Comparing certificates Experimental feature

You are comparing two certificates. By default, only differing attributes are shown. Use the button below to show/hide all attributes.

Showing only differing attributes.
Palo Alto Networks PA-220 Series, PA-400 Series, PA-800 Series, PA-3200 Series, PA-5200 Series, PA-5450, PA-7000 Series, and VM Series Next-Generation Firewall with PAN-OS 10.1
CCEVS-VR-VID-11284-2022
ID&Trust CNS Card: NXP JCOP 2.4.2 R3 Smart Card with ID&Trust HTCNS v1.03
21.0.01/TSE-CCCS-29
name Palo Alto Networks PA-220 Series, PA-400 Series, PA-800 Series, PA-3200 Series, PA-5200 Series, PA-5450, PA-7000 Series, and VM Series Next-Generation Firewall with PAN-OS 10.1 ID&Trust CNS Card: NXP JCOP 2.4.2 R3 Smart Card with ID&Trust HTCNS v1.03
category Network and Network-Related Devices and Systems Products for Digital Signatures
scheme US TR
not_valid_after 13.09.2024 25.08.2018
not_valid_before 31.08.2022 25.08.2015
cert_link https://www.commoncriteriaportal.org/nfs/ccpfiles/files/epfiles/st_vid11284-ci.pdf
report_link https://www.commoncriteriaportal.org/nfs/ccpfiles/files/epfiles/st_vid11284-vr.pdf https://www.commoncriteriaportal.org/nfs/ccpfiles/files/epfiles/cr%2024082015.pdf
st_link https://www.commoncriteriaportal.org/nfs/ccpfiles/files/epfiles/st_vid11284-st.pdf https://www.commoncriteriaportal.org/nfs/ccpfiles/files/epfiles/Security%20Target%20lite%20for%20IDTrust%20SSCD%20Application_v1%2000%20(00000002).pdf
manufacturer Palo Alto Networks, Inc. ID&Trust Ltd.
manufacturer_web https://www.paloaltonetworks.com/ https://www.idandtrust.com/
security_level {} EAL4+, AVA_VAN.5
dgst 150bf4f0cdc34e0e 408b21aad09077ed
heuristics/cert_id CCEVS-VR-VID-11284-2022 21.0.01/TSE-CCCS-29
heuristics/cert_lab US []
heuristics/extracted_sars ADV_FSP.1, ALC_CMC.1, AVA_VAN.1, ATE_IND.1, ALC_CMS.1 ASE_INT.1, ALC_DVS.2, ALC_CMC.4, ASE_ECD.1, ADV_IMP.1, ATE_COV.2, ALC_TAT.1, ASE_SPD.1, AVA_VAN.5, ALC_DEL.1, ALC_LCD.1, AGD_OPE.1, AGD_PRE.1, ALC_CMS.4, ATE_FUN.1, ADV_ARC.1, ASE_OBJ.2, ADV_TDS.3, ATE_DPT.1, ASE_TSS.2, ASE_REQ.2, ADV_FSP.4, ATE_IND.2, ASE_CCL.1
heuristics/extracted_versions 10.1 1.03, 2.4.2
heuristics/scheme_data
  • category: Firewall, Network Device, Traffic Monitoring, Virtual Private Network
  • certification_date: 31.08.2022
  • evaluation_facility: Leidos Common Criteria Testing Laboratory
  • expiration_date: 13.09.2024
  • id: CCEVS-VR-VID11284
  • product: Palo Alto Networks PA-220 Series, PA-400 Series, PA-800 Series, PA-3200 Series, PA-5200 Series, PA-5450, PA-7000 Series, and VM Series Next-Generation Firewall with PAN-OS 10.1
  • scheme: US
  • url: https://www.niap-ccevs.org/product/11284
  • vendor: Palo Alto Networks, Inc.
heuristics/st_references/directly_referencing {} BSI-DSZ-CC-0633-2010
heuristics/st_references/indirectly_referencing {} BSI-DSZ-CC-0633-2010
heuristics/protection_profiles a4784f14919bdbe6, 89f2a255423f4a20 d918b28fd7bb5d79
maintenance_updates
protection_profile_links https://www.commoncriteriaportal.org/nfs/ccpfiles/files/ppfiles/CFG_NDcPP-VPNGW_V1.2.pdf, https://www.commoncriteriaportal.org/nfs/ccpfiles/files/ppfiles/CPP_ND_V2.2E.pdf https://www.commoncriteriaportal.org/nfs/ccpfiles/files/ppfiles/pp0059b_pdf.pdf
pdf_data/cert_filename st_vid11284-ci.pdf
pdf_data/cert_keywords/cc_cert_id
  • US:
    • CCEVS-VR-VID11284-2022: 1
pdf_data/cert_keywords/cc_protection_profile_id
pdf_data/cert_keywords/cc_security_level
pdf_data/cert_keywords/cc_sar
pdf_data/cert_keywords/cc_sfr
pdf_data/cert_keywords/cc_claims
pdf_data/cert_keywords/vendor
pdf_data/cert_keywords/eval_facility
  • Leidos:
    • Leidos: 1
pdf_data/cert_keywords/symmetric_crypto
pdf_data/cert_keywords/asymmetric_crypto
pdf_data/cert_keywords/pq_crypto
pdf_data/cert_keywords/hash_function
pdf_data/cert_keywords/crypto_scheme
pdf_data/cert_keywords/crypto_protocol
  • VPN:
    • VPN: 1
pdf_data/cert_keywords/randomness
pdf_data/cert_keywords/cipher_mode
pdf_data/cert_keywords/ecc_curve
pdf_data/cert_keywords/crypto_engine
pdf_data/cert_keywords/tls_cipher_suite
pdf_data/cert_keywords/crypto_library
pdf_data/cert_keywords/vulnerability
pdf_data/cert_keywords/side_channel_analysis
pdf_data/cert_keywords/technical_report_id
pdf_data/cert_keywords/device_model
pdf_data/cert_keywords/tee_name
pdf_data/cert_keywords/os_name
pdf_data/cert_keywords/cplc_data
pdf_data/cert_keywords/ic_data_group
pdf_data/cert_keywords/standard_id
pdf_data/cert_keywords/javacard_version
pdf_data/cert_keywords/javacard_api_const
