Voice Stream Interceptor (VSI)

CSV information

Status archived
Valid from 21.06.2017
Valid until 21.06.2022
Scheme 🇳🇴 NO
Manufacturer Saab Danmark AS
Category Other Devices and Systems
Security level EAL5+, ALC_FLR.3
Maintenance updates SERTIT-072 MR Maintenance Report v 1.0 (01.10.2021) Certification report Security target

Heuristics summary

Certificate ID: SERTIT-072

Certificate

certificate could not be downloaded, no link is available.

Certification report

Extracted keywords

Hash functions
SHA256
Protocols
VPN

Security level
EAL 5, EAL 2, EAL 4, EAL1, EAL7, EAL5, EAL 5 augmented, EAL 2 augmented
Claims
O.BLACK_VOICE_STREAM, O.STREAM_SETUP, OE.TRUSTED_RELEASE, OE.PREVENT_ACCESS
Security Assurance Requirements (SAR)
ADV_TDS.4, ALC_FLR.3, ALC_FLR, ALC_TAT.2, ATE_COV.2, AVA_VAN.4
Security Functional Requirements (SFR)
FAU_GEN.1, FDP_IFC.1, FMT_MSA.1, FMT_SMR.1, FMT_MSA.3, FPT_STM.1, FPT_FLS.1, FPT_TST.1, FTP_TRP.1
Certificates
SERTIT-072

Standards
ISO/IEC 15408, CCMB-2012-09-004

File metadata

Subject 385678 340600 VEDLEGG01
Author holthj-NSM-PC0709,44FD1973A6,CZC41336S0,CZC41336S0
Creation date D:20170816091149+02'00'
Modification date D:20170816091149+02'00'
Pages 24
Creator PixEdit Version 8.0.6.4, SN 357-92834-02, Nasjonal sikkerhetsmyndighet,(6A3791DF44),www.pixedit.com
Producer Techsoft PixEdit Version 8.0.6.4, SN 357-92834-02, Nasjonal sikkerhetsmyndighet

Security target

Extracted keywords

Protocols
IPsec, VPN

Security level
EAL5, EAL 5
Claims
O.BLACK_VOICE_STREAM, O.RED_VOICE_STREAM, O.STREAM_SETUP, T.TERMINAL_INTEGRITY, T.NETWORK_INTEGRITY, T.WRONG_LABEL, T.CORRUPT_STREAM, T.SETUP, T.CORRUPT_FORMAT, A.SECURE_IP, A.SECURE_LOCATION, A.SECURE_OS, A.TRUSTED_VPN, OT.SELECTOR, OT.SANITY_CHECK, OT.SUBSTITUTION, OT.SEND, OT.LOG, OT.ROBUST, OT.SUPPRESS, OE.TRUSTED_RELEASE, OE.SECURE_IP, OE.SECURE_LOCATION, OE.ENVIRONMENTAL, OE.ACOUSTIC_FEEDBACK, OE.INSTRUCTED_USERS, OE.INSTRUCTED_ADMIN, OE.EVALUATED_OS, OE.LOG_ACCESS, OE.READ_LOG, OE.TRUSTED_REGISTRAR, OE.PREVENT_ACCESS, SA.VOICE_STREAM_CLASSIFICATION
Security Assurance Requirements (SAR)
ALC_FLR.3
Security Functional Requirements (SFR)
FAU_GEN.1, FAU_GEN.1.1, FAU_GEN.1.2, FDP_IFC, FDP_IFC.1, FDP_IFF, FDP_IFF.1, FDP_IFC.1.1, FDP_IFF.1.1, FDP_IFF.1.2, FDP_IFF.1.3, FDP_IFF.1.4, FDP_IFF.1.5, FDP_ITC.1, FMT_MSA, FMT_MSA.3, FMT_MSA.1, FMT_SMR.1, FMT_MSA.3.1, FMT_MSA.3.2, FPT_FLS, FPT_FLS.1, FPT_TST, FPT_TST.1, FPT_STM.1, FPT_FLS.1.1, FPT_TST.1.1, FPT_TST.1.2, FPT_TST.1.3, FTP_TRP, FTP_TRP.1, FTP_TRP.1.1, FTP_TRP.1.2, FTP_TRP.1.3
Certificates
SERTIT-072

File metadata

Author Arne Stig Peters
Creation date D:20170815121252+02'00'
Modification date D:20170815121252+02'00'
Pages 34
Creator Microsoft® Word 2010
Producer Microsoft® Word 2010

Heuristics

Automated inference - use with caution

All attributes shown in this section (e.g., links between certificates, products, vendors, and known CVEs) are generated by automated heuristics and have not been reviewed by humans. These methods can produce false positives or false negatives and should not be treated as definitive without independent verification. For details on our data sources and inference methods, see our methodology. If you believe any information here is inaccurate or harmful, please submit feedback.

