{"product_id":10253,"v_id":10253,"product_name":"Secure Switching Unit Version D with firmware Version 4.1","certification_status":"Not Certified","certification_date":"2009-04-21T00:04:00Z","tech_type":"Network Switch","vendor_id":{"name":"DiCon Fiberoptics","website":"www.diconfiber.com"},"vendor_poc":"Michelle Muha","vendor_phone":"510-620-5105","vendor_email":"mmuha@diconfiber.com","assigned_lab":{"cctl_name":"CygnaCom Solutions, Inc"},"product_description":"<p class=\"MsoNormal\" style=\"margin: 0in 0in 0pt;\"><span style=\"font-size: x-small;\"><span style=\"font-family: Times New Roman;\">The Secure Switching Unit (SSU) is an all-optical switch unit. All data flowing through the optical switches will be optical. Each switch has the capability to connect to optical fibers. These optical fibers are typically connected to optical transceivers on a computer or a signal processing/routing board on the other end. There is no requirement that the connection is to a host computer or a network. The SSU provides multiple point to point fiber connections.</span></span></p>\r\n<p class=\"MsoNormal\" style=\"margin: 0in 0in 0pt;\"><span style=\"font-size: x-small; font-family: Times New Roman;\">&nbsp;</span></p>\r\n<p class=\"MsoNormal\" style=\"margin: 0in 0in 0pt;\"><span style=\"font-size: x-small;\"><span style=\"font-family: Times New Roman;\">The optical switches provide isolation between the output ports of the 1x3 switch block and between separate 1x3 switch blocks. There are 15 duplex pairs of 1x3 switches in the SSU. Two 1x3 switches make up a duplex 1x3 switch, so there are 30 actual switches in the SSU.</span></span></p>\r\n<p class=\"MsoNormal\" style=\"margin: 0in 0in 0pt;\"><span style=\"font-size: x-small; font-family: Times New Roman;\">&nbsp;</span></p>\r\n<p class=\"MsoNormal\" style=\"margin: 0in 0in 0pt;\"><span style=\"font-size: x-small;\"><span style=\"font-family: Times New Roman;\">One way to think of the SSU is as an automated patch panel.<span style=\"mso-spacerun: yes;\">&nbsp; </span>Without the SSU, one would take an optical fiber and patch one optical port to another optical port (like the old telephone switchboards).<span style=\"mso-spacerun: yes;\">&nbsp; </span>The SSU provides a convenient way to switch ports with push buttons.<span style=\"mso-spacerun: yes;\">&nbsp; </span>However, unlike today&rsquo;s data/telecommunication routers, the SSU does not provide ANY sort of traffic or data packet management.</span></span></p>\r\n<p class=\"MsoNormal\" style=\"margin: 0in 0in 0pt;\"><span style=\"font-size: x-small; font-family: Times New Roman;\">&nbsp;</span></p>\r\n<p class=\"MsoNormal\" style=\"margin: 0in 0in 0pt;\"><span style=\"font-size: x-small; font-family: Times New Roman;\">The SSU front LED panel provides switch position indicators. The front panel can be used to select the switch configuration modes, define user configurable modes</span><a style=\"mso-footnote-id: ftn1;\" name=\"_ftnref1\" href=\"http://taurus/ccevs/projects/final_docs/#_ftn1\"><span class=\"MsoFootnoteReference\"><span style=\"mso-special-character: footnote;\"><span class=\"MsoFootnoteReference\"><span style=\"font-size: 10pt; font-family: &quot;Times New Roman&quot;,&quot;serif&quot;; mso-fareast-font-family: 'Times New Roman'; mso-ansi-language: EN-US; mso-fareast-language: EN-US; mso-bidi-language: AR-SA;\">[1]</span></span></span></span></a><span style=\"font-size: x-small;\"><span style=\"font-family: Times New Roman;\">, and to manually configure switch states. The console part on the back of the SSU can be used to define the programmable modes.</span></span></p>\r\n<div style=\"mso-element: footnote-list;\"><br /><span style=\"font-size: x-small; font-family: Times New Roman;\">\r\n<hr size=\"1\" />\r\n</span>\r\n<div id=\"ftn1\" style=\"mso-element: footnote;\">\r\n<p class=\"MsoFootnoteText\" style=\"margin: 6pt 0in 3pt;\"><a style=\"mso-footnote-id: ftn1;\" name=\"_ftn1\" href=\"http://taurus/ccevs/projects/final_docs/#_ftnref1\"><span class=\"MsoFootnoteReference\"><span style=\"mso-special-character: footnote;\"><span class=\"MsoFootnoteReference\"><span style=\"font-size: 10pt; layout-grid-mode: line; font-family: &quot;Times New Roman&quot;,&quot;serif&quot;; mso-fareast-font-family: 'Times New Roman'; mso-ansi-language: EN-US; mso-fareast-language: EN-US; mso-bidi-language: AR-SA;\">[1]</span></span></span></span></a><span style=\"font-size: x-small;\"><span style=\"font-family: Times New Roman;\"> A &ldquo;mode&rdquo; is a pre-stored channel configuration setting.