QSCD | Giesecke+Devrient Mobile Security GmbH | STARCOS 3.5 ID GCC C1R

Type of certificationQSCD | Certi­fi­cation of qualified signature- and seal creation devices
SRC certificate regis­tration numberSRC.00014.TE.02.2012
Valid untilDecember 31, 2023
Certificate holderGiesecke+Devrient Mobile Security GmbH
Certified productSTARCOS 3.5 ID GCC C1R
Test method

According to the regula­tions of SigG and SigV, the confir­mation was performed on the basis of a Common Criteria Evalu­ation according to the Protection Profiles “Protection profile for secure signature creation device, Part 2: Device with key gener­ation” and “Protection Profile — Electronic Identity Card (ID_Card PP)”. The evalu­ation was performed with Evalu­ation Assurance Level (EAL) 4+ and assuming an high attack potential (augmen­tation AVA_VAN.5).

The audit includes
  • the Common Criteria Evalu­ation of the product “STARCOS 3.5 ID GCC C1R” according to the following Protection Profiles with Evalu­ation Assurance Level (EAL) 4+ (EAL 4 with the augmen­tation packages AVA_VAN.5, ATE_DPT.2 and ALC_DVS.2):
    • “Protection profiles for secure signature creation device, Part 2: Device with key generation”
    • “Protection Profile — Electronic Identity Card (ID_Card PP)”
  • the confir­mation of the product according to article 15 paragraph 7 sentence 1, article 17 paragraph 1 Signaturgesetz (SigG) as well as article 15 paragraphs 1 and 4, article 11 paragraph 3 Signaturverordnung (SigV) by the confir­mation body of SRC accredited by Bundesnetzagentur,
  • two amend­ments to extend the confirmation: 
    • Amendment 1: Adaptation of the require­ments of the signature key or card holder
    • Amendment 2: Supple­men­tation of infor­mation on the manufac­turer, extension of the period of validity.

In accor­dance with the transi­tional measures of article 51, paragraph 1 of Regulation (EU) No. 910/2014, the product can be considered as qualified signature creation device (QSCD) in the sense given in this regulation.

Description

The product “STARCOS 3.5 ID GCC C1R” is a secure signature creation device (SSCD) according to SigG and SigV. The card is a new German (electronic) national identity card and has a contactless interface.

The product consists (among other things) of the semicon­ductor (IC) P5CD128V0A from NXP, the card operating system STARCOS 3.5 and an appli­cation for gener­ating qualified signatures.

SRC confirms that the product “STARCOS 3.5 ID GCC C1R” of Giesecke+Devrient Mobile Security GmbH fulfills the require­ments of article 17 paragraphs 1 and 3 number 1 SigG and article 15 paragraphs 1 and 4, annex 1, I, 1.1 to 1.3 SigV.

In accor­dance with the transi­tional measures of article 51, paragraph 1 of Regulation (EU) No. 910/2014, the product can be considered as qualified signature creation device (QSCD) in the sense given in this regulation.