pdf_data/cert_keywords/javacard_packages
pdf_data/cert_keywords/certification_process
pdf_data/cert_metadata
  • /CreationDate: D:20220906175610-04'00'
  • /ModDate: D:20220906175610-04'00'
  • /Producer: iText 2.1.0 (by lowagie.com)
  • pdf_file_size_bytes: 182730
  • pdf_hyperlinks: {}
  • pdf_is_encrypted: False
  • pdf_number_of_pages: 1
pdf_data/report_filename st_vid11284-vr.pdf cr 24082015.pdf
pdf_data/report_frontpage
  • US:
    • cert_id: CCEVS-VR-VID11284-2022
    • cert_item: for Palo Alto Networks PA-220 Series, PA-400 Series, PA- 800 Series, PA-3200 Series, PA-5200 Series, PA-5450, PA-7000 Series, and VM Series Next-Generation Firewall with PAN-OS 10.1
    • cert_lab: US NIAP
  • US:
pdf_data/report_keywords/cc_cert_id
  • US:
    • CCEVS-VR-VID11284-2022: 1
  • DE:
    • BSI-DSZ-CC-0857: 1
  • NL:
    • CC-0633-2010: 1
  • TR:
    • 21.0.01/TSE-CCCS-29: 2
pdf_data/report_keywords/cc_protection_profile_id
  • BSI:
    • BSI-CC-PP-0035-2007: 1
    • BSI-CC-PP-0059: 2
    • BSI-PP-0035: 1
pdf_data/report_keywords/cc_security_level
  • EAL:
    • EAL 4: 2
    • EAL 4+: 2
    • EAL 5: 1
    • EAL 5 augmented: 1
    • EAL 5+: 2
    • EAL4: 1
    • EAL4+: 2
    • EAL5: 1
    • EAL5 augmented: 1
    • EAL5+: 3
pdf_data/report_keywords/cc_sar
  • AVA:
    • AVA_VAN: 1
  • ADV:
    • ADV_ARC.1: 1
    • ADV_FSP.4: 1
    • ADV_IMP.1: 1
    • ADV_TDS.3: 1
  • AGD:
    • AGD_OPE.1: 1
    • AGD_PRE.1: 1
  • ALC:
    • ALC_CMC.4: 1
    • ALC_CMS.4: 1
    • ALC_DEL.1: 1
    • ALC_DVS.2: 5
    • ALC_LCD.1: 1
    • ALC_TAT.1: 1
  • ASE:
    • ASE_CCL.1: 1
    • ASE_ECD.1: 1
    • ASE_INT.1: 1
    • ASE_OBJ.2: 1
    • ASE_REQ.2: 1
    • ASE_SPD.1: 1
    • ASE_TSS.1: 1
    • ASE_TSS.2: 3
  • ATE:
    • ATE_COV.2: 1
    • ATE_DPT.1: 1
    • ATE_FUN.1: 1
    • ATE_IND.2: 1
  • AVA:
    • AVA_VAN.5: 11
pdf_data/report_keywords/cc_sfr
  • FCS:
    • FCS_TLSC_EXT.2.3: 1
  • FIA:
    • FIA_AFL.1: 2
  • FTP:
    • FTP_ITC.1: 1
pdf_data/report_keywords/cc_claims
  • A:
    • A.CGA: 1
    • A.SCA: 1
pdf_data/report_keywords/vendor
  • Microsoft:
    • Microsoft: 4
  • NXP:
    • NXP: 8
pdf_data/report_keywords/eval_facility
  • Leidos:
    • Leidos: 7
  • BrightSight:
    • Brightsight: 1
  • TUBITAK-BILGEM:
    • TÜBİTAK BİLGEM: 5
pdf_data/report_keywords/crypto_scheme
  • KA:
    • Key Agreement: 1
  • KEX:
    • Key Exchange: 1
pdf_data/report_keywords/crypto_protocol
  • IKE:
    • IKE: 3
  • IPsec:
    • IPsec: 46
  • SSH:
    • SSH: 13
    • SSHv2: 2
  • TLS:
    • SSL:
      • SSL: 3
    • TLS:
      • TLS: 16
  • VPN:
    • VPN: 64
pdf_data/report_keywords/cipher_mode
  • GCM:
    • GCM: 1
pdf_data/report_keywords/crypto_engine
  • SmartMX:
    • SmartMX: 1
pdf_data/report_keywords/os_name
  • JCOP:
    • JCOP 2: 11
pdf_data/report_keywords/standard_id
  • RFC:
    • RFC 5077: 1
  • CC:
    • CCMB-2012-09-001: 1
    • CCMB-2012-09-002: 2
    • CCMB-2012-09-003: 2
    • CCMB-2012-09-004: 1
  • ISO:
    • ISO/IEC 17025: 2
    • ISO/IEC 7816-4: 2
    • ISO/IEC 7816-8: 3
    • ISO/IEC 7816-9: 1
pdf_data/report_keywords/javacard_packages
  • org:
    • org.tr: 1
pdf_data/report_metadata
  • /CreationDate: D:20220906174944-04'00'
  • /Creator: Microsoft® Word for Microsoft 365
  • /ModDate: D:20220906174944-04'00'
  • /Producer: Microsoft® Word for Microsoft 365
  • pdf_file_size_bytes: 831523
  • pdf_hyperlinks: http://www.niap-ccevs.org/
  • pdf_is_encrypted: False
  • pdf_number_of_pages: 41
  • /Author: Cengiz GÖREN
  • /CreationDate: D:20150825113013+03'00'
  • /Creator: Microsoft® Word 2013
  • /ModDate: D:20150826103246+03'00'
  • /Producer: Microsoft® Word 2013
  • pdf_file_size_bytes: 1007660
  • pdf_hyperlinks: http://www/
  • pdf_is_encrypted: False
  • pdf_number_of_pages: 22
pdf_data/st_filename st_vid11284-st.pdf Security Target lite for IDTrust SSCD Application_v1 00 (00000002).pdf
pdf_data/st_keywords/cc_cert_id
  • DE:
    • BSI-DSZ-CC-0633-2010: 1
    • BSI-DSZ-CC-0857: 1
pdf_data/st_keywords/cc_protection_profile_id
  • BSI:
    • BSI-CC-PP- 0059: 1
    • BSI-CC-PP-0035-2007: 1
    • BSI-CC-PP-0059: 4
    • BSI-PP-0035: 1
pdf_data/st_keywords/cc_security_level
  • EAL:
    • EAL 4: 2
    • EAL 5: 3
    • EAL 5 augmented: 1
    • EAL 5+: 2
    • EAL4: 8
    • EAL4 augmented: 3
    • EAL4+: 2
    • EAL5: 1
    • EAL5 augmented: 1
    • EAL5+: 3
pdf_data/st_keywords/cc_sar
  • ADV:
    • ADV_FSP.1: 1
  • AGD:
    • AGD_OPE: 1
    • AGD_PRE: 1
  • ALC:
    • ALC_CMC.1: 1
