QSCD | Giesecke+Devrient Mobile Security GmbH | STARCOS 3.5 ID GCC C2R



Type of certificationQSCD | Certification of qualified signature and seal creation devices
SRC certificate registration numberSRC.00022.TE.11.2014
Valid fromNovember 14, 2014
Valid untilDecember 31, 2023
Certificate holderGiesecke+Devrient Mobile Security GmbH
Certified productSTARCOS 3.5 ID GCC C2R
Test methodAccording to the regulations of SigG and SigV, the confirmation was performed on the basis of a Common Criteria Evaluation according to the Protection Profiles “Protection profile for secure signature creation device, Part 2: Device with key generation” and “Protection Profile – Electronic Identity Card (ID_Card PP)”. The evaluation was performed with Evaluation Assurance Level (EAL) 4+ and assuming an high attack potential (augmentation AVA_VAN.5).
The audit includes
  • the Common Criteria Evaluation of the product “STARCOS 3.5 ID GCC C2R” according to the following Protection Profiles with Evaluation Assurance Level (EAL) 4+ (EAL 4 with the augmentation packages AVA_VAN.5, ATE_DPT.2 and ALC_DVS.2):
    • “Protection profiles for secure signature creation device, Part 2: Device with key generation”
    • “Protection Profile – Electronic Identity Card (ID_Card PP)”
  • the confirmation of the product according to article 15 paragraph 7 sentence 1, article 17 paragraph 1 Signaturgesetz (SigG) as well as article 15 paragraphs 1 and 4, article 11 paragraph 3 Signaturverordnung (SigV) by the confirmation body of SRC that is accredited by Bundesnetzagentur and
  • an amendment for extension of the confirmation (supplement to the details about the manufacturer, extension of the validity period of the confirmation).

In accordance with the transitional measures of article 51, paragraph 1 of Regulation (EU) No. 910/2014, the product can be considered as qualified signature creation device (QSCD) in the sense given in this regulation.

DescriptionThe product “STARCOS 3.5 ID GCC C2R” is a secure signature creation device (SSCD) according to SigG and SigV. The card is a new German (electronic) national identity card and has a contactless interface.

The product consists (among other things) of the semiconductor (IC) M7820 A11 from Infineon Technologies AG, the card operating system STARCOS 3.5 and an application for generating qualified signatures.

SRC confirms that the product “STARCOS 3.5 ID GCC C2R” of Giesecke+Devrient Mobile Security GmbH fulfills the requirements of article 17 paragraphs 1 and 3 number 1 SigG and article 15 paragraphs 1 and 4, annex 1, I, 1.1 to 1.3 SigV.

In accordance with the transitional measures of article 51, paragraph 1 of Regulation (EU) No. 910/2014, the product can be considered as qualified signature creation device (QSCD) in the sense given in this regulation.