The TSS consists of three components: a security module, a storage medium, and a unified digital interface. The detailed requirements for these components were developed by the BSI and published in technical guidelines. The security module is further composed of two components, the Cryptographic Service Provider (CSP) and Security Module Application (SMA). For each of the latter, the BSI has defined security requirements according to ISO/IEC 15408 (Common Criteria, CC) specifications. The TSS is certified by the BSI to ensure the compliance of its components and the TSS as a whole with these requirements.
Functional requirements
Section titled “Functional requirements”
Basic structure of the technical security system. Source: BSI TR-03153
The TSS components
Section titled “The TSS components”Security Module
The security module logs cash register transactions and digitally signes them to ensure that they cannot be changed later.
It is composed of the following components:
SMA (SMAERS)Security Module Application — A CC-certified component that receives the transaction data and user commands from the Unified Digital Interface and composes them into log message records. It communicates with the CSP (Cryptographic Service Provider) to sign these records.
CSPCryptographic Service Provider — A CC-certified component that generates the signatures and timestamps of the records to be secured. It is the cryptographic heart of the TSS security.
Storage Medium
The secured records of each transaction are stored for the duration of the legal retention period.
The fiskaly TSS uses databases operated in a secure environment for TSS storage. All external access is restricted by default to the TSS itself, which is only accessible via the unified digital interface.
Unified Digital Interface
The unified digital interface guarantees smooth data transfer for verification purposes.
The fiskaly TSS has a unified digital interface, according to the TR-03153 and TR-03151 specifications. This is integrated into the SIGN DE system, which provides additional services and capabilities, and is accessible via the SIGN DE API. The fiskaly HUB can be used in addition to manage multiple organisations, TSSs, and reporting necessities. It supports multi-user authorization on an organisation level.
📘Third-party accessThird-party service providers, such as archiving services, can also access the TSS export data via this authorization system.