Protection Profile for General Purpose Operating Systems Version 4.2

Profile details

Status archived
Valid from 22.05.2018
Valid until 30.04.2019
Scheme πŸ‡ΊπŸ‡Έ US
Category Operating Systems
Security level N/A

Certification report

certification report could not be downloaded, no link is available.

Protection profile

Extracted keywords

Symmetric Algorithms
AES, AES-, AES-128, AES-256, DES, HMAC, HMAC-SHA-256
Asymmetric Algorithms
ECDHE, ECDSA, ECC, DHE, Diffie-Hellman
Hash functions
SHA-1, SHA-256, SHA-384, SHA-512, SHA-224, SHA256, SHA384, SHA512, SHA-2
Schemes
MAC, Key Exchange
Protocols
SSH, TLS, TLS 1.2, DTLS, DTLS 1.0, DTLS 1.2, IKE, IPsec, VPN
Randomness
DRBG, RNG, RBG
Elliptic Curves
P-256, P-384, P-521, secp256r1, secp384r1, secp521r1
Block cipher modes
CCM
TLS cipher suites
TLS_RSA_WITH_AES_128_CBC_SHA, TLS_RSA_WITH_AES_128_CBC_SHA256, TLS_RSA_WITH_AES_256_CBC_SHA256, TLS_RSA_WITH_AES_256_CBC_SHA384, TLS_DHE_RSA_WITH_AES_128_CBC_SHA256, TLS_DHE_RSA_WITH_AES_256_CBC_SHA256, TLS_DHE_RSA_WITH_AES_256_GCM_SHA384, TLS_ECDHE_ECDSA_WITH_AES_128_CBC_SHA256, TLS_ECDHE_ECDSA_WITH_AES_128_GCM_SHA256, TLS_ECDHE_ECDSA_WITH_AES_256_CBC_SHA384, TLS_ECDHE_ECDSA_WITH_AES_256_GCM_SHA384, TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA256, TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256, TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA384, TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384, TLS_NULL_WITH_NULL_NULL

Claims
O.ACCOUNTABILITY, O.INTEGRITY, O.MANAGEMENT, O.PROTECTED_STORAGE, O.PROTECTED_COMMS, T.NETWORK_ATTACK, T.NETWORK_EAVESDROP, T.LOCAL_ATTACK, T.LIMITED_PHYSICAL_ACCESS, A.PLATFORM, A.PROPER_USER, A.PROPER_ADMIN, OE.PLATFORM, OE.PROPER_USER, OE.PROPER_ADMIN
Security Assurance Requirements (SAR)
ADV_FSP.1, AGD_OPE, AGD_PRE, AGD_OPE.1, AGD_PRE.1, ALC_CMC.1, ALC_CMS.1, ALC_TSU_EXT.1, ATE_IND, ATE_IND.1, AVA_VAN, AVA_VAN.1, ASE_CCL, ASE_CCL.1, ASE_ECD.1, ASE_INT.1, ASE_OBJ.1, ASE_REQ.1, ASE_SPD.1, ASE_TSS.1
Security Functional Requirements (SFR)
FAU_GEN.1, FAU_GEN.1.1, FAU_GEN.1.2, FAU_STG.1, FAU_GEN.2, FAU_SAR.1, FCS_COP.1.1, FCS_STO_EXT.1, FCS_RBG_EXT.1, FCS_TLSC_EXT.1, FCS_TLSC_EXT.2, FCS_TLSC_EXT.3, FCS_TLSC_EXT.4, FCS_DTLS_EXT.1, FCS_CKM.1, FCS_CKM.2, FCS_CKM_EXT.4, FCS_CKM.1.1, FCS_CKM_EXT.4.2, FCS_COP.1, FCS_RBG_EXT.1.1, FCS_TLSC_EXT.1.1, FCS_DTLS_EXT.1.2, FDP_ACF_EXT.1, FDP_IFC_EXT.1, FDP_IFC_EXT.1.1, FIA_AFL.1, FIA_UAU.5, FIA_AFL.1.2, FIA_UAU.5.2, FIA_UAU.5.1, FIA_UAU.1, FIA_UID.1, FMT_MOF_EXT.1, FMT_SMF_EXT.1.1, FMT_SMF_EXT.1, FMT_SMR.1, FPT_SBOP_EXT.1, FPT_ASLR_EXT.1, FPT_TUD_EXT.1, FPT_TUD_EXT.2, FPT_ACF_EXT.1, FPT_SRP_EXT.1, FPT_TST_EXT.1, FPT_ASLR_EXT.1.1, FPT_TST_EXT.1.1, FPT_TUD_EXT.1.2, FPT_TUD_EXT.2.2, FPT_SRP_EXT.1.1, FPT_STM.1, FPT_ACF_EXT.1.2, FTA_TAB.1, FTA_SSL.1, FTA_SSL.2, FTP_ITC_EXT.1, FTP_TRP.1, FTP_ITC_EXT.1.1, FTP_TRP.1.3, FTP_TRP.1.1, FTP_TRP.1.2

