Utimaco HSM first to be Common Criteria EAL4+-certified according to eIDAS Protection Profile EN 419 221-5

Find us on the official Common Criteria portal!

  • Companies can now rely on Utimaco’s CryptoServer CP5 HSM to comply with European eIDAS regulation for digital signatures, seals and timestamps

  • Certification according to eIDAS Protection Profile EN 419 221-5 opens up new business opportunities for Utimaco and its partners

  • Dedicated Utimaco CryptoServer CP5 simulator available for evaluation and integration testing

Aachen, October 9th 2018 – Utimaco, a leading manufacturer of Hardware Security Module (HSM) technology, received the Common Criteria (CC) EAL4+ certification for its CryptoServer CP5 HSM based on the eIDAS Protection Profile EN 419 221-5. CryptoServer CP5 is the first HSM in the market with a CC certification based on this protection profile, making it a future-proof choice for eIDAS trust services. These include local and remote electronic signing and sealing, issuing of certificates, website authentication and timestamping. For application development and regression testing, Utimaco offers a dedicated CryptoServer CP5 HSM simulator to prospects and customers.

eIDAS Protection Profile EN 419 221-5 “Cryptographic Module for Trust Services”

The German hardware security specialist was engaged with and contributed to the creation of the security requirements and protection profiles within the Technical Committee 224, Working Group 17 of the European Committee for Standardization (CEN).

Protection profiles (PP) according to the Common Criteria certification scheme define the requirements for information technology security functions. The eIDAS Protection Profile EN 419 221-5 was certified by an accredited evaluation laboratory in late 2017 and approved by the EU member states earlier this year. With this Protection Profile, CEN standardizes security requirements for cryptographic modules being used as Qualified Signature Creation Device (QSCD) according to the eIDAS regulation.

 

Certified security for a wide range of use cases

The principal aim of the eIDAS regulation is to facilitate a true digital single market in Europe. The related services for electronic identification and trust services lend themselves to a variety of use cases. These include

  • strong website authentication and qualified certificates for sealing communications based on the new PSD2 regulation for the banking and financial services industry,
  • electronic seals for businesses to prove the origin and integrity of data and documents issued by them,

electronic signatures created either locally by the signatory, or remotely by a Trust Service Provider (TSP) on behalf of the signatory. In the latter case, this involves a Signature Activation Module (SAM) supported by a Hardware Security Module to build a Qualified Signature Creation Device for server signing.

New business opportunities with existing and new partners

For Utimaco business partners, this recent certification opens up a wide range of business opportunities, among which remote signing solutions. German-based IT service provider Bank-Verlag, together with software developer achelos and Utimaco, is developing a Signature Activation Module for banking applications. The service enables bank customers to generate online signatures remotely and speeds up and simplifies processes such as signing contracts, opening an account or issuing insurance policies. Ascertia, a global provider of digital signature creation and verification solutions, will be using the Utimaco CP5 HSM within its ADSS SAM Appliance, a remote QSCD currently undergoing CC EAL4+ certification against EN 419 241-2. There is great market interest in the powerful combination of Ascertia software working with Utimaco HSMs to deliver eIDAS compliant remote signing.

“With eIDAS, the European Commission is looking to stimulate the digital market in Europe,” says Malte Pollmann, CEO of Utimaco. “Being the first vendor certified according to Protection Profile EN 419 221-5, Utimaco helps pave the way for compliant and highly secure trust services. These ambitions are reflected in a number of current and upcoming partner projects.”

Proof of concept with the CryptoServer CP5 simulator

Several companies have already made use of the CryptoServer CP5 simulator for testing purposes in the past months. One of these is Halcom, a provider for digital banking solutions based in Slovenia. Having extensively tested the CP5 HSM’s functionalities with the help of the simulator, Halcom is now able to kick-start the implementation of CryptoServer CP5 into its solution and provide its customers with both secure and compliant trust services.

Luka Ribičič, Head of Halcom-CA, notes: “To be able to offer our clients eIDAS-compliant solutions, cooperating with a trustworthy HSM provider was crucial. The CryptoServer CP5 simulator as well as the affordable price point were key factors in our decision for Utimaco.”

Contact:
Utimaco
Alexandra Guennewig
Germanusstraße 4
52080 Aachen
Phone: +49 241 1696-200
E-Mail: pr@utimaco.com

Contact Agency:
Akima Media
Jan Gutheil
Garmischer Str. 8
80339 München
Phone: +49 89 959 18-0
E-Mail: utimaco@akima.de

About UTIMACO

UTIMACO is a global platform provider of trusted Cybersecurity and Compliance solutions and services with headquarters in Aachen (Germany) and Campbell, CA (USA). UTIMACO develops on-premises and cloud-based hardware security modules, solutions for key management, data protection and identity management as well as data intelligence solutions for regulated critical infrastructures and Public Warning Systems. UTIMACO is one of the world's leading manufacturers in its key market segments.

500+ employees around the globe create innovative solutions and services to protect data, identities and communication networks with responsibility for global customers and citizens. Customers and partners in many different industries value the reliability and long-term investment security of UTIMACO’s high-security products and solutions.

How can we help you?

Talk to one of our specialists and find out how Utimaco can support you today.
You have selected two different types of downloads, so you need to submit different forms which you can select via the two tabs.

Your download request(s):

    By submitting below form you will receive links for your selected downloads.

    Your download request(s):

      For this type of documents, your e-mail address needs to be verified. You will receive the links for your selected downloads via e-mail after submitting below form.

      Utimacoのダウンロードについて

      ダウンロードセクションをご覧ください。

      パンフレット、データシート、ホワイトペーパーなどのリソースからお選びいただけます。ほぼすべての資料を直接(ダウンロードボタンをクリックして)閲覧・保存することができます。

      一部の資料については、電子メールアドレスの確認が必要です。ボタンにはEメールのアイコンがあります。

      Download via e-mail

       

      ボタンをクリックすると、オンラインフォームが開きますので、必要事項をご記入の上、送信してください。このタイプのダウンロードをいくつか収集し、1つのフォームをすべてのダウンロードに対して送信するだけで、リンクを電子メールで受け取ることができます。現在のコレクションは空です。