    • ALC_CMS.1: 1
  • ASE:
    • ASE_CCL: 1
    • ASE_ECD: 1
    • ASE_INT: 1
    • ASE_OBJ: 1
    • ASE_REQ: 1
    • ASE_SPD: 1
    • ASE_TSS: 1
  • ATE:
    • ATE_IND.1: 1
  • AVA:
    • AVA_VAN: 1
    • AVA_VAN.1: 2
  • ADV:
    • ADV_ARC.1: 3
    • ADV_FSP.4: 3
    • ADV_IMP.1: 3
    • ADV_TDS.3: 3
  • AGD:
    • AGD_OPE.1: 3
    • AGD_PRE.1: 3
  • ALC:
    • ALC_CMC.4: 1
    • ALC_CMS.4: 1
    • ALC_DEL.1: 1
    • ALC_DVS.1: 1
    • ALC_DVS.2: 5
    • ALC_LCD.1: 1
    • ALC_TAT.1: 1
  • ASE:
    • ASE_CCL.1: 1
    • ASE_ECD.1: 1
    • ASE_INT.1: 1
    • ASE_OBJ.2: 1
    • ASE_REQ.2: 1
    • ASE_SPD.1: 1
    • ASE_TSS.1: 1
    • ASE_TSS.2: 4
  • ATE:
    • ATE_COV.2: 1
    • ATE_DPT.1: 2
    • ATE_FUN.1: 1
    • ATE_IND.2: 1
  • AVA:
    • AVA_VAN.5: 12
pdf_data/st_keywords/cc_sfr
  • FAU:
    • FAU_GEN: 5
    • FAU_GEN.1: 5
    • FAU_GEN.1.1: 1
    • FAU_GEN.1.2: 2
    • FAU_GEN.2: 3
    • FAU_GEN.2.1: 1
    • FAU_STG_EXT: 1
    • FAU_STG_EXT.1: 3
    • FAU_STG_EXT.1.1: 1
    • FAU_STG_EXT.1.2: 1
    • FAU_STG_EXT.1.3: 1
  • FCS:
    • FCS_CKM: 9
    • FCS_CKM.1: 4
    • FCS_CKM.1.1: 1
    • FCS_CKM.2: 7
    • FCS_CKM.2.1: 1
    • FCS_CKM.4: 3
    • FCS_CKM.4.1: 1
    • FCS_COP: 14
    • FCS_COP.1: 4
    • FCS_NTP_EXT.1: 1
    • FCS_NTP_EXT.1.4: 1
    • FCS_RBG_EXT: 1
    • FCS_RBG_EXT.1: 5
    • FCS_RBG_EXT.1.1: 1
    • FCS_RBG_EXT.1.2: 1
    • FCS_SSHS_EXT: 1
    • FCS_SSHS_EXT.1: 3
    • FCS_SSHS_EXT.1.1: 1
    • FCS_SSHS_EXT.1.2: 2
    • FCS_SSHS_EXT.1.3: 1
    • FCS_SSHS_EXT.1.4: 1
    • FCS_SSHS_EXT.1.5: 1
    • FCS_SSHS_EXT.1.6: 1
    • FCS_SSHS_EXT.1.7: 1
    • FCS_SSHS_EXT.1.8: 1
    • FCS_TLSC_EXT: 2
    • FCS_TLSC_EXT.1: 3
    • FCS_TLSC_EXT.1.1: 1
    • FCS_TLSC_EXT.1.2: 1
    • FCS_TLSC_EXT.1.3: 1
    • FCS_TLSC_EXT.1.4: 1
    • FCS_TLSC_EXT.2: 2
    • FCS_TLSC_EXT.2.1: 1
    • FCS_TLSC_EXT.2.3: 1
    • FCS_TLSS_EXT: 2
    • FCS_TLSS_EXT.1: 4
    • FCS_TLSS_EXT.1.1: 1
    • FCS_TLSS_EXT.1.2: 1
    • FCS_TLSS_EXT.1.3: 1
    • FCS_TLSS_EXT.1.4: 1
    • FCS_TLSS_EXT.2: 2
    • FCS_TLSS_EXT.2.1: 1
    • FCS_TLSS_EXT.2.2: 1
    • FCS_TLSS_EXT.2.3: 1
  • FDP:
    • FDP_RIP: 1
    • FDP_RIP.2: 4
  • FIA:
    • FIA_AFL: 1
    • FIA_AFL.1: 9
    • FIA_AFL.1.1: 1
    • FIA_AFL.1.2: 1
    • FIA_PMG_EXT: 1
    • FIA_PMG_EXT.1: 3
    • FIA_PMG_EXT.1.1: 1
    • FIA_UAU: 1
    • FIA_UAU.7: 3
    • FIA_UAU.7.1: 1
    • FIA_UAU_EXT: 1
    • FIA_UAU_EXT.2: 2
    • FIA_UAU_EXT.2.1: 1
    • FIA_UIA_EXT: 1
    • FIA_UIA_EXT.1: 5
    • FIA_UIA_EXT.1.1: 1
    • FIA_UIA_EXT.1.2: 1
  • FMT:
    • FMT_MOF: 8
    • FMT_MOF.1: 2
    • FMT_MTD: 8
    • FMT_MTD.1: 2
    • FMT_SMF: 8
    • FMT_SMF.1: 5
    • FMT_SMF.1.1: 2
    • FMT_SMR: 1
    • FMT_SMR.2: 3
    • FMT_SMR.2.1: 1
    • FMT_SMR.2.2: 1
    • FMT_SMR.2.3: 1
  • FPT:
    • FPT_APW_EXT: 1
    • FPT_APW_EXT.1: 3
    • FPT_APW_EXT.1.1: 1
    • FPT_APW_EXT.1.2: 1
    • FPT_FLS: 3
    • FPT_FLS.1: 1
    • FPT_SKP_EXT: 1
    • FPT_SKP_EXT.1: 3
    • FPT_SKP_EXT.1.1: 1
    • FPT_STM_EXT: 1
    • FPT_STM_EXT.1: 4
    • FPT_STM_EXT.1.1: 1
    • FPT_STM_EXT.1.2: 2
    • FPT_TST_EXT: 3
    • FPT_TST_EXT.1: 3
    • FPT_TST_EXT.1.1: 1
    • FPT_TST_EXT.3: 2
    • FPT_TST_EXT.3.1: 1
    • FPT_TST_EXT.3.2: 1
    • FPT_TUD_EXT: 1
    • FPT_TUD_EXT.1: 3
    • FPT_TUD_EXT.1.1: 1
    • FPT_TUD_EXT.1.2: 1
    • FPT_TUD_EXT.1.3: 1
  • FTA:
    • FTA_SSL: 2
    • FTA_SSL.3: 3
    • FTA_SSL.3.1: 1
    • FTA_SSL.4: 2
    • FTA_SSL.4.1: 1
    • FTA_SSL_EXT: 1
    • FTA_SSL_EXT.1: 3
    • FTA_SSL_EXT.1.1: 1
    • FTA_TAB: 1
    • FTA_TAB.1: 4
    • FTA_TAB.1.1: 1
  • FTP:
    • FTP_ITC: 4
    • FTP_ITC.1: 9
    • FTP_ITC.1.1: 1
    • FTP_ITC.1.2: 1
    • FTP_ITC.1.3: 1
    • FTP_TRP: 4
    • FTP_TRP.1: 3
  • FAU:
    • FAU_ARP.1: 2
    • FAU_GEN: 1
    • FAU_SAS: 1
  • FCO:
    • FCO_NRO: 1
  • FCS:
    • FCS_CKM: 3
    • FCS_CKM.1: 15
    • FCS_CKM.1.1: 2
    • FCS_CKM.2: 3
    • FCS_CKM.3: 1
    • FCS_CKM.4: 12
    • FCS_CKM.4.1: 1
    • FCS_COP: 1
    • FCS_COP.1: 10
    • FCS_COP.1.1: 1
    • FCS_RNG: 1
    • FCS_RNG.1: 1
  • FDP:
    • FDP_ACC: 40
    • FDP_ACC.1: 19
    • FDP_ACC.2: 1
    • FDP_ACF: 31
    • FDP_ACF.1: 18
    • FDP_DAU: 8
    • FDP_DAU.1: 1
    • FDP_DAU.2: 2
    • FDP_IFC: 2
    • FDP_IFC.1: 10
    • FDP_IFF: 2
    • FDP_ITC: 1
    • FDP_ITC.1: 4
    • FDP_ITC.2: 4
    • FDP_RIP: 10
    • FDP_RIP.1: 6
    • FDP_RIP.1.1: 1
    • FDP_ROL: 1
    • FDP_SDI: 16
    • FDP_SDI.1: 2
    • FDP_SDI.2: 6
    • FDP_UIT: 8
    • FDP_UIT.1: 2
  • FIA:
    • FIA_AFL: 2
    • FIA_AFL.1: 5
    • FIA_AFL.1.1: 1
    • FIA_AFL.1.2: 1
    • FIA_ATD: 1
    • FIA_UAU: 2
    • FIA_UAU.1: 8
    • FIA_UAU.1.1: 1
    • FIA_UAU.1.2: 1
    • FIA_UID: 4
    • FIA_UID.1: 13
    • FIA_UID.1.1: 1
    • FIA_UID.1.2: 1
    • FIA_USB: 1
  • FMT:
    • FMT_MOF: 1
    • FMT_MOF.1: 7
    • FMT_MOF.1.1: 1
    • FMT_MSA: 35
    • FMT_MSA.1: 5
    • FMT_MSA.2: 6
    • FMT_MSA.2.1: 1
    • FMT_MSA.3: 17
    • FMT_MSA.3.1: 1
    • FMT_MSA.3.2: 1
    • FMT_MSA.4: 8
    • FMT_MSA.4.1: 1
    • FMT_MTD: 18
    • FMT_MTD.1: 2
    • FMT_SMF: 5
    • FMT_SMF.1: 22
    • FMT_SMF.1.1: 1
    • FMT_SMR: 7
    • FMT_SMR.1: 27
    • FMT_SMR.1.1: 1
    • FMT_SMR.1.2: 1
  • FPR:
    • FPR_UNO.1: 1
  • FPT:
    • FPT_EMS: 6
    • FPT_EMS.1: 9
    • FPT_EMS.1.1: 4
    • FPT_EMS.1.2: 3
    • FPT_FLS: 5
    • FPT_FLS.1: 8
    • FPT_FLS.1.1: 1
    • FPT_PHP: 4
    • FPT_PHP.1: 7
    • FPT_PHP.1.1: 1
    • FPT_PHP.1.2: 1
    • FPT_PHP.3: 9
    • FPT_PHP.3.1: 1
    • FPT_RCV: 1
    • FPT_TDC.1: 1
    • FPT_TST: 2
    • FPT_TST.1: 12
    • FPT_TST.1.1: 1
    • FPT_TST.1.2: 1
    • FPT_TST.1.3: 1
  • FRU:
    • FRU_FLT: 1
  • FTP:
    • FTP_ITC: 20
    • FTP_ITC.1: 14
    • FTP_TRP.1: 2
pdf_data/st_keywords/cc_claims
  • A:
    • A.COMPONENTS_RUNNING: 1
    • A.PHYSICAL_PROTECTION: 1
  • OE:
    • OE.ADMIN_CREDENTIALS_SECURE: 1
    • OE.COMPONENTS_RUNNING: 1
    • OE.CONNECTIONS: 1
    • OE.NO_GENERAL_PURPOSE: 1
    • OE.NO_THRU_TRAFFIC_PROTECTION: 1
    • OE.PHYSICAL: 1
    • OE.RESIDUAL_INFORMATION: 1
    • OE.TRUSTED_ADMIN: 1
    • OE.UPDATES: 1
    • OE.VM_CONFIGURATION: 1
  • A:
    • A.APPLET: 1
    • A.CGA: 3
    • A.PROCESS-: 1
    • A.SCA: 3
    • A.USE_DIAG: 1
    • A.USE_KEYS: 1
    • A.VERIFICATION: 1
  • O:
    • O.CARD-MANAGEMENT: 1
  • OE:
    • OE.APPLET: 1
    • OE.HID_VAD: 4
    • OE.PROCESS_SEC_IC: 1
    • OE.SVD_: 1
    • OE.USE_DIAG: 1
    • OE.USE_KEYS: 1
    • OE.VERIFICATION: 1
  • OSP:
    • OSP.PROCESS-TOE: 1
    • OSP.VERIFICATION: 1
  • OT:
    • OT.CIPHER: 1
    • OT.DTBS: 1
    • OT.EMSEC: 1
    • OT.EXT-MEM: 1
    • OT.GLOBAL_ARRAYS_CONFID: 1
    • OT.IDENTIFICATION: 1
    • OT.INSTALL: 1
    • OT.KEY-MNGT: 1
    • OT.LOAD: 1
    • OT.NATIVE: 1
    • OT.OBJ-DELETION: 1
    • OT.OPERATE: 1
    • OT.PIN-MNGT: 1
    • OT.RESOURCES: 1
    • OT.RND: 1
    • OT.SCD: 3
    • OT.SCP: 1
    • OT.SEC_BOX_FW: 1
  • T:
    • T.CONFID-APPLI-DATA: 2
    • T.CONFID-JCS-CODE: 1
    • T.DELETION: 1
    • T.EXE-CODE: 1
    • T.EXE-CODE-REMOTE: 1
    • T.INSTALL: 1
    • T.INTEG-APPLI-DATA: 1
    • T.INTEG-JCS-CODE: 1
    • T.NATIVE: 1
    • T.PHYSICAL: 3
    • T.RND: 1
    • T.SEC_BOX_BORDER: 1
    • T.SID: 3
pdf_data/st_keywords/vendor
  • Broadcom:
    • Broadcom: 3
  • Microsoft:
    • Microsoft: 5
  • NXP:
    • NXP: 12
pdf_data/st_keywords/eval_facility
  • BrightSight:
    • Brightsight: 1
pdf_data/st_keywords/symmetric_crypto
  • AES_competition:
    • AES:
      • AES: 35
      • AES-: 2
      • AES-256: 5
  • DES:
    • 3DES:
      • 3DES: 1
  • constructions:
    • MAC:
      • HMAC: 13
      • HMAC-SHA-256: 7
      • HMAC-SHA-384: 4
      • HMAC-SHA-512: 6
pdf_data/st_keywords/asymmetric_crypto
  • ECC:
    • ECC:
      • ECC: 7
    • ECDH:
      • ECDH: 2
      • ECDHE: 6
    • ECDSA:
      • ECDSA: 26
  • FF:
    • DH:
      • DH: 32
      • DHE: 3
      • Diffie-Hellman: 8
    • DSA:
      • DSA: 2
  • RSA:
    • RSA 2048: 1
    • RSA-2048: 1
pdf_data/st_keywords/hash_function
  • SHA:
    • SHA1:
      • SHA-1: 7
    • SHA2:
      • SHA-256: 8
      • SHA-384: 6
      • SHA-512: 4
      • SHA256: 4
pdf_data/st_keywords/crypto_scheme
  • KA:
    • Key Agreement: 1
  • KEX:
    • Key Exchange: 1
  • MAC:
    • MAC: 3
pdf_data/st_keywords/crypto_protocol
  • IKE:
    • IKE: 30
    • IKEv1: 15
    • IKEv2: 13
  • IPsec:
    • IPsec: 104
  • SSH:
    • SSH: 59
    • SSHv2: 7
  • TLS:
    • DTLS:
      • DTLS: 1
    • SSL:
      • SSL: 6
      • SSL 2.0: 3
      • SSL 3.0: 3
    • TLS:
      • TLS: 90
      • TLS 1.0: 3
      • TLS 1.1: 3
      • TLS 1.2: 4
      • TLSv1.1: 2
      • TLSv1.2: 6
  • VPN:
    • VPN: 90
pdf_data/st_keywords/randomness
  • PRNG:
    • DRBG: 15
  • RNG:
    • RBG: 2
  • RNG:
    • RND: 2
pdf_data/st_keywords/cipher_mode
  • CBC:
    • CBC: 13
  • CCM:
    • CCM: 5
  • CTR:
    • CTR: 7
  • GCM:
    • GCM: 16
pdf_data/st_keywords/ecc_curve
  • NIST:
    • P-256: 24
    • P-384: 18
    • P-521: 10
    • secp256r1: 5
    • secp384r1: 4
