{"product_id":11663,"v_id":11663,"product_name":"Shift5, Inc. Software File-Based Encryption","certification_status":"Certified","certification_date":"2026-07-28T00:00:00Z","tech_type":"Encrypted Storage","vendor_id":{"name":"Shift5, Inc.","website":"https://www.shift5.io"},"vendor_poc":"Jeremy Turbyfill","vendor_phone":"850-572-4738","vendor_email":"jeremy.turbyfill@shift5.io","assigned_lab":{"cctl_name":"Gossamer Security Solutions"},"product_description":"<p style=\"margin: 0in 0in 12pt; text-align: justify; font-size: 10pt; font-family: Times, serif;\">The Shift5, Inc. Software File-Based Encryption (Shift5 SW FBE) is an OCI-containerized software application that Shift5 distributes as a part of their proprietary OS images for their supported hardware platforms (such as their Manifold product line).&nbsp; The TOE provides file-based encryption for designated files and accepts an administratively provided passphrase to enable its file encryption service or decrypt requested files.</p>\r\n<p style=\"margin: 0in 0in 12pt; text-align: justify; font-size: 10pt; font-family: Times, serif;\">The TOE consists of multiple inner processes. The TOE WebUI binds to a local address and provides an HTTPS interface for administrators to login or configure the TOE. The administrator provides the file-encryption passphrase through the command line and starts the file encryption services through the WebUI on the system.&nbsp; Upon unlocking the TOE Data at Rest Protection (DARP) service, the TOE derives the necessary key values, encrypts data using 256-bit AES-XTS, and writes the encrypted results to disk.&nbsp; Lastly, the TOE also has a separate, command-line interface used for decrypting data.&nbsp; The decryption utility takes in the same file-encryption passphrase, validates the password against a saved fingerprint, decrypts the FEK from file metadata, and saves the decrypted file data to a new file.</p>\r\n<p style=\"margin: 0in 0in 12pt; text-align: justify; font-size: 10pt; font-family: Times, serif;\">The Manifold product used for testing also features a separate full-drive encryption layer that is bundled with the TOE Platform, however that is outside the scope of this evaluation and is evaluated separately. Similarly, the TOE features multiple modes of operation, however the TOE requires that only its attended mode of operation is used in order to be compliant with the evaluated configuration.&nbsp; The attended mode of operation is enabled upon default installation of the TOE, which disables all non-attended, or non-password-based modes of authentication.</p>\r\n<p style=\"margin: 0in 0in 12pt; text-align: justify; font-size: 10pt; font-family: Times, serif;\">&nbsp;</p>","evaluation_configuration":"<p style=\"margin: 0in 0in 12pt; text-align: justify; font-size: 10pt; font-family: Times, serif;\">For the purposes of evaluation, the TOE was tested running on a Shift5 Manifold hardware running the proprietary Shift5 firmware which is based on SUSE Linux Micro 6.0 and an internal Rancher Government Solutions Rancher Kubernetes Engine 2 (RKE2) running on an Atom C3708 CPU.</p>\r\n<p style=\"margin: 0in 0in 12pt; text-align: justify; font-size: 10pt; font-family: Times, serif;\">&nbsp;</p>","security_evaluation_summary":"<p style=\"text-align: justify; margin: 0in; font-size: 10pt; font-family: Times, serif;\"><span style=\"font-size: 10.0pt; font-family: Times, serif;\">The evaluation was carried out in accordance to the Common Criteria Evaluation and Validation Scheme (CCEVS) requirements and guidance.&nbsp; The evaluation demonstrated that the TOE<em> </em>meets the security requirements contained in the Security Target.&nbsp; The criteria against which the TOE was judged are described in the Common Criteria for Information Technology Security Evaluation, Version 3.1, Revision 5, April 2017. The evaluation methodology used by the evaluation team to conduct the evaluation is the Common Methodology for Information Technology Security Evaluation, Evaluation Methodology, Version 3.1, Revision 5, April 2017.