Download Certification Report BSI-DSZ-CC-0438-2007
Transcript
BSI-DSZ-CC-0438-2007 Certification Report Table 4: TOE Security Functions SF1: Environmental Security violation recording and reaction This function records in registers the events notified by the detectors. The integrated detectors are frequency detector, voltage detector, temperature detector, light detector, inner insulation removal detector, active shield removal detector and power glitch detector. The filters integrated are used for preventing noise, glitches and extremely high frequency in the external reset or clock pad from causing undefined or unpredictable behavior of the chip. SF2: Access Control This security function manages access to the security control registers through access control security attributes. The user mode (NORMAL mode) has another function, which is write-enabled bit for security related registers. If the user does not enable this bit in 128 cycles after the reset, the user cannot write security control registers any more (for more details refer to the Security Target [7], chapter 6.1). SF3: Non-reversibility of TEST and NORMAL modes The NORMAL mode of the TOE consists of privilege mode and user mode. This function disables the TEST mode and enables the NORMAL mode of the TOE. This function ensures the non-reversibility of the Normal mode. This function is used once during the manufacturing process only (for more details refer to the Security Target [7], chapter 6.1). SF4: Hardware countermeasures for unobservability This function protects the memory and the address/data bus from probing attacks. This security function protects also the memory contents of the TOE from data analysis on the stored data as well as on internally transmitted data. The algorithms used for encryption are proprietary. The ROM scrambling is static key while the RAM and the EEPROM scrambling are dynamic key. RAM scrambling is performed automatically while EEPROM scrambling is defined and managed by the embedded software. The Central Processing Unit (CPU) of the TOE is synthesizable with glue logic, which makes reverse engineering and signal identification more difficult. Most sensitive hardware components such as buses are also hidden and implemented in deepest layers. The TOE operations can be made asynchronous by using the Internal Variable Clock and the Random Wait Generator security features. They make a full range of intrusive (e.g. probing attacks) and non intrusive attacks (e.g. sidechannel attacks) more complex and difficult. SF5: Cryptography This function is used for encrypting and decrypting data using the Triple DES symmetric algorithm. A Random Number Generator is used for B-7