Download Certification Report BSI-DSZ-CC-0438-2007

Transcript
BSI-DSZ-CC-0438-2007
Certification Report
Table 4: TOE Security Functions
SF1: Environmental Security violation recording and reaction
This function records in registers the events notified by the detectors.
The integrated detectors are frequency detector, voltage detector,
temperature detector, light detector, inner insulation removal detector,
active shield removal detector and power glitch detector.
The filters integrated are used for preventing noise, glitches and
extremely high frequency in the external reset or clock pad from causing
undefined or unpredictable behavior of the chip.
SF2: Access Control
This security function manages access to the security control registers
through access control security attributes. The user mode (NORMAL
mode) has another function, which is write-enabled bit for security related
registers. If the user does not enable this bit in 128 cycles after the reset,
the user cannot write security control registers any more (for more details
refer to the Security Target [7], chapter 6.1).
SF3: Non-reversibility of TEST and NORMAL modes
The NORMAL mode of the TOE consists of privilege mode and user
mode. This function disables the TEST mode and enables the NORMAL
mode of the TOE. This function ensures the non-reversibility of the
Normal mode. This function is used once during the manufacturing
process only (for more details refer to the Security Target [7], chapter
6.1).
SF4: Hardware countermeasures for unobservability
This function protects the memory and the address/data bus from
probing attacks. This security function protects also the memory contents
of the TOE from data analysis on the stored data as well as on internally
transmitted data. The algorithms used for encryption are proprietary. The
ROM scrambling is static key while the RAM and the EEPROM
scrambling are dynamic key. RAM scrambling is performed automatically
while EEPROM scrambling is defined and managed by the embedded
software. The Central Processing Unit (CPU) of the TOE is synthesizable
with glue logic, which makes reverse engineering and signal identification
more difficult. Most sensitive hardware components such as buses are
also hidden and implemented in deepest layers. The TOE operations can
be made asynchronous by using the Internal Variable Clock and the
Random Wait Generator security features. They make a full range of
intrusive (e.g. probing attacks) and non intrusive attacks (e.g. sidechannel attacks) more complex and difficult.
SF5: Cryptography
This function is used for encrypting and decrypting data using the Triple
DES symmetric algorithm. A Random Number Generator is used for
B-7