{"product_id":11629,"v_id":11628,"product_name":"Shift5, Inc. Software Full Drive Encryption","certification_status":"Certified","certification_date":"2025-10-31T00:00:00Z","tech_type":"Encrypted Storage","vendor_id":{"name":"Shift5, Inc.","website":"https://www.shift5.io"},"vendor_poc":"Jeremy Turbyfill","vendor_phone":"850-572-4738","vendor_email":"jeremy.turbyfill@shift5.io","assigned_lab":{"cctl_name":"Gossamer Security Solutions"},"product_description":"<p><span style=\"font-size: 10.0pt; font-family: Times, serif;\"><span style=\"font-size: 10.0pt; mso-bidi-font-size: 12.0pt; font-family: 'Times',serif; mso-fareast-font-family: 'Times New Roman'; mso-bidi-font-family: 'Times New Roman'; mso-ansi-language: EN-US; mso-fareast-language: EN-US; mso-bidi-language: AR-SA;\">The Target of Evaluation (TOE) is Shift5, Inc. Software Full Drive Encryption (Shift5 SW FDE) version 1.2.3. The Shift5, Inc. <span style=\"mso-no-proof: yes;\">Software Full Drive Encryption</span> is a software package that Shift5 integrates into its software images running on their Manifold product line.<span style=\"mso-spacerun: yes;\">&nbsp; </span>These products possess a computing system running SUSE Linux Micro 6.0.<span style=\"mso-spacerun: yes;\">&nbsp; </span>The Product provides full drive encryption of its removable USB data drive and accepts an administratively provided passphrase to unlock the drive.<span style=\"mso-spacerun: yes;\">&nbsp; </span>After receiving the passphrase (the authorization factor), the Product validates the passphrase, and if correct, utilizes it to decrypt the Data Encryption Key ultimately used to encrypt/decrypt derive the data on the removable drive.<span style=\"mso-spacerun: yes;\">&nbsp; </span>The Product also uses its SW FDE to additionally encrypt/protect the system/boot drive within the Manifold; however, this application of the FDE does not comply with the FDE protection profile requirements as the Manifold uses its TPM to unlock at boot&mdash;as opposed to using an administratively supplied password at each boot.<span style=\"mso-spacerun: yes;\">&nbsp; </span>As a result, this evaluation focuses on the FDE protection of the removable drive</span>.</span></p>","evaluation_configuration":"<p><span style=\"font-size: 10.0pt; font-family: 'Times New Roman', serif;\">The Target of Evaluation (TOE) is Shift5, Inc. Software Full Drive Encryption (Shift5 SW FDE) version 1.2.3.</span></p>","security_evaluation_summary":"<p><span style=\"font-size: 10.0pt; font-family: Times, serif;\">The evaluation was carried out in accordance to the Common Criteria Evaluation and Validation Scheme (CCEVS) requirements and guidance.&nbsp; The evaluation demonstrated that the TOE<em> </em>meets the security requirements contained in the Security Target.&nbsp; The criteria against which the TOE was judged are described in the Common Criteria for Information Technology Security Evaluation, Version 3.1, Revision 5, April 2017. The evaluation methodology used by the evaluation team to conduct the evaluation is the Common Methodology for Information Technology Security Evaluation, Evaluation Methodology, Version 3.1, Revision 5, April 2017.&nbsp; The product, when delivered and configured as identified in the Shift5 Shift5 &ndash; Full Disk Encryption (FDE) Administrator Guidance Document, August 19, 2025 document, satisfies all of the security functional requirements stated in the Shift5, Inc. Software Full Drive Encryption Security Target, Version 0.3, September 24, 2025.&nbsp; The project underwent CCEVS Validator review.&nbsp; The evaluation was completed in September 2025.&nbsp; Results of the evaluation can be found in the Common Criteria Evaluation and Validation Scheme Validation Report (report number CCEVS-VR-VID11628-2025) prepared by CCEVS</span></p>","environmental_strengths":"<p style=\"text-align: justify; margin: 0in; font-size: 10pt; font-family: Times, serif;\">The logical boundaries of the Shift5, Inc. Software Full Drive Encryption are realized in the security functions that it implements. Each of these security functions is summarized below.</p>\r\n<p style=\"margin: 0in; font-size: 10pt; font-family: Times, serif;\">&nbsp;</p>\r\n<p style=\"text-align: justify; margin: 0in; font-size: 10pt; font-family: Times, serif;\"><strong>Cryptographic support:</strong></p>\r\n<p style=\"margin: 0in 0in 6pt; text-align: justify; line-height: 11pt; font-size: 10pt; font-family: Times, serif;\"><span style=\"font-family: 'Times New Roman', serif;\">The TOE includes cryptographic functionality for key management, user authentication, and block-based encryption including: symmetric key generation, encryption/decryption, cryptographic hashing, keyed-hash message authentication, and password-based key derivation. These functions are supported with suitable random bit generation, key derivation, salt generation, initialization vector generation, secure key storage, and key destruction. These primitive cryptographic functions are used to encrypt Data-At-Rest (including the generation and protection of keys and key encryption keys) used by the TOE.</span></p>\r\n<p style=\"text-align: justify; margin: 0in; font-size: 10pt; font-family: Times, serif;\"><strong>User data protection:</strong></p>\r\n<p style=\"margin: 0in 0in 6pt; text-align: justify; line-height: 11pt; font-size: 10pt; font-family: Times, serif;\"><span style=\"font-family: 'Times New Roman', serif;\">The TOE performs Full Drive Encryption on all partitions on the removable drive (so that no plaintext exists) and does so without user intervention.</span></p>\r\n<p style=\"text-align: justify; margin: 0in; font-size: 10pt; font-family: Times, serif;\"><strong>Security management:</strong></p>\r\n<p style=\"margin: 0in 0in 6pt; text-align: justify; line-height: 11pt; font-size: 10pt; font-family: Times, serif;\"><span style=\"font-family: 'Times New Roman', serif;\">The TOE provides each of required management services to manage the full drive encryption using a locally accessed Web User Interface (WebUI).</span></p>\r\n<p style=\"text-align: justify; margin: 0in; font-size: 10pt; font-family: Times, serif;\"><strong>Protection of the TSF:</strong></p>\r\n<p><span style=\"font-size: 10.0pt; font-family: 'Times New Roman', serif;\">The TOE implements a number of features to protect itself to ensure the reliability and integrity of its security features. It protects key and key material, and includes functions to perform self-tests and software/firmware integrity checking so that it might detect when it is failing or may be corrupt.&nbsp; If any of the self-tests fail, the TOE will not go into an operational mode.</span></p>","features":[{"id":1902,"feature_name":"Cryptographic Hashing"},{"id":1901,"feature_name":"Cryptographic Signature Verification"},{"id":1899,"feature_name":"DRBG"},{"id":1897,"feature_name":"Full Drive Encryption"},{"id":1898,"feature_name":"Key Destruction"},{"id":1903,"feature_name":"Keyed-hash message authentication"},{"id":1900,"feature_name":"Symmetric Key Generation"}]}