{"product_id":11120,"v_id":11120,"product_name":"Honeywell Mobility Edge Mobile Computer on Android 9","certification_status":"Certified","certification_date":"2021-03-03T00:00:00Z","tech_type":"Mobility","vendor_id":{"name":"Honeywell International Inc.","website":"https://automation.honeywell.com"},"vendor_poc":"David Boppell","vendor_phone":"877-841-2840","vendor_email":"David.Boppell@honeywell.com","assigned_lab":{"cctl_name":"Gossamer Security Solutions"},"product_description":"<p class=\"Standard\" style=\"margin-bottom: 6.0pt; text-align: justify;\"><span style=\"font-family: 'Times',serif; mso-fareast-font-family: 'Times New Roman'; mso-bidi-font-family: 'Times New Roman'; mso-fareast-language: EN-US; mso-bidi-language: AR-SA;\">The Target of Evaluation (TOE) is Honeywell Mobility Edge Mobile Computer on Android 9.<span style=\"mso-spacerun: yes;\">&nbsp; </span>It is an Automatic Identification and Data Capture (AIDC) handheld computer and includes a touch screen user interface and keyboard (some models).<span style=\"mso-spacerun: yes;\">&nbsp; </span>The TOE allows basic telephony features (make and receive phone calls, send and receive SMS/MMS messages) as well as advanced network connectivity (allowing connections to both 802.11 Wi-Fi and 2G/3G/4G LTE mobile data networks).<span style=\"mso-spacerun: yes;\">&nbsp; </span>The TOE supports using client certificates to connect to access points offering WPA2/WPA3 networks with 802.1x/EAP-TLS, or alternatively connecting to cellular base stations when utilizing mobile data.</span></p>\r\n<p class=\"Standard\" style=\"margin-bottom: 6.0pt; text-align: justify;\"><span style=\"font-family: 'Times',serif; mso-fareast-font-family: 'Times New Roman'; mso-bidi-font-family: 'Times New Roman'; mso-fareast-language: EN-US; mso-bidi-language: AR-SA;\">The TOE offers mobile applications an Application Programming Interface (API) including that provided by the Android framework and supports API calls to the Android Management APIs and vendor proprietary MX APIs.<span style=\"mso-spacerun: yes;\">&nbsp; </span></span></p>\r\n<p class=\"Standard\" style=\"margin-bottom: 6.0pt; text-align: justify;\"><span style=\"font-family: 'Times',serif; mso-fareast-font-family: 'Times New Roman'; mso-bidi-font-family: 'Times New Roman'; mso-fareast-language: EN-US; mso-bidi-language: AR-SA;\">The TOE provides a rich API to mobile applications and provides users installing an application the option to either approve or reject an application based upon the API access that the application requires (or to grant applications access at runtime).</span></p>\r\n<p class=\"Standard\" style=\"margin-bottom: 6.0pt; text-align: justify;\"><span style=\"font-family: 'Times',serif; mso-fareast-font-family: 'Times New Roman'; mso-bidi-font-family: 'Times New Roman'; mso-fareast-language: EN-US; mso-bidi-language: AR-SA;\">The TOE also provides users with the ability to protect Data-At-Rest with AES encryption, including all user and mobile application data stored in the user&rsquo;s data partition.<span style=\"mso-spacerun: yes;\">&nbsp; </span>The TOE uses a key hierarchy that combines a Root Encryption Key (REK) with the user&rsquo;s password to provide protection to all user and application cryptographic keys stored in the TOE. The TOE is architected in such a way that a single operating system image can be loaded to each of the different device configurations (CN80G, CT60, CT40, CK65 etc.) This architecture is designed in such a way as to allow runtime configuration of the system to accommodate different display, keyboard, scan engine, wireless connectivity etc. based on the SKU of the device. The SKU configuration of the device is stored in a non-volatile EEPROM outside the application processor. This configuration is loaded during manufacturing. </span></p>\r\n<p class=\"Standard\" style=\"margin-bottom: 6.0pt; text-align: justify;\"><span style=\"font-family: 'Times',serif; mso-fareast-font-family: 'Times New Roman'; mso-bidi-font-family: 'Times New Roman'; mso-fareast-language: EN-US; mso-bidi-language: AR-SA;\">Finally, the TOE can interact with a Mobile Device Management (MDM) system (not part of this evaluation) to allow enterprise control of the configuration and operation of the device so as to ensure adherence to enterprise-wide policies (for example, restricting use of a corporate provided device&rsquo;s camera, forced configuration of maximum login attempts, pulling of audit logs off the TOE, etc.) as well as policies governing enterprise applications and data. An MDM is made up of two parts: the MDM agent and MDM server. The MDM Agent is installed on the phone/mobile computer as an administrator with elevated permissions (allowing it to change the relevant settings on the phone/device) while the MDM Server is used to issue the commands to the MDM Agent.