{"_id": "366854bdda768efb", "_type": "sec_certs.sample.protection_profile.ProtectionProfile", "dgst": "366854bdda768efb", "web_data": {"_type": "sec_certs.sample.protection_profile.ProtectionProfile.WebData", "category": "ICs, Smart Cards and Smart Card-Related Devices and Systems", "status": "active", "is_collaborative": false, "name": "ETSI TS 103 732-1 Consumer Mobile Device Protection Profile", "version": "Version 2.1.2", "security_level": {"_type": "Set", "elements": ["EAL2+", "ALC_FLR.3"]}, "not_valid_before": "2023-12-28", "not_valid_after": null, "report_link": "https://www.commoncriteriaportal.org/nfs/ccpfiles/files/ppfiles/ANSSI-CC-PP-2023-02-rapport.pdf", "pp_link": "https://www.commoncriteriaportal.org/nfs/ccpfiles/files/ppfiles/ANSSI-CC-PP-2023-02-profil.pdf", "scheme": "FR", "maintenances": []}, "pdf_data": {"_type": "sec_certs.sample.protection_profile.ProtectionProfile.PdfData", "report_metadata": {"pdf_file_size_bytes": 406140, "pdf_is_encrypted": false, "pdf_number_of_pages": 11, "/CreationDate": "D:20240105142436+01'00'", "/Creator": "Acrobat PDFMaker 23 pour Word", "/Keywords": "", "/ModDate": "D:20240105150219+01'00'", "/Producer": "Adobe PDF Library 23.1.175", "pdf_hyperlinks": {"_type": "Set", "elements": ["mailto:certification@ssi.gouv.fr", "http://www.sogis.eu/", "http://www.ssi.gouv.fr/", "http://www.commoncriteriaportal.org/"]}}, "pp_metadata": {"pdf_file_size_bytes": 381636, "pdf_is_encrypted": false, "pdf_number_of_pages": 58, "/Author": "CYBER", "/CreationDate": "D:20231114163542+01'00'", "/Creator": "ETSI Secretariat", "/Keywords": "cybersecurity, mobile, privacy, terminal", "/ModDate": "D:20231116095352+01'00'", "/Producer": "Acrobat Distiller 10.0.0 (Windows)", "/Subject": "TS 103 732-1 - V2.1.2", "/Title": "TS 103 732-1 - V2.1.2 - CYBER; Consumer Mobile Device; Part 1: Base Protection Profile", "pdf_hyperlinks": {"_type": "Set", "elements": ["https://www.rfc-editor.org/info/rfc5289", "https://www.bluetooth.com/specifications/specs/core-specification-5-1/", "https://www.commoncriteriaportal.org/files/ccfiles/CCPART3V3.1R5.pdf", "https://portal.etsi.org/People/CommiteeSupportStaff.aspx", "https://www.rfc-editor.org/info/rfc5246", "https://www.iso.org/standard/76156.html", "https://www.rfc-editor.org/info/rfc5288", "https://www.commoncriteriaportal.org/files/ccfiles/CCPART1V3.1R5.pdf", "https://www.rfc-editor.org/info/rfc5280", "https://portal.etsi.org/TB/ETSIDeliverableStatus.aspx", "https://docbox.etsi.org/Reference/", "https://www.bluetooth.com/specifications/specs/core-specification-4-1/", "https://www.bluetooth.com/specifications/specs/core-specification-5-0/", "https://standards.ieee.org/ieee/802.11/5536/", "https://www.rfc-editor.org/info/rfc8446", "https://www.commoncriteriaportal.org/files/ccfiles/CEMV3.1R5.pdf", "https://www.commoncriteriaportal.org/files/ccfiles/CCPART2V3.1R5.pdf", "https://www.etsi.org/standards/coordinated-vulnerability-disclosure", "https://portal.etsi.org/Services/editHelp!