{"product_id":11399,"v_id":11399,"product_name":"KLC Group LLC CipherDriveOne Kryptr 1.1.0","certification_status":"Certified","certification_date":"2024-04-29T00:00:00Z","tech_type":"Encrypted Storage","vendor_id":{"name":"KLC Group LLC","website":"https://www.klc-group.com/"},"vendor_poc":"Kurt Lennartsson","vendor_phone":"+1-408-614-1414","vendor_email":"kurt@klc-group.com","assigned_lab":{"cctl_name":"Lightship Security USA, Inc."},"product_description":"<p class=\"MsoNormal\" style=\"text-align: justify;\">The <span style=\"mso-bidi-font-weight: bold;\">KLC Group LLC CipherDriveOne Kryptr 1.1.0 Target of Evaluation (TOE) is software that </span>provides full disk encryption including pre-boot user authentication, chain-boot to the host Operating System (OS) and management capabilities to control user access and settings. It applies full drive encryption to protect all locally stored data from unauthorized access, loss, and exposure in the event a protected device is lost or stolen. The TOE has two distinct modules:</p>\r\n<p class=\"MsoListParagraphCxSpFirst\" style=\"text-align: justify; text-indent: -0.25in; padding-left: 40px;\"><!-- [if !supportLists]--><span style=\"mso-fareast-font-family: 'Times New Roman';\"><span style=\"mso-list: Ignore;\">a)<span style=\"font: 7.0pt 'Times New Roman';\">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; </span></span></span><!--[endif]-->PBA / Management module.<span style=\"mso-spacerun: yes;\">&nbsp; </span>Provides pre-boot authentication and TOE configuration services.</p>\r\n<p class=\"MsoListParagraphCxSpLast\" style=\"text-align: justify; text-indent: -0.25in; padding-left: 40px;\"><!-- [if !supportLists]--><span style=\"mso-fareast-font-family: 'Times New Roman';\"><span style=\"mso-list: Ignore;\">b)<span style=\"font: 7.0pt 'Times New Roman';\">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; </span></span></span><!--[endif]-->Encryption Engine / Driver. Disk encryption for Linux and Windows Operating Systems.</p>","evaluation_configuration":"<p class=\"Body\">The evaluated configuration encompasses the KLC Group LLC CipherDriveOne Kryptr 1.1.0 software (including Linux Kernel 5.15).</p>","security_evaluation_summary":"<p class=\"MsoNormal\" style=\"text-align: justify;\">The evaluation was carried out in accordance with the Common Criteria Evaluation and Validation Scheme (CCEVS) process and scheme. The evaluation demonstrated that the product meets the security requirements contained in the Security Target. The criteria against which the <span style=\"mso-bidi-font-weight: bold;\">KLC Group LLC CipherDriveOne Kryptr 1.1.0</span> was evaluated are described in the Common Criteria for Information Technology Security Evaluation, Version 3.1, Revision 5, April 2017. The evaluation methodology used by the evaluation team to conduct the evaluation is the Common Methodology for Information Technology Security Evaluation, Version 3.1, Revision 5, April 2017. The product, when delivered and configured as identified in the <em><span style=\"mso-bidi-font-weight: bold;\">KLC Group LLC CipherDriveOne Kryptr 1.1.0</span> Common Criteria Guide</em>, Version 1.1, April 2024, satisfies all the security functional requirements stated in the <em><span style=\"mso-bidi-font-weight: bold;\">KLC Group LLC CipherDriveOne Kryptr 1.1.0</span> Security Target</em>, Version 1.5, April 2024. The project underwent CCEVS Validator review. The evaluation was completed in April 2024. Results of the evaluation can be found in the Common Criteria Evaluation and Validation Scheme Validation Report (report number CCEVS-VR-11399-2024) prepared by CCEVS.</p>","environmental_strengths":"<p class=\"MsoNormal\" style=\"text-align: justify;\">The TOE provides the following security functions:</p>\r\n<p class=\"MsoNormal\" style=\"text-align: justify;\">&nbsp;</p>\r\n<p class=\"MsoNormal\" style=\"text-align: justify;\"><strong style=\"mso-bidi-font-weight: normal;\">User Data Protection</strong></p>\r\n<p class=\"MsoNormal\" style=\"text-align: justify;\">The TOE performs full drive encryption on all storage devices to protect data from unauthorized disclosure in the event of loss or theft of the device. All protected data is encrypted by default without user intervention and with NIST approved algorithms.</p>\r\n<p class=\"MsoNormal\" style=\"text-align: justify;\">&nbsp;</p>\r\n<p class=\"MsoNormal\" style=\"text-align: justify;\"><strong style=\"mso-bidi-font-weight: normal;\">Security Management</strong></p>\r\n<p class=\"MsoNormal\" style=\"text-align: justify;\">The TOE provides dedicated interfaces for the management of its security functions. Access to these management functions can be controlled by way of role-based group assignment to administrative users.</p>\r\n<p class=\"MsoNormal\" style=\"text-align: justify;\">&nbsp;</p>\r\n<p class=\"MsoNormal\" style=\"text-align: justify;\"><strong style=\"mso-bidi-font-weight: normal;\">Protection of the TSF</strong></p>\r\n<p class=\"MsoNormal\" style=\"text-align: justify;\">The TOE ensures the authenticity and integrity of software updates by verifying their digital signatures prior to installation. Various software and cryptographic self-tests are performed at start-up to ensure the secure and correct operation of the TOE. <span style=\"mso-bidi-font-weight: bold;\">All keying material used for storage encryption is securely generated and protected from disclosure. </span></p>\r\n<p class=\"MsoNormal\" style=\"text-align: justify;\">&nbsp;</p>\r\n<p class=\"MsoNormal\" style=\"text-align: justify;\"><strong style=\"mso-bidi-font-weight: normal;\">Cryptographic Support</strong></p>\r\n<p class=\"MsoNormal\" style=\"text-align: justify;\">The TOE performs cryptographic operations, which are tested via relevant Cryptographic Algorithm Validation Program (CAVP) certificates. <span style=\"mso-bidi-font-weight: bold;\">Secure destruction of cryptographic keys and keying material is implemented and occurs during transition to a compliant power saving state, or when the key or keying material is no longer needed.</span></p>","features":[{"id":2992,"feature_name":"Cryptographic Hashing"},{"id":2991,"feature_name":"Cryptographic Signature Verification"},{"id":2986,"feature_name":"DRBG"},{"id":2982,"feature_name":"Full Drive Encryption"},{"id":2984,"feature_name":"Key Destruction"},{"id":2993,"feature_name":"Keyed-hash message authentication"},{"id":2988,"feature_name":"Symmetric Key Generation"}]}