This page was not yet optimized for use on mobile
devices.
PP-Module for Virtual Private Network (VPN) Gateways Version 2.0
Web information
| Status | active |
|---|---|
| Valid from | 21.01.2026 |
| Scheme | πΊπΈ US |
| Category | Network and Network-Related Devices and Systems |
| Security level |
Certification report
certification report could not be downloaded, no link is available.
Protection Profile
Extracted keywords
Symmetric Algorithms
AES-, AES, HMAC, HMAC-SHA-384Asymmetric Algorithms
ECDSA, Diffie-Hellman, DHHash functions
SHA-1, SHA-512, SHA-384, SHA-256, PBKDF, PBKDF2Schemes
Key ExchangeProtocols
SSH, TLS, IKE, IKEv2, IPsec, VPNRandomness
RBGBlock cipher modes
CBC, CTR, GCM, CCM, XTSClaims
T.DATA_INTEGRITY, T.NETWORK_ACCESS, T.NETWORK_DISCLOSURE, T.NETWORK_MISUSE, T.REPLAY_ATTACK, T.WEAK_CRYPTOGRAPHY, T.UNTRUSTED_COMMUNICATION_CHANNELS, T.WEAK_AUTHENTICATION_ENDPOINTS, A.NO_THRU_TRAFFIC_PROTECTION, A.CONNECTIONS, OE.NO_THRU_TRAFFIC_PROTECTION, OE.CONNECTIONSSecurity Assurance Requirements (SAR)
ATE_IND.1Security Functional Requirements (SFR)
FAU_GEN, FAU_GEN.1, FAU_STG_EXT.1, FCS_EAP_EXT, FCS_COP, FCS_COP.1, FCS_EAP_EXT.1, FCS_CKM, FCS_CKM.1, FCS_CKM.2, FCS_EAP_EXT.1.1, FCS_EAP_EXT.1.2, FCS_EAP_EXT.1.3, FCS_RBG.1, FIA_HOTP_EXT, FIA_PSK_EXT, FIA_TOTP_EXT, FIA_XCU_EXT.1.1, FIA_PSK_EXT.1, FIA_HOTP_EXT.1, FIA_PSK_EXT.3, FIA_TOTP_EXT.1, FIA_PSK_EXT.2, FIA_PSK_EXT.1.2, FIA_HOTP_EXT.1.1, FIA_HOTP_EXT.1.2, FIA_HOTP_EXT.1.3, FIA_HOTP_EXT.1.4, FIA_HOTP_EXT.1.5, FIA_HOTP_EXT.1.6, FIA_HOTP_EXT.1.7, FIA_HOTP_EXT.1.8, FIA_TOTP_EXT.1.7, FIA_PSK_EXT.2.1, FIA_PSK_EXT.1.1, FIA_PSK_EXT.3.1, FIA_PSK_EXT.3.2, FIA_PSK_EXT.3.3, FIA_PSK_EXT.3.4, FIA_PSK_EXT.3.5, FIA_PSK_EXT.3.6, FIA_PSK_EXT.3.7, FIA_TOTP_EXT.1.2, FIA_TOTP_EXT.1.3, FIA_TOTP_EXT.1.4, FIA_TOTP_EXT.1.5, FIA_TOTP_EXT.1.6, FIA_TOTP_EXT.1.8, FIA_TOTP_EXT.1.9, FIA_TOTP_EXT.1.1, FMT_MTD, FMT_SMF.1, FMT_MTD.1, FMT_SMF, FPT_TST_EXT, FPT_FLS, FPT_TST_EXT.3, FPT_FLS.1, FPT_TST_EXT.3.1, FPT_TST_EXT.3.2, FPT_STM.1, FTA_VCM_EXT, FTA_VCM_EXT.1, FTA_SSL, FTA_TSE.1, FTA_SSL.3, FTA_TSE.1.1, FTA_TSE, FTA_VCM_EXT.1.1, FTP_ITC, FTP_ITC.1Certification process
out of scope, rather than in an external device, is covered under the Authentication Server PP-Module, and is out of scope for this PP-Module. The MSK derived from EAP is distinct from the PSK. The MSK is substituted inStandards
FIPS PUB 197, FIPS PUB 186-5, NIST SP 800-38C, NIST SP 800-38D, NIST SP 800-132, NIST SP 800-63b, RFC 8603, RFC 4303, RFC 4106, RFC 4868, RFC 7296, RFC 5282, RFC 5114, RFC 3526, RFC 4945, RFC 8784, RFC 7919, RFC 791, RFC 8200, RFC 793, RFC 768, RFC 792, RFC 5216, RFC 8996, RFC 5281, RFC 4226, RFC 6238, ISO/IEC 15408, ISO/IEC 18033-, ISO/IEC 19772:2020, X.509, CCMB-2022-11-001, CCMB-2022-11-002, CCMB-2022-11-003, CCMB-2022-11-005, CCMB-2022-11-006File metadata
| Title | PP-Module for VPN Gateways |
|---|---|
| Creation date | D:20260121154015+00'00' |
| Modification date | D:20260121154015+00'00' |
| Pages | 72 |
| Creator | Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) HeadlessChrome/143.0.0.0 Safari/537.36 |
| Producer | Skia/PDF m143 |
References
No references are available for this protection profile.