<span style=\"mso-spacerun: yes;\">&nbsp; </span>Neither portion of the MDM process is considered part of the TOE, and therefore was not evaluated.</span></p>\r\n<p class=\"Standard\" style=\"margin-bottom: 6.0pt; text-align: justify;\"><span style=\"font-family: 'Times',serif; mso-fareast-font-family: 'Times New Roman'; mso-bidi-font-family: 'Times New Roman'; mso-fareast-language: EN-US; mso-bidi-language: AR-SA;\">The TOE includes several different levels of execution including (from lowest to highest): hardware, a Trusted Execution Environment, Android&rsquo;s Linux kernel, and Android&rsquo;s user space, which provides APIs allowing applications to leverage the cryptographic functionality of the device.</span></p>","evaluation_configuration":"<p class=\"Standard\" style=\"margin-bottom: 6.0pt; text-align: justify; mso-pagination: widow-orphan;\"><span style=\"font-family: 'Times',serif; mso-fareast-font-family: Times; color: black;\">The TOE is a mobile device to support enterprises and individual users alike and this evaluation includes the models and versions listed below.<span style=\"mso-spacerun: yes;\">&nbsp; </span>All these models are built on the Honeywell Mobility Edge platform which uses the same hardware System On Module (SOM) with a difference in mechanical form factors, LCD, scan engines, keypad and durability ratings.</span></p>\r\n<table class=\"MsoNormalTable\" style=\"margin-left: 5.65pt; border-collapse: collapse; mso-table-layout-alt: fixed; mso-yfti-tbllook: 1184; mso-padding-alt: 0in .5pt 0in .5pt;\" border=\"0\" width=\"0\" cellspacing=\"0\" cellpadding=\"0\">\r\n<tbody>\r\n<tr style=\"mso-yfti-irow: 0; mso-yfti-firstrow: yes;\">\r\n<td style=\"width: 63.0pt; border: solid #C0504D 1.0pt; mso-border-alt: solid #C0504D .5pt; background: #C0504D; padding: 0in 5.4pt 0in 5.65pt;\" valign=\"top\" width=\"84\">\r\n<p class=\"Standard\"><strong style=\"mso-bidi-font-weight: normal;\"><span style=\"color: white;\">Product</span></strong></p>\r\n</td>\r\n<td style=\"width: 76.5pt; border: solid #C0504D 1.0pt; border-left: none; mso-border-left-alt: solid #C0504D .5pt; mso-border-alt: solid #C0504D .5pt; background: #C0504D; padding: 0in .5pt 0in .5pt;\" valign=\"top\" width=\"102\">\r\n<p class=\"Standard\"><strong style=\"mso-bidi-font-weight: normal;\"><span style=\"color: white;\">Model #</span></strong></p>\r\n</td>\r\n<td style=\"width: 76.5pt; border: solid #C0504D 1.0pt; border-left: none; mso-border-left-alt: solid #C0504D .5pt; mso-border-alt: solid #C0504D .5pt; background: #C0504D; padding: 0in .5pt 0in .5pt;\" valign=\"top\" width=\"102\">\r\n<p class=\"Standard\"><strong style=\"mso-bidi-font-weight: normal;\"><span style=\"font-size: 9.0pt; color: white;\">CPU</span></strong></p>\r\n</td>\r\n<td style=\"width: .75in; border: solid #C0504D 1.0pt; border-left: none; mso-border-left-alt: solid #C0504D .5pt; mso-border-alt: solid #C0504D .5pt; background: #C0504D; padding: 0in .5pt 0in .5pt;\" valign=\"top\" width=\"72\">\r\n<p class=\"Standard\"><strong style=\"mso-bidi-font-weight: normal;\"><span style=\"color: white;\">Kernel</span></strong></p>\r\n</td>\r\n<td style=\"width: 99.0pt; border: solid #C0504D 1.0pt; border-left: none; mso-border-left-alt: solid #C0504D .5pt; mso-border-alt: solid #C0504D .5pt; background: #C0504D; padding: 0in 5.4pt 0in 5.65pt;\" valign=\"top\" width=\"132\">\r\n<p class=\"Standard\"><strong style=\"mso-bidi-font-weight: normal;\"><span style=\"color: white;\">Android OS version</span></strong></p>\r\n</td>\r\n<td style=\"width: 99.0pt; border: solid #C0504D 1.0pt; border-left: none; mso-border-left-alt: solid #C0504D .5pt; mso-border-alt: solid #C0504D .5pt; background: #C0504D; padding: 0in 5.4pt 0in 5.65pt;\" valign=\"top\" width=\"132\">\r\n<p class=\"Standard\"><strong style=\"mso-bidi-font-weight: normal;\"><span style=\"color: white;\">Security Patch Level</span></strong></p>\r\n</td>\r\n</tr>\r\n<tr style=\"mso-yfti-irow: 1;\">\r\n<td style=\"width: 63.0pt; border: solid #C0504D 1.0pt; border-top: none; mso-border-top-alt: solid #C0504D .5pt; mso-border-alt: solid #C0504D .5pt; padding: 0in 5.4pt 0in 5.65pt;\" valign=\"top\" width=\"84\">\r\n<p class=\"Standard\">CN80G</p>\r\n</td>\r\n<td style=\"width: 76.5pt; border-top: none; border-left: none; border-bottom: solid #C0504D 1.0pt; border-right: solid #C0504D 1.0pt; mso-border-top-alt: solid #C0504D .5pt; mso-border-left-alt: solid #C0504D .5pt; mso-border-alt: solid #C0504D .5pt; padding: 0in .5pt 0in .5pt;\" valign=\"top\" width=\"102\">\r\n<p class=\"Standard\">CN80-L1N</p>\r\n</td>\r\n<td style=\"width: 76.5pt; border-top: none; border-left: none; border-bottom: solid #C0504D 1.0pt; border-right: solid #C0504D 1.0pt; mso-border-top-alt: solid #C0504D .5pt; mso-border-left-alt: solid #C0504D .5pt; mso-border-alt: solid #C0504D .5pt; padding: 0in .5pt 0in .5pt;\" valign=\"top\" width=\"102\">\r\n<p class=\"Standard\">SDM660</p>\r\n</td>\r\n<td style=\"width: .75in; border-top: none; border-left: none; border-bottom: solid #C0504D 1.0pt; border-right: solid #C0504D 1.0pt; mso-border-top-alt: solid #C0504D .5pt; mso-border-left-alt: solid #C0504D .5pt; mso-border-alt: solid #C0504D .5pt; padding: 0in .5pt 0in .5pt;\" valign=\"top\" width=\"72\">\r\n<p class=\"Standard\">4.4.153</p>\r\n</td>\r\n<td style=\"width: 99.0pt; border-top: none; border-left: none; border-bottom: solid #C0504D 1.0pt; border-right: solid #C0504D 1.0pt; mso-border-top-alt: solid #C0504D .5pt; mso-border-left-alt: solid #C0504D .5pt; mso-border-alt: solid #C0504D .5pt; padding: 0in 5.4pt 0in 5.65pt;\" valign=\"top\" width=\"132\">\r\n<p class=\"Standard\">Android 9.0</p>\r\n</td>\r\n<td style=\"width: 99.0pt; border-top: none; border-left: none; border-bottom: solid #C0504D 1.0pt; border-right: solid #C0504D 1.0pt; mso-border-top-alt: solid #C0504D .5pt; mso-border-left-alt: solid #C0504D .5pt; mso-border-alt: solid #C0504D .5pt; padding: 0in 5.4pt 0in 5.65pt;\" valign=\"top\" width=\"132\">\r\n<p class=\"MsoNormal\"><span style=\"font-family: 'Calibri',sans-serif; mso-fareast-font-family: 'Linux Libertine G'; mso-bidi-font-family: 'Linux Libertine G'; mso-fareast-language: ZH-CN; mso-bidi-language: HI;\">January 2021</span></p>\r\n</td>\r\n</tr>\r\n<tr style=\"mso-yfti-irow: 2;\">\r\n<td style=\"width: 63.0pt; border: solid #C0504D 1.0pt; border-top: none; mso-border-top-alt: solid #C0504D .5pt; mso-border-alt: solid #C0504D .5pt; padding: 0in 5.4pt 0in 5.65pt;\" valign=\"top\" width=\"84\">\r\n<p class=\"Standard\">CN80G</p>\r\n</td>\r\n<td style=\"width: 76.5pt; border-top: none; border-left: none; border-bottom: solid #C0504D 1.0pt; border-right: solid #C0504D 1.0pt; mso-border-top-alt: solid #C0504D .5pt; mso-border-left-alt: solid #C0504D .5pt; mso-border-alt: solid #C0504D .5pt; padding: 0in .5pt 0in .5pt;\" valign=\"top\" width=\"102\">\r\n<p class=\"Standard\">CN80-L0N</p>\r\n</td>\r\n<td style=\"width: 76.5pt; border-top: none; border-left: none; border-bottom: solid #C0504D 1.0pt; border-right: solid #C0504D 1.0pt; mso-border-top-alt: solid #C0504D .5pt; mso-border-left-alt: solid #C0504D .5pt; mso-border-alt: solid #C0504D .5pt; padding: 0in .5pt 0in .5pt;\" valign=\"top\" width=\"102\">\r\n<p class=\"Standard\">SDM660</p>\r\n</td>\r\n<td style=\"width: .75in; border-top: none; border-left: none; border-bottom: solid #C0504D 1.0pt; border-right: solid #C0504D 1.0pt; mso-border-top-alt: solid #C0504D .5pt; mso-border-left-alt: solid #C0504D .5pt; mso-border-alt: solid #C0504D .5pt; padding: 0in .5pt 0in .5pt;\" valign=\"top\" width=\"72\">\r\n<p class=\"Standard\">4.4.153</p>\r\n</td>\r\n<td style=\"width: 99.0pt; border-top: none; border-left: none; border-bottom: solid #C0504D 1.0pt; border-right: solid #C0504D 1.0pt; mso-border-top-alt: solid #C0504D .5pt; mso-border-left-alt: solid #C0504D .5pt; mso-border-alt: solid #C0504D .5pt; padding: 0in 5.4pt 0in 5.65pt;\" valign=\"top\" width=\"132\">\r\n<p class=\"Standard\">Android 9.0</p>\r\n</td>\r\n<td style=\"width: 99.0pt; border-top: none; border-left: none; border-bottom: solid #C0504D 1.0pt; border-right: solid #C0504D 1.0pt; mso-border-top-alt: solid #C0504D .5pt; mso-border-left-alt: solid #C0504D .5pt; mso-border-alt: solid #C0504D .5pt; padding: 0in 5.4pt 0in 5.65pt;\" valign=\"top\" width=\"132\">\r\n<p class=\"MsoNormal\"><span style=\"font-family: 'Calibri',sans-serif; mso-fareast-font-family: 'Linux Libertine G'; mso-bidi-font-family: 'Linux Libertine G'; mso-fareast-language: ZH-CN; mso-bidi-language: HI;\">January 2021</span></p>\r\n</td>\r\n</tr>\r\n<tr style=\"mso-yfti-irow: 3;\">\r\n<td style=\"width: 63.0pt; border: solid #C0504D 1.0pt; border-top: none; mso-border-top-alt: solid #C0504D .5pt; mso-border-alt: solid #C0504D .5pt; padding: 0in 5.4pt 0in 5.65pt;\" valign=\"top\" width=\"84\">\r\n<p class=\"Standard\">CK65</p>\r\n</td>\r\n<td style=\"width: 76.5pt; border-top: none; border-left: none; border-bottom: solid #C0504D 1.0pt; border-right: solid #C0504D 1.0pt; mso-border-top-alt: solid #C0504D .5pt; mso-border-left-alt: solid #C0504D .5pt; mso-border-alt: solid #C0504D .5pt; padding: 0in .5pt 0in .5pt;\" valign=\"top\" width=\"102\">\r\n<p