BSI certificate 3S in SoC – first step for cell phone e-SIM

B2B Cyber ​​Security ShortNews

Share post

The German Federal Office for Information Security (BSI) has certified the "Secure Sub-System in System-on-Chip (3S in SoC) Protection Profile" according to Common Criteria (ISO/IEC 15408). With the certification identifier BSI-CC-PP-0117, mobile end devices such as smartphones have a security platform - for example for e-SIM.

The protection profile was developed by the chip manufacturers and test centers organized in the European industry association EUROSMART: Brightsight, Deutsche Telekom Security, Giesecke+Devrient, Infineon, Internet of Trust, JTSec, NXP, Qualcomm, Samsung, STMicroelectronics, Synopsys, Thales, Tiempo-Secure, TrustCB, TÜViT, Winbond and Xilinx.

Secure Sub-System in a System-on-Chip

It specifies requirements for secure chip platforms that are integrated into larger ICs as a subsystem (Secure Sub-System in a System-on-Chip). The manufacturer of such a chip platform can now apply to the BSI for product certification with reference to this protection profile. PP-0117 builds on and extends the protection profile BSI-CC-PP-0084-2014, which is established as the de facto standard for secure chip platforms.

Mobile devices as a secure platform

With the development of PP-0117, the industry follows the trend of concentrating more and more functions on a single chip (system on a chip). While security elements have so far mostly been implemented as individual smart card chips - such as SIM cards - in the future they will increasingly be an integral part of larger chips, such as those built into smartphones, for example.

Mobile end devices such as smartphones, smartwatches or tablets that are equipped with a security element certified according to PP-0117 have a secure execution platform for a wide variety of security applications. These include, for example, eSIM, eID, ticketing or authentication.

More at BSI.Bund.de

 


About the Federal Office for Information Security (BSI)

The Federal Office for Information Security (BSI) is the federal cyber security authority and the creator of secure digitization in Germany. The guiding principle: As the federal cyber security authority, the BSI designs information security in digitization through prevention, detection and reaction for the state, economy and society.


 

Matching articles on the topic

Report: 40 percent more phishing worldwide

The current spam and phishing report from Kaspersky for 2023 speaks for itself: users in Germany are after ➡ Read more

Cybersecurity platform with protection for 5G environments

Cybersecurity specialist Trend Micro unveils its platform-based approach to protecting organizations' ever-expanding attack surface, including securing ➡ Read more

BSI sets minimum standards for web browsers

The BSI has revised the minimum standard for web browsers for administration and published version 3.0. You can remember that ➡ Read more

Stealth malware targets European companies

Hackers are attacking many companies across Europe with stealth malware. ESET researchers have reported a dramatic increase in so-called AceCryptor attacks via ➡ Read more

IT security: Basis for LockBit 4.0 defused

Trend Micro, working with the UK's National Crime Agency (NCA), analyzed the unpublished version that was in development ➡ Read more

MDR and XDR via Google Workspace

Whether in a cafe, airport terminal or home office – employees work in many places. However, this development also brings challenges ➡ Read more

Test: Security software for endpoints and individual PCs

The latest test results from the AV-TEST laboratory show very good performance of 16 established protection solutions for Windows ➡ Read more

FBI: Internet Crime Report counts $12,5 billion in damage 

The FBI's Internet Crime Complaint Center (IC3) has released its 2023 Internet Crime Report, which includes information from over 880.000 ➡ Read more