    • secp521r1: 3
pdf_data/st_keywords/crypto_engine
  • SmartMX:
    • SmartMX: 2
pdf_data/st_keywords/tls_cipher_suite
  • TLS:
    • TLS_DHE_RSA_WITH_AES_128_CBC_SHA: 4
    • TLS_DHE_RSA_WITH_AES_256_CBC_SHA: 4
    • TLS_ECDHE_ECDSA_WITH_AES_128_CBC_SHA: 4
    • TLS_ECDHE_ECDSA_WITH_AES_128_CBC_SHA256: 2
    • TLS_ECDHE_ECDSA_WITH_AES_128_GCM_SHA256: 4
    • TLS_ECDHE_ECDSA_WITH_AES_256_CBC_SHA: 4
    • TLS_ECDHE_ECDSA_WITH_AES_256_CBC_SHA384: 2
    • TLS_ECDHE_ECDSA_WITH_AES_256_GCM_SHA384: 4
    • TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA: 2
    • TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA256: 4
    • TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256: 4
    • TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA: 2
    • TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA384: 4
    • TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384: 4
pdf_data/st_keywords/side_channel_analysis
  • FI:
    • DFA: 1
    • fault injection: 1
    • physical tampering: 5
  • SCA:
    • DPA: 1
    • SPA: 1
    • physical probing: 1
    • timing attacks: 1
pdf_data/st_keywords/os_name
  • JCOP:
    • JCOP 2: 7
pdf_data/st_keywords/standard_id
  • FIPS:
    • FIPS 186-4: 4
    • FIPS PUB 186-4: 20
  • ISO:
    • ISO/IEC 14888-3: 2
    • ISO/IEC 18031:2011: 5
    • ISO/IEC 9796-2: 2
  • NIST:
    • NIST SP 800-56A: 2
    • SP 800-135: 2
    • SP 800-90A: 2
  • PKCS:
    • PKCS #1: 2
    • PKCS#12: 2
  • RFC:
    • RFC 2460: 2
    • RFC 2818: 3
    • RFC 2986: 2
    • RFC 3268: 8
    • RFC 3447: 2
    • RFC 3513: 2
    • RFC 3526: 11
    • RFC 35269: 1
    • RFC 3602: 3
    • RFC 3986: 2
    • RFC 4106: 1
    • RFC 4109: 1
    • RFC 4253: 1
    • RFC 4301: 2
    • RFC 4303: 2
    • RFC 4304: 1
    • RFC 4346: 3
    • RFC 4443: 1
    • RFC 4492: 12
    • RFC 4868: 1
    • RFC 4945: 1
    • RFC 5077: 3
    • RFC 5114: 2
    • RFC 5246: 8
    • RFC 5280: 4
    • RFC 5289: 28
    • RFC 5735: 2
    • RFC 5759: 1
    • RFC 5996: 3
    • RFC 6125: 4
    • RFC 6598: 2
    • RFC 6960: 1
    • RFC 768: 2
    • RFC 791: 2
    • RFC 7919: 1
    • RFC 792: 1
    • RFC 793: 3
    • RFC 959: 1
    • RFC2409: 1
    • RFC4945: 1
  • X509:
    • X.509: 13
  • CC:
    • CCMB-2012-09-001: 1
    • CCMB-2012-09-002: 1
    • CCMB-2012-09-003: 1
  • FIPS:
    • FIPS PUB 186-3: 1
  • ISO:
    • ISO/IEC 14443: 2
    • ISO/IEC 24727-2: 1
    • ISO/IEC 7816-3: 1
    • ISO/IEC 7816-4: 3
    • ISO/IEC 7816-8: 3
    • ISO/IEC 7816-9: 1
pdf_data/st_keywords/javacard_version
  • GlobalPlatform:
    • Global Platform 2.2.1: 1
  • JavaCard:
    • Java Card 3.0.1: 1
pdf_data/st_keywords/certification_process
  • OutOfScope:
    • and URL Filtering security policies/profiles are not evaluated and therefore, these features are out of scope. API request over HTTP By default, the TOE supports API requests over HTTPS or HTTPS tunneled over: 1
    • Policies The TLS and SSH decryption policies are not evaluated and therefore, these features are out of scope. Anti-Virus, Anti-Spyware, Anti- Malware Security Policies The Anti-Virus, Anti-Spyware: 1
    • functional requirements: TLS, HTTPS, SSH, IKE/IPsec. The features below and Normal mode are out of scope. Table 2 Excluded Features Feature Description Telnet and HTTP Management Protocols Telnet and HTTP: 1
    • is secured with TLS using FIPS-approved algorithms. The threat prevention signatures themselves are out of scope (i.e., not evaluated). Page 12 of 84 Management The next-generation firewall provides both direct: 1
    • malformed, fragmented packets. The protection from viruses, worm, and spyware using signatures are out of scope (i.e., not evaluated). • DoS Protection – the firewall is designed to protect against flooding: 1
    • out of scope: 6
    • security policies (i.e., profiles) are not evaluated and therefore, there features are out of scope. File Blocking, DLP, and URL Filtering Security Policies The File Blocking, DLP (Data Loss: 1
  • OutOfScope:
    • 1 FDP_RIP.1 matches the equivalent SFR of the Platform-ST. FDP_RIP.1/TRANSIENT No Correspondence Out of scope (Platform functionality) No contradiction to this ST FDP_ROL.1/FIREWALL No Correspondence Out of: 1
    • 1 of the Platform-ST FDP_ACC.2/SecureBox No Correspondence Out of scope (Platform functionality) No contradiction to this ST FDP_ACF.1/SecureBox No Correspondence Out of: 1
