Schutzprofile fur die elektronische Gesundheitskarte (eGK), Version 2.0

Profile details

Status archived
Valid from 15.02.2007
Valid until 15.11.2012
Scheme πŸ‡©πŸ‡ͺ DE
Category ICs, Smart Cards and Smart Card-Related Devices and Systems
Security level EAL4+

Certification report

Extracted keywords

Symmetric Algorithms
HPC, DES
Schemes
MAC

Security level
EAL 4, EAL4, EAL 4 augmented
Security Assurance Requirements (SAR)
ADV_IMP.2, AVA_MSU.3, AVA_VLA.4, APE_DES.1, APE_ENV.1, APE_INT.1, APE_OBJ.1, APE_REQ.1, APE_SRE.1
Security Functional Requirements (SFR)
FCS_CKM, FCS_CKM.4, FCS_COP, FCS_RND.1, FDP_ACC.2, FDP_ACF.1, FDP_RIP.1, FDP_SDI.2, FDP_UCT.1, FDP_UIT.1, FIA_AFL, FIA_ATD.1, FIA_UID.1, FIA_UAU.1, FIA_UAU.4, FMT_SMF.1, FMT_SMR.1, FMT_MTD, FMT_LIM.1, FMT_LIM.2, FPT_FLS.1, FPT_PHP.3, FPT_TST.1, FPT_RVM.1, FPT_SEP.1, FTP_ITC.1
Protection profiles
BSI-PP-0020-V2-2007, BSI-PP-0005-2002T, BSI-PP-0006-2002T

Side-channel analysis
Physical Tampering
Certification process
Health Card (eHC) – elektronische Gesundheitskarte (eGK), BSI-PP-0020-V2-2007, T-Systems GEI GmbH (confidential document) [7] Common Criteria Protection Profile electronic Health Card (eHC) – elektronische

Standards
ISO/IEC 15408, X.509
Technical reports
BSI 7125, BSI 7148, BSI 7149

Protection profile

Extracted keywords

Symmetric Algorithms
HPC, DES, Triple-DES, TDES
Hash functions
SHA-1, SHA-224
Schemes
MAC
Protocols
SSL
Block cipher modes
CBC

Security level
EAL4, EAL4 augmented
Security Assurance Requirements (SAR)
ADO_DEL, ADO_IGS, ADO_IGS.1, ADV_IMP.2, ADV_SPM.1, ADV_LLD.1, ADV_RCR.1, ADV_FSP.1, ADV_HLD.2, ADV_IMP.1, AGD_ADM.1, AGD_USR.1, ALC_TAT.1, AVA_MSU.3, AVA_VLA.4, ASE_PPC.1
Security Functional Requirements (SFR)
FCS_RND, FCS_CKM.1, FCS_CKM, FCS_CKM.2, FCS_COP.1, FCS_CKM.4, FCS_RND.1, FCS_CKM.4.1, FCS_COP, FCS_RND.1.1, FDP_ITC.1, FDP_ITC.2, FDP_ACC.2, FDP_ACF.1, FDP_UCT.1, FDP_ACC.1, FDP_ACC.2.1, FDP_ACF.1.1, FDP_ACF.1.2, FDP_ACF.1.3, FDP_ACF.1.4, FDP_RIP.1, FDP_RIP.1.1, FDP_SDI.2, FDP_SDI.1, FDP_SDI.2.1, FDP_SDI.2.2, FDP_UIT.1, FDP_UCT.1.1, FDP_IFC.1, FDP_UIT.1.1, FDP_UIT.1.2, FDP_ACF, FDP_ACC, FDP_UCT, FDP_UIT, FIA_UAU.4, FIA_AFL.1, FIA_AFL, FIA_UAU.1, FIA_ATD.1, FIA_ATD.1.1, FIA_UID.1, FIA_UID.1.1, FIA_UID.1.2, FIA_UAU.1.1, FIA_UAU.1.2, FIA_UAU.4.1, FMT_LIM, FMT_MSA.2, FMT_MTD.1, FMT_MSA.3, FMT_SMF.1, FMT_SMR.1, FMT_SMF.1.1, FMT_SMR.1.1, FMT_SMR.1.2, FMT_LIM.1, FMT_LIM.2, FMT_LIM.1.1, FMT_LIM.2.1, FMT_MTD, FMT_MSA.1, FPT_FLS.1, FPT_TST.1, FPT_PHP.3, FPT_RVM.1, FPT_SEP.1, FPT_FLS.1.1, FPT_PHP.3.1, FPT_TST.1.1, FPT_TST.1.2, FPT_TST.1.3, FPT_AMT.1, FPT_RVM.1.1, FPT_SEP.1.1, FPT_SEP.1.2, FTP_ITC.1, FTP_TRP.1, FTP_ITC.1.1, FTP_ITC.1.2, FTP_ITC.1.3
Protection profiles
BSI-PP-0020-V2-2007, BSI-PP-0002, BSI-PP-0005-2002, BSI-PP-0006-2002, BSI-PP- 0005-2002, BSI-PP-****, BSI-PP-0005-2002T, BSI-PP-0006-2002T, BSI-PP-0002-2001
Evaluation facilities
SRC Security Research & Consulting

