{"product_id":10849,"v_id":10849,"product_name":"Samsung Galaxy Devices on Android 7.1","certification_status":"Certified","certification_date":"2017-11-15T00:00:00Z","tech_type":"Mobility, Wireless LAN","vendor_id":{"name":"Samsung Electronics Co., Ltd.","website":"www.samsung.com"},"vendor_poc":"Brian Wood","vendor_phone":"973-440-9125","vendor_email":"be.wood@samsung.com","assigned_lab":{"cctl_name":"Gossamer Security Solutions"},"product_description":"<p><span style=\"font-family: Times; font-size: small;\">The TOE is a mobile device based on Android 7.1 with modifications made to increase the level of security provided to end users and enterprises. The TOE is intended to be used as part of an enterprise messaging solution providing mobile staff with enterprise connectivity.</span></p>\r\n<p style=\"margin: 0in 0in 0pt; text-align: justify;\">&nbsp;</p>\r\n<p style=\"margin: 0in 0in 0pt; text-align: justify;\"><span style=\"font-family: Times; font-size: small;\">The TOE includes a Common Criteria mode (or &ldquo;CC mode&rdquo;) that an administrator can invoke through the use of an MDM or through a dedicated administrative application (see the Guidance for instructions to obtain the application).&nbsp; The TOE must meet the following prerequisites in order for an administrator to transition the TOE to CC mode:</span></p>\r\n<p style=\"margin: 0in 0in 0pt 0.5in; text-align: justify; text-indent: -0.25in;\"><span style=\"font-family: Symbol; mso-fareast-font-family: Symbol; mso-bidi-font-family: Symbol;\"><span style=\"mso-list: Ignore;\"><span style=\"font-size: small;\">&middot;</span><span style=\"font: 7.0pt 'Times New Roman';\">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; </span></span></span><span style=\"font-family: Times New Roman; font-size: small;\">Require a screen lock password (swipe, PIN, pattern, or facial recognition screen locks are not allowed).</span></p>\r\n<p style=\"margin: 0in 0in 0pt 0.5in; text-align: justify; text-indent: -0.25in;\"><span style=\"font-family: Symbol; mso-fareast-font-family: Symbol; mso-bidi-font-family: Symbol;\"><span style=\"mso-list: Ignore;\"><span style=\"font-size: small;\">&middot;</span><span style=\"font: 7.0pt 'Times New Roman';\">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; </span></span></span><span style=\"font-family: Times New Roman; font-size: small;\">The maximum password failure retry policy should be less than or equal to ten.</span></p>\r\n<p style=\"margin: 0in 0in 0pt 0.5in; text-align: justify; text-indent: -0.25in;\"><span style=\"font-family: Symbol; mso-fareast-font-family: Symbol; mso-bidi-font-family: Symbol;\"><span style=\"mso-list: Ignore;\"><span style=\"font-size: small;\">&middot;</span><span style=\"font: 7.0pt 'Times New Roman';\">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; </span></span></span><span style=\"font-family: Times New Roman; font-size: small;\">Device encryption must be enabled or a screen lock password required to decrypt data on boot. </span></p>\r\n<p style=\"margin: 0in 0in 0pt 0.5in; text-align: justify; text-indent: -0.25in;\"><span style=\"font-family: Symbol; mso-fareast-font-family: Symbol; mso-bidi-font-family: Symbol;\"><span style=\"mso-list: Ignore;\"><span style=\"font-size: small;\">&middot;</span><span style=\"font: 7.0pt 'Times New Roman';\">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; </span></span></span><span style=\"font-family: Times New Roman; font-size: small;\">Revocation checking must be enabled.</span></p>\r\n<p style=\"margin: 0in 0in 0pt 0.5in; text-align: justify; text-indent: -0.25in;\"><span style=\"font-family: Symbol; mso-fareast-font-family: Symbol; mso-bidi-font-family: Symbol;\"><span style=\"mso-list: Ignore;\"><span style=\"font-size: small;\">&middot;</span><span style=\"font: 7.0pt 'Times New Roman';\">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; </span></span></span><span style=\"font-family: Times New Roman; font-size: small;\">External storage must be encrypted.</span></p>\r\n<p style=\"margin: 0in 0in 0pt 0.5in; text-align: justify; text-indent: -0.25in;\"><span style=\"font-family: Symbol; mso-fareast-font-family: Symbol; mso-bidi-font-family: Symbol;\"><span style=\"mso-list: Ignore;\"><span style=\"font-size: small;\">&middot;</span><span style=\"font: 7.0pt 'Times New Roman';\">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; </span></span></span><span style=\"font-family: Times New Roman; font-size: small;\">Password (non-container) recovery policy must not be enabled.</span></p>\r\n<p style=\"margin: 0in 0in 0pt; text-align: justify;\"><span style=\"font-family: Times; font-size: small;\">&nbsp;</span></p>\r\n<p style=\"margin: 0in 0in 0pt; text-align: justify;\"><span style=\"font-family: Times; font-size: small;\">When CC mode has been enabled, the TOE behaves as follows:</span></p>\r\n<p style=\"margin: 0in 0in 0pt 0.5in; text-align: justify; text-indent: -0.25in;\"><span style=\"font-family: Symbol; mso-fareast-font-family: Symbol; mso-bidi-font-family: Symbol;\"><span style=\"mso-list: Ignore;\"><span style=\"font-size: small;\">&middot;</span><span style=\"font: 7.0pt 'Times New Roman';\">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; </span></span></span><span style=\"font-family: Times New Roman; font-size: small;\">The TOE sets the system wide Android CC mode property to &ldquo;Enabled&rdquo; if all the prerequisites have been met.