TD0706: FIA_UAU.6 Iterations
Publication Date
2022.12.28
Protection Profiles
PP_MDF_V3.2
Other References
FIA_UAU.6, Table 2, Table 8
Issue Description
MDF v3.2 incorrectly combines two FIA_UAU.6 iterations into one SFR with two elements. Resolution
PP_MDF_V3.2 is modified as follows:
FIA_UAU.6 Re-authentication in Section 5.1.5 is removed and replaced with the following two SFRs:
FIA_UAU.6/CREDENTIAL Re-authenticating (Credential Change) FIA_UAU.6.1/CREDENTIAL The TSF shall re-authenticate the user via the Password Authentication Factor under the conditions [attempted change to any supported authentication mechanisms]. Application Note: The password authentication factor must be entered before either the password or biometric authentication factor, if selected in FIA_UAU_5.1, can be changed. TSS There are no TSS evaluation activities for this element. Guidance There are no guidance evaluation activities for this element. Tests · Test 1: The evaluator shall configure the TSF to use the Password Authentication Factor according to the AGD guidance. The evaluator shall change Password Authentication Factor according to the AGD guidance and verify that the TSF requires the entry of the Password Authentication Factor before allowing the factor to be changed. · Test 2: [conditional] For each BAF selected in FIA_UAU.5.1, the evaluator shall configure the TSF to use the BAF, which includes configurating the Password Authentication Factor, according to the AGD guidance. The evaluator shall change the BAF according to the AGD guidance and verify that the TSF requires the entry of the Password Authentication Factor before allowing the BAF to be changed. · Test 3: [conditional] If “hybrid” is selected in FIA_UAU.5.1, the evaluator shall configure the TSF to use the BAF and PIN or password, which includes configuring the Password Authentication Factor, according to the AGD guidance. The evaluator shall change the BAF and PIN according to the AGD guidance and verify that the TSF requires the entry of the Password Authentication Factor before allowing the factor to be changed.
FIA_UAU.6/LOCKED Re-authenticating (TSF Lock) FIA_UAU.6.1/LOCKED The TSF shall re-authenticate the user via the authentication factor defined in FIA_UAU.5.1 under the conditions TSF-initiated lock, user-initiated lock, [assignment: other conditions]. Application Note: Depending on the selections made in FIA_UAU.5.1, either the password (at a minimum), biometric authentication or hybrid authentication mechanisms can be used to unlock the device. TSF-initiated and user-initiated locking is described in FTA_SSL_EXT.1. TSS There are no TSS evaluation activities for this element. Guidance There are no guidance evaluation activities for this element. Tests · Test 1: The evaluator shall configure the TSF to transition to the locked state after a time of inactivity (FMT_SMF.1) according to the AGD guidance. The evaluator shall wait until the TSF locks and then verify that the TSF requires the entry of the Password Authentication Factor before transitioning to the unlocked state. · Test 2: [conditional] For each BAF selected in FIA_UAU.5.1, the evaluator shall repeat Test 1 verifying that the TSF requires the entry of the BAF before transitioning to the unlocked state. · Test 3: [conditional] If “hybrid” is selected in FIA_UAU.5.1, the evaluator shall repeat Test 1 verifying that the TSF requires the entry of the BAF and PIN/password before transitioning to the unlocked state. · Test 4: The evaluator shall configure user-initiated locking according to the AGD guidance. The evaluator shall lock the TSF and then verify that the TSF requires the entry of the Password Authentication Factor before transitioning to the unlocked state. · Test 5: [conditional] For each BAF selected in FIA_UAU.5.1, the evaluator shall repeat Test 4 verifying that the TSF requires the entry of the BAF before transitioning to the unlocked state. · Test 6: [conditional] If “hybrid” is selected in FIA_UAU.5.1, the evaluator shall repeat Test 4 verifying that the TSF requires the entry of the BAF and PIN/password before transitioning to the unlocked state.
The FIA_UAU.6 entry in Table 3: Additional Auditable Events is modified as follows:
The O.AUTH entry in Table 8: SFR Rationale is modified as follows:
Justification
FIA_UAU.6 only has one element. |