Certification Report - Arbit Data Diode
Certification Report - Arbit Data Diode
Dokument ID CSEC-37-1072
HEMLIG/
enligt Offentlighets- och sekretesslagen
(2009:400)
2016-10-13
Table of Contents
1 Executive Summary 3
2 Identification 4
3 Security Policy 5
4 Assumptions and Clarification of Scope 6
4.1 Usage Assumptions 6
4.2 Environmental Assumptions 6
4.3 Clarification of Scope 6
5 Architectural Information 7
6 Documentation 8
7 IT Product Testing 9
7.1 Test Configuration 9
7.2 Developer Testing 9
7.3 Evaluator Testing Effort 9
7.4 Evaluator Penetration Testing 9
8 Evaluated Configuration 10
9 Results of the Evaluation 11
10 Evaluator Comments and Recommendations 13
11 Glossary 14
12 Bibliography 15
Appendix A Scheme Versions 16
A.1 Scheme/Quality Management System 16
A.2 Scheme Notes 16
1 Executive Summary
The Target of evaluation, TOE, is a one-way data diode for optical information.
The TOE implements the one-way data diode through a repeater, where a fiber optic
network cable is connected to the LOW port and a fiber optic network cable is con-
nected to the HIGH port.
Information can only be received from the LOW network connected on the LOW port,
and no light can spill over to the LOW port from the HIGH port.
Information received on the LOW port is allowed to exit through the HIGH port,
without further processing.
The TOE design is presented solely using modules. The abstraction level of subsys-
tems was not found to be required due to the simple design of the TOE.
The TOE consists of one module, the PCBA module. It represents the populated print-
ed circuit board. The PCBA module has seven interfaces, two of which are TSF inter-
faces.
The TOE is a static hardware-only product, and consists of a printed circuit board.
The evaluation has been performed by atsec information security AB in their premises
in Danderyd, Sweden.
The evaluation was conducted in accordance with the requirements of Common Crite-
ria, version 3.1, release 4, and the Common Methodology for IT Security Evaluation,
version 3.1, release 4.
atsec information security AB is a licensed evaluation facility for Common Criteria
under the Swedish Common Criteria Evaluation and Certification Scheme. atsec in-
formation security AB is is also accredited by the Swedish accreditation body
SWEDAC according to ISO/IEC 17025 for Common Criteria evaluation.
The certifier monitored the activities of the evaluator by reviewing all successive ver-
sions of the evaluation reports. The certifier determined that the evaluation results
confirm the security claims in the Security Target [ST], and have been reached in
agreement with the requirements of the Common Criteria and the Common Methodol-
ogy for evaluation assurance level:
EAL5 + AVA_VAN.5 and ALC_FLR.1
The certification results only apply to the version of the product indicated in the cer-
tificate, and on the condition that all the stipulations in the Security Target are met.
This certificate is not an endorsement of the IT product by CSEC or any other organ-
isation that recognises or gives effect to this certificate, and no warranty of the IT
product by CSEC or any other organisation that recognises or gives effect to this
certificate is either expressed or implied.
2 Identification
Certification Identification
Certification ID CSEC2015011
Name and version of the Arbit Data Diode 2.0
certified IT product
Security Target Identification Arbit Data Diode Security Target, version 4.0, 2016-
09-05
EAL EAL5 +AVA_VAN.5 and ALC_FLR.1
Sponsor Eurotempest AB, Teknikringen 10, Linköping. Swe-
den
Developer Eurotempest AB, Teknikringen 10, Linköping. Swe-
den
ITSEF atsec information security AB, Svärdvägen 3C, S-
182 33 Danderyd, Sweden
Common Criteria version 3.1 release4
CEM version 3.1 release 4
Certification date 2016-10-13
3 Security Policy
The TOE implements the One-Way information flow control policy (One-Way SFP),
which is defined as:
Subjects:
LOW port
The input interface of the data diode.
HIGH port
The output interface of the data diode.
Information:
An optical signal that can traverse the HIGH or LOW port.
Policy:
Information is allowed to enter the TOE through the LOW port and may leave
through the HIGH port.
Information is not allowed to leave the TOE through the LOW port.