</span></p>\r\n<p style=\"margin: 0in 0in 0pt 0.5in; text-align: justify; text-indent: -0.25in;\"><span style=\"font-family: Symbol; mso-fareast-font-family: Symbol; mso-bidi-font-family: Symbol;\"><span style=\"mso-list: Ignore;\"><span style=\"font-size: small;\">&middot;</span><span style=\"font: 7.0pt 'Times New Roman';\">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; </span></span></span><span style=\"font-family: Times New Roman; font-size: small;\">The TOE prevents loading of custom firmware/kernels and requires all updates occur through FOTA (Samsung&rsquo;s Firmware Over The Air firmware update method)</span></p>\r\n<p style=\"margin: 0in 0in 0pt 0.5in; text-align: justify; text-indent: -0.25in;\"><span style=\"font-family: Symbol; mso-fareast-font-family: Symbol; mso-bidi-font-family: Symbol;\"><span style=\"mso-list: Ignore;\"><span style=\"font-size: small;\">&middot;</span><span style=\"font: 7.0pt 'Times New Roman';\">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; </span></span></span><span style=\"font-family: Times New Roman; font-size: small;\">The TOE utilizes CAVP approved cryptographic ciphers for TLS.</span></p>\r\n<p style=\"margin: 0in 0in 0pt 0.5in; text-align: justify; text-indent: -0.25in;\"><span style=\"font-family: Symbol; mso-fareast-font-family: Symbol; mso-bidi-font-family: Symbol;\"><span style=\"mso-list: Ignore;\"><span style=\"font-size: small;\">&middot;</span><span style=\"font: 7.0pt 'Times New Roman';\">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; </span></span></span><span style=\"font-family: Times New Roman; font-size: small;\">The TOE ensures FOTA updates utilize 2048-bit PKCS #1 RSA-PSS formatted signatures (with SHA-512 hashing).</span></p>\r\n<p style=\"margin: 0in 0in 0pt 0.5in; text-align: justify; text-indent: -0.25in;\">&nbsp;</p>\r\n<p style=\"margin: 0in 0in 0pt; text-align: justify;\"><span style=\"font-family: Times; font-size: small;\">The TOE includes a containerization capability, KNOX Workspace, which is part of the KNOX platform. This container provides a way to segment applications and data into two separate areas on the device, such as a personal area and a work area, each with its own separate apps, data and security policies. For this effort the TOE was evaluated both without and with a KNOX Workspace container created (and to create a KNOX Workspace container, one must purchase an additional license).&nbsp; Thus, the evaluation includes several KNOX-specific claims that apply to a KNOX Workspace container when created.</span></p>\r\n<p style=\"margin: 0in 0in 0pt; text-align: justify;\">&nbsp;</p>\r\n<p style=\"margin: 0in 0in 0pt; text-align: justify;\"><span style=\"font-family: Times; font-size: small;\">There are different models of the TOE, the Samsung Galaxy Devices on Android 7.1, and these models differ in their internal components (as described in Evaluated Configuration section below).</span></p>","evaluation_configuration":"<p><span style=\"font-family: Times; font-size: small;\">The model numbers of the mobile device used during evaluation testing are as follows:</span></p>\r\n<div align=\"center\">\r\n<table style=\"border-collapse: collapse; mso-table-layout-alt: fixed; border: none; mso-border-alt: solid #CF7B79 1.0pt; mso-yfti-tbllook: 1184; mso-padding-alt: 0in 5.4pt 0in 5.4pt;\" border=\"1\" cellspacing=\"0\" cellpadding=\"0\">\r\n<tbody>\r\n<tr style=\"mso-yfti-irow: -1; mso-yfti-firstrow: yes; mso-yfti-lastfirstrow: yes;\">\r\n<td style=\"background: #c0504d; border-width: 1pt 0px 1pt 1pt; border-style: solid none solid solid; border-color: #cf7b79 #000000 #cf7b79 #cf7b79; padding: 0in 5.4pt; width: 79.6pt;\" width=\"106\">\r\n<p style=\"margin: 0in 0in 6pt;\"><strong><span style=\"color: white;\"><span style=\"font-family: Times; font-size: small;\">Device Name</span></span></strong></p>\r\n</td>\r\n<td style=\"background: #c0504d; border-width: 1pt 0px; border-style: solid none; border-color: #cf7b79 #000000; padding: 0in 5.4pt; width: 62.95pt;\" width=\"84\">\r\n<p style=\"margin: 0in 0in 6pt;\"><strong><span style=\"color: white;\"><span style=\"font-family: Times; font-size: small;\">Model <br /> Number</span></span></strong></p>\r\n</td>\r\n<td style=\"background: #c0504d; border-width: 1pt 0px; border-style: solid none; border-color: #cf7b79 #000000; padding: 0in 5.4pt; width: 58.55pt;\" width=\"78\">\r\n<p style=\"margin: 0in 0in 6pt;\"><strong><span style=\"color: white;\"><span style=\"font-family: Times; font-size: small;\">Chipset Vendor</span></span></strong></p>\r\n</td>\r\n<td style=\"background: #c0504d; border-width: 1pt 0px; border-style: solid none; border-color: #cf7b79 #000000; padding: 0in 5.4pt; width: 66.35pt;\" width=\"88\">\r\n<p style=\"margin: 0in 0in 6pt;\"><strong><span style=\"color: white;\"><span style=\"font-family: Times; font-size: small;\">CPU</span></span></strong></p>\r\n</td>\r\n<td style=\"background: #c0504d; border-width: 1pt 0px; border-style: solid none; border-color: #cf7b79 #000000; padding: 0in 5.4pt; width: 51.95pt;\" width=\"69\">\r\n<p style=\"margin: 0in 0in 6pt;\"><strong><span style=\"color: white;\"><span style=\"font-family: Times; font-size: small;\">Build Arch/ISA</span></span></strong></p>\r\n</td>\r\n<td style=\"background: #c0504d; border-width: 1pt 0px; border-style: solid none; border-color: #cf7b79 #000000; padding: 0in 5.4pt; width: 49.05pt;\" width=\"65\">\r\n<p style=\"margin: 0in 0in 6pt;\"><strong><span style=\"color: white;\"><span style=\"font-family: Times; font-size: small;\">Android <br /> Version</span></span></strong></p>\r\n</td>\r\n<td style=\"background: #c0504d; border-width: 1pt 0px; border-style: solid none; border-color: #cf7b79 #000000; padding: 0in 5.4pt; width: 44.85pt;\" width=\"60\">\r\n<p style=\"margin: 0in 0in 6pt;\"><strong><span style=\"color: white;\"><span style=\"font-family: Times; font-size: small;\">Kernel Version</span></span></strong></p>\r\n</td>\r\n<td style=\"background: #c0504d; border-width: 1pt 1pt 1pt 0px; border-style: solid solid solid none; border-color: #cf7b79 #cf7b79 #cf7b79 #000000; padding: 0in 5.4pt; width: 54.2pt;\" width=\"72\">\r\n<p style=\"margin: 0in 0in 6pt;\"><strong><span style=\"color: white;\"><span style=\"font-family: Times; font-size: small;\">Build Number</span></span></strong></p>\r\n</td>\r\n</tr>\r\n<tr style=\"mso-yfti-irow: 0;\">\r\n<td style=\"background: #efd3d2; border-width: 0px 0px 1pt 1pt; border-style: none none solid