{"product_id":11170,"v_id":11170,"product_name":"Perspecta Labs SecureIO v2.0.4","certification_status":"Certified","certification_date":"2021-07-12T00:00:00Z","tech_type":"Application Software","vendor_id":{"name":"Perspecta Labs","website":"https://www.peratonlabs.com/secureio.html"},"vendor_poc":"Eric Jung","vendor_phone":"908-748-2684","vendor_email":"ejung@perspectalabs.com","assigned_lab":{"cctl_name":"Acumen Security"},"product_description":"<p class=\"MsoNormal\">The SecureIO application provides a secure communication channel for Android applications by transmitting and receiving network traffic over a secure TLS channel. The traffic is protected in transit using TLS between the Android device and a TLS server.</p>\r\n<p class=\"MsoNormal\">The functionality of the SecureIO service is limited to (i) establishing and shutting down a TLS connection to the Transport Layer Gateway (TLG); (ii) sending and receiving messages to and from the TLG on behalf of Android apps via the TLS connection.</p>\r\n<p class=\"MsoNormal\">The TOE runs on Android versions 8.0, 9.0, and 10.0. All sub-versions of 8.0 (e.g. 8.1.0), 9.0 and 10.0 are supported.</p>","evaluation_configuration":"","security_evaluation_summary":"<p>The evaluation was carried out in accordance with the Common Criteria Evaluation and Validation Scheme (CCEVS) process and scheme. The criteria against which the Perspecta Labs SecureIO v2.0.4 was evaluated are described in the Common Criteria for Information Technology Security Evaluation, Version 3.1 rev 5.&nbsp; The evaluation methodology used by the evaluation team to conduct the evaluation is the Common Methodology for Information Technology Security Evaluation, Version 3.1 rev 5.&nbsp; The product, when delivered configured as identified in the <em>Perspecta Labs SecureIO User Manual, Version 2.0.4</em>, Issue 6, June 2021, satisfies all of the security functional requirements stated in the <em>Perspecta Labs SecureIO v2.0.4 Security Target</em>, Version 0.8, June 30, 2021. The project underwent CCEVS Validator review.&nbsp; The evaluation was completed in July 2021.&nbsp; Results of the evaluation can be found in the Common Criteria Evaluation and Validation Scheme Validation Report (report number CCEVS-VR-VID11170-2021) prepared by CCEVS.</p>","environmental_strengths":"<p class=\"MsoNormal\">The TOE provides the security functionality required by the Protection Profile for Application Software Version 1.3 [SWAPP].</p>\r\n<h4 style=\"margin-left: 0in; text-indent: 0in; mso-list: none; tab-stops: .5in;\"><a name=\"_Toc51964691\"></a><span style=\"font-family: 'Calibri',sans-serif; mso-ascii-theme-font: minor-latin; mso-hansi-theme-font: minor-latin; mso-bidi-font-family: 'Times New Roman'; mso-bidi-theme-font: major-bidi;\">Cryptographic Support</span></h4>\r\n<p class=\"MsoNormal\">The TOE relies on underlying cryptographic functionality provided by the platform for all of its cryptographic operations.</p>\r\n<h4 style=\"text-indent: 0in; mso-list: none; tab-stops: .5in; margin: 6.0pt 0in .0001pt 0in;\"><a name=\"_Toc51964692\"></a><span style=\"font-family: 'Calibri',sans-serif; mso-ascii-theme-font: minor-latin; mso-hansi-theme-font: minor-latin; mso-bidi-font-family: 'Times New Roman'; mso-bidi-theme-font: major-bidi;\">User Data Protection</span></h4>\r\n<p class=\"MsoNormal\">The TOE is a TLS proxy that encrypts data sent by other applications on its host platform.</p>\r\n<h4 style=\"margin-left: 0in; text-indent: 0in; mso-list: none; tab-stops: .5in;\"><a name=\"_Toc51964693\"></a><span style=\"font-family: 'Calibri',sans-serif; mso-ascii-theme-font: minor-latin; mso-hansi-theme-font: minor-latin; mso-bidi-font-family: 'Times New Roman'; mso-bidi-theme-font: major-bidi;\">Security Management</span></h4>\r\n<p class=\"MsoNormal\">The TOE does not come with any default credentials. It identifies itself to the TLS gateway that it connects to using a certificate and private key. These are provisioned onto the TOE by an administrator or end user.</p>\r\n<h4 style=\"margin-left: 0in; text-indent: 0in; mso-list: none; tab-stops: .5in;\"><a name=\"_Toc51964694\"></a><span style=\"font-family: 'Calibri',sans-serif; mso-ascii-theme-font: minor-latin; mso-hansi-theme-font: minor-latin; mso-bidi-font-family: 'Times New Roman'; mso-bidi-theme-font: major-bidi;\">Privacy</span></h4>\r\n<p class=\"MsoNormal\">The TOE itself does not contain or transmit any PII. It functions as a TLS proxy over which other applications on the platform may transmit whatever data they wish.</p>\r\n<h4 style=\"margin-left: 0in; text-indent: 0in; mso-list: none; tab-stops: .5in;\"><a name=\"_Toc51964695\"></a><span style=\"font-family: 'Calibri',sans-serif; mso-ascii-theme-font: minor-latin; mso-hansi-theme-font: minor-latin; mso-bidi-font-family: 'Times New Roman'; mso-bidi-theme-font: major-bidi;\">Protection of the TSF</span></h4>\r\n<p class=\"MsoNormal\">The TOE employs several mechanisms to ensure that it is secure on the host platform. Only documented platform APIs are used by the TOE. The TOE never allocates memory with both write and execute permission. Evaluated platform functionality is used to verify the TOE version and perform updates, and no third-party libraries are used.</p>\r\n<h4 style=\"margin-left: 0in; text-indent: 0in; mso-list: none; tab-stops: .5in;\"><a name=\"_Toc51964696\"></a><span style=\"font-family: 'Calibri',sans-serif; mso-ascii-theme-font: minor-latin; mso-hansi-theme-font: minor-latin; mso-bidi-font-family: 'Times New Roman'; mso-bidi-theme-font: major-bidi;\">Trusted Path/Channels</span></h4>\r\n<p class=\"MsoNormal\">TLS is used to protect all data transmitted to and from the TOE.</p>\r\n<h4 style=\"margin-left: 0in; text-indent: 0in; mso-list: none; tab-stops: .5in;\"><span style=\"font-family: 'Calibri',sans-serif; mso-ascii-theme-font: minor-latin; mso-hansi-theme-font: minor-latin; mso-bidi-font-family: 'Times New Roman'; mso-bidi-theme-font: major-bidi;\">Identification and Authentication</span></h4>\r\n<p class=\"MsoNormal\">Certificate validation and certificate authentication are performed by the TOE as part of TLS, in accordance with RFC 5280.</p>","features":[]}