# Mobile Device Fundamentals {#mobile-device-fundamentals .title style="page-break-be # Mobile Device Fundamentals {#mobile-device-fundamentals .title style="page-break-be # This page is best viewed with JavaScript enabled! {#this-page-is-best-viewed-with-j # This page is best viewed with JavaScript enabled! {#this-page-is-best-viewed-with-j ::: center ::: center ![NIAP Logo](images/niaplogo.png)\ ![NIAP Logo](images/niaplogo.png)\ Version: 4.0\ Version: 4.0\ 2025-01-31\ 2025-01-31\ **National Information Assurance Partnership**\ **National Information Assurance Partnership**\ ::: ::: ## Revision History {#revision-history style="page-break-before:always;"} ## Revision History {#revision-history style="page-break-before:always;"} +-----------------------+-----------------------+-----------------------+ +-----------------------+-----------------------+-----------------------+ | Version | Date | Comment | | Version | Date | Comment | +=======================+=======================+=======================+ +=======================+=======================+=======================+ | 1.0 | 2013-10-21 | Initial Release | | 1.0 | 2013-10-21 | Initial Release | +-----------------------+-----------------------+-----------------------+ +-----------------------+-----------------------+-----------------------+ | 1.1 | 2014-01-12 | Typographical changes | | 1.1 | 2014-01-12 | Typographical changes | | | | and additional | | | | and additional | | | | clarifications in | | | | clarifications in | | | | application notes. | | | | application notes. | | | | Removed assignment | | | | Removed assignment | | | | from FCS_TLS_EXT.1 | | | | from FCS_TLS_EXT.1 | | | | and limited testing | | | | and limited testing | | | | to those ciphersuites | | | | to those ciphersuites | | | | in both FCS_TLS_EXT.1 | | | | in both FCS_TLS_EXT.1 | | | | and FCS_TLS_EXT.2. | | | | and FCS_TLS_EXT.2. | +-----------------------+-----------------------+-----------------------+ +-----------------------+-----------------------+-----------------------+ | 2.0 | 2015-09-14 | Included changes | | 2.0 | 2015-09-14 | Included changes | | | | based on Technical | | | | based on Technical | | | | Rapid Response Team | | | | Rapid Response Team | | | | Decisions. Clarified | | | | Decisions. Clarified | | | | many requirements and | | | | many requirements and | | | | evaluation | | | | evaluation | | | | activities. Mandated | | | | activities. Mandated | | | | objective | | | | objective | | | | requirements:\ | | | | requirements:\ | | | | | | | | | | | | - Application | | | | - Application | | | | Access Control | | | | Access Control | | | | ([FDP_ACF_EXT.1. | | | | ([FDP_ACF_EXT.1. | | | | 2](#FDP_ACF_EXT.1.2)) | | | | 2](#FDP_ACF_EXT.1.2)) | | | | - [VPN](#abbr_VPN) | | | | - [VPN](#abbr_VPN) | | | | Information Flow | | | | Information Flow | | | | Control | | | | Control | | | | ([FDP_IFC_EX | | | | ([FDP_IFC_EX | | | | T.1](#FDP_IFC_EXT.1)) | | | | T.1](#FDP_IFC_EXT.1)) | | | | | | | | | | | | Added new objective | | | | Added new objective | | | | requirements:\ | | | | requirements:\ | | | | | | | | | | | | - Suite B | | | | - Suite B | | | | cryptography for | | | | cryptography for | | | | | | | | | | | | [IEEE](#abbr_IEEE) | | | | [IEEE](#abbr_IEEE) | | | | 802.11 | | | | 802.11 | | | | - Certificate | | | | - Certificate | | | | enrollment | | | | enrollment | | | | - Protection of | | | | - Protection of | | | | additional key | | | | additional key | | | | material types | | | | material types | | | | - Heap overflow | | | | - Heap overflow | | | | protection | | | | protection | | | | - Bluetooth | | | | - Bluetooth | | | | requirements | | | | requirements | | | | - Cryptographic | | | | - Cryptographic | | | | operation | | | | operation | | | | services for | | | | services for | | | | applications | | | | applications | | | | - Remote | | | | - Remote | | | | Attestation | | | | Attestation | | | | ([FPT_NOT_EX | | | | ([FPT_NOT_EX | | | | T.1](#FPT_NOT_EXT.1)) | | | | T.1](#FPT_NOT_EXT.1)) | | | | | | | | | | | | Added transition | | | | Added transition | | | | dates for some | | | | dates for some | | | | objective | | | | objective | | | | requirements.\ | | | | requirements.\ | | | | Included | | | | Included | | | | hardware-isolated | | | | hardware-isolated | | | | [REK](#abbr_REK) and | | | | [REK](#abbr_REK) and | | | | key storage | | | | key storage | | | | selections.\ | | | | selections.\ | | | | Allowed key | | | | Allowed key | | | | derivation by | | | | derivation by | | | | [REK](#abbr_REK).\ | | | | [REK](#abbr_REK).\ | | | | Clarified | | | | Clarified | | | | [FTP_ITC_E | | | | [FTP_ITC_E | | | | XT.1](#FTP_ITC_EXT.1) | | | | XT.1](#FTP_ITC_EXT.1) | | | | and added | | | | and added | | | | FDP_UPC_EXT.1.\ | | | | FDP_UPC_EXT.1.\ | | | | Mandated | | | | Mandated | | | | [HTTPS](#abbr_HTTPS) | | | | [HTTPS](#abbr_HTTPS) | | | | and [TLS](#abbr_TLS) | | | | and [TLS](#abbr_TLS) | | | | for application use. | | | | for application use. | | | | (FDP_UPC_EXT.1)\ | | | | (FDP_UPC_EXT.1)\ | | | | Removed Dual_EC_DRBG | | | | Removed Dual_EC_DRBG | | | | as an approved DRBG.\ | | | | as an approved DRBG.\ | | | | Adopted new | | | | Adopted new | | | | [TLS](#abbr_TLS) | | | | [TLS](#abbr_TLS) | | | | requirements.\ | | | | requirements.\ | | | | Mandated | | | | Mandated | | | | [TSF](#abbr_TSF) Wipe | | | | [TSF](#abbr_TSF) Wipe | | | | upon authentication | | | | upon authentication | | | | failure limit and | | | | failure limit and | | | | required number of | | | | required number of | | | | authentication | | | | authentication | | | | failures be | | | | failures be | | | | maintained across | | | | maintained across | | | | reboot.\ | | | | reboot.\ | | | | Clarified Management | | | | Clarified Management | | | | Class.\ | | | | Class.\ | | | | Included more domain | | | | Included more domain | | | | isolation discussion | | | | isolation discussion | | | | and tests.\ | | | | and tests.\ | | | | Updated Audit | | | | Updated Audit | | | | requirements and | | | | requirements and | | | | added Auditable | | | | added Auditable | | | | Events table.\ | | | | Events table.\ | | | | Added | | | | Added | | | | [SFR](#abbr_SFR) | | | | [SFR](#abbr_SFR) | | | | Category Mapping | | | | Category Mapping | | | | Table.\ | | | | Table.\ | | | | Updated Use Case | | | | Updated Use Case | | | | Templates.\ | | | | Templates.\ | | | | Moved Glossary to | | | | Moved Glossary to | | | | Introduction. | | | | Introduction. | +-----------------------+-----------------------+-----------------------+ +-----------------------+-----------------------+-----------------------+ | 3.0 | 2015-09-17 | Included changes | | 3.0 | 2015-09-17 | Included changes | | | | based on Technical | | | | based on Technical | | | | Rapid Response Team | | | | Rapid Response Team | | | | Decisions.\ | | | | Decisions.\ | | | | Clarified many | | | | Clarified many | | | | requirements and | | | | requirements and | | | | evaluation | | | | evaluation | | | | activities.\ | | | | activities.\ | | | | Mandated objective | | | | Mandated objective | | | | requirements:\ | | | | requirements:\ | | | | | | | | | | | | - Generation of | | | | - Generation of | | | | Audit Records | | | | Audit Records | | | | ([FA | | | | ([FA | | | | U_GEN.1](#FAU_GEN.1)) | | | | U_GEN.1](#FAU_GEN.1)) | | | | - Audit Storage | | | | - Audit Storage | | | | Protection | | | | Protection | | | | (FAU_STG.1) | | | | (FAU_STG.1) | | | | - Audit Storage | | | | - Audit Storage | | | | Overwrite | | | | Overwrite | | | | (FAU_STG.4) | | | | (FAU_STG.4) | | | | - Lock Screen | | | | - Lock Screen | | | | [DAR](#abbr_DAR) | | | | [DAR](#abbr_DAR) | | | | ([FDP_DAR_EX | | | | ([FDP_DAR_EX | | | | T.2](#FDP_DAR_EXT.2)) | | | | T.2](#FDP_DAR_EXT.2)) | | | | - Discard Bluetooth | | | | - Discard Bluetooth | | | | Connection | | | | Connection | | | | Attempts from | | | | Attempts from | | | | Bluetooth | | | | Bluetooth | | | | Addresses with | | | | Addresses with | | | | Existing | | | | Existing | | | | Connection | | | | Connection | | | | (FIA_BLT_EXT.3) | | | | (FIA_BLT_EXT.3) | | | | - JTAG Disablement | | | | - JTAG Disablement | | | | (FPT_JTA) | | | | (FPT_JTA) | | | | | | | | | | | | Added new objective | | | | Added new objective | | | | requirements:\ | | | | requirements:\ | | | | | | | | | | | | - Application | | | | - Application | | | | Backup | | | | Backup | | | | - Biometric | | | | - Biometric | | | | Authentication | | | | Authentication | | | | Factor | | | | Factor | | | | - Access Control | | | | - Access Control | | | | - User | | | | - User | | | | Authentication | | | | Authentication | | | | - Bluetooth | | | | - Bluetooth | | | | Encryption | | | | Encryption | | | | | | | | | | | | WLAN client | | | | WLAN client | | | | requirements moved to | | | | requirements moved to | | | | Extended Package for | | | | Extended Package for | | | | WLAN Client.\ | | | | WLAN Client.\ | | | | Added | | | | Added | | | | [SFRs](#abbr_SFR) to | | | | [SFRs](#abbr_SFR) to | | | | support | | | | support | | | | [BYOD](#abbr_BYOD) | | | | [BYOD](#abbr_BYOD) | | | | Use Case\ | | | | Use Case\ | | | | [BYOD](#abbr_BYOD) | | | | [BYOD](#abbr_BYOD) | | | | Use Case\ | | | | Use Case\ | | | | Updated key | | | | Updated key | | | | destruction | | | | destruction | | | | [SFR](#abbr_SFR) | | | | [SFR](#abbr_SFR) | +-----------------------+-----------------------+-----------------------+ +-----------------------+-----------------------+-----------------------+ | 3.1 | 2017-04-05 | Included changes | | 3.1 | 2017-04-05 | Included changes | | | | based on Technical | | | | based on Technical | | | | Rapid Response Team | | | | Rapid Response Team | | | | Decisions and | | | | Decisions and | | | | incorporated | | | | incorporated | | | | Technical Decisions.\ | | | | Technical Decisions.\ | | | | Modified biometric | | | | Modified biometric | | | | requirements: | | | | requirements: | | | | | | | | | | | | - [FIA | | | | - [FIA | | | | _UAU.5](#FIA_UAU.5) - | | | | _UAU.5](#FIA_UAU.5) - | | | | Added iris, face, | | | | Added iris, face, | | | | voice and vein as | | | | voice and vein as | | | | supported | | | | supported | | | | modalities, in | | | | modalities, in | | | | addition to | | | | addition to | | | | fingerprint | | | | fingerprint | | | | (allowed in | | | | (allowed in | | | | version 3) | | | | version 3) | | | | - FIA_BMG_EXT.1.1 - | | | | - FIA_BMG_EXT.1.1 - | | | | Clarified AA to | | | | Clarified AA to | | | | specify that | | | | specify that | | | | vendor evidence | | | | vendor evidence | | | | is acceptable and | | | | is acceptable and | | | | expectations of | | | | expectations of | | | | evidence | | | | evidence | | | | provided. | | | | provided. | | | | - FIA_BMG_EXT.1.2 - | | | | - FIA_BMG_EXT.1.2 - | | | | | | | | | | | | [SAFAR](#abbr_SAFAR) | | | | [SAFAR](#abbr_SAFAR) | | | | was changed to an | | | | was changed to an | | | | assignment of a | | | | assignment of a | | | | | | | | | | | | [SAFAR](#abbr_SAFAR) | | | | [SAFAR](#abbr_SAFAR) | | | | no greater than | | | | no greater than | | | | 1:500. | | | | 1:500. | | | | - [FIA_AFL_EXT | | | | - [FIA_AFL_EXT | | | | .1](#FIA_AFL_EXT.1) - | | | | .1](#FIA_AFL_EXT.1) - | | | | Updated to allow | | | | Updated to allow | | | | each biometric | | | | each biometric | | | | modality to | | | | modality to | | | | utilize an | | | | utilize an | | | | individual or | | | | individual or | | | | shared counter. | | | | shared counter. | | | | | | | | | | | | FCS_TLSC_EXT.1.1 - | | | | FCS_TLSC_EXT.1.1 - | | | | Removed | | | | Removed | | | | [TLS](#abbr_TLS) | | | | [TLS](#abbr_TLS) | | | | ciphersuites that | | | | ciphersuites that | | | | utilized SHA1 and | | | | utilized SHA1 and | | | | updated optional | | | | updated optional | | | | ciphersuites to be | | | | ciphersuites to be | | | | uniformed across | | | | uniformed across | | | | [PPs](#abbr_PP).\ | | | | [PPs](#abbr_PP).\ | | | | [FCS_STG_EXT.2.2 | | | | [FCS_STG_EXT.2.2 | | | | ](#FCS_STG_EXT.2.2) - | | | | ](#FCS_STG_EXT.2.2) - | | | | Modified to require | | | | Modified to require | | | | long term trusted | | | | long term trusted | | | | channel key material | | | | channel key material | | | | be encrypted by an | | | | be encrypted by an | | | | approved method.\ | | | | approved method.\ | | | | [FIA_UAU_EXT.1.1 | | | | [FIA_UAU_EXT.1.1 | | | | ](#FIA_UAU_EXT.1.1) - | | | | ](#FIA_UAU_EXT.1.1) - | | | | Modified to allow the | | | | Modified to allow the | | | | long term trusted | | | | long term trusted | | | | channel key material | | | | channel key material | | | | to be available prior | | | | to be available prior | | | | to password being | | | | to password being | | | | entered at start-up.\ | | | | entered at start-up.\ | +-----------------------+-----------------------+-----------------------+ +-----------------------+-----------------------+-----------------------+ | 3.2 | 2021-04-15 | Removed | | 3.2 | 2021-04-15 | Removed | | | | [TLS](#abbr_TLS) | | | | [TLS](#abbr_TLS) | | | | [SFRs](#abbr_SFR) and | | | | [SFRs](#abbr_SFR) and | | | | used [TLS](#abbr_TLS) | | | | used [TLS](#abbr_TLS) | | | | Functional Package\ | | | | Functional Package\ | | | | Removed Bluetooth | | | | Removed Bluetooth | | | | [SFRs](#abbr_SFR) and | | | | [SFRs](#abbr_SFR) and | | | | utilized Bluetooth | | | | utilized Bluetooth | | | | Module. Bluetooth | | | | Module. Bluetooth | | | | [SFR](#abbr_SFR) | | | | [SFR](#abbr_SFR) | | | | moved to | | | | moved to | | | | Implementation | | | | Implementation | | | | Dependent.\ | | | | Dependent.\ | | | | [FPT_TUD_EXT | | | | [FPT_TUD_EXT | | | | .4](#FPT_TUD_EXT.4).2 | | | | .4](#FPT_TUD_EXT.4).2 | | | | renumbered to | | | | renumbered to | | | | [FPT_TUD_EXT.5. | | | | [FPT_TUD_EXT.5. | | | | 1](#FPT_TUD_EXT.5.1)\ | | | | 1](#FPT_TUD_EXT.5.1)\ | +-----------------------+-----------------------+-----------------------+ +-----------------------+-----------------------+-----------------------+ | 3.3 | 2022-09-12 | Integrated Biometrics | | 3.3 | 2022-09-12 | Integrated Biometrics | | | | [cPP](#abbr_cPP) | | | | [cPP](#abbr_cPP) | | | | Module, Included | | | | Module, Included | | | | changes based on | | | | changes based on | | | | Technical Rapid | | | | Technical Rapid | | | | Response Team | | | | Response Team | | | | Decisions and open | | | | Decisions and open | | | | issues from GitHub.\ | | | | issues from GitHub.\ | | | | | | | | | | | | Removed biometric | | | | Removed biometric | | | | definitions from Tech | | | | definitions from Tech | | | | Terms | | | | Terms | | | | | | | | | | | | Removed FDP_PBA | | | | Removed FDP_PBA | | | | | | | | | | | | Removed FIA_BMG | | | | Removed FIA_BMG | | | | | | | | | | | | Updated | | | | Updated | | | | [F | | | | [F | | | | IA_UAU.5](#FIA_UAU.5) | | | | IA_UAU.5](#FIA_UAU.5) | | | | to support bio | | | | to support bio | | | | [cPP](#abbr_cPP) | | | | [cPP](#abbr_cPP) | | | | module | | | | module | | | | | | | | | | | | Moved | | | | Moved | | | | [F | | | | [F | | | | TA_TAB.1](#FTA_TAB.1) | | | | TA_TAB.1](#FTA_TAB.1) | | | | to mandatory | | | | to mandatory | | | | | | | | | | | | Moved | | | | Moved | | | | [F | | | | [F | | | | AU_SAR.1](#FAU_SAR.1) | | | | AU_SAR.1](#FAU_SAR.1) | | | | to mandatory | | | | to mandatory | | | | | | | | | | | | Added ECD | | | | Added ECD | | | | | | | | | | | | Updated WLAN Client | | | | Updated WLAN Client | | | | reference from | | | | reference from | | | | Extended Package to | | | | Extended Package to | | | | Module | | | | Module | | | | | | | | | | | | Removed | | | | Removed | | | | Diffie-Hellman group | | | | Diffie-Hellman group | | | | 14 selection from | | | | 14 selection from | | | | FCS_CKM.1.1 and | | | | FCS_CKM.1.1 and | | | | FCS_CKM_EXT.7.1 | | | | FCS_CKM_EXT.7.1 | +-----------------------+-----------------------+-----------------------+ +-----------------------+-----------------------+-----------------------+ | 4.0 | 2024-09-20 | - Updated to | | 4.0 | 2024-09-20 | - Updated to | | | | conform to | | | | conform to | | | | | | | | | | | | [CC](#abbr_CC):2022. | | | | [CC](#abbr_CC):2022. | | | | - Updated | | | | - Updated | | | | [TLS](#abbr_TLS) | | | | [TLS](#abbr_TLS) | | | | package | | | | package | | | | references. | | | | references. | | | | - Incorporated | | | | - Incorporated | | | | X.509 package. | | | | X.509 package. | | | | - Incorporated | | | | - Incorporated | | | | applicable | | | | applicable | | | | technical | | | | technical | | | | decisions. | | | | decisions. | | | | - Updated | | | | - Updated | | | | cryptographic | | | | cryptographic | | | | algorithm | | | | algorithm | | | | strengths to | | | | strengths to | | | | conform to | | | | conform to | | | | | | | | | | | | [CNSA](#abbr_CNSA). | | | | [CNSA](#abbr_CNSA). | +-----------------------+-----------------------+-----------------------+ +-----------------------+-----------------------+-----------------------+ ## Contents ## Contents ::: {#toc .toc} ::: {#toc .toc} [1Introduction](#Introduction){style="text-indent:0px"}[1.1Objectives of [1Introduction](#Introduction){style="text-indent:0px"}[1.1Objectives of Document](#Objectives_of_Document){style="text-indent:10px"}[1.2Terms](#glossary){sty Document](#Objectives_of_Document){style="text-indent:10px"}[1.2Terms](#glossary){sty Criteria Terms](#cc-terms){style="text-indent:20px"}[1.2.2Technical Criteria Terms](#cc-terms){style="text-indent:20px"}[1.2.2Technical Terms](#tech-terms){style="text-indent:20px"}[1.3Scope of Terms](#tech-terms){style="text-indent:20px"}[1.3Scope of Document](#scope){style="text-indent:10px"}[1.4Intended Document](#scope){style="text-indent:10px"}[1.4Intended Readership](#intread){style="text-indent:10px"}[1.5TOE Readership](#intread){style="text-indent:10px"}[1.5TOE Overview](#toeov){style="text-indent:10px"}[1.6Use Overview](#toeov){style="text-indent:10px"}[1.6Use Cases](#Use_Cases){style="text-indent:10px"}[1.7Package Cases](#Use_Cases){style="text-indent:10px"}[1.7Package Usage](#package-usage){style="text-indent:10px"}[1.8Product Features Usage](#package-usage){style="text-indent:10px"}[1.8Product Features Mapped to Implementation-dependent Mapped to Implementation-dependent Requirements](#sec-features){style="text-indent:10px"}[1.8.1Bluetooth](#bluetooth){st Requirements](#sec-features){style="text-indent:10px"}[1.8.1Bluetooth](#bluetooth){st Agreement Agreement Support](#key-agreement-support){style="text-indent:20px"}[2Conformance Support](#key-agreement-support){style="text-indent:20px"}[2Conformance Claims](#Conformance_Claims){style="text-indent:0px"}[3Security Problem Claims](#Conformance_Claims){style="text-indent:0px"}[3Security Problem Definition](#Security_Problem_Definition){style="text-indent:0px"}[3.1Threats](#thr){ | Definition](#Security_Problem_Definition){style="text-indent:0px"}[3.1Threats](#Threa Security Policies](#osp){style="text-indent:10px"}[4Security | Security > Policies](#Organizational_Security_Policies){style="text-indent:10px"}[4Security Objectives](#Security_Objectives){style="text-indent:0px"}[4.1Security Objectives](#Security_Objectives){style="text-indent:0px"}[4.1Security Objectives for the Operational Objectives for the Operational Environment](#sooe){style="text-indent:10px"}[4.2Security Objectives Environment](#sooe){style="text-indent:10px"}[4.2Security Objectives Rationale](#SOR){style="text-indent:10px"}[5Security | Rationale](#){style="text-indent:10px"}[5Security Requirements](#Security_Requirements){style="text-indent:0px"}[5.1Security Requirements](#Security_Requirements){style="text-indent:0px"}[5.1Security Functional Requirements](#sfr){style="text-indent:10px"}[5.1.1Auditable Functional Requirements](#sfr){style="text-indent:10px"}[5.1.1Auditable Events for Mandatory Events for Mandatory SFRs](#ss-audit-table){style="text-indent:20px"}[5.1.2Class FAU: SFRs](#ss-audit-table){style="text-indent:20px"}[5.1.2Class FAU: Security Audit](#fau){style="text-indent:20px"}[5.1.3Class FCS: Security Audit](#fau){style="text-indent:20px"}[5.1.3Class FCS: Cryptographic Support](#fcs){style="text-indent:20px"}[5.1.4Class FDP: Cryptographic Support](#fcs){style="text-indent:20px"}[5.1.4Class FDP: User Data Protection](#fdp){style="text-indent:20px"}[5.1.5Class FIA: User Data Protection](#fdp){style="text-indent:20px"}[5.1.5Class FIA: Identification and Identification and Authentication](#fia){style="text-indent:20px"}[5.1.6Class FMT: Security Authentication](#fia){style="text-indent:20px"}[5.1.6Class FMT: Security Management](#fmt){style="text-indent:20px"}[5.1.7Class FPT: Protection Management](#fmt){style="text-indent:20px"}[5.1.7Class FPT: Protection of the TSF](#fpt){style="text-indent:20px"}[5.1.8Class FTA: TOE of the TSF](#fpt){style="text-indent:20px"}[5.1.8Class FTA: TOE Access](#fta){style="text-indent:20px"}[5.1.9Class FTP: Trusted Access](#fta){style="text-indent:20px"}[5.1.9Class FTP: Trusted Path/Channels](#ftp){style="text-indent:20px"}[5.1.10TOE Security Path/Channels](#ftp){style="text-indent:20px"}[5.1.10TOE Security Functional Requirements Functional Requirements Rationale](#obj-req-map){style="text-indent:20px"}[5.2Security Assurance Rationale](#obj-req-map){style="text-indent:20px"}[5.2Security Assurance Requirements](#sar){style="text-indent:10px"}[5.2.1Class ASE: Security Requirements](#sar){style="text-indent:10px"}[5.2.1Class ASE: Security Target](#ase){style="text-indent:20px"}[5.2.2Class ADV: Target](#ase){style="text-indent:20px"}[5.2.2Class ADV: Development](#adv){style="text-indent:20px"}[5.2.3Class AGD: Guidance Development](#adv){style="text-indent:20px"}[5.2.3Class AGD: Guidance Documentation](#agd){style="text-indent:20px"}[5.2.4Class ALC: Documentation](#agd){style="text-indent:20px"}[5.2.4Class ALC: Life-cycle Support](#alc){style="text-indent:20px"}[5.2.5Class ATE: Life-cycle Support](#alc){style="text-indent:20px"}[5.2.5Class ATE: Tests](#ate){style="text-indent:20px"}[5.2.6Class AVA: Vulnerability Tests](#ate){style="text-indent:20px"}[5.2.6Class AVA: Vulnerability Assessment](#ava){style="text-indent:20px"}[Appendix A - Optional Assessment](#ava){style="text-indent:20px"}[Appendix A - Optional Requirements](#opt-app){style="text-indent:0px"}[A.1Strictly Optional Requirements](#opt-app){style="text-indent:0px"}[A.1Strictly Optional Requirements ](#optional-reqs){style="text-indent:10px"}[A.1.1 Auditable Requirements ](#optional-reqs){style="text-indent:10px"}[A.1.1 Auditable Events for Strictly Optional Requirements Events for Strictly Optional Requirements ](#optional-reqs-audit){style="text-indent:20px"}[A.1.2Class ALC: ](#optional-reqs-audit){style="text-indent:20px"}[A.1.2Class ALC: Life-cycle Support](#-optional){style="text-indent:20px"}[A.1.3Class | Life-cycle Support](#alc-optional){style="text-indent:20px"}[A.1.3Class FIA: Identification and FIA: Identification and Authentication](#-optional){style="text-indent:20px"}[A.2Objective | Authentication](#fia-optional){style="text-indent:20px"}[A.2Objective Requirements ](#objective-reqs){style="text-indent:10px"}[A.2.1 Requirements ](#objective-reqs){style="text-indent:10px"}[A.2.1 Auditable Events for Objective Requirements Auditable Events for Objective Requirements ](#objective-reqs-audit){style="text-indent:20px"}[A.2.2Class FAU: ](#objective-reqs-audit){style="text-indent:20px"}[A.2.2Class FAU: Security Audit](#-objective){style="text-indent:20px"}[A.2.3Class FCS: | Security Audit](#fau-objective){style="text-indent:20px"}[A.2.3Class Cryptographic Support](#-objective){style="text-indent:20px"}[A.2.4Class | FCS: Cryptographic FDP: User Data | Support](#fcs-objective){style="text-indent:20px"}[A.2.4Class FDP: User Protection](#-objective){style="text-indent:20px"}[A.2.5Class FMT: | Data Protection](#fdp-objective){style="text-indent:20px"}[A.2.5Class Security Management](#-objective){style="text-indent:20px"}[A.2.6Class | FMT: Security FPT: Protection of the | Management](#fmt-objective){style="text-indent:20px"}[A.2.6Class FPT: TSF](#-objective){style="text-indent:20px"}[A.3Implementation-dependent | Protection of the > TSF](#fpt-objective){style="text-indent:20px"}[A.3Implementation-dependent Requirements ](#feat-based-reqs){style="text-indent:10px"}[A.3.1 Requirements ](#feat-based-reqs){style="text-indent:10px"}[A.3.1 Auditable Events for Implementation-dependent Requirements Auditable Events for Implementation-dependent Requirements ](#feat-based-reqs-audit){style="text-indent:20px"}[A.3.2Class FCS: ](#feat-based-reqs-audit){style="text-indent:20px"}[A.3.2Class FCS: Cryptographic Cryptographic Support](#-feat-based){style="text-indent:20px"}[A.3.3Class FDP: User | Support](#fcs-feat-based){style="text-indent:20px"}[A.3.3Class FDP: User Data Protection](#-feat-based){style="text-indent:20px"}[Appendix B - | Data Protection](#fdp-feat-based){style="text-indent:20px"}[Appendix B - Selection-based Requirements Selection-based Requirements ](#sel-based-reqs){style="text-indent:0px"}[B.1 Auditable Events for ](#sel-based-reqs){style="text-indent:0px"}[B.1 Auditable Events for Selection-based Requirements Selection-based Requirements ](#sel-based-reqs-audit){style="text-indent:10px"}[B.2Class FCS: ](#sel-based-reqs-audit){style="text-indent:10px"}[B.2Class FCS: Cryptographic Support](#-sel-based){style="text-indent:10px"}[B.3Class | Cryptographic FDP: User Data | Support](#fcs-sel-based){style="text-indent:10px"}[B.3Class FDP: User Protection](#-sel-based){style="text-indent:10px"}[B.4Class FPT: | Data Protection](#fdp-sel-based){style="text-indent:10px"}[B.4Class FPT: Protection of the TSF](#-sel-based){style="text-indent:10px"}[Appendix | Protection of the C - Extended Component | TSF](#fpt-sel-based){style="text-indent:10px"}[Appendix C - Extended > Component Definitions](#ext-comp-defs){style="text-indent:0px"}[C.1Extended Definitions](#ext-comp-defs){style="text-indent:0px"}[C.1Extended Components Components Table](#ext-comp-defs-bg){style="text-indent:10px"}[C.2Extended Table](#ext-comp-defs-bg){style="text-indent:10px"}[C.2Extended Component Component Definitions](#ext-comp-defs-bg){style="text-indent:10px"}[C.2.1Class Definitions](#ext-comp-defs-bg){style="text-indent:10px"}[C.2.1Class FCS: Cryptographic FCS: Cryptographic Support](#ext-comp-){style="text-indent:20px"}[C.2.1.1FCS_CKM_EXT Support](#ext-comp-){style="text-indent:20px"}[C.2.1.1FCS_CKM_EXT Cryptographic Key Cryptographic Key Management](#ext-comp-FCS_CKM_EXT){style="text-indent:30px"}[C.2.1.2FCS_HTTPS_EXT Management](#ext-comp-FCS_CKM_EXT){style="text-indent:30px"}[C.2.1.2FCS_HTTPS_EXT HTTPS HTTPS Protocol](#ext-comp-FCS_HTTPS_EXT){style="text-indent:30px"}[C.2.1.3FCS_IV_EXT Protocol](#ext-comp-FCS_HTTPS_EXT){style="text-indent:30px"}[C.2.1.3FCS_IV_EXT Initialization Vector Initialization Vector Generation](#ext-comp-FCS_IV_EXT){style="text-indent:30px"}[C.2.1.4FCS_RBG_EXT Generation](#ext-comp-FCS_IV_EXT){style="text-indent:30px"}[C.2.1.4FCS_RBG_EXT Random Bit Random Bit Generation](#ext-comp-FCS_RBG_EXT){style="text-indent:30px"}[C.2.1.5FCS_SRV_EXT Generation](#ext-comp-FCS_RBG_EXT){style="text-indent:30px"}[C.2.1.5FCS_SRV_EXT Cryptographic Algorithm Cryptographic Algorithm Services](#ext-comp-FCS_SRV_EXT){style="text-indent:30px"}[C.2.1.6FCS_STG_EXT Services](#ext-comp-FCS_SRV_EXT){style="text-indent:30px"}[C.2.1.6FCS_STG_EXT Cryptographic Key Cryptographic Key Storage](#ext-comp-FCS_STG_EXT){style="text-indent:30px"}[C.2.2Class Storage](#ext-comp-FCS_STG_EXT){style="text-indent:30px"}[C.2.2Class FDP: User Data FDP: User Data Protection](#ext-comp-){style="text-indent:20px"}[C.2.2.1FDP_ACF_EXT Protection](#ext-comp-){style="text-indent:20px"}[C.2.2.1FDP_ACF_EXT Access Control Access Control Functions](#ext-comp-FDP_ACF_EXT){style="text-indent:30px"}[C.2.2.2FDP_BCK_EXT Functions](#ext-comp-FDP_ACF_EXT){style="text-indent:30px"}[C.2.2.2FDP_BCK_EXT Application Application Backup](#ext-comp-FDP_BCK_EXT){style="text-indent:30px"}[C.2.2.3FDP_BLT_EXT Backup](#ext-comp-FDP_BCK_EXT){style="text-indent:30px"}[C.2.2.3FDP_BLT_EXT Limitation of Bluetooth Device Limitation of Bluetooth Device Access](#ext-comp-FDP_BLT_EXT){style="text-indent:30px"}[C.2.2.4FDP_DAR_EXT Access](#ext-comp-FDP_BLT_EXT){style="text-indent:30px"}[C.2.2.4FDP_DAR_EXT Data-at-Rest Data-at-Rest Encryption](#ext-comp-FDP_DAR_EXT){style="text-indent:30px"}[C.2.2.5FDP_IFC_EXT Encryption](#ext-comp-FDP_DAR_EXT){style="text-indent:30px"}[C.2.2.5FDP_IFC_EXT Subset Information Flow Subset Information Flow Control](#ext-comp-FDP_IFC_EXT){style="text-indent:30px"}[C.2.2.6FDP_STG_EXT Control](#ext-comp-FDP_IFC_EXT){style="text-indent:30px"}[C.2.2.6FDP_STG_EXT User Data User Data Storage](#ext-comp-FDP_STG_EXT){style="text-indent:30px"}[C.2.2.7FDP_UPC_EXT Storage](#ext-comp-FDP_STG_EXT){style="text-indent:30px"}[C.2.2.7FDP_UPC_EXT Inter-TSF User Data Transfer Inter-TSF User Data Transfer Protection](#ext-comp-FDP_UPC_EXT){style="text-indent:30px"}[C.2.3Class Protection](#ext-comp-FDP_UPC_EXT){style="text-indent:30px"}[C.2.3Class FIA: Identification and FIA: Identification and Authentication](#ext-comp-){style="text-indent:20px"}[C.2.3.1FIA_AFL_EXT Authentication](#ext-comp-){style="text-indent:20px"}[C.2.3.1FIA_AFL_EXT Authentication Authentication Failures](#ext-comp-FIA_AFL_EXT){style="text-indent:30px"}[C.2.3.2FIA_PMG_EXT Failures](#ext-comp-FIA_AFL_EXT){style="text-indent:30px"}[C.2.3.2FIA_PMG_EXT Password Password Management](#ext-comp-FIA_PMG_EXT){style="text-indent:30px"}[C.2.3.3FIA_TRT_EXT Management](#ext-comp-FIA_PMG_EXT){style="text-indent:30px"}[C.2.3.3FIA_TRT_EXT Authentication Authentication Throttling](#ext-comp-FIA_TRT_EXT){style="text-indent:30px"}[C.2.3.4FIA_UAU_EXT Throttling](#ext-comp-FIA_TRT_EXT){style="text-indent:30px"}[C.2.3.4FIA_UAU_EXT User User Authentication](#ext-comp-FIA_UAU_EXT){style="text-indent:30px"}[C.2.3.5FIA_X509_EXT Authentication](#ext-comp-FIA_UAU_EXT){style="text-indent:30px"}[C.2.3.5FIA_X509_EXT X.509 X.509 Certificates](#ext-comp-FIA_X509_EXT){style="text-indent:30px"}[C.2.4Class Certificates](#ext-comp-FIA_X509_EXT){style="text-indent:30px"}[C.2.4Class FMT: Security FMT: Security Management](#ext-comp-){style="text-indent:20px"}[C.2.4.1FMT_MOF_EXT Management](#ext-comp-){style="text-indent:20px"}[C.2.4.1FMT_MOF_EXT Management of Functions in Management of Functions in TSF](#ext-comp-FMT_MOF_EXT){style="text-indent:30px"}[C.2.4.2FMT_SMF_EXT TSF](#ext-comp-FMT_MOF_EXT){style="text-indent:30px"}[C.2.4.2FMT_SMF_EXT Specification of Management Specification of Management Functions](#ext-comp-FMT_SMF_EXT){style="text-indent:30px"}[C.2.5Class Functions](#ext-comp-FMT_SMF_EXT){style="text-indent:30px"}[C.2.5Class FPT: Protection of the FPT: Protection of the TSF](#ext-comp-){style="text-indent:20px"}[C.2.5.1FPT_AEX_EXT TSF](#ext-comp-){style="text-indent:20px"}[C.2.5.1FPT_AEX_EXT Anti-Exploitation Anti-Exploitation Capabilities](#ext-comp-FPT_AEX_EXT){style="text-indent:30px"}[C.2.5.2FPT_BBD_EXT Capabilities](#ext-comp-FPT_AEX_EXT){style="text-indent:30px"}[C.2.5.2FPT_BBD_EXT Baseband Baseband Processing](#ext-comp-FPT_BBD_EXT){style="text-indent:30px"}[C.2.5.3FPT_BLT_EXT Processing](#ext-comp-FPT_BBD_EXT){style="text-indent:30px"}[C.2.5.3FPT_BLT_EXT Limitation of Bluetooth Profile Limitation of Bluetooth Profile Support](#ext-comp-FPT_BLT_EXT){style="text-indent:30px"}[C.2.5.4FPT_JTA_EXT Support](#ext-comp-FPT_BLT_EXT){style="text-indent:30px"}[C.2.5.4FPT_JTA_EXT JTAG JTAG Disablement](#ext-comp-FPT_JTA_EXT){style="text-indent:30px"}[C.2.5.5FPT_KST_EXT Disablement](#ext-comp-FPT_JTA_EXT){style="text-indent:30px"}[C.2.5.5FPT_KST_EXT Key Key Storage](#ext-comp-FPT_KST_EXT){style="text-indent:30px"}[C.2.5.6FPT_NOT_EXT Storage](#ext-comp-FPT_KST_EXT){style="text-indent:30px"}[C.2.5.6FPT_NOT_EXT Self-Test Self-Test Notification](#ext-comp-FPT_NOT_EXT){style="text-indent:30px"}[C.2.5.7FPT_TST_EXT Notification](#ext-comp-FPT_NOT_EXT){style="text-indent:30px"}[C.2.5.7FPT_TST_EXT TSF Self TSF Self Test](#ext-comp-FPT_TST_EXT){style="text-indent:30px"}[C.2.5.8FPT_TUD_EXT Test](#ext-comp-FPT_TST_EXT){style="text-indent:30px"}[C.2.5.8FPT_TUD_EXT TSF Updates](#ext-comp-FPT_TUD_EXT){style="text-indent:30px"}[C.2.6Class TSF Updates](#ext-comp-FPT_TUD_EXT){style="text-indent:30px"}[C.2.6Class FTA: TOE FTA: TOE Access](#ext-comp-){style="text-indent:20px"}[C.2.6.1FTA_SSL_EXT Session Access](#ext-comp-){style="text-indent:20px"}[C.2.6.1FTA_SSL_EXT Session Locking and Locking and Termination](#ext-comp-FTA_SSL_EXT){style="text-indent:30px"}[C.2.7Class Termination](#ext-comp-FTA_SSL_EXT){style="text-indent:30px"}[C.2.7Class FTP: Trusted FTP: Trusted Path/Channels](#ext-comp-){style="text-indent:20px"}[C.2.7.1FTP_ITC_EXT Path/Channels](#ext-comp-){style="text-indent:20px"}[C.2.7.1FTP_ITC_EXT Inter-TSF Trusted Inter-TSF Trusted Channel](#ext-comp-FTP_ITC_EXT){style="text-indent:30px"}[Appendix D - Channel](#ext-comp-FTP_ITC_EXT){style="text-indent:30px"}[Appendix D - Implicitly Satisfied Implicitly Satisfied Requirements](#satisfiedreqs){style="text-indent:0px"}[Appendix E - Requirements](#satisfiedreqs){style="text-indent:0px"}[Appendix E - Entropy Documentation And Entropy Documentation And Assessment](#entropyappendix){style="text-indent:0px"}[E.1Design Assessment](#entropyappendix){style="text-indent:0px"}[E.1Design Description](#description){style="text-indent:10px"}[E.2Entropy Description](#description){style="text-indent:10px"}[E.2Entropy Justification](#justification){style="text-indent:10px"}[E.3Operating Justification](#justification){style="text-indent:10px"}[E.3Operating Conditions](#conditions){style="text-indent:10px"}[E.4Health Conditions](#conditions){style="text-indent:10px"}[E.4Health Testing](#testing){style="text-indent:10px"}[Appendix F - Initialization Testing](#testing){style="text-indent:10px"}[Appendix F - Initialization Vector Requirements for NIST-Approved Cipher Vector Requirements for NIST-Approved Cipher Modes](#vector){style="text-indent:0px"}[Appendix G - Modes](#vector){style="text-indent:0px"}[Appendix G - Acronyms](#acronyms){style="text-indent:0px"}[Appendix H - Acronyms](#acronyms){style="text-indent:0px"}[Appendix H - Bibliography](#appendix-bibliography){style="text-indent:0px"}[Appendix Bibliography](#appendix-bibliography){style="text-indent:0px"}[Appendix I - Acknowledgments](#ack){style="text-indent:0px"} I - Acknowledgments](#ack){style="text-indent:0px"} ::: ::: # 1 Introduction {#Introduction .indexable level="1"} # 1 Introduction {#Introduction .indexable level="1"} ## 1.1 Objectives of Document {#Objectives_of_Document .indexable level="2"} ## 1.1 Objectives of Document {#Objectives_of_Document .indexable level="2"} The scope of this Protection Profile ([PP](#abbr_PP)) is to describe the The scope of this Protection Profile ([PP](#abbr_PP)) is to describe the security functionality of mobile devices in terms of \[[CC](#abbr_CC)\] security functionality of mobile devices in terms of \[[CC](#abbr_CC)\] and to define functional and assurance requirements for such devices. and to define functional and assurance requirements for such devices. ::: no-link ::: no-link ## 1.2 Terms {#glossary .indexable level="2"} ## 1.2 Terms {#glossary .indexable level="2"} The following sections list Common Criteria and technology terms used in The following sections list Common Criteria and technology terms used in this document. this document. ### 1.2.1 Common Criteria Terms {#cc-terms .indexable level="3"} ### 1.2.1 Common Criteria Terms {#cc-terms .indexable level="3"} +-----------------------------------+-----------------------------------+ +-----------------------------------+-----------------------------------+ | ::: {#Assurance} | Grounds for confidence that a TOE | | ::: {#Assurance} | Grounds for confidence that a TOE | | Assurance | meets the SFRs [\[CC\]](#bibCC). | | Assurance | meets the SFRs [\[CC\]](#bibCC). | | ::: | | | ::: | | +-----------------------------------+-----------------------------------+ +-----------------------------------+-----------------------------------+ | ::: {#Base_Protection_Profile} | Protection Profile used as a | | ::: {#Base_Protection_Profile} | Protection Profile used as a | | Base Protection Profile (Base-PP) | basis to build a | | Base Protection Profile (Base-PP) | basis to build a | | ::: | PP-Configuration. | | ::: | PP-Configuration. | +-----------------------------------+-----------------------------------+ +-----------------------------------+-----------------------------------+ | ::: {# | A Protection Profile developed by | | ::: {# | A Protection Profile developed by | | Collaborative_Protection_Profile} | international technical | | Collaborative_Protection_Profile} | international technical | | Collaborative Protection Profile | communities and approved by | | Collaborative Protection Profile | communities and approved by | | (cPP) | multiple schemes. | | (cPP) | multiple schemes. | | ::: | | | ::: | | +-----------------------------------+-----------------------------------+ +-----------------------------------+-----------------------------------+ | ::: {#Common_Criteria} | Common Criteria for Information | | ::: {#Common_Criteria} | Common Criteria for Information | | Common Criteria (CC) | Technology Security Evaluation | | Common Criteria (CC) | Technology Security Evaluation | | ::: | (International Standard ISO/IEC | | ::: | (International Standard ISO/IEC | | | 15408). | | | 15408). | +-----------------------------------+-----------------------------------+ +-----------------------------------+-----------------------------------+ | ::: {#Co | Within the context of the Common | | ::: {#Co | Within the context of the Common | | mmon_Criteria_Testing_Laboratory} | Criteria Evaluation and | | mmon_Criteria_Testing_Laboratory} | Criteria Evaluation and | | Common Criteria Testing | Validation Scheme (CCEVS), an IT | | Common Criteria Testing | Validation Scheme (CCEVS), an IT | | Laboratory | security evaluation facility | | Laboratory | security evaluation facility | | ::: | accredited by the National | | ::: | accredited by the National | | | Voluntary Laboratory | | | Voluntary Laboratory | | | Accreditation Program (NVLAP) and | | | Accreditation Program (NVLAP) and | | | approved by the NIAP Validation | | | approved by the NIAP Validation | | | Body to conduct Common | | | Body to conduct Common | | | Criteria-based evaluations. | | | Criteria-based evaluations. | +-----------------------------------+-----------------------------------+ +-----------------------------------+-----------------------------------+ | ::: | Common Evaluation Methodology for | | ::: | Common Evaluation Methodology for | | {#Common_Evaluation_Methodology} | Information Technology Security | | {#Common_Evaluation_Methodology} | Information Technology Security | | Common Evaluation Methodology | Evaluation. | | Common Evaluation Methodology | Evaluation. | | (CEM) | | | (CEM) | | | ::: | | | ::: | | +-----------------------------------+-----------------------------------+ +-----------------------------------+-----------------------------------+ | ::: {#Direct_Rationale} | A type of Protection Profile, | | ::: {#Direct_Rationale} | A type of Protection Profile, | | Direct Rationale | PP-Module, or Security Target in | | Direct Rationale | PP-Module, or Security Target in | | ::: | which the security problem | | ::: | which the security problem | | | definition (SPD) elements are | | | definition (SPD) elements are | | | mapped directly to the SFRs and | | | mapped directly to the SFRs and | | | possibly to the security | | | possibly to the security | | | objectives for the operational | | | objectives for the operational | | | environment. There are no | | | environment. There are no | | | security objectives for the TOE. | | | security objectives for the TOE. | +-----------------------------------+-----------------------------------+ +-----------------------------------+-----------------------------------+ | ::: {#Distributed_TOE} | A TOE composed of multiple | | ::: {#Distributed_TOE} | A TOE composed of multiple | | Distributed TOE | components operating as a logical | | Distributed TOE | components operating as a logical | | ::: | whole. | | ::: | whole. | +-----------------------------------+-----------------------------------+ +-----------------------------------+-----------------------------------+ | ::: {#Extended_Package} | A deprecated document form for | | ::: {#Extended_Package} | A deprecated document form for | | Extended Package (EP) | collecting SFRs that implement a | | Extended Package (EP) | collecting SFRs that implement a | | ::: | particular protocol, technology, | | ::: | particular protocol, technology, | | | or functionality. See Functional | | | or functionality. See Functional | | | Packages. | | | Packages. | +-----------------------------------+-----------------------------------+ +-----------------------------------+-----------------------------------+ | ::: {#Functional_Package} | A document that collects SFRs for | | ::: {#Functional_Package} | A document that collects SFRs for | | Functional Package (FP) | a particular protocol, | | Functional Package (FP) | a particular protocol, | | ::: | technology, or functionality. | | ::: | technology, or functionality. | +-----------------------------------+-----------------------------------+ +-----------------------------------+-----------------------------------+ | ::: {#Operational_Environment} | Hardware and software that are | | ::: {#Operational_Environment} | Hardware and software that are | | Operational Environment (OE) | outside the TOE boundary that | | Operational Environment (OE) | outside the TOE boundary that | | ::: | support the TOE functionality and | | ::: | support the TOE functionality and | | | security policy. | | | security policy. | +-----------------------------------+-----------------------------------+ +-----------------------------------+-----------------------------------+ | ::: {#Protection_Profile} | An implementation-independent set | | ::: {#Protection_Profile} | An implementation-independent set | | Protection Profile (PP) | of security requirements for a | | Protection Profile (PP) | of security requirements for a | | ::: | category of products. | | ::: | category of products. | +-----------------------------------+-----------------------------------+ +-----------------------------------+-----------------------------------+ | ::: {# | A comprehensive set of security | | ::: {# | A comprehensive set of security | | Protection_Profile_Configuration} | requirements for a product type | | Protection_Profile_Configuration} | requirements for a product type | | Protection Profile Configuration | that consists of at least one | | Protection Profile Configuration | that consists of at least one | | (PP-Configuration) | Base-PP and at least one | | (PP-Configuration) | Base-PP and at least one | | ::: | PP-Module. | | ::: | PP-Module. | +-----------------------------------+-----------------------------------+ +-----------------------------------+-----------------------------------+ | ::: {#Protection_Profile_Module} | An implementation-independent | | ::: {#Protection_Profile_Module} | An implementation-independent | | Protection Profile Module | statement of security needs for a | | Protection Profile Module | statement of security needs for a | | (PP-Module) | TOE type complementary to one or | | (PP-Module) | TOE type complementary to one or | | ::: | more Base-PPs. | | ::: | more Base-PPs. | +-----------------------------------+-----------------------------------+ +-----------------------------------+-----------------------------------+ | ::: | A requirement to assure the | | ::: | A requirement to assure the | | {#Security_Assurance_Requirement} | security of the TOE. | | {#Security_Assurance_Requirement} | security of the TOE. | | Security Assurance Requirement | | | Security Assurance Requirement | | | (SAR) | | | (SAR) | | | ::: | | | ::: | | +-----------------------------------+-----------------------------------+ +-----------------------------------+-----------------------------------+ | ::: { | A requirement for security | | ::: { | A requirement for security | | #Security_Functional_Requirement} | enforcement by the TOE. | | #Security_Functional_Requirement} | enforcement by the TOE. | | Security Functional Requirement | | | Security Functional Requirement | | | (SFR) | | | (SFR) | | | ::: | | | ::: | | +-----------------------------------+-----------------------------------+ +-----------------------------------+-----------------------------------+ | ::: {#Security_Target} | A set of implementation-dependent | | ::: {#Security_Target} | A set of implementation-dependent | | Security Target (ST) | security requirements for a | | Security Target (ST) | security requirements for a | | ::: | specific product. | | ::: | specific product. | +-----------------------------------+-----------------------------------+ +-----------------------------------+-----------------------------------+ | ::: {#Target_of_Evaluation} | The product under evaluation. | | ::: {#Target_of_Evaluation} | The product under evaluation. | | Target of Evaluation (TOE) | | | Target of Evaluation (TOE) | | | ::: | | | ::: | | +-----------------------------------+-----------------------------------+ +-----------------------------------+-----------------------------------+ | ::: {#TOE_Security_Functionality} | The security functionality of the | | ::: {#TOE_Security_Functionality} | The security functionality of the | | TOE Security Functionality (TSF) | product under evaluation. | | TOE Security Functionality (TSF) | product under evaluation. | | ::: | | | ::: | | +-----------------------------------+-----------------------------------+ +-----------------------------------+-----------------------------------+ | ::: {#TOE_Summary_Specification} | A description of how a TOE | | ::: {#TOE_Summary_Specification} | A description of how a TOE | | TOE Summary Specification (TSS) | satisfies the SFRs in an ST. | | TOE Summary Specification (TSS) | satisfies the SFRs in an ST. | | ::: | | | ::: | | +-----------------------------------+-----------------------------------+ +-----------------------------------+-----------------------------------+ ### 1.2.2 Technical Terms {#tech-terms .indexable level="3"} ### 1.2.2 Technical Terms {#tech-terms .indexable level="3"} +-----------------------------------+-----------------------------------+ +-----------------------------------+-----------------------------------+ | ::: {#Ad | An anti-exploitation feature, | | ::: {#Ad | An anti-exploitation feature, | | dress_Space_Layout_Randomization} | which loads memory mappings into | | dress_Space_Layout_Randomization} | which loads memory mappings into | | Address Space Layout | unpredictable locations. ASLR | | Address Space Layout | unpredictable locations. ASLR | | Randomization (ASLR) | makes it more difficult for an | | Randomization (ASLR) | makes it more difficult for an | | ::: | attacker to redirect control to | | ::: | attacker to redirect control to | | | code that they have introduced | | | code that they have introduced | | | into the address space of a | | | into the address space of a | | | process or the kernel. | | | process or the kernel. | +-----------------------------------+-----------------------------------+ +-----------------------------------+-----------------------------------+ | ::: {#Administrator} | The Administrator is responsible | | ::: {#Administrator} | The Administrator is responsible | | Administrator | for management activities, | | Administrator | for management activities, | | ::: | including setting the policy that | | ::: | including setting the policy that | | | is applied by the enterprise on | | | is applied by the enterprise on | | | the Mobile Device. This | | | the Mobile Device. This | | | administrator is likely to be | | | administrator is likely to be | | | acting remotely and could be the | | | acting remotely and could be the | | | Mobile Device Management (MDM) | | | Mobile Device Management (MDM) | | | Administrator acting through an | | | Administrator acting through an | | | MDM agent. If the device is | | | MDM agent. If the device is | | | unenrolled, the user is the | | | unenrolled, the user is the | | | administrator. | | | administrator. | +-----------------------------------+-----------------------------------+ +-----------------------------------+-----------------------------------+ | ::: {#Auxiliary_Boot_Modes} | Auxiliary boot modes are states | | ::: {#Auxiliary_Boot_Modes} | Auxiliary boot modes are states | | Auxiliary Boot Modes | in which the device provides | | Auxiliary Boot Modes | in which the device provides | | ::: | power to one or more components | | ::: | power to one or more components | | | to provide an interface that | | | to provide an interface that | | | enables an unauthenticated user | | | enables an unauthenticated user | | | to interact with either a | | | to interact with either a | | | specific component or several | | | specific component or several | | | components that exist outside of | | | components that exist outside of | | | the device's fully authenticated, | | | the device's fully authenticated, | | | operational state. | | | operational state. | +-----------------------------------+-----------------------------------+ +-----------------------------------+-----------------------------------+ | ::: { | Authentication factor, which uses | | ::: { | Authentication factor, which uses | | #Biometric_Authentication_Factor} | biometric sample, matched to a | | #Biometric_Authentication_Factor} | biometric sample, matched to a | | Biometric Authentication Factor | biometric authentication template | | Biometric Authentication Factor | biometric authentication template | | (BAF) | to help establish identity. | | (BAF) | to help establish identity. | | ::: | | | ::: | | +-----------------------------------+-----------------------------------+ +-----------------------------------+-----------------------------------+ | :: | Application developers (or | | :: | Application developers (or | | : {#Common_Application_Developer} | software companies) often produce | | : {#Common_Application_Developer} | software companies) often produce | | Common Application Developer | many applications under the same | | Common Application Developer | many applications under the same | | ::: | name. Mobile devices often allow | | ::: | name. Mobile devices often allow | | | shared resources by such | | | shared resources by such | | | applications where otherwise | | | applications where otherwise | | | resources would not be shared. | | | resources would not be shared. | +-----------------------------------+-----------------------------------+ +-----------------------------------+-----------------------------------+ | ::: {#Data} | Program/application or data files | | ::: {#Data} | Program/application or data files | | Data | that are stored or transmitted by | | Data | that are stored or transmitted by | | ::: | a server or Mobile Device (MD). | | ::: | a server or Mobile Device (MD). | +-----------------------------------+-----------------------------------+ +-----------------------------------+-----------------------------------+ | ::: {#Data_Encryption_Key} | A key used to encrypt | | ::: {#Data_Encryption_Key} | A key used to encrypt | | Data Encryption Key (DEK) | data-at-rest. | | Data Encryption Key (DEK) | data-at-rest. | | ::: | | | ::: | | +-----------------------------------+-----------------------------------+ +-----------------------------------+-----------------------------------+ | ::: {#Developer_Modes} | Developer modes are states in | | ::: {#Developer_Modes} | Developer modes are states in | | Developer Modes | which additional services are | | Developer Modes | which additional services are | | ::: | available to a user in order to | | ::: | available to a user in order to | | | provide enhanced system access | | | provide enhanced system access | | | for debugging of software. | | | for debugging of software. | +-----------------------------------+-----------------------------------+ +-----------------------------------+-----------------------------------+ | ::: {#Encrypted_Software_Keys} | These keys are stored in the main | | ::: {#Encrypted_Software_Keys} | These keys are stored in the main | | Encrypted Software Keys | file system encrypted by another | | Encrypted Software Keys | file system encrypted by another | | ::: | key and can be changed and | | ::: | key and can be changed and | | | sanitized. | | | sanitized. | +-----------------------------------+-----------------------------------+ +-----------------------------------+-----------------------------------+ | ::: {#Enrolled_State} | The state in which the Mobile | | ::: {#Enrolled_State} | The state in which the Mobile | | Enrolled State | Device is managed with active | | Enrolled State | Device is managed with active | | ::: | policy settings from the | | ::: | policy settings from the | | | administrator. | | | administrator. | +-----------------------------------+-----------------------------------+ +-----------------------------------+-----------------------------------+ | ::: {#Enterprise_Data} | Enterprise data is any data | | ::: {#Enterprise_Data} | Enterprise data is any data | | Enterprise Data | residing in the enterprise | | Enterprise Data | residing in the enterprise | | ::: | servers, or temporarily stored on | | ::: | servers, or temporarily stored on | | | Mobile Devices to which the | | | Mobile Devices to which the | | | Mobile Device user is allowed | | | Mobile Device user is allowed | | | access according to security | | | access according to security | | | policy defined by the enterprise | | | policy defined by the enterprise | | | and implemented by the | | | and implemented by the | | | administrator. | | | administrator. | +-----------------------------------+-----------------------------------+ +-----------------------------------+-----------------------------------+ | ::: {#Ephemeral_Keys} | These keys are stored in volatile | | ::: {#Ephemeral_Keys} | These keys are stored in volatile | | Ephemeral Keys | memory. | | Ephemeral Keys | memory. | | ::: | | | ::: | | +-----------------------------------+-----------------------------------+ +-----------------------------------+-----------------------------------+ | ::: {#File_Encryption_Key} | A DEK used to encrypt a file or a | | ::: {#File_Encryption_Key} | A DEK used to encrypt a file or a | | File Encryption Key (FEK) | director when File Encryption is | | File Encryption Key (FEK) | director when File Encryption is | | ::: | used. FEKs are unique to each | | ::: | used. FEKs are unique to each | | | encrypted file or directory. | | | encrypted file or directory. | +-----------------------------------+-----------------------------------+ +-----------------------------------+-----------------------------------+ | ::: {#Hardware-Isolated_Keys} | The OS can only access these keys | | ::: {#Hardware-Isolated_Keys} | The OS can only access these keys | | Hardware-Isolated Keys | by reference, if at all, during | | Hardware-Isolated Keys | by reference, if at all, during | | ::: | runtime. | | ::: | runtime. | +-----------------------------------+-----------------------------------+ +-----------------------------------+-----------------------------------+ | ::: {#Hybrid_Authentication} | A hybrid authentication factor is | | ::: {#Hybrid_Authentication} | A hybrid authentication factor is | | Hybrid Authentication | one where a user has to submit a | | Hybrid Authentication | one where a user has to submit a | | ::: | combination of a biometric sample | | ::: | combination of a biometric sample | | | and a PIN or password and both | | | and a PIN or password and both | | | must pass. If either factor | | | must pass. If either factor | | | fails, the entire attempt fails. | | | fails, the entire attempt fails. | | | The user shall not be made aware | | | The user shall not be made aware | | | of which factor failed, if either | | | of which factor failed, if either | | | fails. | | | fails. | +-----------------------------------+-----------------------------------+ +-----------------------------------+-----------------------------------+ | ::: {#Immutable_Hardware_Key} | These keys are stored as | | ::: {#Immutable_Hardware_Key} | These keys are stored as | | Immutable Hardware Key | hardware-protected raw key and | | Immutable Hardware Key | hardware-protected raw key and | | ::: | cannot be changed or sanitized. | | ::: | cannot be changed or sanitized. | +-----------------------------------+-----------------------------------+ +-----------------------------------+-----------------------------------+ | ::: {#Key_Chaining} | The method of using multiple | | ::: {#Key_Chaining} | The method of using multiple | | Key Chaining | layers of encryption keys to | | Key Chaining | layers of encryption keys to | | ::: | protect data. A top layer key | | ::: | protect data. A top layer key | | | encrypts a lower layer key, which | | | encrypts a lower layer key, which | | | encrypts the data; this method | | | encrypts the data; this method | | | can have any number of layers. | | | can have any number of layers. | +-----------------------------------+-----------------------------------+ +-----------------------------------+-----------------------------------+ | ::: {#Key_Encryption_Key} | A key used to encrypt other keys, | | ::: {#Key_Encryption_Key} | A key used to encrypt other keys, | | Key Encryption Key (KEK) | such as DEKs or storage that | | Key Encryption Key (KEK) | such as DEKs or storage that | | ::: | contains keys. | | ::: | contains keys. | +-----------------------------------+-----------------------------------+ +-----------------------------------+-----------------------------------+ | ::: {#Locked_State} | Powered on but most functionality | | ::: {#Locked_State} | Powered on but most functionality | | Locked State | is unavailable for use. User | | Locked State | is unavailable for use. User | | ::: | authentication is required to | | ::: | authentication is required to | | | access functionality. | | | access functionality. | +-----------------------------------+-----------------------------------+ +-----------------------------------+-----------------------------------+ | ::: {#MDM_Agent} | The MDM agent is installed on a | | ::: {#MDM_Agent} | The MDM agent is installed on a | | MDM Agent | Mobile Device as an application | | MDM Agent | Mobile Device as an application | | ::: | or is part of the Mobile Device's | | ::: | or is part of the Mobile Device's | | | OS. The MDM agent establishes a | | | OS. The MDM agent establishes a | | | secure connection back to the MDM | | | secure connection back to the MDM | | | server controlled by the | | | server controlled by the | | | administrator. | | | administrator. | +-----------------------------------+-----------------------------------+ +-----------------------------------+-----------------------------------+ | ::: {#Minutia_Point} | Friction ridge characteristics | | ::: {#Minutia_Point} | Friction ridge characteristics | | Minutia Point | that are used to individualize a | | Minutia Point | that are used to individualize a | | ::: | fingerprint image. Minutia are | | ::: | fingerprint image. Minutia are | | | the points where friction ridges | | | the points where friction ridges | | | begin, terminate, or split into | | | begin, terminate, or split into | | | two or more ridges. In many | | | two or more ridges. In many | | | fingerprint systems, the minutia | | | fingerprint systems, the minutia | | | points are compared for | | | points are compared for | | | recognition purposes. | | | recognition purposes. | +-----------------------------------+-----------------------------------+ +-----------------------------------+-----------------------------------+ | ::: {#Mobile_Device} | A device which is composed of a | | ::: {#Mobile_Device} | A device which is composed of a | | Mobile Device (MD) | hardware platform and its system | | Mobile Device (MD) | hardware platform and its system | | ::: | software. The device typically | | ::: | software. The device typically | | | provides wireless connectivity | | | provides wireless connectivity | | | and may include software for | | | and may include software for | | | functions like secure messaging, | | | functions like secure messaging, | | | email, web, VPN (Virtual Private | | | email, web, VPN (Virtual Private | | | Network) connection, and VoIP | | | Network) connection, and VoIP | | | (Voice over IP), for access to | | | (Voice over IP), for access to | | | the protected enterprise network, | | | the protected enterprise network, | | | enterprise data and applications, | | | enterprise data and applications, | | | and for communicating to other | | | and for communicating to other | | | Mobile Devices. | | | Mobile Devices. | +-----------------------------------+-----------------------------------+ +-----------------------------------+-----------------------------------+ | ::: {#Mobile_Device_Management} | Mobile device management (MDM) | | ::: {#Mobile_Device_Management} | Mobile device management (MDM) | | Mobile Device Management (MDM) | products allow enterprises to | | Mobile Device Management (MDM) | products allow enterprises to | | ::: | apply security policies to mobile | | ::: | apply security policies to mobile | | | devices. This system consists of | | | devices. This system consists of | | | two primary components: the MDM | | | two primary components: the MDM | | | server and the MDM agent. | | | server and the MDM agent. | +-----------------------------------+-----------------------------------+ +-----------------------------------+-----------------------------------+ | ::: {#Mobile_Device_User_(User)} | The individual authorized to | | ::: {#Mobile_Device_User_(User)} | The individual authorized to | | Mobile Device User (User) | physically control and operate | | Mobile Device User (User) | physically control and operate | | ::: | the Mobile Device. Depending on | | ::: | the Mobile Device. Depending on | | | the use case, this can be the | | | the use case, this can be the | | | device owner or an individual | | | device owner or an individual | | | authorized by the device owner. | | | authorized by the device owner. | +-----------------------------------+-----------------------------------+ +-----------------------------------+-----------------------------------+ | ::: {#Modality_(Biometrics)} | A type or class of biometric | | ::: {#Modality_(Biometrics)} | A type or class of biometric | | Modality (Biometrics) | system, such as fingerprint | | Modality (Biometrics) | system, such as fingerprint | | ::: | recognition, facial recognition, | | ::: | recognition, facial recognition, | | | iris recognition, voice | | | iris recognition, voice | | | recognition, signature/sign, and | | | recognition, signature/sign, and | | | others. | | | others. | +-----------------------------------+-----------------------------------+ +-----------------------------------+-----------------------------------+ | ::: {#Mutable_Hardware_Key} | These keys are stored as | | ::: {#Mutable_Hardware_Key} | These keys are stored as | | Mutable Hardware Key | hardware-protected raw key and | | Mutable Hardware Key | hardware-protected raw key and | | ::: | can be changed or sanitized. | | ::: | can be changed or sanitized. | +-----------------------------------+-----------------------------------+ +-----------------------------------+-----------------------------------+ | ::: {#Operating_System} | Software that runs at the highest | | ::: {#Operating_System} | Software that runs at the highest | | Operating System (OS) | privilege level and can directly | | Operating System (OS) | privilege level and can directly | | ::: | control hardware resources. | | ::: | control hardware resources. | | | Modern Mobile Devices typically | | | Modern Mobile Devices typically | | | have at least two primary | | | have at least two primary | | | operating systems: one, which | | | operating systems: one, which | | | runs on the application processor | | | runs on the application processor | | | and one, which runs on the | | | and one, which runs on the | | | cellular baseband processor. The | | | cellular baseband processor. The | | | OS of the application processor | | | OS of the application processor | | | handles most user interactions | | | handles most user interactions | | | and provides the execution | | | and provides the execution | | | environment for apps. The OS of | | | environment for apps. The OS of | | | the cellular baseband processor | | | the cellular baseband processor | | | handles communications with the | | | handles communications with the | | | cellular network and may control | | | cellular network and may control | | | other peripherals. The term OS, | | | other peripherals. The term OS, | | | without context, may be assumed | | | without context, may be assumed | | | to refer to the OS of the | | | to refer to the OS of the | | | application processor. | | | application processor. | +-----------------------------------+-----------------------------------+ +-----------------------------------+-----------------------------------+ | ::: {#PIN_Authentication_Factor} | A PIN is a set of numeric or | | ::: {#PIN_Authentication_Factor} | A PIN is a set of numeric or | | PIN Authentication Factor | alphabetic characters that may be | | PIN Authentication Factor | alphabetic characters that may be | | ::: | used in addition to a biometric | | ::: | used in addition to a biometric | | | factor to provide a hybrid | | | factor to provide a hybrid | | | authentication factor. At this | | | authentication factor. At this | | | time it is not considered as a | | | time it is not considered as a | | | stand-alone authentication | | | stand-alone authentication | | | mechanism. A PIN is distinct from | | | mechanism. A PIN is distinct from | | | a password in that the allowed | | | a password in that the allowed | | | character set and required length | | | character set and required length | | | of a PIN is typically smaller | | | of a PIN is typically smaller | | | than that of a password as it is | | | than that of a password as it is | | | designed to be input quickly. | | | designed to be input quickly. | +-----------------------------------+-----------------------------------+ +-----------------------------------+-----------------------------------+ | ::: | A type of authentication factor | | ::: | A type of authentication factor | | {#Password_Authentication_Factor} | requiring the user to provide a | | {#Password_Authentication_Factor} | requiring the user to provide a | | Password Authentication Factor | secret set of characters to gain | | Password Authentication Factor | secret set of characters to gain | | ::: | access. | | ::: | access. | +-----------------------------------+-----------------------------------+ +-----------------------------------+-----------------------------------+ | ::: {#Powered_Off_State} | The device has been shut down | | ::: {#Powered_Off_State} | The device has been shut down | | Powered Off State | such that no TOE function can be | | Powered Off State | such that no TOE function can be | | ::: | performed. | | ::: | performed. | +-----------------------------------+-----------------------------------+ +-----------------------------------+-----------------------------------+ | ::: {#Protected_Data} | Protected data is all non-TSF | | ::: {#Protected_Data} | Protected data is all non-TSF | | Protected Data (PD) | data, including all user or | | Protected Data (PD) | data, including all user or | | ::: | enterprise data. Some or all of | | ::: | enterprise data. Some or all of | | | this data may be considered | | | this data may be considered | | | sensitive data as well. | | | sensitive data as well. | +-----------------------------------+-----------------------------------+ +-----------------------------------+-----------------------------------+ | ::: {#Root_Encryption_Key} | A key tied to the device used to | | ::: {#Root_Encryption_Key} | A key tied to the device used to | | Root Encryption Key (REK) | encrypt other keys. | | Root Encryption Key (REK) | encrypt other keys. | | ::: | | | ::: | | +-----------------------------------+-----------------------------------+ +-----------------------------------+-----------------------------------+ | ::: {#Sensitive_data} | Sensitive data shall be | | ::: {#Sensitive_data} | Sensitive data shall be | | Sensitive data | identified in the TSS section of | | Sensitive data | identified in the TSS section of | | ::: | the Security Target (ST) by the | | ::: | the Security Target (ST) by the | | | ST author. Sensitive data is a | | | ST author. Sensitive data is a | | | subset or all of the Protected | | | subset or all of the Protected | | | data. Sensitive data may include | | | data. Sensitive data may include | | | all user or enterprise data or | | | all user or enterprise data or | | | may be specific application data | | | may be specific application data | | | such as emails, messaging, | | | such as emails, messaging, | | | documents, calendar items, and | | | documents, calendar items, and | | | contacts. Sensitive data is | | | contacts. Sensitive data is | | | protected while in the locked | | | protected while in the locked | | | state (FDP_DAR_EXT.2). | | | state (FDP_DAR_EXT.2). | +-----------------------------------+-----------------------------------+ +-----------------------------------+-----------------------------------+ | ::: {#Software_Keys} | The OS access the raw bytes of | | ::: {#Software_Keys} | The OS access the raw bytes of | | Software Keys | these keys during runtime. | | Software Keys | these keys during runtime. | | ::: | | | ::: | | +-----------------------------------+-----------------------------------+ +-----------------------------------+-----------------------------------+ | ::: {#TSF_Data} | Data for the operation of the TSF | | ::: {#TSF_Data} | Data for the operation of the TSF | | TSF Data | upon which the enforcement of the | | TSF Data | upon which the enforcement of the | | ::: | requirements relies. | | ::: | requirements relies. | +-----------------------------------+-----------------------------------+ +-----------------------------------+-----------------------------------+ | ::: {#Trust_Anchor_Database} | A list of trusted root | | ::: {#Trust_Anchor_Database} | A list of trusted root | | Trust Anchor Database | Certificate Authority | | Trust Anchor Database | Certificate Authority | | ::: | certificates. | | ::: | certificates. | +-----------------------------------+-----------------------------------+ +-----------------------------------+-----------------------------------+ | ::: {#Unenrolled_State} | The state in which the Mobile | | ::: {#Unenrolled_State} | The state in which the Mobile | | Unenrolled State | Device is not managed. | | Unenrolled State | Device is not managed. | | ::: | | | ::: | | +-----------------------------------+-----------------------------------+ +-----------------------------------+-----------------------------------+ | ::: {#Unlocked_State} | Powered on and device | | ::: {#Unlocked_State} | Powered on and device | | Unlocked State | functionality is available for | | Unlocked State | functionality is available for | | ::: | use. Implies user authentication | | ::: | use. Implies user authentication | | | has occurred (when so | | | has occurred (when so | | | configured). | | | configured). | +-----------------------------------+-----------------------------------+ +-----------------------------------+-----------------------------------+ | ::: {#Verification_(Biometrics)} | A task where the biometric system | | ::: {#Verification_(Biometrics)} | A task where the biometric system | | Verification (Biometrics) | attempts to confirm an | | Verification (Biometrics) | attempts to confirm an | | ::: | individual's claimed identity by | | ::: | individual's claimed identity by | | | comparing a submitted sample to | | | comparing a submitted sample to | | | one or more previously enrolled | | | one or more previously enrolled | | | authentication templates. | | | authentication templates. | +-----------------------------------+-----------------------------------+ +-----------------------------------+-----------------------------------+ ::: ::: ## 1.3 Scope of Document {#scope .indexable level="2"} ## 1.3 Scope of Document {#scope .indexable level="2"} The scope of the [PP](#abbr_PP) within the development and evaluation The scope of the [PP](#abbr_PP) within the development and evaluation process is described in the Common Criteria for Information Technology process is described in the Common Criteria for Information Technology Security Evaluation [\[CC\]](#bibCC). In particular, a [PP](#abbr_PP) Security Evaluation [\[CC\]](#bibCC). In particular, a [PP](#abbr_PP) defines the IT security requirements of a generic type of defines the IT security requirements of a generic type of [TOE](#abbr_TOE) and specifies the functional and assurance security [TOE](#abbr_TOE) and specifies the functional and assurance security measures to be offered by that [TOE](#abbr_TOE) to meet stated measures to be offered by that [TOE](#abbr_TOE) to meet stated requirements [\[CC\]](#bibCC). requirements [\[CC\]](#bibCC). ## 1.4 Intended Readership {#intread .indexable level="2"} ## 1.4 Intended Readership {#intread .indexable level="2"} The target audiences of this [PP](#abbr_PP) are Mobile Device The target audiences of this [PP](#abbr_PP) are Mobile Device developers, [CC](#abbr_CC) consumers, evaluators and schemes. developers, [CC](#abbr_CC) consumers, evaluators and schemes. ## 1.5 TOE Overview {#toeov .indexable level="2"} ## 1.5 TOE Overview {#toeov .indexable level="2"} This assurance standard specifies information security requirements for This assurance standard specifies information security requirements for Mobile Devices for use in an enterprise. A Mobile Device in the context Mobile Devices for use in an enterprise. A Mobile Device in the context of this assurance standard is a device, which is composed of a hardware of this assurance standard is a device, which is composed of a hardware platform and its system software. The device typically provides wireless platform and its system software. The device typically provides wireless connectivity and may include software for functions like secure connectivity and may include software for functions like secure messaging, email, web, [VPN](#abbr_VPN) connection, and VoIP (Voice over messaging, email, web, [VPN](#abbr_VPN) connection, and VoIP (Voice over [IP](#abbr_IP)), for access to the protected enterprise network, [IP](#abbr_IP)), for access to the protected enterprise network, enterprise data and applications, and for communicating to other Mobile enterprise data and applications, and for communicating to other Mobile Devices.\ Devices.\ \ \ [Figure [1]{.counter}](#NetEnv){.NetEnv-ref [Figure [1]{.counter}](#NetEnv){.NetEnv-ref onclick="showTarget('NetEnv')"} illustrates the network operating onclick="showTarget('NetEnv')"} illustrates the network operating environment of the Mobile Device.\ environment of the Mobile Device.\ \ \ ::: {#figure-NetEnv .figure} ::: {#figure-NetEnv .figure} ![](images/figure1.jpg){#NetEnv width="" height=""}\ ![](images/figure1.jpg){#NetEnv width="" height=""}\ [Figure [1]{.counter}]{.ctr myid="NetEnv" counter-type="ct-figure"}: [Figure [1]{.counter}]{.ctr myid="NetEnv" counter-type="ct-figure"}: Mobile Device Network Environment Mobile Device Network Environment ::: ::: \ \ \ \ Examples of a \"Mobile Device\" that should claim conformance to this Examples of a \"Mobile Device\" that should claim conformance to this Protection Profile include smartphones, tablet computers, and other Protection Profile include smartphones, tablet computers, and other Mobile Devices with similar capabilities.\ Mobile Devices with similar capabilities.\ \ \ The Mobile Device provides essential services, such as cryptographic The Mobile Device provides essential services, such as cryptographic services, data-at-rest protection, and key storage services to support services, data-at-rest protection, and key storage services to support the secure operation of applications on the device. Additional security the secure operation of applications on the device. Additional security features such as security policy enforcement, application mandatory features such as security policy enforcement, application mandatory access control, anti-exploitation features, user authentication, and access control, anti-exploitation features, user authentication, and software integrity protection are implemented in order to address software integrity protection are implemented in order to address threats.\ threats.\ \ \ This assurance standard describes these essential security services This assurance standard describes these essential security services provided by the Mobile Device and serves as a foundation for a secure provided by the Mobile Device and serves as a foundation for a secure mobile architecture. The wireless connectivity shall be validated mobile architecture. The wireless connectivity shall be validated against the [PP-Module for Wireless LAN Client, version | against the [PP-Module for Wireless LAN Client, version 2.0](). If the 2.0](https://www.niap-ccevs.org/protectionprofiles/463). If the mobile | mobile device contains Bluetooth functionality (i.e., has Bluetooth device contains Bluetooth functionality (i.e., has Bluetooth hardware), | hardware), the Bluetooth connectivity shall be evaluated against the the Bluetooth connectivity shall be evaluated against the [PP-Module for | [PP-Module for Bluetooth, version 2.0](). As illustrated in [Figure Bluetooth, version | [2]{.counter}](#TOE){.TOE-ref onclick="showTarget('TOE')"}, it is 2.0](https://www.niap-ccevs.org/protectionprofiles/425). As illustrated | expected that a typical deployment would also include either third-party in [Figure [2]{.counter}](#TOE){.TOE-ref onclick="showTarget('TOE')"}, | or bundled components. Whether these components are bundled as part of it is expected that a typical deployment would also include either | the Mobile Device by the manufacturer or developed by a third-party, third-party or bundled components. Whether these components are bundled | they must be separately validated against the related assurance as part of the Mobile Device by the manufacturer or developed by a | standards such as [PP-Module for Mobile Device Management Agent, version third-party, they must be separately validated against the related | 1.1](), [](#mod=vpnclient){.dynref format=""}, and [PP-Module for assurance standards such as [PP-Module for Mobile Device Management | Wireless LAN Client, version 2.0](). It is the responsibility of the Agent, version 1.1](https://www.niap-ccevs.org/protectionprofiles/441), | architect of the overall secure mobile architecture to ensure validation [](#mod=vpnclient){.dynref format=""}, and [PP-Module for Wireless LAN | of these components. Additional applications that may come pre-installed Client, version 2.0](https://www.niap-ccevs.org/protectionprofiles/463). | on the Mobile Device that are not validated are considered to be It is the responsibility of the architect of the overall secure mobile | potentially flawed, but not malicious. Examples include email client and architecture to ensure validation of these components. Additional | web browser.\ applications that may come pre-installed on the Mobile Device that are < not validated are considered to be potentially flawed, but not < malicious. Examples include email client and web browser.\ < \ \ ::: {#figure-TOE .figure} ::: {#figure-TOE .figure} ![](images/figure2.jpg){#TOE width="" height=""}\ ![](images/figure2.jpg){#TOE width="" height=""}\ [Figure [2]{.counter}]{.ctr myid="TOE" counter-type="ct-figure"}: [Figure [2]{.counter}]{.ctr myid="TOE" counter-type="ct-figure"}: Optional Additional Mobile Device Components Optional Additional Mobile Device Components ::: ::: \ \ ## 1.6 Use Cases {#Use_Cases .indexable level="2"} ## 1.6 Use Cases {#Use_Cases .indexable level="2"} The Mobile Device may be operated in a number of use cases. The Mobile Device may be operated in a number of use cases. [[use-case-appendix]{.counter}](#use-case-appendix){.use-case-appendix-ref [[use-case-appendix]{.counter}](#use-case-appendix){.use-case-appendix-ref onclick="showTarget('use-case-appendix')"} provides use case templates onclick="showTarget('use-case-appendix')"} provides use case templates that list those selections, assignments, and objective requirements that that list those selections, assignments, and objective requirements that best support the use cases identified by this [PP](#abbr_PP). In best support the use cases identified by this [PP](#abbr_PP). In addition to providing essential security services, the Mobile Device addition to providing essential security services, the Mobile Device includes the necessary security functionality to support configurations includes the necessary security functionality to support configurations for these various use cases. Each use case may require additional for these various use cases. Each use case may require additional configuration and applications to achieve the desired security. A configuration and applications to achieve the desired security. A selection of these use cases is elaborated below. selection of these use cases is elaborated below. Several of the use case templates include objective requirements that Several of the use case templates include objective requirements that are strongly desired for the indicated use cases. Readers can expect are strongly desired for the indicated use cases. Readers can expect those requirements to be made mandatory in a future revision of this those requirements to be made mandatory in a future revision of this protection profile, and industry should aim to include that security protection profile, and industry should aim to include that security functionality in products in the near-term. functionality in products in the near-term. As of publication of this version of the [PP](#abbr_PP), meeting the As of publication of this version of the [PP](#abbr_PP), meeting the requirements in [Section 5 Security requirements in [Section 5 Security Requirements](#Security_Requirements){.dynref} is necessary for all use Requirements](#Security_Requirements){.dynref} is necessary for all use cases. cases. \[USE CASE 1\] Enterprise-owned device for general-purpose enterprise use and limited \[USE CASE 1\] Enterprise-owned device for general-purpose enterprise use and limited : [ ]{.description} : [ ]{.description} An enterprise-owned device for general-purpose business use is An enterprise-owned device for general-purpose business use is commonly called *Corporately Owned, Personally Enabled (COPE)*. This commonly called *Corporately Owned, Personally Enabled (COPE)*. This use case entails a significant degree of enterprise control over use case entails a significant degree of enterprise control over configuration and, possibly, software inventory. The enterprise configuration and, possibly, software inventory. The enterprise elects to provide users with Mobile Devices and additional elects to provide users with Mobile Devices and additional applications (such as [VPN](#abbr_VPN) or email clients) in order to applications (such as [VPN](#abbr_VPN) or email clients) in order to maintain control of their Enterprise data and security of their maintain control of their Enterprise data and security of their networks. Users may use Internet connectivity to browse the web or networks. Users may use Internet connectivity to browse the web or access corporate mail or run enterprise applications, but this access corporate mail or run enterprise applications, but this connectivity may be under significant control of the enterprise. connectivity may be under significant control of the enterprise. A [TOE](#abbr_TOE) that conforms to this use case is expected to A [TOE](#abbr_TOE) that conforms to this use case is expected to make the following [SFR](#abbr_SFR) claims: make the following [SFR](#abbr_SFR) claims: ------------------------------------------------------------------------------- | ------------------------------------------------------------------------------- **Requirement** **Requirement** [FMT_SMF_EXT.1.1](#FMT_SMF_EXT.1.1) Function 39 (configuration of [USB](#abbr_U [FMT_SMF_EXT.1.1](#FMT_SMF_EXT.1.1) Function 39 (configuration of [USB](#abbr_U [FMT_SMF_EXT.1.1](#FMT_SMF_EXT.1.1) Function 41 (configuration of tethering) | [FMT_SMF_EXT.1.1](#FMT_SMF_EXT.1.1) Function 41 (configuration of tethering) [FPT_BBD_EXT.1](#FPT_BBD_EXT.1) [FPT_BBD_EXT.1](#FPT_BBD_EXT.1) [FPT_TST_EXT.2/POSTKERNEL](#FPT_TST_EXT.2/POSTKERNEL) [FPT_TST_EXT.2/POSTKERNEL](#FPT_TST_EXT.2/POSTKERNEL) [FPT_TUD_EXT.5](#FPT_TUD_EXT.5) [FPT_TUD_EXT.5](#FPT_TUD_EXT.5) ------------------------------------------------------------------------------- | ------------------------------------------------------------------------------- If an [SFR](#abbr_SFR) is not listed here, this use case does not If an [SFR](#abbr_SFR) is not listed here, this use case does not mandate or prohibit any of its available selections or assignments. mandate or prohibit any of its available selections or assignments. \[USE CASE 2\] Enterprise-owned device for specialized, high security use \[USE CASE 2\] Enterprise-owned device for specialized, high security use : [ ]{.description} : [ ]{.description} An enterprise-owned device with intentionally limited network An enterprise-owned device with intentionally limited network connectivity, tightly controlled configuration, and limited software connectivity, tightly controlled configuration, and limited software inventory is appropriate for specialized, high-security use cases. inventory is appropriate for specialized, high-security use cases. For example, the device may not be permitted connectivity to any For example, the device may not be permitted connectivity to any external peripherals. It may only be able to communicate via its external peripherals. It may only be able to communicate via its Wi-Fi or cellular radios with the enterprise-run network, which may Wi-Fi or cellular radios with the enterprise-run network, which may not even permit connectivity to the Internet. Use of the device may not even permit connectivity to the Internet. Use of the device may entail compliance with policies that are more restrictive than those entail compliance with policies that are more restrictive than those in any general-purpose use case, yet may mitigate risks to highly in any general-purpose use case, yet may mitigate risks to highly sensitive information. As in the previous case, the enterprise will sensitive information. As in the previous case, the enterprise will look for additional applications providing enterprise connectivity look for additional applications providing enterprise connectivity and services to have a similar level of assurance as the platform. and services to have a similar level of assurance as the platform. A [TOE](#abbr_TOE) that conforms to this use case is expected to A [TOE](#abbr_TOE) that conforms to this use case is expected to make the following [SFR](#abbr_SFR) claims: make the following [SFR](#abbr_SFR) claims: ------------------------------------------------------------------------------- ------------------------------------------------------------------------------- **Requirement** **Requirement** [FCS_CKM.1.1/AKG](#FCS_CKM.1.1/AKG) [FCS_CKM.1.1/AKG](#FCS_CKM.1.1/AKG) [FCS_CKM_EXT.7.1/LOCKED](#FCS_CKM_EXT.7.1/LOCKED) [FCS_CKM_EXT.7.1/LOCKED](#FCS_CKM_EXT.7.1/LOCKED) [FMT_SMF_EXT.1.1](#FMT_SMF_EXT.1.1) Function 5 (configuration of audio and visu [FMT_SMF_EXT.1.1](#FMT_SMF_EXT.1.1) Function 5 (configuration of audio and visu [FMT_SMF_EXT.1.1](#FMT_SMF_EXT.1.1) Function 44 (unenroll the [TOE](#abbr_TOE) [FMT_SMF_EXT.1.1](#FMT_SMF_EXT.1.1) Function 44 (unenroll the [TOE](#abbr_TOE) ------------------------------------------------------------------------------- ------------------------------------------------------------------------------- If an [SFR](#abbr_SFR) is not listed here, this use case does not If an [SFR](#abbr_SFR) is not listed here, this use case does not mandate or prohibit any of its available selections or assignments. mandate or prohibit any of its available selections or assignments. \[USE CASE 3\] Personally-owned device for personal and enterprise use \[USE CASE 3\] Personally-owned device for personal and enterprise use : [ ]{.description} : [ ]{.description} A personally-owned device that is used for both personal activities A personally-owned device that is used for both personal activities and enterprise data is commonly called Bring Your Own Device and enterprise data is commonly called Bring Your Own Device ([BYOD](#abbr_BYOD)). The device may be provisioned for access to ([BYOD](#abbr_BYOD)). The device may be provisioned for access to enterprise resources after significant personal usage has occurred. enterprise resources after significant personal usage has occurred. Unlike in the enterprise-owned cases, the enterprise is limited in Unlike in the enterprise-owned cases, the enterprise is limited in what security policies it can enforce because the user purchased the what security policies it can enforce because the user purchased the device primarily for personal use and is unlikely to accept policies device primarily for personal use and is unlikely to accept policies that limit the functionality of the device. However, because the that limit the functionality of the device. However, because the enterprise allows the user full (or nearly full) access to the enterprise allows the user full (or nearly full) access to the enterprise network, the enterprise will require their own security enterprise network, the enterprise will require their own security controls to ensure that enterprise resources are protected from controls to ensure that enterprise resources are protected from potential threats posed by the personal activities on the device. potential threats posed by the personal activities on the device. These controls could potentially be enforced by a separation These controls could potentially be enforced by a separation mechanism built-in to the device itself to distinguish between mechanism built-in to the device itself to distinguish between enterprise and personal activities, or by a third-party application enterprise and personal activities, or by a third-party application that provides access to enterprise resources and leverages security that provides access to enterprise resources and leverages security capabilities provided by the mobile device. capabilities provided by the mobile device. A [TOE](#abbr_TOE) that conforms to this use case is expected to A [TOE](#abbr_TOE) that conforms to this use case is expected to make the following [SFR](#abbr_SFR) claims: make the following [SFR](#abbr_SFR) claims: ------------------------------------------------------------------------------- ------------------------------------------------------------------------------- **Requirement** **Requirement** [FDP_ACF_EXT.1.2](#FDP_ACF_EXT.1.2) [FDP_ACF_EXT.1.2](#FDP_ACF_EXT.1.2) [FMT_SMF_EXT.1.1](#FMT_SMF_EXT.1.1) Function 3 ([VPN](#abbr_VPN) protection) [FMT_SMF_EXT.1.1](#FMT_SMF_EXT.1.1) Function 3 ([VPN](#abbr_VPN) protection) [FMT_SMF_EXT.1.1](#FMT_SMF_EXT.1.1) Function 5 (configuration of audio and visu [FMT_SMF_EXT.1.1](#FMT_SMF_EXT.1.1) Function 5 (configuration of audio and visu [FMT_SMF_EXT.1.1](#FMT_SMF_EXT.1.1) Function 28 (wipe Enterprise data) [FMT_SMF_EXT.1.1](#FMT_SMF_EXT.1.1) Function 28 (wipe Enterprise data) [FMT_SMF_EXT.1.1](#FMT_SMF_EXT.1.1) Function 44 (unenroll the [TOE](#abbr_TOE) [FMT_SMF_EXT.1.1](#FMT_SMF_EXT.1.1) Function 44 (unenroll the [TOE](#abbr_TOE) [FMT_SMF_EXT.2.1](#FMT_SMF_EXT.2.1) [FMT_SMF_EXT.2.1](#FMT_SMF_EXT.2.1) ------------------------------------------------------------------------------- ------------------------------------------------------------------------------- If an [SFR](#abbr_SFR) is not listed here, this use case does not If an [SFR](#abbr_SFR) is not listed here, this use case does not mandate or prohibit any of its available selections or assignments. mandate or prohibit any of its available selections or assignments. \[USE CASE 4\] Personally-owned device for personal and limited enterprise use \[USE CASE 4\] Personally-owned device for personal and limited enterprise use : [\ : [\ ]{.description} ]{.description} A personally-owned device that is used for both personal activities A personally-owned device that is used for both personal activities and enterprise data is commonly called Bring Your Own Device and enterprise data is commonly called Bring Your Own Device ([BYOD](#abbr_BYOD)). This device may be provisioned for limited ([BYOD](#abbr_BYOD)). This device may be provisioned for limited access to enterprise resources such as enterprise email. Because the access to enterprise resources such as enterprise email. Because the user does not have full access to the enterprise or enterprise data, user does not have full access to the enterprise or enterprise data, the enterprise may not need to enforce any security policies on the the enterprise may not need to enforce any security policies on the device. However, the enterprise may want secure email and web device. However, the enterprise may want secure email and web browsing with assurance that the services being provided to those browsing with assurance that the services being provided to those clients by the Mobile Device are not compromised. clients by the Mobile Device are not compromised. No specific [SFR](#abbr_SFR) claims are mandated or prohibited for a No specific [SFR](#abbr_SFR) claims are mandated or prohibited for a [TOE](#abbr_TOE) that meets this use case. [TOE](#abbr_TOE) that meets this use case. ## 1.7 Package Usage {#package-usage .indexable level="2"} ## 1.7 Package Usage {#package-usage .indexable level="2"} This section contains selections and assignments that are required when This section contains selections and assignments that are required when the listed Functional Packages are claimed by this [PP](#abbr_PP). the listed Functional Packages are claimed by this [PP](#abbr_PP). **Functional Package for Transport Layer Security (TLS), Version 2.1** **Functional Package for Transport Layer Security (TLS), Version 2.1** **[TLS](#abbr_TLS) Protocol Claims required in FCS_TLS_EXT.1** **[TLS](#abbr_TLS) Protocol Claims required in FCS_TLS_EXT.1** [To support [FTP_ITC_EXT.1](#FTP_ITC_EXT.1) and [To support [FTP_ITC_EXT.1](#FTP_ITC_EXT.1) and [FDP_UPC_EXT.1/APPS](#FDP_UPC_EXT.1/APPS), the [ST](#abbr_ST) author [FDP_UPC_EXT.1/APPS](#FDP_UPC_EXT.1/APPS), the [ST](#abbr_ST) author shall claim support for [TLS](#abbr_TLS) as a client. If shall claim support for [TLS](#abbr_TLS) as a client. If [DTLS](#abbr_DTLS) is claimed in [FTP_ITC_EXT.1](#FTP_ITC_EXT.1), the [DTLS](#abbr_DTLS) is claimed in [FTP_ITC_EXT.1](#FTP_ITC_EXT.1), the [ST](#abbr_ST) author shall also claim support for [DTLS](#abbr_DTLS) as [ST](#abbr_ST) author shall also claim support for [DTLS](#abbr_DTLS) as a client. Support for [TLS](#abbr_TLS) as a server or [DTLS](#abbr_DTLS) a client. Support for [TLS](#abbr_TLS) as a server or [DTLS](#abbr_DTLS) as a server shall not be claimed.]{.description} as a server shall not be claimed.]{.description} **[TLS](#abbr_TLS) Client Claims required in FCS_TLSC_EXT.1** **[TLS](#abbr_TLS) Client Claims required in FCS_TLSC_EXT.1** [To support [FTP_ITC_EXT.1](#FTP_ITC_EXT.1) and [To support [FTP_ITC_EXT.1](#FTP_ITC_EXT.1) and [FDP_UPC_EXT.1/APPS](#FDP_UPC_EXT.1/APPS), the [ST](#abbr_ST) author [FDP_UPC_EXT.1/APPS](#FDP_UPC_EXT.1/APPS), the [ST](#abbr_ST) author shall claim support for mutual authentication in FCS_TLSC_EXT.1.1. To shall claim support for mutual authentication in FCS_TLSC_EXT.1.1. To support [FCS_HTTPS_EXT.1.3](#FCS_HTTPS_EXT.1.3), the [ST](#abbr_ST) support [FCS_HTTPS_EXT.1.3](#FCS_HTTPS_EXT.1.3), the [ST](#abbr_ST) author shall claim how the [TOE](#abbr_TOE) handles invalid certificates author shall claim how the [TOE](#abbr_TOE) handles invalid certificates in a manner that is consistent with the claims made in in a manner that is consistent with the claims made in [FCS_HTTPS_EXT.1.3](#FCS_HTTPS_EXT.1.3). Regardless of the claims made [FCS_HTTPS_EXT.1.3](#FCS_HTTPS_EXT.1.3). Regardless of the claims made for [FCS_HTTPS_EXT.1.3](#FCS_HTTPS_EXT.1.3), to support for [FCS_HTTPS_EXT.1.3](#FCS_HTTPS_EXT.1.3), to support [FDP_UPC_EXT.1/APPS](#FDP_UPC_EXT.1/APPS), the [ST](#abbr_ST) author [FDP_UPC_EXT.1/APPS](#FDP_UPC_EXT.1/APPS), the [ST](#abbr_ST) author shall claim in FCS_TLSC_EXT.1.6 that invalid certificates are rejected shall claim in FCS_TLSC_EXT.1.6 that invalid certificates are rejected with no exceptions in this specific case.]{.description} with no exceptions in this specific case.]{.description} **Necessity of claiming FCS_TLSC_EXT.2** **Necessity of claiming FCS_TLSC_EXT.2** [Because support for [TLS](#abbr_TLS) client mutual authentication is [Because support for [TLS](#abbr_TLS) client mutual authentication is required, the [ST](#abbr_ST) author shall claim required, the [ST](#abbr_ST) author shall claim FCS_TLSC_EXT.2.]{.description} FCS_TLSC_EXT.2.]{.description} **[DTLS](#abbr_DTLS) Client Claims required in FCS_DTLSC_EXT.1** **[DTLS](#abbr_DTLS) Client Claims required in FCS_DTLSC_EXT.1** [To support [FTP_ITC_EXT.1](#FTP_ITC_EXT.1) and [To support [FTP_ITC_EXT.1](#FTP_ITC_EXT.1) and [FDP_UPC_EXT.1/APPS](#FDP_UPC_EXT.1/APPS) specifically in the case where [FDP_UPC_EXT.1/APPS](#FDP_UPC_EXT.1/APPS) specifically in the case where [DTLS](#abbr_DTLS) is claimed in [FTP_ITC_EXT.1.1](#FTP_ITC_EXT.1.1), [DTLS](#abbr_DTLS) is claimed in [FTP_ITC_EXT.1.1](#FTP_ITC_EXT.1.1), the [ST](#abbr_ST) author shall claim support for mutual authentication the [ST](#abbr_ST) author shall claim support for mutual authentication in FCS_DTLSC_EXT.1.1.]{.description} in FCS_DTLSC_EXT.1.1.]{.description} **Necessity of claiming FCS_DTLSC_EXT.2 if [DTLS](#abbr_DTLS) is **Necessity of claiming FCS_DTLSC_EXT.2 if [DTLS](#abbr_DTLS) is Supported** Supported** [[DTLS](#abbr_DTLS) support is not mandatory. However, if [[DTLS](#abbr_DTLS) support is not mandatory. However, if [DTLS](#abbr_DTLS) is claimed in [FTP_ITC_EXT.1](#FTP_ITC_EXT.1) or [DTLS](#abbr_DTLS) is claimed in [FTP_ITC_EXT.1](#FTP_ITC_EXT.1) or [FDP_UPC_EXT.1/APPS](#FDP_UPC_EXT.1/APPS), it is necessary for the [FDP_UPC_EXT.1/APPS](#FDP_UPC_EXT.1/APPS), it is necessary for the [TOE](#abbr_TOE) to support mutual authentication as a [TOE](#abbr_TOE) to support mutual authentication as a [DTLS](#abbr_DTLS) client. In this case, FCS_DTLS_EXT.2 shall be claimed [DTLS](#abbr_DTLS) client. In this case, FCS_DTLS_EXT.2 shall be claimed as a result of the selections made in FCS_DTLSC_EXT.1.1.]{.description} as a result of the selections made in FCS_DTLSC_EXT.1.1.]{.description} **Functional Package for X.509, Version 1.0** **Functional Package for X.509, Version 1.0** **Certificate Validation and Assertion Required in FIA_XCU_EXT.1.1** **Certificate Validation and Assertion Required in FIA_XCU_EXT.1.1** [ The [ST](#abbr_ST) author shall select the options to verify and | [The [ST](#abbr_ST) author shall select the options to verify and assert assert certificate identities. ]{.description} | certificate identities.]{.description} **No Platform-Provided Functionality Claims Permitted** **No Platform-Provided Functionality Claims Permitted** [Because the [TOE](#abbr_TOE) is the entire mobile device and | [ Because the [TOE](#abbr_TOE) is the entire mobile device and encompasses the platform, the [ST](#abbr_ST) author shall not claim encompasses the platform, the [ST](#abbr_ST) author shall not claim platform-provided functionality. In other words, any applicable platform-provided functionality. In other words, any applicable [SFRs](#abbr_SFR) shall select the option to implement or provide the [SFRs](#abbr_SFR) shall select the option to implement or provide the functionality, rather than rely on a platform. These may include one or functionality, rather than rely on a platform. These may include one or more of the following, depending on the [TOE](#abbr_TOE), but apply to more of the following, depending on the [TOE](#abbr_TOE), but apply to all package requirements that have such a selection: ]{.description} all package requirements that have such a selection: ]{.description} - FIA_CMCC_EXT.1 - FIA_CMCC_EXT.1 - FIA_CMPC_EXT.1 - FIA_CMPC_EXT.1 - FIA_ESTC_EXT.1 - FIA_ESTC_EXT.1 - FIA_X509_EXT.1 - FIA_X509_EXT.1 - FIA_X509_EXT.2 - FIA_X509_EXT.2 - FIA_X509_EXT.3 - FIA_X509_EXT.3 **No [CA](#abbr_CA) Claims Permitted** **No [CA](#abbr_CA) Claims Permitted** [ The [ST](#abbr_ST) author shall select the option to request a | [The [ST](#abbr_ST) author shall select the option to request a certificate from an external [CA](#abbr_CA) in FIA_XCU_EXT.2.1 and shall certificate from an external [CA](#abbr_CA) in FIA_XCU_EXT.2.1 and shall not select any options elsewhere in the package that involve claiming not select any options elsewhere in the package that involve claiming the ability to be a [CA](#abbr_CA). ]{.description} | the ability to be a [CA](#abbr_CA).]{.description} **Limitations on Signature Algorithms in FIA_X509_EXT.1.1** **Limitations on Signature Algorithms in FIA_X509_EXT.1.1** [ The [TOE](#abbr_TOE) must utilize appropriate cryptographic algorithms | [The [TOE](#abbr_TOE) must utilize appropriate cryptographic algorithms that conform to [CNSA](#abbr_CNSA) standards. Thus, the [ST](#abbr_ST) that conform to [CNSA](#abbr_CNSA) standards. Thus, the [ST](#abbr_ST) author shall select to utilize no other algorithms outside of those author shall select to utilize no other algorithms outside of those specified in RFC 8603 for certificate or [CRL](#abbr_CRL) signatures. specified in RFC 8603 for certificate or [CRL](#abbr_CRL) signatures. Additionally, the [ST](#abbr_ST) author shall not select to use Additionally, the [ST](#abbr_ST) author shall not select to use [ECDSA](#abbr_ECDSA) with [SHA](#abbr_SHA)-512 signatures for [ECDSA](#abbr_ECDSA) with [SHA](#abbr_SHA)-512 signatures for [OCSP](#abbr_OCSP) responses, and shall select to utilize no other [OCSP](#abbr_OCSP) responses, and shall select to utilize no other algorithms for [OCSP](#abbr_OCSP) responses. ]{.description} | algorithms for [OCSP](#abbr_OCSP) responses.]{.description} **Required Extension Processing for FIA_X509_EXT.1.2** **Required Extension Processing for FIA_X509_EXT.1.2** [ The [ST](#abbr_ST) author shall select the options to process the | [The [ST](#abbr_ST) author shall select the options to process the basicConstraints and extendedKeyUsage extensions. Other extensions may basicConstraints and extendedKeyUsage extensions. Other extensions may be selected as appropriate without restriction. ]{.description} | be selected as appropriate without restriction.]{.description} **[CRL](#abbr_CRL) or [OCSP](#abbr_OCSP)-based Revocation Required for **[CRL](#abbr_CRL) or [OCSP](#abbr_OCSP)-based Revocation Required for FIA_X509_EXT.1.3** FIA_X509_EXT.1.3** [ The [ST](#abbr_ST) author shall select only from options involving | [The [ST](#abbr_ST) author shall select only from options involving [CRL](#abbr_CRL) or [OCSP](#abbr_OCSP) in FIA_X509_EXT.1.3. | [CRL](#abbr_CRL) or [OCSP](#abbr_OCSP) in ]{.description} | FIA_X509_EXT.1.3.]{.description} **Connections to [CRL](#abbr_CRL) or [OCSP](#abbr_OCSP) Servers Required **Connections to [CRL](#abbr_CRL) or [OCSP](#abbr_OCSP) Servers Required for FIA_X509_EXT.1.4** for FIA_X509_EXT.1.4** [ The [ST](#abbr_ST) author shall not select options related to not | [The [ST](#abbr_ST) author shall not select options related to not obtaining revocation status information. Revocation information must be obtaining revocation status information. Revocation information must be obtained from a network connection via a supported [CRL](#abbr_CRL) or obtained from a network connection via a supported [CRL](#abbr_CRL) or [OCSP](#abbr_OCSP) function; [CA](#abbr_CA) retrieval or local status [OCSP](#abbr_OCSP) function; [CA](#abbr_CA) retrieval or local status selections shall not be chosen. ]{.description} | selections shall not be chosen.]{.description} **Restrictions on Acceptable Key Usage Values for FIA_X509_EXT.1.5** **Restrictions on Acceptable Key Usage Values for FIA_X509_EXT.1.5** [ The [ST](#abbr_ST) author shall not select the option to pass [ The [ST](#abbr_ST) author shall not select the option to pass certificate information to supported functions and shall select the certificate information to supported functions and shall select the option to verify certificates by evaluating the extendedKeyUsage field option to verify certificates by evaluating the extendedKeyUsage field in the leaf certificate.\ in the leaf certificate.\ Additionally, the [ST](#abbr_ST) author shall not select the option to Additionally, the [ST](#abbr_ST) author shall not select the option to validate certificates against any rules for S/MIME certificates. validate certificates against any rules for S/MIME certificates. ]{.description} ]{.description} **Restrictions on Acceptable Functions for FIA_X509_EXT.2.1** **Restrictions on Acceptable Functions for FIA_X509_EXT.2.1** [ The [ST](#abbr_ST) author shall not select options that involve the | [The [ST](#abbr_ST) author shall not select options that involve the S/MIME or [SSH](#abbr_SSH) protocols. If the [TOE](#abbr_TOE) supports S/MIME or [SSH](#abbr_SSH) protocols. If the [TOE](#abbr_TOE) supports [TSF](#abbr_TSF) integrity testing (i.e., [TSF](#abbr_TSF) integrity testing (i.e., [FPT_TST_EXT.3](#FPT_TST_EXT.3) is claimed), FIA_X509_EXT.2.1 must [FPT_TST_EXT.3](#FPT_TST_EXT.3) is claimed), FIA_X509_EXT.2.1 must include a claim that X.509 certificates are supported for code signing include a claim that X.509 certificates are supported for code signing for software integrity testing. If the [TOE](#abbr_TOE) supports trusted for software integrity testing. If the [TOE](#abbr_TOE) supports trusted update verification using code signing certificates (i.e., FPT_TST_EXT.4 update verification using code signing certificates (i.e., FPT_TST_EXT.4 is claimed in the context of the [TOE](#abbr_TOE)\'s own updates), is claimed in the context of the [TOE](#abbr_TOE)\'s own updates), FIA_X509_EXT.2.1 must include a claim that X.509 certificates are FIA_X509_EXT.2.1 must include a claim that X.509 certificates are supported for code signing for system software updates. If the supported for code signing for system software updates. If the [TOE](#abbr_TOE) supports code signing for mobile apps (i.e., [TOE](#abbr_TOE) supports code signing for mobile apps (i.e., [FPT_TUD_EXT.4](#FPT_TUD_EXT.4) is claimed in the context of external [FPT_TUD_EXT.4](#FPT_TUD_EXT.4) is claimed in the context of external apps), the assignment in FIA_X509_EXT.2.1 must be completed to reference apps), the assignment in FIA_X509_EXT.2.1 must be completed to reference \"code signing for mobile applications.\" ]{.description} | \"code signing for mobile applications.\"]{.description} **Restrictions on Acceptable Purposes for Certificate Acquisition for **Restrictions on Acceptable Purposes for Certificate Acquisition for FIA_XCU_EXT.2.1** FIA_XCU_EXT.2.1** [ The [ST](#abbr_ST) author shall not select options that involve the | [The [ST](#abbr_ST) author shall not select options that involve the S/MIME or [SSH](#abbr_SSH) protocols. ]{.description} | S/MIME or [SSH](#abbr_SSH) protocols.]{.description} ## 1.8 Product Features Mapped to Implementation-dependent Requirements {#sec-feature ## 1.8 Product Features Mapped to Implementation-dependent Requirements {#sec-feature The feature(s) enumerated below, if implemented by the [TOE](#abbr_TOE), The feature(s) enumerated below, if implemented by the [TOE](#abbr_TOE), require that additional [SFRs](#abbr_SFR) be claimed in the require that additional [SFRs](#abbr_SFR) be claimed in the [ST](#abbr_ST).\ [ST](#abbr_ST).\ ### 1.8.1 Bluetooth {#bluetooth .indexable level="3"} ### 1.8.1 Bluetooth {#bluetooth .indexable level="3"} [Bluetooth is a short-range wireless technology standard that is [Bluetooth is a short-range wireless technology standard that is commonly used for exchanging data between devices over short distances. commonly used for exchanging data between devices over short distances. Most, if not all, mobile devices include Bluetooth hardware.\ Most, if not all, mobile devices include Bluetooth hardware.\ ]{.description}\ ]{.description}\ If this feature is implemented by the [TOE](#abbr_TOE), the following If this feature is implemented by the [TOE](#abbr_TOE), the following requirements must be claimed in the [ST](#abbr_ST): requirements must be claimed in the [ST](#abbr_ST): - **[FDP_UPC_EXT.1/BLUETOOTH](#FDP_UPC_EXT.1/BLUETOOTH)** - **[FDP_UPC_EXT.1/BLUETOOTH](#FDP_UPC_EXT.1/BLUETOOTH)** ### 1.8.2 Key Agreement Support {#key-agreement-support .indexable level="3"} ### 1.8.2 Key Agreement Support {#key-agreement-support .indexable level="3"} [A conformant [TOE](#abbr_TOE) is required to implement trusted [A conformant [TOE](#abbr_TOE) is required to implement trusted communications. Depending on the specific protocols used and the communications. Depending on the specific protocols used and the supported connection parameters for these protocols, it may be necessary supported connection parameters for these protocols, it may be necessary to implement one or more key agreement algorithms as part of key to implement one or more key agreement algorithms as part of key establishment.\ establishment.\ ]{.description}\ ]{.description}\ If this feature is implemented by the [TOE](#abbr_TOE), the following If this feature is implemented by the [TOE](#abbr_TOE), the following requirements must be claimed in the [ST](#abbr_ST): requirements must be claimed in the [ST](#abbr_ST): - **[FCS_CKM_EXT.7/UNLOCKED](#FCS_CKM_EXT.7/UNLOCKED)** - **[FCS_CKM_EXT.7/UNLOCKED](#FCS_CKM_EXT.7/UNLOCKED)** # 2 Conformance Claims {#Conformance_Claims .indexable level="1"} # 2 Conformance Claims {#Conformance_Claims .indexable level="1"} Conformance Statement Conformance Statement : An [ST](#abbr_ST) must claim exact conformance to this : An [ST](#abbr_ST) must claim exact conformance to this [PP](#abbr_PP). [PP](#abbr_PP). : The evaluation methods used for evaluating the [TOE](#abbr_TOE) are : The evaluation methods used for evaluating the [TOE](#abbr_TOE) are a combination of the workunits defined in [\[CEM\]](#bibCEM) as well a combination of the workunits defined in [\[CEM\]](#bibCEM) as well as the Evaluation Activities for ensuring that individual as the Evaluation Activities for ensuring that individual [SFRs](#abbr_SFR) and [SARs](#abbr_SAR) have a sufficient level of [SFRs](#abbr_SFR) and [SARs](#abbr_SAR) have a sufficient level of supporting evidence in the Security Target and guidance supporting evidence in the Security Target and guidance documentation and have been sufficiently tested by the laboratory as documentation and have been sufficiently tested by the laboratory as part of completing [ATE_IND.1](#ATE_IND.1). Any functional packages part of completing [ATE_IND.1](#ATE_IND.1). Any functional packages this [PP](#abbr_PP) claims similarly contain their own Evaluation this [PP](#abbr_PP) claims similarly contain their own Evaluation Activities that are used in this same manner. Activities that are used in this same manner. CC Conformance Claims CC Conformance Claims : This [PP](#abbr_PP) is conformant to Part 2 (extended) and Part 3 : This [PP](#abbr_PP) is conformant to Part 2 (extended) and Part 3 (extended) of Common Criteria [CC](#abbr_CC):2022, Revision 1. (extended) of Common Criteria [CC](#abbr_CC):2022, Revision 1. PP Claim PP Claim : This [PP](#abbr_PP) does not claim conformance to any Protection : This [PP](#abbr_PP) does not claim conformance to any Protection Profile. Profile. : The following [PPs](#abbr_PP) and [PP](#abbr_PP)-Modules are allowed : The following [PPs](#abbr_PP) and [PP](#abbr_PP)-Modules are allowed to be specified in a [PP-Configuration](#abbr_PP-Configuration) with to be specified in a [PP-Configuration](#abbr_PP-Configuration) with this [PP](#abbr_PP): this [PP](#abbr_PP): - [PP-Module](#abbr_PP-Module) for [VPN](#abbr_VPN) Client, - [PP-Module](#abbr_PP-Module) for [VPN](#abbr_VPN) Client, version 3.0 version 3.0 - [PP-Module](#abbr_PP-Module) for Bluetooth, version 2.0 - [PP-Module](#abbr_PP-Module) for Bluetooth, version 2.0 - [PP-Module](#abbr_PP-Module) for [MDM](#abbr_MDM) Agent, version - [PP-Module](#abbr_PP-Module) for [MDM](#abbr_MDM) Agent, version 2.0 2.0 - [PP-Module](#abbr_PP-Module) for WLAN Client, version 2.0 - [PP-Module](#abbr_PP-Module) for WLAN Client, version 2.0 - [cPP](#abbr_cPP)-Module for Biometric Enrolment and - [cPP](#abbr_cPP)-Module for Biometric Enrolment and Verification, version 2.0 Verification, version 2.0 Package Claim Package Claim : - This [PP](#abbr_PP) is Functional Package for Transport Layer : - This [PP](#abbr_PP) is Functional Package for Transport Layer Security Version 2.1 conformant. Security Version 2.1 conformant. - This [PP](#abbr_PP) is Functional Package for X.509 Version 1.0 - This [PP](#abbr_PP) is Functional Package for X.509 Version 1.0 conformant. conformant. - This [PP](#abbr_PP) does not conform to any assurance packages. - This [PP](#abbr_PP) does not conform to any assurance packages. : The functional packages to which the [PP](#abbr_PP) conforms may : The functional packages to which the [PP](#abbr_PP) conforms may include [SFRs](#abbr_SFR) that are not mandatory to claim for the include [SFRs](#abbr_SFR) that are not mandatory to claim for the sake of conformance. An [ST](#abbr_ST) that claims one or more of sake of conformance. An [ST](#abbr_ST) that claims one or more of these functional packages may include any non-mandatory these functional packages may include any non-mandatory [SFRs](#abbr_SFR) that are appropriate to claim based on the [SFRs](#abbr_SFR) that are appropriate to claim based on the capabilities of the [TSF](#abbr_TSF) and on any triggers for their capabilities of the [TSF](#abbr_TSF) and on any triggers for their inclusion based inherently on the [SFR](#abbr_SFR) selections made. inclusion based inherently on the [SFR](#abbr_SFR) selections made. # 3 Security Problem Definition {#Security_Problem_Definition .indexable level="1"} # 3 Security Problem Definition {#Security_Problem_Definition .indexable level="1"} ## 3.1 Threats {#thr .indexable level="2"} | ## 3.1 Threats {#Threats .indexable level="2"} Mobile devices are subject to the threats of traditional computer Mobile devices are subject to the threats of traditional computer systems along with those entailed by their mobile nature. The threats systems along with those entailed by their mobile nature. The threats considered in this [PP](#abbr_PP) are those of network eavesdropping, considered in this [PP](#abbr_PP) are those of network eavesdropping, network attacks, physical access, malicious or flawed applications, network attacks, physical access, malicious or flawed applications, persistent presence, and backup as detailed in the following sections. persistent presence, and backup as detailed in the following sections. T.MALICIOUS_APP T.MALICIOUS_APP : [ Applications loaded onto the Mobile Device may include malicious | : [Applications loaded onto the Mobile Device may include malicious or or exploitable code. This code could be included intentionally or | exploitable code. This code could be included intentionally or unknowingly by the developer, perhaps as part of a software library. unknowingly by the developer, perhaps as part of a software library. Malicious apps may attempt to exfiltrate data to which they have Malicious apps may attempt to exfiltrate data to which they have access. They may also conduct attacks against the platform's system access. They may also conduct attacks against the platform's system software, which will provide them with additional privileges and the software, which will provide them with additional privileges and the ability to conduct further malicious activities. Malicious ability to conduct further malicious activities. Malicious applications may be able to control the device\'s sensors applications may be able to control the device\'s sensors ([GPS](#abbr_GPS), camera, microphone) to gather intelligence about ([GPS](#abbr_GPS), camera, microphone) to gather intelligence about the user\'s surroundings even when those activities do not involve the user\'s surroundings even when those activities do not involve data resident or transmitted from the device. Flawed applications data resident or transmitted from the device. Flawed applications may give an attacker access to perform network-based or physical may give an attacker access to perform network-based or physical attacks that otherwise would have been prevented.]{.description} attacks that otherwise would have been prevented.]{.description} T.NETWORK_ATTACK T.NETWORK_ATTACK : [ An attacker is positioned on a wireless communications channel or | : [An attacker is positioned on a wireless communications channel or elsewhere on the network infrastructure. Attackers may initiate elsewhere on the network infrastructure. Attackers may initiate communications with the Mobile Device or alter communications communications with the Mobile Device or alter communications between the Mobile Device and other endpoints in order to compromise between the Mobile Device and other endpoints in order to compromise the Mobile Device. These attacks include malicious software update the Mobile Device. These attacks include malicious software update of any applications or system software on the device. These attacks of any applications or system software on the device. These attacks also include malicious web pages or email attachments, which are also include malicious web pages or email attachments, which are usually delivered to devices over the network.]{.description} usually delivered to devices over the network.]{.description} T.NETWORK_EAVESDROP T.NETWORK_EAVESDROP : [ An attacker is positioned on a wireless communications channel or | : [An attacker is positioned on a wireless communications channel or elsewhere on the network infrastructure. Attackers may monitor and elsewhere on the network infrastructure. Attackers may monitor and gain access to data exchanged between the Mobile Device and other gain access to data exchanged between the Mobile Device and other endpoints, resulting in modification or disclosure of sensitive endpoints, resulting in modification or disclosure of sensitive communications. ]{.description} | communications.]{.description} T.PERSISTENT_PRESENCE T.PERSISTENT_PRESENCE : [ Persistent presence on a device by an attacker implies that the | : [Persistent presence on a device by an attacker implies that the device has lost integrity and cannot regain it. The device has device has lost integrity and cannot regain it. The device has likely lost this integrity due to some other threat vector, yet the likely lost this integrity due to some other threat vector, yet the continued access by an attacker constitutes an on-going threat in continued access by an attacker constitutes an on-going threat in itself. In this case, the device and its data may be controlled by itself. In this case, the device and its data may be controlled by an adversary as well as by its legitimate owner.]{.description} an adversary as well as by its legitimate owner.]{.description} T.PHYSICAL_ACCESS T.PHYSICAL_ACCESS : [ An attacker, with physical access, may attempt to access user data | : [An attacker, with physical access, may attempt to access user data on the Mobile Device including credentials. These physical access on the Mobile Device including credentials. These physical access threats may involve attacks, which attempt to access the device threats may involve attacks, which attempt to access the device through external hardware ports, impersonate the user authentication through external hardware ports, impersonate the user authentication mechanisms, through its user interface, and also through direct and mechanisms, through its user interface, and also through direct and possibly destructive access to its storage media. Note: Defending possibly destructive access to its storage media. Note: Defending against device re-use after physical compromise is out of scope for against device re-use after physical compromise is out of scope for this [PP](#abbr_PP).]{.description} this [PP](#abbr_PP).]{.description} ## 3.2 Assumptions {#assp .indexable level="2"} | ## 3.2 Assumptions {#Assumptions .indexable level="2"} The specific conditions listed below are assumed to exist in the The specific conditions listed below are assumed to exist in the [TOE](#abbr_TOE)'s Operational Environment. These include both practical [TOE](#abbr_TOE)'s Operational Environment. These include both practical realities in the development of the [TOE](#abbr_TOE) security realities in the development of the [TOE](#abbr_TOE) security requirements and the essential environmental conditions on the use of requirements and the essential environmental conditions on the use of the [TOE](#abbr_TOE). the [TOE](#abbr_TOE). A.CONFIG A.CONFIG : [It is assumed that the [TOE](#abbr_TOE)'s security functions are : [It is assumed that the [TOE](#abbr_TOE)'s security functions are configured correctly in a manner to ensure that the [TOE](#abbr_TOE) configured correctly in a manner to ensure that the [TOE](#abbr_TOE) security policies will be enforced on all applicable network traffic security policies will be enforced on all applicable network traffic flowing among the attached networks.]{.description} flowing among the attached networks.]{.description} A.NOTIFY A.NOTIFY : [It is assumed that the mobile user will immediately notify the : [It is assumed that the mobile user will immediately notify the administrator if the Mobile Device is lost or stolen.]{.description} administrator if the Mobile Device is lost or stolen.]{.description} A.PRECAUTION A.PRECAUTION : [It is assumed that the mobile user exercises precautions to reduce : [It is assumed that the mobile user exercises precautions to reduce the risk of loss or theft of the Mobile Device.]{.description} the risk of loss or theft of the Mobile Device.]{.description} A.PROPER_USER A.PROPER_USER : [ Mobile Device users are not willfully negligent or hostile, and | : [Mobile Device users are not willfully negligent or hostile, and use use the device within compliance of a reasonable Enterprise security | the device within compliance of a reasonable Enterprise security policy. ]{.description} | policy.]{.description} ## 3.3 Organizational Security Policies {#osp .indexable level="2"} | ## 3.3 Organizational Security Policies {#Organizational_Security_Policies .indexable This [PP](#abbr_PP) defines no Organizational Security Policies. This [PP](#abbr_PP) defines no Organizational Security Policies. # 4 Security Objectives {#Security_Objectives .indexable level="1"} # 4 Security Objectives {#Security_Objectives .indexable level="1"} ## 4.1 Security Objectives for the Operational Environment {#sooe .indexable level="2 ## 4.1 Security Objectives for the Operational Environment {#sooe .indexable level="2 The following security objectives for the operational environment assist The following security objectives for the operational environment assist the [OS](#abbr_OS) in correctly providing its security functionality. the [OS](#abbr_OS) in correctly providing its security functionality. These track with the assumptions about the environment. These track with the assumptions about the environment. OE.CONFIG OE.CONFIG : [[TOE](#abbr_TOE) administrators will configure the Mobile Device : [[TOE](#abbr_TOE) administrators will configure the Mobile Device security functions correctly to create the intended security security functions correctly to create the intended security policy]{.description} policy]{.description} OE.NOTIFY OE.NOTIFY : [The Mobile User will immediately notify the administrator if the : [The Mobile User will immediately notify the administrator if the Mobile Device is lost or stolen.]{.description} Mobile Device is lost or stolen.]{.description} OE.PRECAUTION OE.PRECAUTION : [The mobile device user exercises precautions to reduce the risk of : [The mobile device user exercises precautions to reduce the risk of loss or theft of the Mobile Device.]{.description} loss or theft of the Mobile Device.]{.description} OE.PROPER_USER OE.PROPER_USER : [Administrators take measures to ensure that mobile device users are : [Administrators take measures to ensure that mobile device users are adequately vetted against malicious intent and are made aware of the adequately vetted against malicious intent and are made aware of the expectations for appropriate use of the device.]{.description} expectations for appropriate use of the device.]{.description} ## 4.2 Security Objectives Rationale {#SOR .indexable,h2 level="2"} | ## 4.2 Security Objectives Rationale {#security-objectives-rationale .indexable,h2 le This section describes how the assumptions and organizational security This section describes how the assumptions and organizational security policies map to operational environment security objectives. policies map to operational environment security objectives. ---------------------------------- ------------------------------------ ----------- ---------------------------------- ------------------------------------ ----------- Assumption or OSP Security Objectives Rationale Assumption or OSP Security Objectives Rationale [A.CONFIG](#A.CONFIG) [OE.CONFIG](#OE.CONFIG) The operati [A.CONFIG](#A.CONFIG) [OE.CONFIG](#OE.CONFIG) The operati [A.NOTIFY](#A.NOTIFY) [OE.NOTIFY](#OE.NOTIFY) The operati [A.NOTIFY](#A.NOTIFY) [OE.NOTIFY](#OE.NOTIFY) The operati [A.PRECAUTION](#A.PRECAUTION) [OE.PRECAUTION](#OE.PRECAUTION) The operati [A.PRECAUTION](#A.PRECAUTION) [OE.PRECAUTION](#OE.PRECAUTION) The operati [A.PROPER\_​USER](#A.PROPER_USER) [OE.PROPER\_​USER](#OE.PROPER_USER) The operati [A.PROPER\_​USER](#A.PROPER_USER) [OE.PROPER\_​USER](#OE.PROPER_USER) The operati ---------------------------------- ------------------------------------ ----------- ---------------------------------- ------------------------------------ ----------- : [Table [1]{.counter}]{#t-sec-obj-rat .ctr myid="t-sec-obj-rat" : [Table [1]{.counter}]{#t-sec-obj-rat .ctr myid="t-sec-obj-rat" counter-type="ct-Table"}: Security Objectives Rationale counter-type="ct-Table"}: Security Objectives Rationale # 5 Security Requirements {#Security_Requirements .indexable level="1"} # 5 Security Requirements {#Security_Requirements .indexable level="1"} This chapter describes the security requirements which have to be This chapter describes the security requirements which have to be fulfilled by the product under evaluation. Those requirements comprise fulfilled by the product under evaluation. Those requirements comprise functional components from Part 2 and assurance components from Part 3 functional components from Part 2 and assurance components from Part 3 of [\[CC\]](#bibCC). The following conventions are used for the of [\[CC\]](#bibCC). The following conventions are used for the completion of operations: completion of operations: - **Refinement** operation (denoted by **bold text** or - **Refinement** operation (denoted by **bold text** or ~~strikethrough text~~): Is used to add details to a requirement or ~~strikethrough text~~): Is used to add details to a requirement or to remove part of the requirement that is made irrelevant through to remove part of the requirement that is made irrelevant through the completion of another operation, and thus further restricts a the completion of another operation, and thus further restricts a requirement. requirement. - **Selection** (denoted by *italicized text*): Is used to select one - **Selection** (denoted by *italicized text*): Is used to select one or more options provided by the \[[CC](#abbr_CC)\] in stating a or more options provided by the \[[CC](#abbr_CC)\] in stating a requirement. requirement. - **Assignment** operation (denoted by [italicized - **Assignment** operation (denoted by [italicized text]{.assignable-content}): Is used to assign a specific value to text]{.assignable-content}): Is used to assign a specific value to an unspecified parameter, such as the length of a password. Showing an unspecified parameter, such as the length of a password. Showing the value in square brackets indicates assignment. the value in square brackets indicates assignment. - **Iteration** operation: Is indicated by appending the - **Iteration** operation: Is indicated by appending the [SFR](#abbr_SFR) name with a slash and unique identifier suggesting [SFR](#abbr_SFR) name with a slash and unique identifier suggesting the purpose of the operation, e.g. \"/EXAMPLE1.\" the purpose of the operation, e.g. \"/EXAMPLE1.\" ## 5.1 Security Functional Requirements {#sfr .indexable level="2"} ## 5.1 Security Functional Requirements {#sfr .indexable level="2"} ### 5.1.1 Auditable Events for Mandatory SFRs {#ss-audit-table .indexable level="3"} ### 5.1.1 Auditable Events for Mandatory SFRs {#ss-audit-table .indexable level="3"} +-----------------------+-----------------------+-----------------------+ +-----------------------+-----------------------+-----------------------+ | Requirement | Auditable Events | Additional Audit | | Requirement | Auditable Events | Additional Audit | | | | Record Contents | | | | Record Contents | +=======================+=======================+=======================+ +=======================+=======================+=======================+ | [F | | | | [F | | | | AU_GEN.1](#FAU_GEN.1) | | | | AU_GEN.1](#FAU_GEN.1) | | | +-----------------------+-----------------------+-----------------------+ +-----------------------+-----------------------+-----------------------+ | | | | | | | | +-----------------------+-----------------------+-----------------------+ +-----------------------+-----------------------+-----------------------+ | No events specified | N/A | | | No events specified | N/A | | +-----------------------+-----------------------+-----------------------+ +-----------------------+-----------------------+-----------------------+ | [F | | | | [F | | | | AU_SAR.1](#FAU_SAR.1) | | | | AU_SAR.1](#FAU_SAR.1) | | | +-----------------------+-----------------------+-----------------------+ +-----------------------+-----------------------+-----------------------+ | | | | | | | | +-----------------------+-----------------------+-----------------------+ +-----------------------+-----------------------+-----------------------+ | No events specified | N/A | | | No events specified | N/A | | +-----------------------+-----------------------+-----------------------+ +-----------------------+-----------------------+-----------------------+ | [F | | | | [F | | | | AU_STG.2](#FAU_STG.2) | | | | AU_STG.2](#FAU_STG.2) | | | +-----------------------+-----------------------+-----------------------+ +-----------------------+-----------------------+-----------------------+ | | | | | | | | +-----------------------+-----------------------+-----------------------+ +-----------------------+-----------------------+-----------------------+ | No events specified | N/A | | | No events specified | N/A | | +-----------------------+-----------------------+-----------------------+ +-----------------------+-----------------------+-----------------------+ | [F | | | | [F | | | | AU_STG.5](#FAU_STG.5) | | | | AU_STG.5](#FAU_STG.5) | | | +-----------------------+-----------------------+-----------------------+ +-----------------------+-----------------------+-----------------------+ | | | | | | | | +-----------------------+-----------------------+-----------------------+ +-----------------------+-----------------------+-----------------------+ | No events specified | N/A | | | No events specified | N/A | | +-----------------------+-----------------------+-----------------------+ +-----------------------+-----------------------+-----------------------+ | [FCS_CKM.1 | | | | [FCS_CKM.1 | | | | /AKG](#FCS_CKM.1/AKG) | | | | /AKG](#FCS_CKM.1/AKG) | | | +-----------------------+-----------------------+-----------------------+ +-----------------------+-----------------------+-----------------------+ | | | | | | | | +-----------------------+-----------------------+-----------------------+ +-----------------------+-----------------------+-----------------------+ | No events specified | N/A | | | No events specified | N/A | | +-----------------------+-----------------------+-----------------------+ +-----------------------+-----------------------+-----------------------+ | [FCS_CKM.1 | | | | [FCS_CKM.1 | | | | /SKG](#FCS_CKM.1/SKG) | | | | /SKG](#FCS_CKM.1/SKG) | | | +-----------------------+-----------------------+-----------------------+ +-----------------------+-----------------------+-----------------------+ | | | | | | | | +-----------------------+-----------------------+-----------------------+ +-----------------------+-----------------------+-----------------------+ | No events specified | N/A | | | No events specified | N/A | | +-----------------------+-----------------------+-----------------------+ +-----------------------+-----------------------+-----------------------+ | [F | | | | [F | | | | CS_CKM.2](#FCS_CKM.2) | | | | CS_CKM.2](#FCS_CKM.2) | | | +-----------------------+-----------------------+-----------------------+ +-----------------------+-----------------------+-----------------------+ | | | | | | | | +-----------------------+-----------------------+-----------------------+ +-----------------------+-----------------------+-----------------------+ | No events specified | N/A | | | No events specified | N/A | | +-----------------------+-----------------------+-----------------------+ +-----------------------+-----------------------+-----------------------+ | [F | | | | [F | | | | CS_CKM.6](#FCS_CKM.6) | | | | CS_CKM.6](#FCS_CKM.6) | | | +-----------------------+-----------------------+-----------------------+ +-----------------------+-----------------------+-----------------------+ | | | | | | | | +-----------------------+-----------------------+-----------------------+ +-----------------------+-----------------------+-----------------------+ | No events specified | N/A | | | No events specified | N/A | | +-----------------------+-----------------------+-----------------------+ +-----------------------+-----------------------+-----------------------+ | [FCS_CKM_E | | | | [FCS_CKM_E | | | | XT.1](#FCS_CKM_EXT.1) | | | | XT.1](#FCS_CKM_EXT.1) | | | +-----------------------+-----------------------+-----------------------+ +-----------------------+-----------------------+-----------------------+ | | | | | | | | +-----------------------+-----------------------+-----------------------+ +-----------------------+-----------------------+-----------------------+ | \[**selection, choose | No additional | | | \[**selection, choose | No additional | | | one of**: [Generation | information | | | one of**: [Generation | information | | | of a | | | | of a | | | | [RE | | | | [RE | | | | K](#abbr_REK)]{#_s_98 | | | | K](#abbr_REK)]{#_s_98 | | | | .selectable-content}, | | | | .selectable-content}, | | | | [None]{#_s_99 | | | | [None]{#_s_99 | | | | . | | | | . | | | | selectable-content}\] | | | | selectable-content}\] | | | +-----------------------+-----------------------+-----------------------+ +-----------------------+-----------------------+-----------------------+ | [FCS_CKM_E | | | | [FCS_CKM_E | | | | XT.2](#FCS_CKM_EXT.2) | | | | XT.2](#FCS_CKM_EXT.2) | | | +-----------------------+-----------------------+-----------------------+ +-----------------------+-----------------------+-----------------------+ | | | | | | | | +-----------------------+-----------------------+-----------------------+ +-----------------------+-----------------------+-----------------------+ | No events specified | N/A | | | No events specified | N/A | | +-----------------------+-----------------------+-----------------------+ +-----------------------+-----------------------+-----------------------+ | [FCS_CKM_E | | | | [FCS_CKM_E | | | | XT.3](#FCS_CKM_EXT.3) | | | | XT.3](#FCS_CKM_EXT.3) | | | +-----------------------+-----------------------+-----------------------+ +-----------------------+-----------------------+-----------------------+ | | | | | | | | +-----------------------+-----------------------+-----------------------+ +-----------------------+-----------------------+-----------------------+ | No events specified | N/A | | | No events specified | N/A | | +-----------------------+-----------------------+-----------------------+ +-----------------------+-----------------------+-----------------------+ | [FCS_CKM_E | | | | [FCS_CKM_E | | | | XT.5](#FCS_CKM_EXT.5) | | | | XT.5](#FCS_CKM_EXT.5) | | | +-----------------------+-----------------------+-----------------------+ +-----------------------+-----------------------+-----------------------+ | | | | | | | | +-----------------------+-----------------------+-----------------------+ +-----------------------+-----------------------+-----------------------+ | \[**selection, choose | No additional | | | \[**selection, choose | No additional | | | one of**: [Failure of | information | | | one of**: [Failure of | information | | | the wipe]{#_s_127 | | | | the wipe]{#_s_127 | | | | .selectable-content}, | | | | .selectable-content}, | | | | [None]{#_s_128 | | | | [None]{#_s_128 | | | | . | | | | . | | | | selectable-content}\] | | | | selectable-content}\] | | | +-----------------------+-----------------------+-----------------------+ +-----------------------+-----------------------+-----------------------+ | [FCS_CKM_E | | | | [FCS_CKM_E | | | | XT.6](#FCS_CKM_EXT.6) | | | | XT.6](#FCS_CKM_EXT.6) | | | +-----------------------+-----------------------+-----------------------+ +-----------------------+-----------------------+-----------------------+ | | | | | | | | +-----------------------+-----------------------+-----------------------+ +-----------------------+-----------------------+-----------------------+ | No events specified | N/A | | | No events specified | N/A | | +-----------------------+-----------------------+-----------------------+ +-----------------------+-----------------------+-----------------------+ | [FC | | | | [FC | | | | S_CKM_EXT.7/LOCKED](# | | | | S_CKM_EXT.7/LOCKED](# | | | | FCS_CKM_EXT.7/LOCKED) | | | | FCS_CKM_EXT.7/LOCKED) | | | +-----------------------+-----------------------+-----------------------+ +-----------------------+-----------------------+-----------------------+ | | | | | | | | +-----------------------+-----------------------+-----------------------+ +-----------------------+-----------------------+-----------------------+ | No events specified | N/A | | | No events specified | N/A | | +-----------------------+-----------------------+-----------------------+ +-----------------------+-----------------------+-----------------------+ | [FCS_CKM_E | | | | [FCS_CKM_E | | | | XT.8](#FCS_CKM_EXT.8) | | | | XT.8](#FCS_CKM_EXT.8) | | | +-----------------------+-----------------------+-----------------------+ +-----------------------+-----------------------+-----------------------+ | | | | | | | | +-----------------------+-----------------------+-----------------------+ +-----------------------+-----------------------+-----------------------+ | No events specified | N/A | | | No events specified | N/A | | +-----------------------+-----------------------+-----------------------+ +-----------------------+-----------------------+-----------------------+ | [FCS_COP.1/A | | | | [FCS_COP.1/A | | | | EAD](#FCS_COP.1/AEAD) | | | | EAD](#FCS_COP.1/AEAD) | | | +-----------------------+-----------------------+-----------------------+ +-----------------------+-----------------------+-----------------------+ | | | | | | | | +-----------------------+-----------------------+-----------------------+ +-----------------------+-----------------------+-----------------------+ | No events specified | N/A | | | No events specified | N/A | | +-----------------------+-----------------------+-----------------------+ +-----------------------+-----------------------+-----------------------+ | [FCS_COP.1/H | | | | [FCS_COP.1/H | | | | ash](#FCS_COP.1/Hash) | | | | ash](#FCS_COP.1/Hash) | | | +-----------------------+-----------------------+-----------------------+ +-----------------------+-----------------------+-----------------------+ | | | | | | | | +-----------------------+-----------------------+-----------------------+ +-----------------------+-----------------------+-----------------------+ | No events specified | N/A | | | No events specified | N/A | | +-----------------------+-----------------------+-----------------------+ +-----------------------+-----------------------+-----------------------+ | [FCS_COP.1/KeyWrap | | | | [FCS_COP.1/KeyWrap | | | | ](#FCS_COP.1/KeyWrap) | | | | ](#FCS_COP.1/KeyWrap) | | | +-----------------------+-----------------------+-----------------------+ +-----------------------+-----------------------+-----------------------+ | | | | | | | | +-----------------------+-----------------------+-----------------------+ +-----------------------+-----------------------+-----------------------+ | No events specified | N/A | | | No events specified | N/A | | +-----------------------+-----------------------+-----------------------+ +-----------------------+-----------------------+-----------------------+ | [ | | | | [ | | | | FCS_COP.1/KeyedHash]( | | | | FCS_COP.1/KeyedHash]( | | | | #FCS_COP.1/KeyedHash) | | | | #FCS_COP.1/KeyedHash) | | | +-----------------------+-----------------------+-----------------------+ +-----------------------+-----------------------+-----------------------+ | | | | | | | | +-----------------------+-----------------------+-----------------------+ +-----------------------+-----------------------+-----------------------+ | No events specified | N/A | | | No events specified | N/A | | +-----------------------+-----------------------+-----------------------+ +-----------------------+-----------------------+-----------------------+ | [FCS_COP.1 | | | | [FCS_COP.1 | | | | /SKC](#FCS_COP.1/SKC) | | | | /SKC](#FCS_COP.1/SKC) | | | +-----------------------+-----------------------+-----------------------+ +-----------------------+-----------------------+-----------------------+ | | | | | | | | +-----------------------+-----------------------+-----------------------+ +-----------------------+-----------------------+-----------------------+ | No events specified | N/A | | | No events specified | N/A | | +-----------------------+-----------------------+-----------------------+ +-----------------------+-----------------------+-----------------------+ | [FCS_COP.1/SigGe | | | | [FCS_COP.1/SigGe | | | | n](#FCS_COP.1/SigGen) | | | | n](#FCS_COP.1/SigGen) | | | +-----------------------+-----------------------+-----------------------+ +-----------------------+-----------------------+-----------------------+ | | | | | | | | +-----------------------+-----------------------+-----------------------+ +-----------------------+-----------------------+-----------------------+ | No events specified | N/A | | | No events specified | N/A | | +-----------------------+-----------------------+-----------------------+ +-----------------------+-----------------------+-----------------------+ | [FCS_COP.1/SigVe | | | | [FCS_COP.1/SigVe | | | | r](#FCS_COP.1/SigVer) | | | | r](#FCS_COP.1/SigVer) | | | +-----------------------+-----------------------+-----------------------+ +-----------------------+-----------------------+-----------------------+ | | | | | | | | +-----------------------+-----------------------+-----------------------+ +-----------------------+-----------------------+-----------------------+ | No events specified | N/A | | | No events specified | N/A | | +-----------------------+-----------------------+-----------------------+ +-----------------------+-----------------------+-----------------------+ | [FCS_HTTPS_EXT | | | | [FCS_HTTPS_EXT | | | | .1](#FCS_HTTPS_EXT.1) | | | | .1](#FCS_HTTPS_EXT.1) | | | +-----------------------+-----------------------+-----------------------+ +-----------------------+-----------------------+-----------------------+ | | | | | | | | +-----------------------+-----------------------+-----------------------+ +-----------------------+-----------------------+-----------------------+ | Failure of the | - Issuer Name and | | | Failure of the | - Issuer Name and | | | certificate validity | Subject Name of | | | certificate validity | Subject Name of | | | check. | certificate | | | check. | certificate | | | | - \[**selection, | | | | - \[**selection, | | | | choose one of**: | | | | choose one of**: | | | | [User's | | | | [User's | | | | authorization | | | | authorization | | | | decision]{#_s_358 | | | | decision]{#_s_358 | | | | | | | | | | | | .selectable-content}, | | | | .selectable-content}, | | | | [No additional | | | | [No additional | | | | | | | | | | | | information]{#_s_359 | | | | information]{#_s_359 | | | | . | | | | . | | | | selectable-content}\] | | | | selectable-content}\] | | +-----------------------+-----------------------+-----------------------+ +-----------------------+-----------------------+-----------------------+ | [FCS_IV_ | | | | [FCS_IV_ | | | | EXT.1](#FCS_IV_EXT.1) | | | | EXT.1](#FCS_IV_EXT.1) | | | +-----------------------+-----------------------+-----------------------+ +-----------------------+-----------------------+-----------------------+ | | | | | | | | +-----------------------+-----------------------+-----------------------+ +-----------------------+-----------------------+-----------------------+ | No events specified | N/A | | | No events specified | N/A | | +-----------------------+-----------------------+-----------------------+ +-----------------------+-----------------------+-----------------------+ | [F | | | | [F | | | | CS_RBG.1](#FCS_RBG.1) | | | | CS_RBG.1](#FCS_RBG.1) | | | +-----------------------+-----------------------+-----------------------+ +-----------------------+-----------------------+-----------------------+ | | | | | | | | +-----------------------+-----------------------+-----------------------+ +-----------------------+-----------------------+-----------------------+ | No events specified | N/A | | | No events specified | N/A | | +-----------------------+-----------------------+-----------------------+ +-----------------------+-----------------------+-----------------------+ | [F | | | | [F | | | | CS_RBG.6](#FCS_RBG.6) | | | | CS_RBG.6](#FCS_RBG.6) | | | +-----------------------+-----------------------+-----------------------+ +-----------------------+-----------------------+-----------------------+ | | | | | | | | +-----------------------+-----------------------+-----------------------+ +-----------------------+-----------------------+-----------------------+ | No events specified | N/A | | | No events specified | N/A | | +-----------------------+-----------------------+-----------------------+ +-----------------------+-----------------------+-----------------------+ | [FCS_SRV_E | | | | [FCS_SRV_E | | | | XT.1](#FCS_SRV_EXT.1) | | | | XT.1](#FCS_SRV_EXT.1) | | | +-----------------------+-----------------------+-----------------------+ +-----------------------+-----------------------+-----------------------+ | | | | | | | | +-----------------------+-----------------------+-----------------------+ +-----------------------+-----------------------+-----------------------+ | No events specified | N/A | | | No events specified | N/A | | +-----------------------+-----------------------+-----------------------+ +-----------------------+-----------------------+-----------------------+ | [FCS_STG_E | | | | [FCS_STG_E | | | | XT.1](#FCS_STG_EXT.1) | | | | XT.1](#FCS_STG_EXT.1) | | | +-----------------------+-----------------------+-----------------------+ +-----------------------+-----------------------+-----------------------+ | | | | | | | | +-----------------------+-----------------------+-----------------------+ +-----------------------+-----------------------+-----------------------+ | | \[**selection, choose | - Identity of key | | | \[**selection, choose | - Identity of key | | | one of**: [Exceptions | - Role and identity | | | one of**: [Exceptions | - Role and identity | | | to use and | of requester | | | to use and | of requester | | | destruction | | | | destruction | | | | rules]{#_s_418 | | | | rules]{#_s_418 | | | | .selectable-content}, | | | | .selectable-content}, | | | | [None]{#_s_419 | | | | [None]{#_s_419 | | | | . | | | | . | | | | selectable-content}\] | | | | selectable-content}\] | | +-----------------------+-----------------------+-----------------------+ +-----------------------+-----------------------+-----------------------+ | Import or destruction | - Identity of key | | | Import or destruction | - Identity of key | | | of key | - Role and identity | | | of key | - Role and identity | | | | of requester | | | | of requester | | +-----------------------+-----------------------+-----------------------+ +-----------------------+-----------------------+-----------------------+ | [FCS_STG_E | | | | [FCS_STG_E | | | | XT.2](#FCS_STG_EXT.2) | | | | XT.2](#FCS_STG_EXT.2) | | | +-----------------------+-----------------------+-----------------------+ +-----------------------+-----------------------+-----------------------+ | | | | | | | | +-----------------------+-----------------------+-----------------------+ +-----------------------+-----------------------+-----------------------+ | No events specified | N/A | | | No events specified | N/A | | +-----------------------+-----------------------+-----------------------+ +-----------------------+-----------------------+-----------------------+ | [FCS_STG_E | | | | [FCS_STG_E | | | | XT.3](#FCS_STG_EXT.3) | | | | XT.3](#FCS_STG_EXT.3) | | | +-----------------------+-----------------------+-----------------------+ +-----------------------+-----------------------+-----------------------+ | | | | | | | | +-----------------------+-----------------------+-----------------------+ +-----------------------+-----------------------+-----------------------+ | Failure to verify | Identity of key being | | | Failure to verify | Identity of key being | | | integrity of stored | verified | | | integrity of stored | verified | | | key | | | | key | | | +-----------------------+-----------------------+-----------------------+ +-----------------------+-----------------------+-----------------------+ | [FDP_ACF_E | | | | [FDP_ACF_E | | | | XT.1](#FDP_ACF_EXT.1) | | | | XT.1](#FDP_ACF_EXT.1) | | | +-----------------------+-----------------------+-----------------------+ +-----------------------+-----------------------+-----------------------+ | | | | | | | | +-----------------------+-----------------------+-----------------------+ +-----------------------+-----------------------+-----------------------+ | No events specified | N/A | | | No events specified | N/A | | +-----------------------+-----------------------+-----------------------+ +-----------------------+-----------------------+-----------------------+ | [FDP_DAR_E | | | | [FDP_DAR_E | | | | XT.1](#FDP_DAR_EXT.1) | | | | XT.1](#FDP_DAR_EXT.1) | | | +-----------------------+-----------------------+-----------------------+ +-----------------------+-----------------------+-----------------------+ | | | | | | | | +-----------------------+-----------------------+-----------------------+ +-----------------------+-----------------------+-----------------------+ | \[**selection, choose | No additional | | | \[**selection, choose | No additional | | | one of**: [Failure to | information | | | one of**: [Failure to | information | | | encrypt/decrypt | | | | encrypt/decrypt | | | | data]{#_s_490 | | | | data]{#_s_490 | | | | .selectable-content}, | | | | .selectable-content}, | | | | [None]{#_s_491 | | | | [None]{#_s_491 | | | | . | | | | . | | | | selectable-content}\] | | | | selectable-content}\] | | | +-----------------------+-----------------------+-----------------------+ +-----------------------+-----------------------+-----------------------+ | [FDP_DAR_E | | | | [FDP_DAR_E | | | | XT.2](#FDP_DAR_EXT.2) | | | | XT.2](#FDP_DAR_EXT.2) | | | +-----------------------+-----------------------+-----------------------+ +-----------------------+-----------------------+-----------------------+ | | | | | | | | +-----------------------+-----------------------+-----------------------+ +-----------------------+-----------------------+-----------------------+ | \[**selection, choose | No additional | | | \[**selection, choose | No additional | | | one of**: [Failure to | information | | | one of**: [Failure to | information | | | encrypt/decrypt | | | | encrypt/decrypt | | | | data]{#_s_492 | | | | data]{#_s_492 | | | | .selectable-content}, | | | | .selectable-content}, | | | | [None]{#_s_493 | | | | [None]{#_s_493 | | | | . | | | | . | | | | selectable-content}\] | | | | selectable-content}\] | | | +-----------------------+-----------------------+-----------------------+ +-----------------------+-----------------------+-----------------------+ | [FDP_IFC_E | | | | [FDP_IFC_E | | | | XT.1](#FDP_IFC_EXT.1) | | | | XT.1](#FDP_IFC_EXT.1) | | | +-----------------------+-----------------------+-----------------------+ +-----------------------+-----------------------+-----------------------+ | | | | | | | | +-----------------------+-----------------------+-----------------------+ +-----------------------+-----------------------+-----------------------+ | No events specified | N/A | | | No events specified | N/A | | +-----------------------+-----------------------+-----------------------+ +-----------------------+-----------------------+-----------------------+ | [FDP_STG_E | | | | [FDP_STG_E | | | | XT.1](#FDP_STG_EXT.1) | | | | XT.1](#FDP_STG_EXT.1) | | | +-----------------------+-----------------------+-----------------------+ +-----------------------+-----------------------+-----------------------+ | | | | | | | | +-----------------------+-----------------------+-----------------------+ +-----------------------+-----------------------+-----------------------+ | Addition or removal | Subject name of | | | Addition or removal | Subject name of | | | of certificate from | certificate | | | of certificate from | certificate | | | Trust Anchor Database | | | | Trust Anchor Database | | | +-----------------------+-----------------------+-----------------------+ +-----------------------+-----------------------+-----------------------+ | [FDP_UPC_EXT.1/APPS] | | | | [FDP_UPC_EXT.1/APPS] | | | | (#FDP_UPC_EXT.1/APPS) | | | | (#FDP_UPC_EXT.1/APPS) | | | +-----------------------+-----------------------+-----------------------+ +-----------------------+-----------------------+-----------------------+ | | | | | | | | +-----------------------+-----------------------+-----------------------+ +-----------------------+-----------------------+-----------------------+ | Application | - Name of | | | Application | - Name of | | | initiation of trusted | application | | | initiation of trusted | application | | | channel | - Trusted channel | | | channel | - Trusted channel | | | | protocol | | | | protocol | | | | - Non-TOE endpoint | | | | - Non-TOE endpoint | | | | of connection | | | | of connection | | +-----------------------+-----------------------+-----------------------+ +-----------------------+-----------------------+-----------------------+ | [FIA_AFL_E | | | | [FIA_AFL_E | | | | XT.1](#FIA_AFL_EXT.1) | | | | XT.1](#FIA_AFL_EXT.1) | | | +-----------------------+-----------------------+-----------------------+ +-----------------------+-----------------------+-----------------------+ | | | | | | | | +-----------------------+-----------------------+-----------------------+ +-----------------------+-----------------------+-----------------------+ | Excess of | Authentication factor | | | Excess of | Authentication factor | | | authentication | used | | | authentication | used | | | failure limit | | | | failure limit | | | +-----------------------+-----------------------+-----------------------+ +-----------------------+-----------------------+-----------------------+ | [FIA_PMG_E | | | | [FIA_PMG_E | | | | XT.1](#FIA_PMG_EXT.1) | | | | XT.1](#FIA_PMG_EXT.1) | | | +-----------------------+-----------------------+-----------------------+ +-----------------------+-----------------------+-----------------------+ | | | | | | | | +-----------------------+-----------------------+-----------------------+ +-----------------------+-----------------------+-----------------------+ | No events specified | N/A | | | No events specified | N/A | | +-----------------------+-----------------------+-----------------------+ +-----------------------+-----------------------+-----------------------+ | [FIA_TRT_E | | | | [FIA_TRT_E | | | | XT.1](#FIA_TRT_EXT.1) | | | | XT.1](#FIA_TRT_EXT.1) | | | +-----------------------+-----------------------+-----------------------+ +-----------------------+-----------------------+-----------------------+ | | | | | | | | +-----------------------+-----------------------+-----------------------+ +-----------------------+-----------------------+-----------------------+ | No events specified | N/A | | | No events specified | N/A | | +-----------------------+-----------------------+-----------------------+ +-----------------------+-----------------------+-----------------------+ | [F | | | | [F | | | | IA_UAU.5](#FIA_UAU.5) | | | | IA_UAU.5](#FIA_UAU.5) | | | +-----------------------+-----------------------+-----------------------+ +-----------------------+-----------------------+-----------------------+ | | | | | | | | +-----------------------+-----------------------+-----------------------+ +-----------------------+-----------------------+-----------------------+ | No events specified | N/A | | | No events specified | N/A | | +-----------------------+-----------------------+-----------------------+ +-----------------------+-----------------------+-----------------------+ | [FI | | | | [FI | | | | A_UAU.6/CREDENTIAL](# | | | | A_UAU.6/CREDENTIAL](# | | | | FIA_UAU.6/CREDENTIAL) | | | | FIA_UAU.6/CREDENTIAL) | | | +-----------------------+-----------------------+-----------------------+ +-----------------------+-----------------------+-----------------------+ | | | | | | | | +-----------------------+-----------------------+-----------------------+ +-----------------------+-----------------------+-----------------------+ | No events specified | N/A | | | No events specified | N/A | | +-----------------------+-----------------------+-----------------------+ +-----------------------+-----------------------+-----------------------+ | [FIA_UAU.6/LOCKE | | | | [FIA_UAU.6/LOCKE | | | | D](#FIA_UAU.6/LOCKED) | | | | D](#FIA_UAU.6/LOCKED) | | | +-----------------------+-----------------------+-----------------------+ +-----------------------+-----------------------+-----------------------+ | | | | | | | | +-----------------------+-----------------------+-----------------------+ +-----------------------+-----------------------+-----------------------+ | User changes Password | No additional | | | User changes Password | No additional | | | Authentication Factor | information | | | Authentication Factor | information | | +-----------------------+-----------------------+-----------------------+ +-----------------------+-----------------------+-----------------------+ | [F | | | | [F | | | | IA_UAU.7](#FIA_UAU.7) | | | | IA_UAU.7](#FIA_UAU.7) | | | +-----------------------+-----------------------+-----------------------+ +-----------------------+-----------------------+-----------------------+ | | | | | | | | +-----------------------+-----------------------+-----------------------+ +-----------------------+-----------------------+-----------------------+ | No events specified | N/A | | | No events specified | N/A | | +-----------------------+-----------------------+-----------------------+ +-----------------------+-----------------------+-----------------------+ | [FIA_UAU_E | | | | [FIA_UAU_E | | | | XT.1](#FIA_UAU_EXT.1) | | | | XT.1](#FIA_UAU_EXT.1) | | | +-----------------------+-----------------------+-----------------------+ +-----------------------+-----------------------+-----------------------+ | | | | | | | | +-----------------------+-----------------------+-----------------------+ +-----------------------+-----------------------+-----------------------+ | No events specified | N/A | | | No events specified | N/A | | +-----------------------+-----------------------+-----------------------+ +-----------------------+-----------------------+-----------------------+ | [FIA_UAU_E | | | | [FIA_UAU_E | | | | XT.2](#FIA_UAU_EXT.2) | | | | XT.2](#FIA_UAU_EXT.2) | | | +-----------------------+-----------------------+-----------------------+ +-----------------------+-----------------------+-----------------------+ | | | | | | | | +-----------------------+-----------------------+-----------------------+ +-----------------------+-----------------------+-----------------------+ | Action performed | No additional | | | Action performed | No additional | | | before authentication | information | | | before authentication | information | | +-----------------------+-----------------------+-----------------------+ +-----------------------+-----------------------+-----------------------+ | [FIA_X509_EX | | | | [FIA_X509_EX | | | | T.6](#FIA_X509_EXT.6) | | | | T.6](#FIA_X509_EXT.6) | | | +-----------------------+-----------------------+-----------------------+ +-----------------------+-----------------------+-----------------------+ | | | | | | | | +-----------------------+-----------------------+-----------------------+ +-----------------------+-----------------------+-----------------------+ | No events specified | N/A | | | No events specified | N/A | | +-----------------------+-----------------------+-----------------------+ +-----------------------+-----------------------+-----------------------+ | [FMT_MOF_E | | | | [FMT_MOF_E | | | | XT.1](#FMT_MOF_EXT.1) | | | | XT.1](#FMT_MOF_EXT.1) | | | +-----------------------+-----------------------+-----------------------+ +-----------------------+-----------------------+-----------------------+ | | | | | | | | +-----------------------+-----------------------+-----------------------+ +-----------------------+-----------------------+-----------------------+ | No events specified | N/A | | | No events specified | N/A | | +-----------------------+-----------------------+-----------------------+ +-----------------------+-----------------------+-----------------------+ | [FMT_SMF_E | | | | [FMT_SMF_E | | | | XT.1](#FMT_SMF_EXT.1) | | | | XT.1](#FMT_SMF_EXT.1) | | | +-----------------------+-----------------------+-----------------------+ +-----------------------+-----------------------+-----------------------+ | | | | | | | | +-----------------------+-----------------------+-----------------------+ +-----------------------+-----------------------+-----------------------+ | | Initiation of | Name and version of | | | Initiation of | Name and version of | | | application | application | | | application | application | | | installation or | | | | installation or | | | | update | | | | update | | +-----------------------+-----------------------+-----------------------+ +-----------------------+-----------------------+-----------------------+ | | Initiation of policy | Policy name | | | Initiation of policy | Policy name | | | update | | | | update | | +-----------------------+-----------------------+-----------------------+ +-----------------------+-----------------------+-----------------------+ | | Change of settings | - Role of user that | | | Change of settings | - Role of user that | | | | changed setting | | | | changed setting | | | | - Value of new | | | | - Value of new | | | | setting | | | | setting | +-----------------------+-----------------------+-----------------------+ +-----------------------+-----------------------+-----------------------+ | | Success or failure of | - Role of user that | | | Success or failure of | - Role of user that | | | function | performed | | | function | performed | | | | function | | | | function | | | | - Function | | | | - Function | | | | performed | | | | performed | | | | - Reason for | | | | - Reason for | | | | failure | | | | failure | +-----------------------+-----------------------+-----------------------+ +-----------------------+-----------------------+-----------------------+ | Initiation of | Version of update | | | Initiation of | Version of update | | | software update | | | | software update | | | +-----------------------+-----------------------+-----------------------+ +-----------------------+-----------------------+-----------------------+ | [FMT_SMF_E | | | | [FMT_SMF_E | | | | XT.2](#FMT_SMF_EXT.2) | | | | XT.2](#FMT_SMF_EXT.2) | | | +-----------------------+-----------------------+-----------------------+ +-----------------------+-----------------------+-----------------------+ | | | | | | | | +-----------------------+-----------------------+-----------------------+ +-----------------------+-----------------------+-----------------------+ | | Initiation of | - Identity of | | | Initiation of | - Identity of | | | unenrollment | administrator | | | unenrollment | administrator | | | | - Failure of | | | | - Failure of | | | | accepting command | | | | accepting command | | | | to unenroll | | | | to unenroll | +-----------------------+-----------------------+-----------------------+ +-----------------------+-----------------------+-----------------------+ | Unenrollment | Remediation action | | | Unenrollment | Remediation action | | | | performed | | | | performed | | +-----------------------+-----------------------+-----------------------+ +-----------------------+-----------------------+-----------------------+ | [FPT_AEX_E | | | | [FPT_AEX_E | | | | XT.1](#FPT_AEX_EXT.1) | | | | XT.1](#FPT_AEX_EXT.1) | | | +-----------------------+-----------------------+-----------------------+ +-----------------------+-----------------------+-----------------------+ | | | | | | | | +-----------------------+-----------------------+-----------------------+ +-----------------------+-----------------------+-----------------------+ | No events specified | N/A | | | No events specified | N/A | | +-----------------------+-----------------------+-----------------------+ +-----------------------+-----------------------+-----------------------+ | [FPT_AEX_E | | | | [FPT_AEX_E | | | | XT.2](#FPT_AEX_EXT.2) | | | | XT.2](#FPT_AEX_EXT.2) | | | +-----------------------+-----------------------+-----------------------+ +-----------------------+-----------------------+-----------------------+ | | | | | | | | +-----------------------+-----------------------+-----------------------+ +-----------------------+-----------------------+-----------------------+ | No events specified | N/A | | | No events specified | N/A | | +-----------------------+-----------------------+-----------------------+ +-----------------------+-----------------------+-----------------------+ | [FPT_AEX_E | | | | [FPT_AEX_E | | | | XT.3](#FPT_AEX_EXT.3) | | | | XT.3](#FPT_AEX_EXT.3) | | | +-----------------------+-----------------------+-----------------------+ +-----------------------+-----------------------+-----------------------+ | | | | | | | | +-----------------------+-----------------------+-----------------------+ +-----------------------+-----------------------+-----------------------+ | No events specified | N/A | | | No events specified | N/A | | +-----------------------+-----------------------+-----------------------+ +-----------------------+-----------------------+-----------------------+ | [FPT_AEX_E | | | | [FPT_AEX_E | | | | XT.4](#FPT_AEX_EXT.4) | | | | XT.4](#FPT_AEX_EXT.4) | | | +-----------------------+-----------------------+-----------------------+ +-----------------------+-----------------------+-----------------------+ | | | | | | | | +-----------------------+-----------------------+-----------------------+ +-----------------------+-----------------------+-----------------------+ | No events specified | N/A | | | No events specified | N/A | | +-----------------------+-----------------------+-----------------------+ +-----------------------+-----------------------+-----------------------+ | [F | | | | [F | | | | PT_FLS.1](#FPT_FLS.1) | | | | PT_FLS.1](#FPT_FLS.1) | | | +-----------------------+-----------------------+-----------------------+ +-----------------------+-----------------------+-----------------------+ | | | | | | | | +-----------------------+-----------------------+-----------------------+ +-----------------------+-----------------------+-----------------------+ | No events specified | N/A | | | No events specified | N/A | | +-----------------------+-----------------------+-----------------------+ +-----------------------+-----------------------+-----------------------+ | [FPT_JTA_E | | | | [FPT_JTA_E | | | | XT.1](#FPT_JTA_EXT.1) | | | | XT.1](#FPT_JTA_EXT.1) | | | +-----------------------+-----------------------+-----------------------+ +-----------------------+-----------------------+-----------------------+ | | | | | | | | +-----------------------+-----------------------+-----------------------+ +-----------------------+-----------------------+-----------------------+ | No events specified | N/A | | | No events specified | N/A | | +-----------------------+-----------------------+-----------------------+ +-----------------------+-----------------------+-----------------------+ | [FPT_KST_E | | | | [FPT_KST_E | | | | XT.1](#FPT_KST_EXT.1) | | | | XT.1](#FPT_KST_EXT.1) | | | +-----------------------+-----------------------+-----------------------+ +-----------------------+-----------------------+-----------------------+ | | | | | | | | +-----------------------+-----------------------+-----------------------+ +-----------------------+-----------------------+-----------------------+ | No events specified | N/A | | | No events specified | N/A | | +-----------------------+-----------------------+-----------------------+ +-----------------------+-----------------------+-----------------------+ | [FPT_KST_E | | | | [FPT_KST_E | | | | XT.2](#FPT_KST_EXT.2) | | | | XT.2](#FPT_KST_EXT.2) | | | +-----------------------+-----------------------+-----------------------+ +-----------------------+-----------------------+-----------------------+ | | | | | | | | +-----------------------+-----------------------+-----------------------+ +-----------------------+-----------------------+-----------------------+ | No events specified | N/A | | | No events specified | N/A | | +-----------------------+-----------------------+-----------------------+ +-----------------------+-----------------------+-----------------------+ | [FPT_KST_E | | | | [FPT_KST_E | | | | XT.3](#FPT_KST_EXT.3) | | | | XT.3](#FPT_KST_EXT.3) | | | +-----------------------+-----------------------+-----------------------+ +-----------------------+-----------------------+-----------------------+ | | | | | | | | +-----------------------+-----------------------+-----------------------+ +-----------------------+-----------------------+-----------------------+ | No events specified | N/A | | | No events specified | N/A | | +-----------------------+-----------------------+-----------------------+ +-----------------------+-----------------------+-----------------------+ | [FPT_NOT_E | | | | [FPT_NOT_E | | | | XT.1](#FPT_NOT_EXT.1) | | | | XT.1](#FPT_NOT_EXT.1) | | | +-----------------------+-----------------------+-----------------------+ +-----------------------+-----------------------+-----------------------+ | | | | | | | | +-----------------------+-----------------------+-----------------------+ +-----------------------+-----------------------+-----------------------+ | \[**selection, choose | \[**selection, choose | | | \[**selection, choose | \[**selection, choose | | | one of**: | one of**: [Integrity | | | one of**: | one of**: [Integrity | | | [Measurement of | verification | | | [Measurement of | verification | | | [TSF](#abbr_TSF) | value]{#_s_598 | | | [TSF](#abbr_TSF) | value]{#_s_598 | | | software]{#_s_596 | .selectable-content}, | | | software]{#_s_596 | .selectable-content}, | | | .selectable-content}, | [No additional | | | .selectable-content}, | [No additional | | | [None]{#_s_597 | information]{#_s_599 | | | [None]{#_s_597 | information]{#_s_599 | | | . | . | | | . | . | | | selectable-content}\] | selectable-content}\] | | | selectable-content}\] | selectable-content}\] | | +-----------------------+-----------------------+-----------------------+ +-----------------------+-----------------------+-----------------------+ | [F | | | | [F | | | | PT_STM.1](#FPT_STM.1) | | | | PT_STM.1](#FPT_STM.1) | | | +-----------------------+-----------------------+-----------------------+ +-----------------------+-----------------------+-----------------------+ | | | | | | | | +-----------------------+-----------------------+-----------------------+ +-----------------------+-----------------------+-----------------------+ | No events specified | N/A | | | No events specified | N/A | | +-----------------------+-----------------------+-----------------------+ +-----------------------+-----------------------+-----------------------+ | [F | | | | [F | | | | PT_TST.1](#FPT_TST.1) | | | | PT_TST.1](#FPT_TST.1) | | | +-----------------------+-----------------------+-----------------------+ +-----------------------+-----------------------+-----------------------+ | | | | | | | | +-----------------------+-----------------------+-----------------------+ +-----------------------+-----------------------+-----------------------+ | Execution of | None. | | | Execution of | None. | | | self-tests | | | | self-tests | | | +-----------------------+-----------------------+-----------------------+ +-----------------------+-----------------------+-----------------------+ | [FPT_TST_E | | | | [FPT_TST_E | | | | XT.1](#FPT_TST_EXT.1) | | | | XT.1](#FPT_TST_EXT.1) | | | +-----------------------+-----------------------+-----------------------+ +-----------------------+-----------------------+-----------------------+ | | | | | | | | +-----------------------+-----------------------+-----------------------+ +-----------------------+-----------------------+-----------------------+ | | Initiation of | No additional | | | Initiation of | No additional | | | self-test | information | | | self-test | information | +-----------------------+-----------------------+-----------------------+ +-----------------------+-----------------------+-----------------------+ | Failure of self-test | \[**selection, choose | | | Failure of self-test | \[**selection, choose | | | | one of**: [Algorithm | | | | one of**: [Algorithm | | | | that caused the | | | | that caused the | | | | failure]{#_s_606 | | | | failure]{#_s_606 | | | | .selectable-content}, | | | | .selectable-content}, | | | | [No additional | | | | [No additional | | | | information]{#_s_607 | | | | information]{#_s_607 | | | | . | | | | . | | | | selectable-content}\] | | | | selectable-content}\] | | +-----------------------+-----------------------+-----------------------+ +-----------------------+-----------------------+-----------------------+ | [FPT_TST_ | | | | [FPT_TST_ | | | | EXT.2/PREKERNEL](#FPT | | | | EXT.2/PREKERNEL](#FPT | | | | _TST_EXT.2/PREKERNEL) | | | | _TST_EXT.2/PREKERNEL) | | | +-----------------------+-----------------------+-----------------------+ +-----------------------+-----------------------+-----------------------+ | | | | | | | | +-----------------------+-----------------------+-----------------------+ +-----------------------+-----------------------+-----------------------+ | | Start-up of | No additional | | | Start-up of | No additional | | | [TOE](#abbr_TOE) | information | | | [TOE](#abbr_TOE) | information | +-----------------------+-----------------------+-----------------------+ +-----------------------+-----------------------+-----------------------+ | \[**selection, choose | \[**selection, choose | | | \[**selection, choose | \[**selection, choose | | | one of**: [Detected | one of**: [The | | | one of**: [Detected | one of**: [The | | | integrity | [TSF](#abbr_TSF) code | | | integrity | [TSF](#abbr_TSF) code | | | violation]{#_s_614 | file that caused the | | | | violation]{#_s_625 | file that caused the | | | .selectable-content}, | integrity | | | .selectable-content}, | integrity | | | [None]{#_s_615 | violation]{#_s_616 | | | | [None]{#_s_626 | violation]{#_s_627 | | | . | .selectable-content}, | | | . | .selectable-content}, | | | selectable-content}\] | [No additional | | | selectable-content}\] | [No additional | | | | information]{#_s_617 | | | | | information]{#_s_628 | | | | . | | | | . | | | | selectable-content}\] | | | | selectable-content}\] | | +-----------------------+-----------------------+-----------------------+ +-----------------------+-----------------------+-----------------------+ | [FPT_TUD_E | | | | [FPT_TUD_E | | | | XT.1](#FPT_TUD_EXT.1) | | | | XT.1](#FPT_TUD_EXT.1) | | | +-----------------------+-----------------------+-----------------------+ +-----------------------+-----------------------+-----------------------+ | | | | | | | | +-----------------------+-----------------------+-----------------------+ +-----------------------+-----------------------+-----------------------+ | No events specified | N/A | | | No events specified | N/A | | +-----------------------+-----------------------+-----------------------+ +-----------------------+-----------------------+-----------------------+ | [FPT_TUD_E | | | | [FPT_TUD_E | | | | XT.2](#FPT_TUD_EXT.2) | | | | XT.2](#FPT_TUD_EXT.2) | | | +-----------------------+-----------------------+-----------------------+ +-----------------------+-----------------------+-----------------------+ | | | | | | | | +-----------------------+-----------------------+-----------------------+ +-----------------------+-----------------------+-----------------------+ | Success or failure of | No additional | | | Success or failure of | No additional | | | signature | information | | | signature | information | | | verification for | | | | verification for | | | | software updates | | | | software updates | | | +-----------------------+-----------------------+-----------------------+ +-----------------------+-----------------------+-----------------------+ | [FPT_TUD_E | | | | [FPT_TUD_E | | | | XT.3](#FPT_TUD_EXT.3) | | | | XT.3](#FPT_TUD_EXT.3) | | | +-----------------------+-----------------------+-----------------------+ +-----------------------+-----------------------+-----------------------+ | | | | | | | | +-----------------------+-----------------------+-----------------------+ +-----------------------+-----------------------+-----------------------+ | Success or failure of | No additional | | | Success or failure of | No additional | | | signature | information | | | signature | information | | | verification for | | | | verification for | | | | applications | | | | applications | | | +-----------------------+-----------------------+-----------------------+ +-----------------------+-----------------------+-----------------------+ | [FTA_SSL_E | | | | [FTA_SSL_E | | | | XT.1](#FTA_SSL_EXT.1) | | | | XT.1](#FTA_SSL_EXT.1) | | | +-----------------------+-----------------------+-----------------------+ +-----------------------+-----------------------+-----------------------+ | | | | | | | | +-----------------------+-----------------------+-----------------------+ +-----------------------+-----------------------+-----------------------+ | No events specified | N/A | | | No events specified | N/A | | +-----------------------+-----------------------+-----------------------+ +-----------------------+-----------------------+-----------------------+ | [F | | | | [F | | | | TA_TAB.1](#FTA_TAB.1) | | | | TA_TAB.1](#FTA_TAB.1) | | | +-----------------------+-----------------------+-----------------------+ +-----------------------+-----------------------+-----------------------+ | | | | | | | | +-----------------------+-----------------------+-----------------------+ +-----------------------+-----------------------+-----------------------+ | No events specified | N/A | | | No events specified | N/A | | +-----------------------+-----------------------+-----------------------+ +-----------------------+-----------------------+-----------------------+ | [FTP_ITC_E | | | | [FTP_ITC_E | | | | XT.1](#FTP_ITC_EXT.1) | | | | XT.1](#FTP_ITC_EXT.1) | | | +-----------------------+-----------------------+-----------------------+ +-----------------------+-----------------------+-----------------------+ | | | | | | | | +-----------------------+-----------------------+-----------------------+ +-----------------------+-----------------------+-----------------------+ | Initiation and | - Trusted channel | | | Initiation and | - Trusted channel | | | termination of | protocol | | | termination of | protocol | | | trusted channel | - Non-TOE endpoint | | | trusted channel | - Non-TOE endpoint | | | | of connection | | | | of connection | | +-----------------------+-----------------------+-----------------------+ +-----------------------+-----------------------+-----------------------+ : [Table [2]{.counter}]{#t-audit-mandatory .ctr myid="t-audit-mandatory" : [Table [2]{.counter}]{#t-audit-mandatory .ctr myid="t-audit-mandatory" counter-type="ct-Table"}: Auditable Events for Mandatory Requirements counter-type="ct-Table"}: Auditable Events for Mandatory Requirements ### 5.1.2 Class FAU: Security Audit {#fau .indexable level="3"} ### 5.1.2 Class FAU: Security Audit {#fau .indexable level="3"} ::: {#FAU_GEN.1 .comp} ::: {#FAU_GEN.1 .comp} #### FAU_GEN.1 Audit Data Generation #### FAU_GEN.1 Audit Data Generation ::: element ::: element ::: {#FAU_GEN.1.1 .reqid} ::: {#FAU_GEN.1.1 .reqid} [FAU_GEN.1.1](#FAU_GEN.1.1){.abbr} [FAU_GEN.1.1](#FAU_GEN.1.1){.abbr} ::: ::: ::: reqdesc ::: reqdesc The [TSF](#abbr_TSF) shall be able to generate audit data of the The [TSF](#abbr_TSF) shall be able to generate audit data of the following auditable events:\ following auditable events:\ - Start-up and shutdown of the audit functions - Start-up and shutdown of the audit functions - All auditable events for the \[*not specified*\] level of audit - All auditable events for the \[*not specified*\] level of audit - *All administrative actions* - *All administrative actions* - *Start-up and shutdown of the [OS](#abbr_OS)* - *Start-up and shutdown of the [OS](#abbr_OS)* - *Insertion or removal of removable media* - *Insertion or removal of removable media* - *Specifically defined auditable events in [Table - *Specifically defined auditable events in [Table [2]{.counter}](#t-audit-mandatory){.t-audit-mandatory-ref [2]{.counter}](#t-audit-mandatory){.t-audit-mandatory-ref onclick="showTarget('t-audit-mandatory')"}* onclick="showTarget('t-audit-mandatory')"}* - *Auditable events as defined in the [Functional Package for - *Auditable events as defined in the [Functional Package for Transport Layer Security (TLS), version Transport Layer Security (TLS), version 2.1](https://www.niap-ccevs.org/static_html/protection-profile/519);* 2.1](https://www.niap-ccevs.org/static_html/protection-profile/519);* - *Auditable events as defined in the [Functional Package for X.509, - *Auditable events as defined in the [Functional Package for X.509, version 1.0](https://www.niap-ccevs.org/protectionprofiles/511);* version 1.0](https://www.niap-ccevs.org/protectionprofiles/511);* - *\[**selection**:* - *\[**selection**:* - [Audit data reaching \[**assignment**: [integer value less than - [Audit data reaching \[**assignment**: [integer value less than 100]{.assignable-content}\] percent of audit capacity]{#_s_1 | 100]{.assignable-content}\] percent of audit .selectable-content} | capacity]{#fau_gen.1.1_1 .selectable-content} - [Auditable events defined in [Table - [Auditable events defined in [Table [22]{.counter}](#t-audit-objective){.t-audit-objective-ref [22]{.counter}](#t-audit-objective){.t-audit-objective-ref onclick="showTarget('t-audit-objective')"} for Objective onclick="showTarget('t-audit-objective')"} for Objective [SFRs](#abbr_SFR)]{#_s_2 .selectable-content} | [SFRs](#abbr_SFR)]{#fau_gen.1.1_3 .selectable-content} - [Auditable events defined in [Table - [Auditable events defined in [Table [23]{.counter}](#t-audit-feat-based){.t-audit-feat-based-ref [23]{.counter}](#t-audit-feat-based){.t-audit-feat-based-ref onclick="showTarget('t-audit-feat-based')"} for onclick="showTarget('t-audit-feat-based')"} for Implementation-Dependent [SFRs](#abbr_SFR)]{#_s_3 | Implementation-Dependent [SFRs](#abbr_SFR)]{#fau_gen.1.1_4 .selectable-content} .selectable-content} - [Auditable events defined in [Table - [Auditable events defined in [Table [25]{.counter}](#t-audit-sel-based){.t-audit-sel-based-ref [25]{.counter}](#t-audit-sel-based){.t-audit-sel-based-ref onclick="showTarget('t-audit-sel-based')"} for Selection-Based onclick="showTarget('t-audit-sel-based')"} for Selection-Based [SFRs](#abbr_SFR)]{#_s_4 .selectable-content} | [SFRs](#abbr_SFR)]{#fau_gen.1.1_5 .selectable-content} - [no additional auditable events]{#_s_5 .selectable-content} | - [no additional auditable events]{#fau_gen.1.1_6 > .selectable-content} \]\] \]\] ::: appnote ::: appnote [Application Note: ]{.note-header}[ Administrator actions are defined as [Application Note: ]{.note-header}[ Administrator actions are defined as functions labeled as mandatory for [FMT_MOF_EXT.1.2](#FMT_MOF_EXT.1.2) functions labeled as mandatory for [FMT_MOF_EXT.1.2](#FMT_MOF_EXT.1.2) (i.e., 'M-MM' in [Table [18]{.counter}](#fmt_smf){.fmt_smf-ref (i.e., 'M-MM' in [Table [18]{.counter}](#fmt_smf){.fmt_smf-ref onclick="showTarget('fmt_smf')"}). If the [TSF](#abbr_TSF) does not onclick="showTarget('fmt_smf')"}). If the [TSF](#abbr_TSF) does not support removable media, number 4 is implicitly met.\ support removable media, number 4 is implicitly met.\ \ \ The [TSF](#abbr_TSF) must generate audit data for all events contained The [TSF](#abbr_TSF) must generate audit data for all events contained in [Table [2]{.counter}](#t-audit-mandatory){.t-audit-mandatory-ref in [Table [2]{.counter}](#t-audit-mandatory){.t-audit-mandatory-ref onclick="showTarget('t-audit-mandatory')"}. For all other audit tables onclick="showTarget('t-audit-mandatory')"}. For all other audit tables (i.e., tables for non-mandatory [SFRs](#abbr_SFR) and references to (i.e., tables for non-mandatory [SFRs](#abbr_SFR) and references to functional packages), the [ST](#abbr_ST) author includes the audit functional packages), the [ST](#abbr_ST) author includes the audit events (if any) for the [SFRs](#abbr_SFR) that are claimed in the events (if any) for the [SFRs](#abbr_SFR) that are claimed in the [ST](#abbr_ST).\ [ST](#abbr_ST).\ \ \ **[Table [2]{.counter}](#t-audit-mandatory){.t-audit-mandatory-ref **[Table [2]{.counter}](#t-audit-mandatory){.t-audit-mandatory-ref onclick="showTarget('t-audit-mandatory')"} Application Note:**\ onclick="showTarget('t-audit-mandatory')"} Application Note:**\ [FPT_TST_EXT.1](#FPT_TST_EXT.1) -- Audit of self-tests is required only [FPT_TST_EXT.1](#FPT_TST_EXT.1) -- Audit of self-tests is required only at initial start-up. Since the [TOE](#abbr_TOE) \"transitions to at initial start-up. Since the [TOE](#abbr_TOE) \"transitions to non-operational mode\" upon failure of a self-test, per non-operational mode\" upon failure of a self-test, per [FPT_NOT_EXT.1](#FPT_NOT_EXT.1), this is considered equivalent evidence [FPT_NOT_EXT.1](#FPT_NOT_EXT.1), this is considered equivalent evidence to audit data for the failure of a self-test.\ to audit data for the failure of a self-test.\ \ \ [FDP_DAR_EXT.1](#FDP_DAR_EXT.1) - \"None\" must be selected, if the [FDP_DAR_EXT.1](#FDP_DAR_EXT.1) - \"None\" must be selected, if the [TOE](#abbr_TOE) utilizes whole volume encryption for protected data, [TOE](#abbr_TOE) utilizes whole volume encryption for protected data, since it is not feasible to audit when the encryption/decryption fails. since it is not feasible to audit when the encryption/decryption fails. If the [TOE](#abbr_TOE) utilizes file-based encryption for protected If the [TOE](#abbr_TOE) utilizes file-based encryption for protected data and audits when this encryption/decryption fails, then that data and audits when this encryption/decryption fails, then that auditable event should be selected.\ auditable event should be selected.\ \ \ For [FMT_SMF_EXT.1](#FMT_SMF_EXT.1), it is acceptable for the initiation For [FMT_SMF_EXT.1](#FMT_SMF_EXT.1), it is acceptable for the initiation of the software update to be audited without indicating the outcome of the software update to be audited without indicating the outcome (success or failure) of the update.\ (success or failure) of the update.\ ]{.note} ]{.note} ::: ::: ::: ::: ::: ::: ::: element ::: element ::: {#FAU_GEN.1.2 .reqid} ::: {#FAU_GEN.1.2 .reqid} [FAU_GEN.1.2](#FAU_GEN.1.2){.abbr} [FAU_GEN.1.2](#FAU_GEN.1.2){.abbr} ::: ::: ::: reqdesc ::: reqdesc The [TSF](#abbr_TSF) shall record within the audit data at least the The [TSF](#abbr_TSF) shall record within the audit data at least the following information: following information: - Date and time of the event - Date and time of the event - Type of event - Type of event - Subject identity - Subject identity - The outcome (success or failure) of the event - The outcome (success or failure) of the event - Additional information in [Table - Additional information in [Table [2]{.counter}](#t-audit-mandatory){.t-audit-mandatory-ref [2]{.counter}](#t-audit-mandatory){.t-audit-mandatory-ref onclick="showTarget('t-audit-mandatory')"} onclick="showTarget('t-audit-mandatory')"} - Additional information defined in the [Functional Package for - Additional information defined in the [Functional Package for Transport Layer Security (TLS), version Transport Layer Security (TLS), version 2.1](https://www.niap-ccevs.org/static_html/protection-profile/519); 2.1](https://www.niap-ccevs.org/static_html/protection-profile/519); - Additional information defined in the [Functional Package for X.509, - Additional information defined in the [Functional Package for X.509, version 1.0](https://www.niap-ccevs.org/protectionprofiles/511); version 1.0](https://www.niap-ccevs.org/protectionprofiles/511); - \[**selection**: - \[**selection**: - [Additional information defined in [Table - [Additional information defined in [Table [22]{.counter}](#t-audit-objective){.t-audit-objective-ref [22]{.counter}](#t-audit-objective){.t-audit-objective-ref onclick="showTarget('t-audit-objective')"} for Objective onclick="showTarget('t-audit-objective')"} for Objective [SFRs](#abbr_SFR)]{#_s_6 .selectable-content} | [SFRs](#abbr_SFR)]{#fau_gen.1.2_1 .selectable-content} - [Additional information defined in [Table - [Additional information defined in [Table [23]{.counter}](#t-audit-feat-based){.t-audit-feat-based-ref [23]{.counter}](#t-audit-feat-based){.t-audit-feat-based-ref onclick="showTarget('t-audit-feat-based')"} for onclick="showTarget('t-audit-feat-based')"} for Implementation-Dependent [SFRs](#abbr_SFR)]{#_s_7 | Implementation-Dependent [SFRs](#abbr_SFR)]{#fau_gen.1.2_2 .selectable-content} .selectable-content} - [Additional information defined in [Table - [Additional information defined in [Table [25]{.counter}](#t-audit-sel-based){.t-audit-sel-based-ref [25]{.counter}](#t-audit-sel-based){.t-audit-sel-based-ref onclick="showTarget('t-audit-sel-based')"} for Selection-Based onclick="showTarget('t-audit-sel-based')"} for Selection-Based [SFRs](#abbr_SFR)]{#_s_8 .selectable-content} | [SFRs](#abbr_SFR)]{#fau_gen.1.2_3 .selectable-content} - [no additional information]{#_s_9 .selectable-content} | - [no additional information]{#fau_gen.1.2_4 .selectable-content} \] \] ::: appnote ::: appnote [Application Note: ]{.note-header}[ The subject identity is usually the [Application Note: ]{.note-header}[ The subject identity is usually the process name/ID. The event type is often indicated by a severity level, process name/ID. The event type is often indicated by a severity level, for example, 'info', 'warning', or 'error'.\ for example, 'info', 'warning', or 'error'.\ \ \ \ \ \ \ For each audit event selected from [Table For each audit event selected from [Table [22]{.counter}](#t-audit-objective){.t-audit-objective-ref [22]{.counter}](#t-audit-objective){.t-audit-objective-ref onclick="showTarget('t-audit-objective')"}, [Table onclick="showTarget('t-audit-objective')"}, [Table [23]{.counter}](#t-audit-feat-based){.t-audit-feat-based-ref [23]{.counter}](#t-audit-feat-based){.t-audit-feat-based-ref onclick="showTarget('t-audit-feat-based')"}, or [Table onclick="showTarget('t-audit-feat-based')"}, or [Table [25]{.counter}](#t-audit-sel-based){.t-audit-sel-based-ref [25]{.counter}](#t-audit-sel-based){.t-audit-sel-based-ref onclick="showTarget('t-audit-sel-based')"} in onclick="showTarget('t-audit-sel-based')"} in [FAU_GEN.1.1](#FAU_GEN.1.1), if additional information is required to be [FAU_GEN.1.1](#FAU_GEN.1.1), if additional information is required to be recorded within the audit data, it should be included in this selection. recorded within the audit data, it should be included in this selection. ]{.note} ]{.note} ::: ::: ::: ::: ::: ::: ::: {.activity_pane .hide} ::: {.activity_pane .hide} ::: activity_pane_header ::: activity_pane_header [[ Evaluation Activities [[ Evaluation Activities ]{.activity_pane_label}[]{.toggler}](#){onclick="toggle(this);return false;"} ]{.activity_pane_label}[]{.toggler}](#){onclick="toggle(this);return false;"} ::: ::: ::: activity_pane_body ::: activity_pane_body ::: component-activity-header ::: component-activity-header [FAU_GEN.1](#FAU_GEN.1) [FAU_GEN.1](#FAU_GEN.1) ::: ::: ::: eacategory ::: eacategory [TSS](#abbr_TSS) [TSS](#abbr_TSS) ::: ::: ::: ea ::: ea ::: ea ::: ea The evaluator shall check the [TSS](#abbr_TSS) and ensure that it lists The evaluator shall check the [TSS](#abbr_TSS) and ensure that it lists all of the auditable events and provides a format for audit data. Each all of the auditable events and provides a format for audit data. Each audit data format type must be covered, along with a brief description audit data format type must be covered, along with a brief description of each field. The evaluator shall check to make sure that every audit of each field. The evaluator shall check to make sure that every audit event type mandated by the [PP](#abbr_PP) is described and that the event type mandated by the [PP](#abbr_PP) is described and that the description of the fields contains the information required in description of the fields contains the information required in [FAU_GEN.1.2](#FAU_GEN.1.2).\ [FAU_GEN.1.2](#FAU_GEN.1.2).\ \ \ ::: ::: ::: ::: ::: eacategory ::: eacategory Guidance Guidance ::: ::: ::: ea ::: ea ::: ea ::: ea The evaluator shall also make a determination of the administrative The evaluator shall also make a determination of the administrative actions that are relevant in the context of this [PP](#abbr_PP) actions that are relevant in the context of this [PP](#abbr_PP) including those listed in the Management section. The evaluator shall including those listed in the Management section. The evaluator shall examine the administrative guide and make a determination of which examine the administrative guide and make a determination of which administrative commands are related to the configuration (including administrative commands are related to the configuration (including enabling or disabling) of the mechanisms implemented in the enabling or disabling) of the mechanisms implemented in the [TOE](#abbr_TOE) that are necessary to enforce the requirements [TOE](#abbr_TOE) that are necessary to enforce the requirements specified in the [PP](#abbr_PP). The evaluator shall document the specified in the [PP](#abbr_PP). The evaluator shall document the methodology or approach taken while determining which actions in the methodology or approach taken while determining which actions in the administrative guide are security relevant with respect to this administrative guide are security relevant with respect to this [PP](#abbr_PP). The evaluator may perform this activity as part of the [PP](#abbr_PP). The evaluator may perform this activity as part of the activities associated with ensuring the AGD_OPE guidance satisfies the activities associated with ensuring the AGD_OPE guidance satisfies the requirements.\ requirements.\ \ \ ::: ::: ::: ::: ::: eacategory ::: eacategory Tests Tests ::: ::: ::: ea ::: ea ::: ea ::: ea The evaluator shall test the [TOE](#abbr_TOE)'s ability to correctly The evaluator shall test the [TOE](#abbr_TOE)'s ability to correctly generate audit data by having the [TOE](#abbr_TOE) generate audit data generate audit data by having the [TOE](#abbr_TOE) generate audit data for the events listed in the provided table and administrative actions. for the events listed in the provided table and administrative actions. This should include all instances of an event. The evaluator shall test This should include all instances of an event. The evaluator shall test that audit data are generated for the establishment and termination of a that audit data are generated for the establishment and termination of a channel for each of the cryptographic protocols contained in the channel for each of the cryptographic protocols contained in the [ST](#abbr_ST). For administrative actions, the evaluator shall test [ST](#abbr_ST). For administrative actions, the evaluator shall test that each action determined by the evaluator above to be security that each action determined by the evaluator above to be security relevant in the context of this [PP](#abbr_PP) is auditable. When relevant in the context of this [PP](#abbr_PP) is auditable. When verifying the test results, the evaluator shall ensure the audit data verifying the test results, the evaluator shall ensure the audit data generated during testing match the format specified in the generated during testing match the format specified in the administrative guide, and that the fields specified in administrative guide, and that the fields specified in [FAU_GEN.1.2](#FAU_GEN.1.2) are contained in the audit data.\ [FAU_GEN.1.2](#FAU_GEN.1.2) are contained in the audit data.\ \ \ Note that the testing here can be accomplished in conjunction with the Note that the testing here can be accomplished in conjunction with the testing of the security mechanisms directly. For example, testing testing of the security mechanisms directly. For example, testing performed to ensure that the administrative guidance provided is correct performed to ensure that the administrative guidance provided is correct verifies that [AGD_OPE.1](#AGD_OPE.1) is satisfied and should address verifies that [AGD_OPE.1](#AGD_OPE.1) is satisfied and should address the invocation of the administrative actions that are needed to verify the invocation of the administrative actions that are needed to verify the audit data are generated as expected.\ the audit data are generated as expected.\ \ \ ::: ::: ::: ::: ::: ::: ::: ::: ::: ::: ::: {#FAU_SAR.1 .comp} ::: {#FAU_SAR.1 .comp} #### FAU_SAR.1 Audit Review #### FAU_SAR.1 Audit Review ::: element ::: element ::: {#FAU_SAR.1.1 .reqid} ::: {#FAU_SAR.1.1 .reqid} [FAU_SAR.1.1](#FAU_SAR.1.1){.abbr} [FAU_SAR.1.1](#FAU_SAR.1.1){.abbr} ::: ::: ::: reqdesc ::: reqdesc The [TSF](#abbr_TSF) shall provide \[*the administrator*\] with the The [TSF](#abbr_TSF) shall provide \[*the administrator*\] with the capability to read \[*all audited events and data contents*\] from the capability to read \[*all audited events and data contents*\] from the audit data. audit data. ::: appnote ::: appnote [Application Note: ]{.note-header}[]{.note} | [Application Note: ]{.note-header}[ ]{.note} The administrator must have access to read the audit data, perhaps The administrator must have access to read the audit data, perhaps through an [API](#abbr_API) or via an [MDM](#abbr_MDM) agent that through an [API](#abbr_API) or via an [MDM](#abbr_MDM) agent that transfers the local records stored on the [TOE](#abbr_TOE) to the transfers the local records stored on the [TOE](#abbr_TOE) to the [MDM](#abbr_MDM) server, where the enterprise administrator may then [MDM](#abbr_MDM) server, where the enterprise administrator may then view them. view them. ::: ::: ::: ::: ::: ::: ::: element ::: element ::: {#FAU_SAR.1.2 .reqid} ::: {#FAU_SAR.1.2 .reqid} [FAU_SAR.1.2](#FAU_SAR.1.2){.abbr} [FAU_SAR.1.2](#FAU_SAR.1.2){.abbr} ::: ::: ::: reqdesc ::: reqdesc The [TSF](#abbr_TSF) shall provide the audit data in a manner suitable The [TSF](#abbr_TSF) shall provide the audit data in a manner suitable for the user to interpret the information. for the user to interpret the information. ::: ::: ::: ::: ::: {.activity_pane .hide} ::: {.activity_pane .hide} ::: activity_pane_header ::: activity_pane_header [[ Evaluation Activities [[ Evaluation Activities ]{.activity_pane_label}[]{.toggler}](#){onclick="toggle(this);return false;"} ]{.activity_pane_label}[]{.toggler}](#){onclick="toggle(this);return false;"} ::: ::: ::: activity_pane_body ::: activity_pane_body ::: component-activity-header ::: component-activity-header [FAU_SAR.1](#FAU_SAR.1) [FAU_SAR.1](#FAU_SAR.1) ::: ::: ::: eacategory ::: eacategory [TSS](#abbr_TSS) [TSS](#abbr_TSS) ::: ::: ::: ea ::: ea ::: ea ::: ea There are no [TSS](#abbr_TSS) evaluation activities for this component.\ There are no [TSS](#abbr_TSS) evaluation activities for this component.\ \ \ ::: ::: ::: ::: ::: eacategory ::: eacategory Guidance Guidance ::: ::: ::: ea ::: ea ::: ea ::: ea There are no guidance evaluation activities for this component.\ There are no guidance evaluation activities for this component.\ \ \ ::: ::: ::: ::: ::: eacategory ::: eacategory Tests Tests ::: ::: ::: ea ::: ea ::: ea ::: ea The evaluation activity for this requirement is performed in conjunction The evaluation activity for this requirement is performed in conjunction with test for function [32](#mf-auditLogs) of with test for function [32](#mf-auditLogs) of [FMT_SMF_EXT.1](#FMT_SMF_EXT.1). [FMT_SMF_EXT.1](#FMT_SMF_EXT.1). ::: ::: ::: ::: ::: ::: ::: ::: ::: ::: ::: {#FAU_STG.2 .comp} ::: {#FAU_STG.2 .comp} #### FAU_STG.2 Protected Audit Data Storage #### FAU_STG.2 Protected Audit Data Storage ::: element ::: element ::: {#FAU_STG.2.1 .reqid} ::: {#FAU_STG.2.1 .reqid} [FAU_STG.2.1](#FAU_STG.2.1){.abbr} [FAU_STG.2.1](#FAU_STG.2.1){.abbr} ::: ::: ::: reqdesc ::: reqdesc The [TSF](#abbr_TSF) shall protect the stored audit data in the audit The [TSF](#abbr_TSF) shall protect the stored audit data in the audit trail from unauthorized deletion. trail from unauthorized deletion. ::: ::: ::: ::: ::: element ::: element ::: {#FAU_STG.2.2 .reqid} ::: {#FAU_STG.2.2 .reqid} [FAU_STG.2.2](#FAU_STG.2.2){.abbr} [FAU_STG.2.2](#FAU_STG.2.2){.abbr} ::: ::: ::: reqdesc ::: reqdesc The [TSF](#abbr_TSF) shall be able to \[*prevent*\] unauthorized The [TSF](#abbr_TSF) shall be able to \[*prevent*\] unauthorized modifications to the stored audit data in the audit trail. modifications to the stored audit data in the audit trail. ::: ::: ::: ::: ::: {.activity_pane .hide} ::: {.activity_pane .hide} ::: activity_pane_header ::: activity_pane_header [[ Evaluation Activities [[ Evaluation Activities ]{.activity_pane_label}[]{.toggler}](#){onclick="toggle(this);return false;"} ]{.activity_pane_label}[]{.toggler}](#){onclick="toggle(this);return false;"} ::: ::: ::: activity_pane_body ::: activity_pane_body ::: component-activity-header ::: component-activity-header [FAU_STG.2](#FAU_STG.2) [FAU_STG.2](#FAU_STG.2) ::: ::: ::: eacategory ::: eacategory [TSS](#abbr_TSS) [TSS](#abbr_TSS) ::: ::: ::: ea ::: ea ::: ea ::: ea The evaluator shall ensure that the [TSS](#abbr_TSS) lists the location The evaluator shall ensure that the [TSS](#abbr_TSS) lists the location of all logs and the access controls of those files such that of all logs and the access controls of those files such that unauthorized modification and deletion are prevented.\ unauthorized modification and deletion are prevented.\ \ \ ::: ::: ::: ::: ::: eacategory ::: eacategory Guidance Guidance ::: ::: ::: ea ::: ea ::: ea ::: ea There are no guidance evaluation activities for this component.\ There are no guidance evaluation activities for this component.\ \ \ ::: ::: ::: ::: ::: eacategory ::: eacategory Tests Tests ::: ::: ::: ea ::: ea ::: ea ::: ea []{.testlist-} []{.testlist-} - [Test FAU_STG.2:1](#_t_3){#_t_3 .defined}: The evaluator shall - [Test FAU_STG.2:1](#_t_3){#_t_3 .defined}: The evaluator shall attempt to delete the audit trail in a manner that the access attempt to delete the audit trail in a manner that the access controls should prevent (as an unauthorized user) and shall verify controls should prevent (as an unauthorized user) and shall verify that the attempt fails. that the attempt fails. - [Test FAU_STG.2:2](#_t_4){#_t_4 .defined}: The evaluator shall - [Test FAU_STG.2:2](#_t_4){#_t_4 .defined}: The evaluator shall attempt to modify the audit trail in a manner that the access attempt to modify the audit trail in a manner that the access controls should prevent (as an unauthorized application) and shall controls should prevent (as an unauthorized application) and shall verify that the attempt fails. verify that the attempt fails. ::: ::: ::: ::: ::: ::: ::: ::: ::: ::: ::: {#FAU_STG.5 .comp} ::: {#FAU_STG.5 .comp} #### FAU_STG.5 Prevention of Audit Data Loss #### FAU_STG.5 Prevention of Audit Data Loss ::: element ::: element ::: {#FAU_STG.5.1 .reqid} ::: {#FAU_STG.5.1 .reqid} [FAU_STG.5.1](#FAU_STG.5.1){.abbr} [FAU_STG.5.1](#FAU_STG.5.1){.abbr} ::: ::: ::: reqdesc ::: reqdesc The [TSF](#abbr_TSF) shall \[*overwrite the oldest stored audit The [TSF](#abbr_TSF) shall \[*overwrite the oldest stored audit records*\] ~~\[assignment: other actions to be taken in case of audit records*\] ~~\[assignment: other actions to be taken in case of audit storage failure and conditions for the actions\]~~ if the audit data storage failure and conditions for the actions\]~~ if the audit data storage is full. storage is full. ::: ::: ::: ::: ::: {.activity_pane .hide} ::: {.activity_pane .hide} ::: activity_pane_header ::: activity_pane_header [[ Evaluation Activities [[ Evaluation Activities ]{.activity_pane_label}[]{.toggler}](#){onclick="toggle(this);return false;"} ]{.activity_pane_label}[]{.toggler}](#){onclick="toggle(this);return false;"} ::: ::: ::: activity_pane_body ::: activity_pane_body ::: component-activity-header ::: component-activity-header [FAU_STG.5](#FAU_STG.5) [FAU_STG.5](#FAU_STG.5) ::: ::: ::: eacategory ::: eacategory [TSS](#abbr_TSS) [TSS](#abbr_TSS) ::: ::: ::: ea ::: ea ::: ea ::: ea The evaluator shall examine the [TSS](#abbr_TSS) to ensure that it The evaluator shall examine the [TSS](#abbr_TSS) to ensure that it describes the size limits on the audit records, the detection of a full describes the size limits on the audit records, the detection of a full audit trail, and the actions taken by the [TSF](#abbr_TSF) when the audit trail, and the actions taken by the [TSF](#abbr_TSF) when the audit trail is full. The evaluator shall ensure that the actions results audit trail is full. The evaluator shall ensure that the actions results in the deletion or overwrite of the oldest stored record.\ in the deletion or overwrite of the oldest stored record.\ \ \ ::: ::: ::: ::: ::: eacategory ::: eacategory Guidance Guidance ::: ::: ::: ea ::: ea ::: ea ::: ea There are no guidance evaluation activities for this component.\ There are no guidance evaluation activities for this component.\ \ \ ::: ::: ::: ::: ::: eacategory ::: eacategory Tests Tests ::: ::: ::: ea ::: ea ::: ea ::: ea There are no test evaluation activities for this component. There are no test evaluation activities for this component. ::: ::: ::: ::: ::: ::: ::: ::: ::: ::: ### 5.1.3 Class FCS: Cryptographic Support {#fcs .indexable level="3"} ### 5.1.3 Class FCS: Cryptographic Support {#fcs .indexable level="3"} This section describes how keys are generated, derived, combined, This section describes how keys are generated, derived, combined, released and destroyed. There are two major types of keys: | released and destroyed. There are two major types of keys: DEKs and [DEKs](#abbr_DEK) and KEKs. (A [REK](#abbr_REK) is considered a | KEKs. (A [REK](#abbr_REK) is considered a [KEK](#abbr_KEK).) DEKs are [KEK](#abbr_KEK).) [DEKs](#abbr_DEK) are used to protect data (as in the | used to protect data (as in the [DAR](#abbr_DAR) protection described in [DAR](#abbr_DAR) protection described in [FDP_DAR_EXT.1](#FDP_DAR_EXT.1) | [FDP_DAR_EXT.1](#FDP_DAR_EXT.1) and [FDP_DAR_EXT.2](#FDP_DAR_EXT.2)). and [FDP_DAR_EXT.2](#FDP_DAR_EXT.2)). KEKs are used to protect other | KEKs are used to protect other keys -- DEKs, other KEKs, and other types keys -- [DEKs](#abbr_DEK), other KEKs, and other types of keys stored by | of keys stored by the user or applications. The following diagram shows the user or applications. The following diagram shows an example key | an example key hierarchy to illustrate the concepts of this profile. hierarchy to illustrate the concepts of this profile. This example is | This example is not meant as an approved design, but [ST](#abbr_ST) not meant as an approved design, but [ST](#abbr_ST) authors will be | authors will be expected to provide a diagram illustrating their key expected to provide a diagram illustrating their key hierarchy in order | hierarchy in order to demonstrate that they meet the requirements of to demonstrate that they meet the requirements of this profile. Please | this profile. Please note if [biometric in accordance with note if [biometric in accordance with the](#uau_biometric) [cPP-Module | the](#uau_biometric) [cPP-Module for Biometric Enrollment and for Biometric Enrollment and Verification, version | Verification, version 2.0](https://github.com/biometricITC/cPP-biometrics/blob/master/Protection%20Profile/ 2.0](https://github.com/biometricITC/cPP-biometrics/blob/master/Protection%20Profile/ is selected in [FIA_UAU.5.1](#FIA_UAU.5.1), each [BAF](#abbr_BAF) is selected in [FIA_UAU.5.1](#FIA_UAU.5.1), each [BAF](#abbr_BAF) claimed in FIA_MBV_EXT.1.1 in the [cPP-Module for Biometric Enrollment claimed in FIA_MBV_EXT.1.1 in the [cPP-Module for Biometric Enrollment and Verification, version and Verification, version 2.0](https://github.com/biometricITC/cPP-biometrics/blob/master/Protection%20Profile/ 2.0](https://github.com/biometricITC/cPP-biometrics/blob/master/Protection%20Profile/ shall be illustrated in the key hierarchy diagram, to include a shall be illustrated in the key hierarchy diagram, to include a description of when and how the [BAF](#abbr_BAF) is used to release description of when and how the [BAF](#abbr_BAF) is used to release keys. If [hybrid](#uau_hybr) is selected in [FIA_UAU.5.1](#FIA_UAU.5.1), keys. If [hybrid](#uau_hybr) is selected in [FIA_UAU.5.1](#FIA_UAU.5.1), meaning that a PIN or password must be used in conjunction with the meaning that a PIN or password must be used in conjunction with the [BAF](#abbr_BAF), this interaction shall be included.\ [BAF](#abbr_BAF), this interaction shall be included.