{"product_id":11631,"v_id":11630,"product_name":"Samsung SDS EMM and EMM Agent for Android 2.2.5","certification_status":"Certified","certification_date":"2025-12-05T00:00:00Z","tech_type":"Mobility,Network Encryption","vendor_id":{"name":"Samsung SDS Co. Ltd.","website":"https://www.samsungsds.com/en/index.html"},"vendor_poc":"Dakyung Davina Kim","vendor_phone":null,"vendor_email":"dakyung.kim@samsung.com","assigned_lab":{"cctl_name":"Gossamer Security Solutions"},"product_description":"<p style=\"margin: 0in 0in 6pt; text-align: justify; line-height: 11pt; font-size: 10pt; font-family: Times, serif;\">The Target of Evaluation (TOE) is Samsung SDS EMM and EMM Agent for Android version 2.2.5.</p>\r\n<p style=\"margin: 0in 0in 6pt; text-align: justify; line-height: 11pt; font-size: 10pt; font-family: Times, serif;\">The SDS EMM provides centralized management of mobile devices and the EMM Agent for Android (installed on each device) enforces the policies of the Server on each device.</p>\r\n<p style=\"margin: 0in 0in 6pt; text-align: justify; font-size: 10pt; font-family: Times, serif;\">Samsung SDS offers the EMM as a software installation for Java 1.8 (Oracle JRE 8 or OpenJDK 8) running on the Microsoft Windows Server 2016 (64-bit), 2019 (64-bit) or 2022 (64-bit). Note that testing was conducted on Windows Server 2022 (64-bit) with Java 1.8 (OpenJDK 8) operating on hardware with an Intel Xeon E5-2660 v4 (Broadwell). Once installed, the EMM allows administrators to configure policies for devices and also serves as a Mobile Application Store (MAS) server to serve configured applications to enrolled devices.&nbsp; Administrators connect securely to the EMM using a web browser (whether local to the Server itself or remote) and through the EMM&rsquo;s web interface can enroll, audit, lock, unlock, manage, and set policies for enrolled mobile devices.&nbsp; The EMM includes the RSA Crypto-J 6.3 cryptographic module as part of its software, and the EMM&rsquo;s Microsoft Windows platform includes SQL server 2016, 2019, or 2022 and a Microsoft Certificate Authority.</p>\r\n<p style=\"margin: 0in 0in 6pt; text-align: justify; font-size: 10pt; font-family: Times, serif;\">Note that one can install multiple EMM systems in order to allow the overall solution to scale the supported number of mobile devices as a High Availability (HA) option. In this case, the multiple EMM systems can operate concurrently and with the same policies and other information by sharing the same SQL database.&nbsp;</p>\r\n<p style=\"margin: 0in 0in 6pt; text-align: justify; font-size: 10pt; font-family: 'Times New Roman', serif;\"><span style=\"font-size: 10.0pt; font-family: Times, serif;\">Samsung SDS provides the EMM Agent for Android software for evaluated Samsung mobile devices.&nbsp; The EMM Agent software, once installed and enrolled with the EMM, will apply and enforce administrator configured policies communicated through the EMM to the EMM Agent&rsquo;s running on the mobile devices. The scope of supported EMM Agent for Android devices for the evaluation will be limited by the set of devices evaluated on the NIAP PCL</span></p>","evaluation_configuration":"<p style=\"margin: 0in 0in 6pt; text-align: justify; font-size: 12pt; font-family: 'Times New Roman', serif;\">The evaluated configuration consists of the following models:</p>\r\n<ol style=\"margin-bottom: 0in; margin-top: 0px;\">\r\n<li style=\"text-align: justify; margin: 0in 0in 0in 0px; font-size: 11pt; font-family: Calibri, sans-serif;\"><span style=\"font-size: 12.0pt; font-family: 'Times New Roman', serif;\">The EMM Server components (version 2.2.5) installed upon the Microsoft Windows Server 2016, 2019, or 2022 operating system with Java 1.8, Microsoft SQL Server 2016, 2019, or 2022, and Microsoft&rsquo;s Certificate Authority (CA).