Side-channel analysis
physical probing, side channels, DPA, Physical Tampering, physical tampering, Physical tampering, Malfunction, malfunction, fault injection, reverse engineering, Bleichenbacher attack
Certification process
out of scope, FDP_ACF.1 101 Application note 29: Keys and other data for creation of qualified signatures are out of scope of this protection profile. 102 The TOE shall meet the requirement β€œSecurity attribute based access

Standards
FIPS 180-2, FIPS 46-3, FIPS PUB 46-3, PKCS #1, PKCS#1, ISO/IEC9796-2, ISO/IEC 7816-2, ISO/IEC 7816-4, X.509, x.509, CCIMB-2005-08-001, CCIMB-2005-08-002, CCIMB-2005-08-003, CCIMB-2005-08-004

References

No references are available for this protection profile.

Processing updates

Feed
  • The protection profile data changed.
  • The protection profile data changed.
  • The protection profile data changed.
  • The protection profile data changed.
  • The protection profile data changed.
  • The protection profile data changed.
  • The protection profile data changed.
  • The protection profile data changed.
  • The protection profile data changed.
  • The protection profile data changed.
  • The protection profile data changed.
  • The protection profile data changed.
  • The protection profile data changed.
  • The protection profile data changed.
  • The protection profile data changed.
  • The protection profile data changed.
  • The protection profile data changed.
  • The protection profile data changed.
  • The protection profile data changed.
  • The protection profile data changed.
  • The protection profile data changed.
  • The protection profile data changed.
  • The protection profile data changed.
  • The protection profile data changed.
  • The protection profile data changed.
  • The protection profile data changed.
  • The protection profile data changed.
  • The protection profile data changed.
  • The protection profile data changed.
  • The protection profile data changed.
  • The protection profile data changed.
  • The protection profile data changed.
  • The protection profile data changed.
  • The protection profile data changed.
  • The protection profile data changed.
  • The protection profile data changed.
  • The protection profile data changed.
  • The protection profile data changed.
  • The protection profile data changed.
  • The protection profile data changed.
  • The protection profile data changed.
  • The protection profile data changed.
  • The protection profile data changed.
  • The protection profile data changed.
  • The protection profile data changed.
  • The protection profile data changed.
  • The protection profile data changed.
  • The protection profile data changed.
  • The protection profile data changed.
  • The protection profile data changed.
  • The protection profile data changed.
  • The protection profile data changed.
  • The protection profile data changed.
  • The protection profile data changed.
  • The protection profile data changed.
  • The protection profile data changed.
  • The protection profile data changed.
  • The protection profile data changed.
  • The protection profile data changed.
  • The protection profile data changed.
  • The protection profile data changed.
  • The protection profile data changed.
  • The protection profile data changed.
  • The protection profile was first processed.

