{"product_id":10595,"v_id":10595,"product_name":"Samsung Galaxy Note 4, Galaxy Note Edge, Galaxy Alpha, Galaxy Tab S & Galaxy Tab Active VPN Client","certification_status":"Certified","certification_date":"2014-11-17T00:00:00Z","tech_type":"Virtual Private Network","vendor_id":{"name":"Samsung Electronics Co., Ltd.","website":"www.samsung.com"},"vendor_poc":"Brian Wood","vendor_phone":"908-809-7939","vendor_email":"be.wood@samsung.com","assigned_lab":{"cctl_name":"Gossamer Security Solutions"},"product_description":"<p class=\"Body\">The Target of Evaluation (TOE) is the Samsung Electronics Co., Ltd. Samsung Galaxy Devices VPN Client, including the Samsung Galaxy Note 4, Galaxy Note Edge, Galaxy Alpha, Galaxy Tab S 8.4 LTE &amp; 10.5 LTE, &amp; Galaxy Tab Active.&nbsp;</p>\r\n<p class=\"Body\">The TOE Platform is a mobile operating system based on Android 4.4 with modifications made to increase the level of security provided to end users and enterprises. The TOE facilitates secure communications through a VPN, and is intended to be used as part of an enterprise messaging solution providing mobile staff with enterprise connectivity.</p>","evaluation_configuration":"<p>The evaluated configuration consists of several devices with specific processors.&nbsp; The model numbers of the mobile devices are as follows.</p>\r\n<table class=\"MediumShading1-Accent1\" border=\"1\" cellspacing=\"0\" cellpadding=\"0\">\r\n<thead> \r\n<tr>\r\n<td width=\"211\">\r\n<p><strong>Device Name</strong></p>\r\n</td>\r\n<td width=\"90\">\r\n<p><strong>Base Model <br /> Number</strong></p>\r\n</td>\r\n<td width=\"72\">\r\n<p><strong>Android <br /> Version</strong></p>\r\n</td>\r\n<td width=\"72\">\r\n<p><strong>Kernel Version</strong></p>\r\n</td>\r\n<td width=\"72\">\r\n<p><strong>Build Number</strong></p>\r\n</td>\r\n</tr>\r\n</thead> \r\n<tbody>\r\n<tr>\r\n<td width=\"211\">\r\n<p>Galaxy Note 4 (Qualcomm)</p>\r\n</td>\r\n<td rowspan=\"2\" width=\"90\">\r\n<p>SM-N910</p>\r\n</td>\r\n<td rowspan=\"2\" width=\"72\">\r\n<p>4.4.4</p>\r\n</td>\r\n<td width=\"72\" valign=\"top\">\r\n<p>3.10.0</p>\r\n</td>\r\n<td rowspan=\"2\" width=\"72\">\r\n<p>KYU84Q</p>\r\n</td>\r\n</tr>\r\n<tr>\r\n<td width=\"211\">\r\n<p>Galaxy Note 4 (System LSI)</p>\r\n</td>\r\n<td width=\"72\" valign=\"top\">\r\n<p>3.10.9</p>\r\n</td>\r\n</tr>\r\n<tr>\r\n<td width=\"211\">\r\n<p>Galaxy Note Edge (Qualcomm)</p>\r\n</td>\r\n<td rowspan=\"2\" width=\"90\">\r\n<p>SM-N915</p>\r\n</td>\r\n<td rowspan=\"2\" width=\"72\">\r\n<p>4.4.4</p>\r\n</td>\r\n<td width=\"72\" valign=\"top\">\r\n<p>3.10.0</p>\r\n</td>\r\n<td rowspan=\"2\" width=\"72\">\r\n<p>KYU84Q</p>\r\n</td>\r\n</tr>\r\n<tr>\r\n<td width=\"211\">\r\n<p>Galaxy Note Edge (System LSI)</p>\r\n</td>\r\n<td width=\"72\" valign=\"top\">\r\n<p>3.10.9</p>\r\n</td>\r\n</tr>\r\n<tr>\r\n<td width=\"211\">\r\n<p>Galaxy Alpha (Qualcomm)</p>\r\n</td>\r\n<td rowspan=\"2\" width=\"90\">\r\n<p>SM-G850</p>\r\n</td>\r\n<td rowspan=\"2\" width=\"72\">\r\n<p>4.4.4</p>\r\n</td>\r\n<td width=\"72\" valign=\"top\">\r\n<p>3.4.0</p>\r\n</td>\r\n<td rowspan=\"2\" width=\"72\">\r\n<p>KYU84Q</p>\r\n</td>\r\n</tr>\r\n<tr>\r\n<td width=\"211\">\r\n<p>Galaxy Alpha (System LSI)</p>\r\n</td>\r\n<td width=\"72\" valign=\"top\">\r\n<p>3.10.9</p>\r\n</td>\r\n</tr>\r\n<tr>\r\n<td width=\"211\">\r\n<p>Galaxy Tab S 8.4</p>\r\n</td>\r\n<td width=\"90\">\r\n<p>SM-T707</p>\r\n</td>\r\n<td width=\"72\" valign=\"top\">\r\n<p>4.4.2</p>\r\n</td>\r\n<td width=\"72\" valign=\"top\">\r\n<p>3.4.0</p>\r\n</td>\r\n<td width=\"72\" valign=\"top\">\r\n<p>KOT49H</p>\r\n</td>\r\n</tr>\r\n<tr>\r\n<td width=\"211\">\r\n<p>Galaxy Tab S 10.5</p>\r\n</td>\r\n<td width=\"90\">\r\n<p>SM-T807</p>\r\n</td>\r\n<td width=\"72\" valign=\"top\">\r\n<p>4.4.2</p>\r\n</td>\r\n<td width=\"72\" valign=\"top\">\r\n<p>3.4.0</p>\r\n</td>\r\n<td width=\"72\" valign=\"top\">\r\n<p>KOT49H</p>\r\n</td>\r\n</tr>\r\n<tr>\r\n<td width=\"211\">\r\n<p>Galaxy Tab Active</p>\r\n</td>\r\n<td width=\"90\">\r\n<p>SM-T360</p>\r\n</td>\r\n<td width=\"72\" valign=\"top\">\r\n<p>4.4.4</p>\r\n</td>\r\n<td width=\"72\" valign=\"top\">\r\n<p>3.4.0</p>\r\n</td>\r\n<td width=\"72\" valign=\"top\">\r\n<p>KTU84P</p>\r\n</td>\r\n</tr>\r\n</tbody>\r\n</table>\r\n<p>The security software version is MDF v1.1 Release 4.