7 | 7 CENTRO CRIPTOLÔGICO NACIONAL CERTIFICATE CCN-CC-015/2016 KONA2 D2320N ePassport [EAC configuration], v 01 rev 03 patch 00 Type of product Smartcard Operating System Conformance of functionality PP Conformance functionality Protection Profile Conformance Common Criteria Protection Profile Machine Readable Travel Document with “ICAO Application”, Extended Access Control version 1.10, 25th March 2009. Evaluation Facility APPLUS LGAI TECHNOLOGICAL CENTER S.A. Certification Report CCN-CC/2015-30/ INF-1653 Expiration date See Certification Report Pursuant to the authority vested in me under Act 11/2002 regulating the National Intelligence Centre, and under Article 1 and Article 2.2.c of Royal Decree 421/2004 of March 12th regulating the National Cryptologic Centre, | hereby: Certify that the security of KONA2 D2320N ePassport [EAC configuration], version 01 revision 03 patch 00, developed by Kona | Co., Ltd., 8F EXCON Venture-Tower, 3 Eunhaeng-Ro, Yeongdeungpo-Gu, 150-872 Seoul, Korea, has been evaluated using the “Common Methodology for Information Technology Security Evaluation”, version 3.1 R4 and the “Common Criteria for Information Technology Security Evaluation’, and it has met the requirements of its Security Target identified as “SP-06-02 KONA2 D2320N ePassport EAC Security Target, version 1, revision 7. 2016-05-21.”, for evaluation assurance level EAL5 augmented by AVA_VAN.5 and ALC_DVS.2. Madrid) June 16" 2016 Secretary of State Director Felix Sanz Roldan This certificate, its scope and validity are subject to the terms, conditions and requirements specified in the “Reglamento de Evaluaciön y Certificaciön de la Seguridad de las T.I.C.” at PRE/2740/2007, September 19th. The above-mentioned Security Target and Certification Report are available at the National Cryptologic Centre. CRA recognition for components Up to EAL 2 and ALC_FLR only The IT product identified in this certificate has been evaluated at an accredited and licensed/approved evaluation facility using the Common Methodology for IT Security Evaluation, version 3.1.R4 and CC Supporting Documents as listed in the Certification Report, for conformance to the Common Criteria for IT Security Evaluation, version 3.1.R4. This certificate applies only to the specific version and release of the product in its evaluated configuration and in conjunction with the complete Certification Report. The evaluation has been conducted in accordance with the provisions of the Spanish IT Security Evaluation and Certification Scheme, PRE/2740/2007 September the 19th, and the conclusions of the evaluation facility in the evaluation technical report are consistent with the evidence adduced. This certificate is not an endorsement of the IT product by the Spanish Scheme or by any other organisation that recognises or gives effect to this certificate, and no warranty of the IT product by the Spanish Scheme or by any other organisation that recognises or gives effect to this certificate, is either expressed or implied.