The products with digital elements in the scope of this document are the platforms of smartcards and similar devices including secure elements, which consist of a tamper-resistant MCU/MPU and optionally an application environment or operating system. Platforms are designed to store and process sensitive data, and to protect it against physical and logical attacks by attackers with significant resources and skills, at AVA_VAN.4 (moderate attack potential) or AVA_VAN.5 (high attack potential) levels. Although platforms do not delegate data processing to remote entities, these can be involved in operations such as software update, configuration or key provisioning. The platform ensures the authentication of the remote entities before receiving/sending sensitive information and ensures this information is protected during the exchange. Platforms are intended for final products including, but not limited to, electronic identity cards, removable UICCs, eUICC, payment cards, physical access cards, digital tachograph cards or wrist bands with integrated payment secure elements, trust anchors in connected digital products and critical IT systems. This document defines technical requirements for platforms, which meet the essential requirements defined in Regulation (EU) 2024/2847 to the extent described in Annex ZZ. It also defines the methods for assessing the technical requirements. The expression of the technical requirements and the assessment methods use the Common Criteria (CC) formalism defined in the EN ISO/IEC 15408 series and EN ISO/IEC 18045:2023 supplemented by the EUCC state-of-the-art documents for the technical domain smart cards and similar devices. This document covers platforms conformant with the Protection Profiles (PPs) PP0084, PP0117, PP0104 and PP TPM, and identifies the gaps of these specifications against the CRA essential requirements. In this document, PP0104 also refers to the PP0104-based PP-Configuration 0107. The evaluation of platforms against PP0084, PP0117, PP0104 or PP TPM plus the applicable additional technical requirements which cover their gaps allow to demonstrate conformance with the CRA essential requirements. The technical requirements and the mappings against PP0084, PP0117, PP0104 and PP TPM are defined in Clause 7 and Annex B, respectively. This document also covers platforms consisting of a hardware layer and either an application environment, e.g. Java Card platform, or firmware/software. Annex C contains an informative mapping of Java Card platforms towards PP0099. Platforms can have discrete, integrated or embedded form factors, and employ technologies such as integrated circuits, programmable macros or system-in-package or system-on-chip. These do not affect the requirements or the assessment methods. Unless specified, clauses apply to all platforms, from pure hardware to platforms consisting of hardware, firmware and/or software. Platforms are accompanied by guidance which contains all the requirements and recommendations for the secure integration of the platform into further intermediate or final products and the secure usage of the platform by the external entities. The guidance covers all the non-platform aspects which can impact the security of the platform assets. The applications stored and/or running on the platforms, which are an integral part of the final products, are outside the scope of this document. prEN 18330:2026 applies to products composed of a platform and a set of applications.

  • Draft
    144 pages
    English language
    e-Library read for
    1 day