Page 75 of 82
Copyright (c) 2010 RICOH COMPANY, LTD. All Rights Reserved.
Machine control
data items
Range of setting
value
Operations
Authorised setter
Operation
interfaces
Query
General users,
User administrators,
Network
administrators,
File administrators,
Supervisor
Web
Service
Function
Lockout
Flag for
general users
Inactive
Query,
modify
User administrators
Web
Service
Function
Lockout
Flag for
administrators
Inactive
Query,
modify
Supervisor
Web
Service
Function
Lockout
Flag for
supervisor
Inactive
Query,
modify
M achine
administrators
Web
Service
Function
By the above, FIA_AFL.1 (Authentication failure handling), FMT_MTD.1 (Management of TSF data),
FMT_SMF.1 (Specification of management function), and FMT_SMR.1 (Security roles) are satisfied.
7.1.5
SF.CE_OPE_LOCK
Service Mode Lock Function
The Service Mode Lock Function restricts use of the M aintenance Functions to CEs only, based on the
Service Mode Lock Function setting specified by the machine administrator.
The TOE allows the machine administrator to set the Service Mode Lock Function from the Operation
Panel, and allows all authorised users to view the value of the setting. If the Service Mode Lock Function is
set to "Off", the TOE allows only the CE to use the M aintenance Functions. If it is set to "On", the TOE
does not allow the CE to use the M aintenance Functions
.
By the above, FMT_MTD.1 (Management of TSF data) is satisfied.
7.1.6
SF.CIPHER
Encryption Function
The TOE encrypts the document data to be stored on the HDD.
Following are explanations of each functional item in "SF.CIPHER
Encryption Function" and
their corresponding security functional requirements.
7.1.6.1
Encryption of Document Data
The TOE encrypts data with the Ic Ctlr before writing it to the HDD. The TOE decrypts data with the Ic
Ctlr after reading it from the HDD. This process is performed for all data written to and read from the HDD.
Document data is encrypted and decrypted by the TOE in a similar way.
The HDD encryption keys are generated by the machine administrator. If the logged-in user is the machine
administrator, the TOE displays a screen on the Operation Panel that the administrator can use to generate
the HDD encryption keys.
When the machine administrator uses the Operation Panel to instruct the TOE to generate an HDD
encryption key, the TOE generates a 256-bit HDD encryption key using the TRNG encryption key