QSCD | Giesecke+Devrient Mobile Security GmbH | STARCOS 3.5 ID GCC C2R



Certificate SRC.00022.TE.11.2014 Certificate SRC.00022.TE.11.2014 // Addendum 1 Confirmation SRC.00022.TE.11.2014 Confirmation SRC.00022.TE.11.2014 // Addendum 1

Type of certificationQSCD | Certification of qualified signature and seal creation devices
SRC certificate registration numberSRC.00022.TE.11.2014
Valid fromNovember 14, 2014
Valid untilDecember 31, 2023
Certificate holderGiesecke+Devrient Mobile Security GmbH
Certified productSTARCOS 3.5 ID GCC C2R
Test methodIn accordance with the requirements of the SigG and SigV, the confirmation was carried out on the basis of a Common Criteria evaluation against the Protection Profiles “Protection Profile for Secure Signature Creation Device — Part 2: Device with Key Generation” and “Common Criteria Protection Profile – Electronic Identity Card (ID_Card PP)”. The evaluation was performed at assurance level EAL 4+ and against a high attack potential (augmentation AVA_VAN.5).
The assessment covers
  • the Common Criteria evaluation of the product “STARCOS 3.5 ID GCC C2R” against the following Protection Profiles at assurance level EAL 4+ (EAL 4 with the augmentations AVA_VAN.5, ATE_DPT.2 and ALC_DVS.2)
    • “Protection Profiles for Secure Signature Creation Device, Part 2: Device with Key Generation”
    • Protection Profile – Electronic Identity Card (ID_Card PP)”,
  • the confirmation of the product in accordance with Sections 15(7) sentence 1 and 17(1) of the Signature Act (SigG) as well as Sections 15(1) and (4) and 11(1) (3) of the Signature Ordinance (SigV) by SRC’s confirmation body accredited by the Federal Network Agency (Bundesnetzagentur), and
  • an addendum to extend the confirmation (addition of information on the manufacturer, extension of the validity period).

Due to the transitional measures pursuant to Regulation (EU) No. 910/2014, Article 51(1), the product is considered a QSCD under the said Regulation.

DescriptionThe product “STARCOS 3.5 ID GCC C2R” is a secure signature creation device (SSCD) in accordance with the SigG and SigV. The card is a new (electronic) identity card (nPA) and features a contactless interface.

The product consists, among other things, of the semiconductor (IC) M7820 A11 from Infineon Technologies AG, the STARCOS 3.5 card operating system, and an application for creating qualified signatures.

SRC certifies that the product “STARCOS 3.5 ID GCC C2R” from Giesecke+Devrient Mobile Security GmbH meets the requirements pursuant to Section 17(1) and (3) no. 1 SigG as well as Section 15(1) and (4), Annex 1, I, 1.1 to 1.3 SigV.

Due to the transitional measures pursuant to Regulation (EU) No. 910/2014, Article 51(1), the product is considered a QSCD under the said Regulation.