The protection profile defines the security requirements for cryptographic modules used by trust service providers supporting electronic signing and sealing operations and authentication services. It includes optional support for protected backup of keys.
BS EN 419221-5 provides document management and overview information that is required to carry out protection profile registration. This document gives labelling and descriptive information necessary for registering the protection profile.
BS EN 419221-5 provides rationales to demonstrate that:
BS EN 419221-5 covers introductory material for the protection profile, the security problem definition. BS EN 419221-5 presents the assets, threats, organizational security policies and assumptions related to the target of evaluation (TOE).
BS EN 419221-5 on cryptographic module for trust services is useful for:
The protection profile aims at supporting trust services providers as identified by the proposed regulation of the European Parliament and of the Council on electronic identification and trust services for electronic transactions in the internal market (eIDAS) in Regulation (EU).
BS EN 419221-5 specifies a protection profile for cryptographic modules which is intended to suitable for use by trust service providers supporting electronic signature and electronic sealing
operations, certificate issuance and revocation, time stamp operations, and authentication services.
BS EN 419221-5 contains the security functional requirements and security assurance requirements for the TOE and the environment. PD CEN/TS 419221-5 guidelines help you to enable secure electronic signing services and authentication.
EN 419221-5:2018