    • FCS_COP.1 of the Platform matches the equivalent SFR of the TOE. FDP_RIP.1/ABORT No Correspondence Out of scope (Platform functionality) No contradiction to this ST FDP_RIP.1/APDU No Correspondence Out of scope: 1
    • FPT_PHP.3 of this ST matches the FPT_PHP.3/SCP of the Platform ST. hFDP_ACC.1/SCP No Correspondence Out of scope (Platform functionality) No contradiction to this ST FDP_ACF.1/SCP No Correspondence Out of scope: 1
    • OT.RESOURCES OT.ALARM OT.OPERATE OT.MF_FW OT.LOAD OT.SCP.SUPPORT cannot be mapped because these are out of scope. 109 The objectives for the operational environment can be mapped as follows: Table 5 Mapping of: 1
    • Out of scope: 77
    • Platform functionality) No contradiction to this ST FAU_SAS.1/SCP No Correspondence Out of scope (Platform functionality: 1
    • Platform functionality) No contradiction to this ST FCO_NRO.2/CM No Correspondence Out of scope (Platform functionality: 1
    • Platform functionality) No contradiction to this ST FCS_CKM.3 No Correspondence Out of scope (Platform functionality: 1
    • Platform functionality) No contradiction to this ST FDP_ACC.1/EXT_MEM No Correspondence Out of scope (Platform functionality: 1
    • Platform functionality) No contradiction to this ST FDP_ACC.1/LifeCycle No Correspondence Out of scope (Platform functionality: 1
    • Platform functionality) No contradiction to this ST FDP_ACC.2.2/JCRMI No Correspondence Out of scope (Platform functionality: 1
    • Platform functionality) No contradiction to this ST FDP_ACC.2/ADEL No Correspondence Out of scope (Platform functionality) No contradiction to this ST FDP_ACF.1/ADEL No Correspondence Out of scope: 1
    • Platform functionality) No contradiction to this ST FDP_ACF.1/ADEL No Correspondence Out of scope (Platform functionality: 1
    • Platform functionality) No contradiction to this ST FDP_ACF.1/EXT_MEM No Correspondence Out of scope (Platform functionality) No contradiction to this ST FMT_MSA.1/EXT_MEM No Correspondence Out of: 1
    • Platform functionality) No contradiction to this ST FDP_ACF.1/FIREWALL No Correspondence Out of scope (Platform functionality: 1
    • Platform functionality) No contradiction to this ST FDP_ACF.1/JCRMI No Correspondence Out of scope (Platform functionality) No contradiction to this ST FDP_RIP.1/ODEL No Correspondence Out of scope: 1
    • Platform functionality) No contradiction to this ST FDP_ACF.1/LifeCycle No Correspondence Out of scope (Platform functionality) No contradiction to this ST FMT_MSA.1/LifeCycle No Correspondence Out of: 1
    • Platform functionality) No contradiction to this ST FDP_ACF.1/SCP No Correspondence Out of scope (Platform functionality: 1
    • Platform functionality) No contradiction to this ST FDP_ACF.1/SecureBox No Correspondence Out of scope (Platform functionality: 1
    • Platform functionality) No contradiction to this ST FDP_IFF.1/CM No Correspondence Out of scope (Platform functionality: 1
    • Platform functionality) No contradiction to this ST FDP_IFF.1/JCVM No Correspondence Out of scope (Platform functionality: 1
    • Platform functionality) No contradiction to this ST FDP_RIP.1/APDU No Correspondence Out of scope (Platform functionality: 1
    • Platform functionality) No contradiction to this ST FDP_RIP.1/ODEL No Correspondence Out of scope (Platform functionality: 1
    • Platform functionality) No contradiction to this ST FDP_ROL.1/FIREWALL No Correspondence Out of scope (Platform functionality: 1
    • Platform functionality) No contradiction to this ST FIA_AFL.1/PIN No Correspondence Out of scope (Platform functionality: 1
    • Platform functionality) No contradiction to this ST FIA_ATD.1/AID No Correspondence Out of scope (Platform functionality: 1
    • Platform functionality) No contradiction to this ST FIA_UID.1/CM No Correspondence Out of scope (Platform functionality: 1
    • Platform functionality) No contradiction to this ST FIA_USB.1/AID No Correspondence Out of scope (Platform functionality: 1
    • Platform functionality) No contradiction to this ST FMT_MSA.1/ADEL No Correspondence Out of scope (Platform functionality: 1
    • Platform functionality) No contradiction to this ST FMT_MSA.1/EXT_MEM No Correspondence Out of scope (Platform functionality: 1
    • Platform functionality) No contradiction to this ST FMT_MSA.1/JCRE No Correspondence Out of scope (Platform functionality: 1
    • Platform functionality) No contradiction to this ST FMT_MSA.1/LifeCycle No Correspondence Out of scope (Platform functionality: 1