Certificate ID

SERTIT-072

Extracted SARs

ADV_TDS.4, ALC_FLR.3, ALC_TAT.2, ATE_COV.2, AVA_VAN.4

Scheme data

Product Voice Stream Interceptor
Url https://sertit.no/certified-products/product-archive/voice-stream-interceptor
Category Other Devices and Systems
Developer SAAB Danmark A/S
Certification Date 21.06.2017
Enhanced
Description Saab Voice Stream Interceptor (VSI) is a software security product providing secure domain separation between voice with different classification level. VSI has very few requirements to the underlying platform and can be installed on a Common Criteria approved Linux Operating System with IPsec tunnel and Trusted Platform Module (TPM). VSI supports standardized Voice over IP (VoIP) communication and is used for VoIP clients. The VoIP client user application is completely separated from VSI and does not require being trusted for the secure separation of classified voice. The separation between the VoIP client user application and VSI gives the possibility to change or upgrade the user application and still maintain a secure domain separation of classified voice by an unchanged VSI. From an users point of view the VoIP client containing VSI can both be used for classified (RED) and lower classified or non-classified (BLACK) voice communication. In this way, a conversation can start as non-classified and during the conversation be switched to a classified conversation. Operational modes on radio based communication are supported in this way. It is also possible to listen to both BLACK and RED voice at the same time. VSI also controls the suppression of RED incoming voice stream to the VoIP client, such that while sending BLACK voice the possible pickup and cross talk via the speaker to the microphone is eliminated. During authorized configuration the suppression functionality can either be enabled or disabled depending on the required operational procedure. Saab provides the Secure Tacticall VoIP client, where VSI has been integrated into a user friendly end product and can be used in a secure RED/BLACK system solution.
Cert Id SERTIT-072
Mutual Recognition CCRA, SOG-IS
Product Stock no. SV000071, Version 1
Category Other Devices and Systems
Sponsor Norwegian Defence Logistics Organization Naval System
Developer SAAB Danmark A/S
Evaluation Facility NTT Com Security (Norway) AS
Certification Date 21.06.2017
Level EAL 5
Documents frozendict({'cert': [frozendict({'href': 'https://sertit.no/getfile.php/135133-1607953045/SERTIT/Sertifikater/2017/72/C%20SERTIT-072.pdf'})], 'target': [frozendict({'href': 'https://sertit.no/getfile.php/135136-1607953047/SERTIT/Sertifikater/2017/72/SV000073-Voice-Stream-Interceptor-Security-Target-Lite.pdf'}), frozendict({'href': 'https://sertit.no/getfile.php/137492-1633083420/SERTIT/Sertifikater/2017/72/SV000073-Voice-Stream-Interceptor-Security-Target-Lite-2.pdf'})], 'report': [frozendict({'href': 'https://sertit.no/getfile.php/135139-1607953051/SERTIT/Sertifikater/2017/72/CR%20SERTIT-072_1.PDF'})], 'maintenance': [frozendict({'href': 'https://sertit.no/getfile.php/137486-1633083312/SERTIT/Sertifikater/2017/72/SERTIT-072%20MR%20v%201.0.pdf'})]})

References

No references are available for this certificate.

Updates Feed

  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate was first processed.

