Certification Report **EAL 2 Evaluation of** **E DATA Elektronik San. Ve Tic. A.Ş.** **Change v06.00** issued by **Turkish Standards Institution** **Common Criteria Certification Scheme** *Certificate Number: 21.0.03/TSE-CCCS-44* ***TABLE OF CONTENTS*** ***Document InformatIon 3*** ***Document Change Log 3*** ***DISCLAIMER 4*** ***FOREWORD 4*** ***RECOGNITION OF THE CERTIFICATE 5*** ***1. EXECUTIVE SUMMARY 6*** ***1.1 BrIef DescrIptIon 6*** ***1.2 Major SecurIty Features 7*** ***1.3 Threats 8*** ***2. CERTIFICATION RESULTS 10*** ***2.1. IdentIfIcatIon of Target of EvaluatIon 10*** ***2.2. SecurIty PolIcy 11*** ***2.3. AssumptIons and ClarIfIcatIon of Scope 13*** ***2.4. ArchItectural InformatIon 14*** ***2.5. DocumentatIon 15*** ***2.6. IT Product TestIng 15*** ***2.7. Evaluated ConfIguratIon 16*** ***2.8. Results of the EvaluatIon 18*** ***2.9. Evaluator Comments / RecommendatIons 19*** ***3. SECURITY TARGET 20*** ***4. GLOSSARY 21*** ***5. BIBLIOGRAPHY 22*** ***6. ANNEXES 22*** ### Document Information | ***Date of Issue*** | ***23.08.2017*** | |-----------------------------------|-------------------------------------------| | ***Approval Date*** | ***24.08.2017*** | | ***Certification Report Number*** | ***21.0.03/17-008*** | | ***Sponsor and Developer*** | ***E DATA Elektronik San. ve Tic. A.Ş.*** | | ***Evaluation Lab*** | ***TÜBİTAK BİLGEM TDBY OKTEM*** | | ***TOE*** | ***Change v06.00*** | | ***Pages*** | ***22*** | | ***Prepared by*** | ***İbrahim Halil KIRMIZI*** | |---------------------|-------------------------------| | ***Reviewed by*** | ***Zümrüt MÜFTÜOĞLU*** | This report has been prepared by the Certification Expert and reviewed by the Technical Responsible of which signatures are above. ### Document Change Log | ***Release*** | ***Date*** | ***Pages Affected*** | ***Remarks/Change Reference*** | |-----------------|------------------|------------------------|----------------------------------| | ***1.0*** | ***23.08.2017*** | ***All*** | ***First Release*** | ### DISCLAIMER ***This certification report and the IT product defined in the associated Common Criteria document has been evaluated at an accredited and licensed evaluation facility conformance to Common Criteria for IT Security Evaluation, version 3.1, revision 4, using Common Methodology for IT Products Evaluation, version 3.1, revision 4. This certification report and the associated Common Criteria document apply only to the identified version and release of the product in its evaluated configuration. Evaluation has been conducted in accordance with the provisions of the CCCS, and the conclusions of the evaluation facility in the evaluation report are consistent with the evidence adduced.*** ### FOREWORD ***The Certification Report is drawn up to submit the Certification Commission the results and evaluation information upon the completion of a Common Criteria evaluation service performed under the Common Criteria Certification Scheme. Certification Report covers all non-confidential security and technical information related with a Common Criteria evaluation which is made under the ITCD Common Criteria Certification Scheme. This report is issued publicly to and made available to all relevant parties for reference and use.*** ***The Common Criteria Certification Scheme (CCCS) provides an evaluation and certification service to ensure the reliability of Information Security (IS) products. Evaluation and tests are conducted by a public or commercial Common Criteria Evaluation Facility (CCTL = Common Criteria Testing Laboratory) under CCCS’ supervision.*** ***CCTL is a facility, licensed as a result of inspections carried out by CCCS for performing tests and evaluations which will be the basis for Common Criteria certification. As a prerequisite for such certification, the CCTL has to fulfill the requirements of the standard ISO/IEC 17025 and should be accredited by accreditation bodies. The evaluation and tests related with the concerned product have been performed by TÜBİTAK BİLGEM TDBY OKTEM which is a public CCTL*** *.