QSCD | idemia Germany GmbH | IDEMIA_HC_Germany_NEO_G2.1_HBA, V1

Certificate SRC.00036.QSCD.09.2020 Certification Report SRC.00036.QSCD.09.2020 Certificate SRC.00036.QSCD.09.2020 // Amendment 1 Certification Report SRC.00036.QSCD.09.2020 // Amendment 1 Certificate SRC.00036.QSCD.09.2020 // Amendment 2 Certification Report SRC.00036.QSCD.09.2020 // Amendment 2
Type of certificationQSCD | Certification of qualified signature and seal creation devices
SRC certificate registration numberSRC.00036.QSCD.09.2020
Valid from29 September 2020
Valid until31 December 2027
Certificate holderidemia Germany GmbH
Certified productIdemia_HC_Germany_NEO_G2.1_HBA, V1
Test methodAccording to article 30 (3) a) of Regulation (EU) No. 910/2014, the certification was done on basis of a Common Criteria Evaluation against the Protection Profiles EN 419211-2:2013, EN 419211-4:2013 and EN 419211-5:2013 which are listed in the Commission Implementing Decision (EU) 2016/650 of 25 April 2016.

The evaluation was performed with Evaluation Assurance Level (EAL) 4+ and assuming an high attack potential (augmentation AVA_VAN.5).

The audit includes
  • the Common Criteria Evaluation of the product “Idemia_HC_Germany_NEO_G.2.1_HBA, V1” against the following Protection Profiles with Evaluation Assurance Level (EAL) 4+ (EAL 4 with the augmentation packages AVA_VAN.5, ATE_DPT.2 and ALC_DVS.2):
    • “Protection profiles for secure signature creation device, Part 2: Device with key generation”,
    • “Protection profiles for secure signature creation device, Part 4: Extension for device with key generation and trusted communication with certificate generation application”,
    • “Protection profiles for secure signature creation device – Part 5: Extension for device with key generation and trusted channel to signature creation application”.
  • the certification of the product according to article 30 (3) a) of Regulation (EU) No. 910 / 2014 by the certification body of SRC notified by the Federal Network Agency to the EU Commission
  • as well as two amendments for the certification:
    • Amendment 1: (non security impacting) changes to the software of the QSCD.
    • Amendment 2: extension of the validity period of the certification from the end of 2025 to the end of 2027 with the restriction that RSA keys with a key lenghts of 2.048 bit may continue to be used only until the end of 2025.
DescriptionThe product “Idemia_HC_Germany_NEO_G2.1_HBA, V1” is a qualified signature device (QSCD). The card is a dual interface card and has a contact-based and a contactless interface.

The product consists (among other things) of the semiconductor (IC) family H13 from Infineon, the card operating system IDEMIA_HC_GERMANY_NEO_G2.1_COS, V1 and an application for the generation of qualified signatures.

The product is an electronic health professional card of the German e-health system. That means, besides the application for the generation of qualified electronic signatures, the card contains additional applications pursuant to requirements from Gematik on the filesystem of electronic health professional cards.

SRC confirms that the product “Idemia_HC_Germany_NEO_G2.1_HBA, V1” of idemia Germany GmbH fulfills the requirements of annex II of Regulation (EU) No. 910/2014 (eIDAS-Regulation) for qualified signature creation devices.