5 Architectural Information
The TOE is a one-way data diode for optical information. It can be the connection
point between a high security and low security network. The actual transmission is
handled by two dedicated servers, with the data diode in between them. The data diode
ensures that information can only flow from the pitcher to the catcher, but not the oth-
er way. This allows for automated information transfer from the low security network
to the high security network without manual intervention, while preventing the oppo-
site ow direction. Another usage scenario is the export of information from a protected
network to a more open environment. The security goal is in this case to allow the ex-
port, while preventing any potential attacks from reaching the protected network.
The TOE implements the one-way data diode by repeating the signal emitted by the
pitcher (part of the LOW network) to the catcher (part of the HIGH network). The op-
tical fiber from the pitcher connects to the LOW port of the TOE. The optical fiber to
the catcher connects to the HIGH port of the TOE. The only allowed information flow
is therefore from the LOW to the HIGH side. The HIGH port has a physical light
emitter. The LOW port has a physical light receiver and has no light emitting capabil-
ity. The TOE implementation is only utilizing the physical property of the LOW port
and is not dependent on any software.
All signal processing in the TOE is performed in hardware at the Physical Medium
Dependent sublayer in Ethernet [IEEE 802.3]. The TOE does not perform any higher
layer signal parsing such as Ethernet frames or TCP/IP processing.
The TOE supports a range of light signals up to 10.3125 Gbps. The specific supported
light range of each TOE is determined during production based on customer require-
ments.
6 Documentation
Arbit Data Diode Integrator Guide v2.0 [IGUIDE].
7 IT Product Testing
7.1 Test Configuration
Since the TOE is a static hardware product, no configuration of the TOE is needed
during the testing.
7.2.2 Results
The developer has provided the results of all test cases that were performed. All tests
were successful.
7.3.2 Results
The re-run of the developer tests was performed by the evaluator successfully. All
evaluator tests were performed successfully - expected and actual results were con-
sistent.
8 Evaluated Configuration
The TOE is a static hardware product, and consists of a printed circuit board. No con-
figuration is needed or possible.
11 Glossary
CEM Common Methodology for Information Technology Security,
document describing the methodology used in Common Cri-
teria evaluations
ITSEF IT Security Evaluation Facility, test laboratory licensed to
operate within a evaluation and certification scheme
ST Security Target, document containing security requirements
and specifications , used as the basis of a TOE evaluation
TOE Target of Evaluation
Catcher The entity receiving information from the data diode. It re-
sides on the HIGH network.
Data diode A device that allows information to flow from the input to the
output, but not the other way.
HIGH network The network which is to receive information from the LOW
network, through the TOE.
HIGH port The output interface of the data diode. HIGH devices and
networks are connected to this interface.
HIGH system Any system residing on the HIGH network, excluding the
TOE.
Information An optical signal that can traverse the HIGH or LOW port.
LOW network The network from which information is to be sent to the
HIGH network, through the TOE.
LOW port The input interface of the data diode. LOW devices and net-
works are connected to this interface.
LOW system Any system residing on the LOW network, excluding the
TOE.
Pitcher The entity sending information to the data diode. It resides on
the LOW network.
Port The physical interface by which the optical cables are con-
nected to the TOE.
12 Bibliography
[ST] Arbit Data Diode Security Target, version 4.0, 2016-09-05
[IGUIDE] Arbit Data Diode Integrator Guide, version 2.0, 2016-09-05
[IEEE 802.3] IEEE Standard for Ethernet
http://standards.ieee.org/about/get/802/802.3.html
[CCp1] Common Criteria for Information Technology Security Evaluation,
Part 1: Introduction and general model, version 3.1, revision 4, Sep-
tember 2012, CCMB-2012-09-001
[CCp2] Common Criteria for Information Technology Security Evaluation,
Part 2: Security functional components, version 3.1, revision 4, Sep-
tember 2012, CCMB-2012-09-002
[CCp3] Common Criteria for Information Technology Security Evaluation,
Part 3: Security Assurance Components, version 3.1, revision 4,
September 2012, CCMB-2012-09-003
[CEM] Common Methodology for Information Technology Security Evalu-
ation, Evaluation methodology, version 3.1, revision 4, September
2012, CCMB-2012-09-004