so the smart card holds the private key and the EAL6 certification provides some assurance that the keys are secure?