Updates Feed
-
The protection profile was first processed.
Raw data
{
"_id": "084a6f26cac1c6b3",
"_type": "sec_certs.sample.protection_profile.ProtectionProfile",
"dgst": "084a6f26cac1c6b3",
"heuristics": {
"_type": "sec_certs.sample.protection_profile.ProtectionProfile.Heuristics"
},
"pdf_data": {
"_type": "sec_certs.sample.protection_profile.ProtectionProfile.PdfData",
"pp_filename": "",
"pp_keywords": {
"asymmetric_crypto": {
"ECC": {
"ECDSA": {
"ECDSA": 4
}
},
"FF": {
"DH": {
"DH": 4,
"Diffie-Hellman": 1
}
}
},
"cc_cert_id": {},
"cc_claims": {
"A": {
"A.CONNECTIONS": 4,
"A.NO_THRU_TRAFFIC_PROTECTION": 1
},
"OE": {
"OE.CONNECTIONS": 3,
"OE.NO_THRU_TRAFFIC_PROTECTION": 1
},
"T": {
"T.DATA_INTEGRITY": 2,
"T.NETWORK_ACCESS": 2,
"T.NETWORK_DISCLOSURE": 2,
"T.NETWORK_MISUSE": 2,
"T.REPLAY_ATTACK": 2,
"T.UNTRUSTED_COMMUNICATION_CHANNELS": 4,
"T.WEAK_AUTHENTICATION_ENDPOINTS": 1,
"T.WEAK_CRYPTOGRAPHY": 1
}
},
"cc_protection_profile_id": {},
"cc_sar": {
"ATE": {
"ATE_IND.1": 1
}
},
"cc_security_level": {},
"cc_sfr": {
"FAU": {
"FAU_GEN": 9,
"FAU_GEN.1": 3,
"FAU_STG_EXT.1": 1
},
"FCS": {
"FCS_CKM": 5,
"FCS_CKM.1": 3,
"FCS_CKM.2": 1,
"FCS_COP": 14,
"FCS_COP.1": 6,
"FCS_EAP_EXT": 6,
"FCS_EAP_EXT.1": 10,
"FCS_EAP_EXT.1.1": 3,
"FCS_EAP_EXT.1.2": 2,
"FCS_EAP_EXT.1.3": 3,
"FCS_RBG.1": 12
},
"FIA": {
"FIA_HOTP_EXT": 9,
"FIA_HOTP_EXT.1": 11,
"FIA_HOTP_EXT.1.1": 2,
"FIA_HOTP_EXT.1.2": 2,
"FIA_HOTP_EXT.1.3": 2,
"FIA_HOTP_EXT.1.4": 6,
"FIA_HOTP_EXT.1.5": 4,
"FIA_HOTP_EXT.1.6": 5,
"FIA_HOTP_EXT.1.7": 2,
"FIA_HOTP_EXT.1.8": 2,
"FIA_PSK_EXT": 11,
"FIA_PSK_EXT.1": 17,
"FIA_PSK_EXT.1.1": 2,
"FIA_PSK_EXT.1.2": 8,
"FIA_PSK_EXT.2": 8,
"FIA_PSK_EXT.2.1": 4,
"FIA_PSK_EXT.3": 10,
"FIA_PSK_EXT.3.1": 5,
"FIA_PSK_EXT.3.2": 5,
"FIA_PSK_EXT.3.3": 3,
"FIA_PSK_EXT.3.4": 3,
"FIA_PSK_EXT.3.5": 2,
"FIA_PSK_EXT.3.6": 2,
"FIA_PSK_EXT.3.7": 3,
"FIA_TOTP_EXT": 8,
"FIA_TOTP_EXT.1": 10,
"FIA_TOTP_EXT.1.1": 1,
"FIA_TOTP_EXT.1.2": 2,
"FIA_TOTP_EXT.1.3": 2,
"FIA_TOTP_EXT.1.4": 6,
"FIA_TOTP_EXT.1.5": 4,
"FIA_TOTP_EXT.1.6": 5,
"FIA_TOTP_EXT.1.7": 3,
"FIA_TOTP_EXT.1.8": 4,
"FIA_TOTP_EXT.1.9": 2,
"FIA_XCU_EXT.1.1": 2
},
"FMT": {
"FMT_MTD": 3,
"FMT_MTD.1": 2,
"FMT_SMF": 8,
"FMT_SMF.1": 6
},
"FPT": {
"FPT_FLS": 7,
"FPT_FLS.1": 1,
"FPT_STM.1": 1,
"FPT_TST_EXT": 4,
"FPT_TST_EXT.3": 13,
"FPT_TST_EXT.3.1": 2,
"FPT_TST_EXT.3.2": 2