Raw data

{
  "_id": "bb2ba741adffde7d",
  "_type": "sec_certs.sample.protection_profile.ProtectionProfile",
  "dgst": "bb2ba741adffde7d",
  "heuristics": {
    "_type": "sec_certs.sample.protection_profile.ProtectionProfile.Heuristics"
  },
  "pdf_data": {
    "_type": "sec_certs.sample.protection_profile.ProtectionProfile.PdfData",
    "pp_filename": "PP0020_V2b.pdf",
    "pp_keywords": {
      "asymmetric_crypto": {},
      "cc_cert_id": {},
      "cc_claims": {},
      "cc_protection_profile_id": {
        "BSI": {
          "BSI-PP- 0005-2002": 1,
          "BSI-PP-****": 1,
          "BSI-PP-0002": 2,
          "BSI-PP-0002-2001": 1,
          "BSI-PP-0005-2002": 2,
          "BSI-PP-0005-2002T": 1,
          "BSI-PP-0006-2002": 3,
          "BSI-PP-0006-2002T": 1,
          "BSI-PP-0020-V2-2007": 2
        }
      },
      "cc_sar": {
        "ADO": {
          "ADO_DEL": 1,
          "ADO_IGS": 2,
          "ADO_IGS.1": 1
        },
        "ADV": {
          "ADV_FSP.1": 2,
          "ADV_HLD.2": 1,
          "ADV_IMP.1": 1,
          "ADV_IMP.2": 6,
          "ADV_LLD.1": 2,
          "ADV_RCR.1": 1,
          "ADV_SPM.1": 2
        },
        "AGD": {
          "AGD_ADM.1": 2,
          "AGD_USR.1": 2
        },
        "ALC": {
          "ALC_TAT.1": 1
        },
        "ASE": {
          "ASE_PPC.1": 4
        },
        "AVA": {
          "AVA_MSU.3": 5,
          "AVA_VLA.4": 5
        }
      },
      "cc_security_level": {
        "EAL": {
          "EAL4": 12,
          "EAL4 augmented": 2
        }
      },
      "cc_sfr": {
        "FCS": {
          "FCS_CKM": 7,
          "FCS_CKM.1": 21,
          "FCS_CKM.2": 2,
          "FCS_CKM.4": 26,
          "FCS_CKM.4.1": 1,
          "FCS_COP": 44,
          "FCS_COP.1": 13,
          "FCS_RND": 6,
          "FCS_RND.1": 13,
          "FCS_RND.1.1": 2
        },
        "FDP": {
          "FDP_ACC": 1,
          "FDP_ACC.1": 7,
          "FDP_ACC.2": 12,
          "FDP_ACC.2.1": 2,
          "FDP_ACF": 2,
          "FDP_ACF.1": 13,
          "FDP_ACF.1.1": 1,
          "FDP_ACF.1.2": 1,
          "FDP_ACF.1.3": 1,
          "FDP_ACF.1.4": 1,
          "FDP_IFC.1": 4,
          "FDP_ITC.1": 16,
          "FDP_ITC.2": 16,
          "FDP_RIP.1": 7,
          "FDP_RIP.1.1": 1,
          "FDP_SDI.1": 2,
          "FDP_SDI.2": 5,
          "FDP_SDI.2.1": 1,
          "FDP_SDI.2.2": 1,
          "FDP_UCT": 1,
          "FDP_UCT.1": 11,
          "FDP_UCT.1.1": 1,
          "FDP_UIT": 1,
          "FDP_UIT.1": 6,
          "FDP_UIT.1.1": 1,
          "FDP_UIT.1.2": 1
        },
        "FIA": {
          "FIA_AFL": 12,
          "FIA_AFL.1": 5,
          "FIA_ATD.1": 7,
          "FIA_ATD.1.1": 1,
          "FIA_UAU.1": 10,
          "FIA_UAU.1.1": 1,
          "FIA_UAU.1.2": 1,
          "FIA_UAU.4": 8,
          "FIA_UAU.4.1": 1,
          "FIA_UID.1": 8,
          "FIA_UID.1.1": 1,
          "FIA_UID.1.2": 1
        },
        "FMT": {
          "FMT_LIM": 6,
          "FMT_LIM.1": 20,
          "FMT_LIM.1.1": 2,
          "FMT_LIM.2": 19,
          "FMT_LIM.2.1": 1,
          "FMT_MSA.1": 1,
          "FMT_MSA.2": 19,
          "FMT_MSA.3": 2,
          "FMT_MTD": 27,
          "FMT_MTD.1": 9,
          "FMT_SMF.1": 19,
          "FMT_SMF.1.1": 1,
          "FMT_SMR.1": 19,
          "FMT_SMR.1.1": 1,
