PP-Module for Virtual Private Network (VPN) Gateways Version 2.0

Web information

Status active
Valid from 21.01.2026
Scheme πŸ‡ΊπŸ‡Έ US
Category Network and Network-Related Devices and Systems
Security level

Certification report

certification report could not be downloaded, no link is available.

Protection Profile

Extracted keywords

Symmetric Algorithms
AES-, AES, HMAC, HMAC-SHA-384
Asymmetric Algorithms
ECDSA, Diffie-Hellman, DH
Hash functions
SHA-1, SHA-512, SHA-384, SHA-256, PBKDF, PBKDF2
Schemes
Key Exchange
Protocols
SSH, TLS, IKE, IKEv2, IPsec, VPN
Randomness
RBG
Block cipher modes
CBC, CTR, GCM, CCM, XTS

Claims
T.DATA_INTEGRITY, T.NETWORK_ACCESS, T.NETWORK_DISCLOSURE, T.NETWORK_MISUSE, T.REPLAY_ATTACK, T.WEAK_CRYPTOGRAPHY, T.UNTRUSTED_COMMUNICATION_CHANNELS, T.WEAK_AUTHENTICATION_ENDPOINTS, A.NO_THRU_TRAFFIC_PROTECTION, A.CONNECTIONS, OE.NO_THRU_TRAFFIC_PROTECTION, OE.CONNECTIONS
Security Assurance Requirements (SAR)
ATE_IND.1
Security Functional Requirements (SFR)
FAU_GEN, FAU_GEN.1, FAU_STG_EXT.1, FCS_EAP_EXT, FCS_COP, FCS_COP.1, FCS_EAP_EXT.1, FCS_CKM, FCS_CKM.1, FCS_CKM.2, FCS_EAP_EXT.1.1, FCS_EAP_EXT.1.2, FCS_EAP_EXT.1.3, FCS_RBG.1, FIA_HOTP_EXT, FIA_PSK_EXT, FIA_TOTP_EXT, FIA_XCU_EXT.1.1, FIA_PSK_EXT.1, FIA_HOTP_EXT.1, FIA_PSK_EXT.3, FIA_TOTP_EXT.1, FIA_PSK_EXT.2, FIA_PSK_EXT.1.2, FIA_HOTP_EXT.1.1, FIA_HOTP_EXT.1.2, FIA_HOTP_EXT.1.3, FIA_HOTP_EXT.1.4, FIA_HOTP_EXT.1.5, FIA_HOTP_EXT.1.6, FIA_HOTP_EXT.1.7, FIA_HOTP_EXT.1.8, FIA_TOTP_EXT.1.7, FIA_PSK_EXT.2.1, FIA_PSK_EXT.1.1, FIA_PSK_EXT.3.1, FIA_PSK_EXT.3.2, FIA_PSK_EXT.3.3, FIA_PSK_EXT.3.4, FIA_PSK_EXT.3.5, FIA_PSK_EXT.3.6, FIA_PSK_EXT.3.7, FIA_TOTP_EXT.1.2, FIA_TOTP_EXT.1.3, FIA_TOTP_EXT.1.4, FIA_TOTP_EXT.1.5, FIA_TOTP_EXT.1.6, FIA_TOTP_EXT.1.8, FIA_TOTP_EXT.1.9, FIA_TOTP_EXT.1.1, FMT_MTD, FMT_SMF.1, FMT_MTD.1, FMT_SMF, FPT_TST_EXT, FPT_FLS, FPT_TST_EXT.3, FPT_FLS.1, FPT_TST_EXT.3.1, FPT_TST_EXT.3.2, FPT_STM.1, FTA_VCM_EXT, FTA_VCM_EXT.1, FTA_SSL, FTA_TSE.1, FTA_SSL.3, FTA_TSE.1.1, FTA_TSE, FTA_VCM_EXT.1.1, FTP_ITC, FTP_ITC.1

Certification process
out of scope, rather than in an external device, is covered under the Authentication Server PP-Module, and is out of scope for this PP-Module. The MSK derived from EAP is distinct from the PSK. The MSK is substituted in

File metadata

Title PP-Module for VPN Gateways
Creation date D:20260121154015+00'00'
Modification date D:20260121154015+00'00'
Pages 72
Creator Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) HeadlessChrome/143.0.0.0 Safari/537.36
Producer Skia/PDF m143

References

No references are available for this protection profile.