solid; border-color: #000000 #000000 #cf7b79 #cf7b79; padding: 0in 5.4pt; width: 79.6pt;\" width=\"106\">\r\n<p style=\"margin: 0in 0in 6pt;\"><span style=\"font-family: Times; font-size: small;\">Galaxy Note 8</span></p>\r\n</td>\r\n<td style=\"background: #efd3d2; border-width: 0px 0px 1pt; border-style: none none solid; border-color: #000000 #000000 #cf7b79; padding: 0in 5.4pt; width: 62.95pt;\" width=\"84\">\r\n<p style=\"margin: 0in 0in 6pt;\"><span style=\"font-family: Times; font-size: small;\">SM-N950F</span></p>\r\n</td>\r\n<td style=\"background: #efd3d2; border-width: 0px 0px 1pt; border-style: none none solid; border-color: #000000 #000000 #cf7b79; padding: 0in 5.4pt; width: 58.55pt;\" width=\"78\">\r\n<p style=\"margin: 0in 0in 6pt;\"><span style=\"font-family: Times; font-size: small;\">Samsung</span></p>\r\n</td>\r\n<td style=\"background: #efd3d2; border-width: 0px 0px 1pt; border-style: none none solid; border-color: #000000 #000000 #cf7b79; padding: 0in 5.4pt; width: 66.35pt;\" width=\"88\">\r\n<p style=\"margin: 0in 0in 6pt;\"><span style=\"font-family: Times; font-size: small;\">Exynos 8895</span></p>\r\n</td>\r\n<td style=\"background: #efd3d2; border-width: 0px 0px 1pt; border-style: none none solid; border-color: #000000 #000000 #cf7b79; padding: 0in 5.4pt; width: 51.95pt;\" width=\"69\">\r\n<p style=\"margin: 0in 0in 6pt;\"><span style=\"font-family: Times; font-size: small;\">A64</span></p>\r\n</td>\r\n<td style=\"background: #efd3d2; border-width: 0px 0px 1pt; border-style: none none solid; border-color: #000000 #000000 #cf7b79; padding: 0in 5.4pt; width: 49.05pt;\" width=\"65\">\r\n<p style=\"margin: 0in 0in 6pt;\"><span style=\"font-family: Times; font-size: small;\">7.1.1</span></p>\r\n</td>\r\n<td style=\"background: #efd3d2; border-width: 0px 0px 1pt; border-style: none none solid; border-color: #000000 #000000 #cf7b79; padding: 0in 5.4pt; width: 44.85pt;\" width=\"60\">\r\n<p style=\"margin: 0in 0in 6pt;\"><span style=\"font-family: Times; font-size: small;\">4.4.13</span></p>\r\n</td>\r\n<td style=\"background: #efd3d2; border-width: 0px 1pt 1pt 0px; border-style: none solid solid none; border-color: #000000 #cf7b79 #cf7b79 #000000; padding: 0in 5.4pt; width: 54.2pt;\" valign=\"top\" width=\"72\">\r\n<p style=\"margin: 0in 0in 6pt;\"><span style=\"font-family: Times; font-size: small;\">NMF26X</span></p>\r\n</td>\r\n</tr>\r\n<tr style=\"mso-yfti-irow: 1;\">\r\n<td style=\"border-width: 0px 0px 1pt 1pt; border-style: none none solid solid; border-color: #000000 #000000 #cf7b79 #cf7b79; padding: 0in 5.4pt; width: 79.6pt; background-color: transparent;\" width=\"106\">\r\n<p style=\"margin: 0in 0in 6pt;\"><span style=\"font-family: Times; font-size: small;\">Galaxy Note 8</span></p>\r\n</td>\r\n<td style=\"border-width: 0px 0px 1pt; border-style: none none solid; border-color: #000000 #000000 #cf7b79; padding: 0in 5.4pt; width: 62.95pt; background-color: transparent;\" width=\"84\">\r\n<p style=\"margin: 0in 0in 6pt;\"><span style=\"font-family: Times; font-size: small;\">SM-N950U</span></p>\r\n</td>\r\n<td style=\"border-width: 0px 0px 1pt; border-style: none none solid; border-color: #000000 #000000 #cf7b79; padding: 0in 5.4pt; width: 58.55pt; background-color: transparent;\" width=\"78\">\r\n<p style=\"margin: 0in 0in 6pt;\"><span style=\"font-family: Times; font-size: small;\">Qualcomm</span></p>\r\n</td>\r\n<td style=\"border-width: 0px 0px 1pt; border-style: none none solid; border-color: #000000 #000000 #cf7b79; padding: 0in 5.4pt; width: 66.35pt; background-color: transparent;\" width=\"88\">\r\n<p style=\"margin: 0in 0in 6pt;\"><span style=\"font-family: Times; font-size: small;\">MSM8998</span></p>\r\n</td>\r\n<td style=\"border-width: 0px 0px 1pt; border-style: none none solid; border-color: #000000 #000000 #cf7b79; padding: 0in 5.4pt; width: 51.95pt; background-color: transparent;\" width=\"69\">\r\n<p style=\"margin: 0in 0in 6pt;\"><span style=\"font-family: Times; font-size: small;\">A64</span></p>\r\n</td>\r\n<td style=\"border-width: 0px 0px 1pt; border-style: none none solid; border-color: #000000 #000000 #cf7b79; padding: 0in 5.4pt; width: 49.05pt; background-color: transparent;\" width=\"65\">\r\n<p style=\"margin: 0in 0in 6pt;\"><span style=\"font-family: Times; font-size: small;\">7.1.1</span></p>\r\n</td>\r\n<td style=\"border-width: 0px 0px 1pt; border-style: none none solid; border-color: #000000 #000000 #cf7b79; padding: 0in 5.4pt; width: 44.85pt; background-color: transparent;\" width=\"60\">\r\n<p style=\"margin: 0in 0in 6pt;\"><span style=\"font-family: Times; font-size: small;\">4.4.21</span></p>\r\n</td>\r\n<td style=\"border-width: 0px 1pt 1pt 0px; border-style: none solid solid none; border-color: #000000 #cf7b79 #cf7b79 #000000; padding: 0in 5.4pt; width: 54.2pt; background-color: transparent;\" valign=\"top\" width=\"72\">\r\n<p style=\"margin: 0in 0in 6pt;\"><span style=\"font-family: Times; font-size: small;\">NMF26X</span></p>\r\n</td>\r\n</tr>\r\n<tr style=\"mso-yfti-irow: 2; mso-yfti-lastrow: yes;\">\r\n<td style=\"background: #efd3d2; border-width: 0px 0px 1pt 1pt; border-style: none none solid solid; border-color: #000000 #000000 #cf7b79 #cf7b79; padding: 0in 5.4pt; width: 79.6pt;\" width=\"106\">\r\n<p style=\"margin: 0in 0in 6pt;\"><span style=\"font-family: Times; font-size: small;\">Galaxy Tab Active2</span></p>\r\n</td>\r\n<td style=\"background: #efd3d2; border-width: 0px 0px 1pt; border-style: none none solid; border-color: #000000 #000000 #cf7b79; padding: 0in 5.4pt; width: 62.95pt;\" width=\"84\">\r\n<p style=\"margin: 0in 0in 6pt;\"><span style=\"font-family: Times; font-size: small;\">SM-T395</span></p>\r\n</td>\r\n<td style=\"background: #efd3d2; border-width: 0px 0px 1pt; border-style: none none solid; border-color: #000000 #000000 #cf7b79; padding: 0in 5.4pt; width: 58.55pt;\" width=\"78\">\r\n<p style=\"margin: 0in 0in 6pt;\"><span style=\"font-family: Times; font-size: small;\">Samsung</span></p>\r\n</td>\r\n<td style=\"background: #efd3d2; border-width: 0px 0px 1pt; border-style: none none solid; border-color: #000000 #000000 #cf7b79; padding: 0in 5.4pt; width: 66.35pt;\" width=\"88\">\r\n<p style=\"margin: 0in 0in 6pt;\"><span style=\"font-family: Times; font-size: small;\">Exynos 7870</span></p>\r\n</td>\r\n<td style=\"background: #efd3d2; border-width: 0px 0px 1pt; border-style: none none solid; border-color: #000000 #000000 #cf7b79; padding: 0in 5.4pt; width: 51.95pt;\" width=\"69\">\r\n<p style=\"margin: 0in 0in 6pt;\"><span style=\"font-family: Times; font-size: small;\">A32</span></p>\r\n</td>\r\n<td style=\"background: #efd3d2; border-width: 0px 0px 1pt; border-style: none none solid; border-color: #000000 #000000 #cf7b79; padding: 0in 5.4pt; width: 49.05pt;\" width=\"65\">\r\n<p style=\"margin: 0in 0in 6pt;\"><span style=\"font-family: Times; font-size: small;\">7.1.1</span></p>\r\n</td>\r\n<td style=\"background: #efd3d2; border-width: 0px 0px 1pt; border-style: none none solid; border-color: #000000 #000000 #cf7b79; padding: 0in 5.4pt; width: 44.85pt;\" width=\"60\">\r\n<p style=\"margin: 0in 0in 6pt;\"><span style=\"font-family: Times; font-size: small;\">3.18.14</span></p>\r\n</td>\r\n<td style=\"background: #efd3d2; border-width: 0px 1pt 1pt 0px; border-style: none solid solid none; border-color: #000000 #cf7b79 #cf7b79 #000000; padding: 0in 5.4pt; width: 54.2pt;\" valign=\"top\" width=\"72\">\r\n<p style=\"margin: 0in 0in 6pt;\"><span style=\"font-family: Times; font-size: small;\">NMF26X</span></p>\r\n</td>\r\n</tr>\r\n</tbody>\r\n</table>\r\n</div>\r\n<p>&nbsp;</p>\r\n<p style=\"margin: 0in 0.5in 6pt 0in; text-align: center;\" align=\"center\"><a name=\"_Toc491331875\"></a><strong style=\"mso-bidi-font-weight: normal;\"><span style=\"font-size: 10.0pt; mso-bidi-font-size: 9.0pt; font-family: 'Times New Roman',serif;\">Table </span></strong><span style=\"mso-bookmark: _Toc491331875;\"><strong style=\"mso-bidi-font-weight: normal;\"><span style=\"font-size: 10.0pt; mso-bidi-font-size: 9.0pt; font-family: 'Times New Roman',serif;\"><span style=\"mso-no-proof: yes;\">1</span></span></strong></span><span style=\"mso-bookmark: _Toc491331875;\"><strong style=\"mso-bidi-font-weight: normal;\"><span style=\"font-size: 10.0pt; mso-bidi-font-size: 9.0pt; font-family: 'Times New Roman',serif;\"><span style=\"mso-no-proof: yes;\"> Evaluated Devices</span></span></strong></span></p>\r\n<p style=\"margin: 0in 0in 0pt; text-align: justify;\"><span style=\"font-family: Times; font-size: small;\">The devices include a final letter or number at the end of the name that denotes that the device is for a specific carrier (for example, V = Verizon Wireless and A = AT&amp;T, which were used during the evaluation).&nbsp; The following list of letters/numbers denotes the specific models which may be validated: </span></p>\r\n<p style=\"margin: 0in 0in 0pt; text-align: justify;\">&nbsp;</p>\r\n<p style=\"margin: 0in 0in 0pt; text-align: justify; text-indent: 0.5in;\"><span style=\"font-family: Times; font-size: small;\">A &ndash; AT&amp;T</span></p>\r\n<p style=\"margin: 0in 0in 0pt; text-align: justify; text-indent: 0.5in;\"><span style=\"font-family: Times; font-size: small;\">C/F/I &ndash; International</span></p>\r\n<p style=\"margin: 0in 0in 0pt; text-align: justify; text-indent: 0.5in;\"><span style=\"font-family: Times; font-size: small;\">D &ndash; NTT Docomo</span></p>\r\n<p style=\"margin: 0in 0in 0pt; text-align: justify; text-indent: 0.5in;\"><span style=\"font-family: Times; font-size: small;\">J &ndash; KDDI</span></p>\r\n<p style=\"margin: 0in 0in 0pt; text-align: justify; text-indent: 0.5in;\"><span style=\"font-family: Times; font-size: small;\">K &ndash; KT, Korea Telecom </span></p>\r\n<p style=\"margin: 0in 0in 0pt; text-align: justify; text-indent: 0.5in;\"><span style=\"font-family: Times; font-size: small;\">L &ndash; LG Uplus</span></p>\r\n<p style=\"margin: 0in 0in 0pt; text-align: justify; text-indent: 0.5in;\"><span style=\"font-family: Times; font-size: small;\">P &ndash; Sprint</span></p>\r\n<p style=\"margin: 0in 0in 0pt; text-align: justify; text-indent: 0.5in;\"><span style=\"font-family: Times; font-size: small;\">R4 &ndash; US Cellular</span></p>\r\n<p style=\"margin: 0in 0in 0pt; text-align: justify; text-indent: 0.5in;\"><span style=\"font-family: Times; font-size: small;\">S &ndash; SK Telecom</span></p>\r\n<p style=\"margin: 0in 0in 0pt; text-align: justify; text-indent: 0.5in;\"><span style=\"font-family: Times; font-size: small;\">T &ndash; T-Mobile</span></p>\r\n<p style=\"margin: 0in 0in 0pt; text-align: justify; text-indent: 0.5in;\"><span style=\"font-family: Times; font-size: small;\">U &ndash; All US Carriers (unified US model)</span></p>\r\n<p style=\"margin: 0in 0in 12pt; text-align: justify; text-indent: 0.5in;\"><span style=\"font-family: Times; font-size: small;\">V &ndash; Verizon Wireless</span></p>\r\n<p style=\"margin: 0in 0in 0pt; text-align: justify;\"><span style=\"font-family: Times; font-size: small;\">For each device there are specific models which are validated. This table lists the specific carrier models which have the validated configuration.