Specifications
CRP-C0239-01
11
for changing the document file owners).
- It is allowed for the General Users to change their own "authentication
information", "Document Data Default ACL (except for field of the document file
owner)" and "S/MIME User Information".
Since (4) limits the use of the Security Management Function to the "authorized
person to use the Security Management Function", the TOE counters
T.ABUSE_SEC_MNG.
1.5.4.2 Countermeasure to T.SALVAGE
The TOE protects Document Data from leakage by making it difficult to understand
unless the Document Data is accessed in the normal way (using the function described
in "1.2.4 TOE Function" from the Operation Panel or Client PC) to counter T.SALVAGE.
(Stored Data Protection Function)
This function is realized by encrypting the data just before writing it on HDD with the
following cryptographic algorithm and cryptographic key size, and by decrypting the
data just after reading it from HDD.
- Cryptographic algorithm: AES
- Key size: 256 bits
1.5.4.3 Countermeasure to T.TRANSIT
The TOE protects the Document Data and image data that are sent or received by the
TOE via the Internal Networks from interceptions and tampering to counter
T.TRANSIT.
The mechanism, SSL, IPSec or S/MIME, varies depending on the type of data to be
protected. Although S/MIME is realized by the TOE functions, the communication path
for SSL is established by the cooperation of the TOE and client PCs, and the
communication path for IPSec is established by the cooperation of TOE and either SMB
Server or FTP Server.
The protected scope depends on the mechanism used for the data protection. The
following Tables, 1-1(1)-(3), show the specific scopes.
Table 1-1 (1) Specific data, mechanism and scope
Target data
Print data that are sent to Network Unit from client PC via Internal Networks
using the "Printer Function" (except for via USB Ports)
Protection mechanism and protected scope
The Internal Network between client PC and Network Unit is protected by
SSL mechanism
Table 1-1 (2) Specific data, mechanism and scope
Target data
Print data that are sent to Network Unit from client PC via Internal Networks
using the "Fax Function (Fax Transmission from PC)" (except for via USB
Ports)
Protection mechanism and protected scope
The Internal Networks between client PC and Network Unit is protected by
SSL mechanism