Compliant Product - Cisco Secure Client - AnyConnect 5.0 for Android 12
Certificate Date: 2023.07.26CC Certificate Security Target Validation Report
Validation Report Number: CCEVS-VR-VID11398-2023
Product Type: Virtual Private Network
Conformance Claim: Protection Profile Compliant
PP Identifier: PP-Module for VPN Client, Version 2.4
Protection Profile for Application Software Version 1.4
CC Testing Lab: Gossamer Security Solutions
Administrative Guide: Cisco Secure Client - AnyConnect 5.0 for Android 12 CC Configuration Guide
Administrative Guide: Android User Guide for Cisco AnyConnect Secure Mobility Client, Release 4.6.x
Administrative Guide: Cisco Secure Client (including AnyConnect) Administrator Guide, Release 5
Administrative Guide: Cisco AnyConnect Mobile Platforms Administrator Guide, Release 4.1
Administrative Guide: Release Notes for Cisco AnyConnect Secure Mobility Client, Release 4.9
The TOE is Cisco Secure Client - AnyConnect 5.0 for Android 12 (herein after referred to as the VPN client, or the TOE). The TOE enables remote users within an organization to communicate securely as if their devices were directly connected to a private network.
The TOE is a VPN Client software application.A virtual private network (VPN) extends the organization’s private network across a shared or public network.A VPN client establishes an IKEv2/IPsec connection to a VPN Gateway allowing the remote user to securely connect to the organization’s private network.
The evaluated configuration is Cisco Secure Client - AnyConnect v5.0 installed on Android 12.
Security Evaluation Summary
The evaluation was carried out in accordance to the Common Criteria Evaluation and Validation Scheme (CCEVS) requirements and guidance. The evaluation demonstrated that the TOE meets the security requirements contained in the Security Target. The criteria against which the TOE was judged are described in the Common Criteria for Information Technology Security Evaluation, Version 3.1, Revision 5, April 2017. The evaluation methodology used by the evaluation team to conduct the evaluation is the Common Methodology for Information Technology Security Evaluation, Evaluation Methodology, Version 3.1, Revision 5, April 2017. The product, when delivered and configured as identified in the Cisco Secure Client - AnyConnect 5.0 for Android 12 CC Configuration Guide, Version 0.2, July 11, 2023 document, satisfies all of the security functional requirements stated in the Cisco Secure Client - AnyConnect 5.0 for Android 12 Security Target, Version 0.6, July 11, 2023. The project underwent CCEVS Validator review. The evaluation was completed in July 2023. Results of the evaluation can be found in the Common Criteria Evaluation and Validation Scheme Validation Report (report number CCEVS-VR-VID11398-2023) prepared by CCEVS.
The logical boundaries of the Cisco Secure Client - AnyConnect 5.0 for Android 12 are realized in the security functions that it implements. Each of these security functions is summarized below.
The TOE incorporates a cryptographic module, CiscoSSL FIPS Object Module version 7.2a provide the cryptography in support of IPsec with ESP symmetric cryptography for bulk AES encryption/decryption and SHA-2 algorithm for hashing. In addition the TOE provides the cryptography to support Diffie-Hellman key exchange and the derivation function used in the IKEv2 and ESP protocols. The cryptographic algorithm implementation has been validated for CAVP conformance.
The TOE platform provides asymmetric cryptography, which is used by the TOE for IKE peer authentication using digital signature and hashing services. In addition, the TOE platform provides a DRBG.
User data protection:
The TOE platform ensures that residual information from previously sent network packets processed through the platform are protected from being passed into subsequent network packets.
Identification and authentication:
The TOE and TOE platform perform device-level X.509 certificate-based authentication of the VPN Gateway during IKE v2 key exchange. Device-level authentication allows the TOE to establish a secure channel with a trusted VPN Gateway. The secure channel is established only after each endpoint successfully authenticates each other.
The TOE, TOE platform, and VPN Gateway provide the management functions to configure the security functionality provided by the TOE. The TOE provides a Security Administrator role and only the Security Administrator can perform the above security management functions.
The TOE does not store or transmit Personally Identifiable Information (PII) over a network.
Protection of the TSF:
The TOE performs a suite of self-tests during initial start-up to verify correct operation of its CAVP tested algorithms. Upon execution, the integrity of the TOEs software executables is also verified.
The TOE Platform provides for verification of TOE software updates prior to installation.
The TOE’s implementation of IPsec provides a trusted channel ensuring sensitive data is protected from unauthorized disclosure or modification when transmitted from the host to a VPN gateway.
Cisco Systems, Inc.