{"product_id":11471,"v_id":11471,"product_name":"Crestron DigitalMedia NVX®AV-over-IP v7.1","certification_status":"Certified","certification_date":"2024-10-09T00:00:00Z","tech_type":"Network Device","vendor_id":{"name":"Crestron Electronics, Inc","website":"https://www.crestron.com"},"vendor_poc":"Monica Reagor","vendor_phone":"1-888-CRESTRON","vendor_email":"securitydocs@crestron.com","assigned_lab":{"cctl_name":"Leidos Common Criteria Testing Laboratory"},"product_description":"<p style=\"margin: 0in 0in 6pt; text-align: justify; font-size: 10pt; font-family: 'Times New Roman', serif;\"><span style=\"font-size: 11.0pt; font-family: Calibri, sans-serif;\">The TOE is a digital video and audio distribution network device that switches 4K video sources and displays at 60 frames per second (fps) with full 4:4:4 color sampling, High Dynamic Range (HDR) video support, standard 1-Gigabit Ethernet infrastructure, and Pixel Perfect Processing technology to provide video transport in all applications. The digital video and audio transport and encoding/decoding are not evaluated.</span></p>\r\n<p style=\"margin: 0in 0in 6pt; text-align: justify; font-size: 10pt; font-family: 'Times New Roman', serif;\"><span style=\"font-size: 11.0pt; font-family: Calibri, sans-serif;\">For the purpose of this evaluation, the TOE is treated as a network device offering NIST validated cryptographic functions, security auditing, secure administration, trusted updates, self-tests, and secure connections to other servers (e.g., to export audit records), protected using HTTPS/TLS and SSH. </span></p>\r\n<p style=\"margin: 0in 0in 6pt; text-align: justify; font-size: 10pt; font-family: 'Times New Roman', serif;\"><span style=\"font-size: 11.0pt; font-family: Calibri, sans-serif;\">Cryptographic functionality is performed by the TOE&rsquo;s &lsquo;Crestron Crypto Kernel for Open SSL&rsquo; software module that includes third-party SafeLogic OpenSSL in support of higher level protocols (TLS, SSH). The module&rsquo;s FIPS-Approved cryptographic algorithms have obtained CAVP certificates.</span></p>\r\n<p style=\"margin: 0in 0in 6pt; text-align: justify; font-size: 10pt; font-family: 'Times New Roman', serif;\"><span style=\"font-size: 11.0pt; font-family: Calibri, sans-serif;\">The TOE audits security relevant events, stores audit records locally, and can be configured to forward its audit records to an external syslog server in the network environment. An administrator can configure the TOE to solicit time from an NTP server, and alternatively the administrator can manually set the TOE&rsquo;s time.</span></p>\r\n<p style=\"margin: 0in 0in 6pt; text-align: justify; font-size: 10pt; font-family: 'Times New Roman', serif;\"><span style=\"font-size: 11.0pt; font-family: Calibri, sans-serif;\">The TOE uses TLS to protect communications with an external syslog server, offers a management GUI protected by TLS/HTTPS, and provides a management Command Line Interface (CLI) protected by SSH. </span></p>\r\n<p style=\"margin: 0in 0in 6pt; text-align: justify; font-size: 10pt; font-family: 'Times New Roman', serif;\"><span style=\"font-size: 11.0pt; font-family: Calibri, sans-serif;\">Administrators are able to query the current version of the product firmware and manage the security functions of the TOE, including performing updates on the product. Public/private keys are used to provide digital signatures for protection of the update files.