ARCHIVED CERTIFIED PRODUCTS AND SYSTEMS

List of Archived Certified Products and Systems.

MyCC = Products certified by MyCC Scheme before recognized as CCRA Authorizing Participants.

CCRA = Products certified by MyCC Scheme after recognized as CCRA Authorizing Participants.

Project ID
C006
Product Name and Version
MCS Small Machine Operating System - Common Criteria (SMOSCC)
Product Sponsor / Developer
MCS Microsystems Sdn Bhd
Category
ICs, Smart Cards and Smart Card-Related Devices and Systems
Product Type
Multi-application smart card integrated circuit (IC) operating system
Scope

Small Machine Operating System – Common Criteria or SMOSCC version 1.0.0 is a multi-application smart card integrated circuit (IC) operating system purpose-designed for national ID applications which also serves as an ideal platform for national e-passport. SMOSCC from MCS Microsystem Sdn Bhd is the Target of Evaluation (TOE) for Evaluation Assurance Level (EAL) 4 augmented with ALC_DVS.2 and ALC_FLR.1 evaluation.

SMOSCC simultaneously supports multiple custom applets with custom instruction sets and data structures from several agencies on a single smart card, limited only by the IC specification. Consider a national ID card with a host of other functions like driving license, PKI token, e-purse, and frequent traveller which will simplify the cardholder’s dealings with various private and public agencies.

The TOE includes an instruction agnostic virtual machine environment capable of providing a portable interface for smart card applications. It also provides several libraries providing hardware IC services such as cryptography to third party applications. The TOE implements the following components that reside upon hardware platform IC as mention below:

  • Small Machine - To implement a virtual machine to run loaded application and runtime API.
  • Early Lifecycle Manager - Used during the first phases of the TOEs lifecycle in order to commence the setup of the TOE.
  • SMOS Card Manager - Used once the TOE is an initialised state and manages the installation and removal of loaded applications and the SMOS card lifecycle.
  • Hardware Abstraction Layer - To provide access to low level IC routines.

The security function within the scope of TOE includes:

  • Application Firewall - To prevent applications from interfering with the execution and private data of other loaded applications and the operation of the TOE itself.
  • Application and Platform Management - To provide functionality for managing the secure installation/removal of loaded applications and enforcing its lifecycle.
  • Cryptographic Management - To utilise cryptographic mechanism in order to enforce the remaining TOE security functions.
  • TOE Self Protection and Testing - To provide a secure environment on which to host loaded applications. The TOE protects itself from physical tampering attacks and hardware failures by working in conjunction with its underlying hardware platform.

The TOE runs on a Common Criteria certified smart card IC hardware platform specified in Section 1.4 of the Security Target (Ref [6]). However, the underlying IC hardware platform, card acceptance devices and loaded applications (applets) are not part of the TOE. It communicates with card acceptance devices which exist within the environment, and supports ISO/IEC 7816 contact based, and ISO/IEC 14443 contactless based card acceptance devices.

Product Sponsor / Developer Contact Details

HW Chew

4th Floor, IRIS Smart Technology Complex,
Technology Park Malaysia, Bukit Jalil,

57000 Kuala Lumpur
MALAYSIA

URL: http://www.mcs-group.com.my
Email: hwchew@mcs-group.com.my
Phone: +603 8996 9168
Fax: +603 8996 3168

Assurance Level
EAL4+ ALC_DVS.2 ALC_FLR.1
Certificate Date
25-09-2012
Expiry Date
25-09-2017
Recognized By
MyCC
Maintenance

NA

Status
Archive

CONTACT US

Information Security Certification Body (ISCB)
CyberSecurity Malaysia,
Level 7 Tower 1, Menara Cyber Axis,
Jalan Impact, 63000 Cyberjaya,
Selangor Darul Ehsan, Malaysia.

Monday - Friday 08:30-17:30 MYT (Note: closed on Saturday, Sunday and Public Holiday)

T: +603 - 8800 7999
F: +603 - 8008 7000

EMAIL US

For certification enquiry:
  certification[at]cybersecurity.my