* ***A Common Criteria Certificate given to a product means that such product meets the security requirements defined in its security target document that has been approved by the CCCS. The Security Target document is where requirements defining the scope of evaluation and test activities*** *are set forth. Along with this certification report, the user of the IT product should also review the security target document in order to understand any assumptions made in the course of evaluations, the environment where the IT product will run, security requirements of the IT product and the level of assurance provided by the product.* *This certification report is associated with the Common Criteria Certificate issued by the CCCS for Change v06.00 whose evaluation was completed on 02.08.2017 and whose evaluation technical report was drawn up by TÜBİTAK BİLGEM TDBY OKTEM (as CCTL), and with the Security Target document with version no 0.8 of the relevant product.* *The certification report, certificate of product evaluation and security target document are posted on the ITCD Certified Products List at bilisim.tse.org.tr portal and the Common Criteria Portal (the official web site of the Common Criteria Project).* ### RECOGNITION OF THE CERTIFICATE ***The Common Criteria Recognition Arrangement logo is printed on the certificate to indicate that this certificate is issued in accordance with the provisions of the CCRA.*** ***The CCRA has been signed by the Turkey in 2003 and provides mutual recognition of certificates based on the CC evaluation assurance levels up to and including EAL4. The current list of signatory nations and approved certification schemes can be found on:*** [***http://www.commoncriteriaportal.org***](http://www.commoncriteriaportal.org/) ## 1 EXECUTIVE SUMMARY ## This report constitutes the certification results by the certification body on the evaluation results applied with requirements of the Common Criteria for Information Security Evaluation. ## **Evaluated IT product name: Change** **IT Product version: v06.00** **Developer’s Name: E DATA Elektronik San. ve Tic. A.Ş.** **Name of CCTL: TÜBİTAK BİLGEM TDBY OKTEM** **Assurance Package: EAL 2** **Completion date of evaluation:** 02.08.2017 **Hash of the TOE:** SHA-256 (17ba0c8d6b34462ed72342e5da5e65e40e6160607f7dfc43e1288973896481be) ## ## 2 Brief Description The TOE is a Fiscal Application Software and Software Crypto Library which are the main items of a Fiscal Cash Register (FCR). TOE is used to process transaction amount of purchases to be viewed by both seller and buyer. This transaction amount is used to determine tax revenues. Therefore, secure processing, storing and transmitting of this data is very important. The FCR is mandatory for first-and second-class traders. FCR is not mandatory for sellers who sell the goods back to its previous seller completely the same as the purchased good. Figure 1 shows the general overview of the TOE and related components. The green part of Figure 1 is the TOE. The operational environment is also shown in the figure including Input/output interface, fiscal memory, daily memory, database, ERU, fiscal certificate memory. These components are non-TOE environments which are crucial parts of the FCR for functionality and security. Connections between the TOE and its environment are also subject of the evaluation since they are interfaces of the TOE. **Figure 1 - TOE and Related Components** ## 3 Major Security Features TOE Security Functions are; - TOE supports access control. - TOE has the ability to detect disconnection between main processor and fiscal memory and should enter into the maintenance mode. - TOE supports usage of ITU X509 v3 formatted certificate and its protected private key for authentication and secure communication with PRA- IS and TSM. - TOE supports secure communication between EFT-POS/Smart PinPad. - TOE supports secure communication with FCR-PRA-IS and FCR–TSM - TOE ensures the integrity of event data, sales data, authentication data, characterization data and FCR parameters. - TOE records important events given in PRA Messaging Protocol document and send urgent event data to PRA-IS in a secure way. - TOE detects physical attacks to FCR and enters into the maintenance mode. ## 4 Threats The threats are; - **T.AccessControl** Adverse action: Authenticated users could try to use functions which are not allowed. (e.g. FCR Authorized Users gaining access to Authorized Manufacturer User functions) Threat agent: An attacker who has basic attack potential has physical and logical access to FCR. Asset: Event data, sales data, time information. - **T.Authentication** Adverse