Comparing certificates Experimental feature

You are comparing two certificates. By default, only differing attributes are shown. Use the button below to show/hide all attributes.

Showing only differing attributes.
NAVICS MLS Boundary Protection System Operational Software 01.00
BSI-DSZ-CC-1123-2023
IBM Logical Partition Architecture for Power7 operating on IBM Power Systems hardware with AH730_087 or AM740_088
ISCB-5-RPT-C043-CR-v1b
name NAVICS MLS Boundary Protection System Operational Software 01.00 IBM Logical Partition Architecture for Power7 operating on IBM Power Systems hardware with AH730_087 or AM740_088
category Network and Network-Related Devices and Systems Access Control Devices and Systems
scheme DE MY
status active archived
not_valid_after 13.03.2028 31.05.2018
not_valid_before 13.03.2023 31.05.2013
cert_link https://www.commoncriteriaportal.org/nfs/ccpfiles/files/epfiles/1123c_pdf.pdf
report_link https://www.commoncriteriaportal.org/nfs/ccpfiles/files/epfiles/1123a_pdf.pdf https://www.commoncriteriaportal.org/nfs/ccpfiles/files/epfiles/ISCB-5-RPT-C043-CR-v1b.pdf
st_link https://www.commoncriteriaportal.org/nfs/ccpfiles/files/epfiles/1123b_pdf.pdf https://www.commoncriteriaportal.org/nfs/ccpfiles/files/epfiles/IBM-LPAR-Security-Target-v0%2033_FINAL.pdf
manufacturer Rohde&Schwarz SIT GmbH International Business Machine (IBM) Corporation
manufacturer_web https://rohde-schwaz.com https://www.ibm.com/systems/power/
security_level EAL4+, AVA_VAN.4 EAL4+, ALC_FLR.2
dgst b2dc6148fc77cdc3 e891a1bf42b1ef69
heuristics/cert_id BSI-DSZ-CC-1123-2023 ISCB-5-RPT-C043-CR-v1b
heuristics/cert_lab BSI []
heuristics/extracted_sars ADV_TDS.3, ASE_CCL.1, ATE_FUN.1, ASE_OBJ.2, ASE_INT.1, ALC_CMC.4, ASE_REQ.2, AGD_PRE.1, ATE_IND.2, ATE_DPT.1, AVA_VAN.4, ASE_ECD.1, ADV_IMP.1, ALC_LCD.1, ASE_SPD.1, ATE_COV.2, ALC_DVS.1, ALC_TAT.1, AGD_OPE.1, ALC_CMS.4, ALC_DEL.1, ASE_TSS.1, ADV_FSP.4, ADV_ARC.1 ALC_LCD.1, ADV_TDS.3, ALC_TAT.1, AVA_VAN.3, AGD_PRE.1, ATE_FUN.1, ATE_IND.2, ALC_FLR.2, ATE_DPT.1, AGD_OPE.1, ATE_COV.2, ALC_CMS.4, ALC_CMC.4, ADV_IMP.1, ALC_DEL.1, ADV_FSP.4, ADV_ARC.1, ALC_DVS.1
heuristics/extracted_versions 01.00 -
heuristics/scheme_data
  • cert_no: 2013-003-C043
  • certification_date: 31.05.2013
  • developer: International Business Machine (IBM) Corporation
  • enhanced:
    • assurance_level: EAL4+ ALC_FLR.2
    • category: Access Control Devices and System
    • cert_id: C043
    • certification_date: 31.05.2013
    • developer: International Business Machine (IBM) Corporation3605 Hwy 52 NorthRochester, MM 55901UNITED STATES URL:http://www.ibm.com/systems/power/Email: [email protected]: 507 253 7051Fax: 507 253 2870
    • expiration_date: 31.05.2018
    • mutual_recognition: CCRA
    • product: IBM Logical Partition Architecture for Power7 operating on IBM Power Systems hardware with AH730_087 or AM740_088
    • report_link: https://iscb.cybersecurity.my/resources/document/mycc/mycpr/C043/ISCB-5-RPT-C043-CR-v1b.pdf
    • scope: The Target of Evaluation (TOE), IBM Logical Partition Architecture for Power7 operating on IBM Power Systems hardware with AH730_087 or AM740_088 (hereafter referred as LPAR), has been evaluated in the context of hardware models 770 (AM740_088 firmware) and 795 (AH730_087 firmware). The TOE firmware is designed to abstract and virtualise physical hardware resources to provide secure access to the underlying platform for one or more concurrent operating systems. Each virtual platform is known as a partition. The operating systems