          "FMT_SMR.1.2": 1
        },
        "FPT": {
          "FPT_AMT.1": 5,
          "FPT_FLS.1": 11,
          "FPT_FLS.1.1": 1,
          "FPT_PHP.3": 10,
          "FPT_PHP.3.1": 1,
          "FPT_RVM.1": 10,
          "FPT_RVM.1.1": 1,
          "FPT_SEP.1": 10,
          "FPT_SEP.1.1": 1,
          "FPT_SEP.1.2": 1,
          "FPT_TST.1": 11,
          "FPT_TST.1.1": 1,
          "FPT_TST.1.2": 1,
          "FPT_TST.1.3": 2
        },
        "FTP": {
          "FTP_ITC.1": 14,
          "FTP_ITC.1.1": 1,
          "FTP_ITC.1.2": 1,
          "FTP_ITC.1.3": 1,
          "FTP_TRP.1": 4
        }
      },
      "certification_process": {
        "OutOfScope": {
          "FDP_ACF.1 101 Application note 29: Keys and other data for creation of qualified signatures are out of scope of this protection profile. 102 The TOE shall meet the requirement \u201cSecurity attribute based access": 1,
          "out of scope": 1
        }
      },
      "cipher_mode": {
        "CBC": {
          "CBC": 1
        }
      },
      "cplc_data": {},
      "crypto_engine": {},
      "crypto_library": {},
      "crypto_protocol": {
        "TLS": {
          "SSL": {
            "SSL": 1
          }
        }
      },
      "crypto_scheme": {
        "MAC": {
          "MAC": 17
        }
      },
      "device_model": {},
      "ecc_curve": {},
      "eval_facility": {
        "SRC": {
          "SRC Security Research \u0026 Consulting": 1
        }
      },
      "hash_function": {
        "SHA": {
          "SHA1": {
            "SHA-1": 6
          },
          "SHA2": {
            "SHA-224": 1
          }
        }
      },
      "ic_data_group": {},
      "javacard_api_const": {},
      "javacard_packages": {},
      "javacard_version": {},
      "os_name": {},
      "pq_crypto": {},
      "randomness": {},
      "side_channel_analysis": {
        "FI": {
          "Malfunction": 3,
          "Physical Tampering": 2,
          "Physical tampering": 1,
          "fault injection": 1,
          "malfunction": 4,
          "physical tampering": 4
        },
        "SCA": {
          "DPA": 1,
          "physical probing": 4,
          "side channels": 2
        },
        "other": {
          "Bleichenbacher attack": 1,
          "reverse engineering": 1
        }
      },
      "standard_id": {
        "CC": {
          "CCIMB-2005-08-001": 2,
          "CCIMB-2005-08-002": 2,
          "CCIMB-2005-08-003": 2,
          "CCIMB-2005-08-004": 1
        },
        "FIPS": {
          "FIPS 180-2": 1,
          "FIPS 46-3": 1,
          "FIPS PUB 46-3": 1
        },
        "ISO": {
          "ISO/IEC 7816-2": 1,
          "ISO/IEC 7816-4": 1,
          "ISO/IEC9796-2": 2
        },
        "PKCS": {
          "PKCS #1": 1,
          "PKCS#1": 2
        },
        "X509": {
          "X.509": 7,
          "x.509": 2
        }
      },
      "symmetric_crypto": {
        "AES_competition": {
          "HPC": {
            "HPC": 31
          }
        },
        "DES": {
          "3DES": {
            "TDES": 4,
            "Triple-DES": 9
          },
          "DES": {
            "DES": 1
          }
        }
      },
      "technical_report_id": {},
      "tee_name": {},
      "tls_cipher_suite": {},
      "vendor": {},
      "vulnerability": {}
    },
    "pp_metadata": {
