Samsung Multifunction MultiXpress X4220, X4250, X4300, X401, K4250, K4300, K4350, K401 Series
7
Copyright
2014 SAMSUNG ELECTRONICS Co., Ltd., All rights reserved
1
Introduction
This document describes Security Target of Samsung Multifunction MultiXpress X4220, X4250,
X4300, X401, K4250, K4300, K4350, K401 Series.
1.1
Security Target References
Security Target Title
Samsung Multifunction
MultiXpress
X4220,
X4250,
X4300,
X401, K4250, K4300, K4350, K401 Series Security Target
Security Target Version
V1.2
Publication Date
October 14, 2014
Authors
SAMSUNG ELECTRONICS Co., Ltd.
Certification body
IT Security Certification Center (ITSCC)
CC Identification
Common Criteria for Information Technology Security
(CC Version 3.1 Revision 4)
Keywords
Samsung Electronics, Multifunction, Security, IEEE Std 2600.2
TM
-2009
1.2
TOE References
Developer
SAMSUNG ELECTRONICS Co., Ltd.
Name
Samsung Multifunction MultiXpress X4220, X4250, X4300,
X401, K4250, K4300, K4350, K401 Series
Version
B6.09
Hardware (MFP Model)
X4220, X4250, X4300, X401, K4250, K4300, K4350, K401 Series
1.3
TOE Overview
1.3.1
TOE Type, Usage and Security features
This TOE is MFPs (Multi-Function Peripherals) as an IT product. It controls the operation of the
entire MFP, including copy, print, scan, and fax functions on the MFP controller.
This TOE can be used in a wide variety of environments such as home use by consumers, home or
office use by small businesses, office use by medium or large organizations, self-service use by the
public in retail copy shops, libraries, business centers, or educational institutions, and production use
by commercial service providers. This TOE may contain or process valuable or sensitive assets that
need to be protected from unauthorized disclosure and alteration. The utility of the device itself may
be considered a valuable asset which also needs to be protected. There is also a need to ensure that the
TOE cannot be misused in such a way that it causes harm to devices with which it shares network
connections. This TOE is intended to conform the requirements of IEEE Std 2600.2
TM
-2009. IEEE
Std 2600.2
TM
-2009 has defined Operational Environment B. Operational Environment B is generally
characterized as a commercial information processing environment in which a moderate level of
document security, network security, and security assurance are required.
Typically, this environment
will handle the day-to-day proprietary and nonproprietary information needed to operate an enterprise.
The TOE provides the following security features:
Identification & Authentication
The TOE receives U.USER’s information (e.g. ID, password, domain, etc.) through either the
LUI or the RUI, and performs identification & authentication functions using the acquired
information. The TOE provides two types of user identification and authentication methods.
If U.ADMINISTRATOR configures the local authentication, the MFP will authenticate the