-PP-0020-V2-2007
Subject PP Certification Report BSI-PP-0020-V2-2007
Keywords "BSI-PP-0020-V2-2007, eGK, eHC, Gesundheitskarte, Healthcard"
Author BSI
Creation date D:20070227113015+01'00'
Modification date D:20070305151201+01'00'
Pages 21
Creator Acrobat PDFMaker 7.0.7 für Word
Producer Acrobat Distiller 7.0.5 (Windows)

Protection Profile

Extracted keywords

Symmetric Algorithms
HPC, DES, Triple-DES, TDES
Hash functions
SHA-1, SHA-224
Schemes
MAC
Protocols
SSL
Block cipher modes
CBC

Security level
EAL4, EAL4 augmented
Security Assurance Requirements (SAR)
ADO_DEL, ADO_IGS, ADO_IGS.1, ADV_IMP.2, ADV_SPM.1, ADV_LLD.1, ADV_RCR.1, ADV_FSP.1, ADV_HLD.2, ADV_IMP.1, AGD_ADM.1, AGD_USR.1, ALC_TAT.1, AVA_MSU.3, AVA_VLA.4, ASE_PPC.1
Security Functional Requirements (SFR)
FCS_RND, FCS_CKM.1, FCS_CKM, FCS_CKM.2, FCS_COP.1, FCS_CKM.4, FCS_RND.1, FCS_CKM.4.1, FCS_COP, FCS_RND.1.1, FDP_ITC.1, FDP_ITC.2, FDP_ACC.2, FDP_ACF.1, FDP_UCT.1, FDP_ACC.1, FDP_ACC.2.1, FDP_ACF.1.1, FDP_ACF.1.2, FDP_ACF.1.3, FDP_ACF.1.4, FDP_RIP.1, FDP_RIP.1.1, FDP_SDI.2, FDP_SDI.1, FDP_SDI.2.1, FDP_SDI.2.2, FDP_UIT.1, FDP_UCT.1.1, FDP_IFC.1, FDP_UIT.1.1, FDP_UIT.1.2, FDP_ACF, FDP_ACC, FDP_UCT, FDP_UIT, FIA_UAU.4, FIA_AFL.1, FIA_AFL, FIA_UAU.1, FIA_ATD.1, FIA_ATD.1.1, FIA_UID.1, FIA_UID.1.1, FIA_UID.1.2, FIA_UAU.1.1, FIA_UAU.1.2, FIA_UAU.4.1, FMT_LIM, FMT_MSA.2, FMT_MTD.1, FMT_MSA.3, FMT_SMF.1, FMT_SMR.1, FMT_SMF.1.1, FMT_SMR.1.1, FMT_SMR.1.2, FMT_LIM.1, FMT_LIM.2, FMT_LIM.1.1, FMT_LIM.2.1, FMT_MTD, FMT_MSA.1, FPT_FLS.1, FPT_TST.1, FPT_PHP.3, FPT_RVM.1, FPT_SEP.1, FPT_FLS.1.1, FPT_PHP.3.1, FPT_TST.1.1, FPT_TST.1.2, FPT_TST.1.3, FPT_AMT.1, FPT_RVM.1.1, FPT_SEP.1.1, FPT_SEP.1.2, FTP_ITC.1, FTP_TRP.1, FTP_ITC.1.1, FTP_ITC.1.2, FTP_ITC.1.3
Protection profiles
BSI-PP-0020-V2-2007, BSI-PP-0002, BSI-PP-0005-2002, BSI-PP-0006-2002, BSI-PP- 0005-2002, BSI-PP-****, BSI-PP-0005-2002T, BSI-PP-0006-2002T, BSI-PP-0002-2001
Evaluation facilities
SRC Security Research & Consulting

