{"product_id":11654,"v_id":11654,"product_name":"Galleon Embedded Computing Software Encryption Layer","certification_status":"Certified","certification_date":"2026-05-21T00:00:00Z","tech_type":"Encrypted Storage","vendor_id":{"name":"Galleon Embedded Computing","website":"https://www.galleonec.com"},"vendor_poc":"Steve Mills","vendor_phone":"8327865008","vendor_email":"smills@gec-us.com","assigned_lab":{"cctl_name":"Gossamer Security Solutions"},"product_description":"<p style=\"margin: 0in 0in 6pt; text-align: justify; line-height: 11pt; font-size: 10pt; font-family: Times, serif;\">The Target of Evaluation (TOE) is the Galleon Embedded Computing Software Encryption Layer version 1.1 running on Red Hat Enterprise Linux 9.5.</p>\r\n<p style=\"margin: 0in 0in 6pt; line-height: 11pt; font-size: 10pt; font-family: Times, serif;\">The TOE is a software application that provides Full Drive Encryption (FDE) of drives within the system in which the software executes.&nbsp; The TOE has been evaluated on various different computing environments including Galleon&rsquo;s XSR, HPR, G1, G2, and ARINC computing environments.&nbsp;&nbsp; These products/environments can act in multiple different capacities (Network Attached Storage [NAS], data recorder, general server, etc.) and allow for encryption of the drives attached to the system (including a Removable Data Module [RDM]).&nbsp; The XSR model supports encryption of one RDM (at a time), up to 4 internal SSDs, and its internal, non-removable mSATA SSD.&nbsp; The G1 model also supports encryption of one RDM (at a time) and up to 2 internal SSDs.&nbsp; TOE securely encrypts all user data stored on the protected drives.</p>\r\n<p style=\"margin: 0in 0in 6pt; line-height: 11pt; font-size: 10pt; font-family: Times, serif;\">The TOE software executes in a Red Hat Enterprise Linux (RHEL) Release 9.5 operating system running on the computing hardware, and the TOE provides software-based Full Disk Encryption (FDE) of data drives (both internal drives and the RDM).</p>\r\n<p style=\"margin: 0in 0in 6pt; line-height: 11pt; font-size: 10pt; font-family: Times, serif;\">In addition to the software-based FDE layer, some models of Galleon&rsquo;s computing products include a separate, hardware-based Full Drive Encryption (FDE) layer to further encrypt the drives; however, this hardware-based FDE layer is addressed in a separate evaluation.</p>\r\n<p style=\"margin: 0in 0in 6pt; text-align: justify; line-height: 11pt; font-size: 10pt; font-family: Times, serif;\"><span style=\"font-size: 10.0pt; font-family: Times, serif;\">The TOE supports encrypting data stored by software applications running in the RHEL operating system.&nbsp; The RHEL operating system might include software to support protocols including CIFS and NFS, might include the vendor&rsquo;s data recording software, might even include customer provided software applications, or might include additional software running within KVM virtualized guest.&nbsp; The RHEL administrator can enable, disable, or install additional (accessing the system directly) desired protocols, software applications, and KVM guests to support their use-case and application.</span></p>","evaluation_configuration":"<p><span style=\"font-size: 10.0pt; font-family: Times, serif;\">The Target of Evaluation (TOE) is the Galleon Embedded Computing Software Encryption Layer version 1.1 running on Red Hat Enterprise Linux 9.5.</span></p>\r\n<p style=\"margin: 0in; font-size: 10pt; font-family: 'Times New Roman', serif;\">The TOE provides software Full Drive Encryption of removable drives and the software can be installed on Red Hat Enterprise Linux on various Galleon computing platforms (including XSR, G1, G2, HPR, and ARINC models).&nbsp; &nbsp;The following table summarizes the CPU options available.