executing in the available partitions are treated as subjects of the TOE, where the TOE not only provides the necessary operational support for the hosted operating systems, but also serves to separate them from each other to ensure mutual non-interference. While not included as part of the TOE, the TOE is configured using a connected Hardware Management Console (HMC) that provides access to the functions necessary to enable administrative personnel to effectively manage the allocation of resources (i.e., processors, memory, and I/O devices) to the configured partitions. Once the TOE is configured, the HMC must be disconnected so that it offers no interfaces while the TOE is operating in its evaluated configuration. The TOE consists of the PowerVM Hypervisor which provides the virtualisation. The other components of the LPAR such as the Hardware Management Console (HMC), Flexible Service Processor (FSP), Bulk Power Assembly (BPA) and operating systems are outside the TOE scope. The underlying resources of the IBM Power 770 and Power 795 server platforms, including Disks, CPU, RAM, or networking, including the internal virtual switch are considered to be part of the TOE environment. In the context of the evaluation, the TOE provides the following major security features: User data protection – the TOE is designed to instantiate multiple partitions for the purpose of supporting and isolating simultaneous operating systems. As such, it implements a policy where each partition can access only those resources explicitly assigned to it. In terms of access control, the CPU, memory, and I/O devices can be assigned to a given partition and a partition can access those resources only when they are assigned to it. Identification and authentication – the active entity or user of the TOE is partition, which it instantiates. Partitions are implicitly identified and authenticated by internal numerical identifiers associated with partitions (using internal data structures) as they are defined. Being implicitly identified by the TOE, partitions have no need, nor means, to identify themselves. Furthermore, the identification of a partition is guaranteed by the TOE and as such each partition is also continuously authenticated. Security management – the TOE supports several management functions to configure the TOE via the dedicated physical HMC interface (out of scope for this evaluation). Once the TOE is operational (in evaluated configuration), the TOE effectively doesn’t offer any security management functions. However, the TOE serves to restrict the ability to change its own configuration nonetheless. Protection of the TOE Security Function (TSF) – the components of the TOE that protect themselves using the domains provided by Power7 processors. The TOE operates in the privileged domain and the partitions operate in the unprivileged domain. This allows the TOE to protect itself as well as the resources it makes selectively available to the applicable partitions. Beyond protecting itself and its resources, the TOE is also designed such that when the hardware that supports a partition fails, the other partitions will continue uninterrupted.
    • status: Archive
    • target_link: https://iscb.cybersecurity.my/resources/document/mycc/mycpr/C043/IBM-LPAR-Security-Target-v0%2033_FINAL.pdf
    • type: Set of hardware and firmware designed to abstract and virtualise physical hardware resources to provide secure access to the underlying platform for one or more concurrent operating systems.