    • Platform functionality) No contradiction to this ST FMT_MSA.1/SecureBox No Correspondence Out of scope (Platform functionality: 1
    • Platform functionality) No contradiction to this ST FMT_MSA.2/FIREWALL_JCVM No Correspondence Out of scope (Platform functionality: 1
    • Platform functionality) No contradiction to this ST FMT_MSA.3/CM No Correspondence Out of scope (Platform functionality: 1
    • Platform functionality) No contradiction to this ST FMT_MSA.3/EXT_MEM No Correspondence Out of scope (Platform functionality) No contradiction to this ST FMT_SMF.1/EXT_MEM No Correspondence Out of: 1
    • Platform functionality) No contradiction to this ST FMT_MSA.3/JCVM No Correspondence Out of scope (Platform functionality: 1
    • Platform functionality) No contradiction to this ST FMT_MSA.3/LifeCycle No Correspondence Out of scope (Platform functionality) No contradiction to this ST FIA_AFL.1/PIN No Correspondence Out of scope: 1
    • Platform functionality) No contradiction to this ST FMT_MSA.3/SecureBox No Correspondence Out of scope (Platform functionality) No contradiction to this ST FMT_MSA.1/SecureBox No Correspondence Out of: 1
    • Platform functionality) No contradiction to this ST FMT_SMF.1/ADEL No Correspondence Out of scope (Platform functionality: 1
    • Platform functionality) No contradiction to this ST FMT_SMF.1/EXT_MEM No Correspondence Out of scope (Platform functionality: 1
    • Platform functionality) No contradiction to this ST FMT_SMF.1/SecureBox No Correspondence Out of scope (Platform functionality) No contradiction to this ST Table 6 Mapping of Security requirements 2.4.6: 1
    • Platform functionality) No contradiction to this ST FMT_SMR.1 No Correspondence Out of scope (Platform functionality: 1
    • Platform functionality) No contradiction to this ST FMT_SMR.1/CM No Correspondence Out of scope (Platform functionality: 1
    • Platform functionality) No contradiction to this ST FMT_SMR.1/Installer No Correspondence Out of scope (Platform functionality: 1
    • Platform functionality) No contradiction to this ST FPT_FLS.1/ADEL No Correspondence Out of scope (Platform functionality: 1
    • Platform functionality) No contradiction to this ST FPT_FLS.1/Installer No Correspondence Out of scope (Platform functionality) No contradiction to this ST FPT_RCV.3/Installer No Correspondence Out of: 1
    • Platform functionality) No contradiction to this ST FPT_FLS.1/SCP No Correspondence Out of scope (Platform functionality) No contradiction to this ST FRU_FLT.2/SCP No Correspondence Out of scope: 1
    • Platform functionality) No contradiction to this ST FPT_RCV.3/Installer No Correspondence Out of scope (Platform functionality: 1
    • Platform functionality) No contradiction to this ST FRU_FLT.2/SCP No Correspondence Out of scope (Platform functionality: 1
    • Platform functionality) No contradiction to this ST MT_MTD.3/JCRE No Correspondence Out of scope (Platform functionality: 1
    • SFR Corresponding TOE SFR Remarks No contradiction to this ST FCS_RNG.1/RNG2 No Correspondence Out of scope (Platform functionality) No contradiction to this ST FPT_EMSEC.1 FPT_EMS.1 FPT_EMS.1 matches the: 1
    • SFR Corresponding TOE SFR Remarks No contradiction to this ST FDP_IFC.1/JCVM No Correspondence Out of scope (Platform functionality) No contradiction to this ST FDP_IFF.1/JCVM No Correspondence Out of scope: 1
    • SFR Corresponding TOE SFR Remarks No contradiction to this ST FDP_RIP.1/ADEL No Correspondence Out of scope (Platform functionality) No contradiction to this ST FMT_MSA.1/ADEL No Correspondence Out of scope: 1
    • SFR Corresponding TOE SFR Remarks No contradiction to this ST FTP_ITC.1/CM No Correspondence Out of scope (Platform functionality) No contradiction to this ST FDP_ACC.1/EXT_MEM No Correspondence Out of: 1
    • SFR of the Platform-ST. FPT_TDC.1 No Correspondence Out of scope (Platform functionality) No contradiction to this ST FIA_ATD.1/AID No Correspondence Out of scope: 1
    • functionality) No contradiction to this ST FCS_RNG.1 FCS_CKM.1 Out of scope (Platform functionality) ID&Trust HTCNS Security Target lite for Secure signature creation device: 1
    • functionality) No contradiction to this ST FDP_ACC.2/JCRMI No Correspondence Out of scope (Platform functionality) No contradiction to this ST FDP_ACC.2.2/JCRMI No Correspondence Out of: 1
    • functionality) No contradiction to this ST FDP_IFC.2/CM No Correspondence Out of scope (Platform functionality) No contradiction to this ST FDP_IFF.1/CM No Correspondence Out of scope: 1