\ ::: {#figure-Keys .figure} ::: {#figure-Keys .figure} ![](images/figure3.jpg){#Keys width="" height=""}\ ![](images/figure3.jpg){#Keys width="" height=""}\ [Figure [3]{.counter}]{.ctr myid="Keys" counter-type="ct-figure"}: An [Figure [3]{.counter}]{.ctr myid="Keys" counter-type="ct-figure"}: An Illustrative Key Hierarchy Illustrative Key Hierarchy ::: ::: ::: {#FCS_CKM.1/AKG .comp} ::: {#FCS_CKM.1/AKG .comp} #### FCS_CKM.1/AKG Cryptographic Key Generation - Asymmetric Key #### FCS_CKM.1/AKG Cryptographic Key Generation - Asymmetric Key ::: element ::: element ::: {#FCS_CKM.1.1/AKG .reqid} ::: {#FCS_CKM.1.1/AKG .reqid} [FCS_CKM.1.1/AKG](#FCS_CKM.1.1/AKG){.abbr} [FCS_CKM.1.1/AKG](#FCS_CKM.1.1/AKG){.abbr} ::: ::: ::: reqdesc ::: reqdesc The [TSF](#abbr_TSF) shall generate **asymmetric** cryptographic keys in The [TSF](#abbr_TSF) shall generate **asymmetric** cryptographic keys in accordance with a specified cryptographic key generation algorithm accordance with a specified cryptographic key generation algorithm \[**selection**: [Cryptographic Key Generation \[**selection**: [Cryptographic Key Generation Algorithm]{.selectable-content}\] and specified cryptographic Algorithm]{.selectable-content}\] and specified cryptographic **algorithm parameters** ~~key sizes~~ \[**selection**: [Cryptographic **algorithm parameters** ~~key sizes~~ \[**selection**: [Cryptographic Algorithm Parameters]{.selectable-content}\] that meet the following: Algorithm Parameters]{.selectable-content}\] that meet the following: \[**selection**: [List of Standards]{.selectable-content}\] . \[**selection**: [List of Standards]{.selectable-content}\] . [Table [3]{.counter}](#fcs-ckm-1-ak-sels){.fcs-ckm-1-ak-sels-ref [Table [3]{.counter}](#fcs-ckm-1-ak-sels){.fcs-ckm-1-ak-sels-ref onclick="showTarget('fcs-ckm-1-ak-sels')"} provides the allowable onclick="showTarget('fcs-ckm-1-ak-sels')"} provides the allowable choices for completion of the selection operations of choices for completion of the selection operations of [FCS_CKM.1/AKG](#FCS_CKM.1/AKG). [FCS_CKM.1/AKG](#FCS_CKM.1/AKG). +-----------------+-----------------+-----------------+-----------------+ +-----------------+-----------------+-----------------+-----------------+ | Identifier | Cryptographic | Cryptographic | List of | | Identifier | Cryptographic | Cryptographic | List of | | | Key Generation | Algorithm | Standards | | | Key Generation | Algorithm | Standards | | | Algorithm | Parameters | | | | Algorithm | Parameters | | +=================+=================+=================+=================+ +=================+=================+=================+=================+ | [ | [ | Modulus of size | [NI | | [ | [ | Modulus of size | [NI | | RSA](#abbr_RSA) | RSA](#abbr_RSA) | \ | ST](#abbr_NIST) | | RSA](#abbr_RSA) | RSA](#abbr_RSA) | \ | ST](#abbr_NIST) | | | | [**selection**: | [FI | | | | [**selection**: | [FI | | | | [3072]{#sel- | PS](#abbr_FIPS) | | | | [3072]{#sel- | PS](#abbr_FIPS) | | | | exp-ak-rsa-3072 | PUB 186-5 | | | | exp-ak-rsa-3072 | PUB 186-5 | | | | .selec | (Section A.1.1) | | | | .selec | (Section A.1.1) | | | | table-content}, | | | | | table-content}, | | | | | [4096]{#sel- | | | | | [4096]{#sel- | | | | | exp-ak-rsa-4096 | | | | | exp-ak-rsa-4096 | | | | | .selec | | | | | .selec | | | | | table-content}, | | | | | table-content}, | | | | | [6144]{#sel- | | | | | [6144]{#sel- | | | | | exp-ak-rsa-6144 | | | | | exp-ak-rsa-6144 | | | | | .selec | | | | | .selec | | | | | table-content}, | | | | | table-content}, | | | | | [8192]{#sel- | | | | | [8192]{#sel- | | | | | exp-ak-rsa-8192 | | | | | exp-ak-rsa-8192 | | | | | .select | | | | | .select | | | | | able-content}\] | | | | | able-content}\] | | | | | bits | | | | | bits | | +-----------------+-----------------+-----------------+-----------------+ +-----------------+-----------------+-----------------+-----------------+ | ECC-ERB | ECC-ERB - Extra | Elliptic Curve | [FI | | ECC-ERB | ECC-ERB - Extra | Elliptic Curve | [FI | | | Random Bits | \ | PS](#abbr_FIPS) | | | Random Bits | \ | PS](#abbr_FIPS) | | | | [**selection**: | PUB 186-5 | | | | [**selection**: | PUB 186-5 | | | | [P-2 | (Section A.2.1) | | | | [P-2 | (Section A.2.1) | | | | 56]{#sel-exp-ak | | | | | 56]{#sel-exp-ak | | | | | -edcsa-erb-P256 | [NI | | | | -edcsa-erb-P256 | [NI | | | | .selec | ST](#abbr_NIST) | | | | .selec | ST](#abbr_NIST) | | | | table-content}, | SP 800-186 | | | | table-content}, | SP 800-186 | | | | [P-3 | (Section 3) | | | | [P-3 | (Section 3) | | | | 84]{#sel-exp-ak | \[[NI | | | | 84]{#sel-exp-ak | \[[NI | | | | -edcsa-erb-P384 | ST](#abbr_NIST) | | | | -edcsa-erb-P384 | ST](#abbr_NIST) | | | | .selec | Curves\] | | | | .selec | Curves\] | | | | table-content}, | | | | | table-content}, | | | | | [P-5 | | | | | [P-5 | | | | | 21]{#sel-exp-ak | | | | | 21]{#sel-exp-ak | | | | | -edcsa-erb-P521 | | | | | -edcsa-erb-P521 | | | | | .select | | | | | .select | | | | | able-content}\] | | | | | able-content}\] | | +-----------------+-----------------+-----------------+-----------------+ +-----------------+-----------------+-----------------+-----------------+ | ECC-RS | ECC-RS - | Elliptic Curve | [FI | | ECC-RS | ECC-RS - | Elliptic Curve | [FI | | | Rejection | \ | PS](#abbr_FIPS) | | | Rejection | \ | PS](#abbr_FIPS) | | | Sampling | [**selection**: | PUB 186-5 | | | Sampling | [**selection**: | PUB 186-5 | | | | [P- | (Section A.2.2) | | | | [P- | (Section A.2.2) | | | | 256]{#sel-exp-a | | | | | 256]{#sel-exp-a | | | | | k-edcsa-rs-P256 | [NI | | | | k-edcsa-rs-P256 | [NI | | | | .selec | ST](#abbr_NIST) | | | | .selec | ST](#abbr_NIST) | | | | table-content}, | SP 800-186 | | | | table-content}, | SP 800-186 | | | | [P- | (Section 3) | | | | [P- | (Section 3) | | | | 384]{#sel-exp-a | \[[NI | | | | 384]{#sel-exp-a | \[[NI | | | | k-edcsa-rs-P384 | ST](#abbr_NIST) | | | | k-edcsa-rs-P384 | ST](#abbr_NIST) | | | | .selec | Curves\] | | | | .selec | Curves\] | | | | table-content}, | | | | | table-content}, | | | | | [P- | | | | | [P- | | | | | 521]{#sel-exp-a | | | | | 521]{#sel-exp-a | | | | | k-edcsa-rs-P521 | | | | | k-edcsa-rs-P521 | | | | | .select | | | | | .select | | | | | able-content}\] | | | | | able-content}\] | | +-----------------+-----------------+-----------------+-----------------+ +-----------------+-----------------+-----------------+-----------------+ | [FFC] | [FFC](# | Static domain | [NI | | [FFC] | [FFC](# | Static domain | [NI | | (#abbr_FFC)-ERB | abbr_FFC)-ERB - | parameters | ST](#abbr_NIST) | | (#abbr_FFC)-ERB | abbr_FFC)-ERB - | parameters | ST](#abbr_NIST) | | | Extra Random | approved for | SP 800-56A | | | Extra Random | approved for | SP 800-56A | | | Bits | \ | Revision 3 | | | Bits | \ | Revision 3 | | | | [**selection**: | (Section | | | | [**selection**: | (Section | | | | | 5.6.1.1.3) | | | | | 5.6.1.1.3) | | | | - [IKE Groups | \[key pair | | | | - [IKE Groups | \[key pair | | | | \ | generation\] | | | | \ | generation\] | | | | [**selection**: | | | | | [**selection**: | | | | | [MODP-307 | \ | | | | [MODP-307 | \ | | | | 2]{#sel-dp-ak-f | [**selection**: | | | | 2]{#sel-dp-ak-f | [**selection**: | | | | fc-erb-modp3072 | [RFC 3526 \[IKE | | | | fc-erb-modp3072 | [RFC 3526 \[IKE | | | | .selec | g | | | | | .selec | groups\]]{#fc | | | | table-content}, | roups\]]{#_s_34 | | | | | table-content}, | s_ckm.1.1_AKG_3 | | | | [MODP-409 | .selec | | | | [MODP-409 | .selec | | | | 6]{#sel-dp-ak-f | table-content}, | | | | 6]{#sel-dp-ak-f | table-content}, | | | | fc-erb-modp4096 | [RFC 7919 | | | | fc-erb-modp4096 | [RFC 7919 | | | | .selec | \[[ | | | | .selec | \[[ | | | | table-content}, | TLS](#abbr_TLS) | | | | table-content}, | TLS](#abbr_TLS) | | | | [MODP-614 | g | | | | | [MODP-614 | groups\]]{#fc | | | | 4]{#sel-dp-ak-f | roups\]]{#_s_35 | | | | | 4]{#sel-dp-ak-f | s_ckm.1.1_AKG_4 | | | | fc-erb-modp6144 | .select | | | | fc-erb-modp6144 | .select | | | | .selec | able-content}\] | | | | .selec | able-content}\] | | | | table-content}, | | | | | table-content}, | | | | | [MODP-819 | | | | | [MODP-819 | | | | | 2]{#sel-dp-ak-f | | | | | 2]{#sel-dp-ak-f | | | | | fc-erb-modp8192 | | | | | fc-erb-modp8192 | | | | | | | | | | | | | | | .selectable-con | | | | | | .selectable- | | | | | tent}\]]{#_s_24 | | | | | | content}\]]{#fc | | > | | | s_ckm.1.1_AKG_1 | | | | | .sele | | | | | .sele | | | | | ctable-content} | | | | | ctable-content} | | | | | - [[ | | | | | - [[ | | | | | TLS](#abbr_TLS) | | | | | TLS](#abbr_TLS) | | | | | Groups | | | | | Groups | | | | | \ | | | | | \ | | | | | [**selection**: | | | | | [**selection**: | | | | | [ffdhe3072 | | | | | [ffdhe3072 | | | | | ]{#sel-dp-ak-ff | | | | | ]{#sel-dp-ak-ff | | | | | c-erb-ffdhe3072 | | | | | c-erb-ffdhe3072 | | | | | .selec | | | | | .selec | | | | | table-content}, | | | | | table-content}, | | | | | [ffdhe4096 | | | | | [ffdhe4096 | | | | | ]{#sel-dp-ak-ff | | | | | ]{#sel-dp-ak-ff | | | | | c-erb-ffdhe4096 | | | | | c-erb-ffdhe4096 | | | | | .selec | | | | | .selec | | | | | table-content}, | | | | | table-content}, | | | | | [ffdhe6144 | | | | | [ffdhe6144 | | | | | ]{#sel-dp-ak-ff | | | | | ]{#sel-dp-ak-ff | | | | | c-erb-ffdhe6144 | | | | | c-erb-ffdhe6144 | | | | | .selec | | | | | .selec | | | | | table-content}, | | | | | table-content}, | | | | | [ffdhe8192 | | | | | [ffdhe8192 | | | | | ]{#sel-dp-ak-ff | | | | | ]{#sel-dp-ak-ff | | | | | c-erb-ffdhe8192 | | | | | c-erb-ffdhe8192 | | | | | | | | | | | | | | | .selectable-con | | | | | | .selectable- | | | | | tent}\]]{#_s_29 | | | | | | content}\]]{#fc | | > | | | s_ckm.1.1_AKG_2 | | | | | .sele | | | | | .sele | | | | | ctable-content} | | | | | ctable-content} | | | | | | | | | | | | | | | \] | | | | | \] | | +-----------------+-----------------+-----------------+-----------------+ +-----------------+-----------------+-----------------+-----------------+ | [FFC | [FFC]( | Static domain | [NI | | [FFC | [FFC]( | Static domain | [NI | | ](#abbr_FFC)-RS | #abbr_FFC)-RS - | parameters | ST](#abbr_NIST) | | ](#abbr_FFC)-RS | #abbr_FFC)-RS - | parameters | ST](#abbr_NIST) | | | Rejection | approved for | SP 800-56A | | | Rejection | approved for | SP 800-56A | | | Sampling | \ | Revision 3 | | | Sampling | \ | Revision 3 | | | | [**selection**: | (Section | | | | [**selection**: | (Section | | | | | 5.6.1.1.3) | | | | | 5.6.1.1.3) | | | | - [IKE Groups | \[key pair | | | | - [IKE Groups | \[key pair | | | | \ | generation\] | | | | \ | generation\] | | | | [**selection**: | | | | | [**selection**: | | | | | [MODP-30 | \ | | | | [MODP-30 | \ | | | | 72]{#sel-dp-ak- | [**selection**: | | | | 72]{#sel-dp-ak- | [**selection**: | | | | ffc-rs-modp3072 | [RFC 3526 \[IKE | | | | ffc-rs-modp3072 | [RFC 3526 \[IKE | | | | .selec | g | | | | | .selec | groups\]]{#fc | | | | table-content}, | roups\]]{#_s_47 | | | | | table-content}, | s_ckm.1.1_AKG_7 | | | | [MODP-40 | .selec | | | | [MODP-40 | .selec | | | | 96]{#sel-dp-ak- | table-content}, | | | | 96]{#sel-dp-ak- | table-content}, | | | | ffc-rs-modp4096 | [RFC 7919 | | | | ffc-rs-modp4096 | [RFC 7919 | | | | .selec | \[[ | | | | .selec | \[[ | | | | table-content}, | TLS](#abbr_TLS) | | | | table-content}, | TLS](#abbr_TLS) | | | | [MODP-61 | g | | | | | [MODP-61 | groups\]]{#fc | | | | 44]{#sel-dp-ak- | roups\]]{#_s_48 | | | | | 44]{#sel-dp-ak- | s_ckm.1.1_AKG_8 | | | | ffc-rs-modp6144 | .select | | | | ffc-rs-modp6144 | .select | | | | .selec | able-content}\] | | | | .selec | able-content}\] | | | | table-content}, | | | | | table-content}, | | | | | [MODP-81 | | | | | [MODP-81 | | | | | 92]{#sel-dp-ak- | | | | | 92]{#sel-dp-ak- | | | | | ffc-rs-modp8192 | | | | | ffc-rs-modp8192 | | | | | | | | | | | | | | | .selectable-con | | | | | | .selectable- | | | | | tent}\]]{#_s_37 | | | | | | content}\]]{#fc | | > | | | s_ckm.1.1_AKG_5 | | | | | .sele | | | | | .sele | | | | | ctable-content} | | | | | ctable-content} | | | | | - [[ | | | | | - [[ | | | | | TLS](#abbr_TLS) | | | | | TLS](#abbr_TLS) | | | | | Groups | | | | | Groups | | | | | \ | | | | | \ | | | | | [**selection**: | | | | | [**selection**: | | | | | [ffdhe307 | | | | | [ffdhe307 | | | | | 2]{#sel-dp-ak-f | | | | | 2]{#sel-dp-ak-f | | | | | fc-rs-ffdhe3072 | | | | | fc-rs-ffdhe3072 | | | | | .selec | | | | | .selec | | | | | table-content}, | | | | | table-content}, | | | | | [ffdhe409 | | | | | [ffdhe409 | | | | | 6]{#sel-dp-ak-f | | | | | 6]{#sel-dp-ak-f | | | | | fc-rs-ffdhe4096 | | | | | fc-rs-ffdhe4096 | | | | | .selec | | | | | .selec | | | | | table-content}, | | | | | table-content}, | | | | | [ffdhe614 | | | | | [ffdhe614 | | | | | 4]{#sel-dp-ak-f | | | | | 4]{#sel-dp-ak-f | | | | | fc-rs-ffdhe6144 | | | | | fc-rs-ffdhe6144 | | | | | .selec | | | | | .selec | | | | | table-content}, | | | | | table-content}, | | | | | [ffdhe819 | | | | | [ffdhe819 | | | | | 2]{#sel-dp-ak-f | | | | | 2]{#sel-dp-ak-f | | | | | fc-rs-ffdhe8192 | | | | | fc-rs-ffdhe8192 | | | | | | | | | | | | | | | .selectable-con | | | | | | .selectable- | | | | | tent}\]]{#_s_42 | | | | | | content}\]]{#fc | | > | | | s_ckm.1.1_AKG_6 | | | | | .sele | | | | | .sele | | | | | ctable-content} | | | | | ctable-content} | | | | | | | | | | | | | | | \] | | | | | \] | | +-----------------+-----------------+-----------------+-----------------+ +-----------------+-----------------+-----------------+-----------------+ | EdDSA | EdDSA | Domain | [NI | | EdDSA | EdDSA | Domain | [NI | | | | paramaters | ST](#abbr_NIST) | | | | paramaters | ST](#abbr_NIST) | | | | approved for | [FI | | | | approved for | [FI | | | | elliptic curves | PS](#abbr_FIPS) | | | | elliptic curves | PS](#abbr_FIPS) | | | | \[* | PUB 186-5 | | | | \[* | PUB 186-5 | | | | Edwards25519*\] | (sectkon | | | | Edwards25519*\] | (sectkon | | | | | 6 | | | | | 6 | | | | | .2.1)\[key-pair | | | | | .2.1)\[key-pair | | | | | generation\] | | | | | generation\] | | | | | | | | | | | | | | | [NI | | | | | [NI | | | | | ST](#abbr_NIST) | | | | | ST](#abbr_NIST) | | | | | SP 800-186 | | | | | SP 800-186 | | | | | (Section | | | | | (Section | | | | | 3.2.3)\[Edwards | | | | | 3.2.3)\[Edwards | | | | | Curves\] | | | | | Curves\] | +-----------------+-----------------+-----------------+-----------------+ +-----------------+-----------------+-----------------+-----------------+ | LMS | LMS | Private key | RFC 8554 | | LMS | LMS | Private key | RFC 8554 | | | | size = | \[LMS\] | | | | size = | \[LMS\] | | | | \ | | | | | \ | | | | | [**selection**: | [NI | | | | [**selection**: | [NI | | | | | ST](#abbr_NIST) | | | | | ST](#abbr_NIST) | | | | - [*192 bits | SP 800-208 | | | | - [*192 bits | SP 800-208 | | | | with*\ | \[parameters\] | | | | with*\ | \[parameters\] | | | | [**selection**: | | | | | [**selection**: | | | | | [[S | | | | | | [ | | | | | HA](#abbr_SHA)- | | | | | | [SHA](#abbr_SHA | | | | | 256/192]{#_s_52 | | | | | | )-256/192]{#fcs | | > | | | _ckm.1.1_AKG_10 | | | | | .selec | | | | | .selec | | | | | table-content}, | | | | | table-content}, | | | | | [SHAKE | | | | | | [SHA | | | | | 256/192]{#_s_53 | | | | | | KE256/192]{#fcs | | > | | | _ckm.1.1_AKG_11 | | | | | | | | | | | | | | | .selectable-con | | | | | | .selectable- | | | | | tent}\]]{#_s_51 | | | | | | content}\]]{#fc | | > | | | s_ckm.1.1_AKG_9 | | | | | .sele | | | | | .sele | | | | | ctable-content} | | | | | ctable-content} | | | | | - [256 bits | | | | | - [256 bits | | | | | with | | | | | with | | | | | \ | | | | | \ | | | | | [**selection**: | | | | | [**selection**: | | | | | | | | | | | | | | | [[SHA](#abbr_S | | | | | | [[SHA](#abbr | | | | | HA)-256]{#_s_55 | | | | | | _SHA)-256]{#fcs | | > | | | _ckm.1.1_AKG_13 | | | | | .selec | | | | | .selec | | | | | table-content}, | | | | | table-content}, | | | | | [S | | < | | | HAKE256]{#_s_56 | | < | | | | | | | | | | | | | .selectable-con | | | | | | [SHAKE256]{#fcs | | | | | tent}\]]{#_s_54 | | | | | | _ckm.1.1_AKG_14 | | > | | | | | > | | | .selectable-c | | > | | | ontent}\]]{#fcs | | > | | | _ckm.1.1_AKG_12 | | | | | .sele | | | | | .sele | | | | | ctable-content} | | | | | ctable-content} | | | | | | | | | | | | | | | \] | | | | | \] | | | | | | | | | | | | | | | Winternitz | | | | | Winternitz | | | | | parameter = | | | | | parameter = | | | | | \ | | | | | \ | | | | | [**selection**: | | | | | [**selection**: | | | | | [1]{#_s_57 | | | | | | [1]{#fcs | | > | | | _ckm.1.1_AKG_15 | | | | | .selec | | | | | .selec | | | | | table-content}, | | | | | table-content}, | | | | | [2]{#_s_58 | | | | | | [2]{#fcs | | > | | | _ckm.1.1_AKG_16 | | | | | .selec | | | | | .selec | | | | | table-content}, | | | | | table-content}, | | | | | [4]{#_s_59 | | | | | | [4]{#fcs | | > | | | _ckm.1.1_AKG_17 | | | | | .selec | | | | | .selec | | | | | table-content}, | | | | | table-content}, | | | | | [8]{#_s_60 | | | | | | [8]{#fcs | | > | | | _ckm.1.1_AKG_18 | | | | | .select | | | | | .select | | | | | able-content}\] | | | | | able-content}\] | | | | | | | | | | | | | | | Tree height = | | | | | Tree height = | | | | | \ | | | | | \ | | | | | [**selection**: | | | | | [**selection**: | | | | | [5]{#_s_61 | | | | | | [5]{#fcs | | > | | | _ckm.1.1_AKG_19 | | | | | .selec | | | | | .selec | | | | | table-content}, | | | | | table-content}, | | | | | [10]{#_s_62 | | | | | | [10]{#fcs | | > | | | _ckm.1.1_AKG_20 | | | | | .selec | | | | | .selec | | | | | table-content}, | | | | | table-content}, | | | | | [15]{#_s_63 | | | | | | [15]{#fcs | | > | | | _ckm.1.1_AKG_21 | | | | | .selec | | | | | .selec | | | | | table-content}, | | | | | table-content}, | | | | | [20]{#_s_64 | | | | | | [20]{#fcs | | > | | | _ckm.1.1_AKG_22 | | | | | .selec | | | | | .selec | | | | | table-content}, | | | | | table-content}, | | | | | [25]{#_s_65 | | | | | | [25]{#fcs | | > | | | _ckm.1.1_AKG_23 | | | | | .select | | | | | .select | | | | | able-content}\] | | | | | able-content}\] | | +-----------------+-----------------+-----------------+-----------------+ +-----------------+-----------------+-----------------+-----------------+ | ML-KEM | ML-KEM KeyGen | Parameter set = | [NI | | ML-KEM | ML-KEM KeyGen | Parameter set = | [NI | | | | ML-KEM-1024 | ST](#abbr_NIST) | | | | ML-KEM-1024 | ST](#abbr_NIST) | | | | | [FI | | | | | [FI | | | | | PS](#abbr_FIPS) | | | | | PS](#abbr_FIPS) | | | | | 203 (Section | | | | | 203 (Section | | | | | 7.1) | | | | | 7.1) | +-----------------+-----------------+-----------------+-----------------+ +-----------------+-----------------+-----------------+-----------------+ | ML-DSA | ML-DSA KeyGen | Parameter set = | [NI | | ML-DSA | ML-DSA KeyGen | Parameter set = | [NI | | | | ML-DSA-87 | ST](#abbr_NIST) | | | | ML-DSA-87 | ST](#abbr_NIST) | | | | | [FI | | | | | [FI | | | | | PS](#abbr_FIPS) | | | | | PS](#abbr_FIPS) | | | | | 204 (Section | | | | | 204 (Section | | | | | 5.1) | | | | | 5.1) | +-----------------+-----------------+-----------------+-----------------+ +-----------------+-----------------+-----------------+-----------------+ | XMSS | XMSS | Private key | RFC 8391 | | XMSS | XMSS | Private key | RFC 8391 | | | | size = | \[XMSS\] | | | | size = | \[XMSS\] | | | | \ | | | | | \ | | | | | [**selection**: | [NI | | | | [**selection**: | [NI | | | | | ST](#abbr_NIST) | | | | | ST](#abbr_NIST) | | | | - [192 bits | SP 800-208 | | | | - [192 bits | SP 800-208 | | | | with | \[parameters\] | | | | with | \[parameters\] | | | | \ | | | | | \ | | | | | [**selection**: | | | | | [**selection**: | | | | | [[S | | | | | | [ | | | | | HA](#abbr_SHA)- | | | | | | [SHA](#abbr_SHA | | | | | 256/192]{#_s_70 | | | | | | )-256/192]{#fcs | | > | | | _ckm.1.1_AKG_25 | | | | | .selec | | | | | .selec | | | | | table-content}, | | | | | table-content}, | | | | | [SHAKE | | | | | | [SHA | | | | | 256/192]{#_s_71 | | | | | | KE256/192]{#fcs | | > | | | _ckm.1.1_AKG_26 | | | | | | | | | | | | | | | .selectable-con | | | | | | .selectable-c | | | | | tent}\]]{#_s_69 | | | | | | ontent}\]]{#fcs | | > | | | _ckm.1.1_AKG_24 | | | | | .sele | | | | | .sele | | | | | ctable-content} | | | | | ctable-content} | | | | | - [256 bits | | | | | - [256 bits | | | | | with | | | | | with | | | | | \ | | | | | \ | | | | | [**selection**: | | | | | [**selection**: | | | | | | | | | | | | | | | [[SHA](#abbr_S | | | | | | [[SHA](#abbr | | | | | HA)-256]{#_s_73 | | | | | | _SHA)-256]{#fcs | | > | | | _ckm.1.1_AKG_28 | | | | | .selec | | | | | .selec | | | | | table-content}, | | | | | table-content}, | | | | | [S | | < | | | HAKE256]{#_s_74 | | < | | | | | | | | | | | | | .selectable-con | | | | | | [SHAKE256]{#fcs | | | | | tent}\]]{#_s_72 | | | | | | _ckm.1.1_AKG_29 | | > | | | | | > | | | .selectable-c | | > | | | ontent}\]]{#fcs | | > | | | _ckm.1.1_AKG_27 | | | | | .sele | | | | | .sele | | | | | ctable-content} | | | | | ctable-content} | | | | | | | | | | | | | | | \] | | | | | \] | | | | | | | | | | | | | | | Tree height = | | | | | Tree height = | | | | | \ | | | | | \ | | | | | [**selection**: | | | | | [**selection**: | | | | | [10]{#_s_75 | | | | | | [10]{#fcs | | > | | | _ckm.1.1_AKG_30 | | | | | .selec | | | | | .selec | | | | | table-content}, | | | | | table-content}, | | | | | [16]{#_s_76 | | | | | | [16]{#fcs | | > | | | _ckm.1.1_AKG_31 | | | | | .selec | | | | | .selec | | | | | table-content}, | | | | | table-content}, | | | | | [20]{#_s_77 | | | | | | [20]{#fcs | | > | | | _ckm.1.1_AKG_32 | | | | | .select | | | | | .select | | | | | able-content}\] | | | | | able-content}\] | | +-----------------+-----------------+-----------------+-----------------+ +-----------------+-----------------+-----------------+-----------------+ : [Table [3]{.counter}]{#fcs-ckm-1-ak-sels .ctr myid="fcs-ckm-1-ak-sels" : [Table [3]{.counter}]{#fcs-ckm-1-ak-sels .ctr myid="fcs-ckm-1-ak-sels" counter-type="ct-Table"}: Allowable Choices for counter-type="ct-Table"}: Allowable Choices for [FCS_CKM.1/AKG](#FCS_CKM.1/AKG) [FCS_CKM.1/AKG](#FCS_CKM.1/AKG) ::: appnote ::: appnote [Application Note: ]{.note-header}[ ]{.note} [Application Note: ]{.note-header}[ ]{.note} For [RSA](#abbr_RSA) the choice of the modulus implies the resulting key For [RSA](#abbr_RSA) the choice of the modulus implies the resulting key sizes of the public and private keys generated using the specified sizes of the public and private keys generated using the specified standard methods. [RSA](#abbr_RSA) key generation with modulus size 2048 standard methods. [RSA](#abbr_RSA) key generation with modulus size 2048 bits is no longer permitted by [CNSA](#abbr_CNSA). bits is no longer permitted by [CNSA](#abbr_CNSA). For Finite Field Cryptography ([FFC](#abbr_FFC)) [DSA](#abbr_DSA), For Finite Field Cryptography ([FFC](#abbr_FFC)) [DSA](#abbr_DSA), [ST](#abbr_ST) authors should consult schemes for guidelines on use. [ST](#abbr_ST) authors should consult schemes for guidelines on use. [FIPS](#abbr_FIPS) PUB 186-5 does not approve [DSA](#abbr_DSA) for [FIPS](#abbr_FIPS) PUB 186-5 does not approve [DSA](#abbr_DSA) for digital signature generation but allows [DSA](#abbr_DSA) for digital digital signature generation but allows [DSA](#abbr_DSA) for digital signature verification for legacy purposes. "[FFC](#abbr_FFC)-ERB" or signature verification for legacy purposes. "[FFC](#abbr_FFC)-ERB" or "[FFC](#abbr_FFC)--RS" may be claimed only for generating private and "[FFC](#abbr_FFC)--RS" may be claimed only for generating private and public keys when "[DH](#abbr_DH)" is claimed in public keys when "[DH](#abbr_DH)" is claimed in [FCS_CKM_EXT.7/LOCKED](#FCS_CKM_EXT.7/LOCKED) or [FCS_CKM_EXT.7/LOCKED](#FCS_CKM_EXT.7/LOCKED) or [FCS_CKM_EXT.7/UNLOCKED](#FCS_CKM_EXT.7/UNLOCKED). [FCS_CKM_EXT.7/UNLOCKED](#FCS_CKM_EXT.7/UNLOCKED). For ECC selections, "P-256" may only be selected if the [PP-Module for For ECC selections, "P-256" may only be selected if the [PP-Module for Bluetooth, version | Bluetooth, version 2.0]() is included in the [ST](#abbr_ST) and P-256 2.0](https://www.niap-ccevs.org/protectionprofiles/425) is included in | may only be used specifically for Bluetooth functions. the [ST](#abbr_ST) and P-256 may only be used specifically for Bluetooth < functions. < When generating ECC keys pairs for key agreement and if When generating ECC keys pairs for key agreement and if "[ECDH](#abbr_ECDH)" is claimed in "[ECDH](#abbr_ECDH)" is claimed in [FCS_CKM_EXT.7/LOCKED](#FCS_CKM_EXT.7/LOCKED) or [FCS_CKM_EXT.7/LOCKED](#FCS_CKM_EXT.7/LOCKED) or [FCS_CKM_EXT.7/UNLOCKED](#FCS_CKM_EXT.7/UNLOCKED), then "ECC--ERB" or [FCS_CKM_EXT.7/UNLOCKED](#FCS_CKM_EXT.7/UNLOCKED), then "ECC--ERB" or "ECC--RS" must be claimed. The sizes of the private key, which is a "ECC--RS" must be claimed. The sizes of the private key, which is a scalar, and the public key, which is a point on the elliptic curve, are scalar, and the public key, which is a point on the elliptic curve, are determined by the choice of the curve. determined by the choice of the curve. When generating ECC key pairs for digital signature generation and if When generating ECC key pairs for digital signature generation and if "[ECDSA](#abbr_ECDSA)" is claimed in "[ECDSA](#abbr_ECDSA)" is claimed in [FCS_COP.1/SigGen](#FCS_COP.1/SigGen), then "ECC--ERB" or "ECC--RS" must [FCS_COP.1/SigGen](#FCS_COP.1/SigGen), then "ECC--ERB" or "ECC--RS" must be claimed. The sizes of the private key, which is a scalar, and the be claimed. The sizes of the private key, which is a scalar, and the public key, which is a point on the elliptic curve, are determined by public key, which is a point on the elliptic curve, are determined by the choice of the curve. the choice of the curve. ::: ::: ::: ::: ::: ::: ::: {.activity_pane .hide} ::: {.activity_pane .hide} ::: activity_pane_header ::: activity_pane_header [[ Evaluation Activities [[ Evaluation Activities ]{.activity_pane_label}[]{.toggler}](#){onclick="toggle(this);return false;"} ]{.activity_pane_label}[]{.toggler}](#){onclick="toggle(this);return false;"} ::: ::: ::: activity_pane_body ::: activity_pane_body ::: component-activity-header ::: component-activity-header [FCS_CKM.1/AKG](#FCS_CKM.1/AKG) [FCS_CKM.1/AKG](#FCS_CKM.1/AKG) ::: ::: ::: eacategory ::: eacategory [TSS](#abbr_TSS) [TSS](#abbr_TSS) ::: ::: ::: ea ::: ea ::: ea ::: ea The evaluator shall examine the [TSS](#abbr_TSS) to verify that it The evaluator shall examine the [TSS](#abbr_TSS) to verify that it describes how the [TOE](#abbr_TOE) generates a key based on output from describes how the [TOE](#abbr_TOE) generates a key based on output from a random bit generator as specified in [FCS_RBG.1](#FCS_RBG.1). The a random bit generator as specified in [FCS_RBG.1](#FCS_RBG.1). The evaluator shall review the [TSS](#abbr_TSS) to verify that it describes evaluator shall review the [TSS](#abbr_TSS) to verify that it describes how the functionality described by [FCS_RBG.1](#FCS_RBG.1) is invoked. how the functionality described by [FCS_RBG.1](#FCS_RBG.1) is invoked. If support for P-256 is claimed, the evaluator shall examine the If support for P-256 is claimed, the evaluator shall examine the [TSS](#abbr_TSS) to verify that it is only used for Bluetooth functions. [TSS](#abbr_TSS) to verify that it is only used for Bluetooth functions. The evaluator shall examine the [TSS](#abbr_TSS) to verify that it The evaluator shall examine the [TSS](#abbr_TSS) to verify that it identifies the usage and key lifecycle for keys generated using each identifies the usage and key lifecycle for keys generated using each selected algorithm. selected algorithm. The evaluator shall examine the [TSS](#abbr_TSS) to verify that any The evaluator shall examine the [TSS](#abbr_TSS) to verify that any one-time values such as nonces or masks are constructed in accordance one-time values such as nonces or masks are constructed in accordance with the relevant standards. with the relevant standards. If the [TOE](#abbr_TOE) uses the generated key in a key chain or If the [TOE](#abbr_TOE) uses the generated key in a key chain or hierarchy then the evaluator shall verify that the [TSS](#abbr_TSS) hierarchy then the evaluator shall verify that the [TSS](#abbr_TSS) describes how the key is used as part of the key chain or hierarchy. describes how the key is used as part of the key chain or hierarchy. ::: ::: ::: ::: ::: eacategory ::: eacategory Guidance Guidance ::: ::: ::: ea ::: ea ::: ea ::: ea The evaluator shall verify that the guidance instructs the administrator The evaluator shall verify that the guidance instructs the administrator how to configure the [TOE](#abbr_TOE) to generate keys for the selected how to configure the [TOE](#abbr_TOE) to generate keys for the selected key generation algorithms for all key types and uses identified in the key generation algorithms for all key types and uses identified in the [TSS](#abbr_TSS). [TSS](#abbr_TSS). ::: ::: ::: ::: ::: eacategory ::: eacategory Tests Tests ::: ::: ::: ea ::: ea ::: ea ::: ea The following tests are conditional based on the selections made in the The following tests are conditional based on the selections made in the [SFR](#abbr_SFR). The evaluator shall perform the following tests or [SFR](#abbr_SFR). The evaluator shall perform the following tests or witness respective tests executed by the developer. The tests must be witness respective tests executed by the developer. The tests must be executed on a platform that is as close as practically possible to the executed on a platform that is as close as practically possible to the operational platform (but which may be instrumented in terms of, for operational platform (but which may be instrumented in terms of, for example, use of a debug mode). Where the test is not carried out on the example, use of a debug mode). Where the test is not carried out on the [TOE](#abbr_TOE) itself, the test platform shall be identified and the [TOE](#abbr_TOE) itself, the test platform shall be identified and the differences between test environment and [TOE](#abbr_TOE) execution differences between test environment and [TOE](#abbr_TOE) execution environment shall be described. | environment shall be described.\ < \ < **[RSA](#abbr_RSA) Key Generation** **[RSA](#abbr_RSA) Key Generation** ------------------ ---------------------------------------- ----------------------- ------------------ ---------------------------------------- ----------------------- Identifier Cryptographic Key Generation Algorithm Cryptographic Algorithm Identifier Cryptographic Key Generation Algorithm Cryptographic Algorithm [RSA](#abbr_RSA) [RSA](#abbr_RSA) Modulus of size \[**sel [RSA](#abbr_RSA) [RSA](#abbr_RSA) Modulus of size \[**sel ------------------ ---------------------------------------- ----------------------- ------------------ ---------------------------------------- ----------------------- [FIPS](#abbr_FIPS) PUB 186-5 Key Pair generation specifies five methods [FIPS](#abbr_FIPS) PUB 186-5 Key Pair generation specifies five methods for generating the primes *p* and *q*. | for generating the primes *p* and *q*. These are: < These are: < 1. Random provable primes 1. Random provable primes 2. Random probable primes 2. Random probable primes 3. Provable primes with conditions based on auxiliary provable primes 3. Provable primes with conditions based on auxiliary provable primes 4. Probable primes with conditions based on auxiliary provable primes 4. Probable primes with conditions based on auxiliary provable primes 5. Probable primes with conditions based on auxiliary probable primes 5. Probable primes with conditions based on auxiliary probable primes In addition to the key generation method, the input parameters are: In addition to the key generation method, the input parameters are: - Modulus \[3072, 4096, 6144, 8192\] - Modulus \[3072, 4096, 6144, 8192\] - Hash algorithm \[[SHA](#abbr_SHA)-384, [SHA](#abbr_SHA)-512\] - Hash algorithm \[[SHA](#abbr_SHA)-384, [SHA](#abbr_SHA)-512\] (methods 1, 3, 4 only) (methods 1, 3, 4 only) - Rabin-Miller prime test \[2^100^, 2^Security\ String^\] (methods 2, - Rabin-Miller prime test \[2^100^, 2^Security\ String^\] (methods 2, 4, 5 only) 4, 5 only) - *p* mod 8 value \[0,1,3,5,7\] - *p* mod 8 value \[0,1,3,5,7\] - *q* mod 8 value \[0,1,3,5,7\] - *q* mod 8 value \[0,1,3,5,7\] - Private key format \[standard, Chinese Remainder Theorem\] - Private key format \[standard, Chinese Remainder Theorem\] - Public exponent \[fixed value, random\] - Public exponent \[fixed value, random\] The evaluator shall verify the ability of the [TSF](#abbr_TSF) to The evaluator shall verify the ability of the [TSF](#abbr_TSF) to correctly produce values for the [RSA](#abbr_RSA) key components, correctly produce values for the [RSA](#abbr_RSA) key components, including the public verification exponent *e*, the private prime including the public verification exponent *e*, the private prime factors *p* and *q*, the public modulus *n*, and the calculation of the factors *p* and *q*, the public modulus *n*, and the calculation of the private signature exponent *d*. | private signature exponent *d*.\ | ***Testing for Random Provable Primes and Conditional Methods*** To test \ | the key generation method for the random provable primes method and for ***Testing for Random Provable Primes and Conditional Methods*** | all the primes with conditions methods (methods 1, 3-5), the evaluator | shall seed the [TSF](#abbr_TSF) key generation routine with sufficient To test the key generation method for the random provable primes method | data to deterministically generate the [RSA](#abbr_RSA) key pair. For and for all the primes with conditions methods (methods 1, 3-5), the | each supported combination of the above input parameters, the evaluator evaluator shall seed the [TSF](#abbr_TSF) key generation routine with | shall have the [TSF](#abbr_TSF) generate 25 key pairs. The evaluator sufficient data to deterministically generate the [RSA](#abbr_RSA) key | shall verify the correctness of the [TSF](#abbr_TSF)'s implementation by pair. | comparing values generated by the [TSF](#abbr_TSF) with those generated | by a known good implementation using the same input parameters.\ For each supported combination of the above input parameters, the | ***Testing for Random Probable Primes Method*** If the [TOE](#abbr_TOE) evaluator shall have the [TSF](#abbr_TSF) generate 25 key pairs. The | generates random probable primes (method 2) then, if possible, the evaluator shall verify the correctness of the [TSF](#abbr_TSF)'s | random probable primes method should also be verified against a known implementation by comparing values generated by the [TSF](#abbr_TSF) | good implementation as described above. If verification against a known with those generated by a known good implementation using the same input | good implementation is not possible, the evaluator shall have the parameters. | [TSF](#abbr_TSF) generate 25 key pairs for each supported key length | nlen and verify that all of the following are true. \ < ***Testing for Random Probable Primes Method*** < < If the [TOE](#abbr_TOE) generates random probable primes (method 2) < then, if possible, the random probable primes method should also be < verified against a known good implementation as described above. If < verification against a known good implementation is not possible, the < evaluator shall have the [TSF](#abbr_TSF) generate 25 key pairs for each < supported key length nlen and verify that all of the following are true. < - *n* = *p*\**q* - *n* = *p*\**q* - *p* and *q* are probably prime according to Miller-Rabin tests with - *p* and *q* are probably prime according to Miller-Rabin tests with error probability \<2^(-125)^ | error probability \<2 ^(-125)^ - 2^16^ \< *e* \< 2^256^ and *e* is an odd integer - 2^16^ \< *e* \< 2^256^ and *e* is an odd integer - GCD(*p*-1,*e*) = 1 - GCD(*p*-1,*e*) = 1 - GCD(*q*-1,*e*) = 1 - GCD(*q*-1,*e*) = 1 - \|*p*-*q*\| \> 2^(*nlen*/2\ --\ 100)^ - \|*p*-*q*\| \> 2^(*nlen*/2\ --\ 100)^ - *p* ≥ squareroot(2)\*( 2^(*nlen*/2\ -1)^ ) - *p* ≥ squareroot(2)\*( 2^(*nlen*/2\ -1)^ ) - *q* ≥ squareroot(2)\*( 2^(*nlen*/2\ -1)^ ) - *q* ≥ squareroot(2)\*( 2^(*nlen*/2\ -1)^ ) - 2^(*nlen*/2)^ \< d \< LCM(*p*-1,*q*-1) - 2^(*nlen*/2)^ \< d \< LCM(*p*-1,*q*-1) - e\*d = 1 mod LCM(*p*-1,*q*-1) - e\*d = 1 mod LCM(*p*-1,*q*-1) \ \ **Elliptic Curve Key Generation** **Elliptic Curve Key Generation** ----------------- ----------------- ------------------ ---------------------- ----------------- ----------------- ------------------ ---------------------- Identifier Cryptographic Key Cryptographic List of Standards Identifier Cryptographic Key Cryptographic List of Standards Generation Algorithm Generation Algorithm Algorithm Parameters Algorithm Parameters ECC-ERB ECC -- Extra Elliptic Curve [NIST](#abbr_NIST) ECC-ERB ECC -- Extra Elliptic Curve [NIST](#abbr_NIST) Random Bits \[**selection:** [FIPS](#abbr_FIPS) PUB Random Bits \[**selection:** [FIPS](#abbr_FIPS) PUB *P-256, P-384, 186-5 (Section A.2.1) *P-256, P-384, 186-5 (Section A.2.1) P-521*\] P-521*\] [NIST](#abbr_NIST) SP [NIST](#abbr_NIST) SP 800-186 (Section 3) 800-186 (Section 3) \[[NIST](#abbr_NIST) \[[NIST](#abbr_NIST) Curves\] Curves\] ECC-RS ECC -- Rejection Elliptic Curve [NIST](#abbr_NIST) ECC-RS ECC -- Rejection Elliptic Curve [NIST](#abbr_NIST) Sampling \[**selection:** [FIPS](#abbr_FIPS) PUB Sampling \[**selection:** [FIPS](#abbr_FIPS) PUB *P-256, P-384, 186-5 (Section A.2.2) *P-256, P-384, 186-5 (Section A.2.2) P-521*\] P-521*\] [NIST](#abbr_NIST) SP [NIST](#abbr_NIST) SP 800-186 (Section 3) 800-186 (Section 3) \[[NIST](#abbr_NIST) \[[NIST](#abbr_NIST) Curves\] Curves\] ----------------- ----------------- ------------------ ---------------------- ----------------- ----------------- ------------------ ---------------------- To test the [TOE](#abbr_TOE)'s ability to generate asymmetric To test the [TOE](#abbr_TOE)'s ability to generate asymmetric cryptographic keys using elliptic curves, the evaluator shall perform cryptographic keys using elliptic curves, the evaluator shall perform the ECC Key Generation Test and the ECC Key Validation Test using the the ECC Key Generation Test and the ECC Key Validation Test using the following input parameters. following input parameters. - Elliptic curve \[P-256, P-384, P-521\] - Elliptic curve \[P-256, P-384, P-521\] - Key pair generation method \[extra random bits, rejection sampling\] - Key pair generation method \[extra random bits, rejection sampling\] \ \ ***ECC Key Generation Test***\ ***ECC Key Generation Test***\ For each supported combination of the above input parameters the For each supported combination of the above input parameters the evaluator shall require the implementation under test to generate 10 evaluator shall require the implementation under test to generate 10 private and public key pairs (*d, Q*). The private key, *d*, shall be private and public key pairs (*d, Q*). The private key, *d*, shall be generated using a random bit generator as specified in generated using a random bit generator as specified in [FCS_RBG.1](#FCS_RBG.1). The private key, *d*, is used to compute the [FCS_RBG.1](#FCS_RBG.1). The private key, *d*, is used to compute the public key, *Q\'*. The evaluator shall confirm that 0\<*d*\<*n* (where | public key, *Q\'*. The evaluator shall confirm that 0\< *d* \< *n* *n* is the order of the group), and the computed value *Q\'* is then | (where *n* is the order of the group), and the computed value *Q\'* is compared to the generated public and private key pairs' public key, *Q*, | then compared to the generated public and private key pairs' public key, to confirm that *Q* is equal to *Q\'*. | *Q*, to confirm that *Q* is equal to *Q\'*.\ < \ < ***ECC Key Validation Test***\ ***ECC Key Validation Test***\ For each supported combination of the above parameters the evaluator For each supported combination of the above parameters the evaluator shall generate 12 private and public key pairs using the key generation shall generate 12 private and public key pairs using the key generation function of a known good implementation. For each set of 12 public keys, function of a known good implementation. For each set of 12 public keys, the evaluator shall modify four public key values by shifting *x* or *y* the evaluator shall modify four public key values by shifting *x* or *y* out of range by adding the order of the field and modify four other out of range by adding the order of the field and modify four other public key values by shifting *x* or *y* so that they are still in public key values by shifting *x* or *y* so that they are still in bounds, but not on the curve. The remaining public key values are left bounds, but not on the curve. The remaining public key values are left unchanged (i.e., correct). To determine correctness, the evaluator shall unchanged (i.e., correct). To determine correctness, the evaluator shall submit the public keys to the public key validation (PKV) function of submit the public keys to the public key validation (PKV) function of the [TOE](#abbr_TOE) and confirm that the results correspond as expected the [TOE](#abbr_TOE) and confirm that the results correspond as expected for the modified and unmodified values. | for the modified and unmodified values.\ < \ < **Finite Field Cryptography Key Generation** **Finite Field Cryptography Key Generation** ---------------------- ------------------ ------------------ -------------------- ---------------------- ------------------ ------------------ -------------------- Identifier Cryptographic Key Cryptographic List of Standards Identifier Cryptographic Key Cryptographic List of Standards Generation Algorithm Generation Algorithm Algorithm Parameters Algorithm Parameters [FFC](#abbr_FFC)-ERB [FFC](#abbr_FFC) Static domain [NIST](#abbr_NIST) [FFC](#abbr_FFC)-ERB [FFC](#abbr_FFC) Static domain [NIST](#abbr_NIST) -- Extra Random parameters SP 800-56A Revision -- Extra Random parameters SP 800-56A Revision Bits approved for 3 (Section Bits approved for 3 (Section \[**selection:** 5.6.1.1.3) \[key \[**selection:** 5.6.1.1.3) \[key *IKE groups pair generation\] *IKE groups pair generation\] \[**selection:** \[**selection:** MODP-3072, \[**selection:** MODP-3072, \[**selection:** MODP-4096, *RFC 3526 \[IKE MODP-4096, *RFC 3526 \[IKE MODP-6144, groups\], RFC 7919 MODP-6144, groups\], RFC 7919 MODP-8192\], \[[TLS](#abbr_TLS) MODP-8192\], \[[TLS](#abbr_TLS) [TLS](#abbr_TLS) groups\]*\] [TLS](#abbr_TLS) groups\]*\] groups groups \[**selection:** \[**selection:** ffdhe3072, ffdhe3072, ffdhe4096, ffdhe4096, ffdhe6144, ffdhe6144, ffdhe8192\]*\]\] ffdhe8192\]*\]\] [FFC](#abbr_FFC)-RS [FFC](#abbr_FFC) Static domain [NIST](#abbr_NIST) [FFC](#abbr_FFC)-RS [FFC](#abbr_FFC) Static domain [NIST](#abbr_NIST) -- Rejection parameters SP 800-56A Revision -- Rejection parameters SP 800-56A Revision Sampling approved for 3 (Section Sampling approved for 3 (Section \[**selection:** 5.6.1.1.4) \[key \[**selection:** 5.6.1.1.4) \[key IKE groups pair generation\] IKE groups pair generation\] \[**selection:** \[**selection:** *MODP-3072, \[**selection:** *MODP-3072, \[**selection:** MODP-4096, *RFC 3526 \[IKE MODP-4096, *RFC 3526 \[IKE MODP-6144, groups\], RFC 7919 MODP-6144, groups\], RFC 7919 MODP-8192\], \[[TLS](#abbr_TLS) MODP-8192\], \[[TLS](#abbr_TLS) [TLS](#abbr_TLS) groups\]*\] [TLS](#abbr_TLS) groups\]*\] groups groups \[**selection:** \[**selection:** ffdhe3072, ffdhe3072, ffdhe4096, ffdhe4096, ffdhe6144, ffdhe6144, ffdhe8192\]\]*\] | ffdhe8192\]\]* \] ---------------------- ------------------ ------------------ -------------------- ---------------------- ------------------ ------------------ -------------------- To test the [TOE](#abbr_TOE)'s ability to generate asymmetric To test the [TOE](#abbr_TOE)'s ability to generate asymmetric cryptographic keys using finite fields, the evaluator shall perform the cryptographic keys using finite fields, the evaluator shall perform the Safe Primes Generation Test and the Safe Primes Validation Test using Safe Primes Generation Test and the Safe Primes Validation Test using the following input parameter: the following input parameter: - Fields/Groups \[MODP-3072, MODP-4096, MODP-6144, MODP-8192, - Fields/Groups \[MODP-3072, MODP-4096, MODP-6144, MODP-8192, ffdhe3072, ffdhe4096, ffdhe6144, ffdhe8192\] ffdhe3072, ffdhe4096, ffdhe6144, ffdhe8192\] \ \ ***Safe Primes Generation Test***\ ***Safe Primes Generation Test***\ For each supported safe primes group, generate 10 key pairs. The For each supported safe primes group, generate 10 key pairs. The evaluator shall verify the correctness of the [TSF](#abbr_TSF)'s evaluator shall verify the correctness of the [TSF](#abbr_TSF)'s implementation by comparing values generated by the [TSF](#abbr_TSF) implementation by comparing values generated by the [TSF](#abbr_TSF) with those generated by a known good implementation using the same input with those generated by a known good implementation using the same input parameters. | parameters.\ < \ < ***Safe Primes Verification Test***\ ***Safe Primes Verification Test***\ For each supported safe primes group, use a known good implementation to For each supported safe primes group, use a known good implementation to generate 10 key pairs. For each set of 10, the evaluator shall modify generate 10 key pairs. For each set of 10, the evaluator shall modify three so they are incorrect. The remaining values are left unmodified three so they are incorrect. The remaining values are left unmodified (i.e., correct). To determine correctness, the evaluator shall submit (i.e., correct). To determine correctness, the evaluator shall submit the key pairs to the public key validation (PKV) function of the the key pairs to the public key validation (PKV) function of the [TOE](#abbr_TOE) and shall confirm that the results correspond as [TOE](#abbr_TOE) and shall confirm that the results correspond as expected for the modified and unmodified values. | expected for the modified and unmodified values.\ < \ < **EdDSA Key Generation** **EdDSA Key Generation** ----------------- ----------------- ----------------- -------------------- ----------------- ----------------- ----------------- -------------------- Identifier Cryptographic Key Cryptographic List of Standards Identifier Cryptographic Key Cryptographic List of Standards Generation Algorithm Generation Algorithm Algorithm Parameters Algorithm Parameters EdDSA EdDSA Edwards25519 [NIST](#abbr_NIST) EdDSA EdDSA Edwards25519 [NIST](#abbr_NIST) [FIPS](#abbr_FIPS) [FIPS](#abbr_FIPS) PUB 186-5 \[EdDSA\] PUB 186-5 \[EdDSA\] NISTP 800-186 NISTP 800-186 \[parameters\] \[parameters\] ----------------- ----------------- ----------------- -------------------- ----------------- ----------------- ----------------- -------------------- The evaluator shall require the implementation under test (IUT) to The evaluator shall require the implementation under test (IUT) to generate 10 private/public key pairs. The private key shall be generated generate 10 private/public key pairs. The private key shall be generated as specified in RFC 7748 using an approved random bit generator as specified in RFC 7748 using an approved random bit generator ([RBG](#abbr_RBG)) and shall be written in little-endian order (least ([RBG](#abbr_RBG)) and shall be written in little-endian order (least significant byte first). To determine correctness, the evaluator shall significant byte first). To determine correctness, the evaluator shall submit the generated key pairs to the public key verification (PKV) submit the generated key pairs to the public key verification (PKV) function of a known good implementation. | function of a known good implementation. Note: Assuming the PKV function | of the good implementation will (using little-endian order): Note: Assuming the PKV function of the good implementation will (using < little-endian order): < a. Confirm the private and public keys are 32-byte values a. Confirm the private and public keys are 32-byte values b. Confirm the three least significant bits of the first byte of the b. Confirm the three least significant bits of the first byte of the private key are zero private key are zero c. Confirm the most significant bit of the last byte is zero c. Confirm the most significant bit of the last byte is zero d. Confirm the second most significant bit of the last byte is one d. Confirm the second most significant bit of the last byte is one e. Calculate the expected public key from the private key and confirm e. Calculate the expected public key from the private key and confirm it matches the supplied public key it matches the supplied public key The evaluator shall generate 10 private/public key pairs using the key The evaluator shall generate 10 private/public key pairs using the key generation function of a known good implementation and modify 5 of the generation function of a known good implementation and modify 5 of the public key values so that they are incorrect, leaving five values public key values so that they are incorrect, leaving five values unchanged (i.e. correct). The evaluator shall obtain in response a set unchanged (i.e. correct). The evaluator shall obtain in response a set of 10 PASS/FAIL values.\ of 10 PASS/FAIL values.\ **LMS Key Generation** **LMS Key Generation** ----------------- ----------------- ---------------------------- ------------------ ----------------- ----------------- ---------------------------- ------------------ Identifier Cryptographic Key Cryptographic Algorithm List of Standards Identifier Cryptographic Key Cryptographic Algorithm List of Standards Generation Parameters Generation Parameters Algorithm Algorithm LMS LMS Key Private key size = RFC 8554 \[LMS\] LMS LMS Key Private key size = RFC 8554 \[LMS\] Generation \[**selection:** 192 bits Generation \[**selection:** 192 bits with \[**selection:** [NIST](#abbr_NIST) with \[**selection:** [NIST](#abbr_NIST) *[SHA](#abbr_SHA)-256/192, SP 800-208 *[SHA](#abbr_SHA)-256/192, SP 800-208 SHAKE256/192\], 256 bits \[parameters\] SHAKE256/192\], 256 bits \[parameters\] with \[**selection:** with \[**selection:** [SHA](#abbr_SHA)-256, [SHA](#abbr_SHA)-256, SHAKE256\]*\]; Winternitz | SHAKE256\]* \]; Winternitz parameter = \[**selection:** parameter = \[**selection:** *1, 2, 4, 8*\]; Tree height *1, 2, 4, 8*\]; Tree height = \[**selection:** *5, 10, = \[**selection:** *5, 10, 15, 20, 25*\] 15, 20, 25*\] ----------------- ----------------- ---------------------------- ------------------ ----------------- ----------------- ---------------------------- ------------------ To test the [TOE](#abbr_TOE)'s ability to generate asymmetric To test the [TOE](#abbr_TOE)'s ability to generate asymmetric cryptographic keys using LMS, the evaluator shall perform the LMS Key cryptographic keys using LMS, the evaluator shall perform the LMS Key Generation Test using the following input parameters: Generation Test using the following input parameters: - Hash algorithm \[[SHA](#abbr_SHA)-256/192, SHAKE256/192, - Hash algorithm \[[SHA](#abbr_SHA)-256/192, SHAKE256/192, [SHA](#abbr_SHA)-256, SHAKE256\] [SHA](#abbr_SHA)-256, SHAKE256\] - Winternitz \[1, 2, 4, 8\] - Winternitz \[1, 2, 4, 8\] - Tree height \[5, 10, 15, 20, 25\] - Tree height \[5, 10, 15, 20, 25\] \ \ ***LMS Key Generation Test***\ ***LMS Key Generation Test***\ For each supported combination of the hash algorithm, Winternitz For each supported combination of the hash algorithm, Winternitz parameter, and tree height, the evaluator shall generate one public key parameter, and tree height, the evaluator shall generate one public key for each of the test cases. The number of test cases depends on the tree for each of the test cases. The number of test cases depends on the tree height: height: ::: {style="text-align: center;"} ::: {style="text-align: center;"} [Table [4]{.counter}: Number of LMS Test Cases]{#lms-test-cases .ctr [Table [4]{.counter}: Number of LMS Test Cases]{#lms-test-cases .ctr myid="lms-test-cases" counter-type="ct-Table"} myid="lms-test-cases" counter-type="ct-Table"} ::: ::: -------- ---------------------- -------- ---------------------- Height Number of test cases Height Number of test cases 5 5 5 5 10 4 10 4 15 3 15 3 20 2 20 2 25 1 25 1 -------- ---------------------- -------- ---------------------- The evaluator shall verify the correctness of the [TSF](#abbr_TSF)'s The evaluator shall verify the correctness of the [TSF](#abbr_TSF)'s implementation by comparing the public key generated by the implementation by comparing the public key generated by the [TSF](#abbr_TSF) with that generated by a known good implementation [TSF](#abbr_TSF) with that generated by a known good implementation using the same input parameters. | using the same input parameters.\ < \ < **ML-KEM Key Generation** **ML-KEM Key Generation** ------------ ---------------------------------------- ----------------------------- ------------ ---------------------------------------- ----------------------------- Identifier Cryptographic Key Generation Algorithm Cryptographic Algorithm Param Identifier Cryptographic Key Generation Algorithm Cryptographic Algorithm Param ML-KEM ML-KEM Key Generation Parameter set = \[ML-KEM-1024 ML-KEM ML-KEM Key Generation Parameter set = \[ML-KEM-1024 ------------ ---------------------------------------- ----------------------------- ------------ ---------------------------------------- ----------------------------- To test the [TOE](#abbr_TOE)'s ability to generate asymmetric To test the [TOE](#abbr_TOE)'s ability to generate asymmetric cryptographic keys using ML-KEM, the evaluator shall perform the cryptographic keys using ML-KEM, the evaluator shall perform the Algorithm Functional Test using the following input parameters: Algorithm Functional Test using the following input parameters: - Parameter set \[ML-KEM-1024\] - Parameter set \[ML-KEM-1024\] - Random seed d \[32 bytes\] - Random seed d \[32 bytes\] - Random seed z \[32 bytes\] - Random seed z \[32 bytes\] \ \ ***Algorithm Functional Test***\ ***Algorithm Functional Test***\ For each supported parameter set the evaluator shall require the For each supported parameter set the evaluator shall require the implementation under test to generate 25 key pairs using 25 different implementation under test to generate 25 key pairs using 25 different randomly generated pairs of 32-byte seed values (*d, z*). To determine randomly generated pairs of 32-byte seed values (*d, z*). To determine correctness, the evaluator shall compare the resulting key pairs (*ek, correctness, the evaluator shall compare the resulting key pairs (*ek, dk*) with those generated using a known good implementation using the dk*) with those generated using a known good implementation using the same inputs. | same inputs.\ < \ < **ML-DSA Key Generation** **ML-DSA Key Generation** ------------ ---------------------------------------- ----------------------------- ------------ ---------------------------------------- ----------------------------- Identifier Cryptographic Key Generation Algorithm Cryptographic Algorithm Param Identifier Cryptographic Key Generation Algorithm Cryptographic Algorithm Param ML-DSA ML-DSA Key Generation Parameter set = ML-DSA-87 ML-DSA ML-DSA Key Generation Parameter set = ML-DSA-87 ------------ ---------------------------------------- ----------------------------- ------------ ---------------------------------------- ----------------------------- To test the [TOE](#abbr_TOE)'s ability to generate asymmetric To test the [TOE](#abbr_TOE)'s ability to generate asymmetric cryptographic keys using ML-DSA, the evaluator shall perform the cryptographic keys using ML-DSA, the evaluator shall perform the Algorithm Functional Test using the following input parameters: Algorithm Functional Test using the following input parameters: - Parameter set \[ML-DSA-87\] - Parameter set \[ML-DSA-87\] - Random seed \[32 bytes\] - Random seed \[32 bytes\] \ \ ***Algorithm Functional Test***\ ***Algorithm Functional Test***\ For each supported parameter set the evaluator shall require the For each supported parameter set the evaluator shall require the implementation under test to generate 25 key pairs using 25 different implementation under test to generate 25 key pairs using 25 different randomly generated 32-byte seed values. To determine correctness, the randomly generated 32-byte seed values. To determine correctness, the evaluator shall compare the resulting key pairs with those generated evaluator shall compare the resulting key pairs with those generated using a known good implementation using the same inputs. | using a known good implementation using the same inputs.\ < \ < **XMSS Key Generation** **XMSS Key Generation** ----------------- ----------------- --------------------------- ------------------- ----------------- ----------------- --------------------------- ------------------- Identifier Cryptographic Key Cryptographic Algorithm List of Standards Identifier Cryptographic Key Cryptographic Algorithm List of Standards Generation Parameters Generation Parameters Algorithm Algorithm XMSS XMSS Private key size = RFC 8391 \[XMSS\] XMSS XMSS Private key size = RFC 8391 \[XMSS\] \[**selection:** *192 bits \[**selection:** *192 bits with \[**selection:** [NIST](#abbr_NIST) with \[**selection:** [NIST](#abbr_NIST) [SHA](#abbr_SHA)-256/192, SP 800-208 [SHA](#abbr_SHA)-256/192, SP 800-208 SHAKE256/192\], 256 bits \[parameters\] SHAKE256/192\], 256 bits \[parameters\] with \[**selection:** with \[**selection:** [SHA](#abbr_SHA)-256, [SHA](#abbr_SHA)-256, SHAKE256\]*\], tree height | SHAKE256\]* \], tree height = \[**selection:** *10, 16, = \[**selection:** *10, 16, 20*\] 20*\] ----------------- ----------------- --------------------------- ------------------- ----------------- ----------------- --------------------------- ------------------- To test the [TOE](#abbr_TOE)'s ability to generate asymmetric To test the [TOE](#abbr_TOE)'s ability to generate asymmetric cryptographic keys using XMSS, the evaluator shall perform the XMSS Key cryptographic keys using XMSS, the evaluator shall perform the XMSS Key Generation Test using the following input parameters: Generation Test using the following input parameters: - Hash algorithm \[[SHA](#abbr_SHA)-256/192, SHAKE256/192, - Hash algorithm \[[SHA](#abbr_SHA)-256/192, SHAKE256/192, [SHA](#abbr_SHA)-256, SHAKE256\] [SHA](#abbr_SHA)-256, SHAKE256\] - Tree height \[10, 16, 20\] (XMSS only) - Tree height \[10, 16, 20\] (XMSS only) ::: {style="text-align: center;"} ::: {style="text-align: center;"} [Table [5]{.counter}: Number of Test Cases for [Table [5]{.counter}: Number of Test Cases for XMSS^MT^]{#xmss-akg-test-cases .ctr myid="xmss-akg-test-cases" XMSS^MT^]{#xmss-akg-test-cases .ctr myid="xmss-akg-test-cases" counter-type="ct-Table"} counter-type="ct-Table"} ::: ::: -------- ---------------------- -------- ---------------------- Height Number of test cases Height Number of test cases 10 5 10 5 16 4 16 4 20 3 20 3 40 2 40 2 60 1 60 1 -------- ---------------------- -------- ---------------------- \ \ ***XMSS Key Generation Test***\ ***XMSS Key Generation Test***\ For each supported combination of hash algorithm and tree height, the For each supported combination of hash algorithm and tree height, the evaluator shall generate one public key for each test case. The number evaluator shall generate one public key for each test case. The number of test cases depends on the tree height as specified in [Table of test cases depends on the tree height as specified in [Table [5]{.counter}](#xmss-akg-test-cases){.xmss-akg-test-cases-ref [5]{.counter}](#xmss-akg-test-cases){.xmss-akg-test-cases-ref onclick="showTarget('xmss-akg-test-cases')"}. | onclick="showTarget('xmss-akg-test-cases')"}. The evaluator shall verify | the correctness of the [TSF](#abbr_TSF)'s implementation by comparing The evaluator shall verify the correctness of the [TSF](#abbr_TSF)'s | values generated by the [TSF](#abbr_TSF) with those generated by a known implementation by comparing values generated by the [TSF](#abbr_TSF) | good implementation using the same input parameters. Note: The number of with those generated by a known good implementation using the same input | test cases is limited due to the extreme amount of time it can take to parameters. | generate XMSS trees. < Note: The number of test cases is limited due to the extreme amount of < time it can take to generate XMSS trees. < ::: ::: ::: ::: ::: ::: ::: ::: ::: ::: ::: {#FCS_CKM.1/SKG .comp} ::: {#FCS_CKM.1/SKG .comp} #### FCS_CKM.1/SKG Cryptographic Key Generation - Symmetric Key #### FCS_CKM.1/SKG Cryptographic Key Generation - Symmetric Key ::: element ::: element ::: {#FCS_CKM.1.1/SKG .reqid} ::: {#FCS_CKM.1.1/SKG .reqid} [FCS_CKM.1.1/SKG](#FCS_CKM.1.1/SKG){.abbr} [FCS_CKM.1.1/SKG](#FCS_CKM.1.1/SKG){.abbr} ::: ::: ::: reqdesc ::: reqdesc The [TSF](#abbr_TSF) shall generate **symmetric** cryptographic keys in The [TSF](#abbr_TSF) shall generate **symmetric** cryptographic keys in accordance with a specified cryptographic key generation algorithm accordance with a specified cryptographic key generation algorithm \[**selection**: [Cryptographic Key Generation \[**selection**: [Cryptographic Key Generation Algorithm]{.selectable-content}\] and specified cryptographic key sizes Algorithm]{.selectable-content}\] and specified cryptographic key sizes \[**selection**: [Cryptographic Key Sizes]{.selectable-content}\] that \[**selection**: [Cryptographic Key Sizes]{.selectable-content}\] that meet the following: \[**selection**: [List of meet the following: \[**selection**: [List of standards]{.selectable-content}\] . standards]{.selectable-content}\] . [Table [6]{.counter}](#fcs-ckm-1-skg-sels){.fcs-ckm-1-skg-sels-ref [Table [6]{.counter}](#fcs-ckm-1-skg-sels){.fcs-ckm-1-skg-sels-ref onclick="showTarget('fcs-ckm-1-skg-sels')"} provides the allowable onclick="showTarget('fcs-ckm-1-skg-sels')"} provides the allowable choices for completion of the selection operations of choices for completion of the selection operations of [FCS_CKM.1/SKG](#FCS_CKM.1/SKG). [FCS_CKM.1/SKG](#FCS_CKM.1/SKG). Identifier Cryptographic Key Generation Algorithm Identifier Cryptographic Key Generation Algorithm ------------ ---------------------------------------------------------------------- ------------ ---------------------------------------------------------------------- RSK Direct Generation from a Random Bit Generator as specified in [FCS_RBG RSK Direct Generation from a Random Bit Generator as specified in [FCS_RBG : [Table [6]{.counter}]{#fcs-ckm-1-skg-sels .ctr : [Table [6]{.counter}]{#fcs-ckm-1-skg-sels .ctr myid="fcs-ckm-1-skg-sels" counter-type="ct-Table"}: Allowable Choices myid="fcs-ckm-1-skg-sels" counter-type="ct-Table"}: Allowable Choices for [FCS_CKM.1/SKG](#FCS_CKM.1/SKG) for [FCS_CKM.1/SKG](#FCS_CKM.1/SKG) ::: ::: ::: ::: ::: {.activity_pane .hide} ::: {.activity_pane .hide} ::: activity_pane_header ::: activity_pane_header [[ Evaluation Activities [[ Evaluation Activities ]{.activity_pane_label}[]{.toggler}](#){onclick="toggle(this);return false;"} ]{.activity_pane_label}[]{.toggler}](#){onclick="toggle(this);return false;"} ::: ::: ::: activity_pane_body ::: activity_pane_body ::: component-activity-header ::: component-activity-header [FCS_CKM.1/SKG](#FCS_CKM.1/SKG) [FCS_CKM.1/SKG](#FCS_CKM.1/SKG) ::: ::: ::: eacategory ::: eacategory [TSS](#abbr_TSS) [TSS](#abbr_TSS) ::: ::: ::: ea ::: ea ::: ea ::: ea The evaluator shall examine the [TSS](#abbr_TSS) to verify that it The evaluator shall examine the [TSS](#abbr_TSS) to verify that it describes how the [TOE](#abbr_TOE) obtains a symmetric cryptographic key describes how the [TOE](#abbr_TOE) obtains a symmetric cryptographic key through direct generation from a random bit generator as specified in through direct generation from a random bit generator as specified in [FCS_RBG.1](#FCS_RBG.1). The evaluator shall review the [TSS](#abbr_TSS) [FCS_RBG.1](#FCS_RBG.1). The evaluator shall review the [TSS](#abbr_TSS) to verify that it describes how the functionality described by to verify that it describes how the functionality described by [FCS_RBG.1](#FCS_RBG.1) is invoked. [FCS_RBG.1](#FCS_RBG.1) is invoked. The evaluator shall examine the [TSS](#abbr_TSS) to verify that it The evaluator shall examine the [TSS](#abbr_TSS) to verify that it identifies the usage, and key lifecycle for keys generated using each identifies the usage, and key lifecycle for keys generated using each selected algorithm. selected algorithm. If the [TOE](#abbr_TOE) uses the generated key in a key chain/hierarchy If the [TOE](#abbr_TOE) uses the generated key in a key chain/hierarchy then the evaluator shall verify that the [TSS](#abbr_TSS) describes how then the evaluator shall verify that the [TSS](#abbr_TSS) describes how the key is used as part of the key chain/hierarchy. the key is used as part of the key chain/hierarchy. ::: ::: ::: ::: ::: eacategory ::: eacategory Guidance Guidance ::: ::: ::: ea ::: ea ::: ea ::: ea The evaluator shall verify that the AGD instructs the administrator how The evaluator shall verify that the AGD instructs the administrator how to configure the [TOE](#abbr_TOE) to use the DRBG to generate symmetric to configure the [TOE](#abbr_TOE) to use the DRBG to generate symmetric keys for all uses identified in the [ST](#abbr_ST). keys for all uses identified in the [ST](#abbr_ST). ::: ::: ::: ::: ::: eacategory ::: eacategory Tests Tests ::: ::: ::: ea ::: ea ::: ea ::: ea The following tests are conditional based upon the selections made in The following tests are conditional based upon the selections made in the [SFR](#abbr_SFR). The evaluator shall perform the following test or the [SFR](#abbr_SFR). The evaluator shall perform the following test or witness respective tests executed by the developer. The tests must be witness respective tests executed by the developer. The tests must be executed on a platform that is as close as practically possible to the executed on a platform that is as close as practically possible to the operational platform (but which may be instrumented in terms of, for operational platform (but which may be instrumented in terms of, for example, use of a debug mode). Where the test is not carried out on the example, use of a debug mode). Where the test is not carried out on the [TOE](#abbr_TOE) itself, the test platform shall be identified and the [TOE](#abbr_TOE) itself, the test platform shall be identified and the differences between test environment and [TOE](#abbr_TOE) execution differences between test environment and [TOE](#abbr_TOE) execution environment shall be described. | environment shall be described. To test the [TOE](#abbr_TOE)'s ability | to generate symmetric cryptographic keys using a random bit generator, To test the [TOE](#abbr_TOE)'s ability to generate symmetric | the evaluator shall configure the symmetric cryptographic key generation cryptographic keys using a random bit generator, the evaluator shall | capability for each claimed key size. The evaluator shall use the configure the symmetric cryptographic key generation capability for each | description of the DRBG interface to verify that the [TOE](#abbr_TOE) claimed key size. The evaluator shall use the description of the DRBG | requests and receives an amount of DRBG output greater than or equal to interface to verify that the [TOE](#abbr_TOE) requests and receives an | the requested key size. amount of DRBG output greater than or equal to the requested key size. < ::: ::: ::: ::: ::: ::: ::: ::: ::: ::: ::: {#FCS_CKM.2 .comp} ::: {#FCS_CKM.2 .comp} #### FCS_CKM.2 Cryptographic Key Distribution #### FCS_CKM.2 Cryptographic Key Distribution ::: element ::: element ::: {#FCS_CKM.2.1 .reqid} ::: {#FCS_CKM.2.1 .reqid} [FCS_CKM.2.1](#FCS_CKM.2.1){.abbr} [FCS_CKM.2.1](#FCS_CKM.2.1){.abbr} ::: ::: ::: reqdesc ::: reqdesc The [TSF](#abbr_TSF) shall distribute cryptographic keys in accordance The [TSF](#abbr_TSF) shall distribute cryptographic keys in accordance with the specified cryptographic key distribution method **key wrapping with the specified cryptographic key distribution method **key wrapping as specified in [FCS_COP.1/KeyWrap](#FCS_COP.1/KeyWrap)** and as specified in [FCS_COP.1/KeyWrap](#FCS_COP.1/KeyWrap)** and \[**selection**: [key encapsulation as specified in \[**selection**: [key encapsulation as specified in [FCS_COP.1/KeyEncap](#FCS_COP.1/KeyEncap)]{#sel-ckm-2-encap [FCS_COP.1/KeyEncap](#FCS_COP.1/KeyEncap)]{#sel-ckm-2-encap .selectable-content}, [**no other methods**]{#sel-ckm-2-no-other .selectable-content}, [**no other methods**]{#sel-ckm-2-no-other .selectable-content}\] that meets the following: \[*none*\]. .selectable-content}\] that meets the following: \[*none*\]. ::: appnote ::: appnote [Application Note: ]{.note-header}[ ]{.note} [Application Note: ]{.note-header}[ ]{.note} Key encapsulation is used in support of [TLS](#abbr_TLS) when ML-KEM is Key encapsulation is used in support of [TLS](#abbr_TLS) when ML-KEM is used as the method of key establishment. Key wrapping is used in support used as the method of key establishment. Key wrapping is used in support of wireless LAN communications so it is always required. If \"key of wireless LAN communications so it is always required. If \"key encapsulation\...\" is selected, encapsulation\...\" is selected, [FCS_COP.1/KeyEncap](#FCS_COP.1/KeyEncap) is claimed. [FCS_COP.1/KeyEncap](#FCS_COP.1/KeyEncap) is claimed. ::: ::: ::: ::: ::: ::: ::: {.activity_pane .hide} ::: {.activity_pane .hide} ::: activity_pane_header ::: activity_pane_header [[ Evaluation Activities [[ Evaluation Activities ]{.activity_pane_label}[]{.toggler}](#){onclick="toggle(this);return false;"} ]{.activity_pane_label}[]{.toggler}](#){onclick="toggle(this);return false;"} ::: ::: ::: activity_pane_body ::: activity_pane_body ::: component-activity-header ::: component-activity-header [FCS_CKM.2](#FCS_CKM.2) [FCS_CKM.2](#FCS_CKM.2) ::: ::: ::: eacategory ::: eacategory [TSS](#abbr_TSS) [TSS](#abbr_TSS) ::: ::: ::: ea ::: ea ::: ea ::: ea The evaluator shall ensure that the [TSS](#abbr_TSS) documents that the The evaluator shall ensure that the [TSS](#abbr_TSS) documents that the security strength supported by the selected key distribution methods is security strength supported by the selected key distribution methods is sufficient for the security strength of the keys distributed through sufficient for the security strength of the keys distributed through those methods. those methods. It is not necessary to identify the services that use each key It is not necessary to identify the services that use each key distribution method here. That information should be documented in the distribution method here. That information should be documented in the requirements for the individual services and protocols that invoke key requirements for the individual services and protocols that invoke key distribution. distribution. ::: ::: ::: ::: ::: eacategory ::: eacategory Guidance Guidance ::: ::: ::: ea ::: ea ::: ea ::: ea The evaluator shall verify that the AGD guidance instructs the The evaluator shall verify that the AGD guidance instructs the administrator how to configure the [TOE](#abbr_TOE) to use the selected administrator how to configure the [TOE](#abbr_TOE) to use the selected key distribution methods. key distribution methods. ::: ::: ::: ::: ::: eacategory ::: eacategory Tests Tests ::: ::: ::: ea ::: ea ::: ea ::: ea Specific testing for this component is covered by testing for the Specific testing for this component is covered by testing for the claimed components in [FCS_COP.1/KeyEncap](#FCS_COP.1/KeyEncap) or claimed components in [FCS_COP.1/KeyEncap](#FCS_COP.1/KeyEncap) or [FCS_COP.1/KeyWrap](#FCS_COP.1/KeyWrap), depending on selections made. [FCS_COP.1/KeyWrap](#FCS_COP.1/KeyWrap), depending on selections made. ::: ::: ::: ::: ::: ::: ::: ::: ::: ::: ::: {#FCS_CKM.6 .comp} ::: {#FCS_CKM.6 .comp} #### FCS_CKM.6 Timing and Event of Cryptographic Key Destruction #### FCS_CKM.6 Timing and Event of Cryptographic Key Destruction ::: element ::: element ::: {#FCS_CKM.6.1 .reqid} ::: {#FCS_CKM.6.1 .reqid} [FCS_CKM.6.1](#FCS_CKM.6.1){.abbr} [FCS_CKM.6.1](#FCS_CKM.6.1){.abbr} ::: ::: ::: reqdesc ::: reqdesc The [TSF](#abbr_TSF) shall destroy \[*all plaintext keys and keying The [TSF](#abbr_TSF) shall destroy \[*all plaintext keys and keying material*\] when \[**selection**: [no longer needed]{#_s_84 | material*\] when \[**selection**: [no longer needed]{#fcs_ckm.6.1_1 .selectable-content}, [\[**assignment**: [other circumstances for .selectable-content}, [\[**assignment**: [other circumstances for destruction]{.assignable-content}\]]{#_s_85 .selectable-content}\]. | destruction]{.assignable-content}\]]{#fcs_ckm.6.1_2 > .selectable-content}\]. ::: ::: ::: ::: ::: element ::: element ::: {#FCS_CKM.6.2 .reqid} ::: {#FCS_CKM.6.2 .reqid} [FCS_CKM.6.2](#FCS_CKM.6.2){.abbr} [FCS_CKM.6.2](#FCS_CKM.6.2){.abbr} ::: ::: ::: reqdesc ::: reqdesc The [TSF](#abbr_TSF) shall destroy **plaintext** cryptographic keys and The [TSF](#abbr_TSF) shall destroy **plaintext** cryptographic keys and keying material specified by [FCS_CKM.6.1](#FCS_CKM.6.1) in accordance keying material specified by [FCS_CKM.6.1](#FCS_CKM.6.1) in accordance with a specified cryptographic key destruction method \[*in accordance with a specified cryptographic key destruction method \[*in accordance with the following rules:* with the following rules:* - For volatile memory, the destruction shall be executed by a single - For volatile memory, the destruction shall be executed by a single direct overwrite consisting of \[**selection**: [a pseudo-random direct overwrite consisting of \[**selection**: [a pseudo-random pattern using the [TSF](#abbr_TSF) or platform DRBG (as specified in pattern using the [TSF](#abbr_TSF) or platform DRBG (as specified in [FCS_RBG.1](#FCS_RBG.1))]{#_s_86 .selectable-content}, | [FCS_RBG.1](#FCS_RBG.1))]{#fcs_ckm.6.2_1 .selectable-content}, [zeroes]{#_s_87 .selectable-content}\] | [zeroes]{#fcs_ckm.6.2_2 .selectable-content}\] - For non-volatile [EEPROM](#abbr_EEPROM), the destruction shall be - For non-volatile [EEPROM](#abbr_EEPROM), the destruction shall be executed by a single direct overwrite consisting of a pseudo-random executed by a single direct overwrite consisting of a pseudo-random pattern using the [TSF](#abbr_TSF) or platform DRBG (as specified in pattern using the [TSF](#abbr_TSF) or platform DRBG (as specified in [FCS_RBG.1](#FCS_RBG.1)), followed by a read-verify. [FCS_RBG.1](#FCS_RBG.1)), followed by a read-verify. - For non-volatile flash memory, that is not wear-leveled, the - For non-volatile flash memory, that is not wear-leveled, the destruction shall be executed by a \[**selection**: [single direct destruction shall be executed by a \[**selection**: [single direct overwrite consisting of zeroes followed by a read-verify]{#_s_88 | overwrite consisting of zeroes followed by a .selectable-content}, [block erase that erases the reference to | read-verify]{#fcs_ckm.6.2_3 .selectable-content}, [block erase that memory that stores data as well as the data itself]{#_s_89 | erases the reference to memory that stores data as well as the data .selectable-content}\] | itself]{#fcs_ckm.6.2_4 .selectable-content}\] - For non-volatile flash memory that is wear-leveled, the destruction - For non-volatile flash memory that is wear-leveled, the destruction shall be executed by a \[**selection**: [single direct overwrite shall be executed by a \[**selection**: [single direct overwrite consisting of zeroes]{#_s_90 .selectable-content}, [block | consisting of zeroes]{#fcs_ckm.6.2_5 .selectable-content}, [block erase]{#_s_91 .selectable-content}\] | erase]{#fcs_ckm.6.2_6 .selectable-content}\] - For non-volatile memory other than [EEPROM](#abbr_EEPROM) and flash, - For non-volatile memory other than [EEPROM](#abbr_EEPROM) and flash, the destruction shall be executed by a single direct overwrite with the destruction shall be executed by a single direct overwrite with a random pattern that is changed before each write a random pattern that is changed before each write \] that meets the following: \[*no standard*\]. \] that meets the following: \[*no standard*\]. ::: appnote ::: appnote [Application Note: ]{.note-header}[ ]{.note} [Application Note: ]{.note-header}[ ]{.note} For the purposes of this requirement, keying material refers to For the purposes of this requirement, keying material refers to authentication data, passwords, secret/private symmetric keys, private authentication data, passwords, secret/private symmetric keys, private asymmetric keys, data used to derive keys, values derived from asymmetric keys, data used to derive keys, values derived from passwords, etc. "Plaintext keying material" may refer to a passwords, etc. "Plaintext keying material" may refer to a [KEK](#abbr_KEK) that is used to encrypt other keying material. [KEK](#abbr_KEK) that is used to encrypt other keying material. Destruction of encrypted keying material may be accomplished by Destruction of encrypted keying material may be accomplished by destroying the [KEK](#abbr_KEK) used to encrypt it. If different destroying the [KEK](#abbr_KEK) used to encrypt it. If different mechanisms are used for destroying different keying material, all mechanisms are used for destroying different keying material, all relevant claims should be selected and the [TSS](#abbr_TSS) should relevant claims should be selected and the [TSS](#abbr_TSS) should identify which keying material is destroyed by which mechanism. identify which keying material is destroyed by which mechanism. There are multiple situations in which plaintext keying material is no There are multiple situations in which plaintext keying material is no longer needed, including when the [TOE](#abbr_TOE) is powered off, when longer needed, including when the [TOE](#abbr_TOE) is powered off, when the wipe when trusted channels are disconnected, when keying material is the wipe when trusted channels are disconnected, when keying material is no longer needed by the trusted channel per the protocol, and when no longer needed by the trusted channel per the protocol, and when transitioning to the locked state (for those values derived from the transitioning to the locked state (for those values derived from the Password Authentication Factor or that key material which is protected Password Authentication Factor or that key material which is protected by the password-derived or biometric-unlocked [KEK](#abbr_KEK) according by the password-derived or biometric-unlocked [KEK](#abbr_KEK) according to [FCS_STG_EXT.2](#FCS_STG_EXT.2) -- see Figure 3). For keys (or key to [FCS_STG_EXT.2](#FCS_STG_EXT.2) -- see Figure 3). For keys (or key material used to derive those keys) protecting sensitive data received material used to derive those keys) protecting sensitive data received in the locked state, \"no longer needed\" includes \"while in the locked in the locked state, \"no longer needed\" includes \"while in the locked state.\" The assignment for \"other circumstances for destruction\" is state.\" The assignment for \"other circumstances for destruction\" is completed for any user or Administrator directed key destruction such as completed for any user or Administrator directed key destruction such as initiating the wipe function or other manual destruction. initiating the wipe function or other manual destruction. Key storage areas in non-volatile storage can be overwritten with any Key storage areas in non-volatile storage can be overwritten with any value that renders the keys unrecoverable. The value used can be all value that renders the keys unrecoverable. The value used can be all zeroes, all ones, or any other pattern or combination of values zeroes, all ones, or any other pattern or combination of values significantly different than the value of the key itself. When 'a value significantly different than the value of the key itself. When 'a value that does not contain any keying material' is chosen, it means that the that does not contain any keying material' is chosen, it means that the [TOE](#abbr_TOE) uses some other specified data not drawn from a source [TOE](#abbr_TOE) uses some other specified data not drawn from a source that may contain keying material or reveal information about it or any that may contain keying material or reveal information about it or any other [TSF](#abbr_TSF)-protected data. In other words, the data used for other [TSF](#abbr_TSF)-protected data. In other words, the data used for overwriting is carefully selected and not taken from a general 'pool' overwriting is carefully selected and not taken from a general 'pool' that might contain current or residual data that itself requires that might contain current or residual data that itself requires confidentiality protection. If multiple copies exist, all copies must be confidentiality protection. If multiple copies exist, all copies must be destroyed. destroyed. ::: ::: ::: ::: ::: ::: ::: {.activity_pane .hide} ::: {.activity_pane .hide} ::: activity_pane_header ::: activity_pane_header [[ Evaluation Activities [[ Evaluation Activities ]{.activity_pane_label}[]{.toggler}](#){onclick="toggle(this);return false;"} ]{.activity_pane_label}[]{.toggler}](#){onclick="toggle(this);return false;"} ::: ::: ::: activity_pane_body ::: activity_pane_body ::: component-activity-header ::: component-activity-header [FCS_CKM.6](#FCS_CKM.6) [FCS_CKM.6](#FCS_CKM.6) ::: ::: ::: eacategory ::: eacategory [TSS](#abbr_TSS) [TSS](#abbr_TSS) ::: ::: ::: ea ::: ea ::: ea ::: ea The evaluator shall verify that the [TSS](#abbr_TSS) identifies all The evaluator shall verify that the [TSS](#abbr_TSS) identifies all plaintext keys and keying material stored by the [TOE](#abbr_TOE), the plaintext keys and keying material stored by the [TOE](#abbr_TOE), the type of memory in which it is stored, and when and how the keying type of memory in which it is stored, and when and how the keying material is erased. If the [TOE](#abbr_TOE) uses one or more KEKs to material is erased. If the [TOE](#abbr_TOE) uses one or more KEKs to protect stored keying material, the evaluator shall verify that the protect stored keying material, the evaluator shall verify that the [TSS](#abbr_TSS) describes the destruction of that keying material, [TSS](#abbr_TSS) describes the destruction of that keying material, either directly or by destruction of the [KEK](#abbr_KEK) used to either directly or by destruction of the [KEK](#abbr_KEK) used to encrypt it. encrypt it. If different types of memory are used to store the materials to be If different types of memory are used to store the materials to be protected, the evaluator shall check to ensure that the [TSS](#abbr_TSS) protected, the evaluator shall check to ensure that the [TSS](#abbr_TSS) describes the clearing procedure in terms of the memory in which the describes the clearing procedure in terms of the memory in which the data are stored (for example, \"secret keys stored on flash are cleared data are stored (for example, \"secret keys stored on flash are cleared by overwriting once with zeros, while secret keys stored on the internal by overwriting once with zeros, while secret keys stored on the internal persistent storage device are cleared by overwriting one time with a persistent storage device are cleared by overwriting one time with a random pattern that is changed before each write\"). For block erases, random pattern that is changed before each write\"). For block erases, the evaluator shall also ensure that the [TSS](#abbr_TSS) identifies the the evaluator shall also ensure that the [TSS](#abbr_TSS) identifies the block erase command that is used and shall verify that the command used block erase command that is used and shall verify that the command used also addresses any copies of the plaintext key material that may be also addresses any copies of the plaintext key material that may be created, e.g. in order to optimize the use of Flash memory. created, e.g. in order to optimize the use of Flash memory. ::: ::: ::: ::: ::: eacategory ::: eacategory Guidance Guidance ::: ::: ::: ea ::: ea There are no additional Guidance evaluation activities for this There are no additional Guidance evaluation activities for this component.\ component.\ ::: ::: ::: eacategory ::: eacategory Tests Tests ::: ::: ::: ea ::: ea ::: ea ::: ea **Evaluation Activity Note:** The following tests likely require the **Evaluation Activity Note:** The following tests likely require the [TOE](#abbr_TOE) developer to provide access to a test platform that [TOE](#abbr_TOE) developer to provide access to a test platform that provides the evaluator with tools that are typically not found on the provides the evaluator with tools that are typically not found on the end consumer version of the [TOE](#abbr_TOE). | end consumer version of the [TOE](#abbr_TOE). The evaluator shall | perform the following tests for all keys and key material subject to The evaluator shall perform the following tests for all keys and key | destruction by the [TOE](#abbr_TOE). For these tests, the evaluator material subject to destruction by the [TOE](#abbr_TOE). For these | shall utilize an appropriate development environment (e.g., a virtual tests, the evaluator shall utilize an appropriate development | machine) and development tools (debuggers, simulators, etc.) to test environment (e.g., a virtual machine) and development tools (debuggers, | that keys are cleared, including all copies of the key that may have simulators, etc.) to test that keys are cleared, including all copies of | been created internally by the [TOE](#abbr_TOE) during normal the key that may have been created internally by the [TOE](#abbr_TOE) | cryptographic processing with that key. []{.testlist-} during normal cryptographic processing with that key. < < []{.testlist-} < - [Test FCS_CKM.6:1](#_t_5){#_t_5 .defined}: Applied to each key held - [Test FCS_CKM.6:1](#_t_5){#_t_5 .defined}: Applied to each key held as plaintext in volatile memory and subject to destruction by as plaintext in volatile memory and subject to destruction by overwrite by the [TOE](#abbr_TOE) (whether or not the plaintext overwrite by the [TOE](#abbr_TOE) (whether or not the plaintext value is subsequently encrypted for storage in volatile or value is subsequently encrypted for storage in volatile or non-volatile memory). In the case where the only selection made for non-volatile memory). In the case where the only selection made for the destruction method key was removal of power, then this test is the destruction method key was removal of power, then this test is unnecessary. The evaluator shall:\ unnecessary. The evaluator shall:\ 1. Record the value of the key in the [TOE](#abbr_TOE) subject to 1. Record the value of the key in the [TOE](#abbr_TOE) subject to clearing. clearing. 2. Cause the [TOE](#abbr_TOE) to perform a normal cryptographic 2. Cause the [TOE](#abbr_TOE) to perform a normal cryptographic processing with the key from Step #1. processing with the key from Step #1. 3. Cause the [TOE](#abbr_TOE) to clear the key. 3. Cause the [TOE](#abbr_TOE) to clear the key. 4. Cause the [TOE](#abbr_TOE) to stop the execution but not exit. 4. Cause the [TOE](#abbr_TOE) to stop the execution but not exit. 5. Cause the [TOE](#abbr_TOE) to dump the entire memory of the 5. Cause the [TOE](#abbr_TOE) to dump the entire memory of the [TOE](#abbr_TOE) into a binary file. [TOE](#abbr_TOE) into a binary file. 6. Search the content of the binary file created in Step #5 for 6. Search the content of the binary file created in Step #5 for instances of the known key value from Step #1. instances of the known key value from Step #1. 7. Break the key value from Step #1 into 3 similar sized pieces and 7. Break the key value from Step #1 into 3 similar sized pieces and perform a search using each piece. perform a search using each piece. \ \ Steps 1-6 ensure that the complete key does not exist anywhere in Steps 1-6 ensure that the complete key does not exist anywhere in volatile memory. If a copy is found, then the test fails.\ volatile memory. If a copy is found, then the test fails.\ \ \ Step 7 ensures that partial key fragments do not remain in memory. Step 7 ensures that partial key fragments do not remain in memory. If a fragment is found, there is a minuscule chance that it is not If a fragment is found, there is a minuscule chance that it is not within the context of a key (e.g., some random bits that happen to within the context of a key (e.g., some random bits that happen to match). If this is the case the test should be repeated with a match). If this is the case the test should be repeated with a different key in Step #1. If a fragment is found the test fails.\ different key in Step #1. If a fragment is found the test fails.\ \ < - [Test FCS_CKM.6:2](#_t_6){#_t_6 .defined}: Applied to each key held - [Test FCS_CKM.6:2](#_t_6){#_t_6 .defined}: Applied to each key held in non-volatile memory and subject to destruction by overwrite by in non-volatile memory and subject to destruction by overwrite by the [TOE](#abbr_TOE). The evaluator shall use special tools (as the [TOE](#abbr_TOE). The evaluator shall use special tools (as needed), provided by the [TOE](#abbr_TOE) developer if necessary, to needed), provided by the [TOE](#abbr_TOE) developer if necessary, to view the key storage location:\ view the key storage location:\ 1. Record the value of the key in the [TOE](#abbr_TOE) subject to 1. Record the value of the key in the [TOE](#abbr_TOE) subject to clearing. clearing. 2. Cause the [TOE](#abbr_TOE) to perform a normal cryptographic 2. Cause the [TOE](#abbr_TOE) to perform a normal cryptographic processing with the key from Step #1. processing with the key from Step #1. 3. Cause the [TOE](#abbr_TOE) to clear the key. 3. Cause the [TOE](#abbr_TOE) to clear the key. 4. Search the non-volatile memory the key was stored in for 4. Search the non-volatile memory the key was stored in for instances of the known key value from Step #1. If a copy is instances of the known key value from Step #1. If a copy is found, then the test fails. found, then the test fails. 5. Break the key value from Step #1 into 3 similar sized pieces and 5. Break the key value from Step #1 into 3 similar sized pieces and perform a search using each piece. If a fragment is found then perform a search using each piece. If a fragment is found then the test is repeated (as described for test 1 above), and if a the test is repeated (as described for test 1 above), and if a fragment is found in the repeated test then the test fails. fragment is found in the repeated test then the test fails. \ \ \ < - [Test FCS_CKM.6:3](#_t_7){#_t_7 .defined}: Applied to each key held - [Test FCS_CKM.6:3](#_t_7){#_t_7 .defined}: Applied to each key held as non-volatile memory and subject to destruction by overwrite by as non-volatile memory and subject to destruction by overwrite by the [TOE](#abbr_TOE). The evaluator shall use special tools (as the [TOE](#abbr_TOE). The evaluator shall use special tools (as needed), provided by the [TOE](#abbr_TOE) developer if necessary, to needed), provided by the [TOE](#abbr_TOE) developer if necessary, to view the key storage location:\ view the key storage location:\ 1. Record the storage location of the key in the [TOE](#abbr_TOE) 1. Record the storage location of the key in the [TOE](#abbr_TOE) subject to clearing. subject to clearing. 2. Cause the [TOE](#abbr_TOE) to perform a normal cryptographic 2. Cause the [TOE](#abbr_TOE) to perform a normal cryptographic processing with the key from Step #1. processing with the key from Step #1. 3. Cause the [TOE](#abbr_TOE) to clear the key. 3. Cause the [TOE](#abbr_TOE) to clear the key. 4. Read the storage location in Step #1 of non-volatile memory to 4. Read the storage location in Step #1 of non-volatile memory to ensure the appropriate pattern is utilized. ensure the appropriate pattern is utilized. \ \ The test succeeds if correct pattern is used to overwrite the key in The test succeeds if correct pattern is used to overwrite the key in the memory location. If the pattern is not found the test fails. the memory location. If the pattern is not found the test fails. ::: ::: ::: ::: ::: ::: ::: ::: ::: ::: ::: {#FCS_CKM_EXT.1 .comp} ::: {#FCS_CKM_EXT.1 .comp} #### FCS_CKM_EXT.1 Cryptographic Key Support #### FCS_CKM_EXT.1 Cryptographic Key Support ::: element ::: element ::: {#FCS_CKM_EXT.1.1 .reqid} ::: {#FCS_CKM_EXT.1.1 .reqid} [FCS_CKM_EXT.1.1](#FCS_CKM_EXT.1.1){.abbr} [FCS_CKM_EXT.1.1](#FCS_CKM_EXT.1.1){.abbr} ::: ::: ::: reqdesc ::: reqdesc The [TSF](#abbr_TSF) shall support \[**selection**: [immutable The [TSF](#abbr_TSF) shall support \[**selection**: [immutable hardware]{#s-immutable-hardware .selectable-content}, [mutable hardware]{#s-immutable-hardware .selectable-content}, [mutable hardware]{#s-mutable-hardware .selectable-content}\] [REKs](#abbr_REK) | hardware]{#s-mutable-hardware .selectable-content}\] REKs with a with a \[**selection**: [symmetric]{#s-rek-sym .selectable-content}, | \[**selection**: [symmetric]{#s-rek-sym .selectable-content}, [asymmetric]{#s-rek-asym .selectable-content}\] key of strength [asymmetric]{#s-rek-asym .selectable-content}\] key of strength \[**selection**: [192 bits]{#s-rek-192 .selectable-content}, [256 \[**selection**: [192 bits]{#s-rek-192 .selectable-content}, [256 bits]{#s-rek-256 .selectable-content}\]. bits]{#s-rek-256 .selectable-content}\]. ::: ::: ::: ::: ::: element ::: element ::: {#FCS_CKM_EXT.1.2 .reqid} ::: {#FCS_CKM_EXT.1.2 .reqid} [FCS_CKM_EXT.1.2](#FCS_CKM_EXT.1.2){.abbr} [FCS_CKM_EXT.1.2](#FCS_CKM_EXT.1.2){.abbr} ::: ::: ::: reqdesc ::: reqdesc Each [REK](#abbr_REK) shall be hardware-isolated from the [OS](#abbr_OS) Each [REK](#abbr_REK) shall be hardware-isolated from the [OS](#abbr_OS) on the [TSF](#abbr_TSF) in runtime. on the [TSF](#abbr_TSF) in runtime. ::: ::: ::: ::: ::: element ::: element ::: {#FCS_CKM_EXT.1.3 .reqid} ::: {#FCS_CKM_EXT.1.3 .reqid} [FCS_CKM_EXT.1.3](#FCS_CKM_EXT.1.3){.abbr} [FCS_CKM_EXT.1.3](#FCS_CKM_EXT.1.3){.abbr} ::: ::: ::: reqdesc ::: reqdesc Each [REK](#abbr_REK) shall be generated by a DRBG in accordance with Each [REK](#abbr_REK) shall be generated by a DRBG in accordance with [FCS_RBG.1](#FCS_RBG.1). [FCS_RBG.1](#FCS_RBG.1). ::: appnote ::: appnote [Application Note: ]{.note-header}[ Either asymmetric or symmetric keys [Application Note: ]{.note-header}[ Either asymmetric or symmetric keys are allowed; the [ST](#abbr_ST) author makes the selection appropriate are allowed; the [ST](#abbr_ST) author makes the selection appropriate for the device. Symmetric keys must be of size 256 bits in order to for the device. Symmetric keys must be of size 256 bits in order to correspond with [FCS_COP.1/SKC](#FCS_COP.1/SKC). Asymmetric keys may be correspond with [FCS_COP.1/SKC](#FCS_COP.1/SKC). Asymmetric keys may be of any strength corresponding to [FCS_CKM.1/AKG](#FCS_CKM.1/AKG).\ of any strength corresponding to [FCS_CKM.1/AKG](#FCS_CKM.1/AKG).\ \ \ The raw key material of \"immutable hardware\" [REKs](#abbr_REK) is | The raw key material of \"immutable hardware\" REKs is computationally computationally processed by hardware and software cannot access the raw | processed by hardware and software cannot access the raw key material. key material. If [mutable hardware](#s-mutable-hardware) is selected in | If [mutable hardware](#s-mutable-hardware) is selected in [FCS_CKM_EXT.1.1](#FCS_CKM_EXT.1.1), [FCS_CKM_EXT.9](#FCS_CKM_EXT.9) [FCS_CKM_EXT.1.1](#FCS_CKM_EXT.1.1), [FCS_CKM_EXT.9](#FCS_CKM_EXT.9) must be included in the [ST](#abbr_ST).\ must be included in the [ST](#abbr_ST).\ \ \ The lack of a public/documented [API](#abbr_API) for importing or The lack of a public/documented [API](#abbr_API) for importing or exporting the [REK](#abbr_REK), when a private/undocumented exporting the [REK](#abbr_REK), when a private/undocumented [API](#abbr_API) exists, is not sufficient to meet this requirement.\ [API](#abbr_API) exists, is not sufficient to meet this requirement.\ \ \ The DRBG used to generate a [REK](#abbr_REK) may be a DRBG native to the The DRBG used to generate a [REK](#abbr_REK) may be a DRBG native to the hardware key container or may be an off-device DRBG. If performed by an hardware key container or may be an off-device DRBG. If performed by an off-device DRBG, the device manufacturer must not be able to access a off-device DRBG, the device manufacturer must not be able to access a [REK](#abbr_REK) after the manufacturing process has been completed. The [REK](#abbr_REK) after the manufacturing process has been completed. The Evaluation Activities for these two cases differ. ]{.note} Evaluation Activities for these two cases differ. ]{.note} ::: ::: ::: ::: ::: ::: ::: {.activity_pane .hide} ::: {.activity_pane .hide} ::: activity_pane_header ::: activity_pane_header [[ Evaluation Activities [[ Evaluation Activities ]{.activity_pane_label}[]{.toggler}](#){onclick="toggle(this);return false;"} ]{.activity_pane_label}[]{.toggler}](#){onclick="toggle(this);return false;"} ::: ::: ::: activity_pane_body ::: activity_pane_body ::: component-activity-header ::: component-activity-header [FCS_CKM_EXT.1](#FCS_CKM_EXT.1) [FCS_CKM_EXT.1](#FCS_CKM_EXT.1) ::: ::: ::: eacategory ::: eacategory [TSS](#abbr_TSS) [TSS](#abbr_TSS) ::: ::: ::: ea ::: ea ::: ea ::: ea The evaluator shall review the [TSS](#abbr_TSS) to determine that a The evaluator shall review the [TSS](#abbr_TSS) to determine that a [REK](#abbr_REK) is supported by the [TOE](#abbr_TOE), that the [REK](#abbr_REK) is supported by the [TOE](#abbr_TOE), that the [TSS](#abbr_TSS) includes a description of the protection provided by [TSS](#abbr_TSS) includes a description of the protection provided by the [TOE](#abbr_TOE) for a [REK](#abbr_REK), and that the the [TOE](#abbr_TOE) for a [REK](#abbr_REK), and that the [TSS](#abbr_TSS) includes a description of the method of generation of a [TSS](#abbr_TSS) includes a description of the method of generation of a [REK](#abbr_REK).\ [REK](#abbr_REK).\ \ \ The evaluator shall verify that the description of the protection of a The evaluator shall verify that the description of the protection of a [REK](#abbr_REK) describes how any reading, import, and export of that [REK](#abbr_REK) describes how any reading, import, and export of that [REK](#abbr_REK) is prevented. For example, if the hardware protecting [REK](#abbr_REK) is prevented. For example, if the hardware protecting the [REK](#abbr_REK) is removable, the description should include how the [REK](#abbr_REK) is removable, the description should include how other devices are prevented from reading the [REK](#abbr_REK). The other devices are prevented from reading the [REK](#abbr_REK). The evaluator shall verify that the [TSS](#abbr_TSS) describes how evaluator shall verify that the [TSS](#abbr_TSS) describes how encryption/decryption/derivation actions are isolated so as to prevent encryption/decryption/derivation actions are isolated so as to prevent applications and system-level processes from reading the applications and system-level processes from reading the [REK](#abbr_REK) while allowing encryption/decryption/derivation by the [REK](#abbr_REK) while allowing encryption/decryption/derivation by the key.\ key.\ \ \ The evaluator shall verify that the description includes how the The evaluator shall verify that the description includes how the [OS](#abbr_OS) is prevented from accessing the memory containing [OS](#abbr_OS) is prevented from accessing the memory containing [REK](#abbr_REK) key material, which software is allowed access to the [REK](#abbr_REK) key material, which software is allowed access to the [REK](#abbr_REK), how any other software in the execution environment is [REK](#abbr_REK), how any other software in the execution environment is prevented from reading that key material, and what other mechanisms prevented from reading that key material, and what other mechanisms prevent the [REK](#abbr_REK) key material from being written to shared prevent the [REK](#abbr_REK) key material from being written to shared memory locations between the [OS](#abbr_OS) and the separate execution memory locations between the [OS](#abbr_OS) and the separate execution environment.\ environment.\ \ \ If key derivation is performed using a [REK](#abbr_REK), the evaluator If key derivation is performed using a [REK](#abbr_REK), the evaluator shall ensure that the [TSS](#abbr_TSS) description includes a shall ensure that the [TSS](#abbr_TSS) description includes a description of the key derivation function and shall verify the key description of the key derivation function and shall verify the key derivation uses an approved derivation mode and key expansion algorithm derivation uses an approved derivation mode and key expansion algorithm according to [FCS_CKM_EXT.3.2](#FCS_CKM_EXT.3.2).\ according to [FCS_CKM_EXT.3.2](#FCS_CKM_EXT.3.2).\ \ \ The evaluator shall verify that the generation of a [REK](#abbr_REK) The evaluator shall verify that the generation of a [REK](#abbr_REK) meets the [FCS_RBG.1](#FCS_RBG.1) requirement:\ meets the [FCS_RBG.1](#FCS_RBG.1) requirement:\ - If [REKs](#abbr_REK) is/are generated on-device, the | - If REKs is/are generated on-device, the [TSS](#abbr_TSS) shall [TSS](#abbr_TSS) shall include a description of the generation | include a description of the generation mechanism including what mechanism including what triggers a generation, how the | triggers a generation, how the functionality described by functionality described by [FCS_RBG.1](#FCS_RBG.1) is invoked, and | [FCS_RBG.1](#FCS_RBG.1) is invoked, and whether a separate instance whether a separate instance of the DRBG is used for | of the DRBG is used for REKs. [REKs](#abbr_REK). | - If REKs is/are generated off-device, the [TSS](#abbr_TSS) shall - If [REKs](#abbr_REK) is/are generated off-device, the | include evidence that the DRBG meets [FCS_RBG.1](#FCS_RBG.1). This [TSS](#abbr_TSS) shall include evidence that the DRBG meets | will likely necessitate a second set of DRBG documentation [FCS_RBG.1](#FCS_RBG.1). This will likely necessitate a second set | equivalent to the documentation provided for the DRBG Evaluation of DRBG documentation equivalent to the documentation provided for | Activities. In addition, the [TSS](#abbr_TSS) shall describe the the DRBG Evaluation Activities. In addition, the [TSS](#abbr_TSS) | manufacturing process that prevents the device manufacturer from shall describe the manufacturing process that prevents the device | accessing any REKs. manufacturer from accessing any [REKs](#abbr_REK). < \ \ ::: ::: ::: ::: ::: eacategory ::: eacategory Guidance Guidance ::: ::: ::: ea ::: ea ::: ea ::: ea There are no guidance evaluation activities for this component.\ There are no guidance evaluation activities for this component.\ \ \ ::: ::: ::: ::: ::: eacategory ::: eacategory Tests Tests ::: ::: ::: ea ::: ea ::: ea ::: ea There are no test evaluation activities for this component. There are no test evaluation activities for this component. ::: ::: ::: ::: ::: ::: ::: ::: ::: ::: ::: {#FCS_CKM_EXT.2 .comp} ::: {#FCS_CKM_EXT.2 .comp} #### FCS_CKM_EXT.2 Cryptographic Key Random Generation #### FCS_CKM_EXT.2 Cryptographic Key Random Generation ::: element ::: element ::: {#FCS_CKM_EXT.2.1 .reqid} ::: {#FCS_CKM_EXT.2.1 .reqid} [FCS_CKM_EXT.2.1](#FCS_CKM_EXT.2.1){.abbr} [FCS_CKM_EXT.2.1](#FCS_CKM_EXT.2.1){.abbr} ::: ::: ::: reqdesc ::: reqdesc All [DEKs](#abbr_DEK) shall be \[**selection**: | All DEKs shall be \[**selection**: - [randomly generated by a method specified in - [randomly generated by a method specified in [FCS_RBG.1](#FCS_RBG.1),]{#_s_100 .selectable-content} | [FCS_RBG.1](#FCS_RBG.1),]{#fcs_ckm_ext.2.1_1 .selectable-content} - [ from the combination of a randomly generated [DEK](#abbr_DEK) with | - [from the combination of a randomly generated [DEK](#abbr_DEK) with another [DEK](#abbr_DEK) or salt in a way that preserves the another [DEK](#abbr_DEK) or salt in a way that preserves the effective entropy of each factor by \[**selection**: ]{#_s_101 | effective entropy of each factor by \[**selection**: .selectable-content} | ]{#fcs_ckm_ext.2.1_2 .selectable-content} - [using an XOR operation,]{#_s_102 .selectable-content} | - [using an XOR operation,]{#fcs_ckm_ext.2.1_3 > .selectable-content} - [concatenating the keys and using a [KDF](#abbr_KDF) (as - [concatenating the keys and using a [KDF](#abbr_KDF) (as described in SP 800-108),]{#_s_103 .selectable-content} | described in SP 800-108),]{#fcs_ckm_ext.2.1_4 > .selectable-content} - [concatenating the keys and using a [KDF](#abbr_KDF) (as - [concatenating the keys and using a [KDF](#abbr_KDF) (as described in SP 800-56C)]{#s-dek-800-56 .selectable-content} described in SP 800-56C)]{#s-dek-800-56 .selectable-content} \] \] \] with entropy corresponding to the security strength of \] with entropy corresponding to the security strength of [AES](#abbr_AES) key sizes of 256 bits. [AES](#abbr_AES) key sizes of 256 bits. ::: appnote ::: appnote [Application Note: ]{.note-header}[ The intent of this requirement is to [Application Note: ]{.note-header}[ The intent of this requirement is to ensure that the [DEK](#abbr_DEK) cannot be recovered with less work than ensure that the [DEK](#abbr_DEK) cannot be recovered with less work than a full exhaust of the key space for [AES](#abbr_AES). The key generation a full exhaust of the key space for [AES](#abbr_AES). The key generation capability of the [TOE](#abbr_TOE) uses a DRBG implemented on the capability of the [TOE](#abbr_TOE) uses a DRBG implemented on the [TOE](#abbr_TOE) device ([FCS_RBG.1](#FCS_RBG.1)). A [DEK](#abbr_DEK) is [TOE](#abbr_TOE) device ([FCS_RBG.1](#FCS_RBG.1)). A [DEK](#abbr_DEK) is used in addition to the [KEK](#abbr_KEK) so that authentication factors used in addition to the [KEK](#abbr_KEK) so that authentication factors can be changed without having to re-encrypt all of the user data on the can be changed without having to re-encrypt all of the user data on the device.\ device.\ \ \ The [ST](#abbr_ST) author selects all applicable [DEK](#abbr_DEK) The [ST](#abbr_ST) author selects all applicable [DEK](#abbr_DEK) generation types implemented by the [TOE](#abbr_TOE).\ generation types implemented by the [TOE](#abbr_TOE).\ \ \ SP 800-56C specifies a two-step key derivation procedure that employs an SP 800-56C specifies a two-step key derivation procedure that employs an extraction-then-expansion technique for deriving keying material from a extraction-then-expansion technique for deriving keying material from a shared secret generated during a key establishment scheme. The shared secret generated during a key establishment scheme. The Randomness Extraction step as described in Section 5 of SP 800-56C is Randomness Extraction step as described in Section 5 of SP 800-56C is followed by Key Expansion using the key derivation functions defined in followed by Key Expansion using the key derivation functions defined in SP 800-108 (as described in Section 6 of SP 800-56C). ]{.note} SP 800-108 (as described in Section 6 of SP 800-56C). ]{.note} ::: ::: ::: ::: ::: ::: ::: {.activity_pane .hide} ::: {.activity_pane .hide} ::: activity_pane_header ::: activity_pane_header [[ Evaluation Activities [[ Evaluation Activities ]{.activity_pane_label}[]{.toggler}](#){onclick="toggle(this);return false;"} ]{.activity_pane_label}[]{.toggler}](#){onclick="toggle(this);return false;"} ::: ::: ::: activity_pane_body ::: activity_pane_body ::: component-activity-header ::: component-activity-header [FCS_CKM_EXT.2](#FCS_CKM_EXT.2) [FCS_CKM_EXT.2](#FCS_CKM_EXT.2) ::: ::: ::: eacategory ::: eacategory [TSS](#abbr_TSS) [TSS](#abbr_TSS) ::: ::: ::: ea ::: ea ::: ea ::: ea The evaluator shall ensure that the documentation of the product\'s The evaluator shall ensure that the documentation of the product\'s encryption key management is detailed enough that, after reading, the encryption key management is detailed enough that, after reading, the product\'s key management hierarchy is clear and that it meets the product\'s key management hierarchy is clear and that it meets the requirements to ensure the keys are adequately protected. The evaluator requirements to ensure the keys are adequately protected. The evaluator shall ensure that the documentation includes both an essay and one or shall ensure that the documentation includes both an essay and one or more diagrams. Note that this may also be documented as separate more diagrams. Note that this may also be documented as separate proprietary evidence rather than being included in the proprietary evidence rather than being included in the [TSS](#abbr_TSS).\ [TSS](#abbr_TSS).\ \ \ The evaluator shall also examine the key hierarchy section of the The evaluator shall also examine the key hierarchy section of the [TSS](#abbr_TSS) to ensure that the formation of all [DEKs](#abbr_DEK) | [TSS](#abbr_TSS) to ensure that the formation of all DEKs is described is described and that the key sizes match that described by the | and that the key sizes match that described by the [ST](#abbr_ST) [ST](#abbr_ST) author. The evaluator shall examine the key hierarchy | author. The evaluator shall examine the key hierarchy section of the section of the [TSS](#abbr_TSS) to ensure that each [DEK](#abbr_DEK) is | [TSS](#abbr_TSS) to ensure that each [DEK](#abbr_DEK) is generated or generated or combined from keys of equal or greater security strength | combined from keys of equal or greater security strength using one of using one of the selected methods.\ | the selected methods.\ - If the symmetric [DEK](#abbr_DEK) is generated by a DRBG, the - If the symmetric [DEK](#abbr_DEK) is generated by a DRBG, the evaluator shall review the [TSS](#abbr_TSS) to determine that it evaluator shall review the [TSS](#abbr_TSS) to determine that it describes how the functionality described by [FCS_RBG.1](#FCS_RBG.1) describes how the functionality described by [FCS_RBG.1](#FCS_RBG.1) is invoked. The evaluator uses the description of the DRBG is invoked. The evaluator uses the description of the DRBG functionality in [FCS_RBG.1](#FCS_RBG.1) or documentation available functionality in [FCS_RBG.1](#FCS_RBG.1) or documentation available for the operational environment to determine that the key size being for the operational environment to determine that the key size being requested is greater than or equal to the key size and mode to be requested is greater than or equal to the key size and mode to be used for the encryption/decryption of the data. used for the encryption/decryption of the data. - If the [DEK](#abbr_DEK) is formed from a combination, the evaluator - If the [DEK](#abbr_DEK) is formed from a combination, the evaluator shall verify that the [TSS](#abbr_TSS) describes the method of shall verify that the [TSS](#abbr_TSS) describes the method of combination and that this method is either an XOR or a combination and that this method is either an XOR or a [KDF](#abbr_KDF) to justify that the effective entropy of each [KDF](#abbr_KDF) to justify that the effective entropy of each factor is preserved. The evaluator shall also verify that each factor is preserved. The evaluator shall also verify that each combined value was originally generated from an Approved DRBG combined value was originally generated from an Approved DRBG described in [FCS_RBG.1](#FCS_RBG.1). described in [FCS_RBG.1](#FCS_RBG.1). - If [concatenating the keys and using a KDF (as described in SP - If [concatenating the keys and using a KDF (as described in SP 800-56C)](#s-dek-800-56) is selected, the evaluator shall ensure the 800-56C)](#s-dek-800-56) is selected, the evaluator shall ensure the [TSS](#abbr_TSS) includes a description of the randomness extraction [TSS](#abbr_TSS) includes a description of the randomness extraction step. step. The description must include how an approved untruncated MAC function is The description must include how an approved untruncated MAC function is being used for the randomness extraction step and the evaluator shall being used for the randomness extraction step and the evaluator shall verify the [TSS](#abbr_TSS) describes that the output length (in bits) verify the [TSS](#abbr_TSS) describes that the output length (in bits) of the MAC function is at least as large as the targeted security of the MAC function is at least as large as the targeted security strength (in bits) of the parameter set employed by the key strength (in bits) of the parameter set employed by the key establishment scheme (see Tables 1-3 of SP 800-56C).\ establishment scheme (see Tables 1-3 of SP 800-56C).\ \ \ The description must include how the MAC function being used for the The description must include how the MAC function being used for the randomness extraction step is related to the [PRF](#abbr_PRF) used in randomness extraction step is related to the [PRF](#abbr_PRF) used in the key expansion and verify the [TSS](#abbr_TSS) description includes the key expansion and verify the [TSS](#abbr_TSS) description includes the correct MAC function: the correct MAC function: - If an [HMAC](#abbr_HMAC)-hash is used in the randomness extraction - If an [HMAC](#abbr_HMAC)-hash is used in the randomness extraction step, then the same [HMAC](#abbr_HMAC)-hash (with the same hash step, then the same [HMAC](#abbr_HMAC)-hash (with the same hash function hash) is used as the [PRF](#abbr_PRF) in the key expansion function hash) is used as the [PRF](#abbr_PRF) in the key expansion step. step. - If an [AES](#abbr_AES)-CMAC is used in the randomness extraction - If an [AES](#abbr_AES)-CMAC is used in the randomness extraction step, then [AES](#abbr_AES)-CMAC with a 128-bit key is used as the step, then [AES](#abbr_AES)-CMAC with a 128-bit key is used as the [PRF](#abbr_PRF) in the key expansion step. [PRF](#abbr_PRF) in the key expansion step. - The description must include the lengths of the salt values being - The description must include the lengths of the salt values being used in the randomness extraction step and the evaluator shall used in the randomness extraction step and the evaluator shall verify the [TSS](#abbr_TSS) description includes correct salt verify the [TSS](#abbr_TSS) description includes correct salt lengths: lengths: - If an [HMAC](#abbr_HMAC)-hash is being used as the MAC, the salt - If an [HMAC](#abbr_HMAC)-hash is being used as the MAC, the salt length can be any value up to the maximum bit length permitted for length can be any value up to the maximum bit length permitted for input to the hash function hash. input to the hash function hash. - If an [AES](#abbr_AES)-CMAC is being used as the MAC, the salt - If an [AES](#abbr_AES)-CMAC is being used as the MAC, the salt length shall be the same length as the [AES](#abbr_AES) key (i.e., length shall be the same length as the [AES](#abbr_AES) key (i.e., 256 bits). 256 bits). (conditional) If a [KDF](#abbr_KDF) is used, the evaluator shall ensure (conditional) If a [KDF](#abbr_KDF) is used, the evaluator shall ensure that the [TSS](#abbr_TSS) includes a description of the key derivation that the [TSS](#abbr_TSS) includes a description of the key derivation function and shall verify the key derivation uses an approved derivation function and shall verify the key derivation uses an approved derivation mode and key expansion algorithm according to SP 800-108 or SP 800-56C.\ mode and key expansion algorithm according to SP 800-108 or SP 800-56C.\ \ \ ::: ::: ::: ::: ::: eacategory ::: eacategory Guidance Guidance ::: ::: ::: ea ::: ea ::: ea ::: ea The evaluator uses the description of the DRBG functionality in The evaluator uses the description of the DRBG functionality in [FCS_RBG.1](#FCS_RBG.1) or documentation available for the operational [FCS_RBG.1](#FCS_RBG.1) or documentation available for the operational environment to determine that the key size being generated or combined environment to determine that the key size being generated or combined is identical to the key size and mode to be used for the is identical to the key size and mode to be used for the encryption/decryption of the data.\ encryption/decryption of the data.\ \ \ ::: ::: ::: ::: ::: eacategory ::: eacategory Tests Tests ::: ::: ::: ea ::: ea ::: ea ::: ea If a [KDF](#abbr_KDF) is used, the evaluator shall perform one or more If a [KDF](#abbr_KDF) is used, the evaluator shall perform one or more of the following tests to verify the correctness of the key derivation of the following tests to verify the correctness of the key derivation function, depending on the modes that are supported. [Table function, depending on the modes that are supported. [Table [7]{.counter}](#notations){.notations-ref [7]{.counter}](#notations){.notations-ref onclick="showTarget('notations')"} maps the data fields to the notations onclick="showTarget('notations')"} maps the data fields to the notations used in SP 800-108 and SP 800-56C.\ used in SP 800-108 and SP 800-56C.\ \ \ **[Table [7]{.counter}: Notations used in SP 800-108 and SP **[Table [7]{.counter}: Notations used in SP 800-108 and SP 800-56C]{#notations .ctr myid="notations" counter-type="ct-Table"}**\ 800-56C]{#notations .ctr myid="notations" counter-type="ct-Table"}**\ -------------------------------------- ------------------------- ------------------ -------------------------------------- ------------------------- ------------------ Data Fields Notations Data Fields Notations SP 800-108 SP 800-56C SP 800-108 SP 800-56C Pseudorandom function [PRF](#abbr_PRF) [PRF](#abbr_PRF) Pseudorandom function [PRF](#abbr_PRF) [PRF](#abbr_PRF) Counter length r r Counter length r r Length of output of [PRF](#abbr_PRF) h h Length of output of [PRF](#abbr_PRF) h h Length of derived keying material L L Length of derived keying material L L Length of input values l length l length Length of input values l length l length Pseudorandom input values I K1 (key derivation key) Z (shared secret) Pseudorandom input values I K1 (key derivation key) Z (shared secret) Pseudorandom salt values n/a s Pseudorandom salt values n/a s Randomness extraction MAC n/a MAC Randomness extraction MAC n/a MAC -------------------------------------- ------------------------- ------------------ -------------------------------------- ------------------------- ------------------ \ \ \ \ **Counter Mode Tests:**\ **Counter Mode Tests:**\ \ \ The evaluator shall determine the following characteristics of the key The evaluator shall determine the following characteristics of the key derivation function: derivation function: - One or more pseudorandom functions that are supported by the - One or more pseudorandom functions that are supported by the implementation ([PRF](#abbr_PRF)). implementation ([PRF](#abbr_PRF)). - One or more of the values {8, 16, 24, 32} that equal the length of - One or more of the values {8, 16, 24, 32} that equal the length of the binary representation of the counter (r). the binary representation of the counter (r). - The length (in bits) of the output of the [PRF](#abbr_PRF) (h). - The length (in bits) of the output of the [PRF](#abbr_PRF) (h). - Minimum and maximum values for the length (in bits) of the derived - Minimum and maximum values for the length (in bits) of the derived keying material (L). These values can be equal if only one value of keying material (L). These values can be equal if only one value of L is supported. These must be evenly divisible by h. L is supported. These must be evenly divisible by h. - Up to two values of L that are NOT evenly divisible by h. - Up to two values of L that are NOT evenly divisible by h. - Location of the counter relative to fixed input data: before, after, - Location of the counter relative to fixed input data: before, after, or in the middle. or in the middle. - - Counter before fixed input data: fixed input data string length - - Counter before fixed input data: fixed input data string length (in bytes), fixed input data string value. (in bytes), fixed input data string value. - Counter after fixed input data: fixed input data string length - Counter after fixed input data: fixed input data string length (in bytes), fixed input data string value. (in bytes), fixed input data string value. - Counter in the middle of fixed input data: length of data before - Counter in the middle of fixed input data: length of data before counter (in bytes), length of data after counter (in bytes), counter (in bytes), length of data after counter (in bytes), value of string input before counter, value of string input value of string input before counter, value of string input after counter. after counter. - The length (I_length) of the input values I. - The length (I_length) of the input values I. For each supported combination of I_length, MAC, salt, [PRF](#abbr_PRF), For each supported combination of I_length, MAC, salt, [PRF](#abbr_PRF), counter location, value of r, and value of L, the evaluator shall counter location, value of r, and value of L, the evaluator shall generate 10 test vectors that include pseudorandom input values I, and generate 10 test vectors that include pseudorandom input values I, and pseudorandom salt values. If there is only one value of L that is evenly pseudorandom salt values. If there is only one value of L that is evenly divisible by h, the evaluator shall generate 20 test vectors for it. For divisible by h, the evaluator shall generate 20 test vectors for it. For each test vector, the evaluator shall supply this data to the each test vector, the evaluator shall supply this data to the [TOE](#abbr_TOE) in order to produce the keying material output.\ [TOE](#abbr_TOE) in order to produce the keying material output.\ \ \ The results from each test may either be obtained by the evaluator The results from each test may either be obtained by the evaluator directly or by supplying the inputs to the implementer and receiving the directly or by supplying the inputs to the implementer and receiving the results in response. To determine correctness, the evaluator shall results in response. To determine correctness, the evaluator shall compare the resulting values to those obtained by submitting the same compare the resulting values to those obtained by submitting the same inputs to a known good implementation.\ inputs to a known good implementation.\ \ \ **Feedback Mode Tests:**\ **Feedback Mode Tests:**\ \ \ The evaluator shall determine the following characteristics of the key The evaluator shall determine the following characteristics of the key derivation function: derivation function: - One or more pseudorandom functions that are supported by the - One or more pseudorandom functions that are supported by the implementation ([PRF](#abbr_PRF)). implementation ([PRF](#abbr_PRF)). - The length (in bits) of the output of the [PRF](#abbr_PRF) (h). - The length (in bits) of the output of the [PRF](#abbr_PRF) (h). - Minimum and maximum values for the length (in bits) of the derived - Minimum and maximum values for the length (in bits) of the derived keying material (L). These values can be equal if only one value of keying material (L). These values can be equal if only one value of L is supported. These must be evenly divisible by h. L is supported. These must be evenly divisible by h. - Up to two values of L that are NOT evenly divisible by h. - Up to two values of L that are NOT evenly divisible by h. - Whether or not zero-length IVs are supported. - Whether or not zero-length IVs are supported. - Whether or not a counter is used, and if so: - Whether or not a counter is used, and if so: - - One or more of the values {8, 16, 24, 32} that equal the length - - One or more of the values {8, 16, 24, 32} that equal the length of the binary representation of the counter (r). of the binary representation of the counter (r). - Location of the counter relative to fixed input data: before, - Location of the counter relative to fixed input data: before, after, or in the middle. after, or in the middle. - - Counter before fixed input data: fixed input data string - - Counter before fixed input data: fixed input data string length (in bytes), fixed input data string value. length (in bytes), fixed input data string value. - Counter after fixed input data: fixed input data string - Counter after fixed input data: fixed input data string length (in bytes), fixed input data string value. length (in bytes), fixed input data string value. - Counter in the middle of fixed input data: length of data - Counter in the middle of fixed input data: length of data before counter (in bytes), length of data after counter (in before counter (in bytes), length of data after counter (in bytes), value of string input before counter, value of bytes), value of string input before counter, value of string input after counter. string input after counter. - The length (I_length) of the input values I. - The length (I_length) of the input values I. For each supported combination of I_length, MAC, salt, [PRF](#abbr_PRF), For each supported combination of I_length, MAC, salt, [PRF](#abbr_PRF), counter location (if a counter is used), value of r (if a counter is counter location (if a counter is used), value of r (if a counter is used), and value of L, the evaluator shall generate 10 test vectors that used), and value of L, the evaluator shall generate 10 test vectors that include pseudorandom input values I and pseudorandom salt values. If the include pseudorandom input values I and pseudorandom salt values. If the [KDF](#abbr_KDF) supports zero-length IVs, five of these test vectors [KDF](#abbr_KDF) supports zero-length IVs, five of these test vectors will be accompanied by pseudorandom IVs and the other five will use will be accompanied by pseudorandom IVs and the other five will use zero-length IVs. If zero-length IVs are not supported, each test vector zero-length IVs. If zero-length IVs are not supported, each test vector will be accompanied by an pseudorandom IV. If there is only one value of will be accompanied by an pseudorandom IV. If there is only one value of L that is evenly divisible by h, the evaluator shall generate 20 test L that is evenly divisible by h, the evaluator shall generate 20 test vectors for it.\ vectors for it.\ \ \ For each test vector, the evaluator shall supply this data to the For each test vector, the evaluator shall supply this data to the [TOE](#abbr_TOE) in order to produce the keying material output. The [TOE](#abbr_TOE) in order to produce the keying material output. The results from each test may either be obtained by the evaluator directly results from each test may either be obtained by the evaluator directly or by supplying the inputs to the implementer and receiving the results or by supplying the inputs to the implementer and receiving the results in response. To determine correctness, the evaluator shall compare the in response. To determine correctness, the evaluator shall compare the resulting values to those obtained by submitting the same inputs to a resulting values to those obtained by submitting the same inputs to a known good implementation.\ known good implementation.\ \ \ **Double Pipeline Iteration Mode Tests:**\ **Double Pipeline Iteration Mode Tests:**\ \ \ The evaluator shall determine the following characteristics of the key The evaluator shall determine the following characteristics of the key derivation function: derivation function: - One or more pseudorandom functions that are supported by the - One or more pseudorandom functions that are supported by the implementation ([PRF](#abbr_PRF)). implementation ([PRF](#abbr_PRF)). - The length (in bits) of the output of the [PRF](#abbr_PRF) (h). - The length (in bits) of the output of the [PRF](#abbr_PRF) (h). - Minimum and maximum values for the length (in bits) of the derived - Minimum and maximum values for the length (in bits) of the derived keying material (L). These values can be equal if only one value of keying material (L). These values can be equal if only one value of L is supported. These must be evenly divisible by h. L is supported. These must be evenly divisible by h. - Up to two values of L that are NOT evenly divisible by h. - Up to two values of L that are NOT evenly divisible by h. - Whether or not a counter is used, and if so: - Whether or not a counter is used, and if so: - - One or more of the values {8, 16, 24, 32} that equal the length - - One or more of the values {8, 16, 24, 32} that equal the length of the binary representation of the counter (r). of the binary representation of the counter (r). - Location of the counter relative to fixed input data: before, - Location of the counter relative to fixed input data: before, after, or in the middle. after, or in the middle. - - Counter before fixed input data: fixed input data string - - Counter before fixed input data: fixed input data string length (in bytes), fixed input data string value. length (in bytes), fixed input data string value. - Counter after fixed input data: fixed input data string - Counter after fixed input data: fixed input data string length (in bytes), fixed input data string value. length (in bytes), fixed input data string value. - Counter in the middle of fixed input data: length of data - Counter in the middle of fixed input data: length of data before counter (in bytes), length of data after counter (in before counter (in bytes), length of data after counter (in bytes), value of string input before counter, value of bytes), value of string input before counter, value of string input after counter. string input after counter. - The length (I_length) of the input values I. - The length (I_length) of the input values I. For each supported combination of I_length, MAC, salt, [PRF](#abbr_PRF), For each supported combination of I_length, MAC, salt, [PRF](#abbr_PRF), counter location (if a counter is used), value of r (if a counter is counter location (if a counter is used), value of r (if a counter is used), and value of L, the evaluator shall generate 10 test vectors that used), and value of L, the evaluator shall generate 10 test vectors that include pseudorandom input values I, and pseudorandom salt values. If include pseudorandom input values I, and pseudorandom salt values. If there is only one value of L that is evenly divisible by h, the there is only one value of L that is evenly divisible by h, the evaluator shall generate 20 test vectors for it.\ evaluator shall generate 20 test vectors for it.\ \ \ For each test vector, the evaluator shall supply this data to the For each test vector, the evaluator shall supply this data to the [TOE](#abbr_TOE) in order to produce the keying material output. The [TOE](#abbr_TOE) in order to produce the keying material output. The results from each test may either be obtained by the evaluator directly results from each test may either be obtained by the evaluator directly or by supplying the inputs to the implementer and receiving the results or by supplying the inputs to the implementer and receiving the results in response. To determine correctness, the evaluator shall compare the in response. To determine correctness, the evaluator shall compare the resulting values to those obtained by submitting the same inputs to a resulting values to those obtained by submitting the same inputs to a known good implementation.\ known good implementation.\ \ \ ::: ::: ::: ::: ::: ::: ::: ::: ::: ::: ::: {#FCS_CKM_EXT.3 .comp} ::: {#FCS_CKM_EXT.3 .comp} #### FCS_CKM_EXT.3 Cryptographic Key Generation #### FCS_CKM_EXT.3 Cryptographic Key Generation ::: element ::: element ::: {#FCS_CKM_EXT.3.1 .reqid} ::: {#FCS_CKM_EXT.3.1 .reqid} [FCS_CKM_EXT.3.1](#FCS_CKM_EXT.3.1){.abbr} [FCS_CKM_EXT.3.1](#FCS_CKM_EXT.3.1){.abbr} ::: ::: ::: reqdesc ::: reqdesc The [TSF](#abbr_TSF) shall use \[**selection**: [asymmetric KEKs of The [TSF](#abbr_TSF) shall use \[**selection**: [asymmetric KEKs of \[**assignment**: [security strength greater than or equal to 192 \[**assignment**: [security strength greater than or equal to 192 bits]{#a-kek-asym-size .assignable-content}\] security | bits]{.assignable-content}\] security strength]{#s-kek-asym strength]{#s-kek-asym .selectable-content}, [symmetric KEKs of 256-bit | .selectable-content}, [symmetric KEKs of 256-bit security strength security strength corresponding to at least the security strength of the | corresponding to at least the security strength of the keys encrypted by keys encrypted by the [KEK](#abbr_KEK)]{#s-kek-sym | the [KEK](#abbr_KEK)]{#s-kek-sym .selectable-content}\]. .selectable-content}\]. < ::: appnote ::: appnote [Application Note: ]{.note-header}[ The [ST](#abbr_ST) author selects | [Application Note: ]{.note-header}[The [ST](#abbr_ST) author selects all all applicable [KEK](#abbr_KEK) types implemented by the | applicable [KEK](#abbr_KEK) types implemented by the [TOE](#abbr_TOE). ]{.note} | [TOE](#abbr_TOE).]{.note} ::: ::: ::: ::: ::: ::: ::: element ::: element ::: {#FCS_CKM_EXT.3.2 .reqid} ::: {#FCS_CKM_EXT.3.2 .reqid} [FCS_CKM_EXT.3.2](#FCS_CKM_EXT.3.2){.abbr} [FCS_CKM_EXT.3.2](#FCS_CKM_EXT.3.2){.abbr} ::: ::: ::: reqdesc ::: reqdesc The [TSF](#abbr_TSF) shall generate all KEKs using one of the following The [TSF](#abbr_TSF) shall generate all KEKs using one of the following methods: methods: - Derive the [KEK](#abbr_KEK) from a Password Authentication Factor - Derive the [KEK](#abbr_KEK) from a Password Authentication Factor according to [FCS_CKM_EXT.8](#FCS_CKM_EXT.8) and according to [FCS_CKM_EXT.8](#FCS_CKM_EXT.8) and \[**selection**: \[**selection**: - [Generate the [KEK](#abbr_KEK) using a DRBG that meets this profile - [Generate the [KEK](#abbr_KEK) using a DRBG that meets this profile (as specified in [FCS_RBG.1](#FCS_RBG.1))]{#_s_107 | (as specified in [FCS_RBG.1](#FCS_RBG.1))]{#fcs_ckm_ext.3.2_1 .selectable-content} .selectable-content} - [Generate the [KEK](#abbr_KEK) using a key generation scheme that - [Generate the [KEK](#abbr_KEK) using a key generation scheme that meets this profile (as specified in [FCS_CKM.1/AKG](#FCS_CKM.1/AKG) meets this profile (as specified in [FCS_CKM.1/AKG](#FCS_CKM.1/AKG) or [FCS_CKM.1/SKG](#FCS_CKM.1/SKG))]{#_s_108 .selectable-content} | or [FCS_CKM.1/SKG](#FCS_CKM.1/SKG))]{#fcs_ckm_ext.3.2_2 > .selectable-content} - [Combine the [KEK](#abbr_KEK) from other KEKs in a way that - [Combine the [KEK](#abbr_KEK) from other KEKs in a way that preserves the effective entropy of each factor by \[**selection**: preserves the effective entropy of each factor by \[**selection**: [using an XOR operation]{#_s_110 .selectable-content}, | [using an XOR operation]{#fcs_ckm_ext.3.2_4 .selectable-content}, [concatenating the keys and using a [KDF](#abbr_KDF) (as described [concatenating the keys and using a [KDF](#abbr_KDF) (as described in SP 800-108)]{#_s_111 .selectable-content}, [concatenating the | in SP 800-108)]{#fcs_ckm_ext.3.2_5 .selectable-content}, keys and using a [KDF](#abbr_KDF) (as described in SP | [concatenating the keys and using a [KDF](#abbr_KDF) (as described 800-56C)]{#_s_112 .selectable-content}, [encrypting one key with | in SP 800-56C)]{#fcs_ckm_ext.3.2_6 .selectable-content}, [encrypting another]{#_s_113 .selectable-content}\]]{#_s_109 | one key with another]{#fcs_ckm_ext.3.2_7 .selectable-content} | .selectable-content}\]]{#fcs_ckm_ext.3.2_3 .selectable-content} \]. \]. ::: appnote ::: appnote [Application Note: ]{.note-header}[ The conditioning of passwords is [Application Note: ]{.note-header}[ The conditioning of passwords is performed in accordance with [FCS_CKM_EXT.8](#FCS_CKM_EXT.8).\ performed in accordance with [FCS_CKM_EXT.8](#FCS_CKM_EXT.8).\ \ \ It is expected that key generation derived from conditioning, using a It is expected that key generation derived from conditioning, using a DRBG or generation scheme, and through combination, will each be DRBG or generation scheme, and through combination, will each be necessary to meet the requirements set out in this document. In necessary to meet the requirements set out in this document. In particular, [Figure [3]{.counter}](#Keys){.Keys-ref particular, [Figure [3]{.counter}](#Keys){.Keys-ref onclick="showTarget('Keys')"} has KEKs of each type: KEK_3 is generated, onclick="showTarget('Keys')"} has KEKs of each type: KEK_3 is generated, KEK_1 is derived from a Password Authentication Factor, and KEK_2 is KEK_1 is derived from a Password Authentication Factor, and KEK_2 is combined from two KEKs. In [Figure [3]{.counter}](#Keys){.Keys-ref combined from two KEKs. In [Figure [3]{.counter}](#Keys){.Keys-ref onclick="showTarget('Keys')"}, KEK_3 may either be a symmetric key onclick="showTarget('Keys')"}, KEK_3 may either be a symmetric key generated from a DRBG or an asymmetric key generated using a key generated from a DRBG or an asymmetric key generated using a key generation scheme according to [FCS_CKM.1/AKG](#FCS_CKM.1/AKG).\ generation scheme according to [FCS_CKM.1/AKG](#FCS_CKM.1/AKG).\ \ \ If combined, the [ST](#abbr_ST) author should describe which method of If combined, the [ST](#abbr_ST) author should describe which method of combination is used in order to justify that the effective entropy of combination is used in order to justify that the effective entropy of each factor is preserved.\ each factor is preserved.\ \ \ SP 800-56C specifies a two-step key derivation procedure that employs an SP 800-56C specifies a two-step key derivation procedure that employs an extraction-then-expansion technique for deriving keying material from a extraction-then-expansion technique for deriving keying material from a shared secret generated during a key establishment scheme. The shared secret generated during a key establishment scheme. The Randomness Extraction step as described in Section 5 of SP 800-56C is Randomness Extraction step as described in Section 5 of SP 800-56C is followed by Key Expansion using the key derivation functions defined in followed by Key Expansion using the key derivation functions defined in SP 800-108 (as described in Section 6 of SP 800-56C). ]{.note} SP 800-108 (as described in Section 6 of SP 800-56C). ]{.note} ::: ::: ::: ::: ::: ::: ::: {.activity_pane .hide} ::: {.activity_pane .hide} ::: activity_pane_header ::: activity_pane_header [[ Evaluation Activities [[ Evaluation Activities ]{.activity_pane_label}[]{.toggler}](#){onclick="toggle(this);return false;"} ]{.activity_pane_label}[]{.toggler}](#){onclick="toggle(this);return false;"} ::: ::: ::: activity_pane_body ::: activity_pane_body ::: component-activity-header ::: component-activity-header [FCS_CKM_EXT.3](#FCS_CKM_EXT.3) [FCS_CKM_EXT.3](#FCS_CKM_EXT.3) ::: ::: ::: eacategory ::: eacategory [TSS](#abbr_TSS) [TSS](#abbr_TSS) ::: ::: ::: ea ::: ea ::: ea ::: ea The evaluator shall examine the key hierarchy section of the The evaluator shall examine the key hierarchy section of the [TSS](#abbr_TSS) to ensure that the formation of all KEKs are described [TSS](#abbr_TSS) to ensure that the formation of all KEKs are described and that the key sizes match that described by the [ST](#abbr_ST) and that the key sizes match that described by the [ST](#abbr_ST) author. The evaluator shall examine the key hierarchy section of the author. The evaluator shall examine the key hierarchy section of the [TSS](#abbr_TSS) to ensure that each key ([DEKs](#abbr_DEK), | [TSS](#abbr_TSS) to ensure that each key (DEKs, software-based key software-based key storage, and KEKs) is encrypted by keys of equal or | storage, and KEKs) is encrypted by keys of equal or greater security greater security strength using one of the selected methods.\ | strength using one of the selected methods.\ \ \ The evaluator shall review the [TSS](#abbr_TSS) to verify that it The evaluator shall review the [TSS](#abbr_TSS) to verify that it contains a description of the conditioning used to derive KEKs. This contains a description of the conditioning used to derive KEKs. This description must include the size and storage location of salts. This description must include the size and storage location of salts. This activity may be performed in combination with that for activity may be performed in combination with that for [FCS_CKM_EXT.8](#FCS_CKM_EXT.8).\ [FCS_CKM_EXT.8](#FCS_CKM_EXT.8).\ \ \ (conditional) If the symmetric [KEK](#abbr_KEK) is generated by a DRBG, (conditional) If the symmetric [KEK](#abbr_KEK) is generated by a DRBG, the evaluator shall review the [TSS](#abbr_TSS) to determine that it the evaluator shall review the [TSS](#abbr_TSS) to determine that it describes how the functionality described by [FCS_RBG.1](#FCS_RBG.1) is describes how the functionality described by [FCS_RBG.1](#FCS_RBG.1) is invoked. The evaluator uses the description of the DRBG functionality in invoked. The evaluator uses the description of the DRBG functionality in [FCS_RBG.1](#FCS_RBG.1) or documentation available for the operational [FCS_RBG.1](#FCS_RBG.1) or documentation available for the operational environment to determine that the key size being requested is greater environment to determine that the key size being requested is greater than or equal to the key size and mode to be used for the than or equal to the key size and mode to be used for the encryption/decryption of the data.\ encryption/decryption of the data.\ \ \ (conditional) If the [KEK](#abbr_KEK) is generated according to an (conditional) If the [KEK](#abbr_KEK) is generated according to an asymmetric key scheme, the evaluator shall review the [TSS](#abbr_TSS) asymmetric key scheme, the evaluator shall review the [TSS](#abbr_TSS) to determine that it describes how the functionality described by to determine that it describes how the functionality described by [FCS_CKM.1/AKG](#FCS_CKM.1/AKG) is invoked. The evaluator uses the [FCS_CKM.1/AKG](#FCS_CKM.1/AKG) is invoked. The evaluator uses the description of the key generation functionality in description of the key generation functionality in [FCS_CKM.1/AKG](#FCS_CKM.1/AKG) or documentation available for the [FCS_CKM.1/AKG](#FCS_CKM.1/AKG) or documentation available for the operational environment to determine that the key strength being operational environment to determine that the key strength being requested is greater than or equal to 112 bits.\ requested is greater than or equal to 112 bits.\ \ \ (conditional) If the [KEK](#abbr_KEK) is formed from a combination, the (conditional) If the [KEK](#abbr_KEK) is formed from a combination, the evaluator shall verify that the [TSS](#abbr_TSS) describes the method of evaluator shall verify that the [TSS](#abbr_TSS) describes the method of combination and that this method is either an XOR, a [KDF](#abbr_KDF), combination and that this method is either an XOR, a [KDF](#abbr_KDF), or encryption.\ or encryption.\ \ \ (conditional) If a [KDF](#abbr_KDF) is used, the evaluator shall ensure (conditional) If a [KDF](#abbr_KDF) is used, the evaluator shall ensure that the [TSS](#abbr_TSS) includes a description of the key derivation that the [TSS](#abbr_TSS) includes a description of the key derivation function and shall verify the key derivation uses an approved derivation function and shall verify the key derivation uses an approved derivation mode and key expansion algorithm according to SP 800-108.\ mode and key expansion algorithm according to SP 800-108.\ \ \ (conditional) If [concatenating the keys and using a KDF (as described (conditional) If [concatenating the keys and using a KDF (as described in SP 800-56C)](#s-dek-800-56) is selected, the evaluator shall ensure in SP 800-56C)](#s-dek-800-56) is selected, the evaluator shall ensure the [TSS](#abbr_TSS) includes a description of the randomness extraction the [TSS](#abbr_TSS) includes a description of the randomness extraction step. The description must include step. The description must include - How an approved untruncated MAC function is being used for the - How an approved untruncated MAC function is being used for the randomness extraction step and the evaluator shall verify the randomness extraction step and the evaluator shall verify the [TSS](#abbr_TSS) describes that the output length (in bits) of the [TSS](#abbr_TSS) describes that the output length (in bits) of the MAC function is at least as large as the targeted security strength MAC function is at least as large as the targeted security strength (in bits) of the parameter set employed by the key establishment (in bits) of the parameter set employed by the key establishment scheme (see Tables 1-3 of SP 800-56C). scheme (see Tables 1-3 of SP 800-56C). - How the MAC function being used for the randomness extraction step - How the MAC function being used for the randomness extraction step is related to the [PRF](#abbr_PRF) used in the key expansion and is related to the [PRF](#abbr_PRF) used in the key expansion and verify the [TSS](#abbr_TSS) description includes the correct MAC verify the [TSS](#abbr_TSS) description includes the correct MAC function: function: - - If an [HMAC](#abbr_HMAC)-hash is used in the randomness - - If an [HMAC](#abbr_HMAC)-hash is used in the randomness extraction step, then the same [HMAC](#abbr_HMAC)-hash (with the extraction step, then the same [HMAC](#abbr_HMAC)-hash (with the same hash function hash) is used as the [PRF](#abbr_PRF) in the same hash function hash) is used as the [PRF](#abbr_PRF) in the key expansion step. key expansion step. - If an [AES](#abbr_AES)-CMAC (with key length 128, 192, or 256 - If an [AES](#abbr_AES)-CMAC (with key length 128, 192, or 256 bits) is used in the randomness extraction step, then bits) is used in the randomness extraction step, then [AES](#abbr_AES)-CMAC with a 128-bit key is used as the [AES](#abbr_AES)-CMAC with a 128-bit key is used as the [PRF](#abbr_PRF) in the key expansion step. [PRF](#abbr_PRF) in the key expansion step. - The lengths of the salt values being used in the randomness - The lengths of the salt values being used in the randomness extraction step and the evaluator shall verify the [TSS](#abbr_TSS) extraction step and the evaluator shall verify the [TSS](#abbr_TSS) description includes correct salt lengths: description includes correct salt lengths: - - If an [HMAC](#abbr_HMAC)-hash is being used as the MAC, the salt - - If an [HMAC](#abbr_HMAC)-hash is being used as the MAC, the salt length can be any value up to the maximum bit length permitted length can be any value up to the maximum bit length permitted for input to the hash function hash. for input to the hash function hash. - If an [AES](#abbr_AES)-CMAC is being used as the MAC, the salt - If an [AES](#abbr_AES)-CMAC is being used as the MAC, the salt length shall be the same length as the [AES](#abbr_AES) key length shall be the same length as the [AES](#abbr_AES) key (i.e., 256 bits). (i.e., 256 bits). \ \ The evaluator shall also ensure that the documentation of the product\'s The evaluator shall also ensure that the documentation of the product\'s encryption key management is detailed enough that, after reading, the encryption key management is detailed enough that, after reading, the product\'s key management hierarchy is clear and that it meets the product\'s key management hierarchy is clear and that it meets the requirements to ensure the keys are adequately protected. The evaluator requirements to ensure the keys are adequately protected. The evaluator shall ensure that the documentation includes both an essay and one or shall ensure that the documentation includes both an essay and one or more diagrams. Note that this may also be documented as separate more diagrams. Note that this may also be documented as separate proprietary evidence rather than being included in the proprietary evidence rather than being included in the [TSS](#abbr_TSS).\ [TSS](#abbr_TSS).\ \ \ ::: ::: ::: ::: ::: eacategory ::: eacategory Guidance Guidance ::: ::: ::: ea ::: ea ::: ea ::: ea There are no guidance evaluation activities for this component.\ There are no guidance evaluation activities for this component.\ \ \ ::: ::: ::: ::: ::: eacategory ::: eacategory Tests Tests ::: ::: ::: ea ::: ea ::: ea ::: ea If a [KDF](#abbr_KDF) is used, the evaluator shall perform one or more If a [KDF](#abbr_KDF) is used, the evaluator shall perform one or more of the following tests to verify the correctness of the key derivation of the following tests to verify the correctness of the key derivation function, depending on the modes that are supported. [Table function, depending on the modes that are supported. [Table [8]{.counter}](#KDF){.KDF-ref onclick="showTarget('KDF')"} maps the data [8]{.counter}](#KDF){.KDF-ref onclick="showTarget('KDF')"} maps the data fields to the notations used in SP 800-108 and SP 800-56C.\ fields to the notations used in SP 800-108 and SP 800-56C.\ \ \ **[Table [8]{.counter}: Notations used in SP 800-108 and SP **[Table [8]{.counter}: Notations used in SP 800-108 and SP 800-56C]{#KDF .ctr myid="KDF" counter-type="ct-Table"}**\ 800-56C]{#KDF .ctr myid="KDF" counter-type="ct-Table"}**\ -------------------------------------- --------------------------- ---------------- | -------------------------------------- ---------------------------- --------------- Data Fields Notations | Data Fields Notations SP 800-108 SP 800-56C | SP 800-108 SP 800-56C Pseudorandom function [PRF](#abbr_PRF) [PRF](#abbr_PRF) | Pseudorandom function [PRF](#abbr_PRF) [PRF](#abbr_PRF Counter length r r | Counter length r r Length of output of [PRF](#abbr_PRF) h h | Length of output of [PRF](#abbr_PRF) h h Length of derived keying material L L | Length of derived keying material L L Length of input values I_length I_length | Length of input values I_length I_length Pseudorandom input values I K~1~ (key derivation key) Z (shared secret | Pseudorandom input values I K ~1~ (key derivation key) Z (shared secre Pseudorandom salt values n/a s | Pseudorandom salt values n/a s Randomness extraction MAC n/a MAC | Randomness extraction MAC n/a MAC -------------------------------------- --------------------------- ---------------- | -------------------------------------- ---------------------------- --------------- \ \ \ \ **Counter Mode Tests:**\ **Counter Mode Tests:**\ \ \ The evaluator shall determine the following characteristics of the key The evaluator shall determine the following characteristics of the key derivation function: derivation function: - One or more pseudorandom functions that are supported by the - One or more pseudorandom functions that are supported by the implementation ([PRF](#abbr_PRF)). implementation ([PRF](#abbr_PRF)). - One or more of the values {8, 16, 24, 32} that equal the length of - One or more of the values {8, 16, 24, 32} that equal the length of the binary representation of the counter (r). the binary representation of the counter (r). - The length (in bits) of the output of the [PRF](#abbr_PRF) (h). - The length (in bits) of the output of the [PRF](#abbr_PRF) (h). - Minimum and maximum values for the length (in bits) of the derived - Minimum and maximum values for the length (in bits) of the derived keying material (L). These values can be equal if only one value of keying material (L). These values can be equal if only one value of L is supported. These must be evenly divisible by h. L is supported. These must be evenly divisible by h. - Up to two values of L that are NOT evenly divisible by h. - Up to two values of L that are NOT evenly divisible by h. - Location of the counter relative to fixed input data: before, after, - Location of the counter relative to fixed input data: before, after, or in the middle. or in the middle. - Counter before fixed input data: fixed input data string length - Counter before fixed input data: fixed input data string length (in bytes), fixed input data string value. (in bytes), fixed input data string value. - Counter after fixed input data: fixed input data string length - Counter after fixed input data: fixed input data string length (in bytes), fixed input data string value. (in bytes), fixed input data string value. - Counter in the middle of fixed input data: length of data before - Counter in the middle of fixed input data: length of data before counter (in bytes), length of data after counter (in bytes), counter (in bytes), length of data after counter (in bytes), value of string input before counter, value of string input value of string input before counter, value of string input after counter. after counter. - The length (I_length) of the input values I. - The length (I_length) of the input values I. \ \ For each supported combination of I_length, MAC, salt, [PRF](#abbr_PRF), For each supported combination of I_length, MAC, salt, [PRF](#abbr_PRF), counter location, value of r, and value of L, the evaluator shall counter location, value of r, and value of L, the evaluator shall generate 10 test vectors that include pseudorandom input values I, and generate 10 test vectors that include pseudorandom input values I, and pseudorandom salt values. If there is only one value of L that is evenly pseudorandom salt values. If there is only one value of L that is evenly divisible by h, the evaluator shall generate 20 test vectors for it. For divisible by h, the evaluator shall generate 20 test vectors for it. For each test vector, the evaluator shall supply this data to the each test vector, the evaluator shall supply this data to the [TOE](#abbr_TOE) in order to produce the keying material output.\ [TOE](#abbr_TOE) in order to produce the keying material output.\ \ \ The results from each test may either be obtained by the evaluator The results from each test may either be obtained by the evaluator directly or by supplying the inputs to the implementer and receiving the directly or by supplying the inputs to the implementer and receiving the results in response. To determine correctness, the evaluator shall results in response. To determine correctness, the evaluator shall compare the resulting values to those obtained by submitting the same compare the resulting values to those obtained by submitting the same inputs to a known good implementation.\ inputs to a known good implementation.\ \ \ **Feedback Mode Tests:**\ **Feedback Mode Tests:**\ The evaluator shall determine the following characteristics of the key The evaluator shall determine the following characteristics of the key derivation function:\ derivation function:\ - One or more pseudorandom functions that are supported by the - One or more pseudorandom functions that are supported by the implementation ([PRF](#abbr_PRF)). implementation ([PRF](#abbr_PRF)). - The length (in bits) of the output of the [PRF](#abbr_PRF) (h). - The length (in bits) of the output of the [PRF](#abbr_PRF) (h). - Minimum and maximum values for the length (in bits) of the derived - Minimum and maximum values for the length (in bits) of the derived keying material (L). These values can be equal if only one value of keying material (L). These values can be equal if only one value of L is supported. These must be evenly divisible by h. L is supported. These must be evenly divisible by h. - Up to two values of L that are NOT evenly divisible by h. - Up to two values of L that are NOT evenly divisible by h. - Whether or not zero-length IVs are supported. - Whether or not zero-length IVs are supported. - Whether or not a counter is used, and if so: - Whether or not a counter is used, and if so: - One or more of the values {8, 16, 24, 32} that equal the length - One or more of the values {8, 16, 24, 32} that equal the length of the binary representation of the counter (r). of the binary representation of the counter (r). - Location of the counter relative to fixed input data: before, - Location of the counter relative to fixed input data: before, after, or in the middle. after, or in the middle. - - Counter before fixed input data: fixed input data string - - Counter before fixed input data: fixed input data string length (in bytes), fixed input data string value. length (in bytes), fixed input data string value. - Counter after fixed input data: fixed input data string - Counter after fixed input data: fixed input data string length (in bytes), fixed input data string value. length (in bytes), fixed input data string value. - Counter in the middle of fixed input data: length of data - Counter in the middle of fixed input data: length of data before counter (in bytes), length of data after counter (in before counter (in bytes), length of data after counter (in bytes), value of string input before counter, value of bytes), value of string input before counter, value of string input after counter. string input after counter. - The length (I_length) of the input values I. - The length (I_length) of the input values I. \ \ For each supported combination of I_length, MAC, salt, [PRF](#abbr_PRF), For each supported combination of I_length, MAC, salt, [PRF](#abbr_PRF), counter location (if a counter is used), value of r (if a counter is counter location (if a counter is used), value of r (if a counter is used), and value of L, the evaluator shall generate 10 test vectors that used), and value of L, the evaluator shall generate 10 test vectors that include pseudorandom input values I and pseudorandom salt values. If the include pseudorandom input values I and pseudorandom salt values. If the [KDF](#abbr_KDF) supports zero-length IVs, five of these test vectors [KDF](#abbr_KDF) supports zero-length IVs, five of these test vectors will be accompanied by pseudorandom IVs and the other five will use will be accompanied by pseudorandom IVs and the other five will use zero-length IVs. If zero-length IVs are not supported, each test vector zero-length IVs. If zero-length IVs are not supported, each test vector will be accompanied by an pseudorandom IV. If there is only one value of will be accompanied by an pseudorandom IV. If there is only one value of L that is evenly divisible by h, the evaluator shall generate 20 test L that is evenly divisible by h, the evaluator shall generate 20 test vectors for it.\ vectors for it.\ \ \ For each test vector, the evaluator shall supply this data to the For each test vector, the evaluator shall supply this data to the [TOE](#abbr_TOE) in order to produce the keying material output. The [TOE](#abbr_TOE) in order to produce the keying material output. The results from each test may either be obtained by the evaluator directly results from each test may either be obtained by the evaluator directly or by supplying the inputs to the implementer and receiving the results or by supplying the inputs to the implementer and receiving the results in response. To determine correctness, the evaluator shall compare the in response. To determine correctness, the evaluator shall compare the resulting values to those obtained by submitting the same inputs to a resulting values to those obtained by submitting the same inputs to a known good implementation.\ known good implementation.\ \ \ **Double Pipeline Iteration Mode Tests:**\ **Double Pipeline Iteration Mode Tests:**\ The evaluator shall determine the following characteristics of the key The evaluator shall determine the following characteristics of the key derivation function:\ derivation function:\ - One or more pseudorandom functions that are supported by the - One or more pseudorandom functions that are supported by the implementation ([PRF](#abbr_PRF)). implementation ([PRF](#abbr_PRF)). - The length (in bits) of the output of the [PRF](#abbr_PRF) (h). - The length (in bits) of the output of the [PRF](#abbr_PRF) (h). - Minimum and maximum values for the length (in bits) of the derived - Minimum and maximum values for the length (in bits) of the derived keying material (L). These values can be equal if only one value of keying material (L). These values can be equal if only one value of L is supported. These must be evenly divisible by h. L is supported. These must be evenly divisible by h. - Up to two values of L that are NOT evenly divisible by h. - Up to two values of L that are NOT evenly divisible by h. - Whether or not a counter is used, and if so: - Whether or not a counter is used, and if so: - One or more of the values {8, 16, 24, 32} that equal the length - One or more of the values {8, 16, 24, 32} that equal the length of the binary representation of the counter (r). of the binary representation of the counter (r). - Location of the counter relative to fixed input data: before, - Location of the counter relative to fixed input data: before, after, or in the middle. after, or in the middle. - Counter before fixed input data: fixed input data string - Counter before fixed input data: fixed input data string length (in bytes), fixed input data string value. length (in bytes), fixed input data string value. - Counter after fixed input data: fixed input data string - Counter after fixed input data: fixed input data string length (in bytes), fixed input data string value. length (in bytes), fixed input data string value. - Counter in the middle of fixed input data: length of data - Counter in the middle of fixed input data: length of data before counter (in bytes), length of data after counter (in before counter (in bytes), length of data after counter (in bytes), value of string input before counter, value of bytes), value of string input before counter, value of string input after counter. string input after counter. - The length (I_length) of the input values I. - The length (I_length) of the input values I. \ \ For each supported combination of I_length, MAC, salt, [PRF](#abbr_PRF), For each supported combination of I_length, MAC, salt, [PRF](#abbr_PRF), counter location (if a counter is used), value of r (if a counter is counter location (if a counter is used), value of r (if a counter is used), and value of L, the evaluator shall generate 10 test vectors that used), and value of L, the evaluator shall generate 10 test vectors that include pseudorandom input values I, and pseudorandom salt values. If include pseudorandom input values I, and pseudorandom salt values. If there is only one value of L that is evenly divisible by h, the there is only one value of L that is evenly divisible by h, the evaluator shall generate 20 test vectors for it.\ evaluator shall generate 20 test vectors for it.\ \ \ For each test vector, the evaluator shall supply this data to the For each test vector, the evaluator shall supply this data to the [TOE](#abbr_TOE) in order to produce the keying material output. The [TOE](#abbr_TOE) in order to produce the keying material output. The results from each test may either be obtained by the evaluator directly results from each test may either be obtained by the evaluator directly or by supplying the inputs to the implementer and receiving the results or by supplying the inputs to the implementer and receiving the results in response. To determine correctness, the evaluator shall compare the in response. To determine correctness, the evaluator shall compare the resulting values to those obtained by submitting the same inputs to a resulting values to those obtained by submitting the same inputs to a known good implementation. known good implementation. ::: ::: ::: ::: ::: ::: ::: ::: ::: ::: ::: {#FCS_CKM_EXT.5 .comp} ::: {#FCS_CKM_EXT.5 .comp} #### FCS_CKM_EXT.5 TSF Wipe #### FCS_CKM_EXT.5 TSF Wipe ::: element ::: element ::: {#FCS_CKM_EXT.5.1 .reqid} ::: {#FCS_CKM_EXT.5.1 .reqid} [FCS_CKM_EXT.5.1](#FCS_CKM_EXT.5.1){.abbr} [FCS_CKM_EXT.5.1](#FCS_CKM_EXT.5.1){.abbr} ::: ::: ::: reqdesc ::: reqdesc The [TSF](#abbr_TSF) shall wipe all protected data by \[**selection**: The [TSF](#abbr_TSF) shall wipe all protected data by \[**selection**: - [Cryptographically erasing the encrypted [DEKs](#abbr_DEK) or the | - [Cryptographically erasing the encrypted DEKs or the KEKs in KEKs in non-volatile memory by following the requirements in | non-volatile memory by following the requirements in [FCS_CKM.6.2](#FCS_CKM.6.2),]{#_s_121 .selectable-content} | [FCS_CKM.6.2](#FCS_CKM.6.2),]{#fcs_ckm_ext.5.1_1 > .selectable-content} - [Overwriting all protected data according to the following rules: - [Overwriting all protected data according to the following rules: ]{#_s_122 .selectable-content} | ]{#fcs_ckm_ext.5.1_2 .selectable-content} - For [EEPROM](#abbr_EEPROM), the destruction shall be executed by - For [EEPROM](#abbr_EEPROM), the destruction shall be executed by a single direct overwrite consisting of a pseudo random pattern a single direct overwrite consisting of a pseudo random pattern using the [TSF](#abbr_TSF)'s DRBG (as specified in using the [TSF](#abbr_TSF)'s DRBG (as specified in [FCS_RBG.1](#FCS_RBG.1)), followed by a read-verify. [FCS_RBG.1](#FCS_RBG.1)), followed by a read-verify. - For flash memory, that is not wear-leveled, the destruction - For flash memory, that is not wear-leveled, the destruction shall be executed \[**selection**: [by a single direct overwrite shall be executed \[**selection**: [by a single direct overwrite consisting of zeros followed by a read-verify]{#_s_123 | consisting of zeros followed by a .selectable-content}, [by a block erase that erases the | read-verify]{#fcs_ckm_ext.5.1_3 .selectable-content}, [by a reference to memory that stores data as well as the data | block erase that erases the reference to memory that stores data itself]{#_s_124 .selectable-content}\]. | as well as the data itself]{#fcs_ckm_ext.5.1_4 > .selectable-content}\]. - For flash memory, that is wear-leveled, the destruction shall be - For flash memory, that is wear-leveled, the destruction shall be executed \[**selection**: [by a single direct overwrite executed \[**selection**: [by a single direct overwrite consisting of zeros]{#_s_125 .selectable-content}, [by a block | consisting of zeros]{#fcs_ckm_ext.5.1_5 .selectable-content}, erase]{#_s_126 .selectable-content}\]. | [by a block erase]{#fcs_ckm_ext.5.1_6 .selectable-content}\]. - For non-volatile memory other than [EEPROM](#abbr_EEPROM) and - For non-volatile memory other than [EEPROM](#abbr_EEPROM) and flash, the destruction shall be executed by a single direct flash, the destruction shall be executed by a single direct overwrite with a random pattern that is changed before each overwrite with a random pattern that is changed before each write. write. \]. \]. ::: appnote ::: appnote [Application Note: ]{.note-header}[ Protected data is all non-TSF data, | [Application Note: ]{.note-header}[Protected data is all non-TSF data, including all user or enterprise data. Some or all of this data may be including all user or enterprise data. Some or all of this data may be considered sensitive data as well. ]{.note} | considered sensitive data as well.]{.note} ::: ::: ::: ::: ::: ::: ::: element ::: element ::: {#FCS_CKM_EXT.5.2 .reqid} ::: {#FCS_CKM_EXT.5.2 .reqid} [FCS_CKM_EXT.5.2](#FCS_CKM_EXT.5.2){.abbr} [FCS_CKM_EXT.5.2](#FCS_CKM_EXT.5.2){.abbr} ::: ::: ::: reqdesc ::: reqdesc The [TSF](#abbr_TSF) shall perform a power cycle on conclusion of the The [TSF](#abbr_TSF) shall perform a power cycle on conclusion of the wipe procedure. wipe procedure. ::: ::: ::: ::: ::: {.activity_pane .hide} ::: {.activity_pane .hide} ::: activity_pane_header ::: activity_pane_header [[ Evaluation Activities [[ Evaluation Activities ]{.activity_pane_label}[]{.toggler}](#){onclick="toggle(this);return false;"} ]{.activity_pane_label}[]{.toggler}](#){onclick="toggle(this);return false;"} ::: ::: ::: activity_pane_body ::: activity_pane_body ::: component-activity-header ::: component-activity-header [FCS_CKM_EXT.5](#FCS_CKM_EXT.5) [FCS_CKM_EXT.5](#FCS_CKM_EXT.5) ::: ::: ::: eacategory ::: eacategory [TSS](#abbr_TSS) [TSS](#abbr_TSS) ::: ::: ::: ea ::: ea ::: ea ::: ea The evaluator shall check to ensure the [TSS](#abbr_TSS) describes how The evaluator shall check to ensure the [TSS](#abbr_TSS) describes how the device is wiped, the type of clearing procedure that is performed the device is wiped, the type of clearing procedure that is performed (cryptographic erase or overwrite) and, if overwrite is performed, the (cryptographic erase or overwrite) and, if overwrite is performed, the overwrite procedure (overwrite with zeros, overwrite three or more times overwrite procedure (overwrite with zeros, overwrite three or more times by a different alternating pattern, overwrite with random pattern, or by a different alternating pattern, overwrite with random pattern, or block erase).\ block erase).\ \ \ If different types of memory are used to store the data to be protected, If different types of memory are used to store the data to be protected, the evaluator shall check to ensure that the [TSS](#abbr_TSS) describes the evaluator shall check to ensure that the [TSS](#abbr_TSS) describes the clearing procedure in terms of the memory in which the data are the clearing procedure in terms of the memory in which the data are stored (for example, data stored on flash are cleared by overwriting stored (for example, data stored on flash are cleared by overwriting once with zeros, while data stored on the internal persistent storage once with zeros, while data stored on the internal persistent storage device are cleared by overwriting three times with a random pattern that device are cleared by overwriting three times with a random pattern that is changed before each write).\ is changed before each write).\ \ \ ::: ::: ::: ::: ::: eacategory ::: eacategory Guidance Guidance ::: ::: ::: ea ::: ea ::: ea ::: ea The evaluator shall verify that the AGD guidance describes how to enable The evaluator shall verify that the AGD guidance describes how to enable encryption, if it is not enabled by default. Additionally the evaluator encryption, if it is not enabled by default. Additionally the evaluator shall verify that the AGD guidance describes how to initiate the wipe shall verify that the AGD guidance describes how to initiate the wipe command.\ command.\ \ \ ::: ::: ::: ::: ::: eacategory ::: eacategory Tests Tests ::: ::: ::: ea ::: ea ::: ea ::: ea **Evaluation Activity Note:** The following test may require the **Evaluation Activity Note:** The following test may require the developer to provide access to a test platform that provides the developer to provide access to a test platform that provides the evaluator with tools that are typically not found on consumer Mobile evaluator with tools that are typically not found on consumer Mobile Device products.\ Device products.\ \ \ []{.testlist-} []{.testlist-} - [Test FCS_CKM_EXT.5:1](#_t_8){#_t_8 .defined}: The evaluator shall - [Test FCS_CKM_EXT.5:1](#_t_8){#_t_8 .defined}: The evaluator shall perform one of the following tests. The test before and after the perform one of the following tests. The test before and after the wipe command shall be identical. This test shall be repeated for wipe command shall be identical. This test shall be repeated for each type of memory used to store the data to be protected.\ each type of memory used to store the data to be protected.\ \ \ []{.testlist-} []{.testlist-} - [Test FCS_CKM_EXT.5:1.1](#_t_9){#_t_9 .defined}: **For - [Test FCS_CKM_EXT.5:1.1](#_t_9){#_t_9 .defined}: **For File-based Methods:**\ File-based Methods:**\ The evaluator shall enable encryption according to the AGD The evaluator shall enable encryption according to the AGD guidance. The evaluator shall create a user data (protected data guidance. The evaluator shall create a user data (protected data or sensitive data) file, for example, by using an application. or sensitive data) file, for example, by using an application. The evaluator shall use a tool provided by the developer to The evaluator shall use a tool provided by the developer to examine this data stored in memory (for example, by examining a examine this data stored in memory (for example, by examining a decrypted files). The evaluator shall initiate the wipe command decrypted files). The evaluator shall initiate the wipe command according to the AGD guidance provided for according to the AGD guidance provided for [FMT_SMF_EXT.1](#FMT_SMF_EXT.1). The evaluator shall use a tool [FMT_SMF_EXT.1](#FMT_SMF_EXT.1). The evaluator shall use a tool provided by the developer to examine the same data location in provided by the developer to examine the same data location in memory to verify that the data has been wiped according to the memory to verify that the data has been wiped according to the method described in the [TSS](#abbr_TSS) (for example, the files method described in the [TSS](#abbr_TSS) (for example, the files are still encrypted and cannot be accessed). are still encrypted and cannot be accessed). - [Test FCS_CKM_EXT.5:1.2](#_t_10){#_t_10 .defined}: **For - [Test FCS_CKM_EXT.5:1.2](#_t_10){#_t_10 .defined}: **For Volume-based Methods:**\ Volume-based Methods:**\ The evaluator shall enable encryption according to the AGD The evaluator shall enable encryption according to the AGD guidance. The evaluator shall create a unique data string, for guidance. The evaluator shall create a unique data string, for example, by using an application. The evaluator shall use a tool example, by using an application. The evaluator shall use a tool provided by the developer to search decrypted data for the provided by the developer to search decrypted data for the unique string. The evaluator shall initiate the wipe command unique string. The evaluator shall initiate the wipe command according to the AGD guidance provided for according to the AGD guidance provided for [FMT_SMF_EXT.1](#FMT_SMF_EXT.1). The evaluator shall use a tool [FMT_SMF_EXT.1](#FMT_SMF_EXT.1). The evaluator shall use a tool provided by the developer to search for the same unique string provided by the developer to search for the same unique string in decrypted memory to verify that the data has been wiped in decrypted memory to verify that the data has been wiped according to the method described in the [TSS](#abbr_TSS) (for according to the method described in the [TSS](#abbr_TSS) (for example, the files are still encrypted and cannot be accessed). example, the files are still encrypted and cannot be accessed). - [Test FCS_CKM_EXT.5:2](#_t_11){#_t_11 .defined}: The evaluator shall - [Test FCS_CKM_EXT.5:2](#_t_11){#_t_11 .defined}: The evaluator shall cause the device to wipe and verify that the wipe concludes with a cause the device to wipe and verify that the wipe concludes with a power cycle. power cycle. ::: ::: ::: ::: ::: ::: ::: ::: ::: ::: ::: {#FCS_CKM_EXT.6 .comp} ::: {#FCS_CKM_EXT.6 .comp} #### FCS_CKM_EXT.6 Salt Generation #### FCS_CKM_EXT.6 Salt Generation ::: element ::: element ::: {#FCS_CKM_EXT.6.1 .reqid} ::: {#FCS_CKM_EXT.6.1 .reqid} [FCS_CKM_EXT.6.1](#FCS_CKM_EXT.6.1){.abbr} [FCS_CKM_EXT.6.1](#FCS_CKM_EXT.6.1){.abbr} ::: ::: ::: reqdesc ::: reqdesc The [TSF](#abbr_TSF) shall generate all salts using a DRBG that meets The [TSF](#abbr_TSF) shall generate all salts using a DRBG that meets [FCS_RBG.1](#FCS_RBG.1). [FCS_RBG.1](#FCS_RBG.1). ::: appnote ::: appnote [Application Note: ]{.note-header}[This requirement refers only to salt | [Application Note: ]{.note-header}[ This requirement refers only to salt generation. In the examples given, a salt may be used as part of the generation. In the examples given, a salt may be used as part of the scheme/algorithm. Requirements on nonces or ephemeral keys are provided scheme/algorithm. Requirements on nonces or ephemeral keys are provided elsewhere, if needed. The list below is provided for clarity, in order elsewhere, if needed. The list below is provided for clarity, in order to give examples of where the [TSF](#abbr_TSF) may be generating to give examples of where the [TSF](#abbr_TSF) may be generating cryptographic salts; it is not exhaustive nor is it intended to mandate cryptographic salts; it is not exhaustive nor is it intended to mandate implementation of all of these schemes/algorithms. Cryptographic salts implementation of all of these schemes/algorithms. Cryptographic salts are generated for various uses including: ]{.note} are generated for various uses including: ]{.note} - RSASSA-PSS signature generation - RSASSA-PSS signature generation - [DSA](#abbr_DSA) signature generation - [DSA](#abbr_DSA) signature generation - [ECDSA](#abbr_ECDSA) signature generation - [ECDSA](#abbr_ECDSA) signature generation - [DH](#abbr_DH) static key agreement scheme - [DH](#abbr_DH) static key agreement scheme - [PBKDF](#abbr_PBKDF) - [PBKDF](#abbr_PBKDF) - Key Agreement Scheme in [NIST](#abbr_NIST) SP 800-56B - Key Agreement Scheme in [NIST](#abbr_NIST) SP 800-56B - [AES](#abbr_AES) [GCM](#abbr_GCM) - [AES](#abbr_AES) [GCM](#abbr_GCM) ::: ::: ::: ::: ::: ::: ::: {.activity_pane .hide} ::: {.activity_pane .hide} ::: activity_pane_header ::: activity_pane_header [[ Evaluation Activities [[ Evaluation Activities ]{.activity_pane_label}[]{.toggler}](#){onclick="toggle(this);return false;"} ]{.activity_pane_label}[]{.toggler}](#){onclick="toggle(this);return false;"} ::: ::: ::: activity_pane_body ::: activity_pane_body ::: component-activity-header ::: component-activity-header [FCS_CKM_EXT.6](#FCS_CKM_EXT.6) [FCS_CKM_EXT.6](#FCS_CKM_EXT.6) ::: ::: ::: eacategory ::: eacategory [TSS](#abbr_TSS) [TSS](#abbr_TSS) ::: ::: ::: ea ::: ea ::: ea ::: ea The evaluator shall verify that the [TSS](#abbr_TSS) contains a The evaluator shall verify that the [TSS](#abbr_TSS) contains a description regarding the salt generation, including which algorithms on description regarding the salt generation, including which algorithms on the [TOE](#abbr_TOE) require salts. The evaluator shall confirm that the the [TOE](#abbr_TOE) require salts. The evaluator shall confirm that the salt is generated using a DRBG described in [FCS_RBG.1](#FCS_RBG.1). For salt is generated using a DRBG described in [FCS_RBG.1](#FCS_RBG.1). For [PBKDF](#abbr_PBKDF) derivation of KEKs, this evaluation activity may be [PBKDF](#abbr_PBKDF) derivation of KEKs, this evaluation activity may be performed in conjunction with [FCS_CKM_EXT.3.2](#FCS_CKM_EXT.3.2).\ performed in conjunction with [FCS_CKM_EXT.3.2](#FCS_CKM_EXT.3.2).\ \ \ ::: ::: ::: ::: ::: eacategory ::: eacategory Guidance Guidance ::: ::: ::: ea ::: ea ::: ea ::: ea There are no guidance evaluation activities for this component.\ There are no guidance evaluation activities for this component.\ \ \ ::: ::: ::: ::: ::: eacategory ::: eacategory Tests Tests ::: ::: ::: ea ::: ea ::: ea ::: ea There are no test evaluation activities for this component. There are no test evaluation activities for this component. ::: ::: ::: ::: ::: ::: ::: ::: ::: ::: ::: {#FCS_CKM_EXT.7/LOCKED .comp} ::: {#FCS_CKM_EXT.7/LOCKED .comp} #### FCS_CKM_EXT.7/LOCKED Cryptographic Key Establishment (When Locked) #### FCS_CKM_EXT.7/LOCKED Cryptographic Key Establishment (When Locked) ::: element ::: element ::: {#FCS_CKM_EXT.7.1/LOCKED .reqid} ::: {#FCS_CKM_EXT.7.1/LOCKED .reqid} [FCS_CKM_EXT.7.1/LOCKED](#FCS_CKM_EXT.7.1/LOCKED){.abbr} [FCS_CKM_EXT.7.1/LOCKED](#FCS_CKM_EXT.7.1/LOCKED){.abbr} ::: ::: ::: reqdesc ::: reqdesc The [TSF](#abbr_TSF) shall derive shared cryptographic keys with input The [TSF](#abbr_TSF) shall derive shared cryptographic keys with input from multiple parties in accordance with specified cryptographic key from multiple parties in accordance with specified cryptographic key agreement algorithms **for the purposes of encrypting sensitive data agreement algorithms **for the purposes of encrypting sensitive data received while the device is locked**. \[**selection**: [Cryptographic received while the device is locked**. \[**selection**: [Cryptographic Algorithm]{.selectable-content}\] and specified cryptographic parameters Algorithm]{.selectable-content}\] and specified cryptographic parameters \[**selection**: [Cryptographic Parameters]{.selectable-content}\] that \[**selection**: [Cryptographic Parameters]{.selectable-content}\] that meet the following: \[**selection**: [List of meet the following: \[**selection**: [List of Standards]{.selectable-content}\] . Standards]{.selectable-content}\] . [Table [Table [9]{.counter}](#fcs-ckm-ext-7-locked-sels){.fcs-ckm-ext-7-locked-sels-ref [9]{.counter}](#fcs-ckm-ext-7-locked-sels){.fcs-ckm-ext-7-locked-sels-ref onclick="showTarget('fcs-ckm-ext-7-locked-sels')"} provides the onclick="showTarget('fcs-ckm-ext-7-locked-sels')"} provides the allowable choices for completion of the selection operations of allowable choices for completion of the selection operations of [FCS_CKM_EXT.7/LOCKED](#FCS_CKM_EXT.7/LOCKED). [FCS_CKM_EXT.7/LOCKED](#FCS_CKM_EXT.7/LOCKED). +-----------------+-----------------+-----------------+-----------------+ +-----------------+-----------------+-----------------+-----------------+ | Identifier | Cryptographic | Cryptographic | List of | | Identifier | Cryptographic | Cryptographic | List of | | | Algorithm | Parameters | Standards | | | Algorithm | Parameters | Standards | +=================+=================+=================+=================+ +=================+=================+=================+=================+ | KAS2 | [ | Modulus size | [NI | | KAS2 | [ | Modulus size | [NI | | | RSA](#abbr_RSA) | \ | ST](#abbr_NIST) | | | RSA](#abbr_RSA) | \ | ST](#abbr_NIST) | | | | [**selection**: | SP 800-56B | | | | [**selection**: | SP 800-56B | | | | [3072]{#_s_130 | Revision 2 | | | | | [3 | Revision 2 | | | | .selec | (Section 8.3) | | | | | 072]{#fcs_ckm_e | (Section 8.3) | | | | table-content}, | \[KAS2\] | | | | | xt.7.1_LOCKED_1 | \[KAS2\] | | | | [4096]{#_s_131 | | | | | | .selec | | > | | | table-content}, | | > | | | [4 | | > | | | 096]{#fcs_ckm_e | | > | | | xt.7.1_LOCKED_2 | | | | | .selec | | | | | .selec | | | | | table-content}, | | | | | table-content}, | | | | | [6144]{#_s_132 | | | | | | [6 | | > | | | 144]{#fcs_ckm_e | | > | | | xt.7.1_LOCKED_3 | | | | | .selec | | | | | .selec | | | | | table-content}, | | | | | table-content}, | | | | | [8192]{#_s_133 | | | | | | [8 | | > | | | 192]{#fcs_ckm_e | | > | | | xt.7.1_LOCKED_4 | | | | | .select | | | | | .select | | | | | able-content}\] | | | | | able-content}\] | | | | | bits | | | | | bits | | +-----------------+-----------------+-----------------+-----------------+ +-----------------+-----------------+-----------------+-----------------+ | [DH](#abbr_DH) | Finite Field | Static domain | [NI | | [DH](#abbr_DH) | Finite Field | Static domain | [NI | | | Cryptography | parameters | ST](#abbr_NIST) | | | Cryptography | parameters | ST](#abbr_NIST) | | | Diffie-Hellman | approved for | SP 800-56A | | | Diffie-Hellman | approved for | SP 800-56A | | | | \ | Revision 3 | | | | \ | Revision 3 | | | | [**selection**: | (Section | | | | [**selection**: | (Section | | | | | 5.7.1.1) | | | | | 5.7.1.1) | | | | - [IKE Groups | \[[ | | | | - [IKE Groups | \[[ | | | | \ | DH](#abbr_DH)\] | | | | \ | DH](#abbr_DH)\] | | | | [**selection**: | | | | | [**selection**: | | | | | [MO | \ | | | | [MO | \ | | | | DP-3072]{#sel-k | [**selection**: | | | | DP-3072]{#sel-k | [**selection**: | | | | at-ffc-modp3072 | [RFC 3526 \[IKE | | | | at-ffc-modp3072 | [RFC 3526 \[IKE | | | | .selec | gr | | | | | .selec | group | | | | table-content}, | oups\]]{#_s_145 | | | | | table-content}, | s\]]{#fcs_ckm_e | | | | [MO | .selec | | | | | [MO | xt.7.1_LOCKED_7 | | | | DP-4096]{#sel-k | table-content}, | | | | | DP-4096]{#sel-k | .selec | | | | at-ffc-modp4096 | [RFC 7919 | | | | | at-ffc-modp4096 | table-content}, | | | | .selec | \[[ | | | | | .selec | [RFC 7919 | | | | table-content}, | TLS](#abbr_TLS) | | | | | table-content}, | \[[ | | | | [MO | gr | | | | | [MO | TLS](#abbr_TLS) | | | | DP-6144]{#sel-k | oups\]]{#_s_146 | | | | | DP-6144]{#sel-k | group | | | | at-ffc-modp6144 | .select | | | | | at-ffc-modp6144 | s\]]{#fcs_ckm_e | | | | .selec | able-content}\] | | | | | .selec | xt.7.1_LOCKED_8 | | | | table-content}, | | | | | | table-content}, | .select | | | | [MO | | | | | | [MO | able-content}\] | | | | DP-8192]{#sel-k | | | | | DP-8192]{#sel-k | | | | | at-ffc-modp8192 | | | | | at-ffc-modp8192 | | | | | . | | | | | | .sel | | | | | selectable-cont | | | | | | ectable-content | | | | | ent}\]]{#_s_135 | | | | | | }\]]{#fcs_ckm_e | | > | | | xt.7.1_LOCKED_5 | | | | | .sele | | | | | .sele | | | | | ctable-content} | | | | | ctable-content} | | | | | - [[ | | | | | - [[ | | | | | TLS](#abbr_TLS) | | | | | TLS](#abbr_TLS) | | | | | Groups | | | | | Groups | | | | | \ | | | | | \ | | | | | [**selection**: | | | | | [**selection**: | | | | | [ffd | | | | | [ffd | | | | | he3072]{#sel-ka | | | | | he3072]{#sel-ka | | | | | t-ffc-ffdhe3072 | | | | | t-ffc-ffdhe3072 | | | | | .selec | | | | | .selec | | | | | table-content}, | | | | | table-content}, | | | | | [ffd | | | | | [ffd | | | | | he4096]{#sel-ka | | | | | he4096]{#sel-ka | | | | | t-ffc-ffdhe4096 | | | | | t-ffc-ffdhe4096 | | | | | .selec | | | | | .selec | | | | | table-content}, | | | | | table-content}, | | | | | [ffd | | | | | [ffd | | | | | he6144]{#sel-ka | | | | | he6144]{#sel-ka | | | | | t-ffc-ffdhe6144 | | | | | t-ffc-ffdhe6144 | | | | | .selec | | | | | .selec | | | | | table-content}, | | | | | table-content}, | | | | | [ffd | | | | | [ffd | | | | | he8192]{#sel-ka | | | | | he8192]{#sel-ka | | | | | t-ffc-ffdhe8192 | | | | | t-ffc-ffdhe8192 | | | | | . | | | | | | .sel | | | | | selectable-cont | | | | | | ectable-content | | | | | ent}\]]{#_s_140 | | | | | | }\]]{#fcs_ckm_e | | > | | | xt.7.1_LOCKED_6 | | | | | .sele | | | | | .sele | | | | | ctable-content} | | | | | ctable-content} | | | | | | | | | | | | | | | \] | | | | | \] | | +-----------------+-----------------+-----------------+-----------------+ +-----------------+-----------------+-----------------+-----------------+ | [EC | Elliptic Curve | Elliptic Curve | [NI | | [EC | Elliptic Curve | Elliptic Curve | [NI | | DH](#abbr_ECDH) | Diffie-Hellman | \ | ST](#abbr_NIST) | | DH](#abbr_ECDH) | Diffie-Hellman | \ | ST](#abbr_NIST) | | | | [**selection**: | SP 800-56A | | | | [**selection**: | SP 800-56A | | | | [P-384]{#sel-ex | Revision 3 | | | | [P-384]{#sel-ex | Revision 3 | | | | p-kat-ecdh-P384 | (Section | | | | p-kat-ecdh-P384 | (Section | | | | .selec | 5.7.1.2) | | | | .selec | 5.7.1.2) | | | | table-content}, | \[[ECDH | | | | table-content}, | \[[ECDH | | | | [P-521]{#sel-ex | ](#abbr_ECDH)\] | | | | [P-521]{#sel-ex | ](#abbr_ECDH)\] | | | | p-kat-ecdh-P521 | | | | | p-kat-ecdh-P521 | | | | | .select | [NI | | | | .select | [NI | | | | able-content}\] | ST](#abbr_NIST) | | | | able-content}\] | ST](#abbr_NIST) | | | | | SP 800-186 | | | | | SP 800-186 | | | | | (Section 3.2.1) | | | | | (Section 3.2.1) | | | | | \[[NI | | | | | \[[NI | | | | | ST](#abbr_NIST) | | | | | ST](#abbr_NIST) | | | | | Curves\] | | | | | Curves\] | +-----------------+-----------------+-----------------+-----------------+ +-----------------+-----------------+-----------------+-----------------+ | [ECDH] | [EC | Domain | RFC 7748 | | [ECDH] | [EC | Domain | RFC 7748 | | (#abbr_ECDH)-Ed | DH](#abbr_ECDH) | parameters | (Section 5) | | (#abbr_ECDH)-Ed | DH](#abbr_ECDH) | parameters | (Section 5) | | | with Montgomery | approved for | \[[ECDH](# | | | with Montgomery | approved for | \[[ECDH](# | | | Curves | elliptic curves | abbr_ECDH)-Ed\] | | | Curves | elliptic curves | abbr_ECDH)-Ed\] | | | | \ | | | | | \ | | | | | [*curve25519*\] | [NI | | | | [*curve25519*\] | [NI | | | | | ST](#abbr_NIST) | | | | | ST](#abbr_NIST) | | | | | SP 800-186 | | | | | SP 800-186 | | | | | (Section 3.2.2) | | | | | (Section 3.2.2) | | | | | \[Montgomery | | | | | \[Montgomery | | | | | Curves\] | | | | | Curves\] | +-----------------+-----------------+-----------------+-----------------+ +-----------------+-----------------+-----------------+-----------------+ : [Table [9]{.counter}]{#fcs-ckm-ext-7-locked-sels .ctr : [Table [9]{.counter}]{#fcs-ckm-ext-7-locked-sels .ctr myid="fcs-ckm-ext-7-locked-sels" counter-type="ct-Table"}: Allowable myid="fcs-ckm-ext-7-locked-sels" counter-type="ct-Table"}: Allowable choices for [FCS_CKM_EXT.7/LOCKED](#FCS_CKM_EXT.7/LOCKED) choices for [FCS_CKM_EXT.7/LOCKED](#FCS_CKM_EXT.7/LOCKED) ::: appnote ::: appnote [Application Note: ]{.note-header}[ This [SFR](#abbr_SFR) defines the | [Application Note: ]{.note-header}[This [SFR](#abbr_SFR) defines the asymmetric key scheme used to protect data at rest as defined by asymmetric key scheme used to protect data at rest as defined by [FDP_DAR_EXT.2.2](#FDP_DAR_EXT.2.2).]{.note} [FDP_DAR_EXT.2.2](#FDP_DAR_EXT.2.2).]{.note} ::: ::: ::: ::: ::: ::: ::: {.activity_pane .hide} ::: {.activity_pane .hide} ::: activity_pane_header ::: activity_pane_header [[ Evaluation Activities [[ Evaluation Activities ]{.activity_pane_label}[]{.toggler}](#){onclick="toggle(this);return false;"} ]{.activity_pane_label}[]{.toggler}](#){onclick="toggle(this);return false;"} ::: ::: ::: activity_pane_body ::: activity_pane_body ::: component-activity-header ::: component-activity-header [FCS_CKM_EXT.7/LOCKED](#FCS_CKM_EXT.7/LOCKED) [FCS_CKM_EXT.7/LOCKED](#FCS_CKM_EXT.7/LOCKED) ::: ::: ::: eacategory ::: eacategory [TSS](#abbr_TSS) [TSS](#abbr_TSS) ::: ::: ::: ea ::: ea ::: ea ::: ea The evaluator shall ensure that the [TSS](#abbr_TSS) documents that the The evaluator shall ensure that the [TSS](#abbr_TSS) documents that the security strength of the material contributed by the [TOE](#abbr_TOE) is security strength of the material contributed by the [TOE](#abbr_TOE) is sufficient for the security strength of the key and the agreement sufficient for the security strength of the key and the agreement method. method. ::: ::: ::: ::: ::: eacategory ::: eacategory Guidance Guidance ::: ::: ::: ea ::: ea ::: ea ::: ea There are no additional guidance evaluation activities for this There are no additional guidance evaluation activities for this component.\ component.\ \ \ ::: ::: ::: ::: ::: eacategory ::: eacategory Tests Tests ::: ::: ::: ea ::: ea ::: ea ::: ea The following tests are conditional based upon the selections made in The following tests are conditional based upon the selections made in the [SFR](#abbr_SFR). The evaluator shall perform the following test or the [SFR](#abbr_SFR). The evaluator shall perform the following test or witness respective tests executed by the developer. The tests must be witness respective tests executed by the developer. The tests must be executed on a platform that is as close as practically possible to the executed on a platform that is as close as practically possible to the operational platform (but which may be instrumented in terms of, for operational platform (but which may be instrumented in terms of, for example, use of a debug mode). Where the test is not carried out on the example, use of a debug mode). Where the test is not carried out on the [TOE](#abbr_TOE) itself, the test platform shall be identified and the [TOE](#abbr_TOE) itself, the test platform shall be identified and the differences between test environment and [TOE](#abbr_TOE) execution differences between test environment and [TOE](#abbr_TOE) execution environment shall be described. | environment shall be described.\ < \ < **KAS2** **KAS2** ------------ ------------------------- -------------------------------------------- ------------ ------------------------- -------------------------------------------- Identifier Cryptographic Algorithm Cryptographic Parameters Identifier Cryptographic Algorithm Cryptographic Parameters KAS2 [RSA](#abbr_RSA) Modulus Size \[**selection:** 3072, 4096, 61 KAS2 [RSA](#abbr_RSA) Modulus Size \[**selection:** 3072, 4096, 61 ------------ ------------------------- -------------------------------------------- ------------ ------------------------- -------------------------------------------- To test the [TOE](#abbr_TOE)'s implementation of the of the KAS2 To test the [TOE](#abbr_TOE)'s implementation of the of the KAS2 [RSA](#abbr_RSA) Key Agreement scheme, the evaluator shall perform the [RSA](#abbr_RSA) Key Agreement scheme, the evaluator shall perform the Algorithm Functional Test and Validation Test using the following input Algorithm Functional Test and Validation Test using the following input parameters: parameters: - [RSA](#abbr_RSA) Private key format \[Basic, Prime Factor, Chinese - [RSA](#abbr_RSA) Private key format \[Basic, Prime Factor, Chinese Remainder Theorem\] Remainder Theorem\] - Modulo value \[3072, 4096, 6144, 8192\] - Modulo value \[3072, 4096, 6144, 8192\] - Role \[initiator, responder\] - Role \[initiator, responder\] The evaluator shall generate a test group (i.e., set of tests) for each The evaluator shall generate a test group (i.e., set of tests) for each parameter value of the above parameter type with the largest number of parameter value of the above parameter type with the largest number of supported values. For example, if the [TOE](#abbr_TOE) supports all five supported values. For example, if the [TOE](#abbr_TOE) supports all five Modulo values, then the evaluator shall generate five test groups. Each Modulo values, then the evaluator shall generate five test groups. Each of the above supported parameter values must be included in at least one of the above supported parameter values must be included in at least one test group. | test group. Regardless of how many parameter values are supported, there | must be at least two test groups. Half of the test groups are designated Regardless of how many parameter values are supported, there must be at | as Algorithm Functional Tests (AFT) and the remainder are designated as least two test groups. | Validation Tests (VAT). If there is an odd number of groups, then the | extra group is designated randomly as either AFT or VAT.\ Half of the test groups are designated as Algorithm Functional Tests < (AFT) and the remainder are designated as Validation Tests (VAT). If < there is an odd number of groups, then the extra group is designated < randomly as either AFT or VAT. < < \ < ***Algorithm Functional Test***\ ***Algorithm Functional Test***\ For each test group designated as AFT, the evaluator shall generate 10 For each test group designated as AFT, the evaluator shall generate 10 test cases using random data (except for a fixed public exponent, if test cases using random data (except for a fixed public exponent, if supported). The resulting shared secrets shall be compared with those supported). The resulting shared secrets shall be compared with those generated by a known-good implementation using the same inputs. | generated by a known-good implementation using the same inputs.\ < \ < ***Validation Test***\ ***Validation Test***\ For each test group designated as VAT, the evaluator shall generate 25 For each test group designated as VAT, the evaluator shall generate 25 test cases are using random data (except for a fixed public exponent, if test cases are using random data (except for a fixed public exponent, if supported). Of the 25 test cases: supported). Of the 25 test cases: - Two test cases must have a shared secret with a leading nibble of - Two test cases must have a shared secret with a leading nibble of 0s, 0s, - Two test cases have modified derived key material, - Two test cases have modified derived key material, - Two test cases have modified tags, if key confirmation is supported, - Two test cases have modified tags, if key confirmation is supported, - Two test cases have modified MACs, if key confirmation is supported, - Two test cases have modified MACs, if key confirmation is supported, and and - The remaining test cases are not modified. - The remaining test cases are not modified. To determine correctness, the evaluator shall confirm that the resulting To determine correctness, the evaluator shall confirm that the resulting 25 shared secrets correspond as expected for both the modified and 25 shared secrets correspond as expected for both the modified and unmodified values. | unmodified values.\ < \ < **[FFC](#abbr_FFC) Diffie-Hellman Key Agreement** **[FFC](#abbr_FFC) Diffie-Hellman Key Agreement** ----------------- ----------------- ------------------ -------------------- ----------------- ----------------- ------------------ -------------------- Identifier Cryptographic Cryptographic List of Standards Identifier Cryptographic Cryptographic List of Standards Algorithm Parameters Algorithm Parameters [DH](#abbr_DH) Finite Field Static domain [NIST](#abbr_NIST) [DH](#abbr_DH) Finite Field Static domain [NIST](#abbr_NIST) Cryptography parameters SP 800-56A Revision Cryptography parameters SP 800-56A Revision Diffie-Hellman approved for 3 (Section 5.7.1.1) Diffie-Hellman approved for 3 (Section 5.7.1.1) \[**selection:** \[[DH](#abbr_DH)\] \[**selection:** \[[DH](#abbr_DH)\] IKE groups IKE groups \[**selection:** \[**selection:** RFC \[**selection:** \[**selection:** RFC MODP-3072, 3526 \[IKE Groups\], MODP-3072, 3526 \[IKE Groups\], MODP-4096, RFC 7919 MODP-4096, RFC 7919 MODP-6144, \[[TLS](#abbr_TLS) MODP-6144, \[[TLS](#abbr_TLS) MODP-8192\], Groups\]\] MODP-8192\], Groups\]\] [TLS](#abbr_TLS) [TLS](#abbr_TLS) groups groups \[**selection:** \[**selection:** ffdhe3072, ffdhe3072, ffdhe4096, ffdhe4096, ffdhe6144, ffdhe6144, ffdhe8192\]\] ffdhe8192\]\] ----------------- ----------------- ------------------ -------------------- ----------------- ----------------- ------------------ -------------------- To test the [TOE](#abbr_TOE)'s implementation of [FFC](#abbr_FFC) To test the [TOE](#abbr_TOE)'s implementation of [FFC](#abbr_FFC) Diffie-Hellman Key Agreement, the evaluator shall perform the Algorithm Diffie-Hellman Key Agreement, the evaluator shall perform the Algorithm Functional Test and Validation Test using the following input Functional Test and Validation Test using the following input parameters: parameters: - Domain Parameter Group \[MODP-3072, MODP-4096, MODP-6144, MODP-8192, - Domain Parameter Group \[MODP-3072, MODP-4096, MODP-6144, MODP-8192, ffdhe3072, ffdhe4096, ffdhe6144, ffdhe8192\] ffdhe3072, ffdhe4096, ffdhe6144, ffdhe8192\] \ \ ***Algorithm Functional Test***\ ***Algorithm Functional Test***\ For each supported domain parameter group, the evaluator shall generate For each supported domain parameter group, the evaluator shall generate 10 test cases by generating the initiator and responder secret keys 10 test cases by generating the initiator and responder secret keys using random data, calculating the responder public key, and creating using random data, calculating the responder public key, and creating the shared secret. The resulting shared secrets shall be compared with the shared secret. The resulting shared secrets shall be compared with those generated by a known-good implementation using the same inputs. | those generated by a known-good implementation using the same inputs.\ < \ < ***Validation Test***\ ***Validation Test***\ For each supported combination of the above parameters the evaluator For each supported combination of the above parameters the evaluator shall generate 15 Diffie Hellman initiator/responder key pairs using the shall generate 15 Diffie Hellman initiator/responder key pairs using the key generation function of a known-good implementation. For each set of key generation function of a known-good implementation. For each set of key pairs, the evaluator shall modify five initiator private key values. key pairs, the evaluator shall modify five initiator private key values. The remaining key values are left unchanged (i.e., correct). To The remaining key values are left unchanged (i.e., correct). To determine correctness, the evaluator shall confirm that the 15 shared determine correctness, the evaluator shall confirm that the 15 shared secrets correspond as expected for both the modified and unmodified secrets correspond as expected for both the modified and unmodified inputs. | inputs.\ < \ < **Elliptic Curve Diffie-Hellman Key Agreement** **Elliptic Curve Diffie-Hellman Key Agreement** -------------------- ----------------- ------------------ ------------------------ -------------------- ----------------- ------------------ ------------------------ Identifier Cryptographic Cryptographic List of Standards Identifier Cryptographic Cryptographic List of Standards Algorithm Parameters Algorithm Parameters [ECDH](#abbr_ECDH) Elliptic Curve Elliptic Curve [NIST](#abbr_NIST) SP [ECDH](#abbr_ECDH) Elliptic Curve Elliptic Curve [NIST](#abbr_NIST) SP Diffie-Hellman \[**selection:** 800-56A Revision 3 Diffie-Hellman \[**selection:** 800-56A Revision 3 P-384, P-521\] (Section 5.7.1.2) P-384, P-521\] (Section 5.7.1.2) \[[ECDH](#abbr_ECDH)\] \[[ECDH](#abbr_ECDH)\] [NIST](#abbr_NIST) SP [NIST](#abbr_NIST) SP 800-186 (Section 3.2.1) 800-186 (Section 3.2.1) \[[NIST](#abbr_NIST) \[[NIST](#abbr_NIST) Curves\] Curves\] -------------------- ----------------- ------------------ ------------------------ -------------------- ----------------- ------------------ ------------------------ To test the [TOE](#abbr_TOE)'s implementation of Elliptic Curve To test the [TOE](#abbr_TOE)'s implementation of Elliptic Curve Diffie-Hellman Key Agreement, the evaluator shall perform the Algorithm Diffie-Hellman Key Agreement, the evaluator shall perform the Algorithm Functional Test and Validation Test using the following input Functional Test and Validation Test using the following input parameters: parameters: - Elliptic Curve \[P-384, P-521\] - Elliptic Curve \[P-384, P-521\] \ \ ***Algorithm Functional Test***\ ***Algorithm Functional Test***\ For each supported Elliptic Curve the evaluator shall generate 10 test For each supported Elliptic Curve the evaluator shall generate 10 test cases by generating the initiator and responder secret keys using random cases by generating the initiator and responder secret keys using random data, calculating the responder public key, and creating the shared data, calculating the responder public key, and creating the shared secret. The resulting shared secrets shall be compared with those secret. The resulting shared secrets shall be compared with those generated by a known-good implementation using the same inputs. | generated by a known-good implementation using the same inputs.\ < \ < ***Validation Test***\ ***Validation Test***\ For each supported Elliptic Curve the evaluator shall generate 15 Diffie For each supported Elliptic Curve the evaluator shall generate 15 Diffie Hellman initiator/responder key pairs using the key generation function Hellman initiator/responder key pairs using the key generation function of a known-good implementation. For each set of key pairs, the evaluator of a known-good implementation. For each set of key pairs, the evaluator shall modify five initiator private key values. The remaining key values shall modify five initiator private key values. The remaining key values are left unchanged (i.e., correct). To determine correctness, the are left unchanged (i.e., correct). To determine correctness, the evaluator shall confirm that the 15 shared secrets correspond as evaluator shall confirm that the 15 shared secrets correspond as expected for the modified and unmodified values.\ expected for the modified and unmodified values.\ **Curve25519 Key Establishment Schemes** **Curve25519 Key Establishment Schemes** ----------------------- -------------------- ------------------ ------------------- ----------------------- -------------------- ------------------ ------------------- Identifier Cryptographic Cryptographic List of Standards Identifier Cryptographic Cryptographic List of Standards Algorithm Parameters Algorithm Parameters [ECDH](#abbr_ECDH)-Ed [ECDH](#abbr_ECDH) Domain parameters RFC 7748 (Section 5 [ECDH](#abbr_ECDH)-Ed [ECDH](#abbr_ECDH) Domain parameters RFC 7748 (Section 5 with Montgomery approved for \[[ECDH](#abbr_ECDH with Montgomery approved for \[[ECDH](#abbr_ECDH Curves elliptic curves Curves elliptic curves \[*curve25519*\] [NIST](#abbr_NIST) \[*curve25519*\] [NIST](#abbr_NIST) 800-186 (Section 3. 800-186 (Section 3. \[Montgomery Curves \[Montgomery Curves ----------------------- -------------------- ------------------ ------------------- ----------------------- -------------------- ------------------ ------------------- \ \ ***Curve25519 Key Establishment Schemes***\ ***Curve25519 Key Establishment Schemes***\ The evaluator shall verify a [TOE](#abbr_TOE)\'s implementation of the The evaluator shall verify a [TOE](#abbr_TOE)\'s implementation of the key agreement scheme using the following Function and Validity tests. key agreement scheme using the following Function and Validity tests. These validation tests for each key agreement scheme verify that a These validation tests for each key agreement scheme verify that a [TOE](#abbr_TOE) has implemented the components of the key agreement [TOE](#abbr_TOE) has implemented the components of the key agreement scheme according to the specification. These components include the scheme according to the specification. These components include the calculation of the shared secret K and the hash of K. | calculation of the shared secret K and the hash of K.\ < \ < ***Function Test***\ ***Function Test***\ The Function test verifies the ability of the [TOE](#abbr_TOE) to The Function test verifies the ability of the [TOE](#abbr_TOE) to implement the key agreement schemes correctly. To conduct this test the implement the key agreement schemes correctly. To conduct this test the evaluator shall generate or obtain test vectors from a known good evaluator shall generate or obtain test vectors from a known good implementation of the [TOE](#abbr_TOE) supported schemes. For each implementation of the [TOE](#abbr_TOE) supported schemes. For each supported key agreement role and hash function combination, the tester supported key agreement role and hash function combination, the tester shall generate 10 sets of public keys. These keys are static, ephemeral shall generate 10 sets of public keys. These keys are static, ephemeral or both depending on the scheme being tested. | or both depending on the scheme being tested. The evaluator shall obtain | the shared secret value K, and the hash of K. The evaluator shall verify The evaluator shall obtain the shared secret value K, and the hash of K. | the correctness of the [TSF](#abbr_TSF)'s implementation of a given | scheme by using a known good implementation to calculate the shared The evaluator shall verify the correctness of the [TSF](#abbr_TSF)'s | secret value K and compare the hash generated from this value.\ implementation of a given scheme by using a known good implementation to < calculate the shared secret value K and compare the hash generated from < this value. < < \ < ***Validation Test***\ ***Validation Test***\ The Validity test verifies the ability of the [TOE](#abbr_TOE) to The Validity test verifies the ability of the [TOE](#abbr_TOE) to recognize another party's valid and invalid key agreement results. To recognize another party's valid and invalid key agreement results. To conduct this test, the evaluator generates a set of 30 test vectors conduct this test, the evaluator generates a set of 30 test vectors consisting of data sets including the evaluator's public keys and the consisting of data sets including the evaluator's public keys and the [TOE](#abbr_TOE)'s public/private key pairs. | [TOE](#abbr_TOE)'s public/private key pairs. The evaluator shall inject | an error in some of the test vectors to test that the [TOE](#abbr_TOE) The evaluator shall inject an error in some of the test vectors to test | recognizes invalid key agreement results caused by the following fields that the [TOE](#abbr_TOE) recognizes invalid key agreement results | being incorrect: the shared secret value K or the hash of K. At least caused by the following fields being incorrect: the shared secret value | two of the test vectors shall remain unmodified and therefore should K or the hash of K. At least two of the test vectors shall remain | result in valid key agreement results (they should pass). The unmodified and therefore should result in valid key agreement results | [TOE](#abbr_TOE) shall use these modified test vectors to emulate the (they should pass). | key agreement scheme using the corresponding parameters. The evaluator | shall compare the [TOE](#abbr_TOE)'s results with the results using a The [TOE](#abbr_TOE) shall use these modified test vectors to emulate | known good implementation verifying that the [TOE](#abbr_TOE) detects the key agreement scheme using the corresponding parameters. The | these errors. evaluator shall compare the [TOE](#abbr_TOE)'s results with the results < using a known good implementation verifying that the [TOE](#abbr_TOE) < detects these errors. < ::: ::: ::: ::: ::: ::: ::: ::: ::: ::: ::: {#FCS_CKM_EXT.8 .comp} ::: {#FCS_CKM_EXT.8 .comp} #### FCS_CKM_EXT.8 Password-Based Key Derivation #### FCS_CKM_EXT.8 Password-Based Key Derivation ::: element ::: element ::: {#FCS_CKM_EXT.8.1 .reqid} ::: {#FCS_CKM_EXT.8.1 .reqid} [FCS_CKM_EXT.8.1](#FCS_CKM_EXT.8.1){.abbr} [FCS_CKM_EXT.8.1](#FCS_CKM_EXT.8.1){.abbr} ::: ::: ::: reqdesc ::: reqdesc The [TSF](#abbr_TSF) shall perform password-based key derivation The [TSF](#abbr_TSF) shall perform password-based key derivation functions in accordance with a specified cryptographic algorithm functions in accordance with a specified cryptographic algorithm \[[HMAC](#abbr_HMAC)-\[**selection**: [[SHA](#abbr_SHA)-384]{#_s_168 | \[[HMAC](#abbr_HMAC)- \[**selection**: .selectable-content}, [[SHA](#abbr_SHA)-512]{#_s_169 | [[SHA](#abbr_SHA)-384]{#fcs_ckm_ext.8.1_1 .selectable-content}, .selectable-content}\], with iteration count of \[**assignment**: | [[SHA](#abbr_SHA)-512]{#fcs_ckm_ext.8.1_2 .selectable-content}\], with [number of iterations]{.assignable-content}\] using a randomly generated | iteration count of \[**assignment**: [number of salt of length \[**assignment**: [equal to or greater than | iterations]{.assignable-content}\] using a randomly generated salt of > length \[**assignment**: [equal to or greater than 128]{.assignable-content}\] and output cryptographic key sizes 128]{.assignable-content}\] and output cryptographic key sizes \[**selection**: [256]{#_s_170 .selectable-content}, [384]{#_s_171 | \[**selection**: [256]{#fcs_ckm_ext.8.1_5 .selectable-content}, .selectable-content}, [512]{#_s_172 .selectable-content}\] bits that | [384]{#fcs_ckm_ext.8.1_6 .selectable-content}, [512]{#fcs_ckm_ext.8.1_7 meet the following standard: \[[NIST](#abbr_NIST) SP 800-132 (Section | .selectable-content}\] bits that meet the following standard: 5.3) \[PBKDF2\]\]. | \[[NIST](#abbr_NIST) SP 800-132 (Section 5.3) \[PBKDF2\]\]. ::: appnote ::: appnote [Application Note: ]{.note-header}[ [NIST](#abbr_NIST) recommends a [Application Note: ]{.note-header}[ [NIST](#abbr_NIST) recommends a minimum "number of iterations" of 1000 but prefers the largest number minimum "number of iterations" of 1000 but prefers the largest number feasible given performance constraints.]{.note} | feasible given performance constraints. ]{.note} [NIST](#abbr_NIST) recommends that the randomly generated portion of the [NIST](#abbr_NIST) recommends that the randomly generated portion of the salt have length of at least 128 bits and must be derived from Random salt have length of at least 128 bits and must be derived from Random Bit Generation. Bit Generation. If this [SFR](#abbr_SFR) is claimed, then If this [SFR](#abbr_SFR) is claimed, then [FCS_COP.1/KeyedHash](#FCS_COP.1/KeyedHash) and [FCS_RBG.1](#FCS_RBG.1) [FCS_COP.1/KeyedHash](#FCS_COP.1/KeyedHash) and [FCS_RBG.1](#FCS_RBG.1) must also be claimed. must also be claimed. ::: ::: ::: ::: ::: ::: ::: {.activity_pane .hide} ::: {.activity_pane .hide} ::: activity_pane_header ::: activity_pane_header [[ Evaluation Activities [[ Evaluation Activities ]{.activity_pane_label}[]{.toggler}](#){onclick="toggle(this);return false;"} ]{.activity_pane_label}[]{.toggler}](#){onclick="toggle(this);return false;"} ::: ::: ::: activity_pane_body ::: activity_pane_body ::: component-activity-header ::: component-activity-header [FCS_CKM_EXT.8](#FCS_CKM_EXT.8) [FCS_CKM_EXT.8](#FCS_CKM_EXT.8) ::: ::: ::: eacategory ::: eacategory [TSS](#abbr_TSS) [TSS](#abbr_TSS) ::: ::: ::: ea ::: ea ::: ea ::: ea The evaluator shall verify that the [TSS](#abbr_TSS) documents that the The evaluator shall verify that the [TSS](#abbr_TSS) documents that the selection of the keyed hash algorithm, iteration count, length of salt, selection of the keyed hash algorithm, iteration count, length of salt, and other mitigations are sufficient for the security strength of the and other mitigations are sufficient for the security strength of the key derived. key derived. The evaluator shall examine the [TSS](#abbr_TSS) to verify that the salt The evaluator shall examine the [TSS](#abbr_TSS) to verify that the salt is generated in accordance with the relevant specification. is generated in accordance with the relevant specification. The evaluator shall examine the [TSS](#abbr_TSS) to determine whether The evaluator shall examine the [TSS](#abbr_TSS) to determine whether the [TOE](#abbr_TOE) implements other mitigations against the [TOE](#abbr_TOE) implements other mitigations against password-exhaustion attacks. Examples include the use of interface-based password-exhaustion attacks. Examples include the use of interface-based mitigations and secret salts. mitigations and secret salts. ::: ::: ::: ::: ::: eacategory ::: eacategory Guidance Guidance ::: ::: ::: ea ::: ea There are no additional Guidance evaluation activities for this There are no additional Guidance evaluation activities for this component.\ component.