Ricoh Aficio MP 3352 Security Target - Page 92

Software Verification Function, Fax Line Separation Function

Page 92 highlights

Page 91 of 91 7.9 Software Verification Function The Software Verification Function is to verify the integrity of the executable codes of the MFP Control Software and FCU Control Software and confirm that these codes can be trusted. FPT_TST.1 The TOE verifies software at the TOE start-up. The TOE verifies the integrity of the MFP Control Software first by using the hash and then by checking the certificate. If the hash does not match its original value or the certificate verification fails, the TOE displays the error message and becomes unavailable. If the hash matches its original value and the certificate is verified, the TOE becomes available. The TOE also verifies the integrity of the audit log data files. The TOE outputs the information used for integrity verification so that the integrity of the FCU Control Software can be verified. To check the integrity of the FCU Control Software, the information the TOE outputs will be compared with the information described in the guidance documents, so that the integrity of the FCU Control Software can be verified. 7.10 Fax Line Separation Function The Fax Line Separation Function is to receive only faxes as input information from telephone lines so that unauthorised intrusion from telephone lines can be prevented. This function also can be used to prohibit transmissions of received faxes so that unauthorised intrusion from telephone lines to the LAN can be prevented. FPT_FDI_EXP.1 The TOE receives fax data only as input information from telephone lines. If any communication that does not comply with the fax protocol is performed, the line is disconnected. Since the TOE is set to prohibit forwarding of received fax data during installation, received fax data will not be forwarded. Copyright (c) 2011 RICOH COMPANY, LTD. All rights reserved.

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92

Page 91 of
91
Copyright (c) 2011 RICOH COMPANY, LTD. All rights reserved.
7.9
Software Verification Function
The Software Verification Function is to verify the integrity of the executable codes of the MFP Control
Software and FCU Control Software and confirm that these codes can be trusted.
FPT_TST.1
The TOE verifies software at the TOE start-up.
The TOE verifies the integrity of the MFP Control Software first by using the hash and then by checking the
certificate. If the hash does not match its original value or the certificate verification fails, the TOE displays
the error message and becomes unavailable. If the hash matches its original value and the certificate is
verified, the TOE becomes available. The TOE also verifies the integrity of the audit log data files.
The TOE outputs the information used for integrity verification so that the integrity of the FCU Control
Software can be verified. To check the integrity of the FCU Control Software, the information the TOE
outputs will be compared with the information described in the guidance documents, so that the integrity of
the FCU Control Software can be verified.
7.10
Fax Line Separation Function
The Fax Line Separation Function is to receive only faxes as input information from telephone lines so that
unauthorised intrusion from telephone lines can be prevented. This function also can be used to prohibit
transmissions of received faxes so that unauthorised intrusion from telephone lines to the LAN can be
prevented.
FPT_FDI_EXP.1
The TOE receives fax data only as input information from telephone lines. If any communication that does
not comply with the fax protocol is performed, the line is disconnected. Since the TOE is set to prohibit
forwarding of received fax data during installation, received fax data will not be forwarded.