Utimaco HSM first to be Common Criteria EAL4+-certified according to eIDAS Protection Profile EN 419 221-5

Find us on the official Common Criteria portal!

  • Companies can now rely on Utimaco’s CryptoServer CP5 HSM to comply with European eIDAS regulation for digital signatures, seals and timestamps

  • Certification according to eIDAS Protection Profile EN 419 221-5 opens up new business opportunities for Utimaco and its partners

  • Dedicated Utimaco CryptoServer CP5 simulator available for evaluation and integration testing

Aachen, October 9th 2018 – Utimaco, a leading manufacturer of Hardware Security Module (HSM) technology, received the Common Criteria (CC) EAL4+ certification for its CryptoServer CP5 HSM based on the eIDAS Protection Profile EN 419 221-5. CryptoServer CP5 is the first HSM in the market with a CC certification based on this protection profile, making it a future-proof choice for eIDAS trust services. These include local and remote electronic signing and sealing, issuing of certificates, website authentication and timestamping. For application development and regression testing, Utimaco offers a dedicated CryptoServer CP5 HSM simulator to prospects and customers.

eIDAS Protection Profile EN 419 221-5 “Cryptographic Module for Trust Services”

The German hardware security specialist was engaged with and contributed to the creation of the security requirements and protection profiles within the Technical Committee 224, Working Group 17 of the European Committee for Standardization (CEN).

Protection profiles (PP) according to the Common Criteria certification scheme define the requirements for information technology security functions. The eIDAS Protection Profile EN 419 221-5 was certified by an accredited evaluation laboratory in late 2017 and approved by the EU member states earlier this year. With this Protection Profile, CEN standardizes security requirements for cryptographic modules being used as Qualified Signature Creation Device (QSCD) according to the eIDAS regulation.


Certified security for a wide range of use cases

The principal aim of the eIDAS regulation is to facilitate a true digital single market in Europe. The related services for electronic identification and trust services lend themselves to a variety of use cases. These include

  • strong website authentication and qualified certificates for sealing communications based on the new PSD2 regulation for the banking and financial services industry,
  • electronic seals for businesses to prove the origin and integrity of data and documents issued by them,

electronic signatures created either locally by the signatory, or remotely by a Trust Service Provider (TSP) on behalf of the signatory. In the latter case, this involves a Signature Activation Module (SAM) supported by a Hardware Security Module to build a Qualified Signature Creation Device for server signing.

New business opportunities with existing and new partners

For Utimaco business partners, this recent certification opens up a wide range of business opportunities, among which remote signing solutions. German-based IT service provider Bank-Verlag, together with software developer achelos and Utimaco, is developing a Signature Activation Module for banking applications. The service enables bank customers to generate online signatures remotely and speeds up and simplifies processes such as signing contracts, opening an account or issuing insurance policies. Ascertia, a global provider of digital signature creation and verification solutions, will be using the Utimaco CP5 HSM within its ADSS SAM Appliance, a remote QSCD currently undergoing CC EAL4+ certification against EN 419 241-2. There is great market interest in the powerful combination of Ascertia software working with Utimaco HSMs to deliver eIDAS compliant remote signing.

“With eIDAS, the European Commission is looking to stimulate the digital market in Europe,” says Malte Pollmann, CEO of Utimaco. “Being the first vendor certified according to Protection Profile EN 419 221-5, Utimaco helps pave the way for compliant and highly secure trust services. These ambitions are reflected in a number of current and upcoming partner projects.”

Proof of concept with the CryptoServer CP5 simulator

Several companies have already made use of the CryptoServer CP5 simulator for testing purposes in the past months. One of these is Halcom, a provider for digital banking solutions based in Slovenia. Having extensively tested the CP5 HSM’s functionalities with the help of the simulator, Halcom is now able to kick-start the implementation of CryptoServer CP5 into its solution and provide its customers with both secure and compliant trust services.

Luka Ribičič, Head of Halcom-CA, notes: “To be able to offer our clients eIDAS-compliant solutions, cooperating with a trustworthy HSM provider was crucial. The CryptoServer CP5 simulator as well as the affordable price point were key factors in our decision for Utimaco.”

Alexandra Guennewig
Germanusstraße 4
52080 Aachen
Phone: +49 241 1696-200
E-Mail: pr@utimaco.com

Contact Agency:
Akima Media
Jan Gutheil
Garmischer Str. 8
80339 München
Phone: +49 89 959 18-0
E-Mail: utimaco@akima.de


UTIMACO is a global platform provider of trusted Cybersecurity and Compliance solutions and services with headquarters in Aachen (Germany) and Campbell, CA (USA). UTIMACO develops on-premises and cloud-based hardware security modules, solutions for key management, data protection and identity management as well as data intelligence solutions for regulated critical infrastructures and Public Warning Systems. UTIMACO is one of the world's leading manufacturers in its key market segments.

500+ employees around the globe create innovative solutions and services to protect data, identities and communication networks with responsibility for global customers and citizens. Customers and partners in many different industries value the reliability and long-term investment security of UTIMACO’s high-security products and solutions.

¿En qué podemos ayudarle?

Hable con uno de nuestros especialistas y descubra cómo Utimaco puede ayudarle hoy mismo.
Ha seleccionado dos tipos diferentes de Download, por lo que necesita presentar formularios diferentes que puede seleccionar a través de las dos pestañas.

Su(s) solicitud(es) de Download:

    Al enviar el siguiente formulario, recibirá enlaces a las descargas seleccionadas.

    Su(s) solicitud(es) de Download:

      Para este tipo de documentos, es necesario verificar su dirección de correo electrónico. Recibirá los enlaces a las Download seleccionadas por correo electrónico después de enviar el siguiente formulario.

      Descargas de Utimaco

      Visite nuestra sección de descargas y seleccione recursos como folletos, fichas técnicas, libros blancos y mucho más. Puede ver y guardar casi todos ellos directamente (pulsando el botón de descarga).

      Para algunos documentos, es necesario verificar su dirección de correo electrónico. El botón contiene un icono de correo electrónico.

      Download via e-mail

      Al hacer clic en dicho botón se abre un formulario en línea que le rogamos rellene y envíe. Puede recopilar varias descargas de este tipo y recibir los enlaces por correo electrónico simplemente enviando un formulario para todas ellas. Su colección actual está vacía.