Side-channel analysis
physical probing, side channels, DPA, Physical Tampering, physical tampering, Physical tampering, Malfunction, malfunction, fault injection, reverse engineering, Bleichenbacher attack
Certification process
out of scope, FDP_ACF.1 101 Application note 29: Keys and other data for creation of qualified signatures are out of scope of this protection profile. 102 The TOE shall meet the requirement “Security attribute based access

Standards
FIPS 180-2, FIPS 46-3, FIPS PUB 46-3, PKCS #1, PKCS#1, ISO/IEC9796-2, ISO/IEC 7816-2, ISO/IEC 7816-4, X.509, x.509, CCIMB-2005-08-001, CCIMB-2005-08-002, CCIMB-2005-08-003, CCIMB-2005-08-004

File metadata

Title Common Criteria Protection Profile electronic Health Card (eHC)
Keywords BSI-PP-0020-V2-2007, electronic Health Card
Author Bundesamt für Sicherheit in der Informationstechnik
Creation date D:20070301134559+01'00'
Modification date D:20070305151311+01'00'
Pages 83
Creator Acrobat PDFMaker 7.0.7 für Word
Producer Acrobat Distiller 7.0.5 (Windows)

References

No references are available for this protection profile.

Updates Feed

  • The protection profile data changed.
  • The protection profile data changed.
  • The protection profile data changed.
  • The protection profile data changed.
  • The protection profile data changed.
  • The protection profile data changed.
  • The protection profile data changed.
  • The protection profile data changed.
  • The protection profile data changed.
  • The protection profile data changed.
  • The protection profile data changed.
  • The protection profile data changed.
  • The protection profile data changed.
  • The protection profile data changed.
  • The protection profile data changed.
  • The protection profile data changed.
  • The protection profile data changed.
  • The protection profile data changed.
  • The protection profile data changed.
  • The protection profile data changed.
  • The protection profile data changed.
  • The protection profile data changed.
  • The protection profile data changed.
  • The protection profile data changed.
  • The protection profile data changed.
  • The protection profile data changed.
  • The protection profile data changed.
  • The protection profile data changed.
  • The protection profile data changed.
  • The protection profile data changed.
  • The protection profile data changed.
  • The protection profile data changed.
  • The protection profile data changed.
  • The protection profile data changed.
  • The protection profile data changed.
  • The protection profile data changed.
  • The protection profile data changed.
  • The protection profile data changed.
  • The protection profile data changed.
  • The protection profile data changed.
  • The protection profile data changed.
  • The protection profile data changed.
  • The protection profile data changed.
  • The protection profile data changed.
  • The protection profile data changed.
  • The protection profile data changed.
  • The protection profile data changed.
  • The protection profile data changed.
  • The protection profile data changed.
  • The protection profile data changed.
  • The protection profile data changed.
  • The protection profile data changed.
  • The protection profile data changed.
  • The protection profile data changed.
  • The protection profile data changed.
  • The protection profile data changed.
  • The protection profile data changed.
  • The protection profile data changed.
  • The protection profile data changed.
  • The protection profile was first processed.

