QSCD | Giesecke+Devrient Mobile Security GmbH | STARCOS 3.5 ID GCC C2



Type of certificationQSCD | Certification of qualified signature and seal creation devices
SRC certificate registration numberSRC.00012.TE.05.2013
Valid fromMay 14, 2013
Valid untilDecember 31, 2023
Certificate holderGiesecke+Devrient Mobile Security GmbH
Certified productSTARCOS 3.5 ID GCC C2
Test methodAccording to the regulations of SigG and SigV, the confirmation was performed on the basis of a Common Criteria Evaluation according to the Protection Profiles “Protection profile for secure signature creation device, Part 2: Device with key generation” and “Protection Profile – Electronic Identity Card (ID_Card PP)”. The evaluation was performed with Evaluation Assurance Level (EAL) 4+ and assuming an high attack potential (augmentation AVA_VAN.5).
The audit includes
  • the Common Criteria Evaluation of the product “STARCOS 3.5 ID GCC C2” according to the following Protection Profiles with Evaluation Assurance Level (EAL) 4+ (EAL 4 with the augmentation packages AVA_VAN.5, ATE_DPT.2 and ALC_DVS.2):
    • “Protection profiles for secure signature creation device, Part 2: Device with key generation”
    • “Protection Profile – Electronic Identity Card (ID_Card PP)”
  • the confirmation of the product according to article 15 paragraph 7 sentence 1, article 17 paragraph 1 Signaturgesetz (SigG) as well as article 15 paragraphs 1 and 4, article 11 paragraph 3 Signaturverordnung (SigV) by the confirmation body of SRC accredited by Bundesnetzagentur and
  • an amendment to extend the confirmation (addition of information on the manufacturer, extension of validity period).

In accordance with the transitional measures of article 51, paragraph 1 of Regulation (EU) No. 910/2014, the product can be considered as qualified signature creation device (QSCD) in the sense given in this regulation.

DescriptionThe product “STARCOS 3.5 ID GCC C2” is a secure signature creation device (SSCD) according to SigG and SigV. The card is a new German (electronic) national identity card and has a contactless interface.

The product consists (among other things) of the semiconductor (IC) M7820 A11 from Infineon Technologies AG, the card operating system STARCOS 3.5 and an application for generating qualified signatures.

SRC confirms that the product “STARCOS 3.5 ID GCC C2” of Giesecke+Devrient Mobile Security GmbH fulfills the requirements of article 17 paragraphs 1 and 3 number 1 SigG and article 15 paragraphs 1 and 4, annex 1, I, 1.1 to 1.3 SigV.

In accordance with the transitional measures of article 51, paragraph 1 of Regulation (EU) No. 910/2014, the product can be considered as qualified signature creation device (QSCD) in the sense given in this regulation.