&nbsp; The product, when delivered and configured as identified in the Shift5 File &ndash; Based Encryption (FBE) Administrator Guidance Document (AGD), Version 1.3, April 2026 document, satisfies all of the security functional requirements stated in the Shift5, Inc. Software File-Based Encryption Security Target, Version 0.4, July 23, 2026.&nbsp; The project underwent CCEVS Validator review.&nbsp; The evaluation was completed in July 2026.&nbsp; Results of the evaluation can be found in the Common Criteria Evaluation and Validation Scheme Validation Report (report number CCEVS-VR-VID11663-2026) prepared by CCEVS</span>.</p>","environmental_strengths":"<p style=\"text-align: justify; margin: 0in; font-size: 10pt; font-family: Times, serif;\">The logical boundaries of the Shift5 SW FBE are realized in the security functions that it implements. Each of these security functions is summarized below.</p>\r\n<p style=\"margin: 0in; font-size: 10pt; font-family: Times, serif;\">&nbsp;</p>\r\n<p style=\"text-align: justify; margin: 0in; font-size: 10pt; font-family: Times, serif;\"><strong>Cryptographic support:</strong></p>\r\n<p style=\"margin: 0in 0in 6pt; text-align: justify; line-height: 11pt; font-size: 10pt; font-family: Times, serif;\"><span style=\"font-family: 'Times New Roman', serif;\">The TOE uses Automated Cryptographic Validation Test System (ACVTS)-validated cryptographic algorithm implementations, provided by two cryptolibraries managed by the TOE developer.&nbsp; All of these cryptographic libraries are installed with the TOE, to support key generation and derivation, encryption/decryption, and establishment of trusted channels to protect data in transit. Using these cryptographic libraries, the TOE implements a file-based encryption scheme to protect sensitive data at rest. The TOE implements a HTTPS/TLS server to securely provide an administrator WebUI used to manage the TOE. The TOE also relies on direct links to hardware entropy provided by Intel CPUs with RDSEED instructions to generate entropy that is used as input data for each of the TOE&rsquo;s deterministic random bit generator (DRBG).</span></p>\r\n<p style=\"text-align: justify; margin: 0in; font-size: 10pt; font-family: Times, serif;\"><strong>User data protection:</strong></p>\r\n<p style=\"margin: 0in 0in 6pt; text-align: justify; line-height: 11pt; font-size: 10pt; font-family: Times, serif;\"><span style=\"font-family: 'Times New Roman', serif;\">The TOE implements functionality to encrypt sensitive data through its file-based encryption scheme.&nbsp; In order to manage this service, the TOE utilizes command-line level utilities and provides a WebUI interface to enable the file encryption service and manage administrator </span>passphrases<span style=\"font-family: 'Times New Roman', serif;\">.&nbsp; Outside of the network connectivity used by the WebUI and by the user to check for updates, the TOE makes no access to any special hardware or sensitive data repository.&nbsp; The TOE properly protects all data at rest and destroys all references to sensitive and plaintext data upon transitioning to a powered off state.</span></p>\r\n<p style=\"text-align: justify; margin: 0in; font-size: 10pt; font-family: Times, serif;\"><strong>Identification and authentication:</strong></p>\r\n<p style=\"margin: 0in 0in 6pt; text-align: justify; line-height: 11pt; font-size: 10pt; font-family: Times, serif;\"><span style=\"font-family: 'Times New Roman', serif;\">The TOE provides user authorization based on a </span>file-encryption passphrase<span style=\"font-family: 'Times New Roman', serif;\"> in order to protect the keys used for file-based encryption.</span></p>\r\n<p style=\"text-align: justify; margin: 0in; font-size: 10pt; font-family: Times, serif;\"><strong>Security management:</strong></p>\r\n<p style=\"margin: 0in 0in 6pt; text-align: justify; line-height: 11pt; font-size: 10pt; font-family: Times, serif;\"><span style=\"font-family: 'Times New Roman', serif;\">The TOE requires a </span>file-encryption passphrase<span style=\"font-family: 'Times New Roman', serif;\">, a WebUI access passphrase, a webserver certificate and private key, and a web credential </span>passphrase<span style=\"font-family: 'Times New Roman', serif;\"> used to encrypt the webserver private key in storage.