Raw data

{
  "_id": "bb2ba741adffde7d",
  "_type": "sec_certs.sample.protection_profile.ProtectionProfile",
  "dgst": "bb2ba741adffde7d",
  "heuristics": {
    "_type": "sec_certs.sample.protection_profile.ProtectionProfile.Heuristics"
  },
  "pdf_data": {
    "_type": "sec_certs.sample.protection_profile.ProtectionProfile.PdfData",
    "pp_filename": "PP0020_V2b.pdf",
    "pp_keywords": {
      "asymmetric_crypto": {},
      "cc_cert_id": {},
      "cc_claims": {},
      "cc_protection_profile_id": {
        "BSI": {
          "BSI-PP- 0005-2002": 1,
          "BSI-PP-****": 1,
          "BSI-PP-0002": 2,
          "BSI-PP-0002-2001": 1,
          "BSI-PP-0005-2002": 2,
          "BSI-PP-0005-2002T": 1,
          "BSI-PP-0006-2002": 3,
          "BSI-PP-0006-2002T": 1,
          "BSI-PP-0020-V2-2007": 2
        }
      },
      "cc_sar": {
        "ADO": {
          "ADO_DEL": 1,
          "ADO_IGS": 2,
          "ADO_IGS.1": 1
        },
        "ADV": {
          "ADV_FSP.1": 2,
          "ADV_HLD.2": 1,
          "ADV_IMP.1": 1,
          "ADV_IMP.2": 6,
          "ADV_LLD.1": 2,
          "ADV_RCR.1": 1,
          "ADV_SPM.1": 2
        },
        "AGD": {
          "AGD_ADM.1": 2,
          "AGD_USR.1": 2
        },
        "ALC": {
          "ALC_TAT.1": 1
        },
        "ASE": {
          "ASE_PPC.1": 4
        },
        "AVA": {
          "AVA_MSU.3": 5,
          "AVA_VLA.4": 5
        }
      },
      "cc_security_level": {
        "EAL": {
          "EAL4": 12,
          "EAL4 augmented": 2
        }
      },
      "cc_sfr": {
        "FCS": {
          "FCS_CKM": 7,
          "FCS_CKM.1": 21,
          "FCS_CKM.2": 2,
          "FCS_CKM.4": 26,
          "FCS_CKM.4.1": 1,
          "FCS_COP": 44,
          "FCS_COP.1": 13,
          "FCS_RND": 6,
          "FCS_RND.1": 13,
          "FCS_RND.1.1": 2
        },
        "FDP": {
          "FDP_ACC": 1,
          "FDP_ACC.1": 7,
          "FDP_ACC.2": 12,
          "FDP_ACC.2.1": 2,
          "FDP_ACF": 2,
          "FDP_ACF.1": 13,
          "FDP_ACF.1.1": 1,
          "FDP_ACF.1.2": 1,
          "FDP_ACF.1.3": 1,
          "FDP_ACF.1.4": 1,
          "FDP_IFC.1": 4,
          "FDP_ITC.1": 16,
          "FDP_ITC.2": 16,
          "FDP_RIP.1": 7,
          "FDP_RIP.1.1": 1,
          "FDP_SDI.1": 2,
          "FDP_SDI.2": 5,
          "FDP_SDI.2.1": 1,
          "FDP_SDI.2.2": 1,
          "FDP_UCT": 1,
          "FDP_UCT.1": 11,
          "FDP_UCT.1.1": 1,
          "FDP_UIT": 1,
          "FDP_UIT.1": 6,
          "FDP_UIT.1.1": 1,
          "FDP_UIT.1.2": 1
        },
        "FIA": {
          "FIA_AFL": 12,
          "FIA_AFL.1": 5,
          "FIA_ATD.1": 7,
          "FIA_ATD.1.1": 1,
          "FIA_UAU.1": 10,
          "FIA_UAU.1.1": 1,
          "FIA_UAU.1.2": 1,
          "FIA_UAU.4": 8,
          "FIA_UAU.4.1": 1,
          "FIA_UID.1": 8,
          "FIA_UID.1.1": 1,
          "FIA_UID.1.2": 1
        },
        "FMT": {
          "FMT_LIM": 6,
          "FMT_LIM.1": 20,
          "FMT_LIM.1.1": 2,
          "FMT_LIM.2": 19,
          "FMT_LIM.2.1": 1,
          "FMT_MSA.1": 1,
          "FMT_MSA.2": 19,
          "FMT_MSA.3": 2,
          "FMT_MTD": 27,
          "FMT_MTD.1": 9,
          "FMT_SMF.1": 19,
          "FMT_SMF.1.1": 1,
          "FMT_SMR.1": 19,
          "FMT_SMR.1.1": 1,