class=\"Standard\">CK65-L0N</p>\r\n</td>\r\n<td style=\"width: 76.5pt; border-top: none; border-left: none; border-bottom: solid #C0504D 1.0pt; border-right: solid #C0504D 1.0pt; mso-border-top-alt: solid #C0504D .5pt; mso-border-left-alt: solid #C0504D .5pt; mso-border-alt: solid #C0504D .5pt; padding: 0in .5pt 0in .5pt;\" valign=\"top\" width=\"102\">\r\n<p class=\"Standard\">SDM660</p>\r\n</td>\r\n<td style=\"width: .75in; border-top: none; border-left: none; border-bottom: solid #C0504D 1.0pt; border-right: solid #C0504D 1.0pt; mso-border-top-alt: solid #C0504D .5pt; mso-border-left-alt: solid #C0504D .5pt; mso-border-alt: solid #C0504D .5pt; padding: 0in .5pt 0in .5pt;\" valign=\"top\" width=\"72\">\r\n<p class=\"Standard\">4.4.153</p>\r\n</td>\r\n<td style=\"width: 99.0pt; border-top: none; border-left: none; border-bottom: solid #C0504D 1.0pt; border-right: solid #C0504D 1.0pt; mso-border-top-alt: solid #C0504D .5pt; mso-border-left-alt: solid #C0504D .5pt; mso-border-alt: solid #C0504D .5pt; padding: 0in 5.4pt 0in 5.65pt;\" valign=\"top\" width=\"132\">\r\n<p class=\"Standard\">Android 9.0</p>\r\n</td>\r\n<td style=\"width: 99.0pt; border-top: none; border-left: none; border-bottom: solid #C0504D 1.0pt; border-right: solid #C0504D 1.0pt; mso-border-top-alt: solid #C0504D .5pt; mso-border-left-alt: solid #C0504D .5pt; mso-border-alt: solid #C0504D .5pt; padding: 0in 5.4pt 0in 5.65pt;\" valign=\"top\" width=\"132\">\r\n<p class=\"MsoNormal\"><span style=\"font-family: 'Calibri',sans-serif; mso-fareast-font-family: 'Linux Libertine G'; mso-bidi-font-family: 'Linux Libertine G'; mso-fareast-language: ZH-CN; mso-bidi-language: HI;\">January 2021</span></p>\r\n</td>\r\n</tr>\r\n<tr style=\"mso-yfti-irow: 4;\">\r\n<td style=\"width: 63.0pt; border: solid #C0504D 1.0pt; border-top: none; mso-border-top-alt: solid #C0504D .5pt; mso-border-alt: solid #C0504D .5pt; padding: 0in 5.4pt 0in 5.65pt;\" valign=\"top\" width=\"84\">\r\n<p class=\"Standard\">CT60</p>\r\n</td>\r\n<td style=\"width: 76.5pt; border-top: none; border-left: none; border-bottom: solid #C0504D 1.0pt; border-right: solid #C0504D 1.0pt; mso-border-top-alt: solid #C0504D .5pt; mso-border-left-alt: solid #C0504D .5pt; mso-border-alt: solid #C0504D .5pt; padding: 0in .5pt 0in .5pt;\" valign=\"top\" width=\"102\">\r\n<p class=\"Standard\">CT60-L0N</p>\r\n</td>\r\n<td style=\"width: 76.5pt; border-top: none; border-left: none; border-bottom: solid #C0504D 1.0pt; border-right: solid #C0504D 1.0pt; mso-border-top-alt: solid #C0504D .5pt; mso-border-left-alt: solid #C0504D .5pt; mso-border-alt: solid #C0504D .5pt; padding: 0in .5pt 0in .5pt;\" valign=\"top\" width=\"102\">\r\n<p class=\"Standard\">SDM660</p>\r\n</td>\r\n<td style=\"width: .75in; border-top: none; border-left: none; border-bottom: solid #C0504D 1.0pt; border-right: solid #C0504D 1.0pt; mso-border-top-alt: solid #C0504D .5pt; mso-border-left-alt: solid #C0504D .5pt; mso-border-alt: solid #C0504D .5pt; padding: 0in .5pt 0in .5pt;\" valign=\"top\" width=\"72\">\r\n<p class=\"Standard\">4.4.153</p>\r\n</td>\r\n<td style=\"width: 99.0pt; border-top: none; border-left: none; border-bottom: solid #C0504D 1.0pt; border-right: solid #C0504D 1.0pt; mso-border-top-alt: solid #C0504D .5pt; mso-border-left-alt: solid #C0504D .5pt; mso-border-alt: solid #C0504D .5pt; padding: 0in 5.4pt 0in 5.65pt;\" valign=\"top\" width=\"132\">\r\n<p class=\"Standard\">Android 9.0</p>\r\n</td>\r\n<td style=\"width: 99.0pt; border-top: none; border-left: none; border-bottom: solid #C0504D 1.0pt; border-right: solid #C0504D 1.0pt; mso-border-top-alt: solid #C0504D .5pt; mso-border-left-alt: solid #C0504D .5pt; mso-border-alt: solid #C0504D .5pt; padding: 0in 5.4pt 0in 5.65pt;\" valign=\"top\" width=\"132\">\r\n<p class=\"MsoNormal\"><span style=\"font-family: 'Calibri',sans-serif; mso-fareast-font-family: 'Linux Libertine G'; mso-bidi-font-family: 'Linux Libertine G'; mso-fareast-language: ZH-CN; mso-bidi-language: HI;\">January 2021</span></p>\r\n</td>\r\n</tr>\r\n<tr style=\"mso-yfti-irow: 5;\">\r\n<td style=\"width: 63.0pt; border: solid #C0504D 1.0pt; border-top: none; mso-border-top-alt: solid #C0504D .5pt; mso-border-alt: solid #C0504D .5pt; padding: 0in 5.4pt 0in 5.65pt;\" valign=\"top\" width=\"84\">\r\n<p class=\"Standard\">CT60</p>\r\n</td>\r\n<td style=\"width: 76.5pt; border-top: none; border-left: none; border-bottom: solid #C0504D 1.0pt; border-right: solid #C0504D 1.0pt; mso-border-top-alt: solid #C0504D .5pt; mso-border-left-alt: solid #C0504D .5pt; mso-border-alt: solid #C0504D .5pt; padding: 0in .5pt 0in .5pt;\" valign=\"top\" width=\"102\">\r\n<p class=\"Standard\">CT60-L1N</p>\r\n</td>\r\n<td