Table 9 - TEs Affected by the Supplemental Filtering Properties

Table 9 - TEs Affected by the Supplemental Filtering Properties#

TE Impacted by Supplemental TE Filters#

In addition to the basic TE filtering criteria, supplemental filters further refine the selection of applicable test evidence based on specific module properties and security features. Table 9 highlights the TEs affected by these supplemental filtering properties, which include factors such as authentication mechanisms, cryptographic output capabilities, tamper response measures, and other specialized security attributes. By applying these filters, the validation process can be optimized to focus on the most relevant security assurances while reducing redundant or inapplicable tests. This targeted approach enhances the efficiency and accuracy of the TE selection process.

Table 9 - TEs Affected by the Supplemental Filtering Properties#

Filter Property

Include If True

Exclude If False

Number of Affected TEs

Has Excluded Components

TE02.13.01, TE02.13.02, TE02.13.03, TE02.14.01, TE02.15.05, TE02.16.04, TE02.17.04

7

Has EFP

TE07.77.01, TE07.77.02, TE07.77.03, TE07.77.04

4

Uses Split Knowledge

TE09.21.01, TE09.21.02, TE09.21.03, TE09.21.04, TE09.22.01, TE09.23.01, TE09.23.02, TE09.23.04, TE09.24.01

9

Allows Self-Initiated Cryptographic Output

TE04.23.01, TE04.25.01, TE04.25.02, TE04.25.03

4

Supports Bypass Capability

TE04.18.01, TE04.19.01, TE04.19.02, TE04.19.03, TE04.20.01, TE04.20.02, TE04.20.03, TE04.21.01, TE04.21.02, TE04.22.01, TE04.22.02, TE10.21.01, TE10.21.02, TE10.21.03, TE10.21.04, TE10.22.01, TE10.22.02, TE10.22.03, TE10.22.04, TE10.22.05, TE10.48.01, TE10.48.02, TE10.48.03, TE10.49.01, TE10.49.02, TE10.49.03, TE10.51.01, TE10.51.02, TE10.51.03

29

Has Identity-Based Authentication

TE03.20.01, TE04.39.01, TE04.39.02, TE04.39.03, TE04.39.04, TE04.42.01, TE04.42.02, TE04.42.03, TE04.42.04, TE09.22.01

10

Provides Maintenance Access Interface

TE07.50.03

TE07.11.01, TE07.11.02, TE07.12.01, TE07.13.01, TE07.51.07, TE07.51.08, TE07.65.02, TE07.65.07, TE07.65.08, TE11.08.07

11

Uses EDC

TE05.06.02, TE05.07.01

2

Supports Manual SSP Entry

TE09.14.01, TE09.14.02, TE10.46.01, TE10.46.02, TE10.46.03, TE10.46.04

6

Supports Concurrent Operators

TE04.02.01, TE04.02.02, TE04.02.03

3

Supports Software Firmware Loading

TE04.28.01, TE04.29.01, TE04.32.01, TE04.34.01, TE05.13.01, TE05.13.02, TE05.13.03, TE05.13.04, TE05.13.05, TE05.13.06, TE05.13.07, TE05.13.08

12

Supports Complete Image Replacement

TE04.33.01, TE04.35.01, TE04.35.02

3

Uses Hash MAC Integrity

TE05.05.03

1

Has Control Output

TE03.09.01, TE03.09.02, TE03.10.01, TE03.10.02, TE03.10.03, TE03.10.04, TE03.10.05

7

Has Ventilation or Slits

TE07.20.01, TE07.25.01

2

Has EDC

TE10.46.02, TE10.46.03

2

Has External Input Device

TE03.05.02, TE03.08.02

2

Has User Role

TE04.06.01

1

Has External Output Device

TE03.06.02, TE03.11.02

2

Has Removable Cover

TE07.50.03

TE07.13.01, TE07.20.01, TE07.25.01, TE07.39.02, TE07.39.05, TE07.47.01, TE07.47.02, TE07.48.01, TE07.48.02, TE07.51.02, TE07.51.07, TE07.51.08, TE07.62.01, TE07.63.01, TE07.65.02, TE07.65.07, TE07.65.08

18

Outputs Sensitive Data as Plaintext

TE09.16.01, TE09.16.02, TE09.16.03

3

Has Critical Functions

TE10.24.01, TE10.24.02

2

Uses Authentication

TE04.43.01, TE04.43.02, TE04.44.01, TE04.44.02, TE04.45.01, TE04.45.02, TE04.45.03, TE04.47.01, TE04.48.01, TE04.50.01, TE04.50.02, TE04.51.01, TE04.51.02, TE04.52.01, TE04.53.01, TE04.54.01, TE04.54.02, TE04.54.03, TE04.55.01, TE04.55.02

20

Uses Role-Based Authentication

TE04.37.01, TE04.37.02, TE04.38.01, TE04.38.02

4

Has Default Authentication Data

TE04.45.03

1

Has Degraded Mode

TE02.26.01, TE02.26.02, TE02.26.03, TE02.26.04, TE02.26.05, TE02.28.01, TE02.28.02, TE02.30.01, TE02.30.02

9

Has EFT

TE07.81.01, TE07.81.02, TE07.81.03

3

Has Trusted Channel

TE03.16.01, TE03.18.01, TE03.18.02, TE03.19.01, TE03.19.02, TE03.19.03, TE03.19.04, TE03.20.01, TE03.21.01, TE03.22.01, TE09.21.01, TE09.21.04

12

Uses Multi-Factor Authentication

TE04.59.01, TE09.24.01, TE09.24.02

3

Allows Operator to Change Roles

TE04.38.01, TE04.38.02, TE04.42.01, TE04.42.02, TE04.42.03, TE04.42.04

6

Uses Digital Signature Integrity

TE05.05.04

1

Has Maintenance Role

TE04.07.01, TE04.07.02, TE04.07.03

3

Has Additional Mitigations

TE12.01.01, TE12.02.01, TE12.04.01, TE12.04.02, TE12.04.03

5

Supports Sensitive Data I/O

TE09.13.01, TE09.13.02, TE09.13.03, TE09.18.01, TE09.18.02, TE09.19.01

6

Has Tamper Seals

TE07.27.01, TE07.48.01, TE07.48.02, TE07.63.01

4

Has CVE

TE11.38.03

1

Total number of TEs affected by the supplemental filter properties

192

Note: The total number of the TEs affected by the supplemental filter properties is not the sum of the numbers in the column of “Number of Affected TEs” (i.e., 218) because some TEs are affected by multiple filter properties and so appear multiple times in Table 9.