          "FMT_SMR.1.2": 1
        },
        "FPT": {
          "FPT_AMT.1": 5,
          "FPT_FLS.1": 11,
          "FPT_FLS.1.1": 1,
          "FPT_PHP.3": 10,
          "FPT_PHP.3.1": 1,
          "FPT_RVM.1": 10,
          "FPT_RVM.1.1": 1,
          "FPT_SEP.1": 10,
          "FPT_SEP.1.1": 1,
          "FPT_SEP.1.2": 1,
          "FPT_TST.1": 11,
          "FPT_TST.1.1": 1,
          "FPT_TST.1.2": 1,
          "FPT_TST.1.3": 2
        },
        "FTP": {
          "FTP_ITC.1": 14,
          "FTP_ITC.1.1": 1,
          "FTP_ITC.1.2": 1,
          "FTP_ITC.1.3": 1,
          "FTP_TRP.1": 4
        }
      },
      "certification_process": {
        "OutOfScope": {
          "FDP_ACF.1 101 Application note 29: Keys and other data for creation of qualified signatures are out of scope of this protection profile. 102 The TOE shall meet the requirement \u201cSecurity attribute based access": 1,
          "out of scope": 1
        }
      },
      "cipher_mode": {
        "CBC": {
          "CBC": 1
        }
      },
      "cplc_data": {},
      "crypto_engine": {},
      "crypto_library": {},
      "crypto_protocol": {
        "TLS": {
          "SSL": {
            "SSL": 1
          }
        }
      },
      "crypto_scheme": {
        "MAC": {
          "MAC": 17
        }
      },
      "device_model": {},
      "ecc_curve": {},
      "eval_facility": {
        "SRC": {
          "SRC Security Research \u0026 Consulting": 1
        }
      },
      "hash_function": {
        "SHA": {
          "SHA1": {
            "SHA-1": 6
          },
          "SHA2": {
            "SHA-224": 1
          }
        }
      },
      "ic_data_group": {},
      "javacard_api_const": {},
      "javacard_packages": {},
      "javacard_version": {},
      "os_name": {},
      "pq_crypto": {},
      "randomness": {},
      "side_channel_analysis": {
        "FI": {
          "Malfunction": 3,
          "Physical Tampering": 2,
          "Physical tampering": 1,
          "fault injection": 1,
          "malfunction": 4,
          "physical tampering": 4
        },
        "SCA": {
          "DPA": 1,
          "physical probing": 4,
          "side channels": 2
        },
        "other": {
          "Bleichenbacher attack": 1,
          "reverse engineering": 1
        }
      },
      "standard_id": {
        "CC": {
          "CCIMB-2005-08-001": 2,
          "CCIMB-2005-08-002": 2,
          "CCIMB-2005-08-003": 2,
          "CCIMB-2005-08-004": 1
        },
        "FIPS": {
          "FIPS 180-2": 1,
          "FIPS 46-3": 1,
          "FIPS PUB 46-3": 1
        },
        "ISO": {
          "ISO/IEC 7816-2": 1,
          "ISO/IEC 7816-4": 1,
          "ISO/IEC9796-2": 2
        },
        "PKCS": {
          "PKCS #1": 1,
          "PKCS#1": 2
        },
        "X509": {
          "X.509": 7,
          "x.509": 2
        }
      },
      "symmetric_crypto": {
        "AES_competition": {
          "HPC": {
            "HPC": 31
          }
        },
        "DES": {
          "3DES": {
            "TDES": 4,
            "Triple-DES": 9
          },
          "DES": {
            "DES": 1
          }
        }
      },
      "technical_report_id": {},
      "tee_name": {},
      "tls_cipher_suite": {},
      "vendor": {},
      "vulnerability": {}
    },
    "pp_metadata": {