style=\"width: 76.5pt; border-top: none; border-left: none; border-bottom: solid #C0504D 1.0pt; border-right: solid #C0504D 1.0pt; mso-border-top-alt: solid #C0504D .5pt; mso-border-left-alt: solid #C0504D .5pt; mso-border-alt: solid #C0504D .5pt; padding: 0in .5pt 0in .5pt;\" valign=\"top\" width=\"102\">\r\n<p class=\"Standard\">SDM660</p>\r\n</td>\r\n<td style=\"width: .75in; border-top: none; border-left: none; border-bottom: solid #C0504D 1.0pt; border-right: solid #C0504D 1.0pt; mso-border-top-alt: solid #C0504D .5pt; mso-border-left-alt: solid #C0504D .5pt; mso-border-alt: solid #C0504D .5pt; padding: 0in .5pt 0in .5pt;\" valign=\"top\" width=\"72\">\r\n<p class=\"Standard\">4.4.153</p>\r\n</td>\r\n<td style=\"width: 99.0pt; border-top: none; border-left: none; border-bottom: solid #C0504D 1.0pt; border-right: solid #C0504D 1.0pt; mso-border-top-alt: solid #C0504D .5pt; mso-border-left-alt: solid #C0504D .5pt; mso-border-alt: solid #C0504D .5pt; padding: 0in 5.4pt 0in 5.65pt;\" valign=\"top\" width=\"132\">\r\n<p class=\"Standard\">Android 9.0</p>\r\n</td>\r\n<td style=\"width: 99.0pt; border-top: none; border-left: none; border-bottom: solid #C0504D 1.0pt; border-right: solid #C0504D 1.0pt; mso-border-top-alt: solid #C0504D .5pt; mso-border-left-alt: solid #C0504D .5pt; mso-border-alt: solid #C0504D .5pt; padding: 0in 5.4pt 0in 5.65pt;\" valign=\"top\" width=\"132\">\r\n<p class=\"MsoNormal\"><span style=\"font-family: 'Calibri',sans-serif; mso-fareast-font-family: 'Linux Libertine G'; mso-bidi-font-family: 'Linux Libertine G'; mso-fareast-language: ZH-CN; mso-bidi-language: HI;\">January 2021</span></p>\r\n</td>\r\n</tr>\r\n<tr style=\"mso-yfti-irow: 6;\">\r\n<td style=\"width: 63.0pt; border: solid #C0504D 1.0pt; border-top: none; mso-border-top-alt: solid #C0504D .5pt; mso-border-alt: solid #C0504D .5pt; padding: 0in 5.4pt 0in 5.65pt;\" valign=\"top\" width=\"84\">\r\n<p class=\"Standard\">CT40</p>\r\n</td>\r\n<td style=\"width: 76.5pt; border-top: none; border-left: none; border-bottom: solid #C0504D 1.0pt; border-right: solid #C0504D 1.0pt; mso-border-top-alt: solid #C0504D .5pt; mso-border-left-alt: solid #C0504D .5pt; mso-border-alt: solid #C0504D .5pt; padding: 0in .5pt 0in .5pt;\" valign=\"top\" width=\"102\">\r\n<p class=\"Standard\">CT40P-L0N</p>\r\n</td>\r\n<td style=\"width: 76.5pt; border-top: none; border-left: none; border-bottom: solid #C0504D 1.0pt; border-right: solid #C0504D 1.0pt; mso-border-top-alt: solid #C0504D .5pt; mso-border-left-alt: solid #C0504D .5pt; mso-border-alt: solid #C0504D .5pt; padding: 0in .5pt 0in .5pt;\" valign=\"top\" width=\"102\">\r\n<p class=\"Standard\">SDM660</p>\r\n</td>\r\n<td style=\"width: .75in; border-top: none; border-left: none; border-bottom: solid #C0504D 1.0pt; border-right: solid #C0504D 1.0pt; mso-border-top-alt: solid #C0504D .5pt; mso-border-left-alt: solid #C0504D .5pt; mso-border-alt: solid #C0504D .5pt; padding: 0in .5pt 0in .5pt;\" valign=\"top\" width=\"72\">\r\n<p class=\"Standard\">4.4.153</p>\r\n</td>\r\n<td style=\"width: 99.0pt; border-top: none; border-left: none; border-bottom: solid #C0504D 1.0pt; border-right: solid #C0504D 1.0pt; mso-border-top-alt: solid #C0504D .5pt; mso-border-left-alt: solid #C0504D .5pt; mso-border-alt: solid #C0504D .5pt; padding: 0in 5.4pt 0in 5.65pt;\" valign=\"top\" width=\"132\">\r\n<p class=\"Standard\">Android 9.0</p>\r\n</td>\r\n<td style=\"width: 99.0pt; border-top: none; border-left: none; border-bottom: solid #C0504D 1.0pt; border-right: solid #C0504D 1.0pt; mso-border-top-alt: solid #C0504D .5pt; mso-border-left-alt: solid #C0504D .5pt; mso-border-alt: solid #C0504D .5pt; padding: 0in 5.4pt 0in 5.65pt;\" valign=\"top\" width=\"132\">\r\n<p class=\"MsoNormal\"><span style=\"font-family: 'Calibri',sans-serif; mso-fareast-font-family: 'Linux Libertine G'; mso-bidi-font-family: 'Linux Libertine G'; mso-fareast-language: ZH-CN; mso-bidi-language: HI;\">January 2021</span></p>\r\n</td>\r\n</tr>\r\n<tr style=\"mso-yfti-irow: 7; mso-yfti-lastrow: yes;\">\r\n<td style=\"width: 63.0pt; border: solid #C0504D 1.0pt; border-top: none; mso-border-top-alt: solid #C0504D .5pt; mso-border-alt: solid #C0504D .5pt; padding: 0in 5.4pt 0in 5.65pt;\" valign=\"top\" width=\"84\">\r\n<p class=\"Standard\">CT40</p>\r\n</td>\r\n<td style=\"width: 76.5pt; border-top: none; border-left: none; border-bottom: solid #C0504D 1.0pt; border-right: solid #C0504D 1.0pt; mso-border-top-alt: solid #C0504D .5pt; mso-border-left-alt: solid #C0504D .5pt; mso-border-alt: solid #C0504D .5pt; padding: 0in .5pt 0in .5pt;\" valign=\"top\" width=\"102\">\r\n<p class=\"Standard\">CT40P-L1N</p>\r\n</td>\r\n<td style=\"width: 76.5pt; border-top: none; border-left: none; border-bottom: solid #C0504D 1.0pt; border-right: solid #C0504D 1.0pt; mso-border-top-alt: solid #C0504D .5pt; mso-border-left-alt: solid #C0504D .5pt; mso-border-alt: solid #C0504D .5pt; padding: 0in .5pt 0in .5pt;\" valign=\"top\" width=\"102\">\r\n<p class=\"Standard\">SDM660</p>\r\n</td>\r\n<td style=\"width: .75in; border-top: none; border-left: none; border-bottom: solid #C0504D 1.0pt; border-right: solid #C0504D 1.0pt; mso-border-top-alt: solid #C0504D .5pt; mso-border-left-alt: solid #C0504D .5pt; mso-border-alt: solid #C0504D .5pt; padding: 0in .5pt 0in .5pt;\" valign=\"top\" width=\"72\">\r\n<p class=\"Standard\">4.4.153</p>\r\n</td>\r\n<td style=\"width: 99.0pt; border-top: none; border-left: none; border-bottom: solid #C0504D 1.0pt; border-right: solid #C0504D 1.0pt; mso-border-top-alt: solid #C0504D .5pt; mso-border-left-alt: solid #C0504D .5pt; mso-border-alt: solid #C0504D .5pt; padding: 0in 5.4pt 0in 5.65pt;\" valign=\"top\" width=\"132\">\r\n<p class=\"Standard\">Android 9.0</p>\r\n</td>\r\n<td style=\"width: 99.0pt; border-top: none; border-left: none; border-bottom: solid #C0504D 1.0pt; border-right: solid #C0504D 1.0pt; mso-border-top-alt: solid #C0504D .5pt; mso-border-left-alt: solid #C0504D .5pt; mso-border-alt: solid #C0504D .5pt; padding: 0in 5.4pt 0in 5.65pt;\" valign=\"top\" width=\"132\">\r\n<p class=\"MsoNormal\"><span style=\"font-family: 'Calibri',sans-serif; mso-fareast-font-family: 'Linux Libertine G'; mso-bidi-font-family: 'Linux Libertine G'; mso-fareast-language: ZH-CN; mso-bidi-language: HI;\">January 2021</span></p>\r\n</td>\r\n</tr>\r\n</tbody>\r\n</table>\r\n<p class=\"Standard\" style=\"text-align: justify;\">&nbsp;</p>\r\n<p class=\"Standard\" style=\"margin-bottom: 6.0pt; text-align: justify; mso-pagination: widow-orphan;\"><span style=\"font-family: 'Times',serif; mso-fareast-font-family: Times; color: black;\">Each of the hardware models included in this evaluation has the ability to run either an AOSP (Android Open-Source Project) or a GMS (Google Mobile Services) version of the Android 9 operating system. The AOSP version is a purely open-source based version of Android that does not contain any GSM, which are a collection of Google applications and APIs. The GMS version of software contains Google&rsquo;s applications (such as Chrome, Gmail, Google Maps, etc.) along with an additional set of APIs. There is no special configuration required for a particular hardware model to support GMS or AOSP and images can be interchanged on the same device without any special provisioning. Both versions of the Operating System were included in this evaluation.</span></p>","security_evaluation_summary":"<p class=\"Standard\" style=\"margin-bottom: 6.0pt; text-align: justify;\"><span style=\"font-family: 'Times',serif; mso-fareast-font-family: 'Times New Roman'; mso-bidi-font-family: 'Times New Roman'; mso-fareast-language: EN-US; mso-bidi-language: AR-SA;\">The evaluation was carried out in accordance with the Common Criteria Evaluation and Validation Scheme (CCEVS) requirements and guidance.<span style=\"mso-spacerun: yes;\">&nbsp; </span>The criteria against which the TOE was judged are described in the Common Criteria for Information Technology Security Evaluation, Version 3.1, Revision 5, September 2017. The evaluation methodology used by the evaluation team to conduct the evaluation is the Common Methodology for Information Technology Security Evaluation, Evaluation Methodology, Version 3.1, Revision 5, July 2017.<span style=\"mso-spacerun: yes;\">&nbsp;&nbsp;&nbsp; </span>The product, when delivered and configured as identified in the Honeywell Mobility Edge Android 9 Administrator Guidance Documentation, Version 1.2, 2021/03/02 document, satisfies all of the security functional requirements stated in the Honeywell Mobility Edge Mobile Computer on Android 9 (MDFPP31/WLANCEP10) Security Target, Version 1.4, 2021/03/02.<span style=\"mso-spacerun: yes;\">&nbsp; </span>The project underwent CCEVS Validator review.<span style=\"mso-spacerun: yes;\">&nbsp; </span>The evaluation was completed in March 2021.<span style=\"mso-spacerun: yes;\">&nbsp; </span>Results of the evaluation can be found in the Common Criteria Evaluation and Validation Scheme Validation Report prepared by CCEVS.</span></p>","environmental_strengths":"<p class=\"Standard\" style=\"margin-bottom: 6.0pt; text-align: justify;\"><span style=\"font-family: 'Times',serif; mso-fareast-font-family: 'Times New Roman'; mso-bidi-font-family: 'Times New Roman'; mso-fareast-language: EN-US; mso-bidi-language: AR-SA;\">The logical boundaries of the TOE are realized in the security functions that it implements. Each of these security functions is summarized below.