Raw data

{
  "_type": "sec_certs.sample.cc.CCCertificate",
  "category": "Other Devices and Systems",
  "cert_link": null,
  "dgst": "28228ddc7cba794e",
  "heuristics": {
    "_type": "sec_certs.sample.cc.CCCertificate.Heuristics",
    "annotated_references": null,
    "cert_id": "SERTIT-072",
    "cert_lab": null,
    "cpe_matches": null,
    "direct_transitive_cves": null,
    "eal": "EAL5+",
    "extracted_sars": {
      "_type": "Set",
      "elements": [
        {
          "_type": "sec_certs.sample.sar.SAR",
          "family": "ADV_TDS",
          "level": 4
        },
        {
          "_type": "sec_certs.sample.sar.SAR",
          "family": "ALC_TAT",
          "level": 2
        },
        {
          "_type": "sec_certs.sample.sar.SAR",
          "family": "ALC_FLR",
          "level": 3
        },
        {
          "_type": "sec_certs.sample.sar.SAR",
          "family": "ATE_COV",
          "level": 2
        },
        {
          "_type": "sec_certs.sample.sar.SAR",
          "family": "AVA_VAN",
          "level": 4
        }
      ]
    },
    "extracted_versions": {
      "_type": "Set",
      "elements": [
        "-"
      ]
    },
    "indirect_transitive_cves": null,
    "next_certificates": null,
    "prev_certificates": null,
    "protection_profiles": null,
    "related_cves": null,
    "report_references": {
      "_type": "sec_certs.sample.certificate.References",
      "directly_referenced_by": null,
      "directly_referencing": null,
      "indirectly_referenced_by": null,
      "indirectly_referencing": null
    },
    "scheme_data": {
      "category": "Other Devices and Systems",
      "certification_date": "2017-06-21",
      "developer": "SAAB Danmark A/S",
      "enhanced": {
        "category": "Other Devices and Systems",
        "cert_id": "SERTIT-072",
        "certification_date": "2017-06-21",
        "description": "Saab Voice Stream Interceptor (VSI) is a software security product providing secure domain separation between voice with different classification level. VSI has very few requirements to the underlying platform and can be installed on a Common Criteria approved Linux Operating System with IPsec tunnel and Trusted Platform Module (TPM). VSI supports standardized Voice over IP (VoIP) communication and is used for VoIP clients. The VoIP client user application is completely separated from VSI and does not require being trusted for the secure separation of classified voice. The separation between the VoIP client user application and VSI gives the possibility to change or upgrade the user application and still maintain a secure domain separation of classified voice by an unchanged VSI. From an users point of view the VoIP client containing VSI can both be used for classified (RED) and lower classified or non-classified (BLACK) voice communication. In this way, a conversation can start as non-classified and during the conversation be switched to a classified conversation. Operational modes on radio based communication are supported in this way. It is also possible to listen to both BLACK and RED voice at the same time. VSI also controls the suppression of RED incoming voice stream to the VoIP client, such that while sending BLACK voice the possible pickup and cross talk via the speaker to the microphone is eliminated. During authorized configuration the suppression functionality can either be enabled or disabled depending on the required operational procedure. Saab provides the Secure Tacticall VoIP client, where VSI has been integrated into a user friendly end product and can be used in a secure RED/BLACK system solution.",
        "developer": "SAAB Danmark A/S",
        "documents": {
          "cert": [
            {