      "/Author": "Bundesamt f\u00fcr Sicherheit in der Informationstechnik",
      "/Company": "SRC Security Research and Consulting GmbH",
      "/CreationDate": "D:20070301134559+01\u002700\u0027",
      "/Creator": "Acrobat PDFMaker 7.0.7 f\u00fcr Word",
      "/Keywords": "BSI-PP-0020-V2-2007, electronic Health Card",
      "/ModDate": "D:20070305151311+01\u002700\u0027",
      "/Producer": "Acrobat Distiller 7.0.5 (Windows)",
      "/SourceModified": "D:20070301123627",
      "/Title": "Common Criteria Protection Profile electronic Health Card (eHC)",
      "pdf_file_size_bytes": 819630,
      "pdf_hyperlinks": {
        "_type": "Set",
        "elements": [
          "http://www.dimdi.de/de/ehealth/karte/bit4health",
          "http://www.gematik.de/"
        ]
      },
      "pdf_is_encrypted": false,
      "pdf_number_of_pages": 83
    },
    "report_filename": "PP0020_V2a.pdf",
    "report_keywords": {
      "asymmetric_crypto": {},
      "cc_cert_id": {},
      "cc_claims": {},
      "cc_protection_profile_id": {
        "BSI": {
          "BSI-PP-0005-2002T": 1,
          "BSI-PP-0006-2002T": 1,
          "BSI-PP-0020-V2-2007": 12
        }
      },
      "cc_sar": {
        "ADV": {
          "ADV_IMP.2": 2
        },
        "APE": {
          "APE_DES.1": 1,
          "APE_ENV.1": 1,
          "APE_INT.1": 1,
          "APE_OBJ.1": 1,
          "APE_REQ.1": 1,
          "APE_SRE.1": 1
        },
        "AVA": {
          "AVA_MSU.3": 2,
          "AVA_VLA.4": 2
        }
      },
      "cc_security_level": {
        "EAL": {
          "EAL 4": 3,
          "EAL 4 augmented": 2,
          "EAL4": 1
        }
      },
      "cc_sfr": {
        "FCS": {
          "FCS_CKM": 1,
          "FCS_CKM.4": 1,
          "FCS_COP": 7,
          "FCS_RND.1": 1
        },
        "FDP": {
          "FDP_ACC.2": 1,
          "FDP_ACF.1": 1,
          "FDP_RIP.1": 1,
          "FDP_SDI.2": 1,
          "FDP_UCT.1": 1,
          "FDP_UIT.1": 1
        },
        "FIA": {
          "FIA_AFL": 2,
          "FIA_ATD.1": 1,
          "FIA_UAU.1": 1,
          "FIA_UAU.4": 1,
          "FIA_UID.1": 1
        },
        "FMT": {
          "FMT_LIM.1": 1,
          "FMT_LIM.2": 1,
          "FMT_MTD": 5,
          "FMT_SMF.1": 1,
          "FMT_SMR.1": 1
        },
        "FPT": {
          "FPT_FLS.1": 1,
          "FPT_PHP.3": 1,
          "FPT_RVM.1": 1,
          "FPT_SEP.1": 1,
          "FPT_TST.1": 1
        },
        "FTP": {
          "FTP_ITC.1": 1
        }
      },
      "certification_process": {
        "ConfidentialDocument": {
          "Health Card (eHC) \u2013 elektronische Gesundheitskarte (eGK), BSI-PP-0020-V2-2007, T-Systems GEI GmbH (confidential document) [7] Common Criteria Protection Profile electronic Health Card (eHC) \u2013 elektronische": 1
        }
      },
      "cipher_mode": {},
      "cplc_data": {},
      "crypto_engine": {},
      "crypto_library": {},
      "crypto_protocol": {},
      "crypto_scheme": {
        "MAC": {
          "MAC": 1
        }
      },
      "device_model": {},
      "ecc_curve": {},
      "eval_facility": {},
      "hash_function": {},
      "ic_data_group": {},
      "javacard_api_const": {},
      "javacard_packages": {},
      "javacard_version": {},
      "os_name": {},
      "pq_crypto": {},
      "randomness": {},