</span></p>\r\n<p class=\"MsoNormal\" style=\"text-align: justify; mso-outline-level: 1;\"><strong>Security audit:</strong></p>\r\n<p class=\"Standard\" style=\"margin-bottom: 6.0pt; text-align: justify; mso-pagination: widow-orphan;\"><span style=\"font-family: 'Times',serif; mso-fareast-font-family: Times; color: black;\">The TOE implements a security log and logcat that are each stored in a circular memory buffer.<span style=\"mso-spacerun: yes;\">&nbsp; </span>An MDM agent can read/fetch the security logs, can retrieve logcat logs, and then handle appropriately (potentially storing the log to Flash or transmitting its contents to the MDM server).<span style=\"mso-spacerun: yes;\">&nbsp; </span>These log methods meet the logging requirements outlined by FAU_GEN.1 in MDFPPv3.1.</span></p>\r\n<p class=\"MsoNormal\" style=\"text-align: justify; mso-outline-level: 1;\"><strong>Cryptographic support:</strong></p>\r\n<p class=\"Standard\" style=\"margin-bottom: 6.0pt; text-align: justify; mso-pagination: widow-orphan;\"><span style=\"font-family: 'Times',serif; mso-fareast-font-family: Times; color: black;\">The TOE includes multiple cryptographic libraries with CAVP certified algorithms for a wide range of cryptographic functions including the following: asymmetric key generation and establishment, symmetric key generation, encryption/decryption, cryptographic hashing and keyed-hash message authentication. These functions are supported with suitable random bit generation, key derivation, salt generation, initialization vector generation, secure key storage, and key and protected data destruction. These primitive cryptographic functions are used to implement security protocols such as TLS, EAP-TLS, and HTTPS and to encrypt the media (including the generation and protection of data and key encryption keys) used by the TOE. Many of these cryptographic functions are also accessible as services to applications running on the TOE allowing application developers to ensure their application meets the required criteria to remain compliant with MDFPP standards.</span></p>\r\n<p class=\"MsoNormal\" style=\"text-align: justify; mso-outline-level: 1;\"><strong>User data protection:</strong></p>\r\n<p class=\"Standard\" style=\"margin-bottom: 6.0pt; text-align: justify; mso-pagination: widow-orphan;\"><span style=\"font-family: 'Times',serif; mso-fareast-font-family: Times; color: black;\">The TOE controls access to system services by hosted applications, including protection of the Trust Anchor Database. Additionally, the TOE protects user and other sensitive data using encryption so that even if a device is physically lost, the data remains protected. The TOE&rsquo;s evaluated configuration supports Android Enterprise profiles to provide additional separation between application and application data belonging to the Enterprise profile.<span style=\"mso-spacerun: yes;\">&nbsp; </span>Please see the Admin Guide for additional details regarding how to set up and use Enterprise profiles.</span></p>\r\n<p class=\"MsoNormal\" style=\"text-align: justify; mso-outline-level: 1;\"><strong>Identification and authentication:</strong></p>\r\n<p class=\"Standard\" style=\"margin-bottom: 6.0pt; text-align: justify; mso-pagination: widow-orphan;\"><span style=\"font-family: 'Times',serif; mso-fareast-font-family: Times; color: black;\">The TOE supports a number of features related to identification and authentication. From a user perspective, except for FCC mandated (making phone calls to an emergency number) or non-sensitive functions (e.g., choosing the keyboard input method or taking screen shots), a password (i.e., Password Authentication Factor) must be correctly entered to unlock the TOE. Also, even when unlocked, the TOE requires the user re-enter the password to change the password.<span style=\"mso-spacerun: yes;\">&nbsp; </span>Passwords are obscured when entered so they cannot be read from the TOE's display and the frequency of entering passwords is limited.<span style=\"mso-spacerun: yes;\">&nbsp; </span>When a configured number of failures occurs, the TOE will be wiped to protect its contents.<span style=\"mso-spacerun: yes;\">&nbsp; </span>Passwords can be constructed using upper and lower cases characters, numbers, and special characters and passwords up to 16 characters are supported.</span></p>\r\n<p class=\"Standard\" style=\"margin-bottom: 6.0pt; text-align: justify; mso-pagination: widow-orphan;\"><span style=\"font-family: 'Times',serif; mso-fareast-font-family: Times; color: black;\">The TOE can also serve as an 802.1X supplicant and can both use and validate X.509v3 certificates for EAP-TLS, TLS, and HTTPS exchanges.