Search Legislation

Commission Implementing Regulation (EU) 2016/799Show full title

Commission Implementing Regulation (EU) 2016/799 of 18 March 2016 implementing Regulation (EU) No 165/2014 of the European Parliament and of the Council laying down the requirements for the construction, testing, installation, operation and repair of tachographs and their components (Text with EEA relevance)

 Help about what version

What Version

 Help about UK-EU Regulation

Legislation originating from the EU

When the UK left the EU, legislation.gov.uk published EU legislation that had been published by the EU up to IP completion day (31 December 2020 11.00 p.m.). On legislation.gov.uk, these items of legislation are kept up-to-date with any amendments made by the UK since then.

Close

This item of legislation originated from the EU

Legislation.gov.uk publishes the UK version. EUR-Lex publishes the EU version. The EU Exit Web Archive holds a snapshot of EUR-Lex’s version from IP completion day (31 December 2020 11.00 p.m.).

Status:

This is the original version as it was originally adopted in the EU.
This legislation may since have been updated - see the latest available (revised) version

8.CRYPTOGRAPHIC SYSTEMS AND ALGORITHMS

8.1. Cryptographic Systems
CSM_38Vehicle units and tachograph cards shall use an elliptic curve-based public-key cryptographic system to provide the following security services:
  • mutual authentication between a vehicle unit and a card,

  • agreement of AES session keys between a vehicle unit and a card,

  • ensuring the authenticity, integrity and non-repudiation of data downloaded from vehicle units or tachograph cards to external media.

CSM_39Vehicle units and external GNSS facilities shall use an elliptic curve-based public-key cryptographic system to provide the following security services:
  • coupling of a vehicle unit and an external GNSS facility,

  • mutual authentication between a vehicle unit and an external GNSS facility,

  • agreement of an AES session key between a vehicle unit and an external GNSS facility.

CSM_40Vehicle units and tachograph cards shall use an AES-based symmetric cryptographic system to provide the following security services:
  • ensuring authenticity and integrity of data exchanged between a vehicle unit and a tachograph card,

  • where applicable, ensuring confidentiality of data exchanged between a vehicle unit and a tachograph card.

CSM_41Vehicle units and external GNSS facilities shall use an AES-based symmetric cryptographic system to provide the following security services:
  • ensuring authenticity and integrity of data exchanged between a vehicle unit and an external GNSS facility.

CSM_42Vehicle units and motion sensors shall use an AES-based symmetric cryptographic system to provide the following security services:
  • pairing of a vehicle unit and a motion sensor,

  • mutual authentication between a vehicle unit and a motion sensor,

  • ensuring confidentiality of data exchanged between a vehicle unit and a motion sensor.

CSM_43Vehicle units and control cards shall use an AES-based symmetric cryptographic system to provide the following security services on the remote communication interface:
  • ensuring confidentiality, authenticity and integrity of data transmitted from a vehicle unit to a control card.

Notes:
Properly speaking, data is transmitted from a vehicle unit to a remote interrogator under the control of a control officer, using a remote communication facility that may be internal or external to the VU, see Appendix 14. However, the remote interrogator sends the received data to a control card for decryption and validation of authenticity. From a security point of view, the remote communication facility and the remote interrogator are fully transparent.
A workshop card offers the same security services for the DSRC interface as a control card does. This allows a workshop to validate the proper functioning of the remote communication interface of a VU, including security. Please refer to section 9.2.2 for more information.
8.2. Cryptographic Algorithms
8.2.1 Symmetric Algorithms
CSM_44Vehicle units, tachograph cards, motion sensors and external GNSS facilities shall support the AES algorithm as defined in [AES], with key lengths of 128, 192 and 256 bits.
8.2.2 Asymmetric Algorithms and Standardized Domain Parameters
CSM_45Vehicle units, tachograph cards and external GNSS facilities shall support elliptic curve cryptography with a key size of 256, 384 and 512/521 bits.
CSM_46Vehicle units, tachograph cards and external GNSS facilities shall support the ECDSA signing algorithm, as specified in [DSS].
CSM_47Vehicle units, tachograph cards and external GNSS facilities shall support the ECKA-EG key agreement algorithm, as specified in [TR 03111].
CSM_48Vehicle units, tachograph cards and external GNSS facilities shall support all standardized domain parameters specified in Table 1 below for elliptic curve cryptography.
Table 1
Standardized domain parameters
NameSize (bits)ReferenceObject identifier
NIST P-256256[DSS], [RFC 5480]
BrainpoolP256r1256[RFC 5639]
NIST P-384384[DSS], [RFC 5480]
BrainpoolP384r1384[RFC 5639]
BrainpoolP512r1512[RFC 5639]
NIST P-521521[DSS], [RFC 5480]

Note: the object identifiers mentioned in the last column of Table 1 are specified in [RFC 5639] for the Brainpool curves and in [RFC 5480] for the NIST curves.

8.2.3 Hashing algorithms
CSM_49Vehicle units and tachograph cards shall support the SHA-256, SHA-384 and SHA-512 algorithms specified in [SHS].
8.2.4 Cipher Suites
CSM_50In case a symmetric algorithm, an asymmetric algorithm and/or a hashing algorithm are used together to form a security protocol, their respective key lengths and hash sizes shall be of (roughly) equal strength. Table 2 shows the allowed cipher suites:
Table 2
Allowed cipher suites
Cipher suite IdECC key size (bits)AES key length (bits)Hashing algorithmMAC length (bytes)
CS#1256128SHA-2568
CS#2384192SHA-38412
CS#3512/521256SHA-51216

Note: ECC keys sizes of 512 bits and 521 bits are considered to be equal in strength for all purposes within this Appendix.

Back to top

Options/Help

Print Options

You have chosen to open the Whole Regulation

The Whole Regulation you have selected contains over 200 provisions and might take some time to download. You may also experience some issues with your browser, such as an alert box that a script is taking a long time to run.

Would you like to continue?

You have chosen to open Schedules only

The Schedules you have selected contains over 200 provisions and might take some time to download. You may also experience some issues with your browser, such as an alert box that a script is taking a long time to run.

Would you like to continue?

Close

Legislation is available in different versions:

Latest Available (revised):The latest available updated version of the legislation incorporating changes made by subsequent legislation and applied by our editorial team. Changes we have not yet applied to the text, can be found in the ‘Changes to Legislation’ area.

Original (As adopted by EU): The original version of the legislation as it stood when it was first adopted in the EU. No changes have been applied to the text.

Close

Opening Options

Different options to open legislation in order to view more content on screen at once

Close

More Resources

Access essential accompanying documents and information for this legislation item from this tab. Dependent on the legislation item being viewed this may include:

  • the original print PDF of the as adopted version that was used for the EU Official Journal
  • lists of changes made by and/or affecting this legislation item
  • all formats of all associated documents
  • correction slips
  • links to related legislation and further information resources
Close

More Resources

Use this menu to access essential accompanying documents and information for this legislation item. Dependent on the legislation item being viewed this may include:

  • the original print PDF of the as adopted version that was used for the print copy
  • correction slips

Click 'View More' or select 'More Resources' tab for additional information including:

  • lists of changes made by and/or affecting this legislation item
  • confers power and blanket amendment details
  • all formats of all associated documents
  • links to related legislation and further information resources