    • functionality) No contradiction to this ST FDP_ITC.2/Installer No Correspondence Out of scope (Platform functionality) No contradiction to this ST FMT_SMR.1/Installer No Correspondence Out of: 1
    • functionality) No contradiction to this ST FDP_RIP.1/OBJECTS No Correspondence Out of scope (Platform functionality) No contradiction to this ST FMT_MSA.1/JCRE No Correspondence Out of scope: 1
    • functionality) No contradiction to this ST FDP_RIP.1/bArray No Correspondence Out of scope (Platform functionality) No contradiction to this ST ID&Trust HTCNS Security Target lite for: 1
    • functionality) No contradiction to this ST FDP_UIT.1/CM No Correspondence Out of scope (Platform functionality) No contradiction to this ST FIA_UID.1/CM No Correspondence Out of scope: 1
    • functionality) No contradiction to this ST FIA_UID.2/AID No Correspondence Out of scope (Platform functionality) No contradiction to this ST FIA_USB.1/AID No Correspondence Out of scope: 1
    • functionality) No contradiction to this ST FMT_MSA.1/CM No Correspondence Out of scope (Platform functionality) No contradiction to this ST FMT_MSA.3/CM No Correspondence Out of scope: 1
    • functionality) No contradiction to this ST FMT_MSA.1/JCVM No Correspondence Out of scope (Platform functionality) No contradiction to this ST FMT_MSA.2/FIREWALL_JCVM No Correspondence Out: 1
    • functionality) No contradiction to this ST FMT_MSA.3/ADEL No Correspondence Out of scope (Platform functionality) No contradiction to this ST FMT_SMF.1/ADEL No Correspondence Out of scope: 1
    • functionality) No contradiction to this ST FMT_MSA.3/SCP No Correspondence Out of scope (Platform functionality) No contradiction to this ST FDP_ACC.1/LifeCycle No Correspondence Out of: 1
    • functionality) No contradiction to this ST FMT_MTD.1/JCRE No Correspondence Out of scope (Platform functionality) No contradiction to this ST MT_MTD.3/JCRE No Correspondence Out of scope: 1
    • functionality) No contradiction to this ST FMT_SMF.1 No Correspondence Out of scope (Platform functionality) No contradiction to this ST FMT_SMR.1 No Correspondence Out of scope: 1
    • functionality) No contradiction to this ST FMT_SMF.1/CM No Correspondence Out of scope (Platform functionality) No contradiction to this ST FMT_SMR.1/CM No Correspondence Out of scope: 1
    • functionality) No contradiction to this ST FMT_SMR.1/ADEL No Correspondence Out of scope (Platform functionality) No contradiction to this ST FPT_FLS.1/ADEL No Correspondence Out of scope: 1
    • functionality) No contradiction to this ST FPT_FLS.1/ODEL No Correspondence Out of scope (Platform functionality) No contradiction to this ST FCO_NRO.2/CM No Correspondence Out of scope: 1
    • functionality) No contradiction to this ST FTP_ITC.1/LifeCycle No Correspondence Out of scope (Platform functionality) No contradiction to this ST FAU_SAS.1/SCP No Correspondence Out of scope: 1
    • mapped as follows: Platform SFR Corresponding TOE SFR Remarks FDP_ACC.2/FIREWALL No Correspondence Out of scope (Platform functionality) No contradiction to this ST FDP_ACF.1/FIREWALL No Correspondence Out of: 1
    • of the Platform since they contain overlapping requirements. FCS_CKM.2 No Correspondence Out of scope (Platform functionality) No contradiction to this ST FCS_CKM.3 No Correspondence Out of scope: 1
    • out of scope: 1
    • requirement, meaning that the integrity is checked by the Platform. FPR_UNO.1 No Correspondence Out of scope (Platform functionality) No contradiction to this ST FPT_FLS.1 FPT_FLS.1 FPT_FLS.1 matches to the: 1
    • scope (Platform functionality) No contradiction to this ST FMT_MSA.3/FIREWALL No Correspondence Out of scope (Platform functionality) No contradiction to this ST FMT_MSA.3/JCVM No Correspondence Out of scope: 1
pdf_data/st_metadata
  • /CreationDate: D:20150602113211
  • /Producer: FPDF 1.7
  • pdf_file_size_bytes: 778707
  • pdf_hyperlinks: http://www.online-pdf-nocopy.com
  • pdf_is_encrypted: True
  • pdf_number_of_pages: 68
state/cert/convert_garbage True False
state/cert/convert_ok True False
state/cert/download_ok True False
state/cert/extract_ok True False
state/cert/pdf_hash Different Different
state/cert/txt_hash Different Different
state/report/pdf_hash Different Different
state/report/txt_hash Different Different
state/st/pdf_hash Different Different
state/st/txt_hash Different Different