  • expiration_date: 31.05.2018
  • level: EAL4+ ALC_FLR.2
  • product: IBM Logical Partition Architecture for Power7 operating on IBM Power Systems hardware with AH730_087 or AM740_088
  • recognition: CCRA
  • url: https://iscb.cybersecurity.my/index.php/certification/product-certification/mycc/archived-certified-products-and-systems/submission-view/69
pdf_data/cert_filename 1123c_pdf.pdf
pdf_data/cert_keywords/cc_cert_id
  • DE:
    • BSI-DSZ-CC-1123-2023: 1
pdf_data/cert_keywords/cc_protection_profile_id
pdf_data/cert_keywords/cc_security_level
  • EAL:
    • EAL 2: 1
    • EAL 4: 2
    • EAL 4 augmented: 1
pdf_data/cert_keywords/cc_sar
  • ALC:
    • ALC_FLR: 1
  • AVA:
    • AVA_VAN.4: 1
pdf_data/cert_keywords/cc_sfr
pdf_data/cert_keywords/cc_claims
pdf_data/cert_keywords/vendor
pdf_data/cert_keywords/eval_facility
pdf_data/cert_keywords/symmetric_crypto
pdf_data/cert_keywords/asymmetric_crypto
pdf_data/cert_keywords/pq_crypto
pdf_data/cert_keywords/hash_function
pdf_data/cert_keywords/crypto_scheme
pdf_data/cert_keywords/crypto_protocol
pdf_data/cert_keywords/randomness
pdf_data/cert_keywords/cipher_mode
pdf_data/cert_keywords/ecc_curve
pdf_data/cert_keywords/crypto_engine
pdf_data/cert_keywords/tls_cipher_suite
pdf_data/cert_keywords/crypto_library
pdf_data/cert_keywords/vulnerability
pdf_data/cert_keywords/side_channel_analysis
pdf_data/cert_keywords/technical_report_id
pdf_data/cert_keywords/device_model
pdf_data/cert_keywords/tee_name
pdf_data/cert_keywords/os_name
pdf_data/cert_keywords/cplc_data
pdf_data/cert_keywords/ic_data_group
pdf_data/cert_keywords/standard_id
  • ISO:
    • ISO/IEC 15408: 2
    • ISO/IEC 18045: 2
pdf_data/cert_keywords/javacard_version
pdf_data/cert_keywords/javacard_api_const
pdf_data/cert_keywords/javacard_packages
pdf_data/cert_keywords/certification_process
pdf_data/cert_metadata
  • /Author: Bundesamt für Sicherheit in der Informationstechnik
  • /Keywords: "Common Criteria, Certification, Zertifizierung, bidirectional stateless packet filtering gateway, NAVICS MLS"
  • /Subject: Common Criteria, Certification, Zertifizierung, bidirectional stateless packet filtering gateway, NAVICS MLS
  • /Title: Certificate BSI-DSZ-CC-1123-2023
  • pdf_file_size_bytes: 228950
  • pdf_hyperlinks: {}
  • pdf_is_encrypted: False
  • pdf_number_of_pages: 1
pdf_data/report_filename 1123a_pdf.pdf ISCB-5-RPT-C043-CR-v1b.pdf
pdf_data/report_frontpage
  • DE:
    • cert_id: BSI-DSZ-CC-1123-2023
    • cert_item: NAVICS MLS Boundary Protection System Operational Software V01.00
    • cert_lab: BSI
    • developer: ROHDE & SCHWARZ SIT GmbH
    • match_rules: ['(BSI-DSZ-CC-.+?) (?:for|For) (.+?) from (.*)']
  • DE:
pdf_data/report_keywords/cc_cert_id
  • DE:
    • BSI-DSZ-CC-1123-2023: 12
  • MY:
    • ISCB-5-RPT-C043-CR-v1b: 27
pdf_data/report_keywords/cc_security_level
  • EAL:
    • EAL 1: 1
    • EAL 2: 3
    • EAL 4: 8
    • EAL 4 augmented: 3
  • EAL:
    • EAL4: 5
    • EAL4 augmented: 2
    • EAL4+: 6