</span></p>\r\n<p style=\"margin: 0in 0in 6pt; text-align: justify; font-size: 10pt; font-family: 'Times New Roman', serif;\"><span style=\"font-size: 11.0pt; font-family: Calibri, sans-serif;\">The TOE provides self-tests to ensure the integrity and correct operation of the TOE. </span></p>","evaluation_configuration":"<p style=\"margin: 0in 0in 6pt; text-align: justify; font-size: 10pt; font-family: 'Times New Roman', serif;\"><span style=\"font-size: 11.0pt; font-family: Calibri, sans-serif;\">The TOE includes the following appliance models, each with firmware version 7.1.5259.00081:</span></p>\r\n<ul style=\"margin-bottom: 0in; margin-top: 0px;\">\r\n<li style=\"margin: 0in 0in 6pt 0px; text-align: justify; font-size: 10pt; font-family: 'Times New Roman', serif;\"><span style=\"font-size: 11.0pt; font-family: Calibri, sans-serif;\">DM-NVX-E10</span></li>\r\n<li style=\"margin: 0in 0in 6pt 0px; text-align: justify; font-size: 10pt; font-family: 'Times New Roman', serif;\"><span style=\"font-size: 11.0pt; font-family: Calibri, sans-serif;\">DM-NVX-E20</span></li>\r\n<li style=\"margin: 0in 0in 6pt 0px; text-align: justify; font-size: 10pt; font-family: 'Times New Roman', serif;\"><span style=\"font-size: 11.0pt; font-family: Calibri, sans-serif;\">DM-NVX-E20-2G</span></li>\r\n<li style=\"margin: 0in 0in 6pt 0px; text-align: justify; font-size: 10pt; font-family: 'Times New Roman', serif;\"><span style=\"font-size: 11.0pt; font-family: Calibri, sans-serif;\">DM-NVX-E30</span></li>\r\n<li style=\"margin: 0in 0in 6pt 0px; text-align: justify; font-size: 10pt; font-family: 'Times New Roman', serif;\"><span style=\"font-size: 11.0pt; font-family: Calibri, sans-serif;\">DM-NVX-E30C</span></li>\r\n<li style=\"margin: 0in 0in 6pt 0px; text-align: justify; font-size: 10pt; font-family: 'Times New Roman', serif;\"><span style=\"font-size: 11.0pt; font-family: Calibri, sans-serif;\">DM-NVX-E760</span></li>\r\n<li style=\"margin: 0in 0in 6pt 0px; text-align: justify; font-size: 10pt; font-family: 'Times New Roman', serif;\"><span style=\"font-size: 11.0pt; font-family: Calibri, sans-serif;\">DM-NVX-E760C</span></li>\r\n<li style=\"margin: 0in 0in 6pt 0px; text-align: justify; font-size: 10pt; font-family: 'Times New Roman', serif;\"><span style=\"font-size: 11.0pt; font-family: Calibri, sans-serif;\">DM-NVX-D10</span></li>\r\n<li style=\"margin: 0in 0in 6pt 0px; text-align: justify; font-size: 10pt; font-family: 'Times New Roman', serif;\"><span style=\"font-size: 11.0pt; font-family: Calibri, sans-serif;\">DM-NVX-D20</span></li>\r\n<li style=\"margin: 0in 0in 6pt 0px; text-align: justify; font-size: 10pt; font-family: 'Times New Roman', serif;\"><span style=\"font-size: 11.0pt; font-family: Calibri, sans-serif;\">DM-NVX-D30</span></li>\r\n<li style=\"margin: 0in 0in 6pt 0px; text-align: justify; font-size: 10pt; font-family: 'Times New Roman', serif;\"><span style=\"font-size: 11.0pt; font-family: Calibri, sans-serif;\">DM-NVX-D30C</span></li>\r\n<li style=\"margin: 0in 0in 6pt 0px; text-align: justify; font-size: 10pt; font-family: 'Times New Roman', serif;\"><span style=\"font-size: 11.0pt; font-family: Calibri, sans-serif;\">DM-NVX-D200</span></li>\r\n<li style=\"margin: 0in 0in 6pt 0px; text-align: justify; font-size: 10pt; font-family: 'Times New Roman', serif;\"><span style=\"font-size: 11.0pt; font-family: Calibri, sans-serif;\">DM-NVX-D80-IOAV</span></li>\r\n<li style=\"margin: 0in 0in 6pt 0px; text-align: justify; font-size: 10pt; font-family: 'Times New Roman', serif;\"><span style=\"font-size: 11.0pt; font-family: Calibri, sans-serif;\">DM-NVX-350</span></li>\r\n<li style=\"margin: 0in 0in 6pt 0px; text-align: justify; font-size: 10pt; font-family: 'Times New Roman', serif;\"><span style=\"font-size: 11.0pt; font-family: Calibri, sans-serif;\">DM-NVX-350C</span></li>\r\n<li style=\"margin: 0in 0in 6pt 0px; text-align: justify; font-size: 10pt; font-family: 'Times New