Side-channel analysis
malfunction
Certification process
out of scope, may even be effectively extended by privileged applications installed onto it. However, these are out of scope of this PP. [USE CASE 1] End User Devices The OS provides a platform for end user devices such as, The OS relies upon a trustworthy computing platform for its execution. This underlying platform is out of scope of this PP. A.PROPER_USER The user of the OS is not willfully negligent or hostile, and uses the, code, and so on. However, the way in which the hardware stores and protects these keys is out of scope. If all executable code (including bootloader(s), kernel, device drivers, pre-loaded applications, kernel. Software loaded for execution directly by the platform (e.g. first-stage bootloaders) is out of scope. For each additional category of executable code verified before execution, the evaluator will

References

No references are available for this protection profile.

Processing updates

Feed
  • The protection profile was first processed.

Raw data

{
  "_id": "bd8869804c90995f",
  "_type": "sec_certs.sample.protection_profile.ProtectionProfile",
  "dgst": "bd8869804c90995f",
  "heuristics": {
    "_type": "sec_certs.sample.protection_profile.ProtectionProfile.Heuristics"
  },
  "pdf_data": {
    "_type": "sec_certs.sample.protection_profile.ProtectionProfile.PdfData",
    "pp_filename": "",
    "pp_keywords": {
      "asymmetric_crypto": {
        "ECC": {
          "ECC": {
            "ECC": 6
          },
          "ECDH": {
            "ECDHE": 5
          },
          "ECDSA": {
            "ECDSA": 7
          }
        },
        "FF": {
          "DH": {
            "DHE": 3,
            "Diffie-Hellman": 1
          }
        }
      },
      "cc_cert_id": {},
      "cc_claims": {
        "A": {
          "A.PLATFORM": 3,
          "A.PROPER_ADMIN": 3,
          "A.PROPER_USER": 3
        },
        "O": {
          "O.ACCOUNTABILITY": 1,
          "O.INTEGRITY": 5,
          "O.MANAGEMENT": 5,
          "O.PROTECTED_COMMS": 5,
          "O.PROTECTED_STORAGE": 3
        },
        "OE": {
          "OE.PLATFORM": 3,
          "OE.PROPER_ADMIN": 3,
          "OE.PROPER_USER": 3
        },
        "T": {
          "T.LIMITED_PHYSICAL_ACCESS": 2,
          "T.LOCAL_ATTACK": 2,
          "T.NETWORK_ATTACK": 5,
          "T.NETWORK_EAVESDROP": 4
        }
      },
      "cc_protection_profile_id": {},
      "cc_sar": {
        "ADV": {
          "ADV_FSP.1": 9
        },
        "AGD": {
          "AGD_OPE": 1,
          "AGD_OPE.1": 10,
          "AGD_PRE": 1,
          "AGD_PRE.1": 6
        },
        "ALC": {
          "ALC_CMC.1": 8,
          "ALC_CMS.1": 5,
          "ALC_TSU_EXT.1": 5
        },
        "ASE": {
          "ASE_CCL": 1,
          "ASE_CCL.1": 1,
          "ASE_ECD.1": 1,
          "ASE_INT.1": 1,
          "ASE_OBJ.1": 1,
          "ASE_REQ.1": 1,
          "ASE_SPD.1": 1,
          "ASE_TSS.1": 1
        },
        "ATE": {
          "ATE_IND": 3,
          "ATE_IND.1": 5
        },
        "AVA": {
          "AVA_VAN": 1,
          "AVA_VAN.1": 6
        }
      },
      "cc_security_level": {},
      "cc_sfr": {
        "FAU": {
          "FAU_GEN.1": 3,
          "FAU_GEN.1.1": 1,
          "FAU_GEN.1.2": 2,
          "FAU_GEN.2": 1,
          "FAU_SAR.1": 1,