Updates Feed

  • The protection profile was first processed.

Raw data

{
  "_id": "084a6f26cac1c6b3",
  "_type": "sec_certs.sample.protection_profile.ProtectionProfile",
  "dgst": "084a6f26cac1c6b3",
  "heuristics": {
    "_type": "sec_certs.sample.protection_profile.ProtectionProfile.Heuristics"
  },
  "pdf_data": {
    "_type": "sec_certs.sample.protection_profile.ProtectionProfile.PdfData",
    "pp_filename": "",
    "pp_keywords": {
      "asymmetric_crypto": {
        "ECC": {
          "ECDSA": {
            "ECDSA": 4
          }
        },
        "FF": {
          "DH": {
            "DH": 4,
            "Diffie-Hellman": 1
          }
        }
      },
      "cc_cert_id": {},
      "cc_claims": {
        "A": {
          "A.CONNECTIONS": 4,
          "A.NO_THRU_TRAFFIC_PROTECTION": 1
        },
        "OE": {
          "OE.CONNECTIONS": 3,
          "OE.NO_THRU_TRAFFIC_PROTECTION": 1
        },
        "T": {
          "T.DATA_INTEGRITY": 2,
          "T.NETWORK_ACCESS": 2,
          "T.NETWORK_DISCLOSURE": 2,
          "T.NETWORK_MISUSE": 2,
          "T.REPLAY_ATTACK": 2,
          "T.UNTRUSTED_COMMUNICATION_CHANNELS": 4,
          "T.WEAK_AUTHENTICATION_ENDPOINTS": 1,
          "T.WEAK_CRYPTOGRAPHY": 1
        }
      },
      "cc_protection_profile_id": {},
      "cc_sar": {
        "ATE": {
          "ATE_IND.1": 1
        }
      },
      "cc_security_level": {},
      "cc_sfr": {
        "FAU": {
          "FAU_GEN": 9,
          "FAU_GEN.1": 3,
          "FAU_STG_EXT.1": 1
        },
        "FCS": {
          "FCS_CKM": 5,
          "FCS_CKM.1": 3,
          "FCS_CKM.2": 1,
          "FCS_COP": 14,
          "FCS_COP.1": 6,
          "FCS_EAP_EXT": 6,
          "FCS_EAP_EXT.1": 10,
          "FCS_EAP_EXT.1.1": 3,
          "FCS_EAP_EXT.1.2": 2,
          "FCS_EAP_EXT.1.3": 3,
          "FCS_RBG.1": 12
        },
        "FIA": {
          "FIA_HOTP_EXT": 9,
          "FIA_HOTP_EXT.1": 11,
          "FIA_HOTP_EXT.1.1": 2,
          "FIA_HOTP_EXT.1.2": 2,
          "FIA_HOTP_EXT.1.3": 2,
          "FIA_HOTP_EXT.1.4": 6,
          "FIA_HOTP_EXT.1.5": 4,
          "FIA_HOTP_EXT.1.6": 5,
          "FIA_HOTP_EXT.1.7": 2,
          "FIA_HOTP_EXT.1.8": 2,
          "FIA_PSK_EXT": 11,
          "FIA_PSK_EXT.1": 17,
          "FIA_PSK_EXT.1.1": 2,
          "FIA_PSK_EXT.1.2": 8,
          "FIA_PSK_EXT.2": 8,
          "FIA_PSK_EXT.2.1": 4,
          "FIA_PSK_EXT.3": 10,
          "FIA_PSK_EXT.3.1": 5,
          "FIA_PSK_EXT.3.2": 5,
          "FIA_PSK_EXT.3.3": 3,
          "FIA_PSK_EXT.3.4": 3,
          "FIA_PSK_EXT.3.5": 2,
          "FIA_PSK_EXT.3.6": 2,
          "FIA_PSK_EXT.3.7": 3,
          "FIA_TOTP_EXT": 8,
          "FIA_TOTP_EXT.1": 10,
          "FIA_TOTP_EXT.1.1": 1,
          "FIA_TOTP_EXT.1.2": 2,
          "FIA_TOTP_EXT.1.3": 2,
          "FIA_TOTP_EXT.1.4": 6,
          "FIA_TOTP_EXT.1.5": 4,
          "FIA_TOTP_EXT.1.6": 5,
          "FIA_TOTP_EXT.1.7": 3,
          "FIA_TOTP_EXT.1.8": 4,
          "FIA_TOTP_EXT.1.9": 2,
          "FIA_XCU_EXT.1.1": 2
        },
        "FMT": {
          "FMT_MTD": 3,
          "FMT_MTD.1": 2,
          "FMT_SMF": 8,
          "FMT_SMF.1": 6
        },
        "FPT": {
          "FPT_FLS": 7,
          "FPT_FLS.1": 1,
          "FPT_STM.1": 1,
          "FPT_TST_EXT": 4,