&nbsp; Because the Red Hat operating system provides a hardware abstraction layer, the TOE software executes identically irrespective of the underlying CPU.</p>\r\n<p style=\"margin: 0in; font-size: 10pt; font-family: 'Times New Roman', serif;\">&nbsp;</p>\r\n<table class=\"MsoTableGrid\" style=\"width: 486px; margin-left: 5.4pt; border-collapse: collapse; border: none;\" title=\"CPU Options by Model\" border=\"1\" summary=\"asdfasdf\" cellspacing=\"0\" cellpadding=\"0\">\r\n<tbody>\r\n<tr style=\"height: 12.75pt;\">\r\n<td style=\"width: 89.05pt; border: solid windowtext 1.0pt; background: #BFBFBF; padding: 0in 5.4pt 0in 5.4pt;\" valign=\"top\">\r\n<p style=\"margin: 0in; text-align: left; line-height: normal; font-size: 10pt; font-family: Times, serif;\"><strong><span style=\"font-family: 'Times New Roman', serif; color: black;\">Model</span></strong></p>\r\n</td>\r\n<td style=\"width: 275.45pt; border: solid windowtext 1.0pt; border-left: none; background: #BFBFBF; padding: 0in 5.4pt 0in 5.4pt;\" valign=\"top\">\r\n<p style=\"margin: 0in; text-align: left; line-height: normal; font-size: 10pt; font-family: Times, serif;\"><strong><span style=\"font-family: 'Times New Roman', serif; color: black;\">Processor</span></strong></p>\r\n</td>\r\n</tr>\r\n<tr style=\"height: 12.0pt;\">\r\n<td style=\"width: 89.05pt; border: solid windowtext 1.0pt; border-top: none; padding: 0in 5.4pt 0in 5.4pt;\" valign=\"top\">\r\n<p style=\"margin: 0in; text-align: left; line-height: 11pt; font-size: 10pt; font-family: Times, serif;\"><span style=\"font-family: 'Times New Roman', serif;\">XSR</span></p>\r\n</td>\r\n<td style=\"width: 275.45pt; border-top: none; border-left: none; border-bottom: solid windowtext 1.0pt; border-right: solid windowtext 1.0pt; padding: 0in 5.4pt 0in 5.4pt;\" valign=\"top\">\r\n<p style=\"margin: 0in; text-align: left; line-height: 11pt; font-size: 10pt; font-family: Times, serif;\"><span style=\"font-family: 'Times New Roman', serif;\">Intel Xeon E3-1505Lv6 (Kaby Lake)</span></p>\r\n</td>\r\n</tr>\r\n<tr style=\"height: 12.75pt;\">\r\n<td style=\"width: 89.05pt; border: solid windowtext 1.0pt; border-top: none; padding: 0in 5.4pt 0in 5.4pt;\" valign=\"top\">\r\n<p style=\"margin: 0in; text-align: left; line-height: 11pt; font-size: 10pt; font-family: Times, serif;\"><span style=\"font-family: 'Times New Roman', serif;\">XSR</span></p>\r\n</td>\r\n<td style=\"width: 275.45pt; border-top: none; border-left: none; border-bottom: solid windowtext 1.0pt; border-right: solid windowtext 1.0pt; padding: 0in 5.4pt 0in 5.4pt;\" valign=\"top\">\r\n<p style=\"margin: 0in; text-align: left; line-height: 11pt; font-size: 10pt; font-family: Times, serif;\"><span style=\"font-family: 'Times New Roman', serif;\">Intel Xeon E-2276ME (Coffee Lake)</span></p>\r\n</td>\r\n</tr>\r\n<tr style=\"height: 12.0pt;\">\r\n<td style=\"width: 89.05pt; border: solid windowtext 1.0pt; border-top: none; padding: 0in 5.4pt 0in 5.4pt;\" valign=\"top\">\r\n<p style=\"margin: 0in; text-align: left; line-height: 11pt; font-size: 10pt; font-family: Times, serif;\"><span style=\"font-family: 'Times New Roman', serif;\">XSR</span></p>\r\n</td>\r\n<td style=\"width: 275.45pt; border-top: none; border-left: none; border-bottom: solid windowtext 1.0pt; border-right: solid windowtext 1.0pt; padding: 0in 5.4pt 0in 5.4pt;\" valign=\"top\">\r\n<p style=\"margin: 0in; text-align: left; line-height: 11pt; font-size: 10pt; font-family: Times, serif;\"><span style=\"font-family: 'Times New Roman', serif;\">Intel Xeon W-11865MRE (Tiger Lake)</span></p>\r\n</td>\r\n</tr>\r\n<tr style=\"height: 12.75pt;\">\r\n<td style=\"width: 89.05pt; border: solid windowtext 1.0pt; border-top: none; padding: 0in 5.4pt 0in 5.4pt;\" valign=\"top\">\r\n<p style=\"margin: 0in; text-align: left; line-height: 11pt; font-size: 