\ ::: ::: ::: eacategory ::: eacategory Tests Tests ::: ::: ::: ea ::: ea ::: ea ::: ea The following tests are conditional based upon the selections made in The following tests are conditional based upon the selections made in the [SFR](#abbr_SFR). The evaluator shall perform the following test or the [SFR](#abbr_SFR). The evaluator shall perform the following test or witness respective tests executed by the developer. The tests must be witness respective tests executed by the developer. The tests must be executed on a platform that is as close as practically possible to the executed on a platform that is as close as practically possible to the operational platform (but which may be instrumented in terms of, for operational platform (but which may be instrumented in terms of, for example, use of a debug mode). Where the test is not carried out on the example, use of a debug mode). Where the test is not carried out on the [TOE](#abbr_TOE) itself, the test platform shall be identified and the [TOE](#abbr_TOE) itself, the test platform shall be identified and the differences between test environment and [TOE](#abbr_TOE) execution differences between test environment and [TOE](#abbr_TOE) execution environment shall be described. | environment shall be described. To test the [TOE](#abbr_TOE)'s ability | to derive cryptographic keys from a password using PBKDF2 the evaluator To test the [TOE](#abbr_TOE)'s ability to derive cryptographic keys from | shall perform the Algorithm Functional Test using the following input a password using PBKDF2 the evaluator shall perform the Algorithm | parameters: Functional Test using the following input parameters: < - [HMAC](#abbr_HMAC) algorithms \[[SHA](#abbr_SHA)-384, - [HMAC](#abbr_HMAC) algorithms \[[SHA](#abbr_SHA)-384, [SHA](#abbr_SHA)-512\] [SHA](#abbr_SHA)-512\] - Iteration count \[1-10000000\] - Iteration count \[1-10000000\] - Derived Key size \[256, 384, 512\] bits - Derived Key size \[256, 384, 512\] bits - Password length \[8-128\] bytes - Password length \[8-128\] bytes - Salt length \[128-4096\] bits in multiples of 8. - Salt length \[128-4096\] bits in multiples of 8. \ \ **Algorithm Functional Test** | **Algorithm Functional Test** For each supported [HMAC](#abbr_HMAC) | algorithm, the evaluator shall generate 50 test cases using supported For each supported [HMAC](#abbr_HMAC) algorithm, the evaluator shall | values for the above parameters such that generate 50 test cases using supported values for the above parameters < such that < - All supported derived key sizes are tested at least 10 times, - All supported derived key sizes are tested at least 10 times, - Iteration counts are random values between the supported minimum and - Iteration counts are random values between the supported minimum and maximum values, with the supported minimum and maximum tested at maximum values, with the supported minimum and maximum tested at least once each, least once each, - Passwords are random byte strings representing upper- and lower-case - Passwords are random byte strings representing upper- and lower-case letters of random supported lengths such that the minimum and letters of random supported lengths such that the minimum and maximum lengths are tested at least once, and maximum lengths are tested at least once, and - Salts are random values between the supported minimum and maximum - Salts are random values between the supported minimum and maximum lengths such that the supported minimum and maximum lengths are both lengths such that the supported minimum and maximum lengths are both tested at least once. tested at least once. The evaluator shall compare the resulting keys from each test case with The evaluator shall compare the resulting keys from each test case with keys derived using a known-good implementation with the same input keys derived using a known-good implementation with the same input parameters. parameters. ::: ::: ::: ::: ::: ::: ::: ::: ::: ::: ::: {#FCS_COP.1/AEAD .comp} ::: {#FCS_COP.1/AEAD .comp} #### FCS_COP.1/AEAD Cryptographic Operation -- Authenticated Encryption with Associat #### FCS_COP.1/AEAD Cryptographic Operation -- Authenticated Encryption with Associat ::: element ::: element ::: {#FCS_COP.1.1/AEAD .reqid} ::: {#FCS_COP.1.1/AEAD .reqid} [FCS_COP.1.1/AEAD](#FCS_COP.1.1/AEAD){.abbr} [FCS_COP.1.1/AEAD](#FCS_COP.1.1/AEAD){.abbr} ::: ::: ::: reqdesc ::: reqdesc The [TSF](#abbr_TSF) shall perform \[*authenticated encryption with The [TSF](#abbr_TSF) shall perform \[*authenticated encryption with associated data*\] in accordance with a specified cryptographic associated data*\] in accordance with a specified cryptographic algorithm \[**selection**: [Cryptographic algorithm \[**selection**: [Cryptographic algorithm]{.selectable-content}\] and cryptographic key sizes algorithm]{.selectable-content}\] and cryptographic key sizes \[**selection**: [Cryptographic key sizes]{.selectable-content}\] that \[**selection**: [Cryptographic key sizes]{.selectable-content}\] that meet the following: \[**selection**: [List of meet the following: \[**selection**: [List of standards]{.selectable-content}\] . standards]{.selectable-content}\] . [Table [10]{.counter}](#fcs-cop-aead-sels){.fcs-cop-aead-sels-ref [Table [10]{.counter}](#fcs-cop-aead-sels){.fcs-cop-aead-sels-ref onclick="showTarget('fcs-cop-aead-sels')"} provides the allowable onclick="showTarget('fcs-cop-aead-sels')"} provides the allowable choices for completion of the selection operations of choices for completion of the selection operations of [FCS_COP.1/AEAD](#FCS_COP.1/AEAD). [FCS_COP.1/AEAD](#FCS_COP.1/AEAD). ----------------------------------------------------------------------------------- | ----------------------------------------------------------------------------------- Identifier Cryptographic algorithm Cryptographic key sizes List of s | Identifier Cryptographic algorithm Cryptographic key size ---------------------- ------------------------- ------------------------ --------- | ---------------------- ------------------------------------- ---------------------- [AES](#abbr_AES)-CCM [AES](#abbr_AES) in \[**selection**: [128 \[**selec | [AES](#abbr_AES)-CCM [AES](#abbr_AES) in [CCM](#abbr_CCM) \[**selection**: [128 [CCM](#abbr_CCM) mode bits]{#_s_174 [ISO/IEC | mode with unpredictable, bits]{#fcs_cop.1.1_AEA with unpredictable, .selectable-content}, (Subclaus | non-repeating nonce, minimum size of .selectable-content}, non-repeating nonce, [256 bits]{#_s_175 .selectab | 64 bits bits]{#fcs_cop.1.1_AEA minimum size of 64 bits .selectable-content}\] [[FIPS](# | .selectable-content}\] 197]{#_s_ | .selectab | \[[AES](# | | \[**selec | [ISO/IEC | (Clause 7 | .selectab | [[NIST](# | 800-38C]{ | .selectab | \[[CCM](# | | [AES](#abbr_AES)-GCM [AES](#abbr_AES) in 256 bits \[**selec | [AES](#abbr_AES)-GCM [AES](#abbr_AES) in [GCM](#abbr_GCM) 256 bits [GCM](#abbr_GCM) mode [ISO/IEC | mode with non-repeating IVs using with non-repeating IVs (Subclaus | \[**selection**: using \[**selection**: .selectab | [deterministic]{#fcs_cop.1.1_AEAD_7 [deterministic]{#_s_181 [[FIPS](# | .selectable-content}, .selectable-content}, 197]{#_s_ | [DRBG-based]{#fcs_cop.1.1_AEAD_8 [DRBG-based]{#_s_182 .selectab | .selectable-content}\], IV .selectable-content}\], \[[AES](# | construction; the tag must be of IV construction; the tag | length \[**selection**: must be of length \[**selec | [96]{#fcs_cop.1.1_AEAD_9 \[**selection**: [ISO/IEC | .selectable-content}, [96]{#_s_183 (Clause 1 | [104]{#fcs_cop.1.1_AEAD_10 .selectable-content}, .selectab | .selectable-content}, [104]{#_s_184 [[NIST](# | [112]{#fcs_cop.1.1_AEAD_11 .selectable-content}, 800-38D]{ | .selectable-content}, [112]{#_s_185 .selectab | [120]{#fcs_cop.1.1_AEAD_12 .selectable-content}, \[[GCM](# | .selectable-content}, [120]{#_s_186 | [128]{#fcs_cop.1.1_AEAD_13 .selectable-content}, | .selectable-content}\] bits. [128]{#_s_187 | ----------------------------------------------------------------------------------- .selectable-content}\] < bits. < ----------------------------------------------------------------------------------- < : [Table [10]{.counter}]{#fcs-cop-aead-sels .ctr : [Table [10]{.counter}]{#fcs-cop-aead-sels .ctr myid="fcs-cop-aead-sels" counter-type="ct-Table"}: Allowable choices myid="fcs-cop-aead-sels" counter-type="ct-Table"}: Allowable choices for [FCS_COP.1/AEAD](#FCS_COP.1/AEAD) for [FCS_COP.1/AEAD](#FCS_COP.1/AEAD) ::: appnote ::: appnote [Application Note: ]{.note-header}[ The use of 256-bit keys for [Application Note: ]{.note-header}[ The use of 256-bit keys for [AES](#abbr_AES) encryption is required by [CNSA](#abbr_CNSA). 128-bit [AES](#abbr_AES) encryption is required by [CNSA](#abbr_CNSA). 128-bit keys may only be used when the [PP-Module for Bluetooth, version | keys may only be used when the [PP-Module for Bluetooth, version 2.0]() 2.0](https://www.niap-ccevs.org/protectionprofiles/425) is claimed and | is claimed and only for the purpose of Bluetooth communications. only for the purpose of Bluetooth communications. ]{.note} | ]{.note} ::: ::: ::: ::: ::: ::: ::: {.activity_pane .hide} ::: {.activity_pane .hide} ::: activity_pane_header ::: activity_pane_header [[ Evaluation Activities [[ Evaluation Activities ]{.activity_pane_label}[]{.toggler}](#){onclick="toggle(this);return false;"} ]{.activity_pane_label}[]{.toggler}](#){onclick="toggle(this);return false;"} ::: ::: ::: activity_pane_body ::: activity_pane_body ::: component-activity-header ::: component-activity-header [FCS_COP.1/AEAD](#FCS_COP.1/AEAD) [FCS_COP.1/AEAD](#FCS_COP.1/AEAD) ::: ::: ::: eacategory ::: eacategory [TSS](#abbr_TSS) [TSS](#abbr_TSS) ::: ::: ::: ea ::: ea ::: ea ::: ea The evaluator shall examine the [TSS](#abbr_TSS) to ensure that it The evaluator shall examine the [TSS](#abbr_TSS) to ensure that it describes the construction of any IVs, nonces, and tags in conformance describes the construction of any IVs, nonces, and tags in conformance with the relevant specifications. with the relevant specifications. If a [CCM](#abbr_CCM) mode algorithm is selected, then the evaluator If a [CCM](#abbr_CCM) mode algorithm is selected, then the evaluator shall examine the [TOE](#abbr_TOE) summary specification to confirm that shall examine the [TOE](#abbr_TOE) summary specification to confirm that it describes how the nonce is generated and that the same nonce is never it describes how the nonce is generated and that the same nonce is never reused to encrypt different plaintext pairs under the same key. If the reused to encrypt different plaintext pairs under the same key. If the use of 128-bit keys is selected in conjunction with use of 128-bit keys is selected in conjunction with [AES](#abbr_AES)-CCM, the evaluator shall verify that the [AES](#abbr_AES)-CCM, the evaluator shall verify that the [TSS](#abbr_TSS) describes the use of 128-bit [AES](#abbr_AES)-CCM as [TSS](#abbr_TSS) describes the use of 128-bit [AES](#abbr_AES)-CCM as being solely for Bluetooth. being solely for Bluetooth. If a [GCM](#abbr_GCM) mode algorithm is selected, then the evaluator If a [GCM](#abbr_GCM) mode algorithm is selected, then the evaluator shall examine the [TOE](#abbr_TOE) summary specification to confirm that shall examine the [TOE](#abbr_TOE) summary specification to confirm that it describes how the IV is generated and that the same IV is never it describes how the IV is generated and that the same IV is never reused to encrypt different plaintext pairs under the same key. The reused to encrypt different plaintext pairs under the same key. The evaluator shall also confirm that for each invocation of evaluator shall also confirm that for each invocation of [GCM](#abbr_GCM), the length of the plaintext is at most (2^32^)-2 | [GCM](#abbr_GCM), the length of the plaintext is at most (2 ^32^)-2 blocks. blocks. ::: ::: ::: ::: ::: eacategory ::: eacategory Guidance Guidance ::: ::: ::: ea ::: ea There are no additional Guidance evaluation activities for this There are no additional Guidance evaluation activities for this component.\ component.\ ::: ::: ::: eacategory ::: eacategory Tests Tests ::: ::: ::: ea ::: ea ::: ea ::: ea The following tests may require the developer to provide access to a The following tests may require the developer to provide access to a test platform that provides the evaluator with tools that are typically test platform that provides the evaluator with tools that are typically not found on factory products. | not found on factory products. The following tests are conditional based | upon the selections made in the [SFR](#abbr_SFR). The evaluator shall The following tests are conditional based upon the selections made in | perform the following test or witness respective tests executed by the the [SFR](#abbr_SFR). The evaluator shall perform the following test or | developer. The tests must be executed on a platform that is as close as witness respective tests executed by the developer. The tests must be | practically possible to the operational platform (but which may be executed on a platform that is as close as practically possible to the | instrumented in terms of, for example, use of a debug mode). Where the operational platform (but which may be instrumented in terms of, for | test is not carried out on the [TOE](#abbr_TOE) itself, the test example, use of a debug mode). Where the test is not carried out on the | platform shall be identified and the differences between test [TOE](#abbr_TOE) itself, the test platform shall be identified and the | environment and [TOE](#abbr_TOE) execution environment shall be differences between test environment and [TOE](#abbr_TOE) execution | described.\ environment shall be described. < < \ < **[AES](#abbr_AES)-CCM** **[AES](#abbr_AES)-CCM** ---------------------- ------------------ --------------------- ------------------- ---------------------- ------------------ --------------------- ------------------- Identifier Cryptographic Cryptographic Key List of Standards Identifier Cryptographic Cryptographic Key List of Standards Algorithm Sizes Algorithm Sizes [AES](#abbr_AES)-CCM [AES](#abbr_AES) \[**selection:**128 \[**selection:** [AES](#abbr_AES)-CCM [AES](#abbr_AES) \[**selection:**128 \[**selection:** in bits, 256 bits\] ISO/IEC 18033-3:201 in bits, 256 bits\] ISO/IEC 18033-3:201 [CCM](#abbr_CCM) (Subclause 5.2), [CCM](#abbr_CCM) (Subclause 5.2), mode with [FIPS](#abbr_FIPS) mode with [FIPS](#abbr_FIPS) non-repeating 197\] non-repeating 197\] nonce, minimum \[[AES](#abbr_AES)\ nonce, minimum \[[AES](#abbr_AES)\ size of 64 bits size of 64 bits \[**selection:** \[**selection:** ISO/IEC 19772:2020 ISO/IEC 19772:2020 (Clause 7), (Clause 7), [NIST](#abbr_NIST) [NIST](#abbr_NIST) 800-38C\] 800-38C\] \[[CCM](#abbr_CCM)\ \[[CCM](#abbr_CCM)\ ---------------------- ------------------ --------------------- ------------------- ---------------------- ------------------ --------------------- ------------------- To test the [TOE](#abbr_TOE)'s implementation of [AES](#abbr_AES)-CCM To test the [TOE](#abbr_TOE)'s implementation of [AES](#abbr_AES)-CCM authenticated encryption functionality the evaluator shall perform the authenticated encryption functionality the evaluator shall perform the Algorithm Functional Tests described below using the following input Algorithm Functional Tests described below using the following input parameters: parameters: - Key Size \[128,256\] bits - Key Size \[128,256\] bits - Associated data size \[0-65536\] bits in increments of 8 - Associated data size \[0-65536\] bits in increments of 8 - Payload size \[0-256\] bits in increments of 8 - Payload size \[0-256\] bits in increments of 8 - IV/Nonce size \[64-104\] bits in increments of 8 - IV/Nonce size \[64-104\] bits in increments of 8 - Tag size \[32-128\] bits in increments of 16 - Tag size \[32-128\] bits in increments of 16 \ \ **Algorithm Functional Tests** | **Algorithm Functional Tests** Unless otherwise specified, the following | tests should use random data, a tag size of 128 bits, IV/Nonce size of Unless otherwise specified, the following tests should use random data, | 104 bits, payload size of 256 bits, and associated data size of 256 a tag size of 128 bits, IV/Nonce size of 104 bits, payload size of 256 | bits. If any of these values are not supported, any supported value may bits, and associated data size of 256 bits. If any of these values are | be used. The evaluator shall compare the output from each test case not supported, any supported value may be used. The evaluator shall | against results generated by a known-good implementation with the same compare the output from each test case against results generated by a | input parameters.\ known-good implementation with the same input parameters. | ***Variable Associated Data Test*** For each claimed key size, and for | each supported associated data size from 0 through 256 bits in \ | increments of 8 bits, the [TOE](#abbr_TOE) must be tested by encrypting ***Variable Associated Data Test*** | 10 test cases using all random data. In addition, for each key size, the | [TOE](#abbr_TOE) must be tested by encrypting 10 cases with associated For each claimed key size, and for each supported associated data size | data lengths of 65536 bits, if supported.\ from 0 through 256 bits in increments of 8 bits, the [TOE](#abbr_TOE) | ***Variable Payload Test*** For each claimed key size, and for each must be tested by encrypting 10 test cases using all random data. In | supported payload size from 0 through 256 bits in increments of 8 bits, addition, for each key size, the [TOE](#abbr_TOE) must be tested by | the [TOE](#abbr_TOE) must be tested by encrypting 10 test cases using encrypting 10 cases with associated data lengths of 65536 bits, if | all random data.\ supported. | ***Variable Nonce Test*** For each claimed key size, and for each | supported IV/Nonce size from 64 through 104 bits in increments of 8 \ | bits, the [TOE](#abbr_TOE) must be tested by encrypting 10 test cases ***Variable Payload Test*** | using all random data.\ | ***Variable Tag Test*** For each claimed key size, and for each For each claimed key size, and for each supported payload size from 0 | supported tag size from 32 through 128 bits in increments of 16 bits, through 256 bits in increments of 8 bits, the [TOE](#abbr_TOE) must be | the [TOE](#abbr_TOE) must be tested by encrypting 10 test cases using tested by encrypting 10 test cases using all random data. | all random data.\ | ***Decryption Verification Test*** For each claimed key size, for each \ | supported associated data size from 0 through 256 bits in increments of ***Variable Nonce Test*** | 8 bits, for each supported payload size from 0 through 256 bits in | increments of 8 bits, for each supported IV/Nonce size from 64 through For each claimed key size, and for each supported IV/Nonce size from 64 | 104 bits in increments of 8 bits, and for each supported tag size from through 104 bits in increments of 8 bits, the [TOE](#abbr_TOE) must be | 32 through 128 bits in increments of 16 bits, the [TOE](#abbr_TOE) must tested by encrypting 10 test cases using all random data. | be tested by decrypting 10 test cases using all random data.\ < \ < ***Variable Tag Test*** < < For each claimed key size, and for each supported tag size from 32 < through 128 bits in increments of 16 bits, the [TOE](#abbr_TOE) must be < tested by encrypting 10 test cases using all random data. < < \ < ***Decryption Verification Test*** < < For each claimed key size, for each supported associated data size from < 0 through 256 bits in increments of 8 bits, for each supported payload < size from 0 through 256 bits in increments of 8 bits, for each supported < IV/Nonce size from 64 through 104 bits in increments of 8 bits, and for < each supported tag size from 32 through 128 bits in increments of 16 < bits, the [TOE](#abbr_TOE) must be tested by decrypting 10 test cases < using all random data. < < \ < **[AES](#abbr_AES)-GCM** **[AES](#abbr_AES)-GCM** ---------------------- ------------------ ----------------- ---------------------- ---------------------- ------------------ ----------------- ---------------------- Identifier Cryptographic Cryptographic Key List of Standards Identifier Cryptographic Cryptographic Key List of Standards Algorithm Sizes Algorithm Sizes [AES](#abbr_AES)-GCM [AES](#abbr_AES) 256 bits \[**selection:** [AES](#abbr_AES)-GCM [AES](#abbr_AES) 256 bits \[**selection:** in ISO/IEC 18033-3:2010 in ISO/IEC 18033-3:2010 [GCM](#abbr_GCM) (Subclause 5.2), [GCM](#abbr_GCM) (Subclause 5.2), mode with [FIPS](#abbr_FIPS) PUB mode with [FIPS](#abbr_FIPS) PUB non-repeating IVs 197\] non-repeating IVs 197\] using \[[AES](#abbr_AES)\] using \[[AES](#abbr_AES)\] \[**selection:** \[**selection:** deterministic, \[**selection:** deterministic, \[**selection:** DRBG-based\] IV ISO/IEC 19772:2020 DRBG-based\] IV ISO/IEC 19772:2020 construction; the (Clause 10), construction; the (Clause 10), tag must be of [NIST](#abbr_NIST) SP tag must be of [NIST](#abbr_NIST) SP length 800-38D\] length 800-38D\] \[**selection:** \[[GCM](#abbr_GCM)\] \[**selection:** \[[GCM](#abbr_GCM)\] 96, 104, 112, 120, 96, 104, 112, 120, or 128\] bits. or 128\] bits. ---------------------- ------------------ ----------------- ---------------------- ---------------------- ------------------ ----------------- ---------------------- To test the [TOE](#abbr_TOE)'s implementation of [AES](#abbr_AES)-GCM To test the [TOE](#abbr_TOE)'s implementation of [AES](#abbr_AES)-GCM authenticated encryption functionality the evaluator shall perform the authenticated encryption functionality the evaluator shall perform the Encryption Algorithm Functional Tests and Decryption Algorithm Encryption Algorithm Functional Tests and Decryption Algorithm Functional Tests as described below using the following input Functional Tests as described below using the following input parameters: parameters: - Key Size \[256\] bits - Key Size \[256\] bits - Associated data size \[0-65536\] bits - Associated data size \[0-65536\] bits - Payload size \[0-65536\] bits - Payload size \[0-65536\] bits - IV size \[96\] bits - IV size \[96\] bits - Tag size \[96, 104, 112, 120, 128\] bits - Tag size \[96, 104, 112, 120, 128\] bits \ \ **Encryption Algorithm Functional Tests** | **Encryption Algorithm Functional Tests** The evaluator shall generate | 15 test cases using random data for each combination of the above The evaluator shall generate 15 test cases using random data for each | parameters as follows: combination of the above parameters as follows: < - Each claimed key size, - Each claimed key size, - Each supported tag size, - Each supported tag size, - Four supported non-zero payload sizes, such that two are multiples - Four supported non-zero payload sizes, such that two are multiples of 128 bits and two are not multiples of 128 bits, of 128 bits and two are not multiples of 128 bits, - Four supported non-zero associated data sizes, such that two are - Four supported non-zero associated data sizes, such that two are multiples of 128 bits and two are not multiples of 128 bits, and multiples of 128 bits and two are not multiples of 128 bits, and - An associated data size of zero, if supported. - An associated data size of zero, if supported. Note that the IV size is always 96 bits. | Note that the IV size is always 96 bits. The evaluator shall compare the | output from each test case against results generated by a known- good The evaluator shall compare the output from each test case against | implementation with the same input parameters.\ results generated by a known- good implementation with the same input | ***Decryption Algorithm Functional Tests*** The evaluator shall test the parameters. | authenticated decrypt functionality of [AES](#abbr_AES)-GCM by supplying | 15 test cases for the supported combinations of the parameters as \ | described above. For each parameter combination the evaluator shall ***Decryption Algorithm Functional Tests*** | introduce an error into either the Ciphertext or the Tag such that | approximately half of the cases are correct and half the cases contain The evaluator shall test the authenticated decrypt functionality of | errors. [AES](#abbr_AES)-GCM by supplying 15 test cases for the supported < combinations of the parameters as described above. For each parameter < combination the evaluator shall introduce an error into either the < Ciphertext or the Tag such that approximately half of the cases are < correct and half the cases contain errors. < ::: ::: ::: ::: ::: ::: ::: ::: ::: ::: ::: {#FCS_COP.1/Hash .comp} ::: {#FCS_COP.1/Hash .comp} #### FCS_COP.1/Hash Cryptographic Operation - Hashing #### FCS_COP.1/Hash Cryptographic Operation - Hashing ::: element ::: element ::: {#FCS_COP.1.1/Hash .reqid} ::: {#FCS_COP.1.1/Hash .reqid} [FCS_COP.1.1/Hash](#FCS_COP.1.1/Hash){.abbr} [FCS_COP.1.1/Hash](#FCS_COP.1.1/Hash){.abbr} ::: ::: ::: reqdesc ::: reqdesc The [TSF](#abbr_TSF) shall perform \[*cryptographic hashing*\] in The [TSF](#abbr_TSF) shall perform \[*cryptographic hashing*\] in accordance with a specified cryptographic algorithm \[**selection**: accordance with a specified cryptographic algorithm \[**selection**: [[SHA](#abbr_SHA)-256]{#sel-cop1-sha256 .selectable-content}, [[SHA](#abbr_SHA)-256]{#sel-cop1-sha256 .selectable-content}, [[SHA](#abbr_SHA)-384]{#sel-cop1-sha384 .selectable-content}, [[SHA](#abbr_SHA)-384]{#sel-cop1-sha384 .selectable-content}, [[SHA](#abbr_SHA)-512]{#sel-cop1-sha512 .selectable-content}, [[SHA](#abbr_SHA)-512]{#sel-cop1-sha512 .selectable-content}, [SHA3-384]{#sel-cop1-sha3-384 .selectable-content}, [SHA3-384]{#sel-cop1-sha3-384 .selectable-content}, [SHA3-512]{#sel-cop1-sha3-512 .selectable-content}\] that meet the [SHA3-512]{#sel-cop1-sha3-512 .selectable-content}\] that meet the following: \[**selection**: [ISO/IEC 10118-3:2018 \[[SHA](#abbr_SHA), following: \[**selection**: [ISO/IEC 10118-3:2018 \[[SHA](#abbr_SHA), SHA3\]]{#_s_197 .selectable-content}, [[FIPS](#abbr_FIPS) PUB 180-4 | SHA3\]]{#fcs_cop.1.1_Hash_1 .selectable-content}, [[FIPS](#abbr_FIPS) \[[SHA](#abbr_SHA)\]]{#_s_198 .selectable-content}, [[FIPS](#abbr_FIPS) | PUB 180-4 \[[SHA](#abbr_SHA)\]]{#fcs_cop.1.1_Hash_2 PUB 202 \[SHA3\]]{#_s_199 .selectable-content}\]. | .selectable-content}, [[FIPS](#abbr_FIPS) PUB 202 > \[SHA3\]]{#fcs_cop.1.1_Hash_3 .selectable-content}\]. ::: appnote ::: appnote [Application Note: ]{.note-header}[ ]{.note} [Application Note: ]{.note-header}[ ]{.note} In accordance with [CNSA](#abbr_CNSA): In accordance with [CNSA](#abbr_CNSA): - [SHA](#abbr_SHA)-3 hashes may be used only for internal hardware - [SHA](#abbr_SHA)-3 hashes may be used only for internal hardware functionality such as boot integrity checks, and functionality such as boot integrity checks, and - [SHA](#abbr_SHA)-256 is permitted only for use as a [PRF](#abbr_PRF) - [SHA](#abbr_SHA)-256 is permitted only for use as a [PRF](#abbr_PRF) or MAC as part of a key derivation function, or as part of LMS or or MAC as part of a key derivation function, or as part of LMS or XMSS. XMSS. The hash selection should be consistent with the overall strength of the The hash selection should be consistent with the overall strength of the algorithm used for signature generation. For example, the algorithm used for signature generation. For example, the [TOE](#abbr_TOE) should choose [SHA](#abbr_SHA)-384 for 3072-bit [TOE](#abbr_TOE) should choose [SHA](#abbr_SHA)-384 for 3072-bit [RSA](#abbr_RSA), 4096-bit [RSA](#abbr_RSA), or ECC with P-384; and [RSA](#abbr_RSA), 4096-bit [RSA](#abbr_RSA), or ECC with P-384; and [SHA](#abbr_SHA)-512 for ECC with P-521. [SHA](#abbr_SHA)-512 for ECC with P-521. ::: ::: ::: ::: ::: ::: ::: {.activity_pane .hide} ::: {.activity_pane .hide} ::: activity_pane_header ::: activity_pane_header [[ Evaluation Activities [[ Evaluation Activities ]{.activity_pane_label}[]{.toggler}](#){onclick="toggle(this);return false;"} ]{.activity_pane_label}[]{.toggler}](#){onclick="toggle(this);return false;"} ::: ::: ::: activity_pane_body ::: activity_pane_body ::: component-activity-header ::: component-activity-header [FCS_COP.1/Hash](#FCS_COP.1/Hash) [FCS_COP.1/Hash](#FCS_COP.1/Hash) ::: ::: ::: eacategory ::: eacategory [TSS](#abbr_TSS) [TSS](#abbr_TSS) ::: ::: ::: ea ::: ea ::: ea ::: ea The evaluator shall examine the [TSS](#abbr_TSS) to verify that if The evaluator shall examine the [TSS](#abbr_TSS) to verify that if [SHA](#abbr_SHA)-256 is selected, that it is being used only as a [SHA](#abbr_SHA)-256 is selected, that it is being used only as a [PRF](#abbr_PRF) or MAC step in a key derivation function or as part of [PRF](#abbr_PRF) or MAC step in a key derivation function or as part of LMS, and not as a hash algorithm. LMS, and not as a hash algorithm. ::: ::: ::: ::: ::: eacategory ::: eacategory Guidance Guidance ::: ::: ::: ea ::: ea There are no additional Guidance evaluation activities for this There are no additional Guidance evaluation activities for this component.\ component.\ ::: ::: ::: eacategory ::: eacategory Tests Tests ::: ::: ::: ea ::: ea ::: ea ::: ea The following tests may require the developer to provide access to a The following tests may require the developer to provide access to a test platform that provides the evaluator with tools that are typically test platform that provides the evaluator with tools that are typically not found on factory products. | not found on factory products. The following tests are conditional, | based on the selections made in the [SFR](#abbr_SFR). The evaluator The following tests are conditional, based on the selections made in the | shall perform the following tests or witness respective tests executed [SFR](#abbr_SFR). The evaluator shall perform the following tests or | by the developer. The tests must be executed on a platform that is as witness respective tests executed by the developer. The tests must be | close as practically possible to the operational platform (but which may executed on a platform that is as close as practically possible to the | be instrumented in terms of, for example, use of a debug mode). Where operational platform (but which may be instrumented in terms of, for | the test is not carried out on the [TOE](#abbr_TOE) itself, the test example, use of a debug mode). Where the test is not carried out on the | platform shall be identified and the differences between test [TOE](#abbr_TOE) itself, the test platform shall be identified and the | environment and [TOE](#abbr_TOE) execution environment shall be differences between test environment and [TOE](#abbr_TOE) execution | described.\ environment shall be described. | **[SHA](#abbr_SHA)-256, [SHA](#abbr_SHA)-384, [SHA](#abbr_SHA)-512** To | test the [TOE](#abbr_TOE)'s ability to generate hash digests using SHA2, \ | the evaluator shall perform the Algorithm Functional Test, Monte Carlo **[SHA](#abbr_SHA)-256, [SHA](#abbr_SHA)-384, [SHA](#abbr_SHA)-512** | Test, and Large Data Test for each claimed SHA2 algorithm.\ | **Algorithm Functional Test** The evaluator shall generate a number of To test the [TOE](#abbr_TOE)'s ability to generate hash digests using | test cases equal to the block size of the hash (512 for SHA2-256; 1024 SHA2, the evaluator shall perform the Algorithm Functional Test, Monte | for the other SHA2 algorithms). Each test case is to consist of random Carlo Test, and Large Data Test for each claimed SHA2 algorithm. | data of a random length between 0 and 65536 bits, or the largest size | supported.\ \ | **Monte Carlo Test** Monte Carlo tests begin with a single seed and run **Algorithm Functional Test** | 100 iterations of the chained computation. For the standard Monte Carlo | test the message hashed is always three times the length of the initial The evaluator shall generate a number of test cases equal to the block | seed. size of the hash (512 for SHA2-256; 1024 for the other SHA2 algorithms). < < Each test case is to consist of random data of a random length between 0 < and 65536 bits, or the largest size supported. < < \ < **Monte Carlo Test** < < Monte Carlo tests begin with a single seed and run 100 iterations of the < chained computation. < < For the standard Monte Carlo test the message hashed is always three < times the length of the initial seed. < For j = 0 to 99 For j = 0 to 99 A = B = C = SEED A = B = C = SEED For i = 0 to 999 For i = 0 to 999 MSG = A || B || C MSG = A || B || C MD = SHA(MSG) MD = SHA(MSG) A = B A = B B = C B = C C = MD C = MD Output MD Output MD SEED = MD SEED = MD For the alternate version of the Monte Carlo Test, the hashed message is For the alternate version of the Monte Carlo Test, the hashed message is always the same length as the seed. always the same length as the seed. INITIAL_SEED_LENGTH = LEN(SEED) INITIAL_SEED_LENGTH = LEN(SEED) For j = 0 to 99 For j = 0 to 99 A = B = C = SEED A = B = C = SEED For i = 0 to 999 For i = 0 to 999 MSG = A || B || C MSG = A || B || C if LEN(MSG) >= INITIAL_SEED_LENGTH: if LEN(MSG) >= INITIAL_SEED_LENGTH: MSG = leftmost INITIAL_SEED_LENGTH bits of MSG MSG = leftmost INITIAL_SEED_LENGTH bits of MSG else: else: MSG = MSG || INITIAL_SEED_LENGTH - LEN(MSG) 0 bits MSG = MSG || INITIAL_SEED_LENGTH - LEN(MSG) 0 bits MD = SHA(MSG) MD = SHA(MSG) A = B A = B B = C B = C C = MD C = MD Output MD Output MD SEED = MD SEED = MD The evaluator shall compare the output against results generated by a The evaluator shall compare the output against results generated by a known good implementation with the same input. | known good implementation with the same input.\ | **Large Data Test** The implementation must be tested against one test \ | case each on large data messages of 1GB, 2GB, 4GB, and 8GB of data as **Large Data Test** | supported. The data need not be random. It may, for example, consist of | a repeated pattern of 64 bits. The evaluator shall compare the output The implementation must be tested against one test case each on large | against results generated by a known good implementation with the same data messages of 1GB, 2GB, 4GB, and 8GB of data as supported. The data | input.\ need not be random. It may, for example, consist of a repeated pattern | **SHA3-384, SHA3-512** To test the [TOE](#abbr_TOE)'s ability to of 64 bits. | generate hash digests using SHA3 the evaluator shall perform the | Algorithm Functional Test, Monte Carlo Test, and Large Data Tests for The evaluator shall compare the output against results generated by a | each claimed SHA3 algorithm.\ known good implementation with the same input. | **Algorithm Functional Test** Generate a test case consisting of random | data for every message length from 0 bits (or the smallest supported \ | message size) to rate bits, where rate equals **SHA3-384, SHA3-512** < < To test the [TOE](#abbr_TOE)'s ability to generate hash digests using < SHA3 the evaluator shall perform the Algorithm Functional Test, Monte < Carlo Test, and Large Data Tests for each claimed SHA3 algorithm. < < \ < **Algorithm Functional Test** < < Generate a test case consisting of random data for every message length < from 0 bits (or the smallest supported message size) to rate bits, where < rate equals < - 832 for SHA3-384 and - 832 for SHA3-384 and - 576 for SHA3-512. - 576 for SHA3-512. Additionally, generate tests cases of random data for messages of every Additionally, generate tests cases of random data for messages of every multiple of (rate+1) bits starting at length rate, and continuing until multiple of (rate+1) bits starting at length rate, and continuing until 65535 is exceeded. | 65535 is exceeded. The evaluator shall compare the output against | results generated by a known good implementation with the same input.\ The evaluator shall compare the output against results generated by a | **Monte Carlo Test** Monte Carlo tests begin with a single seed and run known good implementation with the same input. | 100 iterations of the chained computation. For this Monte Carlo Test, | the hashed message is always the same length as the seed. \ < **Monte Carlo Test** < < Monte Carlo tests begin with a single seed and run 100 iterations of the < chained computation. < < For this Monte Carlo Test, the hashed message is always the same length < as the seed. < MD[0] = SEED MD[0] = SEED INITIAL_SEED_LENGTH = LEN(SEED) INITIAL_SEED_LENGTH = LEN(SEED) For 100 iterations For 100 iterations For i = 1 to 1000 For i = 1 to 1000 MSG = MD[i-1]; MSG = MD[i-1]; if LEN(MSG) >= INITIAL_SEED_LENGTH: if LEN(MSG) >= INITIAL_SEED_LENGTH: MSG = leftmost INITIAL_SEED_LENGTH bits of MSG MSG = leftmost INITIAL_SEED_LENGTH bits of MSG else: else: MSG = MSG || INITIAL_SEED_LENGTH - LEN(MSG) 0 bits MSG = MSG || INITIAL_SEED_LENGTH - LEN(MSG) 0 bits MD[i] = SHA3(MSG) MD[i] = SHA3(MSG) MD[0] = MD[1000] MD[0] = MD[1000] Output MD[0] Output MD[0] The evaluator shall compare the output against results generated by a The evaluator shall compare the output against results generated by a known good implementation with the same input. | known good implementation with the same input.\ | **Large Data Test** The implementation must be tested against one test \ | case each on large data messages of 1GB, 2GB, 4GB, and 8GB of data as **Large Data Test** | supported. The data need not be random. It may, for example, consist of | a repeated pattern of 64 bits. The evaluator shall compare the output The implementation must be tested against one test case each on large | against results generated by a known good implementation with the same data messages of 1GB, 2GB, 4GB, and 8GB of data as supported. The data | input. need not be random. It may, for example, consist of a repeated pattern < of 64 bits. < < The evaluator shall compare the output against results generated by a < known good implementation with the same input. < ::: ::: ::: ::: ::: ::: ::: ::: ::: ::: ::: {#FCS_COP.1/KeyedHash .comp} ::: {#FCS_COP.1/KeyedHash .comp} #### FCS_COP.1/KeyedHash Cryptographic Operation - Keyed Hash #### FCS_COP.1/KeyedHash Cryptographic Operation - Keyed Hash ::: element ::: element ::: {#FCS_COP.1.1/KeyedHash .reqid} ::: {#FCS_COP.1.1/KeyedHash .reqid} [FCS_COP.1.1/KeyedHash](#FCS_COP.1.1/KeyedHash){.abbr} [FCS_COP.1.1/KeyedHash](#FCS_COP.1.1/KeyedHash){.abbr} ::: ::: ::: reqdesc ::: reqdesc The [TSF](#abbr_TSF) shall perform \[*keyed hash message The [TSF](#abbr_TSF) shall perform \[*keyed hash message authentication*\] in accordance with a specified cryptographic algorithm authentication*\] in accordance with a specified cryptographic algorithm \[**selection**: [Keyed Hash Algorithm]{.selectable-content}\] and \[**selection**: [Keyed Hash Algorithm]{.selectable-content}\] and cryptographic key sizes \[**selection**: [Cryptographic Key cryptographic key sizes \[**selection**: [Cryptographic Key Sizes]{.selectable-content}\] that meet the following: \[**selection**: Sizes]{.selectable-content}\] that meet the following: \[**selection**: [List of Standards]{.selectable-content}\] . [List of Standards]{.selectable-content}\] . [Table [Table [11]{.counter}](#fcs-cop-keyedhash-sels){.fcs-cop-keyedhash-sels-ref [11]{.counter}](#fcs-cop-keyedhash-sels){.fcs-cop-keyedhash-sels-ref onclick="showTarget('fcs-cop-keyedhash-sels')"} provides the allowable onclick="showTarget('fcs-cop-keyedhash-sels')"} provides the allowable choices for completion of the selection operations of choices for completion of the selection operations of [FCS_COP.1/KeyedHash](#FCS_COP.1/KeyedHash). [FCS_COP.1/KeyedHash](#FCS_COP.1/KeyedHash). Keyed Hash Algorithm Cryptographic Key Sizes | Keyed Hash Algorithm Cryptographic Key Sizes ---------------------------- ------------------------------------------------------ | ---------------------------- ------------------------------------------------------ [HMAC](#abbr_HMAC)-SHA-256 256 bits | [HMAC](#abbr_HMAC)-SHA-256 256 bits [HMAC](#abbr_HMAC)-SHA-384 \[**selection**: [*384 (ISO, [FIPS](#abbr_FIPS))*]{#_s | [HMAC](#abbr_HMAC)-SHA-384 \[**selection**: [*384 (ISO, [FIPS](#abbr_FIPS))*]{#fc [HMAC](#abbr_HMAC)-SHA-512 \[**selection**: [*512 (ISO, [FIPS](#abbr_FIPS))*]{#_s | [HMAC](#abbr_HMAC)-SHA-512 \[**selection**: [*512 (ISO, [FIPS](#abbr_FIPS))*]{#fc : [Table [11]{.counter}]{#fcs-cop-keyedhash-sels .ctr : [Table [11]{.counter}]{#fcs-cop-keyedhash-sels .ctr myid="fcs-cop-keyedhash-sels" counter-type="ct-Table"}: Allowable myid="fcs-cop-keyedhash-sels" counter-type="ct-Table"}: Allowable choices for [FCS_COP.1/KeyedHash](#FCS_COP.1/KeyedHash) choices for [FCS_COP.1/KeyedHash](#FCS_COP.1/KeyedHash) ::: appnote ::: appnote [Application Note: ]{.note-header}[ ]{.note} [Application Note: ]{.note-header}[ ]{.note} The intent of this requirement is to specify the keyed-hash message The intent of this requirement is to specify the keyed-hash message authentication function used for key establishment purposes for the authentication function used for key establishment purposes for the various cryptographic protocols used by the [OS](#abbr_OS) (e.g., various cryptographic protocols used by the [OS](#abbr_OS) (e.g., trusted channel). The hash selection must support the message digest trusted channel). The hash selection must support the message digest size selection. The hash selection should be consistent with the overall size selection. The hash selection should be consistent with the overall strength of the algorithm used for [FCS_COP.1/Hash](#FCS_COP.1/Hash). strength of the algorithm used for [FCS_COP.1/Hash](#FCS_COP.1/Hash). In accordance with [CNSA](#abbr_CNSA), [HMAC](#abbr_HMAC)-SHA-256 may be In accordance with [CNSA](#abbr_CNSA), [HMAC](#abbr_HMAC)-SHA-256 may be used only as a [PRF](#abbr_PRF) or MAC step in a key derivation used only as a [PRF](#abbr_PRF) or MAC step in a key derivation function. function. ::: ::: ::: ::: ::: ::: ::: {.activity_pane .hide} ::: {.activity_pane .hide} ::: activity_pane_header ::: activity_pane_header [[ Evaluation Activities [[ Evaluation Activities ]{.activity_pane_label}[]{.toggler}](#){onclick="toggle(this);return false;"} ]{.activity_pane_label}[]{.toggler}](#){onclick="toggle(this);return false;"} ::: ::: ::: activity_pane_body ::: activity_pane_body ::: component-activity-header ::: component-activity-header [FCS_COP.1/KeyedHash](#FCS_COP.1/KeyedHash) [FCS_COP.1/KeyedHash](#FCS_COP.1/KeyedHash) ::: ::: ::: eacategory ::: eacategory [TSS](#abbr_TSS) [TSS](#abbr_TSS) ::: ::: ::: ea ::: ea ::: ea ::: ea The evaluator shall examine the [TSS](#abbr_TSS) to ensure that the size The evaluator shall examine the [TSS](#abbr_TSS) to ensure that the size of the key is sufficient for the desired security strength of the of the key is sufficient for the desired security strength of the output. output. The evaluator shall examine the [TSS](#abbr_TSS) to verify that if The evaluator shall examine the [TSS](#abbr_TSS) to verify that if [HMAC](#abbr_HMAC)-SHA-256 is selected, that it is being used only as a [HMAC](#abbr_HMAC)-SHA-256 is selected, that it is being used only as a [PRF](#abbr_PRF) or MAC step in a key derivation function. [PRF](#abbr_PRF) or MAC step in a key derivation function. ::: ::: ::: ::: ::: eacategory ::: eacategory Guidance Guidance ::: ::: ::: ea ::: ea There are no additional Guidance evaluation activities for this There are no additional Guidance evaluation activities for this component.\ component.\ ::: ::: ::: eacategory ::: eacategory Tests Tests ::: ::: ::: ea ::: ea ::: ea ::: ea The following tests are conditional based on the selections made in the The following tests are conditional based on the selections made in the [SFR](#abbr_SFR). The evaluator shall perform the following tests or [SFR](#abbr_SFR). The evaluator shall perform the following tests or witness respective tests executed by the developer. The tests must be witness respective tests executed by the developer. The tests must be executed on a platform that is as close as practically possible to the executed on a platform that is as close as practically possible to the operational platform (but which may be instrumented in terms of, for operational platform (but which may be instrumented in terms of, for example, use of a debug mode). Where the test is not carried out on the example, use of a debug mode). Where the test is not carried out on the [TOE](#abbr_TOE) itself, the test platform shall be identified and the [TOE](#abbr_TOE) itself, the test platform shall be identified and the differences between test environment and [TOE](#abbr_TOE) execution differences between test environment and [TOE](#abbr_TOE) execution environment shall be described. | environment shall be described.\ < \ < **[HMAC](#abbr_HMAC)** **[HMAC](#abbr_HMAC)** ---------------------------- ------------------------------------------------------ ---------------------------- ------------------------------------------------------ Keyed Hash Algorithm Cryptographic Key Sizes Keyed Hash Algorithm Cryptographic Key Sizes [HMAC](#abbr_HMAC)-SHA-256 256 bits [HMAC](#abbr_HMAC)-SHA-256 256 bits [HMAC](#abbr_HMAC)-SHA-384 \[***selection:** (ISO, [FIPS](#abbr_FIPS)) 384, ([FIP [HMAC](#abbr_HMAC)-SHA-384 \[***selection:** (ISO, [FIPS](#abbr_FIPS)) 384, ([FIP [HMAC](#abbr_HMAC)-SHA-512 \[**selection:** *(ISO, [FIPS](#abbr_FIPS)) 512, ([FIP [HMAC](#abbr_HMAC)-SHA-512 \[**selection:** *(ISO, [FIPS](#abbr_FIPS)) 512, ([FIP ---------------------------- ------------------------------------------------------ ---------------------------- ------------------------------------------------------ To test the [TOE](#abbr_TOE)'s ability to generate keyed hashes using To test the [TOE](#abbr_TOE)'s ability to generate keyed hashes using [HMAC](#abbr_HMAC) the evaluator shall perform the Algorithm Functional [HMAC](#abbr_HMAC) the evaluator shall perform the Algorithm Functional Test for each combination of claimed [HMAC](#abbr_HMAC) algorithm the Test for each combination of claimed [HMAC](#abbr_HMAC) algorithm the following parameters: following parameters: - Hash function \[[SHA](#abbr_SHA)-256, [SHA](#abbr_SHA)-384, - Hash function \[[SHA](#abbr_SHA)-256, [SHA](#abbr_SHA)-384, [SHA](#abbr_SHA)-512\] [SHA](#abbr_SHA)-512\] - Key length \[8-65536\] bits by 8s - Key length \[8-65536\] bits by 8s - MAC length \[32-\[digest size of hash function (256, 384, 512)\]\] - MAC length \[32-\[digest size of hash function (256, 384, 512)\]\] bits bits \ \ **Algorithm Functional Test** | **Algorithm Functional Test** For each supported Hash function the | evaluator shall generate 150 test cases using random input messages of For each supported Hash function the evaluator shall generate 150 test | 128 bits, random supported key lengths, random keys, and random cases using random input messages of 128 bits, random supported key | supported MAC lengths such that across the 150 test cases: lengths, random keys, and random supported MAC lengths such that across < the 150 test cases: < - The key length includes the minimum, the maximum, a key length equal - The key length includes the minimum, the maximum, a key length equal to the block size, and key lengths that are both larger and smaller to the block size, and key lengths that are both larger and smaller than the block size. than the block size. - The MAC size includes the minimum, the maximum, and two other random - The MAC size includes the minimum, the maximum, and two other random values. values. The evaluator shall compare the output against results generated by a The evaluator shall compare the output against results generated by a known good implementation with the same input. known good implementation with the same input. ::: ::: ::: ::: ::: ::: ::: ::: ::: ::: ::: {#FCS_COP.1/KeyWrap .comp} ::: {#FCS_COP.1/KeyWrap .comp} #### FCS_COP.1/KeyWrap Cryptographic Operation - Key Wrapping #### FCS_COP.1/KeyWrap Cryptographic Operation - Key Wrapping ::: element ::: element ::: {#FCS_COP.1.1/KeyWrap .reqid} ::: {#FCS_COP.1.1/KeyWrap .reqid} [FCS_COP.1.1/KeyWrap](#FCS_COP.1.1/KeyWrap){.abbr} [FCS_COP.1.1/KeyWrap](#FCS_COP.1.1/KeyWrap){.abbr} ::: ::: ::: reqdesc ::: reqdesc The [TSF](#abbr_TSF) shall perform \[*key wrapping*\] in accordance with The [TSF](#abbr_TSF) shall perform \[*key wrapping*\] in accordance with a specified cryptographic algorithm \[**selection**: [Cryptographic a specified cryptographic algorithm \[**selection**: [Cryptographic Algorithm]{.selectable-content}\] and cryptographic key sizes Algorithm]{.selectable-content}\] and cryptographic key sizes \[**selection**: [Cryptographic Key Sizes]{.selectable-content}\] that \[**selection**: [Cryptographic Key Sizes]{.selectable-content}\] that meet the following: \[**selection**: [List of meet the following: \[**selection**: [List of Standards]{.selectable-content}\] . Standards]{.selectable-content}\] . [Table [12]{.counter}](#fcs-cop-kw-sels){.fcs-cop-kw-sels-ref [Table [12]{.counter}](#fcs-cop-kw-sels){.fcs-cop-kw-sels-ref onclick="showTarget('fcs-cop-kw-sels')"} provides the allowable choices onclick="showTarget('fcs-cop-kw-sels')"} provides the allowable choices for completion of the selection operations of for completion of the selection operations of [FCS_COP.1/KeyWrap](#FCS_COP.1/KeyWrap). [FCS_COP.1/KeyWrap](#FCS_COP.1/KeyWrap). ----------------------------------------------------------------------------------- | ----------------------------------------------------------------------------------- Identifier Cryptographic Algorithm Cryptographic Key List of Standard | Identifier Cryptographic Algorithm Cryptographic Key Sizes | Sizes ---------------------- ------------------------- ----------------- ---------------- | ---------------------- ----------------------------------------- ----------------- [AES](#abbr_AES)-KW [AES](#abbr_AES) in KW 256 bits \[**selection**: | [AES](#abbr_AES)-KW [AES](#abbr_AES) in KW mode 256 bits mode [ISO/IEC 18033-3 | (Subclause 5.2)] | .selectable-cont | [[FIPS](#abbr_FI | 197]{#_s_217 | .selectable-cont | \[[AES](#abbr_AE | | \[**selection**: | [ISO/IEC 19772:2 | (clause 6)]{#_s_ | .selectable-cont | [[NIST](#abbr_NI | 800-38F (Section | 6.2)]{#_s_219 | .selectable-cont | \[KW mode\] | | [AES](#abbr_AES)-KWP [AES](#abbr_AES) in KWP mode 256 bits [AES](#abbr_AES)-KWP [AES](#abbr_AES) in KWP 256 bits \[**selection**: | mode [ISO/IEC 18033-3 | (Subclause 5.2)] | .selectable-cont | [[FIPS](#abbr_FI | 197]{#_s_222 | .selectable-cont | \[[AES](#abbr_AE | | [NIST](#abbr_NIS | 800-38F (Section | \[KWP mode\] | [AES](#abbr_AES)-CCM [AES](#abbr_AES) in [CCM](#abbr_CCM) mode 256 bits | with unpredictable, non-repeating nonce, [AES](#abbr_AES)-CCM [AES](#abbr_AES) in 256 bits \[**selection**: | minimum size of 64 bits [CCM](#abbr_CCM) mode [ISO/IEC 18033-3 | with unpredictable, (Subclause 5.2)] | non-repeating nonce, .selectable-cont | minimum size of 64 bits [[FIPS](#abbr_FI | 197]{#_s_225 | .selectable-cont | \[[AES](#abbr_AE | | \[**selection**: | [ISO/IEC 19772:2 | (Clause 7)]{#_s_ | .selectable-cont | [[NIST](#abbr_NI | 800-38C]{#_s_227 | .selectable-cont | \[[CCM](#abbr_CC | [AES](#abbr_AES)-GCM [AES](#abbr_AES) in [GCM](#abbr_GCM) mode 256 bits | with non-repeating IVs using [AES](#abbr_AES)-GCM [AES](#abbr_AES) in 256 bits \[**selection**: | \[**selection**: [GCM](#abbr_GCM) mode [ISO/IEC 18033-3 | [deterministic]{#fcs_cop.1.1_KeyWrap_11 with non-repeating IVs (Subclause 5.2)] | .selectable-content}, using \[**selection**: .selectable-cont | [DRBG-based]{#fcs_cop.1.1_KeyWrap_12 [deterministic]{#_s_229 [[FIPS](#abbr_FI | .selectable-content}\], IV construction; .selectable-content}, 197]{#_s_237 | the tag must be of length [DRBG-based]{#_s_230 .selectable-cont | \[**selection**: .selectable-content}\], \[[AES](#abbr_AE | [96]{#fcs_cop.1.1_KeyWrap_13 IV construction; the tag | .selectable-content}, must be of length \[**selection**: | [104]{#fcs_cop.1.1_KeyWrap_14 \[**selection**: [ISO/IEC 19772:2 | .selectable-content}, [96]{#_s_231 (Clause 10)]{#_s | [112]{#fcs_cop.1.1_KeyWrap_15 .selectable-content}, .selectable-cont | .selectable-content}, [104]{#_s_232 [[NIST](#abbr_NI | [120]{#fcs_cop.1.1_KeyWrap_16 .selectable-content}, 800-38D]{#_s_239 | .selectable-content}, [112]{#_s_233 .selectable-cont | [128]{#fcs_cop.1.1_KeyWrap_17 .selectable-content}, \[[GCM](#abbr_GC | .selectable-content}\] bits. [120]{#_s_234 | ----------------------------------------------------------------------------------- .selectable-content}, < [128]{#_s_235 < .selectable-content}\] < bits. < ----------------------------------------------------------------------------------- < : [Table [12]{.counter}]{#fcs-cop-kw-sels .ctr myid="fcs-cop-kw-sels" : [Table [12]{.counter}]{#fcs-cop-kw-sels .ctr myid="fcs-cop-kw-sels" counter-type="ct-Table"}: Allowable choices for counter-type="ct-Table"}: Allowable choices for [FCS_COP.1/KeyWrap](#FCS_COP.1/KeyWrap) [FCS_COP.1/KeyWrap](#FCS_COP.1/KeyWrap) ::: appnote ::: appnote [Application Note: ]{.note-header}[ [NIST](#abbr_NIST) 800-57p1rev5 sec. | [Application Note: ]{.note-header}[[NIST](#abbr_NIST) 800-57p1rev5 sec. 5.6.2 specifies that the size of key used to protect the key being 5.6.2 specifies that the size of key used to protect the key being transported should be at least the security strength of the key it is transported should be at least the security strength of the key it is protecting. ]{.note} | protecting.]{.note} ::: ::: ::: ::: ::: ::: ::: {.activity_pane .hide} ::: {.activity_pane .hide} ::: activity_pane_header ::: activity_pane_header [[ Evaluation Activities [[ Evaluation Activities ]{.activity_pane_label}[]{.toggler}](#){onclick="toggle(this);return false;"} ]{.activity_pane_label}[]{.toggler}](#){onclick="toggle(this);return false;"} ::: ::: ::: activity_pane_body ::: activity_pane_body ::: component-activity-header ::: component-activity-header [FCS_COP.1/KeyWrap](#FCS_COP.1/KeyWrap) [FCS_COP.1/KeyWrap](#FCS_COP.1/KeyWrap) ::: ::: ::: eacategory ::: eacategory [TSS](#abbr_TSS) [TSS](#abbr_TSS) ::: ::: ::: ea ::: ea ::: ea ::: ea The evaluator shall ensure that the [TSS](#abbr_TSS) documents that the The evaluator shall ensure that the [TSS](#abbr_TSS) documents that the selection of the key size is sufficient for the security strength of the selection of the key size is sufficient for the security strength of the key wrapped. key wrapped. The evaluator shall examine the [TSS](#abbr_TSS) to ensure that it The evaluator shall examine the [TSS](#abbr_TSS) to ensure that it describes the construction of any IVs, nonces, and MACs in conformance describes the construction of any IVs, nonces, and MACs in conformance with the relevant specifications. with the relevant specifications. ::: ::: ::: ::: ::: eacategory ::: eacategory Guidance Guidance ::: ::: ::: ea ::: ea There are no additional Guidance evaluation activities for this There are no additional Guidance evaluation activities for this component.\ component.\ ::: ::: ::: eacategory ::: eacategory Tests Tests ::: ::: ::: ea ::: ea ::: ea ::: ea For tests of [AES](#abbr_AES)-GCM and [AES](#abbr_AES)-CCM, see testing For tests of [AES](#abbr_AES)-GCM and [AES](#abbr_AES)-CCM, see testing for [FCS_COP.1/AEAD](#FCS_COP.1/AEAD). | for [FCS_COP.1/AEAD](#FCS_COP.1/AEAD). The following tests are | conditional based upon the selections made in the [SFR](#abbr_SFR). The The following tests are conditional based upon the selections made in | evaluator shall perform the following test or witness respective tests the [SFR](#abbr_SFR). The evaluator shall perform the following test or | executed by the developer. The tests must be executed on a platform that witness respective tests executed by the developer. The tests must be | is as close as practically possible to the operational platform (but executed on a platform that is as close as practically possible to the | which may be instrumented in terms of, for example, use of a debug operational platform (but which may be instrumented in terms of, for | mode). Where the test is not carried out on the [TOE](#abbr_TOE) itself, example, use of a debug mode). Where the test is not carried out on the | the test platform shall be identified and the differences between test [TOE](#abbr_TOE) itself, the test platform shall be identified and the | environment and [TOE](#abbr_TOE) execution environment shall be differences between test environment and [TOE](#abbr_TOE) execution | described.\ environment shall be described. < < \ < **[AES](#abbr_AES)-KW** **[AES](#abbr_AES)-KW** --------------------- ------------------ ----------------- ---------------------- --------------------- ------------------ ----------------- ---------------------- Identifier Cryptographic Cryptographic Key List of Standards Identifier Cryptographic Cryptographic Key List of Standards Algorithm Sizes Algorithm Sizes [AES](#abbr_AES)-KW [AES](#abbr_AES) 256 bits \[**selection:** [AES](#abbr_AES)-KW [AES](#abbr_AES) 256 bits \[**selection:** in KW mode ISO/IEC 18033-3:2010 in KW mode ISO/IEC 18033-3:2010 (Subclause 5.2), (Subclause 5.2), [FIPS](#abbr_FIPS) PUB [FIPS](#abbr_FIPS) PUB 197\] 197\] \[[AES](#abbr_AES)\] \[[AES](#abbr_AES)\] \[**selection:** \[**selection:** ISO/IEC 19772:2020 ISO/IEC 19772:2020 (clause 6), (clause 6), [NIST](#abbr_NIST) SP [NIST](#abbr_NIST) SP 800-38F (Section 800-38F (Section 6.2)\] \[KW mode\] 6.2)\] \[KW mode\] --------------------- ------------------ ----------------- ---------------------- --------------------- ------------------ ----------------- ---------------------- To test the [TOE](#abbr_TOE)'s ability to wrap keys using To test the [TOE](#abbr_TOE)'s ability to wrap keys using [AES](#abbr_AES) in Key Wrap mode the evaluator shall perform the [AES](#abbr_AES) in Key Wrap mode the evaluator shall perform the Algorithm Functional Tests using the following input parameters: Algorithm Functional Tests using the following input parameters: - Key size \[256\] bits - Key size \[256\] bits - Keyword cipher type \[cipher, inverse\] - Keyword cipher type \[cipher, inverse\] - Payload sizes \[128-4096\] bits by 64s - Payload sizes \[128-4096\] bits by 64s \ \ **Algorithm Functional Test** | **Algorithm Functional Test** The evaluator shall generate 100 | encryption test cases using random data for each combination of claimed The evaluator shall generate 100 encryption test cases using random data | key size, keyword cipher type, and six supported payload sizes such that for each combination of claimed key size, keyword cipher type, and six | the payload sizes include the minimum, the maximum, two that are supported payload sizes such that the payload sizes include the minimum, | divisible by 128, and two that are not divisible by 128. The results the maximum, two that are divisible by 128, and two that are not | shall be compared with those generated by a known-good implementation divisible by 128. | using the same inputs. The evaluator shall generate 100 decryption test | cases using the same parameters as above, but with 20 of each 100 test The results shall be compared with those generated by a known-good | cases having modified ciphertext to produce an incorrect result. To implementation using the same inputs. | determine correctness, the evaluator shall confirm that the results | correspond as expected for both the modified and unmodified values.\ The evaluator shall generate 100 decryption test cases using the same < parameters as above, but with 20 of each 100 test cases having modified < ciphertext to produce an incorrect result. To determine correctness, the < evaluator shall confirm that the results correspond as expected for both < the modified and unmodified values. < < \ < **[AES](#abbr_AES)-KWP** **[AES](#abbr_AES)-KWP** ---------------------- ------------------ ----------------- ---------------------- ---------------------- ------------------ ----------------- ---------------------- Identifier Cryptographic Cryptographic Key List of Standards Identifier Cryptographic Cryptographic Key List of Standards Algorithm Sizes Algorithm Sizes [AES](#abbr_AES)-KWP [AES](#abbr_AES) 256 bits \[**selection:** [AES](#abbr_AES)-KWP [AES](#abbr_AES) 256 bits \[**selection:** in KWP mode ISO/IEC 18033-3:2010 in KWP mode ISO/IEC 18033-3:2010 (Subclause 5.2), (Subclause 5.2), [FIPS](#abbr_FIPS) PUB [FIPS](#abbr_FIPS) PUB 197\] 197\] \[[AES](#abbr_AES)\] \[[AES](#abbr_AES)\] [NIST](#abbr_NIST) SP [NIST](#abbr_NIST) SP 800-38F (Section 6.3) 800-38F (Section 6.3) \[KWP mode\] \[KWP mode\] ---------------------- ------------------ ----------------- ---------------------- ---------------------- ------------------ ----------------- ---------------------- To test the [TOE](#abbr_TOE)'s ability to wrap keys using To test the [TOE](#abbr_TOE)'s ability to wrap keys using [AES](#abbr_AES) in Key Wrap with Padding mode with padding the [AES](#abbr_AES) in Key Wrap with Padding mode with padding the evaluator shall perform the Algorithm Functional Tests using the evaluator shall perform the Algorithm Functional Tests using the following input parameters: following input parameters: - Key size \[256\] bits - Key size \[256\] bits - Keyword cipher type \[cipher, inverse\] - Keyword cipher type \[cipher, inverse\] - Payload sizes \[8-4096\] bits by 8s - Payload sizes \[8-4096\] bits by 8s \ \ **Algorithm Functional Test** | **Algorithm Functional Test** The evaluator shall generate 100 | encryption test cases using random data for each combination of claimed The evaluator shall generate 100 encryption test cases using random data | key size, keyword cipher type, and six supported payload sizes such that for each combination of claimed key size, keyword cipher type, and six | the payload sizes include the minimum, the maximum, two that are supported payload sizes such that the payload sizes include the minimum, | divisible by 128, and two that are not divisible by 128. The results the maximum, two that are divisible by 128, and two that are not | shall be compared with those generated by a known-good implementation divisible by 128. | using the same inputs. The evaluator shall generate 100 decryption test | cases using the same parameters as above, but with 20 of each 100 test The results shall be compared with those generated by a known-good | cases having modified ciphertext to produce an incorrect result. To implementation using the same inputs. | determine correctness, the evaluator shall confirm that the results | correspond as expected for both the modified and unmodified values. The evaluator shall generate 100 decryption test cases using the same < parameters as above, but with 20 of each 100 test cases having modified < ciphertext to produce an incorrect result. To determine correctness, the < evaluator shall confirm that the results correspond as expected for both < the modified and unmodified values. < ::: ::: ::: ::: ::: ::: ::: ::: ::: ::: ::: {#FCS_COP.1/SigGen .comp} ::: {#FCS_COP.1/SigGen .comp} #### FCS_COP.1/SigGen Cryptographic Operation - Signature Generation #### FCS_COP.1/SigGen Cryptographic Operation - Signature Generation ::: element ::: element ::: {#FCS_COP.1.1/SigGen .reqid} ::: {#FCS_COP.1.1/SigGen .reqid} [FCS_COP.1.1/SigGen](#FCS_COP.1.1/SigGen){.abbr} [FCS_COP.1.1/SigGen](#FCS_COP.1.1/SigGen){.abbr} ::: ::: ::: reqdesc ::: reqdesc The [TSF](#abbr_TSF) shall perform \[*digital signature generation*\] in The [TSF](#abbr_TSF) shall perform \[*digital signature generation*\] in accordance with a specified cryptographic algorithm \[**selection**: accordance with a specified cryptographic algorithm \[**selection**: [Cryptographic Algorithm]{.selectable-content}\] and cryptographic key [Cryptographic Algorithm]{.selectable-content}\] and cryptographic key sizes \[**selection**: [Cryptographic Key Sizes]{.selectable-content}\] sizes \[**selection**: [Cryptographic Key Sizes]{.selectable-content}\] that meet the following: \[**selection**: [List of that meet the following: \[**selection**: [List of Standards]{.selectable-content}\] . Standards]{.selectable-content}\] . [Table [13]{.counter}](#fcs-cop-siggen-sels){.fcs-cop-siggen-sels-ref [Table [13]{.counter}](#fcs-cop-siggen-sels){.fcs-cop-siggen-sels-ref onclick="showTarget('fcs-cop-siggen-sels')"} provides the allowable onclick="showTarget('fcs-cop-siggen-sels')"} provides the allowable choices for completion of the selection operations in choices for completion of the selection operations in [FCS_COP.1/SigGen](#FCS_COP.1/SigGen). [FCS_COP.1/SigGen](#FCS_COP.1/SigGen). +-----------------+-----------------+-----------------+-----------------+ +-----------------+-----------------+-----------------+-----------------+ | Identifier | Cryptographic | Cryptographic | List of | | Identifier | Cryptographic | Cryptographic | List of | | | Algorithm | Key Sizes | Standards | | | Algorithm | Key Sizes | Standards | +=================+=================+=================+=================+ +=================+=================+=================+=================+ | [RSA]( | RS | Modulus of size | RFC 8017 | | [RSA]( | RS | Modulus of size | RFC 8017 | | #abbr_RSA)-PKCS | ASSA-PKCS1-v1_5 | \ | (Section 8.2) | | #abbr_RSA)-PKCS | ASSA-PKCS1-v1_5 | \ | (Section 8.2) | | | | [**selection**: | \[PKCS #1 | | | | [**selection**: | \[PKCS #1 | | | | [ | v2.2\] | | | | | [*3072*]{#fcs_c | v2.2\] | | | | *3072*]{#_s_241 | | | | | | op.1.1_SigGen_1 | | | | | .selec | [FI | | | | .selec | [FI | | | | table-content}, | PS](#abbr_FIPS) | | | | table-content}, | PS](#abbr_FIPS) | | | | [ | PUB 186-5 | | | | | [*4096*]{#fcs_c | PUB 186-5 | | | | *4096*]{#_s_242 | (Section 5.4) | | | | | op.1.1_SigGen_2 | (Section 5.4) | | | | .selec | \[RSAS | | | | .selec | \[RSAS | | | | table-content}, | SA-PKCS1-v1_5\] | | | | table-content}, | SA-PKCS1-v1_5\] | | | | [ | | | | | | [*6144*]{#fcs_c | | | | | *6144*]{#_s_243 | | | | | | op.1.1_SigGen_3 | | | | | .selec | | | | | .selec | | | | | table-content}, | | | | | table-content}, | | | | | [ | | | | | | [*8192*]{#fcs_c | | | | | *8192*]{#_s_244 | | | | | | op.1.1_SigGen_4 | | | | | .select | | | | | .select | | | | | able-content}\] | | | | | able-content}\] | | | | | bits, hash | | | | | bits, hash | | | | | \ | | | | | \ | | | | | [**selection**: | | | | | [**selection**: | | | | | [* | | | | | | [ | | | | | [SHA](#abbr_SHA | | | | | | *[SHA](#abbr_SH | | | | | )-384*]{#_s_245 | | | | | | A)-384*]{#fcs_c | | > | | | op.1.1_SigGen_5 | | | | | .selec | | | | | .selec | | | | | table-content}, | | | | | table-content}, | | | | | [* | | | | | | [ | | | | | [SHA](#abbr_SHA | | | | | | *[SHA](#abbr_SH | | | | | )-512*]{#_s_246 | | | | | | A)-512*]{#fcs_c | | > | | | op.1.1_SigGen_6 | | | | | .select | | | | | .select | | | | | able-content}\] | | | | | able-content}\] | | +-----------------+-----------------+-----------------+-----------------+ +-----------------+-----------------+-----------------+-----------------+ | [RSA] | RSASSA-PSS | Modulus of size | RFC 8017 | | [RSA] | RSASSA-PSS | Modulus of size | RFC 8017 | | (#abbr_RSA)-PSS | | \ | (Section 8.1) | | (#abbr_RSA)-PSS | | \ | (Section 8.1) | | | | [**selection**: | \[PKCS#1 v2.2\] | | | | [**selection**: | \[PKCS#1 v2.2\] | | | | [ | | | | | | [*3072*]{#fcs_c | | | | | *3072*]{#_s_248 | [FI | | | | | op.1.1_SigGen_7 | [FI | | | | .selec | PS](#abbr_FIPS) | | | | .selec | PS](#abbr_FIPS) | | | | table-content}, | PUB 186-5 | | | | table-content}, | PUB 186-5 | | | | [ | (Section 5.4) | | | | | [*4096*]{#fcs_c | (Section 5.4) | | | | *4096*]{#_s_249 | \[RSASSA-PSS\] | | | | | op.1.1_SigGen_8 | \[RSASSA-PSS\] | | | | .selec | | | | | .selec | | | | | table-content}, | | | | | table-content}, | | | | | [ | | | | | | [*6144*]{#fcs_c | | | | | *6144*]{#_s_250 | | | | | | op.1.1_SigGen_9 | | | | | .selec | | | | | .selec | | | | | table-content}, | | | | | table-content}, | | | | | [ | | | | | [ | | | | | *8192*]{#_s_251 | | | | | | *8192*]{#fcs_co | | > | | | p.1.1_SigGen_10 | | | | | .select | | | | | .select | | | | | able-content}\] | | | | | able-content}\] | | | | | bits, hash | | | | | bits, hash | | | | | \ | | | | | \ | | | | | [**selection**: | | | | | [**selection**: | | | | | [* | | | | | [* | | | | | [SHA](#abbr_SHA | | | | | [SHA](#abbr_SHA | | | | | )-384*]{#_s_252 | | | | | | )-384*]{#fcs_co | | > | | | p.1.1_SigGen_11 | | | | | .selec | | | | | .selec | | | | | table-content}, | | | | | table-content}, | | | | | [* | | | | | [* | | | | | [SHA](#abbr_SHA | | | | | [SHA](#abbr_SHA | | | | | )-512*]{#_s_253 | | | | | | )-512*]{#fcs_co | | > | | | p.1.1_SigGen_12 | | | | | .selecta | | | | | .selecta | | | | | ble-content}\], | | | | | ble-content}\], | | | | | Salt Length | | | | | Salt Length | | | | | (*sLen*) such | | | | | (*sLen*) such | | | | | that | | | | | that | | | | | \[ | | | | | \[ | | | | | **assignment**: | | | | | **assignment**: | | | | | [*0 ≤ *sLen* ≤ | | | | | | [0 ≤ sLen ≤ | | | | | *hLen* (Hash | | | | | | hLen (Hash | | | | | Output | | | | | Output | | | | | Le | | | | | | L | | | | | ngth)*]{.assign | | | | | | ength)]{.assign | | | | | able-content}\] | | | | | able-content}\] | | | | | and Mask | | | | | and Mask | | | | | Generation | | | | | Generation | | | | | Function = MGF1 | | | | | Function = MGF1 | | +-----------------+-----------------+-----------------+-----------------+ +-----------------+-----------------+-----------------+-----------------+ | [ECDS | [ECDS | Elliptic Curve | \ | | [ECDS | [ECDS | Elliptic Curve | \ | | A](#abbr_ECDSA) | A](#abbr_ECDSA) | \ | [**selection**: | | A](#abbr_ECDSA) | A](#abbr_ECDSA) | \ | [**selection**: | | | | [**selection**: | [*ISO/IEC | | | | [**selection**: | [*ISO/IEC | | | | [* | 14888-3:2018 | | | | [* | 14888-3:2018 | | | | P-384*]{#_s_255 | (Subclause | | | | | P-384*]{#fcs_co | (Subclause | | | | .selec | 6.6)*]{#_s_262 | | | | | p.1.1_SigGen_13 | 6.6)*]{#fcs_co | > | | | .selec | p.1.1_SigGen_20 | | | | table-content}, | .selec | | | | table-content}, | .selec | | | | [* | table-content}, | | | | [* | table-content}, | | | | P-521*]{#_s_256 | [*[FI | | | | | P-521*]{#fcs_co | [*[FI | | | | .selecta | PS](#abbr_FIPS) | | | | | p.1.1_SigGen_14 | PS](#abbr_FIPS) | | | | ble-content}\], | PUB 186-5 | | | | | .selecta | PUB 186-5 | | | | per-message | (Sections | | | | | ble-content}\], | (Sections | | | | secret number | 6.3.1, | | | | | per-message | 6.3.1, | | | | generation | 6.4.1*]{#_s_263 | | | | | secret number | 6.4.1*]{#fcs_co | | | | \ | . | | | | | generation | p.1.1_SigGen_21 | | | | [**selection**: | selectable-cont | | | | | \ | .select | | | | [*extra random | ent}\]\[[ECDSA] | | | | | [**selection**: | able-content}\] | | | | bits*]{#_s_257 | (#abbr_ECDSA)\] | | | | | [*extra random | \[[ECDSA] | | | | .selec | | | | | | bits*]{#fcs_co | (#abbr_ECDSA)\] | | | | table-content}, | [NI | | | | | p.1.1_SigGen_15 | | | | | [*rejection | ST](#abbr_NIST) | | | | | .selec | [NI | | | | sam | SP-800 186 | < | | | pling*]{#_s_258 | (Section 4) | < | | | .selec | \[[NI | < | | | table-content}, | ST](#abbr_NIST) | | | | table-content}, | ST](#abbr_NIST) | | | | [*determin | Curves\] | | | | | [*rejection | SP-800 186 | | | | istic*]{#_s_259 | | | | | | sam | (Section 4) | > | | | pling*]{#fcs_co | \[[NI | > | | | p.1.1_SigGen_16 | ST](#abbr_NIST) | > | | | .selec | Curves\] | > | | | table-content}, | | > | | | [*determin | | > | | | istic*]{#fcs_co | | > | | | p.1.1_SigGen_17 | | | | | .select | | | | | .select | | | | | able-content}\] | | | | | able-content}\] | | | | | and hash | | | | | and hash | | | | | function using | | | | | function using | | | | | \ | | | | | \ | | | | | [**selection**: | | | | | [**selection**: | | | | | [* | | | | | [* | | | | | [SHA](#abbr_SHA | | | | | [SHA](#abbr_SHA | | | | | )-384*]{#_s_260 | | | | | | )-384*]{#fcs_co | | > | | | p.1.1_SigGen_18 | | | | | .selec | | | | | .selec | | | | | table-content}, | | | | | table-content}, | | | | | [* | | | | | [* | | | | | [SHA](#abbr_SHA | | | | | [SHA](#abbr_SHA | | | | | )-512*]{#_s_261 | | | | | | )-512*]{#fcs_co | | > | | | p.1.1_SigGen_19 | | | | | .select | | | | | .select | | | | | able-content}\] | | | | | able-content}\] | | +-----------------+-----------------+-----------------+-----------------+ +-----------------+-----------------+-----------------+-----------------+ | LMS | LMS | Private key | RFC 8554 | | LMS | LMS | Private key | RFC 8554 | | | | size = | \[LMS\] | | | | size = | \[LMS\] | | | | \ | | | | | \ | | | | | [**selection**: | [NI | | | | [**selection**: | [NI | | | | | ST](#abbr_NIST) | | | | | ST](#abbr_NIST) | | | | - [192 bits | SP 800-208 | | | | - [192 bits | SP 800-208 | | | | with | \[parameters\] | | | | with | \[parameters\] | | | | \ | | | | | \ | | | | | [**selection**: | | | | | [**selection**: | | | | | [[SH | | | | | [[SH | | | | | A](#abbr_SHA)-2 | | | | | A](#abbr_SHA)-2 | | | | | 56/192]{#_s_266 | | | | | | 56/192]{#fcs_co | | > | | | p.1.1_SigGen_23 | | | | | .selec | | | | | .selec | | | | | table-content}, | | | | | table-content}, | | | | | [SHAKE2 | | | | | [SHAKE2 | | | | | 56/192]{#_s_267 | | | | | | 56/192]{#fcs_co | | > | | | p.1.1_SigGen_24 | | | | | . | | | | | . | | | | | selectable-cont | | | | | selectable-cont | | | | | ent}\]]{#_s_265 | | | | | | ent}\]]{#fcs_co | | > | | | p.1.1_SigGen_22 | | | | | .sele | | | | | .sele | | | | | ctable-content} | | | | | ctable-content} | | | | | - [256 bits | | | | | - [256 bits | | | | | with | | | | | with | | | | | \ | | | | | \ | | | | | [**selection**: | | | | | [**selection**: | | | | | | | | | | | | | | | [[SHA](#abbr_SH | | | | | [[SHA](#abbr_SH | | | | | A)-256]{#_s_269 | | | | | | A)-256]{#fcs_co | | > | | | p.1.1_SigGen_26 | | | | | .selec | | | | | .selec | | | | | table-content}, | | | | | table-content}, | | | | | [SH | | | | | [SH | | | | | AKE256]{#_s_270 | | | | | | AKE256]{#fcs_co | | > | | | p.1.1_SigGen_27 | | | | | . | | | | | . | | | | | selectable-cont | | | | | selectable-cont | | | | | ent}\]]{#_s_268 | | | | | | ent}\]]{#fcs_co | | > | | | p.1.1_SigGen_25 | | | | | .sele | | | | | .sele | | | | | ctable-content} | | | | | ctable-content} | | | | | | | | | | | | | | | \] | | | | | \] | | | | | | | | | | | | | | | Winternitz | | | | | Winternitz | | | | | parameter = | | | | | parameter = | | | | | \ | | | | | \ | | | | | [**selection**: | | | | | [**selection**: | | | | | [1]{#_s_271 | | | | | | [1]{#fcs_co | | > | | | p.1.1_SigGen_28 | | | | | .selec | | | | | .selec | | | | | table-content}, | | | | | table-content}, | | | | | [2]{#_s_272 | | | | | | [2]{#fcs_co | | > | | | p.1.1_SigGen_29 | | | | | .selec | | | | | .selec | | | | | table-content}, | | | | | table-content}, | | | | | [4]{#_s_273 | | | | | | [4]{#fcs_co | | > | | | p.1.1_SigGen_30 | | | | | .selec | | | | | .selec | | | | | table-content}, | | | | | table-content}, | | | | | [8]{#_s_274 | | | | | | [8]{#fcs_co | | > | | | p.1.1_SigGen_31 | | | | | .select | | | | | .select | | | | | able-content}\] | | | | | able-content}\] | | | | | | | | | | | | | | | Tree height = | | | | | Tree height = | | | | | \ | | | | | \ | | | | | [**selection**: | | | | | [**selection**: | | | | | [5]{#_s_275 | | | | | | [5]{#fcs_co | | > | | | p.1.1_SigGen_32 | | | | | .selec | | | | | .selec | | | | | table-content}, | | | | | table-content}, | | | | | [10]{#_s_276 | | | | | | [10]{#fcs_co | | > | | | p.1.1_SigGen_33 | | | | | .selec | | | | | .selec | | | | | table-content}, | | | | | table-content}, | | | | | [15]{#_s_277 | | | | | | [15]{#fcs_co | | > | | | p.1.1_SigGen_34 | | | | | .selec | | | | | .selec | | | | | table-content}, | | | | | table-content}, | | | | | [20]{#_s_278 | | | | | | [20]{#fcs_co | | > | | | p.1.1_SigGen_35 | | | | | .selec | | | | | .selec | | | | | table-content}, | | | | | table-content}, | | | | | [25]{#_s_279 | | | | | | [25]{#fcs_co | | > | | | p.1.1_SigGen_36 | | | | | .select | | | | | .select | | | | | able-content}\] | | | | | able-content}\] | | +-----------------+-----------------+-----------------+-----------------+ +-----------------+-----------------+-----------------+-----------------+ | ML-DSA | ML-DSA | Parameter set = | [NI | | ML-DSA | ML-DSA | Parameter set = | [NI | | | Signature | ML-DSA-87 | ST](#abbr_NIST) | | | Signature | ML-DSA-87 | ST](#abbr_NIST) | | | Generation | | [FI | | | Generation | | [FI | | | | | PS](#abbr_FIPS) | | | | | PS](#abbr_FIPS) | | | | | 204 (Section | | | | | 204 (Section | | | | | 5.2) | | | | | 5.2) | +-----------------+-----------------+-----------------+-----------------+ +-----------------+-----------------+-----------------+-----------------+ | XMSS | XMSS | Private key | RFC 8391 | | XMSS | XMSS | Private key | RFC 8391 | | | | size = | \[XMSS\] | | | | size = | \[XMSS\] | | | | \ | | | | | \ | | | | | [**selection**: | [NI | | | | [**selection**: | [NI | | | | | ST](#abbr_NIST) | | | | | ST](#abbr_NIST) | | | | - [192 bits | SP 800-208 | | | | - [192 bits | SP 800-208 | | | | with | \[parameters\] | | | | with | \[parameters\] | | | | \ | | | | | \ | | | | | [**selection**: | | | | | [**selection**: | | | | | [[SH | | | | | [[SH | | | | | A](#abbr_SHA)-2 | | | | | A](#abbr_SHA)-2 | | | | | 56/192]{#_s_283 | | | | | | 56/192]{#fcs_co | | > | | | p.1.1_SigGen_38 | | | | | .selec | | | | | .selec | | | | | table-content}, | | | | | table-content}, | | | | | [SHAKE2 | | | | | [SHAKE2 | | | | | 56/192]{#_s_284 | | | | | | 56/192]{#fcs_co | | > | | | p.1.1_SigGen_39 | | | | | . | | | | | . | | | | | selectable-cont | | | | | selectable-cont | | | | | ent}\]]{#_s_282 | | | | | | ent}\]]{#fcs_co | | > | | | p.1.1_SigGen_37 | | | | | .sele | | | | | .sele | | | | | ctable-content} | | | | | ctable-content} | | | | | - [256 bits | | | | | - [256 bits | | | | | with | | | | | with | | | | | \ | | | | | \ | | | | | [**selection**: | | | | | [**selection**: | | | | | | | | | | | | | | | [[SHA](#abbr_SH | | | | | [[SHA](#abbr_SH | | | | | A)-256]{#_s_286 | | | | | | A)-256]{#fcs_co | | > | | | p.1.1_SigGen_41 | | | | | .selec | | | | | .selec | | | | | table-content}, | | | | | table-content}, | | | | | [SH | | | | | [SH | | | | | AKE256]{#_s_287 | | | | | | AKE256]{#fcs_co | | > | | | p.1.1_SigGen_42 | | | | | . | | | | | . | | | | | selectable-cont | | | | | selectable-cont | | | | | ent}\]]{#_s_285 | | | | | | ent}\]]{#fcs_co | | > | | | p.1.1_SigGen_40 | | | | | .sele | | | | | .sele | | | | | ctable-content} | | | | | ctable-content} | | | | | | | | | | | | | | | \] | | | | | \] | | | | | | | | | | | | | | | Tree height = | | | | | Tree height = | | | | | \ | | | | | \ | | | | | [**selection**: | | | | | [**selection**: | | | | | [10]{#_s_288 | | | | | | [10]{#fcs_co | | > | | | p.1.1_SigGen_43 | | | | | .selec | | | | | .selec | | | | | table-content}, | | | | | table-content}, | | | | | [16]{#_s_289 | | | | | | [16]{#fcs_co | | > | | | p.1.1_SigGen_44 | | | | | .selec | | | | | .selec | | | | | table-content}, | | | | | table-content}, | | | | | [20]{#_s_290 | | | | | | [20]{#fcs_co | | > | | | p.1.1_SigGen_45 | | | | | .select | | | | | .select | | | | | able-content}\] | | | | | able-content}\] | | +-----------------+-----------------+-----------------+-----------------+ +-----------------+-----------------+-----------------+-----------------+ : [Table [13]{.counter}]{#fcs-cop-siggen-sels .ctr : [Table [13]{.counter}]{#fcs-cop-siggen-sels .ctr myid="fcs-cop-siggen-sels" counter-type="ct-Table"}: Allowable choices myid="fcs-cop-siggen-sels" counter-type="ct-Table"}: Allowable choices for [FCS_COP.1/SigGen](#FCS_COP.1/SigGen) for [FCS_COP.1/SigGen](#FCS_COP.1/SigGen) ::: ::: ::: ::: ::: {.activity_pane .hide} ::: {.activity_pane .hide} ::: activity_pane_header ::: activity_pane_header [[ Evaluation Activities [[ Evaluation Activities ]{.activity_pane_label}[]{.toggler}](#){onclick="toggle(this);return false;"} ]{.activity_pane_label}[]{.toggler}](#){onclick="toggle(this);return false;"} ::: ::: ::: activity_pane_body ::: activity_pane_body ::: component-activity-header ::: component-activity-header [FCS_COP.1/SigGen](#FCS_COP.1/SigGen) [FCS_COP.1/SigGen](#FCS_COP.1/SigGen) ::: ::: ::: eacategory ::: eacategory [TSS](#abbr_TSS) [TSS](#abbr_TSS) ::: ::: ::: ea ::: ea ::: ea ::: ea The evaluator shall examine the [TSS](#abbr_TSS) and verify that any The evaluator shall examine the [TSS](#abbr_TSS) and verify that any hash function is the appropriate security strength for the signing hash function is the appropriate security strength for the signing algorithm. algorithm. The evaluator shall examine the [TSS](#abbr_TSS) to verify that any The evaluator shall examine the [TSS](#abbr_TSS) to verify that any one-time values such as nonces or masks are constructed and used in one-time values such as nonces or masks are constructed and used in accordance with the relevant standards. accordance with the relevant standards. The evaluator shall examine the [TSS](#abbr_TSS) to verify that the The evaluator shall examine the [TSS](#abbr_TSS) to verify that the [TOE](#abbr_TOE) has appropriate measures in place to ensure that [TOE](#abbr_TOE) has appropriate measures in place to ensure that hash-based signature algorithms do not reuse private keys. hash-based signature algorithms do not reuse private keys. ::: ::: ::: ::: ::: eacategory ::: eacategory Guidance Guidance ::: ::: ::: ea ::: ea There are no additional Guidance evaluation activities for this There are no additional Guidance evaluation activities for this component.\ component.\ ::: ::: ::: eacategory ::: eacategory Tests Tests ::: ::: ::: ea ::: ea ::: ea ::: ea The following tests are conditional based on the selections made in the The following tests are conditional based on the selections made in the [SFR](#abbr_SFR). The evaluator shall perform the following tests or [SFR](#abbr_SFR). The evaluator shall perform the following tests or witness respective tests executed by the developer. The tests must be witness respective tests executed by the developer. The tests must be executed on a platform that is as close as practically possible to the executed on a platform that is as close as practically possible to the operational platform (but which may be instrumented in terms of, for operational platform (but which may be instrumented in terms of, for example, use of a debug mode). Where the test is not carried out on the example, use of a debug mode). Where the test is not carried out on the [TOE](#abbr_TOE) itself, the test platform shall be identified and the [TOE](#abbr_TOE) itself, the test platform shall be identified and the differences between test environment and [TOE](#abbr_TOE) execution differences between test environment and [TOE](#abbr_TOE) execution environment shall be described. | environment shall be described.\ < \ < **[RSA](#abbr_RSA)-PKCS Signature Generation** **[RSA](#abbr_RSA)-PKCS Signature Generation** ----------------------- ------------------- ------------------------- ------------- ----------------------- ------------------- ------------------------- ------------- Identifier Cryptographic Cryptographic Key Sizes List of Stand Identifier Cryptographic Cryptographic Key Sizes List of Stand Algorithm Algorithm Parameters Parameters [RSA](#abbr_RSA)-PKCS RSASSA-PKCS1-v1_5 Modulus of size RFC 8017 (Sec [RSA](#abbr_RSA)-PKCS RSASSA-PKCS1-v1_5 Modulus of size RFC 8017 (Sec \[**selection:** *3072, \[PKCS #1 v2. \[**selection:** *3072, \[PKCS #1 v2. 4096, 6144, 8192*\] bits, 4096, 6144, 8192*\] bits, hash \[**selection:** [NIST](#abbr_ hash \[**selection:** [NIST](#abbr_ *[SHA](#abbr_SHA)-384, [FIPS](#abbr_ *[SHA](#abbr_SHA)-384, [FIPS](#abbr_ [SHA](#abbr_SHA)-512*\] 186-5 (Sectio [SHA](#abbr_SHA)-512*\] 186-5 (Sectio \[RSASSA-PKCS \[RSASSA-PKCS ----------------------- ------------------- ------------------------- ------------- ----------------------- ------------------- ------------------------- ------------- To test the [TOE](#abbr_TOE)'s ability to perform [RSA](#abbr_RSA) To test the [TOE](#abbr_TOE)'s ability to perform [RSA](#abbr_RSA) Digital Signature Generation using PKCS1-v1_5 signature type, the Digital Signature Generation using PKCS1-v1_5 signature type, the evaluator shall perform the Generated Data Test using the following evaluator shall perform the Generated Data Test using the following input parameters: input parameters: - Modulus size \[3072, 4096, 6144, 8192\] bits - Modulus size \[3072, 4096, 6144, 8192\] bits - Hash algorithm \[[SHA](#abbr_SHA)-384, [SHA](#abbr_SHA)-512\] - Hash algorithm \[[SHA](#abbr_SHA)-384, [SHA](#abbr_SHA)-512\] \ \ **Generated Data Test** | **Generated Data Test** For each supported combination of the above | parameters, the evaluator shall cause the [TOE](#abbr_TOE) to generate For each supported combination of the above parameters, the evaluator | three test cases using random data. The evaluator shall compare the shall cause the [TOE](#abbr_TOE) to generate three test cases using | results against those from a known good implementation.\ random data. The evaluator shall compare the results against those from < a known good implementation. < < \ < **[RSA](#abbr_RSA)-PSS Signature Generation** **[RSA](#abbr_RSA)-PSS Signature Generation** ---------------------- ----------------- -------------------------- --------------- ---------------------- ----------------- -------------------------- --------------- Identifier Cryptographic Cryptographic Key Sizes List of Standar Identifier Cryptographic Cryptographic Key Sizes List of Standar Algorithm Algorithm Parameters Parameters [RSA](#abbr_RSA)-PSS RSASSA-PSS Modulus of size RFC 8017 (Secti [RSA](#abbr_RSA)-PSS RSASSA-PSS Modulus of size RFC 8017 (Secti \[**selection:** *3072, 8.2) \[PKCS #1 \[**selection:** *3072, 8.2) \[PKCS #1 4096, 6144, 8192*\] bits, v2.2\] 4096, 6144, 8192*\] bits, v2.2\] hash \[**selection:** hash \[**selection:** *[SHA](#abbr_SHA)-384, [NIST](#abbr_NI *[SHA](#abbr_SHA)-384, [NIST](#abbr_NI [SHA](#abbr_SHA)-512*\], [FIPS](#abbr_FI [SHA](#abbr_SHA)-512*\], [FIPS](#abbr_FI Salt Length (*sLen*) such PUB 186-5 (Sect Salt Length (*sLen*) such PUB 186-5 (Sect that \[**assignment:** *0 5.4) \[RSASSA-P that \[**assignment:** *0 5.4) \[RSASSA-P ≤ *sLen* ≤ *hLen* (Hash ≤ *sLen* ≤ *hLen* (Hash Output Length)*\] and Mask Output Length)*\] and Mask Generation Function = MGF1 Generation Function = MGF1 ---------------------- ----------------- -------------------------- --------------- ---------------------- ----------------- -------------------------- --------------- To test the [TOE](#abbr_TOE)'s ability to perform [RSA](#abbr_RSA) To test the [TOE](#abbr_TOE)'s ability to perform [RSA](#abbr_RSA) Digital Signature Generation using PSS signature type, the evaluator Digital Signature Generation using PSS signature type, the evaluator shall perform the Generated Data Test using the following input shall perform the Generated Data Test using the following input parameters: parameters: - Modulus size \[3072, 4096, 6144, 8192\] bits - Modulus size \[3072, 4096, 6144, 8192\] bits - Hash algorithm \[[SHA](#abbr_SHA)-384, [SHA](#abbr_SHA)-512\] - Hash algorithm \[[SHA](#abbr_SHA)-384, [SHA](#abbr_SHA)-512\] - Salt length \[Fixed based on implementation\] - Salt length \[Fixed based on implementation\] - Mask function \[MGF1\] - Mask function \[MGF1\] \ \ **Generated Data Test** | **Generated Data Test** For each supported combination of the above | parameters, the evaluator shall cause the [TOE](#abbr_TOE) to generate For each supported combination of the above parameters, the evaluator | three test cases using random data. The evaluator shall compare the shall cause the [TOE](#abbr_TOE) to generate three test cases using | results against those from a known good implementation.\ random data. The evaluator shall compare the results against those from < a known good implementation. < < \ < **[ECDSA](#abbr_ECDSA) Signature Generation** **[ECDSA](#abbr_ECDSA) Signature Generation** ---------------------- ---------------------- ------------------------- ----------- ---------------------- ---------------------- ------------------------- ----------- Identifier Cryptographic Cryptographic Key Sizes List of Sta Identifier Cryptographic Cryptographic Key Sizes List of Sta Algorithm Parameters Algorithm Parameters [ECDSA](#abbr_ECDSA) [ECDSA](#abbr_ECDSA) Elliptic Curve \[**selecti [ECDSA](#abbr_ECDSA) [ECDSA](#abbr_ECDSA) Elliptic Curve \[**selecti \[**selection:** *P-384, 14888-3:201 \[**selection:** *P-384, 14888-3:201 P-521*\], per-message 6.6), [NIST P-521*\], per-message 6.6), [NIST secret number generation [FIPS](#abb secret number generation [FIPS](#abb \[**selection:** *extra 186-5 (Sect \[**selection:** *extra 186-5 (Sect random bits, rejection 6.4.1*\] random bits, rejection 6.4.1*\] sampling, \[[ECDSA](# sampling, \[[ECDSA](# deterministic*\] and hash deterministic*\] and hash function using [NIST](#abb function using [NIST](#abb \[**selection:** 186 (Sectio \[**selection:** 186 (Sectio *[SHA](#abbr_SHA)-384, \[[NIST](#a *[SHA](#abbr_SHA)-384, \[[NIST](#a [SHA](#abbr_SHA)-512*\] Curves\] [SHA](#abbr_SHA)-512*\] Curves\] ---------------------- ---------------------- ------------------------- ----------- ---------------------- ---------------------- ------------------------- ----------- To test the [TOE](#abbr_TOE)'s ability to perform [ECDSA](#abbr_ECDSA) To test the [TOE](#abbr_TOE)'s ability to perform [ECDSA](#abbr_ECDSA) Digital Signature Generation using extra random bits or rejection Digital Signature Generation using extra random bits or rejection sampling for secret number generation, the evaluator shall perform the sampling for secret number generation, the evaluator shall perform the Algorithm Functional Test using the following input parameters: Algorithm Functional Test using the following input parameters: - Elliptic Curve \[P-384, P-521\] - Elliptic Curve \[P-384, P-521\] - Hash algorithm \[[SHA](#abbr_SHA)-384, [SHA](#abbr_SHA)-512\] - Hash algorithm \[[SHA](#abbr_SHA)-384, [SHA](#abbr_SHA)-512\] To test the [TOE](#abbr_TOE)'s ability to perform [ECDSA](#abbr_ECDSA) To test the [TOE](#abbr_TOE)'s ability to perform [ECDSA](#abbr_ECDSA) Digital Signature Generation using deterministic secret number Digital Signature Generation using deterministic secret number generation, the evaluator shall perform the Algorithm Functional Test generation, the evaluator shall perform the Algorithm Functional Test using the following input parameters: using the following input parameters: - Elliptic Curve \[P-384, P-521\] - Elliptic Curve \[P-384, P-521\] - Hash algorithm \[[SHA](#abbr_SHA)-384, [SHA](#abbr_SHA)-512\] - Hash algorithm \[[SHA](#abbr_SHA)-384, [SHA](#abbr_SHA)-512\] \ \ **Algorithm Functional Test** | **Algorithm Functional Test** For each supported combination of the | above parameters, the evaluator shall cause the [TOE](#abbr_TOE) to For each supported combination of the above parameters, the evaluator | generate 10 test cases using random data. The evaluator shall compare shall cause the [TOE](#abbr_TOE) to generate 10 test cases using random | the results against those from a known good implementation.\ data. The evaluator shall compare the results against those from a known < good implementation. < < \ < **LMS Signature Generation** **LMS Signature Generation** ----------------- ----------------- ----------------------- -------------------- ----------------- ----------------- ----------------------- -------------------- Identifier Cryptographic Cryptographic Key Sizes List of Standards Identifier Cryptographic Cryptographic Key Sizes List of Standards Algorithm Algorithm Parameters Parameters LMS LMS Private key size = RFC 8554 \[LMS\] LMS LMS Private key size = RFC 8554 \[LMS\] \[**selection:** 192 \[**selection:** 192 bits with [NIST](#abbr_NIST) bits with [NIST](#abbr_NIST) \[**selection:** SP 800-208 \[**selection:** SP 800-208 SHA256/192, \[parameters\] SHA256/192, \[parameters\] SHAKE256/192\], 256 SHAKE256/192\], 256 bits with bits with \[**selection:** \[**selection:** [SHA](#abbr_SHA)-256, [SHA](#abbr_SHA)-256, SHAKE256\]\], SHAKE256\]\], Winternitz parameter = Winternitz parameter = \[**selection:** 1, 2, \[**selection:** 1, 2, 4, 8\], and tree height 4, 8\], and tree height = \[**selection:** 5, = \[**selection:** 5, 10, 15, 20, 25\] 10, 15, 20, 25\] ----------------- ----------------- ----------------------- -------------------- ----------------- ----------------- ----------------------- -------------------- To test the [TOE](#abbr_TOE)'s ability to generate cryptographic digital To test the [TOE](#abbr_TOE)'s ability to generate cryptographic digital signature using LMS, the evaluator shall perform the Algorithm signature using LMS, the evaluator shall perform the Algorithm Functional Test using the following input parameters: Functional Test using the following input parameters: - Hash algorithm \[[SHA](#abbr_SHA)-256/192, SHAKE256/192, - Hash algorithm \[[SHA](#abbr_SHA)-256/192, SHAKE256/192, [SHA](#abbr_SHA)-256, SHAKE256\] [SHA](#abbr_SHA)-256, SHAKE256\] - Winternitz \[1, 2, 4, 8\] - Winternitz \[1, 2, 4, 8\] - Tree height \[5, 10, 15, 20, 25\] - Tree height \[5, 10, 15, 20, 25\] \ \ **Algorithm Functional Test** | **Algorithm Functional Test** For each supported combination of the | above parameters, the evaluator shall generate 10 signatures. The For each supported combination of the above parameters, the evaluator | evaluator shall verify the correctness of the implementation by shall generate 10 signatures. The evaluator shall verify the correctness | comparing values generated by the [TOE](#abbr_TOE) with those generated of the implementation by comparing values generated by the | by a known good implementation using the same input parameters.\ [TOE](#abbr_TOE) with those generated by a known good implementation < using the same input parameters. < < \ < **ML-DSA Signature Generation** **ML-DSA Signature Generation** ------------ ------------------------------------ --------------------------- ----- ------------ ------------------------------------ --------------------------- ----- Identifier Cryptographic Algorithm Parameters Cryptographic Key Sizes List Identifier Cryptographic Algorithm Parameters Cryptographic Key Sizes List ML-DSA ML-DSA SigGen Parameter set = ML-DSA-87 [NIST ML-DSA ML-DSA SigGen Parameter set = ML-DSA-87 [NIST ------------ ------------------------------------ --------------------------- ----- ------------ ------------------------------------ --------------------------- ----- To test the [TOE](#abbr_TOE)'s ability to generate digital signatures To test the [TOE](#abbr_TOE)'s ability to generate digital signatures using ML-DSA, the evaluator shall perform the Algorithm Functional Test using ML-DSA, the evaluator shall perform the Algorithm Functional Test using the following input parameters: using the following input parameters: - Parameter set \[ML-DSA-87\] - Parameter set \[ML-DSA-87\] - Seed \[32 random bytes\] (for non-deterministic signature testing), - Seed \[32 random bytes\] (for non-deterministic signature testing), or or - Seed \[32 zero bytes\] (for deterministic signature testing) - Seed \[32 zero bytes\] (for deterministic signature testing) - Message to sign \[8-65535\] bytes - Message to sign \[8-65535\] bytes - *Mu* value (if generated externally) - *Mu* value (if generated externally) - Previously generated private key (*sk*) - Previously generated private key (*sk*) - Context (for external interface testing) - Context (for external interface testing) \ \ **Algorithm Functional Test** | **Algorithm Functional Test** For each combination of supported | parameter set and capabilities, the evaluator shall require the For each combination of supported parameter set and capabilities, the | implementation under test to generate 15 signatures pairs using 15 evaluator shall require the implementation under test to generate 15 | different randomly generated 32-byte seed values. To determine signatures pairs using 15 different randomly generated 32-byte seed | correctness, the evaluator shall compare the resulting key pairs with values. To determine correctness, the evaluator shall compare the | those generated using a known good implementation using the same resulting key pairs with those generated using a known good | inputs.\ implementation using the same inputs. | **Known Answer Test for Rejection Cases** For each supported parameter | set, the evaluator shall cause the [TOE](#abbr_TOE) to generate \ | signatures using the data below and a deterministic seed of all 0's. **Known Answer Test for Rejection Cases** | Correctness is determined by comparing the hash of the resulting | signature with the hash in the fourth row for each corresponding test For each supported parameter set, the evaluator shall cause the | case below. The test values are defined as follows: [TOE](#abbr_TOE) to generate signatures using the data below and a < deterministic seed of all 0's. Correctness is determined by comparing < the hash of the resulting signature with the hash in the fourth row for < each corresponding test case below. < < The test values are defined as follows: < - *Seed* is the seed to generate the key pair (*pk, sk*) - *Seed* is the seed to generate the key pair (*pk, sk*) - *Hash of keys* is computed by [SHA](#abbr_SHA)-256(*pk*\|\|*sk*) - *Hash of keys* is computed by [SHA](#abbr_SHA)-256(*pk*\|\|*sk*) - *Message* is the message to be signed - *Message* is the message to be signed - *Hash of sig* is computed by [SHA](#abbr_SHA)-256(*sig*) - *Hash of sig* is computed by [SHA](#abbr_SHA)-256(*sig*) **ML-DSA-87 Test Cases for Rejection Cases** **ML-DSA-87 Test Cases for Rejection Cases** Test case 87-RC-01 Test case 87-RC-01 Seed: E4F5AFCF697E0EC3C1BDEB66FAA903221E803902F9C3F716E1056A63D Seed: E4F5AFCF697E0EC3C1BDEB66FAA903221E803902F9C3F716E1056A63D Hash of Keys: 61618E8DDA6998072C8EB36974E03880D741CAF0BD523356DFC161E7C Hash of Keys: 61618E8DDA6998072C8EB36974E03880D741CAF0BD523356DFC161E7C Message: F4F1C05004D5B946F69EAFE104C4020519086ADDB9582A20FDE887D13 Message: F4F1C05004D5B946F69EAFE104C4020519086ADDB9582A20FDE887D13 Hash of sig: B584E38FA442FC3C81A147D4BDBF058D73C822CAF5CA4C06B0110867F Hash of sig: B584E38FA442FC3C81A147D4BDBF058D73C822CAF5CA4C06B0110867F Test case 87-RC-02 Test case 87-RC-02 Seed: 8B828D871254D6C57384A8E7025AA3F7160CAD1D2C754499DF3844426 Seed: 8B828D871254D6C57384A8E7025AA3F7160CAD1D2C754499DF3844426 Hash of Keys: BB64481317D6C0DBAD20C0C7EF11078AD54E5D574F4A07652115A95F7 Hash of Keys: BB64481317D6C0DBAD20C0C7EF11078AD54E5D574F4A07652115A95F7 Message: 0F9409C5A4930C25B83FC5B77FDB5BB49C75372DE724D9C1A77DB700C Message: 0F9409C5A4930C25B83FC5B77FDB5BB49C75372DE724D9C1A77DB700C Hash of sig: F86B49BE9DEB2B209BDEB4E922E5939E92D38E562C44BB09AFBD67323 Hash of sig: F86B49BE9DEB2B209BDEB4E922E5939E92D38E562C44BB09AFBD67323 Test case 87-RC-03 Test case 87-RC-03 Seed: E693D282CACB8CE65FD4D108DA7A373F097F0AA9713550BE242AAD5BD Seed: E693D282CACB8CE65FD4D108DA7A373F097F0AA9713550BE242AAD5BD Hash of Keys: B0BEAF56713A69BD4AB2CBEE006FA5001E7B41F3AE541E05F088933AA Hash of Keys: B0BEAF56713A69BD4AB2CBEE006FA5001E7B41F3AE541E05F088933AA Message: 24DABB9D57ADEBD560ED65D9451C5106D437061708F849BA53F3543CD Message: 24DABB9D57ADEBD560ED65D9451C5106D437061708F849BA53F3543CD Hash of sig: DBF65CEFF9F96A74AAF6F3AB27B043231BE6AA04FBA2EEC987A24A00B Hash of sig: DBF65CEFF9F96A74AAF6F3AB27B043231BE6AA04FBA2EEC987A24A00B Test case 87-RC-04 Test case 87-RC-04 Seed: 4002163EB8EED01A8E0919BA8C07D291341EDCAE25B02B9779A2CFFE5 Seed: 4002163EB8EED01A8E0919BA8C07D291341EDCAE25B02B9779A2CFFE5 Hash of Keys: FED1BE685C20ECB322FC40D41DEE7E0E98D0409FBF989CAE71B8AD2D5 Hash of Keys: FED1BE685C20ECB322FC40D41DEE7E0E98D0409FBF989CAE71B8AD2D5 Message: EE316BB5EBED53325B4A55571C60657B53E353B51B831F4A0BBB28107 Message: EE316BB5EBED53325B4A55571C60657B53E353B51B831F4A0BBB28107 Hash of sig: 3BE9B5545FDCED92547B3409C83B3312CCB5792A8EC3A4DA63BA692C7 Hash of sig: 3BE9B5545FDCED92547B3409C83B3312CCB5792A8EC3A4DA63BA692C7 Test case 87-RC-05 Test case 87-RC-05 Seed: 9C7AD524F65854C27E565BCEDF8E86D650F13A40D0448F9AE10C05F10 Seed: 9C7AD524F65854C27E565BCEDF8E86D650F13A40D0448F9AE10C05F10 Hash of Keys: 0EA872CA5A4BEA94F4E8EF7ED31800727899A51059FDEE111E5CB15F0 Hash of Keys: 0EA872CA5A4BEA94F4E8EF7ED31800727899A51059FDEE111E5CB15F0 Message: CE09831294AA96CAF684B9E667947B021C57B24C138EC7D4DA270694C Message: CE09831294AA96CAF684B9E667947B021C57B24C138EC7D4DA270694C Hash of sig: 3B9526CEE6587F2418BFE603ADB0F7DF0D69EBA31C9F9F005C60C9939 Hash of sig: 3B9526CEE6587F2418BFE603ADB0F7DF0D69EBA31C9F9F005C60C9939 Test case 87-RC-06 Test case 87-RC-06 Seed: 2EB7676D4A28700DA7772A7A035EB495CAA6F842352A74824EF5FD891 Seed: 2EB7676D4A28700DA7772A7A035EB495CAA6F842352A74824EF5FD891 Hash of Keys: D5B73703A1DDC5BCB0D14AE39B193A25D6ADA6535827973181ADB0BE7 Hash of Keys: D5B73703A1DDC5BCB0D14AE39B193A25D6ADA6535827973181ADB0BE7 Message: C2B3A0AC483A5517682285C205974B2A506946448A8F7D3E1934C155E Message: C2B3A0AC483A5517682285C205974B2A506946448A8F7D3E1934C155E Hash of sig: 375D598704B722C8A1FEF1626FD7738A532C06329AA4217357460E3B7 Hash of sig: 375D598704B722C8A1FEF1626FD7738A532C06329AA4217357460E3B7 Test case 87-RC-07 Test case 87-RC-07 Seed: E4E80CCE8B26DF1B02B99949851EE2F907FE4F0CC34790352C76D5D91 Seed: E4E80CCE8B26DF1B02B99949851EE2F907FE4F0CC34790352C76D5D91 Hash of Keys: 84B7E61684A12698400B09EA332EA3C4FBCFA47FE37FD6AE725CBC5FA Hash of Keys: 84B7E61684A12698400B09EA332EA3C4FBCFA47FE37FD6AE725CBC5FA Message: 89E6AB43C9CB1CC59C3986D53217A558357E62102A26F666F2B64CD1D Message: 89E6AB43C9CB1CC59C3986D53217A558357E62102A26F666F2B64CD1D Hash of sig: 7C4AABD163CAEF8F6EBFDA3E3EEBC0A9604675B0E991ABAFD284F1AE8 Hash of sig: 7C4AABD163CAEF8F6EBFDA3E3EEBC0A9604675B0E991ABAFD284F1AE8 Test case 87-RC-08 Test case 87-RC-08 Seed: 5787262B803499223D4E5A8C1EE572E89F7A69B359B3F8505355B0BDE Seed: 5787262B803499223D4E5A8C1EE572E89F7A69B359B3F8505355B0BDE Hash of Keys: 85AE1DE605A7B479C02730BF4B7DD6D0FD8FFE5C980893CA6DAD00BD8 Hash of Keys: 85AE1DE605A7B479C02730BF4B7DD6D0FD8FFE5C980893CA6DAD00BD8 Message: D3230C4E061964BBFB17702432D5D36FC1EB3D1068F8CCAA84044776E Message: D3230C4E061964BBFB17702432D5D36FC1EB3D1068F8CCAA84044776E Hash of sig: D3ABE460EE2DD9595F413CFE2780A319E4E4DFD6592995298A7AB0B82 Hash of sig: D3ABE460EE2DD9595F413CFE2780A319E4E4DFD6592995298A7AB0B82 Test case 87-RC-09 Test case 87-RC-09 Seed: CE099B99330537DD153052243FC32ACAD509A126AB982410258858567 Seed: CE099B99330537DD153052243FC32ACAD509A126AB982410258858567 Hash of Keys: E04A9F15EDF8F078EB336CE624249EF2A8EDF2CDBF6A8276E9F5E92ED Hash of Keys: E04A9F15EDF8F078EB336CE624249EF2A8EDF2CDBF6A8276E9F5E92ED Message: 0035931762665F561A1B22176567E3B10FDE2441521F77030733A8E39 Message: 0035931762665F561A1B22176567E3B10FDE2441521F77030733A8E39 Hash of sig: 3EEF413CB5EB179896ECA172D0DBFB9B251545DC561D61580BD5BBC8B Hash of sig: 3EEF413CB5EB179896ECA172D0DBFB9B251545DC561D61580BD5BBC8B Test case 87-RC-10 Test case 87-RC-10 Seed: FC8F2929878CBD81E1CCC23913F290380120C043A4A8A251AEEBF0970 Seed: FC8F2929878CBD81E1CCC23913F290380120C043A4A8A251AEEBF0970 Hash of Keys: 7E2ECCA86F532E8E8092FEBB6E0007F92E7909AD2BCBE2E02AB375DAC Hash of Keys: 7E2ECCA86F532E8E8092FEBB6E0007F92E7909AD2BCBE2E02AB375DAC Message: D3C28875D2671C0EF23BFDC8869E8ECF8868D3F0561C3134D254F7479 Message: D3C28875D2671C0EF23BFDC8869E8ECF8868D3F0561C3134D254F7479 Hash of sig: EB69A908EDCC04320A0B61AD57E21B044465F2037698636B64229CF2D Hash of sig: EB69A908EDCC04320A0B61AD57E21B044465F2037698636B64229CF2D \ \ **XMSS Signature Generation** **XMSS Signature Generation** ----------------- ----------------- ----------------------- -------------------- ----------------- ----------------- ----------------------- -------------------- Identifier Cryptographic Cryptographic Key Sizes List of Standards Identifier Cryptographic Cryptographic Key Sizes List of Standards Algorithm Algorithm Parameters Parameters XMSS XMSS Private key size = RFC 8391 \[XMSS\] XMSS XMSS Private key size = RFC 8391 \[XMSS\] \[**selection:** 192 \[**selection:** 192 bits with [NIST](#abbr_NIST) bits with [NIST](#abbr_NIST) \[**selection:** SP 800-208 \[**selection:** SP 800-208 SHA256/192, \[parameters\] SHA256/192, \[parameters\] SHAKE256/192\], 256 SHAKE256/192\], 256 bits with bits with \[**selection:** \[**selection:** [SHA](#abbr_SHA)-256, [SHA](#abbr_SHA)-256, SHAKE256\]\], and tree SHAKE256\]\], and tree height = height = \[**selection:** 10, \[**selection:** 10, 16, 20\] 16, 20\] ----------------- ----------------- ----------------------- -------------------- ----------------- ----------------- ----------------------- -------------------- To test the [TOE](#abbr_TOE)'s ability to generate digital signatures To test the [TOE](#abbr_TOE)'s ability to generate digital signatures using XMSS, the evaluator shall perform the XMSS Key Generation Test using XMSS, the evaluator shall perform the XMSS Key Generation Test using the following input parameters: using the following input parameters: - Hash algorithm \[[SHA](#abbr_SHA)-256/192, SHAKE256/192, - Hash algorithm \[[SHA](#abbr_SHA)-256/192, SHAKE256/192, [SHA](#abbr_SHA)-256, SHAKE256\] [SHA](#abbr_SHA)-256, SHAKE256\] - Tree height \[10, 16, 20\] - Tree height \[10, 16, 20\] \ \ **XMSS Key Generation Test** | **XMSS Key Generation Test** For each supported combination of the above | parameters, the evaluator shall generate 10 signatures. The evaluator For each supported combination of the above parameters, the evaluator | shall verify the correctness of the implementation by comparing values shall generate 10 signatures. The evaluator shall verify the correctness | generated by the [TOE](#abbr_TOE) with those generated by a known-good of the implementation by comparing values generated by the | implementation using the same input parameters.\ [TOE](#abbr_TOE) with those generated by a known-good implementation < using the same input parameters. < < \ < **Known Answer Test for Large Number of Rejection Cases (Total Rejection **Known Answer Test for Large Number of Rejection Cases (Total Rejection Count)** | Count)** For each supported parameter set, the evaluator shall cause the < For each supported parameter set, the evaluator shall cause the < [TOE](#abbr_TOE) to generate signatures using the data below and a [TOE](#abbr_TOE) to generate signatures using the data below and a deterministic seed of all 0's. Correctness is determined by comparing deterministic seed of all 0's. Correctness is determined by comparing the hash of the resulting signature with the hash in the fourth row of the hash of the resulting signature with the hash in the fourth row of the corresponding test case below. | the corresponding test case below. **ML-DSA-87 Test Cases for Total | Rejection Count** **ML-DSA-87 Test Cases for Total Rejection Count** < Test case 87-LN-01 Test case 87-LN-01 Seed: 98B6298051D92BF37293C93C97370747BF527B87B71F6C4264182F451 Seed: 98B6298051D92BF37293C93C97370747BF527B87B71F6C4264182F451 Hash of Keys: 04A135B5C9B7020332C7B16E7108E8FF7FC1EAE1C23C5FA0B5D5CED0F Hash of Keys: 04A135B5C9B7020332C7B16E7108E8FF7FC1EAE1C23C5FA0B5D5CED0F Message: D7B0341269259083ABF3C8DC47559A19D57669B4486E0224F376DC43E Message: D7B0341269259083ABF3C8DC47559A19D57669B4486E0224F376DC43E Hash of sig: 58D72D76EC0FB65BFB9893C4479366B79DD7B8B7577E4291D13514FCC Hash of sig: 58D72D76EC0FB65BFB9893C4479366B79DD7B8B7577E4291D13514FCC Test case 87-LN-02 Test case 87-LN-02 Seed: DFB5BDD90F58571DCA962426C623F13D046BBE814D183886AC90D143E Seed: DFB5BDD90F58571DCA962426C623F13D046BBE814D183886AC90D143E Hash of Keys: 2B6AB8CFCCCC41F759CAF01932E9413F5DC6D949BC827F73986692968 Hash of Keys: 2B6AB8CFCCCC41F759CAF01932E9413F5DC6D949BC827F73986692968 Message: 21005DB2B583CC826A9684BFFD0EE00AB97E0479FE4A1D26669933754 Message: 21005DB2B583CC826A9684BFFD0EE00AB97E0479FE4A1D26669933754 Hash of sig: C93EA34E00FFFFC3ECEA072D5FB038A83B5539CAF7B831AEDCFA785E5 Hash of sig: C93EA34E00FFFFC3ECEA072D5FB038A83B5539CAF7B831AEDCFA785E5 Test case 87-LN-03 Test case 87-LN-03 Seed: 5AD414E0DD0EF2FE685F342871875FDF06F503717A86C3B3466565ADD Seed: 5AD414E0DD0EF2FE685F342871875FDF06F503717A86C3B3466565ADD Hash of Keys: BD9C2D52F3FC78DB17E682DA2E78947ECFC0898333838D60C892700B2 Hash of Keys: BD9C2D52F3FC78DB17E682DA2E78947ECFC0898333838D60C892700B2 Message: 29139C279816B25F2D6BB52C8247D163544F7BA332C3CF63359B9E23F Message: 29139C279816B25F2D6BB52C8247D163544F7BA332C3CF63359B9E23F Hash of sig: DB4BE2DE19FB40437BDB7E9B6578D665DB05B4E88C16907DF4546EBA9 Hash of sig: DB4BE2DE19FB40437BDB7E9B6578D665DB05B4E88C16907DF4546EBA9 Test case 87-LN-04 Test case 87-LN-04 Seed: 484DD2F406A4D15F49A91AD5FC3BDC1D0FF253622EB68F83D6E1C870D Seed: 484DD2F406A4D15F49A91AD5FC3BDC1D0FF253622EB68F83D6E1C870D Hash of Keys: A719DC9A77C91C46295555C2353BA0CBEA513DA9A92A5C34D2E949EFF Hash of Keys: A719DC9A77C91C46295555C2353BA0CBEA513DA9A92A5C34D2E949EFF Message: 6AD6E959F0EA60126364FB7C95FA71133F246A9265A11B4965EE78AB0 Message: 6AD6E959F0EA60126364FB7C95FA71133F246A9265A11B4965EE78AB0 Hash of sig: 5050D7A665074EC63D9F3966C1F01A1BFB18F9E83AE0B09F838BC1E23 Hash of sig: 5050D7A665074EC63D9F3966C1F01A1BFB18F9E83AE0B09F838BC1E23 Test case 87-LN-05 Test case 87-LN-05 Seed: B25C1816F82D59940D5CB829BAC364AAD013C4C16415CE1CF6DCC2F15 Seed: B25C1816F82D59940D5CB829BAC364AAD013C4C16415CE1CF6DCC2F15 Hash of Keys: ADBB2CD43F222640BD9FF4E61C80E63853E8DC1F759C581B7447C9C16 Hash of Keys: ADBB2CD43F222640BD9FF4E61C80E63853E8DC1F759C581B7447C9C16 Message: 824E47322895BFFE37B6B4AFC41CF6115C07EEC0C24EB81076C87A1B0 Message: 824E47322895BFFE37B6B4AFC41CF6115C07EEC0C24EB81076C87A1B0 Hash of sig: 667ADA46073BC69D64DC47BB9A76DD0D78302E7415D87D5E816B05FB9 Hash of sig: 667ADA46073BC69D64DC47BB9A76DD0D78302E7415D87D5E816B05FB9 Test case 87-LN-06 Test case 87-LN-06 Seed: B2CE72B3560AF07E06465881F56ADA00262BA708D87B73F39E04E310F Seed: B2CE72B3560AF07E06465881F56ADA00262BA708D87B73F39E04E310F Hash of Keys: FD9C4AC53AE803242A62DF933B8E8BAD6CE5207AC4A73683B6D9383B5 Hash of Keys: FD9C4AC53AE803242A62DF933B8E8BAD6CE5207AC4A73683B6D9383B5 Message: A1501CC84C917E0D2D7C27C2AC382220BD8FFFE807DB38E37A9E429EC Message: A1501CC84C917E0D2D7C27C2AC382220BD8FFFE807DB38E37A9E429EC Hash of sig: 779553B195E11558EE59EF3942F5F6B446A2144600D1F4F50B300C6C5 Hash of sig: 779553B195E11558EE59EF3942F5F6B446A2144600D1F4F50B300C6C5 Test case 87-LN-07 Test case 87-LN-07 Seed: AB01D0E591B7DDCD3C03395AED808FA2763C0A486D44119D621BE0FD0 Seed: AB01D0E591B7DDCD3C03395AED808FA2763C0A486D44119D621BE0FD0 Hash of Keys: 93B6ADE34F78A4ADB36B2F6D2C51DB793E659E1243E80488AE1C03B65 Hash of Keys: 93B6ADE34F78A4ADB36B2F6D2C51DB793E659E1243E80488AE1C03B65 Message: 8DE8122D89D15FE84A4C34F6B59B2C4B11F33B6A053154D199B634F55 Message: 8DE8122D89D15FE84A4C34F6B59B2C4B11F33B6A053154D199B634F55 Hash of sig: 0483045999A79B583F403DB96A736F0F0B24E2DFBC4E5CFA9B50E3D91 Hash of sig: 0483045999A79B583F403DB96A736F0F0B24E2DFBC4E5CFA9B50E3D91 Test case 87-LN-08 Test case 87-LN-08 Seed: 15D60D3693762F82C9AC1DCB0576936651AC81D863842EDB91109C8EE Seed: 15D60D3693762F82C9AC1DCB0576936651AC81D863842EDB91109C8EE Hash of Keys: 2DF544E2E939AA717741C2437288FAEB308DEB8FF37A2652FAE34BAE8 Hash of Keys: 2DF544E2E939AA717741C2437288FAEB308DEB8FF37A2652FAE34BAE8 Message: F05946A6113905C34163AEF2246FD69016CE24A7BA40F8E7E42EDAC2D Message: F05946A6113905C34163AEF2246FD69016CE24A7BA40F8E7E42EDAC2D Hash of sig: F8383917AF79C8E540D2356AB05F08B465BF32DFEC444B787CE31BF48 Hash of sig: F8383917AF79C8E540D2356AB05F08B465BF32DFEC444B787CE31BF48 Test case 87-LN-09 Test case 87-LN-09 Seed: 21212285BED53B3411705DAF5F3BDDB6F0618EB571B36EE11A7405340 Seed: 21212285BED53B3411705DAF5F3BDDB6F0618EB571B36EE11A7405340 Hash of Keys: 737061155A9A03F11F9FEBBB940BED4DD54542C4A6212F89A5EB4EC2B Hash of Keys: 737061155A9A03F11F9FEBBB940BED4DD54542C4A6212F89A5EB4EC2B Message: FFE38246BF3DEFD9CAD15CC17CEA511C067D582E04227B479E32F9197 Message: FFE38246BF3DEFD9CAD15CC17CEA511C067D582E04227B479E32F9197 Hash of sig: C4C12C58032052FB2D21F0C6A7388A63154FB85B74287D2859DE6C1C6 Hash of sig: C4C12C58032052FB2D21F0C6A7388A63154FB85B74287D2859DE6C1C6 Test case 87-LN-10 Test case 87-LN-10 Seed: A2744470587C71BA43EC26DC390CE3531978F315993C653E5D3EFD284 Seed: A2744470587C71BA43EC26DC390CE3531978F315993C653E5D3EFD284 Hash of Keys: B1BF37BFFB11531B6ADD697870D7DB2E2462D0A97A63F09C1D0038457 Hash of Keys: B1BF37BFFB11531B6ADD697870D7DB2E2462D0A97A63F09C1D0038457 Message: 9831A830231A160B9847203341A5F30BF3E87A2A482AEEA6886315C92 Message: 9831A830231A160B9847203341A5F30BF3E87A2A482AEEA6886315C92 Hash of sig: 46C669D2FEB643A38E54FF87B790CC33F44043A1B6B31DB9474D30132 Hash of sig: 46C669D2FEB643A38E54FF87B790CC33F44043A1B6B31DB9474D30132 ::: ::: ::: ::: ::: ::: ::: ::: ::: ::: ::: {#FCS_COP.1/SigVer .comp} ::: {#FCS_COP.1/SigVer .comp} #### FCS_COP.1/SigVer Cryptographic Operation - Signature Verification #### FCS_COP.1/SigVer Cryptographic Operation - Signature Verification ::: element ::: element ::: {#FCS_COP.1.1/SigVer .reqid} ::: {#FCS_COP.1.1/SigVer .reqid} [FCS_COP.1.1/SigVer](#FCS_COP.1.1/SigVer){.abbr} [FCS_COP.1.1/SigVer](#FCS_COP.1.1/SigVer){.abbr} ::: ::: ::: reqdesc ::: reqdesc The [TSF](#abbr_TSF) shall perform \[*digital signature verification*\] The [TSF](#abbr_TSF) shall perform \[*digital signature verification*\] in accordance with a specified cryptographic algorithm \[**selection**: in accordance with a specified cryptographic algorithm \[**selection**: [Cryptographic Algorithm]{.selectable-content}\] and cryptographic key [Cryptographic Algorithm]{.selectable-content}\] and cryptographic key sizes \[**selection**: [Cryptographic Key Sizes]{.selectable-content}\] sizes \[**selection**: [Cryptographic Key Sizes]{.selectable-content}\] that meet the following: \[**selection**: [List of that meet the following: \[**selection**: [List of Standards]{.selectable-content}\] . Standards]{.selectable-content}\] . [Table [14]{.counter}](#fcs-cop-sigver-sels){.fcs-cop-sigver-sels-ref [Table [14]{.counter}](#fcs-cop-sigver-sels){.fcs-cop-sigver-sels-ref onclick="showTarget('fcs-cop-sigver-sels')"} provides the allowable onclick="showTarget('fcs-cop-sigver-sels')"} provides the allowable choices for completion of the selection operations in choices for completion of the selection operations in [FCS_COP.1/SigVer](#FCS_COP.1/SigVer). [FCS_COP.1/SigVer](#FCS_COP.1/SigVer). +-----------------+-----------------+-----------------+-----------------+ +-----------------+-----------------+-----------------+-----------------+ | Identifier | Cryptographic | Cryptographic | List of | | Identifier | Cryptographic | Cryptographic | List of | | | Algorithm | Key Sizes | Standards | | | Algorithm | Key Sizes | Standards | +=================+=================+=================+=================+ +=================+=================+=================+=================+ | [RSA]( | RS | Modulus of size | RFC 8017 | | [RSA]( | RS | Modulus of size | RFC 8017 | | #abbr_RSA)-PKCS | ASSA-PKCS1-v1_5 | \ | (Section 8.2) | | #abbr_RSA)-PKCS | ASSA-PKCS1-v1_5 | \ | (Section 8.2) | | | | [**selection**: | \[PKCS #1 | | | | [**selection**: | \[PKCS #1 | | | | [ | v2.2\] | | | | | [*3072*]{#fcs_c | v2.2\] | | | | *3072*]{#_s_292 | | | | | | op.1.1_SigVer_1 | | | | | .selec | [FI | | | | .selec | [FI | | | | table-content}, | PS](#abbr_FIPS) | | | | table-content}, | PS](#abbr_FIPS) | | | | [ | PUB 186-5 | | | | | [*4096*]{#fcs_c | PUB 186-5 | | | | *4096*]{#_s_293 | (Section 5.4) | | | | | op.1.1_SigVer_2 | (Section 5.4) | | | | .selec | \[RSAS | | | | .selec | \[RSAS | | | | table-content}, | SA-PKCS1-v1_5\] | | | | table-content}, | SA-PKCS1-v1_5\] | | | | [ | | | | | | [*6144*]{#fcs_c | | | | | *6144*]{#_s_294 | | | | | | op.1.1_SigVer_3 | | | | | .selec | | | | | .selec | | | | | table-content}, | | | | | table-content}, | | | | | [ | | | | | | [*8192*]{#fcs_c | | | | | *8192*]{#_s_295 | | | | | | op.1.1_SigVer_4 | | | | | .select | | | | | .select | | | | | able-content}\] | | | | | able-content}\] | | | | | bits and hash | | | | | bits and hash | | | | | \ | | | | | \ | | | | | [**selection**: | | | | | [**selection**: | | | | | [* | | | | | | [ | | | | | [SHA](#abbr_SHA | | | | | | *[SHA](#abbr_SH | | | | | )-384*]{#_s_296 | | | | | | A)-384*]{#fcs_c | | > | | | op.1.1_SigVer_5 | | | | | .selec | | | | | .selec | | | | | table-content}, | | | | | table-content}, | | | | | [* | | | | | | [ | | | | | [SHA](#abbr_SHA | | | | | | *[SHA](#abbr_SH | | | | | )-512*]{#_s_297 | | | | | | A)-512*]{#fcs_c | | > | | | op.1.1_SigVer_6 | | | | | .select | | | | | .select | | | | | able-content}\] | | | | | able-content}\] | | +-----------------+-----------------+-----------------+-----------------+ +-----------------+-----------------+-----------------+-----------------+ | [RSA] | RSASSA-PSS | Modulus of size | RFC 8017 | | [RSA] | RSASSA-PSS | Modulus of size | RFC 8017 | | (#abbr_RSA)-PSS | | \ | (Section 8.1) | | (#abbr_RSA)-PSS | | \ | (Section 8.1) | | | | [**selection**: | \[PKCS#1 v2.2\] | | | | [**selection**: | \[PKCS#1 v2.2\] | | | | [ | | | | | | [*3072*]{#fcs_c | | | | | *3072*]{#_s_299 | [FI | | | | | op.1.1_SigVer_7 | [FI | | | | .selec | PS](#abbr_FIPS) | | | | .selec | PS](#abbr_FIPS) | | | | table-content}, | PUB 186-5 | | | | table-content}, | PUB 186-5 | | | | [ | (Section 5.4) | | | | | [*4096*]{#fcs_c | (Section 5.4) | | | | *4096*]{#_s_300 | \[RSASSA-PSS\] | | | | | op.1.1_SigVer_8 | \[RSASSA-PSS\] | | | | .selec | | | | | .selec | | | | | table-content}, | | | | | table-content}, | | | | | [ | | | | | | [*6144*]{#fcs_c | | | | | *6144*]{#_s_301 | | | | | | op.1.1_SigVer_9 | | | | | .selec | | | | | .selec | | | | | table-content}, | | | | | table-content}, | | | | | [ | | | | | [ | | | | | *8192*]{#_s_302 | | | | | | *8192*]{#fcs_co | | > | | | p.1.1_SigVer_10 | | | | | .select | | | | | .select | | | | | able-content}\] | | | | | able-content}\] | | | | | bits and hash | | | | | bits and hash | | | | | \ | | | | | \ | | | | | [**selection**: | | | | | [**selection**: | | | | | [* | | | | | [* | | | | | [SHA](#abbr_SHA | | | | | [SHA](#abbr_SHA | | | | | )-384*]{#_s_303 | | | | | | )-384*]{#fcs_co | | > | | | p.1.1_SigVer_11 | | | | | .selec | | | | | .selec | | | | | table-content}, | | | | | table-content}, | | | | | [* | | | | | [* | | | | | [SHA](#abbr_SHA | | | | | [SHA](#abbr_SHA | | | | | )-512*]{#_s_304 | | | | | | )-512*]{#fcs_co | | > | | | p.1.1_SigVer_12 | | | | | .select | | | | | .select | | | | | able-content}\] | | | | | able-content}\] | | +-----------------+-----------------+-----------------+-----------------+ +-----------------+-----------------+-----------------+-----------------+ | [ECDS | [ECDS | Elliptic Curve | \ | | [ECDS | [ECDS | Elliptic Curve | \ | | A](#abbr_ECDSA) | A](#abbr_ECDSA) | \ | [**selection**: | | A](#abbr_ECDSA) | A](#abbr_ECDSA) | \ | [**selection**: | | | | [**selection**: | [*ISO/IEC | | | | [**selection**: | [*ISO/IEC | | | | [* | 14888-3:2018 | | | | [* | 14888-3:2018 | | | | P-384*]{#_s_306 | (Subclause | | | | | P-384*]{#fcs_co | (Subclause | | | | .selec | 6.6)*]{#_s_310 | | | | | p.1.1_SigVer_13 | 6.6)*]{#fcs_co | > | | | .selec | p.1.1_SigVer_17 | | | | table-content}, | .selec | | | | table-content}, | .selec | | | | [* | table-content}, | | | | [* | table-content}, | | | | P-521*]{#_s_307 | [*[FI | | | | | P-521*]{#fcs_co | [*[FI | | | | .select | PS](#abbr_FIPS) | | | | | p.1.1_SigVer_14 | PS](#abbr_FIPS) | | | | able-content}\] | PUB 186-5 | | | | | .select | PUB 186-5 | | | | using hash | (Section | | | | | able-content}\] | (Section | | | | \ | 6 | | | | | using hash | 6 | | | | [**selection**: | .4.2)*]{#_s_311 | | | | | \ | .4.2)*]{#fcs_co | | | | [* | . | | | | | [**selection**: | p.1.1_SigVer_18 | | | | [SHA](#abbr_SHA | selectable-cont | | | | | [* | .select | | | | )-384*]{#_s_308 | ent}\]\[[ECDSA] | | | | | [SHA](#abbr_SHA | able-content}\] | | | | .selec | (#abbr_ECDSA)\] | | | | | )-384*]{#fcs_co | \[[ECDSA] | | | | table-content}, | | | | | | p.1.1_SigVer_15 | (#abbr_ECDSA)\] | | | | [* | [NI | | | | | .selec | | | | | [SHA](#abbr_SHA | ST](#abbr_NIST) | | | | | table-content}, | [NI | | | | )-512*]{#_s_309 | SP-800 186 | | | | | [* | ST](#abbr_NIST) | | | | .select | (Section 4) | | | | | [SHA](#abbr_SHA | SP-800 186 | | | | able-content}\] | \[[NI | | | | | )-512*]{#fcs_co | (Section 4) | | | | | ST](#abbr_NIST) | | | | | p.1.1_SigVer_16 | \[[NI | | | | | Curves\] | | | | | .select | ST](#abbr_NIST) | > | | | able-content}\] | Curves\] | +-----------------+-----------------+-----------------+-----------------+ +-----------------+-----------------+-----------------+-----------------+ | LMS | LMS | Private key | RFC 8554 | | LMS | LMS | Private key | RFC 8554 | | | | size = | \[LMS\] | | | | size = | \[LMS\] | | | | \ | | | | | \ | | | | | [**selection**: | [NI | | | | [**selection**: | [NI | | | | | ST](#abbr_NIST) | | | | | ST](#abbr_NIST) | | | | - [*192 bits | SP 800-208 | | | | - [*192 bits | SP 800-208 | | | | with* | \[parameters\] | | | | with* | \[parameters\] | | | | \ | | | | | \ | | | | | [**selection**: | | | | | [**selection**: | | | | | [*[SHA | | | | | [*[SHA | | | | | ](#abbr_SHA)-25 | | | | | ](#abbr_SHA)-25 | | | | | 6/192*]{#_s_314 | | | | | | 6/192*]{#fcs_co | | > | | | p.1.1_SigVer_20 | | | | | .selec | | | | | .selec | | | | | table-content}, | | | | | table-content}, | | | | | [*SHAKE25 | | | | | [*SHAKE25 | | | | | 6/192*]{#_s_315 | | | | | | 6/192*]{#fcs_co | | > | | | p.1.1_SigVer_21 | | | | | . | | | | | . | | | | | selectable-cont | | | | | selectable-cont | | | | | ent}\]]{#_s_313 | | | | | | ent}\]]{#fcs_co | | > | | | p.1.1_SigVer_19 | | | | | .sele | | | | | .sele | | | | | ctable-content} | | | | | ctable-content} | | | | | - [*256 bits | | | | | - [*256 bits | | | | | with* | | | | | with* | | | | | \ | | | | | \ | | | | | [**selection**: | | | | | [**selection**: | | | | | [* | | | | | [* | | | | | [SHA](#abbr_SHA | | | | | [SHA](#abbr_SHA | | | | | )-256*]{#_s_317 | | | | | | )-256*]{#fcs_co | | > | | | p.1.1_SigVer_23 | | | | | .selec | | | | | .selec | | | | | table-content}, | | | | | table-content}, | | | | | [*SHA | | | | | [*SHA | | | | | KE256*]{#_s_318 | | | | | | KE256*]{#fcs_co | | > | | | p.1.1_SigVer_24 | | | | | . | | | | | . | | | | | selectable-cont | | | | | selectable-cont | | | | | ent}\]]{#_s_316 | | | | | | ent}\]]{#fcs_co | | > | | | p.1.1_SigVer_22 | | | | | .sele | | | | | .sele | | | | | ctable-content} | | | | | ctable-content} | | | | | | | | | | | | | | | \] | | | | | \] | | | | | | | | | | | | | | | Winternitz | | | | | Winternitz | | | | | parameter = | | | | | parameter = | | | | | \ | | | | | \ | | | | | [**selection**: | | | | | [**selection**: | | | | | [*1*]{#_s_319 | | | | | | [*1*]{#fcs_co | | > | | | p.1.1_SigVer_25 | | | | | .selec | | | | | .selec | | | | | table-content}, | | | | | table-content}, | | | | | [*2*]{#_s_320 | | | | | | [*2*]{#fcs_co | | > | | | p.1.1_SigVer_26 | | | | | .selec | | | | | .selec | | | | | table-content}, | | | | | table-content}, | | | | | [*4*]{#_s_321 | | | | | | [*4*]{#fcs_co | | > | | | p.1.1_SigVer_27 | | | | | .selec | | | | | .selec | | | | | table-content}, | | | | | table-content}, | | | | | [*8*]{#_s_322 | | | | | | [*8*]{#fcs_co | | > | | | p.1.1_SigVer_28 | | | | | .select | | | | | .select | | | | | able-content}\] | | | | | able-content}\] | | | | | | | | | | | | | | | Tree height = | | | | | Tree height = | | | | | \ | | | | | \ | | | | | [**selection**: | | | | | [**selection**: | | | | | [*5*]{#_s_323 | | | | | | [*5*]{#fcs_co | | > | | | p.1.1_SigVer_29 | | | | | .selec | | | | | .selec | | | | | table-content}, | | | | | table-content}, | | | | | [*10*]{#_s_324 | | | | | | [*10*]{#fcs_co | | > | | | p.1.1_SigVer_30 | | | | | .selec | | | | | .selec | | | | | table-content}, | | | | | table-content}, | | | | | [*15*]{#_s_325 | | | | | | [*15*]{#fcs_co | | > | | | p.1.1_SigVer_31 | | | | | .selec | | | | | .selec | | | | | table-content}, | | | | | table-content}, | | | | | [*20*]{#_s_326 | | | | | | [*20*]{#fcs_co | | > | | | p.1.1_SigVer_32 | | | | | .selec | | | | | .selec | | | | | table-content}, | | | | | table-content}, | | | | | [*25*]{#_s_327 | | | | | | [*25*]{#fcs_co | | > | | | p.1.1_SigVer_33 | | | | | .select | | | | | .select | | | | | able-content}\] | | | | | able-content}\] | | +-----------------+-----------------+-----------------+-----------------+ +-----------------+-----------------+-----------------+-----------------+ | XMSS | XMSS | Private key | RFC 8391 | | XMSS | XMSS | Private key | RFC 8391 | | | | size = | \[XMSS\] | | | | size = | \[XMSS\] | | | | \ | | | | | \ | | | | | [**selection**: | [NI | | | | [**selection**: | [NI | | | | | ST](#abbr_NIST) | | | | | ST](#abbr_NIST) | | | | - [*192 bits | SP 800-208 | | | | - [*192 bits | SP 800-208 | | | | with* | \[parameters\] | | | | with* | \[parameters\] | | | | \ | | | | | \ | | | | | [**selection**: | | | | | [**selection**: | | | | | [*[SHA | | | | | [*[SHA | | | | | ](#abbr_SHA)-25 | | | | | ](#abbr_SHA)-25 | | | | | 6/192*]{#_s_330 | | | | | | 6/192*]{#fcs_co | | > | | | p.1.1_SigVer_35 | | | | | .selec | | | | | .selec | | | | | table-content}, | | | | | table-content}, | | | | | [*SHAKE25 | | | | | [*SHAKE25 | | | | | 6/192*]{#_s_331 | | | | | | 6/192*]{#fcs_co | | > | | | p.1.1_SigVer_36 | | | | | . | | | | | . | | | | | selectable-cont | | | | | selectable-cont | | | | | ent}\]]{#_s_329 | | | | | | ent}\]]{#fcs_co | | > | | | p.1.1_SigVer_34 | | | | | .sele | | | | | .sele | | | | | ctable-content} | | | | | ctable-content} | | | | | - [*256 bits | | | | | - [*256 bits | | | | | with* | | | | | with* | | | | | \ | | | | | \ | | | | | [**selection**: | | | | | [**selection**: | | | | | [* | | | | | [* | | | | | [SHA](#abbr_SHA | | | | | [SHA](#abbr_SHA | | | | | )-256*]{#_s_333 | | | | | | )-256*]{#fcs_co | | > | | | p.1.1_SigVer_38 | | | | | .selec | | | | | .selec | | | | | table-content}, | | | | | table-content}, | | | | | [*SHA | | | | | [*SHA | | | | | KE256*]{#_s_334 | | | | | | KE256*]{#fcs_co | | > | | | p.1.1_SigVer_39 | | | | | . | | | | | . | | | | | selectable-cont | | | | | selectable-cont | | | | | ent}\]]{#_s_332 | | | | | | ent}\]]{#fcs_co | | > | | | p.1.1_SigVer_37 | | | | | .sele | | | | | .sele | | | | | ctable-content} | | | | | ctable-content} | | | | | | | | | | | | | | | \] | | | | | \] | | | | | | | | | | | | | | | Tree height = | | | | | Tree height = | | | | | \ | | | | | \ | | | | | [**selection**: | | | | | [**selection**: | | | | | [*10*]{#_s_335 | | | | | | [*10*]{#fcs_co | | > | | | p.1.1_SigVer_40 | | | | | .selec | | | | | .selec | | | | | table-content}, | | | | | table-content}, | | | | | [*16*]{#_s_336 | | | | | | [*16*]{#fcs_co | | > | | | p.1.1_SigVer_41 | | | | | .selec | | | | | .selec | | | | | table-content}, | | | | | table-content}, | | | | | [*20*]{#_s_337 | | | | | | [*20*]{#fcs_co | | > | | | p.1.1_SigVer_42 | | | | | .select | | | | | .select | | | | | able-content}\] | | | | | able-content}\] | | +-----------------+-----------------+-----------------+-----------------+ +-----------------+-----------------+-----------------+-----------------+ | ML-DSA | ML-DSA | Parameter set = | [NI | | ML-DSA | ML-DSA | Parameter set = | [NI | | | Signature | ML-DSA-87 | ST](#abbr_NIST) | | | Signature | ML-DSA-87 | ST](#abbr_NIST) | | | Verification | | [FI | | | Verification | | [FI | | | | | PS](#abbr_FIPS) | | | | | PS](#abbr_FIPS) | | | | | 204 (Section | | | | | 204 (Section | | | | | 5.3) | | | | | 5.3) | +-----------------+-----------------+-----------------+-----------------+ +-----------------+-----------------+-----------------+-----------------+ : [Table [14]{.counter}]{#fcs-cop-sigver-sels .ctr : [Table [14]{.counter}]{#fcs-cop-sigver-sels .ctr myid="fcs-cop-sigver-sels" counter-type="ct-Table"}: Allowable choices myid="fcs-cop-sigver-sels" counter-type="ct-Table"}: Allowable choices for [FCS_COP.1/SigVer](#FCS_COP.1/SigVer) for [FCS_COP.1/SigVer](#FCS_COP.1/SigVer) ::: ::: ::: ::: ::: {.activity_pane .hide} ::: {.activity_pane .hide} ::: activity_pane_header ::: activity_pane_header [[ Evaluation Activities [[ Evaluation Activities ]{.activity_pane_label}[]{.toggler}](#){onclick="toggle(this);return false;"} ]{.activity_pane_label}[]{.toggler}](#){onclick="toggle(this);return false;"} ::: ::: ::: activity_pane_body ::: activity_pane_body ::: component-activity-header ::: component-activity-header [FCS_COP.1/SigVer](#FCS_COP.1/SigVer) [FCS_COP.1/SigVer](#FCS_COP.1/SigVer) ::: ::: ::: eacategory ::: eacategory [TSS](#abbr_TSS) [TSS](#abbr_TSS) ::: ::: ::: ea ::: ea ::: ea ::: ea The evaluator shall examine the [TSS](#abbr_TSS) to verify that any The evaluator shall examine the [TSS](#abbr_TSS) to verify that any one-time values such as nonces or masks are constructed and used in one-time values such as nonces or masks are constructed and used in accordance with the relevant standards. accordance with the relevant standards. ::: ::: ::: ::: ::: eacategory ::: eacategory Guidance Guidance ::: ::: ::: ea ::: ea There are no additional Guidance evaluation activities for this There are no additional Guidance evaluation activities for this component.\ component.\ ::: ::: ::: eacategory ::: eacategory Tests Tests ::: ::: ::: ea ::: ea ::: ea ::: ea The following tests are conditional based on the selections made in the The following tests are conditional based on the selections made in the [SFR](#abbr_SFR). The evaluator shall perform the following tests or [SFR](#abbr_SFR). The evaluator shall perform the following tests or witness respective tests executed by the developer. The tests must be witness respective tests executed by the developer. The tests must be executed on a platform that is as close as practically possible to the executed on a platform that is as close as practically possible to the operational platform (but which may be instrumented in terms of, for operational platform (but which may be instrumented in terms of, for example, use of a debug mode). Where the test is not carried out on the example, use of a debug mode). Where the test is not carried out on the [TOE](#abbr_TOE) itself, the test platform shall be identified and the [TOE](#abbr_TOE) itself, the test platform shall be identified and the differences between test environment and [TOE](#abbr_TOE) execution differences between test environment and [TOE](#abbr_TOE) execution environment shall be described. | environment shall be described.\ < \ < **[RSA](#abbr_RSA)-PKCS Signature Verification** **[RSA](#abbr_RSA)-PKCS Signature Verification** ----------------------- ------------------- ------------------------- ------------- ----------------------- ------------------- ------------------------- ------------- Identifier Cryptographic Cryptographic Key Sizes List of Stand Identifier Cryptographic Cryptographic Key Sizes List of Stand Algorithm Algorithm Parameters Parameters [RSA](#abbr_RSA)-PKCS RSASSA-PKCS1-v1_5 Modulus of size RFC 8017 (Sec [RSA](#abbr_RSA)-PKCS RSASSA-PKCS1-v1_5 Modulus of size RFC 8017 (Sec \[**selection:** *3072, \[PKCS #1 v2. \[**selection:** *3072, \[PKCS #1 v2. 4096, 6144, 8192*\] bits, 4096, 6144, 8192*\] bits, hash \[**selection:** [NIST](#abbr_ hash \[**selection:** [NIST](#abbr_ *[SHA](#abbr_SHA)-384, [FIPS](#abbr_ *[SHA](#abbr_SHA)-384, [FIPS](#abbr_ [SHA](#abbr_SHA)-512*\] 186-5 (Sectio [SHA](#abbr_SHA)-512*\] 186-5 (Sectio \[RSASSA-PKCS \[RSASSA-PKCS ----------------------- ------------------- ------------------------- ------------- ----------------------- ------------------- ------------------------- ------------- To test the [TOE](#abbr_TOE)'s ability to perform [RSA](#abbr_RSA) To test the [TOE](#abbr_TOE)'s ability to perform [RSA](#abbr_RSA) Digital Signature Verification using PKCS1-v1_5 signature type, the Digital Signature Verification using PKCS1-v1_5 signature type, the evaluator shall perform Generated Data Test using the following input evaluator shall perform Generated Data Test using the following input parameters: parameters: - Modulus size \[3072, 4096, 6144, 8192\] bits - Modulus size \[3072, 4096, 6144, 8192\] bits - Hash algorithm \[[SHA](#abbr_SHA)-384, [SHA](#abbr_SHA)-512\] - Hash algorithm \[[SHA](#abbr_SHA)-384, [SHA](#abbr_SHA)-512\] \ \ **Generated Data Test** | **Generated Data Test** For each supported combination of the above | parameters, the evaluator shall cause the [TOE](#abbr_TOE) to generate For each supported combination of the above parameters, the evaluator | six test cases using a random message and its signature such that the shall cause the [TOE](#abbr_TOE) to generate six test cases using a | test cases are modified as follows: random message and its signature such that the test cases are modified < as follows: < - One test case is left unmodified - One test case is left unmodified - For one test case the Message is modified - For one test case the Message is modified - For one test case the Signature is modified - For one test case the Signature is modified - For one test case the exponent (*e*) is modified - For one test case the exponent (*e*) is modified - For one test case the IR is moved - For one test case the IR is moved - For one test case the Trailer is moved - For one test case the Trailer is moved The [TOE](#abbr_TOE) must correctly verify the unmodified signatures and The [TOE](#abbr_TOE) must correctly verify the unmodified signatures and fail to verify the modified signatures. | fail to verify the modified signatures.\ < \ < **[RSA](#abbr_RSA)-PSS Signature Verification** **[RSA](#abbr_RSA)-PSS Signature Verification** ---------------------- ----------------- ------------------------- ---------------- ---------------------- ----------------- ------------------------- ---------------- Identifier Cryptographic Cryptographic Key Sizes List of Standard Identifier Cryptographic Cryptographic Key Sizes List of Standard Algorithm Algorithm Parameters Parameters [RSA](#abbr_RSA)-PSS RSASSA-PSS Modulus of size RFC 8017 (Sectio [RSA](#abbr_RSA)-PSS RSASSA-PSS Modulus of size RFC 8017 (Sectio \[**selection:** *3072, 8.2) \[PKCS #1 \[**selection:** *3072, 8.2) \[PKCS #1 4096, 6144, 8192*\] bits, v2.2\] 4096, 6144, 8192*\] bits, v2.2\] hash \[**selection:** hash \[**selection:** *[SHA](#abbr_SHA)-384, [NIST](#abbr_NIS *[SHA](#abbr_SHA)-384, [NIST](#abbr_NIS [SHA](#abbr_SHA)-512*\] [FIPS](#abbr_FIP [SHA](#abbr_SHA)-512*\] [FIPS](#abbr_FIP PUB 186-5 (Secti PUB 186-5 (Secti 5.4) \[RSASSA-PS 5.4) \[RSASSA-PS ---------------------- ----------------- ------------------------- ---------------- ---------------------- ----------------- ------------------------- ---------------- To test the [TOE](#abbr_TOE)'s ability to perform [RSA](#abbr_RSA) To test the [TOE](#abbr_TOE)'s ability to perform [RSA](#abbr_RSA) Digital Signature Verification using PSS signature type, the evaluator Digital Signature Verification using PSS signature type, the evaluator shall perform the Generated Data Test using the following input shall perform the Generated Data Test using the following input parameters: parameters: - Modulus size \[3072, 4096, 6144, 8192\] bits - Modulus size \[3072, 4096, 6144, 8192\] bits - Hash algorithm \[[SHA](#abbr_SHA)-384, [SHA](#abbr_SHA)-512\] - Hash algorithm \[[SHA](#abbr_SHA)-384, [SHA](#abbr_SHA)-512\] - Salt length \[0-hash length\] - Salt length \[0-hash length\] - Mask function \[MGF1\] - Mask function \[MGF1\] \ \ **Generated Data Test** | **Generated Data Test** For each supported combination of the above | parameters, the evaluator shall cause the [TOE](#abbr_TOE) to generate For each supported combination of the above parameters, the evaluator | six test cases using random data such that the test cases are modified shall cause the [TOE](#abbr_TOE) to generate six test cases using random | as follows: data such that the test cases are modified as follows: < - One test case is left unmodified - One test case is left unmodified - For one test case the Message is modified - For one test case the Message is modified - For one test case the Signature is modified - For one test case the Signature is modified - For one test case the exponent (*e*) is modified - For one test case the exponent (*e*) is modified - For one test case the IR is moved - For one test case the IR is moved - For one test case the Trailer is moved - For one test case the Trailer is moved The [TOE](#abbr_TOE) must correctly verify the unmodified signatures and The [TOE](#abbr_TOE) must correctly verify the unmodified signatures and fail to verify the modified signatures. | fail to verify the modified signatures.\ < \ < **[ECDSA](#abbr_ECDSA) Signature Verification** **[ECDSA](#abbr_ECDSA) Signature Verification** ---------------------- ---------------------- ------------------------- ----------- ---------------------- ---------------------- ------------------------- ----------- Identifier Cryptographic Cryptographic Key Sizes List of Sta Identifier Cryptographic Cryptographic Key Sizes List of Sta Algorithm Parameters Algorithm Parameters [ECDSA](#abbr_ECDSA) [ECDSA](#abbr_ECDSA) Elliptic Curve \[**selecti [ECDSA](#abbr_ECDSA) [ECDSA](#abbr_ECDSA) Elliptic Curve \[**selecti \[**selection:** *P-384, 14888-3:201 \[**selection:** *P-384, 14888-3:201 P-521*\] and hash 6.6), [NIST P-521*\] and hash 6.6), [NIST function using [FIPS](#abb function using [FIPS](#abb \[**selection:** 186-5 (Sect \[**selection:** 186-5 (Sect *[SHA](#abbr_SHA)-384, 6.4.1*\] *[SHA](#abbr_SHA)-384, 6.4.1*\] [SHA](#abbr_SHA)-512*\] \[[ECDSA](# [SHA](#abbr_SHA)-512*\] \[[ECDSA](# [NIST](#abb [NIST](#abb 186 (Sectio 186 (Sectio \[[NIST](#a \[[NIST](#a Curves\] Curves\] ---------------------- ---------------------- ------------------------- ----------- ---------------------- ---------------------- ------------------------- ----------- To test the [TOE](#abbr_TOE)'s ability to perform [ECDSA](#abbr_ECDSA) To test the [TOE](#abbr_TOE)'s ability to perform [ECDSA](#abbr_ECDSA) Digital Signature Verification, the evaluator shall perform the Digital Signature Verification, the evaluator shall perform the Algorithm Functional Test using the following input parameters: Algorithm Functional Test using the following input parameters: - Elliptic Curve \[P-384, P-521\] - Elliptic Curve \[P-384, P-521\] - Hash algorithm \[[SHA](#abbr_SHA)-384, [SHA](#abbr_SHA)-512\] - Hash algorithm \[[SHA](#abbr_SHA)-384, [SHA](#abbr_SHA)-512\] \ \ **Algorithm Functional Test** | **Algorithm Functional Test** For each supported combination of the | above parameters, the evaluator shall cause the [TOE](#abbr_TOE) to For each supported combination of the above parameters, the evaluator | generate test cases consisting of messages and signatures such that the shall cause the [TOE](#abbr_TOE) to generate test cases consisting of | 21 test cases are modified as follows: messages and signatures such that the 21 test cases are modified as < follows: < - Three test cases are left unmodified - Three test cases are left unmodified - For three test cases the Message is modified - For three test cases the Message is modified - For three test cases the key is modified - For three test cases the key is modified - For three test cases the *r* value is modified - For three test cases the *r* value is modified - For three test cases the *s* value is modified - For three test cases the *s* value is modified - For three test cases the value *r* is zeroed - For three test cases the value *r* is zeroed - For three test cases the value *s* is zeroed - For three test cases the value *s* is zeroed The [TOE](#abbr_TOE) must correctly verify the unmodified signatures and The [TOE](#abbr_TOE) must correctly verify the unmodified signatures and fail to verify the modified signatures. | fail to verify the modified signatures.\ < \ < **LMS Signature Verification** **LMS Signature Verification** ----------------- ----------------- ----------------------- -------------------- ----------------- ----------------- ----------------------- -------------------- Identifier Cryptographic Cryptographic Key Sizes List of Standards Identifier Cryptographic Cryptographic Key Sizes List of Standards Algorithm Algorithm Parameters Parameters LMS LMS Private key size = RFC 8554 \[LMS\] LMS LMS Private key size = RFC 8554 \[LMS\] \[**selection:** *192 \[**selection:** *192 bits with [NIST](#abbr_NIST) bits with [NIST](#abbr_NIST) \[**selection:** SP 800-208 \[**selection:** SP 800-208 SHA256/192, \[parameters\] SHA256/192, \[parameters\] SHAKE256/192\], 256 SHAKE256/192\], 256 bits with bits with \[**selection:** \[**selection:** [SHA](#abbr_SHA)-256, [SHA](#abbr_SHA)-256, SHAKE256\]*\], | SHAKE256\]* \], Winternitz parameter = Winternitz parameter = \[**selection:** *1, 2, \[**selection:** *1, 2, 4, 8*\], and tree 4, 8*\], and tree height = height = \[**selection:** *5, \[**selection:** *5, 10, 15, 20, 25*\] 10, 15, 20, 25*\] ----------------- ----------------- ----------------------- -------------------- ----------------- ----------------- ----------------------- -------------------- To test the [TOE](#abbr_TOE)'s ability to verify cryptographic digital To test the [TOE](#abbr_TOE)'s ability to verify cryptographic digital signature using LMS, the evaluator shall perform the Algorithm signature using LMS, the evaluator shall perform the Algorithm Functional Test using the following input parameters: Functional Test using the following input parameters: - Hash algorithm \[[SHA](#abbr_SHA)-256/192, SHAKE256/192, - Hash algorithm \[[SHA](#abbr_SHA)-256/192, SHAKE256/192, [SHA](#abbr_SHA)-256, SHAKE256\] [SHA](#abbr_SHA)-256, SHAKE256\] - Winternitz \[1, 2, 4, 8\] - Winternitz \[1, 2, 4, 8\] - Tree height \[5, 10, 15, 20, 25\] - Tree height \[5, 10, 15, 20, 25\] \ \ **Algorithm Functional Test** | **Algorithm Functional Test** For each supported combination of the | above parameters, the evaluator shall generate four test cases For each supported combination of the above parameters, the evaluator | consisting of signed messages and keys, such that shall generate four test cases consisting of signed messages and keys, < such that < - One test case is unmodified (i.e., correct) - One test case is unmodified (i.e., correct) - For one test case modify the message, i.e., the message is different - For one test case modify the message, i.e., the message is different - For one test case modify the signature, i.e., signature is different - For one test case modify the signature, i.e., signature is different - For one test case modify the signature header so that it is a valid - For one test case modify the signature header so that it is a valid header for a different LMS parameter set. header for a different LMS parameter set. The [TOE](#abbr_TOE) must correctly verify the unmodified test case and The [TOE](#abbr_TOE) must correctly verify the unmodified test case and fail to verify the modified test cases. | fail to verify the modified test cases.\ < \ < **XMSS Signature Verification** **XMSS Signature Verification** ----------------- ----------------- ----------------------- -------------------- ----------------- ----------------- ----------------------- -------------------- Identifier Cryptographic Cryptographic Key Sizes List of Standards Identifier Cryptographic Cryptographic Key Sizes List of Standards Algorithm Algorithm Parameters Parameters XMSS XMSS Private key size = RFC 8391 \[XMSS\] XMSS XMSS Private key size = RFC 8391 \[XMSS\] \[**selection:** *192 \[**selection:** *192 bits with [NIST](#abbr_NIST) bits with [NIST](#abbr_NIST) \[**selection:** SP 800-208 \[**selection:** SP 800-208 SHA256/192, \[parameters\] SHA256/192, \[parameters\] SHAKE256/192\], 256 SHAKE256/192\], 256 bits with bits with \[**selection:** \[**selection:** [SHA](#abbr_SHA)-256, [SHA](#abbr_SHA)-256, SHAKE256\]*\], and tree | SHAKE256\]* \], and height = | tree height = \[**selection:** *10, \[**selection:** *10, 16, 20*\] 16, 20*\] ----------------- ----------------- ----------------------- -------------------- ----------------- ----------------- ----------------------- -------------------- To test the [TOE](#abbr_TOE)'s ability to verify digital signatures To test the [TOE](#abbr_TOE)'s ability to verify digital signatures using XMSS or XMSS MT, the evaluator shall perform the XMSS digital using XMSS or XMSS MT, the evaluator shall perform the XMSS digital signature verification test using the following input parameters: signature verification test using the following input parameters: - Hash algorithm \[[SHA](#abbr_SHA)-256/192, SHAKE256/192, - Hash algorithm \[[SHA](#abbr_SHA)-256/192, SHAKE256/192, [SHA](#abbr_SHA)-256, SHAKE256\] [SHA](#abbr_SHA)-256, SHAKE256\] - Tree height \[10, 16, 20\] - Tree height \[10, 16, 20\] \ \ **XMSS Digital Signature Verification Test** | **XMSS Digital Signature Verification Test** For each supported | combination of the above parameters, the evaluator shall generate four For each supported combination of the above parameters, the evaluator | test cases consisting of signed messages and keys, such that shall generate four test cases consisting of signed messages and keys, < such that < - One test case is unmodified (i.e., correct) - One test case is unmodified (i.e., correct) - For one test case modify the message, i.e., the message is different - For one test case modify the message, i.e., the message is different - For one test case modify the signature, i.e., signature is different - For one test case modify the signature, i.e., signature is different - For one test case modify the signature header so that it is a valid - For one test case modify the signature header so that it is a valid header for a different XMSS parameter set header for a different XMSS parameter set The evaluator shall verify the correctness of the implementation by The evaluator shall verify the correctness of the implementation by verifying that the [TOE](#abbr_TOE) correctly verifies the unmodified verifying that the [TOE](#abbr_TOE) correctly verifies the unmodified test case and fails to verify the modified test cases. | test case and fails to verify the modified test cases.\ < \ < **ML-DSA Signature Verification** **ML-DSA Signature Verification** ------------ ------------------------------------ --------------------------- ----- ------------ ------------------------------------ --------------------------- ----- Identifier Cryptographic Algorithm Parameters Cryptographic Key Sizes List Identifier Cryptographic Algorithm Parameters Cryptographic Key Sizes List ML-DSA ML-DSA SigVer Parameter set = ML-DSA-87 [NIST ML-DSA ML-DSA SigVer Parameter set = ML-DSA-87 [NIST ------------ ------------------------------------ --------------------------- ----- ------------ ------------------------------------ --------------------------- ----- To test the [TOE](#abbr_TOE)'s ability to validate digital signatures To test the [TOE](#abbr_TOE)'s ability to validate digital signatures using ML-DSA, the evaluator shall perform the Algorithm Functional Test using ML-DSA, the evaluator shall perform the Algorithm Functional Test using the following input parameters: using the following input parameters: - Parameter set \[ML-DSA-87\] - Parameter set \[ML-DSA-87\] - Previously generated signed Message \[8-65535\] bytes - Previously generated signed Message \[8-65535\] bytes - *Mu* value (if generated externally) - *Mu* value (if generated externally) - Context (for external interface testing) - Context (for external interface testing) - Previously generated public key (*pk*) - Previously generated public key (*pk*) - Previously generated Signature - Previously generated Signature \ \ **Algorithm Functional Test** | **Algorithm Functional Test** For each combination of supported | parameter set and capabilities, the evaluator shall require the For each combination of supported parameter set and capabilities, the | implementation under test to validate 15 signatures. Each group of 15 evaluator shall require the implementation under test to validate 15 | test cases is modified as follows: signatures. Each group of 15 test cases is modified as follows: < - Three test cases are left unmodified - Three test cases are left unmodified - For three test cases the Signed message is modified - For three test cases the Signed message is modified - For three test cases the component of the signature that commits the - For three test cases the component of the signature that commits the signer to the message is modified signer to the message is modified - For three test cases the component of the signature that allows the - For three test cases the component of the signature that allows the verifier to construct the vector z is modified verifier to construct the vector z is modified - For three test cases the component of the signature that allows the - For three test cases the component of the signature that allows the verifier to construct the hint array is modified verifier to construct the hint array is modified The [TOE](#abbr_TOE) must correctly verify the unmodified signatures and The [TOE](#abbr_TOE) must correctly verify the unmodified signatures and fail to verify the modified signatures. fail to verify the modified signatures. ::: ::: ::: ::: ::: ::: ::: ::: ::: ::: ::: {#FCS_COP.1/SKC .comp} ::: {#FCS_COP.1/SKC .comp} #### FCS_COP.1/SKC Cryptographic Operation - Encryption/Decryption #### FCS_COP.1/SKC Cryptographic Operation - Encryption/Decryption ::: element ::: element ::: {#FCS_COP.1.1/SKC .reqid} ::: {#FCS_COP.1.1/SKC .reqid} [FCS_COP.1.1/SKC](#FCS_COP.1.1/SKC){.abbr} [FCS_COP.1.1/SKC](#FCS_COP.1.1/SKC){.abbr} ::: ::: ::: reqdesc ::: reqdesc The [TSF](#abbr_TSF) shall perform \[*symmetric-key The [TSF](#abbr_TSF) shall perform \[*symmetric-key encryption/decryption*\] in accordance with a specified cryptographic encryption/decryption*\] in accordance with a specified cryptographic algorithm \[**selection**: [Cryptographic algorithm \[**selection**: [Cryptographic Algorithm]{.selectable-content}\] and cryptographic key sizes Algorithm]{.selectable-content}\] and cryptographic key sizes \[**selection**: [Cryptographic Key Sizes]{.selectable-content}\] that \[**selection**: [Cryptographic Key Sizes]{.selectable-content}\] that meet the following: \[**selection**: [List of meet the following: \[**selection**: [List of Standards]{.selectable-content}\] . Standards]{.selectable-content}\] . [Table [15]{.counter}](#fcs-cop-skc-sels){.fcs-cop-skc-sels-ref [Table [15]{.counter}](#fcs-cop-skc-sels){.fcs-cop-skc-sels-ref onclick="showTarget('fcs-cop-skc-sels')"} provides the allowable choices onclick="showTarget('fcs-cop-skc-sels')"} provides the allowable choices for completion of the selection operations of for completion of the selection operations of [FCS_COP.1/SKC](#FCS_COP.1/SKC). [FCS_COP.1/SKC](#FCS_COP.1/SKC). ----------------------------------------------------------------------------------- | ----------------------------------------------------------------------------------- Identifier Cryptographic Cryptographic Key List of Standards Identifier Cryptographic Cryptographic Key List of Standards Algorithm Sizes Algorithm Sizes ---------------------- ------------------ ----------------- ----------------------- | ---------------------- ------------------ ----------------- ----------------------- [AES](#abbr_AES)-CBC [AES](#abbr_AES) 256 bits \[**selection**: | [AES](#abbr_AES)-CBC [AES](#abbr_AES) 256 bits \[**selection**: [ISO/I in [ISO/IEC 18033-3:2010 | in 18033-3:2010 (Subclause [CBC](#abbr_CBC) (Subclause 5.2)]{#_s_34 | [CBC](#abbr_CBC) 5.2)]{#fcs_cop.1.1_SKC_ mode with .selectable-content}, mode with .selectable-content}, non-repeating and [[FIPS](#abbr_FIPS) PUB non-repeating and [[FIPS](#abbr_FIPS) PUB unpredictable IVs 197]{#_s_341 | unpredictable IVs 197]{#fcs_cop.1.1_SKC_2 .selectable-content}\] .selectable-content}\] \[[AES](#abbr_AES)\] \[[AES](#abbr_AES)\] \[**selection**: | \[**selection**: [ISO/I [ISO/IEC 10116:2017 | 10116:2017 (Clause (Clause 7)]{#_s_342 | 7)]{#fcs_cop.1.1_SKC_3 .selectable-content}, .selectable-content}, [[NIST](#abbr_NIST) SP [[NIST](#abbr_NIST) SP 800-38A]{#_s_343 | 800-38A]{#fcs_cop.1.1_S .selectable-content}\] .selectable-content}\] \[[CBC](#abbr_CBC)\] \[[CBC](#abbr_CBC)\] [XTS](#abbr_XTS)-AES [AES](#abbr_AES) 512 bits \[**selection**: | [XTS](#abbr_XTS)-AES [AES](#abbr_AES) 512 bits \[**selection**: [ISO/I in [ISO/IEC 18033-3:2010 | in 18033-3:2010 (Subclause [XTS](#abbr_XTS) (Subclause 5.2)]{#_s_34 | [XTS](#abbr_XTS) 5.2)]{#fcs_cop.1.1_SKC_ mode with unique .selectable-content}, mode with unique .selectable-content}, tweak values that [[FIPS](#abbr_FIPS) PUB tweak values that [[FIPS](#abbr_FIPS) PUB are consecutive 197]{#_s_346 | are consecutive 197]{#fcs_cop.1.1_SKC_6 non-negative .selectable-content}\] non-negative .selectable-content}\] integers starting \[[AES](#abbr_AES)\] integers starting \[[AES](#abbr_AES)\] at an arbitrary at an arbitrary non-negative \[**selection**: non-negative \[**selection**: integer [[IEEE](#abbr_IEEE) Std integer [[IEEE](#abbr_IEEE) Std 1619-2018]{#_s_347 | 1619-2018]{#fcs_cop.1.1 .selectable-content}, .selectable-content}, [[NIST](#abbr_NIST) SP [[NIST](#abbr_NIST) SP 800-38E]{#_s_348 | 800-38E]{#fcs_cop.1.1_S .selectable-content}\] .selectable-content}\] \[[XTS](#abbr_XTS)\] \[[XTS](#abbr_XTS)\] [AES](#abbr_AES)-CTR [AES](#abbr_AES) 256 bits \[**selection**: | [AES](#abbr_AES)-CTR [AES](#abbr_AES) 256 bits \[**selection**: [ISO/I in Counter Mode [ISO/IEC 18033-3:2010 | in Counter Mode 18033-3:2010 (Subclause with a (Subclause 5.2)]{#_s_35 | with a 5.2)]{#fcs_cop.1.1_SKC_ non-repeating .selectable-content}, non-repeating .selectable-content}, initial counter [[FIPS](#abbr_FIPS) PUB initial counter [[FIPS](#abbr_FIPS) PUB and with no 197]{#_s_351 | and with no 197]{#fcs_cop.1.1_SKC_1 repeated use of .selectable-content}\] repeated use of .selectable-content}\] counter values \[[AES](#abbr_AES)\] counter values \[[AES](#abbr_AES)\] across multiple across multiple messages with the \[**selection**: [: | messages with the \[**selection**: [: ISO same secret key ISO/IEC 10116:2017 | same secret key 10116:2017 (Clause (Clause 10)]{#_s_352 | 10)]{#fcs_cop.1.1_SKC_1 .selectable-content}, .selectable-content}, [[NIST](#abbr_NIST) SP [[NIST](#abbr_NIST) SP 800-38A]{#_s_353 | 800-38A]{#fcs_cop.1.1_S .selectable-content}\] .selectable-content}\] \[[CBC](#abbr_CBC)\] \[[CBC](#abbr_CBC)\] ----------------------------------------------------------------------------------- | ----------------------------------------------------------------------------------- : [Table [15]{.counter}]{#fcs-cop-skc-sels .ctr : [Table [15]{.counter}]{#fcs-cop-skc-sels .ctr myid="fcs-cop-skc-sels" counter-type="ct-Table"}: Allowable choices myid="fcs-cop-skc-sels" counter-type="ct-Table"}: Allowable choices for [FCS_COP.1/SKC](#FCS_COP.1/SKC) for [FCS_COP.1/SKC](#FCS_COP.1/SKC) ::: appnote ::: appnote [Application Note: ]{.note-header}[At minimum, the [TOE](#abbr_TOE) is [Application Note: ]{.note-header}[At minimum, the [TOE](#abbr_TOE) is required to support [AES](#abbr_AES)-CBC to provide this algorithm as a required to support [AES](#abbr_AES)-CBC to provide this algorithm as a cryptographic service to tenant software as defined in cryptographic service to tenant software as defined in [FCS_SRV_EXT.1](#FCS_SRV_EXT.1).]{.note} [FCS_SRV_EXT.1](#FCS_SRV_EXT.1).]{.note} ::: ::: ::: ::: ::: ::: ::: {.activity_pane .hide} ::: {.activity_pane .hide} ::: activity_pane_header ::: activity_pane_header [[ Evaluation Activities [[ Evaluation Activities ]{.activity_pane_label}[]{.toggler}](#){onclick="toggle(this);return false;"} ]{.activity_pane_label}[]{.toggler}](#){onclick="toggle(this);return false;"} ::: ::: ::: activity_pane_body ::: activity_pane_body ::: component-activity-header ::: component-activity-header [FCS_COP.1/SKC](#FCS_COP.1/SKC) [FCS_COP.1/SKC](#FCS_COP.1/SKC) ::: ::: ::: eacategory ::: eacategory [TSS](#abbr_TSS) [TSS](#abbr_TSS) ::: ::: ::: ea ::: ea ::: ea ::: ea The evaluator shall examine the [TSS](#abbr_TSS) to ensure that it The evaluator shall examine the [TSS](#abbr_TSS) to ensure that it describes the construction of any IVs, tweak values, and counters in describes the construction of any IVs, tweak values, and counters in conformance with the relevant specifications. conformance with the relevant specifications. If [XTS](#abbr_XTS)-AES is claimed then the evaluator shall examine the If [XTS](#abbr_XTS)-AES is claimed then the evaluator shall examine the [TSS](#abbr_TSS) to verify that the [TOE](#abbr_TOE) creates full-length [TSS](#abbr_TSS) to verify that the [TOE](#abbr_TOE) creates full-length keys by methods that ensure that the two key halves are different and keys by methods that ensure that the two key halves are different and independent. independent. ::: ::: ::: ::: ::: eacategory ::: eacategory Guidance Guidance ::: ::: ::: ea ::: ea There are no additional Guidance evaluation activities for this There are no additional Guidance evaluation activities for this component.\ component.\ ::: ::: ::: eacategory ::: eacategory Tests Tests ::: ::: ::: ea ::: ea ::: ea ::: ea The following tests require the developer to provide access to a test The following tests require the developer to provide access to a test platform that provides the evaluator with tools that are typically not platform that provides the evaluator with tools that are typically not found on factory products. | found on factory products. The following tests are conditional based | upon the selections made in the [SFR](#abbr_SFR). The evaluator shall The following tests are conditional based upon the selections made in | perform the following test or witness respective tests executed by the the [SFR](#abbr_SFR). The evaluator shall perform the following test or | developer. The tests must be executed on a platform that is as close as witness respective tests executed by the developer. The tests must be | practically possible to the operational platform (but which may be executed on a platform that is as close as practically possible to the | instrumented in terms of, for example, use of a debug mode). Where the operational platform (but which may be instrumented in terms of, for | test is not carried out on the [TOE](#abbr_TOE) itself, the test example, use of a debug mode). Where the test is not carried out on the | platform shall be identified and the differences between test [TOE](#abbr_TOE) itself, the test platform shall be identified and the | environment and [TOE](#abbr_TOE) execution environment shall be differences between test environment and [TOE](#abbr_TOE) execution | described.\ environment shall be described. < < \ < **[AES](#abbr_AES)-CBC** **[AES](#abbr_AES)-CBC** ---------------------- ------------------ ----------------- ---------------------- ---------------------- ------------------ ----------------- ---------------------- Identifier Cryptographic Cryptographic Key List of Standards Identifier Cryptographic Cryptographic Key List of Standards Algorithm Sizes Algorithm Sizes [AES](#abbr_AES)-CBC [AES](#abbr_AES) 256 bits \[**selection:** [AES](#abbr_AES)-CBC [AES](#abbr_AES) 256 bits \[**selection:** in ISO/IEC 18033-3:2010 in ISO/IEC 18033-3:2010 [CBC](#abbr_CBC) (Subclause 5.2), [CBC](#abbr_CBC) (Subclause 5.2), mode with [FIPS](#abbr_FIPS) PUB mode with [FIPS](#abbr_FIPS) PUB non-repeating and 197\] non-repeating and 197\] unpredictable IVs \[[AES](#abbr_AES)\] unpredictable IVs \[[AES](#abbr_AES)\] \[**selection:** \[**selection:** ISO/IEC 10116:2017 ISO/IEC 10116:2017 (Clause 7), (Clause 7), [NIST](#abbr_NIST) SP [NIST](#abbr_NIST) SP 800-38A\] 800-38A\] \[[CBC](#abbr_CBC)\] \[[CBC](#abbr_CBC)\] ---------------------- ------------------ ----------------- ---------------------- ---------------------- ------------------ ----------------- ---------------------- To test the [TOE](#abbr_TOE)'s ability to encrypt/decrypt data using To test the [TOE](#abbr_TOE)'s ability to encrypt/decrypt data using [AES](#abbr_AES) in [CBC](#abbr_CBC) mode, the evaluator shall perform [AES](#abbr_AES) in [CBC](#abbr_CBC) mode, the evaluator shall perform Algorithm Functional Tests and Monte Carlo Tests using the following Algorithm Functional Tests and Monte Carlo Tests using the following input parameters: input parameters: - Key size \[256\] bits - Key size \[256\] bits - Direction \[encryption, decryption\] - Direction \[encryption, decryption\] \ \ **Algorithm Functional Tests** | **Algorithm Functional Tests** Algorithm Functional Tests are designed | to verify the correct operation of the logical components of the Algorithm Functional Tests are designed to verify the correct operation | algorithm implementation under normal operation using different block of the logical components of the algorithm implementation under normal | sizes. For [AES](#abbr_AES)-CBC, there are two types of AFTs:\ operation using different block sizes. For [AES](#abbr_AES)-CBC, there | ***Known-Answer Tests*** For each combination of direction and claimed are two types of AFTs: | key size, the [TOE](#abbr_TOE) must be tested using the GFSBox, KeySbox, | VarTxt, and VarKey test cases listed in Appendixes B through E of *The \ | Advanced Encryption Standard Algorithm Validation Suite (AESAVS)*, ***Known-Answer Tests*** | [NIST](#abbr_NIST), 15 November 2002.\ | ***Multi-Block Message Tests*** For each combination of direction and For each combination of direction and claimed key size, the | claimed key size, the [TOE](#abbr_TOE) must be tested against 10 test [TOE](#abbr_TOE) must be tested using the GFSBox, KeySbox, VarTxt, and | cases consisting of a random IV, random key, and random VarKey test cases listed in Appendixes B through E of *The Advanced | plaintext/ciphertext. The plaintext/ciphertext starts with a length of Encryption Standard Algorithm Validation Suite (AESAVS)*, | 16 bytes and increases by 16 bytes for each test case until reaching 160 [NIST](#abbr_NIST), 15 November 2002. | bytes.\ | ***Monte Carlo Tests*** Monte Carlo tests are intended to test the \ | implementation under strenuous conditions. The [TOE](#abbr_TOE) must ***Multi-Block Message Tests*** | process the test cases according to the following algorithm once for | each combination of direction and key size: For each combination of direction and claimed key size, the < [TOE](#abbr_TOE) must be tested against 10 test cases consisting of a < random IV, random key, and random plaintext/ciphertext. The < plaintext/ciphertext starts with a length of 16 bytes and increases by < 16 bytes for each test case until reaching 160 bytes. < < \ < ***Monte Carlo Tests*** < < Monte Carlo tests are intended to test the implementation under < strenuous conditions. The [TOE](#abbr_TOE) must process the test cases < according to the following algorithm once for each combination of < direction and key size: < Key[0] = Key Key[0] = Key IV[0] = IV IV[0] = IV PT[0] = PT PT[0] = PT for i = 0 to 99 { for i = 0 to 99 { Output Key[i], IV[i], PT[0] Output Key[i], IV[i], PT[0] for j = 0 to 999 { for j = 0 to 999 { if (j == 0) { if (j == 0) { CT[j] = AES-CBC-Encrypt(Key[i], IV[i], PT[j]) CT[j] = AES-CBC-Encrypt(Key[i], IV[i], PT[j]) PT[j+1] = IV[i] PT[j+1] = IV[i] } else { } else { CT[j] = AES-CBC-Encrypt(Key[i], PT[j]) CT[j] = AES-CBC-Encrypt(Key[i], PT[j]) PT[j+1] = CT[j-1] PT[j+1] = CT[j-1] } } } } Output CT[j] Output CT[j] AES_KEY_SHUFFLE(Key, CT) AES_KEY_SHUFFLE(Key, CT) IV[i+1] = CT[j] IV[i+1] = CT[j] PT[0] = CT[j-1] PT[0] = CT[j-1] } } where where AES_KEY_SHUFFLE AES_KEY_SHUFFLE is defined as: is defined as: If ( keylen = 128 ) If ( keylen = 128 ) Key[i+1] = Key[i] xor MSB(CT[j], 128) Key[i+1] = Key[i] xor MSB(CT[j], 128) If ( keylen = 192 ) If ( keylen = 192 ) Key[i+1] = Key[i] xor (LSB(CT[j-1], 64) || MSB(CT[j], 128)) Key[i+1] = Key[i] xor (LSB(CT[j-1], 64) || MSB(CT[j], 128)) If ( keylen = 256 ) If ( keylen = 256 ) Key[i+1] = Key[i] xor (MSB(CT[j-1], 128) || MSB(CT[j], 128)) Key[i+1] = Key[i] xor (MSB(CT[j-1], 128) || MSB(CT[j], 128)) The above pseudocode is for encryption. For decryption, swap all The above pseudocode is for encryption. For decryption, swap all instances of CT and PT. | instances of CT and PT. The initial IV, key, and plaintext/ciphertext | should be random. The evaluator shall test the decrypt functionality The initial IV, key, and plaintext/ciphertext should be random. | using the same test as above, exchanging CT and PT, and replacing | [AES](#abbr_AES)-CBC-Encrypt with [AES](#abbr_AES)-CBC-Decrypt.\ The evaluator shall test the decrypt functionality using the same test < as above, exchanging CT and PT, and replacing < [AES](#abbr_AES)-CBC-Encrypt with [AES](#abbr_AES)-CBC-Decrypt. < < \ < **[XTS](#abbr_XTS)-AES** **[XTS](#abbr_XTS)-AES** ---------------------- ------------------ ----------------- ---------------------- ---------------------- ------------------ ----------------- ---------------------- Identifier Cryptographic Cryptographic Key List of Standards Identifier Cryptographic Cryptographic Key List of Standards Algorithm Sizes Algorithm Sizes [XTS](#abbr_XTS)-AES [AES](#abbr_AES) 512 bits \[**selection:** [XTS](#abbr_XTS)-AES [AES](#abbr_AES) 512 bits \[**selection:** in ISO/IEC 18033-3:2010 in ISO/IEC 18033-3:2010 [XTS](#abbr_XTS) (Subclause 5.2), [XTS](#abbr_XTS) (Subclause 5.2), mode with unique [FIPS](#abbr_FIPS) PUB mode with unique [FIPS](#abbr_FIPS) PUB tweak values that 197\] tweak values that 197\] are consecutive \[[AES](#abbr_AES)\] are consecutive \[[AES](#abbr_AES)\] non-negative non-negative integers starting \[**selection:** integers starting \[**selection:** at an arbitrary [IEEE](#abbr_IEEE) at an arbitrary [IEEE](#abbr_IEEE) non-negative Std. 1619-2018, non-negative Std. 1619-2018, integer [NIST](#abbr_NIST) SP integer [NIST](#abbr_NIST) SP 800-38E\] 800-38E\] \[[XTS](#abbr_XTS)\] \[[XTS](#abbr_XTS)\] ---------------------- ------------------ ----------------- ---------------------- ---------------------- ------------------ ----------------- ---------------------- To test the [TOE](#abbr_TOE)'s ability to encrypt/decrypt data using To test the [TOE](#abbr_TOE)'s ability to encrypt/decrypt data using [AES](#abbr_AES) in [XTS](#abbr_XTS) mode, the evaluator shall perform [AES](#abbr_AES) in [XTS](#abbr_XTS) mode, the evaluator shall perform the Single Data Unit Test and the Multiple Data Unit Test using the the Single Data Unit Test and the Multiple Data Unit Test using the following input parameters: following input parameters: - Direction \[encryption, decryption\] - Direction \[encryption, decryption\] - Key size \[512\] bits - Key size \[512\] bits - Tweak value format \[128-bit hex string, data unit sequence number\] - Tweak value format \[128-bit hex string, data unit sequence number\] \ \ **Single Data Unit Test** | **Single Data Unit Test** For each combination of claimed key size, | direction, and supported tweak value format, the evaluator shall For each combination of claimed key size, direction, and supported tweak | generate 50 test cases consisting of random payload data. The payload value format, the evaluator shall generate 50 test cases consisting of | data size is determined randomly for each test case from supported random payload data. The payload data size is determined randomly for | values within the range \[128-65536\] bits. The payload size and data each test case from supported values within the range \[128-65536\] | unit size must be equal.\ bits. The payload size and data unit size must be equal. | **Multiple Data Unit Test** For each combination of claimed key size, | direction, and supported tweak value format, the evaluator shall \ | generate 50 test cases consisting of random payload data. The payload **Multiple Data Unit Test** | data size is determined randomly for each test case from supported | values within the range \[128-65536\] bits. Likewise, the data unit size For each combination of claimed key size, direction, and supported tweak | is determined randomly for each test case from supported values within value format, the evaluator shall generate 50 test cases consisting of | the range \[128-65535\] bits. The payload size and data unit size must random payload data. The payload data size is determined randomly for | not be equal. The evaluator shall verify the correctness of the each test case from supported values within the range \[128-65536\] | [TSF](#abbr_TSF)'s implementation by comparing values generated by the bits. Likewise, the data unit size is determined randomly for each test | [TSF](#abbr_TSF) with those generated by a known good implementation case from supported values within the range \[128-65535\] bits. The | using the same input parameters.\ payload size and data unit size must not be equal. < < The evaluator shall verify the correctness of the [TSF](#abbr_TSF)'s < implementation by comparing values generated by the [TSF](#abbr_TSF) < with those generated by a known good implementation using the same input < parameters. < < \ < **[AES](#abbr_AES)-CTR** **[AES](#abbr_AES)-CTR** ---------------------- ------------------ ----------------- ---------------------- ---------------------- ------------------ ----------------- ---------------------- Identifier Cryptographic Cryptographic Key List of Standards Identifier Cryptographic Cryptographic Key List of Standards Algorithm Sizes Algorithm Sizes [AES](#abbr_AES)-CTR [AES](#abbr_AES) 256 bits \[**selection:** [AES](#abbr_AES)-CTR [AES](#abbr_AES) 256 bits \[**selection:** in Counter Mode ISO/IEC 18033-3:2010 in Counter Mode ISO/IEC 18033-3:2010 with a (Subclause 5.2), with a (Subclause 5.2), non-repeating [FIPS](#abbr_FIPS) PUB non-repeating [FIPS](#abbr_FIPS) PUB initial counter 197\] initial counter 197\] and with no \[[AES](#abbr_AES)\] and with no \[[AES](#abbr_AES)\] repeated use of repeated use of counter values \[**selection:** counter values \[**selection:** across multiple ISO/IEC 10116:2017 across multiple ISO/IEC 10116:2017 messages with the (Clause 10), messages with the (Clause 10), same secret key. [NIST](#abbr_NIST) SP same secret key. [NIST](#abbr_NIST) SP 800-38A\] \[CTR\] 800-38A\] \[CTR\] ---------------------- ------------------ ----------------- ---------------------- ---------------------- ------------------ ----------------- ---------------------- To test the [TOE](#abbr_TOE)'s ability to encrypt/decrypt data using To test the [TOE](#abbr_TOE)'s ability to encrypt/decrypt data using [AES](#abbr_AES) in CTR mode, the evaluator shall perform the Algorithm [AES](#abbr_AES) in CTR mode, the evaluator shall perform the Algorithm Functional Test and the Counter Test using the following input Functional Test and the Counter Test using the following input parameters: parameters: - Direction \[encryption, decryption\] - Direction \[encryption, decryption\] - Key size \[256\] bits - Key size \[256\] bits \ \ **Algorithm Functional Tests** | **Algorithm Functional Tests** Algorithm Functional Tests are designed | to verify the correct operation of the logical components of the Algorithm Functional Tests are designed to verify the correct operation | algorithm implementation under normal operation using different block of the logical components of the algorithm implementation under normal | sizes. For [AES](#abbr_AES)-CTR, there are three types of AFTs:\ operation using different block sizes. For [AES](#abbr_AES)-CTR, there | ***Known-Answer Tests*** For each combination of direction and claimed are three types of AFTs: | key size, the [TOE](#abbr_TOE) must be tested using the GFSBox, KeySbox, | VarTxt, and VarKey test cases listed in Appendixes B through E of *The \ | Advanced Encryption Standard Algorithm Validation Suite (AESAVS)*, ***Known-Answer Tests*** | [NIST](#abbr_NIST), 15 November 2002.\ | ***Single Block Message Tests*** For each combination of direction and For each combination of direction and claimed key size, the | claimed key, the evaluator shall generate 10 test cases with a data size [TOE](#abbr_TOE) must be tested using the GFSBox, KeySbox, VarTxt, and | of 128 bits.\ VarKey test cases listed in Appendixes B through E of *The Advanced | ***Partial Block Message Tests*** Monte Carlo tests are intended to test Encryption Standard Algorithm Validation Suite (AESAVS)*, | the implementation under strenuous conditions. The [TOE](#abbr_TOE) must [NIST](#abbr_NIST), 15 November 2002. | process the test cases according to the following algorithm once for | each combination of direction and key size: For each combination of \ | direction and claimed key, the evaluator shall generate five test cases ***Single Block Message Tests*** | such that the data size is not a multiple of 128 bits. The evaluator | shall verify the correctness of the [TSF](#abbr_TSF)'s implementation by For each combination of direction and claimed key, the evaluator shall | comparing values generated by the [TSF](#abbr_TSF) with those generated generate 10 test cases with a data size of 128 bits. | by a known good implementation using the same input parameters.\ | ***Counter Test*** The evaluator shall generate a single message of 1000 \ | blocks (128000 bits) and either encrypt or decrypt it. Back-compute the ***Partial Block Message Tests*** | IVs used. Verify that they are unique and increasing (encryption) or | decreasing (decryption). Monte Carlo tests are intended to test the implementation under < strenuous conditions. The [TOE](#abbr_TOE) must process the test cases < according to the following algorithm once for each combination of < direction and key size: < < For each combination of direction and claimed key, the evaluator shall < generate five test cases such that the data size is not a multiple of < 128 bits. < < The evaluator shall verify the correctness of the [TSF](#abbr_TSF)'s < implementation by comparing values generated by the [TSF](#abbr_TSF) < with those generated by a known good implementation using the same input < parameters.\ < ***Counter Test*** < < The evaluator shall generate a single message of 1000 blocks (128000 < bits) and either encrypt or decrypt it. Back-compute the IVs used. < Verify that they are unique and increasing (encryption) or decreasing < (decryption). < ::: ::: ::: ::: ::: ::: ::: ::: ::: ::: ::: {#FCS_HTTPS_EXT.1 .comp} ::: {#FCS_HTTPS_EXT.1 .comp} #### FCS_HTTPS_EXT.1 HTTPS Protocol #### FCS_HTTPS_EXT.1 HTTPS Protocol ::: element ::: element ::: {#FCS_HTTPS_EXT.1.1 .reqid} ::: {#FCS_HTTPS_EXT.1.1 .reqid} [FCS_HTTPS_EXT.1.1](#FCS_HTTPS_EXT.1.1){.abbr} [FCS_HTTPS_EXT.1.1](#FCS_HTTPS_EXT.1.1){.abbr} ::: ::: ::: reqdesc ::: reqdesc The [TSF](#abbr_TSF) shall implement the [HTTPS](#abbr_HTTPS) protocol The [TSF](#abbr_TSF) shall implement the [HTTPS](#abbr_HTTPS) protocol that complies with RFC 2818. that complies with RFC 2818. ::: ::: ::: ::: ::: element ::: element ::: {#FCS_HTTPS_EXT.1.2 .reqid} ::: {#FCS_HTTPS_EXT.1.2 .reqid} [FCS_HTTPS_EXT.1.2](#FCS_HTTPS_EXT.1.2){.abbr} [FCS_HTTPS_EXT.1.2](#FCS_HTTPS_EXT.1.2){.abbr} ::: ::: ::: reqdesc ::: reqdesc The [TSF](#abbr_TSF) shall implement [HTTPS](#abbr_HTTPS) using The [TSF](#abbr_TSF) shall implement [HTTPS](#abbr_HTTPS) using [TLS](#abbr_TLS) as defined in \[*the [Functional Package for Transport [TLS](#abbr_TLS) as defined in \[*the [Functional Package for Transport Layer Security (TLS), version Layer Security (TLS), version 2.1](https://www.niap-ccevs.org/static_html/protection-profile/519)*\]. 2.1](https://www.niap-ccevs.org/static_html/protection-profile/519)*\]. ::: appnote ::: appnote [Application Note: ]{.note-header}[ The [Functional Package for [Application Note: ]{.note-header}[ The [Functional Package for Transport Layer Security (TLS), version Transport Layer Security (TLS), version 2.1](https://www.niap-ccevs.org/static_html/protection-profile/519) must 2.1](https://www.niap-ccevs.org/static_html/protection-profile/519) must be included in the [ST](#abbr_ST), with the following selections made: be included in the [ST](#abbr_ST), with the following selections made: ]{.note} ]{.note} - FCS_TLS_EXT.1: - FCS_TLS_EXT.1: - - [TLS](#abbr_TLS) must be selected - - [TLS](#abbr_TLS) must be selected - Client must be selected - Client must be selected ::: ::: ::: ::: ::: ::: ::: element ::: element ::: {#FCS_HTTPS_EXT.1.3 .reqid} ::: {#FCS_HTTPS_EXT.1.3 .reqid} [FCS_HTTPS_EXT.1.3](#FCS_HTTPS_EXT.1.3){.abbr} [FCS_HTTPS_EXT.1.3](#FCS_HTTPS_EXT.1.3){.abbr} ::: ::: ::: reqdesc ::: reqdesc The [TSF](#abbr_TSF) shall notify the application and \[**selection**: The [TSF](#abbr_TSF) shall notify the application and \[**selection**: [not establish the connection]{#s-not-estab .selectable-content}, [not establish the connection]{#s-not-estab .selectable-content}, [request application authorization to establish the [request application authorization to establish the connection]{#s-req-app-auth .selectable-content}, [no other connection]{#s-req-app-auth .selectable-content}, [no other action]{#s-no-other-action .selectable-content}\] if the peer action]{#s-no-other-action .selectable-content}\] if the peer certificate is deemed invalid. certificate is deemed invalid. ::: appnote ::: appnote [Application Note: ]{.note-header}[ ]{.note} [Application Note: ]{.note-header}[ ]{.note} Validity is determined by the certificate path, the expiration date, and Validity is determined by the certificate path, the expiration date, and the revocation status in accordance with RFC 5280. the revocation status in accordance with RFC 5280. The selection made for [FCS_HTTPS_EXT.1.3](#FCS_HTTPS_EXT.1.3) must be The selection made for [FCS_HTTPS_EXT.1.3](#FCS_HTTPS_EXT.1.3) must be consistent with the claims made in FCS_TLSC_EXT.1.6 of [Functional consistent with the claims made in FCS_TLSC_EXT.1.6 of [Functional Package for Transport Layer Security (TLS), version Package for Transport Layer Security (TLS), version 2.1](https://www.niap-ccevs.org/static_html/protection-profile/519), 2.1](https://www.niap-ccevs.org/static_html/protection-profile/519), e.g. if the [TLS](#abbr_TLS) rejects all invalid certificates with no e.g. if the [TLS](#abbr_TLS) rejects all invalid certificates with no exceptions, then \"not establish the connection\" will be selected here. exceptions, then \"not establish the connection\" will be selected here. [FMT_SMF_EXT.1](#FMT_SMF_EXT.1) Function [23](#mf-certInvalid) [FMT_SMF_EXT.1](#FMT_SMF_EXT.1) Function [23](#mf-certInvalid) configures whether to allow or disallow the establishment of a trusted configures whether to allow or disallow the establishment of a trusted channel if the peer certificate is deemed invalid. channel if the peer certificate is deemed invalid. ::: ::: ::: ::: ::: ::: ::: {.activity_pane .hide} ::: {.activity_pane .hide} ::: activity_pane_header ::: activity_pane_header [[ Evaluation Activities [[ Evaluation Activities ]{.activity_pane_label}[]{.toggler}](#){onclick="toggle(this);return false;"} ]{.activity_pane_label}[]{.toggler}](#){onclick="toggle(this);return false;"} ::: ::: ::: activity_pane_body ::: activity_pane_body ::: component-activity-header ::: component-activity-header [FCS_HTTPS_EXT.1](#FCS_HTTPS_EXT.1) [FCS_HTTPS_EXT.1](#FCS_HTTPS_EXT.1) ::: ::: ::: eacategory ::: eacategory [TSS](#abbr_TSS) [TSS](#abbr_TSS) ::: ::: ::: ea ::: ea ::: ea ::: ea There are no [TSS](#abbr_TSS) evaluation activities for this component.\ There are no [TSS](#abbr_TSS) evaluation activities for this component.\ \ \ ::: ::: ::: ::: ::: eacategory ::: eacategory Guidance Guidance ::: ::: ::: ea ::: ea ::: ea ::: ea There are no guidance evaluation activities for this component.\ There are no guidance evaluation activities for this component.\ \ \ ::: ::: ::: ::: ::: eacategory ::: eacategory Tests Tests ::: ::: ::: ea ::: ea ::: ea ::: ea []{.testlist-} []{.testlist-} - [Test FCS_HTTPS_EXT.1:1](#_t_12){#_t_12 .defined}: The evaluator - [Test FCS_HTTPS_EXT.1:1](#_t_12){#_t_12 .defined}: The evaluator shall attempt to establish an [HTTPS](#abbr_HTTPS) connection with a shall attempt to establish an [HTTPS](#abbr_HTTPS) connection with a webserver, observe the traffic with a packet analyzer, and verify webserver, observe the traffic with a packet analyzer, and verify that the connection succeeds and that the traffic is identified as that the connection succeeds and that the traffic is identified as [TLS](#abbr_TLS) or [HTTPS](#abbr_HTTPS). [TLS](#abbr_TLS) or [HTTPS](#abbr_HTTPS). Other tests are performed in conjunction with testing in the Other tests are performed in conjunction with testing in the [Functional Package for Transport Layer Security (TLS), version [Functional Package for Transport Layer Security (TLS), version 2.1](https://www.niap-ccevs.org/static_html/protection-profile/519). 2.1](https://www.niap-ccevs.org/static_html/protection-profile/519). - [Test FCS_HTTPS_EXT.1:2](#_t_13){#_t_13 .defined}: The evaluator - [Test FCS_HTTPS_EXT.1:2](#_t_13){#_t_13 .defined}: The evaluator shall demonstrate that using a certificate without a valid shall demonstrate that using a certificate without a valid certification path results in an application notification. Using the certification path results in an application notification. Using the administrative guidance, the evaluator shall then load a certificate administrative guidance, the evaluator shall then load a certificate or certificates to the Trust Anchor Database needed to validate the or certificates to the Trust Anchor Database needed to validate the certificate to be used in the function, and demonstrate that the certificate to be used in the function, and demonstrate that the function succeeds. The evaluator then shall delete one of the function succeeds. The evaluator then shall delete one of the certificates, and show that the application is notified of the certificates, and show that the application is notified of the validation failure. validation failure. Certificate validity for [HTTPS](#abbr_HTTPS) connections shall be Certificate validity for [HTTPS](#abbr_HTTPS) connections shall be tested in accordance with testing performed for FIA_X509_EXT.1 as tested in accordance with testing performed for FIA_X509_EXT.1 as defined in the [Functional Package for X.509, version defined in the [Functional Package for X.509, version 1.0](https://www.niap-ccevs.org/protectionprofiles/511). 1.0](https://www.niap-ccevs.org/protectionprofiles/511). ::: ::: ::: ::: ::: ::: ::: ::: ::: ::: ::: {#FCS_IV_EXT.1 .comp} ::: {#FCS_IV_EXT.1 .comp} #### FCS_IV_EXT.1 Initialization Vector Generation #### FCS_IV_EXT.1 Initialization Vector Generation ::: element ::: element ::: {#FCS_IV_EXT.1.1 .reqid} ::: {#FCS_IV_EXT.1.1 .reqid} [FCS_IV_EXT.1.1](#FCS_IV_EXT.1.1){.abbr} [FCS_IV_EXT.1.1](#FCS_IV_EXT.1.1){.abbr} ::: ::: ::: reqdesc ::: reqdesc The [TSF](#abbr_TSF) shall generate IVs in accordance with \[*[Table The [TSF](#abbr_TSF) shall generate IVs in accordance with \[*[Table [29]{.counter}](#ivtable){.ivtable-ref onclick="showTarget('ivtable')"}: [29]{.counter}](#ivtable){.ivtable-ref onclick="showTarget('ivtable')"}: References and IV Requirements for [NIST](#abbr_NIST)-approved Cipher References and IV Requirements for [NIST](#abbr_NIST)-approved Cipher Modes*\]. Modes*\]. ::: appnote ::: appnote [Application Note: ]{.note-header}[ [Table [Application Note: ]{.note-header}[ [Table [29]{.counter}](#ivtable){.ivtable-ref onclick="showTarget('ivtable')"} [29]{.counter}](#ivtable){.ivtable-ref onclick="showTarget('ivtable')"} lists the requirements for composition of IVs according to the lists the requirements for composition of IVs according to the [NIST](#abbr_NIST) Special Publications for each cipher mode. The [NIST](#abbr_NIST) Special Publications for each cipher mode. The composition of IVs generated for encryption according to a cryptographic composition of IVs generated for encryption according to a cryptographic protocol is addressed by the protocol. Thus, this requirement addresses protocol is addressed by the protocol. Thus, this requirement addresses only IVs generated for key storage and data storage encryption. ]{.note} only IVs generated for key storage and data storage encryption. ]{.note} ::: ::: ::: ::: ::: ::: ::: {.activity_pane .hide} ::: {.activity_pane .hide} ::: activity_pane_header ::: activity_pane_header [[ Evaluation Activities [[ Evaluation Activities ]{.activity_pane_label}[]{.toggler}](#){onclick="toggle(this);return false;"} ]{.activity_pane_label}[]{.toggler}](#){onclick="toggle(this);return false;"} ::: ::: ::: activity_pane_body ::: activity_pane_body ::: component-activity-header ::: component-activity-header [FCS_IV_EXT.1](#FCS_IV_EXT.1) [FCS_IV_EXT.1](#FCS_IV_EXT.1) ::: ::: ::: eacategory ::: eacategory [TSS](#abbr_TSS) [TSS](#abbr_TSS) ::: ::: ::: ea ::: ea ::: ea ::: ea The evaluator shall examine the key hierarchy section of the The evaluator shall examine the key hierarchy section of the [TSS](#abbr_TSS) to ensure that the encryption of all keys is described [TSS](#abbr_TSS) to ensure that the encryption of all keys is described and the formation of the IVs for each key encrypted by the same and the formation of the IVs for each key encrypted by the same [KEK](#abbr_KEK) meets [FCS_IV_EXT.1](#FCS_IV_EXT.1).\ [KEK](#abbr_KEK) meets [FCS_IV_EXT.1](#FCS_IV_EXT.1).\ \ \ ::: ::: ::: ::: ::: eacategory ::: eacategory Guidance Guidance ::: ::: ::: ea ::: ea ::: ea ::: ea There are no guidance evaluation activities for this component.\ There are no guidance evaluation activities for this component.\ \ \ ::: ::: ::: ::: ::: eacategory ::: eacategory Tests Tests ::: ::: ::: ea ::: ea ::: ea ::: ea There are no test evaluation activities for this component. There are no test evaluation activities for this component. ::: ::: ::: ::: ::: ::: ::: ::: ::: ::: ::: {#FCS_RBG.1 .comp} ::: {#FCS_RBG.1 .comp} #### FCS_RBG.1 Random Bit Generation (RBG) #### FCS_RBG.1 Random Bit Generation (RBG) ::: element ::: element ::: {#FCS_RBG.1.1 .reqid} ::: {#FCS_RBG.1.1 .reqid} [FCS_RBG.1.1](#FCS_RBG.1.1){.abbr} [FCS_RBG.1.1](#FCS_RBG.1.1){.abbr} ::: ::: ::: reqdesc ::: reqdesc The [TSF](#abbr_TSF) shall perform deterministic random bit generation The [TSF](#abbr_TSF) shall perform deterministic random bit generation services using \[**selection**: [DRBG Algorithm]{.selectable-content}\] services using \[**selection**: [DRBG Algorithm]{.selectable-content}\] in accordance with \[**selection**: [List of in accordance with \[**selection**: [List of standards]{.selectable-content}\] after initialization. standards]{.selectable-content}\] after initialization. [Table [16]{.counter}](#fcs-rbg-1-sels){.fcs-rbg-1-sels-ref [Table [16]{.counter}](#fcs-rbg-1-sels){.fcs-rbg-1-sels-ref onclick="showTarget('fcs-rbg-1-sels')"} provides the allowable choices onclick="showTarget('fcs-rbg-1-sels')"} provides the allowable choices for completion of the selection operations of [FCS_RBG.1](#FCS_RBG.1). for completion of the selection operations of [FCS_RBG.1](#FCS_RBG.1). Identifier DRBG Algorithm | Identifier DRBG Algorithm ------------ ---------------------------------------------------------------------- | ------------ ---------------------------------------------------------------------- HASH_DRBG Hash_DRBG with \[**selection**: [[SHA](#abbr_SHA)-384]{#_s_361 .select | HASH_DRBG Hash_DRBG with \[**selection**: [[SHA](#abbr_SHA)-384]{#fcs_rbg.1.1_1 HMAC_DRBG HMAC_DRBG with \[**selection**: [[SHA](#abbr_SHA)-384]{#_s_366 .select | HMAC_DRBG HMAC_DRBG with \[**selection**: [[SHA](#abbr_SHA)-384]{#fcs_rbg.1.1_5 CTR_DRBG CTR_DRBG with [AES](#abbr_AES)-CTR-256 | CTR_DRBG CTR_DRBG with [AES](#abbr_AES)-CTR-256 : [Table [16]{.counter}]{#fcs-rbg-1-sels .ctr myid="fcs-rbg-1-sels" : [Table [16]{.counter}]{#fcs-rbg-1-sels .ctr myid="fcs-rbg-1-sels" counter-type="ct-Table"}: Allowable choices for counter-type="ct-Table"}: Allowable choices for [FCS_RBG.1.1](#FCS_RBG.1.1) [FCS_RBG.1.1](#FCS_RBG.1.1) ::: ::: ::: ::: ::: element ::: element ::: {#FCS_RBG.1.2 .reqid} ::: {#FCS_RBG.1.2 .reqid} [FCS_RBG.1.2](#FCS_RBG.1.2){.abbr} [FCS_RBG.1.2](#FCS_RBG.1.2){.abbr} ::: ::: ::: reqdesc ::: reqdesc The [TSF](#abbr_TSF) shall use a \[**selection**: [[TSF](#abbr_TSF) The [TSF](#abbr_TSF) shall use a \[**selection**: [[TSF](#abbr_TSF) entropy source \[**assignment**: [name of entropy entropy source \[**assignment**: [name of entropy source]{.assignable-content}\]]{#internal-seed .selectable-content}, source]{.assignable-content}\]]{#internal-seed .selectable-content}, [**multiple independent [TSF](#abbr_TSF) entropy sources [**multiple independent [TSF](#abbr_TSF) entropy sources \[**assignment**: [names of entropy \[**assignment**: [names of entropy sources]{.assignable-content}\]**]{#internal-seeds .selectable-content}, sources]{.assignable-content}\]**]{#internal-seeds .selectable-content}, [[TSF](#abbr_TSF) interface for obtaining entropy]{#external-seed [[TSF](#abbr_TSF) interface for obtaining entropy]{#external-seed .selectable-content}\] for initialization and reseeding. .selectable-content}\] for initialization and reseeding. ::: appnote ::: appnote [Application Note: ]{.note-header}[ ]{.note} [Application Note: ]{.note-header}[ ]{.note} Following the approach in SP800-90B/C, noise sources are required to be Following the approach in SP800-90B/C, noise sources are required to be independent. Non-independent noise sources that share dependencies are independent. Non-independent noise sources that share dependencies are treated as a single raw source requiring a single entropy source treated as a single raw source requiring a single entropy source validation. If a [TOE](#abbr_TOE) has multiple dependent noise sources, validation. If a [TOE](#abbr_TOE) has multiple dependent noise sources, they should be grouped according to their dependencies for the purposes they should be grouped according to their dependencies for the purposes of these requirements. For the selection in this requirement, the of these requirements. For the selection in this requirement, the [ST](#abbr_ST) author selects \"[TSF](#abbr_TSF) entropy source\...\" if [ST](#abbr_ST) author selects \"[TSF](#abbr_TSF) entropy source\...\" if a single entropy source is used as input to the DRBG. The [ST](#abbr_ST) a single entropy source is used as input to the DRBG. The [ST](#abbr_ST) author selects \"multiple independent [TSF](#abbr_TSF) entropy author selects \"multiple independent [TSF](#abbr_TSF) entropy sources\...\" if a seed is formed from a combination of two or more sources\...\" if a seed is formed from a combination of two or more independent entropy sources within the [TOE](#abbr_TOE) boundary. If the independent entropy sources within the [TOE](#abbr_TOE) boundary. If the [TSF](#abbr_TSF) implements two or more separate DRBGs that are seeded [TSF](#abbr_TSF) implements two or more separate DRBGs that are seeded in separate manners, this [SFR](#abbr_SFR) should be iterated for each in separate manners, this [SFR](#abbr_SFR) should be iterated for each DRBG. If multiple distinct entropy sources exist such that each DRBG DRBG. If multiple distinct entropy sources exist such that each DRBG only uses one of them, then each iteration would select only uses one of them, then each iteration would select \"[TSF](#abbr_TSF) entropy source\...\"; \"multiple independent \"[TSF](#abbr_TSF) entropy source\...\"; \"multiple independent [TSF](#abbr_TSF) entropy sources\...\" is only selected if a single DRBG [TSF](#abbr_TSF) entropy sources\...\" is only selected if a single DRBG uses multiple independent entropy sources for its seed. The uses multiple independent entropy sources for its seed. The [ST](#abbr_ST) author selects \"[TSF](#abbr_TSF) interface for obtaining [ST](#abbr_ST) author selects \"[TSF](#abbr_TSF) interface for obtaining entropy\" if entropy source data is generated outside the entropy\" if entropy source data is generated outside the [TOE](#abbr_TOE) boundary. [TOE](#abbr_TOE) boundary. If \"[TSF](#abbr_TSF) entropy source\...\" is selected, If \"[TSF](#abbr_TSF) entropy source\...\" is selected, [FCS_RBG.3](#FCS_RBG.3) must be claimed. [FCS_RBG.3](#FCS_RBG.3) must be claimed. If \"multiple independent [TSF](#abbr_TSF) entropy sources\...\" is If \"multiple independent [TSF](#abbr_TSF) entropy sources\...\" is selected, [FCS_RBG.4](#FCS_RBG.4) and [FCS_RBG.5](#FCS_RBG.5) must be selected, [FCS_RBG.4](#FCS_RBG.4) and [FCS_RBG.5](#FCS_RBG.5) must be claimed. claimed. If \"[TSF](#abbr_TSF) interface for obtaining entropy\" is selected, If \"[TSF](#abbr_TSF) interface for obtaining entropy\" is selected, [FCS_RBG.2](#FCS_RBG.2) must be claimed. [FCS_RBG.2](#FCS_RBG.2) must be claimed. ::: ::: ::: ::: ::: ::: ::: element ::: element ::: {#FCS_RBG.1.3 .reqid} ::: {#FCS_RBG.1.3 .reqid} [FCS_RBG.1.3](#FCS_RBG.1.3){.abbr} [FCS_RBG.1.3](#FCS_RBG.1.3){.abbr} ::: ::: ::: reqdesc ::: reqdesc The [TSF](#abbr_TSF) shall update the DRBG state by \[**selection**: The [TSF](#abbr_TSF) shall update the DRBG state by \[**selection**: [reseeding]{#_s_376 .selectable-content}, [uninstantiating and | [reseeding]{#fcs_rbg.1.3_1 .selectable-content}, [uninstantiating and reinstantiating]{#_s_377 .selectable-content}\] using a \[**selection**: | reinstantiating]{#fcs_rbg.1.3_2 .selectable-content}\] using a [[TSF](#abbr_TSF) entropy source \[**assignment**: [name of entropy | \[**selection**: [[TSF](#abbr_TSF) entropy source \[**assignment**: source]{.assignable-content}\]]{#_s_378 .selectable-content}, | [name of entropy source]{.assignable-content}\]]{#fcs_rbg.1.3_3 [[TSF](#abbr_TSF) interface for obtaining entropy \[**assignment**: | .selectable-content}, [[TSF](#abbr_TSF) interface for obtaining entropy [name of the interface]{.assignable-content}\]]{#_s_379 | \[**assignment**: [name of the .selectable-content}\] in the following situations: \[**selection**: | interface]{.assignable-content}\]]{#fcs_rbg.1.3_5 .selectable-content}\] > in the following situations: \[**selection**: - [never]{#_s_380 .selectable-content} | - [never]{#fcs_rbg.1.3_7 .selectable-content} - [on demand]{#_s_381 .selectable-content} | - [on demand]{#fcs_rbg.1.3_8 .selectable-content} - [on the condition: \[**assignment**: - [on the condition: \[**assignment**: [condition]{.assignable-content}\]]{#_s_382 .selectable-content} | [condition]{.assignable-content}\]]{#fcs_rbg.1.3_9 - [after \[**assignment**: [time]{.assignable-content}\]]{#_s_383 < .selectable-content} .selectable-content} > - [after \[**assignment**: > [time]{.assignable-content}\]]{#fcs_rbg.1.3_11 .selectable-content} \] in accordance with \[**assignment**: [list of \] in accordance with \[**assignment**: [list of standards]{.assignable-content}\]. standards]{.assignable-content}\]. ::: ::: ::: ::: ::: {.activity_pane .hide} ::: {.activity_pane .hide} ::: activity_pane_header ::: activity_pane_header [[ Evaluation Activities [[ Evaluation Activities ]{.activity_pane_label}[]{.toggler}](#){onclick="toggle(this);return false;"} ]{.activity_pane_label}[]{.toggler}](#){onclick="toggle(this);return false;"} ::: ::: ::: activity_pane_body ::: activity_pane_body ::: element-activity-header ::: element-activity-header [FCS_RBG.1.1](#FCS_RBG.1.1) [FCS_RBG.1.1](#FCS_RBG.1.1) ::: ::: Documentation will be produced and the evaluator shall perform the Documentation will be produced and the evaluator shall perform the activities in accordance with and the Clarification to the Entropy activities in accordance with and the Clarification to the Entropy Documentation and Assessment Annex. Documentation and Assessment Annex. ::: eacategory ::: eacategory [TSS](#abbr_TSS) [TSS](#abbr_TSS) ::: ::: ::: ea ::: ea The evaluator shall verify that the [TSS](#abbr_TSS) identifies the The evaluator shall verify that the [TSS](#abbr_TSS) identifies the DRBGs used by the [TOE](#abbr_TOE). DRBGs used by the [TOE](#abbr_TOE). ::: ::: ::: eacategory ::: eacategory Guidance Guidance ::: ::: ::: ea ::: ea If the DRBG functionality is configurable, the evaluator shall verify If the DRBG functionality is configurable, the evaluator shall verify that the operational guidance includes instructions on how to configure that the operational guidance includes instructions on how to configure this behavior. this behavior. ::: ::: ::: eacategory ::: eacategory Tests Tests ::: ::: ::: ea ::: ea The evaluator shall perform the following tests: | The evaluator shall perform the following tests: The evaluator shall | perform 15 trials for the DRBG implementation. If the DRBG is The evaluator shall perform 15 trials for the DRBG implementation. If | configurable, the evaluator shall perform 15 trials for each the DRBG is configurable, the evaluator shall perform 15 trials for each < configuration. The evaluator shall also confirm that the operational configuration. The evaluator shall also confirm that the operational guidance contains appropriate instructions for configuring the DRBG guidance contains appropriate instructions for configuring the DRBG functionality. | functionality. If the DRBG has prediction resistance enabled, each trial | consists of: If the DRBG has prediction resistance enabled, each trial consists of: < 1. Instantiate the DRBG. 1. Instantiate the DRBG. 2. Generate a block of random bits. 2. Generate a block of random bits. 3. Generate a second block of random bits. 3. Generate a second block of random bits. 4. Uninstantiate. 4. Uninstantiate. The evaluator shall verify that the second block of random bits is the The evaluator shall verify that the second block of random bits is the expected value. The evaluator shall generate eight input values for each expected value. The evaluator shall generate eight input values for each trial. The first is a count (0 -- 14). The next three are entropy input, trial. The first is a count (0 -- 14). The next three are entropy input, nonce, and personalization string for the instantiate operation. The nonce, and personalization string for the instantiate operation. The next two are additional input and entropy input for the first call to next two are additional input and entropy input for the first call to generate. The final two are additional input and entropy input for the generate. The final two are additional input and entropy input for the second call to generate. These values are randomly generated. \"generate second call to generate. These values are randomly generated. \"generate one block of random bits\" means to generate random bits with number of one block of random bits\" means to generate random bits with number of returned bits equal to the Output Block Length (as defined in returned bits equal to the Output Block Length (as defined in [NIST](#abbr_NIST) SP 800-90A). | [NIST](#abbr_NIST) SP 800-90A). If the DRBG does not have prediction | resistance, each trial consists of: If the DRBG does not have prediction resistance, each trial consists of: < 1. Instantiate the DRBG. 1. Instantiate the DRBG. 2. Generate a block of random bits. 2. Generate a block of random bits. 3. Reseed. 3. Reseed. 4. Generate a second block of random bits. 4. Generate a second block of random bits. 5. Uninstantiate. 5. Uninstantiate. The evaluator shall verify that the second block of random bits is the The evaluator shall verify that the second block of random bits is the expected value. The evaluator shall generate eight input values for each expected value. The evaluator shall generate eight input values for each trial. The first is a count (0 -- 14). The next three are entropy input, trial. The first is a count (0 -- 14). The next three are entropy input, nonce, and personalization string for the instantiate operation. The nonce, and personalization string for the instantiate operation. The fifth value is additional input to the first call to generate. The sixth fifth value is additional input to the first call to generate. The sixth and seventh are additional input and entropy input to the call to and seventh are additional input and entropy input to the call to reseed. The final value is additional input to the second generate call. reseed. The final value is additional input to the second generate call. < The following list contains more information on some of the input values The following list contains more information on some of the input values to be generated/selected by the evaluator. to be generated/selected by the evaluator. - **Entropy input:** The length of the entropy input value must equal - **Entropy input:** The length of the entropy input value must equal the seed length. the seed length. - **Nonce:** If a nonce is supported (CTR_DRBG with no Derivation - **Nonce:** If a nonce is supported (CTR_DRBG with no Derivation Function does not use a nonce), the nonce bit length is one-half the Function does not use a nonce), the nonce bit length is one-half the seed length. seed length. - **Personalization string:** The length of the personalization string - **Personalization string:** The length of the personalization string must be less than or equal to seed length. If the implementation must be less than or equal to seed length. If the implementation only supports one personalization string length, then the same only supports one personalization string length, then the same length can be used for both values. If more than one string length length can be used for both values. If more than one string length is support, the evaluator shall use personalization strings of two is support, the evaluator shall use personalization strings of two different lengths. If the implementation does not use a different lengths. If the implementation does not use a personalization string, no value needs to be supplied. personalization string, no value needs to be supplied. - **Additional input:** The additional input bit lengths have the same - **Additional input:** The additional input bit lengths have the same defaults and restrictions as the personalization string lengths. defaults and restrictions as the personalization string lengths. ::: ::: ::: element-activity-header ::: element-activity-header [FCS_RBG.1.2](#FCS_RBG.1.2) [FCS_RBG.1.2](#FCS_RBG.1.2) ::: ::: There are no additional EAs for this element.\ There are no additional EAs for this element.\ \ \ ::: element-activity-header ::: element-activity-header [FCS_RBG.1.3](#FCS_RBG.1.3) [FCS_RBG.1.3](#FCS_RBG.1.3) ::: ::: ::: eacategory ::: eacategory [TSS](#abbr_TSS) [TSS](#abbr_TSS) ::: ::: ::: ea ::: ea The evaluator shall verify that the [TSS](#abbr_TSS) identifies how the The evaluator shall verify that the [TSS](#abbr_TSS) identifies how the DRBG state is updated, and the situations under which this may occur. DRBG state is updated, and the situations under which this may occur. ::: ::: ::: eacategory ::: eacategory Guidance Guidance ::: ::: ::: ea ::: ea If the [ST](#abbr_ST) claims that the DRBG state can be updated on If the [ST](#abbr_ST) claims that the DRBG state can be updated on demand, the evaluator shall verify that the operational guidance has demand, the evaluator shall verify that the operational guidance has instructions for how to perform this operation. instructions for how to perform this operation. ::: ::: ::: eacategory ::: eacategory Tests Tests ::: ::: There are no test activities for this element.\ There are no test activities for this element.\ \ \ ::: ::: ::: ::: ::: ::: ::: {#FCS_RBG.6 .comp} ::: {#FCS_RBG.6 .comp} #### FCS_RBG.6 Random Bit Generation Service #### FCS_RBG.6 Random Bit Generation Service ::: element ::: element ::: {#FCS_RBG.6.1 .reqid} ::: {#FCS_RBG.6.1 .reqid} [FCS_RBG.6.1](#FCS_RBG.6.1){.abbr} [FCS_RBG.6.1](#FCS_RBG.6.1){.abbr} ::: ::: ::: reqdesc ::: reqdesc The [TSF](#abbr_TSF) shall provide a \[*software*\] interface to make The [TSF](#abbr_TSF) shall provide a \[*software*\] interface to make the output, as specified in [FCS_RBG.1](#FCS_RBG.1) Random bit the output, as specified in [FCS_RBG.1](#FCS_RBG.1) Random bit generation ([RBG](#abbr_RBG)), available as a service to entities generation ([RBG](#abbr_RBG)), available as a service to entities outside of the [TOE](#abbr_TOE). outside of the [TOE](#abbr_TOE). ::: ::: ::: ::: ::: {.activity_pane .hide} ::: {.activity_pane .hide} ::: activity_pane_header ::: activity_pane_header [[ Evaluation Activities [[ Evaluation Activities ]{.activity_pane_label}[]{.toggler}](#){onclick="toggle(this);return false;"} ]{.activity_pane_label}[]{.toggler}](#){onclick="toggle(this);return false;"} ::: ::: ::: activity_pane_body ::: activity_pane_body ::: component-activity-header ::: component-activity-header [FCS_RBG.6](#FCS_RBG.6) [FCS_RBG.6](#FCS_RBG.6) ::: ::: ::: eacategory ::: eacategory [TSS](#abbr_TSS) [TSS](#abbr_TSS) ::: ::: ::: ea ::: ea ::: ea ::: ea The evaluator shall verify that the [TSS](#abbr_TSS) identifies the The evaluator shall verify that the [TSS](#abbr_TSS) identifies the interface that the [TSF](#abbr_TSF) makes available for calling interface that the [TSF](#abbr_TSF) makes available for calling applications to obtain DRBG output. applications to obtain DRBG output. ::: ::: ::: ::: ::: eacategory ::: eacategory Guidance Guidance ::: ::: ::: ea ::: ea ::: ea ::: ea The evaluator shall verify that the guidance documentation includes an The evaluator shall verify that the guidance documentation includes an [API](#abbr_API) specification for the random bit generation service [API](#abbr_API) specification for the random bit generation service such that it is clear how a calling application is able to obtain DRBG such that it is clear how a calling application is able to obtain DRBG output from the [TSF](#abbr_TSF). output from the [TSF](#abbr_TSF). ::: ::: ::: ::: ::: eacategory ::: eacategory Tests Tests ::: ::: ::: ea ::: ea ::: ea ::: ea The evaluator shall invoke the [API](#abbr_API) specified by the The evaluator shall invoke the [API](#abbr_API) specified by the guidance documentation to determine that the [TSF](#abbr_TSF) provides guidance documentation to determine that the [TSF](#abbr_TSF) provides DRBG output upon proper invocation of the [API](#abbr_API). DRBG output upon proper invocation of the [API](#abbr_API). ::: ::: ::: ::: ::: ::: ::: ::: ::: ::: ::: {#FCS_SRV_EXT.1 .comp} ::: {#FCS_SRV_EXT.1 .comp} #### FCS_SRV_EXT.1 Cryptographic Algorithm Services #### FCS_SRV_EXT.1 Cryptographic Algorithm Services ::: element ::: element ::: {#FCS_SRV_EXT.1.1 .reqid} ::: {#FCS_SRV_EXT.1.1 .reqid} [FCS_SRV_EXT.1.1](#FCS_SRV_EXT.1.1){.abbr} [FCS_SRV_EXT.1.1](#FCS_SRV_EXT.1.1){.abbr} ::: ::: ::: reqdesc ::: reqdesc The [TSF](#abbr_TSF) shall provide a mechanism for applications to The [TSF](#abbr_TSF) shall provide a mechanism for applications to request the [TSF](#abbr_TSF) to perform the following cryptographic request the [TSF](#abbr_TSF) to perform the following cryptographic operations: \[ operations: \[ - [AEAD](#abbr_AEAD): \[**assignment**: [one or more - [AEAD](#abbr_AEAD): \[**assignment**: [one or more [AEAD](#abbr_AEAD) algorithms]{.assignable-content}\] as claimed in [AEAD](#abbr_AEAD) algorithms]{.assignable-content}\] as claimed in [FCS_COP.1/AEAD](#FCS_COP.1/AEAD) [FCS_COP.1/AEAD](#FCS_COP.1/AEAD) - Hash: \[**assignment**: [one or more hash - Hash: \[**assignment**: [one or more hash algorithms]{.assignable-content}\] as claimed in algorithms]{.assignable-content}\] as claimed in [FCS_COP.1/Hash](#FCS_COP.1/Hash) [FCS_COP.1/Hash](#FCS_COP.1/Hash) - [HMAC](#abbr_HMAC): \[**assignment**: [one or more - [HMAC](#abbr_HMAC): \[**assignment**: [one or more [HMAC](#abbr_HMAC) algorithms]{.assignable-content}\] as claimed in [HMAC](#abbr_HMAC) algorithms]{.assignable-content}\] as claimed in [FCS_COP.1/KeyedHash](#FCS_COP.1/KeyedHash) [FCS_COP.1/KeyedHash](#FCS_COP.1/KeyedHash) - Digital signature:\[**assignment**: [one or more digital signature | - Digital signature: \[**assignment**: [one or more digital signature generation or verification algorithms]{.assignable-content}\] as generation or verification algorithms]{.assignable-content}\] as claimed in [FCS_COP.1/SigGen](#FCS_COP.1/SigGen) or claimed in [FCS_COP.1/SigGen](#FCS_COP.1/SigGen) or [FCS_COP.1/SigVer](#FCS_COP.1/SigVer) [FCS_COP.1/SigVer](#FCS_COP.1/SigVer) and \[**selection**: and \[**selection**: - [Asymmetric key generation: \[**assignment**: [one or more key - [Asymmetric key generation: \[**assignment**: [one or more key generation algorithms]{.assignable-content}\] as claimed in generation algorithms]{.assignable-content}\] as claimed in [FCS_CKM.1/AKG](#FCS_CKM.1/AKG)]{#_s_390 .selectable-content} | [FCS_CKM.1/AKG](#FCS_CKM.1/AKG)]{#fcs_srv_ext.1.1_5 > .selectable-content} - [Key agreement: \[**assignment**: [one or more key agreement - [Key agreement: \[**assignment**: [one or more key agreement algorithms]{.assignable-content}\] as claimed in algorithms]{.assignable-content}\] as claimed in [FCS_CKM_EXT.7/UNLOCKED](#FCS_CKM_EXT.7/UNLOCKED)]{#_s_391 | [FCS_CKM_EXT.7/UNLOCKED](#FCS_CKM_EXT.7/UNLOCKED)]{#fcs_srv_ext.1.1_7 .selectable-content} .selectable-content} - [Key encapsulation: \[**assignment**: [one or more key encapsulation - [Key encapsulation: \[**assignment**: [one or more key encapsulation algorithms]{.assignable-content}\] as claimed in algorithms]{.assignable-content}\] as claimed in [FCS_COP.1/KeyEncap](#FCS_COP.1/KeyEncap)]{#_s_392 | [FCS_COP.1/KeyEncap](#FCS_COP.1/KeyEncap)]{#fcs_srv_ext.1.1_9 .selectable-content} .selectable-content} - [Key wrapping: \[**assignment**: [one or more key wrap - [Key wrapping: \[**assignment**: [one or more key wrap algorithms]{.assignable-content}\] as claimed in algorithms]{.assignable-content}\] as claimed in [FCS_COP.1/KeyWrap](#FCS_COP.1/KeyWrap)]{#_s_393 | [FCS_COP.1/KeyWrap](#FCS_COP.1/KeyWrap)]{#fcs_srv_ext.1.1_11 .selectable-content} .selectable-content} - [Symmetric encryption: \[**assignment**: [one or more symmetric - [Symmetric encryption: \[**assignment**: [one or more symmetric encryption algorithms]{.assignable-content}\] as claimed in encryption algorithms]{.assignable-content}\] as claimed in [FCS_COP.1/SKC](#FCS_COP.1/SKC)]{#_s_394 .selectable-content} | [FCS_COP.1/SKC](#FCS_COP.1/SKC)]{#fcs_srv_ext.1.1_13 - [no other cryptographic operations]{#_s_395 .selectable-content} | .selectable-content} > - [no other cryptographic operations]{#fcs_srv_ext.1.1_15 > .selectable-content} \]\]. \]\]. ::: appnote ::: appnote [Application Note: ]{.note-header}[ ]{.note} [Application Note: ]{.note-header}[ ]{.note} A conformant [TOE](#abbr_TOE) is required to provide to provide an A conformant [TOE](#abbr_TOE) is required to provide to provide an interface for third-party applications to invoke [AEAD](#abbr_AEAD), interface for third-party applications to invoke [AEAD](#abbr_AEAD), hash, [HMAC](#abbr_HMAC), and digital signature functions. The functions hash, [HMAC](#abbr_HMAC), and digital signature functions. The functions made available by the [TSF](#abbr_TSF) may be a subset of those made available by the [TSF](#abbr_TSF) may be a subset of those functions claimed; for example, if the [TOE](#abbr_TOE) claims both functions claimed; for example, if the [TOE](#abbr_TOE) claims both [CCM](#abbr_CCM) and [GCM](#abbr_GCM) modes in [CCM](#abbr_CCM) and [GCM](#abbr_GCM) modes in [FCS_COP.1/AEAD](#FCS_COP.1/AEAD) but [CCM](#abbr_CCM) is only [FCS_COP.1/AEAD](#FCS_COP.1/AEAD) but [CCM](#abbr_CCM) is only implemented in hardware for the purpose of Bluetooth, it is sufficient implemented in hardware for the purpose of Bluetooth, it is sufficient to offer only [GCM](#abbr_GCM). The [TSF](#abbr_TSF) is not required to to offer only [GCM](#abbr_GCM). The [TSF](#abbr_TSF) is not required to provide algorithm services for the selectable algorithms, but they provide algorithm services for the selectable algorithms, but they should be included within the [TOE](#abbr_TOE) boundary if supported. should be included within the [TOE](#abbr_TOE) boundary if supported. The [TSF](#abbr_TSF) must also provide a service for generation of The [TSF](#abbr_TSF) must also provide a service for generation of symmetric keys as defined in FCS_CKM.1/SKC. However, since this symmetric keys as defined in FCS_CKM.1/SKC. However, since this [PP](#abbr_PP) specifies \"direct generation from a random bit [PP](#abbr_PP) specifies \"direct generation from a random bit generator\" as the only mechanism for doing this, it is not necessary to generator\" as the only mechanism for doing this, it is not necessary to list that service here because [FCS_RBG.6](#FCS_RBG.6) already requires list that service here because [FCS_RBG.6](#FCS_RBG.6) already requires the [TSF](#abbr_TSF) to make the output of its DRBG available to third the [TSF](#abbr_TSF) to make the output of its DRBG available to third parties. There is no extra step to generate a symmetric key from random parties. There is no extra step to generate a symmetric key from random bits; the random bits themselves are the key. bits; the random bits themselves are the key. ::: ::: ::: ::: ::: ::: ::: {.activity_pane .hide} ::: {.activity_pane .hide} ::: activity_pane_header ::: activity_pane_header [[ Evaluation Activities [[ Evaluation Activities ]{.activity_pane_label}[]{.toggler}](#){onclick="toggle(this);return false;"} ]{.activity_pane_label}[]{.toggler}](#){onclick="toggle(this);return false;"} ::: ::: ::: activity_pane_body ::: activity_pane_body ::: component-activity-header ::: component-activity-header [FCS_SRV_EXT.1](#FCS_SRV_EXT.1) [FCS_SRV_EXT.1](#FCS_SRV_EXT.1) ::: ::: ::: eacategory ::: eacategory [TSS](#abbr_TSS) [TSS](#abbr_TSS) ::: ::: ::: ea ::: ea ::: ea ::: ea The evaluation shall verify that the [TSS](#abbr_TSS) (or other product The evaluation shall verify that the [TSS](#abbr_TSS) (or other product documentation) includes the security functions (cryptographic documentation) includes the security functions (cryptographic algorithms) described in these requirements.\ algorithms) described in these requirements.\ \ \ ::: ::: ::: ::: ::: eacategory ::: eacategory Guidance Guidance ::: ::: ::: ea ::: ea ::: ea ::: ea There are no guidance evaluation activities for this component.\ There are no guidance evaluation activities for this component.\ \ \ ::: ::: ::: ::: ::: eacategory ::: eacategory Tests Tests ::: ::: ::: ea ::: ea ::: ea ::: ea The evaluator shall write, or the developer shall provide access to, an The evaluator shall write, or the developer shall provide access to, an application that requests cryptographic operations by the application that requests cryptographic operations by the [TSF](#abbr_TSF). The evaluator shall verify that the results from the [TSF](#abbr_TSF). The evaluator shall verify that the results from the operation match the expected results according to the [API](#abbr_API) operation match the expected results according to the [API](#abbr_API) documentation. This application may be used to assist in verifying the documentation. This application may be used to assist in verifying the cryptographic operation Evaluation Activities for the other algorithm cryptographic operation Evaluation Activities for the other algorithm services requirements. services requirements. ::: ::: ::: ::: ::: ::: ::: ::: ::: ::: ::: {#FCS_STG_EXT.1 .comp} ::: {#FCS_STG_EXT.1 .comp} #### FCS_STG_EXT.1 Cryptographic Key Storage #### FCS_STG_EXT.1 Cryptographic Key Storage ::: element ::: element ::: {#FCS_STG_EXT.1.1 .reqid} ::: {#FCS_STG_EXT.1.1 .reqid} [FCS_STG_EXT.1.1](#FCS_STG_EXT.1.1){.abbr} [FCS_STG_EXT.1.1](#FCS_STG_EXT.1.1){.abbr} ::: ::: ::: reqdesc ::: reqdesc The [TSF](#abbr_TSF) shall provide \[**selection**: [mutable The [TSF](#abbr_TSF) shall provide \[**selection**: [mutable hardware]{#_s_401 .selectable-content}, | hardware]{#fcs_stg_ext.1.1_1 .selectable-content}, [software-based]{#s-software-store .selectable-content}\] secure key [software-based]{#s-software-store .selectable-content}\] secure key storage for asymmetric private keys and \[**selection**: [symmetric storage for asymmetric private keys and \[**selection**: [symmetric keys]{#_s_403 .selectable-content}, [persistent secrets]{#_s_404 | keys]{#fcs_stg_ext.1.1_2 .selectable-content}, [persistent .selectable-content}, [no other keys]{#_s_405 .selectable-content}\]. | secrets]{#fcs_stg_ext.1.1_3 .selectable-content}, [no other > keys]{#fcs_stg_ext.1.1_4 .selectable-content}\]. ::: appnote ::: appnote [Application Note: ]{.note-header}[A hardware keystore can be exposed to | [Application Note: ]{.note-header}[ A hardware keystore can be exposed the [TSF](#abbr_TSF) through a variety of interfaces, including embedded | to the [TSF](#abbr_TSF) through a variety of interfaces, including on the motherboard, [USB](#abbr_USB), microSD, and Bluetooth.\ | embedded on the motherboard, [USB](#abbr_USB), microSD, and Bluetooth.\ \ \ Immutable hardware is considered outside of this requirement and will be Immutable hardware is considered outside of this requirement and will be covered elsewhere.\ covered elsewhere.