SERTIT, P.O. Box 14, N-1306 Bærum postterminal, NORWAY Phone: +47 67 86 40 00 Fax: +47 67 86 40 09 E-mail: post@sertit.no Internet: www.sertit.no Sertifiseringsmyndigheten for IT-sikkerhet Norwegian Certification Authority for IT Security SERTIT-031 CR Certification Report Issue 1.0 26 September 2011 ZTE Mobile Switching Center Server / intelligent Controller Extensive, ZXWN MSCS / ZXUN iCX v4.10.13, ZXUN LIG v3.10.22 CERTIFICATION REPORT - SERTIT STANDARD REPORT TEMPLATE SD 009 VERSION 2.0 13.09.2007 ZTE Mobile Switching Center Server / intelligent Controller Extensive Version ZXWN MSCS / ZXUN iCX v4.10.13, ZXUN LIG v3.10.22 EAL2+ Page 2 of 21 SERTIT-031 CR Issue 1.0 26 September 2011 ARRANGEMENT ON THE RECOGNITION OF COMMON CRITERIA CERTIFICATES IN THE FIELD OF INFORMATION TECHNOLOGY SECURITY SERTIT, the Norwegian Certification Authority for IT Security, is a member of the above Arrangement and as such this confirms that the Common Criteria certificate has been issued by or under the authority of a Party to this Arrangement and is the Party’s claim that the certificate has been issued in accordance wit h the terms of this Arrangement The judgements contained in the certificate and Certification Report are those of SERTIT which issued it and the Norwegian evaluation facility (EVIT) which carried out the evaluation. There is no implication of acceptance by other Members of the Agreement Group of liability in respect of those judgements or for loss sustained as a result of reliance placed upon those judgements by a third party. [*] * Mutual Recognition under the CC recognition arrangement applies to EAL 2 but not to ALC_FLR.2. ZTE Mobile Switching Center Server / intelligent Controller Extensive Version ZXWN MSCS / ZXUN iCX v4.10.13, ZXUN LIG v3.10.22 EAL2+ SERTIT-031 CR Issue 1.0 26 September 2011 Page 3 of 21 Contents 1 Certification Statement 5 2 Abbreviations 6 3 References 8 4 Executive Summary 9 4.1 Introduction 9 4.2 Evaluated Product 9 4.3 TOE scope 9 4.4 Protection Profile Conformance 9 4.5 Assurance Level 9 4.6 Security Policy 9 4.7 Security Claims 10 4.8 Threats Countered 10 4.9 Threats Countered by the TOE’s environment 10 4.10 Threats and Attacks not Countered 10 4.11 Environmental Assumptions and Dependencies 10 4.12 IT Security Objectives 11 4.13 Non-IT Security Objectives 12 4.14 Security Functional Requirements 12 4.14.1 CUS-related SFRs 13 4.14.2 LIG-related SFRs 13 4.14.3 OMM-related SFRs 13 4.14.4 Common SFRs 14 4.15 Security Function Policy 14 4.16 Evaluation Conduct 14 4.17 General Points 14 5 Evaluation Findings 15 5.1 Introduction 16 5.2 Delivery 16 5.3 Installation and Guidance Documentation 16 5.4 Misuse 16 5.5 Vulnerability Analysis 16 5.6 Developer’s Tests 17 5.7 Evaluators’ Tests 17 6 Evaluation Outcome 17 6.1 Certification Result 17 6.2 Recommendations 17 Annex A: Evaluated Configuration 19 TOE Identification 19 TOE Documentation 20 TOE Configuration 21 ZTE Mobile Switching Center Server / intelligent Controller Extensive Version ZXWN MSCS / ZXUN iCX v4.10.13, ZXUN LIG v3.10.22 EAL2+ Page 4 of 21 SERTIT-031 CR Issue 1.0 26 September 2011 ZTE Mobile Switching Center Server I intelligent Controller Extensive EAl2+ Version ZXWN MSCS I ZXUN iCX v4.10.13, ZXUN L1G v3.10.22 .. , .. ­ • • • • • • • • • _ . " • • • • • • 0 • • • . .... . • • • • • • • - '0' • • •• o • • • • • _, • • • •• or • • • • • • • ••• '0' • • • ••• • • " r _ . ' ••• r • • • _ o • • • .................... 1 Certification Statement ZTE Corporation ZTE Mobile Switching Center Server I intelligent Controller Extensive is a softswitch plus clients that together perform the management and control function in an Intelligent Multimedia Subsystem network. ZTE Mobile Switching Center Server I intelligent Controller Extensive version ZXWN MSCS I ZXUN iCX v4.10.13, ZXUN L1G v3.10.22 has been evaluated under the terms of the Norwegian Certification Scheme for IT Security and have met the Common Criteria Part 3 augmented requirements of Evaluation Assurance level EAl2 augmented with AlC_FlR.2 for the specified Common Criteria Part 2 extended functionality for the specified environment when running on the platforms specified in Annex A. """"-------- -.--..-.-.-.-"'"T"--~-------- ---_ _ _._.._-_._--_.- ., IAu thor Kjarta n Jceger Kvassnes Certifier I' f£~ -~ Quality Assurance Lars Bargas Q U a1 L _ -.--