10pt; font-family: Times, serif;\"><span style=\"font-family: 'Times New Roman', serif;\">HPR</span></p>\r\n</td>\r\n<td style=\"width: 275.45pt; border-top: none; border-left: none; border-bottom: solid windowtext 1.0pt; border-right: solid windowtext 1.0pt; padding: 0in 5.4pt 0in 5.4pt;\" valign=\"top\">\r\n<p style=\"margin: 0in; text-align: left; line-height: 11pt; font-size: 10pt; font-family: Times, serif;\"><span style=\"font-family: 'Times New Roman', serif;\">Intel Xeon D-1732TE (Ice Lake)</span></p>\r\n</td>\r\n</tr>\r\n<tr style=\"height: 12.75pt;\">\r\n<td style=\"width: 89.05pt; border: solid windowtext 1.0pt; border-top: none; padding: 0in 5.4pt 0in 5.4pt;\" valign=\"top\">\r\n<p style=\"margin: 0in; text-align: left; line-height: 11pt; font-size: 10pt; font-family: Times, serif;\"><span style=\"font-family: 'Times New Roman', serif;\">G1</span></p>\r\n</td>\r\n<td style=\"width: 275.45pt; border-top: none; border-left: none; border-bottom: solid windowtext 1.0pt; border-right: solid windowtext 1.0pt; padding: 0in 5.4pt 0in 5.4pt;\" valign=\"top\">\r\n<p style=\"margin: 0in; text-align: left; line-height: 11pt; font-size: 10pt; font-family: Times, serif;\"><span style=\"font-family: 'Times New Roman', serif;\">Intel Atom C2758 (Rangeley)</span></p>\r\n</td>\r\n</tr>\r\n<tr style=\"height: 12.75pt;\">\r\n<td style=\"width: 89.05pt; border: solid windowtext 1.0pt; border-top: none; padding: 0in 5.4pt 0in 5.4pt;\" valign=\"top\">\r\n<p style=\"margin: 0in; text-align: left; line-height: 11pt; font-size: 10pt; font-family: Times, serif;\"><span style=\"font-family: 'Times New Roman', serif;\">G2</span></p>\r\n</td>\r\n<td style=\"width: 275.45pt; border-top: none; border-left: none; border-bottom: solid windowtext 1.0pt; border-right: solid windowtext 1.0pt; padding: 0in 5.4pt 0in 5.4pt;\" valign=\"top\">\r\n<p style=\"margin: 0in; text-align: left; line-height: 11pt; font-size: 10pt; font-family: Times, serif;\"><span style=\"font-family: 'Times New Roman', serif;\">Intel Atom C3708 (Deverton)</span></p>\r\n</td>\r\n</tr>\r\n<tr style=\"height: 12.75pt;\">\r\n<td style=\"width: 89.05pt; border: solid windowtext 1.0pt; border-top: none; padding: 0in 5.4pt 0in 5.4pt;\" valign=\"top\">\r\n<p style=\"margin: 0in; text-align: left; line-height: 11pt; font-size: 10pt; font-family: Times, serif;\"><span style=\"font-family: 'Times New Roman', serif;\">ARINC</span></p>\r\n</td>\r\n<td style=\"width: 275.45pt; border-top: none; border-left: none; border-bottom: solid windowtext 1.0pt; border-right: solid windowtext 1.0pt; padding: 0in 5.4pt 0in 5.4pt;\" valign=\"top\">\r\n<p style=\"margin: 0in; text-align: left; line-height: 11pt; font-size: 10pt; font-family: Times, serif;\"><span style=\"font-family: 'Times New Roman', serif;\">Intel Atom x6211E (Elkhart Lake)</span></p>\r\n</td>\r\n</tr>\r\n</tbody>\r\n</table>\r\n<p>&nbsp;</p>","security_evaluation_summary":"<p><span style=\"font-size: 10.0pt; font-family: Times, serif;\">The evaluation was carried out in accordance to the Common Criteria Evaluation and Validation Scheme (CCEVS) requirements and guidance.&nbsp; The evaluation demonstrated that the TOE<em> </em>meets the security requirements contained in the Security Target.&nbsp; The criteria against which the TOE was judged are described in the Common Criteria for Information Technology Security Evaluation, Version 3.1, Revision 5, April 2017. The evaluation methodology used by the evaluation team to conduct the evaluation is the Common Methodology for Information Technology Security Evaluation, Evaluation Methodology, Version 3.1, Revision 5, April 2017.&nbsp; The product, when delivered and configured as identified in the Galleon SW Encryption Layer Certifiable Encryption, Version 1.1.2, May 13, 2026 document, satisfies all of the security functional requirements stated in the Galleon Embedded Computing XSR and G1 Software Encryption Layer Security Target, Version 2.2, May 15, 2026.