action: Unauthenticated users could try to use FCR functions except doing fiscal sales and taking reports which are not fiscal. Threat agent: An attacker who has basic attack potential, has logical and physical access to the FCR. Asset: Sales data, event data, time information - **T.MDData – Manipulation and disclosure of data** Adverse action: This threat deals with five types of data: event data, sales data, characterization data, authentication data and FCR parameters. - An attacker could try to manipulate the event data to hide its actions and unauthorized access to the FCR, failure reports, and deletion of logs. An attacker also could try to disclose important events while transmitted between PRA-IS and FCR. - An attacker could try to manipulate or delete the sales data generated by TOE which may result in tax fraud. In addition, an attacker also could try to disclose sales data while transmitted between PRA-IS and FCR. Manipulation and deletion of sales data located in FCR may be caused by magnetic and electronic reasons. - An attacker could try to manipulate the characterization data to cover information about tax fraud; to masquerade the user identity. - An attacker could try to manipulate the FCR parameters to use FCR in undesired condition. - An attacker also could try to disclose and modify authentication data in FCR to gain access to functions which are not allowed to his/her. Threat agent: An attacker who has basic attack potential, has physical and logical access to the FCR. Asset: Event data, sales data, characterization data, FCR parameters and authentication data. - **T.Eavesdrop – Eavesdropping on event data, sales data and characterization data** Adverse action: An attacker could try to eavesdrop event data, sales data and characterization data transmitted between the TOE and the PRA-IS and also between the TOE and the distributed memory units (Fiscal Memory, Database, Daily Memory and ERU). Threat agent: An attacker who has basic attack potential, has physical access to the FCR and physical access to the FCR communication channel. Asset: Characterization data, sales data, and event data. - **T.Counterfeit – FCR counterfeiting** Adverse action: An attacker could try to imitate FCR by using sensitive data while communicating with PRA-IS and TSM to cover information about tax fraud. Threat agent: An attacker who has basic attack potential and has physical and logical access to the FCR. Asset: Sensitive data - **T.Server counterfeiting** Adverse action: An attacker could try to imitate PRA-IS by changing server certificates (P PRA , P PRA-SIGN , P TSM , P TSM-SIGN ) in FCR. In this way, the attacker could try to receive information from FCR while communicating with PRA-IS and to imitate TSM to set parameters to FCR. Threat agent: An attacker who has basic attack potential, has physical and logical access to the FCR. Asset: Server Certificates - **T.Malfunction – Cause malfunction in FCR** Adverse action: An attacker may try to use FCR out of its normal operational conditions to cause malfunction without the knowledge of TOE. Threat agent: An attacker who has basic attack potential, has physical access to the FCR. Asset: Sales data, event data - **T.ChangingTime** Adverse action: An attacker may try to change time to invalidate the information about logged events and reports in FCR. Threat agent: An attacker who has basic attack potential, has physical and logical access to the FCR. Asset: Time Information. ## 5 CERTIFICATION RESULTS ## ## 6 Identification of Target of Evaluation | Certificate Number | 21.0.03/TSE-CCCS-44 | |-------------------------|------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------| | TOE Name and Version | Change v06.00 | | Security Target Title | Change v 06.00 Security Target | | Security Target Version | V0.8 | | Security Target Date | 31.08.2017 | | Assurance Level | EAL 2 | | Criteria | Common Criteria for Information Technology Security Evaluation, Part 1: Introduction and General Model; CCMB-2012-09-001, Version 3.1, Revision 4, September 2012 Common Criteria for Information Technology Security Evaluation, Part 2: Security Functional Components; CCMB-2012-09-002, Version 3.1 Revision 4, September 2012 Common Criteria for Information Technology Security Evaluation, Part 3: Security Assurance Components; CCMB-2012-09-003, Version 