/Howtostart/ETSIDraftingRules.aspx", "https://www.etsi.org/standards-search", "http://www.etsi.org/deliver", "https://ipr.etsi.org/", "https://www.bluetooth.com/specifications/specs/core-specification-4-2/", "https://www.rfc-editor.org/info/rfc2818", "https://www.bluetooth.com/specifications/specs/core-specification-5-2/", "https://www.commoncriteriaportal.org/files/ccfiles/CCDB-2017-05-17-CCaddenda-Exact_Conformance.pdf"]}}, "report_keywords": {"cc_cert_id": {"FR": {"ANSSI-CC-PP-2023/02": 2}}, "cc_protection_profile_id": {"ANSSI": {"ANSSI-CC-PP-2023/02": 2}}, "cc_security_level": {"EAL": {"EAL2": 3}}, "cc_sar": {"ACE": {"ACE_CCL.1": 1, "ACE_ECD.1": 1, "ACE_INT.1": 1, "ACE_OBJ.1": 1, "ACE_REQ.1": 1, "ACE_SPD.1": 1, "ACE_MCO.1": 1, "ACE_CCO.1": 1}, "ALC": {"ALC_DVS_EXT.1": 3, "ALC_FLR.3": 3}, "APE": {"APE_CCL.1": 1, "APE_ECD.1": 1, "APE_INT.1": 1, "APE_OBJ.2": 1, "APE_REQ.2": 1, "APE_SPD.1": 1}}, "cc_sfr": {"FCS": {"FCS_RNG_EXT.1": 1, "FCS_CKH_EXT.1": 1, "FCS_UPF_EXT.1": 1, "FCS_CKM.1": 1, "FCS_CKM.4": 1, "FCS_COP.1": 1}, "FDP": {"FDP_ACC.1": 1, "FDP_ACC.2": 1, "FDP_ACF.1": 1}, "FIA": {"FIA_UAU.1": 1, "FIA_UID.1": 1, "FIA_UAU.5": 2, "FIA_UAU.7": 1, "FIA_SOS.1": 1, "FIA_AFL.1": 1}, "FMT": {"FMT_MSA.1": 1, "FMT_MSA.3": 1, "FMT_SMF.1": 1}, "FPR": {"FPR_PSE.1": 1}, "FPT": {"FPT_ITC_EXT": 1, "FPT_FLS.1": 1, "FPT_TST.1": 1, "FPT_RCV.2": 1}, "FTP": {"FTP_ITC.1": 1}}, "cc_claims": {}, "vendor": {}, "eval_facility": {"CESTI": {"CESTI": 1}}, "symmetric_crypto": {"DES": {"DES": {"DES": 1}}}, "asymmetric_crypto": {}, "pq_crypto": {}, "hash_function": {}, "crypto_scheme": {}, "crypto_protocol": {}, "randomness": {}, "cipher_mode": {}, "ecc_curve": {}, "crypto_engine": {}, "tls_cipher_suite": {}, "crypto_library": {}, "vulnerability": {}, "side_channel_analysis": {}, "technical_report_id": {}, "device_model": {}, "tee_name": {}, "os_name": {}, "cplc_data": {}, "ic_data_group": {}, "standard_id": {"CC": {"CCMB-2017-04-001": 1, "CCMB-2017-04-002": 1, "CCMB-2017-04-003": 1, "CCMB-2017-04-004": 1}}, "javacard_version": {}, "javacard_api_const": {}, "javacard_packages": {}, "certification_process": {}}, "pp_keywords": {"cc_cert_id": {}, "cc_protection_profile_id": {"BSI": {"BSI-CC-PP-0084-2014": 1}}, "cc_security_level": {"EAL": {"EAL2": 16, "EAL 2": 1, "EAL2 augmented": 2}}, "cc_sar": {"ADV": {"ADV_ARC": 1, "ADV_ARC.1": 2, "ADV_FSP.2": 2, "ADV_TDS.1": 1}, "AGD": {"AGD_OPE.1": 3, "AGD_PRE.1": 3}, "ALC": {"ALC_DVS_EXT": 7, "ALC_DVS_EXT.1": 24, "ALC_FLR.3": 27, "ALC_DVS": 1, "ALC_LCD.1": 1, "ALC_CMC.1": 1, "ALC_FLR.2": 1}, "AVA": {"AVA_VAN": 1, "AVA_VAN.2": 10, "AVA_VAN.1": 1, "AVA_VAN.3": 1, "AVA_VAN.4": 1, "AVA_VAN.5": 1}}, "cc_sfr": {"FCS": {"FCS_RNG_EXT": 3, "FCS_CKH_EXT": 11, "FCS_CKH_EXT.1": 13, "FCS_CKM.4": 28, "FCS_RNG_EXT.1": 9, "FCS_RNG_EXT.1.1": 2, "FCS_RNG_EXT.1.2": 2, "FCS_CKM.1": 13, "FCS_COP.1": 11, "FCS_CKH_EXT.1.1": 1, "FCS_CKH_EXT.1.2": 2, "FCS_CKM": 26, "FCS_COP": 34, "FCS_CKH_EXT.1.3": 2, "FCS_CKM.4.1": 1, "FCS_CKM.2": 4}, "FDP": {"FDP_UPF_EXT": 19, "FDP_UPF_EXT.1": 7, "FDP_UPF_EXT.1.1": 1, "FDP_ACC": 23, "FDP_ACC.1": 8, "FDP_ACF": 34, "FDP_ACF.1": 20, "FDP_ACC.2": 5, "FDP_ITC.1": 8, "FDP_ITC.2": 8, "FDP_IFC.1": 1}, "FIA": {"FIA_UAU.1": 6, "FIA_UAU.1.1": 2, "FIA_UAU.1.2": 1, "FIA_UID.1": 4, "FIA_UID.1.1": 1, "FIA_UID.1.2": 1, "FIA_UAU": 8, "FIA_UAU.5": 4, "FIA_UAU.6": 3, "FIA_UAU.6.1": 1, "FIA_UAU.7": 3, "FIA_UAU.7.1": 1, "FIA_SOS.1": 4, "FIA_SOS.1.1": 1, "FIA_AFL.1": 3, "FIA_AFL.1.1": 1, "FIA_AFL.1.2": 1, "FIA_AFL": 1}, "FMT": {"FMT_SMF": 29, "FMT_MSA": 8, "FMT_MSA.1": 2, "FMT_MSA.3": 6, "FMT_SMF.1": 6, "FMT_SMR.1": 1}, "FPR": {"FPR_PSE": 2, "FPR_PSE.1": 9}, "FPT": {"FPT_PHP.3": 11, "FPT_FLS.1": 5, "FPT_TST.1": 11, "FPT_PHP.3.1": 1, "FPT_FLS.1.1": 1, "FPT_RCV.2": 