},
"FTA": {
"FTA_SSL": 8,
"FTA_SSL.3": 1,
"FTA_TSE": 4,
"FTA_TSE.1": 6,
"FTA_TSE.1.1": 1,
"FTA_VCM_EXT": 4,
"FTA_VCM_EXT.1": 12,
"FTA_VCM_EXT.1.1": 2
},
"FTP": {
"FTP_ITC": 5,
"FTP_ITC.1": 9
}
},
"certification_process": {
"OutOfScope": {
"out of scope": 1,
"rather than in an external device, is covered under the Authentication Server PP-Module, and is out of scope for this PP-Module. The MSK derived from EAP is distinct from the PSK. The MSK is substituted in": 1
}
},
"cipher_mode": {
"CBC": {
"CBC": 1
},
"CCM": {
"CCM": 4
},
"CTR": {
"CTR": 1
},
"GCM": {
"GCM": 6
},
"XTS": {
"XTS": 1
}
},
"cplc_data": {},
"crypto_engine": {},
"crypto_library": {},
"crypto_protocol": {
"IKE": {
"IKE": 12,
"IKEv2": 25
},
"IPsec": {
"IPsec": 36
},
"SSH": {
"SSH": 1
},
"TLS": {
"TLS": {
"TLS": 9
}
},
"VPN": {
"VPN": 128
}
},
"crypto_scheme": {
"KEX": {
"Key Exchange": 1
}
},
"device_model": {},
"ecc_curve": {},
"eval_facility": {},
"hash_function": {
"PBKDF": {
"PBKDF": 2,
"PBKDF2": 1
},
"SHA": {
"SHA1": {
"SHA-1": 4
},
"SHA2": {
"SHA-256": 4,
"SHA-384": 6,
"SHA-512": 5
}
}
},
"ic_data_group": {},
"javacard_api_const": {},
"javacard_packages": {},
"javacard_version": {},
"os_name": {},
"pq_crypto": {},
"randomness": {
"RNG": {
"RBG": 4
}
},
"side_channel_analysis": {},
"standard_id": {
"CC": {
"CCMB-2022-11-001": 1,
"CCMB-2022-11-002": 1,
"CCMB-2022-11-003": 1,
"CCMB-2022-11-005": 1,
"CCMB-2022-11-006": 1
},
"FIPS": {
"FIPS PUB 186-5": 3,
"FIPS PUB 197": 2
},
"ISO": {
"ISO/IEC 15408": 2,
"ISO/IEC 18033-": 2,
"ISO/IEC 19772:2020": 2
},
"NIST": {
"NIST SP 800-132": 1,
"NIST SP 800-38C": 1,
"NIST SP 800-38D": 1,
"NIST SP 800-63b": 1
},
"RFC": {
"RFC 3526": 2,
"RFC 4106": 1,
"RFC 4226": 2,
"RFC 4303": 1,
"RFC 4868": 2,
"RFC 4945": 1,
"RFC 5114": 1,
"RFC 5216": 2,
"RFC 5281": 2,
"RFC 5282": 2,
"RFC 6238": 2,
"RFC 7296": 2,
"RFC 768": 3,
"RFC 791": 3,
"RFC 7919": 1,
"RFC 792": 1,
"RFC 793": 3,
"RFC 8200": 3,
"RFC 8603": 1,
"RFC 8784": 6,
"RFC 8996": 4
},
"X509": {
"X.509": 8
}
},
"symmetric_crypto": {
"AES_competition": {
"AES": {
"AES": 8,
"AES-": 2
}
},
"constructions": {
"MAC": {
"HMAC": 8,
"HMAC-SHA-384": 1
}
}
},
"technical_report_id": {},
"tee_name": {},
"tls_cipher_suite": {},
"vendor": {},
"vulnerability": {}
},
"pp_metadata": {
"/CreationDate": "D:20260121154015+00\u002700\u0027",