3.1 Revision 4, September 2012 | | Methodology | Common Criteria for Information Technology Security Evaluation, Evaluation Methodology; CCMB-2012-09-004, Version 3.1, Revision 4, September 2012 | |--------------------------------|------------------------------------------------------------------------------------------------------------------------------------------------------------| | Protection Profile Conformance | Common Criteria Protection Profile for New Generation Cash Register Fiscal Application Software 2 (NGCRFAS-2 PP) TSE-CCCS/PP-008, version 1.3, 06 May 2015 | ## ## 7 Security Policy Organizational Security Policies are; - **P.Certificate** It has to be assured that certificate which is installed at initialization step is compatible with ITU X.509 v3 format. FCR contains; - FCR certificate, - Certification Authority root and sub-root (subordinate) certificates that are used for verification of all certificates that are produced by Certification Authority, - P PRA and P TSM certificate that is used for key transport process between FCR and PRA-IS, FCR and TSM - P PRA-SIGN and P TSM-SIGN certificate that is used by TOE for signature verification - UpdateControl certificate that is used to verify the signature of the TOE. - **P.Certificates Installation** It has to be assured that environment of TOE provides secure installation of certificates (P PRA , P PRA-SIGN , P TSM , P TSM-SIGN , Certification Authority root and sub-root certificates, UpdateControl certificate) into the FCR at initialization phase. Before the installation of certificates, it has to be assured that asymmetric key pair is generated in a manner which maintains security posture. - **P. Comm_EXT - Communication between TOE and External Device** It has to be assured that communication between TOE and External Devices is used to encrypt using AES algorithm with 256 bits according to External Device Communication Protocol Document [7] - **P. InformationLeakage - Information leakage from FCR** It has to be assured that TOE’s environment provides a secure mechanism which prevents attacker to obtain sensitive information (private key) when FCR performs signature operation; i.e by side channel attacks like SPA (Simple power analysis), SEMA (Simple Electromagnetic Analysis), DPA (Differential power analysis), DEMA (Differential electromagnetic analysis). - **P. SecureEnvironment** It has to be assured that environment of TOE senses disconnection between fiscal memory and main processor. Then TOE enters into the maintenance mode and logs urgent event. It has to be assured that fiscal memory doesn't accept transactions with negative amounts which results in a decrease of total tax value. It has to be assured that environment of TOE provides a mechanism that sales data in daily memory which is not reflected to the fiscal memory cannot be deleted and modified in an uncontrolled way. It has to be assured that sales data in ERU cannot be deleted and modified. - **P. PhysicalTamper** It has to be assured that TOE environment and TOE provide a tamper respondent system which is formed by electromechanical seals. It has to be assured that physical tampering protection system protects the keys (asymmetric key, symmetric key), the certificates, event data, characterization data, FCR parameters and sales data in FCR. It has to be assured that TOE logs this type of events and enters into the maintenance mode when physical tampering protection system detect unauthorized access. It has to be assured that authorized access such as maintenance work or service works are logged. It has to be assured that physical tampering protection system (mesh cover) protects fiscal memory. - **P. SecureEnvironment** It has to be assured that environment of TOE senses disconnection between fiscal memory and main processor. Then TOE enters into the maintenance mode and logs urgent event. It has to be assured that fiscal memory doesn't accept transactions with negative amounts which results in a decrease of total tax value. It has to be assured that environment of TOE provides a mechanism that sales data in daily memory which is not reflected to the fiscal memory cannot be deleted and modified in an uncontrolled way. It has to be assured that sales data in ERU cannot be deleted and modified. - **P. PKI - Public key infrastructure** It