</span></span></p>\r\n</div>\r\n</div>","evaluation_configuration":null,"security_evaluation_summary":"<p class=\"MsoNormal\" style=\"margin: 0in 0in 0pt;\"><span style=\"font-size: x-small;\"><span style=\"font-family: Times New Roman;\">The evaluation was carried out in accordance with the Common Criteria Evaluation and Validation Scheme (CCEVS) processes and procedures. Secure Switching Unit Version D with firmware Version 4.1 </span></span><span style=\"font-size: x-small;\"><span style=\"font-family: Times New Roman;\">was evaluated against the criteria contained in the Common Criteria for Information Technology Security Evaluation, Version 2.3. The evaluation methodology used by the evaluation team to conduct the evaluation is the Common Methodology for Information Technology Security Evaluation, Version 2.3. CygnaCom Solutions has determined that the product meets the security criteria in the Security Target, which specifies an assurance level of EAL4 augmented with AVA_CCA.1 and AVA_VLA.3.</span></span></p>\r\n<p class=\"MsoNormal\" style=\"margin: 0in 0in 0pt;\"><span style=\"font-size: x-small;\"><span style=\"font-family: Times New Roman;\"></span></span></p>\r\n<p class=\"MsoNormal\" style=\"margin: 0in 0in 0pt;\"><span style=\"font-size: x-small;\"><span style=\"font-family: Times New Roman;\">A validator, on behalf of the CCEVS Validation Body, monitored the evaluation.<span style=\"mso-spacerun: yes;\">&nbsp; </span>The evaluation was completed in April 2009. </span></span></p>","environmental_strengths":"<p class=\"MsoNormal\" style=\"margin: 0in 0in 0pt;\"><span style=\"font-size: x-small;\"><span style=\"font-family: Times New Roman;\">The following security functions are in the scope of the evaluation:</span></span></p>\r\n<p class=\"MsoNormal\" style=\"margin: 0in 0in 0pt;\"><span style=\"font-size: x-small; font-family: Times New Roman;\">&nbsp;</span></p>\r\n<h2 style=\"margin: 12pt 0in 3pt 0.4in; text-indent: -0.4in;\"><a name=\"_Toc168902176\"></a><a name=\"_Toc216771397\"><span style=\"mso-bookmark: _Toc168902176;\"><em><span style=\"font-family: Arial;\">Security Management</span></em></span></a><span style=\"mso-bookmark: _Toc168902176;\"><em><span style=\"font-family: Arial;\"> </span></em></span></h2>\r\n<p class=\"MsoNormal\" style=\"margin: 0in 0in 0pt;\"><span style=\"mso-bookmark: _Toc168902176;\"><span style=\"font-size: x-small;\"><span style=\"font-family: Times New Roman;\">The SSU provides the ability perform the following management functions on the SSU:</span></span></span></p>\r\n<ul style=\"margin-top: 0in;\" type=\"disc\">\r\n<li class=\"MsoNormal\" style=\"margin: 6pt 0in 3pt; mso-list: l0 level1 lfo1; tab-stops: list .5in; mso-pagination: none;\"><span style=\"mso-bookmark: _Toc168902176;\"><span style=\"font-size: x-small;\"><span style=\"font-family: Times New Roman;\">Define programmable modes using the Console port.</span></span></span></li>\r\n<li class=\"MsoNormal\" style=\"margin: 6pt 0in 3pt; mso-list: l0 level1 lfo1; tab-stops: list .5in; mso-pagination: none;\"><span style=\"mso-bookmark: _Toc168902176;\"><span style=\"font-size: x-small;\"><span style=\"font-family: Times New Roman;\">Select switch configuration modes, define User Configurable Modes, and manually configure switch states using the Front Panel of the SSU</span></span></span></li>\r\n<li class=\"MsoNormal\" style=\"margin: 6pt 0in 3pt; mso-list: l0 level1 lfo1; tab-stops: list .5in; mso-pagination: none;\"><span style=\"mso-bookmark: _Toc168902176;\"><span style=\"font-size: x-small;\"><span style=\"font-family: Times New Roman;\">Store and recall a preset mode (a pre-stored channel configuration for all 15 switches) via the Front Panel</span></span></span></li>\r\n</ul>\r\n<p class=\"MsoNormal\" style=\"margin: 0in 0in 0pt;\"><span style=\"mso-bookmark: _Toc168902176;\"><span style=\"font-size: x-small;\"><span style=\"font-family: Times New Roman;\">The TOE allows for 16 total switch configuration modes, 9 are programmable modes.</span></span></span></p>\r\n<p class=\"MsoNormal\" style=\"margin: 0in 0in 0pt;\"><span style=\"mso-bookmark: _Toc168902176;\"><span style=\"font-size: x-small;\"><span style=\"font-family: Times New Roman;\">Administrators control the states of the switches using the front panel either by controlling individual duplex pairs or by recalling stored configuration modes.