          "FPT_TST_EXT.3": 13,
          "FPT_TST_EXT.3.1": 2,
          "FPT_TST_EXT.3.2": 2
        },
        "FTA": {
          "FTA_SSL": 8,
          "FTA_SSL.3": 1,
          "FTA_TSE": 4,
          "FTA_TSE.1": 6,
          "FTA_TSE.1.1": 1,
          "FTA_VCM_EXT": 4,
          "FTA_VCM_EXT.1": 12,
          "FTA_VCM_EXT.1.1": 2
        },
        "FTP": {
          "FTP_ITC": 5,
          "FTP_ITC.1": 9
        }
      },
      "certification_process": {
        "OutOfScope": {
          "out of scope": 1,
          "rather than in an external device, is covered under the Authentication Server PP-Module, and is out of scope for this PP-Module. The MSK derived from EAP is distinct from the PSK. The MSK is substituted in": 1
        }
      },
      "cipher_mode": {
        "CBC": {
          "CBC": 1
        },
        "CCM": {
          "CCM": 4
        },
        "CTR": {
          "CTR": 1
        },
        "GCM": {
          "GCM": 6
        },
        "XTS": {
          "XTS": 1
        }
      },
      "cplc_data": {},
      "crypto_engine": {},
      "crypto_library": {},
      "crypto_protocol": {
        "IKE": {
          "IKE": 12,
          "IKEv2": 25
        },
        "IPsec": {
          "IPsec": 36
        },
        "SSH": {
          "SSH": 1
        },
        "TLS": {
          "TLS": {
            "TLS": 9
          }
        },
        "VPN": {
          "VPN": 128
        }
      },
      "crypto_scheme": {
        "KEX": {
          "Key Exchange": 1
        }
      },
      "device_model": {},
      "ecc_curve": {},
      "eval_facility": {},
      "hash_function": {
        "PBKDF": {
          "PBKDF": 2,
          "PBKDF2": 1
        },
        "SHA": {
          "SHA1": {
            "SHA-1": 4
          },
          "SHA2": {
            "SHA-256": 4,
            "SHA-384": 6,
            "SHA-512": 5
          }
        }
      },
      "ic_data_group": {},
      "javacard_api_const": {},
      "javacard_packages": {},
      "javacard_version": {},
      "os_name": {},
      "pq_crypto": {},
      "randomness": {
        "RNG": {
          "RBG": 4
        }
      },
      "side_channel_analysis": {},
      "standard_id": {
        "CC": {
          "CCMB-2022-11-001": 1,
          "CCMB-2022-11-002": 1,
          "CCMB-2022-11-003": 1,
          "CCMB-2022-11-005": 1,
          "CCMB-2022-11-006": 1
        },
        "FIPS": {
          "FIPS PUB 186-5": 3,
          "FIPS PUB 197": 2
        },
        "ISO": {
          "ISO/IEC 15408": 2,
          "ISO/IEC 18033-": 2,
          "ISO/IEC 19772:2020": 2
        },
        "NIST": {
          "NIST SP 800-132": 1,
          "NIST SP 800-38C": 1,
          "NIST SP 800-38D": 1,
          "NIST SP 800-63b": 1
        },
        "RFC": {
          "RFC 3526": 2,
          "RFC 4106": 1,
          "RFC 4226": 2,
          "RFC 4303": 1,
          "RFC 4868": 2,
          "RFC 4945": 1,
          "RFC 5114": 1,
          "RFC 5216": 2,
          "RFC 5281": 2,
          "RFC 5282": 2,
          "RFC 6238": 2,
          "RFC 7296": 2,
          "RFC 768": 3,
          "RFC 791": 3,
          "RFC 7919": 1,
          "RFC 792": 1,
          "RFC 793": 3,
          "RFC 8200": 3,
          "RFC 8603": 1,
          "RFC 8784": 6,