\ \ \ If the secure key storage is implemented in software that is protected If the secure key storage is implemented in software that is protected as required by [FCS_STG_EXT.2](#FCS_STG_EXT.2), the [ST](#abbr_ST) as required by [FCS_STG_EXT.2](#FCS_STG_EXT.2), the [ST](#abbr_ST) author must select [software-based](#s-software-store). If author must select [software-based](#s-software-store). If [software-based](#s-software-store) is selected, the [ST](#abbr_ST) [software-based](#s-software-store) is selected, the [ST](#abbr_ST) author must select [all software-based key author must select [all software-based key storage](#s-all-software-key-store) in storage](#s-all-software-key-store) in [FCS_STG_EXT.2.1](#FCS_STG_EXT.2.1). Support for secure key storage for [FCS_STG_EXT.2.1](#FCS_STG_EXT.2.1). Support for secure key storage for all symmetric keys and persistent secrets will be required in future all symmetric keys and persistent secrets will be required in future revisions. ]{.note} revisions. ]{.note} ::: ::: ::: ::: ::: ::: ::: element ::: element ::: {#FCS_STG_EXT.1.2 .reqid} ::: {#FCS_STG_EXT.1.2 .reqid} [FCS_STG_EXT.1.2](#FCS_STG_EXT.1.2){.abbr} [FCS_STG_EXT.1.2](#FCS_STG_EXT.1.2){.abbr} ::: ::: ::: reqdesc ::: reqdesc The [TSF](#abbr_TSF) shall be capable of importing keys or secrets into The [TSF](#abbr_TSF) shall be capable of importing keys or secrets into the secure key storage upon request of \[**selection**: [the the secure key storage upon request of \[**selection**: [the user]{#import-user .selectable-content}, [the user]{#import-user .selectable-content}, [the administrator]{#s-import-admin .selectable-content}\] and administrator]{#s-import-admin .selectable-content}\] and \[**selection**: [applications running on the [TSF](#abbr_TSF)]{#_s_408 | \[**selection**: [applications running on the .selectable-content}, [no other subjects]{#_s_409 | [TSF](#abbr_TSF)]{#fcs_stg_ext.1.2_1 .selectable-content}, [no other .selectable-content}\]. | subjects]{#fcs_stg_ext.1.2_2 .selectable-content}\]. ::: appnote ::: appnote [Application Note: ]{.note-header}[ If the [ST](#abbr_ST) selects only [Application Note: ]{.note-header}[ If the [ST](#abbr_ST) selects only [the user](#import-user), the [ST](#abbr_ST) author must select function [the user](#import-user), the [ST](#abbr_ST) author must select function [9](#mf-keyStorage) in [FMT_MOF_EXT.1.1](#FMT_MOF_EXT.1.1). ]{.note} [9](#mf-keyStorage) in [FMT_MOF_EXT.1.1](#FMT_MOF_EXT.1.1). ]{.note} ::: ::: ::: ::: ::: ::: ::: element ::: element ::: {#FCS_STG_EXT.1.3 .reqid} ::: {#FCS_STG_EXT.1.3 .reqid} [FCS_STG_EXT.1.3](#FCS_STG_EXT.1.3){.abbr} [FCS_STG_EXT.1.3](#FCS_STG_EXT.1.3){.abbr} ::: ::: ::: reqdesc ::: reqdesc The [TSF](#abbr_TSF) shall be capable of destroying keys or secrets in The [TSF](#abbr_TSF) shall be capable of destroying keys or secrets in the secure key storage upon request of \[**selection**: [the the secure key storage upon request of \[**selection**: [the user]{#_s_410 .selectable-content}, [the administrator]{#_s_411 | user]{#fcs_stg_ext.1.3_1 .selectable-content}, [the .selectable-content}\]. | administrator]{#fcs_stg_ext.1.3_2 .selectable-content}\]. ::: appnote ::: appnote [Application Note: ]{.note-header}[If the [ST](#abbr_ST) selects [the [Application Note: ]{.note-header}[If the [ST](#abbr_ST) selects [the user](#import-user), the [ST](#abbr_ST) author must select function user](#import-user), the [ST](#abbr_ST) author must select function [10](#mf-keyWipe) in [FMT_MOF_EXT.1.1](#FMT_MOF_EXT.1.1). ]{.note} [10](#mf-keyWipe) in [FMT_MOF_EXT.1.1](#FMT_MOF_EXT.1.1). ]{.note} ::: ::: ::: ::: ::: ::: ::: element ::: element ::: {#FCS_STG_EXT.1.4 .reqid} ::: {#FCS_STG_EXT.1.4 .reqid} [FCS_STG_EXT.1.4](#FCS_STG_EXT.1.4){.abbr} [FCS_STG_EXT.1.4](#FCS_STG_EXT.1.4){.abbr} ::: ::: ::: reqdesc ::: reqdesc The [TSF](#abbr_TSF) shall have the capability to allow only the The [TSF](#abbr_TSF) shall have the capability to allow only the application that imported the key or secret the use of the key or application that imported the key or secret the use of the key or secret. Exceptions may only be explicitly authorized by \[**selection**: secret. Exceptions may only be explicitly authorized by \[**selection**: [the user]{#_s_412 .selectable-content}, [the administrator]{#_s_413 | [the user]{#fcs_stg_ext.1.4_1 .selectable-content}, [the .selectable-content}, [a common application developer]{#_s_414 | administrator]{#fcs_stg_ext.1.4_2 .selectable-content}, [a common .selectable-content}\]. | application developer]{#fcs_stg_ext.1.4_3 .selectable-content}\]. ::: appnote ::: appnote [Application Note: ]{.note-header}[If the [ST](#abbr_ST) selects [the | [Application Note: ]{.note-header}[ If the [ST](#abbr_ST) selects [the user](#import-user) or [the administrator](#s-import-admin), the user](#import-user) or [the administrator](#s-import-admin), the [ST](#abbr_ST) author must also select [34](#mf-sharedKeys) in [ST](#abbr_ST) author must also select [34](#mf-sharedKeys) in [FMT_SMF_EXT.1.1](#FMT_SMF_EXT.1.1). If the [ST](#abbr_ST) selects [the [FMT_SMF_EXT.1.1](#FMT_SMF_EXT.1.1). If the [ST](#abbr_ST) selects [the user](#import-user), the [ST](#abbr_ST) author must select function user](#import-user), the [ST](#abbr_ST) author must select function [34](#mf-sharedKeys) in [FMT_MOF_EXT.1.1](#FMT_MOF_EXT.1.1). ]{.note} [34](#mf-sharedKeys) in [FMT_MOF_EXT.1.1](#FMT_MOF_EXT.1.1). ]{.note} ::: ::: ::: ::: ::: ::: ::: element ::: element ::: {#FCS_STG_EXT.1.5 .reqid} ::: {#FCS_STG_EXT.1.5 .reqid} [FCS_STG_EXT.1.5](#FCS_STG_EXT.1.5){.abbr} [FCS_STG_EXT.1.5](#FCS_STG_EXT.1.5){.abbr} ::: ::: ::: reqdesc ::: reqdesc The [TSF](#abbr_TSF) shall allow only the application that imported the The [TSF](#abbr_TSF) shall allow only the application that imported the key or secret to request that the key or secret be destroyed. Exceptions key or secret to request that the key or secret be destroyed. Exceptions may only be explicitly authorized by \[**selection**: [the may only be explicitly authorized by \[**selection**: [the user]{#s-killkey-user .selectable-content}, [the user]{#s-killkey-user .selectable-content}, [the administrator]{#s-killkey-admin .selectable-content}, [a common administrator]{#s-killkey-admin .selectable-content}, [a common application developer]{#_s_417 .selectable-content}\]. | application developer]{#fcs_stg_ext.1.5_1 .selectable-content}\]. ::: appnote ::: appnote [Application Note: ]{.note-header}[If the [ST](#abbr_ST) selects [the | [Application Note: ]{.note-header}[ If the [ST](#abbr_ST) selects [the user](#s-killkey-user) or [the administrator](#s-killkey-admin), the user](#s-killkey-user) or [the administrator](#s-killkey-admin), the [ST](#abbr_ST) author must also select function [35](#mf-keyWipeRules) [ST](#abbr_ST) author must also select function [35](#mf-keyWipeRules) in [FMT_SMF_EXT.1.1](#FMT_SMF_EXT.1.1). If the [ST](#abbr_ST) selects in [FMT_SMF_EXT.1.1](#FMT_SMF_EXT.1.1). If the [ST](#abbr_ST) selects only [the user](#s-killkey-user), the [ST](#abbr_ST) author must select only [the user](#s-killkey-user), the [ST](#abbr_ST) author must select function [35](#mf-keyWipeRules) in [FMT_MOF_EXT.1.1](#FMT_MOF_EXT.1.1). function [35](#mf-keyWipeRules) in [FMT_MOF_EXT.1.1](#FMT_MOF_EXT.1.1). ]{.note} ]{.note} ::: ::: ::: ::: ::: ::: ::: {.activity_pane .hide} ::: {.activity_pane .hide} ::: activity_pane_header ::: activity_pane_header [[ Evaluation Activities [[ Evaluation Activities ]{.activity_pane_label}[]{.toggler}](#){onclick="toggle(this);return false;"} ]{.activity_pane_label}[]{.toggler}](#){onclick="toggle(this);return false;"} ::: ::: ::: activity_pane_body ::: activity_pane_body ::: component-activity-header ::: component-activity-header [FCS_STG_EXT.1](#FCS_STG_EXT.1) [FCS_STG_EXT.1](#FCS_STG_EXT.1) ::: ::: ::: eacategory ::: eacategory [TSS](#abbr_TSS) [TSS](#abbr_TSS) ::: ::: ::: ea ::: ea ::: ea ::: ea The evaluator shall verify that the [API](#abbr_API) documentation The evaluator shall verify that the [API](#abbr_API) documentation provided in the [TSS](#abbr_TSS) (or other documentation) includes the provided in the [TSS](#abbr_TSS) (or other documentation) includes the security functions (import, use, and destruction) described in these security functions (import, use, and destruction) described in these requirements. The [API](#abbr_API) documentation shall include the requirements. The [API](#abbr_API) documentation shall include the method by which applications restrict access to their keys or secrets in method by which applications restrict access to their keys or secrets in order to meet [FCS_STG_EXT.1.4](#FCS_STG_EXT.1.4). order to meet [FCS_STG_EXT.1.4](#FCS_STG_EXT.1.4). The evaluator shall review the [TSS](#abbr_TSS) to determine that the The evaluator shall review the [TSS](#abbr_TSS) to determine that the [TOE](#abbr_TOE) implements the required secure key storage. The [TOE](#abbr_TOE) implements the required secure key storage. The evaluator shall ensure that the [TSS](#abbr_TSS) contains a description evaluator shall ensure that the [TSS](#abbr_TSS) contains a description of the key storage mechanism that justifies the selection of \"mutable of the key storage mechanism that justifies the selection of \"mutable hardware\" or \"software-based\".\ hardware\" or \"software-based\".\ \ \ ::: ::: ::: ::: ::: eacategory ::: eacategory Guidance Guidance ::: ::: ::: ea ::: ea ::: ea ::: ea The evaluator shall review the AGD guidance to determine that it The evaluator shall review the AGD guidance to determine that it describes the steps needed to import or destroy keys or secrets.\ describes the steps needed to import or destroy keys or secrets.\ \ \ ::: ::: ::: ::: ::: eacategory ::: eacategory Tests Tests ::: ::: ::: ea ::: ea ::: ea ::: ea The evaluator shall test the functionality of each security function: The evaluator shall test the functionality of each security function: []{.testlist-} []{.testlist-} - [Test FCS_STG_EXT.1:1](#_t_15){#_t_15 .defined}: The evaluator shall - [Test FCS_STG_EXT.1:1](#_t_15){#_t_15 .defined}: The evaluator shall import keys or secrets of each supported type according to the AGD import keys or secrets of each supported type according to the AGD guidance. The evaluator shall write, or the developer shall provide guidance. The evaluator shall write, or the developer shall provide access to, an application that generates a key or secret of each access to, an application that generates a key or secret of each supported type and calls the import functions. The evaluator shall supported type and calls the import functions. The evaluator shall verify that no errors occur during import. verify that no errors occur during import. - [Test FCS_STG_EXT.1:2](#_t_16){#_t_16 .defined}: The evaluator shall - [Test FCS_STG_EXT.1:2](#_t_16){#_t_16 .defined}: The evaluator shall write, or the developer shall provide access to, an application that write, or the developer shall provide access to, an application that uses an imported key or secret:\ uses an imported key or secret:\ - For [RSA](#abbr_RSA), the secret shall be used to sign data. - For [RSA](#abbr_RSA), the secret shall be used to sign data. - For [ECDSA](#abbr_ECDSA), the secret shall be used to sign data. - For [ECDSA](#abbr_ECDSA), the secret shall be used to sign data. \ \ In the future additional types will be required to be tested:\ In the future additional types will be required to be tested:\ - For symmetric algorithms, the secret shall be used to encrypt - For symmetric algorithms, the secret shall be used to encrypt data. data. - For persistent secrets, the secret shall be compared to the - For persistent secrets, the secret shall be compared to the imported secret. imported secret. \ \ The evaluator shall repeat this test with the application-imported The evaluator shall repeat this test with the application-imported keys or secrets and a different application's imported keys or keys or secrets and a different application's imported keys or secrets. The evaluator shall verify that the [TOE](#abbr_TOE) secrets. The evaluator shall verify that the [TOE](#abbr_TOE) requires approval before allowing the application to use the key or requires approval before allowing the application to use the key or secret imported by the user or by a different application:\ secret imported by the user or by a different application:\ - The evaluator shall deny the approvals to verify that the - The evaluator shall deny the approvals to verify that the application is not able to use the key or secret as described. application is not able to use the key or secret as described. - The evaluator shall repeat the test, allowing the approvals to - The evaluator shall repeat the test, allowing the approvals to verify that the application is able to use the key or secret as verify that the application is able to use the key or secret as described. described. \ \ If the [ST](#abbr_ST) author has selected \"common application If the [ST](#abbr_ST) author has selected \"common application developer\", this test is performed by either using applications developer\", this test is performed by either using applications from different developers or appropriately (according to from different developers or appropriately (according to [API](#abbr_API) documentation) not authorizing sharing. [API](#abbr_API) documentation) not authorizing sharing. - [Test FCS_STG_EXT.1:3](#_t_17){#_t_17 .defined}: The evaluator shall - [Test FCS_STG_EXT.1:3](#_t_17){#_t_17 .defined}: The evaluator shall destroy keys or secrets of each supported type according to the AGD destroy keys or secrets of each supported type according to the AGD guidance. The evaluator shall write, or the developer shall provide guidance. The evaluator shall write, or the developer shall provide access to, an application that destroys an imported key or secret.\ access to, an application that destroys an imported key or secret.\ \ \ The evaluator shall repeat this test with the application-imported The evaluator shall repeat this test with the application-imported keys or secrets and a different application's imported keys or keys or secrets and a different application's imported keys or secrets. The evaluator shall verify that the [TOE](#abbr_TOE) secrets. The evaluator shall verify that the [TOE](#abbr_TOE) requires approval before allowing the application to destroy the key requires approval before allowing the application to destroy the key or secret imported by the administrator or by a different or secret imported by the administrator or by a different application:\ application:\ \ \ - The evaluator shall deny the approvals and verify that the - The evaluator shall deny the approvals and verify that the application is still able to use the key or secret as described. application is still able to use the key or secret as described. - The evaluator shall repeat the test, allowing the approvals and - The evaluator shall repeat the test, allowing the approvals and verifying that the application is no longer able to use the key verifying that the application is no longer able to use the key or secret as described. or secret as described. \ \ If the [ST](#abbr_ST) author has selected \"common application If the [ST](#abbr_ST) author has selected \"common application developer\", this test is performed by either using applications developer\", this test is performed by either using applications from different developers or appropriately (according to from different developers or appropriately (according to [API](#abbr_API) documentation) not authorizing sharing. [API](#abbr_API) documentation) not authorizing sharing. ::: ::: ::: ::: ::: ::: ::: ::: ::: ::: ::: {#FCS_STG_EXT.2 .comp} ::: {#FCS_STG_EXT.2 .comp} #### FCS_STG_EXT.2 Encrypted Cryptographic Key Storage #### FCS_STG_EXT.2 Encrypted Cryptographic Key Storage ::: element ::: element ::: {#FCS_STG_EXT.2.1 .reqid} ::: {#FCS_STG_EXT.2.1 .reqid} [FCS_STG_EXT.2.1](#FCS_STG_EXT.2.1){.abbr} [FCS_STG_EXT.2.1](#FCS_STG_EXT.2.1){.abbr} ::: ::: ::: reqdesc ::: reqdesc The [TSF](#abbr_TSF) shall encrypt all [DEKs](#abbr_DEK), KEKs, | The [TSF](#abbr_TSF) shall encrypt all DEKs, KEKs, \[**assignment**: \[**assignment**: [any long-term trusted channel key | [any long-term trusted channel key material]{.assignable-content}\] and material]{.assignable-content}\] and \[**selection**: [all | \[**selection**: [all software-based key software-based key storage]{#s-all-software-key-store | storage]{#s-all-software-key-store .selectable-content}, [no other .selectable-content}, [no other keys]{#_s_421 .selectable-content}\] by | keys]{#fcs_stg_ext.2.1_2 .selectable-content}\] by KEKs that are KEKs that are \[**selection**: | \[**selection**: - [Protected by the [REK](#abbr_REK) with \[**selection**: ]{#_s_422 | - [Protected by the [REK](#abbr_REK) with \[**selection**: .selectable-content} | ]{#fcs_stg_ext.2.1_3 .selectable-content} - [encryption by a [REK](#abbr_REK)]{#_s_423 .selectable-content} | - [encryption by a [REK](#abbr_REK)]{#fcs_stg_ext.2.1_4 > .selectable-content} - [encryption by a [KEK](#abbr_KEK) chaining from a - [encryption by a [KEK](#abbr_KEK) chaining from a [REK](#abbr_REK)]{#_s_424 .selectable-content} | [REK](#abbr_REK)]{#fcs_stg_ext.2.1_5 .selectable-content} - [encryption by a [KEK](#abbr_KEK) that is derived from a - [encryption by a [KEK](#abbr_KEK) that is derived from a [REK](#abbr_REK)]{#_s_425 .selectable-content} | [REK](#abbr_REK)]{#fcs_stg_ext.2.1_6 .selectable-content} \] \] - [Protected by the [REK](#abbr_REK) and the password with - [Protected by the [REK](#abbr_REK) and the password with \[**selection**: ]{#_s_426 .selectable-content} | \[**selection**: ]{#fcs_stg_ext.2.1_7 .selectable-content} - [encryption by a [REK](#abbr_REK) and the password-derived - [encryption by a [REK](#abbr_REK) and the password-derived [KEK](#abbr_KEK)]{#_s_427 .selectable-content} | [KEK](#abbr_KEK)]{#fcs_stg_ext.2.1_8 .selectable-content} - [encryption by a [KEK](#abbr_KEK) chaining to a [REK](#abbr_REK) - [encryption by a [KEK](#abbr_KEK) chaining to a [REK](#abbr_REK) and the password-derived or biometric-unlocked and the password-derived or biometric-unlocked [KEK](#abbr_KEK)]{#_s_428 .selectable-content} | [KEK](#abbr_KEK)]{#fcs_stg_ext.2.1_9 .selectable-content} - [encryption by a [KEK](#abbr_KEK) that is derived from a - [encryption by a [KEK](#abbr_KEK) that is derived from a [REK](#abbr_REK) and the password-derived or biometric-unlocked [REK](#abbr_REK) and the password-derived or biometric-unlocked [KEK](#abbr_KEK)]{#_s_429 .selectable-content} | [KEK](#abbr_KEK)]{#fcs_stg_ext.2.1_10 .selectable-content} \] \] \]. \]. ::: appnote ::: appnote [Application Note: ]{.note-header}[The [ST](#abbr_ST) author must select | [Application Note: ]{.note-header}[ The [ST](#abbr_ST) author must [all software-based key storage](#s-all-software-key-store) if | select [all software-based key storage](#s-all-software-key-store) if [software-based](#s-software-store) is selected in [software-based](#s-software-store) is selected in [FCS_STG_EXT.1.1](#FCS_STG_EXT.1.1). If the [ST](#abbr_ST) author [FCS_STG_EXT.1.1](#FCS_STG_EXT.1.1). If the [ST](#abbr_ST) author selects [](#mutable_hardware){.dynref format=""} in selects [](#mutable_hardware){.dynref format=""} in [FCS_STG_EXT.1.1](#FCS_STG_EXT.1.1), the secure key storage is not [FCS_STG_EXT.1.1](#FCS_STG_EXT.1.1), the secure key storage is not subject to this requirement. [REKs](#abbr_REK) are not subject to this | subject to this requirement. REKs are not subject to this requirement.\ requirement.\ < \ \ A [REK](#abbr_REK) and the password-derived [KEK](#abbr_KEK) may be A [REK](#abbr_REK) and the password-derived [KEK](#abbr_KEK) may be combined to form a combined [KEK](#abbr_KEK) (as described in combined to form a combined [KEK](#abbr_KEK) (as described in [FCS_CKM_EXT.3](#FCS_CKM_EXT.3)) in order to meet this requirement.\ [FCS_CKM_EXT.3](#FCS_CKM_EXT.3)) in order to meet this requirement.\ \ \ Software-based key storage must be protected by the password or Software-based key storage must be protected by the password or biometric and [REK](#abbr_REK).\ biometric and [REK](#abbr_REK).\ \ \ All keys must ultimately be protected by a [REK](#abbr_REK). In All keys must ultimately be protected by a [REK](#abbr_REK). In particular, [Figure [3]{.counter}](#Keys){.Keys-ref particular, [Figure [3]{.counter}](#Keys){.Keys-ref onclick="showTarget('Keys')"} has KEKs protected according to these onclick="showTarget('Keys')"} has KEKs protected according to these requirements: DEK_1 meets the \"encryption by a [REK](#abbr_REK) and the requirements: DEK_1 meets the \"encryption by a [REK](#abbr_REK) and the password-derived [KEK](#abbr_KEK)\" case and would be appropriate for password-derived [KEK](#abbr_KEK)\" case and would be appropriate for sensitive data, DEK_2 meets the \"encryption by a [KEK](#abbr_KEK) sensitive data, DEK_2 meets the \"encryption by a [KEK](#abbr_KEK) chaining from a [REK](#abbr_REK)\" case and would not be appropriate for chaining from a [REK](#abbr_REK)\" case and would not be appropriate for sensitive data, K_1 meets the \"encryption by a [REK](#abbr_REK)\" case sensitive data, K_1 meets the \"encryption by a [REK](#abbr_REK)\" case and is not considered a sensitive key, and K_2 meets the \"encryption by and is not considered a sensitive key, and K_2 meets the \"encryption by a [KEK](#abbr_KEK) chaining to a [REK](#abbr_REK) and the a [KEK](#abbr_KEK) chaining to a [REK](#abbr_REK) and the password-derived or biometric-unlocked [KEK](#abbr_KEK)\" case and is password-derived or biometric-unlocked [KEK](#abbr_KEK)\" case and is considered a sensitive key.\ considered a sensitive key.\ \ \ Long-term trusted channel key material includes Wi-Fi | Long-term trusted channel key material includes Wi-Fi (PSKs), ([PSKs](#abbr_PSK)), [IPsec](#abbr_IPsec) ([PSKs](#abbr_PSK) and client | [IPsec](#abbr_IPsec) (PSKs and client certificates) and Bluetooth keys. certificates) and Bluetooth keys. These keys must not be protected by | These keys must not be protected by the password, as they may be the password, as they may be necessary in the locked state. For clarity, | necessary in the locked state. For clarity, the [ST](#abbr_ST) author the [ST](#abbr_ST) author must assign any Long-term trusted channel key | must assign any Long-term trusted channel key material supported by the material supported by the [TOE](#abbr_TOE). At a minimum, a | [TOE](#abbr_TOE). At a minimum, a [TOE](#abbr_TOE) must support at least [TOE](#abbr_TOE) must support at least Wi-Fi and Bluetooth keys.]{.note} | Wi-Fi and Bluetooth keys. ]{.note} ::: ::: ::: ::: ::: ::: ::: element ::: element ::: {#FCS_STG_EXT.2.2 .reqid} ::: {#FCS_STG_EXT.2.2 .reqid} [FCS_STG_EXT.2.2](#FCS_STG_EXT.2.2){.abbr} [FCS_STG_EXT.2.2](#FCS_STG_EXT.2.2){.abbr} ::: ::: ::: reqdesc ::: reqdesc [DEKs](#abbr_DEK), KEKs, \[**assignment**: [any long-term trusted | DEKs, KEKs, \[**assignment**: [any long-term trusted channel key channel key material]{.assignable-content}\] and \[**selection**: [all | material]{.assignable-content}\] and \[**selection**: [all software-based key storage]{#_s_430 .selectable-content}, [no other | software-based key storage]{#fcs_stg_ext.2.2_2 .selectable-content}, [no keys]{#_s_431 .selectable-content}\] shall be encrypted using one of the | other keys]{#fcs_stg_ext.2.2_3 .selectable-content}\] shall be encrypted following methods: \[**selection**: | using one of the following methods: \[**selection**: - [using a SP800-56B key establishment scheme]{#_s_432 | - [using a SP800-56B key establishment scheme]{#fcs_stg_ext.2.2_4 .selectable-content} .selectable-content} - [using [AES](#abbr_AES) in the following modes: \[**selection**: - [using [AES](#abbr_AES) in the following modes: \[**selection**: [Key Wrap (KW) as defined in [Key Wrap (KW) as defined in [FCS_COP.1/KeyWrap](#FCS_COP.1/KeyWrap)]{#_s_434 | [FCS_COP.1/KeyWrap](#FCS_COP.1/KeyWrap)]{#fcs_stg_ext.2.2_6 .selectable-content}, [Key Wrap with Padding (KWP) as defined in .selectable-content}, [Key Wrap with Padding (KWP) as defined in [FCS_COP.1/KeyWrap](#FCS_COP.1/KeyWrap)]{#_s_435 | [FCS_COP.1/KeyWrap](#FCS_COP.1/KeyWrap)]{#fcs_stg_ext.2.2_7 .selectable-content}, [[GCM](#abbr_GCM) as defined in .selectable-content}, [[GCM](#abbr_GCM) as defined in [FCS_COP.1/AEAD](#FCS_COP.1/AEAD)]{#_s_436 .selectable-content}, | [FCS_COP.1/AEAD](#FCS_COP.1/AEAD)]{#fcs_stg_ext.2.2_8 [[CCM](#abbr_CCM) as defined in | .selectable-content}, [[CCM](#abbr_CCM) as defined in [FCS_COP.1/AEAD](#FCS_COP.1/AEAD)]{#_s_437 .selectable-content}, | [FCS_COP.1/AEAD](#FCS_COP.1/AEAD)]{#fcs_stg_ext.2.2_9 [[CBC](#abbr_CBC) as defined in | .selectable-content}, [[CBC](#abbr_CBC) as defined in [FCS_COP.1/SKC](#FCS_COP.1/SKC)]{#_s_438 | [FCS_COP.1/SKC](#FCS_COP.1/SKC)]{#fcs_stg_ext.2.2_10 .selectable-content}\]]{#_s_433 .selectable-content} | .selectable-content}\]]{#fcs_stg_ext.2.2_5 .selectable-content} \]. \]. ::: appnote ::: appnote [Application Note: ]{.note-header}[The [ST](#abbr_ST) author selects [Application Note: ]{.note-header}[The [ST](#abbr_ST) author selects which key encryption schemes are used by the [TOE](#abbr_TOE). This which key encryption schemes are used by the [TOE](#abbr_TOE). This requirement refers only to KEKs as defined this [PP](#abbr_PP) and does requirement refers only to KEKs as defined this [PP](#abbr_PP) and does not refer to those KEKs specified in other standards. The [ST](#abbr_ST) not refer to those KEKs specified in other standards. The [ST](#abbr_ST) author must assign the same Long-term trusted channel key material author must assign the same Long-term trusted channel key material assigned in [FCS_STG_EXT.2.1](#FCS_STG_EXT.2.1).]{.note} assigned in [FCS_STG_EXT.2.1](#FCS_STG_EXT.2.1).]{.note} ::: ::: ::: ::: ::: ::: ::: {.activity_pane .hide} ::: {.activity_pane .hide} ::: activity_pane_header ::: activity_pane_header [[ Evaluation Activities [[ Evaluation Activities ]{.activity_pane_label}[]{.toggler}](#){onclick="toggle(this);return false;"} ]{.activity_pane_label}[]{.toggler}](#){onclick="toggle(this);return false;"} ::: ::: ::: activity_pane_body ::: activity_pane_body ::: component-activity-header ::: component-activity-header [FCS_STG_EXT.2](#FCS_STG_EXT.2) [FCS_STG_EXT.2](#FCS_STG_EXT.2) ::: ::: ::: eacategory ::: eacategory [TSS](#abbr_TSS) [TSS](#abbr_TSS) ::: ::: ::: ea ::: ea ::: ea ::: ea The evaluator shall review the [TSS](#abbr_TSS) to determine that the The evaluator shall review the [TSS](#abbr_TSS) to determine that the [TSS](#abbr_TSS) includes key hierarchy description of the protection of [TSS](#abbr_TSS) includes key hierarchy description of the protection of each [DEK](#abbr_DEK) for data-at-rest, of software-based key storage, each [DEK](#abbr_DEK) for data-at-rest, of software-based key storage, of long-term trusted channel keys, and of [KEK](#abbr_KEK) related to of long-term trusted channel keys, and of [KEK](#abbr_KEK) related to the protection of the [DEKs](#abbr_DEK), long-term trusted channel keys, | the protection of the DEKs, long-term trusted channel keys, and and software-based key storage. This description must include a diagram | software-based key storage. This description must include a diagram illustrating the key hierarchy implemented by the [TOE](#abbr_TOE) in illustrating the key hierarchy implemented by the [TOE](#abbr_TOE) in order to demonstrate that the implementation meets order to demonstrate that the implementation meets [FCS_STG_EXT.2](#FCS_STG_EXT.2). The description shall indicate how the [FCS_STG_EXT.2](#FCS_STG_EXT.2). The description shall indicate how the functionality described by [FCS_RBG.1](#FCS_RBG.1) is invoked to functionality described by [FCS_RBG.1](#FCS_RBG.1) is invoked to generate [DEKs](#abbr_DEK) ([FCS_CKM_EXT.2](#FCS_CKM_EXT.2)), the key | generate DEKs ([FCS_CKM_EXT.2](#FCS_CKM_EXT.2)), the key size size ([FCS_CKM_EXT.2](#FCS_CKM_EXT.2) and | ([FCS_CKM_EXT.2](#FCS_CKM_EXT.2) and [FCS_CKM_EXT.3](#FCS_CKM_EXT.3)) [FCS_CKM_EXT.3](#FCS_CKM_EXT.3)) for each key, how each [KEK](#abbr_KEK) | for each key, how each [KEK](#abbr_KEK) is formed (generated, derived, is formed (generated, derived, or combined according to | or combined according to [FCS_CKM_EXT.3](#FCS_CKM_EXT.3)), the integrity [FCS_CKM_EXT.3](#FCS_CKM_EXT.3)), the integrity protection method for | protection method for each encrypted key each encrypted key ([FCS_STG_EXT.3](#FCS_STG_EXT.3)), and the IV | ([FCS_STG_EXT.3](#FCS_STG_EXT.3)), and the IV generation for each key generation for each key encrypted by the same [KEK](#abbr_KEK) | encrypted by the same [KEK](#abbr_KEK) ([FCS_IV_EXT.1](#FCS_IV_EXT.1)). ([FCS_IV_EXT.1](#FCS_IV_EXT.1)). More detail for each task follows the | More detail for each task follows the corresponding requirement.\ corresponding requirement.\ < \ \ The evaluator shall also ensure that the documentation of the product\'s The evaluator shall also ensure that the documentation of the product\'s encryption key management is detailed enough that, after reading, the encryption key management is detailed enough that, after reading, the product\'s key management hierarchy is clear and that it meets the product\'s key management hierarchy is clear and that it meets the requirements to ensure the keys are adequately protected. The evaluator requirements to ensure the keys are adequately protected. The evaluator shall ensure that the documentation includes both an essay and one or shall ensure that the documentation includes both an essay and one or more diagrams. Note that this may also be documented as separate more diagrams. Note that this may also be documented as separate proprietary evidence rather than being included in the proprietary evidence rather than being included in the [TSS](#abbr_TSS).\ [TSS](#abbr_TSS).\ \ \ The evaluator shall examine the key hierarchy description in the The evaluator shall examine the key hierarchy description in the [TSS](#abbr_TSS) section to verify that each [DEK](#abbr_DEK) and [TSS](#abbr_TSS) section to verify that each [DEK](#abbr_DEK) and software-stored key is encrypted according to software-stored key is encrypted according to [FCS_STG_EXT.2](#FCS_STG_EXT.2).\ [FCS_STG_EXT.2](#FCS_STG_EXT.2).\ \ \ ::: ::: ::: ::: ::: eacategory ::: eacategory Guidance Guidance ::: ::: ::: ea ::: ea ::: ea ::: ea There are no guidance evaluation activities for this component.\ There are no guidance evaluation activities for this component.\ \ \ ::: ::: ::: ::: ::: eacategory ::: eacategory Tests Tests ::: ::: ::: ea ::: ea ::: ea ::: ea There are no test evaluation activities for this component. There are no test evaluation activities for this component. ::: ::: ::: ::: ::: ::: ::: ::: ::: ::: ::: {#FCS_STG_EXT.3 .comp} ::: {#FCS_STG_EXT.3 .comp} #### FCS_STG_EXT.3 Integrity of Encrypted Key Storage #### FCS_STG_EXT.3 Integrity of Encrypted Key Storage ::: element ::: element ::: {#FCS_STG_EXT.3.1 .reqid} ::: {#FCS_STG_EXT.3.1 .reqid} [FCS_STG_EXT.3.1](#FCS_STG_EXT.3.1){.abbr} [FCS_STG_EXT.3.1](#FCS_STG_EXT.3.1){.abbr} ::: ::: ::: reqdesc ::: reqdesc The [TSF](#abbr_TSF) shall protect the integrity of any encrypted | The [TSF](#abbr_TSF) shall protect the integrity of any encrypted DEKs [DEKs](#abbr_DEK) and KEKs and \[**selection**: [long-term trusted | and KEKs and \[**selection**: [long-term trusted channel key channel key material]{#_s_441 .selectable-content}, [all software-based | material]{#fcs_stg_ext.3.1_1 .selectable-content}, [all software-based key storage]{#_s_442 .selectable-content}, [no other keys]{#_s_443 | key storage]{#fcs_stg_ext.3.1_2 .selectable-content}, [no other .selectable-content}\] by \[**selection**: | keys]{#fcs_stg_ext.3.1_3 .selectable-content}\] by \[**selection**: - [\[**selection**: [[GCM](#abbr_GCM) as defined in - [\[**selection**: [[GCM](#abbr_GCM) as defined in [FCS_COP.1/AEAD](#FCS_COP.1/AEAD)]{#_s_445 .selectable-content}, | [FCS_COP.1/AEAD](#FCS_COP.1/AEAD)]{#fcs_stg_ext.3.1_5 [[CCM](#abbr_CCM) as defined in | .selectable-content}, [[CCM](#abbr_CCM) as defined in [FCS_COP.1/AEAD](#FCS_COP.1/AEAD)]{#_s_446 .selectable-content}, | [FCS_COP.1/AEAD](#FCS_COP.1/AEAD)]{#fcs_stg_ext.3.1_6 [Key Wrap as defined in | .selectable-content}, [Key Wrap as defined in [FCS_COP.1/KeyWrap](#FCS_COP.1/KeyWrap)]{#_s_447 | [FCS_COP.1/KeyWrap](#FCS_COP.1/KeyWrap)]{#fcs_stg_ext.3.1_7 .selectable-content}, [Key Wrap with Padding as defined in .selectable-content}, [Key Wrap with Padding as defined in [FCS_COP.1/KeyWrap](#FCS_COP.1/KeyWrap)]{#_s_448 | [FCS_COP.1/KeyWrap](#FCS_COP.1/KeyWrap)]{#fcs_stg_ext.3.1_8 .selectable-content}\] cipher mode for encryption according to .selectable-content}\] cipher mode for encryption according to [FCS_STG_EXT.2](#FCS_STG_EXT.2)]{#_s_444 .selectable-content} | [FCS_STG_EXT.2](#FCS_STG_EXT.2)]{#fcs_stg_ext.3.1_4 > .selectable-content} - [a hash (FCS_COP.1**/Hash**) of the stored key that is encrypted by - [a hash (FCS_COP.1**/Hash**) of the stored key that is encrypted by a key protected by [FCS_STG_EXT.2](#FCS_STG_EXT.2)]{#_s_449 | a key protected by > [FCS_STG_EXT.2](#FCS_STG_EXT.2)]{#fcs_stg_ext.3.1_9 .selectable-content} .selectable-content} - [a keyed hash (FCS_COP.1**/KeyedHash**) using a key protected by a - [a keyed hash (FCS_COP.1**/KeyedHash**) using a key protected by a key protected by [FCS_STG_EXT.2](#FCS_STG_EXT.2)]{#_s_450 | key protected by > [FCS_STG_EXT.2](#FCS_STG_EXT.2)]{#fcs_stg_ext.3.1_10 .selectable-content} .selectable-content} - [a digital signature of the stored key using an asymmetric key - [a digital signature of the stored key using an asymmetric key protected according to [FCS_STG_EXT.2](#FCS_STG_EXT.2)]{#_s_451 | protected according to > [FCS_STG_EXT.2](#FCS_STG_EXT.2)]{#fcs_stg_ext.3.1_11 .selectable-content} .selectable-content} - [an immediate application of the key for decrypting the protected - [an immediate application of the key for decrypting the protected data followed by a successful verification of the decrypted data data followed by a successful verification of the decrypted data with previously known information]{#_s_452 .selectable-content} | with previously known information]{#fcs_stg_ext.3.1_12 > .selectable-content} \]. \]. ::: appnote ::: appnote [Application Note: ]{.note-header}[The [ST](#abbr_ST) author must assign [Application Note: ]{.note-header}[The [ST](#abbr_ST) author must assign the same Long-term trusted channel key material assigned in the same Long-term trusted channel key material assigned in [FCS_STG_EXT.2.1](#FCS_STG_EXT.2.1).]{.note} [FCS_STG_EXT.2.1](#FCS_STG_EXT.2.1).]{.note} ::: ::: ::: ::: ::: ::: ::: element ::: element ::: {#FCS_STG_EXT.3.2 .reqid} ::: {#FCS_STG_EXT.3.2 .reqid} [FCS_STG_EXT.3.2](#FCS_STG_EXT.3.2){.abbr} [FCS_STG_EXT.3.2](#FCS_STG_EXT.3.2){.abbr} ::: ::: ::: reqdesc ::: reqdesc The [TSF](#abbr_TSF) shall verify the integrity of the \[**selection**: The [TSF](#abbr_TSF) shall verify the integrity of the \[**selection**: [hash]{#_s_461 .selectable-content}, [digital signature]{#_s_462 | [hash]{#fcs_stg_ext.3.2_1 .selectable-content}, [digital .selectable-content}, [MAC]{#_s_463 .selectable-content}\] of the stored | signature]{#fcs_stg_ext.3.2_2 .selectable-content}, key prior to use of the key. | [MAC]{#fcs_stg_ext.3.2_3 .selectable-content}\] of the stored key prior > to use of the key. ::: appnote ::: appnote [Application Note: ]{.note-header}[This requirement is not applicable to | [Application Note: ]{.note-header}[ This requirement is not applicable derived keys that are not stored. It is not expected that a single key | to derived keys that are not stored. It is not expected that a single will be protected from corruption by multiple of these methods; however, | key will be protected from corruption by multiple of these methods; a product may use one integrity-protection method for one type of key | however, a product may use one integrity-protection method for one type and a different method for other types of keys. The explicit Evaluation | of key and a different method for other types of keys. The explicit Activities for each of the options will be addressed in each of the | Evaluation Activities for each of the options will be addressed in each requirements ([FCS_COP.1.1/Hash](#FCS_COP.1.1/Hash), | of the requirements ([FCS_COP.1.1/Hash](#FCS_COP.1.1/Hash), [FCS_COP.1.1/KeyedHash](#FCS_COP.1.1/KeyedHash)).\ [FCS_COP.1.1/KeyedHash](#FCS_COP.1.1/KeyedHash)).\ \ \ Key Wrapping must be implemented per SP800-38F.]{.note} | Key Wrapping must be implemented per SP800-38F. ]{.note} ::: ::: ::: ::: ::: ::: ::: {.activity_pane .hide} ::: {.activity_pane .hide} ::: activity_pane_header ::: activity_pane_header [[ Evaluation Activities [[ Evaluation Activities ]{.activity_pane_label}[]{.toggler}](#){onclick="toggle(this);return false;"} ]{.activity_pane_label}[]{.toggler}](#){onclick="toggle(this);return false;"} ::: ::: ::: activity_pane_body ::: activity_pane_body ::: component-activity-header ::: component-activity-header [FCS_STG_EXT.3](#FCS_STG_EXT.3) [FCS_STG_EXT.3](#FCS_STG_EXT.3) ::: ::: ::: eacategory ::: eacategory [TSS](#abbr_TSS) [TSS](#abbr_TSS) ::: ::: ::: ea ::: ea ::: ea ::: ea The evaluator shall examine the key hierarchy description in the The evaluator shall examine the key hierarchy description in the [TSS](#abbr_TSS) section to verify that each encrypted key is integrity [TSS](#abbr_TSS) section to verify that each encrypted key is integrity protected according to one of the options in protected according to one of the options in [FCS_STG_EXT.3](#FCS_STG_EXT.3).\ [FCS_STG_EXT.3](#FCS_STG_EXT.3).\ \ \ The evaluator shall also ensure that the documentation of the product\'s The evaluator shall also ensure that the documentation of the product\'s encryption key management is detailed enough that, after reading, the encryption key management is detailed enough that, after reading, the product\'s key management hierarchy is clear and that it meets the product\'s key management hierarchy is clear and that it meets the requirements to ensure the keys are adequately protected. The evaluator requirements to ensure the keys are adequately protected. The evaluator shall ensure that the documentation includes both an essay and one or shall ensure that the documentation includes both an essay and one or more diagrams. Note that this may also be documented as separate more diagrams. Note that this may also be documented as separate proprietary evidence rather than being included in the proprietary evidence rather than being included in the [TSS](#abbr_TSS).\ [TSS](#abbr_TSS).\ \ \ ::: ::: ::: ::: ::: eacategory ::: eacategory Guidance Guidance ::: ::: ::: ea ::: ea ::: ea ::: ea There are no guidance evaluation activities for this component.\ There are no guidance evaluation activities for this component.\ \ \ ::: ::: ::: ::: ::: eacategory ::: eacategory Tests Tests ::: ::: ::: ea ::: ea ::: ea ::: ea There are no test evaluation activities for this component. There are no test evaluation activities for this component. ::: ::: ::: ::: ::: ::: ::: ::: ::: ::: ### 5.1.4 Class FDP: User Data Protection {#fdp .indexable level="3"} ### 5.1.4 Class FDP: User Data Protection {#fdp .indexable level="3"} A subset of the User Data Protection focuses on protecting Data-At-Rest, A subset of the User Data Protection focuses on protecting Data-At-Rest, namely [FDP_DAR_EXT.1](#FDP_DAR_EXT.1) and namely [FDP_DAR_EXT.1](#FDP_DAR_EXT.1) and [FDP_DAR_EXT.2](#FDP_DAR_EXT.2). Three levels of data-at-rest protection [FDP_DAR_EXT.2](#FDP_DAR_EXT.2). Three levels of data-at-rest protection are addressed: [TSF](#abbr_TSF) data, protected data (and keys), and are addressed: [TSF](#abbr_TSF) data, protected data (and keys), and sensitive data. [Table [17]{.counter}](#datalevels){.datalevels-ref sensitive data. [Table [17]{.counter}](#datalevels){.datalevels-ref onclick="showTarget('datalevels')"} addresses the level of protection onclick="showTarget('datalevels')"} addresses the level of protection required for each level of data-at-rest. required for each level of data-at-rest. **[Table [17]{.counter}: Protection of Data Levels]{#datalevels .ctr **[Table [17]{.counter}: Protection of Data Levels]{#datalevels .ctr myid="datalevels" counter-type="ct-Table"}**\ myid="datalevels" counter-type="ct-Table"}**\ \ \ ----------------------- ----------------------------------------------------------- ----------------------- ----------------------------------------------------------- Data Level Protection Required Data Level Protection Required [TSF](#abbr_TSF) Data [TSF](#abbr_TSF) data does not require confidentiality, but [TSF](#abbr_TSF) Data [TSF](#abbr_TSF) data does not require confidentiality, but Protected Data Protected data is encrypted while powered off. ([FDP_DAR_EX Protected Data Protected data is encrypted while powered off. ([FDP_DAR_EX Sensitive Data Sensitive data is encrypted while in the locked state, in a Sensitive Data Sensitive data is encrypted while in the locked state, in a ----------------------- ----------------------------------------------------------- ----------------------- ----------------------------------------------------------- \ \ All keys, protected data, and sensitive data must ultimately be All keys, protected data, and sensitive data must ultimately be protected by the [REK](#abbr_REK). Sensitive data must be protected by protected by the [REK](#abbr_REK). Sensitive data must be protected by the password in addition to the [REK](#abbr_REK). In particular, [Figure the password in addition to the [REK](#abbr_REK). In particular, [Figure [3]{.counter}](#Keys){.Keys-ref onclick="showTarget('Keys')"} has KEKs [3]{.counter}](#Keys){.Keys-ref onclick="showTarget('Keys')"} has KEKs protected according to these requirements: DEK_1 would be appropriate protected according to these requirements: DEK_1 would be appropriate for sensitive data, DEK_2 would not be appropriate for sensitive data, for sensitive data, DEK_2 would not be appropriate for sensitive data, K_1 is not considered a sensitive key, and K_2 is considered a sensitive K_1 is not considered a sensitive key, and K_2 is considered a sensitive key.\ key.\ \ \ These requirements include a capability for encrypting sensitive data These requirements include a capability for encrypting sensitive data received while in the locked state, which may be considered a separate received while in the locked state, which may be considered a separate sub-category of sensitive data. This capability may be met by a key sub-category of sensitive data. This capability may be met by a key transport scheme ([RSA](#abbr_RSA)) by using a public key to encrypt the transport scheme ([RSA](#abbr_RSA)) by using a public key to encrypt the [DEK](#abbr_DEK) while protecting the corresponding private key with a [DEK](#abbr_DEK) while protecting the corresponding private key with a password-derived or biometric-unlocked [KEK](#abbr_KEK).\ password-derived or biometric-unlocked [KEK](#abbr_KEK).\ \ \ This capability may also be met by a key agreement scheme. To do so, the This capability may also be met by a key agreement scheme. To do so, the device generates a device-wide sensitive data asymmetric pair (the device generates a device-wide sensitive data asymmetric pair (the private key of which is protected by a password-derived or private key of which is protected by a password-derived or biometric-unlocked [KEK](#abbr_KEK)) and an asymmetric pair for the biometric-unlocked [KEK](#abbr_KEK)) and an asymmetric pair for the received sensitive data to be stored. In order to store the sensitive received sensitive data to be stored. In order to store the sensitive data, the device-wide public key and data private key are used to data, the device-wide public key and data private key are used to generate a shared secret, which can be used as a [KEK](#abbr_KEK) or a generate a shared secret, which can be used as a [KEK](#abbr_KEK) or a [DEK](#abbr_DEK). The data private key and shared secret are cleared [DEK](#abbr_DEK). The data private key and shared secret are cleared after the data is encrypted and the data public key stored. Thus, no key after the data is encrypted and the data public key stored. Thus, no key material is available in the locked state to decrypt the newly stored material is available in the locked state to decrypt the newly stored data. Upon unlock, the device-wide private key is decrypted and is used data. Upon unlock, the device-wide private key is decrypted and is used with each data public key to regenerate the shared secret and decrypt with each data public key to regenerate the shared secret and decrypt the stored data. [Figure [4]{.counter}](#KeysLocked){.KeysLocked-ref the stored data. [Figure [4]{.counter}](#KeysLocked){.KeysLocked-ref onclick="showTarget('KeysLocked')"}, below, illustrates this scheme.\ onclick="showTarget('KeysLocked')"}, below, illustrates this scheme.\ \ \ ::: {#figure-KeysLocked .figure} ::: {#figure-KeysLocked .figure} ![](images/figure4.jpg){#KeysLocked width="" height=""}\ ![](images/figure4.jpg){#KeysLocked width="" height=""}\ [Figure [4]{.counter}]{.ctr myid="KeysLocked" counter-type="ct-figure"}: [Figure [4]{.counter}]{.ctr myid="KeysLocked" counter-type="ct-figure"}: Key Agreement Scheme for Encrypting Received Sensitive Data in the Key Agreement Scheme for Encrypting Received Sensitive Data in the Locked State Locked State ::: ::: \ \ \ \ ::: {#FDP_ACF_EXT.1 .comp} ::: {#FDP_ACF_EXT.1 .comp} #### FDP_ACF_EXT.1 Access Control for System Services #### FDP_ACF_EXT.1 Access Control for System Services ::: element ::: element ::: {#FDP_ACF_EXT.1.1 .reqid} ::: {#FDP_ACF_EXT.1.1 .reqid} [FDP_ACF_EXT.1.1](#FDP_ACF_EXT.1.1){.abbr} [FDP_ACF_EXT.1.1](#FDP_ACF_EXT.1.1){.abbr} ::: ::: ::: reqdesc ::: reqdesc The [TSF](#abbr_TSF) shall provide a mechanism to restrict the system The [TSF](#abbr_TSF) shall provide a mechanism to restrict the system services that are accessible to an application. services that are accessible to an application. ::: appnote ::: appnote [Application Note: ]{.note-header}[Examples of system services to which | [Application Note: ]{.note-header}[ Examples of system services to which this requirement applies include:\ this requirement applies include:\ \ \ ]{.note} ]{.note} - Obtain data from camera and microphone input devices - Obtain data from camera and microphone input devices - Obtain current device location - Obtain current device location - Retrieve credentials from system-wide credential store - Retrieve credentials from system-wide credential store - Retrieve contacts list / address book - Retrieve contacts list / address book - Retrieve stored pictures - Retrieve stored pictures - Retrieve text messages - Retrieve text messages - Retrieve emails - Retrieve emails - Retrieve device identifier information - Retrieve device identifier information - Obtain network access - Obtain network access ::: ::: ::: ::: ::: ::: ::: element ::: element ::: {#FDP_ACF_EXT.1.2 .reqid} ::: {#FDP_ACF_EXT.1.2 .reqid} [FDP_ACF_EXT.1.2](#FDP_ACF_EXT.1.2){.abbr} [FDP_ACF_EXT.1.2](#FDP_ACF_EXT.1.2){.abbr} ::: ::: ::: reqdesc ::: reqdesc The [TSF](#abbr_TSF) shall provide an access control policy that The [TSF](#abbr_TSF) shall provide an access control policy that prevents \[**selection**: [application]{#s-fdp-app .selectable-content}, prevents \[**selection**: [application]{#s-fdp-app .selectable-content}, [groups of applications]{#fdp_group .selectable-content}\] from [groups of applications]{#fdp_group .selectable-content}\] from accessing \[**selection**: [all]{#_s_466 .selectable-content}, | accessing \[**selection**: [all]{#fdp_acf_ext.1.2_1 [private]{#s-private .selectable-content}\] data stored by other | .selectable-content}, [private]{#s-private .selectable-content}\] data \[**selection**: [application]{#_s_468 .selectable-content}, [groups of | stored by other \[**selection**: [application]{#fdp_acf_ext.1.2_2 applications]{#_s_469 .selectable-content}\]. Exceptions may only be | .selectable-content}, [groups of applications]{#fdp_acf_ext.1.2_3 explicitly authorized for such sharing by \[**selection**: [the | .selectable-content}\]. Exceptions may only be explicitly authorized for user]{#s-acl-user .selectable-content}, [the administrator]{#s-acl-admin | such sharing by \[**selection**: [the user]{#s-acl-user > .selectable-content}, [the administrator]{#s-acl-admin .selectable-content}, [a common application developer]{#s-acl-devel .selectable-content}, [a common application developer]{#s-acl-devel .selectable-content}, [no one]{#_s_473 .selectable-content}\]. | .selectable-content}, [no one]{#fdp_acf_ext.1.2_4 > .selectable-content}\]. ::: appnote ::: appnote [Application Note: ]{.note-header}[Application groups may be designated | [Application Note: ]{.note-header}[ Application groups may be designated Enterprise or Personal. Applications installed by the user default to Enterprise or Personal. Applications installed by the user default to being in the Personal application group unless otherwise designated by being in the Personal application group unless otherwise designated by the administrator in function [43](#mf-appGroups) of the administrator in function [43](#mf-appGroups) of [FMT_SMF_EXT.1.1](#FMT_SMF_EXT.1.1). Applications installed by the [FMT_SMF_EXT.1.1](#FMT_SMF_EXT.1.1). Applications installed by the administrator default to being in the Enterprise application group (this administrator default to being in the Enterprise application group (this category includes applications that the user requests the administrator category includes applications that the user requests the administrator install, for instance by selecting the application for installation install, for instance by selecting the application for installation through an enterprise application catalog) unless otherwise designated through an enterprise application catalog) unless otherwise designated by the administrator in function [43](#mf-appGroups) of by the administrator in function [43](#mf-appGroups) of [FMT_SMF_EXT.1.1](#FMT_SMF_EXT.1.1). It is acceptable for the same [FMT_SMF_EXT.1.1](#FMT_SMF_EXT.1.1). It is acceptable for the same application to have multiple instances installed, each in different application to have multiple instances installed, each in different application groups. Private data is defined as data that is accessible application groups. Private data is defined as data that is accessible only by the application that wrote it. Private data is distinguished only by the application that wrote it. Private data is distinguished from data that an application may, by design, write to shared storage from data that an application may, by design, write to shared storage areas.\ areas.\ \ \ If [groups of applications](#fdp_group) is selected, If [groups of applications](#fdp_group) is selected, [FDP_ACF_EXT.2](#FDP_ACF_EXT.2) must be included in the [ST](#abbr_ST). [FDP_ACF_EXT.2](#FDP_ACF_EXT.2) must be included in the [ST](#abbr_ST). ]{.note} ]{.note} ::: ::: ::: ::: ::: ::: ::: {.activity_pane .hide} ::: {.activity_pane .hide} ::: activity_pane_header ::: activity_pane_header [[ Evaluation Activities [[ Evaluation Activities ]{.activity_pane_label}[]{.toggler}](#){onclick="toggle(this);return false;"} ]{.activity_pane_label}[]{.toggler}](#){onclick="toggle(this);return false;"} ::: ::: ::: activity_pane_body ::: activity_pane_body ::: element-activity-header ::: element-activity-header [FDP_ACF_EXT.1.1](#FDP_ACF_EXT.1.1) [FDP_ACF_EXT.1.1](#FDP_ACF_EXT.1.1) ::: ::: ::: eacategory ::: eacategory [TSS](#abbr_TSS) [TSS](#abbr_TSS) ::: ::: ::: ea ::: ea The evaluator shall ensure the [TSS](#abbr_TSS) lists all system The evaluator shall ensure the [TSS](#abbr_TSS) lists all system services available for use by an application. The evaluator shall also services available for use by an application. The evaluator shall also ensure that the [TSS](#abbr_TSS) describes how applications interface ensure that the [TSS](#abbr_TSS) describes how applications interface with these system services, and means by which these system services are with these system services, and means by which these system services are protected by the [TSF](#abbr_TSF).\ protected by the [TSF](#abbr_TSF).\ \ \ The [TSS](#abbr_TSS) shall describe which of the following categories The [TSS](#abbr_TSS) shall describe which of the following categories each system service falls in:\ each system service falls in:\ 1. No applications are allowed access 1. No applications are allowed access 2. Privileged applications are allowed access 2. Privileged applications are allowed access 3. Applications are allowed access by user authorization 3. Applications are allowed access by user authorization 4. All applications are allowed access 4. All applications are allowed access Privileged applications include any applications developed by the Privileged applications include any applications developed by the [TSF](#abbr_TSF) developer. The [TSS](#abbr_TSS) shall describe how [TSF](#abbr_TSF) developer. The [TSS](#abbr_TSS) shall describe how privileges are granted to third-party applications. For both types of privileges are granted to third-party applications. For both types of privileged applications, the [TSS](#abbr_TSS) shall describe how and privileged applications, the [TSS](#abbr_TSS) shall describe how and when the privileges are verified and how the [TSF](#abbr_TSF) prevents when the privileges are verified and how the [TSF](#abbr_TSF) prevents unprivileged applications from accessing those services.\ unprivileged applications from accessing those services.\ \ \ For any services for which the user may grant access, the evaluator For any services for which the user may grant access, the evaluator shall ensure that the [TSS](#abbr_TSS) identifies whether the user is shall ensure that the [TSS](#abbr_TSS) identifies whether the user is prompted for authorization when the application is installed, or during prompted for authorization when the application is installed, or during runtime. The evaluator shall ensure that the operational user guidance runtime. The evaluator shall ensure that the operational user guidance contains instructions for restricting application access to system contains instructions for restricting application access to system services.\ services.\ \ \ ::: ::: ::: eacategory ::: eacategory Guidance Guidance ::: ::: ::: ea ::: ea There are no guidance evaluation activities for this element.\ There are no guidance evaluation activities for this element.\ \ \ ::: ::: ::: eacategory ::: eacategory Tests Tests ::: ::: ::: ea ::: ea **Evaluation Activity Note:** The following tests require the vendor to **Evaluation Activity Note:** The following tests require the vendor to provide access to a test platform that provides the evaluator with tools provide access to a test platform that provides the evaluator with tools that are typically not found on consumer Mobile Device products.\ that are typically not found on consumer Mobile Device products.\ \ \ The evaluator shall write, or the developer shall provide, applications The evaluator shall write, or the developer shall provide, applications for the purposes of the following tests.\ for the purposes of the following tests.\ \ \ []{.testlist-} []{.testlist-} - [Test FDP_ACF_EXT.1.1:1](#_t_18){#_t_18 .defined}: For each system - [Test FDP_ACF_EXT.1.1:1](#_t_18){#_t_18 .defined}: For each system service to which no applications are allowed access, the evaluator service to which no applications are allowed access, the evaluator shall attempt to access the system service with a test application shall attempt to access the system service with a test application and verify that the application is not able to access that system and verify that the application is not able to access that system service. service. - [Test FDP_ACF_EXT.1.1:2](#_t_19){#_t_19 .defined}: For each system - [Test FDP_ACF_EXT.1.1:2](#_t_19){#_t_19 .defined}: For each system service to which only privileged applications are allowed access, service to which only privileged applications are allowed access, the evaluator shall attempt to access the system service with an the evaluator shall attempt to access the system service with an unprivileged application and verify that the application is not able unprivileged application and verify that the application is not able to access that system service. The evaluator shall attempt to access to access that system service. The evaluator shall attempt to access the system service with a privileged application and verify that the the system service with a privileged application and verify that the application can access the service. application can access the service. - [Test FDP_ACF_EXT.1.1:3](#_t_20){#_t_20 .defined}: For each system - [Test FDP_ACF_EXT.1.1:3](#_t_20){#_t_20 .defined}: For each system service to which the user may grant access, the evaluator shall service to which the user may grant access, the evaluator shall attempt to access the system service with a test application. The attempt to access the system service with a test application. The evaluator shall ensure that either the system blocks such accesses evaluator shall ensure that either the system blocks such accesses or prompts for user authorization. The prompt for user authorization or prompts for user authorization. The prompt for user authorization may occur at runtime or at installation time, and should be may occur at runtime or at installation time, and should be consistent with the behavior described in the [TSS](#abbr_TSS). consistent with the behavior described in the [TSS](#abbr_TSS). - [Test FDP_ACF_EXT.1.1:4](#_t_21){#_t_21 .defined}: For each system - [Test FDP_ACF_EXT.1.1:4](#_t_21){#_t_21 .defined}: For each system service listed in the [TSS](#abbr_TSS) that is accessible by all service listed in the [TSS](#abbr_TSS) that is accessible by all applications, the evaluator shall test that an application can applications, the evaluator shall test that an application can access that system service. access that system service. ::: ::: ::: element-activity-header ::: element-activity-header [FDP_ACF_EXT.1.2](#FDP_ACF_EXT.1.2) [FDP_ACF_EXT.1.2](#FDP_ACF_EXT.1.2) ::: ::: ::: eacategory ::: eacategory [TSS](#abbr_TSS) [TSS](#abbr_TSS) ::: ::: ::: ea ::: ea The evaluator shall examine the [TSS](#abbr_TSS) to verify that it The evaluator shall examine the [TSS](#abbr_TSS) to verify that it describes which data sharing is permitted between applications, which describes which data sharing is permitted between applications, which data sharing is not permitted, and how disallowed sharing is prevented. data sharing is not permitted, and how disallowed sharing is prevented. It is possible to select both \"applications\" and \"groups of It is possible to select both \"applications\" and \"groups of applications\", in which case the [TSS](#abbr_TSS) is expected to applications\", in which case the [TSS](#abbr_TSS) is expected to describe the data sharing policies that would be applied in each case.\ describe the data sharing policies that would be applied in each case.\ \ \ ::: ::: ::: eacategory ::: eacategory Guidance Guidance ::: ::: ::: ea ::: ea There are no guidance evaluation activities for this element.\ There are no guidance evaluation activities for this element.\ \ \ ::: ::: ::: eacategory ::: eacategory Tests Tests ::: ::: ::: ea ::: ea []{.testlist-} []{.testlist-} - [Test FDP_ACF_EXT.1.2:1](#_t_22){#_t_22 .defined}: The evaluator - [Test FDP_ACF_EXT.1.2:1](#_t_22){#_t_22 .defined}: The evaluator shall write, or the developer shall provide, two applications, one shall write, or the developer shall provide, two applications, one that saves data containing a unique string, and a second that that saves data containing a unique string, and a second that attempts to access that data. Based on the selections made, the attempts to access that data. Based on the selections made, the following steps shall be performed: following steps shall be performed: - If [groups of applications](#fdp_group) is selected, the - If [groups of applications](#fdp_group) is selected, the applications shall be placed into different groups. applications shall be placed into different groups. - If [application](#s-fdp-app) is selected, the evaluator shall - If [application](#s-fdp-app) is selected, the evaluator shall install the two applications. install the two applications. - If [private](#s-private) is selected, the application shall not - If [private](#s-private) is selected, the application shall not write to a designated shared storage area. write to a designated shared storage area. The evaluator shall verify that the second application is unable to The evaluator shall verify that the second application is unable to access the stored unique string by default. access the stored unique string by default. - [Test FDP_ACF_EXT.1.2:2](#_t_23){#_t_23 .defined}: \[conditional: - [Test FDP_ACF_EXT.1.2:2](#_t_23){#_t_23 .defined}: \[conditional: \"no one\" is not selected in [FDP_ACF_EXT.1.2](#FDP_ACF_EXT.1.2)\] \"no one\" is not selected in [FDP_ACF_EXT.1.2](#FDP_ACF_EXT.1.2)\] Using the applications from the previous test, the evaluator shall Using the applications from the previous test, the evaluator shall test the explicit authorizations for sharing data between test the explicit authorizations for sharing data between applications as follows, depending on the selections made in applications as follows, depending on the selections made in [FDP_ACF_EXT.1.2](#FDP_ACF_EXT.1.2): [FDP_ACF_EXT.1.2](#FDP_ACF_EXT.1.2): - If [the user](#s-acl-user) is selected, the evaluator shall - If [the user](#s-acl-user) is selected, the evaluator shall grant access as the user and verify that the second application grant access as the user and verify that the second application is able to access the stored unique string. is able to access the stored unique string. - If [the administrator](#s-acl-admin) is selected, the evaluator - If [the administrator](#s-acl-admin) is selected, the evaluator shall grant access as the administrator and verify that the shall grant access as the administrator and verify that the second application is able to access the stored unique string. second application is able to access the stored unique string. - If [a common application developer](#s-acl-devel) is selected, - If [a common application developer](#s-acl-devel) is selected, the evaluator shall grant access to an application with a common the evaluator shall grant access to an application with a common application developer to the first, and verify that the application developer to the first, and verify that the application is able to access the stored unique string. application is able to access the stored unique string. ::: ::: ::: ::: ::: ::: ::: ::: ::: {#FDP_DAR_EXT.1 .comp} ::: {#FDP_DAR_EXT.1 .comp} #### FDP_DAR_EXT.1 Protected Data Encryption #### FDP_DAR_EXT.1 Protected Data Encryption ::: element ::: element ::: {#FDP_DAR_EXT.1.1 .reqid} ::: {#FDP_DAR_EXT.1.1 .reqid} [FDP_DAR_EXT.1.1](#FDP_DAR_EXT.1.1){.abbr} [FDP_DAR_EXT.1.1](#FDP_DAR_EXT.1.1){.abbr} ::: ::: ::: reqdesc ::: reqdesc Encryption shall cover all protected data. Encryption shall cover all protected data. ::: appnote ::: appnote [Application Note: ]{.note-header}[ Protected data is all non-TSF data, | [Application Note: ]{.note-header}[Protected data is all non-TSF data, including all user or enterprise data. Some or all of this data may be including all user or enterprise data. Some or all of this data may be considered sensitive data as well.]{.note} considered sensitive data as well.]{.note} ::: ::: ::: ::: ::: ::: ::: element ::: element ::: {#FDP_DAR_EXT.1.2 .reqid} ::: {#FDP_DAR_EXT.1.2 .reqid} [FDP_DAR_EXT.1.2](#FDP_DAR_EXT.1.2){.abbr} [FDP_DAR_EXT.1.2](#FDP_DAR_EXT.1.2){.abbr} ::: ::: ::: reqdesc ::: reqdesc Encryption shall be performed using [DEKs](#abbr_DEK) with | Encryption shall be performed using DEKs with [AES](#abbr_AES) in the [AES](#abbr_AES) in the \[**selection**: | \[**selection**: [[CBC](#abbr_CBC)]{#fel-dar-how-cbc [[CBC](#abbr_CBC)]{#fel-dar-how-cbc .selectable-content}, | .selectable-content}, [[GCM](#abbr_GCM)]{#fel-dar-how-gcm [[GCM](#abbr_GCM)]{#fel-dar-how-gcm .selectable-content}, | .selectable-content}, [[XTS](#abbr_XTS)]{#fel-dar-how-xts [[XTS](#abbr_XTS)]{#fel-dar-how-xts .selectable-content}\] mode with key | .selectable-content}\] mode with key size \[*256*\] bits. size \[*256*\] bits. < ::: appnote ::: appnote [Application Note: ]{.note-header}[IVs must be generated in accordance [Application Note: ]{.note-header}[IVs must be generated in accordance with [FCS_IV_EXT.1.1](#FCS_IV_EXT.1.1).]{.note} with [FCS_IV_EXT.1.1](#FCS_IV_EXT.1.1).]{.note} ::: ::: ::: ::: ::: ::: ::: {.activity_pane .hide} ::: {.activity_pane .hide} ::: activity_pane_header ::: activity_pane_header [[ Evaluation Activities [[ Evaluation Activities ]{.activity_pane_label}[]{.toggler}](#){onclick="toggle(this);return false;"} ]{.activity_pane_label}[]{.toggler}](#){onclick="toggle(this);return false;"} ::: ::: ::: activity_pane_body ::: activity_pane_body ::: component-activity-header ::: component-activity-header [FDP_DAR_EXT.1](#FDP_DAR_EXT.1) [FDP_DAR_EXT.1](#FDP_DAR_EXT.1) ::: ::: ::: eacategory ::: eacategory [TSS](#abbr_TSS) [TSS](#abbr_TSS) ::: ::: ::: ea ::: ea ::: ea ::: ea The evaluator shall verify that the [TSS](#abbr_TSS) section of the The evaluator shall verify that the [TSS](#abbr_TSS) section of the [ST](#abbr_ST) indicates which data is protected by the [DAR](#abbr_DAR) [ST](#abbr_ST) indicates which data is protected by the [DAR](#abbr_DAR) implementation and what data is considered [TSF](#abbr_TSF) data. The implementation and what data is considered [TSF](#abbr_TSF) data. The evaluator shall ensure that this data includes all protected data. evaluator shall ensure that this data includes all protected data. ::: ::: ::: ::: ::: eacategory ::: eacategory Guidance Guidance ::: ::: ::: ea ::: ea ::: ea ::: ea The evaluator shall review the AGD guidance to determine that the The evaluator shall review the AGD guidance to determine that the description of the configuration and use of the [DAR](#abbr_DAR) description of the configuration and use of the [DAR](#abbr_DAR) protection does not require the user to perform any actions beyond protection does not require the user to perform any actions beyond configuration and providing the authentication credential. The evaluator configuration and providing the authentication credential. The evaluator shall also review the AGD guidance to determine that the configuration shall also review the AGD guidance to determine that the configuration does not require the user to identify encryption on a per-file basis. does not require the user to identify encryption on a per-file basis. ::: ::: ::: ::: ::: eacategory ::: eacategory Tests Tests ::: ::: ::: ea ::: ea ::: ea ::: ea **Evaluation Activity Note:** The following test requires the developer **Evaluation Activity Note:** The following test requires the developer to provide access to a test platform that provides the evaluator with to provide access to a test platform that provides the evaluator with tools that are typically not found on consumer Mobile Device products. tools that are typically not found on consumer Mobile Device products. []{.testlist-} []{.testlist-} - [Test FDP_DAR_EXT.1:1](#_t_26){#_t_26 .defined}: The evaluator shall - [Test FDP_DAR_EXT.1:1](#_t_26){#_t_26 .defined}: The evaluator shall enable encryption according to the AGD guidance. The evaluator shall enable encryption according to the AGD guidance. The evaluator shall create user data (non-system) either by creating a file or by using create user data (non-system) either by creating a file or by using an application. The evaluator shall use a tool provided by the an application. The evaluator shall use a tool provided by the developer to verify that this data is encrypted when the product is developer to verify that this data is encrypted when the product is powered off, in conjunction with [Test powered off, in conjunction with [Test FIA_UAU_EXT.1:1](#unauthenticated-encrypted-data){.dynref}. FIA_UAU_EXT.1:1](#unauthenticated-encrypted-data){.dynref}. ::: ::: ::: ::: ::: ::: ::: ::: ::: ::: ::: {#FDP_DAR_EXT.2 .comp} ::: {#FDP_DAR_EXT.2 .comp} #### FDP_DAR_EXT.2 Sensitive Data Encryption #### FDP_DAR_EXT.2 Sensitive Data Encryption ::: element ::: element ::: {#FDP_DAR_EXT.2.1 .reqid} ::: {#FDP_DAR_EXT.2.1 .reqid} [FDP_DAR_EXT.2.1](#FDP_DAR_EXT.2.1){.abbr} [FDP_DAR_EXT.2.1](#FDP_DAR_EXT.2.1){.abbr} ::: ::: ::: reqdesc ::: reqdesc The [TSF](#abbr_TSF) shall provide a mechanism for applications to mark The [TSF](#abbr_TSF) shall provide a mechanism for applications to mark data and keys as sensitive. data and keys as sensitive. ::: appnote ::: appnote [Application Note: ]{.note-header}[Data and keys that have been marked | [Application Note: ]{.note-header}[ Data and keys that have been marked as sensitive will be subject to certain restrictions (through other as sensitive will be subject to certain restrictions (through other requirements) in both the locked and unlocked states of the Mobile requirements) in both the locked and unlocked states of the Mobile Device. This mechanism allows an application to choose those data and Device. This mechanism allows an application to choose those data and keys under its control to be subject to those requirements.\ keys under its control to be subject to those requirements.\ \ \ In the future, this [PP](#abbr_PP) may require that all data and key In the future, this [PP](#abbr_PP) may require that all data and key created by applications will default to the \"sensitive\" marking, created by applications will default to the \"sensitive\" marking, requiring an explicit \"non-sensitive\" marking rather than an explicit requiring an explicit \"non-sensitive\" marking rather than an explicit \"sensitive\" marking. ]{.note} \"sensitive\" marking. ]{.note} ::: ::: ::: ::: ::: ::: ::: element ::: element ::: {#FDP_DAR_EXT.2.2 .reqid} ::: {#FDP_DAR_EXT.2.2 .reqid} [FDP_DAR_EXT.2.2](#FDP_DAR_EXT.2.2){.abbr} [FDP_DAR_EXT.2.2](#FDP_DAR_EXT.2.2){.abbr} ::: ::: ::: reqdesc ::: reqdesc The [TSF](#abbr_TSF) shall use an asymmetric key scheme to encrypt and The [TSF](#abbr_TSF) shall use an asymmetric key scheme to encrypt and store sensitive data received while the product is locked. store sensitive data received while the product is locked. ::: appnote ::: appnote [Application Note: ]{.note-header}[Sensitive data is encrypted according | [Application Note: ]{.note-header}[ Sensitive data is encrypted to [FDP_DAR_EXT.1.2](#FDP_DAR_EXT.1.2). The asymmetric key scheme must | according to [FDP_DAR_EXT.1.2](#FDP_DAR_EXT.1.2). The asymmetric key be performed in accordance with | scheme must be performed in accordance with [FCS_CKM_EXT.7/LOCKED](#FCS_CKM_EXT.7/LOCKED).\ [FCS_CKM_EXT.7/LOCKED](#FCS_CKM_EXT.7/LOCKED).\ \ \ The intent of this requirement is to allow the device to receive The intent of this requirement is to allow the device to receive sensitive data while locked and to store the received data in such a way sensitive data while locked and to store the received data in such a way as to prevent unauthorized parties from decrypting it while in the as to prevent unauthorized parties from decrypting it while in the locked state. If only a subset of sensitive data may be received in the locked state. If only a subset of sensitive data may be received in the locked state, this subset must be described in the [TSS](#abbr_TSS).\ locked state, this subset must be described in the [TSS](#abbr_TSS).\ \ \ Key material must be cleared when no longer needed according to Key material must be cleared when no longer needed according to [FCS_CKM.6](#FCS_CKM.6). For keys (or key material used to derive those [FCS_CKM.6](#FCS_CKM.6). For keys (or key material used to derive those keys) protecting sensitive data received in the locked state, \"no keys) protecting sensitive data received in the locked state, \"no longer needed\" includes \"while in the locked state.\" For example, in longer needed\" includes \"while in the locked state.\" For example, in the first key scheme, this includes the [DEK](#abbr_DEK) protecting the the first key scheme, this includes the [DEK](#abbr_DEK) protecting the received data as soon as the data is encrypted. In the second key scheme received data as soon as the data is encrypted. In the second key scheme this includes the private key for the data asymmetric pair, the this includes the private key for the data asymmetric pair, the generated shared secret, and any generated [DEKs](#abbr_DEK). Of course, | generated shared secret, and any generated DEKs. Of course, both schemes both schemes require that a private key of an asymmetric pair (the | require that a private key of an asymmetric pair (the [RSA](#abbr_RSA) [RSA](#abbr_RSA) private key and the device-wide private key, | private key and the device-wide private key, respectively) be cleared respectively) be cleared when transitioning to the locked state. | when transitioning to the locked state. ]{.note} ]{.note} < ::: ::: ::: ::: ::: ::: ::: element ::: element ::: {#FDP_DAR_EXT.2.3 .reqid} ::: {#FDP_DAR_EXT.2.3 .reqid} [FDP_DAR_EXT.2.3](#FDP_DAR_EXT.2.3){.abbr} [FDP_DAR_EXT.2.3](#FDP_DAR_EXT.2.3){.abbr} ::: ::: ::: reqdesc ::: reqdesc The [TSF](#abbr_TSF) shall encrypt any stored symmetric key and any The [TSF](#abbr_TSF) shall encrypt any stored symmetric key and any stored private key of the asymmetric keys used for the protection of stored private key of the asymmetric keys used for the protection of sensitive data according to \[*[FCS_STG_EXT.2.1](#FCS_STG_EXT.2.1) sensitive data according to \[*[FCS_STG_EXT.2.1](#FCS_STG_EXT.2.1) selection 2*\]. selection 2*\]. ::: appnote ::: appnote [Application Note: ]{.note-header}[Symmetric keys used to encrypt [Application Note: ]{.note-header}[Symmetric keys used to encrypt sensitive data while the [TSF](#abbr_TSF) is in the unlocked state must sensitive data while the [TSF](#abbr_TSF) is in the unlocked state must be encrypted with (or chain to a [KEK](#abbr_KEK) encrypted with) the be encrypted with (or chain to a [KEK](#abbr_KEK) encrypted with) the [REK](#abbr_REK) and password-derived or biometric-unlocked [REK](#abbr_REK) and password-derived or biometric-unlocked [KEK](#abbr_KEK). A stored private key of the asymmetric key scheme for [KEK](#abbr_KEK). A stored private key of the asymmetric key scheme for encrypting data in the locked state must be encrypted with (or chain to encrypting data in the locked state must be encrypted with (or chain to a [KEK](#abbr_KEK) encrypted with) the [REK](#abbr_REK) and a [KEK](#abbr_KEK) encrypted with) the [REK](#abbr_REK) and password-derived or biometric-unlocked [KEK](#abbr_KEK).]{.note} password-derived or biometric-unlocked [KEK](#abbr_KEK).]{.note} ::: ::: ::: ::: ::: ::: ::: element ::: element ::: {#FDP_DAR_EXT.2.4 .reqid} ::: {#FDP_DAR_EXT.2.4 .reqid} [FDP_DAR_EXT.2.4](#FDP_DAR_EXT.2.4){.abbr} [FDP_DAR_EXT.2.4](#FDP_DAR_EXT.2.4){.abbr} ::: ::: ::: reqdesc ::: reqdesc The [TSF](#abbr_TSF) shall decrypt the sensitive data that was received The [TSF](#abbr_TSF) shall decrypt the sensitive data that was received while in the locked state upon transitioning to the unlocked state using while in the locked state upon transitioning to the unlocked state using the asymmetric key scheme and shall re-encrypt that sensitive data using the asymmetric key scheme and shall re-encrypt that sensitive data using the symmetric key scheme. the symmetric key scheme. ::: ::: ::: ::: ::: {.activity_pane .hide} ::: {.activity_pane .hide} ::: activity_pane_header ::: activity_pane_header [[ Evaluation Activities [[ Evaluation Activities ]{.activity_pane_label}[]{.toggler}](#){onclick="toggle(this);return false;"} ]{.activity_pane_label}[]{.toggler}](#){onclick="toggle(this);return false;"} ::: ::: ::: activity_pane_body ::: activity_pane_body ::: element-activity-header ::: element-activity-header [FDP_DAR_EXT.2.1](#FDP_DAR_EXT.2.1) [FDP_DAR_EXT.2.1](#FDP_DAR_EXT.2.1) ::: ::: ::: eacategory ::: eacategory [TSS](#abbr_TSS) [TSS](#abbr_TSS) ::: ::: ::: ea ::: ea The evaluator shall verify that the [TSS](#abbr_TSS) includes a The evaluator shall verify that the [TSS](#abbr_TSS) includes a description of which data stored by the [TSF](#abbr_TSF) (such as by description of which data stored by the [TSF](#abbr_TSF) (such as by native applications) is treated as sensitive. This data may include all native applications) is treated as sensitive. This data may include all or some user or enterprise data and must be specific regarding the level or some user or enterprise data and must be specific regarding the level of protection of email, contacts, calendar appointments, messages, and of protection of email, contacts, calendar appointments, messages, and documents.\ documents.\ \ \ The evaluator shall examine the [TSS](#abbr_TSS) to determine that it The evaluator shall examine the [TSS](#abbr_TSS) to determine that it describes the mechanism that is provided for applications to use to mark describes the mechanism that is provided for applications to use to mark data and keys as sensitive. This description shall also contain data and keys as sensitive. This description shall also contain information reflecting how data and keys marked in this manner are information reflecting how data and keys marked in this manner are distinguished from data and keys that are not (for instance, tagging, distinguished from data and keys that are not (for instance, tagging, segregation in a \"special\" area of memory or container, etc.).\ segregation in a \"special\" area of memory or container, etc.).\ \ \ ::: ::: ::: eacategory ::: eacategory Guidance Guidance ::: ::: ::: ea ::: ea There are no guidance evaluation activities for this element.\ There are no guidance evaluation activities for this element.\ \ \ ::: ::: ::: eacategory ::: eacategory Tests Tests ::: ::: ::: ea ::: ea The evaluator shall enable encryption of sensitive data and require user The evaluator shall enable encryption of sensitive data and require user authentication according to the AGD guidance. The evaluator shall try to authentication according to the AGD guidance. The evaluator shall try to access and create sensitive data (as defined in the [ST](#abbr_ST) and access and create sensitive data (as defined in the [ST](#abbr_ST) and either by creating a file or using an application to generate sensitive either by creating a file or using an application to generate sensitive data) in order to verify that no other user interaction is required.\ data) in order to verify that no other user interaction is required.\ \ \ ::: ::: ::: element-activity-header ::: element-activity-header [FDP_DAR_EXT.2.2](#FDP_DAR_EXT.2.2) [FDP_DAR_EXT.2.2](#FDP_DAR_EXT.2.2) ::: ::: ::: eacategory ::: eacategory [TSS](#abbr_TSS) [TSS](#abbr_TSS) ::: ::: ::: ea ::: ea The evaluator shall review the [TSS](#abbr_TSS) section of the The evaluator shall review the [TSS](#abbr_TSS) section of the [ST](#abbr_ST) to determine that the [TSS](#abbr_TSS) includes a [ST](#abbr_ST) to determine that the [TSS](#abbr_TSS) includes a description of the process of receiving sensitive data while the device description of the process of receiving sensitive data while the device is in a locked state. The evaluator shall also verify that the is in a locked state. The evaluator shall also verify that the description indicates if sensitive data that may be received in the description indicates if sensitive data that may be received in the locked state is treated differently than sensitive data that cannot be locked state is treated differently than sensitive data that cannot be received in the locked state. The description shall include the key received in the locked state. The description shall include the key scheme for encrypting and storing the received data, which must involve scheme for encrypting and storing the received data, which must involve an asymmetric key and must prevent the sensitive data-at-rest from being an asymmetric key and must prevent the sensitive data-at-rest from being decrypted by wiping all key material used to derive or encrypt the data decrypted by wiping all key material used to derive or encrypt the data (as described in the application note). The introduction to this section (as described in the application note). The introduction to this section provides two different schemes that meet the requirements, but other provides two different schemes that meet the requirements, but other solutions may address this requirement.\ solutions may address this requirement.\ \ \ ::: ::: ::: eacategory ::: eacategory Guidance Guidance ::: ::: ::: ea ::: ea There are no guidance evaluation activities for this element.\ There are no guidance evaluation activities for this element.\ \ \ ::: ::: ::: eacategory ::: eacategory Tests Tests ::: ::: ::: ea ::: ea The evaluator shall perform the tests in [FCS_CKM.6](#FCS_CKM.6) for all The evaluator shall perform the tests in [FCS_CKM.6](#FCS_CKM.6) for all key material no longer needed while in the locked state and shall ensure key material no longer needed while in the locked state and shall ensure that keys for the asymmetric scheme are addressed in the tests performed that keys for the asymmetric scheme are addressed in the tests performed when transitioning to the locked state.\ when transitioning to the locked state.\ \ \ ::: ::: ::: element-activity-header ::: element-activity-header [FDP_DAR_EXT.2.3](#FDP_DAR_EXT.2.3) [FDP_DAR_EXT.2.3](#FDP_DAR_EXT.2.3) ::: ::: ::: eacategory ::: eacategory [TSS](#abbr_TSS) [TSS](#abbr_TSS) ::: ::: ::: ea ::: ea The evaluator shall verify that the key hierarchy section of the The evaluator shall verify that the key hierarchy section of the [TSS](#abbr_TSS) required for [FCS_STG_EXT.2.1](#FCS_STG_EXT.2.1) [TSS](#abbr_TSS) required for [FCS_STG_EXT.2.1](#FCS_STG_EXT.2.1) includes the symmetric encryption keys ([DEKs](#abbr_DEK)) used to | includes the symmetric encryption keys (DEKs) used to encrypt sensitive encrypt sensitive data. The evaluator shall ensure that these | data. The evaluator shall ensure that these DEKs are encrypted by a key [DEKs](#abbr_DEK) are encrypted by a key encrypted with (or chain to a | encrypted with (or chain to a [KEK](#abbr_KEK) encrypted with) the [KEK](#abbr_KEK) encrypted with) the [REK](#abbr_REK) and | [REK](#abbr_REK) and password-derived or biometric-unlocked password-derived or biometric-unlocked [KEK](#abbr_KEK).\ | [KEK](#abbr_KEK).\ \ \ The evaluator shall verify that the [TSS](#abbr_TSS) section of the The evaluator shall verify that the [TSS](#abbr_TSS) section of the [ST](#abbr_ST) that describes the asymmetric key scheme includes the [ST](#abbr_ST) that describes the asymmetric key scheme includes the protection of any private keys of the asymmetric pairs. The evaluator protection of any private keys of the asymmetric pairs. The evaluator shall ensure that any private keys that are not wiped and are stored by shall ensure that any private keys that are not wiped and are stored by the [TSF](#abbr_TSF) are stored encrypted by a key encrypted with (or the [TSF](#abbr_TSF) are stored encrypted by a key encrypted with (or chain to a [KEK](#abbr_KEK) encrypted with) the [REK](#abbr_REK) and chain to a [KEK](#abbr_KEK) encrypted with) the [REK](#abbr_REK) and password-derived or biometric-unlocked [KEK](#abbr_KEK).\ password-derived or biometric-unlocked [KEK](#abbr_KEK).\ \ \ The evaluator shall also ensure that the documentation of the product\'s The evaluator shall also ensure that the documentation of the product\'s encryption key management is detailed enough that, after reading, the encryption key management is detailed enough that, after reading, the product\'s key management hierarchy is clear and that it meets the product\'s key management hierarchy is clear and that it meets the requirements to ensure the keys are adequately protected. The evaluator requirements to ensure the keys are adequately protected. The evaluator shall ensure that the documentation includes both an essay and one or shall ensure that the documentation includes both an essay and one or more diagrams. Note that this may also be documented as separate more diagrams. Note that this may also be documented as separate proprietary evidence rather than being included in the proprietary evidence rather than being included in the [TSS](#abbr_TSS).\ [TSS](#abbr_TSS).\ \ \ ::: ::: ::: eacategory ::: eacategory Guidance Guidance ::: ::: ::: ea ::: ea There are no guidance evaluation activities for this element.\ There are no guidance evaluation activities for this element.\ \ \ ::: ::: ::: eacategory ::: eacategory Tests Tests ::: ::: ::: ea ::: ea There are no test evaluation activities for this element.\ There are no test evaluation activities for this element.\ \ \ ::: ::: ::: element-activity-header ::: element-activity-header [FDP_DAR_EXT.2.4](#FDP_DAR_EXT.2.4) [FDP_DAR_EXT.2.4](#FDP_DAR_EXT.2.4) ::: ::: ::: eacategory ::: eacategory [TSS](#abbr_TSS) [TSS](#abbr_TSS) ::: ::: ::: ea ::: ea The evaluator shall verify that the [TSS](#abbr_TSS) section of the The evaluator shall verify that the [TSS](#abbr_TSS) section of the [ST](#abbr_ST) that describes the asymmetric key scheme includes a [ST](#abbr_ST) that describes the asymmetric key scheme includes a description of the actions taken by the [TSF](#abbr_TSF) for the description of the actions taken by the [TSF](#abbr_TSF) for the purposes of [DAR](#abbr_DAR) upon transitioning to the unlocked state. purposes of [DAR](#abbr_DAR) upon transitioning to the unlocked state. These actions shall minimally include decrypting all received data using These actions shall minimally include decrypting all received data using the asymmetric key scheme and re-encrypting with the symmetric key the asymmetric key scheme and re-encrypting with the symmetric key scheme used to store data while the device is unlocked.\ scheme used to store data while the device is unlocked.\ \ \ ::: ::: ::: eacategory ::: eacategory Guidance Guidance ::: ::: ::: ea ::: ea There are no guidance evaluation activities for this element.\ There are no guidance evaluation activities for this element.\ \ \ ::: ::: ::: eacategory ::: eacategory Tests Tests ::: ::: ::: ea ::: ea There are no test evaluation activities for this element.\ There are no test evaluation activities for this element.\ \ \ ::: ::: ::: ::: ::: ::: ::: ::: ::: {#FDP_IFC_EXT.1 .comp} ::: {#FDP_IFC_EXT.1 .comp} #### FDP_IFC_EXT.1 Subset Information Flow Control #### FDP_IFC_EXT.1 Subset Information Flow Control ::: element ::: element ::: {#FDP_IFC_EXT.1.1 .reqid} ::: {#FDP_IFC_EXT.1.1 .reqid} [FDP_IFC_EXT.1.1](#FDP_IFC_EXT.1.1){.abbr} [FDP_IFC_EXT.1.1](#FDP_IFC_EXT.1.1){.abbr} ::: ::: ::: reqdesc ::: reqdesc The [TSF](#abbr_TSF) shall \[**selection**: The [TSF](#abbr_TSF) shall \[**selection**: - [provide an interface which allows a [VPN](#abbr_VPN) client to - [provide an interface which allows a [VPN](#abbr_VPN) client to protect all [IP](#abbr_IP) traffic using protect all [IP](#abbr_IP) traffic using [IPsec](#abbr_IPsec)]{#_s_494 .selectable-content} | [IPsec](#abbr_IPsec)]{#fdp_ifc_ext.1.1_1 .selectable-content} - [provide a [VPN](#abbr_VPN) client which can protect all - [provide a [VPN](#abbr_VPN) client which can protect all [IP](#abbr_IP) traffic using [IPsec](#abbr_IPsec) **as defined in [IP](#abbr_IP) traffic using [IPsec](#abbr_IPsec) **as defined in the [PP-Module for Virtual Private Network (VPN) Clients, version the [PP-Module for Virtual Private Network (VPN) Clients, version 3.0](https://www.niap-ccevs.org/protectionprofiles/487)**]{#_s_495 | 3.0]()**]{#fdp_ifc_ext.1.1_2 .selectable-content} .selectable-content} < \] with the exception of [IP](#abbr_IP) traffic needed to manage the \] with the exception of [IP](#abbr_IP) traffic needed to manage the [VPN](#abbr_VPN) connection, and \[**selection**: [\[**assignment**: [VPN](#abbr_VPN) connection, and \[**selection**: [\[**assignment**: [traffic needed for correct functioning of the [traffic needed for correct functioning of the [TOE](#abbr_TOE)]{.assignable-content}\]]{#_s_496 .selectable-content}, | [TOE](#abbr_TOE)]{.assignable-content}\]]{#fdp_ifc_ext.1.1_3 [no other traffic]{#_s_497 .selectable-content}\], when the | .selectable-content}, [no other traffic]{#fdp_ifc_ext.1.1_5 [VPN](#abbr_VPN) is enabled. | .selectable-content}\], when the [VPN](#abbr_VPN) is enabled. ::: appnote ::: appnote [Application Note: ]{.note-header}[Typically, the traffic needed to | [Application Note: ]{.note-header}[ Typically, the traffic needed to manage the [VPN](#abbr_VPN) connection is referred to as \"Control manage the [VPN](#abbr_VPN) connection is referred to as \"Control Plane\" traffic; whereas, the [IP](#abbr_IP) traffic protected by the Plane\" traffic; whereas, the [IP](#abbr_IP) traffic protected by the [IPsec](#abbr_IPsec) [VPN](#abbr_VPN) is referred to as \"Data Plane\" [IPsec](#abbr_IPsec) [VPN](#abbr_VPN) is referred to as \"Data Plane\" traffic. All \"Data Plane\" traffic must flow through the traffic. All \"Data Plane\" traffic must flow through the [VPN](#abbr_VPN) connection and the [VPN](#abbr_VPN) must not [VPN](#abbr_VPN) connection and the [VPN](#abbr_VPN) must not split-tunnel. "[IP](#abbr_IP) traffic needed for correct functioning of split-tunnel. "[IP](#abbr_IP) traffic needed for correct functioning of the [TOE](#abbr_TOE)" comprises traffic that would prevent the the [TOE](#abbr_TOE)" comprises traffic that would prevent the [TOE](#abbr_TOE) from proper operation if it was either blocked by or [TOE](#abbr_TOE) from proper operation if it was either blocked by or routed through the [VPN](#abbr_VPN). Enabling the [VPN](#abbr_VPN) means routed through the [VPN](#abbr_VPN). Enabling the [VPN](#abbr_VPN) means that the [VPN](#abbr_VPN) client has been activated by the user. If the that the [VPN](#abbr_VPN) client has been activated by the user. If the [VPN](#abbr_VPN) tunnel gets interrupted, then no "Data Plane" traffic [VPN](#abbr_VPN) tunnel gets interrupted, then no "Data Plane" traffic should be sent without the [VPN](#abbr_VPN) tunnel being re-established should be sent without the [VPN](#abbr_VPN) tunnel being re-established or the user disabling the [VPN](#abbr_VPN) client.\ or the user disabling the [VPN](#abbr_VPN) client.\ \ \ If no native [IPsec](#abbr_IPsec) client is validated or third-party If no native [IPsec](#abbr_IPsec) client is validated or third-party [VPN](#abbr_VPN) clients may also implement the required Information [VPN](#abbr_VPN) clients may also implement the required Information Flow Control, the first option must be selected. In these cases, the Flow Control, the first option must be selected. In these cases, the [TOE](#abbr_TOE) provides an [API](#abbr_API) to third-party [TOE](#abbr_TOE) provides an [API](#abbr_API) to third-party [VPN](#abbr_VPN) clients that allow them to configure the [VPN](#abbr_VPN) clients that allow them to configure the [TOE](#abbr_TOE)'s network stack to perform the required Information [TOE](#abbr_TOE)'s network stack to perform the required Information Flow Control.\ Flow Control.\ \ \ The [ST](#abbr_ST) author must select the second option if the The [ST](#abbr_ST) author must select the second option if the [TSF](#abbr_TSF) implements a native [VPN](#abbr_VPN) client [TSF](#abbr_TSF) implements a native [VPN](#abbr_VPN) client ([IPsec](#s-itc-ipsec) is selected in ([IPsec](#s-itc-ipsec) is selected in [FTP_ITC_EXT.1.1](#FTP_ITC_EXT.1.1)). Thus the [TSF](#abbr_TSF) must be [FTP_ITC_EXT.1.1](#FTP_ITC_EXT.1.1)). Thus the [TSF](#abbr_TSF) must be validated against the [PP-Module for Virtual Private Network (VPN) validated against the [PP-Module for Virtual Private Network (VPN) Clients, version 3.0](https://www.niap-ccevs.org/protectionprofiles/487) | Clients, version 3.0]() and the [ST](#abbr_ST) author must also include and the [ST](#abbr_ST) author must also include < [FDP_IFC_EXT.1]{.no-link} from the [PP-Module for Virtual Private [FDP_IFC_EXT.1]{.no-link} from the [PP-Module for Virtual Private Network (VPN) Clients, version | Network (VPN) Clients, version 3.0]().\ 3.0](https://www.niap-ccevs.org/protectionprofiles/487).\ < \ \ It is optional for the [VPN](#abbr_VPN) client to be configured to be It is optional for the [VPN](#abbr_VPN) client to be configured to be always-on per [FMT_SMF_EXT.1](#FMT_SMF_EXT.1) Function always-on per [FMT_SMF_EXT.1](#FMT_SMF_EXT.1) Function [45](#mf-alwaysOnVPN). Always-on means the establishment of an [45](#mf-alwaysOnVPN). Always-on means the establishment of an [IPsec](#abbr_IPsec) trusted channel to allow any communication by the [IPsec](#abbr_IPsec) trusted channel to allow any communication by the [TSF](#abbr_TSF). ]{.note} [TSF](#abbr_TSF). ]{.note} ::: ::: ::: ::: ::: ::: ::: {.activity_pane .hide} ::: {.activity_pane .hide} ::: activity_pane_header ::: activity_pane_header [[ Evaluation Activities [[ Evaluation Activities ]{.activity_pane_label}[]{.toggler}](#){onclick="toggle(this);return false;"} ]{.activity_pane_label}[]{.toggler}](#){onclick="toggle(this);return false;"} ::: ::: ::: activity_pane_body ::: activity_pane_body ::: component-activity-header ::: component-activity-header [FDP_IFC_EXT.1](#FDP_IFC_EXT.1) [FDP_IFC_EXT.1](#FDP_IFC_EXT.1) ::: ::: ::: eacategory ::: eacategory [TSS](#abbr_TSS) [TSS](#abbr_TSS) ::: ::: ::: ea ::: ea ::: ea ::: ea The evaluator shall verify that the [TSS](#abbr_TSS) section of the The evaluator shall verify that the [TSS](#abbr_TSS) section of the [ST](#abbr_ST) describes the routing of [IP](#abbr_IP) traffic through [ST](#abbr_ST) describes the routing of [IP](#abbr_IP) traffic through processes on the [TSF](#abbr_TSF) when a [VPN](#abbr_VPN) client is processes on the [TSF](#abbr_TSF) when a [VPN](#abbr_VPN) client is enabled. The evaluator shall ensure that the description indicates which enabled. The evaluator shall ensure that the description indicates which traffic does not go through the [VPN](#abbr_VPN) and which traffic does. traffic does not go through the [VPN](#abbr_VPN) and which traffic does. The evaluator shall verify that a configuration exists for each baseband The evaluator shall verify that a configuration exists for each baseband protocol in which only the traffic identified by the [ST](#abbr_ST) protocol in which only the traffic identified by the [ST](#abbr_ST) author as necessary for establishing the [VPN](#abbr_VPN) connection author as necessary for establishing the [VPN](#abbr_VPN) connection (IKE traffic and perhaps [HTTPS](#abbr_HTTPS) or [DNS](#abbr_DNS) (IKE traffic and perhaps [HTTPS](#abbr_HTTPS) or [DNS](#abbr_DNS) traffic) or needed for the correct functioning of the [TOE](#abbr_TOE) traffic) or needed for the correct functioning of the [TOE](#abbr_TOE) is not encapsulated by the [VPN](#abbr_VPN) protocol is not encapsulated by the [VPN](#abbr_VPN) protocol ([IPsec](#abbr_IPsec)). The evaluator shall verify that the ([IPsec](#abbr_IPsec)). The evaluator shall verify that the [TSS](#abbr_TSS) section describes any differences in the routing of [TSS](#abbr_TSS) section describes any differences in the routing of [IP](#abbr_IP) traffic when using any supported baseband protocols (e.g. [IP](#abbr_IP) traffic when using any supported baseband protocols (e.g. Wi-Fi or, [LTE](#abbr_LTE)).\ Wi-Fi or, [LTE](#abbr_LTE)).\ \ \ ::: ::: ::: ::: ::: eacategory ::: eacategory Guidance Guidance ::: ::: ::: ea ::: ea ::: ea ::: ea The evaluator shall verify that one (or more) of the following options The evaluator shall verify that one (or more) of the following options is addressed by the documentation:\ is addressed by the documentation:\ - The description above indicates that if a [VPN](#abbr_VPN) client is - The description above indicates that if a [VPN](#abbr_VPN) client is enabled, all configurations route all Data Plane traffic through the enabled, all configurations route all Data Plane traffic through the tunnel interface established by the [VPN](#abbr_VPN) client. tunnel interface established by the [VPN](#abbr_VPN) client. - The AGD guidance describes how the user or administrator can - The AGD guidance describes how the user or administrator can configure the [TSF](#abbr_TSF) to meet this requirement. configure the [TSF](#abbr_TSF) to meet this requirement. - The [API](#abbr_API) documentation includes a security function that - The [API](#abbr_API) documentation includes a security function that allows a [VPN](#abbr_VPN) client to specify this routing. allows a [VPN](#abbr_VPN) client to specify this routing. \ \ ::: ::: ::: ::: ::: eacategory ::: eacategory Tests Tests ::: ::: ::: ea ::: ea ::: ea ::: ea []{.testlist-} []{.testlist-} - [Test FDP_IFC_EXT.1:1](#_t_27){#_t_27 .defined}: If the - [Test FDP_IFC_EXT.1:1](#_t_27){#_t_27 .defined}: If the [ST](#abbr_ST) author identifies any differences in the routing [ST](#abbr_ST) author identifies any differences in the routing between Wi-Fi and cellular protocols, the evaluator shall repeat between Wi-Fi and cellular protocols, the evaluator shall repeat this test with a base station implementing one of the identified this test with a base station implementing one of the identified cellular protocols.\ cellular protocols.\ \ \ Step 1: The evaluator shall enable a Wi-Fi configuration as Step 1: The evaluator shall enable a Wi-Fi configuration as described in the AGD guidance (as required by described in the AGD guidance (as required by [FTP_ITC_EXT.1](#FTP_ITC_EXT.1)). The evaluator shall use a packet [FTP_ITC_EXT.1](#FTP_ITC_EXT.1)). The evaluator shall use a packet sniffing tool between the wireless access point and an sniffing tool between the wireless access point and an Internet-connected network. The evaluator shall turn on the sniffing Internet-connected network. The evaluator shall turn on the sniffing tool and perform actions with the device such as navigating to tool and perform actions with the device such as navigating to websites, using provided applications, and accessing other Internet websites, using provided applications, and accessing other Internet resources. The evaluator shall verify that the sniffing tool resources. The evaluator shall verify that the sniffing tool captures the traffic generated by these actions, turn off the captures the traffic generated by these actions, turn off the sniffing tool, and save the session data.\ sniffing tool, and save the session data.\ \ \ Step 2: The evaluator shall configure an [IPsec](#abbr_IPsec) Step 2: The evaluator shall configure an [IPsec](#abbr_IPsec) [VPN](#abbr_VPN) client that supports the routing specified in this [VPN](#abbr_VPN) client that supports the routing specified in this requirement, and if necessary, configure the device to perform the requirement, and if necessary, configure the device to perform the routing specified as described in the AGD guidance. The evaluator routing specified as described in the AGD guidance. The evaluator shall ensure the test network is capable of sending any traffic shall ensure the test network is capable of sending any traffic identified as exceptions. The evaluator shall turn on the sniffing identified as exceptions. The evaluator shall turn on the sniffing tool, establish the [VPN](#abbr_VPN) connection, and perform the tool, establish the [VPN](#abbr_VPN) connection, and perform the same actions with the device as performed in the first step, as well same actions with the device as performed in the first step, as well as ensuring that all exception traffic is generated. The evaluator as ensuring that all exception traffic is generated. The evaluator shall verify that the sniffing tool captures traffic generated by shall verify that the sniffing tool captures traffic generated by these actions, turn off the sniffing tool, and save the session these actions, turn off the sniffing tool, and save the session data.\ data.\ \ \ Step 3: The evaluator shall examine the traffic from both step one Step 3: The evaluator shall examine the traffic from both step one and step two to verify that all Data Plane traffic is encapsulated and step two to verify that all Data Plane traffic is encapsulated by [IPsec](#abbr_IPsec), except for any exceptions identified in the by [IPsec](#abbr_IPsec), except for any exceptions identified in the [SFR](#abbr_SFR) (if applicable). For each exception listed in the [SFR](#abbr_SFR) (if applicable). For each exception listed in the [SFR](#abbr_SFR), the evaluator shall verify that traffic is allowed [SFR](#abbr_SFR), the evaluator shall verify that traffic is allowed outside of the [VPN](#abbr_VPN) tunnel. The evaluator shall examine outside of the [VPN](#abbr_VPN) tunnel. The evaluator shall examine the Security Parameter Index ([SPI](#abbr_SPI)) value present in the the Security Parameter Index ([SPI](#abbr_SPI)) value present in the encapsulated packets captured in Step two from the [TOE](#abbr_TOE) encapsulated packets captured in Step two from the [TOE](#abbr_TOE) to the Gateway and shall verify this value is the same for all to the Gateway and shall verify this value is the same for all actions used to generate traffic through the [VPN](#abbr_VPN). Note actions used to generate traffic through the [VPN](#abbr_VPN). Note that it is expected that the [SPI](#abbr_SPI) value for packets from that it is expected that the [SPI](#abbr_SPI) value for packets from the Gateway to the [TOE](#abbr_TOE) is different than the the Gateway to the [TOE](#abbr_TOE) is different than the [SPI](#abbr_SPI) value for packets from the [TOE](#abbr_TOE) to the [SPI](#abbr_SPI) value for packets from the [TOE](#abbr_TOE) to the Gateway. The evaluator shall be aware that [IP](#abbr_IP) traffic on Gateway. The evaluator shall be aware that [IP](#abbr_IP) traffic on the cellular baseband outside of the [IPsec](#abbr_IPsec) tunnel may the cellular baseband outside of the [IPsec](#abbr_IPsec) tunnel may be emanating from the baseband processor and shall verify with the be emanating from the baseband processor and shall verify with the manufacturer that any identified traffic is not emanating from the manufacturer that any identified traffic is not emanating from the application processor.\ application processor.\ \ \ Step 4: (Conditional: If ICMP is not listed as part of the Step 4: (Conditional: If ICMP is not listed as part of the [IP](#abbr_IP) traffic needed for the correct functioning of the [IP](#abbr_IP) traffic needed for the correct functioning of the [TOE](#abbr_TOE)) The evaluator shall perform an ICMP echo from the [TOE](#abbr_TOE)) The evaluator shall perform an ICMP echo from the [TOE](#abbr_TOE) to the [IP](#abbr_IP) address of another device on [TOE](#abbr_TOE) to the [IP](#abbr_IP) address of another device on the local wireless network and shall verify that no packets are sent the local wireless network and shall verify that no packets are sent using the sniffing tool. The evaluator shall attempt to send packets using the sniffing tool. The evaluator shall attempt to send packets to the [TOE](#abbr_TOE) outside the [VPN](#abbr_VPN) tunnel (i.e., to the [TOE](#abbr_TOE) outside the [VPN](#abbr_VPN) tunnel (i.e., not through the [VPN](#abbr_VPN) gateway), including from the local not through the [VPN](#abbr_VPN) gateway), including from the local wireless network, and shall verify that the [TOE](#abbr_TOE) wireless network, and shall verify that the [TOE](#abbr_TOE) discards them. discards them. ::: ::: ::: ::: ::: ::: ::: ::: ::: ::: ::: {#FDP_STG_EXT.1 .comp} ::: {#FDP_STG_EXT.1 .comp} #### FDP_STG_EXT.1 User Data Storage #### FDP_STG_EXT.1 User Data Storage ::: element ::: element ::: {#FDP_STG_EXT.1.1 .reqid} ::: {#FDP_STG_EXT.1.1 .reqid} [FDP_STG_EXT.1.1](#FDP_STG_EXT.1.1){.abbr} [FDP_STG_EXT.1.1](#FDP_STG_EXT.1.1){.abbr} ::: ::: ::: reqdesc ::: reqdesc The [TSF](#abbr_TSF) shall provide protected storage for the Trust The [TSF](#abbr_TSF) shall provide protected storage for the Trust Anchor Database. Anchor Database. ::: ::: ::: ::: ::: {.activity_pane .hide} ::: {.activity_pane .hide} ::: activity_pane_header ::: activity_pane_header [[ Evaluation Activities [[ Evaluation Activities ]{.activity_pane_label}[]{.toggler}](#){onclick="toggle(this);return false;"} ]{.activity_pane_label}[]{.toggler}](#){onclick="toggle(this);return false;"} ::: ::: ::: activity_pane_body ::: activity_pane_body ::: component-activity-header ::: component-activity-header [FDP_STG_EXT.1](#FDP_STG_EXT.1) [FDP_STG_EXT.1](#FDP_STG_EXT.1) ::: ::: ::: eacategory ::: eacategory [TSS](#abbr_TSS) [TSS](#abbr_TSS) ::: ::: ::: ea ::: ea ::: ea ::: ea The evaluator shall ensure the [TSS](#abbr_TSS) describes the Trust The evaluator shall ensure the [TSS](#abbr_TSS) describes the Trust Anchor Database implemented that contain certificates used to meet the Anchor Database implemented that contain certificates used to meet the requirements of this [PP](#abbr_PP). This description shall contain requirements of this [PP](#abbr_PP). This description shall contain information pertaining to how certificates are loaded into the store, information pertaining to how certificates are loaded into the store, and how the store is protected from unauthorized access (for example, and how the store is protected from unauthorized access (for example, UNIX permissions) in accordance with the permissions established in UNIX permissions) in accordance with the permissions established in [FMT_SMF_EXT.1](#FMT_SMF_EXT.1) and [FMT_SMF_EXT.1](#FMT_SMF_EXT.1) and [FMT_MOF_EXT.1.1](#FMT_MOF_EXT.1.1).\ [FMT_MOF_EXT.1.1](#FMT_MOF_EXT.1.1).\ \ \ ::: ::: ::: ::: ::: eacategory ::: eacategory Guidance Guidance ::: ::: ::: ea ::: ea ::: ea ::: ea There are no guidance evaluation activities for this component.\ There are no guidance evaluation activities for this component.\ \ \ ::: ::: ::: ::: ::: eacategory ::: eacategory Tests Tests ::: ::: ::: ea ::: ea ::: ea ::: ea There are no test evaluation activities for this component. There are no test evaluation activities for this component. ::: ::: ::: ::: ::: ::: ::: ::: ::: ::: ::: {#FDP_UPC_EXT.1/APPS .comp} ::: {#FDP_UPC_EXT.1/APPS .comp} #### FDP_UPC_EXT.1/APPS Inter-TSF User Data Transfer Protection (Applications) #### FDP_UPC_EXT.1/APPS Inter-TSF User Data Transfer Protection (Applications) ::: element ::: element ::: {#FDP_UPC_EXT.1.1/APPS .reqid} ::: {#FDP_UPC_EXT.1.1/APPS .reqid} [FDP_UPC_EXT.1.1/APPS](#FDP_UPC_EXT.1.1/APPS){.abbr} [FDP_UPC_EXT.1.1/APPS](#FDP_UPC_EXT.1.1/APPS){.abbr} ::: ::: ::: reqdesc ::: reqdesc The [TSF](#abbr_TSF) shall provide a means for non-TSF applications The [TSF](#abbr_TSF) shall provide a means for non-TSF applications executing on the [TOE](#abbr_TOE) to use \[ executing on the [TOE](#abbr_TOE) to use \[ - Mutually authenticated [TLS](#abbr_TLS) as defined in the - Mutually authenticated [TLS](#abbr_TLS) as defined in the [Functional Package for Transport Layer Security (TLS), version [Functional Package for Transport Layer Security (TLS), version 2.1](https://www.niap-ccevs.org/static_html/protection-profile/519), 2.1](https://www.niap-ccevs.org/static_html/protection-profile/519), - [HTTPS](#abbr_HTTPS), - [HTTPS](#abbr_HTTPS), and \[**selection**: and \[**selection**: - [mutually authenticated [DTLS](#abbr_DTLS) as defined in the - [mutually authenticated [DTLS](#abbr_DTLS) as defined in the [Functional Package for Transport Layer Security (TLS), version [Functional Package for Transport Layer Security (TLS), version 2.1](https://www.niap-ccevs.org/static_html/protection-profile/519)]{#upc_dtls 2.1](https://www.niap-ccevs.org/static_html/protection-profile/519)]{#upc_dtls .selectable-content} .selectable-content} - [[IPsec](#abbr_IPsec) as defined in the [PP-Module for Virtual - [[IPsec](#abbr_IPsec) as defined in the [PP-Module for Virtual Private Network (VPN) Clients, version | Private Network (VPN) Clients, version 3.0]()]{#s-upc-ipsec 3.0](https://www.niap-ccevs.org/protectionprofiles/487)]{#s-upc-ipsec < .selectable-content} .selectable-content} - [no other protocol]{#_s_500 .selectable-content} | - [no other protocol]{#fdp_upc_ext.1.1_APPS_1 .selectable-content} \] \] to provide a protected communication channel between the non-TSF | \]\] to provide a protected communication channel between the non-TSF application and another IT product that is logically distinct from other application and another IT product that is logically distinct from other communication channels, provides assured identification of its end communication channels, provides assured identification of its end points, protects channel data from disclosure, and detects modification points, protects channel data from disclosure, and detects modification of the channel data. of the channel data. ::: appnote ::: appnote [Application Note: ]{.note-header}[ The intent of this requirement is [Application Note: ]{.note-header}[ The intent of this requirement is that one of the selected protocols is available for use by user that one of the selected protocols is available for use by user applications running on the device for use in connecting to distant-end applications running on the device for use in connecting to distant-end services that are not necessarily part of the enterprise infrastructure. services that are not necessarily part of the enterprise infrastructure. It should be noted that the [FTP_ITC_EXT.1](#FTP_ITC_EXT.1) requires It should be noted that the [FTP_ITC_EXT.1](#FTP_ITC_EXT.1) requires that all [TSF](#abbr_TSF) communications be protected using the that all [TSF](#abbr_TSF) communications be protected using the protocols indicated in that requirement, so the protocols required by protocols indicated in that requirement, so the protocols required by this component ride \"on top of\" those listed in this component ride \"on top of\" those listed in [FTP_ITC_EXT.1](#FTP_ITC_EXT.1).\ [FTP_ITC_EXT.1](#FTP_ITC_EXT.1).\ \ \ It should also be noted that some applications are part of the It should also be noted that some applications are part of the [TSF](#abbr_TSF), and [FTP_ITC_EXT.1](#FTP_ITC_EXT.1) requires that [TSF](#abbr_TSF), and [FTP_ITC_EXT.1](#FTP_ITC_EXT.1) requires that [TSF](#abbr_TSF) applications be protected by at least one of the [TSF](#abbr_TSF) applications be protected by at least one of the protocols in first selection in [FTP_ITC_EXT.1](#FTP_ITC_EXT.1). It is protocols in first selection in [FTP_ITC_EXT.1](#FTP_ITC_EXT.1). It is not required to have two different implementations of a protocol, or two not required to have two different implementations of a protocol, or two different protocols, to satisfy both this requirement (for non-TSF apps) different protocols, to satisfy both this requirement (for non-TSF apps) and [FTP_ITC_EXT.1](#FTP_ITC_EXT.1) (for [TSF](#abbr_TSF) apps), as long and [FTP_ITC_EXT.1](#FTP_ITC_EXT.1) (for [TSF](#abbr_TSF) apps), as long as the services specified are provided.\ as the services specified are provided.\ \ \ The [ST](#abbr_ST) author must list which trusted channel protocols are The [ST](#abbr_ST) author must list which trusted channel protocols are implemented by the Mobile Device for use by non-TSF apps.\ implemented by the Mobile Device for use by non-TSF apps.\ \ \ The [TSF](#abbr_TSF) must be validated against FCS_TLSC_EXT requirements The [TSF](#abbr_TSF) must be validated against FCS_TLSC_EXT requirements from the [Functional Package for Transport Layer Security (TLS), version from the [Functional Package for Transport Layer Security (TLS), version 2.1](https://www.niap-ccevs.org/static_html/protection-profile/519), 2.1](https://www.niap-ccevs.org/static_html/protection-profile/519), with the claims from that package made for those requirements as with the claims from that package made for those requirements as specified in [Section 1.7 Package Usage](#package-usage){.dynref}.\ specified in [Section 1.7 Package Usage](#package-usage){.dynref}.\ If [mutually authenticated DTLS as defined in the](#upc_dtls) If [mutually authenticated DTLS as defined in the](#upc_dtls) [Functional Package for Transport Layer Security (TLS), version [Functional Package for Transport Layer Security (TLS), version 2.1](https://www.niap-ccevs.org/static_html/protection-profile/519) is 2.1](https://www.niap-ccevs.org/static_html/protection-profile/519) is selected, the [TSF](#abbr_TSF) must be validated against FCS_DTLS_EXT selected, the [TSF](#abbr_TSF) must be validated against FCS_DTLS_EXT requirements from the [Functional Package for Transport Layer Security requirements from the [Functional Package for Transport Layer Security (TLS), version (TLS), version 2.1](https://www.niap-ccevs.org/static_html/protection-profile/519), 2.1](https://www.niap-ccevs.org/static_html/protection-profile/519), with the claims from that package made for those requirements as with the claims from that package made for those requirements as specified in [Section 1.7 Package Usage](#package-usage){.dynref}.\ specified in [Section 1.7 Package Usage](#package-usage){.dynref}.\ If the [ST](#abbr_ST) author selects [IPsec as defined in If the [ST](#abbr_ST) author selects [IPsec as defined in the](#s-upc-ipsec) [PP-Module for Virtual Private Network (VPN) Clients, the](#s-upc-ipsec) [PP-Module for Virtual Private Network (VPN) Clients, version 3.0](https://www.niap-ccevs.org/protectionprofiles/487), the | version 3.0](), the [TSF](#abbr_TSF) must be validated against the [TSF](#abbr_TSF) must be validated against the [PP-Module for Virtual | [PP-Module for Virtual Private Network (VPN) Clients, version 3.0](). Private Network (VPN) Clients, version | ]{.note} 3.0](https://www.niap-ccevs.org/protectionprofiles/487). ]{.note} < ::: ::: ::: ::: ::: ::: ::: element ::: element ::: {#FDP_UPC_EXT.1.2/APPS .reqid} ::: {#FDP_UPC_EXT.1.2/APPS .reqid} [FDP_UPC_EXT.1.2/APPS](#FDP_UPC_EXT.1.2/APPS){.abbr} [FDP_UPC_EXT.1.2/APPS](#FDP_UPC_EXT.1.2/APPS){.abbr} ::: ::: ::: reqdesc ::: reqdesc The [TSF](#abbr_TSF) shall permit the non-TSF applications to initiate The [TSF](#abbr_TSF) shall permit the non-TSF applications to initiate communication via the trusted channel. communication via the trusted channel. ::: ::: ::: ::: ::: {.activity_pane .hide} ::: {.activity_pane .hide} ::: activity_pane_header ::: activity_pane_header [[ Evaluation Activities [[ Evaluation Activities ]{.activity_pane_label}[]{.toggler}](#){onclick="toggle(this);return false;"} ]{.activity_pane_label}[]{.toggler}](#){onclick="toggle(this);return false;"} ::: ::: ::: activity_pane_body ::: activity_pane_body ::: component-activity-header ::: component-activity-header [FDP_UPC_EXT.1/APPS](#FDP_UPC_EXT.1/APPS) [FDP_UPC_EXT.1/APPS](#FDP_UPC_EXT.1/APPS) ::: ::: ::: eacategory ::: eacategory [TSS](#abbr_TSS) [TSS](#abbr_TSS) ::: ::: ::: ea ::: ea ::: ea ::: ea The evaluator shall verify that the [API](#abbr_API) documentation The evaluator shall verify that the [API](#abbr_API) documentation provided in the [TSS](#abbr_TSS) (or other documentation) includes the provided in the [TSS](#abbr_TSS) (or other documentation) includes the security functions (protection channel) described in these requirements, security functions (protection channel) described in these requirements, and verify that the APIs implemented to support this requirement include and verify that the APIs implemented to support this requirement include the appropriate settings/parameters so that the application can both the appropriate settings/parameters so that the application can both provide and obtain the information needed to assure mutual provide and obtain the information needed to assure mutual identification of the endpoints of the communication as required by this identification of the endpoints of the communication as required by this component. component. The evaluator shall examine the [TSS](#abbr_TSS) to determine that it The evaluator shall examine the [TSS](#abbr_TSS) to determine that it describes that all protocols listed in the [TSS](#abbr_TSS) are describes that all protocols listed in the [TSS](#abbr_TSS) are specified and included in the requirements in the [ST](#abbr_ST).\ specified and included in the requirements in the [ST](#abbr_ST).\ \ \ ::: ::: ::: ::: ::: eacategory ::: eacategory Guidance Guidance ::: ::: ::: ea ::: ea ::: ea ::: ea The evaluator shall confirm that the operational guidance contains The evaluator shall confirm that the operational guidance contains instructions necessary for configuring the protocols selected for use by instructions necessary for configuring the protocols selected for use by the applications.\ the applications.\ \ \ ::: ::: ::: ::: ::: eacategory ::: eacategory Tests Tests ::: ::: ::: ea ::: ea ::: ea ::: ea **Evaluation Activity Note:** The following test requires the developer **Evaluation Activity Note:** The following test requires the developer to provide access to a test platform that provides the evaluator with to provide access to a test platform that provides the evaluator with tools that are typically not found on consumer Mobile Device products.\ tools that are typically not found on consumer Mobile Device products.\ \ \ The evaluator shall perform the following tests: []{.testlist-} The evaluator shall perform the following tests: []{.testlist-} - [Test FDP_UPC_EXT.1/APPS:1](#_t_28){#_t_28 .defined}: The evaluator - [Test FDP_UPC_EXT.1/APPS:1](#_t_28){#_t_28 .defined}: The evaluator shall write, or the developer shall provide access to, an shall write, or the developer shall provide access to, an application that requests protected channel services by the application that requests protected channel services by the [TSF](#abbr_TSF). The evaluator shall verify that the results from [TSF](#abbr_TSF). The evaluator shall verify that the results from the protected channel match the expected results according to the the protected channel match the expected results according to the [API](#abbr_API) documentation. This application may be used to [API](#abbr_API) documentation. This application may be used to assist in verifying the protected channel Evaluation Activities for assist in verifying the protected channel Evaluation Activities for the protocol requirements. the protocol requirements. - [Test FDP_UPC_EXT.1/APPS:2](#_t_29){#_t_29 .defined}: The evaluator - [Test FDP_UPC_EXT.1/APPS:2](#_t_29){#_t_29 .defined}: The evaluator shall ensure that the application is able to initiate communications shall ensure that the application is able to initiate communications with an external IT entity using each protocol specified in the with an external IT entity using each protocol specified in the requirement, setting up the connections as described in the requirement, setting up the connections as described in the operational guidance and ensuring that communication is successful. operational guidance and ensuring that communication is successful. - [Test FDP_UPC_EXT.1/APPS:3](#_t_30){#_t_30 .defined}: The evaluator - [Test FDP_UPC_EXT.1/APPS:3](#_t_30){#_t_30 .defined}: The evaluator shall ensure, for each communication channel with an authorized IT shall ensure, for each communication channel with an authorized IT entity, the channel data are not sent in plaintext. entity, the channel data are not sent in plaintext. ::: ::: ::: ::: ::: ::: ::: ::: ::: ::: ### 5.1.5 Class FIA: Identification and Authentication {#fia .indexable level="3"} ### 5.1.5 Class FIA: Identification and Authentication {#fia .indexable level="3"} ::: {#FIA_AFL_EXT.1 .comp} ::: {#FIA_AFL_EXT.1 .comp} #### FIA_AFL_EXT.1 Authentication Failure Handling #### FIA_AFL_EXT.1 Authentication Failure Handling ::: element ::: element ::: {#FIA_AFL_EXT.1.1 .reqid} ::: {#FIA_AFL_EXT.1.1 .reqid} [FIA_AFL_EXT.1.1](#FIA_AFL_EXT.1.1){.abbr} [FIA_AFL_EXT.1.1](#FIA_AFL_EXT.1.1){.abbr} ::: ::: ::: reqdesc ::: reqdesc The [TSF](#abbr_TSF) shall consider password and \[**selection**: [ | The [TSF](#abbr_TSF) shall consider password and \[**selection**: biometric in accordance with the [cPP-Module for Biometric Enrollment | [biometric in accordance with the [cPP-Module for Biometric Enrollment and Verification, version and Verification, version 2.0](https://github.com/biometricITC/cPP-biometrics/blob/master/Protection%20Profile/ | 2.0](https://github.com/biometricITC/cPP-biometrics/blob/master/Protection%20Profile/ .selectable-content}, [ hybrid]{#_s_502 .selectable-content}, [ no other | .selectable-content}, [hybrid]{#fia_afl_ext.1.1_2 .selectable-content}, mechanism]{#s-authfail-noother .selectable-content}\] as critical | [no other mechanism]{#s-authfail-noother .selectable-content}\] as authentication mechanisms. | critical authentication mechanisms. ::: appnote ::: appnote [Application Note: ]{.note-header}[A critical authentication mechanism | [Application Note: ]{.note-header}[ A critical authentication mechanism is one in which countermeasures are triggered (i.e., wipe of the device) is one in which countermeasures are triggered (i.e., wipe of the device) when the maximum number of unsuccessful authentication attempts is when the maximum number of unsuccessful authentication attempts is exceeded, rendering the other factors unavailable.\ exceeded, rendering the other factors unavailable.\ \ \ If no additional authentication mechanisms are selected in If no additional authentication mechanisms are selected in [FIA_UAU.5.1](#FIA_UAU.5.1), then [no other [FIA_UAU.5.1](#FIA_UAU.5.1), then [no other mechanism](#s-authfail-noother) must be selected. If an additional mechanism](#s-authfail-noother) must be selected. If an additional authentication mechanism is selected in [FIA_UAU.5.1](#FIA_UAU.5.1), authentication mechanism is selected in [FIA_UAU.5.1](#FIA_UAU.5.1), then it must only be selected in [FIA_AFL_EXT.1.1](#FIA_AFL_EXT.1.1) if then it must only be selected in [FIA_AFL_EXT.1.1](#FIA_AFL_EXT.1.1) if surpassing the authentication failure threshold for biometric data surpassing the authentication failure threshold for biometric data causes a countermeasure to be triggered regardless of the failure status causes a countermeasure to be triggered regardless of the failure status of the other authentication mechanisms.\ of the other authentication mechanisms.\ \ \ If the [TOE](#abbr_TOE) implements multiple Authentication Factor If the [TOE](#abbr_TOE) implements multiple Authentication Factor interfaces (for example, a [DAR](#abbr_DAR) decryption interface, a lock interfaces (for example, a [DAR](#abbr_DAR) decryption interface, a lock screen interface, an auxiliary boot mode interface), this component screen interface, an auxiliary boot mode interface), this component applies to all available interfaces. For example, a password is a applies to all available interfaces. For example, a password is a critical authentication mechanism regardless of if it is being entered critical authentication mechanism regardless of if it is being entered at the [DAR](#abbr_DAR) decryption interface or at a lock screen at the [DAR](#abbr_DAR) decryption interface or at a lock screen interface. ]{.note} interface. ]{.note} ::: ::: ::: ::: ::: ::: ::: element ::: element ::: {#FIA_AFL_EXT.1.2 .reqid} ::: {#FIA_AFL_EXT.1.2 .reqid} [FIA_AFL_EXT.1.2](#FIA_AFL_EXT.1.2){.abbr} [FIA_AFL_EXT.1.2](#FIA_AFL_EXT.1.2){.abbr} ::: ::: ::: reqdesc ::: reqdesc The [TSF](#abbr_TSF) shall detect when a configurable positive integer The [TSF](#abbr_TSF) shall detect when a configurable positive integer within \[**assignment**: [range of acceptable values for each within \[**assignment**: [range of acceptable values for each authentication mechanism]{.assignable-content}\] of \[**selection**: authentication mechanism]{.assignable-content}\] of \[**selection**: [unique]{#s-authfail-num-unique .selectable-content}, [unique]{#s-authfail-num-unique .selectable-content}, [non-unique]{#s-authfail-num-non-unique .selectable-content}\] [non-unique]{#s-authfail-num-non-unique .selectable-content}\] unsuccessful authentication attempts occur related to last successful unsuccessful authentication attempts occur related to last successful authentication for each authentication mechanism. authentication for each authentication mechanism. ::: appnote ::: appnote [Application Note: ]{.note-header}[The positive integer is configured | [Application Note: ]{.note-header}[ The positive integer is configured according to [FMT_SMF_EXT.1.1](#FMT_SMF_EXT.1.1) function according to [FMT_SMF_EXT.1.1](#FMT_SMF_EXT.1.1) function [2](#mf-screenlock).\ [2](#mf-screenlock).\ \ \ An unique authentication attempt is defined as any attempt to verify a An unique authentication attempt is defined as any attempt to verify a password or biometric sample, in which the input is different from a password or biometric sample, in which the input is different from a previous attempt. \"[unique](#s-authfail-num-unique)\" must be selected previous attempt. \"[unique](#s-authfail-num-unique)\" must be selected if the authentication system increments the counter only for unique if the authentication system increments the counter only for unique unsuccessful authentication attempts. For example, if the same incorrect unsuccessful authentication attempts. For example, if the same incorrect password is attempted twice the authentication system increments the password is attempted twice the authentication system increments the counter once. \"[non-unique](#s-authfail-num-non-unique)\" must be counter once. \"[non-unique](#s-authfail-num-non-unique)\" must be selected if the authentication system increments the counter for each selected if the authentication system increments the counter for each unsuccessful authentication attempt, regardless of if the input is unsuccessful authentication attempt, regardless of if the input is unique. For example, if the same incorrect password is attempted twice unique. For example, if the same incorrect password is attempted twice the authentication system increments the counter twice.\ the authentication system increments the counter twice.\ \ \ If hybrid authentication (i.e., a combination of biometric and If hybrid authentication (i.e., a combination of biometric and pin/password) is supported, a failed authentication attempt can be pin/password) is supported, a failed authentication attempt can be counted as a single attempt, even if both the biometric and pin/password counted as a single attempt, even if both the biometric and pin/password were incorrect.\ were incorrect.\ \ \ If the [TOE](#abbr_TOE) supports multiple authentication mechanisms per If the [TOE](#abbr_TOE) supports multiple authentication mechanisms per [FIA_UAU.5.1](#FIA_UAU.5.1), this component applies to all [FIA_UAU.5.1](#FIA_UAU.5.1), this component applies to all authentication mechanisms. It is acceptable for each authentication authentication mechanisms. It is acceptable for each authentication mechanism to utilize an independent counter or for multiple mechanism to utilize an independent counter or for multiple authentication mechanisms to utilize a shared counter. The interaction authentication mechanisms to utilize a shared counter. The interaction between the authentication factors in regards to the authentication between the authentication factors in regards to the authentication counter must be in accordance with [FIA_UAU.5.2](#FIA_UAU.5.2).\ counter must be in accordance with [FIA_UAU.5.2](#FIA_UAU.5.2).\ \ \ If the [TOE](#abbr_TOE) implements multiple Authentication Factor If the [TOE](#abbr_TOE) implements multiple Authentication Factor interfaces (for example, a [DAR](#abbr_DAR) decryption interface, a lock interfaces (for example, a [DAR](#abbr_DAR) decryption interface, a lock screen interface, an auxiliary boot mode interface), this component screen interface, an auxiliary boot mode interface), this component applies to all available interfaces. However, it is acceptable for each applies to all available interfaces. However, it is acceptable for each Authentication Factor interface to be configurable with a different Authentication Factor interface to be configurable with a different number of unsuccessful authentication attempts. ]{.note} number of unsuccessful authentication attempts. ]{.note} ::: ::: ::: ::: ::: ::: ::: element ::: element ::: {#FIA_AFL_EXT.1.3 .reqid} ::: {#FIA_AFL_EXT.1.3 .reqid} [FIA_AFL_EXT.1.3](#FIA_AFL_EXT.1.3){.abbr} [FIA_AFL_EXT.1.3](#FIA_AFL_EXT.1.3){.abbr} ::: ::: ::: reqdesc ::: reqdesc The [TSF](#abbr_TSF) shall maintain the number of unsuccessful The [TSF](#abbr_TSF) shall maintain the number of unsuccessful authentication attempts that have occurred upon power off. authentication attempts that have occurred upon power off. ::: appnote ::: appnote [Application Note: ]{.note-header}[The [TOE](#abbr_TOE) may implement an [Application Note: ]{.note-header}[The [TOE](#abbr_TOE) may implement an Authentication Factor interface that precedes another Authentication Authentication Factor interface that precedes another Authentication Factor interface in the boot sequence (for example, a volume Factor interface in the boot sequence (for example, a volume [DAR](#abbr_DAR) decryption interface which precedes the lock screen [DAR](#abbr_DAR) decryption interface which precedes the lock screen interface) before the user can access the device. In this situation, interface) before the user can access the device. In this situation, because the user must successfully authenticate to the first interface because the user must successfully authenticate to the first interface to access the second, the number of unsuccessful authentication attempts to access the second, the number of unsuccessful authentication attempts need not be maintained for the second interface.]{.note} need not be maintained for the second interface.]{.note} ::: ::: ::: ::: ::: ::: ::: element ::: element ::: {#FIA_AFL_EXT.1.4 .reqid} ::: {#FIA_AFL_EXT.1.4 .reqid} [FIA_AFL_EXT.1.4](#FIA_AFL_EXT.1.4){.abbr} [FIA_AFL_EXT.1.4](#FIA_AFL_EXT.1.4){.abbr} ::: ::: ::: reqdesc ::: reqdesc When the defined number of unsuccessful authentication attempts has When the defined number of unsuccessful authentication attempts has exceeded the maximum allowed for a given authentication mechanism, all exceeded the maximum allowed for a given authentication mechanism, all future authentication attempts will be limited to other available future authentication attempts will be limited to other available authentication mechanisms, unless the given mechanism is designated as a authentication mechanisms, unless the given mechanism is designated as a critical authentication mechanism. critical authentication mechanism. ::: appnote ::: appnote [Application Note: ]{.note-header}[In accordance with [Application Note: ]{.note-header}[In accordance with [FIA_AFL_EXT.1.3](#FIA_AFL_EXT.1.3), this requirement also applies after [FIA_AFL_EXT.1.3](#FIA_AFL_EXT.1.3), this requirement also applies after the [TOE](#abbr_TOE) is powered off and powered back on. ]{.note} | the [TOE](#abbr_TOE) is powered off and powered back on.]{.note} ::: ::: ::: ::: ::: ::: ::: element ::: element ::: {#FIA_AFL_EXT.1.5 .reqid} ::: {#FIA_AFL_EXT.1.5 .reqid} [FIA_AFL_EXT.1.5](#FIA_AFL_EXT.1.5){.abbr} [FIA_AFL_EXT.1.5](#FIA_AFL_EXT.1.5){.abbr} ::: ::: ::: reqdesc ::: reqdesc When the defined number of unsuccessful authentication attempts for the When the defined number of unsuccessful authentication attempts for the last available authentication mechanism or single critical last available authentication mechanism or single critical authentication mechanism has been surpassed, the [TSF](#abbr_TSF) shall authentication mechanism has been surpassed, the [TSF](#abbr_TSF) shall perform a wipe of all protected data. perform a wipe of all protected data. ::: appnote ::: appnote [Application Note: ]{.note-header}[Wipe is performed in accordance with | [Application Note: ]{.note-header}[ Wipe is performed in accordance with [FCS_CKM_EXT.5](#FCS_CKM_EXT.5). Protected data is all non-TSF data, [FCS_CKM_EXT.5](#FCS_CKM_EXT.5). Protected data is all non-TSF data, including all user or enterprise data. Some or all of this data may be including all user or enterprise data. Some or all of this data may be considered sensitive data as well.\ considered sensitive data as well.\ \ \ If the [TOE](#abbr_TOE) implements multiple Authentication Factor If the [TOE](#abbr_TOE) implements multiple Authentication Factor interfaces (for example, a [DAR](#abbr_DAR) decryption interface, a lock interfaces (for example, a [DAR](#abbr_DAR) decryption interface, a lock screen interface, an auxiliary boot mode interface), this component screen interface, an auxiliary boot mode interface), this component applies to all available interfaces. ]{.note} applies to all available interfaces. ]{.note} ::: ::: ::: ::: ::: ::: ::: element ::: element ::: {#FIA_AFL_EXT.1.6 .reqid} ::: {#FIA_AFL_EXT.1.6 .reqid} [FIA_AFL_EXT.1.6](#FIA_AFL_EXT.1.6){.abbr} [FIA_AFL_EXT.1.6](#FIA_AFL_EXT.1.6){.abbr} ::: ::: ::: reqdesc ::: reqdesc The [TSF](#abbr_TSF) shall increment the number of unsuccessful The [TSF](#abbr_TSF) shall increment the number of unsuccessful authentication attempts prior to notifying the user that the authentication attempts prior to notifying the user that the authentication was unsuccessful. authentication was unsuccessful. ::: appnote ::: appnote [Application Note: ]{.note-header}[This requirement is to ensure that if [Application Note: ]{.note-header}[This requirement is to ensure that if power is cut to the device directly after an authentication attempt, the power is cut to the device directly after an authentication attempt, the counter will be incremented to reflect that attempt. ]{.note} | counter will be incremented to reflect that attempt.]{.note} ::: ::: ::: ::: ::: ::: ::: {.activity_pane .hide} ::: {.activity_pane .hide} ::: activity_pane_header ::: activity_pane_header [[ Evaluation Activities [[ Evaluation Activities ]{.activity_pane_label}[]{.toggler}](#){onclick="toggle(this);return false;"} ]{.activity_pane_label}[]{.toggler}](#){onclick="toggle(this);return false;"} ::: ::: ::: activity_pane_body ::: activity_pane_body ::: component-activity-header ::: component-activity-header [FIA_AFL_EXT.1](#FIA_AFL_EXT.1) [FIA_AFL_EXT.1](#FIA_AFL_EXT.1) ::: ::: ::: eacategory ::: eacategory [TSS](#abbr_TSS) [TSS](#abbr_TSS) ::: ::: ::: ea ::: ea ::: ea ::: ea The evaluator shall ensure that the [TSS](#abbr_TSS) describes that a The evaluator shall ensure that the [TSS](#abbr_TSS) describes that a value corresponding to the number of unsuccessful authentication value corresponding to the number of unsuccessful authentication attempts since the last successful authentication is kept for each attempts since the last successful authentication is kept for each Authentication Factor interface. The evaluator shall ensure that this Authentication Factor interface. The evaluator shall ensure that this description also includes if and how this value is maintained when the description also includes if and how this value is maintained when the [TOE](#abbr_TOE) loses power, either through a graceful powered off or [TOE](#abbr_TOE) loses power, either through a graceful powered off or an ungraceful loss of power. The evaluator shall ensure that if the an ungraceful loss of power. The evaluator shall ensure that if the value is not maintained, the interface is after another interface in the value is not maintained, the interface is after another interface in the boot sequence for which the value is maintained.\ boot sequence for which the value is maintained.\ \ \ If the [TOE](#abbr_TOE) supports multiple authentication mechanisms, the If the [TOE](#abbr_TOE) supports multiple authentication mechanisms, the evaluator shall ensure that this description also includes how the evaluator shall ensure that this description also includes how the unsuccessful authentication attempts for each mechanism selected in unsuccessful authentication attempts for each mechanism selected in [FIA_UAU.5.1](#FIA_UAU.5.1) is handled. The evaluator shall verify that [FIA_UAU.5.1](#FIA_UAU.5.1) is handled. The evaluator shall verify that the [TSS](#abbr_TSS) describes if each authentication mechanism utilizes the [TSS](#abbr_TSS) describes if each authentication mechanism utilizes its own counter or if multiple authentication mechanisms utilize a its own counter or if multiple authentication mechanisms utilize a shared counter. If multiple authentication mechanisms utilize a shared shared counter. If multiple authentication mechanisms utilize a shared counter, the evaluator shall verify that the [TSS](#abbr_TSS) describes counter, the evaluator shall verify that the [TSS](#abbr_TSS) describes this interaction.\ this interaction.\ \ \ The evaluator shall confirm that the [TSS](#abbr_TSS) describes how the The evaluator shall confirm that the [TSS](#abbr_TSS) describes how the process used to determine if the authentication attempt was successful. process used to determine if the authentication attempt was successful. The evaluator shall ensure that the counter would be updated even if The evaluator shall ensure that the counter would be updated even if power to the device is cut immediately following notifying the power to the device is cut immediately following notifying the [TOE](#abbr_TOE) user if the authentication attempt was successful or [TOE](#abbr_TOE) user if the authentication attempt was successful or not.\ not.\ \ \ ::: ::: ::: ::: ::: eacategory ::: eacategory Guidance Guidance ::: ::: ::: ea ::: ea ::: ea ::: ea The evaluator shall verify that the AGD guidance describes how the The evaluator shall verify that the AGD guidance describes how the administrator configures the maximum number of unique unsuccessful administrator configures the maximum number of unique unsuccessful authentication attempts.\ authentication attempts.\ \ \ ::: ::: ::: ::: ::: eacategory ::: eacategory Tests Tests ::: ::: ::: ea ::: ea ::: ea ::: ea The evaluator shall configure the device with all authentication The evaluator shall configure the device with all authentication mechanisms selected in [FIA_UAU.5.1](#FIA_UAU.5.1). The evaluator shall mechanisms selected in [FIA_UAU.5.1](#FIA_UAU.5.1). The evaluator shall perform the following tests for each available authentication interface: perform the following tests for each available authentication interface: []{.testlist-} []{.testlist-} - [Test FIA_AFL_EXT.1:1](#_t_34){#_t_34 .defined}: The evaluator shall - [Test FIA_AFL_EXT.1:1](#_t_34){#_t_34 .defined}: The evaluator shall configure the [TOE](#abbr_TOE), according to the AGD guidance, with configure the [TOE](#abbr_TOE), according to the AGD guidance, with a maximum number of unsuccessful authentication attempts. The a maximum number of unsuccessful authentication attempts. The evaluator shall enter the locked state and enter incorrect passwords evaluator shall enter the locked state and enter incorrect passwords until the wipe occurs. The evaluator shall verify that the number of until the wipe occurs. The evaluator shall verify that the number of password entries corresponds to the configured maximum and that the password entries corresponds to the configured maximum and that the wipe is implemented. wipe is implemented. - [Test FIA_AFL_EXT.1:2](#_t_35){#_t_35 .defined}: \[conditional\] If - [Test FIA_AFL_EXT.1:2](#_t_35){#_t_35 .defined}: \[conditional\] If the [TOE](#abbr_TOE) supports multiple authentication mechanisms the the [TOE](#abbr_TOE) supports multiple authentication mechanisms the previous test shall be repeated using a combination of previous test shall be repeated using a combination of authentication mechanisms confirming that the critical authentication mechanisms confirming that the critical authentication mechanisms will cause the device to wipe and that authentication mechanisms will cause the device to wipe and that when the maximum number of unsuccessful authentication attempts for when the maximum number of unsuccessful authentication attempts for a non-critical authentication mechanism is exceeded, the device a non-critical authentication mechanism is exceeded, the device limits authentication attempts to other available authentication limits authentication attempts to other available authentication mechanisms. If multiple authentication mechanisms utilize a shared mechanisms. If multiple authentication mechanisms utilize a shared counter, then the evaluator shall verify that the maximum number of counter, then the evaluator shall verify that the maximum number of unsuccessful authentication attempts can be reached by using each unsuccessful authentication attempts can be reached by using each individual authentication mechanism and a combination of all individual authentication mechanism and a combination of all authentication mechanisms that share the counter. authentication mechanisms that share the counter. - [Test FIA_AFL_EXT.1:3](#_t_36){#_t_36 .defined}: The evaluator shall - [Test FIA_AFL_EXT.1:3](#_t_36){#_t_36 .defined}: The evaluator shall repeat the previous tests, but shall power off (by removing the repeat the previous tests, but shall power off (by removing the battery, if possible) the [TOE](#abbr_TOE) between unsuccessful battery, if possible) the [TOE](#abbr_TOE) between unsuccessful authentication attempts. The evaluator shall verify that the total authentication attempts. The evaluator shall verify that the total number of unsuccessful authentication attempts for each number of unsuccessful authentication attempts for each authentication mechanism corresponds to the configured maximum and authentication mechanism corresponds to the configured maximum and that the critical authentication mechanisms cause the device to that the critical authentication mechanisms cause the device to wipe. Alternatively, if the number of authentication failures is not wipe. Alternatively, if the number of authentication failures is not maintained for the interface under test, the evaluator shall verify maintained for the interface under test, the evaluator shall verify that upon booting the [TOE](#abbr_TOE) between unsuccessful that upon booting the [TOE](#abbr_TOE) between unsuccessful authentication attempts another authentication factor interface is authentication attempts another authentication factor interface is presented before the interface under test. presented before the interface under test. ::: ::: ::: ::: ::: ::: ::: ::: ::: ::: ::: {#FIA_PMG_EXT.1 .comp} ::: {#FIA_PMG_EXT.1 .comp} #### FIA_PMG_EXT.1 Password Management #### FIA_PMG_EXT.1 Password Management ::: element ::: element ::: {#FIA_PMG_EXT.1.1 .reqid} ::: {#FIA_PMG_EXT.1.1 .reqid} [FIA_PMG_EXT.1.1](#FIA_PMG_EXT.1.1){.abbr} [FIA_PMG_EXT.1.1](#FIA_PMG_EXT.1.1){.abbr} ::: ::: ::: reqdesc ::: reqdesc The [TSF](#abbr_TSF) shall support the following for the Password The [TSF](#abbr_TSF) shall support the following for the Password Authentication Factor: Authentication Factor: 1. Passwords shall be able to be composed of any combination of 1. Passwords shall be able to be composed of any combination of \[**selection**: [upper and lower case letters]{#_s_508 | \[**selection**: [upper and lower case letters]{#fia_pmg_ext.1.1_1 .selectable-content}, [\[**assignment**: [a character set of at .selectable-content}, [\[**assignment**: [a character set of at least 52 characters]{.assignable-content}\]]{#_s_509 | least 52 characters]{.assignable-content}\]]{#fia_pmg_ext.1.1_2 .selectable-content}\], numbers, and special characters: .selectable-content}\], numbers, and special characters: \[**selection**: [\"!\"]{#_s_510 .selectable-content}, | \[**selection**: [\"!\"]{#fia_pmg_ext.1.1_4 .selectable-content}, [\"@\"]{#_s_511 .selectable-content}, [\"#\"]{#_s_512 | [\"@\"]{#fia_pmg_ext.1.1_5 .selectable-content}, .selectable-content}, [\"\$\"]{#_s_513 .selectable-content}, | [\"#\"]{#fia_pmg_ext.1.1_6 .selectable-content}, [\"%\"]{#_s_514 .selectable-content}, [\"\^\"]{#_s_515 | [\"\$\"]{#fia_pmg_ext.1.1_7 .selectable-content}, .selectable-content}, [\"&\"]{#_s_516 .selectable-content}, [ | [\"%\"]{#fia_pmg_ext.1.1_8 .selectable-content}, \"\*\"]{#_s_517 .selectable-content}, [\"(\"]{#_s_518 | [\"\^\"]{#fia_pmg_ext.1.1_9 .selectable-content}, .selectable-content}, [\")\"]{#_s_519 .selectable-content}, | [\"&\"]{#fia_pmg_ext.1.1_10 .selectable-content}, [\[**assignment**: [other | [\"\*\"]{#fia_pmg_ext.1.1_11 .selectable-content}, characters]{.assignable-content}\]]{#_s_520 .selectable-content}\]; | [\"(\"]{#fia_pmg_ext.1.1_12 .selectable-content}, > [\")\"]{#fia_pmg_ext.1.1_13 .selectable-content}, [\[**assignment**: > [other characters]{.assignable-content}\]]{#fia_pmg_ext.1.1_14 > .selectable-content}\]; 2. Password length up to \[**assignment**: [an integer greater than or 2. Password length up to \[**assignment**: [an integer greater than or equal to 14]{.assignable-content}\] characters shall be supported. equal to 14]{.assignable-content}\] characters shall be supported. ::: appnote ::: appnote [Application Note: ]{.note-header}[While some corporate policies require | [Application Note: ]{.note-header}[ While some corporate policies passwords of 14 characters or better, the use of a [REK](#abbr_REK) for | require passwords of 14 characters or better, the use of a [DAR](#abbr_DAR) protection and key storage protection and the | [REK](#abbr_REK) for [DAR](#abbr_DAR) protection and key storage anti-hammer requirement ([FIA_TRT_EXT.1](#FIA_TRT_EXT.1)) addresses the | protection and the anti-hammer requirement threat of attackers with physical access using much smaller and less | ([FIA_TRT_EXT.1](#FIA_TRT_EXT.1)) addresses the threat of attackers with complex passwords.\ | physical access using much smaller and less complex passwords.\ \ \ The [ST](#abbr_ST) author selects the character set: either the upper The [ST](#abbr_ST) author selects the character set: either the upper and lower case Basic Latin letters or another assigned character set and lower case Basic Latin letters or another assigned character set containing at least 52 characters. The assigned character set must be containing at least 52 characters. The assigned character set must be well defined: either according to an international encoding standard well defined: either according to an international encoding standard (such as Unicode) or defined in the assignment by the [ST](#abbr_ST) (such as Unicode) or defined in the assignment by the [ST](#abbr_ST) author. The [ST](#abbr_ST) author also selects the special characters author. The [ST](#abbr_ST) author also selects the special characters that are supported by the [TOE](#abbr_TOE); they may optionally list that are supported by the [TOE](#abbr_TOE); they may optionally list additional special characters supported using the assignment. ]{.note} additional special characters supported using the assignment. ]{.note} ::: ::: ::: ::: ::: ::: ::: {.activity_pane .hide} ::: {.activity_pane .hide} ::: activity_pane_header ::: activity_pane_header [[ Evaluation Activities [[ Evaluation Activities ]{.activity_pane_label}[]{.toggler}](#){onclick="toggle(this);return false;"} ]{.activity_pane_label}[]{.toggler}](#){onclick="toggle(this);return false;"} ::: ::: ::: activity_pane_body ::: activity_pane_body ::: component-activity-header ::: component-activity-header [FIA_PMG_EXT.1](#FIA_PMG_EXT.1) [FIA_PMG_EXT.1](#FIA_PMG_EXT.1) ::: ::: ::: eacategory ::: eacategory [TSS](#abbr_TSS) [TSS](#abbr_TSS) ::: ::: ::: ea ::: ea ::: ea ::: ea There are no [TSS](#abbr_TSS) evaluation activities for this component.\ There are no [TSS](#abbr_TSS) evaluation activities for this component.\ \ \ ::: ::: ::: ::: ::: eacategory ::: eacategory Guidance Guidance ::: ::: ::: ea ::: ea ::: ea ::: ea The evaluator shall examine the operational guidance to determine that The evaluator shall examine the operational guidance to determine that it provides guidance to security administrators on the composition of it provides guidance to security administrators on the composition of strong passwords, and that it provides instructions on setting the strong passwords, and that it provides instructions on setting the minimum password length. minimum password length. ::: ::: ::: ::: ::: eacategory ::: eacategory Tests Tests ::: ::: ::: ea ::: ea ::: ea ::: ea []{.testlist-} []{.testlist-} - [Test FIA_PMG_EXT.1:1](#_t_37){#_t_37 .defined}: The evaluator shall - [Test FIA_PMG_EXT.1:1](#_t_37){#_t_37 .defined}: The evaluator shall compose passwords that either meet the requirements, or fail to meet compose passwords that either meet the requirements, or fail to meet the requirements, in some way. For each password, the evaluator the requirements, in some way. For each password, the evaluator shall verify that the [TOE](#abbr_TOE) supports the password. While shall verify that the [TOE](#abbr_TOE) supports the password. While the evaluator is not required (nor is it feasible) to test all the evaluator is not required (nor is it feasible) to test all possible compositions of passwords, the evaluator shall ensure that possible compositions of passwords, the evaluator shall ensure that all characters, rule characteristics, and a minimum length listed in all characters, rule characteristics, and a minimum length listed in the requirement are supported, and justify the subset of those the requirement are supported, and justify the subset of those characters chosen for testing. characters chosen for testing. ::: ::: ::: ::: ::: ::: ::: ::: ::: ::: ::: {#FIA_TRT_EXT.1 .comp} ::: {#FIA_TRT_EXT.1 .comp} #### FIA_TRT_EXT.1 Authentication Throttling #### FIA_TRT_EXT.1 Authentication Throttling ::: element ::: element ::: {#FIA_TRT_EXT.1.1 .reqid} ::: {#FIA_TRT_EXT.1.1 .reqid} [FIA_TRT_EXT.1.1](#FIA_TRT_EXT.1.1){.abbr} [FIA_TRT_EXT.1.1](#FIA_TRT_EXT.1.1){.abbr} ::: ::: ::: reqdesc ::: reqdesc The [TSF](#abbr_TSF) shall limit automated user authentication attempts The [TSF](#abbr_TSF) shall limit automated user authentication attempts by \[**selection**: [preventing authentication via an external by \[**selection**: [preventing authentication via an external port]{#_s_521 .selectable-content}, [enforcing a delay between incorrect | port]{#fia_trt_ext.1.1_1 .selectable-content}, [enforcing a delay authentication attempts]{#_s_522 .selectable-content}\] for all | between incorrect authentication attempts]{#fia_trt_ext.1.1_2 authentication mechanisms selected in [FIA_UAU.5.1](#FIA_UAU.5.1). The | .selectable-content}\] for all authentication mechanisms selected in minimum delay shall be such that no more than 10 attempts can be | [FIA_UAU.5.1](#FIA_UAU.5.1). The minimum delay shall be such that no attempted per 500 milliseconds. | more than 10 attempts can be attempted per 500 milliseconds. ::: appnote ::: appnote [Application Note: ]{.note-header}[The authentication throttling applies [Application Note: ]{.note-header}[The authentication throttling applies to all authentication mechanisms selected in to all authentication mechanisms selected in [FIA_UAU.5.1](#FIA_UAU.5.1). The user authentication attempts in this [FIA_UAU.5.1](#FIA_UAU.5.1). The user authentication attempts in this requirement are attempts to guess the Authentication Factor. The requirement are attempts to guess the Authentication Factor. The developer can implement the timing of the delays in the requirements developer can implement the timing of the delays in the requirements using unequal or equal timing of delays. The minimum delay specified in using unequal or equal timing of delays. The minimum delay specified in this requirement provides defense against brute forcing.]{.note} this requirement provides defense against brute forcing.]{.note} ::: ::: ::: ::: ::: ::: ::: {.activity_pane .hide} ::: {.activity_pane .hide} ::: activity_pane_header ::: activity_pane_header [[ Evaluation Activities [[ Evaluation Activities ]{.activity_pane_label}[]{.toggler}](#){onclick="toggle(this);return false;"} ]{.activity_pane_label}[]{.toggler}](#){onclick="toggle(this);return false;"} ::: ::: ::: activity_pane_body ::: activity_pane_body ::: component-activity-header ::: component-activity-header [FIA_TRT_EXT.1](#FIA_TRT_EXT.1) [FIA_TRT_EXT.1](#FIA_TRT_EXT.1) ::: ::: ::: eacategory ::: eacategory [TSS](#abbr_TSS) [TSS](#abbr_TSS) ::: ::: ::: ea ::: ea ::: ea ::: ea The evaluator shall verify that the [TSS](#abbr_TSS) describes the The evaluator shall verify that the [TSS](#abbr_TSS) describes the method by which authentication attempts are not able to be automated. method by which authentication attempts are not able to be automated. The evaluator shall ensure that the [TSS](#abbr_TSS) describes either The evaluator shall ensure that the [TSS](#abbr_TSS) describes either how the [TSF](#abbr_TSF) disables authentication via external interfaces how the [TSF](#abbr_TSF) disables authentication via external interfaces (other than the ordinary user interface) or how authentication attempts (other than the ordinary user interface) or how authentication attempts are delayed in order to slow automated entry and shall ensure that this are delayed in order to slow automated entry and shall ensure that this delay totals at least 500 milliseconds over 10 attempts for all delay totals at least 500 milliseconds over 10 attempts for all authentication mechanisms selected in [FIA_UAU.5.1](#FIA_UAU.5.1).\ authentication mechanisms selected in [FIA_UAU.5.1](#FIA_UAU.5.1).\ \ \ ::: ::: ::: ::: ::: eacategory ::: eacategory Guidance Guidance ::: ::: ::: ea ::: ea ::: ea ::: ea There are no guidance evaluation activities for this component.\ There are no guidance evaluation activities for this component.\ \ \ ::: ::: ::: ::: ::: eacategory ::: eacategory Tests Tests ::: ::: ::: ea ::: ea ::: ea ::: ea There are no test evaluation activities for this component. There are no test evaluation activities for this component. ::: ::: ::: ::: ::: ::: ::: ::: ::: ::: ::: {#FIA_UAU.5 .comp} ::: {#FIA_UAU.5 .comp} #### FIA_UAU.5 Multiple Authentication Mechanisms #### FIA_UAU.5 Multiple Authentication Mechanisms ::: element ::: element ::: {#FIA_UAU.5.1 .reqid} ::: {#FIA_UAU.5.1 .reqid} [FIA_UAU.5.1](#FIA_UAU.5.1){.abbr} [FIA_UAU.5.1](#FIA_UAU.5.1){.abbr} ::: ::: ::: reqdesc ::: reqdesc The [TSF](#abbr_TSF) shall provide **password and** \[**selection**: [ | The [TSF](#abbr_TSF) shall provide **password and** \[**selection**: biometric in accordance with the [cPP-Module for Biometric Enrollment | [biometric in accordance with the [cPP-Module for Biometric Enrollment and Verification, version and Verification, version 2.0](https://github.com/biometricITC/cPP-biometrics/blob/master/Protection%20Profile/ 2.0](https://github.com/biometricITC/cPP-biometrics/blob/master/Protection%20Profile/ .selectable-content}, [ hybrid]{#uau_hybr .selectable-content}, [no | .selectable-content}, [hybrid]{#uau_hybr .selectable-content}, [no other other mechanism]{#_s_525 .selectable-content}\] to support user | mechanism]{#fia_uau.5.1_1 .selectable-content}\] to support user authentication. authentication. ::: appnote ::: appnote [Application Note: ]{.note-header}[The [TSF](#abbr_TSF) must support a | [Application Note: ]{.note-header}[ The [TSF](#abbr_TSF) must support a Password Authentication Factor and may optionally implement a Password Authentication Factor and may optionally implement a [BAF](#abbr_BAF). A hybrid authentication factor is where a user has to [BAF](#abbr_BAF). A hybrid authentication factor is where a user has to submit a combination of PIN/password and biometric sample where both submit a combination of PIN/password and biometric sample where both have to pass and if either fails the user is not made aware of which have to pass and if either fails the user is not made aware of which factor failed.\ factor failed.\ \ \ If [biometric in accordance with the](#uau_biometric) [cPP-Module for If [biometric in accordance with the](#uau_biometric) [cPP-Module for Biometric Enrollment and Verification, version Biometric Enrollment and Verification, version 2.0](https://github.com/biometricITC/cPP-biometrics/blob/master/Protection%20Profile/ 2.0](https://github.com/biometricITC/cPP-biometrics/blob/master/Protection%20Profile/ or [hybrid](#uau_hybr) is selected, then the [TSF](#abbr_TSF) must be or [hybrid](#uau_hybr) is selected, then the [TSF](#abbr_TSF) must be validated against requirements from the [cPP-Module for Biometric validated against requirements from the [cPP-Module for Biometric Enrollment and Verification, version Enrollment and Verification, version 2.0](https://github.com/biometricITC/cPP-biometrics/blob/master/Protection%20Profile/ 2.0](https://github.com/biometricITC/cPP-biometrics/blob/master/Protection%20Profile/ \ \ If [hybrid](#uau_hybr) is selected, [biometric in accordance with If [hybrid](#uau_hybr) is selected, [biometric in accordance with the](#uau_biometric) [cPP-Module for Biometric Enrollment and the](#uau_biometric) [cPP-Module for Biometric Enrollment and Verification, version Verification, version 2.0](https://github.com/biometricITC/cPP-biometrics/blob/master/Protection%20Profile/ 2.0](https://github.com/biometricITC/cPP-biometrics/blob/master/Protection%20Profile/ does not need to be selected, but should be selected if the biometric does not need to be selected, but should be selected if the biometric authentication can be used independent of the hybrid authentication, authentication can be used independent of the hybrid authentication, i.e., without having to enter a PIN/password.\ i.e., without having to enter a PIN/password.\ \ \ The Password Authentication Factor is configured according to The Password Authentication Factor is configured according to [FIA_PMG_EXT.1](#FIA_PMG_EXT.1). ]{.note} [FIA_PMG_EXT.1](#FIA_PMG_EXT.1). ]{.note} ::: ::: ::: ::: ::: ::: ::: element ::: element ::: {#FIA_UAU.5.2 .reqid} ::: {#FIA_UAU.5.2 .reqid} [FIA_UAU.5.2](#FIA_UAU.5.2){.abbr} [FIA_UAU.5.2](#FIA_UAU.5.2){.abbr} ::: ::: ::: reqdesc ::: reqdesc The [TSF](#abbr_TSF) shall authenticate any user\'s claimed identity The [TSF](#abbr_TSF) shall authenticate any user\'s claimed identity according to the \[**assignment**: [rules describing how the multiple according to the \[**assignment**: [rules describing how the multiple authentication mechanisms provide authentication mechanisms provide authentication]{.assignable-content}\]. authentication]{.assignable-content}\]. ::: appnote ::: appnote [Application Note: ]{.note-header}[Rules regarding how the [Application Note: ]{.note-header}[Rules regarding how the authentication factors interact in terms of unsuccessful authentication authentication factors interact in terms of unsuccessful authentication are covered in [FIA_AFL_EXT.1](#FIA_AFL_EXT.1).]{.note} are covered in [FIA_AFL_EXT.1](#FIA_AFL_EXT.1).]{.note} ::: ::: ::: ::: ::: ::: ::: {.activity_pane .hide} ::: {.activity_pane .hide} ::: activity_pane_header ::: activity_pane_header [[ Evaluation Activities [[ Evaluation Activities ]{.activity_pane_label}[]{.toggler}](#){onclick="toggle(this);return false;"} ]{.activity_pane_label}[]{.toggler}](#){onclick="toggle(this);return false;"} ::: ::: ::: activity_pane_body ::: activity_pane_body ::: component-activity-header ::: component-activity-header [FIA_UAU.5](#FIA_UAU.5) [FIA_UAU.5](#FIA_UAU.5) ::: ::: ::: eacategory ::: eacategory [TSS](#abbr_TSS) [TSS](#abbr_TSS) ::: ::: ::: ea ::: ea ::: ea ::: ea The evaluator shall ensure that the [TSS](#abbr_TSS) describes each The evaluator shall ensure that the [TSS](#abbr_TSS) describes each mechanism provided to support user authentication and the rules mechanism provided to support user authentication and the rules describing how the authentication mechanisms provide authentication.\ describing how the authentication mechanisms provide authentication.\ \ \ Specifically, for all authentication mechanisms specified in Specifically, for all authentication mechanisms specified in [FIA_UAU.5.1](#FIA_UAU.5.1), the evaluator shall ensure that the [FIA_UAU.5.1](#FIA_UAU.5.1), the evaluator shall ensure that the [TSS](#abbr_TSS) describes the rules as to how each authentication [TSS](#abbr_TSS) describes the rules as to how each authentication mechanism is used. Example rules are how the authentication mechanism mechanism is used. Example rules are how the authentication mechanism authenticates the user (i.e., how does the [TSF](#abbr_TSF) verify that authenticates the user (i.e., how does the [TSF](#abbr_TSF) verify that the correct password or biometric sample was entered), the result of a the correct password or biometric sample was entered), the result of a successful authentication (i.e., is the user input used to derive or successful authentication (i.e., is the user input used to derive or unlock a key) and which authentication mechanism can be used at which unlock a key) and which authentication mechanism can be used at which authentication factor interfaces (i.e., if there are times, for example, authentication factor interfaces (i.e., if there are times, for example, after a reboot, that only specific authentication mechanisms can be after a reboot, that only specific authentication mechanisms can be used). If multiple [BAFs](#abbr_BAF) are claimed in FIA_MBV_EXT.1.1 in | used). If multiple BAFs are claimed in FIA_MBV_EXT.1.1 in the the [cPP-Module for Biometric Enrollment and Verification, version | [cPP-Module for Biometric Enrollment and Verification, version 2.0](https://github.com/biometricITC/cPP-biometrics/blob/master/Protection%20Profile/ 2.0](https://github.com/biometricITC/cPP-biometrics/blob/master/Protection%20Profile/ the interaction between the [BAFs](#abbr_BAF) must be described. For | the interaction between the BAFs must be described. For example, whether example, whether the multiple [BAFs](#abbr_BAF) can be enabled at the | the multiple BAFs can be enabled at the same time.\ same time.\ < \ \ ::: ::: ::: ::: ::: eacategory ::: eacategory Guidance Guidance ::: ::: ::: ea ::: ea ::: ea ::: ea The evaluator shall verify that configuration guidance for each The evaluator shall verify that configuration guidance for each authentication mechanism is addressed in the AGD guidance.\ authentication mechanism is addressed in the AGD guidance.\ \ \ ::: ::: ::: ::: ::: eacategory ::: eacategory Tests Tests ::: ::: ::: ea ::: ea ::: ea ::: ea []{.testlist-} []{.testlist-} - [Test FIA_UAU.5:1](#_t_38){#_t_38 .defined}: For each authentication - [Test FIA_UAU.5:1](#_t_38){#_t_38 .defined}: For each authentication mechanism selected in [FIA_UAU.5.1](#FIA_UAU.5.1), the evaluator mechanism selected in [FIA_UAU.5.1](#FIA_UAU.5.1), the evaluator shall enable that mechanism and verify that it can be used to shall enable that mechanism and verify that it can be used to authenticate the user at the specified authentication factor authenticate the user at the specified authentication factor interfaces. interfaces. - [Test FIA_UAU.5:2](#_t_39){#_t_39 .defined}: For each authentication - [Test FIA_UAU.5:2](#_t_39){#_t_39 .defined}: For each authentication mechanism rule, the evaluator shall ensure that the authentication mechanism rule, the evaluator shall ensure that the authentication mechanisms behave accordingly. mechanisms behave accordingly. ::: ::: ::: ::: ::: ::: ::: ::: ::: ::: ::: {#FIA_UAU.6/CREDENTIAL .comp} ::: {#FIA_UAU.6/CREDENTIAL .comp} #### FIA_UAU.6/CREDENTIAL Re-Authenticating (Credential Change) #### FIA_UAU.6/CREDENTIAL Re-Authenticating (Credential Change) ::: element ::: element ::: {#FIA_UAU.6.1/CREDENTIAL .reqid} ::: {#FIA_UAU.6.1/CREDENTIAL .reqid} [FIA_UAU.6.1/CREDENTIAL](#FIA_UAU.6.1/CREDENTIAL){.abbr} [FIA_UAU.6.1/CREDENTIAL](#FIA_UAU.6.1/CREDENTIAL){.abbr} ::: ::: ::: reqdesc ::: reqdesc The [TSF](#abbr_TSF) shall re-authenticate the user [via the Password | The [TSF](#abbr_TSF) shall re-authenticate the user **via the Password Authentication Factor]{.refinement} under the conditions \[*attempted | Authentication Factor** under the conditions \[*attempted change to any change to any supported authentication mechanisms*\]. | supported authentication mechanisms*\]. ::: appnote ::: appnote [Application Note: ]{.note-header}[The password authentication factor [Application Note: ]{.note-header}[The password authentication factor must be entered before either the password or biometric authentication must be entered before either the password or biometric authentication factor, if selected in [FIA_UAU.5.1](#FIA_UAU.5.1), can be factor, if selected in [FIA_UAU.5.1](#FIA_UAU.5.1), can be changed.]{.note} changed.]{.note} ::: ::: ::: ::: ::: ::: ::: {.activity_pane .hide} ::: {.activity_pane .hide} ::: activity_pane_header ::: activity_pane_header [[ Evaluation Activities [[ Evaluation Activities ]{.activity_pane_label}[]{.toggler}](#){onclick="toggle(this);return false;"} ]{.activity_pane_label}[]{.toggler}](#){onclick="toggle(this);return false;"} ::: ::: ::: activity_pane_body ::: activity_pane_body ::: element-activity-header ::: element-activity-header [FIA_UAU.6.1/CREDENTIAL](#FIA_UAU.6.1/CREDENTIAL) [FIA_UAU.6.1/CREDENTIAL](#FIA_UAU.6.1/CREDENTIAL) ::: ::: ::: eacategory ::: eacategory [TSS](#abbr_TSS) [TSS](#abbr_TSS) ::: ::: ::: ea ::: ea There are no [TSS](#abbr_TSS) evaluation activities for this element.\ There are no [TSS](#abbr_TSS) evaluation activities for this element.\ \ \ ::: ::: ::: eacategory ::: eacategory Guidance Guidance ::: ::: ::: ea ::: ea There are no guidance evaluation activities for this element.\ There are no guidance evaluation activities for this element.\ \ \ ::: ::: ::: eacategory ::: eacategory Tests Tests ::: ::: ::: ea ::: ea []{.testlist-} []{.testlist-} - [Test FIA_UAU.6.1/CREDENTIAL:1](#_t_40){#_t_40 .defined}: The - [Test FIA_UAU.6.1/CREDENTIAL:1](#_t_40){#_t_40 .defined}: The evaluator shall configure the [TSF](#abbr_TSF) to use the Password evaluator shall configure the [TSF](#abbr_TSF) to use the Password Authentication Factor according to the AGD guidance. The evaluator Authentication Factor according to the AGD guidance. The evaluator shall change Password Authentication Factor according to the AGD shall change Password Authentication Factor according to the AGD guidance and verify that the [TSF](#abbr_TSF) requires the entry of guidance and verify that the [TSF](#abbr_TSF) requires the entry of the Password Authentication Factor before allowing the factor to be the Password Authentication Factor before allowing the factor to be changed. changed. - [Test FIA_UAU.6.1/CREDENTIAL:2](#_t_41){#_t_41 .defined}: - [Test FIA_UAU.6.1/CREDENTIAL:2](#_t_41){#_t_41 .defined}: \[conditional\] If [biometric in accordance with \[conditional\] If [biometric in accordance with the](#uau_biometric) [cPP-Module for Biometric Enrollment and the](#uau_biometric) [cPP-Module for Biometric Enrollment and Verification, version Verification, version 2.0](https://github.com/biometricITC/cPP-biometrics/blob/master/Protection%20Prof 2.0](https://github.com/biometricITC/cPP-biometrics/blob/master/Protection%20Prof is selected in [FIA_UAU.5.1](#FIA_UAU.5.1), for each is selected in [FIA_UAU.5.1](#FIA_UAU.5.1), for each [BAF](#abbr_BAF) claimed in FIA_MBV_EXT.1.1 in the [cPP-Module for [BAF](#abbr_BAF) claimed in FIA_MBV_EXT.1.1 in the [cPP-Module for Biometric Enrollment and Verification, version Biometric Enrollment and Verification, version 2.0](https://github.com/biometricITC/cPP-biometrics/blob/master/Protection%20Prof 2.0](https://github.com/biometricITC/cPP-biometrics/blob/master/Protection%20Prof the evaluator shall configure the [TSF](#abbr_TSF) to use the the evaluator shall configure the [TSF](#abbr_TSF) to use the [BAF](#abbr_BAF), which includes configuring the Password [BAF](#abbr_BAF), which includes configuring the Password Authentication Factor, according to the AGD guidance. The evaluator Authentication Factor, according to the AGD guidance. The evaluator shall change the [BAF](#abbr_BAF) according to the AGD guidance and shall change the [BAF](#abbr_BAF) according to the AGD guidance and verify that the [TSF](#abbr_TSF) requires the entry of the Password verify that the [TSF](#abbr_TSF) requires the entry of the Password Authentication Factor before allowing the [BAF](#abbr_BAF) to be Authentication Factor before allowing the [BAF](#abbr_BAF) to be changed. changed. - [Test FIA_UAU.6.1/CREDENTIAL:3](#_t_42){#_t_42 .defined}: - [Test FIA_UAU.6.1/CREDENTIAL:3](#_t_42){#_t_42 .defined}: \[conditional\] If [hybrid](#uau_hybr) is selected in \[conditional\] If [hybrid](#uau_hybr) is selected in [FIA_UAU.5.1](#FIA_UAU.5.1), the evaluator shall configure the [FIA_UAU.5.1](#FIA_UAU.5.1), the evaluator shall configure the [TSF](#abbr_TSF) to use the [BAF](#abbr_BAF) and PIN or password, [TSF](#abbr_TSF) to use the [BAF](#abbr_BAF) and PIN or password, which includes configuring the Password Authentication Factor, which includes configuring the Password Authentication Factor, according to the AGD guidance. The evaluator shall change the according to the AGD guidance. The evaluator shall change the [BAF](#abbr_BAF) and PIN according to the AGD guidance and verify [BAF](#abbr_BAF) and PIN according to the AGD guidance and verify that the [TSF](#abbr_TSF) requires the entry of the Password that the [TSF](#abbr_TSF) requires the entry of the Password Authentication Factor before allowing the factor to be changed. Authentication Factor before allowing the factor to be changed. ::: ::: ::: ::: ::: ::: ::: ::: ::: {#FIA_UAU.6/LOCKED .comp} ::: {#FIA_UAU.6/LOCKED .comp} #### FIA_UAU.6/LOCKED Re-Authenticating (TSF Lock) #### FIA_UAU.6/LOCKED Re-Authenticating (TSF Lock) ::: element ::: element ::: {#FIA_UAU.6.1/LOCKED .reqid} ::: {#FIA_UAU.6.1/LOCKED .reqid} [FIA_UAU.6.1/LOCKED](#FIA_UAU.6.1/LOCKED){.abbr} [FIA_UAU.6.1/LOCKED](#FIA_UAU.6.1/LOCKED){.abbr} ::: ::: ::: reqdesc ::: reqdesc The [TSF](#abbr_TSF) shall re-authenticate the user [via an | The [TSF](#abbr_TSF) shall re-authenticate the user **via an authentication factor defined in | authentication factor defined in [FIA_UAU.5.1](#FIA_UAU.5.1)** under the [FIA_UAU.5.1](#FIA_UAU.5.1)]{.refinement} under the conditions | conditions **[TSF](#abbr_TSF)-initiated lock, user-initiated lock, [[TSF](#abbr_TSF)-initiated lock, user-initiated lock, \[**assignment**: | \[**assignment**: [other conditions]{.assignable-content}\]**. [other conditions]{.assignable-content}\]]{.refinement}. < ::: appnote ::: appnote [Application Note: ]{.note-header}[Depending on the selections made in [Application Note: ]{.note-header}[Depending on the selections made in [FIA_UAU.5.1](#FIA_UAU.5.1), either the password (at a minimum), [FIA_UAU.5.1](#FIA_UAU.5.1), either the password (at a minimum), biometric authentication or hybrid authentication mechanisms can be used biometric authentication or hybrid authentication mechanisms can be used to unlock the device. [TSF](#abbr_TSF)-initiated and user-initiated to unlock the device. [TSF](#abbr_TSF)-initiated and user-initiated locking is described in [FTA_SSL_EXT.1](#FTA_SSL_EXT.1).]{.note} locking is described in [FTA_SSL_EXT.1](#FTA_SSL_EXT.1).]{.note} ::: ::: ::: ::: ::: ::: ::: {.activity_pane .hide} ::: {.activity_pane .hide} ::: activity_pane_header ::: activity_pane_header [[ Evaluation Activities [[ Evaluation Activities ]{.activity_pane_label}[]{.toggler}](#){onclick="toggle(this);return false;"} ]{.activity_pane_label}[]{.toggler}](#){onclick="toggle(this);return false;"} ::: ::: ::: activity_pane_body ::: activity_pane_body ::: element-activity-header ::: element-activity-header [FIA_UAU.6.1/LOCKED](#FIA_UAU.6.1/LOCKED) [FIA_UAU.6.1/LOCKED](#FIA_UAU.6.1/LOCKED) ::: ::: ::: eacategory ::: eacategory [TSS](#abbr_TSS) [TSS](#abbr_TSS) ::: ::: ::: ea ::: ea There are no [TSS](#abbr_TSS) evaluation activities for this element.\ There are no [TSS](#abbr_TSS) evaluation activities for this element.\ \ \ ::: ::: ::: eacategory ::: eacategory Guidance Guidance ::: ::: ::: ea ::: ea There are no guidance evaluation activities for this element.\ There are no guidance evaluation activities for this element.\ \ \ ::: ::: ::: eacategory ::: eacategory Tests Tests ::: ::: ::: ea ::: ea []{.testlist-} []{.testlist-} - [Test FIA_UAU.6.1/LOCKED:1](#_t_43){#_t_43 .defined}: The evaluator - [Test FIA_UAU.6.1/LOCKED:1](#_t_43){#_t_43 .defined}: The evaluator shall configure the [TSF](#abbr_TSF) to transition to the locked shall configure the [TSF](#abbr_TSF) to transition to the locked state after a time of inactivity ([FMT_SMF_EXT.1](#FMT_SMF_EXT.1)) state after a time of inactivity ([FMT_SMF_EXT.1](#FMT_SMF_EXT.1)) according to the AGD guidance. The evaluator shall wait until the according to the AGD guidance. The evaluator shall wait until the [TSF](#abbr_TSF) locks and then verify that the [TSF](#abbr_TSF) [TSF](#abbr_TSF) locks and then verify that the [TSF](#abbr_TSF) requires the entry of the Password Authentication Factor before requires the entry of the Password Authentication Factor before transitioning to the unlocked state. transitioning to the unlocked state. - [Test FIA_UAU.6.1/LOCKED:2](#_t_44){#_t_44 .defined}: - [Test FIA_UAU.6.1/LOCKED:2](#_t_44){#_t_44 .defined}: \[conditional\] If [biometric in accordance with \[conditional\] If [biometric in accordance with the](#uau_biometric) [cPP-Module for Biometric Enrollment and the](#uau_biometric) [cPP-Module for Biometric Enrollment and Verification, version Verification, version 2.0](https://github.com/biometricITC/cPP-biometrics/blob/master/Protection%20Prof 2.0](https://github.com/biometricITC/cPP-biometrics/blob/master/Protection%20Prof is selected in [FIA_UAU.5.1](#FIA_UAU.5.1), for each is selected in [FIA_UAU.5.1](#FIA_UAU.5.1), for each [BAF](#abbr_BAF) claimed in FIA_MBV_EXT.1.1 in the [cPP-Module for [BAF](#abbr_BAF) claimed in FIA_MBV_EXT.1.1 in the [cPP-Module for Biometric Enrollment and Verification, version Biometric Enrollment and Verification, version 2.0](https://github.com/biometricITC/cPP-biometrics/blob/master/Protection%20Prof 2.0](https://github.com/biometricITC/cPP-biometrics/blob/master/Protection%20Prof the evaluator shall repeat Test 1 verifying that the the evaluator shall repeat Test 1 verifying that the [TSF](#abbr_TSF) requires the entry of the [BAF](#abbr_BAF) before [TSF](#abbr_TSF) requires the entry of the [BAF](#abbr_BAF) before transitioning to the unlocked state. transitioning to the unlocked state. - [Test FIA_UAU.6.1/LOCKED:3](#_t_45){#_t_45 .defined}: - [Test FIA_UAU.6.1/LOCKED:3](#_t_45){#_t_45 .defined}: \[conditional\] If [hybrid](#uau_hybr) is selected in \[conditional\] If [hybrid](#uau_hybr) is selected in [FIA_UAU.5.1](#FIA_UAU.5.1), the evaluator shall repeat Test 1 [FIA_UAU.5.1](#FIA_UAU.5.1), the evaluator shall repeat Test 1 verifying that the [TSF](#abbr_TSF) requires the entry of the verifying that the [TSF](#abbr_TSF) requires the entry of the [BAF](#abbr_BAF) and PIN/password before transitioning to the [BAF](#abbr_BAF) and PIN/password before transitioning to the unlocked state. unlocked state. - [Test FIA_UAU.6.1/LOCKED:4](#t-locks){#t-locks .defined}: The - [Test FIA_UAU.6.1/LOCKED:4](#t-locks){#t-locks .defined}: The evaluator shall configure user-initiated locking according to the evaluator shall configure user-initiated locking according to the AGD guidance. The evaluator shall lock the [TSF](#abbr_TSF) and then AGD guidance. The evaluator shall lock the [TSF](#abbr_TSF) and then verify that the [TSF](#abbr_TSF) requires the entry of the Password verify that the [TSF](#abbr_TSF) requires the entry of the Password Authentication Factor before transitioning to the unlocked state. Authentication Factor before transitioning to the unlocked state. - [Test FIA_UAU.6.1/LOCKED:5](#_t_47){#_t_47 .defined}: - [Test FIA_UAU.6.1/LOCKED:5](#_t_47){#_t_47 .defined}: \[conditional\] If [biometric in accordance with \[conditional\] If [biometric in accordance with the](#uau_biometric) [cPP-Module for Biometric Enrollment and the](#uau_biometric) [cPP-Module for Biometric Enrollment and Verification, version Verification, version 2.0](https://github.com/biometricITC/cPP-biometrics/blob/master/Protection%20Prof 2.0](https://github.com/biometricITC/cPP-biometrics/blob/master/Protection%20Prof is selected in [FIA_UAU.5.1](#FIA_UAU.5.1), for each is selected in [FIA_UAU.5.1](#FIA_UAU.5.1), for each [BAF](#abbr_BAF) claimed in FIA_MBV_EXT.1.1 in the [cPP-Module for [BAF](#abbr_BAF) claimed in FIA_MBV_EXT.1.1 in the [cPP-Module for Biometric Enrollment and Verification, version Biometric Enrollment and Verification, version 2.0](https://github.com/biometricITC/cPP-biometrics/blob/master/Protection%20Prof 2.0](https://github.com/biometricITC/cPP-biometrics/blob/master/Protection%20Prof the evaluator shall repeat [Test the evaluator shall repeat [Test FIA_UAU.6.1/LOCKED:4](#t-locks){.dynref} verifying that the FIA_UAU.6.1/LOCKED:4](#t-locks){.dynref} verifying that the [TSF](#abbr_TSF) requires the entry of the [BAF](#abbr_BAF) before [TSF](#abbr_TSF) requires the entry of the [BAF](#abbr_BAF) before transitioning to the unlocked state. transitioning to the unlocked state. - [Test FIA_UAU.6.1/LOCKED:6](#_t_48){#_t_48 .defined}: - [Test FIA_UAU.6.1/LOCKED:6](#_t_48){#_t_48 .defined}: \[conditional\] If [hybrid](#uau_hybr) is selected in \[conditional\] If [hybrid](#uau_hybr) is selected in [FIA_UAU.5.1](#FIA_UAU.5.1), the evaluator shall repeat [Test [FIA_UAU.5.1](#FIA_UAU.5.1), the evaluator shall repeat [Test FIA_UAU.6.1/LOCKED:4](#t-locks){.dynref} verifying that the FIA_UAU.6.1/LOCKED:4](#t-locks){.dynref} verifying that the [TSF](#abbr_TSF) requires the entry of the [BAF](#abbr_BAF) and [TSF](#abbr_TSF) requires the entry of the [BAF](#abbr_BAF) and PIN/password before transitioning to the unlocked state. PIN/password before transitioning to the unlocked state. ::: ::: ::: ::: ::: ::: ::: ::: ::: {#FIA_UAU.7 .comp} ::: {#FIA_UAU.7 .comp} #### FIA_UAU.7 Protected Authentication Feedback #### FIA_UAU.7 Protected Authentication Feedback ::: element ::: element ::: {#FIA_UAU.7.1 .reqid} ::: {#FIA_UAU.7.1 .reqid} [FIA_UAU.7.1](#FIA_UAU.7.1){.abbr} [FIA_UAU.7.1](#FIA_UAU.7.1){.abbr} ::: ::: ::: reqdesc ::: reqdesc The [TSF](#abbr_TSF) shall provide only \[*obscured feedback to the The [TSF](#abbr_TSF) shall provide only \[*obscured feedback to the device's display*\] to the user while the authentication is in progress. device's display*\] to the user while the authentication is in progress. ::: appnote ::: appnote [Application Note: ]{.note-header}[This applies to all authentication | [Application Note: ]{.note-header}[ This applies to all authentication methods specified in [FIA_UAU.5.1](#FIA_UAU.5.1). The [TSF](#abbr_TSF) methods specified in [FIA_UAU.5.1](#FIA_UAU.5.1). The [TSF](#abbr_TSF) may briefly (1 second or less) display each character or provide an may briefly (1 second or less) display each character or provide an option to allow the user to unmask the password; however, the password option to allow the user to unmask the password; however, the password must be obscured by default.\ must be obscured by default.\ \ \ If [biometric in accordance with the](#uau_biometric) [cPP-Module for If [biometric in accordance with the](#uau_biometric) [cPP-Module for Biometric Enrollment and Verification, version Biometric Enrollment and Verification, version 2.0](https://github.com/biometricITC/cPP-biometrics/blob/master/Protection%20Profile/ 2.0](https://github.com/biometricITC/cPP-biometrics/blob/master/Protection%20Profile/ is selected in [FIA_UAU.5.1](#FIA_UAU.5.1), the [TSF](#abbr_TSF) must is selected in [FIA_UAU.5.1](#FIA_UAU.5.1), the [TSF](#abbr_TSF) must not display sensitive information regarding any [BAF](#abbr_BAF) that not display sensitive information regarding any [BAF](#abbr_BAF) that could aid an adversary in identifying or spoofing the respective could aid an adversary in identifying or spoofing the respective biometric characteristics of a given human user. While it is true that biometric characteristics of a given human user. While it is true that biometric samples, by themselves, are not secret, the analysis performed biometric samples, by themselves, are not secret, the analysis performed by the respective biometric algorithms, as well as output data from by the respective biometric algorithms, as well as output data from these biometric algorithms, is considered sensitive and must be kept these biometric algorithms, is considered sensitive and must be kept secret. Where applicable, the [TSF](#abbr_TSF) must not reveal or make secret. Where applicable, the [TSF](#abbr_TSF) must not reveal or make public the reasons for authentication failure. ]{.note} public the reasons for authentication failure. ]{.note} ::: ::: ::: ::: ::: ::: ::: {.activity_pane .hide} ::: {.activity_pane .hide} ::: activity_pane_header ::: activity_pane_header [[ Evaluation Activities [[ Evaluation Activities ]{.activity_pane_label}[]{.toggler}](#){onclick="toggle(this);return false;"} ]{.activity_pane_label}[]{.toggler}](#){onclick="toggle(this);return false;"} ::: ::: ::: activity_pane_body ::: activity_pane_body ::: component-activity-header ::: component-activity-header [FIA_UAU.7](#FIA_UAU.7) [FIA_UAU.7](#FIA_UAU.7) ::: ::: ::: eacategory ::: eacategory [TSS](#abbr_TSS) [TSS](#abbr_TSS) ::: ::: ::: ea ::: ea ::: ea ::: ea The evaluator shall ensure that the [TSS](#abbr_TSS) describes the means The evaluator shall ensure that the [TSS](#abbr_TSS) describes the means of obscuring the authentication entry, for all authentication methods of obscuring the authentication entry, for all authentication methods specified in [FIA_UAU.5.1](#FIA_UAU.5.1).\ specified in [FIA_UAU.5.1](#FIA_UAU.5.1).\ \ \ ::: ::: ::: ::: ::: eacategory ::: eacategory Guidance Guidance ::: ::: ::: ea ::: ea ::: ea ::: ea The evaluator shall verify that any configuration of this requirement is The evaluator shall verify that any configuration of this requirement is addressed in the AGD guidance and that the password is obscured by addressed in the AGD guidance and that the password is obscured by default. default. ::: ::: ::: ::: ::: eacategory ::: eacategory Tests Tests ::: ::: ::: ea ::: ea ::: ea ::: ea []{.testlist-} []{.testlist-} - [Test FIA_UAU.7:1](#_t_49){#_t_49 .defined}: The evaluator shall - [Test FIA_UAU.7:1](#_t_49){#_t_49 .defined}: The evaluator shall enter passwords on the device, including at least the Password enter passwords on the device, including at least the Password Authentication Factor at lock screen, and verify that the password Authentication Factor at lock screen, and verify that the password is not displayed on the device. is not displayed on the device. - [Test FIA_UAU.7:2](#_t_50){#_t_50 .defined}: \[conditional\] If - [Test FIA_UAU.7:2](#_t_50){#_t_50 .defined}: \[conditional\] If [biometric in accordance with the](#uau_biometric) [cPP-Module for [biometric in accordance with the](#uau_biometric) [cPP-Module for Biometric Enrollment and Verification, version Biometric Enrollment and Verification, version 2.0](https://github.com/biometricITC/cPP-biometrics/blob/master/Protection%20Prof 2.0](https://github.com/biometricITC/cPP-biometrics/blob/master/Protection%20Prof is selected in [FIA_UAU.5.1](#FIA_UAU.5.1), for each is selected in [FIA_UAU.5.1](#FIA_UAU.5.1), for each [BAF](#abbr_BAF) claimed in FIA_MBV_EXT.1.1 in the [cPP-Module for [BAF](#abbr_BAF) claimed in FIA_MBV_EXT.1.1 in the [cPP-Module for Biometric Enrollment and Verification, version Biometric Enrollment and Verification, version 2.0](https://github.com/biometricITC/cPP-biometrics/blob/master/Protection%20Prof 2.0](https://github.com/biometricITC/cPP-biometrics/blob/master/Protection%20Prof the evaluator shall authenticate by producing a biometric sample at the evaluator shall authenticate by producing a biometric sample at lock screen. As the biometric algorithms are performed, the lock screen. As the biometric algorithms are performed, the evaluator shall verify that sensitive images, audio, or other evaluator shall verify that sensitive images, audio, or other information identifying the user are kept secret and are not information identifying the user are kept secret and are not revealed to the user. Additionally, the evaluator shall produce a revealed to the user. Additionally, the evaluator shall produce a biometric sample that fails to authenticate and verify that the biometric sample that fails to authenticate and verify that the reasons for authentication failure (user mismatch, low sample reasons for authentication failure (user mismatch, low sample quality, etc.) are not revealed to the user. It is acceptable for quality, etc.) are not revealed to the user. It is acceptable for the [BAF](#abbr_BAF) to state that it was unable to physically read the [BAF](#abbr_BAF) to state that it was unable to physically read the biometric sample, for example, if the sensor is unclean or the the biometric sample, for example, if the sensor is unclean or the biometric sample was removed too quickly. However, specifics biometric sample was removed too quickly. However, specifics regarding why the presented biometric sample failed authentication regarding why the presented biometric sample failed authentication shall not be revealed to the user. shall not be revealed to the user. ::: ::: ::: ::: ::: ::: ::: ::: ::: ::: ::: {#FIA_UAU_EXT.1 .comp} ::: {#FIA_UAU_EXT.1 .comp} #### FIA_UAU_EXT.1 Authentication for Cryptographic Operation #### FIA_UAU_EXT.1 Authentication for Cryptographic Operation ::: element ::: element ::: {#FIA_UAU_EXT.1.1 .reqid} ::: {#FIA_UAU_EXT.1.1 .reqid} [FIA_UAU_EXT.1.1](#FIA_UAU_EXT.1.1){.abbr} [FIA_UAU_EXT.1.1](#FIA_UAU_EXT.1.1){.abbr} ::: ::: ::: reqdesc ::: reqdesc The [TSF](#abbr_TSF) shall require the user to present the Password The [TSF](#abbr_TSF) shall require the user to present the Password Authentication Factor prior to decryption of protected data and Authentication Factor prior to decryption of protected data and encrypted [DEKs](#abbr_DEK), KEKs and \[**selection**: [long-term | encrypted DEKs, KEKs and \[**selection**: [long-term trusted channel key trusted channel key material]{#_s_526 .selectable-content}, [all | material]{#fia_uau_ext.1.1_1 .selectable-content}, [all software-based software-based key storage]{#_s_527 .selectable-content}, [no other | key storage]{#fia_uau_ext.1.1_2 .selectable-content}, [no other keys]{#_s_528 .selectable-content}\] at startup. | keys]{#fia_uau_ext.1.1_3 .selectable-content}\] at startup. ::: appnote ::: appnote [Application Note: ]{.note-header}[The intent of this requirement is to [Application Note: ]{.note-header}[The intent of this requirement is to prevent decryption of protected data before the user has authorized to prevent decryption of protected data before the user has authorized to the device using the Password Authentication Factor. The Password the device using the Password Authentication Factor. The Password Authentication Factor is also required in order derive the key used to Authentication Factor is also required in order derive the key used to decrypt sensitive data, which includes software-based secure key decrypt sensitive data, which includes software-based secure key storage. ]{.note} | storage.]{.note} ::: ::: ::: ::: ::: ::: ::: {.activity_pane .hide} ::: {.activity_pane .hide} ::: activity_pane_header ::: activity_pane_header [[ Evaluation Activities [[ Evaluation Activities ]{.activity_pane_label}[]{.toggler}](#){onclick="toggle(this);return false;"} ]{.activity_pane_label}[]{.toggler}](#){onclick="toggle(this);return false;"} ::: ::: ::: activity_pane_body ::: activity_pane_body ::: component-activity-header ::: component-activity-header [FIA_UAU_EXT.1](#FIA_UAU_EXT.1) [FIA_UAU_EXT.1](#FIA_UAU_EXT.1) ::: ::: ::: eacategory ::: eacategory [TSS](#abbr_TSS) [TSS](#abbr_TSS) ::: ::: ::: ea ::: ea ::: ea ::: ea The evaluator shall verify that the [TSS](#abbr_TSS) section of the The evaluator shall verify that the [TSS](#abbr_TSS) section of the [ST](#abbr_ST) describes the process for decrypting protected data and [ST](#abbr_ST) describes the process for decrypting protected data and keys. The evaluator shall ensure that this process requires the user to keys. The evaluator shall ensure that this process requires the user to enter a Password Authentication Factor and, in accordance with enter a Password Authentication Factor and, in accordance with [FCS_CKM_EXT.3](#FCS_CKM_EXT.3), derives a [KEK](#abbr_KEK), which is [FCS_CKM_EXT.3](#FCS_CKM_EXT.3), derives a [KEK](#abbr_KEK), which is used to protect the software-based secure key storage and (optionally) used to protect the software-based secure key storage and (optionally) [DEKs](#abbr_DEK) for sensitive data, in accordance with | DEKs for sensitive data, in accordance with [FCS_STG_EXT.2](#FCS_STG_EXT.2).\ [FCS_STG_EXT.2](#FCS_STG_EXT.2).\ \ \ ::: ::: ::: ::: ::: eacategory ::: eacategory Guidance Guidance ::: ::: ::: ea ::: ea ::: ea ::: ea There are no guidance evaluation activities for this component.\ There are no guidance evaluation activities for this component.\ \ \ ::: ::: ::: ::: ::: eacategory ::: eacategory Tests Tests ::: ::: ::: ea ::: ea ::: ea ::: ea The following tests may be performed in conjunction with The following tests may be performed in conjunction with [FDP_DAR_EXT.1](#FDP_DAR_EXT.1) and [FDP_DAR_EXT.2](#FDP_DAR_EXT.2).\ [FDP_DAR_EXT.1](#FDP_DAR_EXT.1) and [FDP_DAR_EXT.2](#FDP_DAR_EXT.2).\ \ \ **Evaluation Activity Note:** The following test require the developer **Evaluation Activity Note:** The following test require the developer to provide access to a test platform that provides the evaluator with to provide access to a test platform that provides the evaluator with tools that are typically not found on consumer Mobile Device products.\ tools that are typically not found on consumer Mobile Device products.\ \ \ []{.testlist-} []{.testlist-} - [Test - [Test FIA_UAU_EXT.1:1](#unauthenticated-encrypted-data){#unauthenticated-encrypted-data FIA_UAU_EXT.1:1](#unauthenticated-encrypted-data){#unauthenticated-encrypted-data .defined}: The evaluator shall enable encryption of protected data .defined}: The evaluator shall enable encryption of protected data and require user authentication according to the AGD guidance. The and require user authentication according to the AGD guidance. The evaluator shall write, or the developer shall provide access to, an evaluator shall write, or the developer shall provide access to, an application that includes a unique string treated as protected application that includes a unique string treated as protected data.\ data.\ \ \ The evaluator shall reboot the device, use a tool provided by The evaluator shall reboot the device, use a tool provided by developer to search for the unique string within the application developer to search for the unique string within the application data, and verify that the unique string cannot be found. The data, and verify that the unique string cannot be found. The evaluator shall enter the Password Authentication Factor to access evaluator shall enter the Password Authentication Factor to access full device functionality, use a tool provided by the developer to full device functionality, use a tool provided by the developer to access the unique string within the application data, and verify access the unique string within the application data, and verify that the unique string can be found. that the unique string can be found. - [Test FIA_UAU_EXT.1:2](#_t_52){#_t_52 .defined}: \[conditional\] The - [Test FIA_UAU_EXT.1:2](#_t_52){#_t_52 .defined}: \[conditional\] The evaluator shall require user authentication according to the AGD evaluator shall require user authentication according to the AGD guidance. The evaluator shall store a key in the software-based guidance. The evaluator shall store a key in the software-based secure key storage.\ secure key storage.\ \ \ The evaluator shall lock the device, use a tool provided by The evaluator shall lock the device, use a tool provided by developer to access the key within the stored data, and verify that developer to access the key within the stored data, and verify that the key cannot be retrieved or accessed. The evaluator shall enter the key cannot be retrieved or accessed. The evaluator shall enter the Password Authentication Factor to access full device the Password Authentication Factor to access full device functionality, use a tool provided by developer to access the key, functionality, use a tool provided by developer to access the key, and verify that the key can be retrieved or accessed. and verify that the key can be retrieved or accessed. - [Test FIA_UAU_EXT.1:3](#_t_53){#_t_53 .defined}: \[conditional\] The - [Test FIA_UAU_EXT.1:3](#_t_53){#_t_53 .defined}: \[conditional\] The evaluator shall enable encryption of sensitive data and require user evaluator shall enable encryption of sensitive data and require user authentication according to the AGD guidance. The evaluator shall authentication according to the AGD guidance. The evaluator shall write, or the developer shall provide access to, an application that write, or the developer shall provide access to, an application that includes a unique string treated as sensitive data.\ includes a unique string treated as sensitive data.\ \ \ The evaluator shall lock the device, use a tool provided by The evaluator shall lock the device, use a tool provided by developer to attempt to access the unique string within the developer to attempt to access the unique string within the application data, and verify that the unique string cannot be found. application data, and verify that the unique string cannot be found. The evaluator shall enter the Password Authentication Factor to The evaluator shall enter the Password Authentication Factor to access full device functionality, use a tool provided by developer access full device functionality, use a tool provided by developer to access the unique string within the application data, and verify to access the unique string within the application data, and verify that the unique string can be retrieved. that the unique string can be retrieved. ::: ::: ::: ::: ::: ::: ::: ::: ::: ::: ::: {#FIA_UAU_EXT.2 .comp} ::: {#FIA_UAU_EXT.2 .comp} #### FIA_UAU_EXT.2 Timing of Authentication #### FIA_UAU_EXT.2 Timing of Authentication ::: element ::: element ::: {#FIA_UAU_EXT.2.1 .reqid} ::: {#FIA_UAU_EXT.2.1 .reqid} [FIA_UAU_EXT.2.1](#FIA_UAU_EXT.2.1){.abbr} [FIA_UAU_EXT.2.1](#FIA_UAU_EXT.2.1){.abbr} ::: ::: ::: reqdesc ::: reqdesc The [TSF](#abbr_TSF) shall allow \[**selection**: [\[**assignment**: The [TSF](#abbr_TSF) shall allow \[**selection**: [\[**assignment**: [list of actions]{.assignable-content}\]]{#_s_529 .selectable-content}, | [list of actions]{.assignable-content}\]]{#fia_uau_ext.2.1_1 [ no actions]{#_s_530 .selectable-content}\] on behalf of the user to be | .selectable-content}, [no actions]{#fia_uau_ext.2.1_3 performed before the user is authenticated. | .selectable-content}\] on behalf of the user to be performed before the > user is authenticated. ::: ::: ::: ::: ::: element ::: element ::: {#FIA_UAU_EXT.2.2 .reqid} ::: {#FIA_UAU_EXT.2.2 .reqid} [FIA_UAU_EXT.2.2](#FIA_UAU_EXT.2.2){.abbr} [FIA_UAU_EXT.2.2](#FIA_UAU_EXT.2.2){.abbr} ::: ::: ::: reqdesc ::: reqdesc The [TSF](#abbr_TSF) shall require each user to be successfully The [TSF](#abbr_TSF) shall require each user to be successfully authenticated before allowing any other [TSF](#abbr_TSF)-mediated authenticated before allowing any other [TSF](#abbr_TSF)-mediated actions on behalf of that user. actions on behalf of that user. ::: appnote ::: appnote [Application Note: ]{.note-header}[The security relevant actions allowed | [Application Note: ]{.note-header}[ The security relevant actions by unauthorized users in locked state must be listed. At a minimum the | allowed by unauthorized users in locked state must be listed. At a actions that correspond to the functions available to the user in | minimum the actions that correspond to the functions available to the [FMT_SMF_EXT.1](#FMT_SMF_EXT.1) and are allowed by unauthorized users in | user in [FMT_SMF_EXT.1](#FMT_SMF_EXT.1) and are allowed by unauthorized locked state should be listed. For example, if the user can | users in locked state should be listed. For example, if the user can enable/disable the camera per function [5](#mf-audioVisual) of enable/disable the camera per function [5](#mf-audioVisual) of [FMT_SMF_EXT.1](#FMT_SMF_EXT.1) and unauthorized users can take a [FMT_SMF_EXT.1](#FMT_SMF_EXT.1) and unauthorized users can take a picture when the device is in locked state, this action must be listed. picture when the device is in locked state, this action must be listed. ]{.note} ]{.note} ::: ::: ::: ::: ::: ::: ::: {.activity_pane .hide} ::: {.activity_pane .hide} ::: activity_pane_header ::: activity_pane_header [[ Evaluation Activities [[ Evaluation Activities ]{.activity_pane_label}[]{.toggler}](#){onclick="toggle(this);return false;"} ]{.activity_pane_label}[]{.toggler}](#){onclick="toggle(this);return false;"} ::: ::: ::: activity_pane_body ::: activity_pane_body ::: component-activity-header ::: component-activity-header [FIA_UAU_EXT.2](#FIA_UAU_EXT.2) [FIA_UAU_EXT.2](#FIA_UAU_EXT.2) ::: ::: ::: eacategory ::: eacategory [TSS](#abbr_TSS) [TSS](#abbr_TSS) ::: ::: ::: ea ::: ea ::: ea ::: ea The evaluator shall verify that the [TSS](#abbr_TSS) describes the The evaluator shall verify that the [TSS](#abbr_TSS) describes the actions allowed by unauthorized users in the locked state.\ actions allowed by unauthorized users in the locked state.\ \ \ ::: ::: ::: ::: ::: eacategory ::: eacategory Guidance Guidance ::: ::: ::: ea ::: ea ::: ea ::: ea There are no guidance evaluation activities for this component.\ There are no guidance evaluation activities for this component.\ \ \ ::: ::: ::: ::: ::: eacategory ::: eacategory Tests Tests ::: ::: ::: ea ::: ea ::: ea ::: ea The evaluator shall attempt to perform some actions not listed in the The evaluator shall attempt to perform some actions not listed in the selection while the device is in the locked state and verify that those selection while the device is in the locked state and verify that those actions do not succeed. actions do not succeed. ::: ::: ::: ::: ::: ::: ::: ::: ::: ::: ::: {#FIA_X509_EXT.6 .comp} ::: {#FIA_X509_EXT.6 .comp} #### FIA_X509_EXT.6 Request Validation of Certificates #### FIA_X509_EXT.6 Request Validation of Certificates ::: element ::: element ::: {#FIA_X509_EXT.6.1 .reqid} ::: {#FIA_X509_EXT.6.1 .reqid} [FIA_X509_EXT.6.1](#FIA_X509_EXT.6.1){.abbr} [FIA_X509_EXT.6.1](#FIA_X509_EXT.6.1){.abbr} ::: ::: ::: reqdesc ::: reqdesc The [TSF](#abbr_TSF) shall provide a certificate validation service to The [TSF](#abbr_TSF) shall provide a certificate validation service to applications. applications. ::: ::: ::: ::: ::: element ::: element ::: {#FIA_X509_EXT.6.2 .reqid} ::: {#FIA_X509_EXT.6.2 .reqid} [FIA_X509_EXT.6.2](#FIA_X509_EXT.6.2){.abbr} [FIA_X509_EXT.6.2](#FIA_X509_EXT.6.2){.abbr} ::: ::: ::: reqdesc ::: reqdesc The [TSF](#abbr_TSF) shall respond to the requesting application with The [TSF](#abbr_TSF) shall respond to the requesting application with the success or failure of the validation. the success or failure of the validation. ::: appnote ::: appnote [Application Note: ]{.note-header}[In order to comply with all of the | [Application Note: ]{.note-header}[ In order to comply with all of the rules in FIA_X509_EXT.1 as defined in the [Functional Package for X.509, rules in FIA_X509_EXT.1 as defined in the [Functional Package for X.509, version 1.0](https://www.niap-ccevs.org/protectionprofiles/511), version 1.0](https://www.niap-ccevs.org/protectionprofiles/511), multiple [API](#abbr_API) calls may be required; all of these calls multiple [API](#abbr_API) calls may be required; all of these calls should be clearly documented.]{.note} | should be clearly documented. ]{.note} ::: ::: ::: ::: ::: ::: ::: {.activity_pane .hide} ::: {.activity_pane .hide} ::: activity_pane_header ::: activity_pane_header [[ Evaluation Activities [[ Evaluation Activities ]{.activity_pane_label}[]{.toggler}](#){onclick="toggle(this);return false;"} ]{.activity_pane_label}[]{.toggler}](#){onclick="toggle(this);return false;"} ::: ::: ::: activity_pane_body ::: activity_pane_body ::: component-activity-header ::: component-activity-header [FIA_X509_EXT.6](#FIA_X509_EXT.6) [FIA_X509_EXT.6](#FIA_X509_EXT.6) ::: ::: ::: eacategory ::: eacategory [TSS](#abbr_TSS) [TSS](#abbr_TSS) ::: ::: ::: ea ::: ea ::: ea ::: ea The evaluator shall verify that the [API](#abbr_API) documentation The evaluator shall verify that the [API](#abbr_API) documentation provided in the [TSS](#abbr_TSS) (or other documentation) includes the provided in the [TSS](#abbr_TSS) (or other documentation) includes the security function (certificate validation) described in this security function (certificate validation) described in this requirement. This documentation shall be clear as to which results requirement. This documentation shall be clear as to which results indicate success and failure.\ indicate success and failure.\ \ \ ::: ::: ::: ::: ::: eacategory ::: eacategory Guidance Guidance ::: ::: ::: ea ::: ea ::: ea ::: ea There are no guidance evaluation activities for this component.\ There are no guidance evaluation activities for this component.\ \ \ ::: ::: ::: ::: ::: eacategory ::: eacategory Tests Tests ::: ::: ::: ea ::: ea ::: ea ::: ea The evaluator shall write, or the developer shall provide access to, an The evaluator shall write, or the developer shall provide access to, an application that requests certificate validation by the application that requests certificate validation by the [TSF](#abbr_TSF). The evaluator shall verify that the results from the [TSF](#abbr_TSF). The evaluator shall verify that the results from the validation match the expected results according to the [API](#abbr_API) validation match the expected results according to the [API](#abbr_API) documentation. This application may be used to verify that import, documentation. This application may be used to verify that import, removal, modification, and validation are performed correctly according removal, modification, and validation are performed correctly according to the tests required by [FDP_STG_EXT.1](#FDP_STG_EXT.1), to the tests required by [FDP_STG_EXT.1](#FDP_STG_EXT.1), [FTP_ITC_EXT.1](#FTP_ITC_EXT.1), [FMT_SMF_EXT.1](#FMT_SMF_EXT.1), and [FTP_ITC_EXT.1](#FTP_ITC_EXT.1), [FMT_SMF_EXT.1](#FMT_SMF_EXT.1), and FIA_X509_EXT.1 as defined in the [Functional Package for X.509, version FIA_X509_EXT.1 as defined in the [Functional Package for X.509, version 1.0](https://www.niap-ccevs.org/protectionprofiles/511). 1.0](https://www.niap-ccevs.org/protectionprofiles/511). ::: ::: ::: ::: ::: ::: ::: ::: ::: ::: ### 5.1.6 Class FMT: Security Management {#fmt .indexable level="3"} ### 5.1.6 Class FMT: Security Management {#fmt .indexable level="3"} Both the user and the administrator may manage the [TOE](#abbr_TOE). Both the user and the administrator may manage the [TOE](#abbr_TOE). This administrator is likely to be acting remotely and could be the This administrator is likely to be acting remotely and could be the Mobile Device Management ([MDM](#abbr_MDM)) Administrator acting through Mobile Device Management ([MDM](#abbr_MDM)) Administrator acting through an [MDM](#abbr_MDM) agent.\ an [MDM](#abbr_MDM) agent.\ \ \ The Administrator is responsible for management activities, including The Administrator is responsible for management activities, including setting the policy that is applied by the enterprise on the Mobile setting the policy that is applied by the enterprise on the Mobile Device. These management functions are likely to be a different set than Device. These management functions are likely to be a different set than those management functions provided to the user. Management functions those management functions provided to the user. Management functions that are provided to the user and not the administrator are listed in that are provided to the user and not the administrator are listed in [FMT_MOF_EXT.1.1](#FMT_MOF_EXT.1.1). Management functions for which the [FMT_MOF_EXT.1.1](#FMT_MOF_EXT.1.1). Management functions for which the administrator may adopt a policy that restricts the user from performing administrator may adopt a policy that restricts the user from performing that function are listed in [FMT_MOF_EXT.1.2](#FMT_MOF_EXT.1.2).\ that function are listed in [FMT_MOF_EXT.1.2](#FMT_MOF_EXT.1.2).\ \ \ [Table [18]{.counter}](#fmt_smf){.fmt_smf-ref [Table [18]{.counter}](#fmt_smf){.fmt_smf-ref onclick="showTarget('fmt_smf')"} identifies the management functions onclick="showTarget('fmt_smf')"} identifies the management functions that this [PP](#abbr_PP) defines, whether they are mandatory or that this [PP](#abbr_PP) defines, whether they are mandatory or optional, and specifies any restrictions on the roles that can perform optional, and specifies any restrictions on the roles that can perform these functions. This table is used with [FMT_MOF_EXT.1](#FMT_MOF_EXT.1) these functions. This table is used with [FMT_MOF_EXT.1](#FMT_MOF_EXT.1) and [FMT_SMF_EXT.1](#FMT_SMF_EXT.1) to specify the management functions and [FMT_SMF_EXT.1](#FMT_SMF_EXT.1) to specify the management functions that the [TOE](#abbr_TOE) supports and the roles that may perform these that the [TOE](#abbr_TOE) supports and the roles that may perform these functions. functions. ::: {#FMT_MOF_EXT.1 .comp} ::: {#FMT_MOF_EXT.1 .comp} #### FMT_MOF_EXT.1 Management of Security Functions Behavior #### FMT_MOF_EXT.1 Management of Security Functions Behavior ::: element ::: element ::: {#FMT_MOF_EXT.1.1 .reqid} ::: {#FMT_MOF_EXT.1.1 .reqid} [FMT_MOF_EXT.1.1](#FMT_MOF_EXT.1.1){.abbr} [FMT_MOF_EXT.1.1](#FMT_MOF_EXT.1.1){.abbr} ::: ::: ::: reqdesc ::: reqdesc The [TSF](#abbr_TSF) shall restrict the ability to perform the functions The [TSF](#abbr_TSF) shall restrict the ability to perform the functions \[*in the \"User Only\" column of [Table \[*in the \"User Only\" column of [Table [18]{.counter}](#fmt_smf){.fmt_smf-ref [18]{.counter}](#fmt_smf){.fmt_smf-ref onclick="showTarget('fmt_smf')"}*\] to the user. onclick="showTarget('fmt_smf')"}*\] to the user. ::: appnote ::: appnote [Application Note: ]{.note-header}[ ]{.note} [Application Note: ]{.note-header}[ ]{.note} The functions that have an \"M\" in the \"User Only\" column of [Table The functions that have an \"M\" in the \"User Only\" column of [Table [18]{.counter}](#fmt_smf){.fmt_smf-ref onclick="showTarget('fmt_smf')"} [18]{.counter}](#fmt_smf){.fmt_smf-ref onclick="showTarget('fmt_smf')"} are mandatory for this component, thus are restricted to the user, are mandatory for this component, thus are restricted to the user, meaning that the administrator cannot manage those functions. The meaning that the administrator cannot manage those functions. The functions that have an \"O\" in the \"User Only\" column are optional functions that have an \"O\" in the \"User Only\" column are optional and may be selected; and those functions with a \"-\" are not applicable and may be selected; and those functions with a \"-\" are not applicable and may not be selected. The [ST](#abbr_ST) author should select those and may not be selected. The [ST](#abbr_ST) author should select those security management functions that only the user may perform (i.e., the security management functions that only the user may perform (i.e., the ones the administrator may not perform). ones the administrator may not perform). The [ST](#abbr_ST) author may use a table in the [ST](#abbr_ST), The [ST](#abbr_ST) author may use a table in the [ST](#abbr_ST), indicating with clear demarcations (to be accompanied by an index) those indicating with clear demarcations (to be accompanied by an index) those functions that are restricted to the user (\"User Only\" column). The functions that are restricted to the user (\"User Only\" column). The [ST](#abbr_ST) author should iterate a row to indicate any variations in [ST](#abbr_ST) author should iterate a row to indicate any variations in the selectable sub-functions or assigned values with respect to the the selectable sub-functions or assigned values with respect to the values in the columns. A function cannot contain an \"M\" in both the values in the columns. A function cannot contain an \"M\" in both the \"User Only\" and \"Admin Only\" columns. \"User Only\" and \"Admin Only\" columns. For functions that are mandatory, any sub-functions not in a selection For functions that are mandatory, any sub-functions not in a selection are also mandatory and any assignments must contain at least one are also mandatory and any assignments must contain at least one assigned value. For non-selectable sub-functions in an optional assigned value. For non-selectable sub-functions in an optional function, all sub-functions outside a selection must be implemented in function, all sub-functions outside a selection must be implemented in order for the function to be listed. order for the function to be listed. ::: ::: ::: ::: ::: ::: ::: element ::: element ::: {#FMT_MOF_EXT.1.2 .reqid} ::: {#FMT_MOF_EXT.1.2 .reqid} [FMT_MOF_EXT.1.2](#FMT_MOF_EXT.1.2){.abbr} [FMT_MOF_EXT.1.2](#FMT_MOF_EXT.1.2){.abbr} ::: ::: ::: reqdesc ::: reqdesc The [TSF](#abbr_TSF) shall restrict the ability to perform the functions The [TSF](#abbr_TSF) shall restrict the ability to perform the functions \[*in the \"Admin Only\" column of [Table \[*in the \"Admin Only\" column of [Table [18]{.counter}](#fmt_smf){.fmt_smf-ref [18]{.counter}](#fmt_smf){.fmt_smf-ref onclick="showTarget('fmt_smf')"}*\] to the administrator when the device onclick="showTarget('fmt_smf')"}*\] to the administrator when the device is enrolled and according to the administrator-configured policy. is enrolled and according to the administrator-configured policy. ::: appnote ::: appnote [Application Note: ]{.note-header}[ ]{.note} [Application Note: ]{.note-header}[ ]{.note} As long as the device is enrolled in management, the administrator (of As long as the device is enrolled in management, the administrator (of the enterprise) must be guaranteed that minimum security functions of the enterprise) must be guaranteed that minimum security functions of the enterprise policy are enforced. Further restrictive policies can be the enterprise policy are enforced. Further restrictive policies can be applied at any time by the user on behalf of the user or other applied at any time by the user on behalf of the user or other administrators. administrators. The functions that have an \"M\" in the \"Admin Only\" column of [Table The functions that have an \"M\" in the \"Admin Only\" column of [Table [18]{.counter}](#fmt_smf){.fmt_smf-ref onclick="showTarget('fmt_smf')"} [18]{.counter}](#fmt_smf){.fmt_smf-ref onclick="showTarget('fmt_smf')"} are mandatory for this component; the functions that have an \"O\" in are mandatory for this component; the functions that have an \"O\" in the \"Admin Only\" column are optional and may be selected; and those the \"Admin Only\" column are optional and may be selected; and those functions with a \"-\" in the \"Admin Only\" column are not applicable functions with a \"-\" in the \"Admin Only\" column are not applicable and may not be selected. and may not be selected. The [ST](#abbr_ST) author should select those security management The [ST](#abbr_ST) author should select those security management functions that the administrator may restrict. The [ST](#abbr_ST) author functions that the administrator may restrict. The [ST](#abbr_ST) author may use a table in the [ST](#abbr_ST), indicating with clear may use a table in the [ST](#abbr_ST), indicating with clear demarcations (to be accompanied by an index) those functions that are demarcations (to be accompanied by an index) those functions that are and are not implemented with APIs for the administrator (as in the and are not implemented with APIs for the administrator (as in the \"Admin\" column). Additionally, the [ST](#abbr_ST) author should \"Admin\" column). Additionally, the [ST](#abbr_ST) author should demarcate which functions the user is prevented from accessing or demarcate which functions the user is prevented from accessing or performing (as in the \"Admin Only\" column). The [ST](#abbr_ST) author performing (as in the \"Admin Only\" column). The [ST](#abbr_ST) author should iterate a row to indicate any variations in the selectable should iterate a row to indicate any variations in the selectable sub-functions or assigned values with respect to the values in the sub-functions or assigned values with respect to the values in the columns. A function cannot contain an \"M\" in both the \"User Only\" columns. A function cannot contain an \"M\" in both the \"User Only\" and \"Admin Only\" columns. and \"Admin Only\" columns. For functions that are mandatory, any sub-functions not in a selection For functions that are mandatory, any sub-functions not in a selection are also mandatory and any assignments must contain at least one are also mandatory and any assignments must contain at least one assigned value. For non-selectable sub-functions in an optional assigned value. For non-selectable sub-functions in an optional function, all sub-functions outside the selection must be implemented in function, all sub-functions outside the selection must be implemented in order for the function to be listed. order for the function to be listed. ::: ::: ::: ::: ::: ::: ::: {.activity_pane .hide} ::: {.activity_pane .hide} ::: activity_pane_header ::: activity_pane_header [[ Evaluation Activities [[ Evaluation Activities ]{.activity_pane_label}[]{.toggler}](#){onclick="toggle(this);return false;"} ]{.activity_pane_label}[]{.toggler}](#){onclick="toggle(this);return false;"} ::: ::: ::: activity_pane_body ::: activity_pane_body ::: element-activity-header ::: element-activity-header [FMT_MOF_EXT.1.1](#FMT_MOF_EXT.1.1) [FMT_MOF_EXT.1.1](#FMT_MOF_EXT.1.1) ::: ::: ::: eacategory ::: eacategory [TSS](#abbr_TSS) [TSS](#abbr_TSS) ::: ::: ::: ea ::: ea The evaluator shall verify that the [TSS](#abbr_TSS) describes those The evaluator shall verify that the [TSS](#abbr_TSS) describes those management functions that may only be performed by the user and confirm management functions that may only be performed by the user and confirm that the [TSS](#abbr_TSS) does not include an Administrator that the [TSS](#abbr_TSS) does not include an Administrator [API](#abbr_API) for any of these management functions. This activity [API](#abbr_API) for any of these management functions. This activity will be performed in conjunction with [FMT_SMF_EXT.1](#FMT_SMF_EXT.1).\ will be performed in conjunction with [FMT_SMF_EXT.1](#FMT_SMF_EXT.1).\ \ \ ::: ::: ::: eacategory ::: eacategory Guidance Guidance ::: ::: ::: ea ::: ea There are no guidance evaluation activities for this element.\ There are no guidance evaluation activities for this element.\ \ \ ::: ::: ::: eacategory ::: eacategory Tests Tests ::: ::: ::: ea ::: ea There are no test evaluation activities for this element.\ There are no test evaluation activities for this element.\ \ \ ::: ::: ::: element-activity-header ::: element-activity-header [FMT_MOF_EXT.1.2](#FMT_MOF_EXT.1.2) [FMT_MOF_EXT.1.2](#FMT_MOF_EXT.1.2) ::: ::: ::: eacategory ::: eacategory [TSS](#abbr_TSS) [TSS](#abbr_TSS) ::: ::: ::: ea ::: ea The evaluator shall verify that the [TSS](#abbr_TSS) describes those The evaluator shall verify that the [TSS](#abbr_TSS) describes those management functions that may be performed by the Administrator, to management functions that may be performed by the Administrator, to include how the user is prevented from accessing, performing, or include how the user is prevented from accessing, performing, or relaxing the function (if applicable), and how applications/APIs are relaxing the function (if applicable), and how applications/APIs are prevented from modifying the Administrator configuration. The prevented from modifying the Administrator configuration. The [TSS](#abbr_TSS) also describes any functionality that is affected by [TSS](#abbr_TSS) also describes any functionality that is affected by administrator-configured policy and how. This activity will be performed administrator-configured policy and how. This activity will be performed in conjunction with [FMT_SMF_EXT.1](#FMT_SMF_EXT.1).\ in conjunction with [FMT_SMF_EXT.1](#FMT_SMF_EXT.1).\ \ \ ::: ::: ::: eacategory ::: eacategory Guidance Guidance ::: ::: ::: ea ::: ea There are no guidance evaluation activities for this element.