pdf_data/report_keywords/cc_sar
  • ALC:
    • ALC_FLR: 3
  • AVA:
    • AVA_VAN.4: 5
  • ALC:
    • ALC_FLR.2: 11
pdf_data/report_keywords/cc_sfr
  • FDP:
    • FDP_ACF.1: 4
    • FDP_IFF.1: 4
  • FIA:
    • FIA_USB.1: 1
  • FMT:
    • FMT_MSA.3: 1
  • FPT:
    • FPT_FLS.1: 1
pdf_data/report_keywords/eval_facility
  • DFKI:
    • DFKI: 2
pdf_data/report_keywords/symmetric_crypto
  • constructions:
    • MAC:
      • CMAC: 11
pdf_data/report_keywords/hash_function
  • SHA:
    • SHA2:
      • SHA-256: 3
pdf_data/report_keywords/technical_report_id
  • BSI:
    • BSI 7148: 1
    • BSI TR-02102: 1
pdf_data/report_keywords/standard_id
  • BSI:
    • AIS 1: 1
    • AIS 32: 1
  • FIPS:
    • FIPS PUB 197: 2
  • ISO:
    • ISO/IEC 15408: 4
    • ISO/IEC 17065: 2
    • ISO/IEC 18045: 4
  • NIST:
    • NIST SP 800-38B: 2
  • ISO:
    • ISO/IEC 18045: 2
    • ISO/IEC15408: 2
pdf_data/report_keywords/certification_process
  • ConfidentialDocument:
    • MLS Software V01.00 – ETR Summary, Deutsches Forschungszentrum für Künstliche Intelligenz GmbH (confidential document) [8] Configuration list for the TOE, Version 47.00, 29 November 2022, Configuration List NAVICS MLS: 1
    • Protection, Part Number 5416.2878.92 (confidential document) [9] Guidance documentation for the TOE: • R&S TF5900M Trusted Filter IP User Manual, Version 06: 1
    • being maintained, is not given any longer. In particular, prior to the dissemination of confidential documentation and information related to the TOE or resulting from the evaluation and certification: 1
  • OutOfScope:
    • out of scope: 1
    • the final product is shipped to the operator. This shipment and further installation is out of scope for this certification. 3. Security Policy The Security Policy is expressed by the set of Security: 1
  • OutOfScope:
    • out of scope: 1
    • several management functions to configure the TOE via the dedicated physical HMC interface (out of scope for PUBLIC FINAL C043 Certification Report - IBM Logical Partition Architecture for Power7: 1
pdf_data/report_metadata
  • /Author: Norhazimah Abdul Malek
  • /Category: PUBLIC
  • /Caveat: FINAL
  • /Classification: PUBLIC
  • /Company: CyberSecurity Malaysia
  • /CreationDate: D:20130613130210+08'00'
  • /Creator: Acrobat PDFMaker 10.1 for Word
  • /Developer: International Business Machine (IBM) Corporation
  • /Document Type: REPORT
  • /Identifier: ISCB-5-RPT-C043-CR-v1b
  • /Index: ISCB_TMP_011
  • /Keywords: LPAR
  • /ModDate: D:20130613130219+08'00'
  • /Phase: External
  • /Producer: Adobe PDF Library 10.0
  • /Released: 31 May 2013
  • /ST: IBM Logical Partition Architecture for Power 7 Security Target
  • /ST Version: v0.33
  • /SourceModified: D:20130613050150
  • /Sponsor: International Business Machine (IBM) Corporation
  • /Subject: IBM Logical Partition Architecture for Power7 operating on IBM Power Systems hardware with AH730_087 or AM740_088
  • /TOE: IBM Logical Partition Architecture for Power7 operating on IBM Power Systems hardware with AH730_087 or AM740_088