              "href": "https://sertit.no/getfile.php/135133-1607953045/SERTIT/Sertifikater/2017/72/C%20SERTIT-072.pdf"
            }
          ],
          "maintenance": [
            {
              "href": "https://sertit.no/getfile.php/137486-1633083312/SERTIT/Sertifikater/2017/72/SERTIT-072%20MR%20v%201.0.pdf"
            }
          ],
          "report": [
            {
              "href": "https://sertit.no/getfile.php/135139-1607953051/SERTIT/Sertifikater/2017/72/CR%20SERTIT-072_1.PDF"
            }
          ],
          "target": [
            {
              "href": "https://sertit.no/getfile.php/135136-1607953047/SERTIT/Sertifikater/2017/72/SV000073-Voice-Stream-Interceptor-Security-Target-Lite.pdf"
            },
            {
              "href": "https://sertit.no/getfile.php/137492-1633083420/SERTIT/Sertifikater/2017/72/SV000073-Voice-Stream-Interceptor-Security-Target-Lite-2.pdf"
            }
          ]
        },
        "evaluation_facility": "NTT Com Security (Norway) AS",
        "level": "EAL 5",
        "mutual_recognition": "CCRA, SOG-IS",
        "product": "Stock no. SV000071, Version 1",
        "sponsor": "Norwegian Defence Logistics Organization Naval System"
      },
      "product": "Voice Stream Interceptor",
      "url": "https://sertit.no/certified-products/product-archive/voice-stream-interceptor"
    },
    "st_references": {
      "_type": "sec_certs.sample.certificate.References",
      "directly_referenced_by": null,
      "directly_referencing": null,
      "indirectly_referenced_by": null,
      "indirectly_referencing": null
    },
    "verified_cpe_matches": null
  },
  "maintenance_updates": {
    "_type": "Set",
    "elements": [
      {
        "_type": "sec_certs.sample.cc.CCCertificate.MaintenanceReport",
        "maintenance_date": "2021-10-01",
        "maintenance_report_link": "https://www.commoncriteriaportal.org/nfs/ccpfiles/files/epfiles/SERTIT-072%20MR%20v%201.0.pdf",
        "maintenance_st_link": "https://www.commoncriteriaportal.org/nfs/ccpfiles/files/epfiles/SV000073-Voice-Stream-Interceptor-Security-Target-Lite-2.pdf",
        "maintenance_title": "SERTIT-072 MR Maintenance Report v 1.0"
      }
    ]
  },
  "manufacturer": "Saab Danmark AS",
  "manufacturer_web": "https://saabgroup.com",
  "name": "Voice Stream Interceptor (VSI)",
  "not_valid_after": "2022-06-21",
  "not_valid_before": "2017-06-21",
  "pdf_data": {
    "_type": "sec_certs.sample.cc.CCCertificate.PdfData",
    "cert_filename": null,
    "cert_frontpage": null,
    "cert_keywords": null,
    "cert_metadata": null,
    "report_filename": "CR SERTIT-072_1.PDF",
    "report_frontpage": {},
    "report_keywords": {
      "asymmetric_crypto": {},
      "cc_cert_id": {
        "NO": {
          "SERTIT-072": 6
        }
      },
      "cc_claims": {
        "O": {
          "O.BLACK_VOICE_STREAM": 1,
          "O.STREAM_SETUP": 1
        },
        "OE": {
          "OE.PREVENT_ACCESS": 2,
          "OE.TRUSTED_RELEASE": 1
        }
      },
      "cc_protection_profile_id": {},
      "cc_sar": {
        "ADV": {
          "ADV_TDS.4": 1
        },
        "ALC": {
          "ALC_FLR": 3,
          "ALC_FLR.3": 25,
          "ALC_TAT.2": 1
        },
        "ATE": {
          "ATE_COV.2": 1
        },
        "AVA": {
          "AVA_VAN.4": 2
        }
      },
      "cc_security_level": {
        "EAL": {
          "EAL 2": 1,
          "EAL 2 augmented": 1,
          "EAL 4": 1,
          "EAL 5": 28,
          "EAL 5 augmented": 26,
          "EAL1": 1,
          "EAL5": 1,
          "EAL7": 1
        }
      },
      "cc_sfr": {
        "FAU": {
          "FAU_GEN.1": 1
        },
        "FDP": {
          "FDP_IFC.1": 1
        },