"/Creator": "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) HeadlessChrome/143.0.0.0 Safari/537.36",
"/ModDate": "D:20260121154015+00\u002700\u0027",
"/Producer": "Skia/PDF m143",
"/Title": "PP-Module for VPN Gateways",
"pdf_file_size_bytes": 4227160,
"pdf_hyperlinks": {
"_type": "Set",
"elements": [
"http://www.commoncriteriaportal.org/files/ccfiles/CC2022PART3R1.pdf",
"http://www.commoncriteriaportal.org/files/ccfiles/CC2022PART2R1.pdf",
"http://www.commoncriteriaportal.org/files/ccfiles/CC2022PART5R1.pdf",
"http://www.commoncriteriaportal.org/files/ccfiles/CC2022PART4R1.pdf",
"http://www.commoncriteriaportal.org/files/ccfiles/CEM2022R1.pdf",
"https://www.niap-ccevs.org/protectionprofiles/524",
"https://www.commoncriteriaportal.org/files/ccfiles/CC2022PART1R1.pdf",
"https://www.niap-ccevs.org/protectionprofiles/511"
]
},
"pdf_is_encrypted": false,
"pdf_number_of_pages": 72
},
"report_filename": null,
"report_keywords": null,
"report_metadata": null
},
"scheme_metadata": {
"cc_version": "CC:2022",
"pp_short_name": "MOD_VPNGW_v2.0",
"pp_sponsor_id": "NIAP",
"pp_transition": null,
"predecessor": "MOD_VPNGW_v1.3",
"source_scheme": "US",
"successor": null
},
"state": {
"_type": "sec_certs.sample.protection_profile.ProtectionProfile.InternalState",
"pp": {
"_type": "sec_certs.sample.document_state.DocumentState",
"convert_ok": true,
"download_ok": true,
"extract_ok": true,
"json_hash": null,
"source_hash": "98a309e09d0ac473c8e23c872991faa0004f3ef0e34d6bade195346d3fb60d8e",
"txt_hash": "019d8f6fd020925fdb0f8e580811d059c52872c1c9b3cf52857a8d4612d15c3f"
},
"report": {
"_type": "sec_certs.sample.document_state.DocumentState",
"convert_ok": false,
"download_ok": false,
"extract_ok": false,
"json_hash": null,
"source_hash": null,
"txt_hash": null
}
},
"web_data": {
"_type": "sec_certs.sample.protection_profile.ProtectionProfile.WebData",
"category": "Network and Network-Related Devices and Systems",
"is_collaborative": false,
"maintenances": [],
"name": "PP-Module for Virtual Private Network (VPN) Gateways Version 2.0",
"not_valid_after": null,
"not_valid_before": "2026-01-21",
"pp_link": "https://www.niap-ccevs.org/api/file/get_public_file/?file_id=37068",
"report_link": null,
"scheme": "US",
"security_level": {
"_type": "Set",
"elements": []
},
"status": "active",
"version": "2.0"
}
}