  • /TOE Name: LPAR
  • /TOE Version: AH730_087 or AM740_088
  • /Title: C043 Certification Report
  • /Version: v1b
  • pdf_file_size_bytes: 295961
  • pdf_hyperlinks: http://www-933.ibm.com/support/fixcentral/?mode=10&page=isoiec.html, mailto:[email protected], http://www.ibm.com/, http://www.cybersecurity.my/mycc
  • pdf_is_encrypted: True
  • pdf_number_of_pages: 28
pdf_data/st_filename 1123b_pdf.pdf IBM-LPAR-Security-Target-v0 33_FINAL.pdf
pdf_data/st_keywords/cc_security_level
  • EAL:
    • EAL 4: 1
    • EAL 4 augmented: 1
    • EAL4: 4
    • EAL4 augmented: 3
  • EAL:
    • EAL 4: 4
    • EAL 4 augmented: 4
    • EAL4: 2
    • EAL4 augmented: 2
pdf_data/st_keywords/cc_sar
  • ADV:
    • ADV_ARC.1: 1
    • ADV_FSP.4: 1
    • ADV_IMP.1: 1
    • ADV_TDS.3: 1
  • AGD:
    • AGD_OPE.1: 3
    • AGD_PRE.1: 1
  • ALC:
    • ALC_CMC.4: 1
    • ALC_CMS.4: 1
    • ALC_DEL.1: 1
    • ALC_DVS.1: 1
    • ALC_LCD.1: 1
    • ALC_TAT.1: 1
  • ASE:
    • ASE_CCL.1: 1
    • ASE_ECD.1: 1
    • ASE_INT.1: 1
    • ASE_OBJ.2: 1
    • ASE_REQ.2: 1
    • ASE_SPD.1: 1
    • ASE_TSS.1: 1
  • ATE:
    • ATE_COV.2: 1
    • ATE_DPT.1: 1
    • ATE_FUN.1: 1
    • ATE_IND.2: 1
  • AVA:
    • AVA_VAN.3: 2
    • AVA_VAN.4: 6
  • ADV:
    • ADV_ARC: 1
    • ADV_ARC.1: 10
    • ADV_FSP: 1
    • ADV_FSP.4: 11
    • ADV_IMP: 1
    • ADV_IMP.1: 7
    • ADV_TDS: 1
    • ADV_TDS.3: 15
  • AGD:
    • AGD_OPE: 1
    • AGD_OPE.1: 10
    • AGD_PRE: 1
    • AGD_PRE.1: 6
  • ALC:
    • ALC_CMC: 1
    • ALC_CMC.4: 15
    • ALC_CMS: 1
    • ALC_CMS.4: 6
    • ALC_DEL: 1
    • ALC_DEL.1: 5
    • ALC_DVS: 1
    • ALC_DVS.1: 5
    • ALC_FLR: 1
    • ALC_FLR.2: 19
    • ALC_LCD: 1
    • ALC_LCD.1: 6
    • ALC_TAT: 1
    • ALC_TAT.1: 7
  • ATE:
    • ATE_COV: 1
    • ATE_COV.2: 5
    • ATE_DPT: 1
    • ATE_DPT.1: 5
    • ATE_FUN: 1
    • ATE_FUN.1: 8
    • ATE_IND: 1
    • ATE_IND.2: 7
  • AVA:
    • AVA_VAN: 1
    • AVA_VAN.3: 7
pdf_data/st_keywords/cc_sfr
  • FCS:
    • FCS_CKM.1: 1
    • FCS_CKM.4: 4
    • FCS_COP.1: 9
    • FCS_COP.1.1: 1
  • FDP:
    • FDP_ACC.1: 2
    • FDP_IFC.1: 38
    • FDP_IFC.1.1: 3
    • FDP_IFF.1: 32
    • FDP_IFF.1.1: 3
    • FDP_IFF.1.2: 3
    • FDP_IFF.1.3: 3
    • FDP_IFF.1.4: 3
    • FDP_IFF.1.5: 4
    • FDP_ITC: 1
    • FDP_ITC.1: 11
    • FDP_ITC.1.1: 1
    • FDP_ITC.1.2: 1
    • FDP_ITC.1.3: 1
    • FDP_ITC.2: 3
    • FDP_ITT.1: 1
    • FDP_ITT.2: 8
    • FDP_ITT.2.1: 1
    • FDP_ITT.2.2: 1
    • FDP_ITT.4: 1
  • FMT:
    • FMT_MSA.3: 8
    • FMT_SMF.1: 19
    • FMT_SMF.1.1: 3
  • FPT:
    • FPT_FLS.1: 1
    • FPT_RCV.1: 7
    • FPT_RCV.1.1: 1
    • FPT_TDC.1: 1
  • FDP:
    • FDP_ACC: 6
    • FDP_ACC.1: 3
    • FDP_ACC.2: 6
    • FDP_ACC.2.1: 1
    • FDP_ACC.2.2: 1
    • FDP_ACF: 4
    • FDP_ACF.1: 4
    • FDP_ACF.1.1: 1
    • FDP_ACF.1.2: 1
    • FDP_ACF.1.3: 1
    • FDP_ACF.1.4: 1
    • FDP_IFC: 4
    • FDP_IFC.1: 2
    • FDP_IFC.2: 6
    • FDP_IFC.2.1: 1
    • FDP_IFC.2.2: 1
    • FDP_IFF: 4