</span></span></span></p>\r\n<h2 style=\"margin: 12pt 0in 3pt 0.4in; text-indent: -0.4in;\"><span style=\"mso-bookmark: _Toc168902176;\"><a name=\"_Toc216771398\"></a><a name=\"_Toc216519582\"></a><a name=\"_Toc209948087\"></a><a name=\"_Toc172957235\"><span style=\"mso-bookmark: _Toc209948087;\"><span style=\"mso-bookmark: _Toc216519582;\"><span style=\"mso-bookmark: _Toc216771398;\"><em><span style=\"font-family: Arial;\">Switching</span></em></span></span></span></a></span></h2>\r\n<p class=\"MsoNormal\" style=\"margin: 0in 0in 0pt;\"><span style=\"mso-bookmark: _Toc168902176;\"><span style=\"font-size: x-small;\"><span style=\"font-family: Times New Roman;\">Switching provides an optical connection between two ports by providing a low-loss path for a light beam to travel between two ports. The TOE provides all-optical switching using MEMS micro-mirrors in which the switching action is controlled by tilting the mirrors to redirect light beams. The mirror tilting mechanism is controlled electronically. This mechanism is proprietary. The signals are purely optical and the SSU does not alter, process, or store any information going through the optical fiber.</span></span></span></p>\r\n<h2 style=\"margin: 12pt 0in 3pt 0.4in; text-indent: -0.4in;\"><span style=\"mso-bookmark: _Toc168902176;\"><a name=\"_Toc216771399\"></a><a name=\"_Toc216519583\"></a><a name=\"_Toc209948088\"></a><a name=\"_Toc172957236\"><span style=\"mso-bookmark: _Toc209948088;\"><span style=\"mso-bookmark: _Toc216519583;\"><span style=\"mso-bookmark: _Toc216771399;\"><em><span style=\"font-family: Arial;\">Protection of TOE Functions</span></em></span></span></span></a></span></h2>\r\n<p class=\"MsoNormal\" style=\"margin: 0in 0in 0pt;\"><span style=\"mso-bookmark: _Toc168902176;\"><span style=\"font-size: x-small;\"><span style=\"font-family: Times New Roman;\">Logical protection of the TOE is required to ensure the TOE security services are not bypassed or tampered with. In addition, the TOE provides a tamper evident seal and the ability to isolate ports from each other.</span></span></span></p>\r\n<h2 style=\"margin: 12pt 0in 3pt 0.4in; text-indent: -0.4in;\"><span style=\"mso-bookmark: _Toc168902176;\"><a name=\"_Toc216771400\"></a><a name=\"_Toc172957237\"><span style=\"mso-bookmark: _Toc216771400;\"><em><span style=\"font-family: Arial;\">Isolation</span></em></span></a><em><span style=\"font-family: Arial;\"> </span></em></span></h2>\r\n<p class=\"MsoNormal\" style=\"margin: 0in 0in 0pt;\"><span style=\"mso-bookmark: _Toc168902176;\"><span style=\"font-size: x-small;\"><span style=\"font-family: Times New Roman;\">The TOE provides the ability to isolate ports from each other to ensure that the security functions are executed on the correct port. Each of the 1x3 duplex pairs may connect the input port to only one output port (also referred to as channels) at a time.</span></span></span></p>\r\n<p class=\"MsoNormal\" style=\"margin: 0in 0in 0pt;\"><span style=\"mso-bookmark: _Toc168902176;\"><span style=\"font-size: x-small; font-family: Times New Roman;\">&nbsp;</span></span></p>\r\n<p class=\"MsoNormal\" style=\"margin: 0in 0in 0pt; tab-stops: center 3.25in;\"><span style=\"mso-bookmark: _Toc168902176;\"><span style=\"font-size: x-small;\"><span style=\"font-family: Times New Roman;\">Each of the 1x3 switches contains one optical On-off switch at each of the output ports.<span style=\"mso-spacerun: yes;\">&nbsp; </span>The 1x3 component provides optical isolation between the output ports by physical separation of output fibers.<span style=\"mso-spacerun: yes;\">&nbsp; </span>The On-off switch provides additional isolation by turning off (by optically cutting off the signal) the inactive output ports.</span></span></span></p>\r\n<h2 style=\"margin: 12pt 0in 3pt 0.4in; text-indent: -0.4in;\"><span style=\"mso-bookmark: _Toc168902176;\"><a name=\"_Toc216771401\"></a><a name=\"_Toc172957238\"><span style=\"mso-bookmark: _Toc216771401;\"><em><span style=\"font-family: Arial;\">Tamper evident seal</span></em></span></a></span></h2>\r\n<p class=\"MsoNormal\" style=\"margin: 0in 0in 0pt;\"><span style=\"mso-bookmark: _Toc168902176;\"><span style=\"font-size: x-small; font-family: Times New Roman;\">All removable panels on the device will be protected by a tamper-evident seal. This tamper-evident seal will provide obvious signs of attempts to physically open the device.</span></span></p>","features":[]}