      "/Author": "Bundesamt f\u00fcr Sicherheit in der Informationstechnik",
      "/Company": "SRC Security Research and Consulting GmbH",
      "/CreationDate": "D:20070301134559+01\u002700\u0027",
      "/Creator": "Acrobat PDFMaker 7.0.7 f\u00fcr Word",
      "/Keywords": "BSI-PP-0020-V2-2007, electronic Health Card",
      "/ModDate": "D:20070305151311+01\u002700\u0027",
      "/Producer": "Acrobat Distiller 7.0.5 (Windows)",
      "/SourceModified": "D:20070301123627",
      "/Title": "Common Criteria Protection Profile electronic Health Card (eHC)",
      "pdf_file_size_bytes": 819630,
      "pdf_hyperlinks": {
        "_type": "Set",
        "elements": [
          "http://www.gematik.de/",
          "http://www.dimdi.de/de/ehealth/karte/bit4health"
        ]
      },
      "pdf_is_encrypted": false,
      "pdf_number_of_pages": 83
    },
    "report_filename": "PP0020_V2a.pdf",
    "report_keywords": {
      "asymmetric_crypto": {},
      "cc_cert_id": {},
      "cc_claims": {},
      "cc_protection_profile_id": {
        "BSI": {
          "BSI-PP-0005-2002T": 1,
          "BSI-PP-0006-2002T": 1,
          "BSI-PP-0020-V2-2007": 12
        }
      },
      "cc_sar": {
        "ADV": {
          "ADV_IMP.2": 2
        },
        "APE": {
          "APE_DES.1": 1,
          "APE_ENV.1": 1,
          "APE_INT.1": 1,
          "APE_OBJ.1": 1,
          "APE_REQ.1": 1,
          "APE_SRE.1": 1
        },
        "AVA": {
          "AVA_MSU.3": 2,
          "AVA_VLA.4": 2
        }
      },
      "cc_security_level": {
        "EAL": {
          "EAL 4": 3,
          "EAL 4 augmented": 2,
          "EAL4": 1
        }
      },
      "cc_sfr": {
        "FCS": {
          "FCS_CKM": 1,
          "FCS_CKM.4": 1,
          "FCS_COP": 7,
          "FCS_RND.1": 1
        },
        "FDP": {
          "FDP_ACC.2": 1,
          "FDP_ACF.1": 1,
          "FDP_RIP.1": 1,
          "FDP_SDI.2": 1,
          "FDP_UCT.1": 1,
          "FDP_UIT.1": 1
        },
        "FIA": {
          "FIA_AFL": 2,
          "FIA_ATD.1": 1,
          "FIA_UAU.1": 1,
          "FIA_UAU.4": 1,
          "FIA_UID.1": 1
        },
        "FMT": {
          "FMT_LIM.1": 1,
          "FMT_LIM.2": 1,
          "FMT_MTD": 5,
          "FMT_SMF.1": 1,
          "FMT_SMR.1": 1
        },
        "FPT": {
          "FPT_FLS.1": 1,
          "FPT_PHP.3": 1,
          "FPT_RVM.1": 1,
          "FPT_SEP.1": 1,
          "FPT_TST.1": 1
        },
        "FTP": {
          "FTP_ITC.1": 1
        }
      },
      "certification_process": {
        "ConfidentialDocument": {
          "Health Card (eHC) \u2013 elektronische Gesundheitskarte (eGK), BSI-PP-0020-V2-2007, T-Systems GEI GmbH (confidential document) [7] Common Criteria Protection Profile electronic Health Card (eHC) \u2013 elektronische": 1
        }
      },
      "cipher_mode": {},
      "cplc_data": {},
      "crypto_engine": {},
      "crypto_library": {},
      "crypto_protocol": {},
      "crypto_scheme": {
        "MAC": {
          "MAC": 1
        }
      },
      "device_model": {},
      "ecc_curve": {},
      "eval_facility": {},
      "hash_function": {},
      "ic_data_group": {},
      "javacard_api_const": {},
      "javacard_packages": {},
      "javacard_version": {},
      "os_name": {},
      "pq_crypto": {},
      "randomness": {},