        "FMT": {
          "FMT_MSA.1": 1,
          "FMT_MSA.3": 1,
          "FMT_SMR.1": 1
        },
        "FPT": {
          "FPT_FLS.1": 1,
          "FPT_STM.1": 1,
          "FPT_TST.1": 1
        },
        "FTP": {
          "FTP_TRP.1": 1
        }
      },
      "certification_process": {},
      "cipher_mode": {},
      "cplc_data": {},
      "crypto_engine": {},
      "crypto_library": {},
      "crypto_protocol": {
        "VPN": {
          "VPN": 6
        }
      },
      "crypto_scheme": {},
      "device_model": {},
      "ecc_curve": {},
      "eval_facility": {},
      "hash_function": {
        "SHA": {
          "SHA2": {
            "SHA256": 2
          }
        }
      },
      "ic_data_group": {},
      "javacard_api_const": {},
      "javacard_packages": {},
      "javacard_version": {},
      "os_name": {},
      "pq_crypto": {},
      "randomness": {},
      "side_channel_analysis": {},
      "standard_id": {
        "CC": {
          "CCMB-2012-09-004": 1
        },
        "ISO": {
          "ISO/IEC 15408": 8
        }
      },
      "symmetric_crypto": {},
      "technical_report_id": {},
      "tee_name": {},
      "tls_cipher_suite": {},
      "vendor": {},
      "vulnerability": {}
    },
    "report_metadata": {
      "/Author": "holthj-NSM-PC0709,44FD1973A6,CZC41336S0,CZC41336S0",
      "/CreationDate": "D:20170816091149+02\u002700\u0027",
      "/Creator": "PixEdit Version 8.0.6.4, SN 357-92834-02, Nasjonal sikkerhetsmyndighet,(6A3791DF44),www.pixedit.com",
      "/ModDate": "D:20170816091149+02\u002700\u0027",
      "/Producer": "Techsoft PixEdit Version 8.0.6.4, SN 357-92834-02, Nasjonal sikkerhetsmyndighet",
      "/Subject": "385678 340600 VEDLEGG01",
      "pdf_file_size_bytes": 7954615,
      "pdf_hyperlinks": {
        "_type": "Set",
        "elements": []
      },
      "pdf_is_encrypted": false,
      "pdf_number_of_pages": 24
    },
    "st_filename": "SV000073-Voice-Stream-Interceptor-Security-Target-Lite.pdf",
    "st_frontpage": null,
    "st_keywords": {
      "asymmetric_crypto": {},
      "cc_cert_id": {
        "NO": {
          "SERTIT-072": 1
        }
      },
      "cc_claims": {
        "A": {
          "A.SECURE_IP": 4,
          "A.SECURE_LOCATION": 3,
          "A.SECURE_OS": 5,
          "A.TRUSTED_VPN": 4
        },
        "O": {
          "O.BLACK_VOICE_STREAM": 9,
          "O.RED_VOICE_STREAM": 6,
          "O.STREAM_SETUP": 6
        },
        "OE": {
          "OE.ACOUSTIC_FEEDBACK": 3,
          "OE.ENVIRONMENTAL": 4,
          "OE.EVALUATED_OS": 7,
          "OE.INSTRUCTED_ADMIN": 9,
          "OE.INSTRUCTED_USERS": 7,
          "OE.LOG_ACCESS": 4,
          "OE.PREVENT_ACCESS": 7,
          "OE.READ_LOG": 4,
          "OE.SECURE_IP": 4,
          "OE.SECURE_LOCATION": 6,
          "OE.TRUSTED_REGISTRAR": 3,
          "OE.TRUSTED_RELEASE": 8
        },
        "OT": {
          "OT.LOG": 8,
          "OT.ROBUST": 6,
          "OT.SANITY_CHECK": 10,
          "OT.SELECTOR": 10,
          "OT.SEND": 8,
          "OT.SUBSTITUTION": 9,
          "OT.SUPPRESS": 7
        },
        "SA": {
          "SA.VOICE_STREAM_CLASSIFICATION": 4
        },
        "T": {
          "T.CORRUPT_FORMAT": 3,
          "T.CORRUPT_STREAM": 3,
          "T.NETWORK_INTEGRITY": 3,
          "T.SETUP": 4,
          "T.TERMINAL_INTEGRITY": 4,
          "T.WRONG_LABEL": 4
        }
      },
      "cc_protection_profile_id": {},
      "cc_sar": {
        "ALC": {
          "ALC_FLR.3": 1
        }
      },
      "cc_security_level": {
        "EAL": {
          "EAL 5": 1,
          "EAL5": 1
        }
      },
      "cc_sfr": {
        "FAU": {
          "FAU_GEN.1": 6,
          "FAU_GEN.1.1": 1,
          "FAU_GEN.1.2": 1