has to be assured that IT environment for the TOE provides public key infrastructure for encryption, signing and key agreement. - **P. UpdateControl** TOE is allowed to be updated by TSM or Authorized Manufacturer User to avoid possible threats during this operation, FCR shall verify the signature of the new version of TOE to ensure that the TOE to be updated is signed by the correct organisation. Thus, the TOE to be updated is ensured to be the correct certified version because only the certified versions will be signed. In addition, FCR shall check version of TOE to ensure that it is in latest version. ## 8 Assumptions and Clarification of Scope Assumptions for the operational environment of the composite TOE are; - **A.TrustedManufacturer** It is assumed that manufacturing is done by trusted manufacturers. They process manufacturing step in a manner which maintains IT security. - **A.Control** It is assumed that PRA-IS personnel performs random controls on FCR. During control PRA-IS should check if tax amount, total amount printed on receipt and sent to PRA-IS is the same. In addition to this, a similar check should be processed for events as well. - **A.Initialization** It is assumed that environment of TOE provides secure initialization steps. Initialization step consists of secure boot of operating systems, and integrity check for TSF data. Moreover, if certificate is handled as soft (not in the smartcard) it is assumed that environment of TOE provides secure installation of it to the FCR in initialization phase. Before certificate installation it is assumed that asymmetric key pair generated in a manner which maintains security posture. - **A.TrustedUser** User is assumed to be trusted. It is assumed that for each sale a sales receipt is provided to the buyer. - **A.Activation** It is assumed that environment of TOE provides secure activation steps at the beginning of the TOE operation phase and after each maintenance process. - **A.AuthorizedService** It is assumed that repairing is done by trusted authorized services. The repairing step is processed in a manner which maintains legal limits. - **A.Ext_Key** It is assumed that External Device (EFT-POS/SMART PINPAD) generates strong key for communicating with TOE and stores it in a secure way. - **A.Ext_Device Pairing** It is assumed that External Device and TOE are paired by Authorized Service. ## ## 9 Architectural Information TOE consists of a fiscal software running on top of Linux operating system (v2.6.36) that is run by a processor; covered by a mesh cover outside and inside together composing the cash register hardware providing the following services; - Storing sales data in fiscal memory - Storing receipt details in daily memory - Storing audit data inside a database - Generating sales reports - Transmitting sales reports and audit data to PRA-IS in PRA Messaging Protocol format which is defined in PRA Messaging Protocol Document [8] - Downloading configuration parameters from TSM in PRA Messaging Protocol format which is defined in PRA Messaging Protocol Document [8] with the following hardware and software components; - A software controlled mesh which covers CPU, NAND flash memory, DDR memory, daily memory and fiscal memory. - A fiscal memory storing all the sales data under the mesh cover - A daily memory storing daily sales data under the mesh cover - Electronic recording unit - A CPU under the mesh cover and a fiscal software running on top of above hardware providing necessary services to TSM unit. ## 10 Documentation Documents below are provided to the customer by the developer alongside the TOE; | **Name of Document** | **Version Number** | **Date** | |---------------------------------------|----------------------|------------| | Change v 06.00 Security Target | V0.8 | 31.07.2017 | | Change v 06.00 Guidance Documentation | V0.4 | 12.06.2017 | ## ## 11 IT Product Testing ### During the evaluation, all evaluation evidences of TOE were delivered and transferred completely to CCTL by the developers. All the delivered evaluation evidences which include software, documents, etc. are mapped to the assurance families Common Criteria and Common Methodology; so the connections between the assurance families and the evaluation evidences has been established. The evaluation results are available in the final Evaluation