</span></li>\r\n<li style=\"text-align: justify; margin: 0in 0in 0in 0px; font-size: 11pt; font-family: Calibri, sans-serif;\"><span style=\"font-size: 12.0pt; font-family: 'Times New Roman', serif;\">The EMM Client version 2.2.5 APKs (EMM Agent, PushAgent, and EMM Agent Resource) installed upon an evaluated Samsung device running Android 14 or 15. (see Security Target for a mapping to Samsung mobile device evaluations)</span></li>\r\n<li style=\"text-align: justify; margin: 0in 0in 0in 0px; font-size: 11pt; font-family: Calibri, sans-serif;\"><span style=\"font-size: 12.0pt; font-family: 'Times New Roman', serif;\">The EMM Client version 2.2.5 application installed upon an evaluated iPhone running iOS 18. (see Security Target for a mapping to Apple mobile device evaluations)&nbsp;</span></li>\r\n</ol>","security_evaluation_summary":"<p><span style=\"font-size: 10.0pt; font-family: Times, serif;\">The evaluation was carried out in accordance to the Common Criteria Evaluation and Validation Scheme (CCEVS) requirements and guidance.&nbsp; The evaluation demonstrated that the TOE<em> </em>meets the security requirements contained in the Security Target.&nbsp; The criteria against which the TOE was judged are described in the Common Criteria for Information Technology Security Evaluation, Version 3.1, Revision 5, April 2017. The evaluation methodology used by the evaluation team to conduct the evaluation is the Common Methodology for Information Technology Security Evaluation, Evaluation Methodology, Version 3.1, Revision 5, April 2017.&nbsp; The product, when delivered and configured as identified in the Samsung EMM Administrator&rsquo;s Guide, Solution version 2.2.5.14, November 2025, Samsung EMM Installation Guide, Solution version 2.2.5.14, April 2025, and Samsung SDS EMM Configuration Guide for Ipsec settings in Microsoft Windows Server 2016/2019/2022 for Common Criteria Evaluation, Solution version 2.2.5.14, September 2025 documents, satisfies all of the security functional requirements stated in the Samsung SDS EMM and EMM Agent for Android 2.2.5 Security Target, Version 0.96, November 20, 2025.&nbsp; The project underwent CCEVS Validator review.&nbsp; The evaluation was completed in November 2025.&nbsp; Results of the evaluation can be found in the Common Criteria Evaluation and Validation Scheme Validation Report (report number CCEVS-VR-VID11630-2025) prepared by CCEVS</span></p>","environmental_strengths":"<p style=\"text-align: justify; margin: 0in; font-size: 10pt; font-family: Times, serif;\">The logical boundaries of the EMM and EMM Agent for Android are realized in the security functions that it implements. Each of these security functions is summarized below.</p>\r\n<p style=\"margin: 0in; font-size: 10pt; font-family: Times, serif;\">&nbsp;</p>\r\n<p style=\"text-align: justify; margin: 0in; font-size: 10pt; font-family: Times, serif;\"><strong>Security audit:</strong></p>\r\n<p style=\"margin: 0in 0in 6pt; text-align: justify; line-height: 11pt; font-size: 10pt; font-family: Times, serif;\"><span style=\"font-family: 'Times New Roman', serif;\">The EMM can generate and store audit records for security-relevant events as they occur.&nbsp; These events are stored and protected by the EMM and can be reviewed by an authorized administrator. The EMM can export the majority of audit events directly through the HTTPS protected GUI in a CSV format.&nbsp; Some low-level events are maintained in text files on the TOE platform and can be exported via RDP using the TOE platform.&nbsp; In both cases, the EMM protects the exported audit records using TLS (as part of HTTPS and RDP). The EMM also supports the ability to query information about MDM agents and export MDM configuration information.