\ There are no guidance evaluation activities for this element.\ \ \ ::: ::: ::: eacategory ::: eacategory Tests Tests ::: ::: ::: ea ::: ea []{.testlist-} []{.testlist-} - [Test FMT_MOF_EXT.1.2:1](#_t_54){#_t_54 .defined}: The evaluator - [Test FMT_MOF_EXT.1.2:1](#_t_54){#_t_54 .defined}: The evaluator shall use the test environment to deploy policies to Mobile Devices. shall use the test environment to deploy policies to Mobile Devices. - [Test FMT_MOF_EXT.1.2:2](#_t_55){#_t_55 .defined}: The evaluator - [Test FMT_MOF_EXT.1.2:2](#_t_55){#_t_55 .defined}: The evaluator shall create policies which collectively include all management shall create policies which collectively include all management functions which are controlled by the (enterprise) administrator and functions which are controlled by the (enterprise) administrator and cannot be overridden/relaxed by the user as defined in cannot be overridden/relaxed by the user as defined in [FMT_MOF_EXT.1.2](#FMT_MOF_EXT.1.2). The evaluator shall apply these [FMT_MOF_EXT.1.2](#FMT_MOF_EXT.1.2). The evaluator shall apply these policies to devices, attempt to override/relax each setting both as policies to devices, attempt to override/relax each setting both as the user (if a setting is available) and as an application (if an the user (if a setting is available) and as an application (if an [API](#abbr_API) is available), and ensure that the [TSF](#abbr_TSF) [API](#abbr_API) is available), and ensure that the [TSF](#abbr_TSF) does not permit it. Note that the user may still apply a more does not permit it. Note that the user may still apply a more restrictive policy than that of the administrator. restrictive policy than that of the administrator. - [Test FMT_MOF_EXT.1.2:3](#_t_56){#_t_56 .defined}: Additional - [Test FMT_MOF_EXT.1.2:3](#_t_56){#_t_56 .defined}: Additional testing of functions provided to the administrator are performed in testing of functions provided to the administrator are performed in conjunction with the testing activities for conjunction with the testing activities for [FMT_SMF_EXT.1.1](#FMT_SMF_EXT.1.1). [FMT_SMF_EXT.1.1](#FMT_SMF_EXT.1.1). ::: ::: ::: ::: ::: ::: ::: ::: ::: {#FMT_SMF_EXT.1 .comp} ::: {#FMT_SMF_EXT.1 .comp} #### FMT_SMF_EXT.1 Specification of Management Functions #### FMT_SMF_EXT.1 Specification of Management Functions ::: element ::: element ::: {#FMT_SMF_EXT.1.1 .reqid} ::: {#FMT_SMF_EXT.1.1 .reqid} [FMT_SMF_EXT.1.1](#FMT_SMF_EXT.1.1){.abbr} [FMT_SMF_EXT.1.1](#FMT_SMF_EXT.1.1){.abbr} ::: ::: ::: reqdesc ::: reqdesc The [TSF](#abbr_TSF) shall be capable of performing the following The [TSF](#abbr_TSF) shall be capable of performing the following management functions:\ management functions:\ \ \ **[Table [18]{.counter}: Management Functions]{#fmt_smf .ctr **[Table [18]{.counter}: Management Functions]{#fmt_smf .ctr myid="fmt_smf" counter-type="ct-Table"}**\ myid="fmt_smf" counter-type="ct-Table"}**\ \ \ Status Markers:\ Status Markers:\ M - Mandatory\ M - Mandatory\ O - Optional/Objective\ O - Optional/Objective\ +-----------+-----------+-----------+-----------+-----------+-----------+ +-----------+-----------+-----------+-----------+-----------+-----------+ | \# | M | Impl. | User Only | Admin | Admin | | \# | M | Impl. | User Only | Admin | Admin | | | anagement | | | | Only | | | anagement | | | | Only | | | Function | | | | | | | Function | | | | | +-----------+-----------+-----------+-----------+-----------+-----------+ +-----------+-----------+-----------+-----------+-----------+-----------+ | 1 | configure | ::: t | ::: t | ::: t | ::: t | | 1 | configure | ::: t | ::: t | ::: t | ::: t | | | password | ooltipped | ooltipped | ooltipped | ooltipped | | | password | ooltipped | ooltipped | ooltipped | ooltipped | | | policy: | M[Mandat | \-[ | M[Mandat | M[Mandat | | | policy: | M[Mandat | \-[ | M[Mandat | M[Mandat | | | | ory]{.too | N/A]{.too | ory]{.too | ory]{.too | | | | ory]{.too | N/A]{.too | ory]{.too | ory]{.too | | | - | ltiptext} | ltiptext} | ltiptext} | ltiptext} | | | - | ltiptext} | ltiptext} | ltiptext} | ltiptext} | | | Minimum | ::: | ::: | ::: | ::: | | | Minimum | ::: | ::: | ::: | ::: | | | | | | | | | | | | | | | | | password | | | | | | | password | | | | | | | | | | | | | | | | | | | | | length | | | | | | | length | | | | | | | - | | | | | | | - | | | | | | | Minimum | | | | | | | Minimum | | | | | | | | | | | | | | | | | | | | | password | | | | | | | password | | | | | | | c | | | | | | | c | | | | | | | omplexity | | | | | | | omplexity | | | | | | | - | | | | | | | - | | | | | | | Maximum | | | | | | | Maximum | | | | | | | | | | | | | | | | | | | | | password | | | | | | | password | | | | | | | | | | | | | | | | | | | | | lifetime | | | | | | | lifetime | | | | | +-----------+-----------+-----------+-----------+-----------+-----------+ +-----------+-----------+-----------+-----------+-----------+-----------+ | 2 | configure | ::: t | ::: t | ::: t | ::: t | | 2 | configure | ::: t | ::: t | ::: t | ::: t | | | session | ooltipped | ooltipped | ooltipped | ooltipped | | | session | ooltipped | ooltipped | ooltipped | ooltipped | | | locking | M[Mandat | \-[ | M[Mandat | M[Mandat | | | locking | M[Mandat | \-[ | M[Mandat | M[Mandat | | | policy: | ory]{.too | N/A]{.too | ory]{.too | ory]{.too | | | policy: | ory]{.too | N/A]{.too | ory]{.too | ory]{.too | | | | ltiptext} | ltiptext} | ltiptext} | ltiptext} | | | | ltiptext} | ltiptext} | ltiptext} | ltiptext} | | | - Sc | ::: | ::: | ::: | ::: | | | - Sc | ::: | ::: | ::: | ::: | | | reen-lock | | | | | | | reen-lock | | | | | | | | | | | | | | | | | | | | | enabled | | | | | | | enabled | | | | | | | /disabled | | | | | | | /disabled | | | | | | | - | | | | | | | - | | | | | | | Screen | | | | | | | Screen | | | | | | | lock | | | | | | | lock | | | | | | | | | | | | | | | | | | | | | timeout | | | | | | | timeout | | | | | | | - | | | | | | | - | | | | | | | Number | | | | | | | Number | | | | | | | of | | | | | | | of | | | | | | | authe | | | | | | | authe | | | | | | | ntication | | | | | | | ntication | | | | | | | | | | | | | | | | | | | | | failures | | | | | | | failures | | | | | +-----------+-----------+-----------+-----------+-----------+-----------+ +-----------+-----------+-----------+-----------+-----------+-----------+ | 3 | enabl | ::: t | ::: t | ::: t | ::: t | | 3 | enabl | ::: t | ::: t | ::: t | ::: t | | | e/disable | ooltipped | ooltipped | ooltipped | ooltipped | | | e/disable | ooltipped | ooltipped | ooltipped | ooltipped | | | the | M[Mandat | O | O | O | | | the | M[Mandat | O | O | O | | | [VPN](# | ory]{.too | [Optional | [Optional | [Optional | | | [VPN](# | ory]{.too | [Optional | [Optional | [Optional | | | abbr_VPN) | ltiptext} | /Conditio | /Conditio | /Conditio | | | abbr_VPN) | ltiptext} | /Conditio | /Conditio | /Conditio | | | pr | ::: | nal]{.too | nal]{.too | nal]{.too | | | pr | ::: | nal]{.too | nal]{.too | nal]{.too | | | otection: | | ltiptext} | ltiptext} | ltiptext} | | | otection: | | ltiptext} | ltiptext} | ltiptext} | | | | | ::: | ::: | ::: | | | | | ::: | ::: | ::: | | | - | | | | | | | - | | | | | | | Across | | | | | | | Across | | | | | | | | | | | | | | | | | | | | | device | | | | | | | device | | | | | | | | | | | | | | | | | | | | | : | | | | | < | | :: indent | | | | | < | | \[**sel | | | | | | | \[**sel | | | | | | | ection**: | | | | | | | ection**: | | | | | | | | | | | | | | | | | | | | | - [on a | | | | | | | - [on a | | | | | | | | | | | | | | | | | | | | | per-app | | | | | | | per-app | | | | | | | bas | | | | | | | bas | | | | | | | is]{#s-vp | | | | | | | is]{#s-vp | | | | | | | n-per-app | | | | | | | n-per-app | | | | | | | .s | | | | | | | .s | | | | | | | electable | | | | | | | electable | | | | | | | -content} | | | | | | | -content} | | | | | | | - [on a | | | | | | | - [on a | | | | | | | | | | | | | | | | | | | | | per-group | | | | | | | per-group | | | | | | | of | | | | | | | of | | | | | | | app | | | | | | | app | | | | | | | lications | | | | | | | lications | | | | | | | | | | | | | | | | | | | | | processes | | | | | | | processes | | | | | | | | | | | | | | | | | | | | | basis]{# | | | | | | | basis]{# | | | | | | | s-vpn-per | | | | | | | s-vpn-per | | | | | | | -appgroup | | | | | | | -appgroup | | | | | | | .s | | | | | | | .s | | | | | | | electable | | | | | | | electable | | | | | | | -content} | | | | | | | -content} | | | | | | | - [no | | | | | | | - [no | | | | | | | other | | | | | | | other | | | | | | | | | | | | | | | | | | | | | method | | | | | | | | method]{ | | | | | | | ]{#_s_533 | | | | | | | | #fmt_smf_ | | | | | > | | ext.1.1_1 | | | | | | | .s | | | | | | | .s | | | | | | | electable | | | | | | | electable | | | | | | | -content} | | | | | | | -content} | | | | | | | | | | | | | | | | | | | | | \] | | | | | | | \] | | | | | | | ::: | | | | | < +-----------+-----------+-----------+-----------+-----------+-----------+ +-----------+-----------+-----------+-----------+-----------+-----------+ | 4 | enabl | ::: t | ::: t | ::: t | ::: t | | 4 | enabl | ::: t | ::: t | ::: t | ::: t | | | e/disable | ooltipped | ooltipped | ooltipped | ooltipped | | | e/disable | ooltipped | ooltipped | ooltipped | ooltipped | | | \[**assi | M[Mandat | O | O | O | | | \[**assi | M[Mandat | O | O | O | | | gnment**: | ory]{.too | [Optional | [Optional | [Optional | | | gnment**: | ory]{.too | [Optional | [Optional | [Optional | | | [list of | ltiptext} | /Conditio | /Conditio | /Conditio | | | [list of | ltiptext} | /Conditio | /Conditio | /Conditio | | | all | ::: | nal]{.too | nal]{.too | nal]{.too | | | all | ::: | nal]{.too | nal]{.too | nal]{.too | | | ra | | ltiptext} | ltiptext} | ltiptext} | | | | rad | | ltiptext} | ltiptext} | ltiptext} | | | dios]{#a- | | ::: | ::: | ::: | | | | ios]{.ass | | ::: | ::: | ::: | | | mf-radios | | | | | < | | .ass | | | | | < | | ignable-c | | | | | | | ignable-c | | | | | | | ontent}\] | | | | | | | ontent}\] | | | | | +-----------+-----------+-----------+-----------+-----------+-----------+ +-----------+-----------+-----------+-----------+-----------+-----------+ | 5 | enabl | ::: t | ::: t | ::: t | ::: t | | 5 | enabl | ::: t | ::: t | ::: t | ::: t | | | e/disable | ooltipped | ooltipped | ooltipped | ooltipped | | | e/disable | ooltipped | ooltipped | ooltipped | ooltipped | | | \[**assi | M[Mandat | O | O | O | | | \[**assi | M[Mandat | O | O | O | | | gnment**: | ory]{.too | [Optional | [Optional | [Optional | | | gnment**: | ory]{.too | [Optional | [Optional | [Optional | | | [list of | ltiptext} | /Conditio | /Conditio | /Conditio | | | [list of | ltiptext} | /Conditio | /Conditio | /Conditio | | | audio or | ::: | nal]{.too | nal]{.too | nal]{.too | | | audio or | ::: | nal]{.too | nal]{.too | nal]{.too | | | visual | | ltiptext} | ltiptext} | ltiptext} | | | visual | | ltiptext} | ltiptext} | ltiptext} | | | c | | ::: | ::: | ::: | | | c | | ::: | ::: | ::: | | | ollection | | | | | | | ollection | | | | | | | d | | | | | | | | devic | | | | | | | evices]{# | | | | | | | | es]{.assi | | | | | | | a-audiovi | | | | | < | | sual-devs | | | | | < | | .assi | | | | | < | | gnable-co | | | | | | | gnable-co | | | | | | | ntent}\]: | | | | | | | ntent}\]: | | | | | | | | | | | | | | | | | | | | | - | | | | | | | - | | | | | | | Across | | | | | | | Across | | | | | | | | | | | | | | | | | | | | | device | | | | | | | device | | | | | | | | | | | | | | | | | | | | | : | | | | | < | | :: indent | | | | | < | | \[**sel | | | | | | | \[**sel | | | | | | | ection**: | | | | | | | ection**: | | | | | | | | | | | | | | | | | | | | | - [on a | | | | | | | - [on a | | | | | | | | | | | | | | | | | | | | | per-app | | | | | | | per-app | | | | | | | ba | | | | | | | ba | | | | | | | sis]{#s-a | | | | | | | sis]{#s-a | | | | | | | udiovisua | | | | | | | udiovisua | | | | | | | l-per-app | | | | | | | l-per-app | | | | | | | .s | | | | | | | .s | | | | | | | electable | | | | | | | electable | | | | | | | -content} | | | | | | | -content} | | | | | | | - [on a | | | | | | | - [on a | | | | | | | | | | | | | | | | | | | | | per-group | | | | | | | per-group | | | | | | | of | | | | | | | of | | | | | | | app | | | | | | | app | | | | | | | lications | | | | | | | lications | | | | | | | | | | | | | | | | | | | | | processes | | | | | | | processes | | | | | | | | | | | | | | | | | | | | | basis]{ | | | | | | | basis]{ | | | | | | | #s-audiov | | | | | | | #s-audiov | | | | | | | isual-per | | | | | | | isual-per | | | | | | | -appgroup | | | | | | | -appgroup | | | | | | | .s | | | | | | | .s | | | | | | | electable | | | | | | | electable | | | | | | | -content} | | | | | | | -content} | | | | | | | - [no | | | | | | | - [no | | | | | | | other | | | | | | | other | | | | | | | | | | | | | | | | | | | | | method | | | | | | | | method]{ | | | | | | | ]{#_s_536 | | | | | | | | #fmt_smf_ | | | | | > | | ext.1.1_2 | | | | | | | .s | | | | | | | .s | | | | | | | electable | | | | | | | electable | | | | | | | -content} | | | | | | | -content} | | | | | | | | | | | | | | | | | | | | | \] | | | | | | | \] | | | | | | | ::: | | | | | < +-----------+-----------+-----------+-----------+-----------+-----------+ +-----------+-----------+-----------+-----------+-----------+-----------+ | 6 | t | ::: t | ::: t | ::: t | ::: t | | 6 | t | ::: t | ::: t | ::: t | ::: t | | | ransition | ooltipped | ooltipped | ooltipped | ooltipped | | | ransition | ooltipped | ooltipped | ooltipped | ooltipped | | | to the | M[Mandat | \-[ | M[Mandat | \-[ | | | to the | M[Mandat | \-[ | M[Mandat | \-[ | | | locked | ory]{.too | N/A]{.too | ory]{.too | N/A]{.too | | | locked | ory]{.too | N/A]{.too | ory]{.too | N/A]{.too | | | state | ltiptext} | ltiptext} | ltiptext} | ltiptext} | | | state | ltiptext} | ltiptext} | ltiptext} | ltiptext} | | | | ::: | ::: | ::: | ::: | | | | ::: | ::: | ::: | ::: | +-----------+-----------+-----------+-----------+-----------+-----------+ +-----------+-----------+-----------+-----------+-----------+-----------+ | 7 | [TSF](# | ::: t | ::: t | ::: t | ::: t | | 7 | [TSF](# | ::: t | ::: t | ::: t | ::: t | | | abbr_TSF) | ooltipped | ooltipped | ooltipped | ooltipped | | | abbr_TSF) | ooltipped | ooltipped | ooltipped | ooltipped | | | wipe of | M[Mandat | \-[ | M[Mandat | \-[ | | | wipe of | M[Mandat | \-[ | M[Mandat | \-[ | | | protected | ory]{.too | N/A]{.too | ory]{.too | N/A]{.too | | | protected | ory]{.too | N/A]{.too | ory]{.too | N/A]{.too | | | data | ltiptext} | ltiptext} | ltiptext} | ltiptext} | | | data | ltiptext} | ltiptext} | ltiptext} | ltiptext} | | | | ::: | ::: | ::: | ::: | | | | ::: | ::: | ::: | ::: | +-----------+-----------+-----------+-----------+-----------+-----------+ +-----------+-----------+-----------+-----------+-----------+-----------+ | 8 | configure | ::: t | ::: t | ::: t | ::: t | | 8 | configure | ::: t | ::: t | ::: t | ::: t | | | ap | ooltipped | ooltipped | ooltipped | ooltipped | | | ap | ooltipped | ooltipped | ooltipped | ooltipped | | | plication | M[Mandat | \-[ | M[Mandat | M[Mandat | | | plication | M[Mandat | \-[ | M[Mandat | M[Mandat | | | ins | ory]{.too | N/A]{.too | ory]{.too | ory]{.too | | | ins | ory]{.too | N/A]{.too | ory]{.too | ory]{.too | | | tallation | ltiptext} | ltiptext} | ltiptext} | ltiptext} | | | tallation | ltiptext} | ltiptext} | ltiptext} | ltiptext} | | | policy by | ::: | ::: | ::: | ::: | | | policy by | ::: | ::: | ::: | ::: | | | | | | | | < | | : | | | | | < | | :: indent | | | | | < | | \[**sel | | | | | | | \[**sel | | | | | | | ection**: | | | | | | | ection**: | | | | | | | | | | | | | | | | | | | | | - [re | | | | | | | - [re | | | | | | | stricting | | | | | | | stricting | | | | | | | the | | | | | | | the | | | | | | | | | | | | | | | | | | | | | sources | | | | | | | sources | | | | | | | of | | | | | | | of | | | | | | | | | | | | | | | | | | | | | applic | | | | | | | applic | | | | | | | ations]{# | | | | | | | ations]{# | | | | | | | mf-appIns | | | | | | | mf-appIns | | | | | | | tallRules | | | | | | | tallRules | | | | | | | -restrict | | | | | | | -restrict | | | | | | | .s | | | | | | | .s | | | | | | | electable | | | | | | | electable | | | | | | | -content} | | | | | | | -content} | | | | | | | - [s | | | | | | | - [s | | | | | | | pecifying | | | | | | | pecifying | | | | | | | a set | | | | | | | a set | | | | | | | of | | | | | | | of | | | | | | | | | | | | | | | | | | | | | allowed | | | | | | | allowed | | | | | | | app | | | | | | | app | | | | | | | lications | | | | | | | lications | | | | | | | based | | | | | | | based | | | | | | | on | | | | | | | on | | | | | | | | | | | | | | | | | | | | | \[**assi | | | | | | | \[**assi | | | | | | | gnment**: | | | | | | | gnment**: | | | | | | | [ap | | | | | | | [ap | | | | | | | plication | | | | | | | plication | | | | | | | cha | | | | | | | cha | | | | | | | racterist | | | | | | | racterist | | | | | | | ics]{.ass | | | | | | | ics]{.ass | | | | | | | ignable-c | | | | | | | ignable-c | | | | | | | ontent}\] | | | | | | | ontent}\] | | | | | | | (an | | | | | | | (an | | | | | | | ap | | | | | | | ap | | | | | | | plication | | | | | | | plication | | | | | | | all | | | | | | | all | | | | | | | owlist)]{ | | | | | | | owlist)]{ | | | | | | | #mf-appIn | | | | | | | #mf-appIn | | | | | | | stallRule | | | | | | | stallRule | | | | | | | s-specify | | | | | | | s-specify | | | | | | | .s | | | | | | | .s | | | | | | | electable | | | | | | | electable | | | | | | | -content} | | | | | | | -content} | | | | | | | - | | | | | | | - | | | | | | | [denying | | | | | | | [denying | | | | | | | ins | | | | | | | ins | | | | | | | tallation | | | | | | | tallation | | | | | | | of | | | | | | | of | | | | | | | ap | | | | | | | ap | | | | | | | plication | | | | | | | plication | | | | | | | s]{#mf-ap | | | | | | | s]{#mf-ap | | | | | | | pInstallR | | | | | | | pInstallR | | | | | | | ules-deny | | | | | | | ules-deny | | | | | | | .s | | | | | | | .s | | | | | | | electable | | | | | | | electable | | | | | | | -content} | | | | | | | -content} | | | | | | | | | | | | | | | | | | | | | \] | | | | | | | \] | | | | | | | ::: | | | | | < +-----------+-----------+-----------+-----------+-----------+-----------+ +-----------+-----------+-----------+-----------+-----------+-----------+ | 9 | import | ::: t | ::: t | ::: t | ::: t | | 9 | import | ::: t | ::: t | ::: t | ::: t | | | keys or | ooltipped | ooltipped | ooltipped | ooltipped | | | keys or | ooltipped | ooltipped | ooltipped | ooltipped | | | secrets | M[Mandat | O | O | \-[ | | | secrets | M[Mandat | O | O | \-[ | | | into the | ory]{.too | [Optional | [Optional | N/A]{.too | | | into the | ory]{.too | [Optional | [Optional | N/A]{.too | | | secure | ltiptext} | /Conditio | /Conditio | ltiptext} | | | secure | ltiptext} | /Conditio | /Conditio | ltiptext} | | | key | ::: | nal]{.too | nal]{.too | ::: | | | key | ::: | nal]{.too | nal]{.too | ::: | | | storage | | ltiptext} | ltiptext} | | | | storage | | ltiptext} | ltiptext} | | | | | | ::: | ::: | | | | | | ::: | ::: | | +-----------+-----------+-----------+-----------+-----------+-----------+ +-----------+-----------+-----------+-----------+-----------+-----------+ | 10 | destroy | ::: t | ::: t | ::: t | ::: t | | 10 | destroy | ::: t | ::: t | ::: t | ::: t | | | imported | ooltipped | ooltipped | ooltipped | ooltipped | | | imported | ooltipped | ooltipped | ooltipped | ooltipped | | | keys or | M[Mandat | O | O | \-[ | | | keys or | M[Mandat | O | O | \-[ | | | secrets | ory]{.too | [Optional | [Optional | N/A]{.too | | | secrets | ory]{.too | [Optional | [Optional | N/A]{.too | | | and | ltiptext} | /Conditio | /Conditio | ltiptext} | | | and | ltiptext} | /Conditio | /Conditio | ltiptext} | | | \[**sel | ::: | nal]{.too | nal]{.too | ::: | | | \[**sel | ::: | nal]{.too | nal]{.too | ::: | | | ection**: | | ltiptext} | ltiptext} | | | | ection**: | | ltiptext} | ltiptext} | | | | [no other | | ::: | ::: | | | | [no other | | ::: | ::: | | | | keys or | | | | | | | keys or | | | | | | | secrets | | | | | | | | secrets]{ | | | | | | | ]{#_s_540 | | | | | | | | #fmt_smf_ | | | | | > | | ext.1.1_4 | | | | | | | .se | | | | | | | .se | | | | | | | lectable- | | | | | | | lectable- | | | | | | | content}, | | | | | | | content}, | | | | | | | [\[**assi | | | | | | | [\[**assi | | | | | | | gnment**: | | | | | | | gnment**: | | | | | | | [list of | | | | | | | [list of | | | | | | | other | | | | | | | other | | | | | | | c | | | | | | | c | | | | | | | ategories | | | | | | | ategories | | | | | | | of keys | | | | | | | of keys | | | | | | | or | | | | | | | or | | | | | | | secr | | | | | | | | secret | | | | | | | ets]{.ass | | | | | | | | s]{.assig | | | | | | | ignable-c | | | | | | | | nable-con | | | | | | | ontent}\] | | | | | | | | tent}\]]{ | | | | | | | ]{#_s_541 | | | | | | | | #fmt_smf_ | | | | | > | | ext.1.1_5 | | | | | | | .sel | | | | | | | .sel | | | | | | | ectable-c | | | | | | | ectable-c | | | | | | | ontent}\] | | | | | | | ontent}\] | | | | | | | in the | | | | | | | in the | | | | | | | secure | | | | | | | secure | | | | | | | key | | | | | | | key | | | | | | | storage | | | | | | | storage | | | | | +-----------+-----------+-----------+-----------+-----------+-----------+ +-----------+-----------+-----------+-----------+-----------+-----------+ | 11 | import | ::: t | ::: t | ::: t | ::: t | | 11 | import | ::: t | ::: t | ::: t | ::: t | | | X.509v3 | ooltipped | ooltipped | ooltipped | ooltipped | | | X.509v3 | ooltipped | ooltipped | ooltipped | ooltipped | | | cer | M[Mandat | \-[ | M[Mandat | O | | | cer | M[Mandat | \-[ | M[Mandat | O | | | tificates | ory]{.too | N/A]{.too | ory]{.too | [Optional | | | tificates | ory]{.too | N/A]{.too | ory]{.too | [Optional | | | into the | ltiptext} | ltiptext} | ltiptext} | /Conditio | | | into the | ltiptext} | ltiptext} | ltiptext} | /Conditio | | | Trust | ::: | ::: | ::: | nal]{.too | | | Trust | ::: | ::: | ::: | nal]{.too | | | Anchor | | | | ltiptext} | | | Anchor | | | | ltiptext} | | | Database | | | | ::: | | | Database | | | | ::: | +-----------+-----------+-----------+-----------+-----------+-----------+ +-----------+-----------+-----------+-----------+-----------+-----------+ | 12 | remove | ::: t | ::: t | ::: t | ::: t | | 12 | remove | ::: t | ::: t | ::: t | ::: t | | | imported | ooltipped | ooltipped | ooltipped | ooltipped | | | imported | ooltipped | ooltipped | ooltipped | ooltipped | | | X.509v3 | M[Mandat | O | O | \-[ | | | X.509v3 | M[Mandat | O | O | \-[ | | | cer | ory]{.too | [Optional | [Optional | N/A]{.too | | | cer | ory]{.too | [Optional | [Optional | N/A]{.too | | | tificates | ltiptext} | /Conditio | /Conditio | ltiptext} | | | tificates | ltiptext} | /Conditio | /Conditio | ltiptext} | | | and | ::: | nal]{.too | nal]{.too | ::: | | | and | ::: | nal]{.too | nal]{.too | ::: | | | \[**sel | | ltiptext} | ltiptext} | | | | \[**sel | | ltiptext} | ltiptext} | | | | ection**: | | ::: | ::: | | | | ection**: | | ::: | ::: | | | | [no other | | | | | | | [no other | | | | | | | X.509v3 | | | | | | | X.509v3 | | | | | | | cer | | | | | | | | certi | | | | | | | tificates | | | | | | | | ficates]{ | | | | | | | ]{#_s_542 | | | | | | | | #fmt_smf_ | | | | | > | | ext.1.1_7 | | | | | | | .se | | | | | | | .se | | | | | | | lectable- | | | | | | | lectable- | | | | | | | content}, | | | | | | | content}, | | | | | | | [\[**assi | | | | | | | [\[**assi | | | | | | | gnment**: | | | | | | | gnment**: | | | | | | | [list of | | | | | | | [list of | | | | | | | other | | | | | | | other | | | | | | | c | | | | | | | c | | | | | | | ategories | | | | | | | ategories | | | | | | | of | | | | | | | of | | | | | | | X.509v3 | | | | | | | X.509v3 | | | | | | | certifica | | | | | | | | ce | | | | | | | tes]{.ass | | | | | | | | rtificate | | | | | | | ignable-c | | | | | | | | s]{.assig | | | | | | | ontent}\] | | | | | | | | nable-con | | | | | | | ]{#_s_543 | | | | | | | | tent}\]]{ | | | | | > | | #fmt_smf_ | | | | | > | | ext.1.1_8 | | | | | | | .sel | | | | | | | .sel | | | | | | | ectable-c | | | | | | | ectable-c | | | | | | | ontent}\] | | | | | | | ontent}\] | | | | | | | in the | | | | | | | in the | | | | | | | Trust | | | | | | | Trust | | | | | | | Anchor | | | | | | | Anchor | | | | | | | Database | | | | | | | Database | | | | | +-----------+-----------+-----------+-----------+-----------+-----------+ +-----------+-----------+-----------+-----------+-----------+-----------+ | 13 | enroll | ::: t | ::: t | ::: t | ::: t | | 13 | enroll | ::: t | ::: t | ::: t | ::: t | | | the | ooltipped | ooltipped | ooltipped | ooltipped | | | the | ooltipped | ooltipped | ooltipped | ooltipped | | | [TOE](# | M[Mandat | O | O | O | | | [TOE](# | M[Mandat | O | O | O | | | abbr_TOE) | ory]{.too | [Optional | [Optional | [Optional | | | abbr_TOE) | ory]{.too | [Optional | [Optional | [Optional | | | in | ltiptext} | /Conditio | /Conditio | /Conditio | | | in | ltiptext} | /Conditio | /Conditio | /Conditio | | | m | ::: | nal]{.too | nal]{.too | nal]{.too | | | m | ::: | nal]{.too | nal]{.too | nal]{.too | | | anagement | | ltiptext} | ltiptext} | ltiptext} | | | anagement | | ltiptext} | ltiptext} | ltiptext} | | | | | ::: | ::: | ::: | | | | | ::: | ::: | ::: | +-----------+-----------+-----------+-----------+-----------+-----------+ +-----------+-----------+-----------+-----------+-----------+-----------+ | 14 | remove | ::: t | ::: t | ::: t | ::: t | | 14 | remove | ::: t | ::: t | ::: t | ::: t | | | app | ooltipped | ooltipped | ooltipped | ooltipped | | | app | ooltipped | ooltipped | ooltipped | ooltipped | | | lications | M[Mandat | \-[ | M[Mandat | O | | | lications | M[Mandat | \-[ | M[Mandat | O | | | | ory]{.too | N/A]{.too | ory]{.too | [Optional | | | | ory]{.too | N/A]{.too | ory]{.too | [Optional | | | | ltiptext} | ltiptext} | ltiptext} | /Conditio | | | | ltiptext} | ltiptext} | ltiptext} | /Conditio | | | | ::: | ::: | ::: | nal]{.too | | | | ::: | ::: | ::: | nal]{.too | | | | | | | ltiptext} | | | | | | | ltiptext} | | | | | | | ::: | | | | | | | ::: | +-----------+-----------+-----------+-----------+-----------+-----------+ +-----------+-----------+-----------+-----------+-----------+-----------+ | 15 | update | ::: t | ::: t | ::: t | ::: t | | 15 | update | ::: t | ::: t | ::: t | ::: t | | | system | ooltipped | ooltipped | ooltipped | ooltipped | | | system | ooltipped | ooltipped | ooltipped | ooltipped | | | software | M[Mandat | \-[ | M[Mandat | O | | | software | M[Mandat | \-[ | M[Mandat | O | | | | ory]{.too | N/A]{.too | ory]{.too | [Optional | | | | ory]{.too | N/A]{.too | ory]{.too | [Optional | | | | ltiptext} | ltiptext} | ltiptext} | /Conditio | | | | ltiptext} | ltiptext} | ltiptext} | /Conditio | | | | ::: | ::: | ::: | nal]{.too | | | | ::: | ::: | ::: | nal]{.too | | | | | | | ltiptext} | | | | | | | ltiptext} | | | | | | | ::: | | | | | | | ::: | +-----------+-----------+-----------+-----------+-----------+-----------+ +-----------+-----------+-----------+-----------+-----------+-----------+ | 16 | install | ::: t | ::: t | ::: t | ::: t | | 16 | install | ::: t | ::: t | ::: t | ::: t | | | app | ooltipped | ooltipped | ooltipped | ooltipped | | | app | ooltipped | ooltipped | ooltipped | ooltipped | | | lications | M[Mandat | \-[ | M[Mandat | O | | | lications | M[Mandat | \-[ | M[Mandat | O | | | | ory]{.too | N/A]{.too | ory]{.too | [Optional | | | | ory]{.too | N/A]{.too | ory]{.too | [Optional | | | | ltiptext} | ltiptext} | ltiptext} | /Conditio | | | | ltiptext} | ltiptext} | ltiptext} | /Conditio | | | | ::: | ::: | ::: | nal]{.too | | | | ::: | ::: | ::: | nal]{.too | | | | | | | ltiptext} | | | | | | | ltiptext} | | | | | | | ::: | | | | | | | ::: | +-----------+-----------+-----------+-----------+-----------+-----------+ +-----------+-----------+-----------+-----------+-----------+-----------+ | 17 | remove | ::: t | ::: t | ::: t | ::: t | | 17 | remove | ::: t | ::: t | ::: t | ::: t | | | E | ooltipped | ooltipped | ooltipped | ooltipped | | | E | ooltipped | ooltipped | ooltipped | ooltipped | | | nterprise | M[Mandat | \-[ | M[Mandat | \-[ | | | nterprise | M[Mandat | \-[ | M[Mandat | \-[ | | | app | ory]{.too | N/A]{.too | ory]{.too | N/A]{.too | | | app | ory]{.too | N/A]{.too | ory]{.too | N/A]{.too | | | lications | ltiptext} | ltiptext} | ltiptext} | ltiptext} | | | lications | ltiptext} | ltiptext} | ltiptext} | ltiptext} | | | | ::: | ::: | ::: | ::: | | | | ::: | ::: | ::: | ::: | +-----------+-----------+-----------+-----------+-----------+-----------+ +-----------+-----------+-----------+-----------+-----------+-----------+ | 18 | enabl | ::: t | ::: t | ::: t | ::: t | | 18 | enabl | ::: t | ::: t | ::: t | ::: t | | | e/disable | ooltipped | ooltipped | ooltipped | ooltipped | | | e/disable | ooltipped | ooltipped | ooltipped | ooltipped | | | display | M[Mandat | O | O | O | | | display | M[Mandat | O | O | O | | | not | ory]{.too | [Optional | [Optional | [Optional | | | not | ory]{.too | [Optional | [Optional | [Optional | | | ification | ltiptext} | /Conditio | /Conditio | /Conditio | | | ification | ltiptext} | /Conditio | /Conditio | /Conditio | | | in the | ::: | nal]{.too | nal]{.too | nal]{.too | | | in the | ::: | nal]{.too | nal]{.too | nal]{.too | | | locked | | ltiptext} | ltiptext} | ltiptext} | | | locked | | ltiptext} | ltiptext} | ltiptext} | | | state of: | | ::: | ::: | ::: | | | state of: | | ::: | ::: | ::: | | | \[**sel | | | | | | | \[**sel | | | | | | | ection**: | | | | | | | ection**: | | | | | | | | | | | | | | | | | | | | | - | | | | | | | - | | | | | | | [email | | | | | | | [email | | | | | | | noti | | | | | | | | | | | | | | | fications | | | | | | | | notific | | | | | | | ]{#_s_544 | | | | | | | | ations]{# | | | | | > | | fmt_smf_e | | | | | > | | xt.1.1_10 | | | | | | | .s | | | | | | | .s | | | | | | | electable | | | | | | | electable | | | | | | | -content} | | | | | | | -content} | | | | | | | - | | | | | | | - | | | | | | | [calendar | | | | | | | [calendar | | | | | | | app | | | | | | | | | | | | | | | ointments | | | | | | | | appoin | | | | | | | ]{#_s_545 | | | | | | | | tments]{# | | | | | > | | fmt_smf_e | | | | | > | | xt.1.1_11 | | | | | | | .s | | | | | | | .s | | | | | | | electable | | | | | | | electable | | | | | | | -content} | | | | | | | -content} | | | | | | | - | | | | | | | - | | | | | | | [contact | | | | | | | [contact | | | | | | | a | | | | | | | a | | | | | | | ssociated | | | | | | | ssociated | | | | | | | with | | | | | | | with | | | | | | | phone | | | | | | | phone | | | | | | | call | | | | | | | call | | | | | | | not | | | | | | | | | | | | | | | ification | | | | | | | | notifi | | | | | | | ]{#_s_546 | | | | | | | | cation]{# | | | | | > | | fmt_smf_e | | | | | > | | xt.1.1_12 | | | | | | | .s | | | | | | | .s | | | | | | | electable | | | | | | | electable | | | | | | | -content} | | | | | | | -content} | | | | | | | - [text | | | | | | | - [text | | | | | | | | | | | | | | | | | | | | | message | | | | | | | message | | | | | | | not | | | | | | | | | | | | | | | ification | | | | | | | | notifi | | | | | | | ]{#_s_547 | | | | | | | | cation]{# | | | | | > | | fmt_smf_e | | | | | > | | xt.1.1_13 | | | | | | | .s | | | | | | | .s | | | | | | | electable | | | | | | | electable | | | | | | | -content} | | | | | | | -content} | | | | | | | - | | | | | | | - | | | | | | | [\[**assi | | | | | | | [\[**assi | | | | | | | gnment**: | | | | | | | gnment**: | | | | | | | | | | | | | | | | | | | | | [other | | | | | | | [other | | | | | | | | | | | | | | | | | | | | | applicat | | | | | | | applicat | | | | | | | ion-based | | | | | | | ion-based | | | | | | | n | | | | | | | | noti | | | | | | | otificati | | | | | | | | fications | | | | | | | ons]{.ass | | | | | | | | ]{.assign | | | | | | | ignable-c | | | | | | | | able-cont | | | | | | | ontent}\] | | | | | | | | ent}\]]{# | | | | | | | ]{#_s_548 | | | | | | | | fmt_smf_e | | | | | > | | xt.1.1_14 | | | | | | | .s | | | | | | | .s | | | | | | | electable | | | | | | | electable | | | | | | | -content} | | | | | | | -content} | | | | | | | - [all | | | | | | | - [all | | | | | | | noti | | | | | | | | | | | | | | | fications | | | | | | | | notific | | | | | | | ]{#_s_549 | | | | | | | | ations]{# | | | | | > | | fmt_smf_e | | | | | > | | xt.1.1_16 | | | | | | | .s | | | | | | | .s | | | | | | | electable | | | | | | | electable | | | | | | | -content} | | | | | | | -content} | | | | | | | | | | | | | | | | | | | | | \] | | | | | | | \] | | | | | +-----------+-----------+-----------+-----------+-----------+-----------+ +-----------+-----------+-----------+-----------+-----------+-----------+ | 19 | enable | ::: t | ::: t | ::: t | ::: t | | 19 | enable | ::: t | ::: t | ::: t | ::: t | | | data-at | ooltipped | ooltipped | ooltipped | ooltipped | | | data-at | ooltipped | ooltipped | ooltipped | ooltipped | | | rest | M[Mandat | O | O | O | | | rest | M[Mandat | O | O | O | | | p | ory]{.too | [Optional | [Optional | [Optional | | | p | ory]{.too | [Optional | [Optional | [Optional | | | rotection | ltiptext} | /Conditio | /Conditio | /Conditio | | | rotection | ltiptext} | /Conditio | /Conditio | /Conditio | | | | ::: | nal]{.too | nal]{.too | nal]{.too | | | | ::: | nal]{.too | nal]{.too | nal]{.too | | | | | ltiptext} | ltiptext} | ltiptext} | | | | | ltiptext} | ltiptext} | ltiptext} | | | | | ::: | ::: | ::: | | | | | ::: | ::: | ::: | +-----------+-----------+-----------+-----------+-----------+-----------+ +-----------+-----------+-----------+-----------+-----------+-----------+ | 20 | enable | ::: t | ::: t | ::: t | ::: t | | 20 | enable | ::: t | ::: t | ::: t | ::: t | | | removable | ooltipped | ooltipped | ooltipped | ooltipped | | | removable | ooltipped | ooltipped | ooltipped | ooltipped | | | media's | M[Mandat | O | O | O | | | media's | M[Mandat | O | O | O | | | dat | ory]{.too | [Optional | [Optional | [Optional | | | dat | ory]{.too | [Optional | [Optional | [Optional | | | a-at-rest | ltiptext} | /Conditio | /Conditio | /Conditio | | | a-at-rest | ltiptext} | /Conditio | /Conditio | /Conditio | | | p | ::: | nal]{.too | nal]{.too | nal]{.too | | | p | ::: | nal]{.too | nal]{.too | nal]{.too | | | rotection | | ltiptext} | ltiptext} | ltiptext} | | | rotection | | ltiptext} | ltiptext} | ltiptext} | | | | | ::: | ::: | ::: | | | | | ::: | ::: | ::: | +-----------+-----------+-----------+-----------+-----------+-----------+ +-----------+-----------+-----------+-----------+-----------+-----------+ | 21 | enabl | ::: t | ::: t | ::: t | ::: t | | 21 | enabl | ::: t | ::: t | ::: t | ::: t | | | e/disable | ooltipped | ooltipped | ooltipped | ooltipped | | | e/disable | ooltipped | ooltipped | ooltipped | ooltipped | | | location | M[Mandat | O | O | O | | | location | M[Mandat | O | O | O | | | services: | ory]{.too | [Optional | [Optional | [Optional | | | services: | ory]{.too | [Optional | [Optional | [Optional | | | | ltiptext} | /Conditio | /Conditio | /Conditio | | | | ltiptext} | /Conditio | /Conditio | /Conditio | | | - | ::: | nal]{.too | nal]{.too | nal]{.too | | | - | ::: | nal]{.too | nal]{.too | nal]{.too | | | Across | | ltiptext} | ltiptext} | ltiptext} | | | Across | | ltiptext} | ltiptext} | ltiptext} | | | | | ::: | ::: | ::: | | | | | ::: | ::: | ::: | | | device | | | | | | | device | | | | | | | | | | | | | | | | | | | | | : | | | | | < | | :: indent | | | | | < | | \[**sel | | | | | | | \[**sel | | | | | | | ection**: | | | | | | | ection**: | | | | | | | | | | | | | | | | | | | | | - [on a | | | | | | | - [on a | | | | | | | | | | | | | | | | | | | | | per-app | | | | | | | per-app | | | | | | | | | | | | | | | | | | | | | basis]{#m | | | | | | | basis]{#m | | | | | | | f-locatio | | | | | | | f-locatio | | | | | | | n-per_app | | | | | | | n-per_app | | | | | | | .s | | | | | | | .s | | | | | | | electable | | | | | | | electable | | | | | | | -content} | | | | | | | -content} | | | | | | | - [on a | | | | | | | - [on a | | | | | | | | | | | | | | | | | | | | | per-group | | | | | | | per-group | | | | | | | of | | | | | | | of | | | | | | | app | | | | | | | app | | | | | | | lications | | | | | | | lications | | | | | | | | | | | | | | | | | | | | | processes | | | | | | | processes | | | | | | | basis | | | | | | | | | | | | | | | ]{#_s_551 | | | | | | | | basis]{# | | | | | > | | fmt_smf_e | | | | | > | | xt.1.1_17 | | | | | | | .s | | | | | | | .s | | | | | | | electable | | | | | | | electable | | | | | | | -content} | | | | | | | -content} | | | | | | | - [no | | | | | | | - [no | | | | | | | other | | | | | | | other | | | | | | | | | | | | | | | | | | | | | method | | | | | | | | method]{# | | | | | | | ]{#_s_552 | | | | | | | | fmt_smf_e | | | | | > | | xt.1.1_18 | | | | | | | .s | | | | | | | .s | | | | | | | electable | | | | | | | electable | | | | | | | -content} | | | | | | | -content} | | | | | | | | | | | | | | | | | | | | | \] | | | | | | | \] | | | | | | | ::: | | | | | < +-----------+-----------+-----------+-----------+-----------+-----------+ +-----------+-----------+-----------+-----------+-----------+-----------+ | 22 | enabl | ::: t | ::: t | ::: t | ::: t | | 22 | enabl | ::: t | ::: t | ::: t | ::: t | | | e/disable | ooltipped | ooltipped | ooltipped | ooltipped | | | e/disable | ooltipped | ooltipped | ooltipped | ooltipped | | | the use | O | O | O | O | | | the use | O | O | O | O | | | of | [Optional | [Optional | [Optional | [Optional | | | of | [Optional | [Optional | [Optional | [Optional | | | \[**sel | /Conditio | /Conditio | /Conditio | /Conditio | | | \[**sel | /Conditio | /Conditio | /Conditio | /Conditio | | | ection**: | nal]{.too | nal]{.too | nal]{.too | nal]{.too | | | ection**: | nal]{.too | nal]{.too | nal]{.too | nal]{.too | | | [ | ltiptext} | ltiptext} | ltiptext} | ltiptext} | | | [ | ltiptext} | ltiptext} | ltiptext} | ltiptext} | | | Biometric | ::: | ::: | ::: | ::: | | | Biometric | ::: | ::: | ::: | ::: | | | Authe | | | | | | | Authe | | | | | | | ntication | | | | | | | ntication | | | | | | | Factor | | | | | | | | Factor]{# | | | | | | | ]{#_s_553 | | | | | | | | fmt_smf_e | | | | | > | | xt.1.1_19 | | | | | | | .se | | | | | | | .se | | | | | | | lectable- | | | | | | | lectable- | | | | | | | content}, | | | | | | | content}, | | | | | | | [Hybrid | | | | | | | [Hybrid | | | | | | | Authe | | | | | | | Authe | | | | | | | ntication | | | | | | | ntication | | | | | | | Factor | | | | | | | | Factor]{# | | | | | | | ]{#_s_554 | | | | | | | | fmt_smf_e | | | | | > | | xt.1.1_20 | | | | | | | .sel | | | | | | | .sel | | | | | | | ectable-c | | | | | | | ectable-c | | | | | | | ontent}\] | | | | | | | ontent}\] | | | | | +-----------+-----------+-----------+-----------+-----------+-----------+ +-----------+-----------+-----------+-----------+-----------+-----------+ | 23 | configure | ::: t | ::: t | ::: t | ::: t | | 23 | configure | ::: t | ::: t | ::: t | ::: t | | | whether | ooltipped | ooltipped | ooltipped | ooltipped | | | whether | ooltipped | ooltipped | ooltipped | ooltipped | | | to allow | O | O | O | O | | | to allow | O | O | O | O | | | or | [Optional | [Optional | [Optional | [Optional | | | or | [Optional | [Optional | [Optional | [Optional | | | disallow | /Conditio | /Conditio | /Conditio | /Conditio | | | disallow | /Conditio | /Conditio | /Conditio | /Conditio | | | esta | nal]{.too | nal]{.too | nal]{.too | nal]{.too | | | esta | nal]{.too | nal]{.too | nal]{.too | nal]{.too | | | blishment | ltiptext} | ltiptext} | ltiptext} | ltiptext} | | | blishment | ltiptext} | ltiptext} | ltiptext} | ltiptext} | | | of | ::: | ::: | ::: | ::: | | | of | ::: | ::: | ::: | ::: | | | \[**assi | | | | | | | \[**assi | | | | | | | gnment**: | | | | | | | gnment**: | | | | | | | [con | | | | | | | [con | | | | | | | figurable | | | | | | | figurable | | | | | | | trusted | | | | | | | trusted | | | | | | | channel | | | | | | | channel | | | | | | | in | | | | | | | in | | | | | | | [FTP_ITC | | | | | | | [FTP_ITC | | | | | | | _EXT.1.1] | | | | | | | _EXT.1.1] | | | | | | | (#FTP_ITC | | | | | | | (#FTP_ITC | | | | | | | _EXT.1.1) | | | | | | | _EXT.1.1) | | | | | | | or | | | | | | | or | | | | | | | [FDP_U | | | | | | | [FDP_U | | | | | | | PC_EXT.1. | | | | | | | PC_EXT.1. | | | | | | | 1/APPS](# | | | | | | | 1/APPS](# | | | | | | | FDP_UPC_E | | | | | | | FDP_UPC_E | | | | | | | XT.1.1/AP | | | | | | | XT.1.1/AP | | | | | | | PS)]{.ass | | | | | | | PS)]{.ass | | | | | | | ignable-c | | | | | | | ignable-c | | | | | | | ontent}\] | | | | | | | ontent}\] | | | | | | | if the | | | | | | | if the | | | | | | | peer or | | | | | | | peer or | | | | | | | server | | | | | | | server | | | | | | | ce | | | | | | | ce | | | | | | | rtificate | | | | | | | rtificate | | | | | | | is deemed | | | | | | | is deemed | | | | | | | invalid. | | | | | | | invalid. | | | | | +-----------+-----------+-----------+-----------+-----------+-----------+ +-----------+-----------+-----------+-----------+-----------+-----------+ | 24 | enabl | ::: t | ::: t | ::: t | ::: t | | 24 | enabl | ::: t | ::: t | ::: t | ::: t | | | e/disable | ooltipped | ooltipped | ooltipped | ooltipped | | | e/disable | ooltipped | ooltipped | ooltipped | ooltipped | | | all data | O | O | O | O | | | all data | O | O | O | O | | | signaling | [Optional | [Optional | [Optional | [Optional | | | signaling | [Optional | [Optional | [Optional | [Optional | | | over | /Conditio | /Conditio | /Conditio | /Conditio | | | over | /Conditio | /Conditio | /Conditio | /Conditio | | | \[**assi | nal]{.too | nal]{.too | nal]{.too | nal]{.too | | | \[**assi | nal]{.too | nal]{.too | nal]{.too | nal]{.too | | | gnment**: | ltiptext} | ltiptext} | ltiptext} | ltiptext} | | | gnment**: | ltiptext} | ltiptext} | ltiptext} | ltiptext} | | | [list of | ::: | ::: | ::: | ::: | | | [list of | ::: | ::: | ::: | ::: | | | e | | | | | | | e | | | | | | | xternally | | | | | | | xternally | | | | | | | a | | | | | | | a | | | | | | | ccessible | | | | | | | ccessible | | | | | | | hardware | | | | | | | hardware | | | | | | | po | | | | | | | po | | | | | | | rts]{.ass | | | | | | | rts]{.ass | | | | | | | ignable-c | | | | | | | ignable-c | | | | | | | ontent}\] | | | | | | | ontent}\] | | | | | +-----------+-----------+-----------+-----------+-----------+-----------+ +-----------+-----------+-----------+-----------+-----------+-----------+ | 25 | enabl | ::: t | ::: t | ::: t | ::: t | | 25 | enabl | ::: t | ::: t | ::: t | ::: t | | | e/disable | ooltipped | ooltipped | ooltipped | ooltipped | | | e/disable | ooltipped | ooltipped | ooltipped | ooltipped | | | \[**assi | O | O | O | O | | | \[**assi | O | O | O | O | | | gnment**: | [Optional | [Optional | [Optional | [Optional | | | gnment**: | [Optional | [Optional | [Optional | [Optional | | | [list of | /Conditio | /Conditio | /Conditio | /Conditio | | | [list of | /Conditio | /Conditio | /Conditio | /Conditio | | | protocols | nal]{.too | nal]{.too | nal]{.too | nal]{.too | | | protocols | nal]{.too | nal]{.too | nal]{.too | nal]{.too | | | where the | ltiptext} | ltiptext} | ltiptext} | ltiptext} | | | where the | ltiptext} | ltiptext} | ltiptext} | ltiptext} | | | device | ::: | ::: | ::: | ::: | | | device | ::: | ::: | ::: | ::: | | | acts as a | | | | | | | acts as a | | | | | | | server]{ | | | | | | | | ser | | | | | | | #a-server | | | | | | | | ver]{.ass | | | | | | | .ass | | | | | < | | ignable-c | | | | | | | ignable-c | | | | | | | ontent}\] | | | | | | | ontent}\] | | | | | +-----------+-----------+-----------+-----------+-----------+-----------+ +-----------+-----------+-----------+-----------+-----------+-----------+ | 26 | enabl | ::: t | ::: t | ::: t | ::: t | | 26 | enabl | ::: t | ::: t | ::: t | ::: t | | | e/disable | ooltipped | ooltipped | ooltipped | ooltipped | | | e/disable | ooltipped | ooltipped | ooltipped | ooltipped | | | developer | O | O | O | O | | | developer | O | O | O | O | | | modes | [Optional | [Optional | [Optional | [Optional | | | modes | [Optional | [Optional | [Optional | [Optional | | | | /Conditio | /Conditio | /Conditio | /Conditio | | | | /Conditio | /Conditio | /Conditio | /Conditio | | | | nal]{.too | nal]{.too | nal]{.too | nal]{.too | | | | nal]{.too | nal]{.too | nal]{.too | nal]{.too | | | | ltiptext} | ltiptext} | ltiptext} | ltiptext} | | | | ltiptext} | ltiptext} | ltiptext} | ltiptext} | | | | ::: | ::: | ::: | ::: | | | | ::: | ::: | ::: | ::: | +-----------+-----------+-----------+-----------+-----------+-----------+ +-----------+-----------+-----------+-----------+-----------+-----------+ | 27 | enabl | ::: t | ::: t | ::: t | ::: t | | 27 | enabl | ::: t | ::: t | ::: t | ::: t | | | e/disable | ooltipped | ooltipped | ooltipped | ooltipped | | | e/disable | ooltipped | ooltipped | ooltipped | ooltipped | | | bypass of | O | O | O | O | | | bypass of | O | O | O | O | | | local | [Optional | [Optional | [Optional | [Optional | | | local | [Optional | [Optional | [Optional | [Optional | | | user | /Conditio | /Conditio | /Conditio | /Conditio | | | user | /Conditio | /Conditio | /Conditio | /Conditio | | | authe | nal]{.too | nal]{.too | nal]{.too | nal]{.too | | | authe | nal]{.too | nal]{.too | nal]{.too | nal]{.too | | | ntication | ltiptext} | ltiptext} | ltiptext} | ltiptext} | | | ntication | ltiptext} | ltiptext} | ltiptext} | ltiptext} | | | | ::: | ::: | ::: | ::: | | | | ::: | ::: | ::: | ::: | +-----------+-----------+-----------+-----------+-----------+-----------+ +-----------+-----------+-----------+-----------+-----------+-----------+ | 28 | wipe | ::: t | ::: t | ::: t | ::: t | | 28 | wipe | ::: t | ::: t | ::: t | ::: t | | | E | ooltipped | ooltipped | ooltipped | ooltipped | | | E | ooltipped | ooltipped | ooltipped | ooltipped | | | nterprise | O | O | O | \-[ | | | nterprise | O | O | O | \-[ | | | data | [Optional | [Optional | [Optional | N/A]{.too | | | data | [Optional | [Optional | [Optional | N/A]{.too | | | | /Conditio | /Conditio | /Conditio | ltiptext} | | | | /Conditio | /Conditio | /Conditio | ltiptext} | | | | nal]{.too | nal]{.too | nal]{.too | ::: | | | | nal]{.too | nal]{.too | nal]{.too | ::: | | | | ltiptext} | ltiptext} | ltiptext} | | | | | ltiptext} | ltiptext} | ltiptext} | | | | | ::: | ::: | ::: | | | | | ::: | ::: | ::: | | +-----------+-----------+-----------+-----------+-----------+-----------+ +-----------+-----------+-----------+-----------+-----------+-----------+ | 29 | approve | ::: t | ::: t | ::: t | ::: t | | 29 | approve | ::: t | ::: t | ::: t | ::: t | | | \[**sel | ooltipped | ooltipped | ooltipped | ooltipped | | | \[**sel | ooltipped | ooltipped | ooltipped | ooltipped | | | ection**: | O | O | O | O | | | ection**: | O | O | O | O | | | [import | [Optional | [Optional | [Optional | [Optional | | | | [ | [Optional | [Optional | [Optional | [Optional | | | ]{#_s_555 | /Conditio | /Conditio | /Conditio | /Conditio | | | | import]{# | /Conditio | /Conditio | /Conditio | /Conditio | | | .se | nal]{.too | nal]{.too | nal]{.too | nal]{.too | | | | fmt_smf_e | nal]{.too | nal]{.too | nal]{.too | nal]{.too | | | lectable- | ltiptext} | ltiptext} | ltiptext} | ltiptext} | | | | xt.1.1_23 | ltiptext} | ltiptext} | ltiptext} | ltiptext} | | | content}, | ::: | ::: | ::: | ::: | | | | .se | ::: | ::: | ::: | ::: | | | [removal | | | | | | | | lectable- | | | | | | | ]{#_s_556 | | | | | | | | content}, | | | | | > | | [r | | | | | > | | emoval]{# | | | | | > | | fmt_smf_e | | | | | > | | xt.1.1_24 | | | | | | | .sel | | | | | | | .sel | | | | | | | ectable-c | | | | | | | ectable-c | | | | | | | ontent}\] | | | | | | | ontent}\] | | | | | | | by | | | | | | | by | | | | | | | app | | | | | | | app | | | | | | | lications | | | | | | | lications | | | | | | | of | | | | | | | of | | | | | | | X.509v3 | | | | | | | X.509v3 | | | | | | | cer | | | | | | | cer | | | | | | | tificates | | | | | | | tificates | | | | | | | in the | | | | | | | in the | | | | | | | Trust | | | | | | | Trust | | | | | | | Anchor | | | | | | | Anchor | | | | | | | Database | | | | | | | Database | | | | | +-----------+-----------+-----------+-----------+-----------+-----------+ +-----------+-----------+-----------+-----------+-----------+-----------+ | 30 | configure | ::: t | ::: t | ::: t | ::: t | | 30 | configure | ::: t | ::: t | ::: t | ::: t | | | whether | ooltipped | ooltipped | ooltipped | ooltipped | | | whether | ooltipped | ooltipped | ooltipped | ooltipped | | | to allow | O | O | O | O | | | to allow | O | O | O | O | | | or | [Optional | [Optional | [Optional | [Optional | | | or | [Optional | [Optional | [Optional | [Optional | | | disallow | /Conditio | /Conditio | /Conditio | /Conditio | | | disallow | /Conditio | /Conditio | /Conditio | /Conditio | | | esta | nal]{.too | nal]{.too | nal]{.too | nal]{.too | | | esta | nal]{.too | nal]{.too | nal]{.too | nal]{.too | | | blishment | ltiptext} | ltiptext} | ltiptext} | ltiptext} | | | blishment | ltiptext} | ltiptext} | ltiptext} | ltiptext} | | | of a | ::: | ::: | ::: | ::: | | | of a | ::: | ::: | ::: | ::: | | | trusted | | | | | | | trusted | | | | | | | channel | | | | | | | channel | | | | | | | if the | | | | | | | if the | | | | | | | [TSF](# | | | | | | | [TSF](# | | | | | | | abbr_TSF) | | | | | | | abbr_TSF) | | | | | | | cannot | | | | | | | cannot | | | | | | | establish | | | | | | | establish | | | | | | | a | | | | | | | a | | | | | | | c | | | | | | | c | | | | | | | onnection | | | | | | | onnection | | | | | | | to | | | | | | | to | | | | | | | determine | | | | | | | determine | | | | | | | the | | | | | | | the | | | | | | | validity | | | | | | | validity | | | | | | | of a | | | | | | | of a | | | | | | | ce | | | | | | | ce | | | | | | | rtificate | | | | | | | rtificate | | | | | +-----------+-----------+-----------+-----------+-----------+-----------+ +-----------+-----------+-----------+-----------+-----------+-----------+ | 31 | enabl | ::: t | ::: t | ::: t | ::: t | | 31 | enabl | ::: t | ::: t | ::: t | ::: t | | | e/disable | ooltipped | ooltipped | ooltipped | ooltipped | | | e/disable | ooltipped | ooltipped | ooltipped | ooltipped | | | the | O | O | O | O | | | the | O | O | O | O | | | cellular | [Optional | [Optional | [Optional | [Optional | | | cellular | [Optional | [Optional | [Optional | [Optional | | | protocols | /Conditio | /Conditio | /Conditio | /Conditio | | | protocols | /Conditio | /Conditio | /Conditio | /Conditio | | | used to | nal]{.too | nal]{.too | nal]{.too | nal]{.too | | | used to | nal]{.too | nal]{.too | nal]{.too | nal]{.too | | | connect | ltiptext} | ltiptext} | ltiptext} | ltiptext} | | | connect | ltiptext} | ltiptext} | ltiptext} | ltiptext} | | | to | ::: | ::: | ::: | ::: | | | to | ::: | ::: | ::: | ::: | | | cellular | | | | | | | cellular | | | | | | | network | | | | | | | network | | | | | | | base | | | | | | | base | | | | | | | stations | | | | | | | stations | | | | | +-----------+-----------+-----------+-----------+-----------+-----------+ +-----------+-----------+-----------+-----------+-----------+-----------+ | 32 | read | ::: t | ::: t | ::: t | ::: t | | 32 | read | ::: t | ::: t | ::: t | ::: t | | | audit | ooltipped | ooltipped | ooltipped | ooltipped | | | audit | ooltipped | ooltipped | ooltipped | ooltipped | | | logs kept | M[Mandat | \-[ | M[Mandat | \-[ | | | logs kept | M[Mandat | \-[ | M[Mandat | \-[ | | | by the | ory]{.too | N/A]{.too | ory]{.too | N/A]{.too | | | by the | ory]{.too | N/A]{.too | ory]{.too | N/A]{.too | | | [TSF](# | ltiptext} | ltiptext} | ltiptext} | ltiptext} | | | [TSF](# | ltiptext} | ltiptext} | ltiptext} | ltiptext} | | | abbr_TSF) | ::: | ::: | ::: | ::: | | | abbr_TSF) | ::: | ::: | ::: | ::: | +-----------+-----------+-----------+-----------+-----------+-----------+ +-----------+-----------+-----------+-----------+-----------+-----------+ | 33 | configure | ::: t | ::: t | ::: t | ::: t | | 33 | configure | ::: t | ::: t | ::: t | ::: t | | | \[**sel | ooltipped | ooltipped | ooltipped | ooltipped | | | \[**sel | ooltipped | ooltipped | ooltipped | ooltipped | | | ection**: | O | O | O | O | | | ection**: | O | O | O | O | | | [ce | [Optional | [Optional | [Optional | [Optional | | | | [certi | [Optional | [Optional | [Optional | [Optional | | | rtificate | /Conditio | /Conditio | /Conditio | /Conditio | | | | ficate]{# | /Conditio | /Conditio | /Conditio | /Conditio | | | ]{#_s_557 | nal]{.too | nal]{.too | nal]{.too | nal]{.too | | | | fmt_smf_e | nal]{.too | nal]{.too | nal]{.too | nal]{.too | | | .se | ltiptext} | ltiptext} | ltiptext} | ltiptext} | | | | xt.1.1_25 | ltiptext} | ltiptext} | ltiptext} | ltiptext} | | | lectable- | ::: | ::: | ::: | ::: | | | | .se | ::: | ::: | ::: | ::: | > | | lectable- | | | | | | | content}, | | | | | | | content}, | | | | | | | [p | | | | | | | | [publ | | | | | | | ublic-key | | | | | | | | ic-key]{# | | | | | | | ]{#_s_558 | | | | | | | | fmt_smf_e | | | | | > | | xt.1.1_26 | | | | | | | .sel | | | | | | | .sel | | | | | | | ectable-c | | | | | | | ectable-c | | | | | | | ontent}\] | | | | | | | ontent}\] | | | | | | | used to | | | | | | | used to | | | | | | | validate | | | | | | | validate | | | | | | | digital | | | | | | | digital | | | | | | | signature | | | | | | | signature | | | | | | | on | | | | | | | on | | | | | | | app | | | | | | | app | | | | | | | lications | | | | | | | lications | | | | | +-----------+-----------+-----------+-----------+-----------+-----------+ +-----------+-----------+-----------+-----------+-----------+-----------+ | 34 | approve | ::: t | ::: t | ::: t | ::: t | | 34 | approve | ::: t | ::: t | ::: t | ::: t | | | e | ooltipped | ooltipped | ooltipped | ooltipped | | | e | ooltipped | ooltipped | ooltipped | ooltipped | | | xceptions | O | O | O | O | | | xceptions | O | O | O | O | | | for | [Optional | [Optional | [Optional | [Optional | | | for | [Optional | [Optional | [Optional | [Optional | | | shared | /Conditio | /Conditio | /Conditio | /Conditio | | | shared | /Conditio | /Conditio | /Conditio | /Conditio | | | use of | nal]{.too | nal]{.too | nal]{.too | nal]{.too | | | use of | nal]{.too | nal]{.too | nal]{.too | nal]{.too | | | keys or | ltiptext} | ltiptext} | ltiptext} | ltiptext} | | | keys or | ltiptext} | ltiptext} | ltiptext} | ltiptext} | | | secrets | ::: | ::: | ::: | ::: | | | secrets | ::: | ::: | ::: | ::: | | | by | | | | | | | by | | | | | | | multiple | | | | | | | multiple | | | | | | | app | | | | | | | app | | | | | | | lications | | | | | | | lications | | | | | +-----------+-----------+-----------+-----------+-----------+-----------+ +-----------+-----------+-----------+-----------+-----------+-----------+ | 35 | approve | ::: t | ::: t | ::: t | ::: t | | 35 | approve | ::: t | ::: t | ::: t | ::: t | | | e | ooltipped | ooltipped | ooltipped | ooltipped | | | e | ooltipped | ooltipped | ooltipped | ooltipped | | | xceptions | O | O | O | O | | | xceptions | O | O | O | O | | | for | [Optional | [Optional | [Optional | [Optional | | | for | [Optional | [Optional | [Optional | [Optional | | | de | /Conditio | /Conditio | /Conditio | /Conditio | | | de | /Conditio | /Conditio | /Conditio | /Conditio | | | struction | nal]{.too | nal]{.too | nal]{.too | nal]{.too | | | struction | nal]{.too | nal]{.too | nal]{.too | nal]{.too | | | of keys | ltiptext} | ltiptext} | ltiptext} | ltiptext} | | | of keys | ltiptext} | ltiptext} | ltiptext} | ltiptext} | | | or | ::: | ::: | ::: | ::: | | | or | ::: | ::: | ::: | ::: | | | secrets | | | | | | | secrets | | | | | | | by | | | | | | | by | | | | | | | app | | | | | | | app | | | | | | | lications | | | | | | | lications | | | | | | | that did | | | | | | | that did | | | | | | | not | | | | | | | not | | | | | | | import | | | | | | | import | | | | | | | the key | | | | | | | the key | | | | | | | or secret | | | | | | | or secret | | | | | +-----------+-----------+-----------+-----------+-----------+-----------+ +-----------+-----------+-----------+-----------+-----------+-----------+ | 36 | configure | ::: t | ::: t | ::: t | ::: t | | 36 | configure | ::: t | ::: t | ::: t | ::: t | | | the | ooltipped | ooltipped | ooltipped | ooltipped | | | the | ooltipped | ooltipped | ooltipped | ooltipped | | | unlock | M[Mandat | \-[ | O | O | | | unlock | M[Mandat | \-[ | O | O | | | banner | ory]{.too | N/A]{.too | [Optional | [Optional | | | banner | ory]{.too | N/A]{.too | [Optional | [Optional | | | | ltiptext} | ltiptext} | /Conditio | /Conditio | | | | ltiptext} | ltiptext} | /Conditio | /Conditio | | | | ::: | ::: | nal]{.too | nal]{.too | | | | ::: | ::: | nal]{.too | nal]{.too | | | | | | ltiptext} | ltiptext} | | | | | | ltiptext} | ltiptext} | | | | | | ::: | ::: | | | | | | ::: | ::: | +-----------+-----------+-----------+-----------+-----------+-----------+ +-----------+-----------+-----------+-----------+-----------+-----------+ | 37 | configure | ::: t | ::: t | ::: t | ::: t | | 37 | configure | ::: t | ::: t | ::: t | ::: t | | | the | ooltipped | ooltipped | ooltipped | ooltipped | | | the | ooltipped | ooltipped | ooltipped | ooltipped | | | auditable | O | \-[ | O | O | | | auditable | O | \-[ | O | O | | | items | [Optional | N/A]{.too | [Optional | [Optional | | | items | [Optional | N/A]{.too | [Optional | [Optional | | | | /Conditio | ltiptext} | /Conditio | /Conditio | | | | /Conditio | ltiptext} | /Conditio | /Conditio | | | | nal]{.too | ::: | nal]{.too | nal]{.too | | | | nal]{.too | ::: | nal]{.too | nal]{.too | | | | ltiptext} | | ltiptext} | ltiptext} | | | | ltiptext} | | ltiptext} | ltiptext} | | | | ::: | | ::: | ::: | | | | ::: | | ::: | ::: | +-----------+-----------+-----------+-----------+-----------+-----------+ +-----------+-----------+-----------+-----------+-----------+-----------+ | 38 | retrieve | ::: t | ::: t | ::: t | ::: t | | 38 | retrieve | ::: t | ::: t | ::: t | ::: t | | | [TSF](# | ooltipped | ooltipped | ooltipped | ooltipped | | | [TSF](# | ooltipped | ooltipped | ooltipped | ooltipped | | | abbr_TSF) | O | O | O | O | | | abbr_TSF) | O | O | O | O | | | -software | [Optional | [Optional | [Optional | [Optional | | | -software | [Optional | [Optional | [Optional | [Optional | | | integrity | /Conditio | /Conditio | /Conditio | /Conditio | | | integrity | /Conditio | /Conditio | /Conditio | /Conditio | | | ver | nal]{.too | nal]{.too | nal]{.too | nal]{.too | | | ver | nal]{.too | nal]{.too | nal]{.too | nal]{.too | | | ification | ltiptext} | ltiptext} | ltiptext} | ltiptext} | | | ification | ltiptext} | ltiptext} | ltiptext} | ltiptext} | | | values | ::: | ::: | ::: | ::: | | | values | ::: | ::: | ::: | ::: | +-----------+-----------+-----------+-----------+-----------+-----------+ +-----------+-----------+-----------+-----------+-----------+-----------+ | 39 | enabl | ::: t | ::: t | ::: t | ::: t | | 39 | enabl | ::: t | ::: t | ::: t | ::: t | | | e/disable | ooltipped | ooltipped | ooltipped | ooltipped | | | e/disable | ooltipped | ooltipped | ooltipped | ooltipped | | | \[**sel | O | O | O | O | | | \[**sel | O | O | O | O | | | ection**: | [Optional | [Optional | [Optional | [Optional | | | ection**: | [Optional | [Optional | [Optional | [Optional | | | | /Conditio | /Conditio | /Conditio | /Conditio | | | | /Conditio | /Conditio | /Conditio | /Conditio | | | - | nal]{.too | nal]{.too | nal]{.too | nal]{.too | | | - | nal]{.too | nal]{.too | nal]{.too | nal]{.too | | | [[USB](# | ltiptext} | ltiptext} | ltiptext} | ltiptext} | | | [[USB](# | ltiptext} | ltiptext} | ltiptext} | ltiptext} | | | abbr_USB) | ::: | ::: | ::: | ::: | | | abbr_USB) | ::: | ::: | ::: | ::: | | | mass | | | | | | | mass | | | | | | | | | | | | | | | | | | | | | storage | | | | | | | storage | | | | | | | | | | | | | | | | | | | | | mode]{#s | | | | | | | mode]{#s | | | | | | | -usbstore | | | | | | | -usbstore | | | | | | | .s | | | | | | | .s | | | | | | | electable | | | | | | | electable | | | | | | | -content} | | | | | | | -content} | | | | | | | - | | | | | | | - | | | | | | | [[USB](# | | | | | | | [[USB](# | | | | | | | abbr_USB) | | | | | | | abbr_USB) | | | | | | | data | | | | | | | data | | | | | | | | | | | | | | | | | | | | | transfer | | | | | | | transfer | | | | | | | | | | | | | | | | | | | | | without | | | | | | | without | | | | | | | user | | | | | | | user | | | | | | | authe | | | | | | | | | | | | | | | ntication | | | | | | | | authenti | | | | | | | ]{#_s_560 | | | | | | | | cation]{# | | | | | > | | fmt_smf_e | | | | | > | | xt.1.1_27 | | | | | | | .s | | | | | | | .s | | | | | | | electable | | | | | | | electable | | | | | | | -content} | | | | | | | -content} | | | | | | | - | | | | | | | - | | | | | | | [[USB](# | | | | | | | [[USB](# | | | | | | | abbr_USB) | | | | | | | abbr_USB) | | | | | | | data | | | | | | | data | | | | | | | | | | | | | | | | | | | | | transfer | | | | | | | transfer | | | | | | | | | | | | | | | | | | | | | without | | | | | | | without | | | | | | | authe | | | | | | | authe | | | | | | | ntication | | | | | | | ntication | | | | | | | of | | | | | | | of | | | | | | | the | | | | | | | the | | | | | | | c | | | | | | | c | | | | | | | onnecting | | | | | | | onnecting | | | | | | | | | | | | | | | | | | | | | system | | | | | | | | system]{# | | | | | | | ]{#_s_561 | | | | | | | | fmt_smf_e | | | | | > | | xt.1.1_28 | | | | | | | .s | | | | | | | .s | | | | | | | electable | | | | | | | electable | | | | | | | -content} | | | | | | | -content} | | | | | | | | | | | | | | | | | | | | | \] | | | | | | | \] | | | | | +-----------+-----------+-----------+-----------+-----------+-----------+ +-----------+-----------+-----------+-----------+-----------+-----------+ | 40 | enabl | ::: t | ::: t | ::: t | ::: t | | 40 | enabl | ::: t | ::: t | ::: t | ::: t | | | e/disable | ooltipped | ooltipped | ooltipped | ooltipped | | | e/disable | ooltipped | ooltipped | ooltipped | ooltipped | | | backup of | O | O | O | O | | | backup of | O | O | O | O | | | \[**sel | [Optional | [Optional | [Optional | [Optional | | | \[**sel | [Optional | [Optional | [Optional | [Optional | | | ection**: | /Conditio | /Conditio | /Conditio | /Conditio | | | ection**: | /Conditio | /Conditio | /Conditio | /Conditio | | | [all | nal]{.too | nal]{.too | nal]{.too | nal]{.too | | | [all | nal]{.too | nal]{.too | nal]{.too | nal]{.too | | | appli | ltiptext} | ltiptext} | ltiptext} | ltiptext} | | | appli | ltiptext} | ltiptext} | ltiptext} | ltiptext} | | | cations]{ | ::: | ::: | ::: | ::: | | | cations]{ | ::: | ::: | ::: | ::: | | | #s-backup | | | | | | | #s-backup | | | | | | | -all-apps | | | | | | | -all-apps | | | | | | | .se | | | | | | | .se | | | | | | | lectable- | | | | | | | lectable- | | | | | | | content}, | | | | | | | content}, | | | | | | | [selected | | | | | | | [selected | | | | | | | appli | | | | | | | appli | | | | | | | cations]{ | | | | | | | cations]{ | | | | | | | #s-backup | | | | | | | #s-backup | | | | | | | -sel-apps | | | | | | | -sel-apps | | | | | | | .se | | | | | | | .se | | | | | | | lectable- | | | | | | | lectable- | | | | | | | content}, | | | | | | | content}, | | | | | | | [selected | | | | | | | [selected | | | | | | | groups of | | | | | | | groups of | | | | | | | appli | | | | | | | appli | | | | | | | cations]{ | | | | | | | cations]{ | | | | | | | #s-backup | | | | | | | #s-backup | | | | | | | -sel-grps | | | | | | | -sel-grps | | | | | | | .se | | | | | | | .se | | | | | | | lectable- | | | | | | | lectable- | | | | | | | content}, | | | | | | | content}, | | | | | | | [conf | | | | | | | [conf | | | | | | | iguration | | | | | | | iguration | | | | | | | d | | | | | | | d | | | | | | | ata]{#s-b | | | | | | | ata]{#s-b | | | | | | | ackup-cfg | | | | | | | ackup-cfg | | | | | | | .sel | | | | | | | .sel | | | | | | | ectable-c | | | | | | | ectable-c | | | | | | | ontent}\] | | | | | | | ontent}\] | | | | | | | to | | | | | | | to | | | | | | | \[**sel | | | | | | | \[**sel | | | | | | | ection**: | | | | | | | ection**: | | | | | | | [locally | | | | | | | [locally | | | | | | | connected | | | | | | | connected | | | | | | | system | | | | | | | | system]{# | | | | | | | ]{#_s_566 | | | | | | | | fmt_smf_e | | | | | > | | xt.1.1_29 | | | | | | | .se | | | | | | | .se | | | | | | | lectable- | | | | | | | lectable- | | | | | | | content}, | | | | | | | content}, | | | | | | | [remote | | | | | | | [remote | | | | | | | system | | | | | | | | system]{# | | | | | | | ]{#_s_567 | | | | | | | | fmt_smf_e | | | | | > | | xt.1.1_30 | | | | | | | .sel | | | | | | | .sel | | | | | | | ectable-c | | | | | | | ectable-c | | | | | | | ontent}\] | | | | | | | ontent}\] | | | | | +-----------+-----------+-----------+-----------+-----------+-----------+ +-----------+-----------+-----------+-----------+-----------+-----------+ | 41 | enabl | ::: t | ::: t | ::: t | ::: t | | 41 | enabl | ::: t | ::: t | ::: t | ::: t | | | e/disable | ooltipped | ooltipped | ooltipped | ooltipped | | | e/disable | ooltipped | ooltipped | ooltipped | ooltipped | | | \[**sel | O | O | O | O | | | \[**sel | O | O | O | O | | | ection**: | [Optional | [Optional | [Optional | [Optional | | | ection**: | [Optional | [Optional | [Optional | [Optional | | | | /Conditio | /Conditio | /Conditio | /Conditio | | | | /Conditio | /Conditio | /Conditio | /Conditio | | | - [ | nal]{.too | nal]{.too | nal]{.too | nal]{.too | | | - [ | nal]{.too | nal]{.too | nal]{.too | nal]{.too | | | Bluetooth | ltiptext} | ltiptext} | ltiptext} | ltiptext} | | | Bluetooth | ltiptext} | ltiptext} | ltiptext} | ltiptext} | | | | ::: | ::: | ::: | ::: | | | | tet | ::: | ::: | ::: | ::: | | | tethering | | | | | | | | hering]{# | | | | | | | ]{#_s_568 | | | | | | | | fmt_smf_e | | | | | > | | xt.1.1_31 | | | | | | | .s | | | | | | | .s | | | | | | | electable | | | | | | | electable | | | | | | | -content} | | | | | | | -content} | | | | | | | - | | | | | | | - | | | | | | | [[USB](# | | | | | | | [[USB](# | | | | | | | abbr_USB) | | | | | | | abbr_USB) | | | | | | | | | | | | | | | | | | | | | tethering | | | | | | | tethering | | | | | | | auth | | | | | | | auth | | | | | | | enticated | | | | | | | enticated | | | | | | | by | | | | | | | by | | | | | | | | | | | | | | | | | | | | | \[**sel | | | | | | | \[**sel | | | | | | | ection**: | | | | | | | ection**: | | | | | | | | | | | | | | | | | | | | | [device | | | | | | | [device | | | | | | | authe | | | | | | | | | | | | | | | ntication | | | | | | | | authenti | | | | | | | ]{#_s_570 | | | | | | | | cation]{# | | | | | > | | fmt_smf_e | | | | | > | | xt.1.1_32 | | | | | | | .se | | | | | | | .se | | | | | | | lectable- | | | | | | | lectable- | | | | | | | content}, | | | | | | | content}, | | | | | | | | | | | | | | | | | | | | | [[USB](# | | | | | | | [[USB](# | | | | | | | abbr_USB) | | | | | | | abbr_USB) | | | | | | | | | | | | | | | | | | | | | device | | | | | | | device | | | | | | | i | | | | | | | | iden | | | | | | | dentifier | | | | | | | | tifier]{# | | | | | | | ]{#_s_571 | | | | | | | | fmt_smf_e | | | | | > | | xt.1.1_33 | | | | | | | .se | | | | | | | .se | | | | | | | lectable- | | | | | | | lectable- | | | | | | | content}, | | | | | | | content}, | | | | | | | [no | | | | | | | [no | | | | | | | authe | | | | | | | | | | | | | | | ntication | | | | | | | | authenti | | | | | | | ]{#_s_572 | | | | | | | | cation]{# | | | | | > | | fmt_smf_e | | | | | > | | xt.1.1_34 | | | | | | | | | | | | | | | | | | | | | .selec | | | | | | | .selec | | | | | | | table-con | | | | | | | table-con | | | | | | | tent}\]]{ | | | | | | | tent}\]]{ | | | | | | | #s-tether | | | | | | | #s-tether | | | | | | | .s | | | | | | | .s | | | | | | | electable | | | | | | | electable | | | | | | | -content} | | | | | | | -content} | | | | | | | | | | | | | | | | | | | | | \] | | | | | | | \] | | | | | +-----------+-----------+-----------+-----------+-----------+-----------+ +-----------+-----------+-----------+-----------+-----------+-----------+ | 42 | approve | ::: t | ::: t | ::: t | ::: t | | 42 | approve | ::: t | ::: t | ::: t | ::: t | | | e | ooltipped | ooltipped | ooltipped | ooltipped | | | e | ooltipped | ooltipped | ooltipped | ooltipped | | | xceptions | O | O | O | O | | | xceptions | O | O | O | O | | | for | [Optional | [Optional | [Optional | [Optional | | | for | [Optional | [Optional | [Optional | [Optional | | | sharing | /Conditio | /Conditio | /Conditio | /Conditio | | | sharing | /Conditio | /Conditio | /Conditio | /Conditio | | | data | nal]{.too | nal]{.too | nal]{.too | nal]{.too | | | data | nal]{.too | nal]{.too | nal]{.too | nal]{.too | | | between | ltiptext} | ltiptext} | ltiptext} | ltiptext} | | | between | ltiptext} | ltiptext} | ltiptext} | ltiptext} | | | \[**sel | ::: | ::: | ::: | ::: | | | \[**sel | ::: | ::: | ::: | ::: | | | ection**: | | | | | | | ection**: | | | | | | | [app | | | | | | | | [applic | | | | | | | lications | | | | | | | | ations]{# | | | | | | | ]{#_s_573 | | | | | | | | fmt_smf_e | | | | | > | | xt.1.1_35 | | | | | | | .se | | | | | | | .se | | | | | | | lectable- | | | | | | | lectable- | | | | | | | content}, | | | | | | | content}, | | | | | | | [groups | | | | | | | [groups | | | | | | | of | | | | | | | of | | | | | | | app | | | | | | | | applic | | | | | | | lications | | | | | | | | ations]{# | | | | | | | ]{#_s_574 | | | | | | | | fmt_smf_e | | | | | > | | xt.1.1_36 | | | | | | | .sel | | | | | | | .sel | | | | | | | ectable-c | | | | | | | ectable-c | | | | | | | ontent}\] | | | | | | | ontent}\] | | | | | +-----------+-----------+-----------+-----------+-----------+-----------+ +-----------+-----------+-----------+-----------+-----------+-----------+ | 43 | place | ::: t | ::: t | ::: t | ::: t | | 43 | place | ::: t | ::: t | ::: t | ::: t | | | app | ooltipped | ooltipped | ooltipped | ooltipped | | | app | ooltipped | ooltipped | ooltipped | ooltipped | | | lications | O | O | O | O | | | lications | O | O | O | O | | | into | [Optional | [Optional | [Optional | [Optional | | | into | [Optional | [Optional | [Optional | [Optional | | | ap | /Conditio | /Conditio | /Conditio | /Conditio | | | ap | /Conditio | /Conditio | /Conditio | /Conditio | | | plication | nal]{.too | nal]{.too | nal]{.too | nal]{.too | | | plication | nal]{.too | nal]{.too | nal]{.too | nal]{.too | | | groups | ltiptext} | ltiptext} | ltiptext} | ltiptext} | | | groups | ltiptext} | ltiptext} | ltiptext} | ltiptext} | | | based on | ::: | ::: | ::: | ::: | | | based on | ::: | ::: | ::: | ::: | | | \[**assi | | | | | | | \[**assi | | | | | | | gnment**: | | | | | | | gnment**: | | | | | | | [e | | | | | | | [e | | | | | | | nterprise | | | | | | | nterprise | | | | | | | conf | | | | | | | conf | | | | | | | iguration | | | | | | | iguration | | | | | | | setti | | | | | | | setti | | | | | | | ngs]{.ass | | | | | | | ngs]{.ass | | | | | | | ignable-c | | | | | | | ignable-c | | | | | | | ontent}\] | | | | | | | ontent}\] | | | | | +-----------+-----------+-----------+-----------+-----------+-----------+ +-----------+-----------+-----------+-----------+-----------+-----------+ | 44 | unenroll | ::: t | ::: t | ::: t | ::: t | | 44 | unenroll | ::: t | ::: t | ::: t | ::: t | | | the | ooltipped | ooltipped | ooltipped | ooltipped | | | the | ooltipped | ooltipped | ooltipped | ooltipped | | | [TOE](# | O | O | O | O | | | [TOE](# | O | O | O | O | | | abbr_TOE) | [Optional | [Optional | [Optional | [Optional | | | abbr_TOE) | [Optional | [Optional | [Optional | [Optional | | | from | /Conditio | /Conditio | /Conditio | /Conditio | | | from | /Conditio | /Conditio | /Conditio | /Conditio | | | m | nal]{.too | nal]{.too | nal]{.too | nal]{.too | | | m | nal]{.too | nal]{.too | nal]{.too | nal]{.too | | | anagement | ltiptext} | ltiptext} | ltiptext} | ltiptext} | | | anagement | ltiptext} | ltiptext} | ltiptext} | ltiptext} | | | | ::: | ::: | ::: | ::: | | | | ::: | ::: | ::: | ::: | +-----------+-----------+-----------+-----------+-----------+-----------+ +-----------+-----------+-----------+-----------+-----------+-----------+ | 45 | enabl | ::: t | ::: t | ::: t | ::: t | | 45 | enabl | ::: t | ::: t | ::: t | ::: t | | | e/disable | ooltipped | ooltipped | ooltipped | ooltipped | | | e/disable | ooltipped | ooltipped | ooltipped | ooltipped | | | the | O | O | O | O | | | the | O | O | O | O | | | Always On | [Optional | [Optional | [Optional | [Optional | | | Always On | [Optional | [Optional | [Optional | [Optional | | | [VPN](# | /Conditio | /Conditio | /Conditio | /Conditio | | | [VPN](# | /Conditio | /Conditio | /Conditio | /Conditio | | | abbr_VPN) | nal]{.too | nal]{.too | nal]{.too | nal]{.too | | | abbr_VPN) | nal]{.too | nal]{.too | nal]{.too | nal]{.too | | | pr | ltiptext} | ltiptext} | ltiptext} | ltiptext} | | | pr | ltiptext} | ltiptext} | ltiptext} | ltiptext} | | | otection: | ::: | ::: | ::: | ::: | | | otection: | ::: | ::: | ::: | ::: | | | | | | | | | | | | | | | | | - | | | | | | | - | | | | | | | Across | | | | | | | Across | | | | | | | | | | | | | | | | | | | | | device | | | | | | | device | | | | | | | | | | | | | | | | | | | | | : | | | | | < | | :: indent | | | | | < | | \[**sel | | | | | | | \[**sel | | | | | | | ection**: | | | | | | | ection**: | | | | | | | | | | | | | | | | | | | | | - [on a | | | | | | | - [on a | | | | | | | | | | | | | | | | | | | | | per-app | | | | | | | per-app | | | | | | | basis | | | | | | | | | | | | | | | ]{#_s_575 | | | | | | | | basis]{# | | | | | > | | fmt_smf_e | | | | | > | | xt.1.1_38 | | | | | | | .s | | | | | | | .s | | | | | | | electable | | | | | | | electable | | | | | | | -content} | | | | | | | -content} | | | | | | | - [on a | | | | | | | - [on a | | | | | | | | | | | | | | | | | | | | | per-group | | | | | | | per-group | | | | | | | of | | | | | | | of | | | | | | | app | | | | | | | app | | | | | | | lications | | | | | | | lications | | | | | | | | | | | | | | | | | | | | | processes | | | | | | | processes | | | | | | | basis | | | | | | | | | | | | | | | ]{#_s_576 | | | | | | | | basis]{# | | | | | > | | fmt_smf_e | | | | | > | | xt.1.1_39 | | | | | | | .s | | | | | | | .s | | | | | | | electable | | | | | | | electable | | | | | | | -content} | | | | | | | -content} | | | | | | | - [no | | | | | | | - [no | | | | | | | other | | | | | | | other | | | | | | | | | | | | | | | | | | | | | method | | | | | | | | method]{# | | | | | | | ]{#_s_577 | | | | | | | | fmt_smf_e | | | | | > | | xt.1.1_40 | | | | | | | .s | | | | | | | .s | | | | | | | electable | | | | | | | electable | | | | | | | -content} | | | | | | | -content} | | | | | | | | | | | | | | | | | | | | | \] | | | | | | | \] | | | | | | | ::: | | | | | < +-----------+-----------+-----------+-----------+-----------+-----------+ +-----------+-----------+-----------+-----------+-----------+-----------+ | 46 | revoke | ::: t | ::: t | ::: t | ::: t | | 46 | revoke | ::: t | ::: t | ::: t | ::: t | | | Biometric | ooltipped | ooltipped | ooltipped | ooltipped | | | Biometric | ooltipped | ooltipped | ooltipped | ooltipped | | | template | O | O | O | O | | | template | O | O | O | O | | | | [Optional | [Optional | [Optional | [Optional | | | | [Optional | [Optional | [Optional | [Optional | | | | /Conditio | /Conditio | /Conditio | /Conditio | | | | /Conditio | /Conditio | /Conditio | /Conditio | | | | nal]{.too | nal]{.too | nal]{.too | nal]{.too | | | | nal]{.too | nal]{.too | nal]{.too | nal]{.too | | | | ltiptext} | ltiptext} | ltiptext} | ltiptext} | | | | ltiptext} | ltiptext} | ltiptext} | ltiptext} | | | | ::: | ::: | ::: | ::: | | | | ::: | ::: | ::: | ::: | +-----------+-----------+-----------+-----------+-----------+-----------+ +-----------+-----------+-----------+-----------+-----------+-----------+ | 47 | \[**assi | ::: t | ::: t | ::: t | ::: t | | 47 | \[**assi | ::: t | ::: t | ::: t | ::: t | | | gnment**: | ooltipped | ooltipped | ooltipped | ooltipped | | | gnment**: | ooltipped | ooltipped | ooltipped | ooltipped | | | [list of | O | O | O | O | | | [list of | O | O | O | O | | | other | [Optional | [Optional | [Optional | [Optional | | | other | [Optional | [Optional | [Optional | [Optional | | | m | /Conditio | /Conditio | /Conditio | /Conditio | | | m | /Conditio | /Conditio | /Conditio | /Conditio | | | anagement | nal]{.too | nal]{.too | nal]{.too | nal]{.too | | | anagement | nal]{.too | nal]{.too | nal]{.too | nal]{.too | | | functions | ltiptext} | ltiptext} | ltiptext} | ltiptext} | | | functions | ltiptext} | ltiptext} | ltiptext} | ltiptext} | | | to be | ::: | ::: | ::: | ::: | | | to be | ::: | ::: | ::: | ::: | | | provided | | | | | | | provided | | | | | | | by the | | | | | | | by the | | | | | | | [TSF | | | | | | | [TSF | | | | | | | ](#abbr_T | | | | | | | ](#abbr_T | | | | | | | SF)]{.ass | | | | | | | SF)]{.ass | | | | | | | ignable-c | | | | | | | ignable-c | | | | | | | ontent}\] | | | | | | | ontent}\] | | | | | +-----------+-----------+-----------+-----------+-----------+-----------+ +-----------+-----------+-----------+-----------+-----------+-----------+ ::: appnote ::: appnote [Application Note: ]{.note-header}[ [Table [Application Note: ]{.note-header}[ [Table [18]{.counter}](#fmt_smf){.fmt_smf-ref onclick="showTarget('fmt_smf')"} [18]{.counter}](#fmt_smf){.fmt_smf-ref onclick="showTarget('fmt_smf')"} identifies the management functions defined by this [PP](#abbr_PP), identifies the management functions defined by this [PP](#abbr_PP), whether they are mandatory or optional, and whether it is mandatory, whether they are mandatory or optional, and whether it is mandatory, optional, or forbidden for a particular role to perform each function.\ optional, or forbidden for a particular role to perform each function.\ \ \ The first column (\"#\") is a sequential numeric identifier while the The first column (\"#\") is a sequential numeric identifier while the second column (\"Management Function\") lists the management functions second column (\"Management Function\") lists the management functions identified in the [PP](#abbr_PP).\ identified in the [PP](#abbr_PP).\ \ \ In the following columns: ]{.note} In the following columns: ]{.note} - 'M' means Mandatory - 'M' means Mandatory - 'O' means Optional/Objective - 'O' means Optional/Objective - \'-\' means that no value (M or O) can be assigned - \'-\' means that no value (M or O) can be assigned \ \ \ \ The third column (\"Impl.\") indicates whether the function is to be The third column (\"Impl.\") indicates whether the function is to be implemented. The [ST](#abbr_ST) author should select which of the implemented. The [ST](#abbr_ST) author should select which of the non-mandatory functions are implemented.\ non-mandatory functions are implemented.\ \ \ The fourth column (\"User Only\") indicates functions that are to be The fourth column (\"User Only\") indicates functions that are to be restricted to the user (i.e., not available to the administrator).\ restricted to the user (i.e., not available to the administrator).\ \ \ The fifth column (\"Admin\") indicates functions that are available to The fifth column (\"Admin\") indicates functions that are available to the administrator. The functions restricted to the user (\"User Only\" the administrator. The functions restricted to the user (\"User Only\" column) cannot also be available to the administrator. Functions column) cannot also be available to the administrator. Functions available to the administrator can still be available to the user, as available to the administrator can still be available to the user, as long as the function is not restricted to the administrator (\"Admin long as the function is not restricted to the administrator (\"Admin Only\" column). Thus, if the [TOE](#abbr_TOE) must offer these functions Only\" column). Thus, if the [TOE](#abbr_TOE) must offer these functions to both the user and the administrator to perform, the \"Admin\" column to both the user and the administrator to perform, the \"Admin\" column entry must be selected.\ entry must be selected.\ \ \ The \"Admin Only\" column ([FMT_MOF_EXT.1.2](#FMT_MOF_EXT.1.2)) The \"Admin Only\" column ([FMT_MOF_EXT.1.2](#FMT_MOF_EXT.1.2)) indicates whether the function is to be restricted to the administrator indicates whether the function is to be restricted to the administrator when the device is enrolled and the administrator applies the indicated when the device is enrolled and the administrator applies the indicated policy. If the function is restricted to the administrator the function policy. If the function is restricted to the administrator the function is not available to the user. This does not prevent the user from is not available to the user. This does not prevent the user from modifying a setting to make the function stricter, but the user cannot modifying a setting to make the function stricter, but the user cannot undo the configuration enforced by the administrator.\ undo the configuration enforced by the administrator.\ \ \ The [ST](#abbr_ST) author may use a table in the [ST](#abbr_ST), listing The [ST](#abbr_ST) author may use a table in the [ST](#abbr_ST), listing only those functions that are implemented. For functions that are only those functions that are implemented. For functions that are mandatory, any sub-functions not in a selection are also mandatory and mandatory, any sub-functions not in a selection are also mandatory and any assignments must contain at least one assigned value. For functions any assignments must contain at least one assigned value. For functions that are optional and contain an assignment or selection, at least one that are optional and contain an assignment or selection, at least one value must be assigned/selected to be included in the [ST](#abbr_ST). value must be assigned/selected to be included in the [ST](#abbr_ST). For non-selectable sub-functions in an optional function, all For non-selectable sub-functions in an optional function, all sub-functions must be implemented in order for the function to be sub-functions must be implemented in order for the function to be included. For functions with a \"per-app basis\" sub function and an included. For functions with a \"per-app basis\" sub function and an assignment, the [ST](#abbr_ST) author must indicate which assigned assignment, the [ST](#abbr_ST) author must indicate which assigned features are manageable on a per-app basis and which are not by features are manageable on a per-app basis and which are not by iterating the row.\ iterating the row.\ \ \ \ \ \ \ **Function-specific Application Notes:**\ **Function-specific Application Notes:**\ \ \ Functions [3](#mf-vpn) , [5](#mf-audioVisual) , and [21](#mf-location) Functions [3](#mf-vpn) , [5](#mf-audioVisual) , and [21](#mf-location) must be implemented on a device-wide basis but may also be implemented must be implemented on a device-wide basis but may also be implemented on a per-app basis or on a per-group of applications basis in which the on a per-app basis or on a per-group of applications basis in which the configuration includes the list of applications or groups of configuration includes the list of applications or groups of applications to which the enable/disable applies. applications to which the enable/disable applies. Function [3](#mf-vpn) addresses enabling and disabling the Function [3](#mf-vpn) addresses enabling and disabling the [IPsec](#abbr_IPsec) [VPN](#abbr_VPN) only. The configuration of the [IPsec](#abbr_IPsec) [VPN](#abbr_VPN) only. The configuration of the [VPN](#abbr_VPN) Client itself (with information such as [VPN](#abbr_VPN) Client itself (with information such as [VPN](#abbr_VPN) Gateway, certificates, and algorithms) is addressed by [VPN](#abbr_VPN) Gateway, certificates, and algorithms) is addressed by the [PP-Module for Virtual Private Network (VPN) Clients, version the [PP-Module for Virtual Private Network (VPN) Clients, version 3.0](https://www.niap-ccevs.org/protectionprofiles/487). The | 3.0](). The administrator options should only be listed if the administrator options should only be listed if the administrator can | administrator can remotely enable/disable the [VPN](#abbr_VPN) remotely enable/disable the [VPN](#abbr_VPN) connection. | connection. Function [3](#mf-vpn) optionally allows the [VPN](#abbr_VPN) to be Function [3](#mf-vpn) optionally allows the [VPN](#abbr_VPN) to be configured per-app or per-groups of apps. If this configuration is configured per-app or per-groups of apps. If this configuration is selected, it does not void [FDP_IFC_EXT.1](#FDP_IFC_EXT.1). Instead selected, it does not void [FDP_IFC_EXT.1](#FDP_IFC_EXT.1). Instead [FDP_IFC_EXT.1](#FDP_IFC_EXT.1) is applied to the application or group [FDP_IFC_EXT.1](#FDP_IFC_EXT.1) is applied to the application or group of applications the [VPN](#abbr_VPN) is applied to. In other words, all of applications the [VPN](#abbr_VPN) is applied to. In other words, all traffic destined for the [VPN](#abbr_VPN)-enabled application or group traffic destined for the [VPN](#abbr_VPN)-enabled application or group of applications, must travel through the [VPN](#abbr_VPN), but traffic of applications, must travel through the [VPN](#abbr_VPN), but traffic not destined for that application or group of applications can travel not destined for that application or group of applications can travel outside the [VPN](#abbr_VPN). When the [VPN](#abbr_VPN) is configured outside the [VPN](#abbr_VPN). When the [VPN](#abbr_VPN) is configured across the device [FDP_IFC_EXT.1](#FDP_IFC_EXT.1) applies to all traffic across the device [FDP_IFC_EXT.1](#FDP_IFC_EXT.1) applies to all traffic and the [VPN](#abbr_VPN) must not split tunnel. and the [VPN](#abbr_VPN) must not split tunnel. The assignment in function [4](#mf-radios) consists of all radios The assignment in function [4](#mf-radios) consists of all radios present on the [TSF](#abbr_TSF), such as Wi-Fi, cellular, present on the [TSF](#abbr_TSF), such as Wi-Fi, cellular, [NFC](#abbr_NFC), Bluetooth [BR/EDR](#abbr_BR/EDR), and Bluetooth [NFC](#abbr_NFC), Bluetooth [BR/EDR](#abbr_BR/EDR), and Bluetooth [LE](#abbr_LE), which can be enabled and disabled. Disablement of the [LE](#abbr_LE), which can be enabled and disabled. Disablement of the cellular radio does not imply that the radio may not be enabled in order cellular radio does not imply that the radio may not be enabled in order to place emergency phone calls; however, it is not expected that a to place emergency phone calls; however, it is not expected that a device in \"airplane mode\", where all radios are disabled, will device in \"airplane mode\", where all radios are disabled, will automatically (without authorization) turn on the cellular radio to automatically (without authorization) turn on the cellular radio to place emergency calls. place emergency calls. The assignment in function [5](#mf-audioVisual) consists of at least one The assignment in function [5](#mf-audioVisual) consists of at least one audio or visual device, such as camera and microphone, which can be audio or visual device, such as camera and microphone, which can be enabled and disabled by either the user or administrator. Disablement of enabled and disabled by either the user or administrator. Disablement of the microphone does not imply that the microphone may not be enabled in the microphone does not imply that the microphone may not be enabled in order to place emergency phone calls. If certain devices are able to be order to place emergency phone calls. If certain devices are able to be restricted to the enterprise (either device-wide, per-app or per-group restricted to the enterprise (either device-wide, per-app or per-group of applications) and others are able to be restricted to users, then of applications) and others are able to be restricted to users, then this function should be iterated in the table with the appropriate table this function should be iterated in the table with the appropriate table entries. entries. Regarding functions [4](#mf-radios) and [5](#mf-audioVisual), Regarding functions [4](#mf-radios) and [5](#mf-audioVisual), disablement of a particular radio or audio/visual device must be disablement of a particular radio or audio/visual device must be effective as soon as the [TOE](#abbr_TOE) has power. Disablement must effective as soon as the [TOE](#abbr_TOE) has power. Disablement must also apply when the [TOE](#abbr_TOE) is booted into auxiliary boot also apply when the [TOE](#abbr_TOE) is booted into auxiliary boot modes, for example, associated with updates or backup. If the modes, for example, associated with updates or backup. If the [TOE](#abbr_TOE) supports states in which security management policy is [TOE](#abbr_TOE) supports states in which security management policy is inaccessible, for example, due to data-at-rest protection, it is inaccessible, for example, due to data-at-rest protection, it is acceptable to meet this requirement by ensuring that these devices are acceptable to meet this requirement by ensuring that these devices are disabled by default while in these states. That these devices are disabled by default while in these states. That these devices are disabled during auxiliary boot modes does not imply that the device disabled during auxiliary boot modes does not imply that the device (particularly the cellular radio) may not be enabled in order to perform (particularly the cellular radio) may not be enabled in order to perform emergency phone calls. emergency phone calls. Wipe of the [TSF](#abbr_TSF) (function [7](#mf-wipe)) is performed Wipe of the [TSF](#abbr_TSF) (function [7](#mf-wipe)) is performed according to [FCS_CKM_EXT.5](#FCS_CKM_EXT.5). Protected data is all according to [FCS_CKM_EXT.5](#FCS_CKM_EXT.5). Protected data is all non-TSF data, including all user or enterprise data. Some or all of this non-TSF data, including all user or enterprise data. Some or all of this data may be considered sensitive data as well. data may be considered sensitive data as well. The selection in function [8](#mf-appInstallRules) allows the The selection in function [8](#mf-appInstallRules) allows the [ST](#abbr_ST) author to select which mechanisms are available to the [ST](#abbr_ST) author to select which mechanisms are available to the administrator through the [MDM](#abbr_MDM) agent to restrict the administrator through the [MDM](#abbr_MDM) agent to restrict the applications which the user may install. The [ST](#abbr_ST) author must applications which the user may install. The [ST](#abbr_ST) author must state if application allowlist is applied device-wide or if it can be state if application allowlist is applied device-wide or if it can be specified to apply to either the Enterprise or Personal applications. specified to apply to either the Enterprise or Personal applications. - If the administrator can restrict the sources from which - If the administrator can restrict the sources from which applications can be installed, the [ST](#abbr_ST) author selects applications can be installed, the [ST](#abbr_ST) author selects \"[restricting the sources of \"[restricting the sources of applications](#mf-appInstallRules-restrict)\". applications](#mf-appInstallRules-restrict)\". - If the administrator can specify a allowlist of allowed - If the administrator can specify a allowlist of allowed applications, the [ST](#abbr_ST) author selects \"[application applications, the [ST](#abbr_ST) author selects \"[application allowlist](#mf-appInstallRules-specify)\". The [ST](#abbr_ST) author allowlist](#mf-appInstallRules-specify)\". The [ST](#abbr_ST) author should list any application characteristics (e.g. name, version, or should list any application characteristics (e.g. name, version, or developer) based on which the allowlist can be formed. developer) based on which the allowlist can be formed. - If the administrator can prevent the user from installing additional - If the administrator can prevent the user from installing additional applications, the [ST](#abbr_ST) author selects \"[denying applications, the [ST](#abbr_ST) author selects \"[denying installation of applications](#mf-appInstallRules-deny)\". installation of applications](#mf-appInstallRules-deny)\". In the future, function [12](#mf-certWipe) may require destruction or In the future, function [12](#mf-certWipe) may require destruction or disabling of any default trusted [CA](#abbr_CA) certificates, excepting disabling of any default trusted [CA](#abbr_CA) certificates, excepting those [CA](#abbr_CA) certificates necessary for continued operation of those [CA](#abbr_CA) certificates necessary for continued operation of the [TSF](#abbr_TSF), such as the developer's certificate. At this time, the [TSF](#abbr_TSF), such as the developer's certificate. At this time, the [ST](#abbr_ST) author must indicate in the assignment whether the [ST](#abbr_ST) author must indicate in the assignment whether pre-installed or any other category of X.509v3 certificates may be pre-installed or any other category of X.509v3 certificates may be removed from the Trust Anchor Database. removed from the Trust Anchor Database. For function [13](#mf-enroll), the enrollment function may be installing For function [13](#mf-enroll), the enrollment function may be installing an [MDM](#abbr_MDM) agent and includes the policies to be applied to the an [MDM](#abbr_MDM) agent and includes the policies to be applied to the device. It is acceptable for the user approval notice to require the device. It is acceptable for the user approval notice to require the user to intentionally opt to view the policies (for example, by user to intentionally opt to view the policies (for example, by \"tapping\" on a \"View\" icon) rather than listing the policies in full \"tapping\" on a \"View\" icon) rather than listing the policies in full in the notice. in the notice. For function [15](#mf-update), the administrator capability to update For function [15](#mf-update), the administrator capability to update the system software may be limited to causing a prompt to the user to the system software may be limited to causing a prompt to the user to update rather than the ability to initiate the update itself. As the update rather than the ability to initiate the update itself. As the administrator is likely to be acting remotely, he/she would be unaware administrator is likely to be acting remotely, he/she would be unaware of inopportune situations, such as low power, which may cause the update of inopportune situations, such as low power, which may cause the update to fail and the device to become inoperable. The user can refuse to to fail and the device to become inoperable. The user can refuse to accept the update in such situations. It is expected that system accept the update in such situations. It is expected that system architects will be cognizant of this limitation and will enforce network architects will be cognizant of this limitation and will enforce network access controls in order to enforce enterprise-critical updates. access controls in order to enforce enterprise-critical updates. Function [16](#mf-appInstall) addresses both installation and update. Function [16](#mf-appInstall) addresses both installation and update. This protection profile does not distinguish between installation and This protection profile does not distinguish between installation and update of applications because mobile devices typically completely update of applications because mobile devices typically completely overwrite the previous installation with a new installation during an overwrite the previous installation with a new installation during an application update. application update. For function [17](#mf-entAppRemove), \"Enterprise applications\" are For function [17](#mf-entAppRemove), \"Enterprise applications\" are those applications that belong to the Enterprise application group. those applications that belong to the Enterprise application group. Applications installed by the enterprise administrator (including Applications installed by the enterprise administrator (including automatic installation by the administrator after being requested by the automatic installation by the administrator after being requested by the user from a catalog of enterprise applications) are by default placed in user from a catalog of enterprise applications) are by default placed in the Enterprise application group unless an exception has been made in the Enterprise application group unless an exception has been made in function [43](#mf-appGroups) of [FMT_SMF_EXT.1.1](#FMT_SMF_EXT.1.1). function [43](#mf-appGroups) of [FMT_SMF_EXT.1.1](#FMT_SMF_EXT.1.1). If the display of notifications in the locked state is supported, the If the display of notifications in the locked state is supported, the configuration of these notifications (function [18](#mf-notifications)) configuration of these notifications (function [18](#mf-notifications)) must be included in the selection. must be included in the selection. Function [19](#mf-dar) must be included in the selection if data-at-rest Function [19](#mf-dar) must be included in the selection if data-at-rest protection is not natively enabled. protection is not natively enabled. Function [20](#mf-rmediaDar) is implicitly met if the [TSF](#abbr_TSF) Function [20](#mf-rmediaDar) is implicitly met if the [TSF](#abbr_TSF) does not support removable media. does not support removable media. For function [21](#mf-location), location services include location For function [21](#mf-location), location services include location information gathered from [GPS](#abbr_GPS), cellular, and Wi-Fi. information gathered from [GPS](#abbr_GPS), cellular, and Wi-Fi. Function [22](#mf-authFactors) must be included in the [ST](#abbr_ST) if Function [22](#mf-authFactors) must be included in the [ST](#abbr_ST) if the [TOE](#abbr_TOE) contains a [BAF](#abbr_BAF). This selection must the [TOE](#abbr_TOE) contains a [BAF](#abbr_BAF). This selection must correspond with the selection made in [FIA_UAU.5.1](#FIA_UAU.5.1). If correspond with the selection made in [FIA_UAU.5.1](#FIA_UAU.5.1). If [biometric in accordance with the](#uau_biometric) [cPP-Module for [biometric in accordance with the](#uau_biometric) [cPP-Module for Biometric Enrollment and Verification, version Biometric Enrollment and Verification, version 2.0](https://github.com/biometricITC/cPP-biometrics/blob/master/Protection%20Profile/ 2.0](https://github.com/biometricITC/cPP-biometrics/blob/master/Protection%20Profile/ is selected in [FIA_UAU.5.1](#FIA_UAU.5.1), \"Biometric Authentication is selected in [FIA_UAU.5.1](#FIA_UAU.5.1), \"Biometric Authentication Factor\" must be selected and the user or admin must have the option to Factor\" must be selected and the user or admin must have the option to disable the use of it. If multiple [BAFs](#abbr_BAF) are claimed in | disable the use of it. If multiple BAFs are claimed in FIA_MBV_EXT.1.1 FIA_MBV_EXT.1.1 in the [cPP-Module for Biometric Enrollment and | in the [cPP-Module for Biometric Enrollment and Verification, version Verification, version < 2.0](https://github.com/biometricITC/cPP-biometrics/blob/master/Protection%20Profile/ 2.0](https://github.com/biometricITC/cPP-biometrics/blob/master/Protection%20Profile/ this applies to all different modalities. If [hybrid](#uau_hybr) is this applies to all different modalities. If [hybrid](#uau_hybr) is selected in [FIA_UAU.5.1](#FIA_UAU.5.1) it must be selected and the user selected in [FIA_UAU.5.1](#FIA_UAU.5.1) it must be selected and the user or admin must have the option to disable the use of it. or admin must have the option to disable the use of it. Function [23](#mf-certInvalid) must be included in the [ST](#abbr_ST) if Function [23](#mf-certInvalid) must be included in the [ST](#abbr_ST) if the function is configurable on the [TOE](#abbr_TOE) for any of the the function is configurable on the [TOE](#abbr_TOE) for any of the trusted channels either mandated or selected in trusted channels either mandated or selected in [FTP_ITC_EXT.1.1](#FTP_ITC_EXT.1.1) or [FTP_ITC_EXT.1.1](#FTP_ITC_EXT.1.1) or [FDP_UPC_EXT.1.1/APPS](#FDP_UPC_EXT.1.1/APPS). The configuration can be [FDP_UPC_EXT.1.1/APPS](#FDP_UPC_EXT.1.1/APPS). The configuration can be different depending on the specific trusted channel(s) and they must be different depending on the specific trusted channel(s) and they must be filled in for the assignment. filled in for the assignment. The assignment in function [24](#mf-externalPorts) consists of all The assignment in function [24](#mf-externalPorts) consists of all externally accessible hardware ports, such as [USB](#abbr_USB), the SD externally accessible hardware ports, such as [USB](#abbr_USB), the SD card, and [HDMI](#abbr_HDMI), whose data transfer capabilities can be card, and [HDMI](#abbr_HDMI), whose data transfer capabilities can be enabled and disabled by either the user or administrator. Disablement of enabled and disabled by either the user or administrator. Disablement of data transfer over an external port must be effective during and after data transfer over an external port must be effective during and after boot into the normal operative mode of the device. If the boot into the normal operative mode of the device. If the [TOE](#abbr_TOE) supports states in which configured security management [TOE](#abbr_TOE) supports states in which configured security management policy is inaccessible, for example, due to data-at-rest protection, it policy is inaccessible, for example, due to data-at-rest protection, it is acceptable to meet this requirement by ensuring that data transfer is is acceptable to meet this requirement by ensuring that data transfer is disabled by default while in these states. Each of the ports may be disabled by default while in these states. Each of the ports may be enabled or disabled separately. The configuration policy need not enabled or disabled separately. The configuration policy need not disable all ports together. In the case of [USB](#abbr_USB), charging is disable all ports together. In the case of [USB](#abbr_USB), charging is still allowed if data transfer capabilities have been disabled. still allowed if data transfer capabilities have been disabled. The assignment in function [25](#mf-serverProtocols) consists of all The assignment in function [25](#mf-serverProtocols) consists of all protocols where the [TSF](#abbr_TSF) acts as a server, which can be protocols where the [TSF](#abbr_TSF) acts as a server, which can be enabled and disabled by either the user or administrator. Hotspot enabled and disabled by either the user or administrator. Hotspot tethering is not a \'protocol\' as defined by this function. This is tethering is not a \'protocol\' as defined by this function. This is defined in management function WL-3 of [PP-Module for Wireless LAN defined in management function WL-3 of [PP-Module for Wireless LAN Client, version 2.0](https://www.niap-ccevs.org/protectionprofiles/463). | Client, version 2.0](). Function [26](#mf-devModes) must be included in the selection if Function [26](#mf-devModes) must be included in the selection if developer modes are supported by the [TSF](#abbr_TSF). developer modes are supported by the [TSF](#abbr_TSF). Function [27](#mf-authBypass) must be included in the selection if Function [27](#mf-authBypass) must be included in the selection if bypass of local user authentication, such as a \"Forgot Password\", bypass of local user authentication, such as a \"Forgot Password\", password hint, or remote authentication feature, is supported. password hint, or remote authentication feature, is supported. Function [29](#mf-appCert) must be included in the selection if the Function [29](#mf-appCert) must be included in the selection if the [TSF](#abbr_TSF) allows applications, other than [MDM](#abbr_MDM) [TSF](#abbr_TSF) allows applications, other than [MDM](#abbr_MDM) agents, to import or remove X.509v3 certificates from the Trust Anchor agents, to import or remove X.509v3 certificates from the Trust Anchor Database. The [MDM](#abbr_MDM) agent is considered to be acting as the Database. The [MDM](#abbr_MDM) agent is considered to be acting as the administrator. This function does not apply to applications trusting a administrator. This function does not apply to applications trusting a certificate for its own validations. The function only applies to certificate for its own validations. The function only applies to situations where the application modifies the device-wide Trust Anchor situations where the application modifies the device-wide Trust Anchor Database, affecting the validations performed by the [TSF](#abbr_TSF) Database, affecting the validations performed by the [TSF](#abbr_TSF) for other applications. The user or administrator may be provided the for other applications. The user or administrator may be provided the ability to globally allow or deny any application requests in order to ability to globally allow or deny any application requests in order to meet this requirement. meet this requirement. Function [30](#mf-certValidity) must be included in the [ST](#abbr_ST) Function [30](#mf-certValidity) must be included in the [ST](#abbr_ST) if \"administrator is allowed to configure certificate acceptance\" is if \"administrator is allowed to configure certificate acceptance\" is selected in FIA_X509_EXT.2.2 in [Functional Package for X.509, version selected in FIA_X509_EXT.2.2 in [Functional Package for X.509, version 1.0](https://www.niap-ccevs.org/protectionprofiles/511) 1.0](https://www.niap-ccevs.org/protectionprofiles/511) Function [33](#mf-digSign) should be included in the selection if Function [33](#mf-digSign) should be included in the selection if [FPT_TUD_EXT.5.1](#FPT_TUD_EXT.5.1) is included in the [ST](#abbr_ST) [FPT_TUD_EXT.5.1](#FPT_TUD_EXT.5.1) is included in the [ST](#abbr_ST) and the configurable option is selected. and the configurable option is selected. Function [34](#mf-sharedKeys) should be included in the selection if Function [34](#mf-sharedKeys) should be included in the selection if user or administrator is selected in user or administrator is selected in [FCS_STG_EXT.1.4](#FCS_STG_EXT.1.4). [FCS_STG_EXT.1.4](#FCS_STG_EXT.1.4). Function [35](#mf-keyWipeRules) should be included in the selection if Function [35](#mf-keyWipeRules) should be included in the selection if [the user](#s-killkey-user) or [the administrator](#s-killkey-admin) is [the user](#s-killkey-user) or [the administrator](#s-killkey-admin) is selected in [FCS_STG_EXT.1.5](#FCS_STG_EXT.1.5). selected in [FCS_STG_EXT.1.5](#FCS_STG_EXT.1.5). Function [37](#mf-auditItems) must be included in the selection if Function [37](#mf-auditItems) must be included in the selection if [FAU_SEL.1](#FAU_SEL.1) is included in the [ST](#abbr_ST). [FAU_SEL.1](#FAU_SEL.1) is included in the [ST](#abbr_ST). Function [41](#mf-hotspot), device authentication for [USB](#abbr_USB) Function [41](#mf-hotspot), device authentication for [USB](#abbr_USB) tethering refers to the user needing to authenticate themselves to the tethering refers to the user needing to authenticate themselves to the mobile device and unlock it in order to initiate a tethered connection. mobile device and unlock it in order to initiate a tethered connection. [USB](#abbr_USB) device authentication references the use of device [USB](#abbr_USB) device authentication references the use of device filtration to permit or reject tethering for certain connected devices filtration to permit or reject tethering for certain connected devices or types of devices. or types of devices. Functions [42](#mf-dataSharing) and [43](#mf-appGroups) correspond to Functions [42](#mf-dataSharing) and [43](#mf-appGroups) correspond to [FDP_ACF_EXT.1.2](#FDP_ACF_EXT.1.2). [FDP_ACF_EXT.1.2](#FDP_ACF_EXT.1.2). For function [44](#mf-unenroll), [FMT_SMF_EXT.2.1](#FMT_SMF_EXT.2.1) For function [44](#mf-unenroll), [FMT_SMF_EXT.2.1](#FMT_SMF_EXT.2.1) specifies actions to be performed when the [TOE](#abbr_TOE) is specifies actions to be performed when the [TOE](#abbr_TOE) is unenrolled from management. unenrolled from management. Function [45](#mf-alwaysOnVPN) must be included in the [ST](#abbr_ST) if Function [45](#mf-alwaysOnVPN) must be included in the [ST](#abbr_ST) if [IPsec](#abbr_IPsec) is selected in [FTP_ITC_EXT.1](#FTP_ITC_EXT.1) and [IPsec](#abbr_IPsec) is selected in [FTP_ITC_EXT.1](#FTP_ITC_EXT.1) and the native [IPsec](#abbr_IPsec) [VPN](#abbr_VPN) client can be the native [IPsec](#abbr_IPsec) [VPN](#abbr_VPN) client can be configured to be Always-On. Always-On is defined as when the configured to be Always-On. Always-On is defined as when the [TOE](#abbr_TOE) has a network connection the [VPN](#abbr_VPN) attempts [TOE](#abbr_TOE) has a network connection the [VPN](#abbr_VPN) attempts to connect, all data leaving the device uses the [VPN](#abbr_VPN) when to connect, all data leaving the device uses the [VPN](#abbr_VPN) when the [VPN](#abbr_VPN) is connected and no data leaves that device when the [VPN](#abbr_VPN) is connected and no data leaves that device when the [VPN](#abbr_VPN) is disconnected. The configuration of the the [VPN](#abbr_VPN) is disconnected. The configuration of the [VPN](#abbr_VPN) Client itself (with information such as [VPN](#abbr_VPN) Client itself (with information such as [VPN](#abbr_VPN) Gateway, certificates, and algorithms) is addressed by [VPN](#abbr_VPN) Gateway, certificates, and algorithms) is addressed by the [PP-Module for Virtual Private Network (VPN) Clients, version the [PP-Module for Virtual Private Network (VPN) Clients, version 3.0](https://www.niap-ccevs.org/protectionprofiles/487). | 3.0](). ::: ::: ::: ::: ::: ::: ::: {.activity_pane .hide} ::: {.activity_pane .hide} ::: activity_pane_header ::: activity_pane_header [[ Evaluation Activities [[ Evaluation Activities ]{.activity_pane_label}[]{.toggler}](#){onclick="toggle(this);return false;"} ]{.activity_pane_label}[]{.toggler}](#){onclick="toggle(this);return false;"} ::: ::: ::: activity_pane_body ::: activity_pane_body ::: component-activity-header ::: component-activity-header [FMT_SMF_EXT.1](#FMT_SMF_EXT.1) [FMT_SMF_EXT.1](#FMT_SMF_EXT.1) ::: ::: ::: eacategory ::: eacategory [TSS](#abbr_TSS) [TSS](#abbr_TSS) ::: ::: ::: ea ::: ea ::: ea ::: ea The evaluator shall verify that the [TSS](#abbr_TSS) describes all The evaluator shall verify that the [TSS](#abbr_TSS) describes all management functions, what roles can perform each function, and how management functions, what roles can perform each function, and how these functions are (or can be) restricted to the roles identified by these functions are (or can be) restricted to the roles identified by [FMT_MOF_EXT.1](#FMT_MOF_EXT.1).\ [FMT_MOF_EXT.1](#FMT_MOF_EXT.1).\ \ \ The following activities are organized according to the function number The following activities are organized according to the function number in the table. These activities include [TSS](#abbr_TSS) Evaluation in the table. These activities include [TSS](#abbr_TSS) Evaluation Activities, AGD Evaluation Activities, and test activities.\ Activities, AGD Evaluation Activities, and test activities.\ \ \ Test activities specified below shall take place in the test environment Test activities specified below shall take place in the test environment described in the evaluation activity for described in the evaluation activity for [FPT_TUD_EXT.1](#FPT_TUD_EXT.1).\ [FPT_TUD_EXT.1](#FPT_TUD_EXT.1).\ \ \ ::: ::: ::: ::: ::: eacategory ::: eacategory Guidance Guidance ::: ::: ::: ea ::: ea ::: ea ::: ea The evaluator shall consult the AGD guidance to perform each of the The evaluator shall consult the AGD guidance to perform each of the specified tests, iterating each test as necessary if both the user and specified tests, iterating each test as necessary if both the user and administrator may perform the function. The evaluator shall verify that administrator may perform the function. The evaluator shall verify that the AGD guidance describes how to perform each management function, the AGD guidance describes how to perform each management function, including any configuration details. For each specified management including any configuration details. For each specified management function tested, the evaluator shall confirm that the underlying function tested, the evaluator shall confirm that the underlying mechanism exhibits the configured setting. mechanism exhibits the configured setting. ::: ::: ::: ::: > ::: eacategory > Tests > ::: > > ::: ea > There are no test activities for this component.\ > ::: > ::: management_function_activities ::: management_function_activities The following EAs correspond to specific management functions. The following EAs correspond to specific management functions. ::: management_function_ea ::: management_function_ea **Function [1](#mf-pwd)**\ **Function [1](#mf-pwd)**\ ::: eacategory ::: eacategory [TSS](#abbr_TSS) [TSS](#abbr_TSS) ::: ::: ::: ea ::: ea The evaluator shall verify the [TSS](#abbr_TSS) defines the allowable The evaluator shall verify the [TSS](#abbr_TSS) defines the allowable policy options: the range of values for both password length and policy options: the range of values for both password length and lifetime, and a description of complexity to include character set and lifetime, and a description of complexity to include character set and complexity policies (e.g., configuration and enforcement of number of complexity policies (e.g., configuration and enforcement of number of uppercase, lowercase, and special characters per password). uppercase, lowercase, and special characters per password). ::: ::: ::: eacategory ::: eacategory > Guidance > ::: > > There are no additional Guidance evaluation activities for this > management function.\ > \ > > ::: eacategory Tests Tests ::: ::: ::: ea ::: ea Test [FMT_SMF_EXT.1](#FMT_SMF_EXT.1):1: The evaluator shall exercise the Test [FMT_SMF_EXT.1](#FMT_SMF_EXT.1):1: The evaluator shall exercise the [TSF](#abbr_TSF) configuration as the administrator and perform positive [TSF](#abbr_TSF) configuration as the administrator and perform positive and negative tests, with at least two values set for each variable and negative tests, with at least two values set for each variable setting, for each of the following:\ setting, for each of the following:\ - Minimum password length - Minimum password length - Minimum password complexity - Minimum password complexity - Maximum password lifetime - Maximum password lifetime ::: ::: \ \ ::: ::: ::: management_function_ea ::: management_function_ea **Function [2](#mf-screenlock)**\ **Function [2](#mf-screenlock)**\ ::: eacategory ::: eacategory [TSS](#abbr_TSS) [TSS](#abbr_TSS) ::: ::: ::: ea ::: ea The evaluator shall verify the [TSS](#abbr_TSS) defines the range of The evaluator shall verify the [TSS](#abbr_TSS) defines the range of values for both timeout period and number of authentication failures for values for both timeout period and number of authentication failures for all supported authentication mechanisms. all supported authentication mechanisms. ::: ::: ::: eacategory ::: eacategory > Guidance > ::: > > There are no additional Guidance evaluation activities for this > management function.\ > \ > > ::: eacategory Tests Tests ::: ::: ::: ea ::: ea Test [FMT_SMF_EXT.1](#FMT_SMF_EXT.1):2: The evaluator shall exercise the Test [FMT_SMF_EXT.1](#FMT_SMF_EXT.1):2: The evaluator shall exercise the [TSF](#abbr_TSF) configuration as the administrator. The evaluator shall [TSF](#abbr_TSF) configuration as the administrator. The evaluator shall perform positive and negative tests, with at least two values set for perform positive and negative tests, with at least two values set for each variable setting, for each of the following:\ each variable setting, for each of the following:\ - Screen-lock enabled/disabled - Screen-lock enabled/disabled - Screen lock timeout - Screen lock timeout - Number of authentication failures (may be combined with test for - Number of authentication failures (may be combined with test for [FIA_AFL_EXT.1](#FIA_AFL_EXT.1)) [FIA_AFL_EXT.1](#FIA_AFL_EXT.1)) ::: ::: \ \ ::: ::: ::: management_function_ea ::: management_function_ea **Function [3](#mf-vpn)**\ **Function [3](#mf-vpn)**\ ::: eacategory ::: eacategory > [TSS](#abbr_TSS) > ::: > > There are no additional [TSS](#abbr_TSS) evaluation activities for this > management function.\ > \ > > ::: eacategory > Guidance > ::: > > There are no additional Guidance evaluation activities for this > management function.\ > \ > > ::: eacategory Tests Tests ::: ::: ::: ea ::: ea The evaluator shall perform the following tests: The evaluator shall perform the following tests: - Test [FMT_SMF_EXT.1](#FMT_SMF_EXT.1):3a: The evaluator shall - Test [FMT_SMF_EXT.1](#FMT_SMF_EXT.1):3a: The evaluator shall exercise the [TSF](#abbr_TSF) configuration to enable the exercise the [TSF](#abbr_TSF) configuration to enable the [VPN](#abbr_VPN) protection. These configuration actions must be [VPN](#abbr_VPN) protection. These configuration actions must be used for the testing of the [FDP_IFC_EXT.1.1](#FDP_IFC_EXT.1.1) used for the testing of the [FDP_IFC_EXT.1.1](#FDP_IFC_EXT.1.1) requirement. requirement. - Test [FMT_SMF_EXT.1](#FMT_SMF_EXT.1):3b: \[conditional\] If \"[on a - Test [FMT_SMF_EXT.1](#FMT_SMF_EXT.1):3b: \[conditional\] If \"[on a per-app basis](#s-vpn-per-app)\" is selected, the evaluator shall per-app basis](#s-vpn-per-app)\" is selected, the evaluator shall create two applications and enable one to use the [VPN](#abbr_VPN) create two applications and enable one to use the [VPN](#abbr_VPN) and the other to not use the [VPN](#abbr_VPN). The evaluator shall and the other to not use the [VPN](#abbr_VPN). The evaluator shall exercise each application (attempting to access network resources; exercise each application (attempting to access network resources; for example, by browsing different websites) individually while for example, by browsing different websites) individually while capturing packets from the [TOE](#abbr_TOE). The evaluator shall capturing packets from the [TOE](#abbr_TOE). The evaluator shall verify from the packet capture that the traffic from the verify from the packet capture that the traffic from the [VPN](#abbr_VPN)-enabled application is encapsulated in [VPN](#abbr_VPN)-enabled application is encapsulated in [IPsec](#abbr_IPsec) and that the traffic from the [IPsec](#abbr_IPsec) and that the traffic from the [VPN](#abbr_VPN)-disabled application is not encapsulated in [VPN](#abbr_VPN)-disabled application is not encapsulated in [IPsec](#abbr_IPsec). [IPsec](#abbr_IPsec). - Test [FMT_SMF_EXT.1](#FMT_SMF_EXT.1):3c: \[conditional\] If \"[on a - Test [FMT_SMF_EXT.1](#FMT_SMF_EXT.1):3c: \[conditional\] If \"[on a per-group of applications processes basis](#s-vpn-per-appgroup)\" is per-group of applications processes basis](#s-vpn-per-appgroup)\" is selected, the evaluator shall create two applications and the selected, the evaluator shall create two applications and the applications shall be placed into different groups. Enable one applications shall be placed into different groups. Enable one application group to use the [VPN](#abbr_VPN) and the other to not application group to use the [VPN](#abbr_VPN) and the other to not use the [VPN](#abbr_VPN). The evaluator shall exercise each use the [VPN](#abbr_VPN). The evaluator shall exercise each application (attempting to access network resources; for example, by application (attempting to access network resources; for example, by browsing different websites) individually while capturing packets browsing different websites) individually while capturing packets from the [TOE](#abbr_TOE). The evaluator shall verify from the from the [TOE](#abbr_TOE). The evaluator shall verify from the packet capture that the traffic from the application in the packet capture that the traffic from the application in the [VPN](#abbr_VPN)-enabled group is encapsulated in [VPN](#abbr_VPN)-enabled group is encapsulated in [IPsec](#abbr_IPsec) and that the traffic from the application in [IPsec](#abbr_IPsec) and that the traffic from the application in the [VPN](#abbr_VPN)-disabled group is not encapsulated in the [VPN](#abbr_VPN)-disabled group is not encapsulated in [IPsec](#abbr_IPsec). [IPsec](#abbr_IPsec). ::: ::: \ \ ::: ::: ::: management_function_ea ::: management_function_ea **Function [4](#mf-radios)**\ **Function [4](#mf-radios)**\ ::: eacategory ::: eacategory [TSS](#abbr_TSS) [TSS](#abbr_TSS) ::: ::: ::: ea ::: ea The evaluator shall verify that the [TSS](#abbr_TSS) includes a The evaluator shall verify that the [TSS](#abbr_TSS) includes a description of each radio and an indication of if the radio can be description of each radio and an indication of if the radio can be enabled/disabled along with what role can do so. In addition the enabled/disabled along with what role can do so. In addition the evaluator shall verify that the frequency ranges at which each radio evaluator shall verify that the frequency ranges at which each radio operates is included in the [TSS](#abbr_TSS). The evaluator shall verify operates is included in the [TSS](#abbr_TSS). The evaluator shall verify that the [TSS](#abbr_TSS) includes at what point in the boot sequence that the [TSS](#abbr_TSS) includes at what point in the boot sequence the radios are powered on and indicates if the radios are used as part the radios are powered on and indicates if the radios are used as part of the initialization of the device. of the initialization of the device. ::: ::: ::: eacategory ::: eacategory Guidance Guidance ::: ::: ::: ea ::: ea The evaluator shall confirm that the AGD guidance describes how to The evaluator shall confirm that the AGD guidance describes how to perform the enable/disable function for each radio. perform the enable/disable function for each radio. ::: ::: ::: eacategory ::: eacategory Tests Tests ::: ::: ::: ea ::: ea Test [FMT_SMF_EXT.1](#FMT_SMF_EXT.1):4: The evaluator shall ensure that Test [FMT_SMF_EXT.1](#FMT_SMF_EXT.1):4: The evaluator shall ensure that minimal signal leakage enters the RF shielded enclosure (i.e., Faraday minimal signal leakage enters the RF shielded enclosure (i.e., Faraday bag, Faraday box, RF shielded room) by performing the following steps: bag, Faraday box, RF shielded room) by performing the following steps: < Step 1: Place the antenna of the spectrum analyzer inside the RF Step 1: Place the antenna of the spectrum analyzer inside the RF shielded enclosure. | shielded enclosure. Step 2: Enable \"Max Hold\" on the spectrum analyzer | and perform a spectrum sweep of the frequency range between 300 MHz - Step 2: Enable \"Max Hold\" on the spectrum analyzer and perform a | 6000 MHz, in 1 kHz steps (this range should encompass 802.11, 802.15, spectrum sweep of the frequency range between 300 MHz - 6000 MHz, in 1 | GSM, UMTS, and [LTE](#abbr_LTE)). This range will not address kHz steps (this range should encompass 802.11, 802.15, GSM, UMTS, and | [NFC](#abbr_NFC) 13.56.MHz, another test should be set up with similar [LTE](#abbr_LTE)). This range will not address [NFC](#abbr_NFC) | constraints to address [NFC](#abbr_NFC). If power above -75 dBm is 13.56.MHz, another test should be set up with similar constraints to | observed, the Faraday box has too great of signal leakage and shall not address [NFC](#abbr_NFC). | be used to complete the test for Function [4](#mf-radios). The evaluator | shall exercise the [TSF](#abbr_TSF) configuration as the administrator If power above -75 dBm is observed, the Faraday box has too great of | and, if not restricted to the administrator, the user, to enable and signal leakage and shall not be used to complete the test for Function | disable the state of each radio (e.g. Wi-Fi, cellular, [NFC](#abbr_NFC), [4](#mf-radios). | Bluetooth). Additionally, the evaluator shall repeat the steps below, | booting into any auxiliary boot mode supported by the device. For each The evaluator shall exercise the [TSF](#abbr_TSF) configuration as the | radio, the evaluator shall: Step 1: Place the antenna of the spectrum administrator and, if not restricted to the administrator, the user, to | analyzer inside the RF shielded enclosure. Configure the spectrum enable and disable the state of each radio (e.g. Wi-Fi, cellular, | analyzer to sweep desired frequency range for the radio to be tested [NFC](#abbr_NFC), Bluetooth). Additionally, the evaluator shall repeat | (based on range provided in the [TSS](#abbr_TSS))). The ambient noise the steps below, booting into any auxiliary boot mode supported by the | floor shall be set to -110 dBm. Place the [TOE](#abbr_TOE) into the RF device. For each radio, the evaluator shall: | shielded enclosure to isolate them from all other RF traffic. Step 2: | The evaluator shall create a baseline of the expected behavior of RF Step 1: Place the antenna of the spectrum analyzer inside the RF | signals. The evaluator shall power on the device, ensure the radio in shielded enclosure. Configure the spectrum analyzer to sweep desired | question is enabled, power off the device, enable \"Max Hold\" on the frequency range for the radio to be tested (based on range provided in < the [TSS](#abbr_TSS))). The ambient noise floor shall be set to -110 < dBm. Place the [TOE](#abbr_TOE) into the RF shielded enclosure to < isolate them from all other RF traffic. < < Step 2: The evaluator shall create a baseline of the expected behavior < of RF signals. The evaluator shall power on the device, ensure the radio < in question is enabled, power off the device, enable \"Max Hold\" on the < spectrum analyzer and power on the device. The evaluator shall wait 2 spectrum analyzer and power on the device. The evaluator shall wait 2 minutes at each Authentication Factor interface prior to entering the minutes at each Authentication Factor interface prior to entering the necessary password to complete the boot process, waiting 5 minutes after necessary password to complete the boot process, waiting 5 minutes after the device is fully booted. The evaluator shall observe that RF spikes the device is fully booted. The evaluator shall observe that RF spikes are present at the expected uplink channel frequency. The evaluator are present at the expected uplink channel frequency. The evaluator shall clear the \"Max Hold\" on the spectrum analyzer. | shall clear the \"Max Hold\" on the spectrum analyzer. Step 3: The | evaluator shall verify the absence of RF activity for the uplink channel Step 3: The evaluator shall verify the absence of RF activity for the | when the radio in question is disabled. The evaluator shall complete the uplink channel when the radio in question is disabled. The evaluator | following test five times. The evaluator shall power on the device, shall complete the following test five times. The evaluator shall power | ensure the radio in question is disabled, power off the device, enable on the device, ensure the radio in question is disabled, power off the | \"Max Hold\" on the spectrum analyzer and power on the device. The device, enable \"Max Hold\" on the spectrum analyzer and power on the | evaluator shall wait 2 minutes at each Authentication Factor interface device. The evaluator shall wait 2 minutes at each Authentication Factor | prior to entering the necessary password to complete the boot process, interface prior to entering the necessary password to complete the boot | waiting 5 minutes after the device is fully booted. The evaluator shall process, waiting 5 minutes after the device is fully booted. The | clear the \"Max Hold\" on the spectrum analyzer. If the radios are used evaluator shall clear the \"Max Hold\" on the spectrum analyzer. If the | for device initialization, then a spike of RF activity for the uplink radios are used for device initialization, then a spike of RF activity | channel can be observed initially at device boot. However, if a spike of for the uplink channel can be observed initially at device boot. | RF activity for the uplink channel of the specific radio frequency band However, if a spike of RF activity for the uplink channel of the | is observed after the device is fully booted or at an Authentication specific radio frequency band is observed after the device is fully | Factor interface it is deemed that the radio is enabled. booted or at an Authentication Factor interface it is deemed that the < radio is enabled. < ::: ::: \ \ ::: ::: ::: management_function_ea ::: management_function_ea **Function [5](#mf-audioVisual)**\ **Function [5](#mf-audioVisual)**\ ::: eacategory ::: eacategory [TSS](#abbr_TSS) [TSS](#abbr_TSS) ::: ::: ::: ea ::: ea The evaluator shall verify that the [TSS](#abbr_TSS) includes a The evaluator shall verify that the [TSS](#abbr_TSS) includes a description of each collection device and an indication of if it can be description of each collection device and an indication of if it can be enabled/disabled along with what role can do so. The evaluator shall enabled/disabled along with what role can do so. The evaluator shall confirm that the AGD guidance describes how to perform the confirm that the AGD guidance describes how to perform the enable/disable function. enable/disable function. ::: ::: ::: eacategory ::: eacategory > Guidance > ::: > > There are no additional Guidance evaluation activities for this > management function.\ > \ > > ::: eacategory Tests Tests ::: ::: ::: ea ::: ea The evaluator shall perform the following tests: The evaluator shall perform the following tests: - Test [FMT_SMF_EXT.1](#FMT_SMF_EXT.1):5a: The evaluator shall - Test [FMT_SMF_EXT.1](#FMT_SMF_EXT.1):5a: The evaluator shall exercise the [TSF](#abbr_TSF) configuration as the administrator exercise the [TSF](#abbr_TSF) configuration as the administrator and, if not restricted to the administrator, the user, to enable and and, if not restricted to the administrator, the user, to enable and disable the state of each audio or visual collection devices (e.g. disable the state of each audio or visual collection devices (e.g. camera, microphone) listed by the [ST](#abbr_ST) author. For each camera, microphone) listed by the [ST](#abbr_ST) author. For each collection device, the evaluator shall disable the device and then collection device, the evaluator shall disable the device and then attempt to use its functionality. The evaluator shall reboot the attempt to use its functionality. The evaluator shall reboot the [TOE](#abbr_TOE) and verify that disabled collection devices may not [TOE](#abbr_TOE) and verify that disabled collection devices may not be used during or early in the boot process. Additionally, the be used during or early in the boot process. Additionally, the evaluator shall boot the device into each available auxiliary boot evaluator shall boot the device into each available auxiliary boot mode and verify that the collection device cannot be used. mode and verify that the collection device cannot be used. - Test [FMT_SMF_EXT.1](#FMT_SMF_EXT.1):5b: \[conditional\] If \"[on a - Test [FMT_SMF_EXT.1](#FMT_SMF_EXT.1):5b: \[conditional\] If \"[on a per-app basis](#s-audiovisual-per-app)\" is selected, the evaluator per-app basis](#s-audiovisual-per-app)\" is selected, the evaluator shall create two applications and enable one to use access the A/V shall create two applications and enable one to use access the A/V device and the other to not access the A/V device. The evaluator device and the other to not access the A/V device. The evaluator shall exercise each application attempting to access the A/V device shall exercise each application attempting to access the A/V device individually. The evaluator shall verify that the enabled individually. The evaluator shall verify that the enabled application is able to access the A/V device and the disabled application is able to access the A/V device and the disabled application is not able to access the A/V device. application is not able to access the A/V device. - Test [FMT_SMF_EXT.1](#FMT_SMF_EXT.1):5c: \[conditional\] If \"[on a - Test [FMT_SMF_EXT.1](#FMT_SMF_EXT.1):5c: \[conditional\] If \"[on a per-group of applications processes per-group of applications processes basis](#s-audiovisual-per-appgroup)\" is selected, the evaluator basis](#s-audiovisual-per-appgroup)\" is selected, the evaluator shall create two applications and the applications shall be placed shall create two applications and the applications shall be placed into different groups. Enable one group to access the A/V device and into different groups. Enable one group to access the A/V device and the other to not access the A/V device. The evaluator shall exercise the other to not access the A/V device. The evaluator shall exercise each application attempting to access the A/V device individually. each application attempting to access the A/V device individually. The evaluator shall verify that the application in the enabled group The evaluator shall verify that the application in the enabled group is able to access the A/V device and the application in the disabled is able to access the A/V device and the application in the disabled group is not able to access the A/V device. group is not able to access the A/V device. ::: ::: \ \ ::: ::: ::: management_function_ea ::: management_function_ea **Function [6](#mf-lockState)**\ **Function [6](#mf-lockState)**\ ::: eacategory ::: eacategory > [TSS](#abbr_TSS) > ::: > > There are no additional [TSS](#abbr_TSS) evaluation activities for this > management function.\ > \ > > ::: eacategory > Guidance > ::: > > There are no additional Guidance evaluation activities for this > management function.\ > \ > > ::: eacategory Tests Tests ::: ::: ::: ea ::: ea Test [FMT_SMF_EXT.1](#FMT_SMF_EXT.1):6: The evaluator shall use the test Test [FMT_SMF_EXT.1](#FMT_SMF_EXT.1):6: The evaluator shall use the test environment to instruct the [TSF](#abbr_TSF), both as a user and as the environment to instruct the [TSF](#abbr_TSF), both as a user and as the administrator, to command the device to transition to a locked state, administrator, to command the device to transition to a locked state, and verify that the device transitions to the locked state upon command. and verify that the device transitions to the locked state upon command. ::: ::: \ \ ::: ::: ::: management_function_ea ::: management_function_ea **Function [7](#mf-wipe)**\ **Function [7](#mf-wipe)**\ ::: eacategory ::: eacategory > [TSS](#abbr_TSS) > ::: > > There are no additional [TSS](#abbr_TSS) evaluation activities for this > management function.\ > \ > > ::: eacategory > Guidance > ::: > > There are no additional Guidance evaluation activities for this > management function.\ > \ > > ::: eacategory Tests Tests ::: ::: ::: ea ::: ea Test [FMT_SMF_EXT.1](#FMT_SMF_EXT.1):7: The evaluator shall use the test Test [FMT_SMF_EXT.1](#FMT_SMF_EXT.1):7: The evaluator shall use the test environment to instruct the [TSF](#abbr_TSF), both as a user and as the environment to instruct the [TSF](#abbr_TSF), both as a user and as the administrator, to command the device to perform a wipe of protected administrator, to command the device to perform a wipe of protected data. The evaluator shall ensure that this management setup is used when data. The evaluator shall ensure that this management setup is used when conducting the Evaluation Activities in [FCS_CKM_EXT.5](#FCS_CKM_EXT.5). conducting the Evaluation Activities in [FCS_CKM_EXT.5](#FCS_CKM_EXT.5). ::: ::: \ \ ::: ::: ::: management_function_ea ::: management_function_ea **Function [8](#mf-appInstallRules)**\ **Function [8](#mf-appInstallRules)**\ ::: eacategory ::: eacategory [TSS](#abbr_TSS) [TSS](#abbr_TSS) ::: ::: ::: ea ::: ea The evaluator shall verify the [TSS](#abbr_TSS) describes the allowable The evaluator shall verify the [TSS](#abbr_TSS) describes the allowable application installation policy options based on the selection included application installation policy options based on the selection included in the [ST](#abbr_ST). If the [application in the [ST](#abbr_ST). If the [application allowlist](#mf-appInstallRules-specify) is selected, the evaluator shall allowlist](#mf-appInstallRules-specify) is selected, the evaluator shall verify that the [TSS](#abbr_TSS) includes a description of each verify that the [TSS](#abbr_TSS) includes a description of each application characteristic upon which the allowlist may be based. application characteristic upon which the allowlist may be based. ::: ::: ::: eacategory ::: eacategory > Guidance > ::: > > There are no additional Guidance evaluation activities for this > management function.\ > \ > > ::: eacategory Tests Tests ::: ::: ::: ea ::: ea The evaluator shall exercise the [TSF](#abbr_TSF) configuration as the The evaluator shall exercise the [TSF](#abbr_TSF) configuration as the administrator to restrict particular applications, sources of administrator to restrict particular applications, sources of applications, or application installation according to the AGD guidance. applications, or application installation according to the AGD guidance. The evaluator shall attempt to install unauthorized applications and The evaluator shall attempt to install unauthorized applications and ensure that this is not possible. The evaluator shall, in conjunction, ensure that this is not possible. The evaluator shall, in conjunction, perform the following specific tests: perform the following specific tests: - Test [FMT_SMF_EXT.1](#FMT_SMF_EXT.1):8a: \[conditional\] The - Test [FMT_SMF_EXT.1](#FMT_SMF_EXT.1):8a: \[conditional\] The evaluator shall attempt to connect to an unauthorized repository in evaluator shall attempt to connect to an unauthorized repository in order to install applications. order to install applications. - Test [FMT_SMF_EXT.1](#FMT_SMF_EXT.1):8b: \[conditional\] The - Test [FMT_SMF_EXT.1](#FMT_SMF_EXT.1):8b: \[conditional\] The evaluator shall attempt to install two applications (one evaluator shall attempt to install two applications (one allowlisted, and one not) from a known allowed repository and verify allowlisted, and one not) from a known allowed repository and verify that the application not on the allowlist is rejected. The evaluator that the application not on the allowlist is rejected. The evaluator shall also attempt to side-load executables or installation packages shall also attempt to side-load executables or installation packages via [USB](#abbr_USB) connections to determine that the white list is via [USB](#abbr_USB) connections to determine that the white list is still adhered to still adhered to ::: ::: \ \ ::: ::: ::: management_function_ea ::: management_function_ea **Functions [9](#mf-keyStorage)/[10](#mf-keyWipe)**\ **Functions [9](#mf-keyStorage)/[10](#mf-keyWipe)**\ ::: eacategory ::: eacategory [TSS](#abbr_TSS) [TSS](#abbr_TSS) ::: ::: ::: ea ::: ea The evaluator shall verify that the [TSS](#abbr_TSS) describes each The evaluator shall verify that the [TSS](#abbr_TSS) describes each category of keys or secrets that can be imported into the category of keys or secrets that can be imported into the [TSF](#abbr_TSF)'s secure key storage. [TSF](#abbr_TSF)'s secure key storage. ::: ::: ::: eacategory ::: eacategory > Guidance > ::: > > There are no additional Guidance evaluation activities for this > management function.\ > \ > > ::: eacategory Tests Tests ::: ::: ::: ea ::: ea The test of these functions is performed in association with The test of these functions is performed in association with [FCS_STG_EXT.1](#FCS_STG_EXT.1). [FCS_STG_EXT.1](#FCS_STG_EXT.1). ::: ::: \ \ ::: ::: ::: management_function_ea ::: management_function_ea **Function [11](#mf-certImport)**\ **Function [11](#mf-certImport)**\ ::: eacategory ::: eacategory > [TSS](#abbr_TSS) > ::: > > There are no additional [TSS](#abbr_TSS) evaluation activities for this > management function.\ > \ > > ::: eacategory Guidance Guidance ::: ::: ::: ea ::: ea The evaluator shall review the AGD guidance to determine that it The evaluator shall review the AGD guidance to determine that it describes the steps needed to import, modify, or remove certificates in describes the steps needed to import, modify, or remove certificates in the Trust Anchor database, and that the users that have authority to the Trust Anchor database, and that the users that have authority to import those certificates (e.g., only administrator, or both import those certificates (e.g., only administrator, or both administrators and users) are identified. administrators and users) are identified. ::: ::: ::: eacategory ::: eacategory Tests Tests ::: ::: ::: ea ::: ea Test [FMT_SMF_EXT.1](#FMT_SMF_EXT.1):11: The evaluator shall import Test [FMT_SMF_EXT.1](#FMT_SMF_EXT.1):11: The evaluator shall import certificates according to the AGD guidance as the user or as the certificates according to the AGD guidance as the user or as the administrator, as determined by the administrative guidance. The administrator, as determined by the administrative guidance. The evaluator shall verify that no errors occur during import. The evaluator evaluator shall verify that no errors occur during import. The evaluator should perform an action requiring use of the X.509v3 certificate to should perform an action requiring use of the X.509v3 certificate to provide assurance that installation was completed properly. provide assurance that installation was completed properly. ::: ::: \ \ ::: ::: ::: management_function_ea ::: management_function_ea **Function [12](#mf-certWipe)**\ **Function [12](#mf-certWipe)**\ ::: eacategory ::: eacategory [TSS](#abbr_TSS) [TSS](#abbr_TSS) ::: ::: ::: ea ::: ea The evaluator shall verify that the [TSS](#abbr_TSS) describes each The evaluator shall verify that the [TSS](#abbr_TSS) describes each additional category of X.509 certificates and their use within the additional category of X.509 certificates and their use within the [TSF](#abbr_TSF). [TSF](#abbr_TSF). ::: ::: ::: eacategory ::: eacategory > Guidance > ::: > > There are no additional Guidance evaluation activities for this > management function.\ > \ > > ::: eacategory Tests Tests ::: ::: ::: ea ::: ea Test [FMT_SMF_EXT.1](#FMT_SMF_EXT.1):12: The evaluator shall remove an Test [FMT_SMF_EXT.1](#FMT_SMF_EXT.1):12: The evaluator shall remove an administrator-imported certificate and any other categories of administrator-imported certificate and any other categories of certificates included in the assignment of function [14](#mf-appRemove) certificates included in the assignment of function [14](#mf-appRemove) from the Trust Anchor Database according to the AGD guidance as the user from the Trust Anchor Database according to the AGD guidance as the user and as the administrator. and as the administrator. ::: ::: \ \ ::: ::: ::: management_function_ea ::: management_function_ea **Function [13](#mf-enroll)**\ **Function [13](#mf-enroll)**\ ::: eacategory ::: eacategory [TSS](#abbr_TSS) [TSS](#abbr_TSS) ::: ::: ::: ea ::: ea The evaluator shall examine the [TSS](#abbr_TSS) to ensure that it The evaluator shall examine the [TSS](#abbr_TSS) to ensure that it contains a description of each management function that will be enforced contains a description of each management function that will be enforced by the enterprise once the device is enrolled. The evaluator shall by the enterprise once the device is enrolled. The evaluator shall examine the AGD guidance to determine that this same information is examine the AGD guidance to determine that this same information is present. present. ::: ::: ::: eacategory ::: eacategory > Guidance > ::: > > There are no additional Guidance evaluation activities for this > management function.\ > \ > > ::: eacategory Tests Tests ::: ::: ::: ea ::: ea Test [FMT_SMF_EXT.1](#FMT_SMF_EXT.1):13: The evaluator shall verify that Test [FMT_SMF_EXT.1](#FMT_SMF_EXT.1):13: The evaluator shall verify that user approval is required to enroll the device into management. user approval is required to enroll the device into management. ::: ::: \ \ ::: ::: ::: management_function_ea ::: management_function_ea **Function [14](#mf-appRemove)**\ **Function [14](#mf-appRemove)**\ ::: eacategory ::: eacategory [TSS](#abbr_TSS) [TSS](#abbr_TSS) ::: ::: ::: ea ::: ea The evaluator shall verify that the [TSS](#abbr_TSS) includes an The evaluator shall verify that the [TSS](#abbr_TSS) includes an indication of what applications (e.g., user-installed applications, indication of what applications (e.g., user-installed applications, Administrator-installed applications, or Enterprise applications) can be Administrator-installed applications, or Enterprise applications) can be removed along with what role can do so. The evaluator shall examine the removed along with what role can do so. The evaluator shall examine the AGD guidance to determine that it details, for each type of application AGD guidance to determine that it details, for each type of application that can be removed, the procedures necessary to remove those that can be removed, the procedures necessary to remove those applications and their associated data. For the purposes of this applications and their associated data. For the purposes of this Evaluation Activity, \"associated data\" refers to data that are created Evaluation Activity, \"associated data\" refers to data that are created by the app during its operation that do not exist independent of the by the app during its operation that do not exist independent of the app\'s existence, for instance, configuration data, or e-mail app\'s existence, for instance, configuration data, or e-mail information that's part of an e-mail client. It does not, on the other information that's part of an e-mail client. It does not, on the other hand, refer to data such as word processing documents (for a word hand, refer to data such as word processing documents (for a word processing app) or photos (for a photo or camera app). processing app) or photos (for a photo or camera app). ::: ::: ::: eacategory ::: eacategory > Guidance > ::: > > There are no additional Guidance evaluation activities for this > management function.\ > \ > > ::: eacategory Tests Tests ::: ::: ::: ea ::: ea Test [FMT_SMF_EXT.1](#FMT_SMF_EXT.1):14: The evaluator shall attempt to Test [FMT_SMF_EXT.1](#FMT_SMF_EXT.1):14: The evaluator shall attempt to remove applications according to the AGD guidance and verify that the remove applications according to the AGD guidance and verify that the [TOE](#abbr_TOE) no longer permits users to access those applications or [TOE](#abbr_TOE) no longer permits users to access those applications or their associated data. their associated data. ::: ::: \ \ ::: ::: ::: management_function_ea ::: management_function_ea **Function [15](#mf-update)**\ **Function [15](#mf-update)**\ ::: eacategory ::: eacategory > [TSS](#abbr_TSS) > ::: > > There are no additional [TSS](#abbr_TSS) evaluation activities for this > management function.\ > \ > > ::: eacategory > Guidance > ::: > > There are no additional Guidance evaluation activities for this > management function.\ > \ > > ::: eacategory Tests Tests ::: ::: ::: ea ::: ea Test [FMT_SMF_EXT.1](#FMT_SMF_EXT.1):15: The evaluator shall attempt to Test [FMT_SMF_EXT.1](#FMT_SMF_EXT.1):15: The evaluator shall attempt to update the [TSF](#abbr_TSF) system software following the procedures in update the [TSF](#abbr_TSF) system software following the procedures in the AGD guidance and verify that updates correctly install and that the the AGD guidance and verify that updates correctly install and that the version numbers of the system software increase. version numbers of the system software increase. ::: ::: \ \ ::: ::: ::: management_function_ea ::: management_function_ea **Function [16](#mf-appInstall)**\ **Function [16](#mf-appInstall)**\ ::: eacategory ::: eacategory > [TSS](#abbr_TSS) > ::: > > There are no additional [TSS](#abbr_TSS) evaluation activities for this > management function.\ > \ > > ::: eacategory > Guidance > ::: > > There are no additional Guidance evaluation activities for this > management function.\ > \ > > ::: eacategory Tests Tests ::: ::: ::: ea ::: ea Test [FMT_SMF_EXT.1](#FMT_SMF_EXT.1):16: The evaluator shall attempt to Test [FMT_SMF_EXT.1](#FMT_SMF_EXT.1):16: The evaluator shall attempt to install an application following the procedures in the AGD guidance and install an application following the procedures in the AGD guidance and verify that the application is installed and available on the verify that the application is installed and available on the [TOE](#abbr_TOE). [TOE](#abbr_TOE). ::: ::: \ \ ::: ::: ::: management_function_ea ::: management_function_ea **Function [17](#mf-entAppRemove)**\ **Function [17](#mf-entAppRemove)**\ ::: eacategory ::: eacategory > [TSS](#abbr_TSS) > ::: > > There are no additional [TSS](#abbr_TSS) evaluation activities for this > management function.\ > \ > > ::: eacategory > Guidance > ::: > > There are no additional Guidance evaluation activities for this > management function.\ > \ > > ::: eacategory Tests Tests ::: ::: ::: ea ::: ea Test [FMT_SMF_EXT.1](#FMT_SMF_EXT.1):17: The evaluator shall attempt to Test [FMT_SMF_EXT.1](#FMT_SMF_EXT.1):17: The evaluator shall attempt to remove any Enterprise applications from the device by following the remove any Enterprise applications from the device by following the administrator guidance. The evaluator shall verify that the administrator guidance. The evaluator shall verify that the [TOE](#abbr_TOE) no longer permits users to access those applications or [TOE](#abbr_TOE) no longer permits users to access those applications or their associated data. their associated data. ::: ::: \ \ ::: ::: ::: management_function_ea ::: management_function_ea **Function [18](#mf-notifications)**\ **Function [18](#mf-notifications)**\ ::: eacategory ::: eacategory > [TSS](#abbr_TSS) > ::: > > There are no additional [TSS](#abbr_TSS) evaluation activities for this > management function.\ > \ > > ::: eacategory Guidance Guidance ::: ::: ::: ea ::: ea The evaluator shall examine the AGD Guidance to determine that it The evaluator shall examine the AGD Guidance to determine that it specifies, for at least each category of information selected for specifies, for at least each category of information selected for Function [18](#mf-notifications), how to enable and disable display Function [18](#mf-notifications), how to enable and disable display information for that type of information in the locked state. information for that type of information in the locked state. ::: ::: ::: eacategory ::: eacategory Tests Tests ::: ::: ::: ea ::: ea Test [FMT_SMF_EXT.1](#FMT_SMF_EXT.1):18: For each category of Test [FMT_SMF_EXT.1](#FMT_SMF_EXT.1):18: For each category of information listed in the AGD guidance, the evaluator shall verify that information listed in the AGD guidance, the evaluator shall verify that when that [TSF](#abbr_TSF) is configured to limit the information when that [TSF](#abbr_TSF) is configured to limit the information according to the AGD, the information is no longer displayed in the according to the AGD, the information is no longer displayed in the locked state. locked state. ::: ::: \ \ ::: ::: ::: management_function_ea ::: management_function_ea **Function [19](#mf-dar)**\ **Function [19](#mf-dar)**\ ::: eacategory ::: eacategory > [TSS](#abbr_TSS) > ::: > > There are no additional [TSS](#abbr_TSS) evaluation activities for this > management function.\ > \ > > ::: eacategory > Guidance > ::: > > There are no additional Guidance evaluation activities for this > management function.\ > \ > > ::: eacategory Tests Tests ::: ::: ::: ea ::: ea Test [FMT_SMF_EXT.1](#FMT_SMF_EXT.1):19: The evaluator shall exercise Test [FMT_SMF_EXT.1](#FMT_SMF_EXT.1):19: The evaluator shall exercise the [TSF](#abbr_TSF) configuration as the administrator and, if not the [TSF](#abbr_TSF) configuration as the administrator and, if not restricted to the administrator, the user, to enable system-wide restricted to the administrator, the user, to enable system-wide data-at-rest protection according to the AGD guidance. The evaluator data-at-rest protection according to the AGD guidance. The evaluator shall ensure that all Evaluation Activities for [DAR](#abbr_DAR) shall ensure that all Evaluation Activities for [DAR](#abbr_DAR) protection (FDP_DAR_EXT) are conducted with the device in this protection (FDP_DAR_EXT) are conducted with the device in this configuration. configuration. ::: ::: \ \ ::: ::: ::: management_function_ea ::: management_function_ea **Function [20](#mf-rmediaDar)**\ **Function [20](#mf-rmediaDar)**\ ::: eacategory ::: eacategory > [TSS](#abbr_TSS) > ::: > > There are no additional [TSS](#abbr_TSS) evaluation activities for this > management function.\ > \ > > ::: eacategory > Guidance > ::: > > There are no additional Guidance evaluation activities for this > management function.\ > \ > > ::: eacategory Tests Tests ::: ::: ::: ea ::: ea Test [FMT_SMF_EXT.1](#FMT_SMF_EXT.1):20: The evaluator shall exercise Test [FMT_SMF_EXT.1](#FMT_SMF_EXT.1):20: The evaluator shall exercise the [TSF](#abbr_TSF) configuration as the administrator and, if not the [TSF](#abbr_TSF) configuration as the administrator and, if not restricted to the administrator, the user, to enable removable media's restricted to the administrator, the user, to enable removable media's data-at-rest protection according to the AGD guidance. The evaluator data-at-rest protection according to the AGD guidance. The evaluator shall ensure that all Evaluation Activities for [DAR](#abbr_DAR) shall ensure that all Evaluation Activities for [DAR](#abbr_DAR) protection (FDP_DAR_EXT) are conducted with the device in this protection (FDP_DAR_EXT) are conducted with the device in this configuration. configuration. ::: ::: \ \ ::: ::: ::: management_function_ea ::: management_function_ea **Function [21](#mf-location)**\ **Function [21](#mf-location)**\ ::: eacategory ::: eacategory > [TSS](#abbr_TSS) > ::: > > There are no additional [TSS](#abbr_TSS) evaluation activities for this > management function.\ > \ > > ::: eacategory > Guidance > ::: > > There are no additional Guidance evaluation activities for this > management function.\ > \ > > ::: eacategory Tests Tests ::: ::: ::: ea ::: ea The evaluator shall perform the following tests. The evaluator shall perform the following tests. - Test [FMT_SMF_EXT.1](#FMT_SMF_EXT.1):21a: The evaluator shall enable - Test [FMT_SMF_EXT.1](#FMT_SMF_EXT.1):21a: The evaluator shall enable location services device-wide and shall verify that an application location services device-wide and shall verify that an application (such as a mapping application) is able to access the (such as a mapping application) is able to access the [TOE](#abbr_TOE)'s location information. The evaluator shall disable [TOE](#abbr_TOE)'s location information. The evaluator shall disable location services device-wide and shall verify that an application location services device-wide and shall verify that an application (such as a mapping application) is unable to access the (such as a mapping application) is unable to access the [TOE](#abbr_TOE)'s location information. [TOE](#abbr_TOE)'s location information. - Test [FMT_SMF_EXT.1](#FMT_SMF_EXT.1):21b: \[conditional\] If [on a - Test [FMT_SMF_EXT.1](#FMT_SMF_EXT.1):21b: \[conditional\] If [on a per-app basis](#mf-location-per_app) is selected, the evaluator per-app basis](#mf-location-per_app) is selected, the evaluator shall create two applications and enable one to use access the shall create two applications and enable one to use access the location services and the other to not access the location services. location services and the other to not access the location services. The evaluator shall exercise each application attempting to access The evaluator shall exercise each application attempting to access location services individually. The evaluator shall verify that the location services individually. The evaluator shall verify that the enabled application is able to access the location services and the enabled application is able to access the location services and the disabled application is not able to access the location services. disabled application is not able to access the location services. ::: ::: \ \ ::: ::: ::: management_function_ea ::: management_function_ea **Function [22](#mf-authFactors) \[CONDITIONAL\]**\ **Function [22](#mf-authFactors) \[CONDITIONAL\]**\ ::: eacategory ::: eacategory > [TSS](#abbr_TSS) > ::: > > There are no additional [TSS](#abbr_TSS) evaluation activities for this > management function.\ > \ > > ::: eacategory > Guidance > ::: > > There are no additional Guidance evaluation activities for this > management function.\ > \ > > ::: eacategory Tests Tests ::: ::: ::: ea ::: ea The evaluator shall verify that the [TSS](#abbr_TSS) states if the The evaluator shall verify that the [TSS](#abbr_TSS) states if the [TOE](#abbr_TOE) supports a [BAF](#abbr_BAF) or hybrid authentication. [TOE](#abbr_TOE) supports a [BAF](#abbr_BAF) or hybrid authentication. If the [TOE](#abbr_TOE) does not include a [BAF](#abbr_BAF) or hybrid If the [TOE](#abbr_TOE) does not include a [BAF](#abbr_BAF) or hybrid authentication this test is implicitly met. authentication this test is implicitly met. - Test [FMT_SMF_EXT.1](#FMT_SMF_EXT.1):22a: \[conditional\] If - Test [FMT_SMF_EXT.1](#FMT_SMF_EXT.1):22a: \[conditional\] If [biometric in accordance with the](#uau_biometric) [cPP-Module for [biometric in accordance with the](#uau_biometric) [cPP-Module for Biometric Enrollment and Verification, version Biometric Enrollment and Verification, version 2.0](https://github.com/biometricITC/cPP-biometrics/blob/master/Protection%20Prof 2.0](https://github.com/biometricITC/cPP-biometrics/blob/master/Protection%20Prof is selected in [FIA_UAU.5.1](#FIA_UAU.5.1), for each is selected in [FIA_UAU.5.1](#FIA_UAU.5.1), for each [BAF](#abbr_BAF) claimed in FIA_MBV_EXT.1.1 in the [cPP-Module for [BAF](#abbr_BAF) claimed in FIA_MBV_EXT.1.1 in the [cPP-Module for Biometric Enrollment and Verification, version Biometric Enrollment and Verification, version 2.0](https://github.com/biometricITC/cPP-biometrics/blob/master/Protection%20Prof 2.0](https://github.com/biometricITC/cPP-biometrics/blob/master/Protection%20Prof the evaluator shall verify that the [TSS](#abbr_TSS) describes the the evaluator shall verify that the [TSS](#abbr_TSS) describes the procedure to enable/disable the [BAF](#abbr_BAF). The evaluator procedure to enable/disable the [BAF](#abbr_BAF). The evaluator shall configure the [TOE](#abbr_TOE) to allow each supported shall configure the [TOE](#abbr_TOE) to allow each supported [BAF](#abbr_BAF) to authenticate and verify that successful [BAF](#abbr_BAF) to authenticate and verify that successful authentication can be achieved using the [BAF](#abbr_BAF). The authentication can be achieved using the [BAF](#abbr_BAF). The evaluator shall configure the [TOE](#abbr_TOE) to disable the use of evaluator shall configure the [TOE](#abbr_TOE) to disable the use of each supported [BAF](#abbr_BAF) for authentication and confirm that each supported [BAF](#abbr_BAF) for authentication and confirm that the [BAF](#abbr_BAF) cannot be used to authenticate. the [BAF](#abbr_BAF) cannot be used to authenticate. - Test [FMT_SMF_EXT.1](#FMT_SMF_EXT.1):22b: \[conditional\] If - Test [FMT_SMF_EXT.1](#FMT_SMF_EXT.1):22b: \[conditional\] If [hybrid](#uau_hybr) is selected the evaluator shall verify that the [hybrid](#uau_hybr) is selected the evaluator shall verify that the [TSS](#abbr_TSS) describes the procedure to enable/disable the [TSS](#abbr_TSS) describes the procedure to enable/disable the hybrid (biometric credential and PIN/password) authentication. The hybrid (biometric credential and PIN/password) authentication. The evaluator shall configure the [TOE](#abbr_TOE) to allow hybrid evaluator shall configure the [TOE](#abbr_TOE) to allow hybrid authentication to authenticate and confirm that successful authentication to authenticate and confirm that successful authentication can be achieved using the hybrid authentication. The authentication can be achieved using the hybrid authentication. The evaluator shall configure the [TOE](#abbr_TOE) to disable the use of evaluator shall configure the [TOE](#abbr_TOE) to disable the use of hybrid authentication and confirm that the hybrid authentication hybrid authentication and confirm that the hybrid authentication cannot be used to authenticate. cannot be used to authenticate. ::: ::: \ \ ::: ::: ::: management_function_ea ::: management_function_ea **Function [23](#mf-certInvalid) \[CONDITIONAL\]**\ **Function [23](#mf-certInvalid) \[CONDITIONAL\]**\ ::: eacategory ::: eacategory > [TSS](#abbr_TSS) > ::: > > There are no additional [TSS](#abbr_TSS) evaluation activities for this > management function.\ > \ > > ::: eacategory > Guidance > ::: > > There are no additional Guidance evaluation activities for this > management function.\ > \ > > ::: eacategory Tests Tests ::: ::: ::: ea ::: ea The test of this function is performed in conjunction with The test of this function is performed in conjunction with FIA_X509_EXT.2.2 in [Functional Package for X.509, version FIA_X509_EXT.2.2 in [Functional Package for X.509, version 1.0](https://www.niap-ccevs.org/protectionprofiles/511) and 1.0](https://www.niap-ccevs.org/protectionprofiles/511) and FCS_TLSC_EXT.1.6 in the [Functional Package for Transport Layer Security FCS_TLSC_EXT.1.6 in the [Functional Package for Transport Layer Security (TLS), version (TLS), version 2.1](https://www.niap-ccevs.org/static_html/protection-profile/519). 2.1](https://www.niap-ccevs.org/static_html/protection-profile/519). ::: ::: \ \ ::: ::: ::: management_function_ea ::: management_function_ea **Function [24](#mf-externalPorts) \[CONDITIONAL\]**\ **Function [24](#mf-externalPorts) \[CONDITIONAL\]**\ ::: eacategory ::: eacategory [TSS](#abbr_TSS) [TSS](#abbr_TSS) ::: ::: ::: ea ::: ea The evaluator shall verify that the [TSS](#abbr_TSS) includes a list of The evaluator shall verify that the [TSS](#abbr_TSS) includes a list of each externally accessible hardware port and an indication of if data each externally accessible hardware port and an indication of if data transfer over that port can be enabled/disabled. AGD guidance will transfer over that port can be enabled/disabled. AGD guidance will describe how to perform the enable/disable function. describe how to perform the enable/disable function. ::: ::: ::: eacategory ::: eacategory > Guidance > ::: > > There are no additional Guidance evaluation activities for this > management function.\ > \ > > ::: eacategory Tests Tests ::: ::: ::: ea ::: ea Test [FMT_SMF_EXT.1](#FMT_SMF_EXT.1):24: The evaluator shall exercise Test [FMT_SMF_EXT.1](#FMT_SMF_EXT.1):24: The evaluator shall exercise the [TSF](#abbr_TSF) configuration to enable and disable data transfer the [TSF](#abbr_TSF) configuration to enable and disable data transfer capabilities over each externally accessible hardware ports (e.g. capabilities over each externally accessible hardware ports (e.g. [USB](#abbr_USB), SD card, [HDMI](#abbr_HDMI)) listed by the [USB](#abbr_USB), SD card, [HDMI](#abbr_HDMI)) listed by the [ST](#abbr_ST) author. The evaluator shall use test equipment for the [ST](#abbr_ST) author. The evaluator shall use test equipment for the particular interface to ensure that while the [TOE](#abbr_TOE) may particular interface to ensure that while the [TOE](#abbr_TOE) may continue to receive data on the RX pins, it is not responding on TX pins continue to receive data on the RX pins, it is not responding on TX pins used for data transfer when they are disabled. For each disabled data used for data transfer when they are disabled. For each disabled data transfer capability, the evaluator shall repeat this test by rebooting transfer capability, the evaluator shall repeat this test by rebooting the device into the normal operational mode and verifying that the the device into the normal operational mode and verifying that the capability is disabled throughout the boot and early execution stage of capability is disabled throughout the boot and early execution stage of the device. the device. ::: ::: \ \ ::: ::: ::: management_function_ea ::: management_function_ea **Function [25](#mf-serverProtocols) \[CONDITIONAL\]**\ **Function [25](#mf-serverProtocols) \[CONDITIONAL\]**\ ::: eacategory ::: eacategory [TSS](#abbr_TSS) [TSS](#abbr_TSS) ::: ::: ::: ea ::: ea The evaluator shall verify that the [TSS](#abbr_TSS) describes how the The evaluator shall verify that the [TSS](#abbr_TSS) describes how the [TSF](#abbr_TSF) acts as a server in each of the protocols listed in the [TSF](#abbr_TSF) acts as a server in each of the protocols listed in the [ST](#abbr_ST), and the reason for acting as a server. [ST](#abbr_ST), and the reason for acting as a server. ::: ::: ::: eacategory ::: eacategory > Guidance > ::: > > There are no additional Guidance evaluation activities for this > management function.\ > \ > > ::: eacategory Tests Tests ::: ::: ::: ea ::: ea Test [FMT_SMF_EXT.1](#FMT_SMF_EXT.1):25: The evaluator shall attempt to Test [FMT_SMF_EXT.1](#FMT_SMF_EXT.1):25: The evaluator shall attempt to disable each listed protocol in the assignment. The evaluator shall disable each listed protocol in the assignment. The evaluator shall verify that remote devices can no longer access the [TOE](#abbr_TOE) or verify that remote devices can no longer access the [TOE](#abbr_TOE) or [TOE](#abbr_TOE) resources using any disabled protocols. [TOE](#abbr_TOE) resources using any disabled protocols. ::: ::: \ \ ::: ::: ::: management_function_ea ::: management_function_ea **Function [26](#mf-devModes) \[CONDITIONAL\]**\ **Function [26](#mf-devModes) \[CONDITIONAL\]**\ ::: eacategory ::: eacategory > [TSS](#abbr_TSS) > ::: > > There are no additional [TSS](#abbr_TSS) evaluation activities for this > management function.\ > \ > > ::: eacategory > Guidance > ::: > > There are no additional Guidance evaluation activities for this > management function.\ > \ > > ::: eacategory Tests Tests ::: ::: ::: ea ::: ea Test [FMT_SMF_EXT.1](#FMT_SMF_EXT.1):26: The evaluator shall exercise Test [FMT_SMF_EXT.1](#FMT_SMF_EXT.1):26: The evaluator shall exercise the [TSF](#abbr_TSF) configuration as the administrator and, if not the [TSF](#abbr_TSF) configuration as the administrator and, if not restricted to the administrator, the user, to enable and disable any restricted to the administrator, the user, to enable and disable any developer mode. The evaluator shall test that developer mode access is developer mode. The evaluator shall test that developer mode access is not available when its configuration is disabled. The evaluator shall not available when its configuration is disabled. The evaluator shall verify the developer mode remains disabled during device reboot. verify the developer mode remains disabled during device reboot. ::: ::: \ \ ::: ::: ::: management_function_ea ::: management_function_ea **Function [27](#mf-authBypass) \[CONDITIONAL\]**\ **Function [27](#mf-authBypass) \[CONDITIONAL\]**\ ::: eacategory ::: eacategory > [TSS](#abbr_TSS) > ::: > > There are no additional [TSS](#abbr_TSS) evaluation activities for this > management function.\ > \ > > ::: eacategory Guidance Guidance ::: ::: ::: ea ::: ea The evaluator shall examine the AGD guidance to determine that it The evaluator shall examine the AGD guidance to determine that it describes how to enable and disable any \"Forgot Password\", password describes how to enable and disable any \"Forgot Password\", password hint, or remote authentication (to bypass local authentication hint, or remote authentication (to bypass local authentication mechanisms) capability. mechanisms) capability. ::: ::: ::: eacategory ::: eacategory Tests Tests ::: ::: ::: ea ::: ea Test [FMT_SMF_EXT.1](#FMT_SMF_EXT.1):27: For each mechanism listed in Test [FMT_SMF_EXT.1](#FMT_SMF_EXT.1):27: For each mechanism listed in the AGD guidance that provides a \"Forgot Password\" feature or other the AGD guidance that provides a \"Forgot Password\" feature or other means where the local authentication process can be bypassed, the means where the local authentication process can be bypassed, the evaluator shall disable the feature and ensure that they are not able to evaluator shall disable the feature and ensure that they are not able to bypass the local authentication process. bypass the local authentication process. ::: ::: \ \ ::: ::: ::: management_function_ea ::: management_function_ea **Function [28](#mf-wipeEntData) \[CONDITIONAL\]**\ **Function [28](#mf-wipeEntData) \[CONDITIONAL\]**\ ::: eacategory ::: eacategory > [TSS](#abbr_TSS) > ::: > > There are no additional [TSS](#abbr_TSS) evaluation activities for this > management function.\ > \ > > ::: eacategory > Guidance > ::: > > There are no additional Guidance evaluation activities for this > management function.\ > \ > > ::: eacategory Tests Tests ::: ::: ::: ea ::: ea Test [FMT_SMF_EXT.1](#FMT_SMF_EXT.1):28: The evaluator shall attempt to Test [FMT_SMF_EXT.1](#FMT_SMF_EXT.1):28: The evaluator shall attempt to wipe Enterprise data resident on the device according to the wipe Enterprise data resident on the device according to the administrator guidance. The evaluator shall verify that the data is no administrator guidance. The evaluator shall verify that the data is no longer accessible by the user. longer accessible by the user. ::: ::: \ \ ::: ::: ::: management_function_ea ::: management_function_ea **Function [29](#mf-appCert) \[CONDITIONAL\]**\ **Function [29](#mf-appCert) \[CONDITIONAL\]**\ ::: eacategory ::: eacategory [TSS](#abbr_TSS) [TSS](#abbr_TSS) ::: ::: ::: ea ::: ea The evaluator shall verify that the [TSS](#abbr_TSS) describes how The evaluator shall verify that the [TSS](#abbr_TSS) describes how approval for an application to perform the selected action (import, approval for an application to perform the selected action (import, removal) with respect to certificates in the Trust Anchor Database is removal) with respect to certificates in the Trust Anchor Database is accomplished (e.g., a pop-up, policy setting, etc.).\ accomplished (e.g., a pop-up, policy setting, etc.).\ \ \ The evaluator shall also verify that the [API](#abbr_API) documentation The evaluator shall also verify that the [API](#abbr_API) documentation provided in the [TSS](#abbr_TSS) (or other documentation) includes any provided in the [TSS](#abbr_TSS) (or other documentation) includes any security functions (import, modification, or destruction of the Trust security functions (import, modification, or destruction of the Trust Anchor Database) allowed by applications. Anchor Database) allowed by applications. ::: ::: ::: eacategory ::: eacategory > Guidance > ::: > > There are no additional Guidance evaluation activities for this > management function.\ > \ > > ::: eacategory Tests Tests ::: ::: ::: ea ::: ea The evaluator shall perform one of the following tests: The evaluator shall perform one of the following tests: - Test [FMT_SMF_EXT.1](#FMT_SMF_EXT.1):29a: \[conditional\] If - Test [FMT_SMF_EXT.1](#FMT_SMF_EXT.1):29a: \[conditional\] If applications may import certificates to the Trust Anchor Database, applications may import certificates to the Trust Anchor Database, the evaluator shall write, or the developer shall provide access to, the evaluator shall write, or the developer shall provide access to, an application that imports a certificate into the Trust Anchor an application that imports a certificate into the Trust Anchor Database. The evaluator shall verify that the [TOE](#abbr_TOE) Database. The evaluator shall verify that the [TOE](#abbr_TOE) requires approval before allowing the application to import the requires approval before allowing the application to import the certificate: certificate: - The evaluator shall deny the approvals to verify that the - The evaluator shall deny the approvals to verify that the application is not able to import the certificate. Failure of application is not able to import the certificate. Failure of import shall be tested by attempting to validate a certificate import shall be tested by attempting to validate a certificate that chains to the certificate whose import was attempted (as that chains to the certificate whose import was attempted (as described in the evaluation activity for FIA_X509_EXT.1 as described in the evaluation activity for FIA_X509_EXT.1 as defined in the [Functional Package for X.509, version defined in the [Functional Package for X.509, version 1.0](https://www.niap-ccevs.org/protectionprofiles/511)). 1.0](https://www.niap-ccevs.org/protectionprofiles/511)). - The evaluator shall repeat the test, allowing the approval to - The evaluator shall repeat the test, allowing the approval to verify that the application is able to import the certificate verify that the application is able to import the certificate and that validation occurs. and that validation occurs. - Test [FMT_SMF_EXT.1](#FMT_SMF_EXT.1):29b: \[conditional\] If - Test [FMT_SMF_EXT.1](#FMT_SMF_EXT.1):29b: \[conditional\] If applications may remove certificates in the Trust Anchor Database, applications may remove certificates in the Trust Anchor Database, the evaluator shall write, or the developer shall provide access to, the evaluator shall write, or the developer shall provide access to, an application that removes certificates from the Trust Anchor an application that removes certificates from the Trust Anchor Database. The evaluator shall verify that the [TOE](#abbr_TOE) Database. The evaluator shall verify that the [TOE](#abbr_TOE) requires approval before allowing the application to remove the requires approval before allowing the application to remove the certificate: certificate: - The evaluator shall deny the approvals to verify that the - The evaluator shall deny the approvals to verify that the application is not able to remove the certificate. Failure of application is not able to remove the certificate. Failure of removal shall be tested by attempting to validate a certificate removal shall be tested by attempting to validate a certificate that chains to the certificate whose removal was attempted (as that chains to the certificate whose removal was attempted (as described in the evaluation activity for FIA_X509_EXT.1 as described in the evaluation activity for FIA_X509_EXT.1 as defined in the [Functional Package for X.509, version defined in the [Functional Package for X.509, version 1.0](https://www.niap-ccevs.org/protectionprofiles/511)). 1.0](https://www.niap-ccevs.org/protectionprofiles/511)). The evaluator shall repeat the test, allowing the approval to The evaluator shall repeat the test, allowing the approval to verify that the application is able to remove/modify the verify that the application is able to remove/modify the certificate and that validation no longer occurs. certificate and that validation no longer occurs. ::: ::: \ \ ::: ::: ::: management_function_ea ::: management_function_ea **Function [30](#mf-certValidity) \[CONDITIONAL\]**\ **Function [30](#mf-certValidity) \[CONDITIONAL\]**\ ::: eacategory ::: eacategory > [TSS](#abbr_TSS) > ::: > > There are no additional [TSS](#abbr_TSS) evaluation activities for this > management function.\ > \ > > ::: eacategory > Guidance > ::: > > There are no additional Guidance evaluation activities for this > management function.\ > \ > > ::: eacategory Tests Tests ::: ::: ::: ea ::: ea The test of this function is performed in conjunction with The test of this function is performed in conjunction with FIA_X509_EXT.2.2 in [Functional Package for X.509, version FIA_X509_EXT.2.2 in [Functional Package for X.509, version 1.0](https://www.niap-ccevs.org/protectionprofiles/511). 1.0](https://www.niap-ccevs.org/protectionprofiles/511). ::: ::: \ \ ::: ::: ::: management_function_ea ::: management_function_ea **Function [31](#mf-cellular) \[CONDITIONAL\]**\ **Function [31](#mf-cellular) \[CONDITIONAL\]**\ ::: eacategory ::: eacategory [TSS](#abbr_TSS) [TSS](#abbr_TSS) ::: ::: ::: ea ::: ea The evaluator shall ensure that the [TSS](#abbr_TSS) describes which The evaluator shall ensure that the [TSS](#abbr_TSS) describes which cellular protocols can be disabled. cellular protocols can be disabled. ::: ::: ::: eacategory ::: eacategory Guidance Guidance ::: ::: ::: ea ::: ea The evaluator shall confirm that the AGD guidance describes the The evaluator shall confirm that the AGD guidance describes the procedure for disabling each cellular protocol identified in the procedure for disabling each cellular protocol identified in the [TSS](#abbr_TSS). [TSS](#abbr_TSS). ::: ::: ::: eacategory ::: eacategory Tests Tests ::: ::: ::: ea ::: ea Test [FMT_SMF_EXT.1](#FMT_SMF_EXT.1):31: The evaluator shall attempt to Test [FMT_SMF_EXT.1](#FMT_SMF_EXT.1):31: The evaluator shall attempt to disable each cellular protocol according to the administrator guidance. disable each cellular protocol according to the administrator guidance. The evaluator shall attempt to connect the device to a cellular network The evaluator shall attempt to connect the device to a cellular network and, using network analysis tools, verify that the device does not allow and, using network analysis tools, verify that the device does not allow negotiation of the disabled protocols. negotiation of the disabled protocols. ::: ::: \ \ ::: ::: ::: management_function_ea ::: management_function_ea **Function [32](#mf-auditLogs)**\ **Function [32](#mf-auditLogs)**\ ::: eacategory ::: eacategory > [TSS](#abbr_TSS) > ::: > > There are no additional [TSS](#abbr_TSS) evaluation activities for this > management function.\ > \ > > ::: eacategory > Guidance > ::: > > There are no additional Guidance evaluation activities for this > management function.\ > \ > > ::: eacategory Tests Tests ::: ::: ::: ea ::: ea Test [FMT_SMF_EXT.1](#FMT_SMF_EXT.1):32: The evaluator shall attempt to Test [FMT_SMF_EXT.1](#FMT_SMF_EXT.1):32: The evaluator shall attempt to read any device audit logs according to the administrator guidance and read any device audit logs according to the administrator guidance and verify that the logs may be read. This test may be performed in verify that the logs may be read. This test may be performed in conjunction with the evaluation activity of [FAU_GEN.1](#FAU_GEN.1). conjunction with the evaluation activity of [FAU_GEN.1](#FAU_GEN.1). ::: ::: \ \ ::: ::: ::: management_function_ea ::: management_function_ea **Function [33](#mf-digSign) \[CONDITIONAL\]**\ **Function [33](#mf-digSign) \[CONDITIONAL\]**\ ::: eacategory ::: eacategory > [TSS](#abbr_TSS) > ::: > > There are no additional [TSS](#abbr_TSS) evaluation activities for this > management function.\ > \ > > ::: eacategory > Guidance > ::: > > There are no additional Guidance evaluation activities for this > management function.\ > \ > > ::: eacategory Tests Tests ::: ::: ::: ea ::: ea The test of this function is performed in conjunction with The test of this function is performed in conjunction with [FPT_TUD_EXT.5.1](#FPT_TUD_EXT.5.1). [FPT_TUD_EXT.5.1](#FPT_TUD_EXT.5.1). ::: ::: \ \ ::: ::: ::: management_function_ea ::: management_function_ea **Function [34](#mf-sharedKeys) \[CONDITIONAL\]**\ **Function [34](#mf-sharedKeys) \[CONDITIONAL\]**\ ::: eacategory ::: eacategory [TSS](#abbr_TSS) [TSS](#abbr_TSS) ::: ::: ::: ea ::: ea The evaluator shall verify that the [TSS](#abbr_TSS) describes how the The evaluator shall verify that the [TSS](#abbr_TSS) describes how the approval for exceptions for shared use of keys or secrets by multiple approval for exceptions for shared use of keys or secrets by multiple applications is accomplished (e.g., a pop-up, policy setting, etc.). applications is accomplished (e.g., a pop-up, policy setting, etc.). ::: ::: ::: eacategory ::: eacategory > Guidance > ::: > > There are no additional Guidance evaluation activities for this > management function.\ > \ > > ::: eacategory Tests Tests ::: ::: ::: ea ::: ea The test of this function is performed in conjunction with The test of this function is performed in conjunction with [FCS_STG_EXT.1](#FCS_STG_EXT.1). [FCS_STG_EXT.1](#FCS_STG_EXT.1). ::: ::: \ \ ::: ::: ::: management_function_ea ::: management_function_ea **Function [35](#mf-keyWipeRules) \[CONDITIONAL\]**\ **Function [35](#mf-keyWipeRules) \[CONDITIONAL\]**\ ::: eacategory ::: eacategory [TSS](#abbr_TSS) [TSS](#abbr_TSS) ::: ::: ::: ea ::: ea The evaluator shall verify that the [TSS](#abbr_TSS) describes how the The evaluator shall verify that the [TSS](#abbr_TSS) describes how the approval for exceptions for destruction of keys or secrets by approval for exceptions for destruction of keys or secrets by applications that did not import the key or secret is accomplished applications that did not import the key or secret is accomplished (e.g., a pop-up, policy setting, etc.). (e.g., a pop-up, policy setting, etc.). ::: ::: ::: eacategory ::: eacategory > Guidance > ::: > > There are no additional Guidance evaluation activities for this > management function.\ > \ > > ::: eacategory Tests Tests ::: ::: ::: ea ::: ea The test of this function is performed in conjunction with The test of this function is performed in conjunction with [FCS_STG_EXT.1](#FCS_STG_EXT.1). [FCS_STG_EXT.1](#FCS_STG_EXT.1). ::: ::: \ \ ::: ::: ::: management_function_ea ::: management_function_ea **Function [36](#mf-unlockBanner)**\ **Function [36](#mf-unlockBanner)**\ ::: eacategory ::: eacategory [TSS](#abbr_TSS) [TSS](#abbr_TSS) ::: ::: ::: ea ::: ea The evaluator shall verify that the [TSS](#abbr_TSS) describes any The evaluator shall verify that the [TSS](#abbr_TSS) describes any restrictions in banner settings (e.g., character limitations). restrictions in banner settings (e.g., character limitations). ::: ::: ::: eacategory ::: eacategory > Guidance > ::: > > There are no additional Guidance evaluation activities for this > management function.\ > \ > > ::: eacategory Tests Tests ::: ::: ::: ea ::: ea The test of this function is performed in conjunction with The test of this function is performed in conjunction with [FTA_TAB.1](#FTA_TAB.1). [FTA_TAB.1](#FTA_TAB.1). ::: ::: \ \ ::: ::: ::: management_function_ea ::: management_function_ea **Function [37](#mf-auditItems) \[CONDITIONAL\]**\ **Function [37](#mf-auditItems) \[CONDITIONAL\]**\ ::: eacategory ::: eacategory > [TSS](#abbr_TSS) > ::: > > There are no additional [TSS](#abbr_TSS) evaluation activities for this > management function.\ > \ > > ::: eacategory > Guidance > ::: > > There are no additional Guidance evaluation activities for this > management function.\ > \ > > ::: eacategory Tests Tests ::: ::: ::: ea ::: ea The test of this function is performed in conjunction with The test of this function is performed in conjunction with [FAU_SEL.1](#FAU_SEL.1). [FAU_SEL.1](#FAU_SEL.1). ::: ::: \ \ ::: ::: ::: management_function_ea ::: management_function_ea **Function [38](#mf-integ) \[CONDITIONAL\]**\ **Function [38](#mf-integ) \[CONDITIONAL\]**\ ::: eacategory ::: eacategory > [TSS](#abbr_TSS) > ::: > > There are no additional [TSS](#abbr_TSS) evaluation activities for this > management function.\ > \ > > ::: eacategory > Guidance > ::: > > There are no additional Guidance evaluation activities for this > management function.\ > \ > > ::: eacategory Tests Tests ::: ::: ::: ea ::: ea The test of this function is performed in conjunction with The test of this function is performed in conjunction with [FPT_NOT_EXT.2.1](#FPT_NOT_EXT.2.1). [FPT_NOT_EXT.2.1](#FPT_NOT_EXT.2.1). ::: ::: \ \ ::: ::: ::: management_function_ea ::: management_function_ea **Function [39](#mf-USB) \[CONDITIONAL\]**\ **Function [39](#mf-USB) \[CONDITIONAL\]**\ ::: eacategory ::: eacategory [TSS](#abbr_TSS) [TSS](#abbr_TSS) ::: ::: ::: ea ::: ea The evaluator shall verify that the [TSS](#abbr_TSS) includes a The evaluator shall verify that the [TSS](#abbr_TSS) includes a description of how data transfers can be managed over [USB](#abbr_USB). description of how data transfers can be managed over [USB](#abbr_USB). ::: ::: ::: eacategory ::: eacategory > Guidance > ::: > > There are no additional Guidance evaluation activities for this > management function.\ > \ > > ::: eacategory Tests Tests ::: ::: ::: ea ::: ea The evaluator shall perform the following tests based on the selections The evaluator shall perform the following tests based on the selections made: made: - Test [FMT_SMF_EXT.1](#FMT_SMF_EXT.1):39a: \[conditional\] The - Test [FMT_SMF_EXT.1](#FMT_SMF_EXT.1):39a: \[conditional\] The evaluator shall disable [USB](#abbr_USB) mass storage mode, attach evaluator shall disable [USB](#abbr_USB) mass storage mode, attach the device to a computer, and verify that the computer cannot mount the device to a computer, and verify that the computer cannot mount the [TOE](#abbr_TOE) as a drive. The evaluator shall reboot the the [TOE](#abbr_TOE) as a drive. The evaluator shall reboot the [TOE](#abbr_TOE) and repeat this test with other supported auxiliary [TOE](#abbr_TOE) and repeat this test with other supported auxiliary boot modes. boot modes. - Test [FMT_SMF_EXT.1](#FMT_SMF_EXT.1):39b: \[conditional\] The - Test [FMT_SMF_EXT.1](#FMT_SMF_EXT.1):39b: \[conditional\] The evaluator shall disable [USB](#abbr_USB) data transfer without user evaluator shall disable [USB](#abbr_USB) data transfer without user authentication, attach the device to a computer, and verify that the authentication, attach the device to a computer, and verify that the [TOE](#abbr_TOE) requires user authentication before the computer [TOE](#abbr_TOE) requires user authentication before the computer can access [TOE](#abbr_TOE) data. The evaluator shall reboot the can access [TOE](#abbr_TOE) data. The evaluator shall reboot the [TOE](#abbr_TOE) and repeat this test with other supported auxiliary [TOE](#abbr_TOE) and repeat this test with other supported auxiliary boot modes. boot modes. - Test [FMT_SMF_EXT.1](#FMT_SMF_EXT.1):39c: \[conditional\] The - Test [FMT_SMF_EXT.1](#FMT_SMF_EXT.1):39c: \[conditional\] The evaluator shall disable [USB](#abbr_USB) data transfer without evaluator shall disable [USB](#abbr_USB) data transfer without connecting system authentication, attach the device to a computer, connecting system authentication, attach the device to a computer, and verify that the [TOE](#abbr_TOE) requires connecting system and verify that the [TOE](#abbr_TOE) requires connecting system authentication before the computer can access [TOE](#abbr_TOE) data. authentication before the computer can access [TOE](#abbr_TOE) data. The evaluator shall then connect the [TOE](#abbr_TOE) to another The evaluator shall then connect the [TOE](#abbr_TOE) to another computer and verify that the computer cannot access [TOE](#abbr_TOE) computer and verify that the computer cannot access [TOE](#abbr_TOE) data. The evaluator shall then connect the [TOE](#abbr_TOE) to the data. The evaluator shall then connect the [TOE](#abbr_TOE) to the original computer and verify that the computer can access original computer and verify that the computer can access [TOE](#abbr_TOE) data. [TOE](#abbr_TOE) data. ::: ::: \ \ ::: ::: ::: management_function_ea ::: management_function_ea **Function [40](#mf-backup) \[CONDITIONAL\]**\ **Function [40](#mf-backup) \[CONDITIONAL\]**\ ::: eacategory ::: eacategory [TSS](#abbr_TSS) [TSS](#abbr_TSS) ::: ::: ::: ea ::: ea The evaluator shall verify that the [TSS](#abbr_TSS) includes a The evaluator shall verify that the [TSS](#abbr_TSS) includes a description of available backup methods that can be enabled/disabled. If description of available backup methods that can be enabled/disabled. If \"selected applications\" or \"selected groups of applications\" are \"selected applications\" or \"selected groups of applications\" are selected the [TSS](#abbr_TSS) shall include which applications of groups selected the [TSS](#abbr_TSS) shall include which applications of groups of applications backup can be enabled/disabled. of applications backup can be enabled/disabled. ::: ::: ::: eacategory ::: eacategory > Guidance > ::: > > There are no additional Guidance evaluation activities for this > management function.\ > \ > > ::: eacategory Tests Tests ::: ::: ::: ea ::: ea - Test [FMT_SMF_EXT.1](#FMT_SMF_EXT.1):40a: \[conditional\] If [all - Test [FMT_SMF_EXT.1](#FMT_SMF_EXT.1):40a: \[conditional\] If [all applications](#s-backup-all-apps) is selected, the evaluator shall applications](#s-backup-all-apps) is selected, the evaluator shall disable each selected backup location in turn and verify that the disable each selected backup location in turn and verify that the [TOE](#abbr_TOE) cannot complete a backup. The evaluator shall then [TOE](#abbr_TOE) cannot complete a backup. The evaluator shall then enable each selected backup location in turn and verify that the enable each selected backup location in turn and verify that the [TOE](#abbr_TOE) can perform a backup. [TOE](#abbr_TOE) can perform a backup. - Test [FMT_SMF_EXT.1](#FMT_SMF_EXT.1):40b: \[conditional\] If - Test [FMT_SMF_EXT.1](#FMT_SMF_EXT.1):40b: \[conditional\] If [selected applications](#s-backup-sel-apps) is selected, the [selected applications](#s-backup-sel-apps) is selected, the evaluator shall disable each selected backup location in turn and evaluator shall disable each selected backup location in turn and verify that for the selected application the [TOE](#abbr_TOE) verify that for the selected application the [TOE](#abbr_TOE) prevents backup from occurring. The evaluator shall then enable each prevents backup from occurring. The evaluator shall then enable each selected backup location in turn and verify that for the selected selected backup location in turn and verify that for the selected application the [TOE](#abbr_TOE) can perform a backup. application the [TOE](#abbr_TOE) can perform a backup. - Test [FMT_SMF_EXT.1](#FMT_SMF_EXT.1):40c: \[conditional\] If - Test [FMT_SMF_EXT.1](#FMT_SMF_EXT.1):40c: \[conditional\] If [selected groups of applications](#s-backup-sel-grps) is selected, [selected groups of applications](#s-backup-sel-grps) is selected, the evaluator shall disable each selected backup location in turn the evaluator shall disable each selected backup location in turn and verify that for a group of applications the [TOE](#abbr_TOE) and verify that for a group of applications the [TOE](#abbr_TOE) prevents the backup from occurring. The evaluator shall then enable prevents the backup from occurring. The evaluator shall then enable each selected backup location in turn and verify for the group of each selected backup location in turn and verify for the group of application the [TOE](#abbr_TOE) can perform a backup. application the [TOE](#abbr_TOE) can perform a backup. - Test [FMT_SMF_EXT.1](#FMT_SMF_EXT.1):40d: \[conditional\] If - Test [FMT_SMF_EXT.1](#FMT_SMF_EXT.1):40d: \[conditional\] If [configuration data](#s-backup-cfg) is selected, the evaluator shall [configuration data](#s-backup-cfg) is selected, the evaluator shall disable each selected backup location in turn and verify that the disable each selected backup location in turn and verify that the [TOE](#abbr_TOE) prevents the backup of configuration data from [TOE](#abbr_TOE) prevents the backup of configuration data from occurring. The evaluator shall then enable each selected backup occurring. The evaluator shall then enable each selected backup location in turn and verify that the [TOE](#abbr_TOE) can perform a location in turn and verify that the [TOE](#abbr_TOE) can perform a backup of configuration data. backup of configuration data. ::: ::: \ \ ::: ::: ::: management_function_ea ::: management_function_ea **Function [41](#mf-hotspot) \[CONDITIONAL\]**\ **Function [41](#mf-hotspot) \[CONDITIONAL\]**\ ::: eacategory ::: eacategory [TSS](#abbr_TSS) [TSS](#abbr_TSS) ::: ::: ::: ea ::: ea The evaluator shall verify that the [TSS](#abbr_TSS) includes a The evaluator shall verify that the [TSS](#abbr_TSS) includes a description of Bluetooth or [USB](#abbr_USB) tethering functionality as description of Bluetooth or [USB](#abbr_USB) tethering functionality as claimed in the function. If [USB](#abbr_USB) tethering is supported, the claimed in the function. If [USB](#abbr_USB) tethering is supported, the evaluator shall verify that it includes the method used for evaluator shall verify that it includes the method used for authentication [USB](#abbr_USB) connections. authentication [USB](#abbr_USB) connections. ::: ::: ::: eacategory ::: eacategory > Guidance > ::: > > There are no additional Guidance evaluation activities for this > management function.\ > \ > > ::: eacategory Tests Tests ::: ::: ::: ea ::: ea The evaluator shall perform the following tests based on the selections The evaluator shall perform the following tests based on the selections in Function [41](#mf-hotspot). in Function [41](#mf-hotspot). - Test [FMT_SMF_EXT.1](#FMT_SMF_EXT.1):41a: \[conditional\] The - Test [FMT_SMF_EXT.1](#FMT_SMF_EXT.1):41a: \[conditional\] The evaluator shall enable Bluetooth tethering functionality. The evaluator shall enable Bluetooth tethering functionality. The evaluator shall use a Bluetooth device to connect to the evaluator shall use a Bluetooth device to connect to the [TOE](#abbr_TOE) and verify that tethering functionality is [TOE](#abbr_TOE) and verify that tethering functionality is implemented. The evaluator shall disable Bluetooth tethering implemented. The evaluator shall disable Bluetooth tethering functionality and verify that the function has been disabled. functionality and verify that the function has been disabled. - Test [FMT_SMF_EXT.1](#FMT_SMF_EXT.1):41b: \[conditional\] The - Test [FMT_SMF_EXT.1](#FMT_SMF_EXT.1):41b: \[conditional\] The evaluator shall enable [USB](#abbr_USB) tethering functionality with evaluator shall enable [USB](#abbr_USB) tethering functionality with each of supported authentication methods. The evaluator shall each of supported authentication methods. The evaluator shall connect to the [TOE](#abbr_TOE) over [USB](#abbr_USB) with another connect to the [TOE](#abbr_TOE) over [USB](#abbr_USB) with another device and verify that the tethering functionality requires the device and verify that the tethering functionality requires the configured authentication method. configured authentication method. ::: ::: \ \ ::: ::: ::: management_function_ea ::: management_function_ea **Function [42](#mf-dataSharing) \[CONDITIONAL\]**\ **Function [42](#mf-dataSharing) \[CONDITIONAL\]**\ ::: eacategory ::: eacategory > [TSS](#abbr_TSS) > ::: > > There are no additional [TSS](#abbr_TSS) evaluation activities for this > management function.\ > \ > > ::: eacategory > Guidance > ::: > > There are no additional Guidance evaluation activities for this > management function.\ > \ > > ::: eacategory Tests Tests ::: ::: ::: ea ::: ea The test of this function is performed in conjunction with The test of this function is performed in conjunction with [FDP_ACF_EXT.1.2](#FDP_ACF_EXT.1.2). [FDP_ACF_EXT.1.2](#FDP_ACF_EXT.1.2). ::: ::: \ \ ::: ::: ::: management_function_ea ::: management_function_ea **Function [43](#mf-appGroups) \[CONDITIONAL\]**\ **Function [43](#mf-appGroups) \[CONDITIONAL\]**\ ::: eacategory ::: eacategory > [TSS](#abbr_TSS) > ::: > > There are no additional [TSS](#abbr_TSS) evaluation activities for this > management function.\ > \ > > ::: eacategory > Guidance > ::: > > There are no additional Guidance evaluation activities for this > management function.\ > \ > > ::: eacategory Tests Tests ::: ::: ::: ea ::: ea Test [FMT_SMF_EXT.1](#FMT_SMF_EXT.1):43: The evaluator shall set a Test [FMT_SMF_EXT.1](#FMT_SMF_EXT.1):43: The evaluator shall set a policy to cause a designated application to be placed into a particular policy to cause a designated application to be placed into a particular application group. The evaluator shall then install the designated application group. The evaluator shall then install the designated application and verify that it was placed into the correct group. application and verify that it was placed into the correct group. ::: ::: \ \ ::: ::: ::: management_function_ea ::: management_function_ea **Function [44](#mf-unenroll) \[CONDITIONAL\]**\ **Function [44](#mf-unenroll) \[CONDITIONAL\]**\ ::: eacategory ::: eacategory > [TSS](#abbr_TSS) > ::: > > There are no additional [TSS](#abbr_TSS) evaluation activities for this > management function.\ > \ > > ::: eacategory > Guidance > ::: > > There are no additional Guidance evaluation activities for this > management function.\ > \ > > ::: eacategory Tests Tests ::: ::: ::: ea ::: ea Test [FMT_SMF_EXT.1](#FMT_SMF_EXT.1):44: The evaluator shall attempt to Test [FMT_SMF_EXT.1](#FMT_SMF_EXT.1):44: The evaluator shall attempt to unenroll the device from management and verify that the steps described unenroll the device from management and verify that the steps described in [FMT_SMF_EXT.2.1](#FMT_SMF_EXT.2.1) are performed. This test should in [FMT_SMF_EXT.2.1](#FMT_SMF_EXT.2.1) are performed. This test should be performed in conjunction with the [FMT_SMF_EXT.2.1](#FMT_SMF_EXT.2.1) be performed in conjunction with the [FMT_SMF_EXT.2.1](#FMT_SMF_EXT.2.1) evaluation activity. evaluation activity. ::: ::: \ \ ::: ::: ::: management_function_ea ::: management_function_ea **Function [45](#mf-alwaysOnVPN) \[CONDITIONAL\]**\ **Function [45](#mf-alwaysOnVPN) \[CONDITIONAL\]**\ ::: eacategory ::: eacategory [TSS](#abbr_TSS) [TSS](#abbr_TSS) ::: ::: ::: ea ::: ea The evaluator shall verify that the [TSS](#abbr_TSS) contains guidance The evaluator shall verify that the [TSS](#abbr_TSS) contains guidance to configure the [VPN](#abbr_VPN) as Always-On. to configure the [VPN](#abbr_VPN) as Always-On. ::: ::: ::: eacategory ::: eacategory > Guidance > ::: > > There are no additional Guidance evaluation activities for this > management function.\ > \ > > ::: eacategory Tests Tests ::: ::: ::: ea ::: ea The evaluator shall configure the [VPN](#abbr_VPN) as Always-On and The evaluator shall configure the [VPN](#abbr_VPN) as Always-On and perform the following tests: perform the following tests: - Test [FMT_SMF_EXT.1](#FMT_SMF_EXT.1):45a: The evaluator shall verify - Test [FMT_SMF_EXT.1](#FMT_SMF_EXT.1):45a: The evaluator shall verify that when the [VPN](#abbr_VPN) is connected all traffic is routed that when the [VPN](#abbr_VPN) is connected all traffic is routed through the [VPN](#abbr_VPN). This test is performed in conjunction through the [VPN](#abbr_VPN). This test is performed in conjunction with [FDP_IFC_EXT.1.1](#FDP_IFC_EXT.1.1). with [FDP_IFC_EXT.1.1](#FDP_IFC_EXT.1.1). - Test [FMT_SMF_EXT.1](#FMT_SMF_EXT.1):45b: The evaluator shall verify - Test [FMT_SMF_EXT.1](#FMT_SMF_EXT.1):45b: The evaluator shall verify that when the [VPN](#abbr_VPN) is not established, that no traffic that when the [VPN](#abbr_VPN) is not established, that no traffic leaves the device. The evaluator shall ensure that the leaves the device. The evaluator shall ensure that the [TOE](#abbr_TOE) has network connectivity and that the [TOE](#abbr_TOE) has network connectivity and that the [VPN](#abbr_VPN) is established. The evaluator shall use a packet [VPN](#abbr_VPN) is established. The evaluator shall use a packet sniffing tool to capture the traffic leaving the [TOE](#abbr_TOE). sniffing tool to capture the traffic leaving the [TOE](#abbr_TOE). The evaluator shall disable the [VPN](#abbr_VPN) connection on the The evaluator shall disable the [VPN](#abbr_VPN) connection on the server side. The evaluator shall perform actions with the device server side. The evaluator shall perform actions with the device such as navigating to websites, using provided applications, and such as navigating to websites, using provided applications, and accessing other Internet resources and verify that no traffic leaves accessing other Internet resources and verify that no traffic leaves the device. the device. - Test [FMT_SMF_EXT.1](#FMT_SMF_EXT.1):45c: The evaluator shall verify - Test [FMT_SMF_EXT.1](#FMT_SMF_EXT.1):45c: The evaluator shall verify that the [TOE](#abbr_TOE) has network connectivity and that the that the [TOE](#abbr_TOE) has network connectivity and that the [VPN](#abbr_VPN) is established. The evaluator shall disable network [VPN](#abbr_VPN) is established. The evaluator shall disable network connectivity (i.e., Airplane Mode) and verify that the connectivity (i.e., Airplane Mode) and verify that the [VPN](#abbr_VPN) disconnects. The evaluator shall re-establish [VPN](#abbr_VPN) disconnects. The evaluator shall re-establish network connectivity and verify that the [VPN](#abbr_VPN) network connectivity and verify that the [VPN](#abbr_VPN) automatically reconnects. automatically reconnects. ::: ::: \ \ ::: ::: ::: management_function_ea ::: management_function_ea **Function [46](#mf-bioRevoke) \[CONDITIONAL\]**\ **Function [46](#mf-bioRevoke) \[CONDITIONAL\]**\ ::: eacategory ::: eacategory [TSS](#abbr_TSS) [TSS](#abbr_TSS) ::: ::: ::: ea ::: ea The evaluator shall verify that the [TSS](#abbr_TSS) describes the The evaluator shall verify that the [TSS](#abbr_TSS) describes the procedure to revoke a biometric credential stored on the procedure to revoke a biometric credential stored on the [TOE](#abbr_TOE). [TOE](#abbr_TOE). ::: ::: ::: eacategory ::: eacategory > Guidance > ::: > > There are no additional Guidance evaluation activities for this > management function.\ > \ > > ::: eacategory Tests Tests ::: ::: ::: ea ::: ea Test [FMT_SMF_EXT.1](#FMT_SMF_EXT.1):46: The evaluator shall configure Test [FMT_SMF_EXT.1](#FMT_SMF_EXT.1):46: The evaluator shall configure the [TOE](#abbr_TOE) to use [BAF](#abbr_BAF) and confirm that the the [TOE](#abbr_TOE) to use [BAF](#abbr_BAF) and confirm that the biometric can be used to authenticate to the device. The evaluator shall biometric can be used to authenticate to the device. The evaluator shall revoke the biometric credential's ability to authenticate to the revoke the biometric credential's ability to authenticate to the [TOE](#abbr_TOE) and confirm that the same [BAF](#abbr_BAF) cannot be [TOE](#abbr_TOE) and confirm that the same [BAF](#abbr_BAF) cannot be used to authenticate to the device. used to authenticate to the device. ::: ::: \ \ ::: ::: ::: management_function_ea ::: management_function_ea **Function [47](#mf-other) \[CONDITIONAL\]**\ **Function [47](#mf-other) \[CONDITIONAL\]**\ ::: eacategory ::: eacategory [TSS](#abbr_TSS) [TSS](#abbr_TSS) ::: ::: ::: ea ::: ea The evaluator shall verify that the [TSS](#abbr_TSS) describes all The evaluator shall verify that the [TSS](#abbr_TSS) describes all assigned security management functions and their intended behavior. assigned security management functions and their intended behavior. ::: ::: ::: eacategory ::: eacategory > Guidance > ::: > > There are no additional Guidance evaluation activities for this > management function.\ > \ > > ::: eacategory Tests Tests ::: ::: ::: ea ::: ea Test [FMT_SMF_EXT.1](#FMT_SMF_EXT.1):47: The evaluator shall design and Test [FMT_SMF_EXT.1](#FMT_SMF_EXT.1):47: The evaluator shall design and perform tests to demonstrate that the function may be configured and perform tests to demonstrate that the function may be configured and that the intended behavior of the function is enacted by the that the intended behavior of the function is enacted by the [TOE](#abbr_TOE). [TOE](#abbr_TOE). ::: ::: \ \ ::: ::: ::: ::: ::: ::: ::: ::: ::: ::: ::: {#FMT_SMF_EXT.2 .comp} ::: {#FMT_SMF_EXT.2 .comp} #### FMT_SMF_EXT.2 Specification of Remediation Actions #### FMT_SMF_EXT.2 Specification of Remediation Actions ::: element ::: element ::: {#FMT_SMF_EXT.2.1 .reqid} ::: {#FMT_SMF_EXT.2.1 .reqid} [FMT_SMF_EXT.2.1](#FMT_SMF_EXT.2.1){.abbr} [FMT_SMF_EXT.2.1](#FMT_SMF_EXT.2.1){.abbr} ::: ::: ::: reqdesc ::: reqdesc The [TSF](#abbr_TSF) shall offer \[**selection**: [wipe of protected The [TSF](#abbr_TSF) shall offer \[**selection**: [wipe of protected data]{#s-smf-wipe-pro .selectable-content}, [wipe of sensitive data]{#s-smf-wipe-pro .selectable-content}, [wipe of sensitive data]{#s-smf-wipe-sen .selectable-content}, [remove Enterprise data]{#s-smf-wipe-sen .selectable-content}, [remove Enterprise applications]{#s-smf-ext-2-rem-ent-app .selectable-content}, [remove all applications]{#s-smf-ext-2-rem-ent-app .selectable-content}, [remove all device-stored Enterprise resource data]{#_s_581 .selectable-content}, | device-stored Enterprise resource data]{#fmt_smf_ext.2.1_1 [remove Enterprise secondary authentication data]{#_s_582 | .selectable-content}, [remove Enterprise secondary authentication .selectable-content}, [\[**assignment**: [list other available | data]{#fmt_smf_ext.2.1_2 .selectable-content}, [\[**assignment**: [list remediation actions]{.assignable-content}\]]{#_s_583 | other available remediation > actions]{.assignable-content}\]]{#fmt_smf_ext.2.1_3 .selectable-content}\] upon unenrollment and \[**selection**: .selectable-content}\] upon unenrollment and \[**selection**: [\[**assignment**: [other administrator-configured [\[**assignment**: [other administrator-configured triggers]{.assignable-content}\]]{#_s_584 .selectable-content}, [ no | triggers]{.assignable-content}\]]{#fmt_smf_ext.2.1_5 other triggers]{#_s_585 .selectable-content}\]. | .selectable-content}, [no other triggers]{#fmt_smf_ext.2.1_7 > .selectable-content}\]. ::: appnote ::: appnote [Application Note: ]{.note-header}[ Unenrollment may consist of removing [Application Note: ]{.note-header}[ Unenrollment may consist of removing the [MDM](#abbr_MDM) agent or removing the administrator's policies. The the [MDM](#abbr_MDM) agent or removing the administrator's policies. The functions in the selection are remediation actions that [TOE](#abbr_TOE) functions in the selection are remediation actions that [TOE](#abbr_TOE) may provide (perhaps via APIs) to the administrator (perhaps via an may provide (perhaps via APIs) to the administrator (perhaps via an [MDM](#abbr_MDM) agent) that may be performed upon unenrollment. [MDM](#abbr_MDM) agent) that may be performed upon unenrollment. \"Enterprise applications\" refers to applications that are in the \"Enterprise applications\" refers to applications that are in the Enterprise application group. \"Enterprise resource data\" refers to all Enterprise application group. \"Enterprise resource data\" refers to all stored Enterprise data and the separate resources that are available to stored Enterprise data and the separate resources that are available to the Enterprise application group, per the Enterprise application group, per [FDP_ACF_EXT.2.1](#FDP_ACF_EXT.2.1). If [FDP_ACF_EXT.2.1](#FDP_ACF_EXT.2.1). If [FDP_ACF_EXT.2.1](#FDP_ACF_EXT.2.1) is included in the [ST](#abbr_ST), [FDP_ACF_EXT.2.1](#FDP_ACF_EXT.2.1) is included in the [ST](#abbr_ST), then \"remove all device-stored Enterprise resource data\" must be then \"remove all device-stored Enterprise resource data\" must be selected, and is defined to be all resources selected in selected, and is defined to be all resources selected in [FDP_ACF_EXT.2.1](#FDP_ACF_EXT.2.1). If [FDP_ACF_EXT.2.1](#FDP_ACF_EXT.2.1). If [FIA_UAU_EXT.4.1](#FIA_UAU_EXT.4.1) is included in the [ST](#abbr_ST), [FIA_UAU_EXT.4.1](#FIA_UAU_EXT.4.1) is included in the [ST](#abbr_ST), then \"remove Enterprise secondary authentication data\" must be then \"remove Enterprise secondary authentication data\" must be selected. If [FIA_UAU_EXT.4.1](#FIA_UAU_EXT.4.1) is not included in the selected. If [FIA_UAU_EXT.4.1](#FIA_UAU_EXT.4.1) is not included in the [ST](#abbr_ST), then \"remove Enterprise secondary authentication data\" [ST](#abbr_ST), then \"remove Enterprise secondary authentication data\" cannot be selected. Enterprise secondary authentication data only refers cannot be selected. Enterprise secondary authentication data only refers to any data stored on the [TOE](#abbr_TOE) that is specifically used as to any data stored on the [TOE](#abbr_TOE) that is specifically used as part of a secondary authentication mechanism to authenticate access to part of a secondary authentication mechanism to authenticate access to Enterprise applications and shared resources. Material that is used for Enterprise applications and shared resources. Material that is used for the [TOE](#abbr_TOE)'s primary authentication mechanism or other the [TOE](#abbr_TOE)'s primary authentication mechanism or other purposes not related to authentication to or protection of Enterprise purposes not related to authentication to or protection of Enterprise applications or shared resources should not be removed.\ applications or shared resources should not be removed.\ \ \ Protected data is all non-TSF data, including all user or enterprise Protected data is all non-TSF data, including all user or enterprise data. Some or all of this data may be considered sensitive data as well. data. Some or all of this data may be considered sensitive data as well. If [wipe of protected data](#s-smf-wipe-pro) is selected it is assumed If [wipe of protected data](#s-smf-wipe-pro) is selected it is assumed that the sensitive data is wiped as well. However, if [wipe of sensitive that the sensitive data is wiped as well. However, if [wipe of sensitive data](#s-smf-wipe-sen) is selected, it does not imply that all non-TSF data](#s-smf-wipe-sen) is selected, it does not imply that all non-TSF data (protected data) is wiped. If [wipe of protected data (protected data) is wiped. If [wipe of protected data](#s-smf-wipe-pro) or [wipe of sensitive data](#s-smf-wipe-sen) is data](#s-smf-wipe-pro) or [wipe of sensitive data](#s-smf-wipe-sen) is selected the wipe must be in accordance with selected the wipe must be in accordance with [FCS_CKM_EXT.5.1](#FCS_CKM_EXT.5.1). Thus cryptographically wiping the [FCS_CKM_EXT.5.1](#FCS_CKM_EXT.5.1). Thus cryptographically wiping the device is an acceptable remediation action. ]{.note} device is an acceptable remediation action. ]{.note} ::: ::: ::: ::: ::: ::: ::: {.activity_pane .hide} ::: {.activity_pane .hide} ::: activity_pane_header ::: activity_pane_header [[ Evaluation Activities [[ Evaluation Activities ]{.activity_pane_label}[]{.toggler}](#){onclick="toggle(this);return false;"} ]{.activity_pane_label}[]{.toggler}](#){onclick="toggle(this);return false;"} ::: ::: ::: activity_pane_body ::: activity_pane_body ::: component-activity-header ::: component-activity-header [FMT_SMF_EXT.2](#FMT_SMF_EXT.2) [FMT_SMF_EXT.2](#FMT_SMF_EXT.2) ::: ::: ::: eacategory ::: eacategory [TSS](#abbr_TSS) [TSS](#abbr_TSS) ::: ::: ::: ea ::: ea ::: ea ::: ea The evaluator shall verify that the [TSS](#abbr_TSS) describes all The evaluator shall verify that the [TSS](#abbr_TSS) describes all available remediation actions, when they are available for use, and any available remediation actions, when they are available for use, and any other administrator-configured triggers. The evaluator shall verify that other administrator-configured triggers. The evaluator shall verify that the [TSS](#abbr_TSS) describes how the remediation actions are provided the [TSS](#abbr_TSS) describes how the remediation actions are provided to the administrator.\ to the administrator.\ \ \ ::: ::: ::: ::: ::: eacategory ::: eacategory Guidance Guidance ::: ::: ::: ea ::: ea ::: ea ::: ea There are no guidance evaluation activities for this component.\ There are no guidance evaluation activities for this component.\ \ \ ::: ::: ::: ::: ::: eacategory ::: eacategory Tests Tests ::: ::: ::: ea ::: ea ::: ea ::: ea The evaluator shall use the test environment to iteratively configure The evaluator shall use the test environment to iteratively configure the device to perform each remediation action in the selection. The the device to perform each remediation action in the selection. The evaluator shall configure the remediation action per how the evaluator shall configure the remediation action per how the [TSS](#abbr_TSS) states it is provided to the administrator. The test [TSS](#abbr_TSS) states it is provided to the administrator. The test environment could be an [MDM](#abbr_MDM) agent application, but can also environment could be an [MDM](#abbr_MDM) agent application, but can also be an application with administrator access. be an application with administrator access. ::: ::: ::: ::: ::: ::: ::: ::: ::: ::: ### 5.1.7 Class FPT: Protection of the TSF {#fpt .indexable level="3"} ### 5.1.7 Class FPT: Protection of the TSF {#fpt .indexable level="3"} ::: {#FPT_AEX_EXT.1 .comp} ::: {#FPT_AEX_EXT.1 .comp} #### FPT_AEX_EXT.1 Application Address Space Layout Randomization #### FPT_AEX_EXT.1 Application Address Space Layout Randomization ::: element ::: element ::: {#FPT_AEX_EXT.1.1 .reqid} ::: {#FPT_AEX_EXT.1.1 .reqid} [FPT_AEX_EXT.1.1](#FPT_AEX_EXT.1.1){.abbr} [FPT_AEX_EXT.1.1](#FPT_AEX_EXT.1.1){.abbr} ::: ::: ::: reqdesc ::: reqdesc The [TSF](#abbr_TSF) shall provide address space layout randomization The [TSF](#abbr_TSF) shall provide address space layout randomization [ASLR](#abbr_ASLR) to applications. [ASLR](#abbr_ASLR) to applications. ::: ::: ::: ::: ::: element ::: element ::: {#FPT_AEX_EXT.1.2 .reqid} ::: {#FPT_AEX_EXT.1.2 .reqid} [FPT_AEX_EXT.1.2](#FPT_AEX_EXT.1.2){.abbr} [FPT_AEX_EXT.1.2](#FPT_AEX_EXT.1.2){.abbr} ::: ::: ::: reqdesc ::: reqdesc The base address of any user-space memory mapping will consist of at The base address of any user-space memory mapping will consist of at least 8 unpredictable bits. least 8 unpredictable bits. ::: appnote ::: appnote [Application Note: ]{.note-header}[The 8 unpredictable bits may be [Application Note: ]{.note-header}[The 8 unpredictable bits may be provided by the [TSF](#abbr_TSF) DRBG (as specified in provided by the [TSF](#abbr_TSF) DRBG (as specified in [FCS_RBG.1](#FCS_RBG.1)) but is not required.]{.note} [FCS_RBG.1](#FCS_RBG.1)) but is not required.]