Technical Report (ETR) of Change v06.00 ### It is concluded that the TOE supports EAL 2. There are 19 assurance families which are all evaluated with the methods detailed in the ETR. ### IT Product Testing is mainly described in two parts: ## 12 Developer Testing Developer has prepared TOE Test Document according to the TOE Functional Specification documentation, TOE Design documentation which includes TSF subsystems and its interactions. Developer has done total of 20 functional tests. ## 13 Evaluator Testing - Independent Testing: Evaluator has done total of 28 test. 13 of them were selected from developer’s tests. The other 15 of them were evaluator’s independent tests. - Penetration Testing: Evaluator has done 10 penetration tests to find out TOE’s vulnerabilities that can be used for malicious purposes. ## 14 Evaluated Configuration This evaluation was performed at the operational environment described below; Name of the Fiscal Cash Register: Farex FR8300 Processor within the FCR: Device uses MAX32590 processor which has an ARM926EJ-S core with a 384 MHz core operating frequency. Cpu core has following features; - Secure Bootloader with Public Key Authentication - AES, DES and SHA Hardware Acclerators - Modulo-Arithmetic Accelerator (MAA) supporting RSA, DSA and ECDSA - Secure Keypad Controller - Hardware TRNG - Die Shield with Dynamic Fault Detection - Six External Tamper Sensors with Independent Random Dynamic Patterns - 256-Bit Flip-Flop based Nonvolatile AES Key Storage - Temperature and Voltage Tamper Monitor - Real-Time External Memory Encryption and Integrity Check - Real-Time Clock Memory within the FCR has following features; - 384KB System SRAM - 4KB Instruction TCM, 4KB Data TCM - 24KB AES User-Encryptable NV SRAM - Dual External Memory Controller (LPDDR400, SDRAM, SRAM, NOR Flash, NAND Flash) - 2KB User Programmable OTP - NAND Flash Controller with hardware ECC I/O and Peripherals; - USB 2.0 Host/Device with Internal Transceviers - Three UART Ports/One I2C Port - Five SPI Ports with I2C Functionality - Two ISO 7816 Smart Card Interfaces - SD/SDHC/SDIO Interface - 10/100 Mbps Ethernet MAC Controller - Thermal Printer Interface - Three Timers with PWM Capability - Up to 160 General-Purpose I/O Pins - 3-Channel 10-Bit ADC - LCD Controller supporting STN and TFT Displays - Monochrome LCD Controller - 16-Channel DMA Controller - Advanced Interrupt Controller Also the battery within the FCR for operation when the FCR isn’t connected to the power is CR2450 (580mAh) During the evaluation; the configuration of evaluation evidences which are composed of Common Criteria documents, guides are shown below; | Name of Document | Version Number | Publication Date | |--------------------------------------------------|-------------------|---------------------| | Change | V06.00 | V06.00 | | Change v 06.00 Security Target | 0.8 | 31.07.2017 | | Change v 06.00 Functional Specification Document | 0.5 | 31.07.2017 | | Change v 06.00 TOE Design Specification Document | 0.8 | 31.07.2017 | | Change v 06.00 Security Architecture Document | 0.5 | 12.06.2017 | | Change v 06.00 Guidance Documentation | 0.4 | 12.06.2017 | | Change v 06.00 Configuration Management Plan | 0.6 | 31.07.2017 | | Change v 06.00 Configuration Items | 0.6 | 31.07.2017 | | Change v 06.00 Delivery Procedure | 0.3 | 12.06.2017 | | Change v 06.00 Test Documentation | 0.5 | 31.07.2017 | | Change v 06.00 Test Coverage Analysis Document | 0.4 | 12.06.2017 | ## ## 15 Results of the Evaluation Table below provides a complete listing of the Security Assurance Requirements for the TOE. These requirements consists of the Evaluation Assurance Level 2 (EAL 2) components as specified in Part 3 of the Common Criteria. | **Assurance Class** | **Component** | **Component Title** | |-----------------------------|-----------------|---------------------------------------------| | Development | ADV_ARC.1 | Security Architecture Description | | | ADV_FSP.2 | Security-enforcing functional specification | | | ADV_TDS.1 | Basic Design | | Guidance Documents | AGD_OPE.1 | Operational User Guidance | | Guidance Documents | AGD_PRE.1 | Preparative Procedures | | Life-Cycle Support | ALC_CMC.2 | Use of a CM system | | | ALC_CMS.2 | Parts of the TOE CM coverage | | | ALC_DEL.1 | Delivery Procedures | | Security Target Evaluation | ASE_CCL.1 | Conformance