      "side_channel_analysis": {
        "FI": {
          "Physical Tampering": 1
        }
      },
      "standard_id": {
        "ISO": {
          "ISO/IEC 15408": 2
        },
        "X509": {
          "X.509": 1
        }
      },
      "symmetric_crypto": {
        "AES_competition": {
          "HPC": {
            "HPC": 3
          }
        },
        "DES": {
          "DES": {
            "DES": 1
          }
        }
      },
      "technical_report_id": {
        "BSI": {
          "BSI 7125": 1,
          "BSI 7148": 1,
          "BSI 7149": 1
        }
      },
      "tee_name": {},
      "tls_cipher_suite": {},
      "vendor": {},
      "vulnerability": {}
    },
    "report_metadata": {
      "/Author": "BSI",
      "/Company": "BSI",
      "/CreationDate": "D:20070227113015+01\u002700\u0027",
      "/Creator": "Acrobat PDFMaker 7.0.7 f\u00fcr Word",
      "/Keywords": "\"BSI-PP-0020-V2-2007, eGK, eHC, Gesundheitskarte, Healthcard\"",
      "/ModDate": "D:20070305151201+01\u002700\u0027",
      "/Producer": "Acrobat Distiller 7.0.5 (Windows)",
      "/SourceModified": "D:20070227102800",
      "/Subject": "PP Certification Report BSI-PP-0020-V2-2007",
      "/Title": "PP Certification Report BSI-PP-0020-V2-2007",
      "pdf_file_size_bytes": 115587,
      "pdf_hyperlinks": {
        "_type": "Set",
        "elements": []
      },
      "pdf_is_encrypted": false,
      "pdf_number_of_pages": 21
    }
  },
  "scheme_metadata": null,
  "state": {
    "_type": "sec_certs.sample.protection_profile.ProtectionProfile.InternalState",
    "pp": {
      "_type": "sec_certs.sample.document_state.DocumentState",
      "convert_ok": true,
      "download_ok": true,
      "extract_ok": true,
      "json_hash": null,
      "source_hash": "1379b877f97f17dd892fad5fb83f78cc15733bcadda9bb3b82e8e41ce56b253d",
      "txt_hash": "75b7f7c082ada24d9aa79f5a4a34fe6be95e82841bfbb3c69b0c8ee94e89335e"
    },
    "report": {
      "_type": "sec_certs.sample.document_state.DocumentState",
      "convert_ok": true,
      "download_ok": true,
      "extract_ok": true,
      "json_hash": null,
      "source_hash": "8258c556eeb68bc812affd33f78b2cfc8301e442715b180d953840a5b2b02ab9",
      "txt_hash": "51c4792d212459136430ec3f98d9ac7ea298cf83f17bb5b3662241b0c30060d1"
    }
  },
  "web_data": {
    "_type": "sec_certs.sample.protection_profile.ProtectionProfile.WebData",
    "category": "ICs, Smart Cards and Smart Card-Related Devices and Systems",
    "is_collaborative": false,
    "maintenances": [
      [
        "2011-04-21",
        "Protection Profile for electronic Health Card (eHC) - elektronische Gesundheitskarte (eGK), Version 2.61",
        "https://www.commoncriteriaportal.org/nfs/ccpfiles/files/ppfiles/pp0020_v2_ma3a_pdf.pdf"
      ]
    ],
    "name": "Schutzprofile fur die elektronische Gesundheitskarte (eGK), Version 2.0",
    "not_valid_after": "2012-11-15",
    "not_valid_before": "2007-02-15",
    "pp_link": "https://www.commoncriteriaportal.org/nfs/ccpfiles/files/ppfiles/PP0020_V2b.pdf",
    "report_link": "https://www.commoncriteriaportal.org/nfs/ccpfiles/files/ppfiles/PP0020_V2a.pdf",
    "scheme": "DE",
    "security_level": {
      "_type": "Set",
      "elements": [
        "EAL4+"
      ]
    },
    "status": "archived",
    "version": "2.0"
  }
}