QSCD | Giesecke+Devrient Mobile Security GmbH | STARCOS 3.5 ID GCC C1R



Type of CertificationQSCD | Certification of Qualified Signature and Seal Creation Devices
SRC Certificate Registration NumberSRC.00014.TE.02.2012
Valid fromFebruary 1, 2012
Valid untilDecember 31, 2023
Certificate HolderGiesecke+Devrient Mobile Security GmbH
Certified ProductSTARCOS 3.5 ID GCC C1R
Testing MethodIn accordance with the requirements of the SigG and SigV, the confirmation was made on the basis of a Common Criteria evaluation according to the Protection Profiles “Protection Profile for secure signature creation device — Part 2: Device with key generation” and “Common Criteria Protection Profile – Electronic Identity Card (ID_Card PP)”. The evaluation was carried out with evaluation assurance level EAL 4+ and against a high attack potential (augmentation AVA_VAN.5).
The examination includes
  • the Common Criteria evaluation of the product “STARCOS 3.5 ID GCC C1R” according to the following Protection Profiles with evaluation assurance level EAL 4+ (EAL 4 with augmentations AVA_VAN.5, ATE_DPT.2 and ALC_DVS.2)
    • “Protection Profile for secure signature creation device — Part 2: Device with key generation”
    • “Common Criteria Protection Profile – Electronic Identity Card (ID_Card PP)”,
  • the confirmation of the product according to §§ 15 para. 7 sentence 1, 17 para. 1 Signature Act (SigG) as well as §§ 15 para. 1 and 4, 11 para. 3 Signature Ordinance (SigV) by the SRC confirmation body accredited by the Federal Network Agency and
  • two addenda to extend the confirmation:
    • Addendum 1: Adjustment of requirements for the signature key or card holder
    • Addendum 2: Addition of manufacturer details, extension of validity period.

Due to the transitional measures according to Regulation (EU) No. 910/2014, Article 51, para. 1, the product is considered a QSCD according to the aforementioned regulation.

DescriptionThe product “STARCOS 3.5 ID GCC C1R” is a secure signature creation device (SSCD) according to SigG and SigV. The card is a new (electronic) identity card (nPA) and has a contactless interface.

The product consists, among other things, of the semiconductor (IC) P5CD128V0A from NXP, the STARCOS 3.5 card operating system, and an application for generating qualified signatures.

SRC certifies that the product “STARCOS 3.5 ID GCC C1R” from Giesecke+Devrient Mobile Security GmbH meets the requirements according to § 17 para. 1 and 3 no. 1 SigG as well as § 15 para. 1 and 4, Annex 1, I, 1.1 to 1.3 SigV.

Due to the transitional measures according to Regulation (EU) No. 910/2014, Article 51, para. 1, the product is considered a QSCD according to the aforementioned regulation.