&nbsp; The project underwent CCEVS Validator review.&nbsp; The evaluation was completed in May 2026.&nbsp; Results of the evaluation can be found in the Common Criteria Evaluation and Validation Scheme Validation Report (report number CCEVS-VR-VID11654-2026) prepared by CCEVS</span></p>","environmental_strengths":"<p style=\"text-align: justify; margin: 0in; font-size: 10pt; font-family: Times, serif;\">The logical boundaries of the Galleon Embedded Computing XSR and G1 Software Encryption Layer are realized in the security functions that it implements. Each of these security functions is summarized below.</p>\r\n<p style=\"margin: 0in; font-size: 10pt; font-family: Times, serif;\">&nbsp;</p>\r\n<p style=\"text-align: justify; margin: 0in; font-size: 10pt; font-family: Times, serif;\"><strong>Cryptographic support:</strong></p>\r\n<p style=\"margin: 0in 0in 6pt; text-align: justify; line-height: 11pt; font-size: 10pt; font-family: Times, serif;\"><span style=\"font-family: 'Times New Roman', serif;\">The TOE includes cryptographic functionality for key management, user authentication, and block-based encryption including: symmetric key generation, encryption/decryption, cryptographic hashing, keyed-hash message authentication, and password-based key derivation. These functions are supported with suitable random bit generation, key derivation, salt generation, initialization vector generation, secure key storage, and key destruction. These primitive cryptographic functions are used to encrypt Data-At-Rest (including the generation and protection of keys and key encryption keys) used by the TOE.</span></p>\r\n<p style=\"text-align: justify; margin: 0in; font-size: 10pt; font-family: Times, serif;\"><strong>User data protection:</strong></p>\r\n<p style=\"margin: 0in 0in 6pt; text-align: justify; line-height: 11pt; font-size: 10pt; font-family: Times, serif;\"><span style=\"font-family: 'Times New Roman', serif;\">The TOE performs Full Drive Encryption on all partitions on the drive (so that no plaintext exists) and does so without user intervention.</span></p>\r\n<p style=\"text-align: justify; margin: 0in; font-size: 10pt; font-family: Times, serif;\"><strong>Security management:</strong></p>\r\n<p style=\"margin: 0in 0in 6pt; text-align: justify; line-height: 11pt; font-size: 10pt; font-family: Times, serif;\"><span style=\"font-family: 'Times New Roman', serif;\">The TOE provides each of the required management services to manage the full drive encryption using a command line interface.</span></p>\r\n<p style=\"text-align: justify; margin: 0in; font-size: 10pt; font-family: Times, serif;\"><strong>Protection of the TSF:</strong></p>\r\n<p><span style=\"font-size: 10.0pt; font-family: 'Times New Roman', serif;\">The TOE implements a number of features to protect itself to ensure the reliability and integrity of its security features. It protects key and key material, and includes functions to perform self-tests and software/firmware integrity checking so that it might detect when it is failing or may be corrupt.&nbsp; If any of the self-tests fail, the TOE will not go into an operational mode.</span></p>\r\n<p>&nbsp;</p>\r\n<p>&nbsp;</p>","features":[{"id":4750,"feature_name":"Cryptographic Hashing"},{"id":4748,"feature_name":"Cryptographic Signature Generation"},{"id":4749,"feature_name":"Cryptographic Signature Verification"},{"id":4747,"feature_name":"Encrypted Storage"},{"id":4746,"feature_name":"Full Drive Encryption"},{"id":4751,"feature_name":"Key Destruction"},{"id":4745,"feature_name":"Keyed-hash message authentication"},{"id":4743,"feature_name":"PBKDF"},{"id":4744,"feature_name":"Trusted Update Function"}]}