Ricoh Aficio MP C3501 Security Target - Page 26

Identification and Authentication Function, Document Access Control Function, Use-of-Feature - login

Page 26 highlights

Page 25 of 93 Identification and Authentication Function The Identification and Authentication Function is to verify persons before they use the TOE. The persons are allowed to use the TOE only when confirmed as the authorised user. Users can use the TOE from the Operation Panel or via the network. By the network, users can use the TOE from a Web browser, printer/fax driver, and RC Gate. To use the TOE from the Operation Panel or a Web browser, a user will be required to enter his or her login user name and login password so that the user can be verified as a normal user, MFP administrator, or supervisor. To use the Printer or Fax Function from the printer or fax driver, a user will be required to enter his or her login user name and login password received from the printer or fax drivers, so that the user can be verified as a normal user. To use the @Remote Service Function from the RC Gate communication interface, it will be verified whether the communication request is sent from RC Gate. Methods to verify normal users are Basic Authentication and external server authentication. The users will be verified by the MFP administrator-specified procedure, whereas the MFP administrator and supervisor can be verified only by the Basic Authentication. This function includes protection functions for the authentication feedback area, where dummy characters are displayed if a login password is entered using the Operation Panel. In addition to this and for the Basic Authentication only, this function can be used to register passwords that fulfil the requirements of the Minimum Character No. (i.e. minimum password length) and obligatory character types the MFP administrator specifies, so that the lockout function can be enabled and login password quality can be protected. Document Access Control Function The Document Access Control Function is to authorise the operations for documents and user jobs by the authorised TOE users who are authenticated by Identification and Authentication Function. It allows user's operation on the user documents and user jobs based on the privileges for the user role, or the operation permissions for each user. Use-of-Feature Restriction Function The Use-of-Feature Restriction Function is to authorise the operations of Copy Function, Printer Function, Scanner Function, Document Server Function and Fax Function by the authorised TOE users who are authenticated by Identification and Authentication Function. It authorises the use of functions based on the user role and the operation permissions for each user. Network Protection Function The Network Protection Function is to prevent information leakage through wiretapping on the LAN and detect data tampering. The protection function can be enabled using a Web browser to specify the URL for possible encrypted communication. If the Printer Function is used, the protection function can be enabled using the printer driver to specify encrypted communication. If the folder transmission function of Scanner Function is used, the protection function can be enabled through encrypted communication. If the e-mail Copyright (c) 2011 RICOH COMPANY, LTD. All rights reserved.

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94

Page 25 of
93
Copyright (c) 2011 RICOH COMPANY, LTD. All rights reserved.
Identification and Authentication Function
The Identification and Authentication Function is to verify persons before they use the TOE. The persons are
allowed to use the TOE only when confirmed as the authorised user.
Users can use the TOE from the Operation Panel or via the network. By the network, users can use the TOE
from a Web browser, printer/fax driver, and RC Gate.
To use the TOE from the Operation Panel or a Web browser, a user will be required to enter his or her login
user name and login password so that the user can be verified as a normal user, MFP administrator, or
supervisor.
To use the Printer or Fax Function from the printer or fax driver, a user will be required to enter his or her
login user name and login password received from the printer or fax drivers, so that the user can be verified
as a normal user.
To use the @Remote Service Function from the RC Gate communication interface, it will be verified
whether the communication request is sent from RC Gate.
Methods to verify normal users are Basic Authentication and external server authentication. The users will be
verified by the MFP administrator-specified procedure, whereas the MFP administrator and supervisor can
be verified only by the Basic Authentication.
This function includes protection functions for the authentication feedback area, where dummy characters are
displayed if a login password is entered using the Operation Panel. In addition to this and for the Basic
Authentication only, this function can be used to register passwords that fulfil the requirements of the
Minimum Character No. (i.e. minimum password length) and obligatory character types the MFP
administrator specifies, so that the lockout function can be enabled and login password quality can be
protected.
Document Access Control Function
The Document Access Control Function is to authorise the operations for documents and user jobs by the
authorised TOE users who are authenticated by Identification and Authentication Function. It allows user's
operation on the user documents and user jobs based on the privileges for the user role, or the operation
permissions for each user.
Use-of-Feature Restriction Function
The Use-of-Feature Restriction Function is to authorise the operations of Copy Function, Printer Function,
Scanner Function, Document Server Function and Fax Function by the authorised TOE users who are
authenticated by Identification and Authentication Function. It authorises the use of functions based on the
user role and the operation permissions for each user.
Network Protection Function
The Network Protection Function is to prevent information leakage through wiretapping on the LAN and
detect data tampering. The protection function can be enabled using a Web browser to specify the URL for
possible encrypted communication. If the Printer Function is used, the protection function can be enabled
using the printer driver to specify encrypted communication. If the folder transmission function of Scanner
Function is used, the protection function can be enabled through encrypted communication. If the e-mail