      "side_channel_analysis": {
        "FI": {
          "Physical Tampering": 1
        }
      },
      "standard_id": {
        "ISO": {
          "ISO/IEC 15408": 2
        },
        "X509": {
          "X.509": 1
        }
      },
      "symmetric_crypto": {
        "AES_competition": {
          "HPC": {
            "HPC": 3
          }
        },
        "DES": {
          "DES": {
            "DES": 1
          }
        }
      },
      "technical_report_id": {
        "BSI": {
          "BSI 7125": 1,
          "BSI 7148": 1,
          "BSI 7149": 1
        }
      },
      "tee_name": {},
      "tls_cipher_suite": {},
      "vendor": {},
      "vulnerability": {}
    },
    "report_metadata": {
      "/Author": "BSI",
      "/Company": "BSI",
      "/CreationDate": "D:20070227113015+01\u002700\u0027",
      "/Creator": "Acrobat PDFMaker 7.0.7 f\u00fcr Word",
      "/Keywords": "\"BSI-PP-0020-V2-2007, eGK, eHC, Gesundheitskarte, Healthcard\"",
      "/ModDate": "D:20070305151201+01\u002700\u0027",
      "/Producer": "Acrobat Distiller 7.0.5 (Windows)",
      "/SourceModified": "D:20070227102800",
      "/Subject": "PP Certification Report BSI-PP-0020-V2-2007",
      "/Title": "PP Certification Report BSI-PP-0020-V2-2007",
      "pdf_file_size_bytes": 115587,
      "pdf_hyperlinks": {
        "_type": "Set",
        "elements": []
      },
      "pdf_is_encrypted": false,
      "pdf_number_of_pages": 21
    }
  },
  "scheme_metadata": null,
  "state": {
    "_type": "sec_certs.sample.protection_profile.ProtectionProfile.InternalState",
    "pp": {
      "_type": "sec_certs.sample.document_state.DocumentState",
      "convert_ok": true,
      "download_ok": true,
      "extract_ok": true,
      "json_hash": null,
      "source_hash": "1379b877f97f17dd892fad5fb83f78cc15733bcadda9bb3b82e8e41ce56b253d",
      "txt_hash": "75b7f7c082ada24d9aa79f5a4a34fe6be95e82841bfbb3c69b0c8ee94e89335e"
    },
    "report": {
      "_type": "sec_certs.sample.document_state.DocumentState",
      "convert_ok": true,
      "download_ok": true,
      "extract_ok": true,
      "json_hash": null,
      "source_hash": "8258c556eeb68bc812affd33f78b2cfc8301e442715b180d953840a5b2b02ab9",
      "txt_hash": "51c4792d212459136430ec3f98d9ac7ea298cf83f17bb5b3662241b0c30060d1"
    }
  },
  "web_data": {
    "_type": "sec_certs.sample.protection_profile.ProtectionProfile.WebData",
    "category": "ICs, Smart Cards and Smart Card-Related Devices and Systems",
    "is_collaborative": false,
    "maintenances": [
      [
        "2011-04-21",
        "Protection Profile for electronic Health Card (eHC) - elektronische Gesundheitskarte (eGK), Version 2.61",
        "https://www.commoncriteriaportal.org/nfs/ccpfiles/files/ppfiles/pp0020_v2_ma3a_pdf.pdf"
      ]
    ],
    "name": "Schutzprofile fur die elektronische Gesundheitskarte (eGK), Version 2.0",
    "not_valid_after": "2012-11-15",
    "not_valid_before": "2007-02-15",
    "pp_link": "https://www.commoncriteriaportal.org/nfs/ccpfiles/files/ppfiles/PP0020_V2b.pdf",
    "report_link": "https://www.commoncriteriaportal.org/nfs/ccpfiles/files/ppfiles/PP0020_V2a.pdf",
    "scheme": "DE",
    "security_level": {
      "_type": "Set",
      "elements": [
        "EAL4+"
      ]
    },
    "status": "archived",
    "version": "2.0"
  }
}