&nbsp; The TOE provides default credentials for the WebUI access credentials that must be changed after first login before the WebUI provides any functionality.&nbsp; For all remaining credentials, the TOE does not provide any default values and are configured by the user during the initial provisioning.&nbsp; The TOE provides two management interfaces: a WebUI which can enable/disable the encryption service, and a local console connection which the administrator can use to provide passwords, start the WebUI interface, manage files, and access the separately managed decryption utility.&nbsp; The TOE relies on a new file-encryption passphrase each time the encryption service is started and that same passphrase can be used to later decrypt any files protected during that instance. By default, the TOE is configured with file permissions to protect itself and its data from unauthorized access.</span></p>\r\n<p style=\"text-align: justify; margin: 0in; font-size: 10pt; font-family: Times, serif;\"><strong>Privacy:</strong></p>\r\n<p style=\"margin: 0in 0in 6pt; text-align: justify; line-height: 11pt; font-size: 10pt; font-family: Times, serif;\"><span style=\"font-family: 'Times New Roman', serif;\">The TOE does not transmit personally identifiable information (PII) over any network interfaces.</span></p>\r\n<p style=\"text-align: justify; margin: 0in; font-size: 10pt; font-family: Times, serif;\"><strong>Protection of the TSF:</strong></p>\r\n<p style=\"margin: 0in 0in 6pt; text-align: justify; line-height: 11pt; font-size: 10pt; font-family: Times, serif;\"><span style=\"font-family: 'Times New Roman', serif;\">The TOE protects itself against exploitation by implementing address space layout randomization (ASLR) and by not allocating any memory region for both write and execute permission.&nbsp; The TOE uses standard, well-documented APIs and includes a number of third-party libraries used to perform its functions. As a part of the evaluation process, the vendor has provided a SBOM listing all of the integrated 3<sup>rd</sup> party libraries to NIAP for approval.</span></p>\r\n<p style=\"margin: 0in 0in 6pt; text-align: justify; line-height: 11pt; font-size: 10pt; font-family: Times, serif;\"><span style=\"font-family: 'Times New Roman', serif;\">The TOE provides the ability to check the version of the TOE as well as to check for TOE updates through its WebUI. TOE software is digitally signed and distributed as a part of the operating system.&nbsp; Updates to the TOE containerized application are signed such that the application platform can cryptographically verify them prior to installation.&nbsp; The TOE does not update its own binary code in any way and when removed, all traces of the TOE application software are deleted.</span></p>\r\n<p style=\"text-align: justify; margin: 0in; font-size: 10pt; font-family: Times, serif;\"><strong>Trusted path/channels:</strong></p>\r\n<p style=\"margin: 0in 0in 6pt; text-align: justify; line-height: 11pt; font-size: 10pt; font-family: Times, serif;\"><span style=\"font-family: 'Times New Roman', serif;\">The TOE protects communications between itself and a remote administrator using the WebUI interface with TLS/HTTPS.</span></p>\r\n<p style=\"margin: 0in 0in 6pt; text-align: justify; line-height: 11pt; font-size: 10pt; font-family: Times, serif;\">&nbsp;</p>","features":[{"id":5639,"feature_name":"Application Software"},{"id":5649,"feature_name":"Cryptograhic Hashing"},{"id":5648,"feature_name":"Cryptograhic Key Generation"},{"id":5646,"feature_name":"Cryptographic Signature Generation"},{"id":5647,"feature_name":"Cryptographic Signature Verification"},{"id":5645,"feature_name":"File Encryption"},{"id":5644,"feature_name":"Keyed-hash message authentication"},{"id":5643,"feature_name":"PBKDF"},{"id":5642,"feature_name":"TLS 1.2"},{"id":5641,"feature_name":"TLS Server without Mutual Authentication"},{"id":5640,"feature_name":"Trusted Update Function"}]}