4, "FPT_TST.1.1": 3, "FPT_TST.1.2": 1, "FPT_TST.1.3": 1, "FPT_RCV.2.1": 2, "FPT_RCV.2.2": 2}, "FTP": {"FTP_ITC_EXT.1": 21, "FTP_ITC": 1, "FTP_ITC_EXT.1.1": 1, "FTP_ITC_EXT.1.2": 1, "FTP_ITC_EXT.1.3": 1, "FTP_ITC_EXT.1.4": 1, "FTP_ITC_EXT": 43}}, "cc_claims": {"O": {"O.PROTECT_COMMS": 4, "O.AUTHENTICATED_UPDATES": 5, "O.PROTECT_ASSETS_AT_REST": 3, "O.DATA_CLASSIFICATION": 2, "O.SECURE_WIPE": 3, "O.CRITICAL_STORAGE": 4, "O.ACCESS_CONTROL": 5, "O.SECURE_BOOT": 6, "O.AUTHENTICATE_USER": 4, "O.CRYPTOGRAPHY": 7, "O.RANDOMS": 6, "O.AUTHENTICATE_PEER_DEVICE": 3, "O.SELF_PROTECTION": 3, "O.SEPARATION": 3}, "T": {"T.EAVESDROP": 3, "T.SPOOF": 3, "T.MODIFY_COMMS": 3, "T.COUNTERFEIT_DEVICE": 3, "T.IMPERSONATE": 3, "T.PHYSICAL": 3, "T.RECOVER_DATA": 3, "T.MODIFY_DEVICE": 3, "T.FLAWAPP_ACCESS": 3, "T.NEW_ATTACKS": 3, "T.FLAWAPP_HACKS_TOE": 3, "T.FLAWAPP_HACKS_OTHER_APPS": 3, "T.PERSISTENT": 1}, "A": {"A.APP_DISTRIBUTION_PLATFORM": 2, "A.TRUSTWORTHY_UPDATE_SOURCE": 2, "A.TRUSTWORTHY_REMOTE_SERVICE": 2, "A.PASSWORD_PIN_PATTERN": 2}, "OE": {"OE.APP_DISTRIBUTION_PLATFORM": 2, "OE.TRUSTWORTHY_UPDATE_SOURCE": 2, "OE.TRUSTWORTHY_REMOTE_SERVICE": 2, "OE.PASSWORD_PIN_PATTERN": 3, "OE.PASSWORD_PIN": 1}}, "vendor": {}, "eval_facility": {}, "symmetric_crypto": {"AES_competition": {"AES": {"AES": 4}}, "miscellaneous": {"Camellia": {"Camellia": 1}}, "constructions": {"MAC": {"HMAC": 1}}}, "asymmetric_crypto": {"ECC": {"ECDH": {"ECDH": 2}, "ECDSA": {"ECDSA": 2}}, "FF": {"DH": {"Diffie-Hellman": 1}}}, "pq_crypto": {}, "hash_function": {"SHA": {"SHA2": {"SHA2": 2}, "SHA3": {"SHA3": 2}}, "PBKDF": {"PBKDF": 2}}, "crypto_scheme": {"MAC": {"MAC": 3}}, "crypto_protocol": {"TLS": {"TLS": {"TLS": 15}}}, "randomness": {"RNG": {"RNG": 4}}, "cipher_mode": {"GCM": {"GCM": 2}}, "ecc_curve": {}, "crypto_engine": {}, "tls_cipher_suite": {"TLS": {"TLS_RSA_WITH_AES_256_GCM_SHA384": 2, "TLS_DHE_RSA_WITH_AES_256_GCM_SHA384": 2, "TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256": 2, "TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384": 2, "TLS_ECDHE_ECDSA_WITH_AES_128_GCM_SHA256": 2, "TLS_ECDHE_ECDSA_WITH_AES_256_GCM_SHA384": 2, "TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA256": 1, "TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA384": 1, "TLS_ECDHE_ECDSA_WITH_AES_128_CBC_SHA256": 1, "TLS_ECDHE_ECDSA_WITH_AES_256_CBC_SHA384": 1}}, "crypto_library": {}, "vulnerability": {}, "side_channel_analysis": {"SCA": {"side-channel": 3}}, "technical_report_id": {}, "device_model": {}, "tee_name": {}, "os_name": {}, "cplc_data": {}, "ic_data_group": {}, "standard_id": {"RFC": {"RFC 2818": 1, "RFC 5280": 1, "RFC 5288": 4, "RFC 5289": 12}, "ISO": {"ISO/IEC 18033-1": 11}, "X509": {"X.509": 1}, "CC": {"CCMB-2017-04-001": 1, "CCMB-2017-04-002": 1, "CCMB-2017-04-003": 1, "CCMB-2017-04-004": 1}}, "javacard_version": {}, "javacard_api_const": {}, "javacard_packages": {}, "certification_process": {"OutOfScope": {"out of scope": 10, "Out of scope": 2, "ADP) (this is out of scope of the TOE": 1, "with the exception of 3GPP-defined radio interfaces which are out of scope for this PP": 1, "which are out of scope, see clause 4.2": 1, "these are out of scope) or request the TSF to provide an unique alias for its use": 1, "outside cellular mobile communications which are out of scope": 1, "for example a memory card. Any data on these devices or services