Belkin®
Secure
DVI
KVM
Switch,
Secure
KM
Switch
and
Secure
Windowing
KVM
EAL
4
augmented
ALC_FLR.3
Security
Target
Rev.
1.01
Page
|
7
The
Belkin
Secure
KVM
product
uses
multiple
microcontrollers
to
emulate
the
connected
peripherals
in
order
to
prevent
various
methods
of
attacks
such
as:
display
signaling,
keyboard
signaling,
power
signaling
etc.
The
product
is
also
equipped
with
multiple
unidirectional
flow
forcing
devices
to
assure
adherence
to
the
organizational
confidentiality
policy
and
flow
between
coupled
computers.
The
Belkin
Secure
KVM
line
products
are
available
in
2,
4,
8
or
16
port
models
with
single
or
dual
‐
head
(displays).
Products
include
traditional
KVM
switching
devices,
desktop
controller
unit
(DCU),
direct
display
connection
products
(KM),
Windowing
KVM
to
allow
secure
interaction
with
multiple
connected
computers.
The
Belkin
Secure
KVM
works
with
standard
Personal
Computers
running
operating
systems
such
as
Windows
or
Linux
and
have
ports
for
USB
keyboard,
USB
mouse,
DVI
‐
I
video,
DVI
‐
D
video,
audio
(input
and
output),
and
USB
Common
Access
Card
(CAC)
or
Smart
‐
Card
reader.
The
TOE
is
intended
to
be
used
in
a
range
of
security
settings
(i.e.
computers
coupled
to
a
single
TOE
can
vary
from
non
‐
classified
Internet
connected
to
those
protected
in
accordance
with
national
security
policy).
Any
data
leakage
across
the
TOE
may
cause
severe
damage
to
the
organization
and
therefore
must
be
prevented.
Unlike
older
Secure
KVM
security
schemes
that
mostly
protected
user
information
transitioning
through
the
TOE,
the
modern
approach
primarily
addresses
the
risk
of
TOE
compromise
through
remote
attacks
to
coupled
networks
which
could
leak
local
user
information.
A
summary
of
the
Belkin
Secure
KVM
security
features
can
be
found
in
Section
1.4.
A
detailed
description
of
the
TOE
security
features
can
be
found
in
Section
6,
TOE
Summary
Specification.
1.3
TOE
Description
This
section
provides
context
for
the
TOE
evaluation
by
identifying
the
logical
and
physical
scope
of
the
TOE,
as
well
as
its
evaluated
configuration.