QSCD | Giesecke+Devrient Mobile Security GmbH | STARCOS 3.6 QES C1

Type of certificationQSCD | Certification of qualified signature and seal creation devices
SRC certificate registration numberSRC.00048.QSCD.05.2022
Valid from30 May 2022
Valid until31 December 2025
Certificate holderGiesecke+Devrient Mobile Security GmbH
Certified productSTARCOS 3.6 QES C1
Test methodAccording to article 30 (3) a) of Regulation (EU) No. 910/2014, the certification was done on basis of a Common Criteria Evaluation against the Protection Profiles EN 419211-2:2013 and EN 419211-4:2013, which are listed in the Commission Implementing Decision (EU) 2016/650 of 25 April 2016.
The audit includes
  • the Common Criteria Evaluation of the product “STARCOS 3.6 QES C1” according to the following Protection Profiles with Evaluation Assurance Level (EAL) 4+ (EAL 4 mit der Augmentierung AVA_VAN.5):
    • “Protection profiles for secure signature creation device, Part 2: Device with key generation”
    • “Protection profiles for secure signature creation device, Part 4: Extension for device with key generation and trusted communication with certificate generation application”
  • and the certification of the product according to article 30 (3) a) of Regulation (EU) No. 910 / 2014 by the certification body of SRC notified by the Federal Network Agency to the EU Commission.
DescriptionThe product “STARCOS 3.6 QES C1” is a qualified signature creation device (QSCD). The card is a dual interface card and has a contact-based and a contactless interface.

The product consists (among other things) of the semiconductor (IC) M7893 B11 from Infineon, the card operating system STARCOS 3.6 COS C1 and an application for the generation of qualified signatures.

The product is an electronic health professional card of the German e-health system. That means, besides the application for the generation of qualified electronic signatures, the card contains additional applications pursuant to requirements from Gematik on the filesystem of electronic health professional cards.

SRC confirms that the product “STARCOS 3.6 QES C1” of Giesecke+Devrient Mobile Security GmbH fulfills the requirements of annex II of Regulation (EU) No. 910/2014 (eIDAS-Regulation) for qualified signature creation devices.