Ricoh Aficio MP 6001 SP Security Target - Page 76

Table 37: List of Cryptographic Operations for Stored Data Protection

Page 76 highlights

Page 75 of 87 Table 37: List of Cryptographic Operations for Stored Data Protection Encryption-triggering Operation Writing data to HDD Reading data from HDD Cryptographic Operations Encrypt Decrypt Standard FIPS197 Cryptographic Algorithm AES Key Size 256 bits FDP_ACC.1(a) (Subset access control) The TOE restricts the following: deleting operation on user documents by the MFP administrator process, operations including deleting, printing, downloading, e-mail transmission, folder transmission, and fax transmission on user documents by the normal user process, and operations on user documents by the supervisor process. It also restricts the deleting operation on user jobs by the MFP administrator process, and deleting operation on own user jobs by the normal user process. FDP_ACC.1(b) (Subset access control) The TOE restricts the execution of the MFP applications (Copy Function, Printer Function, Scanner Function, Fax Function and Document Server Function) by the normal user process. FDP_ACF.1(a) (Security attribute based access control) The TOE defines the rule between each user role that is allowed to access the user document and user job, and operations allowed to each user role as shown in Table 17, Table 18, Table 19 and Table 20. The TOE provides each user who is allowed to access to the user documents and user jobs with the appropriate operation according to this rule. For the access to the user document by the normal user, the available document type of user document is determined by the operation interface for normal user, and MFP application executed by the normal user as follows: - If the MFP application executed from the Operation Panel is the Document Server Function, it is allowed to print and delete the Document Server user document and fax document. - If the MFP application executed from the Operation Panel is the Scanner Function, it is allowed to e-mail and delete the scanner user document and deliver the scanner user document to a folder. - If the MFP application executed from the Operation Panel is the Fax Function, it is allowed to fax, print and delete the fax document and deliver the fax document to a folder, and to print and delete the received fax document from the Operation Panel. - If the MFP application executed from a Web browser is the Document Server Function, it is allowed to print and delete the Document Server user document, to e-mail, download and delete the scanner user document and deliver the scanner user document to a folder, to fax, print, download and delete the fax document. The normal user is required the operation permission for Scanner Function to perform the operation on scanner user document. For the operation for fax document, operation permission for Fax Function is required. - If the MFP application executed from a Web browser is the Fax Function, it is allowed to print, download and delete the received fax document. The normal user is required the operation permission for Document Server Function to perform the operation on received fax document. Copyright (c) 2011 RICOH COMPANY, LTD. All rights reserved.

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88

Page 75 of
87
Table 37: List of Cryptographic Operations for Stored Data Protection
Encryption-triggering
Cryptographic
Cryptographic
Key
Standard
Operation
Operations
Algorithm
Size
Writing data to HDD
Encrypt
FIPS197
AES
256 bits
Reading data from HDD
Decrypt
FDP_ACC.1(a) (Subset access control)
The TOE restricts the following: deleting operation on user documents by the MFP administrator process,
operations including deleting, printing, downloading, e-mail transmission, folder transmission, and fax
transmission on user documents by the normal user process, and operations on user documents by the
supervisor process. It also restricts the deleting operation on user jobs by the MFP administrator process, and
deleting operation on own user jobs by the normal user process.
FDP_ACC.1(b) (Subset access control)
The TOE restricts the execution of the MFP applications (Copy Function, Printer Function, Scanner Function,
Fax Function and Document Server Function) by the normal user process.
FDP_ACF.1(a) (Security attribute based access control)
The TOE defines the rule between each user role that is allowed to access the user document and user job,
and operations allowed to each user role as shown in Table 17, Table 18, Table 19 and Table 20. The TOE
provides each user who is allowed to access to the user documents and user jobs with the appropriate
operation according to this rule.
For the access to the user document by the normal user, the available document type of user document is
determined by the operation interface for normal user, and MFP application executed by the normal user as
follows:
- If the MFP application executed from the Operation Panel is the Document Server Function, it is
allowed to print and delete the Document Server user document and fax document.
- If the MFP application executed from the Operation Panel is the Scanner Function, it is allowed to
e-mail and delete the scanner user document and deliver the scanner user document to a folder.
- If the MFP application executed from the Operation Panel is the Fax Function, it is allowed to fax, print
and delete the fax document and deliver the fax document to a folder, and to print and delete the
received fax document from the Operation Panel.
- If the MFP application executed from a Web browser is the Document Server Function, it is allowed to
print and delete the Document Server user document, to e-mail, download and delete the scanner user
document and deliver the scanner user document to a folder, to fax, print, download and delete the fax
document. The normal user is required the operation permission for Scanner Function to perform the
operation on scanner user document. For the operation for fax document, operation permission for Fax
Function is required.
- If the MFP application executed from a Web browser is the Fax Function, it is allowed to print,
download and delete the received fax document. The normal user is required the operation permission
for Document Server Function to perform the operation on received fax document.
Copyright (c) 2011 RICOH COMPANY, LTD. All rights reserved.