Roman', serif;\"><span style=\"font-size: 11.0pt; font-family: Calibri, sans-serif;\">DM-NVX-351</span></li>\r\n<li style=\"margin: 0in 0in 6pt 0px; text-align: justify; font-size: 10pt; font-family: 'Times New Roman', serif;\"><span style=\"font-size: 11.0pt; font-family: Calibri, sans-serif;\">DM-NVX-351C</span></li>\r\n<li style=\"margin: 0in 0in 6pt 0px; text-align: justify; font-size: 10pt; font-family: 'Times New Roman', serif;\"><span style=\"font-size: 11.0pt; font-family: Calibri, sans-serif;\">DM-NVX-352</span></li>\r\n<li style=\"margin: 0in 0in 6pt 0px; text-align: justify; font-size: 10pt; font-family: 'Times New Roman', serif;\"><span style=\"font-size: 11.0pt; font-family: Calibri, sans-serif;\">DM-NVX-352C</span></li>\r\n<li style=\"margin: 0in 0in 6pt 0px; text-align: justify; font-size: 10pt; font-family: 'Times New Roman', serif;\"><span style=\"font-size: 11.0pt; font-family: Calibri, sans-serif;\">DM-NVX-360</span></li>\r\n<li style=\"margin: 0in 0in 6pt 0px; text-align: justify; font-size: 10pt; font-family: 'Times New Roman', serif;\"><span style=\"font-size: 11.0pt; font-family: Calibri, sans-serif;\">DM-NVX-360C</span></li>\r\n<li style=\"margin: 0in 0in 6pt 0px; text-align: justify; font-size: 10pt; font-family: 'Times New Roman', serif;\"><span style=\"font-size: 11.0pt; font-family: Calibri, sans-serif;\">DM-NVX-363</span></li>\r\n<li style=\"margin: 0in 0in 6pt 0px; text-align: justify; font-size: 10pt; font-family: 'Times New Roman', serif;\"><span style=\"font-size: 11.0pt; font-family: Calibri, sans-serif;\">DM-NVX-363C.</span></li>\r\n</ul>\r\n<p style=\"margin: 0in 0in 6pt; font-size: 12pt; font-family: 'Times New Roman', serif; color: black;\"><span style=\"font-size: 11.0pt; font-family: Calibri, sans-serif;\">Each appliance contains an Intel Arria 10 SX SoC FPGA that includes an ARM Cortex-A9 MPCore processor implementing the ARMv7-A microarchitecture. &ldquo;C&rdquo; indicates that the model is a form factor with a chassis card.</span></p>","security_evaluation_summary":"<p style=\"margin: 0in 0in 6pt; font-size: 12pt; font-family: 'Times New Roman', serif; color: black;\"><span style=\"font-size: 11.0pt; font-family: Calibri, sans-serif;\">The evaluation was carried out in accordance with the Common Criteria Evaluation and Validation Scheme (CCEVS) requirements and guidance. The evaluation demonstrated that the TOE<em>&nbsp;</em>meets the security requirements contained in the Security Target.&nbsp; The criteria against which the TOE was judged are described in <em>Common Criteria for Information Technology Security Evaluation</em>, Version 3.1 rev 5.&nbsp;The evaluation methodology used by the evaluation team to conduct the evaluation is <em>Common Methodology for Information Technology Security Evaluation</em>, Version 3.1 revision 5. The product, when delivered and configured as identified in the <em>DigitalMedia NVX&reg; AV-over-IP v7.1 Common Criteria Evaluated Configuration Guide (CCECG)</em>, Version 1.0, October 4, 2024, satisfies all the security functional requirements stated in the&nbsp;<em>Crestron DigitalMedia NVX&reg; AV-over-IP v7.1 Security Target</em>, Version 1.0, October 3, 2024. The project underwent CCEVS Validator review.&nbsp;The evaluation was completed in October 2024.&nbsp;Results of the evaluation can be found in the Common Criteria Evaluation and Validation Scheme Validation Report (report number CCEVS-VR-VID11471-2024) prepared by CCEVS.</span></p>","environmental_strengths":"<p><strong><em>Security Audit</em></strong></p>\r\n<p>The TOE generates audit events associated with identification and authentication, management, updates, and user sessions. The TOE can store the events in a local log and export them to a syslog server using a TLS protected channel.