</span></p>\r\n<p style=\"margin: 0in 0in 6pt; text-align: justify; line-height: 11pt; font-size: 10pt; font-family: Times, serif;\"><span style=\"font-family: 'Times New Roman', serif;\">The EMM Agent includes the ability to indicate (i.e., respond) to the EMM when it has been enrolled and when it applies policies successfully.&nbsp; The EMM can be configured to alert an administrator based on its configuration. For example, it can be configured to alert the administrator when a policy update fails or an MDM Agent has been enrolled.</span></p>\r\n<p style=\"text-align: justify; margin: 0in; font-size: 10pt; font-family: Times, serif;\"><strong>Cryptographic support:</strong></p>\r\n<p style=\"margin: 0in 0in 6pt; text-align: justify; line-height: 11pt; font-size: 10pt; font-family: Times, serif;\"><span style=\"font-family: 'Times New Roman', serif;\">The EMM and EMM Agent both include or have access to cryptographic modules with Cryptographic Algorithm Validation Program (CAVP) certified algorithms for a wide range of cryptographic functions including: asymmetric key generation and establishment, encryption/decryption, and cryptographic hashing and keyed-hash message authentication. These functions are supported with suitable random bit generation, initialization vector generation, secure key storage, and key and protected data destruction.</span></p>\r\n<p style=\"margin: 0in 0in 6pt; text-align: justify; line-height: 11pt; font-size: 10pt; font-family: Times, serif;\"><span style=\"font-family: 'Times New Roman', serif;\">The primitive cryptographic functions are used to implement security communication protocols (TLS and HTTPS) used for communication between the Server and Agent and between the Server and remote administrators.</span></p>\r\n<p style=\"text-align: justify; margin: 0in; font-size: 10pt; font-family: Times, serif;\"><strong>Identification and authentication:</strong></p>\r\n<p style=\"margin: 0in 0in 6pt; text-align: justify; line-height: 11pt; font-size: 10pt; font-family: Times, serif;\"><span style=\"font-family: 'Times New Roman', serif;\">The EMM authenticates mobile device users (MD users) and administrators prior to allowing those operators to perform any functions.&nbsp; This includes MD users enrolling their device with the EMM using the EMM Agent as well as an administrator logging on to manage the EMM configuration, MDM policies for mobile devices, etc.</span></p>\r\n<p style=\"margin: 0in 0in 6pt; text-align: justify; line-height: 11pt; font-size: 10pt; font-family: Times, serif;\"><span style=\"font-family: 'Times New Roman', serif;\">In addition, both the EMM and Agent utilize X.509 certificates, including certificate validation checking, in conjunction with TLS to secure communications between the EMM and EMM Agents as well as between the EMM and administrators using a web-based user interface for remote administrative access.</span></p>\r\n<p style=\"text-align: justify; margin: 0in; font-size: 10pt; font-family: Times, serif;\"><strong>Security management:</strong></p>\r\n<p style=\"margin: 0in 0in 6pt; text-align: justify; line-height: 11pt; font-size: 10pt; font-family: Times, serif;\"><span style=\"font-family: 'Times New Roman', serif;\">The EMM is designed with two distinct user roles: administrator and mobile device user (MD user).&nbsp; The former interacts directly with the EMM through HTTPS (using a browser) while the latter is the user of a mobile device with the EMM Agent installed.</span></p>\r\n<p style=\"margin: 0in 0in 6pt; text-align: justify; line-height: 11pt; font-size: 10pt; font-family: Times, serif;\"><span style=\"font-family: 'Times New Roman', serif;\">The EMM provides all the function necessary to manage its own security functions as well as to manage mobile device policies that are sent to EMM Agents.&nbsp; In addition, the EMM ensures that security management functions are limited to authorized administrators while allowing MD users to perform only necessary functions such as enrolling with the EMM.