Specifications
Samsung MFP Security Kit Type_B V1.5 Security Target
88
Copyright
2010 Samsung Electronics Co., Ltd., All rights reserved
asterisk (*) for each digit entered, and just provides ambiguous feedback
with success or fail information. This prevents users from acquiring any
information during the trial. The authentication process will be delayed for
3 minutes if wrong passwords are entered 3 times in succession in a local
user interface. If wrong passwords were entered 3 times in succession in
the web user interface, the web browser displays an error message. If
wrong passwords were entered 3 times in succession in the telnet system
interface, the authentication process will be delayed for 1 minute
Relevant SFR: FIA_AFL.1(1), FIA_AFL.1(2), FIA_AFL.1(3), FIA_UAU.2(1),
FIA_UAU.7, FIA_UID.2(1)
6.1.5 Image Overwrite (TSF_IOW)
The TOE provides Image Overwrite functions that delete the stored file
from the hard disk drive. The Image Overwrite function consists of
Automatic Image Overwrite and Manual Image Overwrite. The TOE
implements an image overwrite security function (Automatic Image
Overwrite) to overwrite temporary files created during the copying,
printing, scan-to-email, or scan-to-server processes. Also, users can
delete their own files stored in the TOE.
The image overwrite security function can also be invoked manually only
by the system administrator (Manual Image Overwrite). Once invoked,
the Manual Image Overwrite cancels all print and scan jobs, halts the
printer interface (network), overwrites the contents of the reserved
section the number of times for Image Overwrite that is set(from one to
seven times) on the hard disk, and then the main controller reboots. If
there are any problems during overwriting, the Manual Image Overwrite
job automatically restarts after the problem is resolved to overwrite the
remaining area.
Relevant SFR: FDP_RIP.1, FPT_RCV.4
6.1.6 Information Flow (TSF_FLW)
In the TOE, the memory areas for the fax board and for the network port
on the main controller board are separated. If the received fax data
includes malicious virus content, it may threaten the TOE asset such as
the TOE itself or internal network components. To prevent this kind of
threat, the TOE, before “fax forward to email” or “fax forward to
server(SMB/FTP)”, inspects whether the received fax image is
standardized with MMR, MR, or MH of T.4 specification or not. When the
data is considered to be safe, the memory copy continues from the fax
memory area to network memory area. The fax data in network memory
is transmitted to the SMTP servers through the internal network. When