          "RFC 8996": 4
        },
        "X509": {
          "X.509": 8
        }
      },
      "symmetric_crypto": {
        "AES_competition": {
          "AES": {
            "AES": 8,
            "AES-": 2
          }
        },
        "constructions": {
          "MAC": {
            "HMAC": 8,
            "HMAC-SHA-384": 1
          }
        }
      },
      "technical_report_id": {},
      "tee_name": {},
      "tls_cipher_suite": {},
      "vendor": {},
      "vulnerability": {}
    },
    "pp_metadata": {
      "/CreationDate": "D:20260121154015+00\u002700\u0027",
      "/Creator": "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) HeadlessChrome/143.0.0.0 Safari/537.36",
      "/ModDate": "D:20260121154015+00\u002700\u0027",
      "/Producer": "Skia/PDF m143",
      "/Title": "PP-Module for VPN Gateways",
      "pdf_file_size_bytes": 4227160,
      "pdf_hyperlinks": {
        "_type": "Set",
        "elements": [
          "http://www.commoncriteriaportal.org/files/ccfiles/CC2022PART3R1.pdf",
          "http://www.commoncriteriaportal.org/files/ccfiles/CC2022PART2R1.pdf",
          "http://www.commoncriteriaportal.org/files/ccfiles/CC2022PART5R1.pdf",
          "http://www.commoncriteriaportal.org/files/ccfiles/CC2022PART4R1.pdf",
          "http://www.commoncriteriaportal.org/files/ccfiles/CEM2022R1.pdf",
          "https://www.niap-ccevs.org/protectionprofiles/524",
          "https://www.commoncriteriaportal.org/files/ccfiles/CC2022PART1R1.pdf",
          "https://www.niap-ccevs.org/protectionprofiles/511"
        ]
      },
      "pdf_is_encrypted": false,
      "pdf_number_of_pages": 72
    },
    "report_filename": null,
    "report_keywords": null,
    "report_metadata": null
  },
  "scheme_metadata": {
    "cc_version": "CC:2022",
    "pp_short_name": "MOD_VPNGW_v2.0",
    "pp_sponsor_id": "NIAP",
    "pp_transition": null,
    "predecessor": "MOD_VPNGW_v1.3",
    "source_scheme": "US",
    "successor": null
  },
  "state": {
    "_type": "sec_certs.sample.protection_profile.ProtectionProfile.InternalState",
    "pp": {
      "_type": "sec_certs.sample.document_state.DocumentState",
      "convert_ok": true,
      "download_ok": true,
      "extract_ok": true,
      "json_hash": null,
      "source_hash": "98a309e09d0ac473c8e23c872991faa0004f3ef0e34d6bade195346d3fb60d8e",
      "txt_hash": "019d8f6fd020925fdb0f8e580811d059c52872c1c9b3cf52857a8d4612d15c3f"
    },
    "report": {
      "_type": "sec_certs.sample.document_state.DocumentState",
      "convert_ok": false,
      "download_ok": false,
      "extract_ok": false,
      "json_hash": null,
      "source_hash": null,
      "txt_hash": null
    }
  },
  "web_data": {
    "_type": "sec_certs.sample.protection_profile.ProtectionProfile.WebData",
    "category": "Network and Network-Related Devices and Systems",
    "is_collaborative": false,
    "maintenances": [],
    "name": "PP-Module for Virtual Private Network (VPN) Gateways Version 2.0",
    "not_valid_after": null,
    "not_valid_before": "2026-01-21",
    "pp_link": "https://www.niap-ccevs.org/api/file/get_public_file/?file_id=37068",
    "report_link": null,
    "scheme": "US",
    "security_level": {
      "_type": "Set",
      "elements": []
    },
    "status": "active",
    "version": "2.0"
  }
}