![]() ![]() |
PP for a Secure Signature Creation Device - Part 6: Extension for device with key import and trusted communication with signature creation application
SSCD / Smart card and similar devices
Certification Body |
Bundesamt für Sicherheit in der Informationstechnik (BSI) |
Sponsor |
CEN/ISSS |
Point of Contact |
|
Certification ID |
|
PP Version |
|
CC Version |
3.1 Revision 4 |
CC Conformance Claim |
CC part 2 extended |
Certification status |
Certified 16 April 2013 |
Language |
English |
Summary |
The Protection Profile (PP) is established by CEN/ISSS for use by the European Commission in accordance with the procedure laid down in Article 9 of the Directive 1999/93/ec of the European parliament and of the council of 13 December 1999 on a Community framework for electronic signatures, also referred to as the 'Directive' in the remainder of the PP, as generally recognised standard for electronic-signature products in the Official Journal of the European Communities. The intent of the Protection Profile is to specify functional and assurance requirements defined in the Directive for a secure signature-creation device (SSCD) which is the target of evaluation (TOE). The Protection Profile describes core security requirements for a secure device that can import a signing key (signature-creation data, SCD) and operates to create electronic signatures with the imported key. The data to be signed or a unique representation thereof (DTBS/R) are sent via a trusted channel between the Signature Creation Application (SCA) and the SSCD. After an SSCD has imported a signing key, the corresponding public key (signature verification data, SVD) has to be provided as input to a certificate generation application (CGA). When operated in a secure environment for signature creation a signer may use an SSCD that fulfils only these core security requirements to create an advanced electronic signature. Security requirements for an SSCD used in other environments are not subject of this Protection Profile. |
Relation to other PPs |
This Protection Profile is strictly conforming to the PP for a Secure Signature Creation Device - Part 3: Device with key import. |