Claims | | | ASE_ECD.1 | Extended Components Definition | | | ASE_INT.1 | ST Introduction | | | ASE_OBJ.2 | Security Objectives | | | ASE_REQ.2 | Derived Security Requirements | | | ASE_SPD.1 | Security Problem Definition | | | ASE_TSS.1 | TOE Summary Specification | | Tests | ATE_COV.1 | Evidence of coverage | | | ATE_FUN.1 | Functional Testing | | | ATE_IND.2 | Independent Testing | | Vulnerability Analysis | AVA_VAN.2 | Vulnerability analysis | The Evaluation Team assigned a Pass, Fail, or Inconclusive verdict to each work unit of each EAL 2 assurance component. For Fail or Inconclusive work unit verdicts, the Evaluation Team advised the developer about the issues requiring resolution or clarification within the evaluation evidence. In this way, the Evaluation Team assigned an overall Pass verdict to the assurance component only when all of the work units for that component had been assigned a Pass verdict. So for TOE “Change v06.00”, the results of the assessment of all evaluation tasks are “Pass”. ## 16 Evaluator Comments / Recommendations No recommendations or comments have been communicated to CCCS by the evaluators related to the evaluation process of “Change v06.00” product, result of the evaluation, or the ETR. ## 17 SECURITY TARGET The Security Target associated with this Certification Report is identified by the following terminology: Title: Change v 06.00 Security Target Version: 0.7 Date of Document: 12.06.2017 A public version has been created and verified according to ST-Santizing: Title: Change v 06.00 Security Target Lite Version: 1.0 Date of Document: 21.08.2017 ## 18 GLOSSARY ## ## ADV : Assurance of Development ## AGD : Assurance of Guidance Documents ## ALC : Assurance of Life Cycle ## ASE : Assurance of Security Target Evaluation ## ATE : Assurance of Tests Evaluation ## AVA : Assurance of Vulnerability Analysis ## BİLGEM : Bilişim ve Bilgi Güvenliği İleri Teknolojiler Araştırma Merkezi ## CC : Common Criteria (Ortak Kriterler) ## CCCS : Common Criteria Certification Scheme (TSE) ## CCRA : Common Criteria Recognition Arrangement ## CCTL : Common Criteria Test Laboratory ## CEM :Common Evaluation Methodology ## CMC : Configuration Management Capability ## CMS : Configuration Management Scope ## DEL : Delivery ## EAL : Evaluation Assurance Level ## FCR: Fiscal Cash Register ## GR : Observation Report ## OKTEM : Ortak Kriterler Test Merkezi ## OPE : Opretaional User Guidance ## OSP : Organisational Security Policy ## PP : Protection Profile ## PRE : Preperative Procedures ## SAR : Security Assurance Requirements ## SFR : Security Functional Requirements ## ST : Security Target ## TDBY: Test ve Değerlendirme Başkan Yardımcılığı ## TOE : Target of Evaluation ## TSF : TOE Secırity Functionality ## TSFI : TSF Interface ## 19 BIBLIOGRAPHY [1] Common Criteria for Information Technology Security Evaluation, Version 3.1 Revision 4, September 2012 [2] Common Methodology for Information Technology Security Evaluation, CEM, Version 3.1 Revision 4, September 2012 [3] BTBD-03-01-TL-01 Certification Report Preparation Instructions, Rel.Date: February 8 th 2016 [4] DTR 62 TR 01 PERKON OPT-360 Pico Fiscalapp V3.152-1256 Evaluation Technical Report [5] Technical Guidance (TK1), v4.0, October 20 th 2016 [6] Common Criteria Protection Profile for New Generation Cash Register Fiscal Application Software 2 (NGCRFAS-2 PP) 1.3, TSE-CCCS/PP-008, 06.05.2015 [7] External Device Communication Protocol (GMP3), v3.0, April 12 th 2016 [8] PRA Messaging Protocol, v4.0, May 18 th 2015 ## 20 ANNEXES ## There is no additional information which is inappropriate for reference in other sections | | **BİLİŞİM TEKNOLOJİLERİ** **TEST VE BELGELENDİRME** **DAİRESİ BAŞKANLIĞI /** **INFORMATION TECHNOLOGIES TEST AND CERTIFICATION DEPARTMENT** | **Doküman No** | BTBD-03-01-FR-01 | BTBD-03-01-FR-01 | BTBD-03-01-FR-01 | |----|--------------------------------------------------------------------------------------------------------------------------------------------------|---------------------|--------------------|--------------------|--------------------| | | **CCCS CERTIFICATION REPORT** | **Yayın Tarihi** | 30/07/2015 | 30/07/2015 | 30/07/2015 | | | | **Revizyon Tarihi** | 29/04/2016 | **No** | 05 | **Sayfa 6/22** **Bu dokümanın güncelliği, elektronik ortamda TSE Doküman Yönetim Sisteminden takip edilmelidir.**