</span></p>\r\n<p class=\"MsoNormal\" style=\"text-align: justify; mso-outline-level: 1;\"><strong>Security management:</strong></p>\r\n<p class=\"Standard\" style=\"margin-bottom: 6.0pt; text-align: justify; mso-pagination: widow-orphan;\"><span style=\"font-family: 'Times',serif; mso-fareast-font-family: Times; color: black;\">The TOE provides all the interfaces necessary to manage the security functions identified throughout the Security Target as well as other functions commonly found in mobile devices. Many of the functions are available to users of the TOE while many are restricted to administrators operating through a Mobile Device Management solution once the TOE has been enrolled.</span></p>\r\n<p class=\"MsoNormal\" style=\"text-align: justify; mso-outline-level: 1;\"><strong>Protection of the TSF:</strong></p>\r\n<p class=\"Standard\" style=\"margin-bottom: 6.0pt; text-align: justify; mso-pagination: widow-orphan;\"><span style=\"font-family: 'Times',serif; mso-fareast-font-family: Times; color: black;\">The TOE implements a number of features to protect itself to ensure the reliability and integrity of its security features. It protects particularly sensitive data such as cryptographic keys so that they are not accessible or exportable through the use of the application processor&rsquo;s hardware.<span style=\"mso-spacerun: yes;\">&nbsp; </span>The TOE disallows all read access to the REK and retains all keys derived from the REK within its Trusted Execution Environment (TEE).<span style=\"mso-spacerun: yes;\">&nbsp; </span>Application software can only use keys derived from the REK by reference and receive the result.</span></p>\r\n<p class=\"Standard\" style=\"margin-bottom: 6.0pt; text-align: justify; mso-pagination: widow-orphan;\"><span style=\"font-family: 'Times',serif; mso-fareast-font-family: Times; color: black;\">The TOE also provides its own timing mechanism to ensure that reliable time information is available (e.g., for log accountability). It enforces read, write, and execute memory page protections, uses address space layout randomization, and stack-based buffer overflow protections to minimize the potential to exploit application flaws. It also protects itself from modification by applications as well as isolates the address spaces of applications from one another to protect those applications.</span></p>\r\n<p class=\"Standard\" style=\"margin-bottom: 6.0pt; text-align: justify; mso-pagination: widow-orphan;\"><span style=\"font-family: 'Times',serif; mso-fareast-font-family: Times; color: black;\">The TOE includes functions to perform self-tests and software/firmware integrity checking so that it might detect when it is failing or may be corrupt. If any self-tests fail, the TOE will not go into an operational mode. It also includes mechanisms (i.e., verification of the digital signature of each new image) so that the TOE itself can be updated while ensuring that the updates will not introduce malicious or other unexpected changes in the TOE. Digital signature checking also extends to verifying applications prior to their installation as all applications must have signatures (even if self-signed).</span></p>\r\n<p class=\"MsoNormal\" style=\"text-align: justify; mso-outline-level: 1;\"><strong>TOE access:</strong></p>\r\n<p class=\"Standard\" style=\"margin-bottom: 6.0pt; text-align: justify; mso-pagination: widow-orphan;\"><span style=\"font-family: 'Times',serif; mso-fareast-font-family: Times; color: black;\">The TOE can be locked, obscuring its display, by the user or after a configured interval of inactivity. The TOE also has the capability to display an administrator-specified (using the TOE&rsquo;s MDM API) advisory message (banner) when the user unlocks the TOE for the first use after reboot.</span></p>\r\n<p class=\"Standard\" style=\"margin-bottom: 6.0pt; text-align: justify; mso-pagination: widow-orphan;\"><span style=\"font-family: 'Times',serif; mso-fareast-font-family: Times; color: black;\">The TOE is also able to attempt to connect to wireless networks as configured.</span></p>\r\n<p class=\"MsoNormal\" style=\"text-align: justify; mso-outline-level: 1;\"><strong>Trusted path/channels:</strong></p>\r\n<p class=\"Standard\" style=\"margin-bottom: 6.0pt; text-align: justify; mso-pagination: widow-orphan;\"><span style=\"font-family: 'Times',serif; mso-fareast-font-family: Times; color: black;\">The TOE supports the use of IEEE 802.11-2012, 802.1X, and EAP-TLS and TLS, HTTPS to secure communications channels between itself and other trusted network devices.</span></p>","features":[]}