{.note} ::: ::: ::: ::: ::: ::: ::: {.activity_pane .hide} ::: {.activity_pane .hide} ::: activity_pane_header ::: activity_pane_header [[ Evaluation Activities [[ Evaluation Activities ]{.activity_pane_label}[]{.toggler}](#){onclick="toggle(this);return false;"} ]{.activity_pane_label}[]{.toggler}](#){onclick="toggle(this);return false;"} ::: ::: ::: activity_pane_body ::: activity_pane_body ::: component-activity-header ::: component-activity-header [FPT_AEX_EXT.1](#FPT_AEX_EXT.1) [FPT_AEX_EXT.1](#FPT_AEX_EXT.1) ::: ::: ::: eacategory ::: eacategory [TSS](#abbr_TSS) [TSS](#abbr_TSS) ::: ::: ::: ea ::: ea ::: ea ::: ea The evaluator shall ensure that the [TSS](#abbr_TSS) section of the The evaluator shall ensure that the [TSS](#abbr_TSS) section of the [ST](#abbr_ST) describes how the 8 bits are generated and provides a [ST](#abbr_ST) describes how the 8 bits are generated and provides a justification as to why those bits are unpredictable.\ justification as to why those bits are unpredictable.\ \ \ ::: ::: ::: ::: ::: eacategory ::: eacategory Guidance Guidance ::: ::: ::: ea ::: ea ::: ea ::: ea There are no guidance evaluation activities for this component.\ There are no guidance evaluation activities for this component.\ \ \ ::: ::: ::: ::: ::: eacategory ::: eacategory Tests Tests ::: ::: ::: ea ::: ea ::: ea ::: ea **Evaluation Activity Note:** The following test require the developer **Evaluation Activity Note:** The following test require the developer to provide access to a test platform that provides the evaluator with to provide access to a test platform that provides the evaluator with tools that are typically not found on consumer Mobile Device products.\ tools that are typically not found on consumer Mobile Device products.\ []{.testlist-} []{.testlist-} - [Test FPT_AEX_EXT.1:1](#_t_57){#_t_57 .defined}: - [Test FPT_AEX_EXT.1:1](#_t_57){#_t_57 .defined}: The evaluator shall select 3 apps included with the The evaluator shall select 3 apps included with the [TSF](#abbr_TSF). These must include any web browser or mail client [TSF](#abbr_TSF). These must include any web browser or mail client included with the [TSF](#abbr_TSF). For each of these apps, the included with the [TSF](#abbr_TSF). For each of these apps, the evaluator shall launch the same app on two separate Mobile Devices evaluator shall launch the same app on two separate Mobile Devices of the same type and compare all memory mapping locations. The of the same type and compare all memory mapping locations. The evaluator shall ensure that no memory mappings are placed in the evaluator shall ensure that no memory mappings are placed in the same location on both devices. This test can also be completed on same location on both devices. This test can also be completed on the same Mobile Device if the evaluator reboots the Mobile Device the same Mobile Device if the evaluator reboots the Mobile Device between application launches. between application launches. If the rare (at most 1/256) chance occurs that two mappings are the If the rare (at most 1/256) chance occurs that two mappings are the same for a single app and not the same for the other two apps, the same for a single app and not the same for the other two apps, the evaluator shall repeat the test with that app to verify that in the evaluator shall repeat the test with that app to verify that in the second test the mappings are different. second test the mappings are different. ::: ::: ::: ::: ::: ::: ::: ::: ::: ::: ::: {#FPT_AEX_EXT.2 .comp} ::: {#FPT_AEX_EXT.2 .comp} #### FPT_AEX_EXT.2 Memory Page Permissions #### FPT_AEX_EXT.2 Memory Page Permissions ::: element ::: element ::: {#FPT_AEX_EXT.2.1 .reqid} ::: {#FPT_AEX_EXT.2.1 .reqid} [FPT_AEX_EXT.2.1](#FPT_AEX_EXT.2.1){.abbr} [FPT_AEX_EXT.2.1](#FPT_AEX_EXT.2.1){.abbr} ::: ::: ::: reqdesc ::: reqdesc The [TSF](#abbr_TSF) shall be able to enforce read, write, and execute The [TSF](#abbr_TSF) shall be able to enforce read, write, and execute permissions on every page of physical memory. permissions on every page of physical memory. ::: ::: ::: ::: ::: {.activity_pane .hide} ::: {.activity_pane .hide} ::: activity_pane_header ::: activity_pane_header [[ Evaluation Activities [[ Evaluation Activities ]{.activity_pane_label}[]{.toggler}](#){onclick="toggle(this);return false;"} ]{.activity_pane_label}[]{.toggler}](#){onclick="toggle(this);return false;"} ::: ::: ::: activity_pane_body ::: activity_pane_body ::: component-activity-header ::: component-activity-header [FPT_AEX_EXT.2](#FPT_AEX_EXT.2) [FPT_AEX_EXT.2](#FPT_AEX_EXT.2) ::: ::: ::: eacategory ::: eacategory [TSS](#abbr_TSS) [TSS](#abbr_TSS) ::: ::: ::: ea ::: ea ::: ea ::: ea The evaluator shall ensure that the [TSS](#abbr_TSS) describes of the The evaluator shall ensure that the [TSS](#abbr_TSS) describes of the memory management unit ([MMU](#abbr_MMU)), and ensures that this memory management unit ([MMU](#abbr_MMU)), and ensures that this description documents the ability of the [MMU](#abbr_MMU) to enforce description documents the ability of the [MMU](#abbr_MMU) to enforce read, write, and execute permissions on all pages of virtual memory.\ read, write, and execute permissions on all pages of virtual memory.\ \ \ ::: ::: ::: ::: ::: eacategory ::: eacategory Guidance Guidance ::: ::: ::: ea ::: ea ::: ea ::: ea There are no guidance evaluation activities for this component.\ There are no guidance evaluation activities for this component.\ \ \ ::: ::: ::: ::: ::: eacategory ::: eacategory Tests Tests ::: ::: ::: ea ::: ea ::: ea ::: ea There are no test evaluation activities for this component. There are no test evaluation activities for this component. ::: ::: ::: ::: ::: ::: ::: ::: ::: ::: ::: {#FPT_AEX_EXT.3 .comp} ::: {#FPT_AEX_EXT.3 .comp} #### FPT_AEX_EXT.3 Stack Overflow Protection #### FPT_AEX_EXT.3 Stack Overflow Protection ::: element ::: element ::: {#FPT_AEX_EXT.3.1 .reqid} ::: {#FPT_AEX_EXT.3.1 .reqid} [FPT_AEX_EXT.3.1](#FPT_AEX_EXT.3.1){.abbr} [FPT_AEX_EXT.3.1](#FPT_AEX_EXT.3.1){.abbr} ::: ::: ::: reqdesc ::: reqdesc [TSF](#abbr_TSF) processes that execute in a non-privileged execution [TSF](#abbr_TSF) processes that execute in a non-privileged execution domain on the application processor shall implement stack-based buffer domain on the application processor shall implement stack-based buffer overflow protection. overflow protection. ::: appnote ::: appnote [Application Note: ]{.note-header}[A \"non-privileged execution domain\" [Application Note: ]{.note-header}[A \"non-privileged execution domain\" refers to the user mode (as opposed to kernel mode, for instance) of the refers to the user mode (as opposed to kernel mode, for instance) of the processor. While not all [TSF](#abbr_TSF) processes must implement such processor. While not all [TSF](#abbr_TSF) processes must implement such protection, it is expected that most of the processes (to include protection, it is expected that most of the processes (to include libraries used by [TSF](#abbr_TSF) processes) do implement buffer libraries used by [TSF](#abbr_TSF) processes) do implement buffer overflow protections.]{.note} overflow protections.]{.note} ::: ::: ::: ::: ::: ::: ::: {.activity_pane .hide} ::: {.activity_pane .hide} ::: activity_pane_header ::: activity_pane_header [[ Evaluation Activities [[ Evaluation Activities ]{.activity_pane_label}[]{.toggler}](#){onclick="toggle(this);return false;"} ]{.activity_pane_label}[]{.toggler}](#){onclick="toggle(this);return false;"} ::: ::: ::: activity_pane_body ::: activity_pane_body ::: component-activity-header ::: component-activity-header [FPT_AEX_EXT.3](#FPT_AEX_EXT.3) [FPT_AEX_EXT.3](#FPT_AEX_EXT.3) ::: ::: ::: eacategory ::: eacategory [TSS](#abbr_TSS) [TSS](#abbr_TSS) ::: ::: ::: ea ::: ea ::: ea ::: ea The evaluator shall determine that the [TSS](#abbr_TSS) contains a The evaluator shall determine that the [TSS](#abbr_TSS) contains a description of stack-based buffer overflow protections implemented in description of stack-based buffer overflow protections implemented in the [TSF](#abbr_TSF) software which runs in the non-privileged execution the [TSF](#abbr_TSF) software which runs in the non-privileged execution mode of the application processor. The exact implementation of mode of the application processor. The exact implementation of stack-based buffer overflow protection will vary by platform. Example stack-based buffer overflow protection will vary by platform. Example implementations may be activated through compiler options such as implementations may be activated through compiler options such as \"-fstack-protector-all\", \"-fstack-protector\", and \"/GS\" flags. The \"-fstack-protector-all\", \"-fstack-protector\", and \"/GS\" flags. The evaluator shall ensure that the [TSS](#abbr_TSS) contains an inventory evaluator shall ensure that the [TSS](#abbr_TSS) contains an inventory of [TSF](#abbr_TSF) binaries and libraries, indicating those that of [TSF](#abbr_TSF) binaries and libraries, indicating those that implement stack-based buffer overflow protections as well as those that implement stack-based buffer overflow protections as well as those that do not. The [TSS](#abbr_TSS) must provide a rationale for those binaries do not. The [TSS](#abbr_TSS) must provide a rationale for those binaries and libraries that are not protected in this manner.\ and libraries that are not protected in this manner.\ \ \ ::: ::: ::: ::: ::: eacategory ::: eacategory Guidance Guidance ::: ::: ::: ea ::: ea ::: ea ::: ea There are no guidance evaluation activities for this component.\ There are no guidance evaluation activities for this component.\ \ \ ::: ::: ::: ::: ::: eacategory ::: eacategory Tests Tests ::: ::: ::: ea ::: ea ::: ea ::: ea There are no test evaluation activities for this component. There are no test evaluation activities for this component. ::: ::: ::: ::: ::: ::: ::: ::: ::: ::: ::: {#FPT_AEX_EXT.4 .comp} ::: {#FPT_AEX_EXT.4 .comp} #### FPT_AEX_EXT.4 Domain Isolation #### FPT_AEX_EXT.4 Domain Isolation ::: element ::: element ::: {#FPT_AEX_EXT.4.1 .reqid} ::: {#FPT_AEX_EXT.4.1 .reqid} [FPT_AEX_EXT.4.1](#FPT_AEX_EXT.4.1){.abbr} [FPT_AEX_EXT.4.1](#FPT_AEX_EXT.4.1){.abbr} ::: ::: ::: reqdesc ::: reqdesc The [TSF](#abbr_TSF) shall protect itself from modification by untrusted The [TSF](#abbr_TSF) shall protect itself from modification by untrusted subjects. subjects. ::: ::: ::: ::: ::: element ::: element ::: {#FPT_AEX_EXT.4.2 .reqid} ::: {#FPT_AEX_EXT.4.2 .reqid} [FPT_AEX_EXT.4.2](#FPT_AEX_EXT.4.2){.abbr} [FPT_AEX_EXT.4.2](#FPT_AEX_EXT.4.2){.abbr} ::: ::: ::: reqdesc ::: reqdesc The [TSF](#abbr_TSF) shall enforce isolation of address space between The [TSF](#abbr_TSF) shall enforce isolation of address space between applications. applications. ::: appnote ::: appnote [Application Note: ]{.note-header}[In addition to the [TSF](#abbr_TSF) | [Application Note: ]{.note-header}[ In addition to the [TSF](#abbr_TSF) software (e.g., kernel image, device drivers, trusted applications) that software (e.g., kernel image, device drivers, trusted applications) that resides in storage, the execution context (e.g., address space, resides in storage, the execution context (e.g., address space, processor registers, per-process environment variables) of the software processor registers, per-process environment variables) of the software operating in a privileged mode of the processor (e.g., kernel), as well operating in a privileged mode of the processor (e.g., kernel), as well as the context of the trusted applications is to be protected. In as the context of the trusted applications is to be protected. In addition to the software, any configuration information that controls or addition to the software, any configuration information that controls or influences the behavior of the [TSF](#abbr_TSF) is also to be protected influences the behavior of the [TSF](#abbr_TSF) is also to be protected from modification by untrusted subjects.\ from modification by untrusted subjects.\ \ \ Configuration information includes, but is not limited to, user and Configuration information includes, but is not limited to, user and administrative management function settings, WLAN profiles, and administrative management function settings, WLAN profiles, and Bluetooth data such as the service-level security requirements Bluetooth data such as the service-level security requirements database.\ database.\ \ \ Untrusted subjects include untrusted applications; unauthorized users Untrusted subjects include untrusted applications; unauthorized users who have access to the device while powered off, in a screen-locked who have access to the device while powered off, in a screen-locked state, or when booted into auxiliary boot modes; and, unauthorized users state, or when booted into auxiliary boot modes; and, unauthorized users or untrusted software or hardware which may have access to the device or untrusted software or hardware which may have access to the device over a wired interface, either when the device is in a screen-locked over a wired interface, either when the device is in a screen-locked state or booted into auxiliary boot modes. ]{.note} state or booted into auxiliary boot modes. ]{.note} ::: ::: ::: ::: ::: ::: ::: {.activity_pane .hide} ::: {.activity_pane .hide} ::: activity_pane_header ::: activity_pane_header [[ Evaluation Activities [[ Evaluation Activities ]{.activity_pane_label}[]{.toggler}](#){onclick="toggle(this);return false;"} ]{.activity_pane_label}[]{.toggler}](#){onclick="toggle(this);return false;"} ::: ::: ::: activity_pane_body ::: activity_pane_body ::: component-activity-header ::: component-activity-header [FPT_AEX_EXT.4](#FPT_AEX_EXT.4) [FPT_AEX_EXT.4](#FPT_AEX_EXT.4) ::: ::: ::: eacategory ::: eacategory [TSS](#abbr_TSS) [TSS](#abbr_TSS) ::: ::: ::: ea ::: ea ::: ea ::: ea The evaluator shall ensure that the [TSS](#abbr_TSS) describes the The evaluator shall ensure that the [TSS](#abbr_TSS) describes the mechanisms that are in place that prevents non-TSF software from mechanisms that are in place that prevents non-TSF software from modifying the [TSF](#abbr_TSF) software or [TSF](#abbr_TSF) data that modifying the [TSF](#abbr_TSF) software or [TSF](#abbr_TSF) data that governs the behavior of the [TSF](#abbr_TSF). These mechanisms could governs the behavior of the [TSF](#abbr_TSF). These mechanisms could range from hardware-based means (e.g. \"execution rings\" and memory range from hardware-based means (e.g. \"execution rings\" and memory management functionality); to software-based means (e.g. boundary management functionality); to software-based means (e.g. boundary checking of inputs to APIs). The evaluator determines that the described checking of inputs to APIs). The evaluator determines that the described mechanisms appear reasonable to protect the [TSF](#abbr_TSF) from mechanisms appear reasonable to protect the [TSF](#abbr_TSF) from modification.\ modification.\ \ \ The evaluator shall ensure the [TSS](#abbr_TSS) describes how the The evaluator shall ensure the [TSS](#abbr_TSS) describes how the [TSF](#abbr_TSF) ensures that the address spaces of applications are [TSF](#abbr_TSF) ensures that the address spaces of applications are kept separate from one another.\ kept separate from one another.\ \ \ The evaluator shall ensure the [TSS](#abbr_TSS) details the The evaluator shall ensure the [TSS](#abbr_TSS) details the [USSD](#abbr_USSD) and [MMI](#abbr_MMI) codes available from the dialer [USSD](#abbr_USSD) and [MMI](#abbr_MMI) codes available from the dialer at the locked state or during auxiliary boot modes that may alter the at the locked state or during auxiliary boot modes that may alter the behavior of the [TSF](#abbr_TSF). The evaluator shall ensure that this behavior of the [TSF](#abbr_TSF). The evaluator shall ensure that this description includes the code, the action performed by the description includes the code, the action performed by the [TSF](#abbr_TSF), and a justification that the actions performed do not [TSF](#abbr_TSF), and a justification that the actions performed do not modify user or [TSF](#abbr_TSF) data. If no [USSD](#abbr_USSD) or modify user or [TSF](#abbr_TSF) data. If no [USSD](#abbr_USSD) or [MMI](#abbr_MMI) codes are available, the evaluator shall ensure that [MMI](#abbr_MMI) codes are available, the evaluator shall ensure that the [TSS](#abbr_TSS) provides a description of the method by which the [TSS](#abbr_TSS) provides a description of the method by which actions prescribed by these codes are prevented.\ actions prescribed by these codes are prevented.\ \ \ The evaluator shall ensure the [TSS](#abbr_TSS) documents any The evaluator shall ensure the [TSS](#abbr_TSS) documents any [TSF](#abbr_TSF) data (including software, execution context, [TSF](#abbr_TSF) data (including software, execution context, configuration information, and audit logs) which may be accessed and configuration information, and audit logs) which may be accessed and modified over a wired interface in auxiliary boot modes. The evaluator modified over a wired interface in auxiliary boot modes. The evaluator shall ensure that the description includes data, which is modified in shall ensure that the description includes data, which is modified in support of update or restore of the device. The evaluator shall ensure support of update or restore of the device. The evaluator shall ensure that this documentation includes the auxiliary boot modes in which the that this documentation includes the auxiliary boot modes in which the data may be modified, the methods for entering the auxiliary boot modes, data may be modified, the methods for entering the auxiliary boot modes, the location of the data, the manner in which data may be modified, the the location of the data, the manner in which data may be modified, the data format and packaging necessary to support modification, and data format and packaging necessary to support modification, and software or hardware tools, if any, which are necessary for modifying software or hardware tools, if any, which are necessary for modifying the data.\ the data.\ \ \ The evaluator shall ensure that the [TSS](#abbr_TSS) provides a The evaluator shall ensure that the [TSS](#abbr_TSS) provides a description of the means by which unauthorized and undetected description of the means by which unauthorized and undetected modification (that is, excluding cryptographically verified updates per modification (that is, excluding cryptographically verified updates per [FPT_TUD_EXT.2](#FPT_TUD_EXT.2)) of the [TSF](#abbr_TSF) data over the [FPT_TUD_EXT.2](#FPT_TUD_EXT.2)) of the [TSF](#abbr_TSF) data over the wired interface in auxiliary boots modes is prevented. The lack of wired interface in auxiliary boots modes is prevented. The lack of publicly available tools is not sufficient justification. Examples of publicly available tools is not sufficient justification. Examples of sufficient justification include auditing of changes, cryptographic sufficient justification include auditing of changes, cryptographic verification in the form of a digital signature or hash, disabling the verification in the form of a digital signature or hash, disabling the auxiliary boot modes, and access control mechanisms that prevent writing auxiliary boot modes, and access control mechanisms that prevent writing to files or flashing partitions.\ to files or flashing partitions.\ \ \ ::: ::: ::: ::: ::: eacategory ::: eacategory Guidance Guidance ::: ::: ::: ea ::: ea ::: ea ::: ea There are no guidance evaluation activities for this component.\ There are no guidance evaluation activities for this component.\ \ \ ::: ::: ::: ::: ::: eacategory ::: eacategory Tests Tests ::: ::: ::: ea ::: ea ::: ea ::: ea **Evaluation Activity Note:** The following tests require the vendor to **Evaluation Activity Note:** The following tests require the vendor to provide access to a test platform that provides the evaluator with tools provide access to a test platform that provides the evaluator with tools that are typically not found on consumer Mobile Device products. In that are typically not found on consumer Mobile Device products. In addition, the vendor provides a list of files (e.g., system files, addition, the vendor provides a list of files (e.g., system files, libraries, configuration files, audit logs) that make up the libraries, configuration files, audit logs) that make up the [TSF](#abbr_TSF) data. This list could be organized by [TSF](#abbr_TSF) data. This list could be organized by folders/directories (e.g., /usr/sbin, /etc), as well as individual files folders/directories (e.g., /usr/sbin, /etc), as well as individual files that may exist outside of the identified directories.\ that may exist outside of the identified directories.\ []{.testlist-} []{.testlist-} - [Test FPT_AEX_EXT.4:1](#_t_58){#_t_58 .defined}: The evaluator shall - [Test FPT_AEX_EXT.4:1](#_t_58){#_t_58 .defined}: The evaluator shall create and load an app onto the Mobile Device. This app shall create and load an app onto the Mobile Device. This app shall attempt to traverse over all file systems and report any locations attempt to traverse over all file systems and report any locations to which data can be written or overwritten. The evaluator shall to which data can be written or overwritten. The evaluator shall ensure that none of these locations are part of the [OS](#abbr_OS) ensure that none of these locations are part of the [OS](#abbr_OS) software, device drivers, system and security configuration files, software, device drivers, system and security configuration files, key material, or another untrusted application's image/data. For key material, or another untrusted application's image/data. For example, it is acceptable for a trusted photo editor app to have example, it is acceptable for a trusted photo editor app to have access to the data created by the camera app, but a calculator access to the data created by the camera app, but a calculator application shall not have access to the pictures. application shall not have access to the pictures. - [Test FPT_AEX_EXT.4:2](#_t_59){#_t_59 .defined}: For each available - [Test FPT_AEX_EXT.4:2](#_t_59){#_t_59 .defined}: For each available auxiliary boot mode, the evaluator shall attempt to modify a auxiliary boot mode, the evaluator shall attempt to modify a [TSF](#abbr_TSF) file of their choosing using the software or [TSF](#abbr_TSF) file of their choosing using the software or hardware tools described in the [TSS](#abbr_TSS). The evaluator hardware tools described in the [TSS](#abbr_TSS). The evaluator shall verify that the modification fails. shall verify that the modification fails. ::: ::: ::: ::: ::: ::: ::: ::: ::: ::: ::: {#FPT_FLS.1 .comp} ::: {#FPT_FLS.1 .comp} #### FPT_FLS.1 Failure with Preservation of Secure State #### FPT_FLS.1 Failure with Preservation of Secure State ::: element ::: element ::: {#FPT_FLS.1.1 .reqid} ::: {#FPT_FLS.1.1 .reqid} [FPT_FLS.1.1](#FPT_FLS.1.1){.abbr} [FPT_FLS.1.1](#FPT_FLS.1.1){.abbr} ::: ::: ::: reqdesc ::: reqdesc The [TSF](#abbr_TSF) shall preserve a secure state when the following The [TSF](#abbr_TSF) shall preserve a secure state when the following types of failures occur: \[*DRBG self-test failure*\]. types of failures occur: \[*DRBG self-test failure*\]. ::: appnote ::: appnote [Application Note: ]{.note-header}[The intent of this requirement is to [Application Note: ]{.note-header}[The intent of this requirement is to ensure that cryptographic services requiring random bit generation ensure that cryptographic services requiring random bit generation cannot be performed if a failure of a self-test defined in cannot be performed if a failure of a self-test defined in [FPT_TST.1](#FPT_TST.1) occurs.]{.note} [FPT_TST.1](#FPT_TST.1) occurs.]{.note} ::: ::: ::: ::: ::: ::: ::: {.activity_pane .hide} ::: {.activity_pane .hide} ::: activity_pane_header ::: activity_pane_header [[ Evaluation Activities [[ Evaluation Activities ]{.activity_pane_label}[]{.toggler}](#){onclick="toggle(this);return false;"} ]{.activity_pane_label}[]{.toggler}](#){onclick="toggle(this);return false;"} ::: ::: ::: activity_pane_body ::: activity_pane_body ::: component-activity-header ::: component-activity-header [FPT_FLS.1](#FPT_FLS.1) [FPT_FLS.1](#FPT_FLS.1) ::: ::: ::: eacategory ::: eacategory [TSS](#abbr_TSS) [TSS](#abbr_TSS) ::: ::: ::: ea ::: ea ::: ea ::: ea The evaluator shall verify that the [TSF](#abbr_TSF) describes how the The evaluator shall verify that the [TSF](#abbr_TSF) describes how the [TOE](#abbr_TOE) enters an error state in the event of a DRBG self-test [TOE](#abbr_TOE) enters an error state in the event of a DRBG self-test failure. failure. ::: ::: ::: ::: ::: eacategory ::: eacategory Guidance Guidance ::: ::: ::: ea ::: ea ::: ea ::: ea The evaluator shall verify that the guidance documentation describes the The evaluator shall verify that the guidance documentation describes the error state that results from a DRBG self-test failure and the actions error state that results from a DRBG self-test failure and the actions that a user or administrator should take in response to attempt to that a user or administrator should take in response to attempt to resolve the error state. resolve the error state. ::: ::: ::: ::: ::: eacategory ::: eacategory Tests Tests ::: ::: ::: ea ::: ea There are no test activities for this component.\ There are no test activities for this component.\ ::: ::: ::: ::: ::: ::: ::: ::: ::: {#FPT_JTA_EXT.1 .comp} ::: {#FPT_JTA_EXT.1 .comp} #### FPT_JTA_EXT.1 JTAG Disablement #### FPT_JTA_EXT.1 JTAG Disablement ::: element ::: element ::: {#FPT_JTA_EXT.1.1 .reqid} ::: {#FPT_JTA_EXT.1.1 .reqid} [FPT_JTA_EXT.1.1](#FPT_JTA_EXT.1.1){.abbr} [FPT_JTA_EXT.1.1](#FPT_JTA_EXT.1.1){.abbr} ::: ::: ::: reqdesc ::: reqdesc The [TSF](#abbr_TSF) shall \[**selection**: [disable access through The [TSF](#abbr_TSF) shall \[**selection**: [disable access through hardware]{#s-jtag-kill-hw .selectable-content}, [control access by a hardware]{#s-jtag-kill-hw .selectable-content}, [control access by a signing key]{#s-jtag-control-key .selectable-content}\] to JTAG. signing key]{#s-jtag-control-key .selectable-content}\] to JTAG. ::: appnote ::: appnote [Application Note: ]{.note-header}[This requirement means that access to [Application Note: ]{.note-header}[This requirement means that access to JTAG must be disabled either through hardware or restricted through the JTAG must be disabled either through hardware or restricted through the use of a signing key.]{.note} use of a signing key.]{.note} ::: ::: ::: ::: ::: ::: ::: {.activity_pane .hide} ::: {.activity_pane .hide} ::: activity_pane_header ::: activity_pane_header [[ Evaluation Activities [[ Evaluation Activities ]{.activity_pane_label}[]{.toggler}](#){onclick="toggle(this);return false;"} ]{.activity_pane_label}[]{.toggler}](#){onclick="toggle(this);return false;"} ::: ::: ::: activity_pane_body ::: activity_pane_body ::: component-activity-header ::: component-activity-header [FPT_JTA_EXT.1](#FPT_JTA_EXT.1) [FPT_JTA_EXT.1](#FPT_JTA_EXT.1) ::: ::: ::: eacategory ::: eacategory [TSS](#abbr_TSS) [TSS](#abbr_TSS) ::: ::: ::: ea ::: ea ::: ea ::: ea If [disable access through hardware](#s-jtag-kill-hw) is selected:\ If [disable access through hardware](#s-jtag-kill-hw) is selected:\ The evaluator shall examine the [TSS](#abbr_TSS) to determine the The evaluator shall examine the [TSS](#abbr_TSS) to determine the location of the JTAG ports on the [TSF](#abbr_TSF), to include the order location of the JTAG ports on the [TSF](#abbr_TSF), to include the order of the ports (i.e., Data In, Data Out, Clock, etc.).\ of the ports (i.e., Data In, Data Out, Clock, etc.).\ \ \ If [control access by a signing key](#s-jtag-control-key) is selected:\ If [control access by a signing key](#s-jtag-control-key) is selected:\ The evaluator shall examine the [TSS](#abbr_TSS) to determine how access The evaluator shall examine the [TSS](#abbr_TSS) to determine how access to the JTAG is controlled by a signing key. The evaluator shall examine to the JTAG is controlled by a signing key. The evaluator shall examine the [TSS](#abbr_TSS) to determine when the JTAG can be accessed, i.e. the [TSS](#abbr_TSS) to determine when the JTAG can be accessed, i.e. what has the access to the signing key.\ what has the access to the signing key.\ \ \ ::: ::: ::: ::: ::: eacategory ::: eacategory Guidance Guidance ::: ::: ::: ea ::: ea ::: ea ::: ea There are no guidance evaluation activities for this component.\ There are no guidance evaluation activities for this component.\ \ \ ::: ::: ::: ::: ::: eacategory ::: eacategory Tests Tests ::: ::: ::: ea ::: ea ::: ea ::: ea **Evaluation Activity Note:** The following test requires the developer **Evaluation Activity Note:** The following test requires the developer to provide access to a test platform that provides the evaluator with to provide access to a test platform that provides the evaluator with chip level access. | chip level access. If [disable access through hardware](#s-jtag-kill-hw) | is selected:\ If [disable access through hardware](#s-jtag-kill-hw) is selected:\ < The evaluator shall connect to the available JTAG port(s) on the device. The evaluator shall connect to the available JTAG port(s) on the device. The evaluator shall query the JTAG port(s) to determine if the The evaluator shall query the JTAG port(s) to determine if the functionality of the JTAG access is available. This could be through the functionality of the JTAG access is available. This could be through the retrieval of information that may only be accessible through the JTAG retrieval of information that may only be accessible through the JTAG interface(s) or by other means that can show the status of the interface interface(s) or by other means that can show the status of the interface to accept commands. to accept commands. ::: ::: ::: ::: ::: ::: ::: ::: ::: ::: ::: {#FPT_KST_EXT.1 .comp} ::: {#FPT_KST_EXT.1 .comp} #### FPT_KST_EXT.1 Key Storage #### FPT_KST_EXT.1 Key Storage ::: element ::: element ::: {#FPT_KST_EXT.1.1 .reqid} ::: {#FPT_KST_EXT.1.1 .reqid} [FPT_KST_EXT.1.1](#FPT_KST_EXT.1.1){.abbr} [FPT_KST_EXT.1.1](#FPT_KST_EXT.1.1){.abbr} ::: ::: ::: reqdesc ::: reqdesc The [TSF](#abbr_TSF) shall not store any plaintext key material in The [TSF](#abbr_TSF) shall not store any plaintext key material in readable non-volatile memory. readable non-volatile memory. ::: appnote ::: appnote [Application Note: ]{.note-header}[The intention of this requirement is | [Application Note: ]{.note-header}[ The intention of this requirement is that the [TOE](#abbr_TOE) will not write plaintext keying material to that the [TOE](#abbr_TOE) will not write plaintext keying material to persistent storage. For the purposes of this requirement, keying persistent storage. For the purposes of this requirement, keying material refers to authentication data, passwords, secret/private material refers to authentication data, passwords, secret/private symmetric keys, private asymmetric keys, data used to derive keys, etc. symmetric keys, private asymmetric keys, data used to derive keys, etc. These values must be stored encrypted.\ These values must be stored encrypted.\ \ \ This requirement also applies to any value derived from passwords. Thus, This requirement also applies to any value derived from passwords. Thus, the [TOE](#abbr_TOE) cannot store plaintext password hashes for the [TOE](#abbr_TOE) cannot store plaintext password hashes for comparison purposes before protected data is decrypted, and the comparison purposes before protected data is decrypted, and the [TOE](#abbr_TOE) should use key derivation and decryption to verify the [TOE](#abbr_TOE) should use key derivation and decryption to verify the Password Authentication Factor.\ Password Authentication Factor.\ \ \ If [hybrid](#uau_hybr) is selected in [FIA_UAU.5.1](#FIA_UAU.5.1) keying If [hybrid](#uau_hybr) is selected in [FIA_UAU.5.1](#FIA_UAU.5.1) keying material also refers to the PIN/password used as part of the hybrid material also refers to the PIN/password used as part of the hybrid authentication. ]{.note} authentication. ]{.note} ::: ::: ::: ::: ::: ::: ::: {.activity_pane .hide} ::: {.activity_pane .hide} ::: activity_pane_header ::: activity_pane_header [[ Evaluation Activities [[ Evaluation Activities ]{.activity_pane_label}[]{.toggler}](#){onclick="toggle(this);return false;"} ]{.activity_pane_label}[]{.toggler}](#){onclick="toggle(this);return false;"} ::: ::: ::: activity_pane_body ::: activity_pane_body ::: component-activity-header ::: component-activity-header [FPT_KST_EXT.1](#FPT_KST_EXT.1) [FPT_KST_EXT.1](#FPT_KST_EXT.1) ::: ::: ::: eacategory ::: eacategory [TSS](#abbr_TSS) [TSS](#abbr_TSS) ::: ::: ::: ea ::: ea ::: ea ::: ea The evaluator shall consult the [TSS](#abbr_TSS) section of the The evaluator shall consult the [TSS](#abbr_TSS) section of the [ST](#abbr_ST) in performing the Evaluation Activities for this [ST](#abbr_ST) in performing the Evaluation Activities for this requirement.\ requirement.\ \ \ In performing their review, the evaluator shall determine that the In performing their review, the evaluator shall determine that the [TSS](#abbr_TSS) contains a description of the activities that happen on [TSS](#abbr_TSS) contains a description of the activities that happen on power-up and password authentication relating to the decryption of | power-up and password authentication relating to the decryption of DEKs, [DEKs](#abbr_DEK), stored keys, and data.\ | stored keys, and data.\ \ \ The evaluator shall ensure that the description also covers how the The evaluator shall ensure that the description also covers how the cryptographic functions in the FCS requirements are being used to cryptographic functions in the FCS requirements are being used to perform the encryption functions, including how the KEKs, | perform the encryption functions, including how the KEKs, DEKs, and [DEKs](#abbr_DEK), and stored keys are unwrapped, saved, and used by the | stored keys are unwrapped, saved, and used by the [TOE](#abbr_TOE) so as [TOE](#abbr_TOE) so as to prevent plaintext from being written to | to prevent plaintext from being written to non-volatile storage. The non-volatile storage. The evaluator shall ensure that the | evaluator shall ensure that the [TSS](#abbr_TSS) describes, for each [TSS](#abbr_TSS) describes, for each power-down scenario how the | power-down scenario how the [TOE](#abbr_TOE) ensures that all keys in [TOE](#abbr_TOE) ensures that all keys in non-volatile storage are not | non-volatile storage are not stored in plaintext.\ stored in plaintext.\ < \ \ The evaluator shall ensure that the [TSS](#abbr_TSS) describes how other The evaluator shall ensure that the [TSS](#abbr_TSS) describes how other functions available in the system (e.g., regeneration of the keys) functions available in the system (e.g., regeneration of the keys) ensure that no unencrypted key material is present in persistent ensure that no unencrypted key material is present in persistent storage.\ storage.\ \ \ The evaluator shall review the [TSS](#abbr_TSS) to determine that it The evaluator shall review the [TSS](#abbr_TSS) to determine that it makes a case that key material is not written unencrypted to the makes a case that key material is not written unencrypted to the persistent storage.\ persistent storage.\ \ \ ::: ::: ::: ::: ::: eacategory ::: eacategory Guidance Guidance ::: ::: ::: ea ::: ea ::: ea ::: ea There are no guidance evaluation activities for this component.\ There are no guidance evaluation activities for this component.\ \ \ ::: ::: ::: ::: ::: eacategory ::: eacategory Tests Tests ::: ::: ::: ea ::: ea ::: ea ::: ea There are no test evaluation activities for this component. There are no test evaluation activities for this component. ::: ::: ::: ::: ::: ::: ::: ::: ::: ::: ::: {#FPT_KST_EXT.2 .comp} ::: {#FPT_KST_EXT.2 .comp} #### FPT_KST_EXT.2 No Key Transmission #### FPT_KST_EXT.2 No Key Transmission ::: element ::: element ::: {#FPT_KST_EXT.2.1 .reqid} ::: {#FPT_KST_EXT.2.1 .reqid} [FPT_KST_EXT.2.1](#FPT_KST_EXT.2.1){.abbr} [FPT_KST_EXT.2.1](#FPT_KST_EXT.2.1){.abbr} ::: ::: ::: reqdesc ::: reqdesc The [TSF](#abbr_TSF) shall not transmit any plaintext key material The [TSF](#abbr_TSF) shall not transmit any plaintext key material outside the security boundary of the [TOE](#abbr_TOE). outside the security boundary of the [TOE](#abbr_TOE). ::: appnote ::: appnote [Application Note: ]{.note-header}[The intention of this requirement is | [Application Note: ]{.note-header}[ The intention of this requirement is to prevent the logging of plaintext key information to a service that to prevent the logging of plaintext key information to a service that transmits the information off-device. For the purposes of this transmits the information off-device. For the purposes of this requirement, key material refers to keys, passwords, and other material requirement, key material refers to keys, passwords, and other material that is used to derive keys.\ that is used to derive keys.\ \ \ If [hybrid](#uau_hybr) is selected in [FIA_UAU.5.1](#FIA_UAU.5.1) keying If [hybrid](#uau_hybr) is selected in [FIA_UAU.5.1](#FIA_UAU.5.1) keying material also refers to the PIN/password used as part of the hybrid material also refers to the PIN/password used as part of the hybrid authentication.\ authentication.\ \ \ In the future, this requirement will apply to symmetric and asymmetric In the future, this requirement will apply to symmetric and asymmetric private keys stored in the [TOE](#abbr_TOE) secure key storage where private keys stored in the [TOE](#abbr_TOE) secure key storage where applications are outside the boundary of the [TOE](#abbr_TOE). Thus, the applications are outside the boundary of the [TOE](#abbr_TOE). Thus, the [TSF](#abbr_TSF) will be required to provide cryptographic key [TSF](#abbr_TSF) will be required to provide cryptographic key operations (signature, encryption, and decryption) on behalf of operations (signature, encryption, and decryption) on behalf of applications ([FCS_SRV_EXT.2.1](#FCS_SRV_EXT.2.1)) that have access to applications ([FCS_SRV_EXT.2.1](#FCS_SRV_EXT.2.1)) that have access to those keys. ]{.note} those keys. ]{.note} ::: ::: ::: ::: ::: ::: ::: {.activity_pane .hide} ::: {.activity_pane .hide} ::: activity_pane_header ::: activity_pane_header [[ Evaluation Activities [[ Evaluation Activities ]{.activity_pane_label}[]{.toggler}](#){onclick="toggle(this);return false;"} ]{.activity_pane_label}[]{.toggler}](#){onclick="toggle(this);return false;"} ::: ::: ::: activity_pane_body ::: activity_pane_body ::: component-activity-header ::: component-activity-header [FPT_KST_EXT.2](#FPT_KST_EXT.2) [FPT_KST_EXT.2](#FPT_KST_EXT.2) ::: ::: ::: eacategory ::: eacategory [TSS](#abbr_TSS) [TSS](#abbr_TSS) ::: ::: ::: ea ::: ea ::: ea ::: ea The evaluator shall consult the [TSS](#abbr_TSS) section of the The evaluator shall consult the [TSS](#abbr_TSS) section of the [ST](#abbr_ST) in performing the Evaluation Activities for this [ST](#abbr_ST) in performing the Evaluation Activities for this requirement. The evaluator shall ensure that the [TSS](#abbr_TSS) requirement. The evaluator shall ensure that the [TSS](#abbr_TSS) describes the [TOE](#abbr_TOE) security boundary. The cryptographic describes the [TOE](#abbr_TOE) security boundary. The cryptographic module may very well be a particular kernel module, the Operating module may very well be a particular kernel module, the Operating System, the Application Processor, or up to the entire Mobile Device.\ System, the Application Processor, or up to the entire Mobile Device.\ \ \ In performing their review, the evaluator shall determine that the In performing their review, the evaluator shall determine that the [TSS](#abbr_TSS) contains a description of the activities that happen on [TSS](#abbr_TSS) contains a description of the activities that happen on power-up and password authentication relating to the decryption of | power-up and password authentication relating to the decryption of DEKs, [DEKs](#abbr_DEK), stored keys, and data.\ | stored keys, and data.\ \ \ The evaluator shall ensure that the [TSS](#abbr_TSS) describes how other The evaluator shall ensure that the [TSS](#abbr_TSS) describes how other functions available in the system (e.g., regeneration of the keys) functions available in the system (e.g., regeneration of the keys) ensure that no unencrypted key material is transmitted outside the ensure that no unencrypted key material is transmitted outside the security boundary of the [TOE](#abbr_TOE).\ security boundary of the [TOE](#abbr_TOE).\ \ \ The evaluator shall review the [TSS](#abbr_TSS) to determine that it The evaluator shall review the [TSS](#abbr_TSS) to determine that it makes a case that key material is not transmitted outside the security makes a case that key material is not transmitted outside the security boundary of the [TOE](#abbr_TOE).\ boundary of the [TOE](#abbr_TOE).\ \ \ ::: ::: ::: ::: ::: eacategory ::: eacategory Guidance Guidance ::: ::: ::: ea ::: ea ::: ea ::: ea There are no guidance evaluation activities for this component.\ There are no guidance evaluation activities for this component.\ \ \ ::: ::: ::: ::: ::: eacategory ::: eacategory Tests Tests ::: ::: ::: ea ::: ea ::: ea ::: ea There are no test evaluation activities for this component. There are no test evaluation activities for this component. ::: ::: ::: ::: ::: ::: ::: ::: ::: ::: ::: {#FPT_KST_EXT.3 .comp} ::: {#FPT_KST_EXT.3 .comp} #### FPT_KST_EXT.3 No Plaintext Key Export #### FPT_KST_EXT.3 No Plaintext Key Export ::: element ::: element ::: {#FPT_KST_EXT.3.1 .reqid} ::: {#FPT_KST_EXT.3.1 .reqid} [FPT_KST_EXT.3.1](#FPT_KST_EXT.3.1){.abbr} [FPT_KST_EXT.3.1](#FPT_KST_EXT.3.1){.abbr} ::: ::: ::: reqdesc ::: reqdesc The [TSF](#abbr_TSF) shall ensure it is not possible for the The [TSF](#abbr_TSF) shall ensure it is not possible for the [TOE](#abbr_TOE) users to export plaintext keys. [TOE](#abbr_TOE) users to export plaintext keys. ::: appnote ::: appnote [Application Note: ]{.note-header}[Plaintext keys include | [Application Note: ]{.note-header}[Plaintext keys include DEKs, KEKs, [DEKs](#abbr_DEK), KEKs, and all keys stored in the secure key storage | and all keys stored in the secure key storage ([FCS_STG_EXT.1](#FCS_STG_EXT.1)). The intent of this requirement is to ([FCS_STG_EXT.1](#FCS_STG_EXT.1)). The intent of this requirement is to prevent the plaintext keys from being exported during a backup prevent the plaintext keys from being exported during a backup authorized by the [TOE](#abbr_TOE) user or administrator.]{.note} authorized by the [TOE](#abbr_TOE) user or administrator.]{.note} ::: ::: ::: ::: ::: ::: ::: {.activity_pane .hide} ::: {.activity_pane .hide} ::: activity_pane_header ::: activity_pane_header [[ Evaluation Activities [[ Evaluation Activities ]{.activity_pane_label}[]{.toggler}](#){onclick="toggle(this);return false;"} ]{.activity_pane_label}[]{.toggler}](#){onclick="toggle(this);return false;"} ::: ::: ::: activity_pane_body ::: activity_pane_body ::: component-activity-header ::: component-activity-header [FPT_KST_EXT.3](#FPT_KST_EXT.3) [FPT_KST_EXT.3](#FPT_KST_EXT.3) ::: ::: ::: eacategory ::: eacategory [TSS](#abbr_TSS) [TSS](#abbr_TSS) ::: ::: ::: ea ::: ea ::: ea ::: ea The [ST](#abbr_ST) author will provide a statement of their policy for The [ST](#abbr_ST) author will provide a statement of their policy for handling and protecting keys. The evaluator shall check to ensure the handling and protecting keys. The evaluator shall check to ensure the [TSS](#abbr_TSS) describes a policy in line with not exporting either [TSS](#abbr_TSS) describes a policy in line with not exporting either plaintext [DEKs](#abbr_DEK), KEKs, or keys stored in the secure key | plaintext DEKs, KEKs, or keys stored in the secure key storage.\ storage.\ < \ \ ::: ::: ::: ::: ::: eacategory ::: eacategory Guidance Guidance ::: ::: ::: ea ::: ea ::: ea ::: ea There are no guidance evaluation activities for this component.\ There are no guidance evaluation activities for this component.\ \ \ ::: ::: ::: ::: ::: eacategory ::: eacategory Tests Tests ::: ::: ::: ea ::: ea ::: ea ::: ea There are no test evaluation activities for this component. There are no test evaluation activities for this component. ::: ::: ::: ::: ::: ::: ::: ::: ::: ::: ::: {#FPT_NOT_EXT.1 .comp} ::: {#FPT_NOT_EXT.1 .comp} #### FPT_NOT_EXT.1 Self-Test Notification #### FPT_NOT_EXT.1 Self-Test Notification ::: element ::: element ::: {#FPT_NOT_EXT.1.1 .reqid} ::: {#FPT_NOT_EXT.1.1 .reqid} [FPT_NOT_EXT.1.1](#FPT_NOT_EXT.1.1){.abbr} [FPT_NOT_EXT.1.1](#FPT_NOT_EXT.1.1){.abbr} ::: ::: ::: reqdesc ::: reqdesc The [TSF](#abbr_TSF) shall transition to non-operational mode and The [TSF](#abbr_TSF) shall transition to non-operational mode and \[**selection**: [log failures in the audit record]{#_s_590 | \[**selection**: [log failures in the audit record]{#fpt_not_ext.1.1_1 .selectable-content}, [notify the administrator]{#_s_591 | .selectable-content}, [notify the administrator]{#fpt_not_ext.1.1_2 .selectable-content}, [\[**assignment**: [other .selectable-content}, [\[**assignment**: [other actions]{.assignable-content}\]]{#_s_592 .selectable-content}, [no other | actions]{.assignable-content}\]]{#fpt_not_ext.1.1_3 actions]{#_s_593 .selectable-content}\] when the following types of | .selectable-content}, [no other actions]{#fpt_not_ext.1.1_5 failures occur: | .selectable-content}\] when the following types of failures occur: - failures of the self-tests - failures of the self-tests - [TSF](#abbr_TSF) software integrity verification failures - [TSF](#abbr_TSF) software integrity verification failures - \[**selection**: [no other failures]{#_s_594 .selectable-content}, | - \[**selection**: [no other failures]{#fpt_not_ext.1.1_6 [\[**assignment**: [other failures]{.assignable-content}\]]{#_s_595 | .selectable-content}, [\[**assignment**: [other > failures]{.assignable-content}\]]{#fpt_not_ext.1.1_7 .selectable-content}\] .selectable-content}\] ::: ::: ::: ::: ::: {.activity_pane .hide} ::: {.activity_pane .hide} ::: activity_pane_header ::: activity_pane_header [[ Evaluation Activities [[ Evaluation Activities ]{.activity_pane_label}[]{.toggler}](#){onclick="toggle(this);return false;"} ]{.activity_pane_label}[]{.toggler}](#){onclick="toggle(this);return false;"} ::: ::: ::: activity_pane_body ::: activity_pane_body ::: component-activity-header ::: component-activity-header [FPT_NOT_EXT.1](#FPT_NOT_EXT.1) [FPT_NOT_EXT.1](#FPT_NOT_EXT.1) ::: ::: ::: eacategory ::: eacategory [TSS](#abbr_TSS) [TSS](#abbr_TSS) ::: ::: ::: ea ::: ea ::: ea ::: ea The evaluator shall verify that the [TSS](#abbr_TSS) describes critical The evaluator shall verify that the [TSS](#abbr_TSS) describes critical failures that may occur and the actions to be taken upon these critical failures that may occur and the actions to be taken upon these critical failures.\ failures.\ \ \ ::: ::: ::: ::: ::: eacategory ::: eacategory Guidance Guidance ::: ::: ::: ea ::: ea ::: ea ::: ea There are no guidance evaluation activities for this component.\ There are no guidance evaluation activities for this component.\ \ \ ::: ::: ::: ::: ::: eacategory ::: eacategory Tests Tests ::: ::: ::: ea ::: ea ::: ea ::: ea **Evaluation Activity Note:** The following test require the developer **Evaluation Activity Note:** The following test require the developer to provide access to a test platform that provides the evaluator with to provide access to a test platform that provides the evaluator with tools that are typically not found on consumer Mobile Device products. tools that are typically not found on consumer Mobile Device products. []{.testlist-} []{.testlist-} - [Test FPT_NOT_EXT.1:1](#_t_63){#_t_63 .defined}: The evaluator shall - [Test FPT_NOT_EXT.1:1](#_t_63){#_t_63 .defined}: The evaluator shall use a tool provided by the developer to modify files and processes use a tool provided by the developer to modify files and processes in the system that correspond to critical failures specified in the in the system that correspond to critical failures specified in the second list. The evaluator shall verify that creating these critical second list. The evaluator shall verify that creating these critical failures causes the device to take the remediation actions specified failures causes the device to take the remediation actions specified in the first list. in the first list. ::: ::: ::: ::: ::: ::: ::: ::: ::: ::: ::: {#FPT_STM.1 .comp} ::: {#FPT_STM.1 .comp} #### FPT_STM.1 Reliable Time Stamps #### FPT_STM.1 Reliable Time Stamps ::: element ::: element ::: {#FPT_STM.1.1 .reqid} ::: {#FPT_STM.1.1 .reqid} [FPT_STM.1.1](#FPT_STM.1.1){.abbr} [FPT_STM.1.1](#FPT_STM.1.1){.abbr} ::: ::: ::: reqdesc ::: reqdesc The [TSF](#abbr_TSF) shall be able to provide reliable time stamps [for | The [TSF](#abbr_TSF) shall be able to provide reliable time stamps **for its own use]{.refinement}. | its own use**. ::: ::: ::: ::: ::: {.activity_pane .hide} ::: {.activity_pane .hide} ::: activity_pane_header ::: activity_pane_header [[ Evaluation Activities [[ Evaluation Activities ]{.activity_pane_label}[]{.toggler}](#){onclick="toggle(this);return false;"} ]{.activity_pane_label}[]{.toggler}](#){onclick="toggle(this);return false;"} ::: ::: ::: activity_pane_body ::: activity_pane_body ::: component-activity-header ::: component-activity-header [FPT_STM.1](#FPT_STM.1) [FPT_STM.1](#FPT_STM.1) ::: ::: ::: eacategory ::: eacategory [TSS](#abbr_TSS) [TSS](#abbr_TSS) ::: ::: ::: ea ::: ea ::: ea ::: ea The evaluator shall examine the [TSS](#abbr_TSS) to ensure that it lists The evaluator shall examine the [TSS](#abbr_TSS) to ensure that it lists each security function that makes use of time. The [TSS](#abbr_TSS) each security function that makes use of time. The [TSS](#abbr_TSS) provides a description of how the time is maintained and considered provides a description of how the time is maintained and considered reliable in the context of each of the time related functions. This reliable in the context of each of the time related functions. This documentation must identify whether the [TSF](#abbr_TSF) uses a documentation must identify whether the [TSF](#abbr_TSF) uses a [NTP](#abbr_NTP) server or the carrier's network time as the primary [NTP](#abbr_NTP) server or the carrier's network time as the primary time sources.\ time sources.\ \ \ ::: ::: ::: ::: ::: eacategory ::: eacategory Guidance Guidance ::: ::: ::: ea ::: ea ::: ea ::: ea The evaluator examines the operational guidance to ensure it describes The evaluator examines the operational guidance to ensure it describes how to set the time.\ how to set the time.\ \ \ ::: ::: ::: ::: ::: eacategory ::: eacategory Tests Tests ::: ::: ::: ea ::: ea ::: ea ::: ea []{.testlist-} []{.testlist-} - [Test FPT_STM.1:1](#_t_66){#_t_66 .defined}: The evaluator uses the - [Test FPT_STM.1:1](#_t_66){#_t_66 .defined}: The evaluator uses the operational guide to set the time. The evaluator shall then use an operational guide to set the time. The evaluator shall then use an available interface to observe that the time was set correctly. available interface to observe that the time was set correctly. ::: ::: ::: ::: ::: ::: ::: ::: ::: ::: ::: {#FPT_TST.1 .comp} ::: {#FPT_TST.1 .comp} #### FPT_TST.1 TSF Self-Testing #### FPT_TST.1 TSF Self-Testing ::: element ::: element ::: {#FPT_TST.1.1 .reqid} ::: {#FPT_TST.1.1 .reqid} [FPT_TST.1.1](#FPT_TST.1.1){.abbr} [FPT_TST.1.1](#FPT_TST.1.1){.abbr} ::: ::: ::: reqdesc ::: reqdesc The [TSF](#abbr_TSF) shall run a suite of the following self-tests The [TSF](#abbr_TSF) shall run a suite of the following self-tests \[*during initial start-up, \[**selection**: [periodically during normal \[*during initial start-up, \[**selection**: [periodically during normal operation]{#_s_602 .selectable-content}, [at the request of the | operation]{#fpt_tst.1.1_1 .selectable-content}, [at the request of the authorized user]{#_s_603 .selectable-content}, [at the conditions | authorized user]{#fpt_tst.1.1_2 .selectable-content}, [at the conditions \[**assignment**: [conditions under which self-test should \[**assignment**: [conditions under which self-test should occur]{.assignable-content}\]]{#_s_604 .selectable-content}, [at no | occur]{.assignable-content}\]]{#fpt_tst.1.1_3 .selectable-content}, [at other time]{#_s_605 .selectable-content}\]*\] to demonstrate the correct | no other time]{#fpt_tst.1.1_5 .selectable-content}\]*\] to demonstrate operation of \[*[TSF](#abbr_TSF) DRBG specified in | the correct operation of \[*[TSF](#abbr_TSF) DRBG specified in [FCS_RBG.1](#FCS_RBG.1)*\]: \[**assignment**: [DRBG health [FCS_RBG.1](#FCS_RBG.1)*\]: \[**assignment**: [DRBG health tests]{.assignable-content}\]. tests]{.assignable-content}\]. ::: ::: ::: ::: ::: element ::: element ::: {#FPT_TST.1.2 .reqid} ::: {#FPT_TST.1.2 .reqid} [FPT_TST.1.2](#FPT_TST.1.2){.abbr} [FPT_TST.1.2](#FPT_TST.1.2){.abbr} ::: ::: ::: reqdesc ::: reqdesc The [TSF](#abbr_TSF) shall provide authorized users with the capability The [TSF](#abbr_TSF) shall provide authorized users with the capability to verify the integrity of \[*\[DRBG seed/output data\]*\]. to verify the integrity of \[*\[DRBG seed/output data\]*\]. ::: ::: ::: ::: ::: element ::: element ::: {#FPT_TST.1.3 .reqid} ::: {#FPT_TST.1.3 .reqid} [FPT_TST.1.3](#FPT_TST.1.3){.abbr} [FPT_TST.1.3](#FPT_TST.1.3){.abbr} ::: ::: ::: reqdesc ::: reqdesc The [TSF](#abbr_TSF) shall provide authorized users with the capability The [TSF](#abbr_TSF) shall provide authorized users with the capability to verify the integrity of \[*\[[TSF](#abbr_TSF) DRBG specified in to verify the integrity of \[*\[[TSF](#abbr_TSF) DRBG specified in [FCS_RBG.1](#FCS_RBG.1)\]*\]. [FCS_RBG.1](#FCS_RBG.1)\]*\]. ::: appnote ::: appnote [Application Note: ]{.note-header}[This [SFR](#abbr_SFR) is a required [Application Note: ]{.note-header}[This [SFR](#abbr_SFR) is a required dependency of [FCS_RBG.1](#FCS_RBG.1). It is intended to require that dependency of [FCS_RBG.1](#FCS_RBG.1). It is intended to require that any DRBG implemented by the [TOE](#abbr_TOE) undergo health testing at any DRBG implemented by the [TOE](#abbr_TOE) undergo health testing at startup (and optionally in other circumstances) to ensure that the startup (and optionally in other circumstances) to ensure that the random bit generation functionality has not been degraded. If the random bit generation functionality has not been degraded. If the [TSF](#abbr_TSF) supports multiple DRBGs, this [SFR](#abbr_SFR) should [TSF](#abbr_TSF) supports multiple DRBGs, this [SFR](#abbr_SFR) should be iterated to describe the self-test behavior for each. The be iterated to describe the self-test behavior for each. The [TSF](#abbr_TSF)\'s response to a DRBG health test failure is addressed [TSF](#abbr_TSF)\'s response to a DRBG health test failure is addressed by [FPT_FLS.1](#FPT_FLS.1).]{.note} by [FPT_FLS.1](#FPT_FLS.1).]{.note} ::: ::: ::: ::: ::: ::: ::: {.activity_pane .hide} ::: {.activity_pane .hide} ::: activity_pane_header ::: activity_pane_header [[ Evaluation Activities [[ Evaluation Activities ]{.activity_pane_label}[]{.toggler}](#){onclick="toggle(this);return false;"} ]{.activity_pane_label}[]{.toggler}](#){onclick="toggle(this);return false;"} ::: ::: ::: activity_pane_body ::: activity_pane_body ::: component-activity-header ::: component-activity-header [FPT_TST.1](#FPT_TST.1) [FPT_TST.1](#FPT_TST.1) ::: ::: ::: eacategory ::: eacategory [TSS](#abbr_TSS) [TSS](#abbr_TSS) ::: ::: ::: ea ::: ea ::: ea ::: ea The evaluator shall examine the [TSS](#abbr_TSS) to ensure that it The evaluator shall examine the [TSS](#abbr_TSS) to ensure that it details the self-tests that are run by the [TSF](#abbr_TSF) along with details the self-tests that are run by the [TSF](#abbr_TSF) along with how they are run. This description should include an outline of what the how they are run. This description should include an outline of what the tests are actually doing. The evaluator shall ensure that the tests are actually doing. The evaluator shall ensure that the [TSS](#abbr_TSS) makes an argument that the tests are sufficient to [TSS](#abbr_TSS) makes an argument that the tests are sufficient to demonstrate that the DRBG is operating correctly. demonstrate that the DRBG is operating correctly. Note that this information may also be placed in the entropy Note that this information may also be placed in the entropy documentation specified by [Appendix E - Entropy Documentation And documentation specified by [Appendix E - Entropy Documentation And Assessment](#entropyappendix){.dynref}. Assessment](#entropyappendix){.dynref}. ::: ::: ::: ::: ::: eacategory ::: eacategory Guidance Guidance ::: ::: ::: ea ::: ea ::: ea ::: ea If a self-test can be executed at the request of an authorized user, the If a self-test can be executed at the request of an authorized user, the evaluator shall verify that the operational guidance provides evaluator shall verify that the operational guidance provides instructions on how to execute that self-test. instructions on how to execute that self-test. ::: ::: ::: ::: ::: eacategory ::: eacategory Tests Tests ::: ::: ::: ea ::: ea ::: ea ::: ea For each self-test, the evaluator shall verify that evidence is produced For each self-test, the evaluator shall verify that evidence is produced that the self-test is executed when specified by that the self-test is executed when specified by [FPT_TST.1.1](#FPT_TST.1.1). | [FPT_TST.1.1](#FPT_TST.1.1). If a self-test can be executed at the | request of an authorized user, the evaluator shall verify that following If a self-test can be executed at the request of an authorized user, the | the steps documented in the operational guidance to perform the evaluator shall verify that following the steps documented in the | self-test will result in execution of the self-test. operational guidance to perform the self-test will result in execution < of the self-test. < ::: ::: ::: ::: ::: ::: ::: ::: ::: ::: ::: {#FPT_TST_EXT.1 .comp} ::: {#FPT_TST_EXT.1 .comp} #### FPT_TST_EXT.1 TSF Cryptographic Functionality Testing #### FPT_TST_EXT.1 TSF Cryptographic Functionality Testing ::: element ::: element ::: {#FPT_TST_EXT.1.1 .reqid} ::: {#FPT_TST_EXT.1.1 .reqid} [FPT_TST_EXT.1.1](#FPT_TST_EXT.1.1){.abbr} [FPT_TST_EXT.1.1](#FPT_TST_EXT.1.1){.abbr} ::: ::: ::: reqdesc ::: reqdesc The [TSF](#abbr_TSF) shall run a suite of self-tests during initial The [TSF](#abbr_TSF) shall run a suite of self-tests during initial start-up (on power on) to demonstrate the correct operation of all start-up (on power on) to demonstrate the correct operation of all cryptographic functionality. cryptographic functionality. ::: appnote ::: appnote [Application Note: ]{.note-header}[ ]{.note} [Application Note: ]{.note-header}[ ]{.note} This requirement may be met by performing known answer tests or This requirement may be met by performing known answer tests or pair-wise consistency tests. The self-tests must be performed before the pair-wise consistency tests. The self-tests must be performed before the cryptographic functionality is exercised (for example, during the cryptographic functionality is exercised (for example, during the initialization of a process that utilizes the functionality). initialization of a process that utilizes the functionality). The cryptographic functionality includes the cryptographic operations in The cryptographic functionality includes the cryptographic operations in FCS_COP and the key generation functions in FCS_CKM. DRBG self-test FCS_COP and the key generation functions in FCS_CKM. DRBG self-test functionality is specifically addressed by [FPT_TST.1](#FPT_TST.1). functionality is specifically addressed by [FPT_TST.1](#FPT_TST.1). The [TSF](#abbr_TSF)\'s response to a self-test failure is addressed by The [TSF](#abbr_TSF)\'s response to a self-test failure is addressed by [FPT_NOT_EXT.1](#FPT_NOT_EXT.1). [FPT_NOT_EXT.1](#FPT_NOT_EXT.1). ::: ::: ::: ::: ::: ::: ::: {.activity_pane .hide} ::: {.activity_pane .hide} ::: activity_pane_header ::: activity_pane_header [[ Evaluation Activities [[ Evaluation Activities ]{.activity_pane_label}[]{.toggler}](#){onclick="toggle(this);return false;"} ]{.activity_pane_label}[]{.toggler}](#){onclick="toggle(this);return false;"} ::: ::: ::: activity_pane_body ::: activity_pane_body ::: component-activity-header ::: component-activity-header [FPT_TST_EXT.1](#FPT_TST_EXT.1) [FPT_TST_EXT.1](#FPT_TST_EXT.1) ::: ::: ::: eacategory ::: eacategory [TSS](#abbr_TSS) [TSS](#abbr_TSS) ::: ::: ::: ea ::: ea ::: ea ::: ea The evaluator shall examine the [TSS](#abbr_TSS) to ensure that it The evaluator shall examine the [TSS](#abbr_TSS) to ensure that it specifies the self-tests that are performed at start-up. This specifies the self-tests that are performed at start-up. This description must include an outline of the test procedures conducted by description must include an outline of the test procedures conducted by the [TSF](#abbr_TSF) (e.g., rather than saying \"memory is tested\", a the [TSF](#abbr_TSF) (e.g., rather than saying \"memory is tested\", a description similar to \"memory is tested by writing a value to each description similar to \"memory is tested by writing a value to each memory location and reading it back to ensure it is identical to what memory location and reading it back to ensure it is identical to what was written\" shall be used). The [TSS](#abbr_TSS) must include any was written\" shall be used). The [TSS](#abbr_TSS) must include any error states that the [TSF](#abbr_TSF) may enter when self-tests fail, error states that the [TSF](#abbr_TSF) may enter when self-tests fail, and the conditions and actions necessary to exit the error states and and the conditions and actions necessary to exit the error states and resume normal operation. The evaluator shall verify that the resume normal operation. The evaluator shall verify that the [TSS](#abbr_TSS) indicates these self-tests are run at start-up [TSS](#abbr_TSS) indicates these self-tests are run at start-up automatically, and do not involve any inputs from or actions by the user automatically, and do not involve any inputs from or actions by the user or operator.\ or operator.\ \ \ The evaluator shall inspect the list of self-tests in the The evaluator shall inspect the list of self-tests in the [TSS](#abbr_TSS) and verify that it includes algorithm self-tests. The [TSS](#abbr_TSS) and verify that it includes algorithm self-tests. The algorithm self-tests will typically be conducted using known answer algorithm self-tests will typically be conducted using known answer tests.\ tests.\ \ \ ::: ::: ::: ::: ::: eacategory ::: eacategory Guidance Guidance ::: ::: ::: ea ::: ea ::: ea ::: ea There are no guidance evaluation activities for this component.\ There are no guidance evaluation activities for this component.\ \ \ ::: ::: ::: ::: ::: eacategory ::: eacategory Tests Tests ::: ::: ::: ea ::: ea ::: ea ::: ea There are no test evaluation activities for this component. There are no test evaluation activities for this component. ::: ::: ::: ::: ::: ::: ::: ::: ::: ::: ::: {#FPT_TST_EXT.2/PREKERNEL .comp} ::: {#FPT_TST_EXT.2/PREKERNEL .comp} #### FPT_TST_EXT.2/PREKERNEL TSF Integrity Checking (Pre-Kernel) #### FPT_TST_EXT.2/PREKERNEL TSF Integrity Checking (Pre-Kernel) ::: element ::: element ::: {#FPT_TST_EXT.2.1/PREKERNEL .reqid} ::: {#FPT_TST_EXT.2.1/PREKERNEL .reqid} [FPT_TST_EXT.2.1/PREKERNEL](#FPT_TST_EXT.2.1/PREKERNEL){.abbr} [FPT_TST_EXT.2.1/PREKERNEL](#FPT_TST_EXT.2.1/PREKERNEL){.abbr} ::: ::: ::: reqdesc ::: reqdesc The [TSF](#abbr_TSF) shall verify the integrity of \[*the bootchain up The [TSF](#abbr_TSF) shall verify the integrity of \[*the bootchain up through the Application Processor [OS](#abbr_OS) kernel*\] stored in through the Application Processor [OS](#abbr_OS) kernel*\] stored in mutable media prior to its execution through the use of \[**selection**: mutable media prior to its execution through the use of \[**selection**: [a digital signature using an immutable hardware asymmetric key]{#_s_610 | [a digital signature using an immutable hardware asymmetric .selectable-content}, [an immutable hardware hash of an asymmetric | key]{#fpt_tst_ext.2.1_PREKERNEL_1 .selectable-content}, [an immutable key]{#_s_611 .selectable-content}, [an immutable hardware hash]{#_s_612 | hardware hash of an asymmetric key]{#fpt_tst_ext.2.1_PREKERNEL_2 .selectable-content}, [a digital signature using a hardware-protected | .selectable-content}, [an immutable hardware asymmetric key]{#_s_613 .selectable-content}\]. | hash]{#fpt_tst_ext.2.1_PREKERNEL_3 .selectable-content}, [a digital | signature using a hardware-protected asymmetric ::: appnote | key]{#fpt_tst_ext.2.1_PREKERNEL_4 .selectable-content}\]. [Application Note: ]{.note-header}[The bootchain of the [TSF](#abbr_TSF) | is the sequence of firmware and software, including [ROM](#abbr_ROM), | ::: appnote bootloaders, and kernel, which ultimately result in loading the kernel | [Application Note: ]{.note-header}[ The bootchain of the on the Application Processor, regardless of which processor executes | [TSF](#abbr_TSF) is the sequence of firmware and software, including that code. Executable code that would be loaded after the kernel is | [ROM](#abbr_ROM), bootloaders, and kernel, which ultimately result in covered in [FPT_TST_EXT.2/POSTKERNEL](#FPT_TST_EXT.2/POSTKERNEL).\ | loading the kernel on the Application Processor, regardless of which > processor executes that code. Executable code that would be loaded after > the kernel is covered in > [FPT_TST_EXT.2/POSTKERNEL](#FPT_TST_EXT.2/POSTKERNEL).\ \ \ In order to meet this requirement, the hardware protection may be In order to meet this requirement, the hardware protection may be transitive in nature: a hardware-protected public key, hash of an transitive in nature: a hardware-protected public key, hash of an asymmetric key, or hash may be used to verify the mutable bootloader asymmetric key, or hash may be used to verify the mutable bootloader code which contains a key or hash used by the bootloader to verify the code which contains a key or hash used by the bootloader to verify the mutable [OS](#abbr_OS) kernel code, which contains a key or hash to mutable [OS](#abbr_OS) kernel code, which contains a key or hash to verify the next layer of executable code, and so on.\ verify the next layer of executable code, and so on.\ \ \ The cryptographic mechanism used to verify the (initial) mutable The cryptographic mechanism used to verify the (initial) mutable executable code must be protected, such as being implemented in hardware executable code must be protected, such as being implemented in hardware or in read-only memory ([ROM](#abbr_ROM)). ]{.note} or in read-only memory ([ROM](#abbr_ROM)). ]{.note} ::: ::: ::: ::: ::: ::: ::: {.activity_pane .hide} ::: {.activity_pane .hide} ::: activity_pane_header ::: activity_pane_header [[ Evaluation Activities [[ Evaluation Activities ]{.activity_pane_label}[]{.toggler}](#){onclick="toggle(this);return false;"} ]{.activity_pane_label}[]{.toggler}](#){onclick="toggle(this);return false;"} ::: ::: ::: activity_pane_body ::: activity_pane_body ::: component-activity-header ::: component-activity-header [FPT_TST_EXT.2/PREKERNEL](#FPT_TST_EXT.2/PREKERNEL) [FPT_TST_EXT.2/PREKERNEL](#FPT_TST_EXT.2/PREKERNEL) ::: ::: ::: eacategory ::: eacategory [TSS](#abbr_TSS) [TSS](#abbr_TSS) ::: ::: ::: ea ::: ea ::: ea ::: ea The evaluator shall verify that the [TSS](#abbr_TSS) section of the The evaluator shall verify that the [TSS](#abbr_TSS) section of the [ST](#abbr_ST) includes a description of the boot procedures, including [ST](#abbr_ST) includes a description of the boot procedures, including a description of the entire bootchain, of the software for the a description of the entire bootchain, of the software for the [TSF](#abbr_TSF)'s Application Processor. The evaluator shall ensure [TSF](#abbr_TSF)'s Application Processor. The evaluator shall ensure that before loading the bootloaders for the operating system and the that before loading the bootloaders for the operating system and the kernel, all bootloaders and the kernel software itself is kernel, all bootloaders and the kernel software itself is cryptographically verified. For each additional category of executable cryptographically verified. For each additional category of executable code verified before execution, the evaluator shall verify that the code verified before execution, the evaluator shall verify that the description in the [TSS](#abbr_TSS) describes how that software is description in the [TSS](#abbr_TSS) describes how that software is cryptographically verified.\ cryptographically verified.\ \ \ The evaluator shall verify that the [TSS](#abbr_TSS) contains a The evaluator shall verify that the [TSS](#abbr_TSS) contains a justification for the protection of the cryptographic key or hash, justification for the protection of the cryptographic key or hash, preventing it from being modified by unverified or unauthenticated preventing it from being modified by unverified or unauthenticated software. The evaluator shall verify that the [TSS](#abbr_TSS) contains software. The evaluator shall verify that the [TSS](#abbr_TSS) contains a description of the protection afforded to the mechanism performing the a description of the protection afforded to the mechanism performing the cryptographic verification.\ cryptographic verification.\ \ \ The evaluator shall verify that the [TSS](#abbr_TSS) describes each The evaluator shall verify that the [TSS](#abbr_TSS) describes each auxiliary boot mode available on the [TOE](#abbr_TOE) during the boot auxiliary boot mode available on the [TOE](#abbr_TOE) during the boot procedures. The evaluator shall verify that, for each auxiliary boot procedures. The evaluator shall verify that, for each auxiliary boot mode, a description of the cryptographic integrity of the executed code mode, a description of the cryptographic integrity of the executed code through the kernel is verified before each execution.\ through the kernel is verified before each execution.\ \ \ ::: ::: ::: ::: ::: eacategory ::: eacategory Guidance Guidance ::: ::: ::: ea ::: ea ::: ea ::: ea There are no guidance evaluation activities for this component.\ There are no guidance evaluation activities for this component.\ \ \ ::: ::: ::: ::: ::: eacategory ::: eacategory Tests Tests ::: ::: ::: ea ::: ea ::: ea ::: ea **Evaluation Activity Note:** The following tests require the vendor to **Evaluation Activity Note:** The following tests require the vendor to provide access to a test platform that provides the evaluator with tools provide access to a test platform that provides the evaluator with tools that are typically not found on consumer Mobile Device products.\ that are typically not found on consumer Mobile Device products.\ \ \ The evaluator shall perform the following tests: []{.testlist-} The evaluator shall perform the following tests: []{.testlist-} - [Test FPT_TST_EXT.2/PREKERNEL:1](#_t_67){#_t_67 .defined}: The - [Test FPT_TST_EXT.2/PREKERNEL:1](#_t_67){#_t_67 .defined}: The evaluator shall perform actions to cause [TSF](#abbr_TSF) software evaluator shall perform actions to cause [TSF](#abbr_TSF) software to load and observe that the integrity mechanism does not flag any to load and observe that the integrity mechanism does not flag any executables as containing integrity errors and that the executables as containing integrity errors and that the [TOE](#abbr_TOE) properly boots. [TOE](#abbr_TOE) properly boots. - [Test FPT_TST_EXT.2/PREKERNEL:2](#_t_68){#_t_68 .defined}: The - [Test FPT_TST_EXT.2/PREKERNEL:2](#_t_68){#_t_68 .defined}: The evaluator shall modify a [TSF](#abbr_TSF) executable that is evaluator shall modify a [TSF](#abbr_TSF) executable that is integrity protected and cause that executable to be successfully integrity protected and cause that executable to be successfully loaded by the [TSF](#abbr_TSF). The evaluator observes that an loaded by the [TSF](#abbr_TSF). The evaluator observes that an integrity violation is triggered and the [TOE](#abbr_TOE) does not integrity violation is triggered and the [TOE](#abbr_TOE) does not boot. (Care must be taken so that the integrity violation is boot. (Care must be taken so that the integrity violation is determined to be the cause of the failure to load the module, and determined to be the cause of the failure to load the module, and not the fact that the module was modified so that it was rendered not the fact that the module was modified so that it was rendered unable to run because its format was corrupt). unable to run because its format was corrupt). - [Test FPT_TST_EXT.2/PREKERNEL:3](#_t_69){#_t_69 .defined}: - [Test FPT_TST_EXT.2/PREKERNEL:3](#_t_69){#_t_69 .defined}: \[conditional\] If the [ST](#abbr_ST) author indicates that the \[conditional\] If the [ST](#abbr_ST) author indicates that the integrity verification is performed using a public key, the integrity verification is performed using a public key, the evaluator shall verify that the update mechanism includes a evaluator shall verify that the update mechanism includes a certificate validation according to FIA_X509_EXT.1 as defined in the certificate validation according to FIA_X509_EXT.1 as defined in the [Functional Package for X.509, version [Functional Package for X.509, version 1.0](https://www.niap-ccevs.org/protectionprofiles/511). The 1.0](https://www.niap-ccevs.org/protectionprofiles/511). The evaluator shall digitally sign the [TSF](#abbr_TSF) executable with evaluator shall digitally sign the [TSF](#abbr_TSF) executable with a certificate that does not have the Code Signing purpose in the a certificate that does not have the Code Signing purpose in the extendedKeyUsage field and verify that an integrity violation is extendedKeyUsage field and verify that an integrity violation is triggered. The evaluator shall repeat the test using a certificate triggered. The evaluator shall repeat the test using a certificate that contains the Code Signing purpose and verify that the integrity that contains the Code Signing purpose and verify that the integrity verification succeeds. Ideally, the two certificates should be verification succeeds. Ideally, the two certificates should be identical except for the extendedKeyUsage field. identical except for the extendedKeyUsage field. ::: ::: ::: ::: ::: ::: ::: ::: ::: ::: ::: {#FPT_TUD_EXT.1 .comp} ::: {#FPT_TUD_EXT.1 .comp} #### FPT_TUD_EXT.1 TSF Version Query #### FPT_TUD_EXT.1 TSF Version Query ::: element ::: element ::: {#FPT_TUD_EXT.1.1 .reqid} ::: {#FPT_TUD_EXT.1.1 .reqid} [FPT_TUD_EXT.1.1](#FPT_TUD_EXT.1.1){.abbr} [FPT_TUD_EXT.1.1](#FPT_TUD_EXT.1.1){.abbr} ::: ::: ::: reqdesc ::: reqdesc The [TSF](#abbr_TSF) shall provide authorized users the ability to query The [TSF](#abbr_TSF) shall provide authorized users the ability to query the current version of the [TOE](#abbr_TOE) firmware/software. the current version of the [TOE](#abbr_TOE) firmware/software. ::: ::: ::: ::: ::: element ::: element ::: {#FPT_TUD_EXT.1.2 .reqid} ::: {#FPT_TUD_EXT.1.2 .reqid} [FPT_TUD_EXT.1.2](#FPT_TUD_EXT.1.2){.abbr} [FPT_TUD_EXT.1.2](#FPT_TUD_EXT.1.2){.abbr} ::: ::: ::: reqdesc ::: reqdesc The [TSF](#abbr_TSF) shall provide authorized users the ability to query The [TSF](#abbr_TSF) shall provide authorized users the ability to query the current version of the hardware model of the device. the current version of the hardware model of the device. ::: appnote ::: appnote [Application Note: ]{.note-header}[The current version of the hardware [Application Note: ]{.note-header}[The current version of the hardware model of the device is an identifier that is sufficient to indicate (in model of the device is an identifier that is sufficient to indicate (in tandem with manufacturer documentation) the hardware which comprises the tandem with manufacturer documentation) the hardware which comprises the device.]{.note} device.]{.note} ::: ::: ::: ::: ::: ::: ::: element ::: element ::: {#FPT_TUD_EXT.1.3 .reqid} ::: {#FPT_TUD_EXT.1.3 .reqid} [FPT_TUD_EXT.1.3](#FPT_TUD_EXT.1.3){.abbr} [FPT_TUD_EXT.1.3](#FPT_TUD_EXT.1.3){.abbr} ::: ::: ::: reqdesc ::: reqdesc The [TSF](#abbr_TSF) shall provide authorized users the ability to query The [TSF](#abbr_TSF) shall provide authorized users the ability to query the current version of installed mobile applications. the current version of installed mobile applications. ::: appnote ::: appnote [Application Note: ]{.note-header}[The current version of mobile [Application Note: ]{.note-header}[The current version of mobile applications is the name and published version number of each installed applications is the name and published version number of each installed mobile application.]{.note} mobile application.]{.note} ::: ::: ::: ::: ::: ::: ::: {.activity_pane .hide} ::: {.activity_pane .hide} ::: activity_pane_header ::: activity_pane_header [[ Evaluation Activities [[ Evaluation Activities ]{.activity_pane_label}[]{.toggler}](#){onclick="toggle(this);return false;"} ]{.activity_pane_label}[]{.toggler}](#){onclick="toggle(this);return false;"} ::: ::: ::: activity_pane_body ::: activity_pane_body ::: component-activity-header ::: component-activity-header [FPT_TUD_EXT.1](#FPT_TUD_EXT.1) [FPT_TUD_EXT.1](#FPT_TUD_EXT.1) ::: ::: The evaluator shall establish a test environment consisting of the The evaluator shall establish a test environment consisting of the Mobile Device and any supporting software that demonstrates usage of the Mobile Device and any supporting software that demonstrates usage of the management functions. This can be test software from the developer, a management functions. This can be test software from the developer, a reference implementation of management software from the developer, or reference implementation of management software from the developer, or other commercially available software. The evaluator shall set up the other commercially available software. The evaluator shall set up the Mobile Device and the other software to exercise the management Mobile Device and the other software to exercise the management functions according to the provided guidance documentation.\ functions according to the provided guidance documentation.\ \ \ ::: eacategory ::: eacategory [TSS](#abbr_TSS) [TSS](#abbr_TSS) ::: ::: ::: ea ::: ea ::: ea ::: ea There are no [TSS](#abbr_TSS) evaluation activities for this component.\ There are no [TSS](#abbr_TSS) evaluation activities for this component.\ \ \ ::: ::: ::: ::: ::: eacategory ::: eacategory Guidance Guidance ::: ::: ::: ea ::: ea ::: ea ::: ea There are no guidance evaluation activities for this component.\ There are no guidance evaluation activities for this component.\ \ \ ::: ::: ::: ::: ::: eacategory ::: eacategory Tests Tests ::: ::: ::: ea ::: ea ::: ea ::: ea []{.testlist-} []{.testlist-} - [Test FPT_TUD_EXT.1:1](#_t_70){#_t_70 .defined}: Using the AGD - [Test FPT_TUD_EXT.1:1](#_t_70){#_t_70 .defined}: Using the AGD guidance provided, the evaluator shall test that the administrator guidance provided, the evaluator shall test that the administrator and user can query: and user can query: - The current version of the [TSF](#abbr_TSF) operating system and - The current version of the [TSF](#abbr_TSF) operating system and any firmware that can be updated separately any firmware that can be updated separately - The hardware model of the [TSF](#abbr_TSF) - The hardware model of the [TSF](#abbr_TSF) - The current version of all installed mobile applications - The current version of all installed mobile applications The evaluator shall review manufacturer documentation to ensure that The evaluator shall review manufacturer documentation to ensure that the hardware model identifier is sufficient to identify the hardware the hardware model identifier is sufficient to identify the hardware which comprises the device. which comprises the device. ::: ::: ::: ::: ::: ::: ::: ::: ::: ::: ::: {#FPT_TUD_EXT.2 .comp} ::: {#FPT_TUD_EXT.2 .comp} #### FPT_TUD_EXT.2 TSF Update Verification #### FPT_TUD_EXT.2 TSF Update Verification ::: element ::: element ::: {#FPT_TUD_EXT.2.1 .reqid} ::: {#FPT_TUD_EXT.2.1 .reqid} [FPT_TUD_EXT.2.1](#FPT_TUD_EXT.2.1){.abbr} [FPT_TUD_EXT.2.1](#FPT_TUD_EXT.2.1){.abbr} ::: ::: ::: reqdesc ::: reqdesc The [TSF](#abbr_TSF) shall verify software updates to the Application The [TSF](#abbr_TSF) shall verify software updates to the Application Processor system software and \[**selection**: [\[**assignment**: [other Processor system software and \[**selection**: [\[**assignment**: [other processor system software]{.assignable-content}\]]{#_s_629 | processor system software]{.assignable-content}\]]{#fpt_tud_ext.2.1_1 .selectable-content}, [no other processor system software]{#_s_630 | .selectable-content}, [no other processor system .selectable-content}\] using a digital signature verified by the | software]{#fpt_tud_ext.2.1_3 .selectable-content}\] using a digital manufacturer trusted key prior to installing those updates. | signature verified by the manufacturer trusted key prior to installing > those updates. ::: appnote ::: appnote [Application Note: ]{.note-header}[ ]{.note} [Application Note: ]{.note-header}[ ]{.note} The digital signature mechanism is implemented in accordance with The digital signature mechanism is implemented in accordance with [FCS_COP.1.1/SigVer](#FCS_COP.1.1/SigVer). [FCS_COP.1.1/SigVer](#FCS_COP.1.1/SigVer). At this time, this requirement does not require verification of software At this time, this requirement does not require verification of software updates to the software operating outside the Application Processor. updates to the software operating outside the Application Processor. Any change, via a supported mechanism, to software residing in Any change, via a supported mechanism, to software residing in non-volatile storage is deemed a software update. Thus, this requirement non-volatile storage is deemed a software update. Thus, this requirement applies to [TSF](#abbr_TSF) software updates regardless of how the applies to [TSF](#abbr_TSF) software updates regardless of how the software arrives or is delivered to the device. This includes software arrives or is delivered to the device. This includes over-the-air ([OTA](#abbr_OTA)) updates as well as partition images over-the-air ([OTA](#abbr_OTA)) updates as well as partition images containing software which may be delivered to the device over a wired containing software which may be delivered to the device over a wired interface. interface. ::: ::: ::: ::: ::: ::: ::: element ::: element ::: {#FPT_TUD_EXT.2.2 .reqid} ::: {#FPT_TUD_EXT.2.2 .reqid} [FPT_TUD_EXT.2.2](#FPT_TUD_EXT.2.2){.abbr} [FPT_TUD_EXT.2.2](#FPT_TUD_EXT.2.2){.abbr} ::: ::: ::: reqdesc ::: reqdesc The [TSF](#abbr_TSF) shall \[**selection**: [never update]{#_s_631 | The [TSF](#abbr_TSF) shall \[**selection**: [never .selectable-content}, [update only by verified software]{#_s_632 | update]{#fpt_tud_ext.2.2_1 .selectable-content}, [update only by .selectable-content}\] the [TSF](#abbr_TSF) boot integrity | verified software]{#fpt_tud_ext.2.2_2 .selectable-content}\] the \[**selection**: [key]{#_s_633 .selectable-content}, [hash]{#_s_634 | [TSF](#abbr_TSF) boot integrity \[**selection**: > [key]{#fpt_tud_ext.2.2_3 .selectable-content}, [hash]{#fpt_tud_ext.2.2_4 .selectable-content}\]. .selectable-content}\]. ::: appnote ::: appnote [Application Note: ]{.note-header}[The key or hash updated via this [Application Note: ]{.note-header}[The key or hash updated via this requirement is used for verifying software before execution in requirement is used for verifying software before execution in [FPT_TST_EXT.2/PREKERNEL](#FPT_TST_EXT.2/PREKERNEL). The key or hash is [FPT_TST_EXT.2/PREKERNEL](#FPT_TST_EXT.2/PREKERNEL). The key or hash is verified as a part of the digital signature on an update, and the verified as a part of the digital signature on an update, and the software which performs the update of the key or hash is verified by software which performs the update of the key or hash is verified by [FPT_TST_EXT.2/PREKERNEL](#FPT_TST_EXT.2/PREKERNEL). ]{.note} | [FPT_TST_EXT.2/PREKERNEL](#FPT_TST_EXT.2/PREKERNEL).]{.note} ::: ::: ::: ::: ::: ::: ::: element ::: element ::: {#FPT_TUD_EXT.2.3 .reqid} ::: {#FPT_TUD_EXT.2.3 .reqid} [FPT_TUD_EXT.2.3](#FPT_TUD_EXT.2.3){.abbr} [FPT_TUD_EXT.2.3](#FPT_TUD_EXT.2.3){.abbr} ::: ::: ::: reqdesc ::: reqdesc The [TSF](#abbr_TSF) shall verify that the digital signature The [TSF](#abbr_TSF) shall verify that the digital signature verification key used for [TSF](#abbr_TSF) updates \[**selection**: [is verification key used for [TSF](#abbr_TSF) updates \[**selection**: [is validated to a public key in the Trust Anchor Database]{#_s_635 | validated to a public key in the Trust Anchor .selectable-content}, [matches an immutable hardware public key]{#_s_636 | Database]{#fpt_tud_ext.2.3_1 .selectable-content}, [matches an immutable .selectable-content}\]. | hardware public key]{#fpt_tud_ext.2.3_2 .selectable-content}\]. ::: appnote ::: appnote [Application Note: ]{.note-header}[The [ST](#abbr_ST) author must | [Application Note: ]{.note-header}[ The [ST](#abbr_ST) author must indicate the method by which the signing key for system software updates indicate the method by which the signing key for system software updates is limited and, if selected in [FPT_TUD_EXT.2.3](#FPT_TUD_EXT.2.3), must is limited and, if selected in [FPT_TUD_EXT.2.3](#FPT_TUD_EXT.2.3), must indicate how this signing key is protected by the hardware.\ indicate how this signing key is protected by the hardware.\ \ \ If certificates are used, certificates are validated for the purpose of If certificates are used, certificates are validated for the purpose of software updates in accordance with FIA_X509_EXT.1 as defined in the software updates in accordance with FIA_X509_EXT.1 as defined in the [Functional Package for X.509, version [Functional Package for X.509, version 1.0](https://www.niap-ccevs.org/protectionprofiles/511) and should be 1.0](https://www.niap-ccevs.org/protectionprofiles/511) and should be selected in FIA_X509_EXT.2.1 as defined in the [Functional Package for selected in FIA_X509_EXT.2.1 as defined in the [Functional Package for X.509, version 1.0](https://www.niap-ccevs.org/protectionprofiles/511). X.509, version 1.0](https://www.niap-ccevs.org/protectionprofiles/511). Additionally, [FPT_TUD_EXT.4](#FPT_TUD_EXT.4) must be included in the Additionally, [FPT_TUD_EXT.4](#FPT_TUD_EXT.4) must be included in the [ST](#abbr_ST). ]{.note} [ST](#abbr_ST). ]{.note} ::: ::: ::: ::: ::: ::: ::: {.activity_pane .hide} ::: {.activity_pane .hide} ::: activity_pane_header ::: activity_pane_header [[ Evaluation Activities [[ Evaluation Activities ]{.activity_pane_label}[]{.toggler}](#){onclick="toggle(this);return false;"} ]{.activity_pane_label}[]{.toggler}](#){onclick="toggle(this);return false;"} ::: ::: ::: activity_pane_body ::: activity_pane_body ::: component-activity-header ::: component-activity-header [FPT_TUD_EXT.2](#FPT_TUD_EXT.2) [FPT_TUD_EXT.2](#FPT_TUD_EXT.2) ::: ::: ::: eacategory ::: eacategory [TSS](#abbr_TSS) [TSS](#abbr_TSS) ::: ::: ::: ea ::: ea ::: ea ::: ea The evaluator shall verify that the [TSS](#abbr_TSS) section of the The evaluator shall verify that the [TSS](#abbr_TSS) section of the [ST](#abbr_ST) describes all [TSF](#abbr_TSF) software update mechanisms [ST](#abbr_ST) describes all [TSF](#abbr_TSF) software update mechanisms for updating the system software. The evaluator shall verify that the for updating the system software. The evaluator shall verify that the description includes a digital signature verification of the software description includes a digital signature verification of the software before installation and that installation fails if the verification before installation and that installation fails if the verification fails. The evaluator shall verify that all software and firmware fails. The evaluator shall verify that all software and firmware involved in updating the [TSF](#abbr_TSF) is described and, if multiple involved in updating the [TSF](#abbr_TSF) is described and, if multiple stages and software are indicated, that the software/firmware stages and software are indicated, that the software/firmware responsible for each stage is indicated and that the stages which responsible for each stage is indicated and that the stages which perform signature verification of the update are identified.\ perform signature verification of the update are identified.\ \ \ The evaluator shall verify that the [TSS](#abbr_TSS) describes the The evaluator shall verify that the [TSS](#abbr_TSS) describes the method by which the digital signature is verified and that the public method by which the digital signature is verified and that the public key used to verify the signature is either hardware-protected or is key used to verify the signature is either hardware-protected or is validated to chain to a public key in the Trust Anchor Database. If validated to chain to a public key in the Trust Anchor Database. If hardware-protection is selected, the evaluator shall verify that the hardware-protection is selected, the evaluator shall verify that the method of hardware-protection is described and that the [ST](#abbr_ST) method of hardware-protection is described and that the [ST](#abbr_ST) author has justified why the public key may not be modified by author has justified why the public key may not be modified by unauthorized parties.\ unauthorized parties.\ \ \ \[conditional\] If the [ST](#abbr_ST) author indicates that software \[conditional\] If the [ST](#abbr_ST) author indicates that software updates to system software running on other processors is verified, the updates to system software running on other processors is verified, the evaluator shall verify that these other processors are listed in the evaluator shall verify that these other processors are listed in the [TSS](#abbr_TSS) and that the description includes the software update [TSS](#abbr_TSS) and that the description includes the software update mechanism for these processors, if different than the update mechanism mechanism for these processors, if different than the update mechanism for the software executing on the Application Processor.\ for the software executing on the Application Processor.\ \ \ \[conditional\] If the [ST](#abbr_ST) author indicates that the public \[conditional\] If the [ST](#abbr_ST) author indicates that the public key is used for software update digital signature verification, the key is used for software update digital signature verification, the evaluator shall verify that the update mechanism includes a certificate evaluator shall verify that the update mechanism includes a certificate validation according to FIA_X509_EXT.1 as defined in the [Functional validation according to FIA_X509_EXT.1 as defined in the [Functional Package for X.509, version Package for X.509, version 1.0](https://www.niap-ccevs.org/protectionprofiles/511) and a check for 1.0](https://www.niap-ccevs.org/protectionprofiles/511) and a check for the Code Signing purpose in the extendedKeyUsage.\ the Code Signing purpose in the extendedKeyUsage.\ \ \ ::: ::: ::: ::: ::: eacategory ::: eacategory Guidance Guidance ::: ::: ::: ea ::: ea ::: ea ::: ea There are no guidance evaluation activities for this component.\ There are no guidance evaluation activities for this component.\ \ \ ::: ::: ::: ::: ::: eacategory ::: eacategory Tests Tests ::: ::: ::: ea ::: ea ::: ea ::: ea The evaluator shall verify that the developer has provided evidence that The evaluator shall verify that the developer has provided evidence that the following tests were performed for each available update mechanism: the following tests were performed for each available update mechanism: []{.testlist-} []{.testlist-} - [Test FPT_TUD_EXT.2:1](#_t_71){#_t_71 .defined}: The tester shall - [Test FPT_TUD_EXT.2:1](#_t_71){#_t_71 .defined}: The tester shall try to install an update without the digital signature and shall try to install an update without the digital signature and shall verify that installation fails. The tester shall attempt to install verify that installation fails. The tester shall attempt to install an update with digital signature, and verify that installation an update with digital signature, and verify that installation succeeds.\ | succeeds. - [Test FPT_TUD_EXT.2:2](#_t_72){#_t_72 .defined}: The tester shall - [Test FPT_TUD_EXT.2:2](#_t_72){#_t_72 .defined}: The tester shall digitally sign the update with a key disallowed by the device and digitally sign the update with a key disallowed by the device and verify that installation fails. The tester shall attempt to install verify that installation fails. The tester shall attempt to install an update signed with the allowed key and verify that installation an update signed with the allowed key and verify that installation succeeds.\ | succeeds. - [Test FPT_TUD_EXT.2:3](#_t_73){#_t_73 .defined}: \[conditional\] The - [Test FPT_TUD_EXT.2:3](#_t_73){#_t_73 .defined}: \[conditional\] The tester shall digitally sign the update with an invalid certificate tester shall digitally sign the update with an invalid certificate and verify that update installation fails. The tester attempt to and verify that update installation fails. The tester attempt to install an update that was digitally signed using a valid install an update that was digitally signed using a valid certificate and a certificate that contains the purpose and verify certificate and a certificate that contains the purpose and verify that the update installation succeeds.\ | that the update installation succeeds. - [Test FPT_TUD_EXT.2:4](#_t_74){#_t_74 .defined}: \[conditional\] The - [Test FPT_TUD_EXT.2:4](#_t_74){#_t_74 .defined}: \[conditional\] The tester shall repeat these test for the software executing on each tester shall repeat these test for the software executing on each processor listed in the first selection. The tester shall attempt to processor listed in the first selection. The tester shall attempt to install an update without the digital signature and shall verify install an update without the digital signature and shall verify that installation fails. The tester shall attempt to install an that installation fails. The tester shall attempt to install an update with digital signature, and verify that installation update with digital signature, and verify that installation succeeds. succeeds. ::: ::: ::: ::: ::: ::: ::: ::: ::: ::: ::: {#FPT_TUD_EXT.3 .comp} ::: {#FPT_TUD_EXT.3 .comp} #### FPT_TUD_EXT.3 Application Signing #### FPT_TUD_EXT.3 Application Signing ::: element ::: element ::: {#FPT_TUD_EXT.3.1 .reqid} ::: {#FPT_TUD_EXT.3.1 .reqid} [FPT_TUD_EXT.3.1](#FPT_TUD_EXT.3.1){.abbr} [FPT_TUD_EXT.3.1](#FPT_TUD_EXT.3.1){.abbr} ::: ::: ::: reqdesc ::: reqdesc The [TSF](#abbr_TSF) shall verify mobile application software using a The [TSF](#abbr_TSF) shall verify mobile application software using a digital signature mechanism prior to installation. digital signature mechanism prior to installation. ::: appnote ::: appnote [Application Note: ]{.note-header}[This requirement does not necessitate | [Application Note: ]{.note-header}[ This requirement does not an X.509v3 certificate or certificate validation. X.509v3 certificates | necessitate an X.509v3 certificate or certificate validation. X.509v3 and certificate validation are addressed in | certificates and certificate validation are addressed in [FPT_TUD_EXT.5.1](#FPT_TUD_EXT.5.1).]{.note} | [FPT_TUD_EXT.5.1](#FPT_TUD_EXT.5.1). ]{.note} ::: ::: ::: ::: ::: ::: ::: {.activity_pane .hide} ::: {.activity_pane .hide} ::: activity_pane_header ::: activity_pane_header [[ Evaluation Activities [[ Evaluation Activities ]{.activity_pane_label}[]{.toggler}](#){onclick="toggle(this);return false;"} ]{.activity_pane_label}[]{.toggler}](#){onclick="toggle(this);return false;"} ::: ::: ::: activity_pane_body ::: activity_pane_body ::: component-activity-header ::: component-activity-header [FPT_TUD_EXT.3](#FPT_TUD_EXT.3) [FPT_TUD_EXT.3](#FPT_TUD_EXT.3) ::: ::: ::: eacategory ::: eacategory [TSS](#abbr_TSS) [TSS](#abbr_TSS) ::: ::: ::: ea ::: ea ::: ea ::: ea The evaluator shall verify that the [TSS](#abbr_TSS) describes how The evaluator shall verify that the [TSS](#abbr_TSS) describes how mobile application software is verified at installation. The evaluator mobile application software is verified at installation. The evaluator shall ensure that this method uses a digital signature.\ shall ensure that this method uses a digital signature.\ \ \ ::: ::: ::: ::: ::: eacategory ::: eacategory Guidance Guidance ::: ::: ::: ea ::: ea ::: ea ::: ea There are no guidance evaluation activities for this component.\ There are no guidance evaluation activities for this component.\ \ \ ::: ::: ::: ::: ::: eacategory ::: eacategory Tests Tests ::: ::: ::: ea ::: ea ::: ea ::: ea **Evaluation Activity Note:** The following test does not have to be **Evaluation Activity Note:** The following test does not have to be tested using the commercial application store.\ tested using the commercial application store.\ \ \ []{.testlist-} []{.testlist-} - [Test FPT_TUD_EXT.3:1](#_t_75){#_t_75 .defined}: The evaluator shall - [Test FPT_TUD_EXT.3:1](#_t_75){#_t_75 .defined}: The evaluator shall write, or the developer shall provide access to, an application. The write, or the developer shall provide access to, an application. The evaluator shall try to install this application without a digitally evaluator shall try to install this application without a digitally signature and shall verify that installation fails. The evaluator signature and shall verify that installation fails. The evaluator shall attempt to install a digitally signed application, and verify shall attempt to install a digitally signed application, and verify that installation succeeds. that installation succeeds. ::: ::: ::: ::: ::: ::: ::: ::: ::: ::: ### 5.1.8 Class FTA: TOE Access {#fta .indexable level="3"} ### 5.1.8 Class FTA: TOE Access {#fta .indexable level="3"} ::: {#FTA_SSL_EXT.1 .comp} ::: {#FTA_SSL_EXT.1 .comp} #### FTA_SSL_EXT.1 TSF- and User-initiated Locked State #### FTA_SSL_EXT.1 TSF- and User-initiated Locked State ::: element ::: element ::: {#FTA_SSL_EXT.1.1 .reqid} ::: {#FTA_SSL_EXT.1.1 .reqid} [FTA_SSL_EXT.1.1](#FTA_SSL_EXT.1.1){.abbr} [FTA_SSL_EXT.1.1](#FTA_SSL_EXT.1.1){.abbr} ::: ::: ::: reqdesc ::: reqdesc The [TSF](#abbr_TSF) shall transition to a locked state after a time The [TSF](#abbr_TSF) shall transition to a locked state after a time interval of inactivity. interval of inactivity. ::: ::: ::: ::: ::: element ::: element ::: {#FTA_SSL_EXT.1.2 .reqid} ::: {#FTA_SSL_EXT.1.2 .reqid} [FTA_SSL_EXT.1.2](#FTA_SSL_EXT.1.2){.abbr} [FTA_SSL_EXT.1.2](#FTA_SSL_EXT.1.2){.abbr} ::: ::: ::: reqdesc ::: reqdesc The [TSF](#abbr_TSF) shall transition to a locked state after initiation The [TSF](#abbr_TSF) shall transition to a locked state after initiation by either the user or the administrator. by either the user or the administrator. ::: ::: ::: ::: ::: element ::: element ::: {#FTA_SSL_EXT.1.3 .reqid} ::: {#FTA_SSL_EXT.1.3 .reqid} [FTA_SSL_EXT.1.3](#FTA_SSL_EXT.1.3){.abbr} [FTA_SSL_EXT.1.3](#FTA_SSL_EXT.1.3){.abbr} ::: ::: ::: reqdesc ::: reqdesc The [TSF](#abbr_TSF) shall, upon transitioning to the locked state, The [TSF](#abbr_TSF) shall, upon transitioning to the locked state, perform the following operations: perform the following operations: - Clearing or overwriting display devices, obscuring the previous - Clearing or overwriting display devices, obscuring the previous contents; contents; - \[**assignment**: [Other actions performed upon transitioning to the - \[**assignment**: [Other actions performed upon transitioning to the locked state]{.assignable-content}\]. locked state]{.assignable-content}\]. ::: appnote ::: appnote [Application Note: ]{.note-header}[ The time interval of inactivity is [Application Note: ]{.note-header}[ The time interval of inactivity is configured using [FMT_SMF_EXT.1](#FMT_SMF_EXT.1) function configured using [FMT_SMF_EXT.1](#FMT_SMF_EXT.1) function [2](#mf-screenlock). The user/administrator-initiated lock is specified [2](#mf-screenlock). The user/administrator-initiated lock is specified in [FMT_SMF_EXT.1](#FMT_SMF_EXT.1) function [6](#mf-lockState).]{.note} | in [FMT_SMF_EXT.1](#FMT_SMF_EXT.1) function [6](#mf-lockState). ]{.note} ::: ::: ::: ::: ::: ::: ::: {.activity_pane .hide} ::: {.activity_pane .hide} ::: activity_pane_header ::: activity_pane_header [[ Evaluation Activities [[ Evaluation Activities ]{.activity_pane_label}[]{.toggler}](#){onclick="toggle(this);return false;"} ]{.activity_pane_label}[]{.toggler}](#){onclick="toggle(this);return false;"} ::: ::: ::: activity_pane_body ::: activity_pane_body ::: component-activity-header ::: component-activity-header [FTA_SSL_EXT.1](#FTA_SSL_EXT.1) [FTA_SSL_EXT.1](#FTA_SSL_EXT.1) ::: ::: ::: eacategory ::: eacategory [TSS](#abbr_TSS) [TSS](#abbr_TSS) ::: ::: ::: ea ::: ea ::: ea ::: ea The evaluator shall verify the [TSS](#abbr_TSS) describes the actions The evaluator shall verify the [TSS](#abbr_TSS) describes the actions performed upon transitioning to the locked state.\ performed upon transitioning to the locked state.\ \ \ ::: ::: ::: ::: ::: eacategory ::: eacategory Guidance Guidance ::: ::: ::: ea ::: ea ::: ea ::: ea The evaluation shall verify that the AGD guidance describes the method The evaluation shall verify that the AGD guidance describes the method of setting the inactivity interval and of commanding a lock. The of setting the inactivity interval and of commanding a lock. The evaluator shall verify that the [TSS](#abbr_TSS) describes the evaluator shall verify that the [TSS](#abbr_TSS) describes the information allowed to be displayed to unauthorized users.\ information allowed to be displayed to unauthorized users.\ \ \ ::: ::: ::: ::: ::: eacategory ::: eacategory Tests Tests ::: ::: ::: ea ::: ea ::: ea ::: ea []{.testlist-} []{.testlist-} - [Test FTA_SSL_EXT.1:1](#_t_81){#_t_81 .defined}: The evaluator shall - [Test FTA_SSL_EXT.1:1](#_t_81){#_t_81 .defined}: The evaluator shall configure the [TSF](#abbr_TSF) to transition to the locked state configure the [TSF](#abbr_TSF) to transition to the locked state after a time of inactivity ([FMT_SMF_EXT.1](#FMT_SMF_EXT.1)) after a time of inactivity ([FMT_SMF_EXT.1](#FMT_SMF_EXT.1)) according to the AGD guidance. The evaluator shall wait until the according to the AGD guidance. The evaluator shall wait until the [TSF](#abbr_TSF) locks and verify that the display is cleared or [TSF](#abbr_TSF) locks and verify that the display is cleared or overwritten and that the only actions allowed in the locked state overwritten and that the only actions allowed in the locked state are unlocking the session and those actions specified in are unlocking the session and those actions specified in [FIA_UAU_EXT.2](#FIA_UAU_EXT.2). [FIA_UAU_EXT.2](#FIA_UAU_EXT.2). - [Test FTA_SSL_EXT.1:2](#_t_82){#_t_82 .defined}: The evaluator shall - [Test FTA_SSL_EXT.1:2](#_t_82){#_t_82 .defined}: The evaluator shall command the [TSF](#abbr_TSF) to transition to the locked state command the [TSF](#abbr_TSF) to transition to the locked state according to the AGD guidance as both the user and the according to the AGD guidance as both the user and the administrator. The evaluator shall wait until the [TSF](#abbr_TSF) administrator. The evaluator shall wait until the [TSF](#abbr_TSF) locks and verify that the display is cleared or overwritten and that locks and verify that the display is cleared or overwritten and that the only actions allowed in the locked state are unlocking the the only actions allowed in the locked state are unlocking the session and those actions specified in session and those actions specified in [FIA_UAU_EXT.2](#FIA_UAU_EXT.2). [FIA_UAU_EXT.2](#FIA_UAU_EXT.2). ::: ::: ::: ::: ::: ::: ::: ::: ::: ::: ::: {#FTA_TAB.1 .comp} ::: {#FTA_TAB.1 .comp} #### FTA_TAB.1 Default TOE Access Banners #### FTA_TAB.1 Default TOE Access Banners ::: element ::: element ::: {#FTA_TAB.1.1 .reqid} ::: {#FTA_TAB.1.1 .reqid} [FTA_TAB.1.1](#FTA_TAB.1.1){.abbr} [FTA_TAB.1.1](#FTA_TAB.1.1){.abbr} ::: ::: ::: reqdesc ::: reqdesc Before establishing a user session, the \[*[TSF](#abbr_TSF)*\] shall Before establishing a user session, the \[*[TSF](#abbr_TSF)*\] shall display an \[*advisory warning*\] message **regarding unauthorized use display an \[*advisory warning*\] message **regarding unauthorized use of the [TOE](#abbr_TOE)**. of the [TOE](#abbr_TOE)**. ::: appnote ::: appnote [Application Note: ]{.note-header}[This requirement may be met with the | [Application Note: ]{.note-header}[ This requirement may be met with the configuration of either text or an image containing the text of the configuration of either text or an image containing the text of the desired message. The [TSF](#abbr_TSF) must minimally display this desired message. The [TSF](#abbr_TSF) must minimally display this information at startup, but may also display the information at every information at startup, but may also display the information at every unlock. The banner is configured according to unlock. The banner is configured according to [FMT_SMF_EXT.1](#FMT_SMF_EXT.1) function [36](#mf-unlockBanner).]{.note} | [FMT_SMF_EXT.1](#FMT_SMF_EXT.1) function [36](#mf-unlockBanner). > ]{.note} ::: ::: ::: ::: ::: ::: ::: {.activity_pane .hide} ::: {.activity_pane .hide} ::: activity_pane_header ::: activity_pane_header [[ Evaluation Activities [[ Evaluation Activities ]{.activity_pane_label}[]{.toggler}](#){onclick="toggle(this);return false;"} ]{.activity_pane_label}[]{.toggler}](#){onclick="toggle(this);return false;"} ::: ::: ::: activity_pane_body ::: activity_pane_body ::: component-activity-header ::: component-activity-header [FTA_TAB.1](#FTA_TAB.1) [FTA_TAB.1](#FTA_TAB.1) ::: ::: ::: eacategory ::: eacategory [TSS](#abbr_TSS) [TSS](#abbr_TSS) ::: ::: ::: ea ::: ea ::: ea ::: ea The [TSS](#abbr_TSS) shall describe when the banner is displayed.\ The [TSS](#abbr_TSS) shall describe when the banner is displayed.\ \ \ ::: ::: ::: ::: ::: eacategory ::: eacategory Guidance Guidance ::: ::: ::: ea ::: ea ::: ea ::: ea There are no guidance evaluation activities for this component.\ There are no guidance evaluation activities for this component.\ \ \ ::: ::: ::: ::: ::: eacategory ::: eacategory Tests Tests ::: ::: ::: ea ::: ea ::: ea ::: ea The evaluator shall also perform the following test: []{.testlist-} The evaluator shall also perform the following test: []{.testlist-} - [Test FTA_TAB.1:1](#_t_83){#_t_83 .defined}: The evaluator follows - [Test FTA_TAB.1:1](#_t_83){#_t_83 .defined}: The evaluator follows the operational guidance to configure a notice and consent warning the operational guidance to configure a notice and consent warning message. The evaluator shall then start up or unlock the message. The evaluator shall then start up or unlock the [TSF](#abbr_TSF). The evaluator shall verify that the notice and [TSF](#abbr_TSF). The evaluator shall verify that the notice and consent warning message is displayed in each instance described in consent warning message is displayed in each instance described in the [TSS](#abbr_TSS). the [TSS](#abbr_TSS). ::: ::: ::: ::: ::: ::: ::: ::: ::: ::: ### 5.1.9 Class FTP: Trusted Path/Channels {#ftp .indexable level="3"} ### 5.1.9 Class FTP: Trusted Path/Channels {#ftp .indexable level="3"} ::: {#FTP_ITC_EXT.1 .comp} ::: {#FTP_ITC_EXT.1 .comp} #### FTP_ITC_EXT.1 Trusted Channel Communication #### FTP_ITC_EXT.1 Trusted Channel Communication ::: element ::: element ::: {#FTP_ITC_EXT.1.1 .reqid} ::: {#FTP_ITC_EXT.1.1 .reqid} [FTP_ITC_EXT.1.1](#FTP_ITC_EXT.1.1){.abbr} [FTP_ITC_EXT.1.1](#FTP_ITC_EXT.1.1){.abbr} ::: ::: ::: reqdesc ::: reqdesc The [TSF](#abbr_TSF) shall use The [TSF](#abbr_TSF) shall use - 802.11-2012 in accordance with the \[*[PP-Module for Wireless LAN - 802.11-2012 in accordance with the \[*[PP-Module for Wireless LAN Client, version | Client, version 2.0]()*\], 2.0](https://www.niap-ccevs.org/protectionprofiles/463)*\], < - 802.1X in accordance with the \[*[PP-Module for Wireless LAN Client, - 802.1X in accordance with the \[*[PP-Module for Wireless LAN Client, version 2.0](https://www.niap-ccevs.org/protectionprofiles/463)*\], | version 2.0]()*\], - [EAP](#abbr_EAP)-TLS in accordance with the \[*[PP-Module for - [EAP](#abbr_EAP)-TLS in accordance with the \[*[PP-Module for Wireless LAN Client, version | Wireless LAN Client, version 2.0]()*\], 2.0](https://www.niap-ccevs.org/protectionprofiles/463)*\], < - Mutually authenticated [TLS](#abbr_TLS) in accordance with the - Mutually authenticated [TLS](#abbr_TLS) in accordance with the \[*[Functional Package for Transport Layer Security (TLS), version \[*[Functional Package for Transport Layer Security (TLS), version 2.1](https://www.niap-ccevs.org/static_html/protection-profile/519)*\] 2.1](https://www.niap-ccevs.org/static_html/protection-profile/519)*\] and \[**selection**: and \[**selection**: - [[IPsec](#abbr_IPsec) in accordance with the [PP-Module for Virtual - [[IPsec](#abbr_IPsec) in accordance with the [PP-Module for Virtual Private Network (VPN) Clients, version | Private Network (VPN) Clients, version 3.0]()]{#s-itc-ipsec 3.0](https://www.niap-ccevs.org/protectionprofiles/487)]{#s-itc-ipsec < .selectable-content} .selectable-content} - [mutually authenticated [DTLS](#abbr_DTLS) as defined in the - [mutually authenticated [DTLS](#abbr_DTLS) as defined in the [Functional Package for Transport Layer Security (TLS), version [Functional Package for Transport Layer Security (TLS), version 2.1](https://www.niap-ccevs.org/static_html/protection-profile/519)]{#itc_dtls 2.1](https://www.niap-ccevs.org/static_html/protection-profile/519)]{#itc_dtls .selectable-content} .selectable-content} - [[HTTPS](#abbr_HTTPS)]{#_s_641 .selectable-content} | - [[HTTPS](#abbr_HTTPS)]{#ftp_itc_ext.1.1_1 .selectable-content} \] protocols to provide a communication channel between itself and \] protocols to provide a communication channel between itself and another trusted IT product using certificates as defined in another trusted IT product using certificates as defined in \[*[Functional Package for X.509, version \[*[Functional Package for X.509, version 1.0](https://www.niap-ccevs.org/protectionprofiles/511)*\] that is 1.0](https://www.niap-ccevs.org/protectionprofiles/511)*\] that is logically distinct from other communication channels, provides assured logically distinct from other communication channels, provides assured identification of its end points, protects channel data from disclosure, identification of its end points, protects channel data from disclosure, and detects modification of the channel data. and detects modification of the channel data. ::: appnote ::: appnote [Application Note: ]{.note-header}[ The intent of the mandatory portion [Application Note: ]{.note-header}[ The intent of the mandatory portion of the above requirement is to use the cryptographic protocols of the above requirement is to use the cryptographic protocols identified in the requirement to establish and maintain a trusted identified in the requirement to establish and maintain a trusted channel between the [TOE](#abbr_TOE) and an access point, channel between the [TOE](#abbr_TOE) and an access point, [VPN](#abbr_VPN) Gateway, or other trusted IT product.\ [VPN](#abbr_VPN) Gateway, or other trusted IT product.\ \ \ \ \ [Appendix B - Selection-based Requirements](#sel-based-reqs){.dynref [Appendix B - Selection-based Requirements](#sel-based-reqs){.dynref format=""} contains the requirements for implementing each of the other format=""} contains the requirements for implementing each of the other optional trusted channel protocols. The [ST](#abbr_ST) author must optional trusted channel protocols. The [ST](#abbr_ST) author must include the security functional requirements for the trusted channel include the security functional requirements for the trusted channel protocol selected in [FTP_ITC_EXT.1](#FTP_ITC_EXT.1) in the main body of protocol selected in [FTP_ITC_EXT.1](#FTP_ITC_EXT.1) in the main body of the [ST](#abbr_ST).\ the [ST](#abbr_ST).\ \ \ Assured identification of endpoints is performed according to the Assured identification of endpoints is performed according to the authentication mechanisms used by the listed trusted channel protocols.\ authentication mechanisms used by the listed trusted channel protocols.\ \ \ ]{.note} ]{.note} Claims from the [Functional Package for X.509, version Claims from the [Functional Package for X.509, version 1.0](https://www.niap-ccevs.org/protectionprofiles/511) are only 1.0](https://www.niap-ccevs.org/protectionprofiles/511) are only required to the extent that they are needed to support the functionality required to the extent that they are needed to support the functionality required by the trusted protocols that are claimed. required by the trusted protocols that are claimed. The [TSF](#abbr_TSF) is mandated to support mutually authenticated The [TSF](#abbr_TSF) is mandated to support mutually authenticated [TLS](#abbr_TLS), which means that it implements a protocol that [TLS](#abbr_TLS), which means that it implements a protocol that requires the validation of a certificate presented by an external requires the validation of a certificate presented by an external entity. Therefore, FIA_X509_EXT.1 and FIA_X509_EXT.2 as defined in entity. Therefore, FIA_X509_EXT.1 and FIA_X509_EXT.2 as defined in [Functional Package for X.509, version [Functional Package for X.509, version 1.0](https://www.niap-ccevs.org/protectionprofiles/511) will be claimed, 1.0](https://www.niap-ccevs.org/protectionprofiles/511) will be claimed, as will FIA_TSM_EXT.1 for management of the trust store. as will FIA_TSM_EXT.1 for management of the trust store. The requirement to implement mutually authenticated [TLS](#abbr_TLS) The requirement to implement mutually authenticated [TLS](#abbr_TLS) also means that it implements a protocol that requires the presentation also means that it implements a protocol that requires the presentation of any certificates to an external entity. Therefore, FIA_XCU_EXT.2 will of any certificates to an external entity. Therefore, FIA_XCU_EXT.2 will be claimed. [FIA_X509_EXT.6](#FIA_X509_EXT.6) will also be claimed, be claimed. [FIA_X509_EXT.6](#FIA_X509_EXT.6) will also be claimed, along with any applicable dependencies, depending on how the along with any applicable dependencies, depending on how the certificates presented by the [TOE](#abbr_TOE) are obtained. certificates presented by the [TOE](#abbr_TOE) are obtained. ::: ::: ::: ::: ::: ::: ::: element ::: element ::: {#FTP_ITC_EXT.1.2 .reqid} ::: {#FTP_ITC_EXT.1.2 .reqid} [FTP_ITC_EXT.1.2](#FTP_ITC_EXT.1.2){.abbr} [FTP_ITC_EXT.1.2](#FTP_ITC_EXT.1.2){.abbr} ::: ::: ::: reqdesc ::: reqdesc The [TSF](#abbr_TSF) shall permit the [TSF](#abbr_TSF) to initiate The [TSF](#abbr_TSF) shall permit the [TSF](#abbr_TSF) to initiate communication via the trusted channel. communication via the trusted channel. ::: ::: ::: ::: ::: element ::: element ::: {#FTP_ITC_EXT.1.3 .reqid} ::: {#FTP_ITC_EXT.1.3 .reqid} [FTP_ITC_EXT.1.3](#FTP_ITC_EXT.1.3){.abbr} [FTP_ITC_EXT.1.3](#FTP_ITC_EXT.1.3){.abbr} ::: ::: ::: reqdesc ::: reqdesc The [TSF](#abbr_TSF) shall initiate communication via the trusted The [TSF](#abbr_TSF) shall initiate communication via the trusted channel for wireless access point connections, administrative channel for wireless access point connections, administrative communication, configured enterprise connections, and \[**selection**: communication, configured enterprise connections, and \[**selection**: [[OTA](#abbr_OTA) updates]{#_s_642 .selectable-content}, [no other | [[OTA](#abbr_OTA) updates]{#ftp_itc_ext.1.3_1 .selectable-content}, [no connections]{#_s_643 .selectable-content}\]. | other connections]{#ftp_itc_ext.1.3_2 .selectable-content}\]. ::: ::: ::: ::: ::: {.activity_pane .hide} ::: {.activity_pane .hide} ::: activity_pane_header ::: activity_pane_header [[ Evaluation Activities [[ Evaluation Activities ]{.activity_pane_label}[]{.toggler}](#){onclick="toggle(this);return false;"} ]{.activity_pane_label}[]{.toggler}](#){onclick="toggle(this);return false;"} ::: ::: ::: activity_pane_body ::: activity_pane_body ::: component-activity-header ::: component-activity-header [FTP_ITC_EXT.1](#FTP_ITC_EXT.1) [FTP_ITC_EXT.1](#FTP_ITC_EXT.1) ::: ::: ::: eacategory ::: eacategory [TSS](#abbr_TSS) [TSS](#abbr_TSS) ::: ::: ::: ea ::: ea ::: ea ::: ea The evaluator shall examine the [TSS](#abbr_TSS) to determine that it The evaluator shall examine the [TSS](#abbr_TSS) to determine that it describes the details of the [TOE](#abbr_TOE) connecting to access describes the details of the [TOE](#abbr_TOE) connecting to access points, [VPN](#abbr_VPN) Gateways, and other trusted IT products in points, [VPN](#abbr_VPN) Gateways, and other trusted IT products in terms of the cryptographic protocols specified in the requirement, along terms of the cryptographic protocols specified in the requirement, along with [TOE](#abbr_TOE)-specific options or procedures that might not be with [TOE](#abbr_TOE)-specific options or procedures that might not be reflected in the specifications. The evaluator shall also confirm that reflected in the specifications. The evaluator shall also confirm that all protocols listed in the [TSS](#abbr_TSS) are specified and included all protocols listed in the [TSS](#abbr_TSS) are specified and included in the requirements in the [ST](#abbr_ST).\ in the requirements in the [ST](#abbr_ST).\ \ \ If [OTA](#abbr_OTA) updates are selected, the [TSS](#abbr_TSS) shall If [OTA](#abbr_OTA) updates are selected, the [TSS](#abbr_TSS) shall describe which trusted channel protocol is initiated by the describe which trusted channel protocol is initiated by the [TOE](#abbr_TOE) and is used for updates.\ [TOE](#abbr_TOE) and is used for updates.\ \ \ ::: ::: ::: ::: ::: eacategory ::: eacategory Guidance Guidance ::: ::: ::: ea ::: ea ::: ea ::: ea The evaluator shall confirm that the operational guidance contains The evaluator shall confirm that the operational guidance contains instructions for establishing the connection to access points, instructions for establishing the connection to access points, [VPN](#abbr_VPN) Gateways, and other trusted IT products.\ [VPN](#abbr_VPN) Gateways, and other trusted IT products.\ \ \ ::: ::: ::: ::: ::: eacategory ::: eacategory Tests Tests ::: ::: ::: ea ::: ea ::: ea ::: ea The evaluator shall also perform the following tests for each protocol The evaluator shall also perform the following tests for each protocol listed: []{.testlist-} listed: []{.testlist-} - [Test FTP_ITC_EXT.1:1](#_t_84){#_t_84 .defined}: The evaluator shall - [Test FTP_ITC_EXT.1:1](#_t_84){#_t_84 .defined}: The evaluator shall ensure, for each communication channel with an authorized IT entity, ensure, for each communication channel with an authorized IT entity, the channel data are not sent in plaintext and that a protocol the channel data are not sent in plaintext and that a protocol analyzer identifies the traffic as the protocol under testing. analyzer identifies the traffic as the protocol under testing. - [Test FTP_ITC_EXT.1:2](#_t_85){#_t_85 .defined}: \[conditional\] If - [Test FTP_ITC_EXT.1:2](#_t_85){#_t_85 .defined}: \[conditional\] If [IPsec](#s-itc-ipsec) is selected, the evaluator shall ensure that [IPsec](#s-itc-ipsec) is selected, the evaluator shall ensure that the [TOE](#abbr_TOE) is able to initiate communications with a the [TOE](#abbr_TOE) is able to initiate communications with a [VPN](#abbr_VPN) Gateway, setting up the connections as described in [VPN](#abbr_VPN) Gateway, setting up the connections as described in the operational guidance and ensuring that communication is the operational guidance and ensuring that communication is successful. successful. - [Test FTP_ITC_EXT.1:3](#_t_86){#_t_86 .defined}: \[conditional\] If - [Test FTP_ITC_EXT.1:3](#_t_86){#_t_86 .defined}: \[conditional\] If [OTA](#abbr_OTA) updates are selected, the evaluator shall trigger [OTA](#abbr_OTA) updates are selected, the evaluator shall trigger an update request according to the operational guidance and shall an update request according to the operational guidance and shall ensure that the communication is successful. ensure that the communication is successful. - [Test FTP_ITC_EXT.1:4](#_t_87){#_t_87 .defined}: For any other - [Test FTP_ITC_EXT.1:4](#_t_87){#_t_87 .defined}: For any other selected protocol (not tested in Test 1, 2, or 3), the evaluator selected protocol (not tested in Test 1, 2, or 3), the evaluator shall ensure that the [TOE](#abbr_TOE) is able to initiate shall ensure that the [TOE](#abbr_TOE) is able to initiate communications with a trusted IT product using the protocol, setting communications with a trusted IT product using the protocol, setting up the connection as described in the operational guidance and up the connection as described in the operational guidance and ensuring that the communication is successful. ensuring that the communication is successful. ::: ::: ::: ::: ::: ::: ::: ::: ::: ::: ### 5.1.10 TOE Security Functional Requirements Rationale {#obj-req-map .indexable le ### 5.1.10 TOE Security Functional Requirements Rationale {#obj-req-map .indexable le The following rationale provides justification for each [SFR](#abbr_SFR) The following rationale provides justification for each [SFR](#abbr_SFR) for the [TOE](#abbr_TOE), showing that the [SFRs](#abbr_SFR) are for the [TOE](#abbr_TOE), showing that the [SFRs](#abbr_SFR) are suitable to address the specified threats:\ suitable to address the specified threats:\ Threat Addressed by | Threat Addressed by -------------------------------------------------- -------------------------------- | -------------------------------------------------- -------------------------------- [T.MALICIOUS\_​APP](#T.MALICIOUS_APP) [FAU_GEN.1](#FAU_GEN.1) | [T.MALICIOUS\_​APP](#T.MALICIOUS_APP) [FAU_GEN.1](#FAU_GEN.1) [FAU_SAR.1](#FAU_SAR.1) | [FAU_SAR.1](#FAU_SAR.1) [FAU_STG.2](#FAU_STG.2) | [FAU_SEL.1](#FAU_SEL.1) (Objecti [FAU_STG.5](#FAU_STG.5) | [FAU_STG.2](#FAU_STG.2) [FCS_COP.1/SKC](#FCS_COP.1/SKC) | [FAU_STG.5](#FAU_STG.5) [FCS_RBG.6](#FCS_RBG.6) | [FCS_COP.1/SKC](#FCS_COP.1/SKC) [FCS_SRV_EXT.1](#FCS_SRV_EXT.1) | [FCS_RBG.6](#FCS_RBG.6) [FDP_ACF_EXT.1](#FDP_ACF_EXT.1) | [FCS_SRV_EXT.1](#FCS_SRV_EXT.1) [FMT_MOF_EXT.1](#FMT_MOF_EXT.1) | [FCS_SRV_EXT.2](#FCS_SRV_EXT.2) [FMT_SMF_EXT.1](#FMT_SMF_EXT.1) | [FDP_ACF_EXT.1](#FDP_ACF_EXT.1) [FMT_SMF_EXT.2](#FMT_SMF_EXT.2) | [FDP_ACF_EXT.2](#FDP_ACF_EXT.2) [FPT_AEX_EXT.1](#FPT_AEX_EXT.1) | [FDP_ACF_EXT.3](#FDP_ACF_EXT.3) [FPT_AEX_EXT.2](#FPT_AEX_EXT.2) | [FDP_BCK_EXT.1](#FDP_BCK_EXT.1) [FPT_AEX_EXT.3](#FPT_AEX_EXT.3) | [FDP_BLT_EXT.1](#FDP_BLT_EXT.1) [FPT_AEX_EXT.4](#FPT_AEX_EXT.4) | [FMT_MOF_EXT.1](#FMT_MOF_EXT.1) [FPT_NOT_EXT.1](#FPT_NOT_EXT.1) | [FMT_SMF_EXT.1](#FMT_SMF_EXT.1) [FPT_STM.1](#FPT_STM.1) | [FMT_SMF_EXT.2](#FMT_SMF_EXT.2) [FPT_TST_EXT.1](#FPT_TST_EXT.1) | [FMT_SMF_EXT.3](#FMT_SMF_EXT.3) [FPT_TST_EXT.2/PREKERNEL](#FPT_T | [FPT_AEX_EXT.1](#FPT_AEX_EXT.1) [FPT_TUD_EXT.1](#FPT_TUD_EXT.1) | [FPT_AEX_EXT.2](#FPT_AEX_EXT.2) [FPT_TUD_EXT.2](#FPT_TUD_EXT.2) | [FPT_AEX_EXT.3](#FPT_AEX_EXT.3) [FPT_TUD_EXT.3](#FPT_TUD_EXT.3) | [FPT_AEX_EXT.4](#FPT_AEX_EXT.4) [FAU_SEL.1](#FAU_SEL.1) (objecti | [FPT_AEX_EXT.5](#FPT_AEX_EXT.5) [FCS_SRV_EXT.2](#FCS_SRV_EXT.2) | [FPT_AEX_EXT.6](#FPT_AEX_EXT.6) [FDP_ACF_EXT.3](#FDP_ACF_EXT.3) | [FPT_BBD_EXT.1](#FPT_BBD_EXT.1) [FDP_BCK_EXT.1](#FDP_BCK_EXT.1) | [FPT_BLT_EXT.1](#FPT_BLT_EXT.1) [FDP_BLT_EXT.1](#FDP_BLT_EXT.1) | [FPT_NOT_EXT.1](#FPT_NOT_EXT.1) [FMT_SMF_EXT.3](#FMT_SMF_EXT.3) | [FPT_NOT_EXT.2](#FPT_NOT_EXT.2) [FPT_AEX_EXT.5](#FPT_AEX_EXT.5) | [FPT_STM.1](#FPT_STM.1) [FPT_AEX_EXT.6](#FPT_AEX_EXT.6) | [FPT_TST_EXT.1](#FPT_TST_EXT.1) [FPT_BBD_EXT.1](#FPT_BBD_EXT.1) | [FPT_TST_EXT.2/POSTKERNEL](#FPT_ [FPT_BLT_EXT.1](#FPT_BLT_EXT.1) | [FPT_TST_EXT.2/PREKERNEL](#FPT_T [FPT_NOT_EXT.2](#FPT_NOT_EXT.2) | [FPT_TST_EXT.3](#FPT_TST_EXT.3) [FPT_TST_EXT.2/POSTKERNEL](#FPT_ | [FPT_TUD_EXT.1](#FPT_TUD_EXT.1) [FPT_TUD_EXT.5](#FPT_TUD_EXT.5) | [FPT_TUD_EXT.2](#FPT_TUD_EXT.2) [FPT_TUD_EXT.6](#FPT_TUD_EXT.6) | [FPT_TUD_EXT.3](#FPT_TUD_EXT.3) [FDP_ACF_EXT.2](#FDP_ACF_EXT.2) | [FPT_TUD_EXT.4](#FPT_TUD_EXT.4) [FPT_TST_EXT.3](#FPT_TST_EXT.3) | [FPT_TUD_EXT.5](#FPT_TUD_EXT.5) [FPT_TUD_EXT.4](#FPT_TUD_EXT.4) | [FPT_TUD_EXT.6](#FPT_TUD_EXT.6) [T.NETWORK\_​ATTACK](#T.NETWORK_ATTACK) [FAU_GEN.1](#FAU_GEN.1) | [T.NETWORK\_​ATTACK](#T.NETWORK_ATTACK) [FAU_GEN.1](#FAU_GEN.1) [FAU_SAR.1](#FAU_SAR.1) | [FAU_SAR.1](#FAU_SAR.1) [FAU_STG.2](#FAU_STG.2) | [FAU_SEL.1](#FAU_SEL.1) (Objecti [FAU_STG.5](#FAU_STG.5) | [FAU_STG.2](#FAU_STG.2) [FCS_CKM.1/AKG](#FCS_CKM.1/AKG) | [FAU_STG.5](#FAU_STG.5) [FCS_CKM.1/SKG](#FCS_CKM.1/SKG) | [FCS_CKM_EXT.6](#FCS_CKM_EXT.6) [FCS_CKM.2](#FCS_CKM.2) | [FCS_CKM_EXT.7/UNLOCKED](#FCS_CK [FCS_CKM_EXT.6](#FCS_CKM_EXT.6) | [FCS_CKM.1/AKG](#FCS_CKM.1/AKG) [FCS_COP.1/AEAD](#FCS_COP.1/AEAD | [FCS_CKM.1/SKG](#FCS_CKM.1/SKG) [FCS_COP.1/Hash](#FCS_COP.1/Hash | [FCS_CKM.2](#FCS_CKM.2) [FCS_COP.1/KeyedHash](#FCS_COP.1 | [FCS_COP.1/AEAD](#FCS_COP.1/AEAD [FCS_COP.1/SigGen](#FCS_COP.1/Si | [FCS_COP.1/Hash](#FCS_COP.1/Hash [FCS_COP.1/SigVer](#FCS_COP.1/Si | [FCS_COP.1/KeyedHash](#FCS_COP.1 [FCS_HTTPS_EXT.1](#FCS_HTTPS_EXT | [FCS_COP.1/SigGen](#FCS_COP.1/Si [FCS_RBG.1](#FCS_RBG.1) | [FCS_COP.1/SigVer](#FCS_COP.1/Si [FCS_RBG.6](#FCS_RBG.6) | [FCS_HTTPS_EXT.1](#FCS_HTTPS_EXT [FCS_SRV_EXT.1](#FCS_SRV_EXT.1) | [FCS_RBG_EXT.2](#FCS_RBG_EXT.2) [FDP_IFC_EXT.1](#FDP_IFC_EXT.1) | [FCS_RBG.1](#FCS_RBG.1) [FDP_STG_EXT.1](#FDP_STG_EXT.1) | [FCS_RBG.2](#FCS_RBG.2) (Selecti [FDP_UPC_EXT.1/APPS](#FDP_UPC_EX | [FCS_RBG.3](#FCS_RBG.3) (Selecti [FMT_MOF_EXT.1](#FMT_MOF_EXT.1) | [FCS_RBG.4](#FCS_RBG.4) (Selecti [FMT_SMF_EXT.1](#FMT_SMF_EXT.1) | [FCS_RBG.5](#FCS_RBG.5) (Selecti [FMT_SMF_EXT.2](#FMT_SMF_EXT.2) | [FCS_RBG.6](#FCS_RBG.6) [FPT_FLS.1](#FPT_FLS.1) | [FCS_SRV_EXT.1](#FCS_SRV_EXT.1) [FPT_STM.1](#FPT_STM.1) | [FCS_SRV_EXT.2](#FCS_SRV_EXT.2) [FPT_TST.1](#FPT_TST.1) | [FDP_BLT_EXT.1](#FDP_BLT_EXT.1) [FTA_SSL_EXT.1](#FTA_SSL_EXT.1) | [FDP_IFC_EXT.1](#FDP_IFC_EXT.1) [FTP_ITC_EXT.1](#FTP_ITC_EXT.1) | [FDP_STG_EXT.1](#FDP_STG_EXT.1) [FAU_SEL.1](#FAU_SEL.1) (objecti | [FDP_UPC_EXT.1/APPS](#FDP_UPC_EX [FCS_RBG_EXT.2](#FCS_RBG_EXT.2) | [FDP_UPC_EXT.1/BLUETOOTH](#FDP_U [FCS_SRV_EXT.2](#FCS_SRV_EXT.2) | [FMT_MOF_EXT.1](#FMT_MOF_EXT.1) [FDP_BLT_EXT.1](#FDP_BLT_EXT.1) | [FMT_SMF_EXT.1](#FMT_SMF_EXT.1) [FPT_BLT_EXT.1](#FPT_BLT_EXT.1) | [FMT_SMF_EXT.2](#FMT_SMF_EXT.2) [FTA_TAB.1](#FTA_TAB.1) (objecti | [FPT_BLT_EXT.1](#FPT_BLT_EXT.1) [FCS_CKM_EXT.7/UNLOCKED](#FCS_CK | [FPT_FLS.1](#FPT_FLS.1) [FDP_UPC_EXT.1/BLUETOOTH](#FDP_U | [FPT_STM.1](#FPT_STM.1) [FCS_RBG.2](#FCS_RBG.2) (selecti | [FPT_TST.1](#FPT_TST.1) [FCS_RBG.3](#FCS_RBG.3) (selecti | [FTA_SSL_EXT.1](#FTA_SSL_EXT.1) [FCS_RBG.4](#FCS_RBG.4) (selecti | [FTA_TAB.1](#FTA_TAB.1) [FCS_RBG.5](#FCS_RBG.5) (selecti | [FTP_ITC_EXT.1](#FTP_ITC_EXT.1) [T.NETWORK\_​EAVESDROP](#T.NETWORK_EAVESDROP) [FCS_CKM.1/AKG](#FCS_CKM.1/AKG) | [T.NETWORK\_​EAVESDROP](#T.NETWORK_EAVESDROP) [FCS_CKM_EXT.6](#FCS_CKM_EXT.6) [FCS_CKM.1/SKG](#FCS_CKM.1/SKG) | [FCS_CKM_EXT.7/UNLOCKED](#FCS_CK [FCS_CKM.2](#FCS_CKM.2) | [FCS_CKM.1/AKG](#FCS_CKM.1/AKG) [FCS_CKM_EXT.6](#FCS_CKM_EXT.6) | [FCS_CKM.1/SKG](#FCS_CKM.1/SKG) [FCS_COP.1/AEAD](#FCS_COP.1/AEAD | [FCS_CKM.2](#FCS_CKM.2) [FCS_COP.1/Hash](#FCS_COP.1/Hash | [FCS_COP.1/AEAD](#FCS_COP.1/AEAD [FCS_COP.1/KeyedHash](#FCS_COP.1 | [FCS_COP.1/Hash](#FCS_COP.1/Hash [FCS_COP.1/SigGen](#FCS_COP.1/Si | [FCS_COP.1/KeyedHash](#FCS_COP.1 [FCS_COP.1/SigVer](#FCS_COP.1/Si | [FCS_COP.1/SigGen](#FCS_COP.1/Si [FCS_HTTPS_EXT.1](#FCS_HTTPS_EXT | [FCS_COP.1/SigVer](#FCS_COP.1/Si [FCS_RBG.6](#FCS_RBG.6) | [FCS_HTTPS_EXT.1](#FCS_HTTPS_EXT [FCS_SRV_EXT.1](#FCS_SRV_EXT.1) | [FCS_RBG_EXT.2](#FCS_RBG_EXT.2) [FDP_IFC_EXT.1](#FDP_IFC_EXT.1) | [FCS_RBG_EXT.3](#FCS_RBG_EXT.3) [FDP_STG_EXT.1](#FDP_STG_EXT.1) | [FCS_RBG.2](#FCS_RBG.2) (Selecti [FDP_UPC_EXT.1/APPS](#FDP_UPC_EX | [FCS_RBG.3](#FCS_RBG.3) (Selecti [FIA_X509_EXT.6](#FIA_X509_EXT.6 | [FCS_RBG.4](#FCS_RBG.4) (Selecti [FPT_FLS.1](#FPT_FLS.1) | [FCS_RBG.5](#FCS_RBG.5) (Selecti [FPT_TST.1](#FPT_TST.1) | [FCS_RBG.6](#FCS_RBG.6) [FTP_ITC_EXT.1](#FTP_ITC_EXT.1) | [FCS_SRV_EXT.1](#FCS_SRV_EXT.1) [FCS_RBG_EXT.2](#FCS_RBG_EXT.2) | [FDP_BLT_EXT.1](#FDP_BLT_EXT.1) [FCS_RBG_EXT.3](#FCS_RBG_EXT.3) | [FDP_IFC_EXT.1](#FDP_IFC_EXT.1) [FDP_BLT_EXT.1](#FDP_BLT_EXT.1) | [FDP_STG_EXT.1](#FDP_STG_EXT.1) [FPT_BLT_EXT.1](#FPT_BLT_EXT.1) | [FDP_UPC_EXT.1/APPS](#FDP_UPC_EX [FCS_CKM_EXT.7/UNLOCKED](#FCS_CK | [FDP_UPC_EXT.1/BLUETOOTH](#FDP_U [FCS_COP.1/AEAD](#FCS_COP.1/AEAD | [FIA_X509_EXT.6](#FIA_X509_EXT.6 [FDP_UPC_EXT.1/BLUETOOTH](#FDP_U | [FPT_BLT_EXT.1](#FPT_BLT_EXT.1) [FCS_RBG.2](#FCS_RBG.2) (selecti | [FPT_FLS.1](#FPT_FLS.1) [FCS_RBG.3](#FCS_RBG.3) (selecti | [FPT_TST.1](#FPT_TST.1) [FCS_RBG.4](#FCS_RBG.4) (selecti | [FTP_ITC_EXT.1](#FTP_ITC_EXT.1) [FCS_RBG.5](#FCS_RBG.5) (selecti | [T.PERSISTENT\_​PRESENCE](#T.PERSISTENT_PRESENCE) [FCS_COP.1/AEAD](#FCS_COP.1/AEAD [T.PERSISTENT\_​PRESENCE](#T.PERSISTENT_PRESENCE) [FCS_COP.1/AEAD](#FCS_COP.1/AEAD | [FCS_COP.1/KeyWrap](#FCS_COP.1/K [FCS_COP.1/KeyWrap](#FCS_COP.1/K | [FCS_STG_EXT.3](#FCS_STG_EXT.3) [FCS_STG_EXT.3](#FCS_STG_EXT.3) | [FMT_MOF_EXT.1](#FMT_MOF_EXT.1) [FMT_MOF_EXT.1](#FMT_MOF_EXT.1) | [FMT_SMF_EXT.1](#FMT_SMF_EXT.1) [FMT_SMF_EXT.1](#FMT_SMF_EXT.1) | [FMT_SMF_EXT.2](#FMT_SMF_EXT.2) [FMT_SMF_EXT.2](#FMT_SMF_EXT.2) | [FPT_NOT_EXT.1](#FPT_NOT_EXT.1) [FPT_NOT_EXT.1](#FPT_NOT_EXT.1) | [FPT_TST_EXT.1](#FPT_TST_EXT.1) [FPT_TST_EXT.1](#FPT_TST_EXT.1) | [FPT_TST_EXT.2/PREKERNEL](#FPT_T [FPT_TST_EXT.2/PREKERNEL](#FPT_T | [FPT_TST_EXT.3](#FPT_TST_EXT.3) [FPT_TUD_EXT.2](#FPT_TUD_EXT.2) | [FPT_TUD_EXT.2](#FPT_TUD_EXT.2) [FPT_TUD_EXT.3](#FPT_TUD_EXT.3) | [FPT_TUD_EXT.3](#FPT_TUD_EXT.3) [FPT_TUD_EXT.5](#FPT_TUD_EXT.5) | [FPT_TUD_EXT.4](#FPT_TUD_EXT.4) [FPT_TUD_EXT.6](#FPT_TUD_EXT.6) | [FPT_TUD_EXT.5](#FPT_TUD_EXT.5) [FPT_TST_EXT.3](#FPT_TST_EXT.3) | [FPT_TUD_EXT.6](#FPT_TUD_EXT.6) [FPT_TUD_EXT.4](#FPT_TUD_EXT.4) | [T.PHYSICAL\_​ACCESS](#T.PHYSICAL_ACCESS) [FCS_CKM_EXT.1](#FCS_CKM_EXT.1) [T.PHYSICAL\_​ACCESS](#T.PHYSICAL_ACCESS) [FCS_CKM.2](#FCS_CKM.2) | [FCS_CKM_EXT.3](#FCS_CKM_EXT.3) [FCS_CKM.6](#FCS_CKM.6) | [FCS_CKM_EXT.5](#FCS_CKM_EXT.5) [FCS_CKM_EXT.1](#FCS_CKM_EXT.1) | [FCS_CKM_EXT.6](#FCS_CKM_EXT.6) [FCS_CKM_EXT.7/LOCKED](#FCS_CKM_ | [FCS_CKM_EXT.7/LOCKED](#FCS_CKM_ [FCS_CKM_EXT.3](#FCS_CKM_EXT.3) | [FCS_CKM_EXT.7/UNLOCKED](#FCS_CK [FCS_CKM_EXT.5](#FCS_CKM_EXT.5) | [FCS_CKM_EXT.8](#FCS_CKM_EXT.8) [FCS_CKM_EXT.6](#FCS_CKM_EXT.6) | [FCS_CKM_EXT.9](#FCS_CKM_EXT.9) [FCS_CKM_EXT.8](#FCS_CKM_EXT.8) | [FCS_CKM.2](#FCS_CKM.2) [FCS_COP.1/AEAD](#FCS_COP.1/AEAD | [FCS_CKM.6](#FCS_CKM.6) [FCS_COP.1/Hash](#FCS_COP.1/Hash | [FCS_COP.1/AEAD](#FCS_COP.1/AEAD [FCS_COP.1/KeyedHash](#FCS_COP.1 | [FCS_COP.1/Hash](#FCS_COP.1/Hash [FCS_COP.1/SigGen](#FCS_COP.1/Si | [FCS_COP.1/KeyedHash](#FCS_COP.1 [FCS_COP.1/SigVer](#FCS_COP.1/Si | [FCS_COP.1/SigGen](#FCS_COP.1/Si [FCS_COP.1/SKC](#FCS_COP.1/SKC) | [FCS_COP.1/SigVer](#FCS_COP.1/Si [FCS_IV_EXT.1](#FCS_IV_EXT.1) | [FCS_COP.1/SKC](#FCS_COP.1/SKC) [FCS_RBG.1](#FCS_RBG.1) | [FCS_IV_EXT.1](#FCS_IV_EXT.1) [FCS_STG_EXT.1](#FCS_STG_EXT.1) | [FCS_RBG.1](#FCS_RBG.1) [FCS_STG_EXT.2](#FCS_STG_EXT.2) | [FCS_RBG.2](#FCS_RBG.2) (Selecti [FCS_STG_EXT.3](#FCS_STG_EXT.3) | [FCS_RBG.3](#FCS_RBG.3) (Selecti [FDP_DAR_EXT.1](#FDP_DAR_EXT.1) | [FCS_RBG.4](#FCS_RBG.4) (Selecti [FDP_DAR_EXT.2](#FDP_DAR_EXT.2) | [FCS_RBG.5](#FCS_RBG.5) (Selecti [FIA_AFL_EXT.1](#FIA_AFL_EXT.1) | [FCS_STG_EXT.1](#FCS_STG_EXT.1) [FIA_PMG_EXT.1](#FIA_PMG_EXT.1) | [FCS_STG_EXT.2](#FCS_STG_EXT.2) [FIA_TRT_EXT.1](#FIA_TRT_EXT.1) | [FCS_STG_EXT.3](#FCS_STG_EXT.3) [FIA_UAU.5](#FIA_UAU.5) | [FDP_DAR_EXT.1](#FDP_DAR_EXT.1) [FIA_UAU.6/CREDENTIAL](#FIA_UAU. | [FDP_DAR_EXT.2](#FDP_DAR_EXT.2) [FIA_UAU.6/LOCKED](#FIA_UAU.6/LO | [FIA_AFL_EXT.1](#FIA_AFL_EXT.1) [FIA_UAU.7](#FIA_UAU.7) | [FIA_PMG_EXT.1](#FIA_PMG_EXT.1) [FIA_UAU_EXT.1](#FIA_UAU_EXT.1) | [FIA_TRT_EXT.1](#FIA_TRT_EXT.1) [FIA_UAU_EXT.2](#FIA_UAU_EXT.2) | [FIA_UAU_EXT.1](#FIA_UAU_EXT.1) [FPT_FLS.1](#FPT_FLS.1) | [FIA_UAU_EXT.2](#FIA_UAU_EXT.2) [FPT_JTA_EXT.1](#FPT_JTA_EXT.1) | [FIA_UAU_EXT.4](#FIA_UAU_EXT.4) [FPT_KST_EXT.1](#FPT_KST_EXT.1) | [FIA_UAU.5](#FIA_UAU.5) [FPT_KST_EXT.2](#FPT_KST_EXT.2) | [FIA_UAU.6/CREDENTIAL](#FIA_UAU. [FPT_KST_EXT.3](#FPT_KST_EXT.3) | [FIA_UAU.6/LOCKED](#FIA_UAU.6/LO [FPT_TST.1](#FPT_TST.1) | [FIA_UAU.7](#FIA_UAU.7) [FTA_SSL_EXT.1](#FTA_SSL_EXT.1) | [FPT_FLS.1](#FPT_FLS.1) [FIA_UAU_EXT.4](#FIA_UAU_EXT.4) | [FPT_JTA_EXT.1](#FPT_JTA_EXT.1) [FCS_CKM_EXT.7/UNLOCKED](#FCS_CK | [FPT_KST_EXT.1](#FPT_KST_EXT.1) [FCS_CKM_EXT.9](#FCS_CKM_EXT.9) | [FPT_KST_EXT.2](#FPT_KST_EXT.2) [FCS_RBG.2](#FCS_RBG.2) (selecti | [FPT_KST_EXT.3](#FPT_KST_EXT.3) [FCS_RBG.3](#FCS_RBG.3) (selecti | [FPT_TST.1](#FPT_TST.1) [FCS_RBG.4](#FCS_RBG.4) (selecti | [FTA_SSL_EXT.1](#FTA_SSL_EXT.1) [FCS_RBG.5](#FCS_RBG.5) (selecti < : [Table [19]{.counter}]{#t-obj_map .ctr myid="t-obj_map" : [Table [19]{.counter}]{#t-obj_map .ctr myid="t-obj_map" counter-type="ct-Table"}: [SFR](#abbr_SFR) Rationale counter-type="ct-Table"}: [SFR](#abbr_SFR) Rationale ## 5.2 Security Assurance Requirements {#sar .indexable level="2"} ## 5.2 Security Assurance Requirements {#sar .indexable level="2"} The Security Objectives in [Section 4 Security The Security Objectives in [Section 4 Security Objectives](#Security_Objectives){.dynref} were constructed to address Objectives](#Security_Objectives){.dynref} were constructed to address threats identified in [Section 3 Security Problem threats identified in [Section 3 Security Problem Definition](#Security_Problem_Definition){.dynref}. The Security Definition](#Security_Problem_Definition){.dynref}. The Security Functional Requirements ([SFRs](#abbr_SFR)) in [Section 5.1 Security Functional Requirements ([SFRs](#abbr_SFR)) in [Section 5.1 Security Functional Requirements](#sfr){.dynref} are a formal instantiation of Functional Requirements](#sfr){.dynref} are a formal instantiation of the Security Objectives. The [PP](#abbr_PP) identifies the Security the Security Objectives. The [PP](#abbr_PP) identifies the Security Assurance Requirements ([SARs](#abbr_SAR)) to frame the extent to which Assurance Requirements ([SARs](#abbr_SAR)) to frame the extent to which the evaluator assesses the documentation applicable for the evaluation the evaluator assesses the documentation applicable for the evaluation and performs independent testing.\ and performs independent testing.\ \ \ This section lists the set of [SARs](#abbr_SAR) from [CC](#abbr_CC) part This section lists the set of [SARs](#abbr_SAR) from [CC](#abbr_CC) part 3 that are required in evaluations against this [PP](#abbr_PP). 3 that are required in evaluations against this [PP](#abbr_PP). Individual Evaluation Activities to be performed are specified both in Individual Evaluation Activities to be performed are specified both in [Section 5.1 Security Functional Requirements](#sfr){.dynref} as well as [Section 5.1 Security Functional Requirements](#sfr){.dynref} as well as in this section.\ in this section.\ \ \ The general model for evaluation of [TOEs](#abbr_TOE) against The general model for evaluation of [TOEs](#abbr_TOE) against [STs](#abbr_ST) written to conform to this [PP](#abbr_PP) is as [STs](#abbr_ST) written to conform to this [PP](#abbr_PP) is as follows:\ follows:\ \ \ After the [ST](#abbr_ST) has been approved for evaluation, the ITSEF After the [ST](#abbr_ST) has been approved for evaluation, the ITSEF will obtain the [TOE](#abbr_TOE), supporting environmental IT, and the will obtain the [TOE](#abbr_TOE), supporting environmental IT, and the administrative/user guides for the [TOE](#abbr_TOE). The ITSEF is administrative/user guides for the [TOE](#abbr_TOE). The ITSEF is expected to perform actions mandated by the Common Evaluation expected to perform actions mandated by the Common Evaluation Methodology ([CEM](#abbr_CEM)) for the ASE and ALC [SARs](#abbr_SAR). Methodology ([CEM](#abbr_CEM)) for the ASE and ALC [SARs](#abbr_SAR). The ITSEF also performs the Evaluation Activities contained within The ITSEF also performs the Evaluation Activities contained within [Section 5.1 Security Functional Requirements](#sfr){.dynref}, which are [Section 5.1 Security Functional Requirements](#sfr){.dynref}, which are intended to be an interpretation of the other [CEM](#abbr_CEM) intended to be an interpretation of the other [CEM](#abbr_CEM) evaluation requirements as they apply to the specific technology evaluation requirements as they apply to the specific technology instantiated in the [TOE](#abbr_TOE). The Evaluation Activities that are instantiated in the [TOE](#abbr_TOE). The Evaluation Activities that are captured in [Section 5.1 Security Functional captured in [Section 5.1 Security Functional Requirements](#sfr){.dynref} also provide clarification as to what the Requirements](#sfr){.dynref} also provide clarification as to what the developer needs to provide to demonstrate the [TOE](#abbr_TOE) is developer needs to provide to demonstrate the [TOE](#abbr_TOE) is compliant with the [PP](#abbr_PP). compliant with the [PP](#abbr_PP). The [TOE](#abbr_TOE) Security Assurance Requirements are identified in The [TOE](#abbr_TOE) Security Assurance Requirements are identified in [Table [20]{.counter}](#sartable){.sartable-ref [Table [20]{.counter}](#sartable){.sartable-ref onclick="showTarget('sartable')"}.\ onclick="showTarget('sartable')"}.\ \ \ [Table [20]{.counter}: Security Assurance Requirements]{#sartable .ctr [Table [20]{.counter}: Security Assurance Requirements]{#sartable .ctr myid="sartable" counter-type="ct-Table"} myid="sartable" counter-type="ct-Table"} -------------------------------- -------------------------------------------------- -------------------------------- -------------------------------------------------- Assurance Class Assurance Components Assurance Class Assurance Components Security Target (ASE) Conformance Claims (ASE_CCL.1) Security Target (ASE) Conformance Claims (ASE_CCL.1) Extended Components Definition (ASE_ECD.1) Extended Components Definition (ASE_ECD.1) [ST](#abbr_ST) Introduction (ASE_INT.1) [ST](#abbr_ST) Introduction (ASE_INT.1) Security Objectives for the Operational Environmen Security Objectives for the Operational Environmen Direct Rationale Security Requirements (ASE_REQ.1) Direct Rationale Security Requirements (ASE_REQ.1) Security Problem Definition (ASE_SPD.1) Security Problem Definition (ASE_SPD.1) [TOE](#abbr_TOE) Summary Specification (ASE_TSS.1) [TOE](#abbr_TOE) Summary Specification (ASE_TSS.1) Development (ADV) Basic Functional Specification ([ADV_FSP.1](#ADV_F Development (ADV) Basic Functional Specification ([ADV_FSP.1](#ADV_F Guidance Documents (AGD) Operational User Guidance ([AGD_OPE.1](#AGD_OPE.1) Guidance Documents (AGD) Operational User Guidance ([AGD_OPE.1](#AGD_OPE.1) Preparative Procedures ([AGD_PRE.1](#AGD_PRE.1)) Preparative Procedures ([AGD_PRE.1](#AGD_PRE.1)) Life Cycle Support (ALC) Labeling of the [TOE](#abbr_TOE) ([ALC_CMC.1](#ALC Life Cycle Support (ALC) Labeling of the [TOE](#abbr_TOE) ([ALC_CMC.1](#ALC [TOE](#abbr_TOE) CM Coverage ([ALC_CMS.1](#ALC_CMS [TOE](#abbr_TOE) CM Coverage ([ALC_CMS.1](#ALC_CMS Timely Security Updates ([ALC_TSU_EXT.1](#ALC_TSU_ Timely Security Updates ([ALC_TSU_EXT.1](#ALC_TSU_ Tests (ATE) Independent Testing -- Conformance ([ATE_IND.1](#A Tests (ATE) Independent Testing -- Conformance ([ATE_IND.1](#A Vulnerability Assessment (AVA) Vulnerability Survey ([AVA_VAN.1](#AVA_VAN.1)) Vulnerability Assessment (AVA) Vulnerability Survey ([AVA_VAN.1](#AVA_VAN.1)) -------------------------------- -------------------------------------------------- -------------------------------- -------------------------------------------------- ### 5.2.1 Class ASE: Security Target {#ase .indexable level="3"} ### 5.2.1 Class ASE: Security Target {#ase .indexable level="3"} The [ST](#abbr_ST) is evaluated as per ASE activities defined in the The [ST](#abbr_ST) is evaluated as per ASE activities defined in the [CEM](#abbr_CEM) for ASE_CCL.1, ASE_ECD.1, ASE_INT.1, ASE_OBJ.1, [CEM](#abbr_CEM) for ASE_CCL.1, ASE_ECD.1, ASE_INT.1, ASE_OBJ.1, ASE_REQ.1, ASE_SPD.1, and ASE_TSS.1. In addition, there may be ASE_REQ.1, ASE_SPD.1, and ASE_TSS.1. In addition, there may be Evaluation Activities specified within [Section 5.1 Security Functional Evaluation Activities specified within [Section 5.1 Security Functional Requirements](#sfr){.dynref} that call for necessary descriptions to be Requirements](#sfr){.dynref} that call for necessary descriptions to be included in the [TSS](#abbr_TSS) that are specific to the included in the [TSS](#abbr_TSS) that are specific to the [TOE](#abbr_TOE) technology type. [TOE](#abbr_TOE) technology type. ### 5.2.2 Class ADV: Development {#adv .indexable level="3"} ### 5.2.2 Class ADV: Development {#adv .indexable level="3"} The design information about the [TOE](#abbr_TOE) is contained in the The design information about the [TOE](#abbr_TOE) is contained in the guidance documentation available to the end user as well as the guidance documentation available to the end user as well as the [TSS](#abbr_TSS) portion of the [ST](#abbr_ST), and any additional [TSS](#abbr_TSS) portion of the [ST](#abbr_ST), and any additional information required by this [PP](#abbr_PP) that is not to be made information required by this [PP](#abbr_PP) that is not to be made public. public. ::: {#ADV_FSP.1 .comp} ::: {#ADV_FSP.1 .comp} #### ADV_FSP.1 Basic Functional Specification #### ADV_FSP.1 Basic Functional Specification The functional specification describes the [TOE](#abbr_TOE) Security The functional specification describes the [TOE](#abbr_TOE) Security Functions Interface ([TSFIs](#abbr_TSFI)). It is not necessary to have a Functions Interface ([TSFIs](#abbr_TSFI)). It is not necessary to have a formal or complete specification of these interfaces. Additionally, formal or complete specification of these interfaces. Additionally, because [TOEs](#abbr_TOE) conforming to this [PP](#abbr_PP) will because [TOEs](#abbr_TOE) conforming to this [PP](#abbr_PP) will necessarily have interfaces to the Operational Environment that are not necessarily have interfaces to the Operational Environment that are not directly invokable by [TOE](#abbr_TOE) users, there is little point directly invokable by [TOE](#abbr_TOE) users, there is little point specifying that such interfaces be described in and of themselves since specifying that such interfaces be described in and of themselves since only indirect testing of such interfaces may be possible. For this only indirect testing of such interfaces may be possible. For this [PP](#abbr_PP), the activities for this family should focus on [PP](#abbr_PP), the activities for this family should focus on understanding the interfaces presented in the [TSS](#abbr_TSS) in understanding the interfaces presented in the [TSS](#abbr_TSS) in response to the functional requirements and the interfaces presented in response to the functional requirements and the interfaces presented in the AGD documentation. No additional \"functional specification\" the AGD documentation. No additional \"functional specification\" documentation is necessary to satisfy the evaluation activities documentation is necessary to satisfy the evaluation activities specified.\ specified.\ \ \ Several [TSS](#abbr_TSS) evaluation activities reference the need for Several [TSS](#abbr_TSS) evaluation activities reference the need for the [TOE](#abbr_TOE) to have [API](#abbr_API) documentation to the [TOE](#abbr_TOE) to have [API](#abbr_API) documentation to demonstrate that certain functions exist and can be performed in the demonstrate that certain functions exist and can be performed in the manner required by this [PP](#abbr_PP). These evaluation activities manner required by this [PP](#abbr_PP). These evaluation activities reference \"other documentation\" as it may not be practical to include reference \"other documentation\" as it may not be practical to include this in the [TSS](#abbr_TSS) itself. Vendor [API](#abbr_API) this in the [TSS](#abbr_TSS) itself. Vendor [API](#abbr_API) documentation may exist outside the [ST](#abbr_ST) and be referenced documentation may exist outside the [ST](#abbr_ST) and be referenced separately.\ separately.\ \ \ The interfaces that need to be evaluated are characterized through the The interfaces that need to be evaluated are characterized through the information needed to perform the evaluation activities listed, rather information needed to perform the evaluation activities listed, rather than as an independent, abstract list. than as an independent, abstract list. #### Developer action elements: #### Developer action elements: ::: element ::: element ::: {#ADV_FSP.1.1D .reqid} ::: {#ADV_FSP.1.1D .reqid} [ADV_FSP.1.1D](#ADV_FSP.1.1D){.abbr} [ADV_FSP.1.1D](#ADV_FSP.1.1D){.abbr} ::: ::: ::: reqdesc ::: reqdesc The developer shall provide a functional specification. The developer shall provide a functional specification. ::: ::: ::: ::: ::: element ::: element ::: {#ADV_FSP.1.2D .reqid} ::: {#ADV_FSP.1.2D .reqid} [ADV_FSP.1.2D](#ADV_FSP.1.2D){.abbr} [ADV_FSP.1.2D](#ADV_FSP.1.2D){.abbr} ::: ::: ::: reqdesc ::: reqdesc The developer shall provide a tracing from the functional specification The developer shall provide a tracing from the functional specification to the [SFRs](#abbr_SFR). to the [SFRs](#abbr_SFR). ::: appnote ::: appnote [Application Note: ]{.note-header}[As indicated in the introduction to | [Application Note: ]{.note-header}[ As indicated in the introduction to this section, the functional specification is comprised of the this section, the functional specification is comprised of the information contained in the AGD_OPE, AGD_PRE, and the [API](#abbr_API) information contained in the AGD_OPE, AGD_PRE, and the [API](#abbr_API) information that is provided to application developers, including the information that is provided to application developers, including the APIs that require privilege to invoke.\ APIs that require privilege to invoke.\ \ \ The developer may reference a website accessible to application The developer may reference a website accessible to application developers and the evaluator. The [API](#abbr_API) documentation must developers and the evaluator. The [API](#abbr_API) documentation must include those interfaces required in this profile. The [API](#abbr_API) include those interfaces required in this profile. The [API](#abbr_API) documentation must clearly indicate to which products and versions each documentation must clearly indicate to which products and versions each available function applies.\ available function applies.\ \ \ The evaluation activities in the functional requirements point to The evaluation activities in the functional requirements point to evidence that should exist in the documentation and [TSS](#abbr_TSS) evidence that should exist in the documentation and [TSS](#abbr_TSS) section; since these are directly associated with the [SFRs](#abbr_SFR), section; since these are directly associated with the [SFRs](#abbr_SFR), the tracing in element [ADV_FSP.1.2D](#ADV_FSP.1.2D) is implicitly the tracing in element [ADV_FSP.1.2D](#ADV_FSP.1.2D) is implicitly already done and no additional documentation is necessary.]{.note} | already done and no additional documentation is necessary. ]{.note} ::: ::: ::: ::: ::: ::: #### Content and presentation elements: #### Content and presentation elements: ::: element ::: element ::: {#ADV_FSP.1.1C .reqid} ::: {#ADV_FSP.1.1C .reqid} [ADV_FSP.1.1C](#ADV_FSP.1.1C){.abbr} [ADV_FSP.1.1C](#ADV_FSP.1.1C){.abbr} ::: ::: ::: reqdesc ::: reqdesc The functional specification shall describe the purpose and method of The functional specification shall describe the purpose and method of use for each [SFR](#abbr_SFR)-enforcing and [SFR](#abbr_SFR)-supporting use for each [SFR](#abbr_SFR)-enforcing and [SFR](#abbr_SFR)-supporting [TSFI](#abbr_TSFI). [TSFI](#abbr_TSFI). ::: ::: ::: ::: ::: element ::: element ::: {#ADV_FSP.1.2C .reqid} ::: {#ADV_FSP.1.2C .reqid} [ADV_FSP.1.2C](#ADV_FSP.1.2C){.abbr} [ADV_FSP.1.2C](#ADV_FSP.1.2C){.abbr} ::: ::: ::: reqdesc ::: reqdesc The functional specification shall identify all parameters associated The functional specification shall identify all parameters associated with each [SFR](#abbr_SFR)-enforcing and [SFR](#abbr_SFR)-supporting with each [SFR](#abbr_SFR)-enforcing and [SFR](#abbr_SFR)-supporting [TSFI](#abbr_TSFI). [TSFI](#abbr_TSFI). ::: ::: ::: ::: ::: element ::: element ::: {#ADV_FSP.1.3C .reqid} ::: {#ADV_FSP.1.3C .reqid} [ADV_FSP.1.3C](#ADV_FSP.1.3C){.abbr} [ADV_FSP.1.3C](#ADV_FSP.1.3C){.abbr} ::: ::: ::: reqdesc ::: reqdesc The functional specification shall provide rationale for the implicit The functional specification shall provide rationale for the implicit categorization of interfaces as [SFR](#abbr_SFR)-non-interfering. categorization of interfaces as [SFR](#abbr_SFR)-non-interfering. ::: ::: ::: ::: ::: element ::: element ::: {#ADV_FSP.1.4C .reqid} ::: {#ADV_FSP.1.4C .reqid} [ADV_FSP.1.4C](#ADV_FSP.1.4C){.abbr} [ADV_FSP.1.4C](#ADV_FSP.1.4C){.abbr} ::: ::: ::: reqdesc ::: reqdesc The tracing shall demonstrate that the [SFRs](#abbr_SFR) trace to The tracing shall demonstrate that the [SFRs](#abbr_SFR) trace to [TSFIs](#abbr_TSFI) in the functional specification. [TSFIs](#abbr_TSFI) in the functional specification. ::: ::: ::: ::: #### Evaluator action elements: #### Evaluator action elements: ::: element ::: element ::: {#ADV_FSP.1.1E .reqid} ::: {#ADV_FSP.1.1E .reqid} [ADV_FSP.1.1E](#ADV_FSP.1.1E){.abbr} [ADV_FSP.1.1E](#ADV_FSP.1.1E){.abbr} ::: ::: ::: reqdesc ::: reqdesc The evaluator shall confirm that the information provided meets all The evaluator shall confirm that the information provided meets all requirements for content and presentation of evidence. requirements for content and presentation of evidence. ::: ::: ::: ::: ::: element ::: element ::: {#ADV_FSP.1.2E .reqid} ::: {#ADV_FSP.1.2E .reqid} [ADV_FSP.1.2E](#ADV_FSP.1.2E){.abbr} [ADV_FSP.1.2E](#ADV_FSP.1.2E){.abbr} ::: ::: ::: reqdesc ::: reqdesc The evaluator shall determine that the functional specification is an The evaluator shall determine that the functional specification is an accurate and complete instantiation of the [SFRs](#abbr_SFR). accurate and complete instantiation of the [SFRs](#abbr_SFR). ::: ::: ::: ::: ::: {.activity_pane .hide} ::: {.activity_pane .hide} ::: activity_pane_header ::: activity_pane_header [[ Evaluation Activities [[ Evaluation Activities ]{.activity_pane_label}[]{.toggler}](#){onclick="toggle(this);return false;"} ]{.activity_pane_label}[]{.toggler}](#){onclick="toggle(this);return false;"} ::: ::: ::: activity_pane_body ::: activity_pane_body ::: component-activity-header ::: component-activity-header [ADV_FSP.1](#ADV_FSP.1) [ADV_FSP.1](#ADV_FSP.1) ::: ::: There are no specific evaluation activities associated with these There are no specific evaluation activities associated with these [SARs](#abbr_SAR), except ensuring the information is provided. The [SARs](#abbr_SAR), except ensuring the information is provided. The functional specification documentation is provided to support the functional specification documentation is provided to support the evaluation activities described in [Section 5.1 Security Functional evaluation activities described in [Section 5.1 Security Functional Requirements](#sfr){.dynref}, and other activities described for AGD, Requirements](#sfr){.dynref}, and other activities described for AGD, ATE, and AVA [SARs](#abbr_SAR). The requirements on the content of the ATE, and AVA [SARs](#abbr_SAR). The requirements on the content of the functional specification information is implicitly assessed by virtue of functional specification information is implicitly assessed by virtue of the other evaluation activities being performed; if the evaluator is the other evaluation activities being performed; if the evaluator is unable to perform an activity because there is insufficient interface unable to perform an activity because there is insufficient interface information, then an adequate functional specification has not been information, then an adequate functional specification has not been provided. provided. ::: ::: ::: ::: ::: ::: ### 5.2.3 Class AGD: Guidance Documentation {#agd .indexable level="3"} ### 5.2.3 Class AGD: Guidance Documentation {#agd .indexable level="3"} The guidance documents will be provided with the [ST](#abbr_ST). The guidance documents will be provided with the [ST](#abbr_ST). Guidance must include a description of how the IT personnel verifies Guidance must include a description of how the IT personnel verifies that the Operational Environment can fulfill its role for the security that the Operational Environment can fulfill its role for the security functionality. The documentation should be in an informal style and functionality. The documentation should be in an informal style and readable by the IT personnel.\ readable by the IT personnel.\ \ \ Guidance must be provided for every operational environment that the Guidance must be provided for every operational environment that the product supports as claimed in the [ST](#abbr_ST). This guidance product supports as claimed in the [ST](#abbr_ST). This guidance includes: includes: - Instructions to successfully install the [TSF](#abbr_TSF) in that - Instructions to successfully install the [TSF](#abbr_TSF) in that environment environment - Instructions to manage the security of the [TSF](#abbr_TSF) as a - Instructions to manage the security of the [TSF](#abbr_TSF) as a product and as a component of the larger operational environment product and as a component of the larger operational environment - Instructions to provide a protected administrative capability - Instructions to provide a protected administrative capability \ \ Guidance pertaining to particular security functionality is also Guidance pertaining to particular security functionality is also provided; requirements on such guidance are contained in the evaluation provided; requirements on such guidance are contained in the evaluation activities specified with each requirement. activities specified with each requirement. ::: {#AGD_OPE.1 .comp} ::: {#AGD_OPE.1 .comp} #### AGD_OPE.1 Operational User Guidance #### AGD_OPE.1 Operational User Guidance #### Developer action elements: #### Developer action elements: ::: element ::: element ::: {#AGD_OPE.1.1D .reqid} ::: {#AGD_OPE.1.1D .reqid} [AGD_OPE.1.1D](#AGD_OPE.1.1D){.abbr} [AGD_OPE.1.1D](#AGD_OPE.1.1D){.abbr} ::: ::: ::: reqdesc ::: reqdesc The developer shall provide operational user guidance. The developer shall provide operational user guidance. ::: appnote ::: appnote [Application Note: ]{.note-header}[The operational user guidance does | [Application Note: ]{.note-header}[ The operational user guidance does not have to be contained in a single document. Guidance to users, not have to be contained in a single document. Guidance to users, administrators and application developers can be spread among documents administrators and application developers can be spread among documents or web pages. Where appropriate, the guidance documentation is expressed or web pages. Where appropriate, the guidance documentation is expressed in the eXtensible Configuration Checklist Description Format in the eXtensible Configuration Checklist Description Format ([XCCDF](#abbr_XCCDF)) to support security automation.\ ([XCCDF](#abbr_XCCDF)) to support security automation.\ \ \ Rather than repeat information here, the developer should review the Rather than repeat information here, the developer should review the evaluation activities for this component to ascertain the specifics of evaluation activities for this component to ascertain the specifics of the guidance that the evaluator will be checking for. This will provide the guidance that the evaluator will be checking for. This will provide the necessary information for the preparation of acceptable | the necessary information for the preparation of acceptable guidance. guidance.]{.note} | ]{.note} ::: ::: ::: ::: ::: ::: #### Content and presentation elements: #### Content and presentation elements: ::: element ::: element ::: {#AGD_OPE.1.1C .reqid} ::: {#AGD_OPE.1.1C .reqid} [AGD_OPE.1.1C](#AGD_OPE.1.1C){.abbr} [AGD_OPE.1.1C](#AGD_OPE.1.1C){.abbr} ::: ::: ::: reqdesc ::: reqdesc The operational user guidance shall describe, for each user role, the The operational user guidance shall describe, for each user role, the user-accessible functions and privileges that should be controlled in a user-accessible functions and privileges that should be controlled in a secure processing environment, including appropriate warnings. secure processing environment, including appropriate warnings. ::: appnote ::: appnote [Application Note: ]{.note-header}[User and administrator (e.g., [Application Note: ]{.note-header}[User and administrator (e.g., [MDM](#abbr_MDM) agent), and application developer are to be considered [MDM](#abbr_MDM) agent), and application developer are to be considered in the definition of user role.]{.note} in the definition of user role.]{.note} ::: ::: ::: ::: ::: ::: ::: element ::: element ::: {#AGD_OPE.1.2C .reqid} ::: {#AGD_OPE.1.2C .reqid} [AGD_OPE.1.2C](#AGD_OPE.1.2C){.abbr} [AGD_OPE.1.2C](#AGD_OPE.1.2C){.abbr} ::: ::: ::: reqdesc ::: reqdesc The operational user guidance shall describe, for each user role, how to The operational user guidance shall describe, for each user role, how to use the available interfaces provided by the [TOE](#abbr_TOE) in a use the available interfaces provided by the [TOE](#abbr_TOE) in a secure manner. secure manner. ::: ::: ::: ::: ::: element ::: element ::: {#AGD_OPE.1.3C .reqid} ::: {#AGD_OPE.1.3C .reqid} [AGD_OPE.1.3C](#AGD_OPE.1.3C){.abbr} [AGD_OPE.1.3C](#AGD_OPE.1.3C){.abbr} ::: ::: ::: reqdesc ::: reqdesc The operational user guidance shall describe, for each user role, the The operational user guidance shall describe, for each user role, the available functions and interfaces, in particular all security available functions and interfaces, in particular all security parameters under the control of the user, indicating secure values as parameters under the control of the user, indicating secure values as appropriate. appropriate. ::: ::: ::: ::: ::: element ::: element ::: {#AGD_OPE.1.4C .reqid} ::: {#AGD_OPE.1.4C .reqid} [AGD_OPE.1.4C](#AGD_OPE.1.4C){.abbr} [AGD_OPE.1.4C](#AGD_OPE.1.4C){.abbr} ::: ::: ::: reqdesc ::: reqdesc The operational user guidance shall, for each user role, clearly present The operational user guidance shall, for each user role, clearly present each type of security-relevant event relative to the user-accessible each type of security-relevant event relative to the user-accessible functions that need to be performed, including changing the security functions that need to be performed, including changing the security characteristics of entities under the control of the [TSF](#abbr_TSF). characteristics of entities under the control of the [TSF](#abbr_TSF). ::: ::: ::: ::: ::: element ::: element ::: {#AGD_OPE.1.5C .reqid} ::: {#AGD_OPE.1.5C .reqid} [AGD_OPE.1.5C](#AGD_OPE.1.5C){.abbr} [AGD_OPE.1.5C](#AGD_OPE.1.5C){.abbr} ::: ::: ::: reqdesc ::: reqdesc The operational user guidance shall identify all possible modes of The operational user guidance shall identify all possible modes of operation of the [OS](#abbr_OS) (including operation following failure operation of the [OS](#abbr_OS) (including operation following failure or operational error), their consequences, and implications for or operational error), their consequences, and implications for maintaining secure operation. maintaining secure operation. ::: ::: ::: ::: ::: element ::: element ::: {#AGD_OPE.1.6C .reqid} ::: {#AGD_OPE.1.6C .reqid} [AGD_OPE.1.6C](#AGD_OPE.1.6C){.abbr} [AGD_OPE.1.6C](#AGD_OPE.1.6C){.abbr} ::: ::: ::: reqdesc ::: reqdesc The operational user guidance shall, for each user role, describe the The operational user guidance shall, for each user role, describe the security measures to be followed in order to fulfill the security security measures to be followed in order to fulfill the security objectives for the operational environment as described in the objectives for the operational environment as described in the [ST](#abbr_ST). [ST](#abbr_ST). ::: ::: ::: ::: ::: element ::: element ::: {#AGD_OPE.1.7C .reqid} ::: {#AGD_OPE.1.7C .reqid} [AGD_OPE.1.7C](#AGD_OPE.1.7C){.abbr} [AGD_OPE.1.7C](#AGD_OPE.1.7C){.abbr} ::: ::: ::: reqdesc ::: reqdesc The operational user guidance shall be clear and reasonable. The operational user guidance shall be clear and reasonable. ::: ::: ::: ::: #### Evaluator action elements: #### Evaluator action elements: ::: element ::: element ::: {#AGD_OPE.1.1E .reqid} ::: {#AGD_OPE.1.1E .reqid} [AGD_OPE.1.1E](#AGD_OPE.1.1E){.abbr} [AGD_OPE.1.1E](#AGD_OPE.1.1E){.abbr} ::: ::: ::: reqdesc ::: reqdesc The evaluator shall confirm that the information provided meets all The evaluator shall confirm that the information provided meets all requirements for content and presentation of evidence. requirements for content and presentation of evidence. ::: ::: ::: ::: ::: {.activity_pane .hide} ::: {.activity_pane .hide} ::: activity_pane_header ::: activity_pane_header [[ Evaluation Activities [[ Evaluation Activities ]{.activity_pane_label}[]{.toggler}](#){onclick="toggle(this);return false;"} ]{.activity_pane_label}[]{.toggler}](#){onclick="toggle(this);return false;"} ::: ::: ::: activity_pane_body ::: activity_pane_body ::: component-activity-header ::: component-activity-header [AGD_OPE.1](#AGD_OPE.1) [AGD_OPE.1](#AGD_OPE.1) ::: ::: Some of the contents of the operational guidance are verified by the Some of the contents of the operational guidance are verified by the evaluation activities in [Section 5.1 Security Functional evaluation activities in [Section 5.1 Security Functional Requirements](#sfr){.dynref} and evaluation of the [TOE](#abbr_TOE) Requirements](#sfr){.dynref} and evaluation of the [TOE](#abbr_TOE) according to the [\[CEM\]](#bibCEM){.dynref format=""}. The following according to the [\[CEM\]](#bibCEM){.dynref format=""}. The following additional information is also required.\ additional information is also required.\ \ \ The operational guidance shall contain a list of natively installed The operational guidance shall contain a list of natively installed applications and any relevant version numbers. If any third party applications and any relevant version numbers. If any third party vendors are permitted to install applications before purchase by the end vendors are permitted to install applications before purchase by the end user or enterprise, these applications shall also be listed.\ user or enterprise, these applications shall also be listed.\ \ \ The operational guidance shall contain instructions for configuring the The operational guidance shall contain instructions for configuring the cryptographic engine associated with the evaluated configuration of the cryptographic engine associated with the evaluated configuration of the [TOE](#abbr_TOE). It shall provide a warning to the administrator that [TOE](#abbr_TOE). It shall provide a warning to the administrator that use of other cryptographic engines was not evaluated nor tested during use of other cryptographic engines was not evaluated nor tested during the [CC](#abbr_CC) evaluation of the [TOE](#abbr_TOE).\ the [CC](#abbr_CC) evaluation of the [TOE](#abbr_TOE).\ \ \ The documentation must describe the process for verifying updates to the The documentation must describe the process for verifying updates to the [TOE](#abbr_TOE) by verifying a digital signature. The evaluator shall [TOE](#abbr_TOE) by verifying a digital signature. The evaluator shall verify that this process includes the following steps: verify that this process includes the following steps: - Instructions for obtaining the update itself. This should include - Instructions for obtaining the update itself. This should include instructions for making the update accessible to the instructions for making the update accessible to the [TOE](#abbr_TOE) (e.g., placement in a specific directory). [TOE](#abbr_TOE) (e.g., placement in a specific directory). - Instructions for initiating the update process, as well as - Instructions for initiating the update process, as well as discerning whether the process was successful or unsuccessful. This discerning whether the process was successful or unsuccessful. This includes generation of the hash/digital signature. includes generation of the hash/digital signature. The [TOE](#abbr_TOE) will likely contain security functionality that The [TOE](#abbr_TOE) will likely contain security functionality that does not fall in the scope of evaluation under this [PP](#abbr_PP). The does not fall in the scope of evaluation under this [PP](#abbr_PP). The operational guidance shall make it clear to an administrator which operational guidance shall make it clear to an administrator which security functionality is covered by the evaluation activities. security functionality is covered by the evaluation activities. ::: ::: ::: ::: ::: ::: ::: {#AGD_PRE.1 .comp} ::: {#AGD_PRE.1 .comp} #### AGD_PRE.1 Preparative Procedures #### AGD_PRE.1 Preparative Procedures #### Developer action elements: #### Developer action elements: ::: element ::: element ::: {#AGD_PRE.1.1D .reqid} ::: {#AGD_PRE.1.1D .reqid} [AGD_PRE.1.1D](#AGD_PRE.1.1D){.abbr} [AGD_PRE.1.1D](#AGD_PRE.1.1D){.abbr} ::: ::: ::: reqdesc ::: reqdesc The developer shall provide the [TOE](#abbr_TOE), including its The developer shall provide the [TOE](#abbr_TOE), including its preparative procedures. preparative procedures. ::: appnote ::: appnote [Application Note: ]{.note-header}[As with the operational guidance, the [Application Note: ]{.note-header}[As with the operational guidance, the developer should look to the evaluation activities to determine the developer should look to the evaluation activities to determine the required content with respect to preparative procedures.]{.note} required content with respect to preparative procedures.]{.note} ::: ::: ::: ::: ::: ::: #### Content and presentation elements: #### Content and presentation elements: ::: element ::: element ::: {#AGD_PRE.1.1C .reqid} ::: {#AGD_PRE.1.1C .reqid} [AGD_PRE.1.1C](#AGD_PRE.1.1C){.abbr} [AGD_PRE.1.1C](#AGD_PRE.1.1C){.abbr} ::: ::: ::: reqdesc ::: reqdesc The preparative procedures shall describe all the steps necessary for The preparative procedures shall describe all the steps necessary for secure acceptance of the delivered [TOE](#abbr_TOE) in accordance with secure acceptance of the delivered [TOE](#abbr_TOE) in accordance with the developer\'s delivery procedures. the developer\'s delivery procedures. ::: ::: ::: ::: ::: element ::: element ::: {#AGD_PRE.1.2C .reqid} ::: {#AGD_PRE.1.2C .reqid} [AGD_PRE.1.2C](#AGD_PRE.1.2C){.abbr} [AGD_PRE.1.2C](#AGD_PRE.1.2C){.abbr} ::: ::: ::: reqdesc ::: reqdesc The preparative procedures shall describe all the steps necessary for The preparative procedures shall describe all the steps necessary for secure installation of the [TOE](#abbr_TOE) and for the secure secure installation of the [TOE](#abbr_TOE) and for the secure preparation of the operational environment in accordance with the preparation of the operational environment in accordance with the security objectives for the operational environment as described in the security objectives for the operational environment as described in the [ST](#abbr_ST). [ST](#abbr_ST). ::: ::: ::: ::: #### Evaluator action elements: #### Evaluator action elements: ::: element ::: element ::: {#AGD_PRE.1.1E .reqid} ::: {#AGD_PRE.1.1E .reqid} [AGD_PRE.1.1E](#AGD_PRE.1.1E){.abbr} [AGD_PRE.1.1E](#AGD_PRE.1.1E){.abbr} ::: ::: ::: reqdesc ::: reqdesc The evaluator shall confirm that the information provided meets all The evaluator shall confirm that the information provided meets all requirements for content and presentation of evidence. requirements for content and presentation of evidence. ::: ::: ::: ::: ::: element ::: element ::: {#AGD_PRE.1.2E .reqid} ::: {#AGD_PRE.1.2E .reqid} [AGD_PRE.1.2E](#AGD_PRE.1.2E){.abbr} [AGD_PRE.1.2E](#AGD_PRE.1.2E){.abbr} ::: ::: ::: reqdesc ::: reqdesc The evaluator shall apply the preparative procedures to confirm that the The evaluator shall apply the preparative procedures to confirm that the [OS](#abbr_OS) can be prepared securely for operation. [OS](#abbr_OS) can be prepared securely for operation. ::: ::: ::: ::: ::: {.activity_pane .hide} ::: {.activity_pane .hide} ::: activity_pane_header ::: activity_pane_header [[ Evaluation Activities [[ Evaluation Activities ]{.activity_pane_label}[]{.toggler}](#){onclick="toggle(this);return false;"} ]{.activity_pane_label}[]{.toggler}](#){onclick="toggle(this);return false;"} ::: ::: ::: activity_pane_body ::: activity_pane_body ::: component-activity-header ::: component-activity-header [AGD_PRE.1](#AGD_PRE.1) [AGD_PRE.1](#AGD_PRE.1) ::: ::: As indicated in the introduction above, there are significant As indicated in the introduction above, there are significant expectations with respect to the documentation---especially when expectations with respect to the documentation---especially when configuring the operational environment to support [TOE](#abbr_TOE) configuring the operational environment to support [TOE](#abbr_TOE) functional requirements. The evaluator shall check to ensure that the functional requirements. The evaluator shall check to ensure that the guidance provided for the [TOE](#abbr_TOE) adequately addresses all guidance provided for the [TOE](#abbr_TOE) adequately addresses all platforms claimed for the [TOE](#abbr_TOE) in the [ST](#abbr_ST). platforms claimed for the [TOE](#abbr_TOE) in the [ST](#abbr_ST). ::: ::: ::: ::: ::: ::: ### 5.2.4 Class ALC: Life-cycle Support {#alc .indexable level="3"} ### 5.2.4 Class ALC: Life-cycle Support {#alc .indexable level="3"} At the assurance level provided for [TOEs](#abbr_TOE) conformant to this At the assurance level provided for [TOEs](#abbr_TOE) conformant to this [PP](#abbr_PP), life-cycle support is limited to end-user-visible [PP](#abbr_PP), life-cycle support is limited to end-user-visible aspects of the life-cycle, rather than an examination of the aspects of the life-cycle, rather than an examination of the [TOE](#abbr_TOE) vendor's development and configuration management [TOE](#abbr_TOE) vendor's development and configuration management process. This is not meant to diminish the critical role that a process. This is not meant to diminish the critical role that a developer's practices play in contributing to the overall developer's practices play in contributing to the overall trustworthiness of a product; rather, it is a reflection on the trustworthiness of a product; rather, it is a reflection on the information to be made available for evaluation at this assurance level. information to be made available for evaluation at this assurance level. ::: {#ALC_CMC.1 .comp} ::: {#ALC_CMC.1 .comp} #### ALC_CMC.1 Labeling of the TOE #### ALC_CMC.1 Labeling of the TOE This component is targeted at identifying the [TOE](#abbr_TOE) such that This component is targeted at identifying the [TOE](#abbr_TOE) such that it can be distinguished from other products or versions from the same it can be distinguished from other products or versions from the same vendor and can be easily specified when being procured by an end user. vendor and can be easily specified when being procured by an end user. #### Developer action elements: #### Developer action elements: ::: element ::: element ::: {#ALC_CMC.1.1D .reqid} ::: {#ALC_CMC.1.1D .reqid} [ALC_CMC.1.1D](#ALC_CMC.1.1D){.abbr} [ALC_CMC.1.1D](#ALC_CMC.1.1D){.abbr} ::: ::: ::: reqdesc ::: reqdesc The developer shall provide the [TOE](#abbr_TOE) and a reference for the The developer shall provide the [TOE](#abbr_TOE) and a reference for the [TOE](#abbr_TOE). [TOE](#abbr_TOE). ::: ::: ::: ::: #### Content and presentation elements: #### Content and presentation elements: ::: element ::: element ::: {#ALC_CMC.1.1C .reqid} ::: {#ALC_CMC.1.1C .reqid} [ALC_CMC.1.1C](#ALC_CMC.1.1C){.abbr} [ALC_CMC.1.1C](#ALC_CMC.1.1C){.abbr} ::: ::: ::: reqdesc ::: reqdesc The [TOE](#abbr_TOE) shall be labeled with a unique reference. The [TOE](#abbr_TOE) shall be labeled with a unique reference. ::: ::: ::: ::: #### Evaluator action elements: #### Evaluator action elements: ::: element ::: element ::: {#ALC_CMC.1.1E .reqid} ::: {#ALC_CMC.1.1E .reqid} [ALC_CMC.1.1E](#ALC_CMC.1.1E){.abbr} [ALC_CMC.1.1E](#ALC_CMC.1.1E){.abbr} ::: ::: ::: reqdesc ::: reqdesc The evaluator shall confirm that the information provided meets all The evaluator shall confirm that the information provided meets all requirements for content and presentation of evidence. requirements for content and presentation of evidence. ::: ::: ::: ::: ::: {.activity_pane .hide} ::: {.activity_pane .hide} ::: activity_pane_header ::: activity_pane_header [[ Evaluation Activities [[ Evaluation Activities ]{.activity_pane_label}[]{.toggler}](#){onclick="toggle(this);return false;"} ]{.activity_pane_label}[]{.toggler}](#){onclick="toggle(this);return false;"} ::: ::: ::: activity_pane_body ::: activity_pane_body ::: component-activity-header ::: component-activity-header [ALC_CMC.1](#ALC_CMC.1) [ALC_CMC.1](#ALC_CMC.1) ::: ::: The evaluator shall check the [ST](#abbr_ST) to ensure that it contains The evaluator shall check the [ST](#abbr_ST) to ensure that it contains an identifier (such as a product name/version number) that specifically an identifier (such as a product name/version number) that specifically identifies the version that meets the requirements of the identifies the version that meets the requirements of the [ST](#abbr_ST). Further, the evaluator shall check the AGD guidance and [ST](#abbr_ST). Further, the evaluator shall check the AGD guidance and [TOE](#abbr_TOE) samples received for testing to ensure that the version [TOE](#abbr_TOE) samples received for testing to ensure that the version number is consistent with that in the [ST](#abbr_ST). If the vendor number is consistent with that in the [ST](#abbr_ST). If the vendor maintains a web site advertising the [TOE](#abbr_TOE), the evaluator maintains a web site advertising the [TOE](#abbr_TOE), the evaluator shall examine the information on the web site to ensure that the shall examine the information on the web site to ensure that the information in the [ST](#abbr_ST) is sufficient to distinguish the information in the [ST](#abbr_ST) is sufficient to distinguish the product. product. ::: ::: ::: ::: ::: ::: ::: {#ALC_CMS.1 .comp} ::: {#ALC_CMS.1 .comp} #### ALC_CMS.1 TOE CM Coverage #### ALC_CMS.1 TOE CM Coverage Given the scope of the [TOE](#abbr_TOE) and its associated evaluation Given the scope of the [TOE](#abbr_TOE) and its associated evaluation evidence requirements, this component's evaluation activities are evidence requirements, this component's evaluation activities are covered by the evaluation activities listed for [ALC_CMC.1](#ALC_CMC.1). covered by the evaluation activities listed for [ALC_CMC.1](#ALC_CMC.1). #### Developer action elements: #### Developer action elements: ::: element ::: element ::: {#ALC_CMS.1.1D .reqid} ::: {#ALC_CMS.1.1D .reqid} [ALC_CMS.1.1D](#ALC_CMS.1.1D){.abbr} [ALC_CMS.1.1D](#ALC_CMS.1.1D){.abbr} ::: ::: ::: reqdesc ::: reqdesc The developer shall provide a configuration list for the The developer shall provide a configuration list for the [TOE](#abbr_TOE). [TOE](#abbr_TOE). ::: ::: ::: ::: #### Content and presentation elements: #### Content and presentation elements: ::: element ::: element ::: {#ALC_CMS.1.1C .reqid} ::: {#ALC_CMS.1.1C .reqid} [ALC_CMS.1.1C](#ALC_CMS.1.1C){.abbr} [ALC_CMS.1.1C](#ALC_CMS.1.1C){.abbr} ::: ::: ::: reqdesc ::: reqdesc The configuration list shall include the following: the [TOE](#abbr_TOE) The configuration list shall include the following: the [TOE](#abbr_TOE) itself; and the evaluation evidence required by the [SARs](#abbr_SAR). itself; and the evaluation evidence required by the [SARs](#abbr_SAR). ::: ::: ::: ::: ::: element ::: element ::: {#ALC_CMS.1.2C .reqid} ::: {#ALC_CMS.1.2C .reqid} [ALC_CMS.1.2C](#ALC_CMS.1.2C){.abbr} [ALC_CMS.1.2C](#ALC_CMS.1.2C){.abbr} ::: ::: ::: reqdesc ::: reqdesc The configuration list shall uniquely identify the configuration items. The configuration list shall uniquely identify the configuration items. ::: ::: ::: ::: #### Evaluator action elements: #### Evaluator action elements: ::: element ::: element ::: {#ALC_CMS.1.1E .reqid} ::: {#ALC_CMS.1.1E .reqid} [ALC_CMS.1.1E](#ALC_CMS.1.1E){.abbr} [ALC_CMS.1.1E](#ALC_CMS.1.1E){.abbr} ::: ::: ::: reqdesc ::: reqdesc The evaluator shall confirm that the information provided meets all The evaluator shall confirm that the information provided meets all requirements for content and presentation of evidence. requirements for content and presentation of evidence. ::: appnote ::: appnote [Application Note: ]{.note-header}[ The \"evaluation evidence required [Application Note: ]{.note-header}[ The \"evaluation evidence required by the [SARs](#abbr_SAR)\" in this [PP](#abbr_PP) is limited to the by the [SARs](#abbr_SAR)\" in this [PP](#abbr_PP) is limited to the information in the [ST](#abbr_ST) coupled with the guidance provided to information in the [ST](#abbr_ST) coupled with the guidance provided to administrators and users under the AGD requirements. By ensuring that administrators and users under the AGD requirements. By ensuring that the [TOE](#abbr_TOE) is specifically identified and that this the [TOE](#abbr_TOE) is specifically identified and that this identification is consistent in the [ST](#abbr_ST) and in the AGD identification is consistent in the [ST](#abbr_ST) and in the AGD guidance (as done in the evaluation activity for guidance (as done in the evaluation activity for [ALC_CMC.1](#ALC_CMC.1)), the evaluator implicitly confirms the [ALC_CMC.1](#ALC_CMC.1)), the evaluator implicitly confirms the information required by this component.\ information required by this component.\ \ \ Life-cycle support is targeted aspects of the developer's life-cycle and Life-cycle support is targeted aspects of the developer's life-cycle and instructions to providers of applications for the developer's devices, instructions to providers of applications for the developer's devices, rather than an in-depth examination of the [TSF](#abbr_TSF) rather than an in-depth examination of the [TSF](#abbr_TSF) manufacturer's development and configuration management process. This is manufacturer's development and configuration management process. This is not meant to diminish the critical role that a developer's practices not meant to diminish the critical role that a developer's practices play in contributing to the overall trustworthiness of a product; play in contributing to the overall trustworthiness of a product; rather, it's a reflection on the information to be made available for rather, it's a reflection on the information to be made available for evaluation.]{.note} | evaluation. ]{.note} ::: ::: ::: ::: ::: ::: ::: {.activity_pane .hide} ::: {.activity_pane .hide} ::: activity_pane_header ::: activity_pane_header [[ Evaluation Activities [[ Evaluation Activities ]{.activity_pane_label}[]{.toggler}](#){onclick="toggle(this);return false;"} ]{.activity_pane_label}[]{.toggler}](#){onclick="toggle(this);return false;"} ::: ::: ::: activity_pane_body ::: activity_pane_body ::: component-activity-header ::: component-activity-header [ALC_CMS.1](#ALC_CMS.1) [ALC_CMS.1](#ALC_CMS.1) ::: ::: The evaluator shall ensure that the developer has identified (in The evaluator shall ensure that the developer has identified (in public-facing development guidance for their platform) one or more public-facing development guidance for their platform) one or more development environments appropriate for use in developing applications development environments appropriate for use in developing applications for the developer's platform. For each of these development for the developer's platform. For each of these development environments, the developer shall provide information on how to environments, the developer shall provide information on how to configure the environment to ensure that buffer overflow protection configure the environment to ensure that buffer overflow protection mechanisms in the environments are invoked (e.g., compiler and linker mechanisms in the environments are invoked (e.g., compiler and linker flags). The evaluator shall ensure that this documentation also includes flags). The evaluator shall ensure that this documentation also includes an indication of whether such protections are on by default, or have to an indication of whether such protections are on by default, or have to be specifically enabled.\ be specifically enabled.\ \ \ The evaluator shall ensure that the [TSF](#abbr_TSF) is uniquely The evaluator shall ensure that the [TSF](#abbr_TSF) is uniquely identified (with respect to other products from the [TSF](#abbr_TSF) identified (with respect to other products from the [TSF](#abbr_TSF) vendor), and that documentation provided by the developer in association vendor), and that documentation provided by the developer in association with the requirements in the [ST](#abbr_ST) is associated with the with the requirements in the [ST](#abbr_ST) is associated with the [TSF](#abbr_TSF) using this unique identification. [TSF](#abbr_TSF) using this unique identification. ::: ::: ::: ::: ::: ::: ::: {#ALC_TSU_EXT.1 .comp} ::: {#ALC_TSU_EXT.1 .comp} #### ALC_TSU_EXT.1 Timely Security Updates #### ALC_TSU_EXT.1 Timely Security Updates This component requires the [TOE](#abbr_TOE) developer, in conjunction This component requires the [TOE](#abbr_TOE) developer, in conjunction with any other necessary parties, to provide information as to how the with any other necessary parties, to provide information as to how the end-user devices are updated to address security issues in a timely end-user devices are updated to address security issues in a timely manner. The documentation describes the process of providing updates to manner. The documentation describes the process of providing updates to the public from the time a security flaw is reported/discovered, to the the public from the time a security flaw is reported/discovered, to the time an update is released. This description includes the parties time an update is released. This description includes the parties involved (e.g., the developer, cellular carriers) and the steps that are involved (e.g., the developer, cellular carriers) and the steps that are performed (e.g., developer testing, carrier testing), including performed (e.g., developer testing, carrier testing), including worst-case time periods, before an update is made available to the worst-case time periods, before an update is made available to the public. public. #### Developer action elements: #### Developer action elements: ::: element ::: element ::: {#ALC_TSU_EXT.1.1D .reqid} ::: {#ALC_TSU_EXT.1.1D .reqid} [ALC_TSU_EXT.1.1D](#ALC_TSU_EXT.1.1D){.abbr} [ALC_TSU_EXT.1.1D](#ALC_TSU_EXT.1.1D){.abbr} ::: ::: ::: reqdesc ::: reqdesc The developer shall provide a description in the [TSS](#abbr_TSS) of how The developer shall provide a description in the [TSS](#abbr_TSS) of how timely security updates are made to the [TOE](#abbr_TOE). timely security updates are made to the [TOE](#abbr_TOE). ::: ::: ::: ::: #### Content and presentation elements: #### Content and presentation elements: ::: element ::: element ::: {#ALC_TSU_EXT.1.1C .reqid} ::: {#ALC_TSU_EXT.1.1C .reqid} [ALC_TSU_EXT.1.1C](#ALC_TSU_EXT.1.1C){.abbr} [ALC_TSU_EXT.1.1C](#ALC_TSU_EXT.1.1C){.abbr} ::: ::: ::: reqdesc ::: reqdesc The description shall include the process for creating and deploying The description shall include the process for creating and deploying security updates for the [TOE](#abbr_TOE) software. security updates for the [TOE](#abbr_TOE) software. ::: appnote ::: appnote [ Note: ]{.note-header}[The software to be described includes the | [Application Note: ]{.note-header}[The software to be described includes operating systems of the application processor and the baseband | the operating systems of the application processor and the baseband processor, as well as any firmware and applications. The process processor, as well as any firmware and applications. The process description includes the [TOE](#abbr_TOE) developer processes as well as description includes the [TOE](#abbr_TOE) developer processes as well as any third-party (carrier) processes. The process description includes any third-party (carrier) processes. The process description includes each deployment mechanism (e.g., over-the-air updates, per-carrier each deployment mechanism (e.g., over-the-air updates, per-carrier updates, downloaded updates).]{.note} updates, downloaded updates).]{.note} ::: ::: ::: ::: ::: ::: ::: element ::: element ::: {#ALC_TSU_EXT.1.2C .reqid} ::: {#ALC_TSU_EXT.1.2C .reqid} [ALC_TSU_EXT.1.2C](#ALC_TSU_EXT.1.2C){.abbr} [ALC_TSU_EXT.1.2C](#ALC_TSU_EXT.1.2C){.abbr} ::: ::: ::: reqdesc ::: reqdesc The description shall express the time window as the length of time, in The description shall express the time window as the length of time, in days, between public disclosure of a vulnerability and the public days, between public disclosure of a vulnerability and the public availability of security updates to the [TOE](#abbr_TOE). availability of security updates to the [TOE](#abbr_TOE). ::: appnote ::: appnote [ Note: ]{.note-header}[ The total length of time may be presented as a | [Application Note: ]{.note-header}[The total length of time may be summation of the periods of time that each party (e.g., [TOE](#abbr_TOE) | presented as a summation of the periods of time that each party (e.g., developer, mobile carrier) on the critical path consumes. The time | [TOE](#abbr_TOE) developer, mobile carrier) on the critical path period until public availability per deployment mechanism may differ; | consumes. The time period until public availability per deployment each is described.]{.note} | mechanism may differ; each is described.]{.note} ::: ::: ::: ::: ::: ::: ::: element ::: element ::: {#ALC_TSU_EXT.1.3C .reqid} ::: {#ALC_TSU_EXT.1.3C .reqid} [ALC_TSU_EXT.1.3C](#ALC_TSU_EXT.1.3C){.abbr} [ALC_TSU_EXT.1.3C](#ALC_TSU_EXT.1.3C){.abbr} ::: ::: ::: reqdesc ::: reqdesc The description shall include the mechanisms publicly available for The description shall include the mechanisms publicly available for reporting security issues pertaining to the [TOE](#abbr_TOE). reporting security issues pertaining to the [TOE](#abbr_TOE). ::: appnote ::: appnote [ Note: ]{.note-header}[The reporting mechanism could include web sites, | [Application Note: ]{.note-header}[The reporting mechanism could include email addresses, as well as a means to protect the sensitive nature of | web sites, email addresses, as well as a means to protect the sensitive the report (e.g., public keys that could be used to encrypt the details | nature of the report (e.g., public keys that could be used to encrypt of a proof-of-concept exploit).]{.note} | the details of a proof-of-concept exploit).]{.note} ::: ::: ::: ::: ::: ::: ::: element ::: element ::: {#ALC_TSU_EXT.1.4C .reqid} ::: {#ALC_TSU_EXT.1.4C .reqid} [ALC_TSU_EXT.1.4C](#ALC_TSU_EXT.1.4C){.abbr} [ALC_TSU_EXT.1.4C](#ALC_TSU_EXT.1.4C){.abbr} ::: ::: ::: reqdesc ::: reqdesc The description shall include where users can seek information about the The description shall include where users can seek information about the availability of new updates including details (e.g. CVE identifiers) of availability of new updates including details (e.g. CVE identifiers) of the specific public vulnerabilities corrected by each update. the specific public vulnerabilities corrected by each update. ::: appnote ::: appnote [ Note: ]{.note-header}[The purpose of providing this information is so | [Application Note: ]{.note-header}[The purpose of providing this that users and enterprises can determine which devices are susceptible | information is so that users and enterprises can determine which devices to publicly known vulnerabilities so that they can make appropriate risk | are susceptible to publicly known vulnerabilities so that they can make decisions, such as limiting access to enterprise resources until updates | appropriate risk decisions, such as limiting access to enterprise are installed. ]{.note} | resources until updates are installed.]{.note} ::: ::: ::: ::: ::: ::: #### Evaluator action elements: #### Evaluator action elements: ::: element ::: element ::: {#ALC_TSU_EXT.1.1E .reqid} ::: {#ALC_TSU_EXT.1.1E .reqid} [ALC_TSU_EXT.1.1E](#ALC_TSU_EXT.1.1E){.abbr} [ALC_TSU_EXT.1.1E](#ALC_TSU_EXT.1.1E){.abbr} ::: ::: ::: reqdesc ::: reqdesc The evaluator shall confirm that the information provided meets all The evaluator shall confirm that the information provided meets all requirements for content and presentation of evidence. requirements for content and presentation of evidence. ::: ::: ::: ::: ::: {.activity_pane .hide} ::: {.activity_pane .hide} ::: activity_pane_header ::: activity_pane_header [[ Evaluation Activities [[ Evaluation Activities ]{.activity_pane_label}[]{.toggler}](#){onclick="toggle(this);return false;"} ]{.activity_pane_label}[]{.toggler}](#){onclick="toggle(this);return false;"} ::: ::: ::: activity_pane_body ::: activity_pane_body ::: component-activity-header ::: component-activity-header [ALC_TSU_EXT.1](#ALC_TSU_EXT.1) [ALC_TSU_EXT.1](#ALC_TSU_EXT.1) ::: ::: The evaluator shall verify that the [TSS](#abbr_TSS) contains a The evaluator shall verify that the [TSS](#abbr_TSS) contains a description of the timely security update process used by the developer description of the timely security update process used by the developer to create and deploy security updates. The evaluator shall verify that to create and deploy security updates. The evaluator shall verify that this description addresses the [TOE](#abbr_TOE) [OS](#abbr_OS), the this description addresses the [TOE](#abbr_TOE) [OS](#abbr_OS), the firmware, and bundled applications, each. The evaluator shall also firmware, and bundled applications, each. The evaluator shall also verify that, in addition to the [TOE](#abbr_TOE) developer's process, verify that, in addition to the [TOE](#abbr_TOE) developer's process, any carrier or other third-party processes are also addressed in the any carrier or other third-party processes are also addressed in the description. The evaluator shall also verify that each mechanism for description. The evaluator shall also verify that each mechanism for deployment of security updates is described.\ deployment of security updates is described.\ \ \ The evaluator shall verify that, for each deployment mechanism described The evaluator shall verify that, for each deployment mechanism described for the update process, the [TSS](#abbr_TSS) lists a time between public for the update process, the [TSS](#abbr_TSS) lists a time between public disclosure of a vulnerability and public availability of the security disclosure of a vulnerability and public availability of the security update to the [TOE](#abbr_TOE) patching this vulnerability, to include update to the [TOE](#abbr_TOE) patching this vulnerability, to include any third-party or carrier delays in deployment. The evaluator shall any third-party or carrier delays in deployment. The evaluator shall verify that this time is expressed in a number or range of days.\ verify that this time is expressed in a number or range of days.\ \ \ The evaluator shall verify that this description includes the publicly The evaluator shall verify that this description includes the publicly available mechanisms (including either an email address or website) for available mechanisms (including either an email address or website) for reporting security issues related to the [TOE](#abbr_TOE). The evaluator reporting security issues related to the [TOE](#abbr_TOE). The evaluator shall verify that the description of this mechanism includes a method shall verify that the description of this mechanism includes a method for protecting the report either using a public key for encrypting email for protecting the report either using a public key for encrypting email or a trusted channel for a website.\ or a trusted channel for a website.\ \ \ The evaluator shall verify that the description includes where users can The evaluator shall verify that the description includes where users can seek information about the availability of new security updates seek information about the availability of new security updates including details of the specific public vulnerabilities corrected by including details of the specific public vulnerabilities corrected by each update. The evaluator shall verify that the description includes each update. The evaluator shall verify that the description includes the minimum amount of time that the [TOE](#abbr_TOE) is expected to be the minimum amount of time that the [TOE](#abbr_TOE) is expected to be supported with security updates, and the process by which users can seek supported with security updates, and the process by which users can seek information about when the [TOE](#abbr_TOE) is no longer expected to information about when the [TOE](#abbr_TOE) is no longer expected to receive security updates. receive security updates. ::: ::: ::: ::: ::: ::: ### 5.2.5 Class ATE: Tests {#ate .indexable level="3"} ### 5.2.5 Class ATE: Tests {#ate .indexable level="3"} Testing is specified for functional aspects of the system as well as Testing is specified for functional aspects of the system as well as aspects that take advantage of design or implementation weaknesses. The aspects that take advantage of design or implementation weaknesses. The former is done through the ATE_IND family, while the latter is through former is done through the ATE_IND family, while the latter is through the AVA_VAN family. At the assurance level specified in this the AVA_VAN family. At the assurance level specified in this [PP](#abbr_PP), testing is based on advertised functionality and [PP](#abbr_PP), testing is based on advertised functionality and interfaces with dependency on the availability of design information. interfaces with dependency on the availability of design information. One of the primary outputs of the evaluation process is the test report One of the primary outputs of the evaluation process is the test report as specified in the following requirements.\ as specified in the following requirements.\ \ \ Since many of the APIs are not exposed at the user interface (e.g., Since many of the APIs are not exposed at the user interface (e.g., touch screen), the ability to stimulate the necessary interfaces touch screen), the ability to stimulate the necessary interfaces requires a developer's test environment. This test environment will requires a developer's test environment. This test environment will allow the evaluator, for example, to access APIs and view file system allow the evaluator, for example, to access APIs and view file system information that is not available on consumer Mobile Devices. information that is not available on consumer Mobile Devices. ::: {#ATE_IND.1 .comp} ::: {#ATE_IND.1 .comp} #### ATE_IND.1 Independent Testing -- Conformance #### ATE_IND.1 Independent Testing -- Conformance Testing is performed to confirm the functionality described in the Testing is performed to confirm the functionality described in the [TSS](#abbr_TSS) as well as the administrative (including configuration [TSS](#abbr_TSS) as well as the administrative (including configuration and operational) documentation provided. The focus of the testing is to and operational) documentation provided. The focus of the testing is to confirm that the requirements specified in [Section 5.1 Security confirm that the requirements specified in [Section 5.1 Security Functional Requirements](#sfr){.dynref} being met, although some Functional Requirements](#sfr){.dynref} being met, although some additional testing is specified for [SARs](#abbr_SAR) in [Section 5.2 additional testing is specified for [SARs](#abbr_SAR) in [Section 5.2 Security Assurance Requirements](#sar){.dynref}. The Evaluation Security Assurance Requirements](#sar){.dynref}. The Evaluation Activities identify the additional testing activities associated with Activities identify the additional testing activities associated with these components. The evaluator produces a test report documenting the these components. The evaluator produces a test report documenting the plan for and results of testing, as well as coverage arguments focused plan for and results of testing, as well as coverage arguments focused on the platform/[TOE](#abbr_TOE) combinations that are claiming on the platform/[TOE](#abbr_TOE) combinations that are claiming conformance to this [PP](#abbr_PP). conformance to this [PP](#abbr_PP). #### Developer action elements: #### Developer action elements: ::: element ::: element ::: {#ATE_IND.1.1D .reqid} ::: {#ATE_IND.1.1D .reqid} [ATE_IND.1.1D](#ATE_IND.1.1D){.abbr} [ATE_IND.1.1D](#ATE_IND.1.1D){.abbr} ::: ::: ::: reqdesc ::: reqdesc The developer shall provide the [TOE](#abbr_TOE) for testing. The developer shall provide the [TOE](#abbr_TOE) for testing. ::: ::: ::: ::: #### Content and presentation elements: #### Content and presentation elements: ::: element ::: element ::: {#ATE_IND.1.1C .reqid} ::: {#ATE_IND.1.1C .reqid} [ATE_IND.1.1C](#ATE_IND.1.1C){.abbr} [ATE_IND.1.1C](#ATE_IND.1.1C){.abbr} ::: ::: ::: reqdesc ::: reqdesc The [TOE](#abbr_TOE) shall be suitable for testing. The [TOE](#abbr_TOE) shall be suitable for testing. ::: ::: ::: ::: #### Evaluator action elements: #### Evaluator action elements: ::: element ::: element ::: {#ATE_IND.1.1E .reqid} ::: {#ATE_IND.1.1E .reqid} [ATE_IND.1.1E](#ATE_IND.1.1E){.abbr} [ATE_IND.1.1E](#ATE_IND.1.1E){.abbr} ::: ::: ::: reqdesc ::: reqdesc The evaluator shall confirm that the information provided meets all The evaluator shall confirm that the information provided meets all requirements for content and presentation of evidence. requirements for content and presentation of evidence. ::: ::: ::: ::: ::: element ::: element ::: {#ATE_IND.1.2E .reqid} ::: {#ATE_IND.1.2E .reqid} [ATE_IND.1.2E](#ATE_IND.1.2E){.abbr} [ATE_IND.1.2E](#ATE_IND.1.2E){.abbr} ::: ::: ::: reqdesc ::: reqdesc The evaluator shall test a subset of the [TSF](#abbr_TSF) to confirm The evaluator shall test a subset of the [TSF](#abbr_TSF) to confirm that the [TSF](#abbr_TSF) operates as specified. that the [TSF](#abbr_TSF) operates as specified. ::: ::: ::: ::: ::: {.activity_pane .hide} ::: {.activity_pane .hide} ::: activity_pane_header ::: activity_pane_header [[ Evaluation Activities [[ Evaluation Activities ]{.activity_pane_label}[]{.toggler}](#){onclick="toggle(this);return false;"} ]{.activity_pane_label}[]{.toggler}](#){onclick="toggle(this);return false;"} ::: ::: ::: activity_pane_body ::: activity_pane_body ::: component-activity-header ::: component-activity-header [ATE_IND.1](#ATE_IND.1) [ATE_IND.1](#ATE_IND.1) ::: ::: The evaluator shall prepare a test plan and report documenting the The evaluator shall prepare a test plan and report documenting the testing aspects of the system. The test plan covers all of the testing testing aspects of the system. The test plan covers all of the testing actions contained in the [\[CEM\]](#bibCEM){.dynref format=""} and the actions contained in the [\[CEM\]](#bibCEM){.dynref format=""} and the body of this [PP](#abbr_PP)'s Evaluation Activities. While it is not body of this [PP](#abbr_PP)'s Evaluation Activities. While it is not necessary to have one test case per test listed in an evaluation necessary to have one test case per test listed in an evaluation activity, the evaluator shall document in the test plan that each activity, the evaluator shall document in the test plan that each applicable testing requirement in the [ST](#abbr_ST) is covered.\ applicable testing requirement in the [ST](#abbr_ST) is covered.\ \ \ The test plan identifies the platforms to be tested, and for those The test plan identifies the platforms to be tested, and for those platforms not included in the test plan but included in the platforms not included in the test plan but included in the [ST](#abbr_ST), the test plan provides a justification for not testing [ST](#abbr_ST), the test plan provides a justification for not testing the platforms. This justification must address the differences between the platforms. This justification must address the differences between the tested platforms and the untested platforms, and make an argument the tested platforms and the untested platforms, and make an argument that the differences do not affect the testing to be performed. It is that the differences do not affect the testing to be performed. It is not sufficient to merely assert that the differences have no affect; not sufficient to merely assert that the differences have no affect; rationale must be provided. If all platforms claimed in the rationale must be provided. If all platforms claimed in the [ST](#abbr_ST) are tested, then no rationale is necessary.\ [ST](#abbr_ST) are tested, then no rationale is necessary.\ \ \ The test plan describes the composition of each platform to be tested, The test plan describes the composition of each platform to be tested, and any setup that is necessary beyond what is contained in the AGD and any setup that is necessary beyond what is contained in the AGD documentation. It should be noted that the evaluator is expected to documentation. It should be noted that the evaluator is expected to follow the AGD documentation for installation and setup of each platform follow the AGD documentation for installation and setup of each platform either as part of a test or as a standard pre-test condition. This may either as part of a test or as a standard pre-test condition. This may include special test drivers or tools. For each driver or tool, an include special test drivers or tools. For each driver or tool, an argument (not just an assertion) should be provided that the driver or argument (not just an assertion) should be provided that the driver or tool will not adversely affect the performance of the functionality by tool will not adversely affect the performance of the functionality by the [TOE](#abbr_TOE) and its platform. This also includes the the [TOE](#abbr_TOE) and its platform. This also includes the configuration of the cryptographic engine to be used. The cryptographic configuration of the cryptographic engine to be used. The cryptographic algorithms implemented by this engine are those specified by this algorithms implemented by this engine are those specified by this [PP](#abbr_PP) and used by the cryptographic protocols being evaluated [PP](#abbr_PP) and used by the cryptographic protocols being evaluated ([IPsec](#abbr_IPsec), [TLS](#abbr_TLS)/[HTTPS](#abbr_HTTPS), ([IPsec](#abbr_IPsec), [TLS](#abbr_TLS)/[HTTPS](#abbr_HTTPS), [SSH](#abbr_SSH)).\ [SSH](#abbr_SSH)).\ \ \ The test plan identifies high-level test objectives as well as the test The test plan identifies high-level test objectives as well as the test procedures to be followed to achieve those objectives. These procedures procedures to be followed to achieve those objectives. These procedures include expected results. The test report (which could just be an include expected results. The test report (which could just be an annotated version of the test plan) details the activities that took annotated version of the test plan) details the activities that took place when the test procedures were executed, and includes the actual place when the test procedures were executed, and includes the actual results of the tests. This shall be a cumulative account, so if there results of the tests. This shall be a cumulative account, so if there was a test run that resulted in a failure; a fix installed; and then a was a test run that resulted in a failure; a fix installed; and then a successful re-run of the test, the report would show a \"fail\" and successful re-run of the test, the report would show a \"fail\" and \"pass\" result (and the supporting details), and not just the \"pass\" \"pass\" result (and the supporting details), and not just the \"pass\" result. result. ::: ::: ::: ::: ::: ::: ### 5.2.6 Class AVA: Vulnerability Assessment {#ava .indexable level="3"} ### 5.2.6 Class AVA: Vulnerability Assessment {#ava .indexable level="3"} For the current generation of this protection profile, the evaluation For the current generation of this protection profile, the evaluation lab is expected to survey open sources to discover what vulnerabilities lab is expected to survey open sources to discover what vulnerabilities have been discovered in these types of products. In most cases, these have been discovered in these types of products. In most cases, these vulnerabilities will require sophistication beyond that of a basic vulnerabilities will require sophistication beyond that of a basic attacker. Until penetration tools are created and uniformly distributed attacker. Until penetration tools are created and uniformly distributed to the evaluation labs, the evaluator will not be expected to test for to the evaluation labs, the evaluator will not be expected to test for these vulnerabilities in the [TOE](#abbr_TOE). The labs will be expected these vulnerabilities in the [TOE](#abbr_TOE). The labs will be expected to comment on the likelihood of these vulnerabilities given the to comment on the likelihood of these vulnerabilities given the documentation provided by the vendor. This information will be used in documentation provided by the vendor. This information will be used in the development of penetration testing tools and for the development of the development of penetration testing tools and for the development of future protection profiles. future protection profiles. ::: {#AVA_VAN.1 .comp} ::: {#AVA_VAN.1 .comp} #### AVA_VAN.1 Vulnerability Survey #### AVA_VAN.1 Vulnerability Survey #### Developer action elements: #### Developer action elements: ::: element ::: element ::: {#AVA_VAN.1.1D .reqid} ::: {#AVA_VAN.1.1D .reqid} [AVA_VAN.1.1D](#AVA_VAN.1.1D){.abbr} [AVA_VAN.1.1D](#AVA_VAN.1.1D){.abbr} ::: ::: ::: reqdesc ::: reqdesc The developer shall provide the [TOE](#abbr_TOE) for testing. The developer shall provide the [TOE](#abbr_TOE) for testing. ::: ::: ::: ::: #### Content and presentation elements: #### Content and presentation elements: ::: element ::: element ::: {#AVA_VAN.1.1C .reqid} ::: {#AVA_VAN.1.1C .reqid} [AVA_VAN.1.1C](#AVA_VAN.1.1C){.abbr} [AVA_VAN.1.1C](#AVA_VAN.1.1C){.abbr} ::: ::: ::: reqdesc ::: reqdesc The [TOE](#abbr_TOE) shall be suitable for testing. The [TOE](#abbr_TOE) shall be suitable for testing. ::: ::: ::: ::: #### Evaluator action elements: #### Evaluator action elements: ::: element ::: element ::: {#AVA_VAN.1.1E .reqid} ::: {#AVA_VAN.1.1E .reqid} [AVA_VAN.1.1E](#AVA_VAN.1.1E){.abbr} [AVA_VAN.1.1E](#AVA_VAN.1.1E){.abbr} ::: ::: ::: reqdesc ::: reqdesc The evaluator shall confirm that the information provided meets all The evaluator shall confirm that the information provided meets all requirements for content and presentation of evidence. requirements for content and presentation of evidence. ::: ::: ::: ::: ::: element ::: element ::: {#AVA_VAN.1.2E .reqid} ::: {#AVA_VAN.1.2E .reqid} [AVA_VAN.1.2E](#AVA_VAN.1.2E){.abbr} [AVA_VAN.1.2E](#AVA_VAN.1.2E){.abbr} ::: ::: ::: reqdesc ::: reqdesc The evaluator shall perform a search of public domain sources to The evaluator shall perform a search of public domain sources to identify potential vulnerabilities in the [TOE](#abbr_TOE). identify potential vulnerabilities in the [TOE](#abbr_TOE). ::: appnote ::: appnote [Application Note: ]{.note-header}[Public domain sources include the [Application Note: ]{.note-header}[Public domain sources include the Common Vulnerabilities and Exposures (CVE) dictionary for publicly-known Common Vulnerabilities and Exposures (CVE) dictionary for publicly-known vulnerabilities. ]{.note} | vulnerabilities.]{.note} ::: ::: ::: ::: ::: ::: ::: element ::: element ::: {#AVA_VAN.1.3E .reqid} ::: {#AVA_VAN.1.3E .reqid} [AVA_VAN.1.3E](#AVA_VAN.1.3E){.abbr} [AVA_VAN.1.3E](#AVA_VAN.1.3E){.abbr} ::: ::: ::: reqdesc ::: reqdesc The evaluator shall conduct penetration testing, based on the identified The evaluator shall conduct penetration testing, based on the identified potential vulnerabilities, to determine that the [TOE](#abbr_TOE) is potential vulnerabilities, to determine that the [TOE](#abbr_TOE) is resistant to attacks performed by an attacker possessing Basic attack resistant to attacks performed by an attacker possessing Basic attack potential. potential. ::: ::: ::: ::: ::: {.activity_pane .hide} ::: {.activity_pane .hide} ::: activity_pane_header ::: activity_pane_header [[ Evaluation Activities [[ Evaluation Activities ]{.activity_pane_label}[]{.toggler}](#){onclick="toggle(this);return false;"} ]{.activity_pane_label}[]{.toggler}](#){onclick="toggle(this);return false;"} ::: ::: ::: activity_pane_body ::: activity_pane_body ::: component-activity-header ::: component-activity-header [AVA_VAN.1](#AVA_VAN.1) [AVA_VAN.1](#AVA_VAN.1) ::: ::: The evaluator shall generate a report to document their findings with The evaluator shall generate a report to document their findings with respect to this requirement. This report could physically be part of the respect to this requirement. This report could physically be part of the overall test report mentioned in ATE_IND, or a separate document. The overall test report mentioned in ATE_IND, or a separate document. The evaluator performs a search of public information to find evaluator performs a search of public information to find vulnerabilities that have been found in mobile devices and the vulnerabilities that have been found in mobile devices and the implemented communication protocols in general, as well as those that implemented communication protocols in general, as well as those that pertain to the particular [TOE](#abbr_TOE). The evaluator documents the pertain to the particular [TOE](#abbr_TOE). The evaluator documents the sources consulted and the vulnerabilities found in the report.\ sources consulted and the vulnerabilities found in the report.\ \ \ For each vulnerability found, the evaluator either provides a rationale For each vulnerability found, the evaluator either provides a rationale with respect to its non-applicability, or the evaluator formulates a with respect to its non-applicability, or the evaluator formulates a test (using the guidelines provided in ATE_IND) to confirm the test (using the guidelines provided in ATE_IND) to confirm the vulnerability, if suitable. Suitability is determined by assessing the vulnerability, if suitable. Suitability is determined by assessing the attack vector needed to take advantage of the vulnerability. If attack vector needed to take advantage of the vulnerability. If exploiting the vulnerability requires expert skills and an electron exploiting the vulnerability requires expert skills and an electron microscope, for instance, then a test would not be suitable and an microscope, for instance, then a test would not be suitable and an appropriate justification would be formulated. appropriate justification would be formulated. ::: ::: ::: ::: ::: ::: # Appendix A - Optional Requirements {#opt-app .indexable level="A"} # Appendix A - Optional Requirements {#opt-app .indexable level="A"} As indicated in the introduction to this [PP](#abbr_PP), the baseline As indicated in the introduction to this [PP](#abbr_PP), the baseline requirements (those that must be performed by the [TOE](#abbr_TOE)) are requirements (those that must be performed by the [TOE](#abbr_TOE)) are contained in the body of this [PP](#abbr_PP). This appendix contains contained in the body of this [PP](#abbr_PP). This appendix contains three other types of optional requirements:\ three other types of optional requirements:\ \ \ The first type, defined in Appendix [A.1 Strictly Optional The first type, defined in Appendix [A.1 Strictly Optional Requirements](#optional-reqs){.dynref}, are strictly optional Requirements](#optional-reqs){.dynref}, are strictly optional requirements. If the [TOE](#abbr_TOE) meets any of these requirements requirements. If the [TOE](#abbr_TOE) meets any of these requirements the vendor is encouraged to claim the associated [SFRs](#abbr_SFR) in the vendor is encouraged to claim the associated [SFRs](#abbr_SFR) in the [ST](#abbr_ST), but doing so is not required in order to conform to the [ST](#abbr_ST), but doing so is not required in order to conform to this [PP](#abbr_PP).\ this [PP](#abbr_PP).\ \ \ The second type, defined in Appendix [A.2 Objective The second type, defined in Appendix [A.2 Objective Requirements](#objective-reqs){.dynref}, are objective requirements. Requirements](#objective-reqs){.dynref}, are objective requirements. These describe security functionality that is not yet widely available These describe security functionality that is not yet widely available in commercial technology. Objective requirements are not currently in commercial technology. Objective requirements are not currently mandated by this [PP](#abbr_PP), but will be mandated in the future. mandated by this [PP](#abbr_PP), but will be mandated in the future. Adoption by vendors is encouraged, but claiming these [SFRs](#abbr_SFR) Adoption by vendors is encouraged, but claiming these [SFRs](#abbr_SFR) is not required in order to conform to this [PP](#abbr_PP).\ is not required in order to conform to this [PP](#abbr_PP).