Press Releases

GlobalPlatform helps Secure Element ecosystem demonstrate security & regulatory compliance

November 29, 2021

Posted by: Anasia D'mello

Gil Bernabeu of GlobalPlatform

November 29, 2021 – GlobalPlatform, the standard for secure digital services and devices, has certified its Secure Element (SE) Protection Profile (PP) with the international standard for computer security certification, Common Criteria (CC).

The document is the latest update to GlobalPlatform’s Security Certification Program. It will make it quicker and easier for stakeholders across industries to validate and compare security features, protect applications and data against high-profile attacks and comply with evolving IoT and cybersecurity regulations.

Since 2000 GlobalPlatform has been the de-facto standard for secure element technologies. Today, there are over 50 billion GlobalPlatform-certified SEs in-market; equipping solutions like mobile phones, IoT devices, banking cards and eID documents, with a tamper-resistant hardware platform to securely host applications and store confidential data.

As the use of digital services continues to proliferate, the newly released PP will address the need for consistent and verifiable security. It offers a simple framework for:

“Smart cards used to host one or just a few apps,” comments Gil Bernabeu, technical director of GlobalPlatform. “Now, SEs support multiple domains with many apps and increasingly innovative ways of connecting to them and using the secure services they offer. We need secure, confidential ways to remotely load and manage apps without them interfering with each other. Our specifications and Protection Profiles are the vehicle to enable this, fostering trust and collaboration across the industry, and ensuring the same stringent level of security across different deployment models.”

Thanks to a modular structure, the PP enables the evaluation of different SE use cases and form factors. This includes smart card SEs including payment, SIM cards or ID documents, to embedded SEs in smartphones and IoT devices, and also advanced uses cases available on integrated form factors which have emerged to address the security requirements of connected device designs.

To enable simple access to the secure services offered by SEs, like signature or user authentication for consumer payment and identity use cases, as well as Secure Boot or attestation for device-based use cases, GlobalPlatform has selected a security assurance level of EAL4+ augmented with ALC_DVS.2 (sufficiency of security measures) and AVA_VAN.5 (advanced methodical vulnerability analysis).

This assures stakeholders including Mobile Network Operators (MNOs), application developers, IoT cloud platforms and service providers that their critical assets loaded on a GlobalPlatform-certified SE are protected from complex attacks.

The specification is available for free download for use when building, certifying and selecting SE products. To learn more visit the website.

Comment on this article below or via Twitter @IoTGN