associated with these devices is out of scope of the TOE. ETSI ETSI TS 103 732-1 V2.1.2 (2023-11) 13 The security functionality and radio": 1, "certified by a CC Certification Body. Therefore, these cellular mobile communication functions are out of scope for the present document. It is assumed that the TOE meets applicable security requirements defined": 1, "the choice of the user. Generally this is done through an App Distribution Platform (ADP) (this is out of scope of the TOE), though the exact mechanism for the installation of an app is up to the user. TOE": 1, "cellular). As specified in the TOE boundary, the connectivity provided by the Mobile Network is out of scope for this evaluation, though the connection offered by the network may be used by the TOE to access": 1, "of loopholes, vulnerabilities or backdoors. How the ADP performs security checks of applications is out of scope of this evaluation. The ADP application included on the TOE is in scope. To be considered a": 1, "of state of art, but it is not assumed App Distribution Platform is free of malicious apps. - (Out of scope) A user may install additional ADP applications, in which case the user takes the responsibility": 1, "for secure remote connections but it is up to the app developer to utilize those capabilities. \u2022 (Out of scope) one or more Mobile Network Operators when the TOE supports cellular radio connection. This will be": 1, "when transit to and from the TSF (with the exception of 3GPP-defined radio interfaces which are out of scope for this PP). Interfaces of the TOE: \u2022 The radio interface(s): these are wireless interfaces to": 1, "networks such as those defined by 3GPP (which are out of scope, see clause 4.2), Wi-Fi\u00ae or Bluetooth\u00ae . \u2022 The network interface(s): these are interfaces to": 1, "Note 15: Use of an EAF assumes that the EAF is trusted by the user and so its security is out of scope of the evaluation. The use of the EAF shall be described and the connection to the TOE shall be": 1, "may be able to generate their own aliases on top of ones provided by the TOE itself (these are out of scope) or request the TSF to provide an unique alias for its use. The TOE may provide unique aliases for": 1, "to be the most fundamental to a mobile device (outside cellular mobile communications which are out of scope). These cover Bluetooth and WLAN wireless communications as well as software functions to ensure": 1}}}, "report_filename": "ANSSI-CC-PP-2023-02-rapport.pdf", "pp_filename": "ANSSI-CC-PP-2023-02-profil.pdf"}, "heuristics": {"_type": "sec_certs.sample.protection_profile.ProtectionProfile.Heuristics"}, "state": {"_type": "sec_certs.sample.protection_profile.ProtectionProfile.InternalState", "pp": {"_type": "sec_certs.sample.document_state.DocumentState", "download_ok": true, "convert_ok": true, "extract_ok": true, "source_hash": "226b2aff697e457006f4253201cc8a7c4b095dfec52ca03ffd8b46d417875a73", "txt_hash": "1587ac6e7fc4f60a9dc5b4bc8b8d81ae91d06d2e9a3c490cd30898d9577ba646", "json_hash": null}, "report": {"_type": "sec_certs.sample.document_state.DocumentState", "download_ok": true, "convert_ok": true, "extract_ok": true, "source_hash": "98ddfdb13705ca33203f23d3fc8a017318e175344350caee46f837bbcf41abce", "txt_hash": "c9fa4915acfa05e6e46318c3bc55307019d8a3a41211ab194acb94567053aca5", "json_hash": null}}}