Specifications
Samsung MFP Security Kit Type_B V1.5 Security Target
23
Copyright
2010 Samsung Electronics Co., Ltd., All rights reserved
The TOE provides management functions about TSF data, security
functions, and security configurations. Only authorized web, local, or
telnet administrators can access the management functions related to
security.
Accessible functions for each user type are described in Table 5. Security
functions for the web administrator are setting security audit functions,
downloading audit logs, and managing the account for a web
administrator. Security functions for the local administrator are managing
PINs for the local administrator and configuring data for Image Overwrite
function. Security functions for the telnet administrator are changing or
reading the protocol and port.
TSF data includes information on local/web administrator’s authentication,
information on Automatic Image Overwrite function configuration,
information on security audit configuration for web administrators,
security audit log, and information on network configuration.
Only authorized web administrators can download the TOE security audit
record by using the web user interface through “Save as Text File”. Once
the web administrator has successfully logged on to the TOE, the security
audit log can be downloaded.
System Authentication (TSF_SAU)
The system administrator must be authenticated by entering a PIN prior
to being granted access to the system administration functions. The web
administrator types the ID and password in the web user interface, the
local administrator types the PIN in the local user interface and the telnet
administrator types the ID and password in the telnet user interface. The
TOE displays an asterisk for each digit entered to hide the value entered.
Identification of the local administrator at the local user interface is
implicit -- administrators will identify themselves by entering their PINs.
The authentication process will be delayed at the local user interface for 3
minutes if wrong PINs are entered 3 times in succession. If wrong PINs
are entered 3 times at the web interface from one particular browser
session, the TOE will send an error message to this browser session. The
authentication process will be delayed at the telnet interface for 1 minute
if wrong PINs are entered 3 times in succession by the telnet
administrator.
Image Overwrite (TSF_IOW)
The TOE implements a hard disk drive image overwrite security function
to overwrite temporary files created during the printing, network scan,