    • FDP_IFF.1: 4
    • FDP_IFF.1.1: 1
    • FDP_IFF.1.2: 1
    • FDP_IFF.1.3: 1
    • FDP_IFF.1.4: 1
    • FDP_IFF.1.5: 1
    • FDP_RIP: 3
    • FDP_RIP.1: 4
    • FDP_RIP.1.1: 1
  • FIA:
    • FIA_ATD: 3
    • FIA_ATD.1: 5
    • FIA_ATD.1.1: 1
    • FIA_USB: 3
    • FIA_USB.1: 4
    • FIA_USB.1.1: 1
    • FIA_USB.1.2: 1
    • FIA_USB.1.3: 1
  • FMT:
    • FMT_MSA: 8
    • FMT_MSA.1: 5
    • FMT_MSA.1.1: 1
    • FMT_MSA.3: 10
    • FMT_MSA.3.1: 1
    • FMT_MSA.3.2: 1
    • FMT_SMF.1: 5
    • FMT_SMR.1: 6
  • FPT:
    • FPT_FLS: 3
    • FPT_FLS.1: 4
    • FPT_FLS.1.1: 1
pdf_data/st_keywords/cc_claims
  • A:
    • A.H: 1
    • A.HIGHNETWORKSECURITY: 2
    • A.T: 2
    • A.TRUSTEDADMINISTRATORS: 2
    • A.TRUSTEDUSERS: 2
  • OE:
    • OE.HIGHNETWORKSECURITY: 5
    • OE.PROTECTEDTRANSMISSION: 3
    • OE.SECUREPLATFORM: 4
    • OE.SECURERULES: 5
    • OE.TRUSTEDADMINISTRATORS: 3
    • OE.TRUSTEDUSERS: 3
  • OT:
    • OT.S: 1
    • OT.SECURESTATE: 3
    • OT.T: 2
    • OT.TRUSTEDFILTERMANAGEMENT: 5
    • OT.TRUSTEDFILTERVOICE: 4
    • OT.V: 1
    • OT.VOICETERMINAL: 3
  • T:
    • T.D: 1
    • T.DISCLOSURE: 2
    • T.M: 1
    • T.MANIPULATION: 2
  • A:
    • A.CONNECT: 3
    • A.LOCATE: 2
    • A.MANAGE: 3
  • O:
    • O.AUTHORIZATION: 4
    • O.COMMUNICATION: 3
    • O.NONINTERFERE: 4
  • OE:
    • OE.ADMIN: 2
    • OE.INSTALL: 2
    • OE.PHYSICAL: 2
  • T:
    • T.ACCESS: 3
    • T.COMMUNICATE: 2
    • T.INTERFERE: 3
pdf_data/st_keywords/eval_facility
  • DFKI:
    • DFKI: 20
pdf_data/st_keywords/symmetric_crypto
  • AES_competition:
    • AES:
      • AES: 6
      • AES-256: 2
  • constructions:
    • MAC:
      • CMAC: 51
pdf_data/st_keywords/standard_id
  • CC:
    • CCMB-2017-04-001: 1
    • CCMB-2017-04-002: 1
    • CCMB-2017-04-003: 1
  • FIPS:
    • FIPS PUB 197: 4
  • NIST:
    • NIST SP 800-38B: 4
pdf_data/st_metadata
  • /Author: Jöckel Teresa 11SI-GS1
  • /Title: Security Target NAVICS MLS Boundary Protection System Operational Software
  • pdf_file_size_bytes: 1276404
  • pdf_hyperlinks: {}
  • pdf_is_encrypted: False
  • pdf_number_of_pages: 45
  • /Author: Jim Arnold & Dave McDermitt
  • /Company: International Business Machines Corporation
  • /CreationDate: D:20130412111346-04'00'
  • /Creator: Acrobat PDFMaker 10.0 for Word
  • /Keywords:
  • /Manager: Julie Taylor
  • /ModDate: D:20130412111407-04'00'
  • /Producer: Adobe PDF Library 10.0
  • /SourceModified: D:20130412151122
  • /Subject: Security Target
  • /Title: Dynamic Logical Partition Architecture for Power5 Security Target
  • pdf_file_size_bytes: 207813
  • pdf_hyperlinks: {}
  • pdf_is_encrypted: False
  • pdf_number_of_pages: 27
state/cert/convert_ok True False
state/cert/download_ok True False
state/cert/extract_ok True False
state/cert/pdf_hash Different Different
state/cert/txt_hash Different Different
state/report/pdf_hash Different Different
state/report/txt_hash Different Different
state/st/pdf_hash Different Different
state/st/txt_hash Different Different