</span></p>\r\n<p style=\"margin: 0in 0in 0pt; text-align: justify;\">&nbsp;</p>\r\n<table style=\"width: 474.5pt; border-collapse: collapse; border: none; mso-border-alt: solid #CF7B79 1.0pt; mso-yfti-tbllook: 1184; mso-padding-alt: 0in 5.4pt 0in 5.4pt;\" border=\"1\" width=\"0\" cellspacing=\"0\" cellpadding=\"0\">\r\n<tbody>\r\n<tr style=\"mso-yfti-irow: -1; mso-yfti-firstrow: yes; mso-yfti-lastfirstrow: yes;\">\r\n<td style=\"background: #c0504d; border-width: 1pt 0px 1pt 1pt; border-style: solid none solid solid; border-color: #cf7b79 #000000 #cf7b79 #cf7b79; padding: 0in 5.4pt; width: 155pt;\" valign=\"top\" width=\"207\">\r\n<p style=\"margin: 0in 0in 6pt;\"><strong><span style=\"color: white;\"><span style=\"font-family: Times; font-size: small;\">Device Name</span></span></strong></p>\r\n</td>\r\n<td style=\"background: #c0504d; border-width: 1pt 0px; border-style: solid none; border-color: #cf7b79 #000000; padding: 0in 5.4pt; width: 67.5pt;\" valign=\"top\" width=\"90\">\r\n<p style=\"margin: 0in 0in 6pt; text-align: center;\" align=\"center\"><strong><span style=\"color: white;\"><span style=\"font-family: Times; font-size: small;\">Base Model <br /> Number</span></span></strong></p>\r\n</td>\r\n<td style=\"background: #c0504d; border-width: 1pt 0px; border-style: solid none; border-color: #cf7b79 #000000; padding: 0in 5.4pt; width: 0.75in;\" valign=\"top\" width=\"72\">\r\n<p style=\"margin: 0in 0in 6pt; text-align: center;\" align=\"center\"><strong><span style=\"color: white;\"><span style=\"font-family: Times; font-size: small;\">Android <br /> Version</span></span></strong></p>\r\n</td>\r\n<td style=\"background: #c0504d; border-width: 1pt 0px; border-style: solid none; border-color: #cf7b79 #000000; padding: 0in 5.4pt; width: 0.75in;\" valign=\"top\" width=\"72\">\r\n<p style=\"margin: 0in 0in 6pt; text-align: center;\" align=\"center\"><strong><span style=\"color: white;\"><span style=\"font-family: Times; font-size: small;\">Kernel Version</span></span></strong></p>\r\n</td>\r\n<td style=\"background: #c0504d; border-width: 1pt 0px; border-style: solid none; border-color: #cf7b79 #000000; padding: 0in 5.4pt; width: 58.5pt;\" valign=\"top\" width=\"78\">\r\n<p style=\"margin: 0in 0in 6pt; text-align: center;\" align=\"center\"><strong><span style=\"color: white;\"><span style=\"font-family: Times; font-size: small;\">Build Number</span></span></strong></p>\r\n</td>\r\n<td style=\"background: #c0504d; border-width: 1pt 1pt 1pt 0px; border-style: solid solid solid none; border-color: #cf7b79 #cf7b79 #cf7b79 #000000; padding: 0in 5.4pt; width: 85.5pt;\" valign=\"top\" width=\"114\">\r\n<p style=\"margin: 0in 0in 6pt; text-align: center;\" align=\"center\"><strong><span style=\"color: white;\"><span style=\"font-family: Times; font-size: small;\">Carrier Models</span></span></strong></p>\r\n</td>\r\n</tr>\r\n<tr style=\"mso-yfti-irow: 0;\">\r\n<td style=\"background: #efd3d2; border-width: 0px 0px 1pt 1pt; border-style: none none solid solid; border-color: #000000 #000000 #cf7b79 #cf7b79; padding: 0in 5.4pt; width: 155pt;\" valign=\"top\" width=\"207\">\r\n<p style=\"margin: 0in 0in 6pt;\"><span style=\"color: black; mso-bidi-font-weight: bold;\"><span style=\"font-family: Times; font-size: small;\">Galaxy Note 8 (Qualcomm)</span></span></p>\r\n</td>\r\n<td style=\"background: #efd3d2; border-width: 0px 0px 1pt; border-style: none none solid; border-color: #000000 #000000 #cf7b79; padding: 0in 5.4pt; width: 67.5pt;\" valign=\"top\" width=\"90\">\r\n<p style=\"margin: 0in 0in 6pt; text-align: center;\" align=\"center\"><span style=\"color: black;\"><span style=\"font-family: Times; font-size: small;\">SM-N950</span></span></p>\r\n</td>\r\n<td style=\"background: #efd3d2; border-width: 0px 0px 1pt; border-style: none none solid; border-color: #000000 #000000 #cf7b79; padding: 0in 5.4pt; width: 0.75in;\" valign=\"top\" width=\"72\">\r\n<p style=\"margin: 0in 0in 6pt; text-align: center;\" align=\"center\"><span style=\"color: black;\"><span style=\"font-family: Times; font-size: small;\">7.1</span></span></p>\r\n</td>\r\n<td style=\"background: #efd3d2; border-width: 0px 0px 1pt; border-style: none none solid; border-color: #000000 #000000 #cf7b79; padding: 0in 5.4pt; width: 0.75in;\" valign=\"top\" width=\"72\">\r\n<p style=\"margin: 0in 0in 6pt; text-align: center;\" align=\"center\"><span style=\"font-family: Times; font-size: small;\">4.4.21</span></p>\r\n</td>\r\n<td style=\"background: #efd3d2; border-width: 0px 0px 1pt; border-style: none none solid; border-color: #000000 #000000 #cf7b79; padding: 0in 5.4pt; width: 58.5pt;\" valign=\"top\" width=\"78\">\r\n<p style=\"margin: 0in 0in 6pt; text-align: center;\" align=\"center\"><span style=\"color: black;\"><span style=\"font-family: Times; font-size: small;\">NMF26X</span></span></p>\r\n</td>\r\n<td style=\"background: #efd3d2; border-width: 0px 1pt 1pt 0px; border-style: none solid solid none; border-color: #000000 #cf7b79 #cf7b79 #000000; padding: 0in 5.4pt; width: 85.5pt;\" valign=\"top\" width=\"114\">\r\n<p style=\"margin: 0in 0in 6pt; text-align: center;\" align=\"center\"><span style=\"color: black;\"><span style=\"font-family: Times; font-size: small;\">U, J, D</span></span></p>\r\n</td>\r\n</tr>\r\n<tr style=\"mso-yfti-irow: 1;\">\r\n<td style=\"border-width: 0px 0px 1pt 1pt; border-style: none none solid solid; border-color: #000000 #000000 #cf7b79 #cf7b79; padding: 0in 5.4pt; width: 0in; background-color: transparent;\" valign=\"top\" width=\"207\">\r\n<p style=\"margin: 0in 0in 6pt;\"><span style=\"color: black; mso-bidi-font-weight: bold;\"><span style=\"font-family: Times; font-size: small;\">Galaxy Note 8 (Samsung)</span></span></p>\r\n</td>\r\n<td style=\"border-width: 0px 0px 1pt; border-style: none none solid; border-color: #000000 #000000 #cf7b79; padding: 0in 5.4pt; width: 0in; background-color: transparent;\" valign=\"top\" width=\"90\">\r\n<p style=\"margin: 0in 0in 6pt; text-align: center;\" align=\"center\"><span style=\"color: black;\"><span style=\"font-family: Times; font-size: small;\">SM-N950</span></span></p>\r\n</td>\r\n<td style=\"border-width: 0px 0px 1pt; border-style: none none solid; border-color: #000000 #000000 #cf7b79; padding: 0in 5.4pt; width: 0in; background-color: transparent;\" valign=\"top\" width=\"72\">\r\n<p style=\"margin: 0in 0in 6pt; text-align: center;\" align=\"center\"><span style=\"color: black;\"><span style=\"font-family: Times; font-size: small;\">7.1</span></span></p>\r\n</td>\r\n<td style=\"border-width: 0px 0px 1pt; border-style: none none solid; border-color: #000000 #000000 #cf7b79; padding: 0in 5.4pt; width: 0in; background-color: transparent;\" valign=\"top\" width=\"72\">\r\n<p style=\"margin: 0in 0in 6pt; text-align: center;\" align=\"center\"><span style=\"font-family: Times; font-size: small;\">4.4.13</span></p>\r\n</td>\r\n<td style=\"border-width: 0px 0px 1pt; border-style: none none solid; border-color: #000000 #000000 #cf7b79; padding: 0in 5.4pt; width: 0in; background-color: transparent;\" valign=\"top\" width=\"78\">\r\n<p style=\"margin: 0in 0in 6pt; text-align: center;\" align=\"center\"><span style=\"color: black;\"><span style=\"font-family: Times; font-size: small;\">NMF26X</span></span></p>\r\n</td>\r\n<td style=\"border-width: 0px 1pt 1pt 0px; border-style: none solid solid none; border-color: #000000 #cf7b79 #cf7b79 #000000; padding: 0in 5.4pt; width: 0in; background-color: transparent;\" valign=\"top\" width=\"114\">\r\n<p style=\"margin: 0in 0in 6pt; text-align: center;\" align=\"center\"><span style=\"color: black;\"><span style=\"font-family: Times; font-size: small;\">N, F</span></span></p>\r\n</td>\r\n</tr>\r\n<tr style=\"mso-yfti-irow: 2;\">\r\n<td style=\"background: #efd3d2; border-width: 0px 0px 1pt 1pt; border-style: none none solid solid; border-color: #000000 #000000 #cf7b79 #cf7b79; padding: 0in 5.4pt; width: 155pt;\" rowspan=\"3\" valign=\"top\" width=\"207\">\r\n<p style=\"margin: 0in 0in 6pt;\"><span style=\"font-family: Times; font-size: small;\">Galaxy Tab Active2</span></p>\r\n</td>\r\n<td style=\"background: #efd3d2; border-width: 0px 0px 1pt; border-style: none none solid; border-color: #000000 #000000 #cf7b79; padding: 0in 5.4pt; width: 67.5pt;\" valign=\"top\" width=\"90\">\r\n<p style=\"margin: 0in 0in 6pt; text-align: center;\" align=\"center\"><span style=\"font-family: Times; font-size: small;\">SM-T390</span></p>\r\n</td>\r\n<td style=\"background: #efd3d2; border-width: 0px 0px 1pt; border-style: none none solid; border-color: #000000 #000000 #cf7b79; padding: 0in 5.4pt; width: 0.75in;\" valign=\"top\" width=\"72\">\r\n<p style=\"margin: 0in 0in 6pt; text-align: center;\" align=\"center\"><span style=\"color: black;\"><span style=\"font-family: Times; font-size: small;\">7.1</span></span></p>\r\n</td>\r\n<td style=\"background: #efd3d2; border-width: 0px 0px 1pt; border-style: none none solid; border-color: #000000 #000000 #cf7b79; padding: 0in 5.4pt; width: 0.75in;\" valign=\"top\" width=\"72\">\r\n<p style=\"margin: 0in 0in 6pt; text-align: center;\" align=\"center\"><span style=\"font-family: Times; font-size: small;\">3.18.14</span></p>\r\n</td>\r\n<td style=\"background: #efd3d2; border-width: 0px 0px 1pt; border-style: none none solid; border-color: #000000 #000000 #cf7b79; padding: 0in 5.4pt; width: 58.5pt;\" valign=\"top\" width=\"78\">\r\n<p style=\"margin: 0in 0in 6pt; text-align: center;\" align=\"center\"><span style=\"color: black;\"><span style=\"font-family: Times; font-size: small;\">NMF26X</span></span></p>\r\n</td>\r\n<td style=\"background: #efd3d2; border-width: 0px 1pt 1pt 0px; border-style: none solid solid none; border-color: #000000 #cf7b79 #cf7b79 #000000; padding: 0in 5.4pt; width: 85.5pt;\" valign=\"top\" width=\"114\">\r\n<p style=\"margin: 0in 0in 6pt; text-align: center;\" align=\"center\"><span style=\"font-family: Times; font-size: small;\">None</span></p>\r\n</td>\r\n</tr>\r\n<tr style=\"mso-yfti-irow: 3;\">\r\n<td style=\"border-width: 0px 0px 1pt; border-style: none none solid; border-color: #000000 #000000 #cf7b79; padding: 0in 5.4pt; width: 0in; background-color: transparent;\" valign=\"top\" width=\"90\">\r\n<p style=\"margin: 0in 0in 6pt; text-align: center;\" align=\"center\"><span style=\"font-family: Times; font-size: small;\">SM-T395</span></p>\r\n</td>\r\n<td style=\"border-width: 0px 0px 1pt; border-style: none none solid; border-color: #000000 #000000 #cf7b79; padding: 0in 5.4pt; width: 0in; background-color: transparent;\" valign=\"top\" width=\"72\">\r\n<p style=\"margin: 0in 0in 6pt; text-align: center;\" align=\"center\"><span style=\"color: black;\"><span style=\"font-family: Times; font-size: small;\">7.1</span></span></p>\r\n</td>\r\n<td style=\"border-width: 0px 0px 1pt; border-style: none none solid; border-color: #000000 #000000 #cf7b79; padding: 0in 5.4pt; width: 0in; background-color: transparent;\" valign=\"top\" width=\"72\">\r\n<p style=\"margin: 0in 0in 6pt; text-align: center;\" align=\"center\"><span style=\"font-family: Times; font-size: small;\">3.18.14</span></p>\r\n</td>\r\n<td style=\"border-width: 0px 0px 1pt; border-style: none none solid; border-color: #000000 #000000 #cf7b79; padding: 0in 5.4pt; width: 0in; background-color: transparent;\" valign=\"top\" width=\"78\">\r\n<p style=\"margin: 0in 0in 6pt; text-align: center;\" align=\"center\"><span style=\"color: black;\"><span style=\"font-family: Times; font-size: small;\">NMF26X</span></span></p>\r\n</td>\r\n<td style=\"border-width: 0px 1pt 1pt 0px; border-style: none solid solid none; border-color: #000000 #cf7b79 #cf7b79 #000000; padding: 0in 5.4pt; width: 0in; background-color: transparent;\" valign=\"top\" width=\"114\">\r\n<p style=\"margin: 0in 0in 6pt; text-align: center;\" align=\"center\"><span style=\"font-family: Times; font-size: small;\">N, None</span></p>\r\n</td>\r\n</tr>\r\n<tr style=\"mso-yfti-irow: 4; mso-yfti-lastrow: yes;\">\r\n<td style=\"background: #efd3d2; border-width: 0px 0px 1pt; border-style: none none solid; border-color: #000000 #000000 #cf7b79; padding: 0in 5.4pt; width: 67.5pt;\" valign=\"top\" width=\"90\">\r\n<p style=\"margin: 0in 0in 6pt; text-align: center;\" align=\"center\"><span style=\"font-family: Times; font-size: small;\">SM-T397</span></p>\r\n</td>\r\n<td style=\"background: #efd3d2; border-width: 0px 0px 1pt; border-style: none none solid; border-color: #000000 #000000 #cf7b79; padding: 0in 5.4pt; width: 0.75in;\" valign=\"top\" width=\"72\">\r\n<p style=\"margin: 0in 0in 6pt; text-align: center;\" align=\"center\"><span style=\"color: black;\"><span style=\"font-family: Times; font-size: small;\">7.1</span></span></p>\r\n</td>\r\n<td style=\"background: #efd3d2; border-width: 0px 0px 1pt; border-style: none none solid; border-color: #000000 #000000 #cf7b79; padding: 0in 5.4pt; width: 0.75in;\" valign=\"top\" width=\"72\">\r\n<p style=\"margin: 0in 0in 6pt; text-align: center;\" align=\"center\"><span style=\"font-family: Times; font-size: small;\">3.18.14</span></p>\r\n</td>\r\n<td style=\"background: #efd3d2; border-width: 0px 0px 1pt; border-style: none none solid; border-color: #000000 #000000 #cf7b79; padding: 0in 5.4pt; width: 58.5pt;\" valign=\"top\" width=\"78\">\r\n<p style=\"margin: 0in 0in 6pt; text-align: center;\" align=\"center\"><span style=\"color: black;\"><span style=\"font-family: Times; font-size: small;\">NMF26X</span></span></p>\r\n</td>\r\n<td style=\"background: #efd3d2; border-width: 0px 1pt 1pt 0px; border-style: none solid solid none; border-color: #000000 #cf7b79 #cf7b79 #000000; padding: 0in 5.4pt; width: 85.5pt;\" valign=\"top\" width=\"114\">\r\n<p style=\"margin: 0in 0in 6pt; text-align: center;\" align=\"center\"><span style=\"font-family: Times; font-size: small;\">None</span></p>\r\n</td>\r\n</tr>\r\n</tbody>\r\n</table>\r\n<p>&nbsp;</p>\r\n<p style=\"margin: 0in 0in 6pt;\"><span style=\"font-family: Times; font-size: small;\">The absence of a final carrier letter indicates a device without a carrier model designation suffix can also be placed into the validated configuration.</span></p>","security_evaluation_summary":"<p><span style=\"font-family: Times; font-size: small;\">The evaluation was carried out in accordance to the Common Criteria Evaluation and Validation Scheme (CCEVS) requirements and guidance. The evaluation demonstrated that the TOE</span> <span style=\"font-family: Times; font-size: small;\">meets the security requirements contained in the Security Target.&nbsp; The criteria against which the TOE was judged are described in the Common Criteria for Information Technology Security Evaluation, Version 3.1, Revision 4, September 2012. The evaluation methodology used by the evaluation team to conduct the evaluation is the Common Methodology for Information Technology Security Evaluation, Evaluation Methodology, Version 3.1, Revision 4, July 2012.&nbsp; Gossamer Security Solutions determined that the evaluation assurance level (EAL) for the TOE is EAL 1.&nbsp; The product, when delivered and configured as identified in the Samsung Android 7 on Galaxy Devices Guidance documentation, Version 3.1, November 13, 2017 document, satisfies all of the security functional requirements stated in the Samsung Galaxy Devices on Android 7.1 (MDFPP31/WLANCEP10) Security Target, Version 0.7, November 13, 2017.&nbsp; The project underwent CCEVS Validator review.&nbsp; The evaluation was completed in November 2017.&nbsp; Results of the evaluation can be found in the Common Criteria Evaluation and Validation Scheme Validation Report (report number CCEVS-VR-VID10849-2017) prepared by CCEVS.</span></p>","environmental_strengths":"<p><span style=\"font-family: Times; font-size: small;\">The logical boundaries of the Samsung Galaxy Devices on Android 7.1 are realized in the security functions that it implements. Each of these security functions is summarized below.</span></p>\r\n<p style=\"margin: 0in 0in 0pt; text-align: justify;\"><span style=\"font-family: Times; font-size: small;\">&nbsp;</span></p>\r\n<p style=\"margin: 0in 0in 0pt; text-align: justify;\"><strong style=\"mso-bidi-font-weight: normal;\"><span lang=\"EN-GB\" style=\"mso-ansi-language: EN-GB;\"><span style=\"font-family: Times; font-size: small;\">Security Audit</span></span></strong><span lang=\"EN-GB\" style=\"mso-ansi-language: EN-GB;\"><span style=\"font-family: Times; font-size: small;\">: </span></span></p>\r\n<p style=\"margin: 0in 0in 0pt; text-align: justify;\"><span style=\"font-family: Times; font-size: small;\">The TOE generates logs for a range of security relevant events. The TOE stores the logs locally so they can be accessed by an administrator or they can be exported to an MDM.</span></p>\r\n<p style=\"margin: 0in 0in 0pt; text-align: justify;\"><span style=\"font-family: Times; font-size: small;\">&nbsp;</span></p>\r\n<p style=\"margin: 0in 0in 0pt; text-align: justify;\"><strong style=\"mso-bidi-font-weight: normal;\"><span lang=\"EN-GB\" style=\"mso-ansi-language: EN-GB;\"><span style=\"font-family: Times; font-size: small;\">Cryptographic support: </span></span></strong></p>\r\n<p style=\"margin: 0in 0in 6pt;\"><span style=\"font-family: 'Times New Roman',serif;\"><span style=\"font-size: small;\">The TOE includes a cryptographic library with CAVP certified algorithms for a wide range of cryptographic functions including: asymmetric key generation and establishment, symmetric key generation, encryption/decryption, cryptographic hashing and keyed-hash message authentication. These functions are supported with suitable random bit generation, key derivation, salt generation, initialization vector generation, secure key storage, and key and protected data destruction. These primitive cryptographic functions are used to implement security protocols such as TLS, IPsec, and HTTPS and also to encrypt the media (including the generation and protection of data and key encryption keys) used by the TOE.&nbsp; Many of these cryptographic functions are also accessible as services to applications running on the TOE.</span></span></p>\r\n<p style=\"margin: 0in 0in 0pt; text-align: justify;\"><strong style=\"mso-bidi-font-weight: normal;\"><span lang=\"EN-GB\" style=\"mso-ansi-language: EN-GB;\"><span style=\"font-family: Times; font-size: small;\">User data protection: </span></span></strong></p>\r\n<p style=\"margin: 0in 0in 6pt;\"><span style=\"font-family: 'Times New Roman',serif;\"><span style=\"font-size: small;\">The TOE controls access to system services by hosted applications, including protection of the Trust Anchor Database. Additionally, the TOE protects user and other sensitive data using encryption so that even if a device is physically lost, the data remains protected. &nbsp;The functionality provided by a KNOX Workspace container enhances the security of user data by providing an additional layer of separation between apps and data while the device is in use.