          "FAU_STG.1": 1
        },
        "FCS": {
          "FCS_CKM.1": 4,
          "FCS_CKM.1.1": 3,
          "FCS_CKM.2": 4,
          "FCS_CKM_EXT.4": 2,
          "FCS_CKM_EXT.4.2": 1,
          "FCS_COP.1": 8,
          "FCS_COP.1.1": 5,
          "FCS_DTLS_EXT.1": 5,
          "FCS_DTLS_EXT.1.2": 1,
          "FCS_RBG_EXT.1": 3,
          "FCS_RBG_EXT.1.1": 1,
          "FCS_STO_EXT.1": 2,
          "FCS_TLSC_EXT.1": 12,
          "FCS_TLSC_EXT.1.1": 2,
          "FCS_TLSC_EXT.2": 3,
          "FCS_TLSC_EXT.3": 2,
          "FCS_TLSC_EXT.4": 2
        },
        "FDP": {
          "FDP_ACF_EXT.1": 2,
          "FDP_IFC_EXT.1": 3,
          "FDP_IFC_EXT.1.1": 1
        },
        "FIA": {
          "FIA_AFL.1": 5,
          "FIA_AFL.1.2": 1,
          "FIA_UAU.1": 1,
          "FIA_UAU.5": 2,
          "FIA_UAU.5.1": 1,
          "FIA_UAU.5.2": 1,
          "FIA_UID.1": 1
        },
        "FMT": {
          "FMT_MOF_EXT.1": 6,
          "FMT_SMF_EXT.1": 1,
          "FMT_SMF_EXT.1.1": 2,
          "FMT_SMR.1": 1
        },
        "FPT": {
          "FPT_ACF_EXT.1": 3,
          "FPT_ACF_EXT.1.2": 1,
          "FPT_ASLR_EXT.1": 2,
          "FPT_ASLR_EXT.1.1": 1,
          "FPT_SBOP_EXT.1": 2,
          "FPT_SRP_EXT.1": 2,
          "FPT_SRP_EXT.1.1": 1,
          "FPT_STM.1": 1,
          "FPT_TST_EXT.1": 2,
          "FPT_TST_EXT.1.1": 1,
          "FPT_TUD_EXT.1": 2,
          "FPT_TUD_EXT.1.2": 2,
          "FPT_TUD_EXT.2": 2,
          "FPT_TUD_EXT.2.2": 2
        },
        "FTA": {
          "FTA_SSL.1": 1,
          "FTA_SSL.2": 1,
          "FTA_TAB.1": 1
        },
        "FTP": {
          "FTP_ITC_EXT.1": 11,
          "FTP_ITC_EXT.1.1": 3,
          "FTP_TRP.1": 2,
          "FTP_TRP.1.1": 1,
          "FTP_TRP.1.2": 1,
          "FTP_TRP.1.3": 3
        }
      },
      "certification_process": {
        "OutOfScope": {
          "The OS relies upon a trustworthy computing platform for its execution. This underlying platform is out of scope of this PP. A.PROPER_USER The user of the OS is not willfully negligent or hostile, and uses the": 1,
          "code, and so on. However, the way in which the hardware stores and protects these keys is out of scope. If all executable code (including bootloader(s), kernel, device drivers, pre-loaded applications": 1,
          "kernel. Software loaded for execution directly by the platform (e.g. first-stage bootloaders) is out of scope. For each additional category of executable code verified before execution, the evaluator will": 1,
          "may even be effectively extended by privileged applications installed onto it. However, these are out of scope of this PP. [USE CASE 1] End User Devices The OS provides a platform for end user devices such as": 1,
          "out of scope": 4
        }
      },
      "cipher_mode": {
        "CCM": {
          "CCM": 1
        }
      },
      "cplc_data": {},
      "crypto_engine": {},
      "crypto_library": {},
      "crypto_protocol": {
        "IKE": {
          "IKE": 1
        },
        "IPsec": {
          "IPsec": 17
        },
        "SSH": {
          "SSH": 7
        },
        "TLS": {
          "DTLS": {
            "DTLS": 11,
            "DTLS 1.0": 1,
            "DTLS 1.2": 3
          },
          "TLS": {
            "TLS": 35,
            "TLS 1.2": 3