\ \ \ The third type, defined in Appendix [A.3 Implementation-dependent The third type, defined in Appendix [A.3 Implementation-dependent Requirements](#feat-based-reqs){.dynref}, are Implementation-dependent Requirements](#feat-based-reqs){.dynref}, are Implementation-dependent requirements. If the [TOE](#abbr_TOE) implements the product features requirements. If the [TOE](#abbr_TOE) implements the product features associated with the listed [SFRs](#abbr_SFR), either the associated with the listed [SFRs](#abbr_SFR), either the [SFRs](#abbr_SFR) must be claimed or the product features must be [SFRs](#abbr_SFR) must be claimed or the product features must be disabled in the evaluated configuration. disabled in the evaluated configuration. ## A.1 Strictly Optional Requirements {#optional-reqs .indexable level="2"} ## A.1 Strictly Optional Requirements {#optional-reqs .indexable level="2"} ### A.1.1 Auditable Events for Strictly Optional Requirements {#optional-reqs-audit . ### A.1.1 Auditable Events for Strictly Optional Requirements {#optional-reqs-audit . Requirement Auditable Events Additional Audit Record Conten Requirement Auditable Events Additional Audit Record Conten --------------------------------- ------------------ ------------------------------ --------------------------------- ------------------ ------------------------------ [FIA_UAU_EXT.4](#FIA_UAU_EXT.4) [FIA_UAU_EXT.4](#FIA_UAU_EXT.4) No events specified N/A No events specified N/A : [Table [21]{.counter}]{#t-audit-optional .ctr : [Table [21]{.counter}]{#t-audit-optional .ctr myid="t-audit-optional" counter-type="ct-Table"}: Auditable Events for myid="t-audit-optional" counter-type="ct-Table"}: Auditable Events for Strictly Optional Requirements Strictly Optional Requirements ### A.1.2 Class ALC: Life-cycle Support {#-optional .indexable level="3"} | ### A.1.2 Class ALC: Life-cycle Support {#alc-optional .indexable level="3"} ::: {#ALC_FLR.1 .comp} ::: {#ALC_FLR.1 .comp} #### ALC_FLR.1 Basic Flaw Remediation (ALC_FLR.1) #### ALC_FLR.1 Basic Flaw Remediation (ALC_FLR.1) ::: statustag ::: statustag ***This [SAR](#abbr_SAR) is optional and may be claimed at the ***This [SAR](#abbr_SAR) is optional and may be claimed at the [ST](#abbr_ST)-Author\'s discretion.*** [ST](#abbr_ST)-Author\'s discretion.*** ::: ::: #### Developer action elements: #### Developer action elements: ::: element ::: element ::: {#ALC_FLR.1.1D .reqid} ::: {#ALC_FLR.1.1D .reqid} [ALC_FLR.1.1D](#ALC_FLR.1.1D){.abbr} [ALC_FLR.1.1D](#ALC_FLR.1.1D){.abbr} ::: ::: ::: reqdesc ::: reqdesc The developer shall document and provide flaw remediation procedures The developer shall document and provide flaw remediation procedures addressed to [TOE](#abbr_TOE) developers. addressed to [TOE](#abbr_TOE) developers. ::: ::: ::: ::: #### Content and presentation elements: #### Content and presentation elements: ::: element ::: element ::: {#ALC_FLR.1.1C .reqid} ::: {#ALC_FLR.1.1C .reqid} [ALC_FLR.1.1C](#ALC_FLR.1.1C){.abbr} [ALC_FLR.1.1C](#ALC_FLR.1.1C){.abbr} ::: ::: ::: reqdesc ::: reqdesc The flaw remediation procedures documentation shall describe the The flaw remediation procedures documentation shall describe the procedures used to track all reported security flaws in each release of procedures used to track all reported security flaws in each release of the [TOE](#abbr_TOE). the [TOE](#abbr_TOE). ::: ::: ::: ::: ::: element ::: element ::: {#ALC_FLR.1.2C .reqid} ::: {#ALC_FLR.1.2C .reqid} [ALC_FLR.1.2C](#ALC_FLR.1.2C){.abbr} [ALC_FLR.1.2C](#ALC_FLR.1.2C){.abbr} ::: ::: ::: reqdesc ::: reqdesc The flaw remediation procedures shall require that a description of the The flaw remediation procedures shall require that a description of the nature and effect of each security flaw be provided, as well as the nature and effect of each security flaw be provided, as well as the status of finding a correction to that flaw. status of finding a correction to that flaw. ::: ::: ::: ::: ::: element ::: element ::: {#ALC_FLR.1.3C .reqid} ::: {#ALC_FLR.1.3C .reqid} [ALC_FLR.1.3C](#ALC_FLR.1.3C){.abbr} [ALC_FLR.1.3C](#ALC_FLR.1.3C){.abbr} ::: ::: ::: reqdesc ::: reqdesc The flaw remediation procedures shall require that corrective actions be The flaw remediation procedures shall require that corrective actions be identified for each of the security flaws. identified for each of the security flaws. ::: ::: ::: ::: ::: element ::: element ::: {#ALC_FLR.1.4C .reqid} ::: {#ALC_FLR.1.4C .reqid} [ALC_FLR.1.4C](#ALC_FLR.1.4C){.abbr} [ALC_FLR.1.4C](#ALC_FLR.1.4C){.abbr} ::: ::: ::: reqdesc ::: reqdesc The flaw remediation procedures documentation shall describe the methods The flaw remediation procedures documentation shall describe the methods used to provide flaw information, corrections and guidance on corrective used to provide flaw information, corrections and guidance on corrective actions to [TOE](#abbr_TOE) users. actions to [TOE](#abbr_TOE) users. ::: ::: ::: ::: #### Evaluator action elements: #### Evaluator action elements: ::: element ::: element ::: {#ALC_FLR.1.1E .reqid} ::: {#ALC_FLR.1.1E .reqid} [ALC_FLR.1.1E](#ALC_FLR.1.1E){.abbr} [ALC_FLR.1.1E](#ALC_FLR.1.1E){.abbr} ::: ::: ::: reqdesc ::: reqdesc The evaluator shall confirm that the information provided meets all The evaluator shall confirm that the information provided meets all requirements for content and presentation of evidence. requirements for content and presentation of evidence. ::: ::: ::: ::: ::: {.activity_pane .hide} ::: {.activity_pane .hide} ::: activity_pane_header ::: activity_pane_header [[ Evaluation Activities [[ Evaluation Activities ]{.activity_pane_label}[]{.toggler}](#){onclick="toggle(this);return false;"} ]{.activity_pane_label}[]{.toggler}](#){onclick="toggle(this);return false;"} ::: ::: ::: activity_pane_body ::: activity_pane_body ::: component-activity-header ::: component-activity-header [ALC_FLR.1](#ALC_FLR.1) [ALC_FLR.1](#ALC_FLR.1) ::: ::: Evaluated as specified by [\[CEM\]](#bibCEM){.dynref format=""}. Evaluated as specified by [\[CEM\]](#bibCEM){.dynref format=""}. ::: ::: ::: ::: ::: ::: ::: {#ALC_FLR.2 .comp} ::: {#ALC_FLR.2 .comp} #### ALC_FLR.2 Flaw Reporting Procedures (ALC_FLR.2) #### ALC_FLR.2 Flaw Reporting Procedures (ALC_FLR.2) ::: statustag ::: statustag ***This [SAR](#abbr_SAR) is optional and may be claimed at the ***This [SAR](#abbr_SAR) is optional and may be claimed at the [ST](#abbr_ST)-Author\'s discretion.*** [ST](#abbr_ST)-Author\'s discretion.*** ::: ::: #### Developer action elements: #### Developer action elements: ::: element ::: element ::: {#ALC_FLR.2.1D .reqid} ::: {#ALC_FLR.2.1D .reqid} [ALC_FLR.2.1D](#ALC_FLR.2.1D){.abbr} [ALC_FLR.2.1D](#ALC_FLR.2.1D){.abbr} ::: ::: ::: reqdesc ::: reqdesc The developer shall document and provide flaw remediation procedures The developer shall document and provide flaw remediation procedures addressed to [TOE](#abbr_TOE) developers. addressed to [TOE](#abbr_TOE) developers. ::: ::: ::: ::: ::: element ::: element ::: {#ALC_FLR.2.2D .reqid} ::: {#ALC_FLR.2.2D .reqid} [ALC_FLR.2.2D](#ALC_FLR.2.2D){.abbr} [ALC_FLR.2.2D](#ALC_FLR.2.2D){.abbr} ::: ::: ::: reqdesc ::: reqdesc The developer shall establish a procedure for accepting and acting upon The developer shall establish a procedure for accepting and acting upon all reports of security flaws and requests for corrections to those all reports of security flaws and requests for corrections to those flaws. flaws. ::: ::: ::: ::: ::: element ::: element ::: {#ALC_FLR.2.3D .reqid} ::: {#ALC_FLR.2.3D .reqid} [ALC_FLR.2.3D](#ALC_FLR.2.3D){.abbr} [ALC_FLR.2.3D](#ALC_FLR.2.3D){.abbr} ::: ::: ::: reqdesc ::: reqdesc The developer shall provide flaw remediation guidance addressed to The developer shall provide flaw remediation guidance addressed to [TOE](#abbr_TOE) users. [TOE](#abbr_TOE) users. ::: ::: ::: ::: #### Content and presentation elements: #### Content and presentation elements: ::: element ::: element ::: {#ALC_FLR.2.1C .reqid} ::: {#ALC_FLR.2.1C .reqid} [ALC_FLR.2.1C](#ALC_FLR.2.1C){.abbr} [ALC_FLR.2.1C](#ALC_FLR.2.1C){.abbr} ::: ::: ::: reqdesc ::: reqdesc The flaw remediation procedures documentation shall describe the The flaw remediation procedures documentation shall describe the procedures used to track all reported security flaws in each release of procedures used to track all reported security flaws in each release of the [TOE](#abbr_TOE). the [TOE](#abbr_TOE). ::: ::: ::: ::: ::: element ::: element ::: {#ALC_FLR.2.2C .reqid} ::: {#ALC_FLR.2.2C .reqid} [ALC_FLR.2.2C](#ALC_FLR.2.2C){.abbr} [ALC_FLR.2.2C](#ALC_FLR.2.2C){.abbr} ::: ::: ::: reqdesc ::: reqdesc The flaw remediation procedures shall require that a description of the The flaw remediation procedures shall require that a description of the nature and effect of each security flaw be provided, as well as the nature and effect of each security flaw be provided, as well as the status of finding a correction to that flaw. status of finding a correction to that flaw. ::: ::: ::: ::: ::: element ::: element ::: {#ALC_FLR.2.3C .reqid} ::: {#ALC_FLR.2.3C .reqid} [ALC_FLR.2.3C](#ALC_FLR.2.3C){.abbr} [ALC_FLR.2.3C](#ALC_FLR.2.3C){.abbr} ::: ::: ::: reqdesc ::: reqdesc The flaw remediation procedures shall require that corrective actions be The flaw remediation procedures shall require that corrective actions be identified for each of the security flaws. identified for each of the security flaws. ::: ::: ::: ::: ::: element ::: element ::: {#ALC_FLR.2.4C .reqid} ::: {#ALC_FLR.2.4C .reqid} [ALC_FLR.2.4C](#ALC_FLR.2.4C){.abbr} [ALC_FLR.2.4C](#ALC_FLR.2.4C){.abbr} ::: ::: ::: reqdesc ::: reqdesc The flaw remediation procedures documentation shall describe the methods The flaw remediation procedures documentation shall describe the methods used to provide flaw information, corrections and guidance on corrective used to provide flaw information, corrections and guidance on corrective actions to [TOE](#abbr_TOE) users. actions to [TOE](#abbr_TOE) users. ::: ::: ::: ::: ::: element ::: element ::: {#ALC_FLR.2.5C .reqid} ::: {#ALC_FLR.2.5C .reqid} [ALC_FLR.2.5C](#ALC_FLR.2.5C){.abbr} [ALC_FLR.2.5C](#ALC_FLR.2.5C){.abbr} ::: ::: ::: reqdesc ::: reqdesc The flaw remediation procedures shall describe a means by which the The flaw remediation procedures shall describe a means by which the developer receives from [TOE](#abbr_TOE) users reports and enquiries of developer receives from [TOE](#abbr_TOE) users reports and enquiries of suspected security flaws in the [TOE](#abbr_TOE). suspected security flaws in the [TOE](#abbr_TOE). ::: ::: ::: ::: ::: element ::: element ::: {#ALC_FLR.2.6C .reqid} ::: {#ALC_FLR.2.6C .reqid} [ALC_FLR.2.6C](#ALC_FLR.2.6C){.abbr} [ALC_FLR.2.6C](#ALC_FLR.2.6C){.abbr} ::: ::: ::: reqdesc ::: reqdesc The procedures for processing reported security flaws shall ensure that The procedures for processing reported security flaws shall ensure that any reported flaws are remediated and the remediation procedures issued any reported flaws are remediated and the remediation procedures issued to [TOE](#abbr_TOE) users. to [TOE](#abbr_TOE) users. ::: ::: ::: ::: ::: element ::: element ::: {#ALC_FLR.2.7C .reqid} ::: {#ALC_FLR.2.7C .reqid} [ALC_FLR.2.7C](#ALC_FLR.2.7C){.abbr} [ALC_FLR.2.7C](#ALC_FLR.2.7C){.abbr} ::: ::: ::: reqdesc ::: reqdesc The procedures for processing reported security flaws shall provide The procedures for processing reported security flaws shall provide safeguards that any corrections to these security flaws do not introduce safeguards that any corrections to these security flaws do not introduce any new flaws. any new flaws. ::: ::: ::: ::: ::: element ::: element ::: {#ALC_FLR.2.8C .reqid} ::: {#ALC_FLR.2.8C .reqid} [ALC_FLR.2.8C](#ALC_FLR.2.8C){.abbr} [ALC_FLR.2.8C](#ALC_FLR.2.8C){.abbr} ::: ::: ::: reqdesc ::: reqdesc The flaw remediation guidance shall describe a means by which The flaw remediation guidance shall describe a means by which [TOE](#abbr_TOE) users report to the developer any suspected security [TOE](#abbr_TOE) users report to the developer any suspected security flaws in the [TOE](#abbr_TOE). flaws in the [TOE](#abbr_TOE). ::: ::: ::: ::: #### Evaluator action elements: #### Evaluator action elements: ::: element ::: element ::: {#ALC_FLR.2.1E .reqid} ::: {#ALC_FLR.2.1E .reqid} [ALC_FLR.2.1E](#ALC_FLR.2.1E){.abbr} [ALC_FLR.2.1E](#ALC_FLR.2.1E){.abbr} ::: ::: ::: reqdesc ::: reqdesc The evaluator shall confirm that the information provided meets all The evaluator shall confirm that the information provided meets all requirements for content and presentation of evidence. requirements for content and presentation of evidence. ::: ::: ::: ::: ::: {.activity_pane .hide} ::: {.activity_pane .hide} ::: activity_pane_header ::: activity_pane_header [[ Evaluation Activities [[ Evaluation Activities ]{.activity_pane_label}[]{.toggler}](#){onclick="toggle(this);return false;"} ]{.activity_pane_label}[]{.toggler}](#){onclick="toggle(this);return false;"} ::: ::: ::: activity_pane_body ::: activity_pane_body ::: component-activity-header ::: component-activity-header [ALC_FLR.2](#ALC_FLR.2) [ALC_FLR.2](#ALC_FLR.2) ::: ::: Evaluated as specified by [\[CEM\]](#bibCEM){.dynref format=""}. Evaluated as specified by [\[CEM\]](#bibCEM){.dynref format=""}. ::: ::: ::: ::: ::: ::: ::: {#ALC_FLR.3 .comp} ::: {#ALC_FLR.3 .comp} #### ALC_FLR.3 Systematic Flaw Remediation (ALC_FLR.3) #### ALC_FLR.3 Systematic Flaw Remediation (ALC_FLR.3) ::: statustag ::: statustag ***This [SAR](#abbr_SAR) is optional and may be claimed at the ***This [SAR](#abbr_SAR) is optional and may be claimed at the [ST](#abbr_ST)-Author\'s discretion.*** [ST](#abbr_ST)-Author\'s discretion.*** ::: ::: #### Developer action elements: #### Developer action elements: ::: element ::: element ::: {#ALC_FLR.3.1D .reqid} ::: {#ALC_FLR.3.1D .reqid} [ALC_FLR.3.1D](#ALC_FLR.3.1D){.abbr} [ALC_FLR.3.1D](#ALC_FLR.3.1D){.abbr} ::: ::: ::: reqdesc ::: reqdesc The developer shall document and provide flaw remediation procedures The developer shall document and provide flaw remediation procedures addressed to [TOE](#abbr_TOE) developers. addressed to [TOE](#abbr_TOE) developers. ::: ::: ::: ::: ::: element ::: element ::: {#ALC_FLR.3.2D .reqid} ::: {#ALC_FLR.3.2D .reqid} [ALC_FLR.3.2D](#ALC_FLR.3.2D){.abbr} [ALC_FLR.3.2D](#ALC_FLR.3.2D){.abbr} ::: ::: ::: reqdesc ::: reqdesc The developer shall establish a procedure for accepting and acting upon The developer shall establish a procedure for accepting and acting upon all reports of security flaws and requests for corrections to those all reports of security flaws and requests for corrections to those flaws. flaws. ::: ::: ::: ::: ::: element ::: element ::: {#ALC_FLR.3.3D .reqid} ::: {#ALC_FLR.3.3D .reqid} [ALC_FLR.3.3D](#ALC_FLR.3.3D){.abbr} [ALC_FLR.3.3D](#ALC_FLR.3.3D){.abbr} ::: ::: ::: reqdesc ::: reqdesc The developer shall provide flaw remediation guidance addressed to The developer shall provide flaw remediation guidance addressed to [TOE](#abbr_TOE) users. [TOE](#abbr_TOE) users. ::: ::: ::: ::: #### Content and presentation elements: #### Content and presentation elements: ::: element ::: element ::: {#ALC_FLR.3.1C .reqid} ::: {#ALC_FLR.3.1C .reqid} [ALC_FLR.3.1C](#ALC_FLR.3.1C){.abbr} [ALC_FLR.3.1C](#ALC_FLR.3.1C){.abbr} ::: ::: ::: reqdesc ::: reqdesc The flaw remediation procedures documentation shall describe the The flaw remediation procedures documentation shall describe the procedures used to track all reported security flaws in each release of procedures used to track all reported security flaws in each release of the [TOE](#abbr_TOE). the [TOE](#abbr_TOE). ::: ::: ::: ::: ::: element ::: element ::: {#ALC_FLR.3.2C .reqid} ::: {#ALC_FLR.3.2C .reqid} [ALC_FLR.3.2C](#ALC_FLR.3.2C){.abbr} [ALC_FLR.3.2C](#ALC_FLR.3.2C){.abbr} ::: ::: ::: reqdesc ::: reqdesc The flaw remediation procedures shall require that a description of the The flaw remediation procedures shall require that a description of the nature and effect of each security flaw be provided, as well as the nature and effect of each security flaw be provided, as well as the status of finding a correction to that flaw. status of finding a correction to that flaw. ::: ::: ::: ::: ::: element ::: element ::: {#ALC_FLR.3.3C .reqid} ::: {#ALC_FLR.3.3C .reqid} [ALC_FLR.3.3C](#ALC_FLR.3.3C){.abbr} [ALC_FLR.3.3C](#ALC_FLR.3.3C){.abbr} ::: ::: ::: reqdesc ::: reqdesc The flaw remediation procedures shall require that corrective actions be The flaw remediation procedures shall require that corrective actions be identified for each of the security flaws. identified for each of the security flaws. ::: ::: ::: ::: ::: element ::: element ::: {#ALC_FLR.3.4C .reqid} ::: {#ALC_FLR.3.4C .reqid} [ALC_FLR.3.4C](#ALC_FLR.3.4C){.abbr} [ALC_FLR.3.4C](#ALC_FLR.3.4C){.abbr} ::: ::: ::: reqdesc ::: reqdesc The flaw remediation procedures documentation shall describe the methods The flaw remediation procedures documentation shall describe the methods used to provide flaw information, corrections and guidance on corrective used to provide flaw information, corrections and guidance on corrective actions to [TOE](#abbr_TOE) users. actions to [TOE](#abbr_TOE) users. ::: ::: ::: ::: ::: element ::: element ::: {#ALC_FLR.3.5C .reqid} ::: {#ALC_FLR.3.5C .reqid} [ALC_FLR.3.5C](#ALC_FLR.3.5C){.abbr} [ALC_FLR.3.5C](#ALC_FLR.3.5C){.abbr} ::: ::: ::: reqdesc ::: reqdesc The flaw remediation procedures shall describe a means by which the The flaw remediation procedures shall describe a means by which the developer receives from [TOE](#abbr_TOE) users reports and enquiries of developer receives from [TOE](#abbr_TOE) users reports and enquiries of suspected security flaws in the [TOE](#abbr_TOE). suspected security flaws in the [TOE](#abbr_TOE). ::: ::: ::: ::: ::: element ::: element ::: {#ALC_FLR.3.6C .reqid} ::: {#ALC_FLR.3.6C .reqid} [ALC_FLR.3.6C](#ALC_FLR.3.6C){.abbr} [ALC_FLR.3.6C](#ALC_FLR.3.6C){.abbr} ::: ::: ::: reqdesc ::: reqdesc The flaw remediation procedures shall include a procedure requiring The flaw remediation procedures shall include a procedure requiring timely response and the automatic distribution of security flaw reports timely response and the automatic distribution of security flaw reports and the associated corrections to registered users who might be affected and the associated corrections to registered users who might be affected by the security flaw. by the security flaw. ::: ::: ::: ::: ::: element ::: element ::: {#ALC_FLR.3.7C .reqid} ::: {#ALC_FLR.3.7C .reqid} [ALC_FLR.3.7C](#ALC_FLR.3.7C){.abbr} [ALC_FLR.3.7C](#ALC_FLR.3.7C){.abbr} ::: ::: ::: reqdesc ::: reqdesc The procedures for processing reported security flaws shall ensure that The procedures for processing reported security flaws shall ensure that any reported flaws are remediated and the remediation procedures issued any reported flaws are remediated and the remediation procedures issued to [TOE](#abbr_TOE) users. to [TOE](#abbr_TOE) users. ::: ::: ::: ::: ::: element ::: element ::: {#ALC_FLR.3.8C .reqid} ::: {#ALC_FLR.3.8C .reqid} [ALC_FLR.3.8C](#ALC_FLR.3.8C){.abbr} [ALC_FLR.3.8C](#ALC_FLR.3.8C){.abbr} ::: ::: ::: reqdesc ::: reqdesc The procedures for processing reported security flaws shall provide The procedures for processing reported security flaws shall provide safeguards that any corrections to these security flaws do not introduce safeguards that any corrections to these security flaws do not introduce any new flaws. any new flaws. ::: ::: ::: ::: ::: element ::: element ::: {#ALC_FLR.3.9C .reqid} ::: {#ALC_FLR.3.9C .reqid} [ALC_FLR.3.9C](#ALC_FLR.3.9C){.abbr} [ALC_FLR.3.9C](#ALC_FLR.3.9C){.abbr} ::: ::: ::: reqdesc ::: reqdesc The flaw remediation guidance shall describe a means by which The flaw remediation guidance shall describe a means by which [TOE](#abbr_TOE) users report to the developer any suspected security [TOE](#abbr_TOE) users report to the developer any suspected security flaws in the [TOE](#abbr_TOE). flaws in the [TOE](#abbr_TOE). ::: ::: ::: ::: ::: element ::: element ::: {#ALC_FLR.3.10C .reqid} ::: {#ALC_FLR.3.10C .reqid} [ALC_FLR.3.10C](#ALC_FLR.3.10C){.abbr} [ALC_FLR.3.10C](#ALC_FLR.3.10C){.abbr} ::: ::: ::: reqdesc ::: reqdesc The flaw remediation guidance shall describe a means by which The flaw remediation guidance shall describe a means by which [TOE](#abbr_TOE) users may register with the developer, to be eligible [TOE](#abbr_TOE) users may register with the developer, to be eligible to receive security flaw reports and corrections. to receive security flaw reports and corrections. ::: ::: ::: ::: ::: element ::: element ::: {#ALC_FLR.3.11C .reqid} ::: {#ALC_FLR.3.11C .reqid} [ALC_FLR.3.11C](#ALC_FLR.3.11C){.abbr} [ALC_FLR.3.11C](#ALC_FLR.3.11C){.abbr} ::: ::: ::: reqdesc ::: reqdesc The flaw remediation guidance shall identify the specific points of The flaw remediation guidance shall identify the specific points of contact for all reports and enquiries about security issues involving contact for all reports and enquiries about security issues involving the [TOE](#abbr_TOE). the [TOE](#abbr_TOE). ::: ::: ::: ::: #### Evaluator action elements: #### Evaluator action elements: ::: element ::: element ::: {#ALC_FLR.3.1E .reqid} ::: {#ALC_FLR.3.1E .reqid} [ALC_FLR.3.1E](#ALC_FLR.3.1E){.abbr} [ALC_FLR.3.1E](#ALC_FLR.3.1E){.abbr} ::: ::: ::: reqdesc ::: reqdesc The evaluator shall confirm that the information provided meets all The evaluator shall confirm that the information provided meets all requirements for content and presentation of evidence. requirements for content and presentation of evidence. ::: ::: ::: ::: ::: {.activity_pane .hide} ::: {.activity_pane .hide} ::: activity_pane_header ::: activity_pane_header [[ Evaluation Activities [[ Evaluation Activities ]{.activity_pane_label}[]{.toggler}](#){onclick="toggle(this);return false;"} ]{.activity_pane_label}[]{.toggler}](#){onclick="toggle(this);return false;"} ::: ::: ::: activity_pane_body ::: activity_pane_body ::: component-activity-header ::: component-activity-header [ALC_FLR.3](#ALC_FLR.3) [ALC_FLR.3](#ALC_FLR.3) ::: ::: Evaluated as specified by [\[CEM\]](#bibCEM){.dynref format=""}. Evaluated as specified by [\[CEM\]](#bibCEM){.dynref format=""}. ::: ::: ::: ::: ::: ::: ### A.1.3 Class FIA: Identification and Authentication {#-optional .indexable level=" | ### A.1.3 Class FIA: Identification and Authentication {#fia-optional .indexable leve ::: {#FIA_UAU_EXT.4 .comp} ::: {#FIA_UAU_EXT.4 .comp} #### FIA_UAU_EXT.4 Secondary User Authentication #### FIA_UAU_EXT.4 Secondary User Authentication ::: element ::: element ::: {#FIA_UAU_EXT.4.1 .reqid} ::: {#FIA_UAU_EXT.4.1 .reqid} [FIA_UAU_EXT.4.1](#FIA_UAU_EXT.4.1){.abbr} [FIA_UAU_EXT.4.1](#FIA_UAU_EXT.4.1){.abbr} ::: ::: ::: reqdesc ::: reqdesc The [TSF](#abbr_TSF) shall provide a secondary authentication mechanism The [TSF](#abbr_TSF) shall provide a secondary authentication mechanism for accessing Enterprise applications and resources. The secondary for accessing Enterprise applications and resources. The secondary authentication mechanism shall control access to the Enterprise authentication mechanism shall control access to the Enterprise application and shared resources and shall be incorporated into the application and shared resources and shall be incorporated into the encryption of protected and sensitive data belonging to Enterprise encryption of protected and sensitive data belonging to Enterprise applications and shared resources. applications and shared resources. ::: appnote ::: appnote [Application Note: ]{.note-header}[For the [BYOD](#abbr_BYOD) use case, | [Application Note: ]{.note-header}[ For the [BYOD](#abbr_BYOD) use case, Enterprise applications and data must be protected using a different Enterprise applications and data must be protected using a different password than the user authentication to gain access to the personal password than the user authentication to gain access to the personal applications and data, if configured.\ applications and data, if configured.\ \ \ This requirement must be included in the [ST](#abbr_ST) if the This requirement must be included in the [ST](#abbr_ST) if the [TOE](#abbr_TOE) implements a container solution, in which there is a [TOE](#abbr_TOE) implements a container solution, in which there is a separate authentication, to separate user and Enterprise applications separate authentication, to separate user and Enterprise applications and resources. ]{.note} and resources. ]{.note} ::: ::: ::: ::: ::: ::: ::: element ::: element ::: {#FIA_UAU_EXT.4.2 .reqid} ::: {#FIA_UAU_EXT.4.2 .reqid} [FIA_UAU_EXT.4.2](#FIA_UAU_EXT.4.2){.abbr} [FIA_UAU_EXT.4.2](#FIA_UAU_EXT.4.2){.abbr} ::: ::: ::: reqdesc ::: reqdesc The [TSF](#abbr_TSF) shall require the user to present the secondary The [TSF](#abbr_TSF) shall require the user to present the secondary authentication factor prior to decryption of Enterprise application data authentication factor prior to decryption of Enterprise application data and Enterprise shared resource data. and Enterprise shared resource data. ::: appnote ::: appnote [Application Note: ]{.note-header}[ The intent of this requirement is to | [Application Note: ]{.note-header}[The intent of this requirement is to prevent decryption of protected Enterprise application data and prevent decryption of protected Enterprise application data and Enterprise shared resource data before the user has authenticated to the Enterprise shared resource data before the user has authenticated to the device using the secondary authentication factor. Enterprise shared device using the secondary authentication factor. Enterprise shared resource data consists of the [FDP_ACF_EXT.2.1](#FDP_ACF_EXT.2.1) resource data consists of the [FDP_ACF_EXT.2.1](#FDP_ACF_EXT.2.1) selections.]{.note} selections.]{.note} ::: ::: ::: ::: ::: ::: ::: {.activity_pane .hide} ::: {.activity_pane .hide} ::: activity_pane_header ::: activity_pane_header [[ Evaluation Activities [[ Evaluation Activities ]{.activity_pane_label}[]{.toggler}](#){onclick="toggle(this);return false;"} ]{.activity_pane_label}[]{.toggler}](#){onclick="toggle(this);return false;"} ::: ::: ::: activity_pane_body ::: activity_pane_body ::: element-activity-header ::: element-activity-header [FIA_UAU_EXT.4.1](#FIA_UAU_EXT.4.1) [FIA_UAU_EXT.4.1](#FIA_UAU_EXT.4.1) ::: ::: ::: eacategory ::: eacategory [TSS](#abbr_TSS) [TSS](#abbr_TSS) ::: ::: ::: ea ::: ea There are no [TSS](#abbr_TSS) evaluation activities for this element.\ There are no [TSS](#abbr_TSS) evaluation activities for this element.\ \ \ ::: ::: ::: eacategory ::: eacategory Guidance Guidance ::: ::: ::: ea ::: ea There are no guidance evaluation activities for this element.\ There are no guidance evaluation activities for this element.\ \ \ ::: ::: ::: eacategory ::: eacategory Tests Tests ::: ::: ::: ea ::: ea The Evaluation Activities for any selected requirements related to The Evaluation Activities for any selected requirements related to device authentication must be separately performed for the secondary device authentication must be separately performed for the secondary authentication mechanism (in addition to activities performed for the authentication mechanism (in addition to activities performed for the primary authentication mechanism). The requirements are: primary authentication mechanism). The requirements are: [FIA_UAU.6/CREDENTIAL](#FIA_UAU.6/CREDENTIAL), [FIA_UAU.6/CREDENTIAL](#FIA_UAU.6/CREDENTIAL), [FIA_UAU.6/LOCKED](#FIA_UAU.6/LOCKED), [FIA_PMG_EXT.1](#FIA_PMG_EXT.1), [FIA_UAU.6/LOCKED](#FIA_UAU.6/LOCKED), [FIA_PMG_EXT.1](#FIA_PMG_EXT.1), [FIA_TRT_EXT.1](#FIA_TRT_EXT.1), [FIA_UAU.7](#FIA_UAU.7), [FIA_TRT_EXT.1](#FIA_TRT_EXT.1), [FIA_UAU.7](#FIA_UAU.7), [FIA_UAU_EXT.2](#FIA_UAU_EXT.2), [FTA_SSL_EXT.1](#FTA_SSL_EXT.1), [FIA_UAU_EXT.2](#FIA_UAU_EXT.2), [FTA_SSL_EXT.1](#FTA_SSL_EXT.1), [FCS_STG_EXT.2](#FCS_STG_EXT.2), [FCS_STG_EXT.2](#FCS_STG_EXT.2), [FMT_SMF_EXT.1](#FMT_SMF_EXT.1)/[FMT_MOF_EXT.1](#FMT_MOF_EXT.1) #1, #2, [FMT_SMF_EXT.1](#FMT_SMF_EXT.1)/[FMT_MOF_EXT.1](#FMT_MOF_EXT.1) #1, #2, #8, #21, and #36.\ #8, #21, and #36.\ \ \ Additionally, [FIA_AFL_EXT.1](#FIA_AFL_EXT.1) must be met, except that Additionally, [FIA_AFL_EXT.1](#FIA_AFL_EXT.1) must be met, except that in [FIA_AFL_EXT.1.2](#FIA_AFL_EXT.1.2) the separate test is performed in [FIA_AFL_EXT.1.2](#FIA_AFL_EXT.1.2) the separate test is performed with the text \"wipe of all protected data\" changed to \"wipe of all with the text \"wipe of all protected data\" changed to \"wipe of all Enterprise application data and all Enterprise shared resource data.\" Enterprise application data and all Enterprise shared resource data.\" ::: ::: ::: element-activity-header ::: element-activity-header [FIA_UAU_EXT.4.2](#FIA_UAU_EXT.4.2) [FIA_UAU_EXT.4.2](#FIA_UAU_EXT.4.2) ::: ::: ::: eacategory ::: eacategory [TSS](#abbr_TSS) [TSS](#abbr_TSS) ::: ::: ::: ea ::: ea The evaluator shall verify that the [TSS](#abbr_TSS) section of the The evaluator shall verify that the [TSS](#abbr_TSS) section of the [ST](#abbr_ST) describes the process for decrypting Enterprise [ST](#abbr_ST) describes the process for decrypting Enterprise application data and shared resource data. The evaluator shall ensure application data and shared resource data. The evaluator shall ensure that this process requires the user to enter an Authentication Factor that this process requires the user to enter an Authentication Factor and, in accordance with [FCS_CKM_EXT.3](#FCS_CKM_EXT.3), derives a and, in accordance with [FCS_CKM_EXT.3](#FCS_CKM_EXT.3), derives a [KEK](#abbr_KEK) which is used to protect the software-based secure key [KEK](#abbr_KEK) which is used to protect the software-based secure key storage and (optionally) [DEKs](#abbr_DEK) for sensitive data, in | storage and (optionally) DEKs for sensitive data, in accordance with accordance with [FCS_STG_EXT.2](#FCS_STG_EXT.2).\ | [FCS_STG_EXT.2](#FCS_STG_EXT.2).\ \ \ ::: ::: ::: eacategory ::: eacategory Guidance Guidance ::: ::: ::: ea ::: ea There are no guidance evaluation activities for this element.\ There are no guidance evaluation activities for this element.\ \ \ ::: ::: ::: eacategory ::: eacategory Tests Tests ::: ::: ::: ea ::: ea There are no test evaluation activities for this element.\ There are no test evaluation activities for this element.\ \ \ ::: ::: ::: ::: ::: ::: ::: ::: ## A.2 Objective Requirements {#objective-reqs .indexable level="2"} ## A.2 Objective Requirements {#objective-reqs .indexable level="2"} ### A.2.1 Auditable Events for Objective Requirements {#objective-reqs-audit .indexab ### A.2.1 Auditable Events for Objective Requirements {#objective-reqs-audit .indexab Requirement Requirement ----------------------------------------------------------------------------------- ----------------------------------------------------------------------------------- [FAU_SEL.1](#FAU_SEL.1) [FAU_SEL.1](#FAU_SEL.1) All modifications to the audit configuration that occur while the audit collection All modifications to the audit configuration that occur while the audit collection [FCS_RBG_EXT.2](#FCS_RBG_EXT.2) [FCS_RBG_EXT.2](#FCS_RBG_EXT.2) No events specified No events specified [FCS_RBG_EXT.3](#FCS_RBG_EXT.3) [FCS_RBG_EXT.3](#FCS_RBG_EXT.3) No events specified No events specified [FCS_SRV_EXT.2](#FCS_SRV_EXT.2) [FCS_SRV_EXT.2](#FCS_SRV_EXT.2) No events specified No events specified [FDP_ACF_EXT.3](#FDP_ACF_EXT.3) [FDP_ACF_EXT.3](#FDP_ACF_EXT.3) No events specified No events specified [FDP_BCK_EXT.1](#FDP_BCK_EXT.1) [FDP_BCK_EXT.1](#FDP_BCK_EXT.1) No events specified No events specified [FDP_BLT_EXT.1](#FDP_BLT_EXT.1) [FDP_BLT_EXT.1](#FDP_BLT_EXT.1) No events specified No events specified [FMT_SMF_EXT.3](#FMT_SMF_EXT.3) [FMT_SMF_EXT.3](#FMT_SMF_EXT.3) No events specified No events specified [FPT_AEX_EXT.5](#FPT_AEX_EXT.5) [FPT_AEX_EXT.5](#FPT_AEX_EXT.5) No events specified No events specified [FPT_AEX_EXT.6](#FPT_AEX_EXT.6) [FPT_AEX_EXT.6](#FPT_AEX_EXT.6) No events specified No events specified [FPT_BBD_EXT.1](#FPT_BBD_EXT.1) [FPT_BBD_EXT.1](#FPT_BBD_EXT.1) No events specified No events specified [FPT_BLT_EXT.1](#FPT_BLT_EXT.1) [FPT_BLT_EXT.1](#FPT_BLT_EXT.1) No events specified No events specified [FPT_NOT_EXT.2](#FPT_NOT_EXT.2) [FPT_NOT_EXT.2](#FPT_NOT_EXT.2) No events specified No events specified [FPT_TST_EXT.2/POSTKERNEL](#FPT_TST_EXT.2/POSTKERNEL) [FPT_TST_EXT.2/POSTKERNEL](#FPT_TST_EXT.2/POSTKERNEL) \[**selection, choose one of**: [Detected integrity violation]{#_s_625 .selectable- | \[**selection, choose one of**: [Detected integrity violation]{#_s_617 .selectable- [FPT_TUD_EXT.5](#FPT_TUD_EXT.5) [FPT_TUD_EXT.5](#FPT_TUD_EXT.5) No events specified No events specified [FPT_TUD_EXT.6](#FPT_TUD_EXT.6) [FPT_TUD_EXT.6](#FPT_TUD_EXT.6) No events specified No events specified : [Table [22]{.counter}]{#t-audit-objective .ctr : [Table [22]{.counter}]{#t-audit-objective .ctr myid="t-audit-objective" counter-type="ct-Table"}: Auditable Events myid="t-audit-objective" counter-type="ct-Table"}: Auditable Events for Objective Requirements for Objective Requirements ### A.2.2 Class FAU: Security Audit {#-objective .indexable level="3"} | ### A.2.2 Class FAU: Security Audit {#fau-objective .indexable level="3"} ::: {#FAU_SEL.1 .comp} ::: {#FAU_SEL.1 .comp} #### FAU_SEL.1 Selective Audit #### FAU_SEL.1 Selective Audit ::: element ::: element ::: {#FAU_SEL.1.1 .reqid} ::: {#FAU_SEL.1.1 .reqid} [FAU_SEL.1.1](#FAU_SEL.1.1){.abbr} [FAU_SEL.1.1](#FAU_SEL.1.1){.abbr} ::: ::: ::: reqdesc ::: reqdesc The [TSF](#abbr_TSF) shall be able to select the set of events to be The [TSF](#abbr_TSF) shall be able to select the set of events to be audited from the set of all auditable events based on the following audited from the set of all auditable events based on the following attributes attributes a. \[*event type*\] a. \[*event type*\] b. \[*success of auditable security events* b. \[*success of auditable security events* c. *failure of auditable security events* c. *failure of auditable security events* d. *\[**assignment**: [other attributes]{.assignable-content}\]*\] d. *\[**assignment**: [other attributes]{.assignable-content}\]*\] ::: appnote ::: appnote [Application Note: ]{.note-header}[ The intent of this requirement is to | [Application Note: ]{.note-header}[The intent of this requirement is to identify all criteria that can be selected to trigger an audit event. identify all criteria that can be selected to trigger an audit event. This can be configured through an interface on the [TSF](#abbr_TSF) for This can be configured through an interface on the [TSF](#abbr_TSF) for a user or administrator to invoke. For the [ST](#abbr_ST) author, the a user or administrator to invoke. For the [ST](#abbr_ST) author, the assignment is used to list any additional criteria or \"none\". ]{.note} | assignment is used to list any additional criteria or \"none\".]{.note} ::: ::: ::: ::: ::: ::: ::: {.activity_pane .hide} ::: {.activity_pane .hide} ::: activity_pane_header ::: activity_pane_header [[ Evaluation Activities [[ Evaluation Activities ]{.activity_pane_label}[]{.toggler}](#){onclick="toggle(this);return false;"} ]{.activity_pane_label}[]{.toggler}](#){onclick="toggle(this);return false;"} ::: ::: ::: activity_pane_body ::: activity_pane_body ::: component-activity-header ::: component-activity-header [FAU_SEL.1](#FAU_SEL.1) [FAU_SEL.1](#FAU_SEL.1) ::: ::: ::: eacategory ::: eacategory [TSS](#abbr_TSS) [TSS](#abbr_TSS) ::: ::: ::: ea ::: ea ::: ea ::: ea There are no [TSS](#abbr_TSS) evaluation activities for this component.\ There are no [TSS](#abbr_TSS) evaluation activities for this component.\ \ \ ::: ::: ::: ::: ::: eacategory ::: eacategory Guidance Guidance ::: ::: ::: ea ::: ea ::: ea ::: ea The evaluator shall review the administrative guidance to ensure that The evaluator shall review the administrative guidance to ensure that the guidance itemizes all event types, as well as describes all the guidance itemizes all event types, as well as describes all attributes that are to be selectable in accordance with the requirement, attributes that are to be selectable in accordance with the requirement, to include those attributes listed in the assignment. The administrative to include those attributes listed in the assignment. The administrative guidance shall also contain instructions on how to set the pre-selection guidance shall also contain instructions on how to set the pre-selection as well as explain the syntax (if present) for multi-value as well as explain the syntax (if present) for multi-value pre-selection. The administrative guidance shall also identify those pre-selection. The administrative guidance shall also identify those audit data that are always recorded, regardless of the selection audit data that are always recorded, regardless of the selection criteria currently being enforced.\ criteria currently being enforced.\ \ \ ::: ::: ::: ::: ::: eacategory ::: eacategory Tests Tests ::: ::: ::: ea ::: ea ::: ea ::: ea The evaluator shall also perform the following tests:\ The evaluator shall also perform the following tests:\ []{.testlist-} []{.testlist-} - [Test FAU_SEL.1:1](#_t_1){#_t_1 .defined}: For each attribute listed - [Test FAU_SEL.1:1](#_t_1){#_t_1 .defined}: For each attribute listed in the requirement, the evaluator shall devise a test to show that in the requirement, the evaluator shall devise a test to show that selecting the attribute causes only audit events with that attribute selecting the attribute causes only audit events with that attribute (or those that are always recorded, as identified in the (or those that are always recorded, as identified in the administrative guidance) to be recorded. administrative guidance) to be recorded. - [Test FAU_SEL.1:2](#_t_2){#_t_2 .defined}: \[conditional\] If the - [Test FAU_SEL.1:2](#_t_2){#_t_2 .defined}: \[conditional\] If the [TSF](#abbr_TSF) supports specification of more complex audit [TSF](#abbr_TSF) supports specification of more complex audit pre-selection criteria (e.g., multiple attributes, logical pre-selection criteria (e.g., multiple attributes, logical expressions using attributes) then the evaluator shall devise tests expressions using attributes) then the evaluator shall devise tests showing that this capability is correctly implemented. The evaluator showing that this capability is correctly implemented. The evaluator shall also, in the test plan, provide a short narrative justifying shall also, in the test plan, provide a short narrative justifying the set of tests as representative and sufficient to exercise the the set of tests as representative and sufficient to exercise the capability. capability. ::: ::: ::: ::: ::: ::: ::: ::: ::: ::: ### A.2.3 Class FCS: Cryptographic Support {#-objective .indexable level="3"} | ### A.2.3 Class FCS: Cryptographic Support {#fcs-objective .indexable level="3"} ::: {#FCS_RBG_EXT.2 .comp} ::: {#FCS_RBG_EXT.2 .comp} #### FCS_RBG_EXT.2 Random Bit Generator State Preservation #### FCS_RBG_EXT.2 Random Bit Generator State Preservation ::: element ::: element ::: {#FCS_RBG_EXT.2.1 .reqid} ::: {#FCS_RBG_EXT.2.1 .reqid} [FCS_RBG_EXT.2.1](#FCS_RBG_EXT.2.1){.abbr} [FCS_RBG_EXT.2.1](#FCS_RBG_EXT.2.1){.abbr} ::: ::: ::: reqdesc ::: reqdesc The [TSF](#abbr_TSF) shall save the state of the DRBG at power-off, and The [TSF](#abbr_TSF) shall save the state of the DRBG at power-off, and shall use this state as input to the DRBG at startup. shall use this state as input to the DRBG at startup. ::: appnote ::: appnote [Application Note: ]{.note-header}[ The capability to add the state | [Application Note: ]{.note-header}[The capability to add the state saved saved at power-off as input to the DRBG prevents a DRBG that is slow to | at power-off as input to the DRBG prevents a DRBG that is slow to gather gather entropy from producing the same output regularly and across | entropy from producing the same output regularly and across reboots. reboots. Since there is no guarantee of the protections provided when | Since there is no guarantee of the protections provided when the state the state is stored (or a requirement for any such protection), it is | is stored (or a requirement for any such protection), it is assumed that assumed that the state is \'known\', and therefore cannot contribute | the state is \'known\', and therefore cannot contribute entropy to the entropy to the DRBG, but can introduce enough variation that the initial | DRBG, but can introduce enough variation that the initial DRBG values DRBG values are not predictable and exploitable. ]{.note} | are not predictable and exploitable.]{.note} ::: ::: ::: ::: ::: ::: ::: {.activity_pane .hide} ::: {.activity_pane .hide} ::: activity_pane_header ::: activity_pane_header [[ Evaluation Activities [[ Evaluation Activities ]{.activity_pane_label}[]{.toggler}](#){onclick="toggle(this);return false;"} ]{.activity_pane_label}[]{.toggler}](#){onclick="toggle(this);return false;"} ::: ::: ::: activity_pane_body ::: activity_pane_body ::: component-activity-header ::: component-activity-header [FCS_RBG_EXT.2](#FCS_RBG_EXT.2) [FCS_RBG_EXT.2](#FCS_RBG_EXT.2) ::: ::: ::: eacategory ::: eacategory [TSS](#abbr_TSS) [TSS](#abbr_TSS) ::: ::: ::: ea ::: ea ::: ea ::: ea The evaluation activity for this requirement is captured in the DRBG The evaluation activity for this requirement is captured in the DRBG documentation for [Appendix E - Entropy Documentation And documentation for [Appendix E - Entropy Documentation And Assessment](#entropyappendix){.dynref}. The evaluator shall verify that Assessment](#entropyappendix){.dynref}. The evaluator shall verify that the documentation describes how the state is generated so as to be the documentation describes how the state is generated so as to be available for the next startup, how the state is used as input to the available for the next startup, how the state is used as input to the DRBG, and any protection measures used for the state while the DRBG, and any protection measures used for the state while the [TOE](#abbr_TOE) is powered off.\ [TOE](#abbr_TOE) is powered off.\ \ \ ::: ::: ::: ::: ::: eacategory ::: eacategory Guidance Guidance ::: ::: ::: ea ::: ea ::: ea ::: ea There are no guidance evaluation activities for this component.\ There are no guidance evaluation activities for this component.\ \ \ ::: ::: ::: ::: ::: eacategory ::: eacategory Tests Tests ::: ::: ::: ea ::: ea ::: ea ::: ea There are no test evaluation activities for this component. There are no test evaluation activities for this component. ::: ::: ::: ::: ::: ::: ::: ::: ::: ::: ::: {#FCS_RBG_EXT.3 .comp} ::: {#FCS_RBG_EXT.3 .comp} #### FCS_RBG_EXT.3 Support for Personalization String #### FCS_RBG_EXT.3 Support for Personalization String ::: element ::: element ::: {#FCS_RBG_EXT.3.1 .reqid} ::: {#FCS_RBG_EXT.3.1 .reqid} [FCS_RBG_EXT.3.1](#FCS_RBG_EXT.3.1){.abbr} [FCS_RBG_EXT.3.1](#FCS_RBG_EXT.3.1){.abbr} ::: ::: ::: reqdesc ::: reqdesc The [TSF](#abbr_TSF) shall allow applications to add data to the DRBG The [TSF](#abbr_TSF) shall allow applications to add data to the DRBG using the Personalization String as defined in SP 800-90A. using the Personalization String as defined in SP 800-90A. ::: appnote ::: appnote [Application Note: ]{.note-header}[ As specified in SP 800-90A, the | [Application Note: ]{.note-header}[As specified in SP 800-90A, the [TSF](#abbr_TSF) must not count data input from an application towards [TSF](#abbr_TSF) must not count data input from an application towards the entropy required by [FCS_RBG.1](#FCS_RBG.1). Thus, the the entropy required by [FCS_RBG.1](#FCS_RBG.1). Thus, the [TSF](#abbr_TSF) must not allow the only input to the DRBG seed to be [TSF](#abbr_TSF) must not allow the only input to the DRBG seed to be from an application. ]{.note} | from an application.]{.note} ::: ::: ::: ::: ::: ::: ::: {.activity_pane .hide} ::: {.activity_pane .hide} ::: activity_pane_header ::: activity_pane_header [[ Evaluation Activities [[ Evaluation Activities ]{.activity_pane_label}[]{.toggler}](#){onclick="toggle(this);return false;"} ]{.activity_pane_label}[]{.toggler}](#){onclick="toggle(this);return false;"} ::: ::: ::: activity_pane_body ::: activity_pane_body ::: component-activity-header ::: component-activity-header [FCS_RBG_EXT.3](#FCS_RBG_EXT.3) [FCS_RBG_EXT.3](#FCS_RBG_EXT.3) ::: ::: The evaluator shall verify that this function is included as an The evaluator shall verify that this function is included as an interface to the DRBG in the documentation required by [Appendix E - interface to the DRBG in the documentation required by [Appendix E - Entropy Documentation And Assessment](#entropyappendix){.dynref} and Entropy Documentation And Assessment](#entropyappendix){.dynref} and that the behavior of the DRBG following a call to this interface is that the behavior of the DRBG following a call to this interface is described. The evaluator shall also verify that the documentation of the described. The evaluator shall also verify that the documentation of the DRBG describes the conditions of use and possible values for the DRBG describes the conditions of use and possible values for the Personalization String input to the SP 800-90A specified DRBG.\ Personalization String input to the SP 800-90A specified DRBG.\ \ \ ::: eacategory ::: eacategory [TSS](#abbr_TSS) [TSS](#abbr_TSS) ::: ::: ::: ea ::: ea ::: ea ::: ea There are no [TSS](#abbr_TSS) evaluation activities for this component.\ There are no [TSS](#abbr_TSS) evaluation activities for this component.\ \ \ ::: ::: ::: ::: ::: eacategory ::: eacategory Guidance Guidance ::: ::: ::: ea ::: ea ::: ea ::: ea There are no guidance evaluation activities for this component.\ There are no guidance evaluation activities for this component.\ \ \ ::: ::: ::: ::: ::: eacategory ::: eacategory Tests Tests ::: ::: ::: ea ::: ea ::: ea ::: ea []{.testlist-} []{.testlist-} - [Test FCS_RBG_EXT.3:1](#_t_14){#_t_14 .defined}: The evaluator shall - [Test FCS_RBG_EXT.3:1](#_t_14){#_t_14 .defined}: The evaluator shall write, or the developer shall provide, an application that adds data write, or the developer shall provide, an application that adds data to the DRBG via the Personalization String. The evaluator shall to the DRBG via the Personalization String. The evaluator shall verify that the request succeeds. verify that the request succeeds. ::: ::: ::: ::: ::: ::: ::: ::: ::: ::: ::: {#FCS_SRV_EXT.2 .comp} ::: {#FCS_SRV_EXT.2 .comp} #### FCS_SRV_EXT.2 Cryptographic Key Storage Services #### FCS_SRV_EXT.2 Cryptographic Key Storage Services ::: element ::: element ::: {#FCS_SRV_EXT.2.1 .reqid} ::: {#FCS_SRV_EXT.2.1 .reqid} [FCS_SRV_EXT.2.1](#FCS_SRV_EXT.2.1){.abbr} [FCS_SRV_EXT.2.1](#FCS_SRV_EXT.2.1){.abbr} ::: ::: ::: reqdesc ::: reqdesc The [TSF](#abbr_TSF) shall provide a mechanism for applications to The [TSF](#abbr_TSF) shall provide a mechanism for applications to request the [TSF](#abbr_TSF) to perform the following cryptographic request the [TSF](#abbr_TSF) to perform the following cryptographic operations: \[**selection**: operations: \[**selection**: - [Algorithms in [FCS_COP.1/AEAD](#FCS_COP.1/AEAD)]{#_s_396 | - [Algorithms in [FCS_COP.1/AEAD](#FCS_COP.1/AEAD)]{#fcs_srv_ext.2.1_1 .selectable-content} .selectable-content} - [Algorithms in [FCS_COP.1/KeyWrap](#FCS_COP.1/KeyWrap)]{#_s_397 | - [Algorithms in > [FCS_COP.1/KeyWrap](#FCS_COP.1/KeyWrap)]{#fcs_srv_ext.2.1_2 .selectable-content} .selectable-content} - [Algorithms in [FCS_COP.1/SigGen](#FCS_COP.1/SigGen)]{#_s_398 | - [Algorithms in > [FCS_COP.1/SigGen](#FCS_COP.1/SigGen)]{#fcs_srv_ext.2.1_3 .selectable-content} .selectable-content} - [Algorithms in [FCS_COP.1/SigVer](#FCS_COP.1/SigVer)]{#_s_399 | - [Algorithms in > [FCS_COP.1/SigVer](#FCS_COP.1/SigVer)]{#fcs_srv_ext.2.1_4 .selectable-content} .selectable-content} - [Algorithms in [FCS_COP.1/SKC](#FCS_COP.1/SKC)]{#_s_400 | - [Algorithms in [FCS_COP.1/SKC](#FCS_COP.1/SKC)]{#fcs_srv_ext.2.1_5 .selectable-content} .selectable-content} \] by keys stored in the secure key storage. \] by keys stored in the secure key storage. ::: appnote ::: appnote [Application Note: ]{.note-header}[The [TOE](#abbr_TOE) will, therefore, [Application Note: ]{.note-header}[The [TOE](#abbr_TOE) will, therefore, be required to perform cryptographic operations on behalf of be required to perform cryptographic operations on behalf of applications using the keys stored in the [TOE](#abbr_TOE)'s secure key applications using the keys stored in the [TOE](#abbr_TOE)'s secure key storage. ]{.note} | storage.]{.note} ::: ::: ::: ::: ::: ::: ::: {.activity_pane .hide} ::: {.activity_pane .hide} ::: activity_pane_header ::: activity_pane_header [[ Evaluation Activities [[ Evaluation Activities ]{.activity_pane_label}[]{.toggler}](#){onclick="toggle(this);return false;"} ]{.activity_pane_label}[]{.toggler}](#){onclick="toggle(this);return false;"} ::: ::: ::: activity_pane_body ::: activity_pane_body ::: component-activity-header ::: component-activity-header [FCS_SRV_EXT.2](#FCS_SRV_EXT.2) [FCS_SRV_EXT.2](#FCS_SRV_EXT.2) ::: ::: The evaluator shall verify that the [API](#abbr_API) documentation for The evaluator shall verify that the [API](#abbr_API) documentation for the secure key storage includes the cryptographic operations by the the secure key storage includes the cryptographic operations by the stored keys.\ stored keys.\ \ \ ::: eacategory ::: eacategory [TSS](#abbr_TSS) [TSS](#abbr_TSS) ::: ::: ::: ea ::: ea ::: ea ::: ea There are no [TSS](#abbr_TSS) evaluation activities for this component.\ There are no [TSS](#abbr_TSS) evaluation activities for this component.\ \ \ ::: ::: ::: ::: ::: eacategory ::: eacategory Guidance Guidance ::: ::: ::: ea ::: ea ::: ea ::: ea There are no guidance evaluation activities for this component.\ There are no guidance evaluation activities for this component.\ \ \ ::: ::: ::: ::: ::: eacategory ::: eacategory Tests Tests ::: ::: ::: ea ::: ea ::: ea ::: ea The evaluator shall write, or the developer shall provide access to, an The evaluator shall write, or the developer shall provide access to, an application that requests cryptographic operations of stored keys by the application that requests cryptographic operations of stored keys by the [TSF](#abbr_TSF). The evaluator shall verify that the results from the [TSF](#abbr_TSF). The evaluator shall verify that the results from the operation match the expected results according to the [API](#abbr_API) operation match the expected results according to the [API](#abbr_API) documentation. The evaluator shall use these APIs to test the documentation. The evaluator shall use these APIs to test the functionality of the secure key storage according to the Evaluation functionality of the secure key storage according to the Evaluation Activities in [FCS_STG_EXT.1](#FCS_STG_EXT.1). Activities in [FCS_STG_EXT.1](#FCS_STG_EXT.1). ::: ::: ::: ::: ::: ::: ::: ::: ::: ::: ### A.2.4 Class FDP: User Data Protection {#-objective .indexable level="3"} | ### A.2.4 Class FDP: User Data Protection {#fdp-objective .indexable level="3"} ::: {#FDP_ACF_EXT.3 .comp} ::: {#FDP_ACF_EXT.3 .comp} #### FDP_ACF_EXT.3 Security Attribute Based Access Control #### FDP_ACF_EXT.3 Security Attribute Based Access Control ::: element ::: element ::: {#FDP_ACF_EXT.3.1 .reqid} ::: {#FDP_ACF_EXT.3.1 .reqid} [FDP_ACF_EXT.3.1](#FDP_ACF_EXT.3.1){.abbr} [FDP_ACF_EXT.3.1](#FDP_ACF_EXT.3.1){.abbr} ::: ::: ::: reqdesc ::: reqdesc The [TSF](#abbr_TSF) shall enforce an access control policy that The [TSF](#abbr_TSF) shall enforce an access control policy that prohibits an application from granting both write and execute permission prohibits an application from granting both write and execute permission to a file on the device except for \[**selection**: [files stored in the to a file on the device except for \[**selection**: [files stored in the application\'s private data folder]{#_s_483 .selectable-content}, [no | application\'s private data folder]{#fdp_acf_ext.3.1_1 exceptions]{#_s_484 .selectable-content}\]. | .selectable-content}, [no exceptions]{#fdp_acf_ext.3.1_2 > .selectable-content}\]. ::: ::: ::: ::: ::: {.activity_pane .hide} ::: {.activity_pane .hide} ::: activity_pane_header ::: activity_pane_header [[ Evaluation Activities [[ Evaluation Activities ]{.activity_pane_label}[]{.toggler}](#){onclick="toggle(this);return false;"} ]{.activity_pane_label}[]{.toggler}](#){onclick="toggle(this);return false;"} ::: ::: ::: activity_pane_body ::: activity_pane_body ::: component-activity-header ::: component-activity-header [FDP_ACF_EXT.3](#FDP_ACF_EXT.3) [FDP_ACF_EXT.3](#FDP_ACF_EXT.3) ::: ::: ::: eacategory ::: eacategory [TSS](#abbr_TSS) [TSS](#abbr_TSS) ::: ::: ::: ea ::: ea ::: ea ::: ea There are no [TSS](#abbr_TSS) evaluation activities for this component.\ There are no [TSS](#abbr_TSS) evaluation activities for this component.\ \ \ ::: ::: ::: ::: ::: eacategory ::: eacategory Guidance Guidance ::: ::: ::: ea ::: ea ::: ea ::: ea There are no guidance evaluation activities for this component.\ There are no guidance evaluation activities for this component.\ \ \ ::: ::: ::: ::: ::: eacategory ::: eacategory Tests Tests ::: ::: ::: ea ::: ea ::: ea ::: ea **Evaluation Activity Note:** The following tests require the developer **Evaluation Activity Note:** The following tests require the developer to provide access to a test platform that provides the evaluator with to provide access to a test platform that provides the evaluator with tools that are typically not found on consumer Mobile Device products.\ tools that are typically not found on consumer Mobile Device products.\ \ \ []{.testlist-} []{.testlist-} - [Test FDP_ACF_EXT.3:1](#_t_24){#_t_24 .defined}: The evaluator shall - [Test FDP_ACF_EXT.3:1](#_t_24){#_t_24 .defined}: The evaluator shall write, or the developer shall provide, an application that attempts write, or the developer shall provide, an application that attempts to store a file with both write and execute permissions. If the to store a file with both write and execute permissions. If the selection is \"no exceptions\", then the evaluator shall verify that selection is \"no exceptions\", then the evaluator shall verify that this action fails and that the permissions on the file are not this action fails and that the permissions on the file are not simultaneously write and execute. If the selection is simultaneously write and execute. If the selection is \"application\'s private data folder\", then the evaluator shall \"application\'s private data folder\", then the evaluator shall ensure that the attempt to store the file is outside of the ensure that the attempt to store the file is outside of the application\'s private data folder. application\'s private data folder. - [Test FDP_ACF_EXT.3:2](#_t_25){#_t_25 .defined}: The evaluator shall - [Test FDP_ACF_EXT.3:2](#_t_25){#_t_25 .defined}: The evaluator shall traverse the file system examining the permission on each traverse the file system examining the permission on each [TSF](#abbr_TSF) file to verify that no file has both write and [TSF](#abbr_TSF) file to verify that no file has both write and execute permissions set. If the selection is \"application\'s execute permissions set. If the selection is \"application\'s private data folder\", then only files outside of this folder need private data folder\", then only files outside of this folder need to be examined by the evaluator for this test. to be examined by the evaluator for this test. ::: ::: ::: ::: ::: ::: ::: ::: ::: ::: ::: {#FDP_BCK_EXT.1 .comp} ::: {#FDP_BCK_EXT.1 .comp} #### FDP_BCK_EXT.1 Application Backup #### FDP_BCK_EXT.1 Application Backup ::: element ::: element ::: {#FDP_BCK_EXT.1.1 .reqid} ::: {#FDP_BCK_EXT.1.1 .reqid} [FDP_BCK_EXT.1.1](#FDP_BCK_EXT.1.1){.abbr} [FDP_BCK_EXT.1.1](#FDP_BCK_EXT.1.1){.abbr} ::: ::: ::: reqdesc ::: reqdesc The [TSF](#abbr_TSF) shall provide a mechanism for applications to mark The [TSF](#abbr_TSF) shall provide a mechanism for applications to mark \[**selection**: [all application data]{#s-all-app-data \[**selection**: [all application data]{#s-all-app-data .selectable-content}, [selected application data]{#s-sel-app-data .selectable-content}, [selected application data]{#s-sel-app-data .selectable-content}\] to be excluded from device backups. .selectable-content}\] to be excluded from device backups. ::: appnote ::: appnote [Application Note: ]{.note-header}[ Device backups include any mechanism | [Application Note: ]{.note-header}[Device backups include any mechanism built into the [TOE](#abbr_TOE) that allows stored application data to built into the [TOE](#abbr_TOE) that allows stored application data to be extracted over a physical port or sent over the network, but does not be extracted over a physical port or sent over the network, but does not include any functionality implemented by a specific application itself include any functionality implemented by a specific application itself if the application is not included in the [TOE](#abbr_TOE). The lack of if the application is not included in the [TOE](#abbr_TOE). The lack of a public/documented [API](#abbr_API) for performing backups, when a a public/documented [API](#abbr_API) for performing backups, when a private/undocumented [API](#abbr_API) exists, is not sufficient to meet private/undocumented [API](#abbr_API) exists, is not sufficient to meet this requirement. ]{.note} | this requirement.]{.note} ::: ::: ::: ::: ::: ::: ::: {.activity_pane .hide} ::: {.activity_pane .hide} ::: activity_pane_header ::: activity_pane_header [[ Evaluation Activities [[ Evaluation Activities ]{.activity_pane_label}[]{.toggler}](#){onclick="toggle(this);return false;"} ]{.activity_pane_label}[]{.toggler}](#){onclick="toggle(this);return false;"} ::: ::: ::: activity_pane_body ::: activity_pane_body ::: component-activity-header ::: component-activity-header [FDP_BCK_EXT.1](#FDP_BCK_EXT.1) [FDP_BCK_EXT.1](#FDP_BCK_EXT.1) ::: ::: ::: eacategory ::: eacategory [TSS](#abbr_TSS) [TSS](#abbr_TSS) ::: ::: ::: ea ::: ea ::: ea ::: ea There are no [TSS](#abbr_TSS) evaluation activities for this component.\ There are no [TSS](#abbr_TSS) evaluation activities for this component.\ \ \ ::: ::: ::: ::: ::: eacategory ::: eacategory Guidance Guidance ::: ::: ::: ea ::: ea ::: ea ::: ea There are no guidance evaluation activities for this component.\ There are no guidance evaluation activities for this component.\ \ \ ::: ::: ::: ::: ::: eacategory ::: eacategory Tests Tests ::: ::: ::: ea ::: ea ::: ea ::: ea If [all application data](#s-all-app-data) is selected, the evaluator If [all application data](#s-all-app-data) is selected, the evaluator shall install an application that has marked all of its application data shall install an application that has marked all of its application data to be excluded from backups. The evaluator shall cause data to be placed to be excluded from backups. The evaluator shall cause data to be placed into the application's storage area. The evaluator shall attempt to back into the application's storage area. The evaluator shall attempt to back up the application data and verify that the backup fails or that the up the application data and verify that the backup fails or that the application's data was not included in the backup.\ application's data was not included in the backup.\ \ \ If [selected application data](#s-sel-app-data) is selected, the If [selected application data](#s-sel-app-data) is selected, the evaluator shall install an application that has marked selected evaluator shall install an application that has marked selected application data to be excluded from backups. The evaluator shall cause application data to be excluded from backups. The evaluator shall cause data covered by \"selected application data\" to be placed into the data covered by \"selected application data\" to be placed into the application's storage area. The evaluator shall attempt to backup that application's storage area. The evaluator shall attempt to backup that selected application data and verify that either the backup fails or selected application data and verify that either the backup fails or that the selected data is excluded from the backup. that the selected data is excluded from the backup. ::: ::: ::: ::: ::: ::: ::: ::: ::: ::: ::: {#FDP_BLT_EXT.1 .comp} ::: {#FDP_BLT_EXT.1 .comp} #### FDP_BLT_EXT.1 Limitation of Bluetooth Device Access #### FDP_BLT_EXT.1 Limitation of Bluetooth Device Access ::: element ::: element ::: {#FDP_BLT_EXT.1.1 .reqid} ::: {#FDP_BLT_EXT.1.1 .reqid} [FDP_BLT_EXT.1.1](#FDP_BLT_EXT.1.1){.abbr} [FDP_BLT_EXT.1.1](#FDP_BLT_EXT.1.1){.abbr} ::: ::: ::: reqdesc ::: reqdesc The [TSF](#abbr_TSF) shall limit the applications that may communicate The [TSF](#abbr_TSF) shall limit the applications that may communicate with a particular paired Bluetooth device. with a particular paired Bluetooth device. ::: appnote ::: appnote [Application Note: ]{.note-header}[ Not every application with | [Application Note: ]{.note-header}[Not every application with privileges privileges to use Bluetooth should be permitted to communicate with | to use Bluetooth should be permitted to communicate with every paired every paired Bluetooth device. For example, the [TSF](#abbr_TSF) may | Bluetooth device. For example, the [TSF](#abbr_TSF) may choose to choose to require that only the application that initiated the current | require that only the application that initiated the current connection connection may communicate with the device, or it may strictly tie the | may communicate with the device, or it may strictly tie the paired paired device to the first application that makes a socket connection to | device to the first application that makes a socket connection to the the device following initial pairing. Additionally, for more | device following initial pairing. Additionally, for more flexibility, flexibility, the [TSF](#abbr_TSF) may choose to provide the user with a | the [TSF](#abbr_TSF) may choose to provide the user with a way to select way to select which applications on the device may communicate with or | which applications on the device may communicate with or observe observe communications with each paired Bluetooth device. ]{.note} | communications with each paired Bluetooth device.]{.note} ::: ::: ::: ::: ::: ::: ::: {.activity_pane .hide} ::: {.activity_pane .hide} ::: activity_pane_header ::: activity_pane_header [[ Evaluation Activities [[ Evaluation Activities ]{.activity_pane_label}[]{.toggler}](#){onclick="toggle(this);return false;"} ]{.activity_pane_label}[]{.toggler}](#){onclick="toggle(this);return false;"} ::: ::: ::: activity_pane_body ::: activity_pane_body ::: component-activity-header ::: component-activity-header [FDP_BLT_EXT.1](#FDP_BLT_EXT.1) [FDP_BLT_EXT.1](#FDP_BLT_EXT.1) ::: ::: ::: eacategory ::: eacategory [TSS](#abbr_TSS) [TSS](#abbr_TSS) ::: ::: ::: ea ::: ea ::: ea ::: ea The evaluator shall ensure that the [TSS](#abbr_TSS) describes the The evaluator shall ensure that the [TSS](#abbr_TSS) describes the mechanism used to prevent unrestricted access to paired Bluetooth mechanism used to prevent unrestricted access to paired Bluetooth devices (or their communication data) by every application with access devices (or their communication data) by every application with access to the Bluetooth system service on the [TOE](#abbr_TOE). The evaluator to the Bluetooth system service on the [TOE](#abbr_TOE). The evaluator shall verify that this method either restricts access to a single shall verify that this method either restricts access to a single application or provides explicit control of the applications that may application or provides explicit control of the applications that may communicate with the paired Bluetooth device.\ communicate with the paired Bluetooth device.\ \ \ ::: ::: ::: ::: ::: eacategory ::: eacategory Guidance Guidance ::: ::: ::: ea ::: ea ::: ea ::: ea The evaluator shall verify that the AGD contains the steps to configure The evaluator shall verify that the AGD contains the steps to configure which applications are allowed to communicate with a given Bluetooth which applications are allowed to communicate with a given Bluetooth peripheral.\ peripheral.\ \ \ ::: ::: ::: ::: ::: eacategory ::: eacategory Tests Tests ::: ::: ::: ea ::: ea ::: ea ::: ea The evaluator shall establish a Bluetooth connection with any The evaluator shall establish a Bluetooth connection with any peripheral. The evaluator shall verify that an application that is peripheral. The evaluator shall verify that an application that is allowed to communicate with the Bluetooth peripheral is able to and that allowed to communicate with the Bluetooth peripheral is able to and that an application that is not allowed to communicate with that Bluetooth an application that is not allowed to communicate with that Bluetooth peripheral is unable to communicate with the peripheral. peripheral is unable to communicate with the peripheral. ::: ::: ::: ::: ::: ::: ::: ::: ::: ::: ### A.2.5 Class FMT: Security Management {#-objective .indexable level="3"} | ### A.2.5 Class FMT: Security Management {#fmt-objective .indexable level="3"} ::: {#FMT_SMF_EXT.3 .comp} ::: {#FMT_SMF_EXT.3 .comp} #### FMT_SMF_EXT.3 Current Administrator #### FMT_SMF_EXT.3 Current Administrator ::: element ::: element ::: {#FMT_SMF_EXT.3.1 .reqid} ::: {#FMT_SMF_EXT.3.1 .reqid} [FMT_SMF_EXT.3.1](#FMT_SMF_EXT.3.1){.abbr} [FMT_SMF_EXT.3.1](#FMT_SMF_EXT.3.1){.abbr} ::: ::: ::: reqdesc ::: reqdesc The [TSF](#abbr_TSF) shall provide a mechanism that allows users to view The [TSF](#abbr_TSF) shall provide a mechanism that allows users to view a list of currently authorized administrators and the management a list of currently authorized administrators and the management functions that each administrator is authorized to perform. functions that each administrator is authorized to perform. ::: ::: ::: ::: ::: {.activity_pane .hide} ::: {.activity_pane .hide} ::: activity_pane_header ::: activity_pane_header [[ Evaluation Activities [[ Evaluation Activities ]{.activity_pane_label}[]{.toggler}](#){onclick="toggle(this);return false;"} ]{.activity_pane_label}[]{.toggler}](#){onclick="toggle(this);return false;"} ::: ::: ::: activity_pane_body ::: activity_pane_body ::: component-activity-header ::: component-activity-header [FMT_SMF_EXT.3](#FMT_SMF_EXT.3) [FMT_SMF_EXT.3](#FMT_SMF_EXT.3) ::: ::: ::: eacategory ::: eacategory [TSS](#abbr_TSS) [TSS](#abbr_TSS) ::: ::: ::: ea ::: ea ::: ea ::: ea There are no [TSS](#abbr_TSS) evaluation activities for this component.\ There are no [TSS](#abbr_TSS) evaluation activities for this component.\ \ \ ::: ::: ::: ::: ::: eacategory ::: eacategory Guidance Guidance ::: ::: ::: ea ::: ea ::: ea ::: ea There are no guidance evaluation activities for this component.\ There are no guidance evaluation activities for this component.\ \ \ ::: ::: ::: ::: ::: eacategory ::: eacategory Tests Tests ::: ::: ::: ea ::: ea ::: ea ::: ea The evaluator shall cause the [TOE](#abbr_TOE) to be enrolled into The evaluator shall cause the [TOE](#abbr_TOE) to be enrolled into management. The evaluator shall then invoke this mechanism and verify management. The evaluator shall then invoke this mechanism and verify the ability to view that the device has been enrolled, and view the the ability to view that the device has been enrolled, and view the management functions that the administrator is authorized to perform. management functions that the administrator is authorized to perform. ::: ::: ::: ::: ::: ::: ::: ::: ::: ::: ### A.2.6 Class FPT: Protection of the TSF {#-objective .indexable level="3"} | ### A.2.6 Class FPT: Protection of the TSF {#fpt-objective .indexable level="3"} ::: {#FPT_AEX_EXT.5 .comp} ::: {#FPT_AEX_EXT.5 .comp} #### FPT_AEX_EXT.5 Kernel Address Space Layout Randomization #### FPT_AEX_EXT.5 Kernel Address Space Layout Randomization ::: element ::: element ::: {#FPT_AEX_EXT.5.1 .reqid} ::: {#FPT_AEX_EXT.5.1 .reqid} [FPT_AEX_EXT.5.1](#FPT_AEX_EXT.5.1){.abbr} [FPT_AEX_EXT.5.1](#FPT_AEX_EXT.5.1){.abbr} ::: ::: ::: reqdesc ::: reqdesc The [TSF](#abbr_TSF) shall provide address space layout randomization The [TSF](#abbr_TSF) shall provide address space layout randomization ([ASLR](#abbr_ASLR)) to the kernel. ([ASLR](#abbr_ASLR)) to the kernel. ::: ::: ::: ::: ::: element ::: element ::: {#FPT_AEX_EXT.5.2 .reqid} ::: {#FPT_AEX_EXT.5.2 .reqid} [FPT_AEX_EXT.5.2](#FPT_AEX_EXT.5.2){.abbr} [FPT_AEX_EXT.5.2](#FPT_AEX_EXT.5.2){.abbr} ::: ::: ::: reqdesc ::: reqdesc The base address of any kernel-space memory mapping will consist of The base address of any kernel-space memory mapping will consist of \[**assignment**: [number greater than or equal to \[**assignment**: [number greater than or equal to 4]{.assignable-content}\] unpredictable bits. 4]{.assignable-content}\] unpredictable bits. ::: appnote ::: appnote [Application Note: ]{.note-header}[The unpredictable bits may be [Application Note: ]{.note-header}[The unpredictable bits may be provided by the [TSF](#abbr_TSF) DRBG (as specified in provided by the [TSF](#abbr_TSF) DRBG (as specified in [FCS_RBG.1](#FCS_RBG.1)). ]{.note} | [FCS_RBG.1](#FCS_RBG.1)).]{.note} ::: ::: ::: ::: ::: ::: ::: {.activity_pane .hide} ::: {.activity_pane .hide} ::: activity_pane_header ::: activity_pane_header [[ Evaluation Activities [[ Evaluation Activities ]{.activity_pane_label}[]{.toggler}](#){onclick="toggle(this);return false;"} ]{.activity_pane_label}[]{.toggler}](#){onclick="toggle(this);return false;"} ::: ::: ::: activity_pane_body ::: activity_pane_body ::: component-activity-header ::: component-activity-header [FPT_AEX_EXT.5](#FPT_AEX_EXT.5) [FPT_AEX_EXT.5](#FPT_AEX_EXT.5) ::: ::: ::: eacategory ::: eacategory [TSS](#abbr_TSS) [TSS](#abbr_TSS) ::: ::: ::: ea ::: ea ::: ea ::: ea The evaluator shall ensure that the [TSS](#abbr_TSS) section of the The evaluator shall ensure that the [TSS](#abbr_TSS) section of the [ST](#abbr_ST) describes how the bits are generated and provides a [ST](#abbr_ST) describes how the bits are generated and provides a justification as to why those bits are unpredictable.\ justification as to why those bits are unpredictable.\ \ \ ::: ::: ::: ::: ::: eacategory ::: eacategory Guidance Guidance ::: ::: ::: ea ::: ea ::: ea ::: ea There are no guidance evaluation activities for this component.\ There are no guidance evaluation activities for this component.\ \ \ ::: ::: ::: ::: ::: eacategory ::: eacategory Tests Tests ::: ::: ::: ea ::: ea ::: ea ::: ea **Evaluation Activity Note:** The following test require the developer **Evaluation Activity Note:** The following test require the developer to provide access to a test platform that provides the evaluator with to provide access to a test platform that provides the evaluator with tools that are typically not found on consumer Mobile Device products. tools that are typically not found on consumer Mobile Device products. []{.testlist-} []{.testlist-} - [Test FPT_AEX_EXT.5:1](#_t_60){#_t_60 .defined}: The evaluator shall - [Test FPT_AEX_EXT.5:1](#_t_60){#_t_60 .defined}: The evaluator shall reboot the [TOE](#abbr_TOE) six times. For each of these reboots, reboot the [TOE](#abbr_TOE) six times. For each of these reboots, the evaluator shall examine memory mapping locations of the kernel. the evaluator shall examine memory mapping locations of the kernel. The evaluator shall ensure that for at least five reboots the memory The evaluator shall ensure that for at least five reboots the memory mappings are not placed in the same location on both devices. mappings are not placed in the same location on both devices. ::: ::: ::: ::: ::: ::: ::: ::: ::: ::: ::: {#FPT_AEX_EXT.6 .comp} ::: {#FPT_AEX_EXT.6 .comp} #### FPT_AEX_EXT.6 Write or Execute Memory Page Permissions #### FPT_AEX_EXT.6 Write or Execute Memory Page Permissions ::: element ::: element ::: {#FPT_AEX_EXT.6.1 .reqid} ::: {#FPT_AEX_EXT.6.1 .reqid} [FPT_AEX_EXT.6.1](#FPT_AEX_EXT.6.1){.abbr} [FPT_AEX_EXT.6.1](#FPT_AEX_EXT.6.1){.abbr} ::: ::: ::: reqdesc ::: reqdesc The [TSF](#abbr_TSF) shall prevent write and execute permissions from The [TSF](#abbr_TSF) shall prevent write and execute permissions from being simultaneously granted to any page of physical memory being simultaneously granted to any page of physical memory \[**selection**: [with no exceptions]{#_s_586 .selectable-content}, | \[**selection**: [with no exceptions]{#fpt_aex_ext.6.1_1 [\[**assignment**: [specific exceptions]{.assignable-content}\]]{#_s_587 | .selectable-content}, [\[**assignment**: [specific > exceptions]{.assignable-content}\]]{#fpt_aex_ext.6.1_2 .selectable-content}\]. .selectable-content}\]. ::: appnote ::: appnote [Application Note: ]{.note-header}[Memory used for just-in-time (JIT) [Application Note: ]{.note-header}[Memory used for just-in-time (JIT) compilation is anticipated as an exception in this requirement; if so, compilation is anticipated as an exception in this requirement; if so, the [ST](#abbr_ST) author must address how this exception is permitted. the [ST](#abbr_ST) author must address how this exception is permitted. It is expected that the memory management unit will transition the It is expected that the memory management unit will transition the system to a non-operational state if any violation is detected in kernel system to a non-operational state if any violation is detected in kernel memory space.]{.note} memory space.]{.note} ::: ::: ::: ::: ::: ::: ::: {.activity_pane .hide} ::: {.activity_pane .hide} ::: activity_pane_header ::: activity_pane_header [[ Evaluation Activities [[ Evaluation Activities ]{.activity_pane_label}[]{.toggler}](#){onclick="toggle(this);return false;"} ]{.activity_pane_label}[]{.toggler}](#){onclick="toggle(this);return false;"} ::: ::: ::: activity_pane_body ::: activity_pane_body ::: component-activity-header ::: component-activity-header [FPT_AEX_EXT.6](#FPT_AEX_EXT.6) [FPT_AEX_EXT.6](#FPT_AEX_EXT.6) ::: ::: ::: eacategory ::: eacategory [TSS](#abbr_TSS) [TSS](#abbr_TSS) ::: ::: ::: ea ::: ea ::: ea ::: ea The evaluator shall ensure that the [TSS](#abbr_TSS) describes how the The evaluator shall ensure that the [TSS](#abbr_TSS) describes how the operating system of the application processor prevents all processes operating system of the application processor prevents all processes executing in a non-privileged execution domain from achieving write and executing in a non-privileged execution domain from achieving write and execute permissions on any page of memory (with only specified execute permissions on any page of memory (with only specified exceptions). The evaluator shall ensure that the [TSS](#abbr_TSS) exceptions). The evaluator shall ensure that the [TSS](#abbr_TSS) describes how such processes are unable to request pages of memory with describes how such processes are unable to request pages of memory with such permissions, and how they are unable to change permissions to both such permissions, and how they are unable to change permissions to both write and execute on any pages already allocated to them.\ write and execute on any pages already allocated to them.\ \ \ ::: ::: ::: ::: ::: eacategory ::: eacategory Guidance Guidance ::: ::: ::: ea ::: ea ::: ea ::: ea There are no guidance evaluation activities for this component.\ There are no guidance evaluation activities for this component.\ \ \ ::: ::: ::: ::: ::: eacategory ::: eacategory Tests Tests ::: ::: ::: ea ::: ea ::: ea ::: ea There are no test evaluation activities for this component. There are no test evaluation activities for this component. ::: ::: ::: ::: ::: ::: ::: ::: ::: ::: ::: {#FPT_BBD_EXT.1 .comp} ::: {#FPT_BBD_EXT.1 .comp} #### FPT_BBD_EXT.1 Application Processor Mediation #### FPT_BBD_EXT.1 Application Processor Mediation ::: element ::: element ::: {#FPT_BBD_EXT.1.1 .reqid} ::: {#FPT_BBD_EXT.1.1 .reqid} [FPT_BBD_EXT.1.1](#FPT_BBD_EXT.1.1){.abbr} [FPT_BBD_EXT.1.1](#FPT_BBD_EXT.1.1){.abbr} ::: ::: ::: reqdesc ::: reqdesc The [TSF](#abbr_TSF) shall prevent code executing on any baseband The [TSF](#abbr_TSF) shall prevent code executing on any baseband processor ([BP](#abbr_BP)) from accessing application processor processor ([BP](#abbr_BP)) from accessing application processor ([AP](#abbr_AP)) resources except when mediated by the [AP](#abbr_AP). ([AP](#abbr_AP)) resources except when mediated by the [AP](#abbr_AP). ::: appnote ::: appnote [Application Note: ]{.note-header}[ These resources include:\ [Application Note: ]{.note-header}[ These resources include:\ ]{.note} ]{.note} - Volatile and non-volatile memory - Volatile and non-volatile memory - Control of and data from integrated and non-integrated peripherals - Control of and data from integrated and non-integrated peripherals (e.g. [USB](#abbr_USB) controllers, touch screen controllers, LCD (e.g. [USB](#abbr_USB) controllers, touch screen controllers, LCD controller, codecs) controller, codecs) - Control of and data from integrated and non-integrated I/O sensors - Control of and data from integrated and non-integrated I/O sensors (e.g. camera, light, microphone, [GPS](#abbr_GPS), accelerometers, (e.g. camera, light, microphone, [GPS](#abbr_GPS), accelerometers, geomagnetic field sensors) geomagnetic field sensors) \ \ Mobile devices are becoming increasingly complex having an application Mobile devices are becoming increasingly complex having an application processor that runs an operating system and user applications and processor that runs an operating system and user applications and separate baseband processors that handle cellular and other wireless separate baseband processors that handle cellular and other wireless network connectivity.\ network connectivity.\ \ \ - The application processor within most modern Mobile Devices is a - The application processor within most modern Mobile Devices is a system on a chip ([SoC](#abbr_SoC)) that integrates, for example, system on a chip ([SoC](#abbr_SoC)) that integrates, for example, [CPU](#abbr_CPU)/[GPU](#abbr_GPU) cores and memory interface [CPU](#abbr_CPU)/[GPU](#abbr_GPU) cores and memory interface electronics into a single, power-efficient package. electronics into a single, power-efficient package. - Baseband processors are becoming increasingly complex themselves - Baseband processors are becoming increasingly complex themselves delivering voice encoding alongside multiple independent radios delivering voice encoding alongside multiple independent radios ([LTE](#abbr_LTE), Wi-Fi, Bluetooth, [FM](#abbr_FM), ([LTE](#abbr_LTE), Wi-Fi, Bluetooth, [FM](#abbr_FM), [GPS](#abbr_GPS)) in a single package containing multiple | [GPS](#abbr_GPS)) in a single package containing multiple CPUs and [CPUs](#abbr_CPU) and DSPs. | DSPs. \ \ Thus, the baseband processors in these requirements include such Thus, the baseband processors in these requirements include such integrated [SoCs](#abbr_SoC) and include any radio processors | integrated SoCs and include any radio processors (integrated or not) on (integrated or not) on the Mobile Device.\ | the Mobile Device.\ \ \ All other requirements mostly, except where noted, apply to All other requirements mostly, except where noted, apply to firmware/software on the application processor, but future requirements firmware/software on the application processor, but future requirements (notably, all Integrity, Access Control, and Anti-Exploitation (notably, all Integrity, Access Control, and Anti-Exploitation requirements) will apply to application processors and baseband requirements) will apply to application processors and baseband processors. processors. ::: ::: ::: ::: ::: ::: ::: {.activity_pane .hide} ::: {.activity_pane .hide} ::: activity_pane_header ::: activity_pane_header [[ Evaluation Activities [[ Evaluation Activities ]{.activity_pane_label}[]{.toggler}](#){onclick="toggle(this);return false;"} ]{.activity_pane_label}[]{.toggler}](#){onclick="toggle(this);return false;"} ::: ::: ::: activity_pane_body ::: activity_pane_body ::: component-activity-header ::: component-activity-header [FPT_BBD_EXT.1](#FPT_BBD_EXT.1) [FPT_BBD_EXT.1](#FPT_BBD_EXT.1) ::: ::: ::: eacategory ::: eacategory [TSS](#abbr_TSS) [TSS](#abbr_TSS) ::: ::: ::: ea ::: ea ::: ea ::: ea The evaluator shall ensure that the [TSS](#abbr_TSS) section of the The evaluator shall ensure that the [TSS](#abbr_TSS) section of the [ST](#abbr_ST) describes at a high level how the processors on the [ST](#abbr_ST) describes at a high level how the processors on the Mobile Device interact, including which bus protocols they use to Mobile Device interact, including which bus protocols they use to communicate, any other devices operating on that bus (peripherals and communicate, any other devices operating on that bus (peripherals and sensors), and identification of any shared resources. The evaluator sensors), and identification of any shared resources. The evaluator shall verify that the design described in the [TSS](#abbr_TSS) does not shall verify that the design described in the [TSS](#abbr_TSS) does not permit any [BPs](#abbr_BP) from accessing any of the peripherals and | permit any BPs from accessing any of the peripherals and sensors or from sensors or from accessing main memory (volatile and non-volatile) used | accessing main memory (volatile and non-volatile) used by the by the [AP](#abbr_AP). In particular, the evaluator shall ensure that | [AP](#abbr_AP). In particular, the evaluator shall ensure that the the design prevents modification of executable memory of the | design prevents modification of executable memory of the [AP](#abbr_AP) [AP](#abbr_AP) by the [BP](#abbr_BP).\ | by the [BP](#abbr_BP).\ \ \ ::: ::: ::: ::: ::: eacategory ::: eacategory Guidance Guidance ::: ::: ::: ea ::: ea ::: ea ::: ea There are no guidance evaluation activities for this component.\ There are no guidance evaluation activities for this component.\ \ \ ::: ::: ::: ::: ::: eacategory ::: eacategory Tests Tests ::: ::: ::: ea ::: ea ::: ea ::: ea There are no test evaluation activities for this component. There are no test evaluation activities for this component. ::: ::: ::: ::: ::: ::: ::: ::: ::: ::: ::: {#FPT_BLT_EXT.1 .comp} ::: {#FPT_BLT_EXT.1 .comp} #### FPT_BLT_EXT.1 Limitation of Bluetooth Profile Support #### FPT_BLT_EXT.1 Limitation of Bluetooth Profile Support ::: element ::: element ::: {#FPT_BLT_EXT.1.1 .reqid} ::: {#FPT_BLT_EXT.1.1 .reqid} [FPT_BLT_EXT.1.1](#FPT_BLT_EXT.1.1){.abbr} [FPT_BLT_EXT.1.1](#FPT_BLT_EXT.1.1){.abbr} ::: ::: ::: reqdesc ::: reqdesc The [TSF](#abbr_TSF) shall disable support for \[**assignment**: [list The [TSF](#abbr_TSF) shall disable support for \[**assignment**: [list of Bluetooth profiles]{.assignable-content}\] Bluetooth profiles when of Bluetooth profiles]{.assignable-content}\] Bluetooth profiles when they are not currently being used by an application on the Mobile they are not currently being used by an application on the Mobile Device, and shall require explicit user action to enable them. Device, and shall require explicit user action to enable them. ::: appnote ::: appnote [Application Note: ]{.note-header}[ Some Bluetooth services incur more [Application Note: ]{.note-header}[ Some Bluetooth services incur more serious consequences if unauthorized remote devices gain access to them. serious consequences if unauthorized remote devices gain access to them. Such services should be protected by measures like disabling support for Such services should be protected by measures like disabling support for the associated Bluetooth profile unless it is actively being used by an the associated Bluetooth profile unless it is actively being used by an application on the Mobile Device (in order to prevent discovery by a application on the Mobile Device (in order to prevent discovery by a Service Discovery Protocol search), and then requiring explicit user Service Discovery Protocol search), and then requiring explicit user action to enable those profiles in order to use the services. It may be action to enable those profiles in order to use the services. It may be further appropriate to require additional user action before granting a further appropriate to require additional user action before granting a remote device access to that service.\ remote device access to that service.\ \ \ For example, it may be appropriate to disable the OBEX Push Profile For example, it may be appropriate to disable the OBEX Push Profile until a user on the Mobile Device pushes a button in an application until a user on the Mobile Device pushes a button in an application indicating readiness to transfer an object. After completion of the indicating readiness to transfer an object. After completion of the object transfer, support for the OBEX profile should be suspended until object transfer, support for the OBEX profile should be suspended until the next time the user requests its use.]{.note} | the next time the user requests its use. ]{.note} ::: ::: ::: ::: ::: ::: ::: {.activity_pane .hide} ::: {.activity_pane .hide} ::: activity_pane_header ::: activity_pane_header [[ Evaluation Activities [[ Evaluation Activities ]{.activity_pane_label}[]{.toggler}](#){onclick="toggle(this);return false;"} ]{.activity_pane_label}[]{.toggler}](#){onclick="toggle(this);return false;"} ::: ::: ::: activity_pane_body ::: activity_pane_body ::: component-activity-header ::: component-activity-header [FPT_BLT_EXT.1](#FPT_BLT_EXT.1) [FPT_BLT_EXT.1](#FPT_BLT_EXT.1) ::: ::: ::: eacategory ::: eacategory [TSS](#abbr_TSS) [TSS](#abbr_TSS) ::: ::: ::: ea ::: ea ::: ea ::: ea The evaluator shall ensure that the [TSS](#abbr_TSS) lists all Bluetooth The evaluator shall ensure that the [TSS](#abbr_TSS) lists all Bluetooth profiles that are disabled while not in use by an application and which profiles that are disabled while not in use by an application and which need explicit user action in order to become enabled.\ need explicit user action in order to become enabled.\ \ \ ::: ::: ::: ::: ::: eacategory ::: eacategory Guidance Guidance ::: ::: ::: ea ::: ea ::: ea ::: ea There are no guidance evaluation activities for this component.\ There are no guidance evaluation activities for this component.\ \ \ ::: ::: ::: ::: ::: eacategory ::: eacategory Tests Tests ::: ::: ::: ea ::: ea ::: ea ::: ea The evaluator shall perform the following tests: []{.testlist-} The evaluator shall perform the following tests: []{.testlist-} - [Test FPT_BLT_EXT.1:1](#_t_61){#_t_61 .defined}: While the service - [Test FPT_BLT_EXT.1:1](#_t_61){#_t_61 .defined}: While the service is not in active use by an application on the [TOE](#abbr_TOE), the is not in active use by an application on the [TOE](#abbr_TOE), the evaluator shall attempt to discover a service associated with a evaluator shall attempt to discover a service associated with a \"protected\" Bluetooth profile (as specified by the requirement) on \"protected\" Bluetooth profile (as specified by the requirement) on the [TOE](#abbr_TOE) via a Service Discovery Protocol search. The the [TOE](#abbr_TOE) via a Service Discovery Protocol search. The evaluator shall verify that the service does not appear in the evaluator shall verify that the service does not appear in the Service Discovery Protocol search results. Next, the evaluator shall Service Discovery Protocol search results. Next, the evaluator shall attempt to gain remote access to the service from a device that does attempt to gain remote access to the service from a device that does not currently have a trusted device relationship with the not currently have a trusted device relationship with the [TOE](#abbr_TOE). The evaluator shall verify that this attempt fails [TOE](#abbr_TOE). The evaluator shall verify that this attempt fails due to the unavailability of the service and profile. due to the unavailability of the service and profile. - [Test FPT_BLT_EXT.1:2](#_t_62){#_t_62 .defined}: The evaluator shall - [Test FPT_BLT_EXT.1:2](#_t_62){#_t_62 .defined}: The evaluator shall repeat Test 1 with a device that currently has a trusted device repeat Test 1 with a device that currently has a trusted device relationship with the [TOE](#abbr_TOE) and verify that the same relationship with the [TOE](#abbr_TOE) and verify that the same behavior is exhibited. behavior is exhibited. ::: ::: ::: ::: ::: ::: ::: ::: ::: ::: ::: {#FPT_NOT_EXT.2 .comp} ::: {#FPT_NOT_EXT.2 .comp} #### FPT_NOT_EXT.2 Software Integrity Verification #### FPT_NOT_EXT.2 Software Integrity Verification ::: element ::: element ::: {#FPT_NOT_EXT.2.1 .reqid} ::: {#FPT_NOT_EXT.2.1 .reqid} [FPT_NOT_EXT.2.1](#FPT_NOT_EXT.2.1){.abbr} [FPT_NOT_EXT.2.1](#FPT_NOT_EXT.2.1){.abbr} ::: ::: ::: reqdesc ::: reqdesc The [TSF](#abbr_TSF) shall \[**selection**: [audit]{#_s_600 | The [TSF](#abbr_TSF) shall \[**selection**: [audit]{#fpt_not_ext.2.1_1 .selectable-content}, [provide the administrator with]{#_s_601 | .selectable-content}, [provide the administrator .selectable-content}\] [TSF](#abbr_TSF)-software integrity verification | with]{#fpt_not_ext.2.1_2 .selectable-content}\] values. | [TSF](#abbr_TSF)-software integrity verification values. ::: appnote ::: appnote [Application Note: ]{.note-header}[These notifications are typically [Application Note: ]{.note-header}[These notifications are typically called remote attestation and these integrity values are typically called remote attestation and these integrity values are typically called measurements. The integrity values are calculated from hashes of called measurements. The integrity values are calculated from hashes of critical memory and values, including executable code. The critical memory and values, including executable code. The [ST](#abbr_ST) author must select whether these values are logged as a [ST](#abbr_ST) author must select whether these values are logged as a part of [FAU_GEN.1.1](#FAU_GEN.1.1) or are provided to the part of [FAU_GEN.1.1](#FAU_GEN.1.1) or are provided to the administrator. ]{.note} | administrator.]{.note} ::: ::: ::: ::: ::: ::: ::: element ::: element ::: {#FPT_NOT_EXT.2.2 .reqid} ::: {#FPT_NOT_EXT.2.2 .reqid} [FPT_NOT_EXT.2.2](#FPT_NOT_EXT.2.2){.abbr} [FPT_NOT_EXT.2.2](#FPT_NOT_EXT.2.2){.abbr} ::: ::: ::: reqdesc ::: reqdesc The [TSF](#abbr_TSF) shall cryptographically sign all integrity The [TSF](#abbr_TSF) shall cryptographically sign all integrity verification values. verification values. ::: appnote ::: appnote [Application Note: ]{.note-header}[The intent of this requirement is to [Application Note: ]{.note-header}[The intent of this requirement is to provide assurance to the administrator that the responses provided are provide assurance to the administrator that the responses provided are from the [TOE](#abbr_TOE) and have not been modified or spoofed by a from the [TOE](#abbr_TOE) and have not been modified or spoofed by a man-in-the-middle such as a network-based adversary or a malicious man-in-the-middle such as a network-based adversary or a malicious [MDM](#abbr_MDM) Agent. ]{.note} | [MDM](#abbr_MDM) Agent.]{.note} ::: ::: ::: ::: ::: ::: ::: {.activity_pane .hide} ::: {.activity_pane .hide} ::: activity_pane_header ::: activity_pane_header [[ Evaluation Activities [[ Evaluation Activities ]{.activity_pane_label}[]{.toggler}](#){onclick="toggle(this);return false;"} ]{.activity_pane_label}[]{.toggler}](#){onclick="toggle(this);return false;"} ::: ::: ::: activity_pane_body ::: activity_pane_body ::: element-activity-header ::: element-activity-header [FPT_NOT_EXT.2.1](#FPT_NOT_EXT.2.1) [FPT_NOT_EXT.2.1](#FPT_NOT_EXT.2.1) ::: ::: ::: eacategory ::: eacategory [TSS](#abbr_TSS) [TSS](#abbr_TSS) ::: ::: ::: ea ::: ea The evaluator shall verify that the [TSS](#abbr_TSS) describes which The evaluator shall verify that the [TSS](#abbr_TSS) describes which critical memory is measured for these integrity values and how the critical memory is measured for these integrity values and how the measurement is performed (including which [TOE](#abbr_TOE) software measurement is performed (including which [TOE](#abbr_TOE) software generates these values, how that software accesses the critical memory, generates these values, how that software accesses the critical memory, and which algorithms are used).\ and which algorithms are used).\ \ \ ::: ::: ::: eacategory ::: eacategory Guidance Guidance ::: ::: ::: ea ::: ea If the integrity values are provided to the administrator, the evaluator If the integrity values are provided to the administrator, the evaluator shall verify that the AGD guidance contains instructions for retrieving shall verify that the AGD guidance contains instructions for retrieving these values and information for interpreting them. For example, if these values and information for interpreting them. For example, if multiple measurements are taken, what those measurements are and how multiple measurements are taken, what those measurements are and how changes to those values relate to changes in the device state.\ changes to those values relate to changes in the device state.\ \ \ ::: ::: ::: eacategory ::: eacategory Tests Tests ::: ::: ::: ea ::: ea **Evaluation Activity Note:** The following test may require the **Evaluation Activity Note:** The following test may require the developer to provide access to a test platform that provides the developer to provide access to a test platform that provides the evaluator with tools that are typically not found on consumer Mobile evaluator with tools that are typically not found on consumer Mobile Device products.\ Device products.\ \ \ The evaluator shall repeat the following test for each measurement: The evaluator shall repeat the following test for each measurement: []{.testlist-} []{.testlist-} - [Test FPT_NOT_EXT.2.1:1](#_t_64){#_t_64 .defined}: The evaluator - [Test FPT_NOT_EXT.2.1:1](#_t_64){#_t_64 .defined}: The evaluator shall boot the device in an approved state and record the shall boot the device in an approved state and record the measurement taken (either from the log or by using the measurement taken (either from the log or by using the administrative guidance to retrieve the value via an administrative guidance to retrieve the value via an [MDM](#abbr_MDM) agent). The evaluator shall modify the critical [MDM](#abbr_MDM) agent). The evaluator shall modify the critical memory or value that is measured. The evaluator shall boot the memory or value that is measured. The evaluator shall boot the device and verify that the measurement changed. device and verify that the measurement changed. ::: ::: ::: element-activity-header ::: element-activity-header [FPT_NOT_EXT.2.2](#FPT_NOT_EXT.2.2) [FPT_NOT_EXT.2.2](#FPT_NOT_EXT.2.2) ::: ::: ::: eacategory ::: eacategory [TSS](#abbr_TSS) [TSS](#abbr_TSS) ::: ::: ::: ea ::: ea The evaluator shall verify that the [TSS](#abbr_TSS) describes which key The evaluator shall verify that the [TSS](#abbr_TSS) describes which key the [TSF](#abbr_TSF) uses to sign the responses to queries and the the [TSF](#abbr_TSF) uses to sign the responses to queries and the certificate used to prove ownership of the key, and the method of certificate used to prove ownership of the key, and the method of associating the certificate with a particular device manufacturer and associating the certificate with a particular device manufacturer and model.\ model.\ \ \ ::: ::: ::: eacategory ::: eacategory Guidance Guidance ::: ::: ::: ea ::: ea There are no guidance evaluation activities for this component.\ There are no guidance evaluation activities for this component.\ \ \ ::: ::: ::: eacategory ::: eacategory Tests Tests ::: ::: ::: ea ::: ea The evaluator shall perform the following test: []{.testlist-} The evaluator shall perform the following test: []{.testlist-} - [Test FPT_NOT_EXT.2.2:1](#_t_65){#_t_65 .defined}: The evaluator - [Test FPT_NOT_EXT.2.2:1](#_t_65){#_t_65 .defined}: The evaluator shall write, or the developer shall provide, a management shall write, or the developer shall provide, a management application that queries either the audit logs or the measurements. application that queries either the audit logs or the measurements. The evaluator shall verify that the responses to these queries are The evaluator shall verify that the responses to these queries are signed and verify the signatures against the [TOE](#abbr_TOE)'s signed and verify the signatures against the [TOE](#abbr_TOE)'s certificate. certificate. ::: ::: ::: ::: ::: ::: ::: ::: ::: {#FPT_TST_EXT.2/POSTKERNEL .comp} ::: {#FPT_TST_EXT.2/POSTKERNEL .comp} #### FPT_TST_EXT.2/POSTKERNEL TSF Integrity Checking (Post-Kernel) #### FPT_TST_EXT.2/POSTKERNEL TSF Integrity Checking (Post-Kernel) ::: element ::: element ::: {#FPT_TST_EXT.2.1/POSTKERNEL .reqid} ::: {#FPT_TST_EXT.2.1/POSTKERNEL .reqid} [FPT_TST_EXT.2.1/POSTKERNEL](#FPT_TST_EXT.2.1/POSTKERNEL){.abbr} [FPT_TST_EXT.2.1/POSTKERNEL](#FPT_TST_EXT.2.1/POSTKERNEL){.abbr} ::: ::: ::: reqdesc ::: reqdesc The [TSF](#abbr_TSF) shall verify the integrity of \[**selection**: [all The [TSF](#abbr_TSF) shall verify the integrity of \[**selection**: [all executable code]{#s-all-exe .selectable-content}, [\[**assignment**: executable code]{#s-all-exe .selectable-content}, [\[**assignment**: [subset of executable code]{.assignable-content}\]]{#_s_619 | [subset of executable > code]{.assignable-content}\]]{#fpt_tst_ext.2.1_POSTKERNEL_1 .selectable-content}\] stored in mutable media prior to its execution .selectable-content}\] stored in mutable media prior to its execution through the use of \[**selection**: [a digital signature using an through the use of \[**selection**: [a digital signature using an immutable hardware asymmetric key]{#_s_620 .selectable-content}, [an | immutable hardware asymmetric key]{#fpt_tst_ext.2.1_POSTKERNEL_3 immutable hardware hash of an asymmetric key]{#_s_621 | .selectable-content}, [an immutable hardware hash of an asymmetric .selectable-content}, [an immutable hardware hash]{#_s_622 | key]{#fpt_tst_ext.2.1_POSTKERNEL_4 .selectable-content}, [an immutable .selectable-content}, [a digital signature using a hardware-protected | hardware hash]{#fpt_tst_ext.2.1_POSTKERNEL_5 .selectable-content}, [a asymmetric key]{#_s_623 .selectable-content}, [hardware-protected | digital signature using a hardware-protected asymmetric hash]{#_s_624 .selectable-content}\]. | key]{#fpt_tst_ext.2.1_POSTKERNEL_6 .selectable-content}, > [hardware-protected hash]{#fpt_tst_ext.2.1_POSTKERNEL_7 > .selectable-content}\]. ::: appnote ::: appnote [Application Note: ]{.note-header}[All executable code covered in this | [Application Note: ]{.note-header}[ All executable code covered in this requirement is executed after the kernel is loaded.\ requirement is executed after the kernel is loaded.\ \ \ If \"all executable code in mutable media\" is verified, implementation If \"all executable code in mutable media\" is verified, implementation in hardware or in read-only memory is a natural logical consequence.\ in hardware or in read-only memory is a natural logical consequence.\ \ \ At this time, the verification of software executed on other processors At this time, the verification of software executed on other processors stored in mutable media is not required; however, it may be added in the stored in mutable media is not required; however, it may be added in the first assignment. If all executable code (including bootloaders, kernel, first assignment. If all executable code (including bootloaders, kernel, device drivers, pre-loaded applications, user-loaded applications, and device drivers, pre-loaded applications, user-loaded applications, and libraries) is verified, \"all executable code stored in mutable media\" libraries) is verified, \"all executable code stored in mutable media\" should be selected. ]{.note} should be selected. ]{.note} ::: ::: ::: ::: ::: ::: ::: {.activity_pane .hide} ::: {.activity_pane .hide} ::: activity_pane_header ::: activity_pane_header [[ Evaluation Activities [[ Evaluation Activities ]{.activity_pane_label}[]{.toggler}](#){onclick="toggle(this);return false;"} ]{.activity_pane_label}[]{.toggler}](#){onclick="toggle(this);return false;"} ::: ::: ::: activity_pane_body ::: activity_pane_body ::: component-activity-header ::: component-activity-header [FPT_TST_EXT.2/POSTKERNEL](#FPT_TST_EXT.2/POSTKERNEL) [FPT_TST_EXT.2/POSTKERNEL](#FPT_TST_EXT.2/POSTKERNEL) ::: ::: ::: eacategory ::: eacategory [TSS](#abbr_TSS) [TSS](#abbr_TSS) ::: ::: ::: ea ::: ea ::: ea ::: ea There are no [TSS](#abbr_TSS) evaluation activities for this component.\ There are no [TSS](#abbr_TSS) evaluation activities for this component.\ \ \ ::: ::: ::: ::: ::: eacategory ::: eacategory Guidance Guidance ::: ::: ::: ea ::: ea ::: ea ::: ea There are no guidance evaluation activities for this component.\ There are no guidance evaluation activities for this component.\ \ \ ::: ::: ::: ::: ::: eacategory ::: eacategory Tests Tests ::: ::: ::: ea ::: ea ::: ea ::: ea The evaluation activity shall be completed in conjunction with The evaluation activity shall be completed in conjunction with [FPT_TST_EXT.2/PREKERNEL](#FPT_TST_EXT.2/PREKERNEL) for all executable [FPT_TST_EXT.2/PREKERNEL](#FPT_TST_EXT.2/PREKERNEL) for all executable code specified. code specified. ::: ::: ::: ::: ::: ::: ::: ::: ::: ::: ::: {#FPT_TUD_EXT.5 .comp} ::: {#FPT_TUD_EXT.5 .comp} #### FPT_TUD_EXT.5 Application Verification #### FPT_TUD_EXT.5 Application Verification ::: element ::: element ::: {#FPT_TUD_EXT.5.1 .reqid} ::: {#FPT_TUD_EXT.5.1 .reqid} [FPT_TUD_EXT.5.1](#FPT_TUD_EXT.5.1){.abbr} [FPT_TUD_EXT.5.1](#FPT_TUD_EXT.5.1){.abbr} ::: ::: ::: reqdesc ::: reqdesc The [TSF](#abbr_TSF) shall by default only install mobile applications The [TSF](#abbr_TSF) shall by default only install mobile applications cryptographically verified by \[**selection**: [a built-in X.509v3 cryptographically verified by \[**selection**: [a built-in X.509v3 certificate]{#_s_637 .selectable-content}, [a configured X.509v3 | certificate]{#fpt_tud_ext.5.1_1 .selectable-content}, [a configured certificate]{#_s_638 .selectable-content}\]. | X.509v3 certificate]{#fpt_tud_ext.5.1_2 .selectable-content}\]. ::: appnote ::: appnote [Application Note: ]{.note-header}[The built-in certificate is installed | [Application Note: ]{.note-header}[ The built-in certificate is by the manufacturer either at time of manufacture or as a part of system | installed by the manufacturer either at time of manufacture or as a part updates. The configured certificate used to verify the signature is set | of system updates. The configured certificate used to verify the according to [FMT_SMF_EXT.1](#FMT_SMF_EXT.1) function | signature is set according to [FMT_SMF_EXT.1](#FMT_SMF_EXT.1) function [33](#mf-digSign).]{.note} | [33](#mf-digSign). ]{.note} ::: ::: ::: ::: ::: ::: ::: {.activity_pane .hide} ::: {.activity_pane .hide} ::: activity_pane_header ::: activity_pane_header [[ Evaluation Activities [[ Evaluation Activities ]{.activity_pane_label}[]{.toggler}](#){onclick="toggle(this);return false;"} ]{.activity_pane_label}[]{.toggler}](#){onclick="toggle(this);return false;"} ::: ::: ::: activity_pane_body ::: activity_pane_body ::: component-activity-header ::: component-activity-header [FPT_TUD_EXT.5](#FPT_TUD_EXT.5) [FPT_TUD_EXT.5](#FPT_TUD_EXT.5) ::: ::: ::: eacategory ::: eacategory [TSS](#abbr_TSS) [TSS](#abbr_TSS) ::: ::: ::: ea ::: ea ::: ea ::: ea The evaluator shall verify that the [TSS](#abbr_TSS) describes how The evaluator shall verify that the [TSS](#abbr_TSS) describes how mobile application software is verified at installation. The evaluator mobile application software is verified at installation. The evaluator shall ensure that this method uses a digital signature by a code signing shall ensure that this method uses a digital signature by a code signing certificate.\ certificate.\ \ \ ::: ::: ::: ::: ::: eacategory ::: eacategory Guidance Guidance ::: ::: ::: ea ::: ea ::: ea ::: ea There are no guidance evaluation activities for this component.\ There are no guidance evaluation activities for this component.\ \ \ ::: ::: ::: ::: ::: eacategory ::: eacategory Tests Tests ::: ::: ::: ea ::: ea ::: ea ::: ea []{.testlist-} []{.testlist-} - [Test FPT_TUD_EXT.5:1](#_t_76){#_t_76 .defined}: The evaluator shall - [Test FPT_TUD_EXT.5:1](#_t_76){#_t_76 .defined}: The evaluator shall write, or the developer shall provide access to, an application. The write, or the developer shall provide access to, an application. The evaluator shall try to install this application without a digitally evaluator shall try to install this application without a digitally signature and shall verify that installation fails. The evaluator signature and shall verify that installation fails. The evaluator shall attempt to install an application digitally signed with an shall attempt to install an application digitally signed with an appropriate certificate, and verify that installation succeeds. appropriate certificate, and verify that installation succeeds. - [Test FPT_TUD_EXT.5:2](#_t_77){#_t_77 .defined}: The evaluator shall - [Test FPT_TUD_EXT.5:2](#_t_77){#_t_77 .defined}: The evaluator shall digitally sign the application with an invalid certificate and digitally sign the application with an invalid certificate and verify that application installation fails. The evaluator shall verify that application installation fails. The evaluator shall digitally sign the application with a certificate that does not have digitally sign the application with a certificate that does not have the Code Signing purpose and verify that application installation the Code Signing purpose and verify that application installation fails. This test may be performed in conjunction with the Evaluation fails. This test may be performed in conjunction with the Evaluation Activities for FIA_X509_EXT.1 as defined in the [Functional Package Activities for FIA_X509_EXT.1 as defined in the [Functional Package for X.509, version for X.509, version 1.0](https://www.niap-ccevs.org/protectionprofiles/511). 1.0](https://www.niap-ccevs.org/protectionprofiles/511). - [Test FPT_TUD_EXT.5:3](#_t_78){#_t_78 .defined}: If necessary, the - [Test FPT_TUD_EXT.5:3](#_t_78){#_t_78 .defined}: If necessary, the evaluator shall configure the device to limit the public keys that evaluator shall configure the device to limit the public keys that can sign application software according to the AGD guidance. The can sign application software according to the AGD guidance. The evaluator shall digitally sign the application with a certificate evaluator shall digitally sign the application with a certificate disallowed by the device or configuration and verify that disallowed by the device or configuration and verify that application installation fails. The evaluator shall attempt to application installation fails. The evaluator shall attempt to install an application digitally signed with an authorized install an application digitally signed with an authorized certificate and verify that application installation succeeds. certificate and verify that application installation succeeds. ::: ::: ::: ::: ::: ::: ::: ::: ::: ::: ::: {#FPT_TUD_EXT.6 .comp} ::: {#FPT_TUD_EXT.6 .comp} #### FPT_TUD_EXT.6 Trusted Update Verification #### FPT_TUD_EXT.6 Trusted Update Verification ::: element ::: element ::: {#FPT_TUD_EXT.6.1 .reqid} ::: {#FPT_TUD_EXT.6.1 .reqid} [FPT_TUD_EXT.6.1](#FPT_TUD_EXT.6.1){.abbr} [FPT_TUD_EXT.6.1](#FPT_TUD_EXT.6.1){.abbr} ::: ::: ::: reqdesc ::: reqdesc The [TSF](#abbr_TSF) shall verify that software updates to the The [TSF](#abbr_TSF) shall verify that software updates to the [TSF](#abbr_TSF) are a current or later version than the current version [TSF](#abbr_TSF) are a current or later version than the current version of the [TSF](#abbr_TSF). of the [TSF](#abbr_TSF). ::: appnote ::: appnote [Application Note: ]{.note-header}[ A later version has a larger version | [Application Note: ]{.note-header}[A later version has a larger version number. The method for distinguishing newer software versions from older number. The method for distinguishing newer software versions from older versions is determined by the manufacturer. ]{.note} | versions is determined by the manufacturer.]{.note} ::: ::: ::: ::: ::: ::: ::: {.activity_pane .hide} ::: {.activity_pane .hide} ::: activity_pane_header ::: activity_pane_header [[ Evaluation Activities [[ Evaluation Activities ]{.activity_pane_label}[]{.toggler}](#){onclick="toggle(this);return false;"} ]{.activity_pane_label}[]{.toggler}](#){onclick="toggle(this);return false;"} ::: ::: ::: activity_pane_body ::: activity_pane_body ::: component-activity-header ::: component-activity-header [FPT_TUD_EXT.6](#FPT_TUD_EXT.6) [FPT_TUD_EXT.6](#FPT_TUD_EXT.6) ::: ::: ::: eacategory ::: eacategory [TSS](#abbr_TSS) [TSS](#abbr_TSS) ::: ::: ::: ea ::: ea ::: ea ::: ea The evaluator shall verify that the [TSS](#abbr_TSS) describes the The evaluator shall verify that the [TSS](#abbr_TSS) describes the mechanism that prevents the [TSF](#abbr_TSF) from installing software mechanism that prevents the [TSF](#abbr_TSF) from installing software updates that are an older version that the currently installed version.\ updates that are an older version that the currently installed version.\ \ \ ::: ::: ::: ::: ::: eacategory ::: eacategory Guidance Guidance ::: ::: ::: ea ::: ea ::: ea ::: ea There are no guidance evaluation activities for this component.\ There are no guidance evaluation activities for this component.\ \ \ ::: ::: ::: ::: ::: eacategory ::: eacategory Tests Tests ::: ::: ::: ea ::: ea ::: ea ::: ea The evaluator shall repeat the following tests to cover all allowed The evaluator shall repeat the following tests to cover all allowed software update mechanisms as described in the [TSS](#abbr_TSS). For software update mechanisms as described in the [TSS](#abbr_TSS). For example, if the update mechanism replaces an entire partition containing example, if the update mechanism replaces an entire partition containing many separate code files, the evaluator does not need to repeat the test many separate code files, the evaluator does not need to repeat the test for each individual file. []{.testlist-} for each individual file. []{.testlist-} - [Test FPT_TUD_EXT.6:1](#_t_79){#_t_79 .defined}: The evaluator shall - [Test FPT_TUD_EXT.6:1](#_t_79){#_t_79 .defined}: The evaluator shall attempt to install an earlier version of software (as determined by attempt to install an earlier version of software (as determined by the manufacturer). The evaluator shall verify that this attempt the manufacturer). The evaluator shall verify that this attempt fails by checking the version identifiers or cryptographic hashes of fails by checking the version identifiers or cryptographic hashes of the privileged software against those previously recorded and the privileged software against those previously recorded and checking that the values have not changed. checking that the values have not changed. - [Test FPT_TUD_EXT.6:2](#_t_80){#_t_80 .defined}: The evaluator shall - [Test FPT_TUD_EXT.6:2](#_t_80){#_t_80 .defined}: The evaluator shall attempt to install a current or later version and shall verify that attempt to install a current or later version and shall verify that the update succeeds. the update succeeds. ::: ::: ::: ::: ::: ::: ::: ::: ::: ::: ## A.3 Implementation-dependent Requirements {#feat-based-reqs .indexable level="2"} ## A.3 Implementation-dependent Requirements {#feat-based-reqs .indexable level="2"} ### A.3.1 Auditable Events for Implementation-dependent Requirements {#feat-based-req ### A.3.1 Auditable Events for Implementation-dependent Requirements {#feat-based-req +-----------------------+-----------------------+-----------------------+ +-----------------------+-----------------------+-----------------------+ | Requirement | Auditable Events | Additional Audit | | Requirement | Auditable Events | Additional Audit | | | | Record Contents | | | | Record Contents | +=======================+=======================+=======================+ +=======================+=======================+=======================+ | [FCS_CK | | | | [FCS_CK | | | | M_EXT.7/UNLOCKED](#FC | | | | M_EXT.7/UNLOCKED](#FC | | | | S_CKM_EXT.7/UNLOCKED) | | | | S_CKM_EXT.7/UNLOCKED) | | | +-----------------------+-----------------------+-----------------------+ +-----------------------+-----------------------+-----------------------+ | | | | | | | | +-----------------------+-----------------------+-----------------------+ +-----------------------+-----------------------+-----------------------+ | No events specified | N/A | | | No events specified | N/A | | +-----------------------+-----------------------+-----------------------+ +-----------------------+-----------------------+-----------------------+ | [FDP_UPC_ | | | | [FDP_UPC_ | | | | EXT.1/BLUETOOTH](#FDP | | | | EXT.1/BLUETOOTH](#FDP | | | | _UPC_EXT.1/BLUETOOTH) | | | | _UPC_EXT.1/BLUETOOTH) | | | +-----------------------+-----------------------+-----------------------+ +-----------------------+-----------------------+-----------------------+ | | | | | | | | +-----------------------+-----------------------+-----------------------+ +-----------------------+-----------------------+-----------------------+ | Application | - Name of | | | Application | - Name of | | | initiation of trusted | application | | | initiation of trusted | application | | | channel | - Trusted channel | | | channel | - Trusted channel | | | | protocol | | | | protocol | | | | - Non-TOE endpoint | | | | - Non-TOE endpoint | | | | of connection | | | | of connection | | +-----------------------+-----------------------+-----------------------+ +-----------------------+-----------------------+-----------------------+ : [Table [23]{.counter}]{#t-audit-feat-based .ctr : [Table [23]{.counter}]{#t-audit-feat-based .ctr myid="t-audit-feat-based" counter-type="ct-Table"}: Auditable Events for myid="t-audit-feat-based" counter-type="ct-Table"}: Auditable Events for Implementation-dependent Requirements Implementation-dependent Requirements ### A.3.2 Class FCS: Cryptographic Support {#-feat-based .indexable level="3"} | ### A.3.2 Class FCS: Cryptographic Support {#fcs-feat-based .indexable level="3"} ::: {#FCS_CKM_EXT.7/UNLOCKED .comp} ::: {#FCS_CKM_EXT.7/UNLOCKED .comp} #### FCS_CKM_EXT.7/UNLOCKED Cryptographic Key Establishment (When Unlocked) #### FCS_CKM_EXT.7/UNLOCKED Cryptographic Key Establishment (When Unlocked) ::: statustag ::: statustag ***This component must be included in the [ST](#abbr_ST) if the ***This component must be included in the [ST](#abbr_ST) if the [TOE](#abbr_TOE) implements any of the following features:***\ [TOE](#abbr_TOE) implements any of the following features:***\ - ***[Key Agreement Support](#key-agreement-support)*** - ***[Key Agreement Support](#key-agreement-support)*** ::: ::: ::: element ::: element ::: {#FCS_CKM_EXT.7.1/UNLOCKED .reqid} ::: {#FCS_CKM_EXT.7.1/UNLOCKED .reqid} [FCS_CKM_EXT.7.1/UNLOCKED](#FCS_CKM_EXT.7.1/UNLOCKED){.abbr} [FCS_CKM_EXT.7.1/UNLOCKED](#FCS_CKM_EXT.7.1/UNLOCKED){.abbr} ::: ::: ::: reqdesc ::: reqdesc The [TSF](#abbr_TSF) shall derive shared cryptographic keys with input The [TSF](#abbr_TSF) shall derive shared cryptographic keys with input from multiple parties in accordance with specified cryptographic key from multiple parties in accordance with specified cryptographic key agreement algorithms \[**selection**: [Cryptographic agreement algorithms \[**selection**: [Cryptographic algorithm]{.selectable-content}\] and specified cryptographic parameters algorithm]{.selectable-content}\] and specified cryptographic parameters \[**selection**: [Cryptographic parameters]{.selectable-content}\] that \[**selection**: [Cryptographic parameters]{.selectable-content}\] that meet the following: \[**selection**: [List of meet the following: \[**selection**: [List of standards]{.selectable-content}\] . standards]{.selectable-content}\] . [Table [Table [24]{.counter}](#fcs-ckm-ext-7-unlocked-sels){.fcs-ckm-ext-7-unlocked-sels-ref [24]{.counter}](#fcs-ckm-ext-7-unlocked-sels){.fcs-ckm-ext-7-unlocked-sels-ref onclick="showTarget('fcs-ckm-ext-7-unlocked-sels')"} provides the onclick="showTarget('fcs-ckm-ext-7-unlocked-sels')"} provides the allowable choices for completion of the selection operations of allowable choices for completion of the selection operations of [FCS_CKM_EXT.7/UNLOCKED](#FCS_CKM_EXT.7/UNLOCKED). [FCS_CKM_EXT.7/UNLOCKED](#FCS_CKM_EXT.7/UNLOCKED). +-----------------+-----------------+-----------------+-----------------+ +-----------------+-----------------+-----------------+-----------------+ | Identifier | Cryptographic | Cryptographic | List of | | Identifier | Cryptographic | Cryptographic | List of | | | algorithm | parameters | standards | | | algorithm | parameters | standards | +=================+=================+=================+=================+ +=================+=================+=================+=================+ | [DH](#abbr_DH) | Finite Field | Static domain | [NI | | [DH](#abbr_DH) | Finite Field | Static domain | [NI | | | Cryptography | parameters | ST](#abbr_NIST) | | | Cryptography | parameters | ST](#abbr_NIST) | | | Diffie-Hellman | approved for | SP 800-56A | | | Diffie-Hellman | approved for | SP 800-56A | | | | \ | Revision 3 | | | | \ | Revision 3 | | | | [**selection**: | (Section | | | | [**selection**: | (Section | | | | | 5.7.1.1) | | | | | 5.7.1.1) | | | | - [IKE Groups | \[[ | | | | - [IKE Groups | \[[ | | | | \ | DH](#abbr_DH)\] | | | | \ | DH](#abbr_DH)\] | | | | [**selection**: | | | | | [**selection**: | | | | | [MO | \ | | | | [MO | \ | | | | DP-3072]{#sel-k | [**selection**: | | | | DP-3072]{#sel-k | [**selection**: | | | | at-ffc-modp3072 | [RFC 3526 \[IKE | | | | at-ffc-modp3072 | [RFC 3526 \[IKE | | | | .selec | gr | | | | | .selec | groups\ | | | | table-content}, | oups\]]{#_s_162 | | | | | table-content}, | ]]{#fcs_ckm_ext | | | | [MO | .selec | | | | | [MO | .7.1_UNLOCKED_3 | | | | DP-4096]{#sel-k | table-content}, | | | | | DP-4096]{#sel-k | .selec | | | | at-ffc-modp4096 | [RFC 7919 | | | | | at-ffc-modp4096 | table-content}, | | | | .selec | \[[ | | | | | .selec | [RFC 7919 | | | | table-content}, | TLS](#abbr_TLS) | | | | | table-content}, | \[[ | | | | [MO | gr | | | | | [MO | TLS](#abbr_TLS) | | | | DP-6144]{#sel-k | oups\]]{#_s_163 | | | | | DP-6144]{#sel-k | groups\ | | | | at-ffc-modp6144 | .select | | | | | at-ffc-modp6144 | ]]{#fcs_ckm_ext | | | | .selec | able-content}\] | | | | | .selec | .7.1_UNLOCKED_4 | | | | table-content}, | | | | | | table-content}, | .select | | | | [MO | | | | | | [MO | able-content}\] | | | | DP-8192]{#sel-k | | | | | DP-8192]{#sel-k | | | | | at-ffc-modp8192 | | | | | at-ffc-modp8192 | | | | | . | | | | | | .selec | | | | | selectable-cont | | | | | | table-content}\ | | | | | ent}\]]{#_s_152 | | | | | | ]]{#fcs_ckm_ext | | > | | | .7.1_UNLOCKED_1 | | | | | .sele | | | | | .sele | | | | | ctable-content} | | | | | ctable-content} | | | | | - [[ | | | | | - [[ | | | | | TLS](#abbr_TLS) | | | | | TLS](#abbr_TLS) | | | | | Groups | | | | | Groups | | | | | \ | | | | | \ | | | | | [**selection**: | | | | | [**selection**: | | | | | [ffd | | | | | [ffd | | | | | he3072]{#sel-ka | | | | | he3072]{#sel-ka | | | | | t-ffc-ffdhe3072 | | | | | t-ffc-ffdhe3072 | | | | | .selec | | | | | .selec | | | | | table-content}, | | | | | table-content}, | | | | | [ffd | | | | | [ffd | | | | | he4096]{#sel-ka | | | | | he4096]{#sel-ka | | | | | t-ffc-ffdhe4096 | | | | | t-ffc-ffdhe4096 | | | | | .selec | | | | | .selec | | | | | table-content}, | | | | | table-content}, | | | | | [ffd | | | | | [ffd | | | | | he6144]{#sel-ka | | | | | he6144]{#sel-ka | | | | | t-ffc-ffdhe6144 | | | | | t-ffc-ffdhe6144 | | | | | .selec | | | | | .selec | | | | | table-content}, | | | | | table-content}, | | | | | [ffd | | | | | [ffd | | | | | he8192]{#sel-ka | | | | | he8192]{#sel-ka | | | | | t-ffc-ffdhe8192 | | | | | t-ffc-ffdhe8192 | | | | | . | | | | | | .selec | | | | | selectable-cont | | | | | | table-content}\ | | | | | ent}\]]{#_s_157 | | | | | | ]]{#fcs_ckm_ext | | > | | | .7.1_UNLOCKED_2 | | | | | .sele | | | | | .sele | | | | | ctable-content} | | | | | ctable-content} | | | | | | | | | | | | | | | \] | | | | | \] | | +-----------------+-----------------+-----------------+-----------------+ +-----------------+-----------------+-----------------+-----------------+ | [EC | Elliptic Curve | Elliptic Curve | [NI | | [EC | Elliptic Curve | Elliptic Curve | [NI | | DH](#abbr_ECDH) | Diffie-Hellman | \ | ST](#abbr_NIST) | | DH](#abbr_ECDH) | Diffie-Hellman | \ | ST](#abbr_NIST) | | | | [**selection**: | SP 800-56A | | | | [**selection**: | SP 800-56A | | | | [P-256]{#sel-ex | Revision 3 | | | | [P-256]{#sel-ex | Revision 3 | | | | p-kat-ecdh-P384 | (Section | | | | p-kat-ecdh-P384 | (Section | | | | .selec | 5.7.1.2) | | | | .selec | 5.7.1.2) | | | | table-content}, | \[[ECDH | | | | table-content}, | \[[ECDH | | | | [P-384]{#sel-ex | ](#abbr_ECDH)\] | | | | [P-384]{#sel-ex | ](#abbr_ECDH)\] | | | | p-kat-ecdh-P384 | | | | | p-kat-ecdh-P384 | | | | | .selec | [NI | | | | .selec | [NI | | | | table-content}, | ST](#abbr_NIST) | | | | table-content}, | ST](#abbr_NIST) | | | | [P-521]{#sel-ex | SP 800-186 | | | | [P-521]{#sel-ex | SP 800-186 | | | | p-kat-ecdh-P521 | (Section 3.2.1) | | | | p-kat-ecdh-P521 | (Section 3.2.1) | | | | .select | \[[NI | | | | .select | \[[NI | | | | able-content}\] | ST](#abbr_NIST) | | | | able-content}\] | ST](#abbr_NIST) | | | | | Curves\] | | | | | Curves\] | +-----------------+-----------------+-----------------+-----------------+ +-----------------+-----------------+-----------------+-----------------+ : [Table [24]{.counter}]{#fcs-ckm-ext-7-unlocked-sels .ctr : [Table [24]{.counter}]{#fcs-ckm-ext-7-unlocked-sels .ctr myid="fcs-ckm-ext-7-unlocked-sels" counter-type="ct-Table"}: Allowable myid="fcs-ckm-ext-7-unlocked-sels" counter-type="ct-Table"}: Allowable choices for [FCS_CKM_EXT.7/UNLOCKED](#FCS_CKM_EXT.7/UNLOCKED) choices for [FCS_CKM_EXT.7/UNLOCKED](#FCS_CKM_EXT.7/UNLOCKED) ::: appnote ::: appnote [Application Note: ]{.note-header}[ This [SFR](#abbr_SFR) is claimed if [Application Note: ]{.note-header}[ This [SFR](#abbr_SFR) is claimed if the [TSF](#abbr_TSF) supports key agreement schemes as a method of key the [TSF](#abbr_TSF) supports key agreement schemes as a method of key establishment for external communications channels. This will generally establishment for external communications channels. This will generally apply to all conformant [TOEs](#abbr_TOE), except in the rare (but apply to all conformant [TOEs](#abbr_TOE), except in the rare (but possible) case where only key encapsulation is used.]{.note} | possible) case where only key encapsulation is used. ]{.note} This [SFR](#abbr_SFR) must be included in the [ST](#abbr_ST) if This [SFR](#abbr_SFR) must be included in the [ST](#abbr_ST) if agreement is a service provided by the [TOE](#abbr_TOE) to tenant agreement is a service provided by the [TOE](#abbr_TOE) to tenant software, or if it is used by the [TOE](#abbr_TOE) itself to support or software, or if it is used by the [TOE](#abbr_TOE) itself to support or implement [PP](#abbr_PP)-specified security functionality. implement [PP](#abbr_PP)-specified security functionality. The above algorithms are [CNSA](#abbr_CNSA) compliant with the exception The above algorithms are [CNSA](#abbr_CNSA) compliant with the exception of P-256 [ECDH](#abbr_ECDH). This may only be selected if the [PP-Module of P-256 [ECDH](#abbr_ECDH). This may only be selected if the [PP-Module for Bluetooth, version | for Bluetooth, version 2.0]() is included in the [ST](#abbr_ST) and 2.0](https://www.niap-ccevs.org/protectionprofiles/425) is included in | P-256 may only be used specifically for Bluetooth functions. the [ST](#abbr_ST) and P-256 may only be used specifically for Bluetooth < functions. < ::: ::: ::: ::: ::: ::: ::: {.activity_pane .hide} ::: {.activity_pane .hide} ::: activity_pane_header ::: activity_pane_header [[ Evaluation Activities [[ Evaluation Activities ]{.activity_pane_label}[]{.toggler}](#){onclick="toggle(this);return false;"} ]{.activity_pane_label}[]{.toggler}](#){onclick="toggle(this);return false;"} ::: ::: ::: activity_pane_body ::: activity_pane_body ::: component-activity-header ::: component-activity-header [FCS_CKM_EXT.7/UNLOCKED](#FCS_CKM_EXT.7/UNLOCKED) [FCS_CKM_EXT.7/UNLOCKED](#FCS_CKM_EXT.7/UNLOCKED) ::: ::: ::: eacategory ::: eacategory [TSS](#abbr_TSS) [TSS](#abbr_TSS) ::: ::: ::: ea ::: ea ::: ea ::: ea The evaluator shall ensure that the [TSS](#abbr_TSS) documents that the The evaluator shall ensure that the [TSS](#abbr_TSS) documents that the security strength of the material contributed by the [TOE](#abbr_TOE) is security strength of the material contributed by the [TOE](#abbr_TOE) is sufficient for the security strength of the key and the agreement sufficient for the security strength of the key and the agreement method. If support for P-256 is claimed, the evaluator shall examine the method. If support for P-256 is claimed, the evaluator shall examine the [TSS](#abbr_TSS) to verify that it is only used for Bluetooth functions. [TSS](#abbr_TSS) to verify that it is only used for Bluetooth functions. ::: ::: ::: ::: ::: eacategory ::: eacategory Guidance Guidance ::: ::: ::: ea ::: ea ::: ea ::: ea There are no additional Guidance evaluation activities for this There are no additional Guidance evaluation activities for this component. component. ::: ::: ::: ::: ::: eacategory ::: eacategory Tests Tests ::: ::: ::: ea ::: ea ::: ea ::: ea The following tests are conditional based upon the selections made in The following tests are conditional based upon the selections made in the [SFR](#abbr_SFR). The evaluator shall perform the following test or the [SFR](#abbr_SFR). The evaluator shall perform the following test or witness respective tests executed by the developer. The tests must be witness respective tests executed by the developer. The tests must be executed on a platform that is as close as practically possible to the executed on a platform that is as close as practically possible to the operational platform (but which may be instrumented in terms of, for operational platform (but which may be instrumented in terms of, for example, use of a debug mode). Where the test is not carried out on the example, use of a debug mode). Where the test is not carried out on the [TOE](#abbr_TOE) itself, the test platform shall be identified and the [TOE](#abbr_TOE) itself, the test platform shall be identified and the differences between test environment and [TOE](#abbr_TOE) execution differences between test environment and [TOE](#abbr_TOE) execution environment shall be described. | environment shall be described.\ < \ < **[FFC](#abbr_FFC) Diffie-Hellman Key Agreement** **[FFC](#abbr_FFC) Diffie-Hellman Key Agreement** ----------------- ----------------- ------------------ -------------------- ----------------- ----------------- ------------------ -------------------- Identifier Cryptographic Cryptographic List of Standards Identifier Cryptographic Cryptographic List of Standards Algorithm Parameters Algorithm Parameters [DH](#abbr_DH) Finite Field Static domain [NIST](#abbr_NIST) [DH](#abbr_DH) Finite Field Static domain [NIST](#abbr_NIST) Cryptography parameters SP 800-56A Revision Cryptography parameters SP 800-56A Revision Diffie-Hellman approved for 3 (Section 5.7.1.1) Diffie-Hellman approved for 3 (Section 5.7.1.1) \[**selection:** \[[DH](#abbr_DH)\] \[**selection:** \[[DH](#abbr_DH)\] IKE groups IKE groups \[**selection:** \[**selection:** RFC \[**selection:** \[**selection:** RFC MODP-3072, 3526 \[IKE Groups\], MODP-3072, 3526 \[IKE Groups\], MODP-4096, RFC 7919 MODP-4096, RFC 7919 MODP-6144, \[[TLS](#abbr_TLS) MODP-6144, \[[TLS](#abbr_TLS) MODP-8192\], Groups\]\] MODP-8192\], Groups\]\] [TLS](#abbr_TLS) [TLS](#abbr_TLS) groups groups \[**selection:** \[**selection:** ffdhe3072, ffdhe3072, ffdhe4096, ffdhe4096, ffdhe6144, ffdhe6144, ffdhe8192\]\] ffdhe8192\]\] ----------------- ----------------- ------------------ -------------------- ----------------- ----------------- ------------------ -------------------- To test the [TOE](#abbr_TOE)'s implementation of [FFC](#abbr_FFC) To test the [TOE](#abbr_TOE)'s implementation of [FFC](#abbr_FFC) Diffie-Hellman Key Agreement, the evaluator shall perform the Algorithm Diffie-Hellman Key Agreement, the evaluator shall perform the Algorithm Functional Test and Validation Test using the following input Functional Test and Validation Test using the following input parameters: parameters: - Domain Parameter Group \[MODP-3072, MODP-4096, MODP-6144, MODP-8192, - Domain Parameter Group \[MODP-3072, MODP-4096, MODP-6144, MODP-8192, ffdhe3072, ffdhe4096, ffdhe6144, ffdhe8192\] ffdhe3072, ffdhe4096, ffdhe6144, ffdhe8192\] \ \ ***Algorithm Functional Test***\ ***Algorithm Functional Test***\ For each supported domain parameter group, the evaluator shall generate For each supported domain parameter group, the evaluator shall generate 10 test cases by generating the initiator and responder secret keys 10 test cases by generating the initiator and responder secret keys using random data, calculating the responder public key, and creating using random data, calculating the responder public key, and creating the shared secret. The resulting shared secrets shall be compared with the shared secret. The resulting shared secrets shall be compared with those generated by a known-good implementation using the same inputs. | those generated by a known-good implementation using the same inputs.\ < \ < ***Validation Test***\ ***Validation Test***\ For each supported combination of the above parameters the evaluator For each supported combination of the above parameters the evaluator shall generate 15 Diffie Hellman initiator/responder key pairs using the shall generate 15 Diffie Hellman initiator/responder key pairs using the key generation function of a known-good implementation. For each set of key generation function of a known-good implementation. For each set of key pairs, the evaluator shall modify five initiator private key values. key pairs, the evaluator shall modify five initiator private key values. The remaining key values are left unchanged (i.e., correct). To The remaining key values are left unchanged (i.e., correct). To determine correctness, the evaluator shall confirm that the 15 shared determine correctness, the evaluator shall confirm that the 15 shared secrets correspond as expected for both the modified and unmodified secrets correspond as expected for both the modified and unmodified inputs. | inputs.\ < \ < **Elliptic Curve Diffie-Hellman Key Agreement** **Elliptic Curve Diffie-Hellman Key Agreement** -------------------- ----------------- ------------------ ------------------------ -------------------- ----------------- ------------------ ------------------------ Identifier Cryptographic Cryptographic List of Standards Identifier Cryptographic Cryptographic List of Standards Algorithm Parameters Algorithm Parameters [ECDH](#abbr_ECDH) Elliptic Curve Elliptic Curve [NIST](#abbr_NIST) SP [ECDH](#abbr_ECDH) Elliptic Curve Elliptic Curve [NIST](#abbr_NIST) SP Diffie-Hellman \[**selection:** 800-56A Revision 3 Diffie-Hellman \[**selection:** 800-56A Revision 3 P-256, P-384, (Section 5.7.1.2) P-256, P-384, (Section 5.7.1.2) P-521 \[[ECDH](#abbr_ECDH)\] P-521 \[[ECDH](#abbr_ECDH)\] [NIST](#abbr_NIST) SP [NIST](#abbr_NIST) SP 800-186 (Section 3.2.1) 800-186 (Section 3.2.1) \[[NIST](#abbr_NIST) \[[NIST](#abbr_NIST) Curves\] Curves\] -------------------- ----------------- ------------------ ------------------------ -------------------- ----------------- ------------------ ------------------------ To test the [TOE](#abbr_TOE)'s implementation of Elliptic Curve To test the [TOE](#abbr_TOE)'s implementation of Elliptic Curve Diffie-Hellman Key Agreement, the evaluator shall perform the Algorithm Diffie-Hellman Key Agreement, the evaluator shall perform the Algorithm Functional Test and Validation Test using the following input Functional Test and Validation Test using the following input parameters: parameters: - Elliptic Curve \[P-256, P-384, P-521\] - Elliptic Curve \[P-256, P-384, P-521\] \ \ ***Algorithm Functional Test***\ ***Algorithm Functional Test***\ For each supported Elliptic Curve the evaluator shall generate 10 test For each supported Elliptic Curve the evaluator shall generate 10 test cases by generating the initiator and responder secret keys using random cases by generating the initiator and responder secret keys using random data, calculating the responder public key, and creating the shared data, calculating the responder public key, and creating the shared secret. The resulting shared secrets shall be compared with those secret. The resulting shared secrets shall be compared with those generated by a known-good implementation using the same inputs. | generated by a known-good implementation using the same inputs.\ < \ < ***Validation Test***\ ***Validation Test***\ For each supported Elliptic Curve the evaluator shall generate 15 Diffie For each supported Elliptic Curve the evaluator shall generate 15 Diffie Hellman initiator/responder key pairs using the key generation function Hellman initiator/responder key pairs using the key generation function of a known-good implementation. For each set of key pairs, the evaluator of a known-good implementation. For each set of key pairs, the evaluator shall modify five initiator private key values. The remaining key values shall modify five initiator private key values. The remaining key values are left unchanged (i.e., correct). To determine correctness, the are left unchanged (i.e., correct). To determine correctness, the evaluator shall confirm that the 15 shared secrets correspond as evaluator shall confirm that the 15 shared secrets correspond as expected for the modified and unmodified values. expected for the modified and unmodified values. ::: ::: ::: ::: ::: ::: ::: ::: ::: ::: ### A.3.3 Class FDP: User Data Protection {#-feat-based .indexable level="3"} | ### A.3.3 Class FDP: User Data Protection {#fdp-feat-based .indexable level="3"} ::: {#FDP_UPC_EXT.1/BLUETOOTH .comp} ::: {#FDP_UPC_EXT.1/BLUETOOTH .comp} #### FDP_UPC_EXT.1/BLUETOOTH Inter-TSF User Data Transfer Protection (Bluetooth) #### FDP_UPC_EXT.1/BLUETOOTH Inter-TSF User Data Transfer Protection (Bluetooth) ::: statustag ::: statustag ***This component must be included in the [ST](#abbr_ST) if the ***This component must be included in the [ST](#abbr_ST) if the [TOE](#abbr_TOE) implements any of the following features:***\ [TOE](#abbr_TOE) implements any of the following features:***\ - ***[Bluetooth](#bluetooth)*** - ***[Bluetooth](#bluetooth)*** ::: ::: ::: element ::: element ::: {#FDP_UPC_EXT.1.1/BLUETOOTH .reqid} ::: {#FDP_UPC_EXT.1.1/BLUETOOTH .reqid} [FDP_UPC_EXT.1.1/BLUETOOTH](#FDP_UPC_EXT.1.1/BLUETOOTH){.abbr} [FDP_UPC_EXT.1.1/BLUETOOTH](#FDP_UPC_EXT.1.1/BLUETOOTH){.abbr} ::: ::: ::: reqdesc ::: reqdesc The [TSF](#abbr_TSF) shall provide a means for non-TSF applications The [TSF](#abbr_TSF) shall provide a means for non-TSF applications executing on the [TOE](#abbr_TOE) to use Bluetooth as defined in \[*the executing on the [TOE](#abbr_TOE) to use Bluetooth as defined in \[*the [PP-Module for Bluetooth, version | [PP-Module for Bluetooth, version 2.0]()*\] to provide a protected 2.0](https://www.niap-ccevs.org/protectionprofiles/425)*\] to provide a | communication channel between the non-TSF application and another IT protected communication channel between the non-TSF application and | product that is logically distinct from other communication channels, another IT product that is logically distinct from other communication | provides assured identification of its end points, protects channel data channels, provides assured identification of its end points, protects | from disclosure, and detects modification of the channel data. channel data from disclosure, and detects modification of the channel < data. < ::: appnote ::: appnote [Application Note: ]{.note-header}[ ]{.note} [Application Note: ]{.note-header}[ ]{.note} If the [TOE](#abbr_TOE) implements Bluetooth, this requirement must be If the [TOE](#abbr_TOE) implements Bluetooth, this requirement must be included in the [ST](#abbr_ST). The intent of this requirement is that included in the [ST](#abbr_ST). The intent of this requirement is that Bluetooth is available for use by user applications running on the Bluetooth is available for use by user applications running on the device for use in connecting to distant-end services that are not device for use in connecting to distant-end services that are not necessarily part of the enterprise infrastructure. The [ST](#abbr_ST) necessarily part of the enterprise infrastructure. The [ST](#abbr_ST) author must list which trusted channel protocols are implemented by the author must list which trusted channel protocols are implemented by the Mobile Device for use by non-TSF apps. Mobile Device for use by non-TSF apps. The [TSF](#abbr_TSF) must be validated against requirements from the The [TSF](#abbr_TSF) must be validated against requirements from the [PP-Module for Bluetooth, version | [PP-Module for Bluetooth, version 2.0](). It should be noted that the 2.0](https://www.niap-ccevs.org/protectionprofiles/425). It should be | [FTP_ITC_EXT.1](#FTP_ITC_EXT.1) requires that all [TSF](#abbr_TSF) noted that the [FTP_ITC_EXT.1](#FTP_ITC_EXT.1) requires that all | communications be protected using the protocols indicated in that [TSF](#abbr_TSF) communications be protected using the protocols | requirement, so the protocols required by this component ride \"on top indicated in that requirement, so the protocols required by this | of\" those listed in [FTP_ITC_EXT.1](#FTP_ITC_EXT.1). component ride \"on top of\" those listed in < [FTP_ITC_EXT.1](#FTP_ITC_EXT.1). < ::: ::: ::: ::: ::: ::: ::: element ::: element ::: {#FDP_UPC_EXT.1.2/BLUETOOTH .reqid} ::: {#FDP_UPC_EXT.1.2/BLUETOOTH .reqid} [FDP_UPC_EXT.1.2/BLUETOOTH](#FDP_UPC_EXT.1.2/BLUETOOTH){.abbr} [FDP_UPC_EXT.1.2/BLUETOOTH](#FDP_UPC_EXT.1.2/BLUETOOTH){.abbr} ::: ::: ::: reqdesc ::: reqdesc The [TSF](#abbr_TSF) shall permit the non-TSF applications to initiate The [TSF](#abbr_TSF) shall permit the non-TSF applications to initiate communication via the trusted channel. communication via the trusted channel. ::: ::: ::: ::: ::: {.activity_pane .hide} ::: {.activity_pane .hide} ::: activity_pane_header ::: activity_pane_header [[ Evaluation Activities [[ Evaluation Activities ]{.activity_pane_label}[]{.toggler}](#){onclick="toggle(this);return false;"} ]{.activity_pane_label}[]{.toggler}](#){onclick="toggle(this);return false;"} ::: ::: ::: activity_pane_body ::: activity_pane_body ::: component-activity-header ::: component-activity-header [FDP_UPC_EXT.1/BLUETOOTH](#FDP_UPC_EXT.1/BLUETOOTH) [FDP_UPC_EXT.1/BLUETOOTH](#FDP_UPC_EXT.1/BLUETOOTH) ::: ::: ::: eacategory ::: eacategory [TSS](#abbr_TSS) [TSS](#abbr_TSS) ::: ::: ::: ea ::: ea ::: ea ::: ea The evaluator shall verify that the [API](#abbr_API) documentation The evaluator shall verify that the [API](#abbr_API) documentation provided in the [TSS](#abbr_TSS) (or other documentation) includes the provided in the [TSS](#abbr_TSS) (or other documentation) includes the security functions (protection channel) described in these requirements, security functions (protection channel) described in these requirements, and verify that the APIs implemented to support this requirement include and verify that the APIs implemented to support this requirement include the appropriate settings/parameters so that the application can both the appropriate settings/parameters so that the application can both provide and obtain the information needed to assure mutual provide and obtain the information needed to assure mutual identification of the endpoints of the communication as required by this identification of the endpoints of the communication as required by this component. component. The evaluator shall examine the [TSS](#abbr_TSS) to determine that it The evaluator shall examine the [TSS](#abbr_TSS) to determine that it describes that all protocols listed in the [TSS](#abbr_TSS) are describes that all protocols listed in the [TSS](#abbr_TSS) are specified and included in the requirements in the [ST](#abbr_ST).\ specified and included in the requirements in the [ST](#abbr_ST).\ \ \ ::: ::: ::: ::: ::: eacategory ::: eacategory Guidance Guidance ::: ::: ::: ea ::: ea ::: ea ::: ea The evaluator shall confirm that the operational guidance contains The evaluator shall confirm that the operational guidance contains instructions necessary for configuring the protocols selected for use by instructions necessary for configuring the protocols selected for use by the applications.\ the applications.\ \ \ ::: ::: ::: ::: ::: eacategory ::: eacategory Tests Tests ::: ::: ::: ea ::: ea ::: ea ::: ea **Evaluation Activity Note:** The following test requires the developer **Evaluation Activity Note:** The following test requires the developer to provide access to a test platform that provides the evaluator with to provide access to a test platform that provides the evaluator with tools that are typically not found on consumer Mobile Device products.\ tools that are typically not found on consumer Mobile Device products.\ \ \ The evaluator shall perform the following tests: []{.testlist-} The evaluator shall perform the following tests: []{.testlist-} - [Test FDP_UPC_EXT.1/BLUETOOTH:1](#_t_31){#_t_31 .defined}: The - [Test FDP_UPC_EXT.1/BLUETOOTH:1](#_t_31){#_t_31 .defined}: The evaluator shall write, or the developer shall provide access to, an evaluator shall write, or the developer shall provide access to, an application that requests protected channel services by the application that requests protected channel services by the [TSF](#abbr_TSF). The evaluator shall verify that the results from [TSF](#abbr_TSF). The evaluator shall verify that the results from the protected channel match the expected results according to the the protected channel match the expected results according to the [API](#abbr_API) documentation. This application may be used to [API](#abbr_API) documentation. This application may be used to assist in verifying the protected channel Evaluation Activities for assist in verifying the protected channel Evaluation Activities for the protocol requirements. the protocol requirements. - [Test FDP_UPC_EXT.1/BLUETOOTH:2](#_t_32){#_t_32 .defined}: The - [Test FDP_UPC_EXT.1/BLUETOOTH:2](#_t_32){#_t_32 .defined}: The evaluator shall ensure that the application is able to initiate evaluator shall ensure that the application is able to initiate communications with an external IT entity using each protocol communications with an external IT entity using each protocol specified in the requirement, setting up the connections as specified in the requirement, setting up the connections as described in the operational guidance and ensuring that described in the operational guidance and ensuring that communication is successful. communication is successful. - [Test FDP_UPC_EXT.1/BLUETOOTH:3](#_t_33){#_t_33 .defined}: The - [Test FDP_UPC_EXT.1/BLUETOOTH:3](#_t_33){#_t_33 .defined}: The evaluator shall ensure, for each communication channel with an evaluator shall ensure, for each communication channel with an authorized IT entity, the channel data are not sent in plaintext. authorized IT entity, the channel data are not sent in plaintext. ::: ::: ::: ::: ::: ::: ::: ::: ::: ::: # Appendix B - Selection-based Requirements {#sel-based-reqs .indexable level="A"} # Appendix B - Selection-based Requirements {#sel-based-reqs .indexable level="A"} [ ]{.description} [ ]{.description} As indicated in the introduction to this [PP](#abbr_PP), the baseline As indicated in the introduction to this [PP](#abbr_PP), the baseline requirements (those that must be performed by the [TOE](#abbr_TOE) or requirements (those that must be performed by the [TOE](#abbr_TOE) or its underlying platform) are contained in the body of this its underlying platform) are contained in the body of this [PP](#abbr_PP). There are additional requirements based on selections in [PP](#abbr_PP). There are additional requirements based on selections in the body of the [PP](#abbr_PP): if certain selections are made, then the body of the [PP](#abbr_PP): if certain selections are made, then additional requirements below must be included. additional requirements below must be included. ## B.1 Auditable Events for Selection-based Requirements {#sel-based-reqs-audit .inde ## B.1 Auditable Events for Selection-based Requirements {#sel-based-reqs-audit .inde Requirement Auditable Events Additional Audit Rec Requirement Auditable Events Additional Audit Rec ------------------------------------------- ------------------ -------------------- ------------------------------------------- ------------------ -------------------- [FCS_CKM_EXT.9](#FCS_CKM_EXT.9) [FCS_CKM_EXT.9](#FCS_CKM_EXT.9) No events specified N/A No events specified N/A [FCS_COP.1/KeyEncap](#FCS_COP.1/KeyEncap) [FCS_COP.1/KeyEncap](#FCS_COP.1/KeyEncap) No events specified N/A No events specified N/A [FCS_COP.1/XOF](#FCS_COP.1/XOF) [FCS_COP.1/XOF](#FCS_COP.1/XOF) No events specified N/A No events specified N/A [FCS_RBG.2](#FCS_RBG.2) [FCS_RBG.2](#FCS_RBG.2) No events specified N/A No events specified N/A [FCS_RBG.3](#FCS_RBG.3) [FCS_RBG.3](#FCS_RBG.3) No events specified N/A No events specified N/A [FCS_RBG.4](#FCS_RBG.4) [FCS_RBG.4](#FCS_RBG.4) No events specified N/A No events specified N/A [FCS_RBG.5](#FCS_RBG.5) [FCS_RBG.5](#FCS_RBG.5) No events specified N/A No events specified N/A [FDP_ACF_EXT.2](#FDP_ACF_EXT.2) [FDP_ACF_EXT.2](#FDP_ACF_EXT.2) No events specified N/A No events specified N/A [FPT_TST_EXT.3](#FPT_TST_EXT.3) [FPT_TST_EXT.3](#FPT_TST_EXT.3) No events specified N/A No events specified N/A [FPT_TUD_EXT.4](#FPT_TUD_EXT.4) [FPT_TUD_EXT.4](#FPT_TUD_EXT.4) No events specified N/A No events specified N/A : [Table [25]{.counter}]{#t-audit-sel-based .ctr : [Table [25]{.counter}]{#t-audit-sel-based .ctr myid="t-audit-sel-based" counter-type="ct-Table"}: Auditable Events myid="t-audit-sel-based" counter-type="ct-Table"}: Auditable Events for Selection-based Requirements for Selection-based Requirements ## B.2 Class FCS: Cryptographic Support {#-sel-based .indexable level="2"} | ## B.2 Class FCS: Cryptographic Support {#fcs-sel-based .indexable level="2"} ::: {#FCS_CKM_EXT.9 .comp} ::: {#FCS_CKM_EXT.9 .comp} #### FCS_CKM_EXT.9 Hardware Key Confidentiality #### FCS_CKM_EXT.9 Hardware Key Confidentiality ::: statustag ::: statustag ***The inclusion of this selection-based component depends upon ***The inclusion of this selection-based component depends upon selection in:*** selection in:*** - ***[FCS_CKM_EXT.1.1](#FCS_CKM_EXT.1.1)*** - ***[FCS_CKM_EXT.1.1](#FCS_CKM_EXT.1.1)*** ::: ::: ::: element ::: element ::: {#FCS_CKM_EXT.9.1 .reqid} ::: {#FCS_CKM_EXT.9.1 .reqid} [FCS_CKM_EXT.9.1](#FCS_CKM_EXT.9.1){.abbr} [FCS_CKM_EXT.9.1](#FCS_CKM_EXT.9.1){.abbr} ::: ::: ::: reqdesc ::: reqdesc A \[*[REK](#abbr_REK)*\] shall not be able to be read from or exported A \[*[REK](#abbr_REK)*\] shall not be able to be read from or exported from hardware. from hardware. ::: appnote ::: appnote [Application Note: ]{.note-header}[]{.note} | [Application Note: ]{.note-header}[ ]{.note} This [SFR](#abbr_SFR) is claimed if \"mutable hardware\" is selected in This [SFR](#abbr_SFR) is claimed if \"mutable hardware\" is selected in [FCS_CKM_EXT.1.1](#FCS_CKM_EXT.1.1). It is not claimed if \"immutable [FCS_CKM_EXT.1.1](#FCS_CKM_EXT.1.1). It is not claimed if \"immutable hardware\" is selected because it is implicitly met in that case. hardware\" is selected because it is implicitly met in that case. The lack of a public or documented [API](#abbr_API) for performing this The lack of a public or documented [API](#abbr_API) for performing this function is not sufficient to meet the requirement if a private or function is not sufficient to meet the requirement if a private or undocumented function exists to perform it. undocumented function exists to perform it. ::: ::: ::: ::: ::: ::: ::: {.activity_pane .hide} ::: {.activity_pane .hide} ::: activity_pane_header ::: activity_pane_header [[ Evaluation Activities [[ Evaluation Activities ]{.activity_pane_label}[]{.toggler}](#){onclick="toggle(this);return false;"} ]{.activity_pane_label}[]{.toggler}](#){onclick="toggle(this);return false;"} ::: ::: ::: activity_pane_body ::: activity_pane_body ::: component-activity-header ::: component-activity-header [FCS_CKM_EXT.9](#FCS_CKM_EXT.9) [FCS_CKM_EXT.9](#FCS_CKM_EXT.9) ::: ::: ::: eacategory ::: eacategory [TSS](#abbr_TSS) [TSS](#abbr_TSS) ::: ::: ::: ea ::: ea ::: ea ::: ea The evaluation activity for this component is performed in conjunction The evaluation activity for this component is performed in conjunction with the evaluation activity for [FCS_CKM_EXT.1](#FCS_CKM_EXT.1). with the evaluation activity for [FCS_CKM_EXT.1](#FCS_CKM_EXT.1). ::: ::: ::: ::: ::: eacategory ::: eacategory Guidance Guidance ::: ::: ::: ea ::: ea There are no additional Guidance evaluation activities for this There are no additional Guidance evaluation activities for this component.\ component.\ ::: ::: ::: eacategory ::: eacategory Tests Tests ::: ::: ::: ea ::: ea There are no test activities for this component.\ There are no test activities for this component.\ ::: ::: ::: ::: ::: ::: ::: ::: ::: {#FCS_COP.1/KeyEncap .comp} ::: {#FCS_COP.1/KeyEncap .comp} #### FCS_COP.1/KeyEncap Cryptographic Operation - Key Encapsulation #### FCS_COP.1/KeyEncap Cryptographic Operation - Key Encapsulation ::: statustag ::: statustag ***The inclusion of this selection-based component depends upon ***The inclusion of this selection-based component depends upon selection in:*** selection in:*** - ***[FCS_CKM.2.1](#FCS_CKM.2.1)*** - ***[FCS_CKM.2.1](#FCS_CKM.2.1)*** ::: ::: ::: element ::: element ::: {#FCS_COP.1.1/KeyEncap .reqid} ::: {#FCS_COP.1.1/KeyEncap .reqid} [FCS_COP.1.1/KeyEncap](#FCS_COP.1.1/KeyEncap){.abbr} [FCS_COP.1.1/KeyEncap](#FCS_COP.1.1/KeyEncap){.abbr} ::: ::: ::: reqdesc ::: reqdesc The [TSF](#abbr_TSF) shall perform \[*key encapsulation*\] in accordance The [TSF](#abbr_TSF) shall perform \[*key encapsulation*\] in accordance with a specified cryptographic algorithm \[**selection**: [Cryptographic with a specified cryptographic algorithm \[**selection**: [Cryptographic Algorithm]{.selectable-content}\] and cryptographic key sizes Algorithm]{.selectable-content}\] and cryptographic key sizes \[**selection**: [Cryptographic Key Sizes]{.selectable-content}\] that \[**selection**: [Cryptographic Key Sizes]{.selectable-content}\] that meet the following: \[**selection**: [List of meet the following: \[**selection**: [List of Standards]{.selectable-content}\] . Standards]{.selectable-content}\] . [Table [Table [26]{.counter}](#fcs-cop-keyencap-sels){.fcs-cop-keyencap-sels-ref [26]{.counter}](#fcs-cop-keyencap-sels){.fcs-cop-keyencap-sels-ref onclick="showTarget('fcs-cop-keyencap-sels')"} provides the allowable onclick="showTarget('fcs-cop-keyencap-sels')"} provides the allowable choices for completion of the selection operations of choices for completion of the selection operations of [FCS_COP.1/KeyEncap](#FCS_COP.1/KeyEncap). [FCS_COP.1/KeyEncap](#FCS_COP.1/KeyEncap). Identifier Cryptographic Algorithm Cryptographic Key Sizes List of Standa Identifier Cryptographic Algorithm Cryptographic Key Sizes List of Standa ------------ ------------------------- ----------------------------- -------------- ------------ ------------------------- ----------------------------- -------------- ML-KEM ML-KEM Parameter set = ML-KEM-1024 [NIST](#abbr_N ML-KEM ML-KEM Parameter set = ML-KEM-1024 [NIST](#abbr_N : [Table [26]{.counter}]{#fcs-cop-keyencap-sels .ctr : [Table [26]{.counter}]{#fcs-cop-keyencap-sels .ctr myid="fcs-cop-keyencap-sels" counter-type="ct-Table"}: Allowable myid="fcs-cop-keyencap-sels" counter-type="ct-Table"}: Allowable choices for [FCS_COP.1/KeyEncap](#FCS_COP.1/KeyEncap) choices for [FCS_COP.1/KeyEncap](#FCS_COP.1/KeyEncap) ::: appnote ::: appnote [Application Note: ]{.note-header}[ This [SFR](#abbr_SFR) is claimed | [Application Note: ]{.note-header}[This [SFR](#abbr_SFR) is claimed when when \"key encapsulation\" is selected in [FCS_CKM.2.1](#FCS_CKM.2.1). | \"key encapsulation\" is selected in [FCS_CKM.2.1](#FCS_CKM.2.1). For For this [PP](#abbr_PP), the only anticipated use of key encapsulation | this [PP](#abbr_PP), the only anticipated use of key encapsulation is is the use of ML-KEM as part of key establishment for trusted | the use of ML-KEM as part of key establishment for trusted communications. ]{.note} | communications.]{.note} ::: ::: ::: ::: ::: ::: ::: {.activity_pane .hide} ::: {.activity_pane .hide} ::: activity_pane_header ::: activity_pane_header [[ Evaluation Activities [[ Evaluation Activities ]{.activity_pane_label}[]{.toggler}](#){onclick="toggle(this);return false;"} ]{.activity_pane_label}[]{.toggler}](#){onclick="toggle(this);return false;"} ::: ::: ::: activity_pane_body ::: activity_pane_body ::: component-activity-header ::: component-activity-header [FCS_COP.1/KeyEncap](#FCS_COP.1/KeyEncap) [FCS_COP.1/KeyEncap](#FCS_COP.1/KeyEncap) ::: ::: ::: eacategory ::: eacategory [TSS](#abbr_TSS) [TSS](#abbr_TSS) ::: ::: ::: ea ::: ea ::: ea ::: ea The evaluator shall ensure that the [TSS](#abbr_TSS) documents that the The evaluator shall ensure that the [TSS](#abbr_TSS) documents that the selection of the key size is sufficient for the security strength of the selection of the key size is sufficient for the security strength of the key encapsulated. key encapsulated. The evaluator shall examine the [TSS](#abbr_TSS) to verify that any The evaluator shall examine the [TSS](#abbr_TSS) to verify that any one-time values such as nonces or masks are constructed and used in one-time values such as nonces or masks are constructed and used in accordance with the relevant standards. accordance with the relevant standards. ::: ::: ::: ::: ::: eacategory ::: eacategory Guidance Guidance ::: ::: ::: ea ::: ea There are no additional Guidance evaluation activities for this There are no additional Guidance evaluation activities for this component.\ component.\ ::: ::: ::: eacategory ::: eacategory Tests Tests ::: ::: ::: ea ::: ea ::: ea ::: ea The following test may require the developer to provide access to a test The following test may require the developer to provide access to a test platform that provides the evaluator with tools that are typically not platform that provides the evaluator with tools that are typically not found on factory products. | found on factory products. The following tests are conditional based | upon the selections made in the [SFR](#abbr_SFR). The evaluator shall The following tests are conditional based upon the selections made in | perform the following test or witness respective tests executed by the the [SFR](#abbr_SFR). The evaluator shall perform the following test or | developer. The tests must be executed on a platform that is as close as witness respective tests executed by the developer. The tests must be | practically possible to the operational platform (but which may be executed on a platform that is as close as practically possible to the | instrumented in terms of, for example, use of a debug mode). Where the operational platform (but which may be instrumented in terms of, for | test is not carried out on the [TOE](#abbr_TOE) itself, the test example, use of a debug mode). Where the test is not carried out on the | platform shall be identified and the differences between test [TOE](#abbr_TOE) itself, the test platform shall be identified and the | environment and [TOE](#abbr_TOE) execution environment shall be differences between test environment and [TOE](#abbr_TOE) execution | described.\ environment shall be described. < < \ < **ML-KEM Key Encapsulation** **ML-KEM Key Encapsulation** ------------ ------------------------- ----------------------------- -------------- ------------ ------------------------- ----------------------------- -------------- Identifier Cryptographic Algorithm Cryptographic Key Sizes List of Standa Identifier Cryptographic Algorithm Cryptographic Key Sizes List of Standa ML-KEM ML-KEM Parameter set = ML-KEM-1024 [NIST](#abbr_N ML-KEM ML-KEM Parameter set = ML-KEM-1024 [NIST](#abbr_N ------------ ------------------------- ----------------------------- -------------- ------------ ------------------------- ----------------------------- -------------- To test the [TOE](#abbr_TOE)'s implementation of ML-KEM key To test the [TOE](#abbr_TOE)'s implementation of ML-KEM key encapsulation/decapsulation, the evaluator shall perform the encapsulation/decapsulation, the evaluator shall perform the Encapsulation Test and the Decapsulation Test using the following input Encapsulation Test and the Decapsulation Test using the following input parameters: parameters: - Encapsulation Parameters: - Encapsulation Parameters: - Parameter set \[ML-KEM-1024\] - Parameter set \[ML-KEM-1024\] - Previously generated encapsulation key (*ek*) - Previously generated encapsulation key (*ek*) - Random value (*m*) \[32 bytes\] - Random value (*m*) \[32 bytes\] - Decapsulation Parameters: - Decapsulation Parameters: - Parameter set \[ML-KEM-1024\] - Parameter set \[ML-KEM-1024\] - Previously generated decapsulation key (*dk*) - Previously generated decapsulation key (*dk*) - Previously generated ciphertext (*c*) \[32 bytes\] - Previously generated ciphertext (*c*) \[32 bytes\] \ \ **Encapsulation Test** | **Encapsulation Test** For each supported parameter set the evaluator | shall generate 25 test cases consisting of an encapsulation key ek and For each supported parameter set the evaluator shall generate 25 test | random value m. For each test case the valuator shall require the cases consisting of an encapsulation key ek and random value m. For each | implementation under test to generate the corresponding shared secret k test case the valuator shall require the implementation under test to | and ciphertext c. To determine correctness, the evaluator shall compare generate the corresponding shared secret k and ciphertext c. To | the resulting values with those generated using a known-good determine correctness, the evaluator shall compare the resulting values | implementation using the same inputs.\ with those generated using a known-good implementation using the same | **Encapsulation Key Check (if supported)** The evaluator shall generate inputs. | 10 encapsulation keys such that: < \ < **Encapsulation Key Check (if supported)** < < The evaluator shall generate 10 encapsulation keys such that: < - Five of the encapsulation keys are valid, and - Five of the encapsulation keys are valid, and - Five of the encapsulation keys are modified such that a value in the - Five of the encapsulation keys are modified such that a value in the noisy linear system is encoded into the key as a value greater than noisy linear system is encoded into the key as a value greater than Q. Q. The evaluator shall invoke the [TOE](#abbr_TOE)'s Encapsulation Key The evaluator shall invoke the [TOE](#abbr_TOE)'s Encapsulation Key Check functionality to determine the validity of the 10 keys. The Check functionality to determine the validity of the 10 keys. The unmodified keys should be determined valid, and the modified keys should unmodified keys should be determined valid, and the modified keys should be determined invalid. | be determined invalid.\ | **Decapsulation Key Check (if supported)** The evaluator shall generate \ | 10 decapsulation keys such that: **Decapsulation Key Check (if supported)** < < The evaluator shall generate 10 decapsulation keys such that: < - Five of the decapsulation keys are valid, and - Five of the decapsulation keys are valid, and - Five of the decapsulation keys are modified such that the - Five of the decapsulation keys are modified such that the concatenated values ek\|\|H(ek) will no longer match by modifying concatenated values ek\|\|H(ek) will no longer match by modifying H(ek) to be a different value. H(ek) to be a different value. The evaluator shall invoke the [TOE](#abbr_TOE)'s Decapsulation Key The evaluator shall invoke the [TOE](#abbr_TOE)'s Decapsulation Key Check functionality to determine the validity of the 10 keys. The Check functionality to determine the validity of the 10 keys. The unmodified keys should be determined valid, and the modified keys should unmodified keys should be determined valid, and the modified keys should be determined invalid. | be determined invalid.\ | **Decapsulation Test** For each supported parameter set the evaluator \ | shall use a single previously generated decapsulation key *dk* and **Decapsulation Test** | generate 10 test cases consisting of valid and invalid ciphertexts c. | For each test case the evaluator shall require the implementation under For each supported parameter set the evaluator shall use a single | test to generate the corresponding shared secret *k* whether or not the previously generated decapsulation key *dk* and generate 10 test cases | ciphertext is valid. To determine correctness, the evaluator shall consisting of valid and invalid ciphertexts c. For each test case the | compare the resulting values with those generated using a known-good evaluator shall require the implementation under test to generate the | implementation using the same inputs. corresponding shared secret *k* whether or not the ciphertext is valid. < To determine correctness, the evaluator shall compare the resulting < values with those generated using a known-good implementation using the < same inputs. < ::: ::: ::: ::: ::: ::: ::: ::: ::: ::: ::: {#FCS_COP.1/XOF .comp} ::: {#FCS_COP.1/XOF .comp} #### FCS_COP.1/XOF Cryptographic Operation - Extendable-Output Function #### FCS_COP.1/XOF Cryptographic Operation - Extendable-Output Function ::: statustag ::: statustag ***The inclusion of this selection-based component depends upon ***The inclusion of this selection-based component depends upon selection in:*** selection in:*** - ***[FCS_CKM.1.1/AKG](#FCS_CKM.1.1/AKG),*** - ***[FCS_CKM.1.1/AKG](#FCS_CKM.1.1/AKG),*** - ***[FCS_COP.1.1/SigVer](#FCS_COP.1.1/SigVer)*** - ***[FCS_COP.1.1/SigVer](#FCS_COP.1.1/SigVer)*** ::: ::: ::: element ::: element ::: {#FCS_COP.1.1/XOF .reqid} ::: {#FCS_COP.1.1/XOF .reqid} [FCS_COP.1.1/XOF](#FCS_COP.1.1/XOF){.abbr} [FCS_COP.1.1/XOF](#FCS_COP.1.1/XOF){.abbr} ::: ::: ::: reqdesc ::: reqdesc The [TSF](#abbr_TSF) shall perform \[*extendable-output function*\] in The [TSF](#abbr_TSF) shall perform \[*extendable-output function*\] in accordance with a specified cryptographic algorithm \[**selection**: accordance with a specified cryptographic algorithm \[**selection**: [Cryptographic Algorithm]{.selectable-content}\] and parameters [Cryptographic Algorithm]{.selectable-content}\] and parameters \[**selection**: [Parameters]{.selectable-content}\] that meet the \[**selection**: [Parameters]{.selectable-content}\] that meet the following: \[**selection**: [List of Standards]{.selectable-content}\] . following: \[**selection**: [List of Standards]{.selectable-content}\] . [Table [27]{.counter}](#fcs-cop-xof-sels){.fcs-cop-xof-sels-ref [Table [27]{.counter}](#fcs-cop-xof-sels){.fcs-cop-xof-sels-ref onclick="showTarget('fcs-cop-xof-sels')"} provides the allowable choices onclick="showTarget('fcs-cop-xof-sels')"} provides the allowable choices for completion of the selection operations of for completion of the selection operations of [FCS_COP.1/XOF](#FCS_COP.1/XOF). [FCS_COP.1/XOF](#FCS_COP.1/XOF). Cryptographic Algorithm Parameters List of Standards Cryptographic Algorithm Parameters List of Standards ------------------------- -------------------------- ------------------------------ ------------------------- -------------------------- ------------------------------ SHAKE Functions = \[SHAKE256\] [NIST](#abbr_NIST) [FIPS](#abb SHAKE Functions = \[SHAKE256\] [NIST](#abbr_NIST) [FIPS](#abb : [Table [27]{.counter}]{#fcs-cop-xof-sels .ctr : [Table [27]{.counter}]{#fcs-cop-xof-sels .ctr myid="fcs-cop-xof-sels" counter-type="ct-Table"}: Allowable choices myid="fcs-cop-xof-sels" counter-type="ct-Table"}: Allowable choices for [FCS_COP.1/XOF](#FCS_COP.1/XOF) for [FCS_COP.1/XOF](#FCS_COP.1/XOF) ::: appnote ::: appnote [Application Note: ]{.note-header}[ In accordance with | [Application Note: ]{.note-header}[In accordance with [CNSA](#abbr_CNSA) [CNSA](#abbr_CNSA) 2.0, SHAKE is permitted to be used only as a | 2.0, SHAKE is permitted to be used only as a component of LMS or XMSS. component of LMS or XMSS. Therefore this component is claimed only if | Therefore this component is claimed only if LMS or XMSS is claimed in LMS or XMSS is claimed in [FCS_COP.1/SigVer](#FCS_COP.1/SigVer). | [FCS_COP.1/SigVer](#FCS_COP.1/SigVer).]{.note} ]{.note} < ::: ::: ::: ::: ::: ::: ::: {.activity_pane .hide} ::: {.activity_pane .hide} ::: activity_pane_header ::: activity_pane_header [[ Evaluation Activities [[ Evaluation Activities ]{.activity_pane_label}[]{.toggler}](#){onclick="toggle(this);return false;"} ]{.activity_pane_label}[]{.toggler}](#){onclick="toggle(this);return false;"} ::: ::: ::: activity_pane_body ::: activity_pane_body ::: component-activity-header ::: component-activity-header [FCS_COP.1/XOF](#FCS_COP.1/XOF) [FCS_COP.1/XOF](#FCS_COP.1/XOF) ::: ::: ::: eacategory ::: eacategory [TSS](#abbr_TSS) [TSS](#abbr_TSS) ::: ::: ::: ea ::: ea There are no additional [TSS](#abbr_TSS) evaluation activities for this There are no additional [TSS](#abbr_TSS) evaluation activities for this component.\ component.\ ::: ::: ::: eacategory ::: eacategory Guidance Guidance ::: ::: ::: ea ::: ea There are no additional Guidance evaluation activities for this There are no additional Guidance evaluation activities for this component.\ component.\ ::: ::: ::: eacategory ::: eacategory Tests Tests ::: ::: ::: ea ::: ea ::: ea ::: ea The following tests are conditional based on the selections made in the The following tests are conditional based on the selections made in the [SFR](#abbr_SFR). The evaluator shall perform the following tests or [SFR](#abbr_SFR). The evaluator shall perform the following tests or witness respective tests executed by the developer. The tests must be witness respective tests executed by the developer. The tests must be executed on a platform that is as close as practically possible to the executed on a platform that is as close as practically possible to the operational platform (but which may be instrumented in terms of, for operational platform (but which may be instrumented in terms of, for example, use of a debug mode). Where the test is not carried out on the example, use of a debug mode). Where the test is not carried out on the [TOE](#abbr_TOE) itself, the test platform shall be identified and the [TOE](#abbr_TOE) itself, the test platform shall be identified and the differences between test environment and [TOE](#abbr_TOE) execution differences between test environment and [TOE](#abbr_TOE) execution environment shall be described. | environment shall be described.\ < \ < **SHAKE** **SHAKE** ------------------------- ------------------------- ------------------------------- ------------------------- ------------------------- ------------------------------- Cryptographic Algorithm Parameters List of Standards Cryptographic Algorithm Parameters List of Standards SHAKE Function = \[SHAKE256\] [NIST](#abbr_NIST) [FIPS](#abbr SHAKE Function = \[SHAKE256\] [NIST](#abbr_NIST) [FIPS](#abbr ------------------------- ------------------------- ------------------------------- ------------------------- ------------------------- ------------------------------- To test the [TOE](#abbr_TOE)'s implementation of the SHAKE Extendable To test the [TOE](#abbr_TOE)'s implementation of the SHAKE Extendable Output Function the evaluator shall perform the Algorithm Functional Output Function the evaluator shall perform the Algorithm Functional Test, Monte Carlo Test, and Variable Output Test using the following Test, Monte Carlo Test, and Variable Output Test using the following input parameters: input parameters: - Function \[SHAKE256\] - Function \[SHAKE256\] - Output length \[16-65536\] bits - Output length \[16-65536\] bits \ \ ***Algorithm Functional Test*** | ***Algorithm Functional Test*** For each supported function, generate | test cases consisting of random data for every message length from 0 For each supported function, generate test cases consisting of random | bits (if supported) to *rate* -1 bits, where *rate* equals 1088. data for every message length from 0 bits (if supported) to *rate*-1 < bits, where *rate* equals < < 1088\. < < Additionally, generate tests cases of random data for messages of every Additionally, generate tests cases of random data for messages of every multiple of (rate+1) bits starting at length rate, and continuing until multiple of (rate+1) bits starting at length rate, and continuing until 65535 is exceeded. | 65535 is exceeded.\ | ***Monte Carlo Test*** The Monte Carlo test takes in a single 128-bit \ | message (SEED) and desired output length in bits, and runs 100 ***Monte Carlo Test*** | iterations of the chained computation. MaxOutBytes and MinOutBytes are | the largest and smallest supported input and output sizes in bytes, The Monte Carlo test takes in a single 128-bit message (SEED) and | respectively. desired output length in bits, and runs 100 iterations of the chained < computation. MaxOutBytes and MinOutBytes are the largest and smallest < supported input and output sizes in bytes, respectively. < Range = maxOutBytes - minOutBytes + 1 Range = maxOutBytes - minOutBytes + 1 OutputLen = maxOutBytes OutputLen = maxOutBytes For j = 0 to 99 For j = 0 to 99 MD[0] = SEED MD[0] = SEED For i = 1 to 1000 For i = 1 to 1000 MSG[i] = 128 leftmost bits of MD[i-1] MSG[i] = 128 leftmost bits of MD[i-1] if (MSG[i] < 128 bits) if (MSG[i] < 128 bits) Append 0 bits on rightmost side of MSG[i] til MSG[i] is 128 bit Append 0 bits on rightmost side of MSG[i] til MSG[i] is 128 bit MD[i] = SHAKE(MSG[i], OutputLen * 8) MD[i] = SHAKE(MSG[i], OutputLen * 8) RightmostOutputBits = 16 rightmost bits of MD[i] as an integer RightmostOutputBits = 16 rightmost bits of MD[i] as an integer OutputLen = minOutBytes + (RightmostOutputBits % Range) OutputLen = minOutBytes + (RightmostOutputBits % Range) Output MD[1000], OutputLen Output MD[1000], OutputLen SEED = MD[1000] SEED = MD[1000] \ \ ***Variable Output Test*** | ***Variable Output Test*** This test measures the ability of the | [TOE](#abbr_TOE) to generate output digests of varying sizes. The This test measures the ability of the [TOE](#abbr_TOE) to generate | evaluator shall generate 512 test cases such that the input for each output digests of varying sizes. < < The evaluator shall generate 512 test cases such that the input for each < test case consists of 128- bits of random data, and the output length test case consists of 128- bits of random data, and the output length includes the minimum supported value, the maximum supported value, and includes the minimum supported value, the maximum supported value, and 510 random values between the minimum and maximum digest sizes supported 510 random values between the minimum and maximum digest sizes supported by the implementation. by the implementation. ::: ::: ::: ::: ::: ::: ::: ::: ::: ::: ::: {#FCS_RBG.2 .comp} ::: {#FCS_RBG.2 .comp} #### FCS_RBG.2 Random Bit Generation (External Seeding) #### FCS_RBG.2 Random Bit Generation (External Seeding) ::: statustag ::: statustag ***The inclusion of this selection-based component depends upon ***The inclusion of this selection-based component depends upon selection in:*** selection in:*** - ***[FCS_RBG.1.2](#FCS_RBG.1.2)*** - ***[FCS_RBG.1.2](#FCS_RBG.1.2)*** ::: ::: ::: element ::: element ::: {#FCS_RBG.2.1 .reqid} ::: {#FCS_RBG.2.1 .reqid} [FCS_RBG.2.1](#FCS_RBG.2.1){.abbr} [FCS_RBG.2.1](#FCS_RBG.2.1){.abbr} ::: ::: ::: reqdesc ::: reqdesc The [TSF](#abbr_TSF) shall be able to accept a minimum input of \[*384 The [TSF](#abbr_TSF) shall be able to accept a minimum input of \[*384 bits of min-entropy*\] from a [TSF](#abbr_TSF) interface for obtaining bits of min-entropy*\] from a [TSF](#abbr_TSF) interface for obtaining entropy. entropy. ::: appnote ::: appnote [Application Note: ]{.note-header}[ ]{.note} [Application Note: ]{.note-header}[ ]{.note} This [SFR](#abbr_SFR) is claimed if \"[TSF](#abbr_TSF) interface for This [SFR](#abbr_SFR) is claimed if \"[TSF](#abbr_TSF) interface for obtaining entropy\" is selected in [FCS_RBG.1.2](#FCS_RBG.1.2), i.e., obtaining entropy\" is selected in [FCS_RBG.1.2](#FCS_RBG.1.2), i.e., the [TOE](#abbr_TOE)\'s entropy source is outside the [TOE](#abbr_TOE) the [TOE](#abbr_TOE)\'s entropy source is outside the [TOE](#abbr_TOE) boundary. In the case of a mobile device this would likely only occur boundary. In the case of a mobile device this would likely only occur when the entropy source is a Dedicated Security Component that is when the entropy source is a Dedicated Security Component that is integrated with the [TOE](#abbr_TOE). integrated with the [TOE](#abbr_TOE). If the environmental entropy source produces full entropy, the amount of If the environmental entropy source produces full entropy, the amount of entropy data collected is equal to the amount specified in the entropy data collected is equal to the amount specified in the selection. If the entropy source does not assure full entropy (i.e., the selection. If the entropy source does not assure full entropy (i.e., the ratio of min-entropy to collected data is less than 1:1), then the ratio of min-entropy to collected data is less than 1:1), then the [TSF](#abbr_TSF) must collect sufficient additional entropy data and [TSF](#abbr_TSF) must collect sufficient additional entropy data and perform a derivation function on it to reduce the collected data to a perform a derivation function on it to reduce the collected data to a seed with the claimed min-entropy. In this case, the entropy seed with the claimed min-entropy. In this case, the entropy documentation is expected to identify the min-entropy rate of the source documentation is expected to identify the min-entropy rate of the source data, how much data the [TSF](#abbr_TSF) collects, and what derivation data, how much data the [TSF](#abbr_TSF) collects, and what derivation function is performed on this collected data to ensure that it has the function is performed on this collected data to ensure that it has the claimed min-entropy. claimed min-entropy. One should not apply [NIST](#abbr_NIST) SP 800-90B (or AIS-31) One should not apply [NIST](#abbr_NIST) SP 800-90B (or AIS-31) statistical tests against an external entropy source since the statistical tests against an external entropy source since the [TSF](#abbr_TSF) is unable to enforce entropy requirements or [TSF](#abbr_TSF) is unable to enforce entropy requirements or conditioning requirements against something outside of its logical conditioning requirements against something outside of its logical boundary. However, the [TSS](#abbr_TSS) may include estimates for boundary. However, the [TSS](#abbr_TSS) may include estimates for min-entropy from external sources that contribute to the overall entropy min-entropy from external sources that contribute to the overall entropy requirements for the DRBG. requirements for the DRBG. ::: ::: ::: ::: ::: ::: ::: {.activity_pane .hide} ::: {.activity_pane .hide} ::: activity_pane_header ::: activity_pane_header [[ Evaluation Activities [[ Evaluation Activities ]{.activity_pane_label}[]{.toggler}](#){onclick="toggle(this);return false;"} ]{.activity_pane_label}[]{.toggler}](#){onclick="toggle(this);return false;"} ::: ::: ::: activity_pane_body ::: activity_pane_body ::: component-activity-header ::: component-activity-header [FCS_RBG.2](#FCS_RBG.2) [FCS_RBG.2](#FCS_RBG.2) ::: ::: The evaluator shall examine the entropy documentation required by The evaluator shall examine the entropy documentation required by [FCS_RBG.1](#FCS_RBG.1) to verify that it identifies, for each DRBG [FCS_RBG.1](#FCS_RBG.1) to verify that it identifies, for each DRBG function implemented by the [TOE](#abbr_TOE), the [TSF](#abbr_TSF) function implemented by the [TOE](#abbr_TOE), the [TSF](#abbr_TSF) external interface that is used to seed the [TOE](#abbr_TOE)\'s DRBG. external interface that is used to seed the [TOE](#abbr_TOE)\'s DRBG. The evaluator shall verify that this includes the amount of sampled data The evaluator shall verify that this includes the amount of sampled data and the min-entropy rate of the sampled data such that it can be and the min-entropy rate of the sampled data such that it can be determined that the [TSF](#abbr_TSF) can derive a seed from it that has determined that the [TSF](#abbr_TSF) can derive a seed from it that has the claimed amount of min-entropy. If the [TSF](#abbr_TSF) uses an the claimed amount of min-entropy. If the [TSF](#abbr_TSF) uses an entropy source that can be assumed to have full entropy, the seed is the entropy source that can be assumed to have full entropy, the seed is the output data from the entropy source. If the [TSF](#abbr_TSF) uses an output data from the entropy source. If the [TSF](#abbr_TSF) uses an entropy source where the min-entropy of the data is less than 1:1, the entropy source where the min-entropy of the data is less than 1:1, the evaluator shall verify that the entropy documentation identifies how evaluator shall verify that the entropy documentation identifies how large the collected data sample is and how [TSF](#abbr_TSF) derives this large the collected data sample is and how [TSF](#abbr_TSF) derives this data into a seed that has the claimed min-entropy. data into a seed that has the claimed min-entropy. ::: eacategory ::: eacategory [TSS](#abbr_TSS) [TSS](#abbr_TSS) ::: ::: ::: ea ::: ea There are no additional [TSS](#abbr_TSS) evaluation activities for this There are no additional [TSS](#abbr_TSS) evaluation activities for this component.\ component.\ ::: ::: ::: eacategory ::: eacategory Guidance Guidance ::: ::: ::: ea ::: ea There are no additional Guidance evaluation activities for this There are no additional Guidance evaluation activities for this component.\ component.\ ::: ::: ::: eacategory ::: eacategory Tests Tests ::: ::: ::: ea ::: ea There are no test activities for this component.\ There are no test activities for this component.\ ::: ::: ::: ::: ::: ::: ::: ::: ::: {#FCS_RBG.3 .comp} ::: {#FCS_RBG.3 .comp} #### FCS_RBG.3 Random Bit Generation (Internal Seeding - Single Source) #### FCS_RBG.3 Random Bit Generation (Internal Seeding - Single Source) ::: statustag ::: statustag ***The inclusion of this selection-based component depends upon ***The inclusion of this selection-based component depends upon selection in:*** selection in:*** - ***[FCS_RBG.1.2](#FCS_RBG.1.2)*** - ***[FCS_RBG.1.2](#FCS_RBG.1.2)*** ::: ::: ::: element ::: element ::: {#FCS_RBG.3.1 .reqid} ::: {#FCS_RBG.3.1 .reqid} [FCS_RBG.3.1](#FCS_RBG.3.1){.abbr} [FCS_RBG.3.1](#FCS_RBG.3.1){.abbr} ::: ::: ::: reqdesc ::: reqdesc The [TSF](#abbr_TSF) shall be able to seed the DRBG using a The [TSF](#abbr_TSF) shall be able to seed the DRBG using a \[**selection, choose one of**: [[TSF](#abbr_TSF) software-based entropy \[**selection, choose one of**: [[TSF](#abbr_TSF) software-based entropy source]{#_s_384 .selectable-content}, [[TSF](#abbr_TSF) hardware-based | source]{#fcs_rbg.3.1_1 .selectable-content}, [[TSF](#abbr_TSF) entropy source]{#_s_385 .selectable-content}\] \[**assignment**: [name | hardware-based entropy source]{#fcs_rbg.3.1_2 .selectable-content}\] of entropy source]{.assignable-content}\] with \[*a minimum of 384*\] | \[**assignment**: [name of entropy source]{.assignable-content}\] with bits of min-entropy. | \[*a minimum of 384*\] bits of min-entropy. ::: appnote ::: appnote [Application Note: ]{.note-header}[ ]{.note} [Application Note: ]{.note-header}[ ]{.note} This [SFR](#abbr_SFR) is claimed if \"[TSF](#abbr_TSF) entropy This [SFR](#abbr_SFR) is claimed if \"[TSF](#abbr_TSF) entropy source\...\" is selected in [FCS_RBG.1.2](#FCS_RBG.1.2), i.e., the source\...\" is selected in [FCS_RBG.1.2](#FCS_RBG.1.2), i.e., the [TOE](#abbr_TOE) has a single entropy source that is inside the [TOE](#abbr_TOE) has a single entropy source that is inside the [TOE](#abbr_TOE) boundary. If the [TOE](#abbr_TOE) obtains seed material [TOE](#abbr_TOE) boundary. If the [TOE](#abbr_TOE) obtains seed material from an environmental component, this is specified using from an environmental component, this is specified using [FCS_RBG.2](#FCS_RBG.2). [FCS_RBG.2](#FCS_RBG.2). If the [TSF](#abbr_TSF) entropy source produces full entropy, the amount If the [TSF](#abbr_TSF) entropy source produces full entropy, the amount of entropy data collected is equal to the amount specified in the of entropy data collected is equal to the amount specified in the selection. If the entropy source does not assure full entropy (i.e., the selection. If the entropy source does not assure full entropy (i.e., the ratio of min-entropy to collected data is less than 1:1), then the ratio of min-entropy to collected data is less than 1:1), then the [TSF](#abbr_TSF) must collect sufficient additional entropy data and [TSF](#abbr_TSF) must collect sufficient additional entropy data and perform a derivation function on it to reduce the collected data to a perform a derivation function on it to reduce the collected data to a seed with the claimed min-entropy. In this case, the entropy seed with the claimed min-entropy. In this case, the entropy documentation is expected to identify the min-entropy rate of the source documentation is expected to identify the min-entropy rate of the source data, how much data the [TSF](#abbr_TSF) collects, and what derivation data, how much data the [TSF](#abbr_TSF) collects, and what derivation function is performed on this collected data to ensure that it has the function is performed on this collected data to ensure that it has the claimed min-entropy. claimed min-entropy. One can apply [NIST](#abbr_NIST) SP 800-90B (or AIS-31) statistical One can apply [NIST](#abbr_NIST) SP 800-90B (or AIS-31) statistical tests against internal entropy sources (aka raw entropy) to confirm the tests against internal entropy sources (aka raw entropy) to confirm the min-entropy of the entropy source. min-entropy of the entropy source. ::: ::: ::: ::: ::: ::: ::: {.activity_pane .hide} ::: {.activity_pane .hide} ::: activity_pane_header ::: activity_pane_header [[ Evaluation Activities [[ Evaluation Activities ]{.activity_pane_label}[]{.toggler}](#){onclick="toggle(this);return false;"} ]{.activity_pane_label}[]{.toggler}](#){onclick="toggle(this);return false;"} ::: ::: ::: activity_pane_body ::: activity_pane_body ::: component-activity-header ::: component-activity-header [FCS_RBG.3](#FCS_RBG.3) [FCS_RBG.3](#FCS_RBG.3) ::: ::: The evaluator shall examine the entropy documentation required by The evaluator shall examine the entropy documentation required by [FCS_RBG.1](#FCS_RBG.1) to verify that it identifies, for each DRBG [FCS_RBG.1](#FCS_RBG.1) to verify that it identifies, for each DRBG function implemented by the [TOE](#abbr_TOE), the [TSF](#abbr_TSF) function implemented by the [TOE](#abbr_TOE), the [TSF](#abbr_TSF) entropy source that is used to seed the [TOE](#abbr_TOE)\'s DRBG. The entropy source that is used to seed the [TOE](#abbr_TOE)\'s DRBG. The evaluator shall verify that this includes the amount of sampled data and evaluator shall verify that this includes the amount of sampled data and the min-entropy rate of the sampled data such that it can be determined the min-entropy rate of the sampled data such that it can be determined that the [TSF](#abbr_TSF) can derive a seed from it that has the claimed that the [TSF](#abbr_TSF) can derive a seed from it that has the claimed amount of min-entropy. If the [TSF](#abbr_TSF) uses an entropy source amount of min-entropy. If the [TSF](#abbr_TSF) uses an entropy source that can be assumed to have full entropy, the seed is the output data that can be assumed to have full entropy, the seed is the output data from the entropy source. If the [TSF](#abbr_TSF) uses an entropy source from the entropy source. If the [TSF](#abbr_TSF) uses an entropy source where the min-entropy of the data is less than 1:1, the evaluator shall where the min-entropy of the data is less than 1:1, the evaluator shall verify that the entropy documentation identifies how large the collected verify that the entropy documentation identifies how large the collected data sample is and how [TSF](#abbr_TSF) derives this data into a seed data sample is and how [TSF](#abbr_TSF) derives this data into a seed that has the claimed min-entropy. that has the claimed min-entropy. ::: eacategory ::: eacategory [TSS](#abbr_TSS) [TSS](#abbr_TSS) ::: ::: ::: ea ::: ea There are no additional [TSS](#abbr_TSS) evaluation activities for this There are no additional [TSS](#abbr_TSS) evaluation activities for this component.\ component.\ ::: ::: ::: eacategory ::: eacategory Guidance Guidance ::: ::: ::: ea ::: ea There are no additional Guidance evaluation activities for this There are no additional Guidance evaluation activities for this component.\ component.\ ::: ::: ::: eacategory ::: eacategory Tests Tests ::: ::: ::: ea ::: ea There are no test activities for this component.\ There are no test activities for this component.\ ::: ::: ::: ::: ::: ::: ::: ::: ::: {#FCS_RBG.4 .comp} ::: {#FCS_RBG.4 .comp} #### FCS_RBG.4 Random Bit Generation (Internal Seeding - Multiple Sources) #### FCS_RBG.4 Random Bit Generation (Internal Seeding - Multiple Sources) ::: statustag ::: statustag ***The inclusion of this selection-based component depends upon ***The inclusion of this selection-based component depends upon selection in:*** selection in:*** - ***[FCS_RBG.1.2](#FCS_RBG.1.2)*** - ***[FCS_RBG.1.2](#FCS_RBG.1.2)*** ::: ::: ::: element ::: element ::: {#FCS_RBG.4.1 .reqid} ::: {#FCS_RBG.4.1 .reqid} [FCS_RBG.4.1](#FCS_RBG.4.1){.abbr} [FCS_RBG.4.1](#FCS_RBG.4.1){.abbr} ::: ::: ::: reqdesc ::: reqdesc The [TSF](#abbr_TSF) shall be able to seed the DRBG using The [TSF](#abbr_TSF) shall be able to seed the DRBG using \[**selection**: [\[**assignment**: [number]{.assignable-content}\] \[**selection**: [\[**assignment**: [number]{.assignable-content}\] independent [TSF](#abbr_TSF) software-based entropy source(s)]{#_s_386 | independent [TSF](#abbr_TSF) software-based entropy .selectable-content}, [\[**assignment**: [number]{.assignable-content}\] | source(s)]{#fcs_rbg.4.1_1 .selectable-content}, [\[**assignment**: independent [TSF](#abbr_TSF) hardware-based entropy source(s)]{#_s_387 | [number]{.assignable-content}\] independent [TSF](#abbr_TSF) .selectable-content}\]. | hardware-based entropy source(s)]{#fcs_rbg.4.1_3 .selectable-content}\]. ::: appnote ::: appnote [Application Note: ]{.note-header}[ ]{.note} [Application Note: ]{.note-header}[ ]{.note} This [SFR](#abbr_SFR) is claimed if \"multiple independent This [SFR](#abbr_SFR) is claimed if \"multiple independent [TSF](#abbr_TSF) entropy sources\...\" is selected in [TSF](#abbr_TSF) entropy sources\...\" is selected in [FCS_RBG.1.2](#FCS_RBG.1.2), i.e., the [TSF](#abbr_TSF) performs some [FCS_RBG.1.2](#FCS_RBG.1.2), i.e., the [TSF](#abbr_TSF) performs some sort of operation to combine data from multiple distinct sources into a sort of operation to combine data from multiple distinct sources into a value that is used to derive a seed. If the [TOE](#abbr_TOE) has only a value that is used to derive a seed. If the [TOE](#abbr_TOE) has only a single entropy source, this is specified using [FCS_RBG.3](#FCS_RBG.3). single entropy source, this is specified using [FCS_RBG.3](#FCS_RBG.3). [FCS_RBG.5](#FCS_RBG.5) defines the mechanism by which these sources are [FCS_RBG.5](#FCS_RBG.5) defines the mechanism by which these sources are combined to ensure sufficient minimum entropy. combined to ensure sufficient minimum entropy. ::: ::: ::: ::: ::: ::: ::: {.activity_pane .hide} ::: {.activity_pane .hide} ::: activity_pane_header ::: activity_pane_header [[ Evaluation Activities [[ Evaluation Activities ]{.activity_pane_label}[]{.toggler}](#){onclick="toggle(this);return false;"} ]{.activity_pane_label}[]{.toggler}](#){onclick="toggle(this);return false;"} ::: ::: ::: activity_pane_body ::: activity_pane_body ::: component-activity-header ::: component-activity-header [FCS_RBG.4](#FCS_RBG.4) [FCS_RBG.4](#FCS_RBG.4) ::: ::: The evaluator shall examine the entropy documentation required by The evaluator shall examine the entropy documentation required by [FCS_RBG.1](#FCS_RBG.1) to verify that it identifies, for each DRBG [FCS_RBG.1](#FCS_RBG.1) to verify that it identifies, for each DRBG function implemented by the [TOE](#abbr_TOE), each [TSF](#abbr_TSF) function implemented by the [TOE](#abbr_TOE), each [TSF](#abbr_TSF) entropy source used to seed the [TOE](#abbr_TOE)\'s DRBG. entropy source used to seed the [TOE](#abbr_TOE)\'s DRBG. ::: eacategory ::: eacategory [TSS](#abbr_TSS) [TSS](#abbr_TSS) ::: ::: ::: ea ::: ea There are no additional [TSS](#abbr_TSS) evaluation activities for this There are no additional [TSS](#abbr_TSS) evaluation activities for this component.\ component.\ ::: ::: ::: eacategory ::: eacategory Guidance Guidance ::: ::: ::: ea ::: ea There are no additional Guidance evaluation activities for this There are no additional Guidance evaluation activities for this component.\ component.\ ::: ::: ::: eacategory ::: eacategory Tests Tests ::: ::: ::: ea ::: ea There are no test activities for this component.\ There are no test activities for this component.\ ::: ::: ::: ::: ::: ::: ::: ::: ::: {#FCS_RBG.5 .comp} ::: {#FCS_RBG.5 .comp} #### FCS_RBG.5 Random Bit Generation (Combining Entropy Sources) #### FCS_RBG.5 Random Bit Generation (Combining Entropy Sources) ::: statustag ::: statustag ***The inclusion of this selection-based component depends upon ***The inclusion of this selection-based component depends upon selection in:*** selection in:*** - ***[FCS_RBG.1.2](#FCS_RBG.1.2)*** - ***[FCS_RBG.1.2](#FCS_RBG.1.2)*** ::: ::: ::: element ::: element ::: {#FCS_RBG.5.1 .reqid} ::: {#FCS_RBG.5.1 .reqid} [FCS_RBG.5.1](#FCS_RBG.5.1){.abbr} [FCS_RBG.5.1](#FCS_RBG.5.1){.abbr} ::: ::: ::: reqdesc ::: reqdesc The [TSF](#abbr_TSF) shall \[**assignment**: [combining The [TSF](#abbr_TSF) shall \[**assignment**: [combining operation]{.assignable-content}\] \[**selection**: [output from operation]{.assignable-content}\] \[**selection**: [output from [TSF](#abbr_TSF) entropy source(s)]{#_s_388 .selectable-content}, [input | [TSF](#abbr_TSF) entropy source(s)]{#fcs_rbg.5.1_2 .selectable-content}, from [TSF](#abbr_TSF) interface(s) for obtaining entropy]{#_s_389 | [input from [TSF](#abbr_TSF) interface(s) for obtaining .selectable-content}\] resulting in a minimum of \[*384*\] bits of | entropy]{#fcs_rbg.5.1_3 .selectable-content}\] resulting in a minimum of min-entropy to create the entropy input into the derivation function as | \[*384*\] bits of min-entropy to create the entropy input into the defined in \[**assignment**: [list of standards]{.assignable-content}\]. | derivation function as defined in \[**assignment**: [list of > standards]{.assignable-content}\]. ::: appnote ::: appnote [Application Note: ]{.note-header}[ ]{.note} [Application Note: ]{.note-header}[ ]{.note} This [SFR](#abbr_SFR) is claimed if \"multiple [TSF](#abbr_TSF) entropy This [SFR](#abbr_SFR) is claimed if \"multiple [TSF](#abbr_TSF) entropy sources\...\" is selected in [FCS_RBG.1.2](#FCS_RBG.1.2), i.e., the sources\...\" is selected in [FCS_RBG.1.2](#FCS_RBG.1.2), i.e., the [TSF](#abbr_TSF) performs some sort of operation to combine data from [TSF](#abbr_TSF) performs some sort of operation to combine data from multiple distinct sources into a value that is used to derive a seed. If multiple distinct sources into a value that is used to derive a seed. If the [TOE](#abbr_TOE) has only a single entropy source, this is specified the [TOE](#abbr_TOE) has only a single entropy source, this is specified using [FCS_RBG.3](#FCS_RBG.3). using [FCS_RBG.3](#FCS_RBG.3). If the environmental entropy source produces full entropy, the amount of If the environmental entropy source produces full entropy, the amount of entropy data collected is equal to the amount specified in the entropy data collected is equal to the amount specified in the selection. If the entropy source does not assure full entropy (i.e., the selection. If the entropy source does not assure full entropy (i.e., the ratio of min-entropy to collected data is less than 1:1), then the ratio of min-entropy to collected data is less than 1:1), then the [TSF](#abbr_TSF) must collect sufficient additional entropy data and [TSF](#abbr_TSF) must collect sufficient additional entropy data and perform a derivation function on it to reduce the collected data to a perform a derivation function on it to reduce the collected data to a seed with the claimed min-entropy. In this case, the entropy seed with the claimed min-entropy. In this case, the entropy documentation is expected to identify the min-entropy rate of the source documentation is expected to identify the min-entropy rate of the source data, how much data the [TSF](#abbr_TSF) collects, and what derivation data, how much data the [TSF](#abbr_TSF) collects, and what derivation function is performed on this collected data to ensure that it has the function is performed on this collected data to ensure that it has the claimed min-entropy. claimed min-entropy. One can apply [NIST](#abbr_NIST) SP 800-90B (or AIS-31) statistical One can apply [NIST](#abbr_NIST) SP 800-90B (or AIS-31) statistical tests against internal entropy sources (aka raw entropy) to confirm the tests against internal entropy sources (aka raw entropy) to confirm the min-entropy of the entropy sources either in aggregate or individually. min-entropy of the entropy sources either in aggregate or individually. ::: ::: ::: ::: ::: ::: ::: {.activity_pane .hide} ::: {.activity_pane .hide} ::: activity_pane_header ::: activity_pane_header [[ Evaluation Activities [[ Evaluation Activities ]{.activity_pane_label}[]{.toggler}](#){onclick="toggle(this);return false;"} ]{.activity_pane_label}[]{.toggler}](#){onclick="toggle(this);return false;"} ::: ::: ::: activity_pane_body ::: activity_pane_body ::: component-activity-header ::: component-activity-header [FCS_RBG.5](#FCS_RBG.5) [FCS_RBG.5](#FCS_RBG.5) ::: ::: Using the entropy sources specified in [FCS_RBG.4](#FCS_RBG.4), the Using the entropy sources specified in [FCS_RBG.4](#FCS_RBG.4), the evaluator shall examine the entropy documentation required by evaluator shall examine the entropy documentation required by [FCS_RBG.1](#FCS_RBG.1) to verify that it describes the method by which [FCS_RBG.1](#FCS_RBG.1) to verify that it describes the method by which data from these sources are combined into a single seed. This should data from these sources are combined into a single seed. This should include an estimation of the rate at which each entropy source outputs include an estimation of the rate at which each entropy source outputs data and whether this is dependent on any system-specific factors so data and whether this is dependent on any system-specific factors so that each source\'s relative contribution to the overall entropy is that each source\'s relative contribution to the overall entropy is understood. The evaluator shall verify that the amount of sampled data, understood. The evaluator shall verify that the amount of sampled data, the min-entropy rate of the sampled data, and the method by which the the min-entropy rate of the sampled data, and the method by which the multiple sampled data sources are combined can be used to determine that multiple sampled data sources are combined can be used to determine that the [TSF](#abbr_TSF) can derive a seed from it that has the claimed the [TSF](#abbr_TSF) can derive a seed from it that has the claimed amount of min-entropy. This includes any description of how the amount of min-entropy. This includes any description of how the [TSF](#abbr_TSF) derives data larger than the seed value into a seed [TSF](#abbr_TSF) derives data larger than the seed value into a seed that has the claimed min-entropy. that has the claimed min-entropy. ::: eacategory ::: eacategory [TSS](#abbr_TSS) [TSS](#abbr_TSS) ::: ::: ::: ea ::: ea There are no additional [TSS](#abbr_TSS) evaluation activities for this There are no additional [TSS](#abbr_TSS) evaluation activities for this component.\ component.\ ::: ::: ::: eacategory ::: eacategory Guidance Guidance ::: ::: ::: ea ::: ea There are no additional Guidance evaluation activities for this There are no additional Guidance evaluation activities for this component.\ component.\ ::: ::: ::: eacategory ::: eacategory Tests Tests ::: ::: ::: ea ::: ea There are no test activities for this component.\ There are no test activities for this component.\ ::: ::: ::: ::: ::: ::: ::: ::: ## B.3 Class FDP: User Data Protection {#-sel-based .indexable level="2"} | ## B.3 Class FDP: User Data Protection {#fdp-sel-based .indexable level="2"} ::: {#FDP_ACF_EXT.2 .comp} ::: {#FDP_ACF_EXT.2 .comp} #### FDP_ACF_EXT.2 Access Control for System Resources #### FDP_ACF_EXT.2 Access Control for System Resources ::: statustag ::: statustag ***The inclusion of this selection-based component depends upon ***The inclusion of this selection-based component depends upon selection in:*** selection in:*** - ***[FDP_ACF_EXT.1.2](#FDP_ACF_EXT.1.2)*** - ***[FDP_ACF_EXT.1.2](#FDP_ACF_EXT.1.2)*** ::: ::: ::: element ::: element ::: {#FDP_ACF_EXT.2.1 .reqid} ::: {#FDP_ACF_EXT.2.1 .reqid} [FDP_ACF_EXT.2.1](#FDP_ACF_EXT.2.1){.abbr} [FDP_ACF_EXT.2.1](#FDP_ACF_EXT.2.1){.abbr} ::: ::: ::: reqdesc ::: reqdesc The [TSF](#abbr_TSF) shall provide a separate \[**selection**: [address The [TSF](#abbr_TSF) shall provide a separate \[**selection**: [address book]{#_s_476 .selectable-content}, [calendar]{#_s_477 | book]{#fdp_acf_ext.2.1_1 .selectable-content}, .selectable-content}, [keystore]{#_s_478 .selectable-content}, [account | [calendar]{#fdp_acf_ext.2.1_2 .selectable-content}, credential database, \[**assignment**: [list of additional | [keystore]{#fdp_acf_ext.2.1_3 .selectable-content}, [account credential resources]{.assignable-content}\]]{#_s_479 .selectable-content}\] for | database, \[**assignment**: [list of additional each application group and only allow applications within that process | resources]{.assignable-content}\]]{#fdp_acf_ext.2.1_4 group to access the resource. Exceptions may only be explicitly | .selectable-content}\] for each application group and only allow authorized for such sharing by \[**selection**: [the user]{#_s_480 | applications within that process group to access the resource. .selectable-content}, [the administrator]{#_s_481 .selectable-content}, | Exceptions may only be explicitly authorized for such sharing by [no one]{#_s_482 .selectable-content}\]. | \[**selection**: [the user]{#fdp_acf_ext.2.1_6 .selectable-content}, > [the administrator]{#fdp_acf_ext.2.1_7 .selectable-content}, [no > one]{#fdp_acf_ext.2.1_8 .selectable-content}\]. ::: appnote ::: appnote [Application Note: ]{.note-header}[If [groups of | [Application Note: ]{.note-header}[ If [groups of applications](#fdp_group) is selected in applications](#fdp_group) is selected in [FDP_ACF_EXT.1.2](#FDP_ACF_EXT.1.2), [FDP_ACF_EXT.2](#FDP_ACF_EXT.2) [FDP_ACF_EXT.1.2](#FDP_ACF_EXT.1.2), [FDP_ACF_EXT.2](#FDP_ACF_EXT.2) must be included in the [ST](#abbr_ST). ]{.note} must be included in the [ST](#abbr_ST). ]{.note} ::: ::: ::: ::: ::: ::: ::: {.activity_pane .hide} ::: {.activity_pane .hide} ::: activity_pane_header ::: activity_pane_header [[ Evaluation Activities [[ Evaluation Activities ]{.activity_pane_label}[]{.toggler}](#){onclick="toggle(this);return false;"} ]{.activity_pane_label}[]{.toggler}](#){onclick="toggle(this);return false;"} ::: ::: ::: activity_pane_body ::: activity_pane_body ::: component-activity-header ::: component-activity-header [FDP_ACF_EXT.2](#FDP_ACF_EXT.2) [FDP_ACF_EXT.2](#FDP_ACF_EXT.2) ::: ::: ::: eacategory ::: eacategory [TSS](#abbr_TSS) [TSS](#abbr_TSS) ::: ::: ::: ea ::: ea ::: ea ::: ea There are no [TSS](#abbr_TSS) evaluation activities for this component.\ There are no [TSS](#abbr_TSS) evaluation activities for this component.\ \ \ ::: ::: ::: ::: ::: eacategory ::: eacategory Guidance Guidance ::: ::: ::: ea ::: ea ::: ea ::: ea There are no guidance evaluation activities for this component.\ There are no guidance evaluation activities for this component.\ \ \ ::: ::: ::: ::: ::: eacategory ::: eacategory Tests Tests ::: ::: ::: ea ::: ea ::: ea ::: ea For each selected resource, the evaluator shall cause data to be placed For each selected resource, the evaluator shall cause data to be placed into the Enterprise group's instance of that shared resource. The into the Enterprise group's instance of that shared resource. The evaluator shall install an application into the Personal group that evaluator shall install an application into the Personal group that attempts to access the shared resource information and verify that it attempts to access the shared resource information and verify that it cannot access the information. cannot access the information. ::: ::: ::: ::: ::: ::: ::: ::: ::: ::: ## B.4 Class FPT: Protection of the TSF {#-sel-based .indexable level="2"} | ## B.4 Class FPT: Protection of the TSF {#fpt-sel-based .indexable level="2"} ::: {#FPT_TST_EXT.3 .comp} ::: {#FPT_TST_EXT.3 .comp} #### FPT_TST_EXT.3 TSF Integrity Testing #### FPT_TST_EXT.3 TSF Integrity Testing ::: statustag ::: statustag ***The inclusion of this selection-based component depends upon ***The inclusion of this selection-based component depends upon selection in:*** selection in:*** - ***FIA_X509_EXT.2.1 from [Functional Package for X.509, version - ***FIA_X509_EXT.2.1 from [Functional Package for X.509, version 1.0](https://www.niap-ccevs.org/protectionprofiles/511)*** 1.0](https://www.niap-ccevs.org/protectionprofiles/511)*** ::: ::: ::: element ::: element ::: {#FPT_TST_EXT.3.1 .reqid} ::: {#FPT_TST_EXT.3.1 .reqid} [FPT_TST_EXT.3.1](#FPT_TST_EXT.3.1){.abbr} [FPT_TST_EXT.3.1](#FPT_TST_EXT.3.1){.abbr} ::: ::: ::: reqdesc ::: reqdesc The [TSF](#abbr_TSF) shall not execute code if the code signing The [TSF](#abbr_TSF) shall not execute code if the code signing certificate is deemed invalid. certificate is deemed invalid. ::: appnote ::: appnote [Application Note: ]{.note-header}[Certificates may optionally be used | [Application Note: ]{.note-header}[ Certificates may optionally be used for code signing for integrity verification for code signing for integrity verification ([FPT_TST_EXT.2.1/PREKERNEL](#FPT_TST_EXT.2.1/PREKERNEL)). If \"code ([FPT_TST_EXT.2.1/PREKERNEL](#FPT_TST_EXT.2.1/PREKERNEL)). If \"code signing for software integrity testing\" is selected in FIA_X509_EXT.2.1 signing for software integrity testing\" is selected in FIA_X509_EXT.2.1 in [Functional Package for X.509, version in [Functional Package for X.509, version 1.0](https://www.niap-ccevs.org/protectionprofiles/511), 1.0](https://www.niap-ccevs.org/protectionprofiles/511), [FPT_TST_EXT.3.1](#FPT_TST_EXT.3.1) must be included in the [FPT_TST_EXT.3.1](#FPT_TST_EXT.3.1) must be included in the [ST](#abbr_ST).\ [ST](#abbr_ST).\ \ \ Validity is determined by the certificate path, the expiration date, and Validity is determined by the certificate path, the expiration date, and the revocation status in accordance with RFC 5280. ]{.note} the revocation status in accordance with RFC 5280. ]{.note} ::: ::: ::: ::: ::: ::: ::: {.activity_pane .hide} ::: {.activity_pane .hide} ::: activity_pane_header ::: activity_pane_header [[ Evaluation Activities [[ Evaluation Activities ]{.activity_pane_label}[]{.toggler}](#){onclick="toggle(this);return false;"} ]{.activity_pane_label}[]{.toggler}](#){onclick="toggle(this);return false;"} ::: ::: ::: activity_pane_body ::: activity_pane_body ::: component-activity-header ::: component-activity-header [FPT_TST_EXT.3](#FPT_TST_EXT.3) [FPT_TST_EXT.3](#FPT_TST_EXT.3) ::: ::: ::: eacategory ::: eacategory [TSS](#abbr_TSS) [TSS](#abbr_TSS) ::: ::: ::: ea ::: ea ::: ea ::: ea There are no [TSS](#abbr_TSS) evaluation activities for this component.\ There are no [TSS](#abbr_TSS) evaluation activities for this component.\ \ \ ::: ::: ::: ::: ::: eacategory ::: eacategory Guidance Guidance ::: ::: ::: ea ::: ea ::: ea ::: ea There are no guidance evaluation activities for this component.\ There are no guidance evaluation activities for this component.\ \ \ ::: ::: ::: ::: ::: eacategory ::: eacategory Tests Tests ::: ::: ::: ea ::: ea ::: ea ::: ea Testing for this component is performed in conjunction with the Testing for this component is performed in conjunction with the Evaluation Activities for Evaluation Activities for [FPT_TST_EXT.2.1/PREKERNEL](#FPT_TST_EXT.2.1/PREKERNEL). [FPT_TST_EXT.2.1/PREKERNEL](#FPT_TST_EXT.2.1/PREKERNEL). ::: ::: ::: ::: ::: ::: ::: ::: ::: ::: ::: {#FPT_TUD_EXT.4 .comp} ::: {#FPT_TUD_EXT.4 .comp} #### FPT_TUD_EXT.4 Trusted Update Verification #### FPT_TUD_EXT.4 Trusted Update Verification ::: statustag ::: statustag ***The inclusion of this selection-based component depends upon ***The inclusion of this selection-based component depends upon selection in:*** selection in:*** - ***FIA_X509_EXT.2.1 from [Functional Package for X.509, version - ***FIA_X509_EXT.2.1 from [Functional Package for X.509, version 1.0](https://www.niap-ccevs.org/protectionprofiles/511)*** 1.0](https://www.niap-ccevs.org/protectionprofiles/511)*** ::: ::: ::: element ::: element ::: {#FPT_TUD_EXT.4.1 .reqid} ::: {#FPT_TUD_EXT.4.1 .reqid} [FPT_TUD_EXT.4.1](#FPT_TUD_EXT.4.1){.abbr} [FPT_TUD_EXT.4.1](#FPT_TUD_EXT.4.1){.abbr} ::: ::: ::: reqdesc ::: reqdesc The [TSF](#abbr_TSF) shall not install code if the code signing The [TSF](#abbr_TSF) shall not install code if the code signing certificate is deemed invalid. certificate is deemed invalid. ::: appnote ::: appnote [Application Note: ]{.note-header}[Certificates may optionally be used | [Application Note: ]{.note-header}[ Certificates may optionally be used for code signing of system software updates for code signing of system software updates ([FPT_TUD_EXT.2.3](#FPT_TUD_EXT.2.3)) and of mobile applications ([FPT_TUD_EXT.2.3](#FPT_TUD_EXT.2.3)) and of mobile applications ([FPT_TUD_EXT.5.1](#FPT_TUD_EXT.5.1)). This element must be included in ([FPT_TUD_EXT.5.1](#FPT_TUD_EXT.5.1)). This element must be included in the [ST](#abbr_ST) if certificates are used for either update element. the [ST](#abbr_ST) if certificates are used for either update element. If \"code signing for system software updates\" is selected or the If \"code signing for system software updates\" is selected or the assignment is selected and specifies the use of X.509 in code signing assignment is selected and specifies the use of X.509 in code signing for mobile applications in FIA_X509_EXT.2.1 in [Functional Package for for mobile applications in FIA_X509_EXT.2.1 in [Functional Package for X.509, version 1.0](https://www.niap-ccevs.org/protectionprofiles/511), X.509, version 1.0](https://www.niap-ccevs.org/protectionprofiles/511), [FPT_TUD_EXT.4](#FPT_TUD_EXT.4) must be included in the [ST](#abbr_ST).\ [FPT_TUD_EXT.4](#FPT_TUD_EXT.4) must be included in the [ST](#abbr_ST).\ \ \ Validity is determined by the certificate path, the expiration date, and Validity is determined by the certificate path, the expiration date, and the revocation status in accordance with RFC 5280. ]{.note} the revocation status in accordance with RFC 5280. ]{.note} ::: ::: ::: ::: ::: ::: ::: {.activity_pane .hide} ::: {.activity_pane .hide} ::: activity_pane_header ::: activity_pane_header [[ Evaluation Activities [[ Evaluation Activities ]{.activity_pane_label}[]{.toggler}](#){onclick="toggle(this);return false;"} ]{.activity_pane_label}[]{.toggler}](#){onclick="toggle(this);return false;"} ::: ::: ::: activity_pane_body ::: activity_pane_body ::: component-activity-header ::: component-activity-header [FPT_TUD_EXT.4](#FPT_TUD_EXT.4) [FPT_TUD_EXT.4](#FPT_TUD_EXT.4) ::: ::: ::: eacategory ::: eacategory [TSS](#abbr_TSS) [TSS](#abbr_TSS) ::: ::: ::: ea ::: ea ::: ea ::: ea There are no [TSS](#abbr_TSS) evaluation activities for this component.\ There are no [TSS](#abbr_TSS) evaluation activities for this component.\ \ \ ::: ::: ::: ::: ::: eacategory ::: eacategory Guidance Guidance ::: ::: ::: ea ::: ea ::: ea ::: ea There are no guidance evaluation activities for this component.\ There are no guidance evaluation activities for this component.\ \ \ ::: ::: ::: ::: ::: eacategory ::: eacategory Tests Tests ::: ::: ::: ea ::: ea ::: ea ::: ea Testing for this component is performed in conjunction with the Testing for this component is performed in conjunction with the Evaluation Activities for [FPT_TUD_EXT.2](#FPT_TUD_EXT.2) and Evaluation Activities for [FPT_TUD_EXT.2](#FPT_TUD_EXT.2) and [FPT_TUD_EXT.5](#FPT_TUD_EXT.5). [FPT_TUD_EXT.5](#FPT_TUD_EXT.5). ::: ::: ::: ::: ::: ::: ::: ::: ::: ::: # Appendix C - Extended Component Definitions {#ext-comp-defs .indexable level="A"} # Appendix C - Extended Component Definitions {#ext-comp-defs .indexable level="A"} This appendix contains the definitions for all extended requirements This appendix contains the definitions for all extended requirements specified in the [PP](#abbr_PP). specified in the [PP](#abbr_PP). ## C.1 Extended Components Table {#ext-comp-defs-bg .indexable level="2"} ## C.1 Extended Components Table {#ext-comp-defs-bg .indexable level="2"} All extended components specified in the [PP](#abbr_PP) are listed in All extended components specified in the [PP](#abbr_PP) are listed in this table: this table: ----------------------------------------------------------------------- ----------------------------------------------------------------------- Functional Class Functional Components Functional Class Functional Components ----------------------------------- ----------------------------------- ----------------------------------- ----------------------------------- Class FCS: Cryptographic Support FCS_CKM_EXT Cryptographic Key Class FCS: Cryptographic Support FCS_CKM_EXT Cryptographic Key Management\ Management\ FCS_HTTPS_EXT [HTTPS](#abbr_HTTPS) FCS_HTTPS_EXT [HTTPS](#abbr_HTTPS) Protocol\ Protocol\ FCS_IV_EXT Initialization Vector FCS_IV_EXT Initialization Vector Generation\ Generation\ FCS_RBG_EXT Random Bit Generation\ FCS_RBG_EXT Random Bit Generation\ FCS_SRV_EXT Cryptographic Algorithm FCS_SRV_EXT Cryptographic Algorithm Services\ Services\ FCS_STG_EXT Cryptographic Key FCS_STG_EXT Cryptographic Key Storage\ Storage\ Class FDP: User Data Protection FDP_ACF_EXT Access Control Class FDP: User Data Protection FDP_ACF_EXT Access Control Functions\ Functions\ FDP_BCK_EXT Application Backup\ FDP_BCK_EXT Application Backup\ FDP_BLT_EXT Limitation of Bluetooth FDP_BLT_EXT Limitation of Bluetooth Device Access\ Device Access\ FDP_DAR_EXT Data-at-Rest FDP_DAR_EXT Data-at-Rest Encryption\ Encryption\ FDP_IFC_EXT Subset Information Flow FDP_IFC_EXT Subset Information Flow Control\ Control\ FDP_STG_EXT User Data Storage\ FDP_STG_EXT User Data Storage\ FDP_UPC_EXT Inter-TSF User Data FDP_UPC_EXT Inter-TSF User Data Transfer Protection\ Transfer Protection\ Class FIA: Identification and FIA_AFL_EXT Authentication Class FIA: Identification and FIA_AFL_EXT Authentication Authentication Failures\ Authentication Failures\ FIA_PMG_EXT Password Management\ FIA_PMG_EXT Password Management\ FIA_TRT_EXT Authentication FIA_TRT_EXT Authentication Throttling\ Throttling\ FIA_UAU_EXT User Authentication\ FIA_UAU_EXT User Authentication\ FIA_X509_EXT X.509 Certificates\ FIA_X509_EXT X.509 Certificates\ Class FMT: Security Management FMT_MOF_EXT Management of Functions Class FMT: Security Management FMT_MOF_EXT Management of Functions in [TSF](#abbr_TSF)\ in [TSF](#abbr_TSF)\ FMT_SMF_EXT Specification of FMT_SMF_EXT Specification of Management Functions\ Management Functions\ Class FPT: Protection of the FPT_AEX_EXT Anti-Exploitation Class FPT: Protection of the FPT_AEX_EXT Anti-Exploitation [TSF](#abbr_TSF) Capabilities\ [TSF](#abbr_TSF) Capabilities\ FPT_BBD_EXT Baseband Processing\ FPT_BBD_EXT Baseband Processing\ FPT_BLT_EXT Limitation of Bluetooth FPT_BLT_EXT Limitation of Bluetooth Profile Support\ Profile Support\ FPT_JTA_EXT JTAG Disablement\ FPT_JTA_EXT JTAG Disablement\ FPT_KST_EXT Key Storage\ FPT_KST_EXT Key Storage\ FPT_NOT_EXT Self-Test Notification\ FPT_NOT_EXT Self-Test Notification\ FPT_TST_EXT [TSF](#abbr_TSF) Self FPT_TST_EXT [TSF](#abbr_TSF) Self Test\ Test\ FPT_TUD_EXT [TSF](#abbr_TSF) FPT_TUD_EXT [TSF](#abbr_TSF) Updates\ Updates\ Class FTA: [TOE](#abbr_TOE) Access FTA_SSL_EXT Session Locking and Class FTA: [TOE](#abbr_TOE) Access FTA_SSL_EXT Session Locking and Termination\ Termination\ Class FTP: Trusted Path/Channels FTP_ITC_EXT Inter-TSF Trusted Class FTP: Trusted Path/Channels FTP_ITC_EXT Inter-TSF Trusted Channel\ Channel\ ----------------------------------------------------------------------- ----------------------------------------------------------------------- : **[Table [28]{.counter}]{.ctr myid="" counter-type="ct-Table"}: : **[Table [28]{.counter}]{.ctr myid="" counter-type="ct-Table"}: Extended Component Definitions** Extended Component Definitions** ## C.2 Extended Component Definitions {#ext-comp-defs-bg .indexable level="2"} ## C.2 Extended Component Definitions {#ext-comp-defs-bg .indexable level="2"} [[]{sortkey="Class FCS: Cryptographic Support"}]{.sort_kids_} [[]{sortkey="Class FCS: Cryptographic Support"}]{.sort_kids_} ### C.2.1 Class FCS: Cryptographic Support {#ext-comp- .indexable level="3"} ### C.2.1 Class FCS: Cryptographic Support {#ext-comp- .indexable level="3"} This [PP](#abbr_PP) defines the following extended components as part of This [PP](#abbr_PP) defines the following extended components as part of the class originally defined by [CC](#abbr_CC) Part 2: the class originally defined by [CC](#abbr_CC) Part 2: ### C.2.1.1 FCS_CKM_EXT Cryptographic Key Management {#ext-comp-FCS_CKM_EXT .indexabl ### C.2.1.1 FCS_CKM_EXT Cryptographic Key Management {#ext-comp-FCS_CKM_EXT .indexabl ::: {style="margin-left: 1em;"} ::: {style="margin-left: 1em;"} #### Family Behavior #### Family Behavior
This family defines requirements for management of cryptographic keys This family defines requirements for management of cryptographic keys that are not addressed by FCS_CKM in [CC](#abbr_CC) Part 2. that are not addressed by FCS_CKM in [CC](#abbr_CC) Part 2.