</p>\r\n<p><strong><em>Cryptographic Support</em></strong></p>\r\n<p>The TOE provides CAVP certified cryptography in support of its SSH, TLS, and NTP implementations and for verifying TOE update package signatures. Cryptographic services include key management, random bit generation, symmetric encryption and decryption, digital signature, and secure hashing.</p>\r\n<p><strong><em>Identification and Authentication</em></strong></p>\r\n<p>The TOE requires users to be identified and authenticated before they can use functions mediated by the TOE, with the exception of reading the login banner. The TOE authenticates a user&rsquo;s credentials (password, key) using a local mechanism provided by the TOE. The TOE also provides X.509 certificate checking for its TLS connections.</p>\r\n<p><strong><em>Security Management</em></strong></p>\r\n<p>The TOE provides CLI and web-based management interfaces that an administrator can access remotely via a network port. The CLI can also be accessed locally by directly connecting to a network port and using SSH. Remote connections to the management interface are protected with SSH for the CLI and HTTPS for the GUI. The management interface is limited to the authorized administrator.</p>\r\n<p><strong><em>Protection of the TSF</em></strong></p>\r\n<p>The TOE implements various self-protection mechanisms. The TOE performs self-tests that cover the correct operation of the TOE. It provides functions necessary to securely update the TOE. It relies upon either manually provided time or an NTP server in its environment to ensure reliable timestamps. It protects sensitive data such as passwords and cryptographic keys stored on the TOE&rsquo;s internal Flash so that they are not accessible even by an authorized administrator.</p>\r\n<p><strong><em>TOE Access</em></strong></p>\r\n<p>The TOE will terminate local and remote interactive sessions after a configurable period of inactivity. The TOE additionally provides the capability for administrators to terminate their own interactive sessions. The TOE can be configured to display an advisory and consent warning message before establishing a user session.</p>\r\n<p><strong><em>Trusted Path/Channels</em></strong></p>\r\n<p>The TOE provides local administration which is subject to physical protection. To access the TOE locally, an administrator must directly connect their workstation to a network port and use SSH and successfully login. When accessed remotely, the CLI and GUI management interfaces are protected by SSH and TLS respectively, thus ensuring protection against modification and disclosure.</p>\r\n<p>The TOE protects communications with the external syslog servers from modification and disclosure by using TLS.</p>","features":[{"id":2744,"feature_name":"Asymmetric Key Generation"},{"id":2740,"feature_name":"Auditing"},{"id":2760,"feature_name":"Certificate Authentication"},{"id":2750,"feature_name":"Certificate Validation"},{"id":2747,"feature_name":"Cryptographic Hashing"},{"id":2745,"feature_name":"Cryptographic Key Establishment"},{"id":2746,"feature_name":"Cryptographic Signature Verification"},{"id":2742,"feature_name":"DRBG"},{"id":2758,"feature_name":"HTTPS Client"},{"id":2759,"feature_name":"HTTPS Server without Mutual Authentication"},{"id":2741,"feature_name":"Key Destruction"},{"id":2748,"feature_name":"Keyed-hash message authentication"},{"id":2757,"feature_name":"SSH Server"},{"id":2762,"feature_name":"TLS 1.2"},{"id":2753,"feature_name":"TLS Client"},{"id":2755,"feature_name":"TLS Server without Mutual Authentication"},{"id":2743,"feature_name":"Virtual Network Device"}]}