          }
        },
        "VPN": {
          "VPN": 23
        }
      },
      "crypto_scheme": {
        "KEX": {
          "Key Exchange": 3
        },
        "MAC": {
          "MAC": 18
        }
      },
      "device_model": {},
      "ecc_curve": {
        "NIST": {
          "P-256": 12,
          "P-384": 12,
          "P-521": 10,
          "secp256r1": 1,
          "secp384r1": 1,
          "secp521r1": 1
        }
      },
      "eval_facility": {},
      "hash_function": {
        "SHA": {
          "SHA1": {
            "SHA-1": 10
          },
          "SHA2": {
            "SHA-2": 1,
            "SHA-224": 1,
            "SHA-256": 4,
            "SHA-384": 3,
            "SHA-512": 3,
            "SHA256": 1,
            "SHA384": 1,
            "SHA512": 1
          }
        }
      },
      "ic_data_group": {},
      "javacard_api_const": {},
      "javacard_packages": {},
      "javacard_version": {},
      "os_name": {},
      "pq_crypto": {},
      "randomness": {
        "PRNG": {
          "DRBG": 8
        },
        "RNG": {
          "RBG": 10,
          "RNG": 6
        }
      },
      "side_channel_analysis": {
        "FI": {
          "malfunction": 1
        }
      },
      "standard_id": {
        "CC": {
          "CCMB-2017-04-001": 1,
          "CCMB-2017-04-002": 1,
          "CCMB-2017-04-003": 1,
          "CCMB-2017-04-004": 1
        },
        "FIPS": {
          "FIPS 186-4": 4,
          "FIPS PUB 186-4": 6,
          "FIPS PUB 197": 1
        },
        "NIST": {
          "NIST SP 800-131A": 1,
          "NIST SP 800-38A": 1,
          "NIST SP 800-38C": 2,
          "NIST SP 800-38D": 1,
          "NIST SP 800-38E": 1,
          "NIST SP 800-38F": 2,
          "NIST SP 800-56B": 1,
          "NIST SP 800-57": 1,
          "NIST SP 800-57A": 1,
          "NIST SP 800-90A": 2,
          "NIST SP 800-90B": 1,
          "SP 800-131A": 1,
          "SP 800-56A": 1,
          "SP 800-56B": 1
        },
        "RFC": {
          "RFC 2560": 1,
          "RFC 4347": 1,
          "RFC 5246": 7,
          "RFC 5280": 3,
          "RFC 5288": 2,
          "RFC 5289": 8,
          "RFC 5759": 1,
          "RFC 6066": 1,
          "RFC 6125": 2,
          "RFC 6347": 3,
          "RFC 6460": 1
        },
        "X509": {
          "X.509": 6
        }
      },
      "symmetric_crypto": {
        "AES_competition": {
          "AES": {
            "AES": 13,
            "AES-": 4,
            "AES-128": 1,
            "AES-256": 1
          }
        },
        "DES": {
          "DES": {
            "DES": 1
          }
        },
        "constructions": {
          "MAC": {
            "HMAC": 5,
            "HMAC-SHA-256": 1
          }
        }
      },
      "technical_report_id": {},
      "tee_name": {},
      "tls_cipher_suite": {
        "TLS": {
          "TLS_DHE_RSA_WITH_AES_128_CBC_SHA256": 1,
          "TLS_DHE_RSA_WITH_AES_256_CBC_SHA256": 1,
          "TLS_DHE_RSA_WITH_AES_256_GCM_SHA384": 1,
          "TLS_ECDHE_ECDSA_WITH_AES_128_CBC_SHA256": 1,
          "TLS_ECDHE_ECDSA_WITH_AES_128_GCM_SHA256": 1,
          "TLS_ECDHE_ECDSA_WITH_AES_256_CBC_SHA384": 1,
          "TLS_ECDHE_ECDSA_WITH_AES_256_GCM_SHA384": 1,
          "TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA256": 1,
