Tamper resistance

Tamper resistance is a device's ability to withstand physical and logical attacks on its keys, certified via Common Criteria, FIPS 140-3, or EN 419221-5.

Tamper resistance is a device's ability to withstand physical and logical attacks on its secrets. It sits alongside two related properties that are not simply weaker versions of it: tamper evidence, the guarantee that an attack at least leaves visible traces, and tamper detection with response, where sensors trigger an active countermeasure such as key erasure. Detection and response is the stronger of the two ideas, not the lesser one: in FIPS 140-3 the tamper-active level 4 sits above the tamper-resistant level 3, because a device that notices an attack and destroys its keys defeats attacks that mere hardness only delays. No device is truly tamper proof; protection is always graded against a certain attack potential, for example expressed as an AVA_VAN rating. Certified HSMs combine all three: sensors and meshes that detect drilling, probing, temperature and voltage manipulation, and that erase (zeroize) the keys the moment intrusion is detected. Certification typically follows standards such as Common Criteria (attack potential, e.g. AVA_VAN.5), FIPS 140-3 physical security levels, or EN 419221-5 for HSMs used in qualified trust services.

The same thinking scales down to smartcards and to the WSCD behind the EUDI Wallet, which the reference framework defines by this property rather than by a chip: a tamper-resistant device providing the environment in which the wallet's critical operations run. That leaves room for more than one architecture - a secure element in the phone, an external smartcard, or a remote HSM - so "the WSCD" is not a synonym for "secure element".

Under eIDAS, Annex II states what a QSCD has to achieve without naming hardware; certification under Article 30 is where that becomes a device, and in practice that means certified tamper-resistant hardware. Since the EUCC scheme took over from the national Common Criteria schemes, that certification runs through it. Either way, this is what makes sole control over signing keys credible in law.

Frequently asked questions

Back to glossary