</p>","security_evaluation_summary":"<p>The evaluation was carried out in accordance with the Common Criteria Evaluation and Validation Scheme (CCEVS) process and scheme. The criteria against which the Samsung Galaxy Devices VPN Client was judged are described in the Common Criteria for Information Technology Security Evaluation, Version 3.1 rev 4.&nbsp; The evaluation methodology used by the evaluation team to conduct the evaluation is the Common Methodology for Information Technology Security Evaluation, Version 3.1 rev 4.&nbsp; Gossamer Security Solutions determined that the evaluation assurance level (EAL) for the product is EAL 1.&nbsp; The product, when delivered and configured as identified in the Samsung VPN Client on Galaxy Devices Guidance documentation, Version 1.1, October 28, 2014 &nbsp;&nbsp;document, satisfies all of the security functional requirements stated in the Samsung Electronics Co., Ltd. Samsung Galaxy Note 4, Galaxy Note Edge, Galaxy Alpha, Galaxy Tab S &amp; Galaxy Tab Active VPN Client (IVPNCPP14) Security Target, Version 1.4, November 11, 2014.&nbsp; The project underwent CCEVS Validator review.&nbsp; The evaluation was completed in November 2014.&nbsp; Results of the evaluation can be found in the Common Criteria Evaluation and Validation Scheme Validation Report (report number CCEVS-VR-VID10595-2014) prepared by CCEVS.</p>","environmental_strengths":"<p>The logical boundaries of the Samsung Galaxy Devices VPN Client, including the Samsung Galaxy Note 4, Galaxy Note Edge, Galaxy Alpha, Galaxy Tab S 8.4 LTE &amp; 10.5 LTE, &amp; Galaxy Tab Active TOE are realized in the security functions that it implements. Each of these security functions is summarized below.</p>\r\n<p><strong>Cryptographic Support</strong> - The IPsec implementation is the primary function of the TOE. IPsec is used by the TOE to protect communication between itself and a VPN Gateway over an unprotected network. With the exception of the IPsec implementation, the TOE relies upon its underlying evaluated platform for the cryptographic services specified in this Security Target.</p>\r\n<p><strong>User Data Protection</strong> - The TOE ensures that residual information is protected from potential reuse in accessible objects such as network packets.</p>\r\n<p class=\"Body\"><strong>Identification and Authentication</strong> - The TOE provides the ability to use, store, and protect X.509 certificates and pre-shared keys that are used for IPsec Virtual Private Network (VPN) connections.</p>\r\n<p><strong>Security Management</strong> - The TOE provides all the interfaces necessary to manage the security functions required by the VPN client to meet the requirements. In particular, the IPsec VPN is fully configurable by a combination of functions provided directly by The TOE and those available to the associated VPN gateway.</p>\r\n<p class=\"Body\"><strong>TSF Protection</strong> - The TOE relies upon its underlying platform to perform self-tests that cover the TOE as well as the functions necessary to securely update the TOE.</p>\r\n<p><strong>Trusted Path/Channels</strong> - The TOE acts as a VPN client using IPsec to established secure channels to corresponding VPN gateways.</p>","features":[]}