          "TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256": 1,
          "TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA384": 1,
          "TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384": 1,
          "TLS_NULL_WITH_NULL_NULL": 1,
          "TLS_RSA_WITH_AES_128_CBC_SHA": 3,
          "TLS_RSA_WITH_AES_128_CBC_SHA256": 1,
          "TLS_RSA_WITH_AES_256_CBC_SHA256": 1,
          "TLS_RSA_WITH_AES_256_CBC_SHA384": 1
        }
      },
      "vendor": {},
      "vulnerability": {}
    },
    "pp_metadata": {
      "/CreationDate": "D:20180524121459Z",
      "/Creator": "wkhtmltopdf 0.12.4",
      "/Producer": "Qt 4.8.7",
      "/Title": "Protection Profile for General Purpose Operating Systems",
      "pdf_file_size_bytes": 1238602,
      "pdf_hyperlinks": {
        "_type": "Set",
        "elements": [
          "https://www.niap-ccevs.org/Documents_and_Guidance/ccevs/Entropy Documentation and Assessment Clarification.pdf",
          "http://www.commoncriteriaportal.org/files/ccfiles/CCPART3V3.1R5.pdf",
          "https://www.gov.uk/government/collections/end-user-devices-security-guidance",
          "http://www.commoncriteriaportal.org/files/ccfiles/CCPART2V3.1R5.pdf",
          "https://www.niap-ccevs.org/pp/",
          "http://www.commoncriteriaportal.org/files/ccfiles/CEMV3.1R5.pdf",
          "https://tools.ietf.org/html/rfc5280",
          "http://csrc.nist.gov/groups/SMA/ispab/documents/csa_87.txt",
          "http://www.commoncriteriaportal.org/files/ccfiles/CCPART1V3.1R5.pdf",
          "http://www.whitehouse.gov/sites/default/files/omb/memoranda/fy2006/m06-19.pdf"
        ]
      },
      "pdf_is_encrypted": false,
      "pdf_number_of_pages": 66
    },
    "report_filename": null,
    "report_keywords": null,
    "report_metadata": null
  },
  "scheme_metadata": {
    "cc_version": "3.1",
    "pp_short_name": "PP_OS_V4.2",
    "pp_sponsor_id": "NIAP",
    "pp_transition": "2018-08-22T00:00:00Z",
    "predecessor": "PP_OS_V4.1",
    "source_scheme": "US",
    "successor": "PP_OS_V4.2.1"
  },
  "state": {
    "_type": "sec_certs.sample.protection_profile.ProtectionProfile.InternalState",
    "pp": {
      "_type": "sec_certs.sample.document_state.DocumentState",
      "convert_ok": true,
      "download_ok": true,
      "extract_ok": true,
      "json_hash": null,
      "source_hash": "9124ae0bd9758fa0482ed8c159caad94a157bf3587a7268ca680579489b52e05",
      "txt_hash": "78577b1d255af6d461cd1104449cad29220022498fa9fe0594a4667d737913db"
    },
    "report": {
      "_type": "sec_certs.sample.document_state.DocumentState",
      "convert_ok": false,
      "download_ok": false,
      "extract_ok": false,
      "json_hash": null,
      "source_hash": null,
      "txt_hash": null
    }
  },
  "web_data": {
    "_type": "sec_certs.sample.protection_profile.ProtectionProfile.WebData",
    "category": "Operating Systems",
    "is_collaborative": false,
    "maintenances": [],
    "name": "Protection Profile for General Purpose Operating Systems Version 4.2",
    "not_valid_after": "2019-04-30",
    "not_valid_before": "2018-05-22",
    "pp_link": "https://www.niap-ccevs.org/api/file/get_public_file/?file_id=11378",
    "report_link": null,
    "scheme": "US",
    "security_level": {
      "_type": "Set",
      "elements": []
    },
    "status": "archived",
    "version": "4.2"
  }
}