#### Component Leveling #### Component Leveling ![](data:image/svg+xml;base64,PHN2ZyBzdHlsZT0ibWF4LWhlaWdodDogMTcwcHg7Ij48dGV4dCB4PSI ![](data:image/svg+xml;base64,PHN2ZyBzdHlsZT0ibWF4LWhlaWdodDogMTcwcHg7Ij48dGV4dCB4PSI [FCS_CKM_EXT.1](#FCS_CKM_EXT.1), Cryptographic Key Support, requires the [FCS_CKM_EXT.1](#FCS_CKM_EXT.1), Cryptographic Key Support, requires the [TSF](#abbr_TSF) to implement a Root Encryption Key ([REK](#abbr_REK)). [TSF](#abbr_TSF) to implement a Root Encryption Key ([REK](#abbr_REK)). [FCS_CKM_EXT.2](#FCS_CKM_EXT.2), Cryptographic Key Random Generation, [FCS_CKM_EXT.2](#FCS_CKM_EXT.2), Cryptographic Key Random Generation, requires the [TSF](#abbr_TSF) to specify the mechanism it uses to requires the [TSF](#abbr_TSF) to specify the mechanism it uses to generate Data Encryption Keys ([DEKs](#abbr_DEK)). | generate Data Encryption Keys (DEKs). [FCS_CKM_EXT.3](#FCS_CKM_EXT.3), Cryptographic Key Generation, requires [FCS_CKM_EXT.3](#FCS_CKM_EXT.3), Cryptographic Key Generation, requires the [TSF](#abbr_TSF) to generate and manage the strength of Key the [TSF](#abbr_TSF) to generate and manage the strength of Key Encryption Keys (KEKs). Encryption Keys (KEKs). [FCS_CKM_EXT.5](#FCS_CKM_EXT.5), [TSF](#abbr_TSF) Wipe, requires the [FCS_CKM_EXT.5](#FCS_CKM_EXT.5), [TSF](#abbr_TSF) Wipe, requires the [TSF](#abbr_TSF) to implement a cryptographic or other mechanism to make [TSF](#abbr_TSF) to implement a cryptographic or other mechanism to make [TSF](#abbr_TSF) data unreadable. [TSF](#abbr_TSF) data unreadable. [FCS_CKM_EXT.6](#FCS_CKM_EXT.6), Salt Generation, requires the [FCS_CKM_EXT.6](#FCS_CKM_EXT.6), Salt Generation, requires the [TSF](#abbr_TSF) to generate salts in a specified manner. [TSF](#abbr_TSF) to generate salts in a specified manner. FCS_CKM_EXT.7, Cryptographic Key Establishment, requires the FCS_CKM_EXT.7, Cryptographic Key Establishment, requires the [TSF](#abbr_TSF) to perform key establishment regardless of whether the [TSF](#abbr_TSF) to perform key establishment regardless of whether the device is locked or unlocked. device is locked or unlocked. [FCS_CKM_EXT.8](#FCS_CKM_EXT.8), Password-Based Key Derivation, requires [FCS_CKM_EXT.8](#FCS_CKM_EXT.8), Password-Based Key Derivation, requires that password-based key derivation be performed in accordance with that password-based key derivation be performed in accordance with specified standards. specified standards. [FCS_CKM_EXT.9](#FCS_CKM_EXT.9), Hardware Key Confidentiality, requires [FCS_CKM_EXT.9](#FCS_CKM_EXT.9), Hardware Key Confidentiality, requires the [TSF](#abbr_TSF) to enforce the confidentiality of key data stored the [TSF](#abbr_TSF) to enforce the confidentiality of key data stored in mutable hardware by ensuring no mechanism exists to read or export in mutable hardware by ensuring no mechanism exists to read or export it. it. #### Management: FCS_CKM_EXT.1 #### Management: FCS_CKM_EXT.1 There are no management activities foreseen. There are no management activities foreseen. #### Audit: FCS_CKM_EXT.1 #### Audit: FCS_CKM_EXT.1 The following actions should be auditable if FAU_GEN Security audit data The following actions should be auditable if FAU_GEN Security audit data generation is included in the [PP](#abbr_PP), generation is included in the [PP](#abbr_PP), [PP-Module](#abbr_PP-Module), functional package or [ST](#abbr_ST): [PP-Module](#abbr_PP-Module), functional package or [ST](#abbr_ST): - Generation of a [REK](#abbr_REK). - Generation of a [REK](#abbr_REK). #### FCS_CKM_EXT.1 Cryptographic Key Support #### FCS_CKM_EXT.1 Cryptographic Key Support ::: {style="margin-left: 1em;"} ::: {style="margin-left: 1em;"} ------------------ ----------------------------------------------- ------------------ ----------------------------------------------- Hierarchical to: No other components. Hierarchical to: No other components. Dependencies to: [FCS_RBG.1](#FCS_RBG.1) Random Bit Generation Dependencies to: [FCS_RBG.1](#FCS_RBG.1) Random Bit Generation ------------------ ----------------------------------------------- ------------------ ----------------------------------------------- #### FCS_CKM_EXT.1.1 {#ext-comp-FCS_CKM_EXT.1.1} #### FCS_CKM_EXT.1.1 {#ext-comp-FCS_CKM_EXT.1.1} The [TSF](#abbr_TSF) shall support \[**assignment**: [description of The [TSF](#abbr_TSF) shall support \[**assignment**: [description of [REKs](#abbr_REK)]{.assignable-content}\] | REKs]{.assignable-content}\] #### FCS_CKM_EXT.1.2 {#ext-comp-FCS_CKM_EXT.1.2} #### FCS_CKM_EXT.1.2 {#ext-comp-FCS_CKM_EXT.1.2} Each [REK](#abbr_REK) shall be hardware-isolated from the [OS](#abbr_OS) Each [REK](#abbr_REK) shall be hardware-isolated from the [OS](#abbr_OS) on the [TSF](#abbr_TSF) in runtime. on the [TSF](#abbr_TSF) in runtime. #### FCS_CKM_EXT.1.3 {#ext-comp-FCS_CKM_EXT.1.3} #### FCS_CKM_EXT.1.3 {#ext-comp-FCS_CKM_EXT.1.3} Each [REK](#abbr_REK) shall be generated by a DRBG in accordance with Each [REK](#abbr_REK) shall be generated by a DRBG in accordance with [FCS_RBG.1](#FCS_RBG.1). [FCS_RBG.1](#FCS_RBG.1). ::: ::: #### Management: FCS_CKM_EXT.2 #### Management: FCS_CKM_EXT.2 There are no management activities foreseen. There are no management activities foreseen. #### Audit: FCS_CKM_EXT.2 #### Audit: FCS_CKM_EXT.2 There are no auditable events foreseen. There are no auditable events foreseen. #### FCS_CKM_EXT.2 Cryptographic Key Random Generation #### FCS_CKM_EXT.2 Cryptographic Key Random Generation ::: {style="margin-left: 1em;"} ::: {style="margin-left: 1em;"} ------------------ ----------------------------------------------- ------------------ ----------------------------------------------- Hierarchical to: No other components. Hierarchical to: No other components. Dependencies to: [FCS_RBG.1](#FCS_RBG.1) Random Bit Generation Dependencies to: [FCS_RBG.1](#FCS_RBG.1) Random Bit Generation ------------------ ----------------------------------------------- ------------------ ----------------------------------------------- #### FCS_CKM_EXT.2.1 {#ext-comp-FCS_CKM_EXT.2.1} #### FCS_CKM_EXT.2.1 {#ext-comp-FCS_CKM_EXT.2.1} All [DEKs](#abbr_DEK) shall be \[**assignment**: [generation | All DEKs shall be \[**assignment**: [generation mechanism]{.assignable-content}\] with entropy corresponding to the mechanism]{.assignable-content}\] with entropy corresponding to the security strength of [AES](#abbr_AES) key sizes of 256 bits. security strength of [AES](#abbr_AES) key sizes of 256 bits. ::: ::: #### Management: FCS_CKM_EXT.3 #### Management: FCS_CKM_EXT.3 There are no management activities foreseen. There are no management activities foreseen. #### Audit: FCS_CKM_EXT.3 #### Audit: FCS_CKM_EXT.3 There are no auditable events foreseen. There are no auditable events foreseen. #### FCS_CKM_EXT.3 Cryptographic Key Generation #### FCS_CKM_EXT.3 Cryptographic Key Generation ::: {style="margin-left: 1em;"} ::: {style="margin-left: 1em;"} ----------------------------------- ----------------------------------- ----------------------------------- ----------------------------------- Hierarchical to: No other components. Hierarchical to: No other components. Dependencies to: FCS_CKM.1 Cryptographic Key Dependencies to: FCS_CKM.1 Cryptographic Key Generation\ Generation\ FCS_COP.1 Cryptographic Operation\ FCS_COP.1 Cryptographic Operation\ [FCS_RBG.1](#FCS_RBG.1) Random Bit [FCS_RBG.1](#FCS_RBG.1) Random Bit Generation\ Generation\ ----------------------------------- ----------------------------------- ----------------------------------- ----------------------------------- #### FCS_CKM_EXT.3.1 {#ext-comp-FCS_CKM_EXT.3.1} #### FCS_CKM_EXT.3.1 {#ext-comp-FCS_CKM_EXT.3.1} The [TSF](#abbr_TSF) shall use \[**assignment**: [description of The [TSF](#abbr_TSF) shall use \[**assignment**: [description of KEKs]{.assignable-content}\]. KEKs]{.assignable-content}\]. #### FCS_CKM_EXT.3.2 {#ext-comp-FCS_CKM_EXT.3.2} #### FCS_CKM_EXT.3.2 {#ext-comp-FCS_CKM_EXT.3.2} The [TSF](#abbr_TSF) shall generate all KEKs using one of the following The [TSF](#abbr_TSF) shall generate all KEKs using one of the following methods: methods: - Derive the [KEK](#abbr_KEK) from a Password Authentication Factor - Derive the [KEK](#abbr_KEK) from a Password Authentication Factor according to FCS_COP.1.1 and according to FCS_COP.1.1 and \[**selection**: \[**selection**: - [Generate the [KEK](#abbr_KEK) using a DRBG that meets this profile - [Generate the [KEK](#abbr_KEK) using a DRBG that meets this profile (as specified in [FCS_RBG.1](#FCS_RBG.1))]{#_s_114 (as specified in [FCS_RBG.1](#FCS_RBG.1))]{#_s_114 .selectable-content} .selectable-content} - [Generate the [KEK](#abbr_KEK) using a key generation scheme that - [Generate the [KEK](#abbr_KEK) using a key generation scheme that meets this profile (as specified in [FCS_CKM.1/AKG](#FCS_CKM.1/AKG) meets this profile (as specified in [FCS_CKM.1/AKG](#FCS_CKM.1/AKG) or [FCS_CKM.1/SKG](#FCS_CKM.1/SKG))]{#_s_115 .selectable-content} or [FCS_CKM.1/SKG](#FCS_CKM.1/SKG))]{#_s_115 .selectable-content} - [Combine the [KEK](#abbr_KEK) from other KEKs in a way that | - [ Combine the [KEK](#abbr_KEK) from other KEKs in a way that preserves the effective entropy of each factor by \[**selection**: preserves the effective entropy of each factor by \[**selection**: [using an XOR operation]{#_s_117 .selectable-content}, [using an XOR operation]{#_s_117 .selectable-content}, [concatenating the keys and using a [KDF](#abbr_KDF) (as described [concatenating the keys and using a [KDF](#abbr_KDF) (as described in SP 800-108)]{#_s_118 .selectable-content}, [concatenating the in SP 800-108)]{#_s_118 .selectable-content}, [concatenating the keys and using a [KDF](#abbr_KDF) (as described in SP keys and using a [KDF](#abbr_KDF) (as described in SP 800-56C)]{#_s_119 .selectable-content}, [encrypting one key with 800-56C)]{#_s_119 .selectable-content}, [encrypting one key with another]{#_s_120 .selectable-content}\]]{#_s_116 another]{#_s_120 .selectable-content}\]]{#_s_116 .selectable-content} .selectable-content} \]. \]. ::: ::: #### Management: FCS_CKM_EXT.5 #### Management: FCS_CKM_EXT.5 The following actions could be considered for the management functions The following actions could be considered for the management functions in FMT: in FMT: - [TSF](#abbr_TSF) wipe of protected data. - [TSF](#abbr_TSF) wipe of protected data. - [TSF](#abbr_TSF) wipe of enterprise data. - [TSF](#abbr_TSF) wipe of enterprise data. #### Audit: FCS_CKM_EXT.5 #### Audit: FCS_CKM_EXT.5 The following actions should be auditable if FAU_GEN Security audit data The following actions should be auditable if FAU_GEN Security audit data generation is included in the [PP](#abbr_PP), generation is included in the [PP](#abbr_PP), [PP-Module](#abbr_PP-Module), functional package or [ST](#abbr_ST): [PP-Module](#abbr_PP-Module), functional package or [ST](#abbr_ST): - Failure of the wipe. - Failure of the wipe. #### FCS_CKM_EXT.5 TSF Wipe #### FCS_CKM_EXT.5 TSF Wipe ::: {style="margin-left: 1em;"} ::: {style="margin-left: 1em;"} ----------------------------------- ----------------------------------- ----------------------------------- ----------------------------------- Hierarchical to: No other components. Hierarchical to: No other components. Dependencies to: [FCS_CKM.6](#FCS_CKM.6) Timing and Dependencies to: [FCS_CKM.6](#FCS_CKM.6) Timing and Event of Cryptographic Key Event of Cryptographic Key Destruction\ Destruction\ [FCS_RBG.1](#FCS_RBG.1) Random Bit [FCS_RBG.1](#FCS_RBG.1) Random Bit Generation Generation ----------------------------------- ----------------------------------- ----------------------------------- ----------------------------------- #### FCS_CKM_EXT.5.1 {#ext-comp-FCS_CKM_EXT.5.1} #### FCS_CKM_EXT.5.1 {#ext-comp-FCS_CKM_EXT.5.1} The [TSF](#abbr_TSF) shall wipe all protected data by \[**selection**: The [TSF](#abbr_TSF) shall wipe all protected data by \[**selection**: - [Cryptographically erasing the encrypted [DEKs](#abbr_DEK) or the | - [Cryptographically erasing the encrypted DEKs or the KEKs in KEKs in non-volatile memory by following the requirements in | non-volatile memory by following the requirements in [FCS_CKM.6.2](#FCS_CKM.6.2),]{#_s_121 .selectable-content} | [FCS_CKM.6.2](#FCS_CKM.6.2),]{#fcs_ckm_ext.5.1_1 > .selectable-content} - [Overwriting all protected data according to the following rules: - [Overwriting all protected data according to the following rules: ]{#_s_122 .selectable-content} | ]{#fcs_ckm_ext.5.1_2 .selectable-content} - For [EEPROM](#abbr_EEPROM), the destruction shall be executed by - For [EEPROM](#abbr_EEPROM), the destruction shall be executed by a single direct overwrite consisting of a pseudo random pattern a single direct overwrite consisting of a pseudo random pattern using the [TSF](#abbr_TSF)'s DRBG (as specified in using the [TSF](#abbr_TSF)'s DRBG (as specified in [FCS_RBG.1](#FCS_RBG.1)), followed by a read-verify. [FCS_RBG.1](#FCS_RBG.1)), followed by a read-verify. - For flash memory, that is not wear-leveled, the destruction - For flash memory, that is not wear-leveled, the destruction shall be executed \[**selection**: [by a single direct overwrite shall be executed \[**selection**: [by a single direct overwrite consisting of zeros followed by a read-verify]{#_s_123 | consisting of zeros followed by a .selectable-content}, [by a block erase that erases the | read-verify]{#fcs_ckm_ext.5.1_3 .selectable-content}, [by a reference to memory that stores data as well as the data | block erase that erases the reference to memory that stores data itself]{#_s_124 .selectable-content}\]. | as well as the data itself]{#fcs_ckm_ext.5.1_4 > .selectable-content}\]. - For flash memory, that is wear-leveled, the destruction shall be - For flash memory, that is wear-leveled, the destruction shall be executed \[**selection**: [by a single direct overwrite executed \[**selection**: [by a single direct overwrite consisting of zeros]{#_s_125 .selectable-content}, [by a block | consisting of zeros]{#fcs_ckm_ext.5.1_5 .selectable-content}, erase]{#_s_126 .selectable-content}\]. | [by a block erase]{#fcs_ckm_ext.5.1_6 .selectable-content}\]. - For non-volatile memory other than [EEPROM](#abbr_EEPROM) and - For non-volatile memory other than [EEPROM](#abbr_EEPROM) and flash, the destruction shall be executed by a single direct flash, the destruction shall be executed by a single direct overwrite with a random pattern that is changed before each overwrite with a random pattern that is changed before each write. write. \]. \]. #### FCS_CKM_EXT.5.2 {#ext-comp-FCS_CKM_EXT.5.2} #### FCS_CKM_EXT.5.2 {#ext-comp-FCS_CKM_EXT.5.2} The [TSF](#abbr_TSF) shall perform a power cycle on conclusion of the The [TSF](#abbr_TSF) shall perform a power cycle on conclusion of the wipe procedure. wipe procedure. ::: ::: #### Management: FCS_CKM_EXT.6 #### Management: FCS_CKM_EXT.6 There are no management activities foreseen. There are no management activities foreseen. #### Audit: FCS_CKM_EXT.6 #### Audit: FCS_CKM_EXT.6 There are no auditable events foreseen. There are no auditable events foreseen. #### FCS_CKM_EXT.6 Salt Generation #### FCS_CKM_EXT.6 Salt Generation ::: {style="margin-left: 1em;"} ::: {style="margin-left: 1em;"} ------------------ ----------------------------------------------- ------------------ ----------------------------------------------- Hierarchical to: No other components. Hierarchical to: No other components. Dependencies to: [FCS_RBG.1](#FCS_RBG.1) Random Bit Generation Dependencies to: [FCS_RBG.1](#FCS_RBG.1) Random Bit Generation ------------------ ----------------------------------------------- ------------------ ----------------------------------------------- #### FCS_CKM_EXT.6.1 {#ext-comp-FCS_CKM_EXT.6.1} #### FCS_CKM_EXT.6.1 {#ext-comp-FCS_CKM_EXT.6.1} The [TSF](#abbr_TSF) shall generate all salts using a DRBG that meets The [TSF](#abbr_TSF) shall generate all salts using a DRBG that meets [FCS_RBG.1](#FCS_RBG.1). [FCS_RBG.1](#FCS_RBG.1). ::: ::: #### Management: FCS_CKM_EXT.7 #### Management: FCS_CKM_EXT.7 There are no management functions foreseen. There are no management functions foreseen. #### Audit: FCS_CKM_EXT.7 #### Audit: FCS_CKM_EXT.7 The following actions should be auditable if FAU_GEN Security audit data The following actions should be auditable if FAU_GEN Security audit data generation is included in the [PP](#abbr_PP), generation is included in the [PP](#abbr_PP), [PP-Module](#abbr_PP-Module), functional package or [ST](#abbr_ST):\ [PP-Module](#abbr_PP-Module), functional package or [ST](#abbr_ST):\ - minimal: Success and failure of the activity; - minimal: Success and failure of the activity; - basic: The object attribute(s), and object value(s) excluding any - basic: The object attribute(s), and object value(s) excluding any sensitive information. sensitive information. #### FCS_CKM_EXT.7 Cryptographic Key Establishment #### FCS_CKM_EXT.7 Cryptographic Key Establishment ::: {style="margin-left: 1em;"} ::: {style="margin-left: 1em;"} ----------------------------------- ----------------------------------- ----------------------------------- ----------------------------------- Hierarchical to: No other components. Hierarchical to: No other components. Dependencies to: \ Dependencies to: \ \ \ \[FDP_ITC.1 Import of User Data \[FDP_ITC.1 Import of User Data without Security Attributes, or\ without Security Attributes, or\ FDP_ITC.2 Import of User Data with FDP_ITC.2 Import of User Data with Security Attributes, or\ Security Attributes, or\ FCS_CKM.1 Cryptographic Key FCS_CKM.1 Cryptographic Key Generation, or\ Generation, or\ FCS_CKM.5 Cryptographic Key FCS_CKM.5 Cryptographic Key Derivation, or\ Derivation, or\ [FCS_CKM_EXT.8](#FCS_CKM_EXT.8) [FCS_CKM_EXT.8](#FCS_CKM_EXT.8) Password-Based Key Derivation\],\ Password-Based Key Derivation\],\ \[FCS_CKM_EXT.7 Cryptographic Key \[FCS_CKM_EXT.7 Cryptographic Key Distribution, or\ Distribution, or\ FCS_COP.1 Cryptographic FCS_COP.1 Cryptographic Operation\]\ Operation\]\ [FCS_CKM.6](#FCS_CKM.6) Timing and [FCS_CKM.6](#FCS_CKM.6) Timing and Event of Cryptographic Key Event of Cryptographic Key Destruction\ Destruction\ FCS_COP.1 Cryptographic Operation FCS_COP.1 Cryptographic Operation ----------------------------------- ----------------------------------- ----------------------------------- ----------------------------------- #### FCS_CKM_EXT.7.1 {#ext-comp-FCS_CKM_EXT.7.1} #### FCS_CKM_EXT.7.1 {#ext-comp-FCS_CKM_EXT.7.1} The [TSF](#abbr_TSF) shall derive shared cryptographic keys with input The [TSF](#abbr_TSF) shall derive shared cryptographic keys with input from multiple parties in accordance with specified cryptographic key from multiple parties in accordance with specified cryptographic key agreement algorithms \[**assignment**: [cryptographic agreement algorithms \[**assignment**: [cryptographic algorithm]{.assignable-content}\] and specified cryptographic parameters algorithm]{.assignable-content}\] and specified cryptographic parameters \[**assignment**: [cryptographic parameters]{.assignable-content}\] that \[**assignment**: [cryptographic parameters]{.assignable-content}\] that meet the following: \[**assignment**: [list of meet the following: \[**assignment**: [list of standards]{.assignable-content}\]. standards]{.assignable-content}\]. ::: ::: #### Management: FCS_CKM_EXT.8 #### Management: FCS_CKM_EXT.8 There are no management functions foreseen. There are no management functions foreseen. #### Audit: FCS_CKM_EXT.8 #### Audit: FCS_CKM_EXT.8 The following actions should be auditable if FAU_GEN Security audit data The following actions should be auditable if FAU_GEN Security audit data generation is included in the [PP](#abbr_PP), generation is included in the [PP](#abbr_PP), [PP-Module](#abbr_PP-Module), functional package or [ST](#abbr_ST):\ [PP-Module](#abbr_PP-Module), functional package or [ST](#abbr_ST):\ - minimal: Success and failure of the activity; - minimal: Success and failure of the activity; - basic: The object attribute(s), and object value(s) excluding any - basic: The object attribute(s), and object value(s) excluding any sensitive information. sensitive information. #### FCS_CKM_EXT.8 Password-Based Key Derivation #### FCS_CKM_EXT.8 Password-Based Key Derivation ::: {style="margin-left: 1em;"} ::: {style="margin-left: 1em;"} ----------------------------------- ----------------------------------- ----------------------------------- ----------------------------------- Hierarchical to: No other components. Hierarchical to: No other components. Dependencies to: \ Dependencies to: \ \ \ \[[FCS_CKM.2](#FCS_CKM.2) \[[FCS_CKM.2](#FCS_CKM.2) Cryptographic Key Distribution, or\ Cryptographic Key Distribution, or\ FCS_COP.1 Cryptographic FCS_COP.1 Cryptographic Operation\]\ Operation\]\ FCS_CKM_EXT.7 Cryptographic Key FCS_CKM_EXT.7 Cryptographic Key Establishment\],\ Establishment\],\ [FCS_CKM.6](#FCS_CKM.6) Timing and [FCS_CKM.6](#FCS_CKM.6) Timing and Event of Cryptographic Key Event of Cryptographic Key Destruction Destruction ----------------------------------- ----------------------------------- ----------------------------------- ----------------------------------- #### FCS_CKM_EXT.8.1 {#ext-comp-FCS_CKM_EXT.8.1} #### FCS_CKM_EXT.8.1 {#ext-comp-FCS_CKM_EXT.8.1} The [TSF](#abbr_TSF) shall perform password-based key derivation The [TSF](#abbr_TSF) shall perform password-based key derivation functions in accordance with a specified cryptographic algorithm functions in accordance with a specified cryptographic algorithm \[[HMAC](#abbr_HMAC)-\[**selection**: [[SHA](#abbr_SHA)-384]{#_s_168 | \[[HMAC](#abbr_HMAC)- \[**selection**: .selectable-content}, [[SHA](#abbr_SHA)-512]{#_s_169 | [[SHA](#abbr_SHA)-384]{#fcs_ckm_ext.8.1_1 .selectable-content}, .selectable-content}\], with iteration count of \[**assignment**: | [[SHA](#abbr_SHA)-512]{#fcs_ckm_ext.8.1_2 .selectable-content}\], with [number of iterations]{.assignable-content}\] using a randomly generated | iteration count of \[**assignment**: [number of salt of length \[**assignment**: [equal to or greater than | iterations]{.assignable-content}\] using a randomly generated salt of > length \[**assignment**: [equal to or greater than 128]{.assignable-content}\] and output cryptographic key sizes 128]{.assignable-content}\] and output cryptographic key sizes \[**selection**: [256]{#_s_170 .selectable-content}, [384]{#_s_171 | \[**selection**: [256]{#fcs_ckm_ext.8.1_5 .selectable-content}, .selectable-content}, [512]{#_s_172 .selectable-content}\] bits that | [384]{#fcs_ckm_ext.8.1_6 .selectable-content}, [512]{#fcs_ckm_ext.8.1_7 meet the following standard: \[[NIST](#abbr_NIST) SP 800-132 (Section | .selectable-content}\] bits that meet the following standard: 5.3) \[PBKDF2\]\]. | \[[NIST](#abbr_NIST) SP 800-132 (Section 5.3) \[PBKDF2\]\]. ::: ::: #### Management: FCS_CKM_EXT.9 #### Management: FCS_CKM_EXT.9 There are no management functions foreseen. There are no management functions foreseen. #### Audit: FCS_CKM_EXT.9 #### Audit: FCS_CKM_EXT.9 There are no audit events foreseen. There are no audit events foreseen. #### FCS_CKM_EXT.9 Hardware Key Confidentiality #### FCS_CKM_EXT.9 Hardware Key Confidentiality ::: {style="margin-left: 1em;"} ::: {style="margin-left: 1em;"} ------------------ ----------------------------------------------------------- ------------------ ----------------------------------------------------------- Hierarchical to: No other components. Hierarchical to: No other components. Dependencies to: [FCS_CKM_EXT.1](#FCS_CKM_EXT.1) Cryptographic Key Support Dependencies to: [FCS_CKM_EXT.1](#FCS_CKM_EXT.1) Cryptographic Key Support ------------------ ----------------------------------------------------------- ------------------ ----------------------------------------------------------- #### FCS_CKM_EXT.9.1 {#ext-comp-FCS_CKM_EXT.9.1} #### FCS_CKM_EXT.9.1 {#ext-comp-FCS_CKM_EXT.9.1} A \[**assignment**: [key, type of keys, or list of A \[**assignment**: [key, type of keys, or list of keys]{.assignable-content}\] shall not be able to be read from or keys]{.assignable-content}\] shall not be able to be read from or exported from hardware. exported from hardware. ::: ::: ::: ::: ### C.2.1.2 FCS_HTTPS_EXT HTTPS Protocol {#ext-comp-FCS_HTTPS_EXT .indexable level="4 ### C.2.1.2 FCS_HTTPS_EXT HTTPS Protocol {#ext-comp-FCS_HTTPS_EXT .indexable level="4 ::: {style="margin-left: 1em;"} ::: {style="margin-left: 1em;"} #### Family Behavior #### Family Behavior
This family defines requirements for implementation of the This family defines requirements for implementation of the [HTTPS](#abbr_HTTPS) protocol. [HTTPS](#abbr_HTTPS) protocol.
#### Component Leveling #### Component Leveling ![](data:image/svg+xml;base64,PHN2ZyBzdHlsZT0ibWF4LWhlaWdodDogMzBweDsiPjx0ZXh0IHg9IjQ ![](data:image/svg+xml;base64,PHN2ZyBzdHlsZT0ibWF4LWhlaWdodDogMzBweDsiPjx0ZXh0IHg9IjQ [FCS_HTTPS_EXT.1](#FCS_HTTPS_EXT.1), [HTTPS](#abbr_HTTPS) Protocol, [FCS_HTTPS_EXT.1](#FCS_HTTPS_EXT.1), [HTTPS](#abbr_HTTPS) Protocol, requires the [TSF](#abbr_TSF) to implement the [HTTPS](#abbr_HTTPS) requires the [TSF](#abbr_TSF) to implement the [HTTPS](#abbr_HTTPS) protocol in accordance with the specified standard, using protocol in accordance with the specified standard, using [TLS](#abbr_TLS), and notifying the application if invalid. [TLS](#abbr_TLS), and notifying the application if invalid. #### Management: FCS_HTTPS_EXT.1 #### Management: FCS_HTTPS_EXT.1 The following actions could be considered for the management functions The following actions could be considered for the management functions in FMT: in FMT: - Configuring whether to allow or disallow establishment of a trusted - Configuring whether to allow or disallow establishment of a trusted channel if the peer or server certificate is deemed invalid. channel if the peer or server certificate is deemed invalid. #### Audit: FCS_HTTPS_EXT.1 #### Audit: FCS_HTTPS_EXT.1 The following actions should be auditable if FAU_GEN Security audit data The following actions should be auditable if FAU_GEN Security audit data generation is included in the [PP](#abbr_PP), generation is included in the [PP](#abbr_PP), [PP-Module](#abbr_PP-Module), functional package or [ST](#abbr_ST): [PP-Module](#abbr_PP-Module), functional package or [ST](#abbr_ST): - Failure of the certificate validity check. - Failure of the certificate validity check. #### FCS_HTTPS_EXT.1 HTTPS Protocol #### FCS_HTTPS_EXT.1 HTTPS Protocol ::: {style="margin-left: 1em;"} ::: {style="margin-left: 1em;"} ----------------------------------- ----------------------------------- ----------------------------------- ----------------------------------- Hierarchical to: No other components. Hierarchical to: No other components. Dependencies to: FCS_TLS_EXT.1 [TLS](#abbr_TLS) Dependencies to: FCS_TLS_EXT.1 [TLS](#abbr_TLS) Protocol\ Protocol\ FIA_X509_EXT.1 X.509 Validation of FIA_X509_EXT.1 X.509 Validation of Certificates Certificates ----------------------------------- ----------------------------------- ----------------------------------- ----------------------------------- #### FCS_HTTPS_EXT.1.1 {#ext-comp-FCS_HTTPS_EXT.1.1} #### FCS_HTTPS_EXT.1.1 {#ext-comp-FCS_HTTPS_EXT.1.1} The [TSF](#abbr_TSF) shall implement the [HTTPS](#abbr_HTTPS) protocol The [TSF](#abbr_TSF) shall implement the [HTTPS](#abbr_HTTPS) protocol that complies with RFC 2818. that complies with RFC 2818. #### FCS_HTTPS_EXT.1.2 {#ext-comp-FCS_HTTPS_EXT.1.2} #### FCS_HTTPS_EXT.1.2 {#ext-comp-FCS_HTTPS_EXT.1.2} The [TSF](#abbr_TSF) shall implement [HTTPS](#abbr_HTTPS) using The [TSF](#abbr_TSF) shall implement [HTTPS](#abbr_HTTPS) using [TLS](#abbr_TLS) as defined in \[**assignment**: [specification that [TLS](#abbr_TLS) as defined in \[**assignment**: [specification that defines [TLS](#abbr_TLS) implementation defines [TLS](#abbr_TLS) implementation requirements]{.assignable-content}\]. requirements]{.assignable-content}\]. #### FCS_HTTPS_EXT.1.3 {#ext-comp-FCS_HTTPS_EXT.1.3} #### FCS_HTTPS_EXT.1.3 {#ext-comp-FCS_HTTPS_EXT.1.3} The [TSF](#abbr_TSF) shall notify the application and \[**assignment**: The [TSF](#abbr_TSF) shall notify the application and \[**assignment**: [a response]{.assignable-content}\] if the peer certificate is deemed [a response]{.assignable-content}\] if the peer certificate is deemed invalid. invalid. ::: ::: ::: ::: ### C.2.1.3 FCS_IV_EXT Initialization Vector Generation {#ext-comp-FCS_IV_EXT .indexa ### C.2.1.3 FCS_IV_EXT Initialization Vector Generation {#ext-comp-FCS_IV_EXT .indexa ::: {style="margin-left: 1em;"} ::: {style="margin-left: 1em;"} #### Family Behavior #### Family Behavior
This family defines requirements for initialization vector generation in This family defines requirements for initialization vector generation in support of key generation. support of key generation.
#### Component Leveling #### Component Leveling ![](data:image/svg+xml;base64,PHN2ZyBzdHlsZT0ibWF4LWhlaWdodDogMzBweDsiPjx0ZXh0IHg9IjQ ![](data:image/svg+xml;base64,PHN2ZyBzdHlsZT0ibWF4LWhlaWdodDogMzBweDsiPjx0ZXh0IHg9IjQ [FCS_IV_EXT.1](#FCS_IV_EXT.1), Initialization Vector Generation, [FCS_IV_EXT.1](#FCS_IV_EXT.1), Initialization Vector Generation, requires the [TSF](#abbr_TSF) to generate IVs in accordance with a set requires the [TSF](#abbr_TSF) to generate IVs in accordance with a set of approved modes. of approved modes. #### Management: FCS_IV_EXT.1 #### Management: FCS_IV_EXT.1 There are no management activities foreseen. There are no management activities foreseen. #### Audit: FCS_IV_EXT.1 #### Audit: FCS_IV_EXT.1 There are no auditable events foreseen. There are no auditable events foreseen. #### FCS_IV_EXT.1 Initialization Vector Generation #### FCS_IV_EXT.1 Initialization Vector Generation ::: {style="margin-left: 1em;"} ::: {style="margin-left: 1em;"} ------------------ ---------------------- ------------------ ---------------------- Hierarchical to: No other components. Hierarchical to: No other components. Dependencies to: No dependencies. Dependencies to: No dependencies. ------------------ ---------------------- ------------------ ---------------------- #### FCS_IV_EXT.1.1 {#ext-comp-FCS_IV_EXT.1.1} #### FCS_IV_EXT.1.1 {#ext-comp-FCS_IV_EXT.1.1} The [TSF](#abbr_TSF) shall generate IVs in accordance with The [TSF](#abbr_TSF) shall generate IVs in accordance with \[**assignment**: [standard or specification for IV \[**assignment**: [standard or specification for IV generation]{.assignable-content}\]. generation]{.assignable-content}\]. ::: ::: ::: ::: ### C.2.1.4 FCS_RBG_EXT Random Bit Generation {#ext-comp-FCS_RBG_EXT .indexable level ### C.2.1.4 FCS_RBG_EXT Random Bit Generation {#ext-comp-FCS_RBG_EXT .indexable level ::: {style="margin-left: 1em;"} ::: {style="margin-left: 1em;"} #### Family Behavior #### Family Behavior
This family defines requirements for the generation of random bits. This family defines requirements for the generation of random bits.
#### Component Leveling #### Component Leveling ![](data:image/svg+xml;base64,PHN2ZyBzdHlsZT0ibWF4LWhlaWdodDogNTBweDsiPjx0ZXh0IHg9IjQ ![](data:image/svg+xml;base64,PHN2ZyBzdHlsZT0ibWF4LWhlaWdodDogNTBweDsiPjx0ZXh0IHg9IjQ [FCS_RBG_EXT.2](#FCS_RBG_EXT.2), Random Bit Generator State [FCS_RBG_EXT.2](#FCS_RBG_EXT.2), Random Bit Generator State Preservation, requires the [TSF](#abbr_TSF) to save and restore the Preservation, requires the [TSF](#abbr_TSF) to save and restore the state of the DRBG when powering off and starting up. state of the DRBG when powering off and starting up. [FCS_RBG_EXT.3](#FCS_RBG_EXT.3), Support for Personalization String, [FCS_RBG_EXT.3](#FCS_RBG_EXT.3), Support for Personalization String, requires the [TSF](#abbr_TSF) to support a personalization string as a requires the [TSF](#abbr_TSF) to support a personalization string as a DRBG input parameter. DRBG input parameter. #### Management: FCS_RBG_EXT.2 #### Management: FCS_RBG_EXT.2 There are no management activities foreseen. There are no management activities foreseen. #### Audit: FCS_RBG_EXT.2 #### Audit: FCS_RBG_EXT.2 There are no auditable events foreseen. There are no auditable events foreseen. #### FCS_RBG_EXT.2 Random Bit Generator State Preservation #### FCS_RBG_EXT.2 Random Bit Generator State Preservation ::: {style="margin-left: 1em;"} ::: {style="margin-left: 1em;"} ------------------ ----------------------------------------------- ------------------ ----------------------------------------------- Hierarchical to: No other components. Hierarchical to: No other components. Dependencies to: [FCS_RBG.1](#FCS_RBG.1) Random Bit Generation Dependencies to: [FCS_RBG.1](#FCS_RBG.1) Random Bit Generation ------------------ ----------------------------------------------- ------------------ ----------------------------------------------- #### FCS_RBG_EXT.2.1 {#ext-comp-FCS_RBG_EXT.2.1} #### FCS_RBG_EXT.2.1 {#ext-comp-FCS_RBG_EXT.2.1} The [TSF](#abbr_TSF) shall save the state of the DRBG at power-off, and The [TSF](#abbr_TSF) shall save the state of the DRBG at power-off, and shall use this state as input to the DRBG at startup. shall use this state as input to the DRBG at startup. ::: ::: #### Management: FCS_RBG_EXT.3 #### Management: FCS_RBG_EXT.3 There are no management activities foreseen. There are no management activities foreseen. #### Audit: FCS_RBG_EXT.3 #### Audit: FCS_RBG_EXT.3 There are no auditable events foreseen. There are no auditable events foreseen. #### FCS_RBG_EXT.3 Support for Personalization String #### FCS_RBG_EXT.3 Support for Personalization String ::: {style="margin-left: 1em;"} ::: {style="margin-left: 1em;"} ------------------ ----------------------------------------------- ------------------ ----------------------------------------------- Hierarchical to: No other components. Hierarchical to: No other components. Dependencies to: [FCS_RBG.1](#FCS_RBG.1) Random Bit Generation Dependencies to: [FCS_RBG.1](#FCS_RBG.1) Random Bit Generation ------------------ ----------------------------------------------- ------------------ ----------------------------------------------- #### FCS_RBG_EXT.3.1 {#ext-comp-FCS_RBG_EXT.3.1} #### FCS_RBG_EXT.3.1 {#ext-comp-FCS_RBG_EXT.3.1} The [TSF](#abbr_TSF) shall allow applications to add data to the DRBG The [TSF](#abbr_TSF) shall allow applications to add data to the DRBG using the Personalization String as defined in SP 800-90A. using the Personalization String as defined in SP 800-90A. ::: ::: ::: ::: ### C.2.1.5 FCS_SRV_EXT Cryptographic Algorithm Services {#ext-comp-FCS_SRV_EXT .inde ### C.2.1.5 FCS_SRV_EXT Cryptographic Algorithm Services {#ext-comp-FCS_SRV_EXT .inde ::: {style="margin-left: 1em;"} ::: {style="margin-left: 1em;"} #### Family Behavior #### Family Behavior
This family defines requirements for the ability of the [TOE](#abbr_TOE) This family defines requirements for the ability of the [TOE](#abbr_TOE) to make its cryptographic operations available to non-TSF components. to make its cryptographic operations available to non-TSF components.
#### Component Leveling #### Component Leveling ![](data:image/svg+xml;base64,PHN2ZyBzdHlsZT0ibWF4LWhlaWdodDogNTBweDsiPjx0ZXh0IHg9IjQ ![](data:image/svg+xml;base64,PHN2ZyBzdHlsZT0ibWF4LWhlaWdodDogNTBweDsiPjx0ZXh0IHg9IjQ [FCS_SRV_EXT.1](#FCS_SRV_EXT.1), Cryptographic Algorithm Services, [FCS_SRV_EXT.1](#FCS_SRV_EXT.1), Cryptographic Algorithm Services, requires the [TSF](#abbr_TSF) to have externally-accessible requires the [TSF](#abbr_TSF) to have externally-accessible cryptographic services for making algorithm functions available to cryptographic services for making algorithm functions available to applications. applications. [FCS_SRV_EXT.2](#FCS_SRV_EXT.2), Cryptographic Key Storage Services, [FCS_SRV_EXT.2](#FCS_SRV_EXT.2), Cryptographic Key Storage Services, requires the [TSF](#abbr_TSF) to support its stored keys being usable by requires the [TSF](#abbr_TSF) to support its stored keys being usable by external applications through cryptographic algorithm services. external applications through cryptographic algorithm services. #### Management: FCS_SRV_EXT.1 #### Management: FCS_SRV_EXT.1 There are no management activities foreseen. There are no management activities foreseen. #### Audit: FCS_SRV_EXT.1 #### Audit: FCS_SRV_EXT.1 There are no auditable events foreseen. There are no auditable events foreseen. #### FCS_SRV_EXT.1 Cryptographic Algorithm Services #### FCS_SRV_EXT.1 Cryptographic Algorithm Services ::: {style="margin-left: 1em;"} ::: {style="margin-left: 1em;"} ----------------------------------- ----------------------------------- ----------------------------------- ----------------------------------- Hierarchical to: No other components. Hierarchical to: No other components. Dependencies to: FCS_CKM.1 Cryptographic Key Dependencies to: FCS_CKM.1 Cryptographic Key Generation\ Generation\ FCS_COP.1 Cryptographic Operation FCS_COP.1 Cryptographic Operation ----------------------------------- ----------------------------------- ----------------------------------- ----------------------------------- #### FCS_SRV_EXT.1.1 {#ext-comp-FCS_SRV_EXT.1.1} #### FCS_SRV_EXT.1.1 {#ext-comp-FCS_SRV_EXT.1.1} The [TSF](#abbr_TSF) shall provide a mechanism for applications to The [TSF](#abbr_TSF) shall provide a mechanism for applications to request the [TSF](#abbr_TSF) to perform the following cryptographic request the [TSF](#abbr_TSF) to perform the following cryptographic operations: \[**assignment**: [cryptographic operations: \[**assignment**: [cryptographic functions]{.assignable-content}\]. functions]{.assignable-content}\]. ::: ::: #### Management: FCS_SRV_EXT.2 #### Management: FCS_SRV_EXT.2 There are no management activities foreseen. There are no management activities foreseen. #### Audit: FCS_SRV_EXT.2 #### Audit: FCS_SRV_EXT.2 There are no auditable events foreseen. There are no auditable events foreseen. #### FCS_SRV_EXT.2 Cryptographic Key Storage Services #### FCS_SRV_EXT.2 Cryptographic Key Storage Services ::: {style="margin-left: 1em;"} ::: {style="margin-left: 1em;"} ------------------ ----------------------------------- ------------------ ----------------------------------- Hierarchical to: No other components. Hierarchical to: No other components. Dependencies to: FCS_COP.1 Cryptographic Operation Dependencies to: FCS_COP.1 Cryptographic Operation ------------------ ----------------------------------- ------------------ ----------------------------------- #### FCS_SRV_EXT.2.1 {#ext-comp-FCS_SRV_EXT.2.1} #### FCS_SRV_EXT.2.1 {#ext-comp-FCS_SRV_EXT.2.1} The [TSF](#abbr_TSF) shall provide a mechanism for applications to The [TSF](#abbr_TSF) shall provide a mechanism for applications to request the [TSF](#abbr_TSF) to perform the following cryptographic request the [TSF](#abbr_TSF) to perform the following cryptographic operations: \[**assignment**: [cryptographic operations defined by the operations: \[**assignment**: [cryptographic operations defined by the [TSF](#abbr_TSF) in FCS_COP.1]{.assignable-content}\] by keys stored in [TSF](#abbr_TSF) in FCS_COP.1]{.assignable-content}\] by keys stored in the secure key storage. the secure key storage. ::: ::: ::: ::: ### C.2.1.6 FCS_STG_EXT Cryptographic Key Storage {#ext-comp-FCS_STG_EXT .indexable l ### C.2.1.6 FCS_STG_EXT Cryptographic Key Storage {#ext-comp-FCS_STG_EXT .indexable l ::: {style="margin-left: 1em;"} ::: {style="margin-left: 1em;"} #### Family Behavior #### Family Behavior
This family defines requirements for the implementation of secure key This family defines requirements for the implementation of secure key storage with access control, confidentiality, and integrity protections. storage with access control, confidentiality, and integrity protections.
#### Component Leveling #### Component Leveling ![](data:image/svg+xml;base64,PHN2ZyBzdHlsZT0ibWF4LWhlaWdodDogNzBweDsiPjx0ZXh0IHg9IjQ ![](data:image/svg+xml;base64,PHN2ZyBzdHlsZT0ibWF4LWhlaWdodDogNzBweDsiPjx0ZXh0IHg9IjQ [FCS_STG_EXT.1](#FCS_STG_EXT.1), Cryptographic Key Storage, requires the [FCS_STG_EXT.1](#FCS_STG_EXT.1), Cryptographic Key Storage, requires the [TSF](#abbr_TSF) to implement a secure key storage and defines the [TSF](#abbr_TSF) to implement a secure key storage and defines the access restrictions to be enforced on this. access restrictions to be enforced on this. [FCS_STG_EXT.2](#FCS_STG_EXT.2), Encrypted Cryptographic Key Storage, [FCS_STG_EXT.2](#FCS_STG_EXT.2), Encrypted Cryptographic Key Storage, requires the [TSF](#abbr_TSF) to implement confidentiality measures to requires the [TSF](#abbr_TSF) to implement confidentiality measures to protect the key storage. protect the key storage. [FCS_STG_EXT.3](#FCS_STG_EXT.3), Integrity of Encrypted Key Storage, [FCS_STG_EXT.3](#FCS_STG_EXT.3), Integrity of Encrypted Key Storage, requires the [TSF](#abbr_TSF) to implement integrity measures to protect requires the [TSF](#abbr_TSF) to implement integrity measures to protect the key storage. the key storage. #### Management: FCS_STG_EXT.1 #### Management: FCS_STG_EXT.1 The following actions could be considered for the management functions The following actions could be considered for the management functions in FMT: in FMT: - Importing keys or secrets into the secure key storage. - Importing keys or secrets into the secure key storage. - Destroying imported keys or secrets in the secure key storage. - Destroying imported keys or secrets in the secure key storage. - Approving exceptions for shared use of keys or secrets by multiple - Approving exceptions for shared use of keys or secrets by multiple applications. applications. - Approving exceptions for destruction of keys or secrets by - Approving exceptions for destruction of keys or secrets by applications that did not import the key or secret applications that did not import the key or secret #### Audit: FCS_STG_EXT.1 #### Audit: FCS_STG_EXT.1 The following actions should be auditable if FAU_GEN Security audit data The following actions should be auditable if FAU_GEN Security audit data generation is included in the [PP](#abbr_PP), generation is included in the [PP](#abbr_PP), [PP-Module](#abbr_PP-Module), functional package or [ST](#abbr_ST): [PP-Module](#abbr_PP-Module), functional package or [ST](#abbr_ST): - Import or destruction of key. - Import or destruction of key. - Exceptions to use and destruction rules. - Exceptions to use and destruction rules. #### FCS_STG_EXT.1 Cryptographic Key Storage #### FCS_STG_EXT.1 Cryptographic Key Storage ::: {style="margin-left: 1em;"} ::: {style="margin-left: 1em;"} ----------------------------------- ----------------------------------- ----------------------------------- ----------------------------------- Hierarchical to: No other components. Hierarchical to: No other components. Dependencies to: \[FCS_CKM.1 Cryptographic Key Dependencies to: \[FCS_CKM.1 Cryptographic Key Generation, or\ Generation, or\ FDP_ITC.1 Import of User Data FDP_ITC.1 Import of User Data without Security Attributes, or\ without Security Attributes, or\ FDP_ITC.2 Import of User Data with FDP_ITC.2 Import of User Data with Security Attributes\]\ Security Attributes\]\ FMT_SMF.1 Specification of FMT_SMF.1 Specification of Management Functions\ Management Functions\ FMT_SMR.1 Security Roles FMT_SMR.1 Security Roles ----------------------------------- ----------------------------------- ----------------------------------- ----------------------------------- #### FCS_STG_EXT.1.1 {#ext-comp-FCS_STG_EXT.1.1} #### FCS_STG_EXT.1.1 {#ext-comp-FCS_STG_EXT.1.1} The [TSF](#abbr_TSF) shall provide \[**assignment**: [storage The [TSF](#abbr_TSF) shall provide \[**assignment**: [storage medium]{.assignable-content}\] secure key storage for asymmetric private medium]{.assignable-content}\] secure key storage for asymmetric private keys and \[**assignment**: [list of secrets]{.assignable-content}\] . | keys and \[**assignment**: [list of secrets]{.assignable-content}\]. #### FCS_STG_EXT.1.2 {#ext-comp-FCS_STG_EXT.1.2} #### FCS_STG_EXT.1.2 {#ext-comp-FCS_STG_EXT.1.2} The [TSF](#abbr_TSF) shall be capable of importing keys or secrets into The [TSF](#abbr_TSF) shall be capable of importing keys or secrets into the secure key storage upon request of \[**assignment**: [list of the secure key storage upon request of \[**assignment**: [list of users]{.assignable-content}\] and \[**assignment**: [list of other users]{.assignable-content}\] and \[**assignment**: [list of other subjects]{.assignable-content}\]. subjects]{.assignable-content}\]. #### FCS_STG_EXT.1.3 {#ext-comp-FCS_STG_EXT.1.3} #### FCS_STG_EXT.1.3 {#ext-comp-FCS_STG_EXT.1.3} The [TSF](#abbr_TSF) shall be capable of destroying keys or secrets in The [TSF](#abbr_TSF) shall be capable of destroying keys or secrets in the secure key storage upon request of \[**selection**: [the the secure key storage upon request of \[**selection**: [the user]{#_s_410 .selectable-content}, [the administrator]{#_s_411 | user]{#fcs_stg_ext.1.3_1 .selectable-content}, [the .selectable-content}\]. | administrator]{#fcs_stg_ext.1.3_2 .selectable-content}\]. #### FCS_STG_EXT.1.4 {#ext-comp-FCS_STG_EXT.1.4} #### FCS_STG_EXT.1.4 {#ext-comp-FCS_STG_EXT.1.4} The [TSF](#abbr_TSF) shall have the capability to allow only the The [TSF](#abbr_TSF) shall have the capability to allow only the application that imported the key or secret the use of the key or application that imported the key or secret the use of the key or secret. Exceptions may only be explicitly authorized by \[**selection**: secret. Exceptions may only be explicitly authorized by \[**selection**: [the user]{#_s_412 .selectable-content}, [the administrator]{#_s_413 | [the user]{#fcs_stg_ext.1.4_1 .selectable-content}, [the .selectable-content}, [a common application developer]{#_s_414 | administrator]{#fcs_stg_ext.1.4_2 .selectable-content}, [a common .selectable-content}\]. | application developer]{#fcs_stg_ext.1.4_3 .selectable-content}\]. #### FCS_STG_EXT.1.5 {#ext-comp-FCS_STG_EXT.1.5} #### FCS_STG_EXT.1.5 {#ext-comp-FCS_STG_EXT.1.5} The [TSF](#abbr_TSF) shall allow only the application that imported the The [TSF](#abbr_TSF) shall allow only the application that imported the key or secret to request that the key or secret be destroyed. Exceptions key or secret to request that the key or secret be destroyed. Exceptions may only be explicitly authorized by \[**assignment**: [list of may only be explicitly authorized by \[**assignment**: [list of subjects]{.assignable-content}\]. subjects]{.assignable-content}\]. ::: ::: #### Management: FCS_STG_EXT.2 #### Management: FCS_STG_EXT.2 There are no management activities foreseen. There are no management activities foreseen. #### Audit: FCS_STG_EXT.2 #### Audit: FCS_STG_EXT.2 There are no auditable events foreseen. There are no auditable events foreseen. #### FCS_STG_EXT.2 Encrypted Cryptographic Key Storage #### FCS_STG_EXT.2 Encrypted Cryptographic Key Storage ::: {style="margin-left: 1em;"} ::: {style="margin-left: 1em;"} ----------------------------------- ----------------------------------- ----------------------------------- ----------------------------------- Hierarchical to: No other components. Hierarchical to: No other components. Dependencies to: [FCS_CKM_EXT.3](#FCS_CKM_EXT.3) Dependencies to: [FCS_CKM_EXT.3](#FCS_CKM_EXT.3) Cryptographic Key Generation\ Cryptographic Key Generation\ FCS_COP.1 Cryptographic Operation\ FCS_COP.1 Cryptographic Operation\ [FCS_STG_EXT.1](#FCS_STG_EXT.1) [FCS_STG_EXT.1](#FCS_STG_EXT.1) Cryptographic Key Storage Cryptographic Key Storage ----------------------------------- ----------------------------------- ----------------------------------- ----------------------------------- #### FCS_STG_EXT.2.1 {#ext-comp-FCS_STG_EXT.2.1} #### FCS_STG_EXT.2.1 {#ext-comp-FCS_STG_EXT.2.1} The [TSF](#abbr_TSF) shall encrypt all [DEKs](#abbr_DEK), KEKs, | The [TSF](#abbr_TSF) shall encrypt all DEKs, KEKs, \[**assignment**: \[**assignment**: [any long-term trusted channel key | [any long-term trusted channel key material]{.assignable-content}\] and material]{.assignable-content}\] and \[**assignment**: [other secrets | \[**assignment**: [other secrets]{.assignable-content}\] by KEKs that ]{.assignable-content}\] by KEKs that are \[**assignment**: [protection | are \[**assignment**: [protection mechanism]{.assignable-content}\]. mechanism]{.assignable-content}\]. < #### FCS_STG_EXT.2.2 {#ext-comp-FCS_STG_EXT.2.2} #### FCS_STG_EXT.2.2 {#ext-comp-FCS_STG_EXT.2.2} [DEKs](#abbr_DEK), KEKs, \[**assignment**: [any long-term trusted | DEKs, KEKs, \[**assignment**: [any long-term trusted channel key channel key material]{.assignable-content}\] and \[**selection**: [all | material]{.assignable-content}\] and \[**selection**: [all software-based key storage]{#_s_439 .selectable-content}, [no other software-based key storage]{#_s_439 .selectable-content}, [no other keys]{#_s_440 .selectable-content}\] shall be encrypted using one of the keys]{#_s_440 .selectable-content}\] shall be encrypted using one of the following methods: \[**assignment**: [key encryption following methods: \[**assignment**: [key encryption method]{.assignable-content}\] method]{.assignable-content}\] ::: ::: #### Management: FCS_STG_EXT.3 #### Management: FCS_STG_EXT.3 There are no management activities foreseen. There are no management activities foreseen. #### Audit: FCS_STG_EXT.3 #### Audit: FCS_STG_EXT.3 The following actions should be auditable if FAU_GEN Security audit data The following actions should be auditable if FAU_GEN Security audit data generation is included in the [PP](#abbr_PP), generation is included in the [PP](#abbr_PP), [PP-Module](#abbr_PP-Module), functional package or [ST](#abbr_ST): [PP-Module](#abbr_PP-Module), functional package or [ST](#abbr_ST): - Failure to verify the integrity of stored key. - Failure to verify the integrity of stored key. #### FCS_STG_EXT.3 Integrity of Encrypted Key Storage #### FCS_STG_EXT.3 Integrity of Encrypted Key Storage ::: {style="margin-left: 1em;"} ::: {style="margin-left: 1em;"} ----------------------------------- ----------------------------------- ----------------------------------- ----------------------------------- Hierarchical to: No other components. Hierarchical to: No other components. Dependencies to: FCS_COP.1 Cryptographic Operation\ Dependencies to: FCS_COP.1 Cryptographic Operation\ [FCS_STG_EXT.2](#FCS_STG_EXT.2) [FCS_STG_EXT.2](#FCS_STG_EXT.2) Encrypted Cryptographic Key Storage Encrypted Cryptographic Key Storage ----------------------------------- ----------------------------------- ----------------------------------- ----------------------------------- #### FCS_STG_EXT.3.1 {#ext-comp-FCS_STG_EXT.3.1} #### FCS_STG_EXT.3.1 {#ext-comp-FCS_STG_EXT.3.1} The [TSF](#abbr_TSF) shall protect the integrity of any encrypted | The [TSF](#abbr_TSF) shall protect the integrity of any encrypted DEKs [DEKs](#abbr_DEK) and KEKs and \[**selection**: [long-term trusted | and KEKs and \[**selection**: [long-term trusted channel key channel key material]{#_s_453 .selectable-content}, [all software-based | material]{#_s_453 .selectable-content}, [all software-based key key storage]{#_s_454 .selectable-content}, [no other keys]{#_s_455 | storage]{#_s_454 .selectable-content}, [no other keys]{#_s_455 .selectable-content}\] by \[**selection**: .selectable-content}\] by \[**selection**: - [\[**assignment**: [[AES](#abbr_AES) - [\[**assignment**: [[AES](#abbr_AES) algorithm]{.assignable-content}\] cipher mode for encryption algorithm]{.assignable-content}\] cipher mode for encryption according to [FCS_STG_EXT.2](#FCS_STG_EXT.2)]{#_s_456 according to [FCS_STG_EXT.2](#FCS_STG_EXT.2)]{#_s_456 .selectable-content} .selectable-content} - [a hash (FCS_COP.1) of the stored key that is encrypted by a key - [a hash (FCS_COP.1) of the stored key that is encrypted by a key protected by [FCS_STG_EXT.2](#FCS_STG_EXT.2)]{#_s_457 protected by [FCS_STG_EXT.2](#FCS_STG_EXT.2)]{#_s_457 .selectable-content} .selectable-content} - [a keyed hash (FCS_COP.1) using a key protected by a key protected - [a keyed hash (FCS_COP.1) using a key protected by a key protected by [FCS_STG_EXT.2](#FCS_STG_EXT.2)]{#_s_458 .selectable-content} by [FCS_STG_EXT.2](#FCS_STG_EXT.2)]{#_s_458 .selectable-content} - [a digital signature of the stored key using an asymmetric key - [a digital signature of the stored key using an asymmetric key protected according to [FCS_STG_EXT.2](#FCS_STG_EXT.2)]{#_s_459 protected according to [FCS_STG_EXT.2](#FCS_STG_EXT.2)]{#_s_459 .selectable-content} .selectable-content} - [an immediate application of the key for decrypting the protected - [an immediate application of the key for decrypting the protected data followed by a successful verification of the decrypted data data followed by a successful verification of the decrypted data with previously known information]{#_s_460 .selectable-content} with previously known information]{#_s_460 .selectable-content} \]. \]. #### FCS_STG_EXT.3.2 {#ext-comp-FCS_STG_EXT.3.2} #### FCS_STG_EXT.3.2 {#ext-comp-FCS_STG_EXT.3.2} The [TSF](#abbr_TSF) shall verify the integrity of the \[**selection**: The [TSF](#abbr_TSF) shall verify the integrity of the \[**selection**: [hash]{#_s_461 .selectable-content}, [digital signature]{#_s_462 | [hash]{#fcs_stg_ext.3.2_1 .selectable-content}, [digital .selectable-content}, [MAC]{#_s_463 .selectable-content}\] of the stored | signature]{#fcs_stg_ext.3.2_2 .selectable-content}, key prior to use of the key. | [MAC]{#fcs_stg_ext.3.2_3 .selectable-content}\] of the stored key prior > to use of the key. ::: ::: ::: ::: []{sortkey="Class FDP: User Data Protection"} []{sortkey="Class FDP: User Data Protection"} ### C.2.2 Class FDP: User Data Protection {#ext-comp- .indexable level="3"} ### C.2.2 Class FDP: User Data Protection {#ext-comp- .indexable level="3"} This [PP](#abbr_PP) defines the following extended components as part of This [PP](#abbr_PP) defines the following extended components as part of the class originally defined by [CC](#abbr_CC) Part 2: the class originally defined by [CC](#abbr_CC) Part 2: ### C.2.2.1 FDP_ACF_EXT Access Control Functions {#ext-comp-FDP_ACF_EXT .indexable le ### C.2.2.1 FDP_ACF_EXT Access Control Functions {#ext-comp-FDP_ACF_EXT .indexable le ::: {style="margin-left: 1em;"} ::: {style="margin-left: 1em;"} #### Family Behavior #### Family Behavior
This family defines the rules for access control functions that are not This family defines the rules for access control functions that are not addressed by the FDP_ACF family in [CC](#abbr_CC) Part 2. addressed by the FDP_ACF family in [CC](#abbr_CC) Part 2.
#### Component Leveling #### Component Leveling ![](data:image/svg+xml;base64,PHN2ZyBzdHlsZT0ibWF4LWhlaWdodDogNzBweDsiPjx0ZXh0IHg9IjQ ![](data:image/svg+xml;base64,PHN2ZyBzdHlsZT0ibWF4LWhlaWdodDogNzBweDsiPjx0ZXh0IHg9IjQ [FDP_ACF_EXT.1](#FDP_ACF_EXT.1), Access Control for System Services, [FDP_ACF_EXT.1](#FDP_ACF_EXT.1), Access Control for System Services, requires the [TSF](#abbr_TSF) to be able to control access to its own requires the [TSF](#abbr_TSF) to be able to control access to its own services. services. [FDP_ACF_EXT.2](#FDP_ACF_EXT.2), Access Control for System Resources, [FDP_ACF_EXT.2](#FDP_ACF_EXT.2), Access Control for System Resources, requires the [TSF](#abbr_TSF) to be able to provide separate copies of requires the [TSF](#abbr_TSF) to be able to provide separate copies of system resources for different application groups. system resources for different application groups. [FDP_ACF_EXT.3](#FDP_ACF_EXT.3), Security Attribute Based Access [FDP_ACF_EXT.3](#FDP_ACF_EXT.3), Security Attribute Based Access Control, requires the [TSF](#abbr_TSF) to enforce policies on Control, requires the [TSF](#abbr_TSF) to enforce policies on applications that prohibit write and execute permissions from being applications that prohibit write and execute permissions from being granted simultaneously. granted simultaneously. #### Management: FDP_ACF_EXT.1 #### Management: FDP_ACF_EXT.1 The following actions could be considered for the management functions The following actions could be considered for the management functions in FMT: in FMT: - Placing applications into application groups based on enterprise - Placing applications into application groups based on enterprise configuration settings. configuration settings. - Enabling/disabling location services. - Enabling/disabling location services. - Enabling/disabling data signaling over externally-accessible - Enabling/disabling data signaling over externally-accessible hardware ports. hardware ports. #### Audit: FDP_ACF_EXT.1 #### Audit: FDP_ACF_EXT.1 There are no auditable events foreseen. There are no auditable events foreseen. #### FDP_ACF_EXT.1 Access Control for System Services #### FDP_ACF_EXT.1 Access Control for System Services ::: {style="margin-left: 1em;"} ::: {style="margin-left: 1em;"} ------------------ -------------------------- ------------------ -------------------------- Hierarchical to: No other components. Hierarchical to: No other components. Dependencies to: FMT_SMR.1 Security Roles Dependencies to: FMT_SMR.1 Security Roles ------------------ -------------------------- ------------------ -------------------------- #### FDP_ACF_EXT.1.1 {#ext-comp-FDP_ACF_EXT.1.1} #### FDP_ACF_EXT.1.1 {#ext-comp-FDP_ACF_EXT.1.1} The [TSF](#abbr_TSF) shall provide a mechanism to restrict the system The [TSF](#abbr_TSF) shall provide a mechanism to restrict the system services that are accessible to an application. services that are accessible to an application. #### FDP_ACF_EXT.1.2 {#ext-comp-FDP_ACF_EXT.1.2} #### FDP_ACF_EXT.1.2 {#ext-comp-FDP_ACF_EXT.1.2} The [TSF](#abbr_TSF) shall provide an access control policy that The [TSF](#abbr_TSF) shall provide an access control policy that prevents \[**assignment**: [list of subjects]{.assignable-content}\] prevents \[**assignment**: [list of subjects]{.assignable-content}\] from accessing \[**selection**: [all]{#_s_474 .selectable-content}, from accessing \[**selection**: [all]{#_s_474 .selectable-content}, [private]{#_s_475 .selectable-content}\] data stored by other [private]{#_s_475 .selectable-content}\] data stored by other \[**assignment**: [list of subjects]{.assignable-content}\]. Exceptions \[**assignment**: [list of subjects]{.assignable-content}\]. Exceptions may only be explicitly authorized for such sharing by \[**assignment**: may only be explicitly authorized for such sharing by \[**assignment**: [list of authorized subjects]{.assignable-content}\]. [list of authorized subjects]{.assignable-content}\]. ::: ::: #### Management: FDP_ACF_EXT.2 #### Management: FDP_ACF_EXT.2 The following actions could be considered for the management functions The following actions could be considered for the management functions in FMT: in FMT: - Approving exceptions for sharing data between applications or groups - Approving exceptions for sharing data between applications or groups of applications. of applications. #### Audit: FDP_ACF_EXT.2 #### Audit: FDP_ACF_EXT.2 There are no auditable events foreseen. There are no auditable events foreseen. #### FDP_ACF_EXT.2 Access Control for System Resources #### FDP_ACF_EXT.2 Access Control for System Resources ::: {style="margin-left: 1em;"} ::: {style="margin-left: 1em;"} ----------------------------------- ----------------------------------- ----------------------------------- ----------------------------------- Hierarchical to: No other components. Hierarchical to: No other components. Dependencies to: [FDP_ACF_EXT.1](#FDP_ACF_EXT.1) Dependencies to: [FDP_ACF_EXT.1](#FDP_ACF_EXT.1) Access Control for System Services\ Access Control for System Services\ FMT_SMR.1 Security Roles FMT_SMR.1 Security Roles ----------------------------------- ----------------------------------- ----------------------------------- ----------------------------------- #### FDP_ACF_EXT.2.1 {#ext-comp-FDP_ACF_EXT.2.1} #### FDP_ACF_EXT.2.1 {#ext-comp-FDP_ACF_EXT.2.1} The [TSF](#abbr_TSF) shall provide a separate \[**selection**: [address The [TSF](#abbr_TSF) shall provide a separate \[**selection**: [address book]{#_s_476 .selectable-content}, [calendar]{#_s_477 | book]{#fdp_acf_ext.2.1_1 .selectable-content}, .selectable-content}, [keystore]{#_s_478 .selectable-content}, [account | [calendar]{#fdp_acf_ext.2.1_2 .selectable-content}, credential database, \[**assignment**: [list of additional | [keystore]{#fdp_acf_ext.2.1_3 .selectable-content}, [account credential resources]{.assignable-content}\]]{#_s_479 .selectable-content}\] for | database, \[**assignment**: [list of additional each application group and only allow applications within that process | resources]{.assignable-content}\]]{#fdp_acf_ext.2.1_4 group to access the resource. Exceptions may only be explicitly | .selectable-content}\] for each application group and only allow authorized for such sharing by \[**selection**: [the user]{#_s_480 | applications within that process group to access the resource. .selectable-content}, [the administrator]{#_s_481 .selectable-content}, | Exceptions may only be explicitly authorized for such sharing by [no one]{#_s_482 .selectable-content}\]. | \[**selection**: [the user]{#fdp_acf_ext.2.1_6 .selectable-content}, > [the administrator]{#fdp_acf_ext.2.1_7 .selectable-content}, [no > one]{#fdp_acf_ext.2.1_8 .selectable-content}\]. ::: ::: #### Management: FDP_ACF_EXT.3 #### Management: FDP_ACF_EXT.3 There are no management activities foreseen. There are no management activities foreseen. #### Audit: FDP_ACF_EXT.3 #### Audit: FDP_ACF_EXT.3 There are no auditable events foreseen. There are no auditable events foreseen. #### FDP_ACF_EXT.3 Security Attribute Based Access Control #### FDP_ACF_EXT.3 Security Attribute Based Access Control ::: {style="margin-left: 1em;"} ::: {style="margin-left: 1em;"} ------------------ ---------------------- ------------------ ---------------------- Hierarchical to: No other components. Hierarchical to: No other components. Dependencies to: No dependencies. Dependencies to: No dependencies. ------------------ ---------------------- ------------------ ---------------------- #### FDP_ACF_EXT.3.1 {#ext-comp-FDP_ACF_EXT.3.1} #### FDP_ACF_EXT.3.1 {#ext-comp-FDP_ACF_EXT.3.1} The [TSF](#abbr_TSF) shall enforce an access control policy that The [TSF](#abbr_TSF) shall enforce an access control policy that prohibits an application from granting both write and execute permission prohibits an application from granting both write and execute permission to a file on the device except for \[**selection**: [files stored in the to a file on the device except for \[**selection**: [files stored in the application\'s private data folder]{#_s_483 .selectable-content}, [no | application\'s private data folder]{#fdp_acf_ext.3.1_1 exceptions]{#_s_484 .selectable-content}\]. | .selectable-content}, [no exceptions]{#fdp_acf_ext.3.1_2 > .selectable-content}\]. ::: ::: ::: ::: ### C.2.2.2 FDP_BCK_EXT Application Backup {#ext-comp-FDP_BCK_EXT .indexable level="4 ### C.2.2.2 FDP_BCK_EXT Application Backup {#ext-comp-FDP_BCK_EXT .indexable level="4 ::: {style="margin-left: 1em;"} ::: {style="margin-left: 1em;"} #### Family Behavior #### Family Behavior
This family defines requirements for managing device backups. This family defines requirements for managing device backups.
#### Component Leveling #### Component Leveling ![](data:image/svg+xml;base64,PHN2ZyBzdHlsZT0ibWF4LWhlaWdodDogMzBweDsiPjx0ZXh0IHg9IjQ ![](data:image/svg+xml;base64,PHN2ZyBzdHlsZT0ibWF4LWhlaWdodDogMzBweDsiPjx0ZXh0IHg9IjQ [FDP_BCK_EXT.1](#FDP_BCK_EXT.1), Application Backup, requires the [FDP_BCK_EXT.1](#FDP_BCK_EXT.1), Application Backup, requires the [TSF](#abbr_TSF) to be able to determine which data to include in backup [TSF](#abbr_TSF) to be able to determine which data to include in backup operations. operations. #### Management: FDP_BCK_EXT.1 #### Management: FDP_BCK_EXT.1 The following actions could be considered for the management functions The following actions could be considered for the management functions in FMT: in FMT: - Enable/disable backup of certain applications to a local or remote - Enable/disable backup of certain applications to a local or remote system. system. #### Audit: FDP_BCK_EXT.1 #### Audit: FDP_BCK_EXT.1 There are no auditable events foreseen. There are no auditable events foreseen. #### FDP_BCK_EXT.1 Application Backup #### FDP_BCK_EXT.1 Application Backup ::: {style="margin-left: 1em;"} ::: {style="margin-left: 1em;"} ------------------ ---------------------- ------------------ ---------------------- Hierarchical to: No other components. Hierarchical to: No other components. Dependencies to: No dependencies. Dependencies to: No dependencies. ------------------ ---------------------- ------------------ ---------------------- #### FDP_BCK_EXT.1.1 {#ext-comp-FDP_BCK_EXT.1.1} #### FDP_BCK_EXT.1.1 {#ext-comp-FDP_BCK_EXT.1.1} The [TSF](#abbr_TSF) shall provide a mechanism for applications to mark The [TSF](#abbr_TSF) shall provide a mechanism for applications to mark \[**assignment**: [list of data categories ]{.assignable-content}\] to | \[**assignment**: [list of data categories]{.assignable-content}\] to be be excluded from device backups. | excluded from device backups. ::: ::: ::: ::: ### C.2.2.3 FDP_BLT_EXT Limitation of Bluetooth Device Access {#ext-comp-FDP_BLT_EXT ### C.2.2.3 FDP_BLT_EXT Limitation of Bluetooth Device Access {#ext-comp-FDP_BLT_EXT ::: {style="margin-left: 1em;"} ::: {style="margin-left: 1em;"} #### Family Behavior #### Family Behavior
This family defines requirements for managing Bluetooth devices. This family defines requirements for managing Bluetooth devices.
#### Component Leveling #### Component Leveling ![](data:image/svg+xml;base64,PHN2ZyBzdHlsZT0ibWF4LWhlaWdodDogMzBweDsiPjx0ZXh0IHg9IjQ ![](data:image/svg+xml;base64,PHN2ZyBzdHlsZT0ibWF4LWhlaWdodDogMzBweDsiPjx0ZXh0IHg9IjQ [FDP_BLT_EXT.1](#FDP_BLT_EXT.1), Limitation of Bluetooth Device Access, [FDP_BLT_EXT.1](#FDP_BLT_EXT.1), Limitation of Bluetooth Device Access, requires the [TSF](#abbr_TSF) to manage which applications communicate requires the [TSF](#abbr_TSF) to manage which applications communicate with Bluetooth devices. with Bluetooth devices. #### Management: FDP_BLT_EXT.1 #### Management: FDP_BLT_EXT.1 There are no management activities foreseen. There are no management activities foreseen. #### Audit: FDP_BLT_EXT.1 #### Audit: FDP_BLT_EXT.1 There are no auditable events foreseen. There are no auditable events foreseen. #### FDP_BLT_EXT.1 Limitation of Bluetooth Device Access #### FDP_BLT_EXT.1 Limitation of Bluetooth Device Access ::: {style="margin-left: 1em;"} ::: {style="margin-left: 1em;"} ------------------ ---------------------- ------------------ ---------------------- Hierarchical to: No other components. Hierarchical to: No other components. Dependencies to: No dependencies. Dependencies to: No dependencies. ------------------ ---------------------- ------------------ ---------------------- #### FDP_BLT_EXT.1.1 {#ext-comp-FDP_BLT_EXT.1.1} #### FDP_BLT_EXT.1.1 {#ext-comp-FDP_BLT_EXT.1.1} The [TSF](#abbr_TSF) shall limit the applications that may communicate The [TSF](#abbr_TSF) shall limit the applications that may communicate with a particular paired Bluetooth device. with a particular paired Bluetooth device. ::: ::: ::: ::: ### C.2.2.4 FDP_DAR_EXT Data-at-Rest Encryption {#ext-comp-FDP_DAR_EXT .indexable lev ### C.2.2.4 FDP_DAR_EXT Data-at-Rest Encryption {#ext-comp-FDP_DAR_EXT .indexable lev ::: {style="margin-left: 1em;"} ::: {style="margin-left: 1em;"} #### Family Behavior #### Family Behavior
This family defines requirements for implementation of data-at-rest This family defines requirements for implementation of data-at-rest protection. protection.
#### Component Leveling #### Component Leveling ![](data:image/svg+xml;base64,PHN2ZyBzdHlsZT0ibWF4LWhlaWdodDogNTBweDsiPjx0ZXh0IHg9IjQ ![](data:image/svg+xml;base64,PHN2ZyBzdHlsZT0ibWF4LWhlaWdodDogNTBweDsiPjx0ZXh0IHg9IjQ [FDP_DAR_EXT.1](#FDP_DAR_EXT.1), Protected Data Encryption, requires the [FDP_DAR_EXT.1](#FDP_DAR_EXT.1), Protected Data Encryption, requires the [TSF](#abbr_TSF) to be able to protect all data with a chosen method of [TSF](#abbr_TSF) to be able to protect all data with a chosen method of encryption. encryption. [FDP_DAR_EXT.2](#FDP_DAR_EXT.2), Sensitive Data Encryption, requires the [FDP_DAR_EXT.2](#FDP_DAR_EXT.2), Sensitive Data Encryption, requires the [TSF](#abbr_TSF) to protect the Trust Anchor Database. [TSF](#abbr_TSF) to protect the Trust Anchor Database. #### Management: FDP_DAR_EXT.1 #### Management: FDP_DAR_EXT.1 The following actions could be considered for the management functions The following actions could be considered for the management functions in FMT: in FMT: - Enabling data-at-rest protection. - Enabling data-at-rest protection. - Enabling removable media's data-at-rest protection. - Enabling removable media's data-at-rest protection. #### Audit: FDP_DAR_EXT.1 #### Audit: FDP_DAR_EXT.1 The following actions should be auditable if FAU_GEN Security audit data The following actions should be auditable if FAU_GEN Security audit data generation is included in the [PP](#abbr_PP), generation is included in the [PP](#abbr_PP), [PP-Module](#abbr_PP-Module), functional package or [ST](#abbr_ST): [PP-Module](#abbr_PP-Module), functional package or [ST](#abbr_ST): - Failure to encrypt/decrypt data. - Failure to encrypt/decrypt data. #### FDP_DAR_EXT.1 Protected Data Encryption #### FDP_DAR_EXT.1 Protected Data Encryption ::: {style="margin-left: 1em;"} ::: {style="margin-left: 1em;"} ------------------ ----------------------------------- ------------------ ----------------------------------- Hierarchical to: No other components. Hierarchical to: No other components. Dependencies to: FCS_COP.1 Cryptographic Operation Dependencies to: FCS_COP.1 Cryptographic Operation ------------------ ----------------------------------- ------------------ ----------------------------------- #### FDP_DAR_EXT.1.1 {#ext-comp-FDP_DAR_EXT.1.1} #### FDP_DAR_EXT.1.1 {#ext-comp-FDP_DAR_EXT.1.1} Encryption shall cover all protected data. Encryption shall cover all protected data. #### FDP_DAR_EXT.1.2 {#ext-comp-FDP_DAR_EXT.1.2} #### FDP_DAR_EXT.1.2 {#ext-comp-FDP_DAR_EXT.1.2} Encryption shall be performed using [DEKs](#abbr_DEK) with | Encryption shall be performed using DEKs with [AES](#abbr_AES) in the [AES](#abbr_AES) in the \[**assignment**: [list of [AES](#abbr_AES) | \[**assignment**: [list of [AES](#abbr_AES) modes]{.assignable-content}\] mode with key size \[**assignment**: [list modes]{.assignable-content}\] mode with key size \[**assignment**: [list of acceptable key sizes]{.assignable-content}\] bits. of acceptable key sizes]{.assignable-content}\] bits. ::: ::: #### Management: FDP_DAR_EXT.2 #### Management: FDP_DAR_EXT.2 The following actions could be considered for the management functions The following actions could be considered for the management functions in FMT: in FMT: - Importing X.509v3 certificates into the Trust Anchor Database. - Importing X.509v3 certificates into the Trust Anchor Database. - Removing imported X.509v3 certificates from the Trust Anchor - Removing imported X.509v3 certificates from the Trust Anchor Database. Database. - Approving import and removal by applications of X.509v3 certificates - Approving import and removal by applications of X.509v3 certificates in the Trust Anchor Database. in the Trust Anchor Database. #### Audit: FDP_DAR_EXT.2 #### Audit: FDP_DAR_EXT.2 The following actions should be auditable if FAU_GEN Security audit data The following actions should be auditable if FAU_GEN Security audit data generation is included in the [PP](#abbr_PP), generation is included in the [PP](#abbr_PP), [PP-Module](#abbr_PP-Module), functional package or [ST](#abbr_ST): [PP-Module](#abbr_PP-Module), functional package or [ST](#abbr_ST): - Addition or removal of certificate from Trust Anchor Database - Addition or removal of certificate from Trust Anchor Database #### FDP_DAR_EXT.2 Sensitive Data Encryption #### FDP_DAR_EXT.2 Sensitive Data Encryption ::: {style="margin-left: 1em;"} ::: {style="margin-left: 1em;"} ----------------------------------- ----------------------------------- ----------------------------------- ----------------------------------- Hierarchical to: No other components. Hierarchical to: No other components. Dependencies to: FCS_COP.1 Cryptographic Operation\ Dependencies to: FCS_COP.1 Cryptographic Operation\ FCS_CKM_EXT.7 Cryptographic Key FCS_CKM_EXT.7 Cryptographic Key Establishment\ Establishment\ [FCS_STG_EXT.2](#FCS_STG_EXT.2) [FCS_STG_EXT.2](#FCS_STG_EXT.2) Encrypted Cryptographic Key Storage Encrypted Cryptographic Key Storage ----------------------------------- ----------------------------------- ----------------------------------- ----------------------------------- #### FDP_DAR_EXT.2.1 {#ext-comp-FDP_DAR_EXT.2.1} #### FDP_DAR_EXT.2.1 {#ext-comp-FDP_DAR_EXT.2.1} The [TSF](#abbr_TSF) shall provide a mechanism for applications to mark The [TSF](#abbr_TSF) shall provide a mechanism for applications to mark data and keys as sensitive. data and keys as sensitive. #### FDP_DAR_EXT.2.2 {#ext-comp-FDP_DAR_EXT.2.2} #### FDP_DAR_EXT.2.2 {#ext-comp-FDP_DAR_EXT.2.2} The [TSF](#abbr_TSF) shall use an asymmetric key scheme to encrypt and The [TSF](#abbr_TSF) shall use an asymmetric key scheme to encrypt and store sensitive data received while the product is locked. store sensitive data received while the product is locked. #### FDP_DAR_EXT.2.3 {#ext-comp-FDP_DAR_EXT.2.3} #### FDP_DAR_EXT.2.3 {#ext-comp-FDP_DAR_EXT.2.3} The [TSF](#abbr_TSF) shall encrypt any stored symmetric key and any The [TSF](#abbr_TSF) shall encrypt any stored symmetric key and any stored private key of the asymmetric keys used for the protection of stored private key of the asymmetric keys used for the protection of sensitive data according to \[**assignment**: [mechanism for encrypted sensitive data according to \[**assignment**: [mechanism for encrypted key storage]{.assignable-content}\]. key storage]{.assignable-content}\]. #### FDP_DAR_EXT.2.4 {#ext-comp-FDP_DAR_EXT.2.4} #### FDP_DAR_EXT.2.4 {#ext-comp-FDP_DAR_EXT.2.4} The [TSF](#abbr_TSF) shall decrypt the sensitive data that was received The [TSF](#abbr_TSF) shall decrypt the sensitive data that was received while in the locked state upon transitioning to the unlocked state using while in the locked state upon transitioning to the unlocked state using the asymmetric key scheme and shall re-encrypt that sensitive data using the asymmetric key scheme and shall re-encrypt that sensitive data using the symmetric key scheme. the symmetric key scheme. ::: ::: ::: ::: ### C.2.2.5 FDP_IFC_EXT Subset Information Flow Control {#ext-comp-FDP_IFC_EXT .index ### C.2.2.5 FDP_IFC_EXT Subset Information Flow Control {#ext-comp-FDP_IFC_EXT .index ::: {style="margin-left: 1em;"} ::: {style="margin-left: 1em;"} #### Family Behavior #### Family Behavior
This family defines requirements for handling of information flows that This family defines requirements for handling of information flows that are not addressed by FDP_IFC in [CC](#abbr_CC) Part 2. are not addressed by FDP_IFC in [CC](#abbr_CC) Part 2.
#### Component Leveling #### Component Leveling ![](data:image/svg+xml;base64,PHN2ZyBzdHlsZT0ibWF4LWhlaWdodDogMzBweDsiPjx0ZXh0IHg9IjQ ![](data:image/svg+xml;base64,PHN2ZyBzdHlsZT0ibWF4LWhlaWdodDogMzBweDsiPjx0ZXh0IHg9IjQ [FDP_IFC_EXT.1](#FDP_IFC_EXT.1), Subset Information Flow Control, [FDP_IFC_EXT.1](#FDP_IFC_EXT.1), Subset Information Flow Control, requires the [TSF](#abbr_TSF) to be able to support the use of an requires the [TSF](#abbr_TSF) to be able to support the use of an [IPsec](#abbr_IPsec) [VPN](#abbr_VPN) to protect data in transit. [IPsec](#abbr_IPsec) [VPN](#abbr_VPN) to protect data in transit. #### Management: FDP_IFC_EXT.1 #### Management: FDP_IFC_EXT.1 The following actions could be considered for the management functions The following actions could be considered for the management functions in FMT: in FMT: - Enabling/disabling [VPN](#abbr_VPN) protection. - Enabling/disabling [VPN](#abbr_VPN) protection. - Enabling/disabling Always On [VPN](#abbr_VPN) protection. - Enabling/disabling Always On [VPN](#abbr_VPN) protection. #### Audit: FDP_IFC_EXT.1 #### Audit: FDP_IFC_EXT.1 There are no auditable events foreseen. There are no auditable events foreseen. #### FDP_IFC_EXT.1 Subset Information Flow Control #### FDP_IFC_EXT.1 Subset Information Flow Control ::: {style="margin-left: 1em;"} ::: {style="margin-left: 1em;"} ------------------ --------------------------------------------------------------- ------------------ --------------------------------------------------------------- Hierarchical to: No other components. Hierarchical to: No other components. Dependencies to: [FTP_ITC_EXT.1](#FTP_ITC_EXT.1) Trusted Channel Communication Dependencies to: [FTP_ITC_EXT.1](#FTP_ITC_EXT.1) Trusted Channel Communication ------------------ --------------------------------------------------------------- ------------------ --------------------------------------------------------------- #### FDP_IFC_EXT.1.1 {#ext-comp-FDP_IFC_EXT.1.1} #### FDP_IFC_EXT.1.1 {#ext-comp-FDP_IFC_EXT.1.1} The [TSF](#abbr_TSF) shall \[**selection**: The [TSF](#abbr_TSF) shall \[**selection**: - [provide an interface which allows a [VPN](#abbr_VPN) client to - [provide an interface which allows a [VPN](#abbr_VPN) client to protect all [IP](#abbr_IP) traffic using protect all [IP](#abbr_IP) traffic using [IPsec](#abbr_IPsec)]{#_s_494 .selectable-content} | [IPsec](#abbr_IPsec)]{#fdp_ifc_ext.1.1_1 .selectable-content} - [provide a [VPN](#abbr_VPN) client which can protect all - [provide a [VPN](#abbr_VPN) client which can protect all [IP](#abbr_IP) traffic using [IPsec](#abbr_IPsec) **as defined in [IP](#abbr_IP) traffic using [IPsec](#abbr_IPsec) **as defined in the [PP-Module for Virtual Private Network (VPN) Clients, version the [PP-Module for Virtual Private Network (VPN) Clients, version 3.0](https://www.niap-ccevs.org/protectionprofiles/487)**]{#_s_495 | 3.0]()**]{#fdp_ifc_ext.1.1_2 .selectable-content} .selectable-content} < \] with the exception of [IP](#abbr_IP) traffic needed to manage the \] with the exception of [IP](#abbr_IP) traffic needed to manage the [VPN](#abbr_VPN) connection, and \[**selection**: [\[**assignment**: [VPN](#abbr_VPN) connection, and \[**selection**: [\[**assignment**: [traffic needed for correct functioning of the [traffic needed for correct functioning of the [TOE](#abbr_TOE)]{.assignable-content}\]]{#_s_496 .selectable-content}, | [TOE](#abbr_TOE)]{.assignable-content}\]]{#fdp_ifc_ext.1.1_3 [no other traffic]{#_s_497 .selectable-content}\], when the | .selectable-content}, [no other traffic]{#fdp_ifc_ext.1.1_5 [VPN](#abbr_VPN) is enabled. | .selectable-content}\], when the [VPN](#abbr_VPN) is enabled. ::: ::: ::: ::: ### C.2.2.6 FDP_STG_EXT User Data Storage {#ext-comp-FDP_STG_EXT .indexable level="4" ### C.2.2.6 FDP_STG_EXT User Data Storage {#ext-comp-FDP_STG_EXT .indexable level="4" ::: {style="margin-left: 1em;"} ::: {style="margin-left: 1em;"} #### Family Behavior #### Family Behavior
This family defines requirements for managing data storage. This family defines requirements for managing data storage.
#### Component Leveling #### Component Leveling ![](data:image/svg+xml;base64,PHN2ZyBzdHlsZT0ibWF4LWhlaWdodDogMzBweDsiPjx0ZXh0IHg9IjQ ![](data:image/svg+xml;base64,PHN2ZyBzdHlsZT0ibWF4LWhlaWdodDogMzBweDsiPjx0ZXh0IHg9IjQ [FDP_STG_EXT.1](#FDP_STG_EXT.1), User Data Storage, requires the [FDP_STG_EXT.1](#FDP_STG_EXT.1), User Data Storage, requires the [TSF](#abbr_TSF) to be able to label, encrypt, store, and decrypt [TSF](#abbr_TSF) to be able to label, encrypt, store, and decrypt sensitive data and keys. sensitive data and keys. #### Management: FDP_STG_EXT.1 #### Management: FDP_STG_EXT.1 There are no management activities foreseen. There are no management activities foreseen. #### Audit: FDP_STG_EXT.1 #### Audit: FDP_STG_EXT.1 The following actions should be auditable if FAU_GEN Security audit data The following actions should be auditable if FAU_GEN Security audit data generation is included in the [PP](#abbr_PP), generation is included in the [PP](#abbr_PP), [PP-Module](#abbr_PP-Module), functional package or [ST](#abbr_ST): [PP-Module](#abbr_PP-Module), functional package or [ST](#abbr_ST): - Failure to encrypt/decrypt data. - Failure to encrypt/decrypt data. #### FDP_STG_EXT.1 User Data Storage #### FDP_STG_EXT.1 User Data Storage ::: {style="margin-left: 1em;"} ::: {style="margin-left: 1em;"} ----------------------------------- ----------------------------------- ----------------------------------- ----------------------------------- Hierarchical to: No other components. Hierarchical to: No other components. Dependencies to: FCS_COP.1 Cryptographic Operation\ Dependencies to: FCS_COP.1 Cryptographic Operation\ [FCS_STG_EXT.2](#FCS_STG_EXT.2) [FCS_STG_EXT.2](#FCS_STG_EXT.2) Encrypted Cryptographic Key Storage Encrypted Cryptographic Key Storage ----------------------------------- ----------------------------------- ----------------------------------- ----------------------------------- #### FDP_STG_EXT.1.1 {#ext-comp-FDP_STG_EXT.1.1} #### FDP_STG_EXT.1.1 {#ext-comp-FDP_STG_EXT.1.1} The [TSF](#abbr_TSF) shall provide protected storage for the Trust The [TSF](#abbr_TSF) shall provide protected storage for the Trust Anchor Database. Anchor Database. ::: ::: ::: ::: ### C.2.2.7 FDP_UPC_EXT Inter-TSF User Data Transfer Protection {#ext-comp-FDP_UPC_EX ### C.2.2.7 FDP_UPC_EXT Inter-TSF User Data Transfer Protection {#ext-comp-FDP_UPC_EX ::: {style="margin-left: 1em;"} ::: {style="margin-left: 1em;"} #### Family Behavior #### Family Behavior
This family defines requirements for the use of trusted channel This family defines requirements for the use of trusted channel protocols to protect user data. protocols to protect user data.
#### Component Leveling #### Component Leveling ![](data:image/svg+xml;base64,PHN2ZyBzdHlsZT0ibWF4LWhlaWdodDogMzBweDsiPjx0ZXh0IHg9IjQ ![](data:image/svg+xml;base64,PHN2ZyBzdHlsZT0ibWF4LWhlaWdodDogMzBweDsiPjx0ZXh0IHg9IjQ FDP_UPC_EXT.1, Inter-TSF User Data Transfer Protection, requires the FDP_UPC_EXT.1, Inter-TSF User Data Transfer Protection, requires the [TSF](#abbr_TSF) to be able to protect communication channels between [TSF](#abbr_TSF) to be able to protect communication channels between products using a chosen secure method. products using a chosen secure method. #### Management: FDP_UPC_EXT.1 #### Management: FDP_UPC_EXT.1 There are no management activities foreseen. There are no management activities foreseen. #### Audit: FDP_UPC_EXT.1 #### Audit: FDP_UPC_EXT.1 The following actions should be auditable if FAU_GEN Security audit data The following actions should be auditable if FAU_GEN Security audit data generation is included in the [PP](#abbr_PP), generation is included in the [PP](#abbr_PP), [PP-Module](#abbr_PP-Module), functional package or [ST](#abbr_ST): [PP-Module](#abbr_PP-Module), functional package or [ST](#abbr_ST): - Application initiation of trusted channel. - Application initiation of trusted channel. #### FDP_UPC_EXT.1 Inter-TSF User Data Transfer Protection #### FDP_UPC_EXT.1 Inter-TSF User Data Transfer Protection ::: {style="margin-left: 1em;"} ::: {style="margin-left: 1em;"} ------------------ --------------------------------------------------------------- ------------------ --------------------------------------------------------------- Hierarchical to: No other components. Hierarchical to: No other components. Dependencies to: [FTP_ITC_EXT.1](#FTP_ITC_EXT.1) Trusted Channel Communication Dependencies to: [FTP_ITC_EXT.1](#FTP_ITC_EXT.1) Trusted Channel Communication ------------------ --------------------------------------------------------------- ------------------ --------------------------------------------------------------- #### FDP_UPC_EXT.1.1 {#ext-comp-FDP_UPC_EXT.1.1} #### FDP_UPC_EXT.1.1 {#ext-comp-FDP_UPC_EXT.1.1} The [TSF](#abbr_TSF) shall provide a means for non-TSF applications The [TSF](#abbr_TSF) shall provide a means for non-TSF applications executing on the [TOE](#abbr_TOE) to use \[**assignment**: [data executing on the [TOE](#abbr_TOE) to use \[**assignment**: [data transfer protocol]{.assignable-content}\] to provide a protected transfer protocol]{.assignable-content}\] to provide a protected communication channel between the non-TSF application and another IT communication channel between the non-TSF application and another IT product that is logically distinct from other communication channels, product that is logically distinct from other communication channels, provides assured identification of its end points, protects channel data provides assured identification of its end points, protects channel data from disclosure, and detects modification of the channel data. from disclosure, and detects modification of the channel data. #### FDP_UPC_EXT.1.2 {#ext-comp-FDP_UPC_EXT.1.2} #### FDP_UPC_EXT.1.2 {#ext-comp-FDP_UPC_EXT.1.2} The [TSF](#abbr_TSF) shall permit the non-TSF applications to initiate The [TSF](#abbr_TSF) shall permit the non-TSF applications to initiate communication via the trusted channel. communication via the trusted channel. ::: ::: ::: ::: []{sortkey="Class FIA: Identification and Authentication"} []{sortkey="Class FIA: Identification and Authentication"} ### C.2.3 Class FIA: Identification and Authentication {#ext-comp- .indexable level=" ### C.2.3 Class FIA: Identification and Authentication {#ext-comp- .indexable level=" This [PP](#abbr_PP) defines the following extended components as part of This [PP](#abbr_PP) defines the following extended components as part of the class originally defined by [CC](#abbr_CC) Part 2: the class originally defined by [CC](#abbr_CC) Part 2: ### C.2.3.1 FIA_AFL_EXT Authentication Failures {#ext-comp-FIA_AFL_EXT .indexable lev ### C.2.3.1 FIA_AFL_EXT Authentication Failures {#ext-comp-FIA_AFL_EXT .indexable lev ::: {style="margin-left: 1em;"} ::: {style="margin-left: 1em;"} #### Family Behavior #### Family Behavior
This family defines requirements for authentication failure handling This family defines requirements for authentication failure handling that are not addressed by the FIA_AFL family in [CC](#abbr_CC) Part 2. that are not addressed by the FIA_AFL family in [CC](#abbr_CC) Part 2.
#### Component Leveling #### Component Leveling ![](data:image/svg+xml;base64,PHN2ZyBzdHlsZT0ibWF4LWhlaWdodDogMzBweDsiPjx0ZXh0IHg9IjQ ![](data:image/svg+xml;base64,PHN2ZyBzdHlsZT0ibWF4LWhlaWdodDogMzBweDsiPjx0ZXh0IHg9IjQ [FIA_AFL_EXT.1](#FIA_AFL_EXT.1), Authentication Failure Handling, [FIA_AFL_EXT.1](#FIA_AFL_EXT.1), Authentication Failure Handling, requires the [TSF](#abbr_TSF) be able to manage unsuccessful requires the [TSF](#abbr_TSF) be able to manage unsuccessful authentication attempts and limit the number of attempts for each authentication attempts and limit the number of attempts for each method. method. #### Management: FIA_AFL_EXT.1 #### Management: FIA_AFL_EXT.1 The following actions could be considered for the management functions The following actions could be considered for the management functions in FMT: in FMT: - Configuration of authentication failure limit. - Configuration of authentication failure limit. #### Audit: FIA_AFL_EXT.1 #### Audit: FIA_AFL_EXT.1 The following actions should be auditable if FAU_GEN Security audit data The following actions should be auditable if FAU_GEN Security audit data generation is included in the [PP](#abbr_PP), generation is included in the [PP](#abbr_PP), [PP-Module](#abbr_PP-Module), functional package or [ST](#abbr_ST): [PP-Module](#abbr_PP-Module), functional package or [ST](#abbr_ST): - Exceeding configured authentication failure limit. - Exceeding configured authentication failure limit. #### FIA_AFL_EXT.1 Authentication Failure Handling #### FIA_AFL_EXT.1 Authentication Failure Handling ::: {style="margin-left: 1em;"} ::: {style="margin-left: 1em;"} ----------------------------------- ----------------------------------- ----------------------------------- ----------------------------------- Hierarchical to: No other components. Hierarchical to: No other components. Dependencies to: [FCS_CKM_EXT.5](#FCS_CKM_EXT.5) Dependencies to: [FCS_CKM_EXT.5](#FCS_CKM_EXT.5) [TSF](#abbr_TSF) Wipe\ [TSF](#abbr_TSF) Wipe\ FIA_UAU.1 Timing of Authentication FIA_UAU.1 Timing of Authentication [FIA_UAU.5](#FIA_UAU.5) Multiple [FIA_UAU.5](#FIA_UAU.5) Multiple Authentication Mechanisms Authentication Mechanisms ----------------------------------- ----------------------------------- ----------------------------------- ----------------------------------- #### FIA_AFL_EXT.1.1 {#ext-comp-FIA_AFL_EXT.1.1} #### FIA_AFL_EXT.1.1 {#ext-comp-FIA_AFL_EXT.1.1} The [TSF](#abbr_TSF) shall consider password and \[**assignment**: [list The [TSF](#abbr_TSF) shall consider password and \[**assignment**: [list of acceptable authentication mechanisms]{.assignable-content}\] as of acceptable authentication mechanisms]{.assignable-content}\] as critical authentication mechanisms. critical authentication mechanisms. #### FIA_AFL_EXT.1.2 {#ext-comp-FIA_AFL_EXT.1.2} #### FIA_AFL_EXT.1.2 {#ext-comp-FIA_AFL_EXT.1.2} The [TSF](#abbr_TSF) shall detect when a configurable positive integer The [TSF](#abbr_TSF) shall detect when a configurable positive integer within \[**assignment**: [range of acceptable values for each within \[**assignment**: [range of acceptable values for each authentication mechanism]{.assignable-content}\] of \[**selection**: authentication mechanism]{.assignable-content}\] of \[**selection**: [unique]{#_s_506 .selectable-content}, [non-unique]{#_s_507 [unique]{#_s_506 .selectable-content}, [non-unique]{#_s_507 .selectable-content}\] unsuccessful authentication attempts occur .selectable-content}\] unsuccessful authentication attempts occur related to last successful authentication for each authentication related to last successful authentication for each authentication mechanism. mechanism. #### FIA_AFL_EXT.1.3 {#ext-comp-FIA_AFL_EXT.1.3} #### FIA_AFL_EXT.1.3 {#ext-comp-FIA_AFL_EXT.1.3} The [TSF](#abbr_TSF) shall maintain the number of unsuccessful The [TSF](#abbr_TSF) shall maintain the number of unsuccessful authentication attempts that have occurred upon power off. authentication attempts that have occurred upon power off. #### FIA_AFL_EXT.1.4 {#ext-comp-FIA_AFL_EXT.1.4} #### FIA_AFL_EXT.1.4 {#ext-comp-FIA_AFL_EXT.1.4} When the defined number of unsuccessful authentication attempts has When the defined number of unsuccessful authentication attempts has exceeded the maximum allowed for a given authentication mechanism, all exceeded the maximum allowed for a given authentication mechanism, all future authentication attempts will be limited to other available future authentication attempts will be limited to other available authentication mechanisms, unless the given mechanism is designated as a authentication mechanisms, unless the given mechanism is designated as a critical authentication mechanism. critical authentication mechanism. #### FIA_AFL_EXT.1.5 {#ext-comp-FIA_AFL_EXT.1.5} #### FIA_AFL_EXT.1.5 {#ext-comp-FIA_AFL_EXT.1.5} When the defined number of unsuccessful authentication attempts for the When the defined number of unsuccessful authentication attempts for the last available authentication mechanism or single critical last available authentication mechanism or single critical authentication mechanism has been surpassed, the [TSF](#abbr_TSF) shall authentication mechanism has been surpassed, the [TSF](#abbr_TSF) shall perform a wipe of all protected data. perform a wipe of all protected data. #### FIA_AFL_EXT.1.6 {#ext-comp-FIA_AFL_EXT.1.6} #### FIA_AFL_EXT.1.6 {#ext-comp-FIA_AFL_EXT.1.6} The [TSF](#abbr_TSF) shall increment the number of unsuccessful The [TSF](#abbr_TSF) shall increment the number of unsuccessful authentication attempts prior to notifying the user that the authentication attempts prior to notifying the user that the authentication was unsuccessful. authentication was unsuccessful. ::: ::: ::: ::: ### C.2.3.2 FIA_PMG_EXT Password Management {#ext-comp-FIA_PMG_EXT .indexable level=" ### C.2.3.2 FIA_PMG_EXT Password Management {#ext-comp-FIA_PMG_EXT .indexable level=" ::: {style="margin-left: 1em;"} ::: {style="margin-left: 1em;"} #### Family Behavior #### Family Behavior
This family defines requirements for the composition of password This family defines requirements for the composition of password credentials. credentials.
#### Component Leveling #### Component Leveling ![](data:image/svg+xml;base64,PHN2ZyBzdHlsZT0ibWF4LWhlaWdodDogMzBweDsiPjx0ZXh0IHg9IjQ ![](data:image/svg+xml;base64,PHN2ZyBzdHlsZT0ibWF4LWhlaWdodDogMzBweDsiPjx0ZXh0IHg9IjQ [FIA_PMG_EXT.1](#FIA_PMG_EXT.1), Password Management, requires the [FIA_PMG_EXT.1](#FIA_PMG_EXT.1), Password Management, requires the [TSF](#abbr_TSF) to enforce character length and composition [TSF](#abbr_TSF) to enforce character length and composition requirements for password credentials. requirements for password credentials. #### Management: FIA_PMG_EXT.1 #### Management: FIA_PMG_EXT.1 The following actions could be considered for the management functions The following actions could be considered for the management functions in FMT: in FMT: - Configuring password policy. - Configuring password policy. #### Audit: FIA_PMG_EXT.1 #### Audit: FIA_PMG_EXT.1 There are no auditable events foreseen. There are no auditable events foreseen. #### FIA_PMG_EXT.1 Password Management #### FIA_PMG_EXT.1 Password Management ::: {style="margin-left: 1em;"} ::: {style="margin-left: 1em;"} ------------------ ------------------------------------------------------------ ------------------ ------------------------------------------------------------ Hierarchical to: No other components. Hierarchical to: No other components. Dependencies to: [FIA_UAU.5](#FIA_UAU.5) Multiple Authentication Mechanisms Dependencies to: [FIA_UAU.5](#FIA_UAU.5) Multiple Authentication Mechanisms ------------------ ------------------------------------------------------------ ------------------ ------------------------------------------------------------ #### FIA_PMG_EXT.1.1 {#ext-comp-FIA_PMG_EXT.1.1} #### FIA_PMG_EXT.1.1 {#ext-comp-FIA_PMG_EXT.1.1} The [TSF](#abbr_TSF) shall support the following for the Password The [TSF](#abbr_TSF) shall support the following for the Password Authentication Factor: Authentication Factor: 1. Passwords shall be able to be composed of any combination of 1. Passwords shall be able to be composed of any combination of \[**selection**: [upper and lower case letters]{#_s_508 | \[**selection**: [upper and lower case letters]{#fia_pmg_ext.1.1_1 .selectable-content}, [\[**assignment**: [a character set of at .selectable-content}, [\[**assignment**: [a character set of at least 52 characters]{.assignable-content}\]]{#_s_509 | least 52 characters]{.assignable-content}\]]{#fia_pmg_ext.1.1_2 .selectable-content}\], numbers, and special characters: .selectable-content}\], numbers, and special characters: \[**selection**: [\"!\"]{#_s_510 .selectable-content}, | \[**selection**: [\"!\"]{#fia_pmg_ext.1.1_4 .selectable-content}, [\"@\"]{#_s_511 .selectable-content}, [\"#\"]{#_s_512 | [\"@\"]{#fia_pmg_ext.1.1_5 .selectable-content}, .selectable-content}, [\"\$\"]{#_s_513 .selectable-content}, | [\"#\"]{#fia_pmg_ext.1.1_6 .selectable-content}, [\"%\"]{#_s_514 .selectable-content}, [\"\^\"]{#_s_515 | [\"\$\"]{#fia_pmg_ext.1.1_7 .selectable-content}, .selectable-content}, [\"&\"]{#_s_516 .selectable-content}, [ | [\"%\"]{#fia_pmg_ext.1.1_8 .selectable-content}, \"\*\"]{#_s_517 .selectable-content}, [\"(\"]{#_s_518 | [\"\^\"]{#fia_pmg_ext.1.1_9 .selectable-content}, .selectable-content}, [\")\"]{#_s_519 .selectable-content}, | [\"&\"]{#fia_pmg_ext.1.1_10 .selectable-content}, [\[**assignment**: [other | [\"\*\"]{#fia_pmg_ext.1.1_11 .selectable-content}, characters]{.assignable-content}\]]{#_s_520 .selectable-content}\]; | [\"(\"]{#fia_pmg_ext.1.1_12 .selectable-content}, > [\")\"]{#fia_pmg_ext.1.1_13 .selectable-content}, [\[**assignment**: > [other characters]{.assignable-content}\]]{#fia_pmg_ext.1.1_14 > .selectable-content}\]; 2. Password length up to \[**assignment**: [an integer greater than or 2. Password length up to \[**assignment**: [an integer greater than or equal to 14]{.assignable-content}\] characters shall be supported. equal to 14]{.assignable-content}\] characters shall be supported. ::: ::: ::: ::: ### C.2.3.3 FIA_TRT_EXT Authentication Throttling {#ext-comp-FIA_TRT_EXT .indexable l ### C.2.3.3 FIA_TRT_EXT Authentication Throttling {#ext-comp-FIA_TRT_EXT .indexable l ::: {style="margin-left: 1em;"} ::: {style="margin-left: 1em;"} #### Family Behavior #### Family Behavior
This family defines requirements for prevention of brute-force This family defines requirements for prevention of brute-force authentication attempts. authentication attempts.
#### Component Leveling #### Component Leveling ![](data:image/svg+xml;base64,PHN2ZyBzdHlsZT0ibWF4LWhlaWdodDogMzBweDsiPjx0ZXh0IHg9IjQ ![](data:image/svg+xml;base64,PHN2ZyBzdHlsZT0ibWF4LWhlaWdodDogMzBweDsiPjx0ZXh0IHg9IjQ [FIA_TRT_EXT.1](#FIA_TRT_EXT.1), Authentication Throttling, requires the [FIA_TRT_EXT.1](#FIA_TRT_EXT.1), Authentication Throttling, requires the [TSF](#abbr_TSF) to limit authentication attempts by number of attempts [TSF](#abbr_TSF) to limit authentication attempts by number of attempts in a set amount of time. in a set amount of time. #### Management: FIA_TRT_EXT.1 #### Management: FIA_TRT_EXT.1 There are no management activities foreseen. There are no management activities foreseen. #### Audit: FIA_TRT_EXT.1 #### Audit: FIA_TRT_EXT.1 There are no auditable events foreseen. There are no auditable events foreseen. #### FIA_TRT_EXT.1 Authentication Throttling #### FIA_TRT_EXT.1 Authentication Throttling ::: {style="margin-left: 1em;"} ::: {style="margin-left: 1em;"} ------------------ ------------------------------------------------------------ ------------------ ------------------------------------------------------------ Hierarchical to: No other components. Hierarchical to: No other components. Dependencies to: [FIA_UAU.5](#FIA_UAU.5) Multiple Authentication Mechanisms Dependencies to: [FIA_UAU.5](#FIA_UAU.5) Multiple Authentication Mechanisms ------------------ ------------------------------------------------------------ ------------------ ------------------------------------------------------------ #### FIA_TRT_EXT.1.1 {#ext-comp-FIA_TRT_EXT.1.1} #### FIA_TRT_EXT.1.1 {#ext-comp-FIA_TRT_EXT.1.1} The [TSF](#abbr_TSF) shall limit automated user authentication attempts The [TSF](#abbr_TSF) shall limit automated user authentication attempts by \[**selection**: [preventing authentication via an external by \[**selection**: [preventing authentication via an external port]{#_s_521 .selectable-content}, [enforcing a delay between incorrect | port]{#fia_trt_ext.1.1_1 .selectable-content}, [enforcing a delay authentication attempts]{#_s_522 .selectable-content}\] for all | between incorrect authentication attempts]{#fia_trt_ext.1.1_2 authentication mechanisms selected in [FIA_UAU.5.1](#FIA_UAU.5.1). The | .selectable-content}\] for all authentication mechanisms selected in minimum delay shall be such that no more than 10 attempts can be | [FIA_UAU.5.1](#FIA_UAU.5.1). The minimum delay shall be such that no attempted per 500 milliseconds. | more than 10 attempts can be attempted per 500 milliseconds. ::: ::: ::: ::: ### C.2.3.4 FIA_UAU_EXT User Authentication {#ext-comp-FIA_UAU_EXT .indexable level=" ### C.2.3.4 FIA_UAU_EXT User Authentication {#ext-comp-FIA_UAU_EXT .indexable level=" ::: {style="margin-left: 1em;"} ::: {style="margin-left: 1em;"} #### Family Behavior #### Family Behavior
This family defines requirements for user authentication that are not This family defines requirements for user authentication that are not addressed by FIA_UAU in [CC](#abbr_CC) Part 2. addressed by FIA_UAU in [CC](#abbr_CC) Part 2.
#### Component Leveling #### Component Leveling ![](data:image/svg+xml;base64,PHN2ZyBzdHlsZT0ibWF4LWhlaWdodDogNzBweDsiPjx0ZXh0IHg9IjQ ![](data:image/svg+xml;base64,PHN2ZyBzdHlsZT0ibWF4LWhlaWdodDogNzBweDsiPjx0ZXh0IHg9IjQ [FIA_UAU_EXT.1](#FIA_UAU_EXT.1), Authentication for Cryptographic [FIA_UAU_EXT.1](#FIA_UAU_EXT.1), Authentication for Cryptographic Operation, requires the [TSF](#abbr_TSF) enforce data-at-rest protection Operation, requires the [TSF](#abbr_TSF) enforce data-at-rest protection until successful authentication has occurred. until successful authentication has occurred. [FIA_UAU_EXT.2](#FIA_UAU_EXT.2), Timing of Authentication, requires the [FIA_UAU_EXT.2](#FIA_UAU_EXT.2), Timing of Authentication, requires the [TSF](#abbr_TSF) to prevent a subject's use of [TOE](#abbr_TOE) until [TSF](#abbr_TSF) to prevent a subject's use of [TOE](#abbr_TOE) until the user is authenticated. the user is authenticated. [FIA_UAU_EXT.4](#FIA_UAU_EXT.4), Secondary User Authentication, requires [FIA_UAU_EXT.4](#FIA_UAU_EXT.4), Secondary User Authentication, requires the [TSF](#abbr_TSF) to enforce the use of a secondary authentication the [TSF](#abbr_TSF) to enforce the use of a secondary authentication factor to access certain user data. factor to access certain user data. #### Management: FIA_UAU_EXT.1 #### Management: FIA_UAU_EXT.1 There are no management activities foreseen. There are no management activities foreseen. #### Audit: FIA_UAU_EXT.1 #### Audit: FIA_UAU_EXT.1 There are no auditable events foreseen. There are no auditable events foreseen. #### FIA_UAU_EXT.1 Authentication for Cryptographic Operation #### FIA_UAU_EXT.1 Authentication for Cryptographic Operation ::: {style="margin-left: 1em;"} ::: {style="margin-left: 1em;"} ----------------------------------- ----------------------------------- ----------------------------------- ----------------------------------- Hierarchical to: No other components. Hierarchical to: No other components. Dependencies to: [FDP_DAR_EXT.1](#FDP_DAR_EXT.1) Dependencies to: [FDP_DAR_EXT.1](#FDP_DAR_EXT.1) Protected Data Encryption\ Protected Data Encryption\ [FDP_DAR_EXT.2](#FDP_DAR_EXT.2) [FDP_DAR_EXT.2](#FDP_DAR_EXT.2) Sensitive Data Encryption Sensitive Data Encryption ----------------------------------- ----------------------------------- ----------------------------------- ----------------------------------- #### FIA_UAU_EXT.1.1 {#ext-comp-FIA_UAU_EXT.1.1} #### FIA_UAU_EXT.1.1 {#ext-comp-FIA_UAU_EXT.1.1} The [TSF](#abbr_TSF) shall require the user to present the Password The [TSF](#abbr_TSF) shall require the user to present the Password Authentication Factor prior to decryption of protected data and Authentication Factor prior to decryption of protected data and encrypted [DEKs](#abbr_DEK), KEKs and \[**selection**: [long-term | encrypted DEKs, KEKs and \[**selection**: [long-term trusted channel key trusted channel key material]{#_s_526 .selectable-content}, [all | material]{#fia_uau_ext.1.1_1 .selectable-content}, [all software-based software-based key storage]{#_s_527 .selectable-content}, [no other | key storage]{#fia_uau_ext.1.1_2 .selectable-content}, [no other keys]{#_s_528 .selectable-content}\] at startup. | keys]{#fia_uau_ext.1.1_3 .selectable-content}\] at startup. ::: ::: #### Management: FIA_UAU_EXT.2 #### Management: FIA_UAU_EXT.2 The following actions could be considered for the management functions The following actions could be considered for the management functions in FMT: in FMT: - Enabling/disabling display [TSF](#abbr_TSF) notifications while in - Enabling/disabling display [TSF](#abbr_TSF) notifications while in the locked state. the locked state. - Enabling/disabling bypass of local user authentication. - Enabling/disabling bypass of local user authentication. #### Audit: FIA_UAU_EXT.2 #### Audit: FIA_UAU_EXT.2 The following actions should be auditable if FAU_GEN Security audit data The following actions should be auditable if FAU_GEN Security audit data generation is included in the [PP](#abbr_PP), generation is included in the [PP](#abbr_PP), [PP-Module](#abbr_PP-Module), functional package or [ST](#abbr_ST): [PP-Module](#abbr_PP-Module), functional package or [ST](#abbr_ST): - Action performed before authentication. - Action performed before authentication. #### FIA_UAU_EXT.2 Timing of Authentication #### FIA_UAU_EXT.2 Timing of Authentication ::: {style="margin-left: 1em;"} ::: {style="margin-left: 1em;"} ------------------ ---------------------- ------------------ ---------------------- Hierarchical to: No other components. Hierarchical to: No other components. Dependencies to: No dependencies. Dependencies to: No dependencies. ------------------ ---------------------- ------------------ ---------------------- #### FIA_UAU_EXT.2.1 {#ext-comp-FIA_UAU_EXT.2.1} #### FIA_UAU_EXT.2.1 {#ext-comp-FIA_UAU_EXT.2.1} The [TSF](#abbr_TSF) shall allow \[**selection**: [\[**assignment**: The [TSF](#abbr_TSF) shall allow \[**selection**: [\[**assignment**: [list of actions]{.assignable-content}\]]{#_s_529 .selectable-content}, | [list of actions]{.assignable-content}\]]{#fia_uau_ext.2.1_1 [ no actions]{#_s_530 .selectable-content}\] on behalf of the user to be | .selectable-content}, [no actions]{#fia_uau_ext.2.1_3 performed before the user is authenticated. | .selectable-content}\] on behalf of the user to be performed before the > user is authenticated. #### FIA_UAU_EXT.2.2 {#ext-comp-FIA_UAU_EXT.2.2} #### FIA_UAU_EXT.2.2 {#ext-comp-FIA_UAU_EXT.2.2} The [TSF](#abbr_TSF) shall require each user to be successfully The [TSF](#abbr_TSF) shall require each user to be successfully authenticated before allowing any other [TSF](#abbr_TSF)-mediated authenticated before allowing any other [TSF](#abbr_TSF)-mediated actions on behalf of that user. actions on behalf of that user. ::: ::: #### Management: FIA_UAU_EXT.4 #### Management: FIA_UAU_EXT.4 There are no management activities foreseen. There are no management activities foreseen. #### Audit: FIA_UAU_EXT.4 #### Audit: FIA_UAU_EXT.4 There are no auditable events foreseen. There are no auditable events foreseen. #### FIA_UAU_EXT.4 Secondary User Authentication #### FIA_UAU_EXT.4 Secondary User Authentication ::: {style="margin-left: 1em;"} ::: {style="margin-left: 1em;"} ----------------------------------- ----------------------------------- ----------------------------------- ----------------------------------- Hierarchical to: No other components. Hierarchical to: No other components. Dependencies to: [FDP_ACF_EXT.2](#FDP_ACF_EXT.2) Dependencies to: [FDP_ACF_EXT.2](#FDP_ACF_EXT.2) Access Control for System Access Control for System Resources\ Resources\ [FIA_UAU.5](#FIA_UAU.5) Multiple [FIA_UAU.5](#FIA_UAU.5) Multiple Authentication Mechanisms Authentication Mechanisms ----------------------------------- ----------------------------------- ----------------------------------- ----------------------------------- #### FIA_UAU_EXT.4.1 {#ext-comp-FIA_UAU_EXT.4.1} #### FIA_UAU_EXT.4.1 {#ext-comp-FIA_UAU_EXT.4.1} The [TSF](#abbr_TSF) shall provide a secondary authentication mechanism The [TSF](#abbr_TSF) shall provide a secondary authentication mechanism for accessing Enterprise applications and resources. The secondary for accessing Enterprise applications and resources. The secondary authentication mechanism shall control access to the Enterprise authentication mechanism shall control access to the Enterprise application and shared resources and shall be incorporated into the application and shared resources and shall be incorporated into the encryption of protected and sensitive data belonging to Enterprise encryption of protected and sensitive data belonging to Enterprise applications and shared resources. applications and shared resources. #### FIA_UAU_EXT.4.2 {#ext-comp-FIA_UAU_EXT.4.2} #### FIA_UAU_EXT.4.2 {#ext-comp-FIA_UAU_EXT.4.2} The [TSF](#abbr_TSF) shall require the user to present the secondary The [TSF](#abbr_TSF) shall require the user to present the secondary authentication factor prior to decryption of Enterprise application data authentication factor prior to decryption of Enterprise application data and Enterprise shared resource data. and Enterprise shared resource data. ::: ::: ::: ::: ### C.2.3.5 FIA_X509_EXT X.509 Certificates {#ext-comp-FIA_X509_EXT .indexable level= ### C.2.3.5 FIA_X509_EXT X.509 Certificates {#ext-comp-FIA_X509_EXT .indexable level= ::: {style="margin-left: 1em;"} ::: {style="margin-left: 1em;"} #### Family Behavior #### Family Behavior
This family defines requirements for the management and use of X.509 This family defines requirements for the management and use of X.509 certificates. certificates.
#### Component Leveling #### Component Leveling ![](data:image/svg+xml;base64,PHN2ZyBzdHlsZT0ibWF4LWhlaWdodDogMzBweDsiPjx0ZXh0IHg9IjQ ![](data:image/svg+xml;base64,PHN2ZyBzdHlsZT0ibWF4LWhlaWdodDogMzBweDsiPjx0ZXh0IHg9IjQ [FIA_X509_EXT.6](#FIA_X509_EXT.6), Request Validation of Certificates, [FIA_X509_EXT.6](#FIA_X509_EXT.6), Request Validation of Certificates, requires the [TSF](#abbr_TSF) to make a certificate validation service requires the [TSF](#abbr_TSF) to make a certificate validation service available to environmental components. available to environmental components. #### Management: FIA_X509_EXT.6 #### Management: FIA_X509_EXT.6 There are no management activities foreseen. There are no management activities foreseen. #### Audit: FIA_X509_EXT.6 #### Audit: FIA_X509_EXT.6 There are no auditable events foreseen. There are no auditable events foreseen. #### FIA_X509_EXT.6 Request Validation of Certificates #### FIA_X509_EXT.6 Request Validation of Certificates ::: {style="margin-left: 1em;"} ::: {style="margin-left: 1em;"} ------------------ ------------------------------------------------- ------------------ ------------------------------------------------- Hierarchical to: No other components. Hierarchical to: No other components. Dependencies to: FIA_X509_EXT.1 X.509 Validation of Certificates Dependencies to: FIA_X509_EXT.1 X.509 Validation of Certificates ------------------ ------------------------------------------------- ------------------ ------------------------------------------------- #### FIA_X509_EXT.6.1 {#ext-comp-FIA_X509_EXT.6.1} #### FIA_X509_EXT.6.1 {#ext-comp-FIA_X509_EXT.6.1} The [TSF](#abbr_TSF) shall provide a certificate validation service to The [TSF](#abbr_TSF) shall provide a certificate validation service to applications. applications. #### FIA_X509_EXT.6.2 {#ext-comp-FIA_X509_EXT.6.2} #### FIA_X509_EXT.6.2 {#ext-comp-FIA_X509_EXT.6.2} The [TSF](#abbr_TSF) shall respond to the requesting application with The [TSF](#abbr_TSF) shall respond to the requesting application with the success or failure of the validation. the success or failure of the validation. ::: ::: ::: ::: []{sortkey="Class FMT: Security Management"} []{sortkey="Class FMT: Security Management"} ### C.2.4 Class FMT: Security Management {#ext-comp- .indexable level="3"} ### C.2.4 Class FMT: Security Management {#ext-comp- .indexable level="3"} This [PP](#abbr_PP) defines the following extended components as part of This [PP](#abbr_PP) defines the following extended components as part of the class originally defined by [CC](#abbr_CC) Part 2: the class originally defined by [CC](#abbr_CC) Part 2: ### C.2.4.1 FMT_MOF_EXT Management of Functions in TSF {#ext-comp-FMT_MOF_EXT .indexa ### C.2.4.1 FMT_MOF_EXT Management of Functions in TSF {#ext-comp-FMT_MOF_EXT .indexa ::: {style="margin-left: 1em;"} ::: {style="margin-left: 1em;"} #### Family Behavior #### Family Behavior
This family defines requirements for authorization to manage the This family defines requirements for authorization to manage the behavior of the [TSF](#abbr_TSF) that are not addressed by FMT_MOF in behavior of the [TSF](#abbr_TSF) that are not addressed by FMT_MOF in [CC](#abbr_CC) Part 2. [CC](#abbr_CC) Part 2.
#### Component Leveling #### Component Leveling ![](data:image/svg+xml;base64,PHN2ZyBzdHlsZT0ibWF4LWhlaWdodDogMzBweDsiPjx0ZXh0IHg9IjQ ![](data:image/svg+xml;base64,PHN2ZyBzdHlsZT0ibWF4LWhlaWdodDogMzBweDsiPjx0ZXh0IHg9IjQ [FMT_MOF_EXT.1](#FMT_MOF_EXT.1), Management of Security Functions [FMT_MOF_EXT.1](#FMT_MOF_EXT.1), Management of Security Functions Behavior, requires the [TSF](#abbr_TSF) to apply restrictions to access Behavior, requires the [TSF](#abbr_TSF) to apply restrictions to access its management functions to the authorized roles. its management functions to the authorized roles. #### Management: FMT_MOF_EXT.1 #### Management: FMT_MOF_EXT.1 The following actions could be considered for the management functions The following actions could be considered for the management functions in FMT: in FMT: - Managing the group of roles that can interact with the functions in - Managing the group of roles that can interact with the functions in the [TSF](#abbr_TSF). the [TSF](#abbr_TSF). #### Audit: FMT_MOF_EXT.1 #### Audit: FMT_MOF_EXT.1 There are no auditable events foreseen. There are no auditable events foreseen. #### FMT_MOF_EXT.1 Management of Security Functions Behavior #### FMT_MOF_EXT.1 Management of Security Functions Behavior ::: {style="margin-left: 1em;"} ::: {style="margin-left: 1em;"} ----------------------------------- ----------------------------------- ----------------------------------- ----------------------------------- Hierarchical to: No other components. Hierarchical to: No other components. Dependencies to: FMT_SMF.1 Specification of Dependencies to: FMT_SMF.1 Specification of Management Functions\ Management Functions\ FMT_SMR.1 Security Roles FMT_SMR.1 Security Roles ----------------------------------- ----------------------------------- ----------------------------------- ----------------------------------- #### FMT_MOF_EXT.1.1 {#ext-comp-FMT_MOF_EXT.1.1} #### FMT_MOF_EXT.1.1 {#ext-comp-FMT_MOF_EXT.1.1} The [TSF](#abbr_TSF) shall restrict the ability to perform the functions The [TSF](#abbr_TSF) shall restrict the ability to perform the functions \[**assignment**: [reference to list of management \[**assignment**: [reference to list of management functions]{.assignable-content}\] to the user. functions]{.assignable-content}\] to the user. #### FMT_MOF_EXT.1.2 {#ext-comp-FMT_MOF_EXT.1.2} #### FMT_MOF_EXT.1.2 {#ext-comp-FMT_MOF_EXT.1.2} The [TSF](#abbr_TSF) shall restrict the ability to perform the functions The [TSF](#abbr_TSF) shall restrict the ability to perform the functions \[**assignment**: [reference to list of management \[**assignment**: [reference to list of management functions]{.assignable-content}\] to the administrator when the device functions]{.assignable-content}\] to the administrator when the device is enrolled and according to the administrator-configured policy. is enrolled and according to the administrator-configured policy. ::: ::: ::: ::: ### C.2.4.2 FMT_SMF_EXT Specification of Management Functions {#ext-comp-FMT_SMF_EXT ### C.2.4.2 FMT_SMF_EXT Specification of Management Functions {#ext-comp-FMT_SMF_EXT ::: {style="margin-left: 1em;"} ::: {style="margin-left: 1em;"} #### Family Behavior #### Family Behavior
This family defines requirements for security-relevant management This family defines requirements for security-relevant management functions that are not addressed by FMT_SMF in [CC](#abbr_CC) Part 2. functions that are not addressed by FMT_SMF in [CC](#abbr_CC) Part 2.
#### Component Leveling #### Component Leveling ![](data:image/svg+xml;base64,PHN2ZyBzdHlsZT0ibWF4LWhlaWdodDogNzBweDsiPjx0ZXh0IHg9IjQ ![](data:image/svg+xml;base64,PHN2ZyBzdHlsZT0ibWF4LWhlaWdodDogNzBweDsiPjx0ZXh0IHg9IjQ [FMT_SMF_EXT.1](#FMT_SMF_EXT.1), Specification of Management Functions, [FMT_SMF_EXT.1](#FMT_SMF_EXT.1), Specification of Management Functions, requires the [TSF](#abbr_TSF) to define the management functions that it requires the [TSF](#abbr_TSF) to define the management functions that it implements. implements. [FMT_SMF_EXT.2](#FMT_SMF_EXT.2), Specification of Remediation Actions, [FMT_SMF_EXT.2](#FMT_SMF_EXT.2), Specification of Remediation Actions, requires the [TSF](#abbr_TSF) to automatically perform specific requires the [TSF](#abbr_TSF) to automatically perform specific management functions in response to a specific event. management functions in response to a specific event. [FMT_SMF_EXT.3](#FMT_SMF_EXT.3), Current Administrator, requires the [FMT_SMF_EXT.3](#FMT_SMF_EXT.3), Current Administrator, requires the [TSF](#abbr_TSF) to provide users with a list of administrators and [TSF](#abbr_TSF) to provide users with a list of administrators and their specified functions. their specified functions. #### Management: FMT_SMF_EXT.1 #### Management: FMT_SMF_EXT.1 There are no management activities foreseen. There are no management activities foreseen. #### Audit: FMT_SMF_EXT.1 #### Audit: FMT_SMF_EXT.1 The following actions should be auditable if FAU_GEN Security audit data The following actions should be auditable if FAU_GEN Security audit data generation is included in the [PP](#abbr_PP)/[ST](#abbr_ST): generation is included in the [PP](#abbr_PP)/[ST](#abbr_ST): - Initiation of policy update. - Initiation of policy update. - Change of settings. - Change of settings. - Success or failure of function - Success or failure of function - Initiation of software update. - Initiation of software update. - Initiation of application installation or update. - Initiation of application installation or update. #### FMT_SMF_EXT.1 Specification of Management Functions #### FMT_SMF_EXT.1 Specification of Management Functions ::: {style="margin-left: 1em;"} ::: {style="margin-left: 1em;"} ------------------ ---------------------- ------------------ ---------------------- Hierarchical to: No other components. Hierarchical to: No other components. Dependencies to: No dependencies. Dependencies to: No dependencies. ------------------ ---------------------- ------------------ ---------------------- #### FMT_SMF_EXT.1.1 {#ext-comp-FMT_SMF_EXT.1.1} #### FMT_SMF_EXT.1.1 {#ext-comp-FMT_SMF_EXT.1.1} The [TSF](#abbr_TSF) shall be capable of performing \[**assignment**: The [TSF](#abbr_TSF) shall be capable of performing \[**assignment**: [list of management functions]{.assignable-content}\]. [list of management functions]{.assignable-content}\]. ::: ::: #### Management: FMT_SMF_EXT.2 #### Management: FMT_SMF_EXT.2 The following actions could be considered for the management functions The following actions could be considered for the management functions in FMT: in FMT: - Configuration of the functions that are performed in response to - Configuration of the functions that are performed in response to unenrollment event. unenrollment event. #### Audit: FMT_SMF_EXT.2 #### Audit: FMT_SMF_EXT.2 The following actions should be auditable if FAU_GEN Security audit data The following actions should be auditable if FAU_GEN Security audit data generation is included in the [PP](#abbr_PP), generation is included in the [PP](#abbr_PP), [PP-Module](#abbr_PP-Module), functional package or [ST](#abbr_ST): [PP-Module](#abbr_PP-Module), functional package or [ST](#abbr_ST): - Initiation of unenrollment. - Initiation of unenrollment. - Completion of unenrollment. - Completion of unenrollment. #### FMT_SMF_EXT.2 Specification of Remediation Actions #### FMT_SMF_EXT.2 Specification of Remediation Actions ::: {style="margin-left: 1em;"} ::: {style="margin-left: 1em;"} ------------------ ---------------------- ------------------ ---------------------- Hierarchical to: No other components. Hierarchical to: No other components. Dependencies to: No dependencies. Dependencies to: No dependencies. ------------------ ---------------------- ------------------ ---------------------- #### FMT_SMF_EXT.2.1 {#ext-comp-FMT_SMF_EXT.2.1} #### FMT_SMF_EXT.2.1 {#ext-comp-FMT_SMF_EXT.2.1} The [TSF](#abbr_TSF) shall offer \[**assignment**: [list of remediation The [TSF](#abbr_TSF) shall offer \[**assignment**: [list of remediation actions]{.assignable-content}\] upon unenrollment and \[**assignment**: actions]{.assignable-content}\] upon unenrollment and \[**assignment**: [list of triggers]{.assignable-content}\]. [list of triggers]{.assignable-content}\]. ::: ::: #### Management: FMT_SMF_EXT.3 #### Management: FMT_SMF_EXT.3 There are no management activities foreseen. There are no management activities foreseen. #### Audit: FMT_SMF_EXT.3 #### Audit: FMT_SMF_EXT.3 There are no auditable events foreseen. There are no auditable events foreseen. #### FMT_SMF_EXT.3 Current Administrator #### FMT_SMF_EXT.3 Current Administrator ::: {style="margin-left: 1em;"} ::: {style="margin-left: 1em;"} ------------------ -------------------------- ------------------ -------------------------- Hierarchical to: No other components. Hierarchical to: No other components. Dependencies to: FMT_SMR.1 Security Roles Dependencies to: FMT_SMR.1 Security Roles ------------------ -------------------------- ------------------ -------------------------- #### FMT_SMF_EXT.3.1 {#ext-comp-FMT_SMF_EXT.3.1} #### FMT_SMF_EXT.3.1 {#ext-comp-FMT_SMF_EXT.3.1} The [TSF](#abbr_TSF) shall provide a mechanism that allows users to view The [TSF](#abbr_TSF) shall provide a mechanism that allows users to view a list of currently authorized administrators and the management a list of currently authorized administrators and the management functions that each administrator is authorized to perform. functions that each administrator is authorized to perform. ::: ::: ::: ::: []{sortkey="Class FPT: Protection of the TSF"} []{sortkey="Class FPT: Protection of the TSF"} ### C.2.5 Class FPT: Protection of the TSF {#ext-comp- .indexable level="3"} ### C.2.5 Class FPT: Protection of the TSF {#ext-comp- .indexable level="3"} This [PP](#abbr_PP) defines the following extended components as part of This [PP](#abbr_PP) defines the following extended components as part of the class originally defined by [CC](#abbr_CC) Part 2: the class originally defined by [CC](#abbr_CC) Part 2: ### C.2.5.1 FPT_AEX_EXT Anti-Exploitation Capabilities {#ext-comp-FPT_AEX_EXT .indexa ### C.2.5.1 FPT_AEX_EXT Anti-Exploitation Capabilities {#ext-comp-FPT_AEX_EXT .indexa ::: {style="margin-left: 1em;"} ::: {style="margin-left: 1em;"} #### Family Behavior #### Family Behavior
This family defines requirements for protecting against common types of This family defines requirements for protecting against common types of software exploitation techniques. software exploitation techniques.
#### Component Leveling #### Component Leveling ![](data:image/svg+xml;base64,PHN2ZyBzdHlsZT0ibWF4LWhlaWdodDogMTMwcHg7Ij48dGV4dCB4PSI ![](data:image/svg+xml;base64,PHN2ZyBzdHlsZT0ibWF4LWhlaWdodDogMTMwcHg7Ij48dGV4dCB4PSI [FPT_AEX_EXT.1](#FPT_AEX_EXT.1), Application Address Space Layout [FPT_AEX_EXT.1](#FPT_AEX_EXT.1), Application Address Space Layout Randomization, requires the [TSF](#abbr_TSF) to support address space Randomization, requires the [TSF](#abbr_TSF) to support address space layout randomization ([ASLR](#abbr_ASLR)). layout randomization ([ASLR](#abbr_ASLR)). [FPT_AEX_EXT.2](#FPT_AEX_EXT.2), Memory Page Permissions, requires the [FPT_AEX_EXT.2](#FPT_AEX_EXT.2), Memory Page Permissions, requires the [TSF](#abbr_TSF) to enforce access permissions on physical memory. [TSF](#abbr_TSF) to enforce access permissions on physical memory. [FPT_AEX_EXT.3](#FPT_AEX_EXT.3), Stack Overflow Protection, requires the [FPT_AEX_EXT.3](#FPT_AEX_EXT.3), Stack Overflow Protection, requires the [TSF](#abbr_TSF) to implement stack overflow protection. [TSF](#abbr_TSF) to implement stack overflow protection. [FPT_AEX_EXT.4](#FPT_AEX_EXT.4), Domain Isolation, requires the [FPT_AEX_EXT.4](#FPT_AEX_EXT.4), Domain Isolation, requires the [TSF](#abbr_TSF) to protect itself from untrusted subjects and enforce [TSF](#abbr_TSF) to protect itself from untrusted subjects and enforce address space isolation. address space isolation. [FPT_AEX_EXT.5](#FPT_AEX_EXT.5), Kernel Address Space Layout [FPT_AEX_EXT.5](#FPT_AEX_EXT.5), Kernel Address Space Layout Randomization, requires the [TSF](#abbr_TSF) to provide Randomization, requires the [TSF](#abbr_TSF) to provide [ASLR](#abbr_ASLR) to the kernel. [ASLR](#abbr_ASLR) to the kernel. [FPT_AEX_EXT.6](#FPT_AEX_EXT.6), Write or Execute Memory Page [FPT_AEX_EXT.6](#FPT_AEX_EXT.6), Write or Execute Memory Page Permissions, requires the [TSF](#abbr_TSF) to prevent physical memory Permissions, requires the [TSF](#abbr_TSF) to prevent physical memory from being both writable and executable. from being both writable and executable. #### Management: FPT_AEX_EXT.1 #### Management: FPT_AEX_EXT.1 There are no management activities foreseen. There are no management activities foreseen. #### Audit: FPT_AEX_EXT.1 #### Audit: FPT_AEX_EXT.1 There are no auditable events foreseen. There are no auditable events foreseen. #### FPT_AEX_EXT.1 Application Address Space Layout Randomization #### FPT_AEX_EXT.1 Application Address Space Layout Randomization ::: {style="margin-left: 1em;"} ::: {style="margin-left: 1em;"} ------------------ ----------------------------------------------- ------------------ ----------------------------------------------- Hierarchical to: No other components. Hierarchical to: No other components. Dependencies to: [FCS_RBG.1](#FCS_RBG.1) Random Bit Generation Dependencies to: [FCS_RBG.1](#FCS_RBG.1) Random Bit Generation ------------------ ----------------------------------------------- ------------------ ----------------------------------------------- #### FPT_AEX_EXT.1.1 {#ext-comp-FPT_AEX_EXT.1.1} #### FPT_AEX_EXT.1.1 {#ext-comp-FPT_AEX_EXT.1.1} The [TSF](#abbr_TSF) shall provide address space layout randomization The [TSF](#abbr_TSF) shall provide address space layout randomization [ASLR](#abbr_ASLR) to applications. [ASLR](#abbr_ASLR) to applications. #### FPT_AEX_EXT.1.2 {#ext-comp-FPT_AEX_EXT.1.2} #### FPT_AEX_EXT.1.2 {#ext-comp-FPT_AEX_EXT.1.2} The base address of any user-space memory mapping will consist of at The base address of any user-space memory mapping will consist of at least 8 unpredictable bits. least 8 unpredictable bits. ::: ::: #### Management: FPT_AEX_EXT.2 #### Management: FPT_AEX_EXT.2 There are no management activities foreseen. There are no management activities foreseen. #### Audit: FPT_AEX_EXT.2 #### Audit: FPT_AEX_EXT.2 There are no auditable events foreseen. There are no auditable events foreseen. #### FPT_AEX_EXT.2 Memory Page Permissions #### FPT_AEX_EXT.2 Memory Page Permissions ::: {style="margin-left: 1em;"} ::: {style="margin-left: 1em;"} ------------------ ---------------------- ------------------ ---------------------- Hierarchical to: No other components. Hierarchical to: No other components. Dependencies to: No dependencies. Dependencies to: No dependencies. ------------------ ---------------------- ------------------ ---------------------- #### FPT_AEX_EXT.2.1 {#ext-comp-FPT_AEX_EXT.2.1} #### FPT_AEX_EXT.2.1 {#ext-comp-FPT_AEX_EXT.2.1} The [TSF](#abbr_TSF) shall be able to enforce read, write, and execute The [TSF](#abbr_TSF) shall be able to enforce read, write, and execute permissions on every page of physical memory. permissions on every page of physical memory. ::: ::: #### Management: FPT_AEX_EXT.3 #### Management: FPT_AEX_EXT.3 There are no management activities foreseen. There are no management activities foreseen. #### Audit: FPT_AEX_EXT.3 #### Audit: FPT_AEX_EXT.3 There are no auditable events foreseen. There are no auditable events foreseen. #### FPT_AEX_EXT.3 Stack Overflow Protection #### FPT_AEX_EXT.3 Stack Overflow Protection ::: {style="margin-left: 1em;"} ::: {style="margin-left: 1em;"} ------------------ ---------------------- ------------------ ---------------------- Hierarchical to: No other components. Hierarchical to: No other components. Dependencies to: No dependencies. Dependencies to: No dependencies. ------------------ ---------------------- ------------------ ---------------------- #### FPT_AEX_EXT.3.1 {#ext-comp-FPT_AEX_EXT.3.1} #### FPT_AEX_EXT.3.1 {#ext-comp-FPT_AEX_EXT.3.1} [TSF](#abbr_TSF) processes that execute in a non-privileged execution [TSF](#abbr_TSF) processes that execute in a non-privileged execution domain on the application processor shall implement stack-based buffer domain on the application processor shall implement stack-based buffer overflow protection. overflow protection. ::: ::: #### Management: FPT_AEX_EXT.4 #### Management: FPT_AEX_EXT.4 There are no management activities foreseen. There are no management activities foreseen. #### Audit: FPT_AEX_EXT.4 #### Audit: FPT_AEX_EXT.4 There are no auditable events foreseen. There are no auditable events foreseen. #### FPT_AEX_EXT.4 Domain Isolation #### FPT_AEX_EXT.4 Domain Isolation ::: {style="margin-left: 1em;"} ::: {style="margin-left: 1em;"} ------------------ ---------------------- ------------------ ---------------------- Hierarchical to: No other components. Hierarchical to: No other components. Dependencies to: No dependencies. Dependencies to: No dependencies. ------------------ ---------------------- ------------------ ---------------------- #### FPT_AEX_EXT.4.1 {#ext-comp-FPT_AEX_EXT.4.1} #### FPT_AEX_EXT.4.1 {#ext-comp-FPT_AEX_EXT.4.1} The [TSF](#abbr_TSF) shall protect itself from modification by untrusted The [TSF](#abbr_TSF) shall protect itself from modification by untrusted subjects. subjects. #### FPT_AEX_EXT.4.2 {#ext-comp-FPT_AEX_EXT.4.2} #### FPT_AEX_EXT.4.2 {#ext-comp-FPT_AEX_EXT.4.2} The [TSF](#abbr_TSF) shall enforce isolation of address space between The [TSF](#abbr_TSF) shall enforce isolation of address space between applications. applications. ::: ::: #### Management: FPT_AEX_EXT.5 #### Management: FPT_AEX_EXT.5 There are no management activities foreseen. There are no management activities foreseen. #### Audit: FPT_AEX_EXT.5 #### Audit: FPT_AEX_EXT.5 There are no auditable events foreseen. There are no auditable events foreseen. #### FPT_AEX_EXT.5 Kernel Address Space Layout Randomization #### FPT_AEX_EXT.5 Kernel Address Space Layout Randomization ::: {style="margin-left: 1em;"} ::: {style="margin-left: 1em;"} ------------------ ---------------------------------------------------------------- ------------------ ---------------------------------------------------------------- Hierarchical to: No other components. Hierarchical to: No other components. Dependencies to: [FCS_RBG.1](#FCS_RBG.1) Random Bit Generation ([RBG](#abbr_RBG)) Dependencies to: [FCS_RBG.1](#FCS_RBG.1) Random Bit Generation ([RBG](#abbr_RBG)) ------------------ ---------------------------------------------------------------- ------------------ ---------------------------------------------------------------- #### FPT_AEX_EXT.5.1 {#ext-comp-FPT_AEX_EXT.5.1} #### FPT_AEX_EXT.5.1 {#ext-comp-FPT_AEX_EXT.5.1} The [TSF](#abbr_TSF) shall provide address space layout randomization The [TSF](#abbr_TSF) shall provide address space layout randomization ([ASLR](#abbr_ASLR)) to the kernel. ([ASLR](#abbr_ASLR)) to the kernel. #### FPT_AEX_EXT.5.2 {#ext-comp-FPT_AEX_EXT.5.2} #### FPT_AEX_EXT.5.2 {#ext-comp-FPT_AEX_EXT.5.2} The base address of any kernel-space memory mapping will consist of The base address of any kernel-space memory mapping will consist of \[**assignment**: [number greater than or equal to \[**assignment**: [number greater than or equal to 4]{.assignable-content}\] unpredictable bits. 4]{.assignable-content}\] unpredictable bits. ::: ::: #### Management: FPT_AEX_EXT.6 #### Management: FPT_AEX_EXT.6 There are no management activities foreseen. There are no management activities foreseen. #### Audit: FPT_AEX_EXT.6 #### Audit: FPT_AEX_EXT.6 There are no auditable events foreseen. There are no auditable events foreseen. #### FPT_AEX_EXT.6 Write or Execute Memory Page Permissions #### FPT_AEX_EXT.6 Write or Execute Memory Page Permissions ::: {style="margin-left: 1em;"} ::: {style="margin-left: 1em;"} ------------------ ---------------------- ------------------ ---------------------- Hierarchical to: No other components. Hierarchical to: No other components. Dependencies to: No dependencies. Dependencies to: No dependencies. ------------------ ---------------------- ------------------ ---------------------- #### FPT_AEX_EXT.6.1 {#ext-comp-FPT_AEX_EXT.6.1} #### FPT_AEX_EXT.6.1 {#ext-comp-FPT_AEX_EXT.6.1} The [TSF](#abbr_TSF) shall prevent write and execute permissions from The [TSF](#abbr_TSF) shall prevent write and execute permissions from being simultaneously granted to any page of physical memory being simultaneously granted to any page of physical memory \[**selection**: [with no exceptions]{#_s_586 .selectable-content}, | \[**selection**: [with no exceptions]{#fpt_aex_ext.6.1_1 [\[**assignment**: [specific exceptions]{.assignable-content}\]]{#_s_587 | .selectable-content}, [\[**assignment**: [specific > exceptions]{.assignable-content}\]]{#fpt_aex_ext.6.1_2 .selectable-content}\]. .selectable-content}\]. ::: ::: ::: ::: ### C.2.5.2 FPT_BBD_EXT Baseband Processing {#ext-comp-FPT_BBD_EXT .indexable level=" ### C.2.5.2 FPT_BBD_EXT Baseband Processing {#ext-comp-FPT_BBD_EXT .indexable level=" ::: {style="margin-left: 1em;"} ::: {style="margin-left: 1em;"} #### Family Behavior #### Family Behavior
This family defines requirements for separation of baseband and This family defines requirements for separation of baseband and application processor execution. application processor execution.
#### Component Leveling #### Component Leveling ![](data:image/svg+xml;base64,PHN2ZyBzdHlsZT0ibWF4LWhlaWdodDogMzBweDsiPjx0ZXh0IHg9IjQ ![](data:image/svg+xml;base64,PHN2ZyBzdHlsZT0ibWF4LWhlaWdodDogMzBweDsiPjx0ZXh0IHg9IjQ [FPT_BBD_EXT.1](#FPT_BBD_EXT.1), Application Processor Mediation, [FPT_BBD_EXT.1](#FPT_BBD_EXT.1), Application Processor Mediation, requires the [TSF](#abbr_TSF) to enforce separation between baseband and requires the [TSF](#abbr_TSF) to enforce separation between baseband and application processor execution except through application processor application processor execution except through application processor mechanisms. mechanisms. #### Management: FPT_BBD_EXT.1 #### Management: FPT_BBD_EXT.1 There are no management activities foreseen. There are no management activities foreseen. #### Audit: FPT_BBD_EXT.1 #### Audit: FPT_BBD_EXT.1 There are no auditable events foreseen. There are no auditable events foreseen. #### FPT_BBD_EXT.1 Application Processor Mediation #### FPT_BBD_EXT.1 Application Processor Mediation ::: {style="margin-left: 1em;"} ::: {style="margin-left: 1em;"} ------------------ ---------------------- ------------------ ---------------------- Hierarchical to: No other components. Hierarchical to: No other components. Dependencies to: No dependencies. Dependencies to: No dependencies. ------------------ ---------------------- ------------------ ---------------------- #### FPT_BBD_EXT.1.1 {#ext-comp-FPT_BBD_EXT.1.1} #### FPT_BBD_EXT.1.1 {#ext-comp-FPT_BBD_EXT.1.1} The [TSF](#abbr_TSF) shall prevent code executing on any baseband The [TSF](#abbr_TSF) shall prevent code executing on any baseband processor ([BP](#abbr_BP)) from accessing application processor processor ([BP](#abbr_BP)) from accessing application processor ([AP](#abbr_AP)) resources except when mediated by the [AP](#abbr_AP). ([AP](#abbr_AP)) resources except when mediated by the [AP](#abbr_AP). ::: ::: ::: ::: ### C.2.5.3 FPT_BLT_EXT Limitation of Bluetooth Profile Support {#ext-comp-FPT_BLT_EX ### C.2.5.3 FPT_BLT_EXT Limitation of Bluetooth Profile Support {#ext-comp-FPT_BLT_EX ::: {style="margin-left: 1em;"} ::: {style="margin-left: 1em;"} #### Family Behavior #### Family Behavior
This family defines requirements for limiting Bluetooth capabilities This family defines requirements for limiting Bluetooth capabilities without user action. without user action.
#### Component Leveling #### Component Leveling ![](data:image/svg+xml;base64,PHN2ZyBzdHlsZT0ibWF4LWhlaWdodDogMzBweDsiPjx0ZXh0IHg9IjQ ![](data:image/svg+xml;base64,PHN2ZyBzdHlsZT0ibWF4LWhlaWdodDogMzBweDsiPjx0ZXh0IHg9IjQ [FPT_BLT_EXT.1](#FPT_BLT_EXT.1), Limitation of Bluetooth Profile [FPT_BLT_EXT.1](#FPT_BLT_EXT.1), Limitation of Bluetooth Profile Support, requires the [TSF](#abbr_TSF) to maintain a disabled by default Support, requires the [TSF](#abbr_TSF) to maintain a disabled by default posture for Bluetooth profiles. posture for Bluetooth profiles. #### Management: FPT_BLT_EXT.1 #### Management: FPT_BLT_EXT.1 There are no management activities foreseen. There are no management activities foreseen. #### Audit: FPT_BLT_EXT.1 #### Audit: FPT_BLT_EXT.1 There are no auditable events foreseen. There are no auditable events foreseen. #### FPT_BLT_EXT.1 Limitation of Bluetooth Profile Support #### FPT_BLT_EXT.1 Limitation of Bluetooth Profile Support ::: {style="margin-left: 1em;"} ::: {style="margin-left: 1em;"} ------------------ ---------------------- ------------------ ---------------------- Hierarchical to: No other components. Hierarchical to: No other components. Dependencies to: No dependencies. Dependencies to: No dependencies. ------------------ ---------------------- ------------------ ---------------------- #### FPT_BLT_EXT.1.1 {#ext-comp-FPT_BLT_EXT.1.1} #### FPT_BLT_EXT.1.1 {#ext-comp-FPT_BLT_EXT.1.1} The [TSF](#abbr_TSF) shall disable support for \[**assignment**: [list The [TSF](#abbr_TSF) shall disable support for \[**assignment**: [list of Bluetooth profiles]{.assignable-content}\] Bluetooth profiles when of Bluetooth profiles]{.assignable-content}\] Bluetooth profiles when they are not currently being used by an application on the Mobile they are not currently being used by an application on the Mobile Device, and shall require explicit user action to enable them. Device, and shall require explicit user action to enable them. ::: ::: ::: ::: ### C.2.5.4 FPT_JTA_EXT JTAG Disablement {#ext-comp-FPT_JTA_EXT .indexable level="4"} ### C.2.5.4 FPT_JTA_EXT JTAG Disablement {#ext-comp-FPT_JTA_EXT .indexable level="4"} ::: {style="margin-left: 1em;"} ::: {style="margin-left: 1em;"} #### Family Behavior #### Family Behavior
This family defines requirements for JTAG interface access limitations. This family defines requirements for JTAG interface access limitations.
#### Component Leveling #### Component Leveling ![](data:image/svg+xml;base64,PHN2ZyBzdHlsZT0ibWF4LWhlaWdodDogMzBweDsiPjx0ZXh0IHg9IjQ ![](data:image/svg+xml;base64,PHN2ZyBzdHlsZT0ibWF4LWhlaWdodDogMzBweDsiPjx0ZXh0IHg9IjQ [FPT_JTA_EXT.1](#FPT_JTA_EXT.1), JTAG Disablement, requires the [FPT_JTA_EXT.1](#FPT_JTA_EXT.1), JTAG Disablement, requires the [TSF](#abbr_TSF) to specify the mechanism used to restrict access to its [TSF](#abbr_TSF) to specify the mechanism used to restrict access to its JTAG interface. JTAG interface. #### Management: FPT_JTA_EXT.1 #### Management: FPT_JTA_EXT.1 There are no management activities foreseen. There are no management activities foreseen. #### Audit: FPT_JTA_EXT.1 #### Audit: FPT_JTA_EXT.1 There are no auditable events foreseen. There are no auditable events foreseen. #### FPT_JTA_EXT.1 JTAG Disablement #### FPT_JTA_EXT.1 JTAG Disablement ::: {style="margin-left: 1em;"} ::: {style="margin-left: 1em;"} ------------------ ---------------------- ------------------ ---------------------- Hierarchical to: No other components. Hierarchical to: No other components. Dependencies to: No dependencies. Dependencies to: No dependencies. ------------------ ---------------------- ------------------ ---------------------- #### FPT_JTA_EXT.1.1 {#ext-comp-FPT_JTA_EXT.1.1} #### FPT_JTA_EXT.1.1 {#ext-comp-FPT_JTA_EXT.1.1} The [TSF](#abbr_TSF) shall \[**assignment**: [list access control The [TSF](#abbr_TSF) shall \[**assignment**: [list access control mechanisms]{.assignable-content}\] to JTAG. mechanisms]{.assignable-content}\] to JTAG. ::: ::: ::: ::: ### C.2.5.5 FPT_KST_EXT Key Storage {#ext-comp-FPT_KST_EXT .indexable level="4"} ### C.2.5.5 FPT_KST_EXT Key Storage {#ext-comp-FPT_KST_EXT .indexable level="4"} ::: {style="margin-left: 1em;"} ::: {style="margin-left: 1em;"} #### Family Behavior #### Family Behavior
This family defines requirements for protecting plaintext keys. This family defines requirements for protecting plaintext keys.
#### Component Leveling #### Component Leveling ![](data:image/svg+xml;base64,PHN2ZyBzdHlsZT0ibWF4LWhlaWdodDogNzBweDsiPjx0ZXh0IHg9IjQ ![](data:image/svg+xml;base64,PHN2ZyBzdHlsZT0ibWF4LWhlaWdodDogNzBweDsiPjx0ZXh0IHg9IjQ [FPT_KST_EXT.1](#FPT_KST_EXT.1), Key Storage, requires the [FPT_KST_EXT.1](#FPT_KST_EXT.1), Key Storage, requires the [TSF](#abbr_TSF) to avoid storage of plaintext keys in readable memory. [TSF](#abbr_TSF) to avoid storage of plaintext keys in readable memory. [FPT_KST_EXT.2](#FPT_KST_EXT.2), No Key Transmission, requires the [FPT_KST_EXT.2](#FPT_KST_EXT.2), No Key Transmission, requires the [TSF](#abbr_TSF) to prevent transmitting plaintext key material to the [TSF](#abbr_TSF) to prevent transmitting plaintext key material to the operational environment. operational environment. [FPT_KST_EXT.3](#FPT_KST_EXT.3), No Plaintext Key Export, requires the [FPT_KST_EXT.3](#FPT_KST_EXT.3), No Plaintext Key Export, requires the [TSF](#abbr_TSF) to prevent the export of plaintext keys. [TSF](#abbr_TSF) to prevent the export of plaintext keys. #### Management: FPT_KST_EXT.1 #### Management: FPT_KST_EXT.1 There are no management activities foreseen. There are no management activities foreseen. #### Audit: FPT_KST_EXT.1 #### Audit: FPT_KST_EXT.1 There are no auditable events foreseen. There are no auditable events foreseen. #### FPT_KST_EXT.1 Key Storage #### FPT_KST_EXT.1 Key Storage ::: {style="margin-left: 1em;"} ::: {style="margin-left: 1em;"} ------------------ ---------------------- ------------------ ---------------------- Hierarchical to: No other components. Hierarchical to: No other components. Dependencies to: No dependencies. Dependencies to: No dependencies. ------------------ ---------------------- ------------------ ---------------------- #### FPT_KST_EXT.1.1 {#ext-comp-FPT_KST_EXT.1.1} #### FPT_KST_EXT.1.1 {#ext-comp-FPT_KST_EXT.1.1} The [TSF](#abbr_TSF) shall not store any plaintext key material in The [TSF](#abbr_TSF) shall not store any plaintext key material in readable non-volatile memory. readable non-volatile memory. ::: ::: #### Management: FPT_KST_EXT.2 #### Management: FPT_KST_EXT.2 There are no management activities foreseen. There are no management activities foreseen. #### Audit: FPT_KST_EXT.2 #### Audit: FPT_KST_EXT.2 There are no auditable events foreseen. There are no auditable events foreseen. #### FPT_KST_EXT.2 No Key Transmission #### FPT_KST_EXT.2 No Key Transmission ::: {style="margin-left: 1em;"} ::: {style="margin-left: 1em;"} ------------------ ---------------------- ------------------ ---------------------- Hierarchical to: No other components. Hierarchical to: No other components. Dependencies to: No dependencies. Dependencies to: No dependencies. ------------------ ---------------------- ------------------ ---------------------- #### FPT_KST_EXT.2.1 {#ext-comp-FPT_KST_EXT.2.1} #### FPT_KST_EXT.2.1 {#ext-comp-FPT_KST_EXT.2.1} The [TSF](#abbr_TSF) shall not transmit any plaintext key material The [TSF](#abbr_TSF) shall not transmit any plaintext key material outside the security boundary of the [TOE](#abbr_TOE). outside the security boundary of the [TOE](#abbr_TOE). ::: ::: #### Management: FPT_KST_EXT.3 #### Management: FPT_KST_EXT.3 There are no management activities foreseen. There are no management activities foreseen. #### Audit: FPT_KST_EXT.3 #### Audit: FPT_KST_EXT.3 There are no auditable events foreseen. There are no auditable events foreseen. #### FPT_KST_EXT.3 No Plaintext Key Export #### FPT_KST_EXT.3 No Plaintext Key Export ::: {style="margin-left: 1em;"} ::: {style="margin-left: 1em;"} ------------------ ---------------------- ------------------ ---------------------- Hierarchical to: No other components. Hierarchical to: No other components. Dependencies to: No dependencies. Dependencies to: No dependencies. ------------------ ---------------------- ------------------ ---------------------- #### FPT_KST_EXT.3.1 {#ext-comp-FPT_KST_EXT.3.1} #### FPT_KST_EXT.3.1 {#ext-comp-FPT_KST_EXT.3.1} The [TSF](#abbr_TSF) shall ensure it is not possible for the The [TSF](#abbr_TSF) shall ensure it is not possible for the [TOE](#abbr_TOE) users to export plaintext keys. [TOE](#abbr_TOE) users to export plaintext keys. ::: ::: ::: ::: ### C.2.5.6 FPT_NOT_EXT Self-Test Notification {#ext-comp-FPT_NOT_EXT .indexable leve ### C.2.5.6 FPT_NOT_EXT Self-Test Notification {#ext-comp-FPT_NOT_EXT .indexable leve ::: {style="margin-left: 1em;"} ::: {style="margin-left: 1em;"} #### Family Behavior #### Family Behavior
This family defines requirements for generation of notifications in This family defines requirements for generation of notifications in response to completed self-tests. response to completed self-tests.
#### Component Leveling #### Component Leveling ![](data:image/svg+xml;base64,PHN2ZyBzdHlsZT0ibWF4LWhlaWdodDogNTBweDsiPjx0ZXh0IHg9IjQ ![](data:image/svg+xml;base64,PHN2ZyBzdHlsZT0ibWF4LWhlaWdodDogNTBweDsiPjx0ZXh0IHg9IjQ [FPT_NOT_EXT.1](#FPT_NOT_EXT.1), Self-Test Notification, requires the [FPT_NOT_EXT.1](#FPT_NOT_EXT.1), Self-Test Notification, requires the [TSF](#abbr_TSF) to become non-operational when certain failures occur. [TSF](#abbr_TSF) to become non-operational when certain failures occur. [FPT_NOT_EXT.2](#FPT_NOT_EXT.2), Software Integrity Verification, [FPT_NOT_EXT.2](#FPT_NOT_EXT.2), Software Integrity Verification, requires the [TSF](#abbr_TSF) to generate and sign software integrity requires the [TSF](#abbr_TSF) to generate and sign software integrity verification values. verification values. #### Management: FPT_NOT_EXT.1 #### Management: FPT_NOT_EXT.1 There are no management activities foreseen. There are no management activities foreseen. #### Audit: FPT_NOT_EXT.1 #### Audit: FPT_NOT_EXT.1 The following actions should be auditable if FAU_GEN Security audit data The following actions should be auditable if FAU_GEN Security audit data generation is included in the [PP](#abbr_PP), generation is included in the [PP](#abbr_PP), [PP-Module](#abbr_PP-Module), functional package or [ST](#abbr_ST): [PP-Module](#abbr_PP-Module), functional package or [ST](#abbr_ST): - Measurement of [TSF](#abbr_TSF) software. - Measurement of [TSF](#abbr_TSF) software. #### FPT_NOT_EXT.1 Self-Test Notification #### FPT_NOT_EXT.1 Self-Test Notification ::: {style="margin-left: 1em;"} ::: {style="margin-left: 1em;"} ----------------------------------- ----------------------------------- ----------------------------------- ----------------------------------- Hierarchical to: No other components. Hierarchical to: No other components. Dependencies to: [FPT_TST_EXT.1](#FPT_TST_EXT.1) Dependencies to: [FPT_TST_EXT.1](#FPT_TST_EXT.1) [TSF](#abbr_TSF) Cryptographic [TSF](#abbr_TSF) Cryptographic Functionality Testing\ Functionality Testing\ FPT_TST_EXT.2 [TSF](#abbr_TSF) FPT_TST_EXT.2 [TSF](#abbr_TSF) Integrity Checking Integrity Checking ----------------------------------- ----------------------------------- ----------------------------------- ----------------------------------- #### FPT_NOT_EXT.1.1 {#ext-comp-FPT_NOT_EXT.1.1} #### FPT_NOT_EXT.1.1 {#ext-comp-FPT_NOT_EXT.1.1} The [TSF](#abbr_TSF) shall transition to non-operational mode and The [TSF](#abbr_TSF) shall transition to non-operational mode and \[**selection**: [log failures in the audit record]{#_s_590 | \[**selection**: [log failures in the audit record]{#fpt_not_ext.1.1_1 .selectable-content}, [notify the administrator]{#_s_591 | .selectable-content}, [notify the administrator]{#fpt_not_ext.1.1_2 .selectable-content}, [\[**assignment**: [other .selectable-content}, [\[**assignment**: [other actions]{.assignable-content}\]]{#_s_592 .selectable-content}, [no other | actions]{.assignable-content}\]]{#fpt_not_ext.1.1_3 actions]{#_s_593 .selectable-content}\] when the following types of | .selectable-content}, [no other actions]{#fpt_not_ext.1.1_5 failures occur: | .selectable-content}\] when the following types of failures occur: - failures of the self-tests - failures of the self-tests - [TSF](#abbr_TSF) software integrity verification failures - [TSF](#abbr_TSF) software integrity verification failures - \[**selection**: [no other failures]{#_s_594 .selectable-content}, | - \[**selection**: [no other failures]{#fpt_not_ext.1.1_6 [\[**assignment**: [other failures]{.assignable-content}\]]{#_s_595 | .selectable-content}, [\[**assignment**: [other > failures]{.assignable-content}\]]{#fpt_not_ext.1.1_7 .selectable-content}\] .selectable-content}\] ::: ::: #### Management: FPT_NOT_EXT.2 #### Management: FPT_NOT_EXT.2 The following actions could be considered for the management functions The following actions could be considered for the management functions in FMT: in FMT: - Retrieval of [TSF](#abbr_TSF) software integrity verification - Retrieval of [TSF](#abbr_TSF) software integrity verification values. values. #### Audit: FPT_NOT_EXT.2 #### Audit: FPT_NOT_EXT.2 There are no auditable events foreseen. There are no auditable events foreseen. #### FPT_NOT_EXT.2 Software Integrity Verification #### FPT_NOT_EXT.2 Software Integrity Verification ::: {style="margin-left: 1em;"} ::: {style="margin-left: 1em;"} ------------------ ----------------------------------- ------------------ ----------------------------------- Hierarchical to: No other components. Hierarchical to: No other components. Dependencies to: FCS_COP.1 Cryptographic Operation Dependencies to: FCS_COP.1 Cryptographic Operation ------------------ ----------------------------------- ------------------ ----------------------------------- #### FPT_NOT_EXT.2.1 {#ext-comp-FPT_NOT_EXT.2.1} #### FPT_NOT_EXT.2.1 {#ext-comp-FPT_NOT_EXT.2.1} The [TSF](#abbr_TSF) shall \[**selection**: [audit]{#_s_600 | The [TSF](#abbr_TSF) shall \[**selection**: [audit]{#fpt_not_ext.2.1_1 .selectable-content}, [provide the administrator with]{#_s_601 | .selectable-content}, [provide the administrator .selectable-content}\] [TSF](#abbr_TSF)-software integrity verification | with]{#fpt_not_ext.2.1_2 .selectable-content}\] values. | [TSF](#abbr_TSF)-software integrity verification values. #### FPT_NOT_EXT.2.2 {#ext-comp-FPT_NOT_EXT.2.2} #### FPT_NOT_EXT.2.2 {#ext-comp-FPT_NOT_EXT.2.2} The [TSF](#abbr_TSF) shall cryptographically sign all integrity The [TSF](#abbr_TSF) shall cryptographically sign all integrity verification values. verification values. ::: ::: ::: ::: ### C.2.5.7 FPT_TST_EXT TSF Self Test {#ext-comp-FPT_TST_EXT .indexable level="4"} ### C.2.5.7 FPT_TST_EXT TSF Self Test {#ext-comp-FPT_TST_EXT .indexable level="4"} ::: {style="margin-left: 1em;"} ::: {style="margin-left: 1em;"} #### Family Behavior #### Family Behavior
This family defines requirements for execution of self-tests that are This family defines requirements for execution of self-tests that are not addressed by FPT_TST in [CC](#abbr_CC) Part 2. not addressed by FPT_TST in [CC](#abbr_CC) Part 2.
#### Component Leveling #### Component Leveling ![](data:image/svg+xml;base64,PHN2ZyBzdHlsZT0ibWF4LWhlaWdodDogNzBweDsiPjx0ZXh0IHg9IjQ ![](data:image/svg+xml;base64,PHN2ZyBzdHlsZT0ibWF4LWhlaWdodDogNzBweDsiPjx0ZXh0IHg9IjQ [FPT_TST_EXT.1](#FPT_TST_EXT.1), [TSF](#abbr_TSF) Cryptographic [FPT_TST_EXT.1](#FPT_TST_EXT.1), [TSF](#abbr_TSF) Cryptographic Functionality Testing, requires the [TSF](#abbr_TSF) to run self-test at Functionality Testing, requires the [TSF](#abbr_TSF) to run self-test at start-up to verify correct operation. start-up to verify correct operation. FPT_TST_EXT.2, [TSF](#abbr_TSF) Integrity Checking, requires the FPT_TST_EXT.2, [TSF](#abbr_TSF) Integrity Checking, requires the [TSF](#abbr_TSF) to verify code and bootchain integrity is stored prior [TSF](#abbr_TSF) to verify code and bootchain integrity is stored prior to execution by a designated key or hash. to execution by a designated key or hash. [FPT_TST_EXT.3](#FPT_TST_EXT.3), [TSF](#abbr_TSF) Integrity Testing, [FPT_TST_EXT.3](#FPT_TST_EXT.3), [TSF](#abbr_TSF) Integrity Testing, requires the [TSF](#abbr_TSF) to validate a code signing certificate requires the [TSF](#abbr_TSF) to validate a code signing certificate before the associated code is executed. before the associated code is executed. #### Management: FPT_TST_EXT.1 #### Management: FPT_TST_EXT.1 There are no management activities foreseen. There are no management activities foreseen. #### Audit: FPT_TST_EXT.1 #### Audit: FPT_TST_EXT.1 The following actions should be auditable if FAU_GEN Security audit data The following actions should be auditable if FAU_GEN Security audit data generation is included in the [PP](#abbr_PP)/[ST](#abbr_ST): generation is included in the [PP](#abbr_PP)/[ST](#abbr_ST): - Initiation of self-test. - Initiation of self-test. - Failure of self-test. - Failure of self-test. #### FPT_TST_EXT.1 TSF Cryptographic Functionality Testing #### FPT_TST_EXT.1 TSF Cryptographic Functionality Testing ::: {style="margin-left: 1em;"} ::: {style="margin-left: 1em;"} ------------------ ----------------------------------- ------------------ ----------------------------------- Hierarchical to: No other components. Hierarchical to: No other components. Dependencies to: FCS_COP.1 Cryptographic Operation Dependencies to: FCS_COP.1 Cryptographic Operation ------------------ ----------------------------------- ------------------ ----------------------------------- #### FPT_TST_EXT.1.1 {#ext-comp-FPT_TST_EXT.1.1} #### FPT_TST_EXT.1.1 {#ext-comp-FPT_TST_EXT.1.1} The [TSF](#abbr_TSF) shall run a suite of self-tests during initial The [TSF](#abbr_TSF) shall run a suite of self-tests during initial start-up (on power on) to demonstrate the correct operation of all start-up (on power on) to demonstrate the correct operation of all cryptographic functionality. cryptographic functionality. ::: ::: #### Management: FPT_TST_EXT.2 #### Management: FPT_TST_EXT.2 There are no management activities foreseen. There are no management activities foreseen. #### Audit: FPT_TST_EXT.2 #### Audit: FPT_TST_EXT.2 The following actions should be auditable if FAU_GEN Security audit data The following actions should be auditable if FAU_GEN Security audit data generation is included in the [PP](#abbr_PP)/[ST](#abbr_ST): generation is included in the [PP](#abbr_PP)/[ST](#abbr_ST): - Start-up of [TOE](#abbr_TOE). - Start-up of [TOE](#abbr_TOE). - \[**selection**: [Detected integrity violation]{#_s_608 - \[**selection**: [Detected integrity violation]{#_s_608 .selectable-content}, [None]{#_s_609 .selectable-content}\] .selectable-content}, [None]{#_s_609 .selectable-content}\] #### FPT_TST_EXT.2 TSF Integrity Checking #### FPT_TST_EXT.2 TSF Integrity Checking ::: {style="margin-left: 1em;"} ::: {style="margin-left: 1em;"} ------------------ ----------------------------------- ------------------ ----------------------------------- Hierarchical to: No other components. Hierarchical to: No other components. Dependencies to: FCS_COP.1 Cryptographic Operation Dependencies to: FCS_COP.1 Cryptographic Operation ------------------ ----------------------------------- ------------------ ----------------------------------- #### FPT_TST_EXT.2.1 {#ext-comp-FPT_TST_EXT.2.1} #### FPT_TST_EXT.2.1 {#ext-comp-FPT_TST_EXT.2.1} The [TSF](#abbr_TSF) shall verify the integrity of \[**assignment**: The [TSF](#abbr_TSF) shall verify the integrity of \[**assignment**: [[TSF](#abbr_TSF) data]{.assignable-content}\] stored in mutable media [[TSF](#abbr_TSF) data]{.assignable-content}\] stored in mutable media prior to its execution through the use of \[**assignment**: prior to its execution through the use of \[**assignment**: [cryptographic or immutable hardware mechanism]{.assignable-content}\]. [cryptographic or immutable hardware mechanism]{.assignable-content}\]. ::: ::: #### Management: FPT_TST_EXT.3 #### Management: FPT_TST_EXT.3 There are no management activities foreseen. There are no management activities foreseen. #### Audit: FPT_TST_EXT.3 #### Audit: FPT_TST_EXT.3 There are no auditable events foreseen. There are no auditable events foreseen. #### FPT_TST_EXT.3 TSF Integrity Testing #### FPT_TST_EXT.3 TSF Integrity Testing ::: {style="margin-left: 1em;"} ::: {style="margin-left: 1em;"} ----------------------------------- ----------------------------------- ----------------------------------- ----------------------------------- Hierarchical to: No other components. Hierarchical to: No other components. Dependencies to: FPT_TST_EXT.2 [TSF](#abbr_TSF) Dependencies to: FPT_TST_EXT.2 [TSF](#abbr_TSF) Integrity Checking\ Integrity Checking\ FIA_X509_EXT.1 X.509 Validation of FIA_X509_EXT.1 X.509 Validation of Certificates\ Certificates\ FIA_X509_EXT.2 X.509 Certificate FIA_X509_EXT.2 X.509 Certificate Authentication Authentication ----------------------------------- ----------------------------------- ----------------------------------- ----------------------------------- #### FPT_TST_EXT.3.1 {#ext-comp-FPT_TST_EXT.3.1} #### FPT_TST_EXT.3.1 {#ext-comp-FPT_TST_EXT.3.1} The [TSF](#abbr_TSF) shall not execute code if the code signing The [TSF](#abbr_TSF) shall not execute code if the code signing certificate is deemed invalid. certificate is deemed invalid. ::: ::: ::: ::: ### C.2.5.8 FPT_TUD_EXT TSF Updates {#ext-comp-FPT_TUD_EXT .indexable level="4"} ### C.2.5.8 FPT_TUD_EXT TSF Updates {#ext-comp-FPT_TUD_EXT .indexable level="4"} ::: {style="margin-left: 1em;"} ::: {style="margin-left: 1em;"} #### Family Behavior #### Family Behavior
This family defines requirements for trusted updates. This family defines requirements for trusted updates.
#### Component Leveling #### Component Leveling ![](data:image/svg+xml;base64,PHN2ZyBzdHlsZT0ibWF4LWhlaWdodDogMTMwcHg7Ij48dGV4dCB4PSI ![](data:image/svg+xml;base64,PHN2ZyBzdHlsZT0ibWF4LWhlaWdodDogMTMwcHg7Ij48dGV4dCB4PSI [FPT_TUD_EXT.1](#FPT_TUD_EXT.1), [TSF](#abbr_TSF) Version Query, [FPT_TUD_EXT.1](#FPT_TUD_EXT.1), [TSF](#abbr_TSF) Version Query, requires the [TSF](#abbr_TSF) to provide authorized users the ability to requires the [TSF](#abbr_TSF) to provide authorized users the ability to query the version of the [TOE](#abbr_TOE) hardware, [TOE](#abbr_TOE) query the version of the [TOE](#abbr_TOE) hardware, [TOE](#abbr_TOE) software, and installed applications. software, and installed applications. [FPT_TUD_EXT.2](#FPT_TUD_EXT.2), [TSF](#abbr_TSF) Update Verification, [FPT_TUD_EXT.2](#FPT_TUD_EXT.2), [TSF](#abbr_TSF) Update Verification, requires the [TSF](#abbr_TSF) to ensure that system software updates are requires the [TSF](#abbr_TSF) to ensure that system software updates are digitally signed prior to installation. digitally signed prior to installation. [FPT_TUD_EXT.3](#FPT_TUD_EXT.3), Application Signing, requires the [FPT_TUD_EXT.3](#FPT_TUD_EXT.3), Application Signing, requires the [TSF](#abbr_TSF) to ensure that application software updates are [TSF](#abbr_TSF) to ensure that application software updates are digitally signed prior to installation. digitally signed prior to installation. [FPT_TUD_EXT.4](#FPT_TUD_EXT.4), Trusted Update Verification, requires [FPT_TUD_EXT.4](#FPT_TUD_EXT.4), Trusted Update Verification, requires the [TSF](#abbr_TSF) to enforce validity of system software's code the [TSF](#abbr_TSF) to enforce validity of system software's code signing certificate prior to installation. signing certificate prior to installation. [FPT_TUD_EXT.5](#FPT_TUD_EXT.5), Application Verification, requires the [FPT_TUD_EXT.5](#FPT_TUD_EXT.5), Application Verification, requires the [TSF](#abbr_TSF) to enforce validity of application software's code [TSF](#abbr_TSF) to enforce validity of application software's code signing certificate prior to installation. signing certificate prior to installation. [FPT_TUD_EXT.6](#FPT_TUD_EXT.6), Trusted Update Verification, requires [FPT_TUD_EXT.6](#FPT_TUD_EXT.6), Trusted Update Verification, requires the [TSF](#abbr_TSF) to prevent the intentional rollback of software the [TSF](#abbr_TSF) to prevent the intentional rollback of software updates. updates. #### Management: FPT_TUD_EXT.1 #### Management: FPT_TUD_EXT.1 There are no management activities foreseen. There are no management activities foreseen. #### Audit: FPT_TUD_EXT.1 #### Audit: FPT_TUD_EXT.1 There are no auditable events foreseen. There are no auditable events foreseen. #### FPT_TUD_EXT.1 TSF Version Query #### FPT_TUD_EXT.1 TSF Version Query ::: {style="margin-left: 1em;"} ::: {style="margin-left: 1em;"} ------------------ -------------------------- ------------------ -------------------------- Hierarchical to: No other components. Hierarchical to: No other components. Dependencies to: FMT_SMR.1 Security Roles Dependencies to: FMT_SMR.1 Security Roles ------------------ -------------------------- ------------------ -------------------------- #### FPT_TUD_EXT.1.1 {#ext-comp-FPT_TUD_EXT.1.1} #### FPT_TUD_EXT.1.1 {#ext-comp-FPT_TUD_EXT.1.1} The [TSF](#abbr_TSF) shall provide authorized users the ability to query The [TSF](#abbr_TSF) shall provide authorized users the ability to query the current version of the [TOE](#abbr_TOE) firmware/software. the current version of the [TOE](#abbr_TOE) firmware/software. #### FPT_TUD_EXT.1.2 {#ext-comp-FPT_TUD_EXT.1.2} #### FPT_TUD_EXT.1.2 {#ext-comp-FPT_TUD_EXT.1.2} The [TSF](#abbr_TSF) shall provide authorized users the ability to query The [TSF](#abbr_TSF) shall provide authorized users the ability to query the current version of the hardware model of the device. the current version of the hardware model of the device. #### FPT_TUD_EXT.1.3 {#ext-comp-FPT_TUD_EXT.1.3} #### FPT_TUD_EXT.1.3 {#ext-comp-FPT_TUD_EXT.1.3} The [TSF](#abbr_TSF) shall provide authorized users the ability to query The [TSF](#abbr_TSF) shall provide authorized users the ability to query the current version of installed mobile applications. the current version of installed mobile applications. ::: ::: #### Management: FPT_TUD_EXT.2 #### Management: FPT_TUD_EXT.2 The following actions could be considered for the management functions The following actions could be considered for the management functions in FMT: in FMT: - Updating of system software. - Updating of system software. #### Audit: FPT_TUD_EXT.2 #### Audit: FPT_TUD_EXT.2 The following actions should be auditable if FAU_GEN Security audit data The following actions should be auditable if FAU_GEN Security audit data generation is included in the [PP](#abbr_PP), generation is included in the [PP](#abbr_PP), [PP-Module](#abbr_PP-Module), functional package or [ST](#abbr_ST): [PP-Module](#abbr_PP-Module), functional package or [ST](#abbr_ST): - Success or failure of signature verification for applications. - Success or failure of signature verification for applications. #### FPT_TUD_EXT.2 TSF Update Verification #### FPT_TUD_EXT.2 TSF Update Verification ::: {style="margin-left: 1em;"} ::: {style="margin-left: 1em;"} ------------------ ----------------------------------- ------------------ ----------------------------------- Hierarchical to: No other components. Hierarchical to: No other components. Dependencies to: FCS_COP.1 Cryptographic Operation Dependencies to: FCS_COP.1 Cryptographic Operation ------------------ ----------------------------------- ------------------ ----------------------------------- #### FPT_TUD_EXT.2.1 {#ext-comp-FPT_TUD_EXT.2.1} #### FPT_TUD_EXT.2.1 {#ext-comp-FPT_TUD_EXT.2.1} The [TSF](#abbr_TSF) shall verify software updates to the Application The [TSF](#abbr_TSF) shall verify software updates to the Application Processor system software and \[**selection**: [\[**assignment**: [other Processor system software and \[**selection**: [\[**assignment**: [other processor system software]{.assignable-content}\]]{#_s_629 | processor system software]{.assignable-content}\]]{#fpt_tud_ext.2.1_1 .selectable-content}, [no other processor system software]{#_s_630 | .selectable-content}, [no other processor system .selectable-content}\] using a digital signature verified by the | software]{#fpt_tud_ext.2.1_3 .selectable-content}\] using a digital manufacturer trusted key prior to installing those updates. | signature verified by the manufacturer trusted key prior to installing > those updates. #### FPT_TUD_EXT.2.2 {#ext-comp-FPT_TUD_EXT.2.2} #### FPT_TUD_EXT.2.2 {#ext-comp-FPT_TUD_EXT.2.2} The [TSF](#abbr_TSF) shall \[**selection**: [never update]{#_s_631 | The [TSF](#abbr_TSF) shall \[**selection**: [never .selectable-content}, [update only by verified software]{#_s_632 | update]{#fpt_tud_ext.2.2_1 .selectable-content}, [update only by .selectable-content}\] the [TSF](#abbr_TSF) boot integrity | verified software]{#fpt_tud_ext.2.2_2 .selectable-content}\] the \[**selection**: [key]{#_s_633 .selectable-content}, [hash]{#_s_634 | [TSF](#abbr_TSF) boot integrity \[**selection**: > [key]{#fpt_tud_ext.2.2_3 .selectable-content}, [hash]{#fpt_tud_ext.2.2_4 .selectable-content}\]. .selectable-content}\]. #### FPT_TUD_EXT.2.3 {#ext-comp-FPT_TUD_EXT.2.3} #### FPT_TUD_EXT.2.3 {#ext-comp-FPT_TUD_EXT.2.3} The [TSF](#abbr_TSF) shall verify that the digital signature The [TSF](#abbr_TSF) shall verify that the digital signature verification key used for [TSF](#abbr_TSF) updates \[**selection**: [is verification key used for [TSF](#abbr_TSF) updates \[**selection**: [is validated to a public key in the Trust Anchor Database]{#_s_635 | validated to a public key in the Trust Anchor .selectable-content}, [matches an immutable hardware public key]{#_s_636 | Database]{#fpt_tud_ext.2.3_1 .selectable-content}, [matches an immutable .selectable-content}\]. | hardware public key]{#fpt_tud_ext.2.3_2 .selectable-content}\]. ::: ::: #### Management: FPT_TUD_EXT.3 #### Management: FPT_TUD_EXT.3 There are no management activities foreseen. There are no management activities foreseen. #### Audit: FPT_TUD_EXT.3 #### Audit: FPT_TUD_EXT.3 The following actions should be auditable if FAU_GEN Security audit data The following actions should be auditable if FAU_GEN Security audit data generation is included in the [PP](#abbr_PP), generation is included in the [PP](#abbr_PP), [PP-Module](#abbr_PP-Module), functional package or [ST](#abbr_ST): [PP-Module](#abbr_PP-Module), functional package or [ST](#abbr_ST): - Success or failure of signature verification for applications. - Success or failure of signature verification for applications. #### FPT_TUD_EXT.3 Application Signing #### FPT_TUD_EXT.3 Application Signing ::: {style="margin-left: 1em;"} ::: {style="margin-left: 1em;"} ------------------ ----------------------------------- ------------------ ----------------------------------- Hierarchical to: No other components. Hierarchical to: No other components. Dependencies to: FCS_COP.1 Cryptographic Operation Dependencies to: FCS_COP.1 Cryptographic Operation ------------------ ----------------------------------- ------------------ ----------------------------------- #### FPT_TUD_EXT.3.1 {#ext-comp-FPT_TUD_EXT.3.1} #### FPT_TUD_EXT.3.1 {#ext-comp-FPT_TUD_EXT.3.1} The [TSF](#abbr_TSF) shall verify mobile application software using a The [TSF](#abbr_TSF) shall verify mobile application software using a digital signature mechanism prior to installation. digital signature mechanism prior to installation. ::: ::: #### Management: FPT_TUD_EXT.4 #### Management: FPT_TUD_EXT.4 There are no management activities foreseen. There are no management activities foreseen. #### Audit: FPT_TUD_EXT.4 #### Audit: FPT_TUD_EXT.4 There are no auditable events foreseen. There are no auditable events foreseen. #### FPT_TUD_EXT.4 Trusted Update Verification #### FPT_TUD_EXT.4 Trusted Update Verification ::: {style="margin-left: 1em;"} ::: {style="margin-left: 1em;"} ----------------------------------- ----------------------------------- ----------------------------------- ----------------------------------- Hierarchical to: No other components. Hierarchical to: No other components. Dependencies to: FIA_X509_EXT.1 X.509 Validation of Dependencies to: FIA_X509_EXT.1 X.509 Validation of Certificates\ Certificates\ FIA_X509_EXT.2 X.509 Certificate FIA_X509_EXT.2 X.509 Certificate Authentication Authentication ----------------------------------- ----------------------------------- ----------------------------------- ----------------------------------- #### FPT_TUD_EXT.4.1 {#ext-comp-FPT_TUD_EXT.4.1} #### FPT_TUD_EXT.4.1 {#ext-comp-FPT_TUD_EXT.4.1} The [TSF](#abbr_TSF) shall not install code if the code signing The [TSF](#abbr_TSF) shall not install code if the code signing certificate is deemed invalid. certificate is deemed invalid. ::: ::: #### Management: FPT_TUD_EXT.5 #### Management: FPT_TUD_EXT.5 The following actions should be auditable if FAU_GEN Security audit data The following actions should be auditable if FAU_GEN Security audit data generation is included in the [PP](#abbr_PP)/[ST](#abbr_ST): generation is included in the [PP](#abbr_PP)/[ST](#abbr_ST): - Configure certificate or public key used to validate digital - Configure certificate or public key used to validate digital signature on applications. signature on applications. #### Audit: FPT_TUD_EXT.5 #### Audit: FPT_TUD_EXT.5 There are no auditable events foreseen. There are no auditable events foreseen. #### FPT_TUD_EXT.5 Application Verification #### FPT_TUD_EXT.5 Application Verification ::: {style="margin-left: 1em;"} ::: {style="margin-left: 1em;"} ----------------------------------- ----------------------------------- ----------------------------------- ----------------------------------- Hierarchical to: No other components. Hierarchical to: No other components. Dependencies to: FIA_X509_EXT.1 X.509 Validation of Dependencies to: FIA_X509_EXT.1 X.509 Validation of Certificates\ Certificates\ FIA_X509_EXT.2 X.509 Certificate FIA_X509_EXT.2 X.509 Certificate Authentication Authentication ----------------------------------- ----------------------------------- ----------------------------------- ----------------------------------- #### FPT_TUD_EXT.5.1 {#ext-comp-FPT_TUD_EXT.5.1} #### FPT_TUD_EXT.5.1 {#ext-comp-FPT_TUD_EXT.5.1} The [TSF](#abbr_TSF) shall by default only install mobile applications The [TSF](#abbr_TSF) shall by default only install mobile applications cryptographically verified by \[**selection**: [a built-in X.509v3 cryptographically verified by \[**selection**: [a built-in X.509v3 certificate]{#_s_637 .selectable-content}, [a configured X.509v3 | certificate]{#fpt_tud_ext.5.1_1 .selectable-content}, [a configured certificate]{#_s_638 .selectable-content}\]. | X.509v3 certificate]{#fpt_tud_ext.5.1_2 .selectable-content}\]. ::: ::: #### Management: FPT_TUD_EXT.6 #### Management: FPT_TUD_EXT.6 There are no management activities foreseen. There are no management activities foreseen. #### Audit: FPT_TUD_EXT.6 #### Audit: FPT_TUD_EXT.6 There are no auditable events foreseen. There are no auditable events foreseen. #### FPT_TUD_EXT.6 Trusted Update Verification #### FPT_TUD_EXT.6 Trusted Update Verification ::: {style="margin-left: 1em;"} ::: {style="margin-left: 1em;"} ------------------ ---------------------- ------------------ ---------------------- Hierarchical to: No other components. Hierarchical to: No other components. Dependencies to: No dependencies. Dependencies to: No dependencies. ------------------ ---------------------- ------------------ ---------------------- #### FPT_TUD_EXT.6.1 {#ext-comp-FPT_TUD_EXT.6.1} #### FPT_TUD_EXT.6.1 {#ext-comp-FPT_TUD_EXT.6.1} The [TSF](#abbr_TSF) shall verify that software updates to the The [TSF](#abbr_TSF) shall verify that software updates to the [TSF](#abbr_TSF) are a current or later version than the current version [TSF](#abbr_TSF) are a current or later version than the current version of the [TSF](#abbr_TSF). of the [TSF](#abbr_TSF). ::: ::: ::: ::: []{sortkey="Class FTA: TOE Access"} []{sortkey="Class FTA: TOE Access"} ### C.2.6 Class FTA: TOE Access {#ext-comp- .indexable level="3"} ### C.2.6 Class FTA: TOE Access {#ext-comp- .indexable level="3"} This [PP](#abbr_PP) defines the following extended components as part of This [PP](#abbr_PP) defines the following extended components as part of the class originally defined by [CC](#abbr_CC) Part 2: the class originally defined by [CC](#abbr_CC) Part 2: ### C.2.6.1 FTA_SSL_EXT Session Locking and Termination {#ext-comp-FTA_SSL_EXT .index ### C.2.6.1 FTA_SSL_EXT Session Locking and Termination {#ext-comp-FTA_SSL_EXT .index ::: {style="margin-left: 1em;"} ::: {style="margin-left: 1em;"} #### Family Behavior #### Family Behavior
This family defines requirements for session locking capabilities that This family defines requirements for session locking capabilities that are not addressed by FTA_SSL in [CC](#abbr_CC) Part 2. are not addressed by FTA_SSL in [CC](#abbr_CC) Part 2.
#### Component Leveling #### Component Leveling ![](data:image/svg+xml;base64,PHN2ZyBzdHlsZT0ibWF4LWhlaWdodDogMzBweDsiPjx0ZXh0IHg9IjQ ![](data:image/svg+xml;base64,PHN2ZyBzdHlsZT0ibWF4LWhlaWdodDogMzBweDsiPjx0ZXh0IHg9IjQ [FTA_SSL_EXT.1](#FTA_SSL_EXT.1), [TSF](#abbr_TSF)- and User-initiated [FTA_SSL_EXT.1](#FTA_SSL_EXT.1), [TSF](#abbr_TSF)- and User-initiated Locked State , requires the [TSF](#abbr_TSF) to manage the transition to Locked State , requires the [TSF](#abbr_TSF) to manage the transition to a locked state and what operations can be performed. a locked state and what operations can be performed. #### Management: FTA_SSL_EXT.1 #### Management: FTA_SSL_EXT.1 The following actions could be considered for the management functions The following actions could be considered for the management functions in FMT: in FMT: - Configuring session locking policy. - Configuring session locking policy. - Transitioning to the locked state. - Transitioning to the locked state. #### Audit: FTA_SSL_EXT.1 #### Audit: FTA_SSL_EXT.1 There are no auditable events foreseen. There are no auditable events foreseen. #### FTA_SSL_EXT.1 TSF- and User-initiated Locked State #### FTA_SSL_EXT.1 TSF- and User-initiated Locked State ::: {style="margin-left: 1em;"} ::: {style="margin-left: 1em;"} ----------------------------------- ----------------------------------- ----------------------------------- ----------------------------------- Hierarchical to: No other components. Hierarchical to: No other components. Dependencies to: FMT_SMR.1 Security Roles\ Dependencies to: FMT_SMR.1 Security Roles\ [FPT_STM.1](#FPT_STM.1) Reliable [FPT_STM.1](#FPT_STM.1) Reliable Time Stamps Time Stamps ----------------------------------- ----------------------------------- ----------------------------------- ----------------------------------- #### FTA_SSL_EXT.1.1 {#ext-comp-FTA_SSL_EXT.1.1} #### FTA_SSL_EXT.1.1 {#ext-comp-FTA_SSL_EXT.1.1} The [TSF](#abbr_TSF) shall transition to a locked state after a time The [TSF](#abbr_TSF) shall transition to a locked state after a time interval of inactivity. interval of inactivity. #### FTA_SSL_EXT.1.2 {#ext-comp-FTA_SSL_EXT.1.2} #### FTA_SSL_EXT.1.2 {#ext-comp-FTA_SSL_EXT.1.2} The [TSF](#abbr_TSF) shall transition to a locked state after initiation The [TSF](#abbr_TSF) shall transition to a locked state after initiation by either the user or the administrator. by either the user or the administrator. #### FTA_SSL_EXT.1.3 {#ext-comp-FTA_SSL_EXT.1.3} #### FTA_SSL_EXT.1.3 {#ext-comp-FTA_SSL_EXT.1.3} The [TSF](#abbr_TSF) shall, upon transitioning to the locked state, The [TSF](#abbr_TSF) shall, upon transitioning to the locked state, perform the following operations: perform the following operations: - Clearing or overwriting display devices, obscuring the previous - Clearing or overwriting display devices, obscuring the previous contents; contents; - \[**assignment**: [Other actions performed upon transitioning to the - \[**assignment**: [Other actions performed upon transitioning to the locked state]{.assignable-content}\]. locked state]{.assignable-content}\]. ::: ::: ::: ::: []{sortkey="Class FTP: Trusted Path/Channels"} []{sortkey="Class FTP: Trusted Path/Channels"} ### C.2.7 Class FTP: Trusted Path/Channels {#ext-comp- .indexable level="3"} ### C.2.7 Class FTP: Trusted Path/Channels {#ext-comp- .indexable level="3"} This [PP](#abbr_PP) defines the following extended components as part of This [PP](#abbr_PP) defines the following extended components as part of the class originally defined by [CC](#abbr_CC) Part 2: the class originally defined by [CC](#abbr_CC) Part 2: ### C.2.7.1 FTP_ITC_EXT Inter-TSF Trusted Channel {#ext-comp-FTP_ITC_EXT .indexable l ### C.2.7.1 FTP_ITC_EXT Inter-TSF Trusted Channel {#ext-comp-FTP_ITC_EXT .indexable l ::: {style="margin-left: 1em;"} ::: {style="margin-left: 1em;"} #### Family Behavior #### Family Behavior
This family defines requirements for trusted channels that are not This family defines requirements for trusted channels that are not addressed by FTP_ITC in [CC](#abbr_CC) Part 2 because they apply addressed by FTP_ITC in [CC](#abbr_CC) Part 2 because they apply specifically to channels required by a mobile device. specifically to channels required by a mobile device.
#### Component Leveling #### Component Leveling ![](data:image/svg+xml;base64,PHN2ZyBzdHlsZT0ibWF4LWhlaWdodDogMzBweDsiPjx0ZXh0IHg9IjQ ![](data:image/svg+xml;base64,PHN2ZyBzdHlsZT0ibWF4LWhlaWdodDogMzBweDsiPjx0ZXh0IHg9IjQ [FTP_ITC_EXT.1](#FTP_ITC_EXT.1), Trusted Channel Communication, requires [FTP_ITC_EXT.1](#FTP_ITC_EXT.1), Trusted Channel Communication, requires the [TSF](#abbr_TSF) to manage the communication channel between itself the [TSF](#abbr_TSF) to manage the communication channel between itself and other trusted products. and other trusted products. #### Management: FTP_ITC_EXT.1 #### Management: FTP_ITC_EXT.1 The following actions could be considered for the management functions The following actions could be considered for the management functions in FMT: in FMT: - Configuring the actions that require trusted channel, if applicable. - Configuring the actions that require trusted channel, if applicable. - Enabling/disabling communications protocols where the - Enabling/disabling communications protocols where the [TSF](#abbr_TSF) acts as a server. [TSF](#abbr_TSF) acts as a server. #### Audit: FTP_ITC_EXT.1 #### Audit: FTP_ITC_EXT.1 The following actions should be auditable if FAU_GEN Security audit data The following actions should be auditable if FAU_GEN Security audit data generation is included in the [PP](#abbr_PP), generation is included in the [PP](#abbr_PP), [PP-Module](#abbr_PP-Module), functional package or [ST](#abbr_ST): [PP-Module](#abbr_PP-Module), functional package or [ST](#abbr_ST): - Initiation and termination of trusted channel. - Initiation and termination of trusted channel. #### FTP_ITC_EXT.1 Trusted Channel Communication #### FTP_ITC_EXT.1 Trusted Channel Communication ::: {style="margin-left: 1em;"} ::: {style="margin-left: 1em;"} ------------------ ---------------------- ------------------ ---------------------- Hierarchical to: No other components. Hierarchical to: No other components. Dependencies to: No dependencies. Dependencies to: No dependencies. ------------------ ---------------------- ------------------ ---------------------- #### FTP_ITC_EXT.1.1 {#ext-comp-FTP_ITC_EXT.1.1} #### FTP_ITC_EXT.1.1 {#ext-comp-FTP_ITC_EXT.1.1} The [TSF](#abbr_TSF) shall use The [TSF](#abbr_TSF) shall use - 802.11-2012 in accordance with \[**assignment**: [requirements or - 802.11-2012 in accordance with \[**assignment**: [requirements or standards defining implementation of this standards defining implementation of this protocol]{.assignable-content}\], protocol]{.assignable-content}\], - 802.1X in accordance with \[**assignment**: [requirements or - 802.1X in accordance with \[**assignment**: [requirements or standards defining implementation of this standards defining implementation of this protocol]{.assignable-content}\], protocol]{.assignable-content}\], - [EAP](#abbr_EAP)-TLS in accordance with \[**assignment**: - [EAP](#abbr_EAP)-TLS in accordance with \[**assignment**: [requirements or standards defining implementation of this [requirements or standards defining implementation of this protocol]{.assignable-content}\], protocol]{.assignable-content}\], - Mutually authenticated [TLS](#abbr_TLS) in accordance with - Mutually authenticated [TLS](#abbr_TLS) in accordance with \[**assignment**: [requirements or standards defining implementation \[**assignment**: [requirements or standards defining implementation of this protocol]{.assignable-content}\] of this protocol]{.assignable-content}\] and \[**assignment**: [other protocols]{.assignable-content}\] protocols and \[**assignment**: [other protocols]{.assignable-content}\] protocols to provide a communication channel between itself and another trusted IT to provide a communication channel between itself and another trusted IT product using certificates as defined in \[**assignment**: [requirement product using certificates as defined in \[**assignment**: [requirement or standard defining the use of certificates]{.assignable-content}\] or standard defining the use of certificates]{.assignable-content}\] that is logically distinct from other communication channels, provides that is logically distinct from other communication channels, provides assured identification of its end points, protects channel data from assured identification of its end points, protects channel data from disclosure, and detects modification of the channel data. disclosure, and detects modification of the channel data. #### FTP_ITC_EXT.1.2 {#ext-comp-FTP_ITC_EXT.1.2} #### FTP_ITC_EXT.1.2 {#ext-comp-FTP_ITC_EXT.1.2} The [TSF](#abbr_TSF) shall permit the [TSF](#abbr_TSF) to initiate The [TSF](#abbr_TSF) shall permit the [TSF](#abbr_TSF) to initiate communication via the trusted channel. communication via the trusted channel. #### FTP_ITC_EXT.1.3 {#ext-comp-FTP_ITC_EXT.1.3} #### FTP_ITC_EXT.1.3 {#ext-comp-FTP_ITC_EXT.1.3} The [TSF](#abbr_TSF) shall initiate communication via the trusted The [TSF](#abbr_TSF) shall initiate communication via the trusted channel for wireless access point connections, administrative channel for wireless access point connections, administrative communication, configured enterprise connections, and \[**selection**: communication, configured enterprise connections, and \[**selection**: [[OTA](#abbr_OTA) updates]{#_s_642 .selectable-content}, [no other | [[OTA](#abbr_OTA) updates]{#ftp_itc_ext.1.3_1 .selectable-content}, [no connections]{#_s_643 .selectable-content}\]. | other connections]{#ftp_itc_ext.1.3_2 .selectable-content}\]. ::: ::: ::: ::: # Appendix D - Implicitly Satisfied Requirements {#satisfiedreqs .indexable level="A" # Appendix D - Implicitly Satisfied Requirements {#satisfiedreqs .indexable level="A" This appendix lists requirements that should be considered satisfied by This appendix lists requirements that should be considered satisfied by products successfully evaluated against this [PP](#abbr_PP). These products successfully evaluated against this [PP](#abbr_PP). These requirements are not featured explicitly as [SFRs](#abbr_SFR) and should requirements are not featured explicitly as [SFRs](#abbr_SFR) and should not be included in the [ST](#abbr_ST). They are not included as not be included in the [ST](#abbr_ST). They are not included as standalone [SFRs](#abbr_SFR) because it would increase the time, cost, standalone [SFRs](#abbr_SFR) because it would increase the time, cost, and complexity of evaluation. This approach is permitted by and complexity of evaluation. This approach is permitted by [\[CC\]](#bibCC) Part 1, 8.3 Dependencies between components. [\[CC\]](#bibCC) Part 1, 8.3 Dependencies between components. This information benefits systems engineering activities which call for This information benefits systems engineering activities which call for inclusion of particular security controls. Evaluation against the inclusion of particular security controls. Evaluation against the [PP](#abbr_PP) provides evidence that these controls are present and [PP](#abbr_PP) provides evidence that these controls are present and have been evaluated. have been evaluated. Requirement Ratio Requirement Ratio ----------------------------------------------------------------------------- ----- ----------------------------------------------------------------------------- ----- [FAU_SEL.1](#FAU_SEL.1) - Selective Audit [FAU_ [FAU_SEL.1](#FAU_SEL.1) - Selective Audit [FAU_ [FCS_STG_EXT.1](#FCS_STG_EXT.1) - Cryptographic Key Storage [FCS_ [FCS_STG_EXT.1](#FCS_STG_EXT.1) - Cryptographic Key Storage [FCS_ [FDP_ACF_EXT.1](#FDP_ACF_EXT.1) - Access Control for System Services [FDP_ [FDP_ACF_EXT.1](#FDP_ACF_EXT.1) - Access Control for System Services [FDP_ [FDP_ACF_EXT.2](#FDP_ACF_EXT.2) - Access Control for System Resources [FDP_ [FDP_ACF_EXT.2](#FDP_ACF_EXT.2) - Access Control for System Resources [FDP_ [FIA_AFL_EXT.1](#FIA_AFL_EXT.1) - Authentication Failure Handling [FIA_ [FIA_AFL_EXT.1](#FIA_AFL_EXT.1) - Authentication Failure Handling [FIA_ [FIA_PMG_EXT.1](#FIA_PMG_EXT.1) - Password Management [FIA_ [FIA_PMG_EXT.1](#FIA_PMG_EXT.1) - Password Management [FIA_ [FIA_UAU.7](#FIA_UAU.7) - Protected Authentication Feedback [FIA_ [FIA_UAU.7](#FIA_UAU.7) - Protected Authentication Feedback [FIA_ [FMT_MOF_EXT.1](#FMT_MOF_EXT.1) - Management of Security Functions Behavior [FMT_ [FMT_MOF_EXT.1](#FMT_MOF_EXT.1) - Management of Security Functions Behavior [FMT_ [FMT_SMF_EXT.3](#FMT_SMF_EXT.3) - Current Administrator [FMT_ [FMT_SMF_EXT.3](#FMT_SMF_EXT.3) - Current Administrator [FMT_ # Appendix E - Entropy Documentation And Assessment {#entropyappendix .indexable leve # Appendix E - Entropy Documentation And Assessment {#entropyappendix .indexable leve The documentation of the entropy source should be detailed enough that, The documentation of the entropy source should be detailed enough that, after reading, the evaluator will thoroughly understand the entropy after reading, the evaluator will thoroughly understand the entropy source and why it can be relied upon to provide entropy. This source and why it can be relied upon to provide entropy. This documentation should include multiple detailed sections: design documentation should include multiple detailed sections: design description, entropy justification, operating conditions, and health description, entropy justification, operating conditions, and health testing. This documentation is not required to be part of the testing. This documentation is not required to be part of the [TSS](#abbr_TSS). [TSS](#abbr_TSS). ## E.1 Design Description {#description .indexable level="2"} ## E.1 Design Description {#description .indexable level="2"} Documentation shall include the design of the entropy source as a whole, Documentation shall include the design of the entropy source as a whole, including the interaction of all entropy source components. It will including the interaction of all entropy source components. It will describe the operation of the entropy source to include how it works, describe the operation of the entropy source to include how it works, how entropy is produced, and how unprocessed (raw) data can be obtained how entropy is produced, and how unprocessed (raw) data can be obtained from within the entropy source for testing purposes. The documentation from within the entropy source for testing purposes. The documentation should walk through the entropy source design indicating where the should walk through the entropy source design indicating where the random comes from, where it is passed next, any post-processing of the random comes from, where it is passed next, any post-processing of the raw outputs (hash, XOR, etc.), if/where it is stored, and finally, how raw outputs (hash, XOR, etc.), if/where it is stored, and finally, how it is output from the entropy source. Any conditions placed on the it is output from the entropy source. Any conditions placed on the process (e.g., blocking) should also be described in the entropy source process (e.g., blocking) should also be described in the entropy source design. Diagrams and examples are encouraged.\ design. Diagrams and examples are encouraged.\ \ \ This design must also include a description of the content of the This design must also include a description of the content of the security boundary of the entropy source and a description of how the security boundary of the entropy source and a description of how the security boundary ensures that an adversary outside the boundary cannot security boundary ensures that an adversary outside the boundary cannot affect the entropy rate.\ affect the entropy rate.\ \ \ If implemented, the design description shall include a description of If implemented, the design description shall include a description of how third-party applications can add entropy to the DRBG. A description how third-party applications can add entropy to the DRBG. A description of any DRBG state saving between power-off and power-on shall be of any DRBG state saving between power-off and power-on shall be included. included. ## E.2 Entropy Justification {#justification .indexable level="2"} ## E.2 Entropy Justification {#justification .indexable level="2"} There should be a technical argument for where the unpredictability in There should be a technical argument for where the unpredictability in the source comes from and why there is confidence in the entropy source the source comes from and why there is confidence in the entropy source exhibiting probabilistic behavior (an explanation of the probability exhibiting probabilistic behavior (an explanation of the probability distribution and justification for that distribution given the distribution and justification for that distribution given the particular source is one way to describe this). This argument will particular source is one way to describe this). This argument will include a description of the expected entropy rate and explain how you include a description of the expected entropy rate and explain how you ensure that sufficient entropy is going into the [TOE](#abbr_TOE) ensure that sufficient entropy is going into the [TOE](#abbr_TOE) randomizer seeding process. This discussion will be part of a randomizer seeding process. This discussion will be part of a justification for why the entropy source can be relied upon to produce justification for why the entropy source can be relied upon to produce bits with entropy.\ bits with entropy.\ \ \ The entropy justification shall not include any data added from any The entropy justification shall not include any data added from any third-party application or from any state saving between restarts. third-party application or from any state saving between restarts. ## E.3 Operating Conditions {#conditions .indexable level="2"} ## E.3 Operating Conditions {#conditions .indexable level="2"} Documentation will also include the range of operating conditions under Documentation will also include the range of operating conditions under which the entropy source is expected to generate random data. It will which the entropy source is expected to generate random data. It will clearly describe the measures that have been taken in the system design clearly describe the measures that have been taken in the system design to ensure the entropy source continues to operate under those to ensure the entropy source continues to operate under those conditions. Similarly, documentation shall describe the conditions under conditions. Similarly, documentation shall describe the conditions under which the entropy source is known to malfunction or become inconsistent. which the entropy source is known to malfunction or become inconsistent. Methods used to detect failure or degradation of the source shall be Methods used to detect failure or degradation of the source shall be included. included. ## E.4 Health Testing {#testing .indexable level="2"} ## E.4 Health Testing {#testing .indexable level="2"} More specifically, all entropy source health tests and their rationale More specifically, all entropy source health tests and their rationale will be documented. This will include a description of the health tests, will be documented. This will include a description of the health tests, the rate and conditions under which each health test is performed (e.g., the rate and conditions under which each health test is performed (e.g., at startup, continuously, or on-demand), the expected results for each at startup, continuously, or on-demand), the expected results for each health test, and rationale indicating why each test is believed to be health test, and rationale indicating why each test is believed to be appropriate for detecting one or more failures in the entropy source. appropriate for detecting one or more failures in the entropy source. # Appendix F - Initialization Vector Requirements for NIST-Approved Cipher Modes {#ve # Appendix F - Initialization Vector Requirements for NIST-Approved Cipher Modes {#ve [Table [29]{.counter}: References and IV Requirements for [Table [29]{.counter}: References and IV Requirements for [NIST](#abbr_NIST)-approved Cipher Modes]{#ivtable .ctr myid="ivtable" [NIST](#abbr_NIST)-approved Cipher Modes]{#ivtable .ctr myid="ivtable" counter-type="ct-Table"} counter-type="ct-Table"} ----------------------------------------------------------------------------------- ----------------------------------------------------------------------------------- Cipher Mode Cipher Mode Electronic Codebook (ECB) Electronic Codebook (ECB) Counter (CTR) Counter (CTR) Cipher Block Chaining ([CBC](#abbr_CBC)) Cipher Block Chaining ([CBC](#abbr_CBC)) Output Feedback (OFB) Output Feedback (OFB) Cipher Feedback (CFB) Cipher Feedback (CFB) XEX (XOR Encrypt XOR) Tweakable Block Cipher with Ciphertext Stealing ([XTS](#abbr_ XEX (XOR Encrypt XOR) Tweakable Block Cipher with Ciphertext Stealing ([XTS](#abbr_ Cipher-based Message Authentication Code (CMAC) Cipher-based Message Authentication Code (CMAC) Key Wrap and Key Wrap with Padding Key Wrap and Key Wrap with Padding Counter with [CBC](#abbr_CBC)-Message Authentication Code ([CCM](#abbr_CCM)) Counter with [CBC](#abbr_CBC)-Message Authentication Code ([CCM](#abbr_CCM)) Galois Counter Mode ([GCM](#abbr_GCM)) Galois Counter Mode ([GCM](#abbr_GCM)) ----------------------------------------------------------------------------------- ----------------------------------------------------------------------------------- # Appendix G - Acronyms {#acronyms .indexable level="A"} # Appendix G - Acronyms {#acronyms .indexable level="A"} Acronym Meanin Acronym Meanin ---------------------------------------------------------------------------- ------ ---------------------------------------------------------------------------- ------ [[AEAD](#abbr_AEAD)]{#abbr_AEAD .term} [Authe [[AEAD](#abbr_AEAD)]{#abbr_AEAD .term} [Authe [[AES](#abbr_AES)]{#abbr_AES .term} [Advan [[AES](#abbr_AES)]{#abbr_AES .term} [Advan [[ANSI](#abbr_ANSI)]{#abbr_ANSI .term} [Ameri [[ANSI](#abbr_ANSI)]{#abbr_ANSI .term} [Ameri [[AP](#abbr_AP)]{#abbr_AP .term} [Appli [[AP](#abbr_AP)]{#abbr_AP .term} [Appli [[API](#abbr_API)]{#abbr_API .term} [Appli [[API](#abbr_API)]{#abbr_API .term} [Appli [[ASLR](#abbr_ASLR)]{#abbr_ASLR .term} [Addre [[ASLR](#abbr_ASLR)]{#abbr_ASLR .term} [Addre [[BAF](#abbr_BAF)]{#abbr_BAF .term plural="BAFs"} [Biome | [[BAF](#abbr_BAF)]{#abbr_BAF .term} [Biome [[Base-PP](#abbr_Base-PP)]{#abbr_Base-PP .term plural="Base-PPs"} [Base [[Base-PP](#abbr_Base-PP)]{#abbr_Base-PP .term plural="Base-PPs"} [Base [[BP](#abbr_BP)]{#abbr_BP .term plural="BPs"} [Baseb | [[BP](#abbr_BP)]{#abbr_BP .term} [Baseb [[BR/EDR](#abbr_BR/EDR)]{#abbr_BR/EDR .term} [(Blue [[BR/EDR](#abbr_BR/EDR)]{#abbr_BR/EDR .term} [(Blue [[BYOD](#abbr_BYOD)]{#abbr_BYOD .term} [Bring [[BYOD](#abbr_BYOD)]{#abbr_BYOD .term} [Bring [[CA](#abbr_CA)]{#abbr_CA .term} [Certi [[CA](#abbr_CA)]{#abbr_CA .term} [Certi [[CBC](#abbr_CBC)]{#abbr_CBC .term} [Ciphe [[CBC](#abbr_CBC)]{#abbr_CBC .term} [Ciphe [[CC](#abbr_CC)]{#abbr_CC .term} [Commo [[CC](#abbr_CC)]{#abbr_CC .term} [Commo [[CCM](#abbr_CCM)]{#abbr_CCM .term} [Count [[CCM](#abbr_CCM)]{#abbr_CCM .term} [Count [[CCMP](#abbr_CCMP)]{#abbr_CCMP .term} [[CCM] [[CCMP](#abbr_CCMP)]{#abbr_CCMP .term} [[CCM] [[CEM](#abbr_CEM)]{#abbr_CEM .term} [Commo [[CEM](#abbr_CEM)]{#abbr_CEM .term} [Commo [[CMC](#abbr_CMC)]{#abbr_CMC .term} [Certi [[CMC](#abbr_CMC)]{#abbr_CMC .term} [Certi [[CNSA](#abbr_CNSA)]{#abbr_CNSA .term} [Comme [[CNSA](#abbr_CNSA)]{#abbr_CNSA .term} [Comme [[cPP](#abbr_cPP)]{#abbr_cPP .term plural="cPPs"} [Colla [[cPP](#abbr_cPP)]{#abbr_cPP .term plural="cPPs"} [Colla [[CPU](#abbr_CPU)]{#abbr_CPU .term plural="CPUs"} [Centr | [[CPU](#abbr_CPU)]{#abbr_CPU .term} [Centr [[CRL](#abbr_CRL)]{#abbr_CRL .term} [Certi [[CRL](#abbr_CRL)]{#abbr_CRL .term} [Certi [[DAR](#abbr_DAR)]{#abbr_DAR .term} [Data [[DAR](#abbr_DAR)]{#abbr_DAR .term} [Data [[DEK](#abbr_DEK)]{#abbr_DEK .term plural="DEKs"} [Data | [[DEK](#abbr_DEK)]{#abbr_DEK .term} [Data [[DEK](#abbr_DEK)]{#abbr_DEK .term} [Data [[DEK](#abbr_DEK)]{#abbr_DEK .term} [Data [[DEP](#abbr_DEP)]{#abbr_DEP .term} [Data [[DEP](#abbr_DEP)]{#abbr_DEP .term} [Data [[DH](#abbr_DH)]{#abbr_DH .term} [Diffi [[DH](#abbr_DH)]{#abbr_DH .term} [Diffi [[DNS](#abbr_DNS)]{#abbr_DNS .term} [Domai [[DNS](#abbr_DNS)]{#abbr_DNS .term} [Domai [[DSA](#abbr_DSA)]{#abbr_DSA .term} [Digit [[DSA](#abbr_DSA)]{#abbr_DSA .term} [Digit [[DTLS](#abbr_DTLS)]{#abbr_DTLS .term} [Datag [[DTLS](#abbr_DTLS)]{#abbr_DTLS .term} [Datag [[EAP](#abbr_EAP)]{#abbr_EAP .term} [Exten [[EAP](#abbr_EAP)]{#abbr_EAP .term} [Exten [[EAPOL](#abbr_EAPOL)]{#abbr_EAPOL .term} [[EAP] [[EAPOL](#abbr_EAPOL)]{#abbr_EAPOL .term} [[EAP] [[ECDH](#abbr_ECDH)]{#abbr_ECDH .term} [Ellip [[ECDH](#abbr_ECDH)]{#abbr_ECDH .term} [Ellip [[ECDSA](#abbr_ECDSA)]{#abbr_ECDSA .term} [Ellip [[ECDSA](#abbr_ECDSA)]{#abbr_ECDSA .term} [Ellip [[EEPROM](#abbr_EEPROM)]{#abbr_EEPROM .term} [Elect [[EEPROM](#abbr_EEPROM)]{#abbr_EEPROM .term} [Elect [[EP](#abbr_EP)]{#abbr_EP .term} [Exten [[EP](#abbr_EP)]{#abbr_EP .term} [Exten [[EST](#abbr_EST)]{#abbr_EST .term} [Enrol [[EST](#abbr_EST)]{#abbr_EST .term} [Enrol [[FEK](#abbr_FEK)]{#abbr_FEK .term plural="FEKs"} [File | [[FEK](#abbr_FEK)]{#abbr_FEK .term} [File [[FFC](#abbr_FFC)]{#abbr_FFC .term} [Finit [[FFC](#abbr_FFC)]{#abbr_FFC .term} [Finit [[FIPS](#abbr_FIPS)]{#abbr_FIPS .term} [Feder [[FIPS](#abbr_FIPS)]{#abbr_FIPS .term} [Feder [[FM](#abbr_FM)]{#abbr_FM .term} [Frequ [[FM](#abbr_FM)]{#abbr_FM .term} [Frequ [[FP](#abbr_FP)]{#abbr_FP .term} [Funct [[FP](#abbr_FP)]{#abbr_FP .term} [Funct [[FQDN](#abbr_FQDN)]{#abbr_FQDN .term} [Fully [[FQDN](#abbr_FQDN)]{#abbr_FQDN .term} [Fully [[GCM](#abbr_GCM)]{#abbr_GCM .term} [Galoi [[GCM](#abbr_GCM)]{#abbr_GCM .term} [Galoi [[GPS](#abbr_GPS)]{#abbr_GPS .term} [Globa [[GPS](#abbr_GPS)]{#abbr_GPS .term} [Globa [[GPU](#abbr_GPU)]{#abbr_GPU .term} [Graph [[GPU](#abbr_GPU)]{#abbr_GPU .term} [Graph [[HDMI](#abbr_HDMI)]{#abbr_HDMI .term} [High [[HDMI](#abbr_HDMI)]{#abbr_HDMI .term} [High [[HMAC](#abbr_HMAC)]{#abbr_HMAC .term} [Keyed [[HMAC](#abbr_HMAC)]{#abbr_HMAC .term} [Keyed [[HTTPS](#abbr_HTTPS)]{#abbr_HTTPS .term} [Hyper [[HTTPS](#abbr_HTTPS)]{#abbr_HTTPS .term} [Hyper [[IEEE](#abbr_IEEE)]{#abbr_IEEE .term} [Insti [[IEEE](#abbr_IEEE)]{#abbr_IEEE .term} [Insti [[IP](#abbr_IP)]{#abbr_IP .term} [Inter [[IP](#abbr_IP)]{#abbr_IP .term} [Inter [[IPC](#abbr_IPC)]{#abbr_IPC .term} [Inter [[IPC](#abbr_IPC)]{#abbr_IPC .term} [Inter [[IPsec](#abbr_IPsec)]{#abbr_IPsec .term} [Inter [[IPsec](#abbr_IPsec)]{#abbr_IPsec .term} [Inter [[KAT](#abbr_KAT)]{#abbr_KAT .term plural="KATs"} [Known | [[KAT](#abbr_KAT)]{#abbr_KAT .term} [Known [[KDF](#abbr_KDF)]{#abbr_KDF .term} [Key D [[KDF](#abbr_KDF)]{#abbr_KDF .term} [Key D [[KEK](#abbr_KEK)]{#abbr_KEK .term} [Key E [[KEK](#abbr_KEK)]{#abbr_KEK .term} [Key E [[LE](#abbr_LE)]{#abbr_LE .term} [(Blue [[LE](#abbr_LE)]{#abbr_LE .term} [(Blue [[LTE](#abbr_LTE)]{#abbr_LTE .term} [Long [[LTE](#abbr_LTE)]{#abbr_LTE .term} [Long [[MD](#abbr_MD)]{#abbr_MD .term} [Mobil [[MD](#abbr_MD)]{#abbr_MD .term} [Mobil [[MDM](#abbr_MDM)]{#abbr_MDM .term} [Mobil [[MDM](#abbr_MDM)]{#abbr_MDM .term} [Mobil [[MMI](#abbr_MMI)]{#abbr_MMI .term} [Man-M [[MMI](#abbr_MMI)]{#abbr_MMI .term} [Man-M [[MMS](#abbr_MMS)]{#abbr_MMS .term} [Multi [[MMS](#abbr_MMS)]{#abbr_MMS .term} [Multi [[MMU](#abbr_MMU)]{#abbr_MMU .term} [Memor [[MMU](#abbr_MMU)]{#abbr_MMU .term} [Memor [[NFC](#abbr_NFC)]{#abbr_NFC .term} [Near [[NFC](#abbr_NFC)]{#abbr_NFC .term} [Near [[NIST](#abbr_NIST)]{#abbr_NIST .term} [Natio [[NIST](#abbr_NIST)]{#abbr_NIST .term} [Natio [[NTP](#abbr_NTP)]{#abbr_NTP .term} [Netwo [[NTP](#abbr_NTP)]{#abbr_NTP .term} [Netwo [[NX](#abbr_NX)]{#abbr_NX .term} [Never [[NX](#abbr_NX)]{#abbr_NX .term} [Never [[OCSP](#abbr_OCSP)]{#abbr_OCSP .term} [Onlin [[OCSP](#abbr_OCSP)]{#abbr_OCSP .term} [Onlin [[OE](#abbr_OE)]{#abbr_OE .term} [Opera [[OE](#abbr_OE)]{#abbr_OE .term} [Opera [[OID](#abbr_OID)]{#abbr_OID .term} [Objec [[OID](#abbr_OID)]{#abbr_OID .term} [Objec [[OS](#abbr_OS)]{#abbr_OS .term} [Opera [[OS](#abbr_OS)]{#abbr_OS .term} [Opera [[OTA](#abbr_OTA)]{#abbr_OTA .term} [Over [[OTA](#abbr_OTA)]{#abbr_OTA .term} [Over [[PAE](#abbr_PAE)]{#abbr_PAE .term} [Port [[PAE](#abbr_PAE)]{#abbr_PAE .term} [Port [[PBKDF](#abbr_PBKDF)]{#abbr_PBKDF .term} [Passw [[PBKDF](#abbr_PBKDF)]{#abbr_PBKDF .term} [Passw [[PD](#abbr_PD)]{#abbr_PD .term} [Prote [[PD](#abbr_PD)]{#abbr_PD .term} [Prote [[PIV](#abbr_PIV)]{#abbr_PIV .term} [Perso [[PIV](#abbr_PIV)]{#abbr_PIV .term} [Perso [[PMK](#abbr_PMK)]{#abbr_PMK .term} [Pairw [[PMK](#abbr_PMK)]{#abbr_PMK .term} [Pairw [[PP](#abbr_PP)]{#abbr_PP .term plural="PPs"} [Prote [[PP](#abbr_PP)]{#abbr_PP .term plural="PPs"} [Prote [[PP-Configuration](#abbr_PP-Configuration)]{#abbr_PP-Configuration .term} [Prote [[PP-Configuration](#abbr_PP-Configuration)]{#abbr_PP-Configuration .term} [Prote [[PP-Module](#abbr_PP-Module)]{#abbr_PP-Module .term} [Prote [[PP-Module](#abbr_PP-Module)]{#abbr_PP-Module .term} [Prote [[PRF](#abbr_PRF)]{#abbr_PRF .term} [Pseud [[PRF](#abbr_PRF)]{#abbr_PRF .term} [Pseud [[PSK](#abbr_PSK)]{#abbr_PSK .term plural="PSKs"} [Pre-S | [[PSK](#abbr_PSK)]{#abbr_PSK .term} [Pre-S [[PTK](#abbr_PTK)]{#abbr_PTK .term} [Pairw [[PTK](#abbr_PTK)]{#abbr_PTK .term} [Pairw [[RA](#abbr_RA)]{#abbr_RA .term} [Regis [[RA](#abbr_RA)]{#abbr_RA .term} [Regis [[RBG](#abbr_RBG)]{#abbr_RBG .term} [Rando [[RBG](#abbr_RBG)]{#abbr_RBG .term} [Rando [[REK](#abbr_REK)]{#abbr_REK .term plural="REKs"} [Root | [[REK](#abbr_REK)]{#abbr_REK .term} [Root [[ROM](#abbr_ROM)]{#abbr_ROM .term} [Read- [[ROM](#abbr_ROM)]{#abbr_ROM .term} [Read- [[RSA](#abbr_RSA)]{#abbr_RSA .term} [Rives [[RSA](#abbr_RSA)]{#abbr_RSA .term} [Rives [[SAFAR](#abbr_SAFAR)]{#abbr_SAFAR .term plural="SAFARs"} [Syste | [[SAFAR](#abbr_SAFAR)]{#abbr_SAFAR .term} [Syste [[SAR](#abbr_SAR)]{#abbr_SAR .term plural="SARs"} [Secur [[SAR](#abbr_SAR)]{#abbr_SAR .term plural="SARs"} [Secur [[SFR](#abbr_SFR)]{#abbr_SFR .term plural="SFRs"} [Secur [[SFR](#abbr_SFR)]{#abbr_SFR .term plural="SFRs"} [Secur [[SHA](#abbr_SHA)]{#abbr_SHA .term} [Secur [[SHA](#abbr_SHA)]{#abbr_SHA .term} [Secur [[SMS](#abbr_SMS)]{#abbr_SMS .term} [Short [[SMS](#abbr_SMS)]{#abbr_SMS .term} [Short [[SoC](#abbr_SoC)]{#abbr_SoC .term plural="SoCs"} [Syste | [[SoC](#abbr_SoC)]{#abbr_SoC .term} [Syste [[SPI](#abbr_SPI)]{#abbr_SPI .term} [Secur [[SPI](#abbr_SPI)]{#abbr_SPI .term} [Secur [[SSH](#abbr_SSH)]{#abbr_SSH .term} [Secur [[SSH](#abbr_SSH)]{#abbr_SSH .term} [Secur [[SSID](#abbr_SSID)]{#abbr_SSID .term} [Servi [[SSID](#abbr_SSID)]{#abbr_SSID .term} [Servi [[ST](#abbr_ST)]{#abbr_ST .term plural="STs"} [Secur [[ST](#abbr_ST)]{#abbr_ST .term plural="STs"} [Secur [[TLS](#abbr_TLS)]{#abbr_TLS .term} [Trans [[TLS](#abbr_TLS)]{#abbr_TLS .term} [Trans [[TOE](#abbr_TOE)]{#abbr_TOE .term plural="TOEs"} [Targe [[TOE](#abbr_TOE)]{#abbr_TOE .term plural="TOEs"} [Targe [[TSF](#abbr_TSF)]{#abbr_TSF .term} [[TOE] [[TSF](#abbr_TSF)]{#abbr_TSF .term} [[TOE] [[TSFI](#abbr_TSFI)]{#abbr_TSFI .term plural="TSFIs"} [[TSF] [[TSFI](#abbr_TSFI)]{#abbr_TSFI .term plural="TSFIs"} [[TSF] [[TSS](#abbr_TSS)]{#abbr_TSS .term} [[TOE] [[TSS](#abbr_TSS)]{#abbr_TSS .term} [[TOE] [[URI](#abbr_URI)]{#abbr_URI .term} [Unifo [[URI](#abbr_URI)]{#abbr_URI .term} [Unifo [[USB](#abbr_USB)]{#abbr_USB .term} [Unive [[USB](#abbr_USB)]{#abbr_USB .term} [Unive [[USSD](#abbr_USSD)]{#abbr_USSD .term} [Unstr [[USSD](#abbr_USSD)]{#abbr_USSD .term} [Unstr [[VPN](#abbr_VPN)]{#abbr_VPN .term} [Virtu [[VPN](#abbr_VPN)]{#abbr_VPN .term} [Virtu [[XCCDF](#abbr_XCCDF)]{#abbr_XCCDF .term} [eXten [[XCCDF](#abbr_XCCDF)]{#abbr_XCCDF .term} [eXten [[XTS](#abbr_XTS)]{#abbr_XTS .term} [XEX ( [[XTS](#abbr_XTS)]{#abbr_XTS .term} [XEX ( : [Table [30]{.counter}]{#t-acronyms .ctr myid="t-acronyms" : [Table [30]{.counter}]{#t-acronyms .ctr myid="t-acronyms" counter-type="ct-Table"}: Acronyms counter-type="ct-Table"}: Acronyms # Appendix H - Bibliography {#appendix-bibliography .indexable level="A"} # Appendix H - Bibliography {#appendix-bibliography .indexable level="A"} +-----------------------------------+-----------------------------------+ +-----------------------------------+-----------------------------------+ | Identifier | Title | | Identifier | Title | +===================================+===================================+ +===================================+===================================+ | [\[[CC](#abbr_CC)\]]{#bibCC} | [Common Criteria for Information | | [\[[CC](#abbr_CC)\]]{#bibCC} | [Common Criteria for Information | | | Technology Security Evaluation - | | | Technology Security Evaluation - | | | ]{.description} | | | ]{.description} | | | | | | | | | - [Part 1: Introduction and | | | - [Part 1: Introduction and | | | general | | | general | | | model](http | | | model](http | | | s://www.commoncriteriaportal.org/ | | | s://www.commoncriteriaportal.org/ | | | files/ccfiles/CC2022PART1R1.pdf), | | | files/ccfiles/CC2022PART1R1.pdf), | | | CCMB-2022-11-001, | | | CCMB-2022-11-001, | | | [CC](#abbr_CC):2022, Revision | | | [CC](#abbr_CC):2022, Revision | | | 1, November 2022. | | | 1, November 2022. | | | - [Part 2: Security functional | | | - [Part 2: Security functional | | | requirements](htt | | | requirements](htt | | | p://www.commoncriteriaportal.org/ | | | p://www.commoncriteriaportal.org/ | | | files/ccfiles/CC2022PART2R1.pdf), | | | files/ccfiles/CC2022PART2R1.pdf), | | | CCMB-2022-11-002, | | | CCMB-2022-11-002, | | | [CC](#abbr_CC):2022, Revision | | | [CC](#abbr_CC):2022, Revision | | | 1, November 2022. | | | 1, November 2022. | | | - [Part 3: Security assurance | | | - [Part 3: Security assurance | | | requirements](htt | | | requirements](htt | | | p://www.commoncriteriaportal.org/ | | | p://www.commoncriteriaportal.org/ | | | files/ccfiles/CC2022PART3R1.pdf), | | | files/ccfiles/CC2022PART3R1.pdf), | | | CCMB-2022-11-003, | | | CCMB-2022-11-003, | | | [CC](#abbr_CC):2022, Revision | | | [CC](#abbr_CC):2022, Revision | | | 1, November 2022. | | | 1, November 2022. | | | - [Part 4: Framework for the | | | - [Part 4: Framework for the | | | specification of evaluation | | | specification of evaluation | | | methods and | | | methods and | | | activities](htt | | | activities](htt | | | p://www.commoncriteriaportal.org/ | | | p://www.commoncriteriaportal.org/ | | | files/ccfiles/CC2022PART4R1.pdf), | | | files/ccfiles/CC2022PART4R1.pdf), | | | CCMB-2022-11-004, | | | CCMB-2022-11-004, | | | [CC](#abbr_CC):2022, Revision | | | [CC](#abbr_CC):2022, Revision | | | 1, November 2022. | | | 1, November 2022. | | | - [Part 5: Pre-defined packages | | | - [Part 5: Pre-defined packages | | | of security | | | of security | | | requirements](htt | | | requirements](htt | | | p://www.commoncriteriaportal.org/ | | | p://www.commoncriteriaportal.org/ | | | files/ccfiles/CC2022PART5R1.pdf), | | | files/ccfiles/CC2022PART5R1.pdf), | | | CCMB-2022-11-005, | | | CCMB-2022-11-005, | | | [CC](#abbr_CC):2022, Revision | | | [CC](#abbr_CC):2022, Revision | | | 1, November 2022. | | | 1, November 2022. | +-----------------------------------+-----------------------------------+ +-----------------------------------+-----------------------------------+ | [\[[CEM](#abbr_CEM)\]]{#bibCEM} | [Common Methodology for | | [\[[CEM](#abbr_CEM)\]]{#bibCEM} | [Common Methodology for | | | Information Technology Security | | | Information Technology Security | | | Evaluation - ]{.description} | | | Evaluation - ]{.description} | | | | | | | | | - [Evaluation | | | - [Evaluation | | | methodology] | | | methodology] | | | (http://www.commoncriteriaportal. | | | (http://www.commoncriteriaportal. | | | org/files/ccfiles/CEM2022R1.pdf), | | | org/files/ccfiles/CEM2022R1.pdf), | | | CCMB-2022-11-006, | | | CCMB-2022-11-006, | | | [CC](#abbr_CC):2022, Revision | | | [CC](#abbr_CC):2022, Revision | | | 1, November 2022. | | | 1, November 2022. | +-----------------------------------+-----------------------------------+ +-----------------------------------+-----------------------------------+ | [\[Errata\]]{#bibCCerrata} | [ [Errata and Interpretation for | | [\[Errata\]]{#bibCCerrata} | [ [Errata and Interpretation for | | | CC:2022 (Release 1) and CEM:2022 | | | CC:2022 (Release 1) and CEM:2022 | | | (Release | | | (Release | | | 1)](https://ww | | | 1)](https://ww | | | w.commoncriteriaportal.org/files/ | | | w.commoncriteriaportal.org/files/ | | | ccfiles/CCMB-2025-001-v1_2-Errata | | | ccfiles/CCMB-2025-001-v1_2-Errata | | | _Interpretation_CC_CEM_2022.pdf), | | | _Interpretation_CC_CEM_2022.pdf), | | | Version 1.2 ]{.description} | | | Version 1.2 ]{.description} | +-----------------------------------+-----------------------------------+ +-----------------------------------+-----------------------------------+ | [\[OMB\]]{#bibOMB} | [ [Reporting Incidents Involving | | | [\[OMB\]]{#bibOMB} | [[Reporting Incidents Involving | | | Personally Identifiable | | | Personally Identifiable | | | Information and Incorporating the | | | Information and Incorporating the | | | Cost for Security in Agency | | | Cost for Security in Agency | | | Information Technology | | | Information Technology | | | Investments](http://www.wh | | | Investments](http://www.wh | | | itehouse.gov/sites/default/files/ | | | itehouse.gov/sites/default/files/ | | | omb/memoranda/fy2006/m06-19.pdf), | | | omb/memoranda/fy2006/m06-19.pdf), | | | OMB M-06-19, July 12, 2006. | | | OMB M-06-19, July 12, 2006. | | | ]{.description} | | | ]{.description} | +-----------------------------------+-----------------------------------+ +-----------------------------------+-----------------------------------+ : [Table [31]{.counter}]{#t-biblio .ctr myid="t-biblio" : [Table [31]{.counter}]{#t-biblio .ctr myid="t-biblio" counter-type="ct-Table"}: Bibliography counter-type="ct-Table"}: Bibliography # Appendix I - Acknowledgments {#ack .indexable level="A"} # Appendix I - Acknowledgments {#ack .indexable level="A"} This protection profile was developed by the Mobility Technical This protection profile was developed by the Mobility Technical Community with representatives from industry, U.S. Government agencies, Community with representatives from industry, U.S. Government agencies, Common Criteria Test Laboratories, and international Common Criteria Common Criteria Test Laboratories, and international Common Criteria schemes. The National Information Assurance Partnership wishes to schemes. The National Information Assurance Partnership wishes to acknowledge and thank the members of this group whose dedicated efforts acknowledge and thank the members of this group whose dedicated efforts contributed significantly to the publication. These organizations contributed significantly to the publication. These organizations include:\ include:\ \ \ **U.S. Government**\ **U.S. Government**\ Defense Information Systems Agency (DISA)\ Defense Information Systems Agency (DISA)\ CyberSecurity Directorate (CSD)\ CyberSecurity Directorate (CSD)\ National Information Assurance Partnership (NIAP)\ National Information Assurance Partnership (NIAP)\ National Institute of Standards and Technology ([NIST](#abbr_NIST))\ National Institute of Standards and Technology ([NIST](#abbr_NIST))\ \ \ **International Common Criteria Schemes**\ **International Common Criteria Schemes**\ Australian Information Security Evaluation Program (AISEP)\ Australian Information Security Evaluation Program (AISEP)\ Canadian Common Criteria Evaluation and Certification Scheme (CSEC)\ Canadian Common Criteria Evaluation and Certification Scheme (CSEC)\ Information-technology Promotion Agency, Japan (IPA)\ Information-technology Promotion Agency, Japan (IPA)\ UK IT Security Evaluation and Certificate Scheme (NCSC)\ UK IT Security Evaluation and Certificate Scheme (NCSC)\ \ \ **Industry**\ **Industry**\ Apple, Inc.\ Apple, Inc.\ BlackBerry\ BlackBerry\ Google, LLC\ Google, LLC\ LG Electronics, Inc.\ LG Electronics, Inc.\ Microsoft Corporation\ Microsoft Corporation\ Motorola Solutions\ Motorola Solutions\ Samsung Electronics Co., Ltd.\ Samsung Electronics Co., Ltd.\ Other Members of the Mobility Technical Community\ Other Members of the Mobility Technical Community\ \ \ **Common Criteria Test Laboratories**\ **Common Criteria Test Laboratories**\ EWA-Canada, Ltd.\ EWA-Canada, Ltd.\ Gossamer Security Solutions\ Gossamer Security Solutions\