</span></p>\r\n<p style=\"margin: 0in 0in 6pt; text-align: justify; line-height: 11pt; font-size: 10pt; font-family: Times, serif;\"><span style=\"font-family: 'Times New Roman', serif;\">The EMM Agents provide the functions necessary to securely communicate and enroll with the EMM, apply policies received from the EMM, and report the results of applying policies.</span></p>\r\n<p style=\"text-align: justify; margin: 0in; font-size: 10pt; font-family: Times, serif;\"><strong>Protection of the TSF:</strong></p>\r\n<p style=\"margin: 0in 0in 6pt; text-align: justify; line-height: 11pt; font-size: 10pt; font-family: Times, serif;\"><span style=\"font-family: 'Times New Roman', serif;\">The EMM and Agent work together to ensure that all security related communication between the server and agent components is protected from disclosure and modification.</span></p>\r\n<p style=\"margin: 0in 0in 6pt; text-align: justify; line-height: 11pt; font-size: 10pt; font-family: Times, serif;\"><span style=\"font-family: 'Times New Roman', serif;\">Both the EMM and Agent include self-testing capabilities to ensure that they are functioning properly as well as to cryptographically verify that their executable images have not been corrupted.</span></p>\r\n<p style=\"margin: 0in 0in 6pt; text-align: justify; line-height: 11pt; font-size: 10pt; font-family: Times, serif;\"><span style=\"font-family: 'Times New Roman', serif;\">The EMM also includes mechanisms (i.e., verification of the digital signature of each new image) so that the TOE itself can be updated while ensuring that the updates will not introduce malicious or other unexpected changes in the TOE.</span></p>\r\n<p style=\"text-align: justify; margin: 0in; font-size: 10pt; font-family: Times, serif;\"><strong>TOE access:</strong></p>\r\n<p style=\"margin: 0in 0in 6pt; text-align: justify; line-height: 11pt; font-size: 10pt; font-family: Times, serif;\"><span style=\"font-family: 'Times New Roman', serif;\">The MDM Server has the capability to display an advisory banner when users attempt to login in order to manage the TOE.</span></p>\r\n<p style=\"text-align: justify; margin: 0in; font-size: 10pt; font-family: Times, serif;\"><strong>Trusted path/channels:</strong></p>\r\n<p style=\"margin: 0in 0in 6pt; text-align: justify; line-height: 11pt; font-size: 10pt; font-family: Times, serif;\"><span style=\"font-family: 'Times New Roman', serif;\">The EMM uses TLS/HTTPS to secure communication channels between its distributed components and remote administrators accessing the Server via a web-based user interface.</span></p>\r\n<p><span style=\"font-size: 10.0pt; font-family: 'Times New Roman', serif;\">It also uses TLS to secure communication channels between itself and mobile device users (MD users). In this latter case, the protected communication channel is established between the EMM and EMM Agent.&nbsp;</span></p>","features":[{"id":188,"feature_name":"Asymmetric Key Generation"},{"id":187,"feature_name":"Certificate Authentication"},{"id":186,"feature_name":"Certificate Validation"},{"id":190,"feature_name":"Cryptograhic Hashing"},{"id":189,"feature_name":"Cryptographic Key Establishment"},{"id":192,"feature_name":"Cryptographic Signature Generation"},{"id":191,"feature_name":"Cryptographic Signature Verification"},{"id":185,"feature_name":"DRBG"},{"id":193,"feature_name":"Keyed-hash message authentication"},{"id":194,"feature_name":"MDM-Agent"},{"id":1931,"feature_name":"Mobile Application Management"},{"id":1932,"feature_name":"Mobile Content Management"},{"id":184,"feature_name":"Mobile Device Management"},{"id":195,"feature_name":"TLS 1.2"},{"id":196,"feature_name":"TLS Client"},{"id":197,"feature_name":"TLS Server with Mutual Authentication"}]}