QSCD | T-Systems International GmbH | TCOS Health Professional Card Version 2.0 Release 1/SLE78CLX1440P



Type of certificationQSCD | Certification of qualified signature and seal creation devices
SRC certificate registration numberSRC.00023.TE.04.2016
Valid fromApril 18, 2016
Valid untilDecember 31, 2022
Certificate holderT-Systems International GmbH
Certified productTCOS Health Professional Card Version 2.0 Release 1/SLE78CLX1440P
Test methodAccording to the regulations of SigG and SigV, the confirmation was performed on basis of a Common Criteria Evaluation against the Protection Profiles “Protection profiles for secure signature creation device, Part 2: Device with key generation” and “Protection profiles for secure signature creation device, Part 4: Extension for device with key generation and trusted communication with certificate generation application”. The evaluation was performed with Evaluation Assurance Level (EAL) 4+ and assuming an high attack potential (augmentation AVA_VAN.5).
The audit includes
  • the Common Criteria Evaluation of the product “TCOS Identity Card Version 1.1 Release 2/P60D144” against the following Protection Profiles with Evaluation Assurance Level (EAL) 4+ (EAL 4 with the augmentation packages AVA_VAN.5, ATE_DPT.2 and ALC_DVS.2):
    • “Protection profiles for secure signature creation device, Part 2: Device with key generation”
    • “Protection profiles for secure signature creation device, Part 4: Extension for device with key generation and trusted communication with certificate generation application” and
  • the confirmation of the product according to article 15 paragraph 7 sentence 1, article 17 paragraph 1 Signaturgesetz (SigG) as well as article 15 paragraphs 1 and 4, article 11 paragraph 3 Signaturverordnung (SigV) by the confirmation body of SRC that is accredited by Bundesnetzagentur.

In accordance with the transitional measures of article 51, paragraph 1 of Regulation (EU) No. 910/2014, the product can be considered as qualified signature creation device (QSCD) in the sense given in this Regulation.

DescriptionThe product “TCOS Health Professional Card Version 2.0 Release 1/SLE78CLX1440P” is a secure signature creation device (SSCD) in accordance with SigG and SigV. The card is a dual interface card and has a contact-based and a contactless interface.

The product consists (among other things) of the semiconductor (IC) SLE78CLX1440P A11 from Infineon, the card operating system TCOS FlexCert 2.0 Release 1/SLE78CLX1440P and an application for the generation of qualified signatures.

The product is an electronic health professional card of the German e-health system. That means, besides the application for the generation of qualified electronic signatures, the card contains additional applications pursuant to requirements from Gematik on the filesystem of electronic health professional cards.

SRC confirms that the product “TCOS Health Professional Card Version 2.0 Release 1/SLE78CLX1440P” of T-Systems International GmbH fulfills the requirements of article 17 paragraph 1 and paragraph 3 number 1 SigG and article 15 paragraph 1 and 4, annex 1, I, 1.1 to 1.3 SigV.

In accordance with the transitional measures of article 51, paragraph 1 of Regulation (EU) No. 910/2014, the product can be considered as qualified signature creation device (QSCD) in the sense given in this Regulation.