EAL

Embed This Widget

Theme


      
    

Widget powered by . Free, no account required.

ความปลอดภัย

Evaluation Assurance Level -- a numerical rating (1-7) indicating the depth and rigor of a Common Criteria security evaluation.

Also known as: Evaluation Assurance Level

EAL

An Evaluation Assurance Level (EAL) is a numerical rating from 1 to 7 that indicates the depth, rigor, and formality of a Common Criteria security evaluation. Higher EAL levels require more extensive documentation, more thorough testing, and more formal design verification methods. In the smart card industry, EAL ratings determine whether a chip or card platform can be deployed in payment, government, and telecom applications.

EAL Scale

Level Name Description
EAL1 Functionally tested Basic independent testing
EAL2 Structurally tested Developer testing + vulnerability analysis
EAL3 Methodically tested and checked Design and test evidence
EAL4 Methodically designed, tested, and reviewed Full design documentation + independent testing
EAL5 Semi-formally designed and tested Formal modeling of security functions
EAL6 Semi-formally verified design and tested Formal modeling + structured implementation
EAL7 Formally verified design and tested Mathematical proof of security properties

EAL Augmentation (EAL4+, EAL5+)

Smart card certifications almost always use augmented EAL levels, denoted with a "+" suffix. The augmentation adds specific assurance components — most commonly AVA_VAN.5 (high resistance to attackers with high attack potential). This is critical for smart cards because the physical attack surface requires evaluation of resistance to SPA/DPA power analysis, fault injection, and other side-channel attacks.

For example, an EMV payment chip certified at "EAL4+ AVA_VAN.5" has undergone EAL4 design review plus high-level vulnerability analysis equivalent to EAL6 attack-resistance testing.

Industry Requirements

Application Typical EAL Mandated By
EMV payment chips EAL4+ EMVCo
ePassport chips EAL5+ ICAO 9303 + national PP
eID cards EAL5+ BSI TR-03110, national regulations
SIM/UICC EAL4+ to EAL6+ GSMA SAS
MULTOS OS EAL7 MULTOS consortium
FIPS 140 Level 3 EAL4+ (CC mapping) NIST

Evaluation Cost and Timeline

A typical smart card CC evaluation takes 6-18 months and costs $200K-$1M depending on the EAL level and complexity. Chip vendors (NXP, Infineon, Samsung) maintain composite evaluations covering the hardware IC, while card OS vendors (JavaCard implementations) certify the software platform separately. The final card product may receive a composite certificate combining both evaluations.

SIM Card Types Explained

เริ่มต้นใช้งาน

…Requires rework Not replaceable Common Criteria EAL EAL4+ typical EAL4+ (SoC-level) Choosing the Right Form…

Common Criteria for Smart Cards

ความปลอดภัย

…an independent, reproducible assurance that a card's EAL claims are genuine. Use the EAL Comparator to compare…

Smart Card Cryptography

ความปลอดภัย

…— is essential before selecting a card platform. Use the EAL Comparator to cross-reference algorithm support against…

Side-Channel Attacks and Countermeasures

ความปลอดภัย

…against these attacks at high attack potential. Use the EAL Comparator to identify which certified cards have passed…

Post-Quantum Cryptography for Smart Cards

ความปลอดภัย

…and Protection Profiles as they evolve for PQC, see EAL Comparator .

Smart Card Lifecycle Security

ความปลอดภัย

…the lifecycle. Security controls: - Wafer-level testing in EAL-certified cleanroom - CPLC (Card Production Life Cycle)…

MULTOS Application Development

การเขียนโปรแกรม

…Shareable Interface Object (SIO) Certification level EAL 5+ typical EAL4+ typical Language C / MEL assembly Java…

National eID Card Deployment

การใช้งานในอุตสาหกรรม

…signature certs) Common Criteria evaluation — typically EAL 4+ or EAL 5+ — is required for the chip and often for the…

Frequently Asked Questions

The smart card glossary is a comprehensive reference of technical terms, acronyms, and concepts used in smart card technology. It covers protocols (APDU, T=0, T=1), security (Common Criteria, EAL, HSM), hardware (SE, EEPROM, contact pad), and applications (EMV, ePassport, eSIM). It serves developers, product managers, and engineers.

Yes. SmartCardFYI provides glossary definitions in 15 languages including English, Korean, Japanese, Chinese, Spanish, Portuguese, Hindi, Arabic, French, Russian, German, Turkish, Vietnamese, Indonesian, and Thai.