</span></span></p>\r\n<p style=\"margin: 0in 0in 0pt; text-align: justify;\"><strong style=\"mso-bidi-font-weight: normal;\"><span lang=\"EN-GB\" style=\"mso-ansi-language: EN-GB;\"><span style=\"font-family: Times; font-size: small;\">Identification and authentication: </span></span></strong></p>\r\n<p style=\"margin: 0in 0in 6pt;\"><span style=\"font-family: 'Times New Roman',serif;\"><span style=\"font-size: small;\">The TOE supports a number of features related to identification and authentication. From a user perspective, except for making phone calls to an emergency number, a password or Biometric Authentication Factor (BAF) must be correctly entered to unlock the TOE. Also, even when the TOE is unlocked the password must be re-entered to change the password or re-enroll the biometric template. Passwords are obscured when entered so they cannot be read from the TOE's display and the frequency of entering passwords is limited and when a configured number of failures occurs, the TOE will be wiped to protect its contents. Passwords can be constructed using upper and lower cases characters, numbers, and special characters and passwords between 4 and 16 characters are supported.</span></span></p>\r\n<p style=\"margin: 0in 0in 6pt;\"><span style=\"font-family: 'Times New Roman',serif;\"><span style=\"font-size: small;\">The TOE can also serve as an 802.1X supplicant and can use X509v3 and validate certificates for EAP-TLS, TLS and IPsec exchanges.</span></span></p>\r\n<p style=\"margin: 0in 0in 0pt; text-align: justify;\"><strong style=\"mso-bidi-font-weight: normal;\"><span lang=\"EN-GB\" style=\"mso-ansi-language: EN-GB;\"><span style=\"font-family: Times; font-size: small;\">Security management: </span></span></strong></p>\r\n<p style=\"margin: 0in 0in 6pt;\"><span style=\"font-family: 'Times New Roman',serif;\"><span style=\"font-size: small;\">The TOE provides all the interfaces necessary to manage the security functions identified throughout this Security Target as well as other functions commonly found in mobile devices. Many of the available functions are available to users of the TOE while many are restricted to administrators operating through a Mobile Device Management solution once the TOE has been enrolled. Once the TOE has been enrolled and then un-enrolled, it removes all MDM policies and disables CC mode.</span></span></p>\r\n<p style=\"margin: 0in 0in 0pt; text-align: justify;\"><strong style=\"mso-bidi-font-weight: normal;\"><span lang=\"EN-GB\" style=\"mso-ansi-language: EN-GB;\"><span style=\"font-family: Times; font-size: small;\">Protection of the TSF: </span></span></strong></p>\r\n<p style=\"margin: 0in 0in 6pt;\"><span style=\"font-family: 'Times New Roman',serif;\"><span style=\"font-size: small;\">The TOE implements a number of features to protect itself to ensure the reliability and integrity of its security features. It protects particularly sensitive data such as cryptographic keys so that they are not accessible or exportable. It also provides its own timing mechanism to ensure that reliable time information is available (e.g., for log accountability). It enforces read, write, and execute memory page protections, uses address space layout randomization, and stack-based buffer overflow protections to minimize the potential to exploit application flaws. It also protects itself from modification by applications as well as to isolate the address spaces of applications from one another to protect those applications. </span></span></p>\r\n<p style=\"margin: 0in 0in 6pt;\"><span style=\"font-family: 'Times New Roman',serif;\"><span style=\"font-size: small;\">The TOE includes functions to perform self-tests and software/firmware integrity checking so that it might detect when it is failing or may be corrupt. If any of the self-tests fail, the TOE will not go into an operational mode. It also includes mechanisms (i.e., verification of the digital signature of each new image) so that the TOE itself can be updated while ensuring that the updates will not introduce malicious or other unexpected changes in the TOE. Digital signature checking also extends to verifying applications prior to their installation.</span></span></p>\r\n<p style=\"margin: 0in 0in 0pt; text-align: justify;\"><strong style=\"mso-bidi-font-weight: normal;\"><span lang=\"EN-GB\" style=\"mso-ansi-language: EN-GB;\"><span style=\"font-family: Times; font-size: small;\">TOE Access: </span></span></strong></p>\r\n<p style=\"margin: 0in 0in 6pt;\"><span style=\"font-family: 'Times New Roman',serif;\"><span style=\"font-size: small;\">The TOE can be locked, obscuring its display, by the user or after a configured interval of inactivity. The TOE also has the capability to display an advisory message (banner) when users unlock the TOE for use.</span></span></p>\r\n<p style=\"margin: 0in 0in 6pt;\"><span style=\"font-family: 'Times New Roman',serif;\"><span style=\"font-size: small;\">The TOE is also able to attempt to connect to wireless networks as configured.</span></span></p>\r\n<p style=\"margin: 0in 0in 0pt; text-align: justify;\"><strong style=\"mso-bidi-font-weight: normal;\"><span lang=\"EN-GB\" style=\"mso-ansi-language: EN-GB;\"><span style=\"font-family: Times; font-size: small;\">Trusted path/channels: </span></span></strong></p>\r\n<p style=\"margin: 0in 0in 6pt;\"><span style=\"font-family: 'Times New Roman',serif;\"><span style=\"font-size: small;\">The TOE supports the use of 802.11-2012, 802.1X, EAP-TLS, TLS and IPsec to secure communications channels between itself and other trusted network devices.</span></span></p>","features":[]}