        },
        "FDP": {
          "FDP_IFC": 2,
          "FDP_IFC.1": 20,
          "FDP_IFC.1.1": 3,
          "FDP_IFF": 2,
          "FDP_IFF.1": 22,
          "FDP_IFF.1.1": 3,
          "FDP_IFF.1.2": 3,
          "FDP_IFF.1.3": 3,
          "FDP_IFF.1.4": 3,
          "FDP_IFF.1.5": 3,
          "FDP_ITC.1": 1
        },
        "FMT": {
          "FMT_MSA": 2,
          "FMT_MSA.1": 4,
          "FMT_MSA.3": 12,
          "FMT_MSA.3.1": 1,
          "FMT_MSA.3.2": 1,
          "FMT_SMR.1": 4
        },
        "FPT": {
          "FPT_FLS": 2,
          "FPT_FLS.1": 6,
          "FPT_FLS.1.1": 1,
          "FPT_STM.1": 4,
          "FPT_TST": 2,
          "FPT_TST.1": 5,
          "FPT_TST.1.1": 1,
          "FPT_TST.1.2": 1,
          "FPT_TST.1.3": 1
        },
        "FTP": {
          "FTP_TRP": 2,
          "FTP_TRP.1": 6,
          "FTP_TRP.1.1": 1,
          "FTP_TRP.1.2": 1,
          "FTP_TRP.1.3": 1
        }
      },
      "certification_process": {},
      "cipher_mode": {},
      "cplc_data": {},
      "crypto_engine": {},
      "crypto_library": {},
      "crypto_protocol": {
        "IPsec": {
          "IPsec": 2
        },
        "VPN": {
          "VPN": 14
        }
      },
      "crypto_scheme": {},
      "device_model": {},
      "ecc_curve": {},
      "eval_facility": {},
      "hash_function": {},
      "ic_data_group": {},
      "javacard_api_const": {},
      "javacard_packages": {},
      "javacard_version": {},
      "os_name": {},
      "pq_crypto": {},
      "randomness": {},
      "side_channel_analysis": {},
      "standard_id": {},
      "symmetric_crypto": {},
      "technical_report_id": {},
      "tee_name": {},
      "tls_cipher_suite": {},
      "vendor": {},
      "vulnerability": {}
    },
    "st_metadata": {
      "/Author": "Arne Stig Peters",
      "/CreationDate": "D:20170815121252+02\u002700\u0027",
      "/Creator": "Microsoft\u00ae Word 2010",
      "/ModDate": "D:20170815121252+02\u002700\u0027",
      "/Producer": "Microsoft\u00ae Word 2010",
      "pdf_file_size_bytes": 1265855,
      "pdf_hyperlinks": {
        "_type": "Set",
        "elements": []
      },
      "pdf_is_encrypted": false,
      "pdf_number_of_pages": 34
    }
  },
  "protection_profile_links": {
    "_type": "Set",
    "elements": []
  },
  "report_link": "https://www.commoncriteriaportal.org/nfs/ccpfiles/files/epfiles/CR%20SERTIT-072_1.PDF",
  "scheme": "NO",
  "security_level": {
    "_type": "Set",
    "elements": [
      "EAL5+",
      "ALC_FLR.3"
    ]
  },
  "st_link": "https://www.commoncriteriaportal.org/nfs/ccpfiles/files/epfiles/SV000073-Voice-Stream-Interceptor-Security-Target-Lite.pdf",
  "state": {
    "_type": "sec_certs.sample.cc.CCCertificate.InternalState",
    "cert": {
      "_type": "sec_certs.sample.document_state.DocumentState",
      "convert_ok": false,
      "download_ok": false,
      "extract_ok": false,
      "json_hash": null,
      "pdf_hash": null,
      "txt_hash": null
    },
    "report": {
      "_type": "sec_certs.sample.document_state.DocumentState",
      "convert_ok": true,
      "download_ok": true,
      "extract_ok": true,
      "json_hash": null,
      "pdf_hash": "701b52ee9b40730b549faa8eae4ed6148d2a79a69c9de5801abab586e05024b1",
      "txt_hash": "f06e9e1584d9da95a2df7fef170026ddc66f8e2ce65c259e2014b8e49ff720d2"
    },
    "st": {
      "_type": "sec_certs.sample.document_state.DocumentState",
      "convert_ok": true,
      "download_ok": true,
      "extract_ok": true,
      "json_hash": null,
      "pdf_hash": "da1dea83fcf09a40aa852df7d95ef859922c7bee3cb25b070e250dbdf19c073b",
      "txt_hash": "409e9956df2dcfd0a3da273a140c49599fbbc4800fe852d4008c4f1ddedcf2c6"
    }
  },
  "status": "archived"
}