QSCD | Giesecke+Devrient Mobile Security GmbH | STARCOS 3.5 ID ECC C1R



Type of certificationQSCD | Certification of qualified signature and seal creation devices
SRC certificate registration numberSRC.00021.TE.05.2013
Valid fromMay 13, 2013
Valid untilDecember 31, 2023
Certificate holderGiesecke+Devrient Mobile Security GmbH
Certified productSTARCOS 3.5 ID ECC C1R
Test methodAccording to the regulations of SigG and SigV, the confirmation was performed on the basis of a Common Criteria Evaluation according to the Protection Profiles “Protection Profile for secure signature creation device – Part 2: Device with key generation”. The evaluation was performed with Evaluation Assurance Level (EAL) 4+ and assuming an high attack potential (augmentation AVA_VAN.5).
The audit includes
  • the Common Criteria Evaluation of the product “STARCOS 3.5 ID ECC C1R” according to the following Protection Profiles with Evaluation Assurance Level (EAL) 4+ (EAL 4 with the augmentation package AVA_VAN.5):
    • “Protection Profiles for secure signature creation device — Part 2: Device with key generation”
  • the confirmation of the product according to article 15 paragraph 7 sentence 1, article 17 paragraph 1 Signaturgesetz (SigG) as well as article 15 paragraphs 1 and 4, article 11 paragraph 3 Signaturverordnung (SigV) by the confirmation body of SRC that is accredited by Bundesnetzagentur,
  • a corrigendum for editorial work on the confirmation and
  • five amendments for the extension of the confirmation:
    • Amendment 1: Supplement of further trade names
    • Amendment 2: Supplement to the functional description and the usage conditions
    • Amendment 3: Extension of the validity period of the confirmation
    • Amendment 4: Supplement to the details about the manufacturer
    • Amendment 5: Supplement to the functional description

In accordance with the transitional measures of article 51, paragraph 1 of Regulation (EU) No. 910/2014, the product can be considered as qualified signature creation device (QSCD) in the sense given in this regulation.

Description

The product “STARCOS 3.5 ID ECC C1R” is a secure signature creation device (SSCD) according to SigG and SigV. The card is a dual interface card and can be used (depending on its configuration) purely contact-based, purely contactless or as dual interface card.

The product consists (among other things) of the semiconductor (IC) M7820 A11 from Infineon Technologies AG, the card operating system STARCOS 3.5 and an application for generating qualified signatures. Depending on the underlying hardware, the product is also distributed  under the tradenames STARCOS 3.5 ID ECC C1R/360, /800 or /1280. Those variations differ only in the available storage size.

SRC confirms that the product “STARCOS 3.5 ID ECC C1R” of Giesecke+Devrient Mobile Security GmbH fulfills the requirements of article 17 paragraphs 1 and 3 number 1 SigG and article 15 paragraphs 1 and 4, annex 1, I, 1.1 to 1.3 SigV.

In accordance with the transitional measures of article 51, paragraph 1 of Regulation (EU) No. 910/2014, the product can be considered as qualified signature creation device (QSCD) in the sense given in this regulation.