Table 9 - TEs Affected by the Supplemental Filtering Properties#
TE Impacted by Supplemental TE Filters#
In addition to the basic TE filtering criteria, supplemental filters further refine the selection of applicable test evidence based on specific module properties and security features. Table 9 highlights the TEs affected by these supplemental filtering properties, which include factors such as authentication mechanisms, cryptographic output capabilities, tamper response measures, and other specialized security attributes. By applying these filters, the validation process can be optimized to focus on the most relevant security assurances while reducing redundant or inapplicable tests. This targeted approach enhances the efficiency and accuracy of the TE selection process.
Filter Property |
Include If True |
Exclude If False |
Number of Affected TEs |
|---|---|---|---|
Has Excluded Components |
TE02.13.01, TE02.13.02, TE02.13.03, TE02.14.01, TE02.15.05, TE02.16.04, TE02.17.04 |
7 |
|
Has EFP |
TE07.77.01, TE07.77.02, TE07.77.03, TE07.77.04 |
4 |
|
Uses Split Knowledge |
TE09.21.01, TE09.21.02, TE09.21.03, TE09.21.04, TE09.22.01, TE09.23.01, TE09.23.02, TE09.23.04, TE09.24.01 |
9 |
|
Allows Self-Initiated Cryptographic Output |
TE04.23.01, TE04.25.01, TE04.25.02, TE04.25.03 |
4 |
|
Supports Bypass Capability |
TE04.18.01, TE04.19.01, TE04.19.02, TE04.19.03, TE04.20.01, TE04.20.02, TE04.20.03, TE04.21.01, TE04.21.02, TE04.22.01, TE04.22.02, TE10.21.01, TE10.21.02, TE10.21.03, TE10.21.04, TE10.22.01, TE10.22.02, TE10.22.03, TE10.22.04, TE10.22.05, TE10.48.01, TE10.48.02, TE10.48.03, TE10.49.01, TE10.49.02, TE10.49.03, TE10.51.01, TE10.51.02, TE10.51.03 |
29 |
|
Has Identity-Based Authentication |
TE03.20.01, TE04.39.01, TE04.39.02, TE04.39.03, TE04.39.04, TE04.42.01, TE04.42.02, TE04.42.03, TE04.42.04, TE09.22.01 |
10 |
|
Provides Maintenance Access Interface |
TE07.50.03 |
TE07.11.01, TE07.11.02, TE07.12.01, TE07.13.01, TE07.51.07, TE07.51.08, TE07.65.02, TE07.65.07, TE07.65.08, TE11.08.07 |
11 |
Uses EDC |
TE05.06.02, TE05.07.01 |
2 |
|
Supports Manual SSP Entry |
TE09.14.01, TE09.14.02, TE10.46.01, TE10.46.02, TE10.46.03, TE10.46.04 |
6 |
|
Supports Concurrent Operators |
TE04.02.01, TE04.02.02, TE04.02.03 |
3 |
|
Supports Software Firmware Loading |
TE04.28.01, TE04.29.01, TE04.32.01, TE04.34.01, TE05.13.01, TE05.13.02, TE05.13.03, TE05.13.04, TE05.13.05, TE05.13.06, TE05.13.07, TE05.13.08 |
12 |
|
Supports Complete Image Replacement |
TE04.33.01, TE04.35.01, TE04.35.02 |
3 |
|
Uses Hash MAC Integrity |
TE05.05.03 |
1 |
|
Has Control Output |
TE03.09.01, TE03.09.02, TE03.10.01, TE03.10.02, TE03.10.03, TE03.10.04, TE03.10.05 |
7 |
|
Has Ventilation or Slits |
TE07.20.01, TE07.25.01 |
2 |
|
Has EDC |
TE10.46.02, TE10.46.03 |
2 |
|
Has External Input Device |
TE03.05.02, TE03.08.02 |
2 |
|
Has User Role |
TE04.06.01 |
1 |
|
Has External Output Device |
TE03.06.02, TE03.11.02 |
2 |
|
Has Removable Cover |
TE07.50.03 |
TE07.13.01, TE07.20.01, TE07.25.01, TE07.39.02, TE07.39.05, TE07.47.01, TE07.47.02, TE07.48.01, TE07.48.02, TE07.51.02, TE07.51.07, TE07.51.08, TE07.62.01, TE07.63.01, TE07.65.02, TE07.65.07, TE07.65.08 |
18 |
Outputs Sensitive Data as Plaintext |
TE09.16.01, TE09.16.02, TE09.16.03 |
3 |
|
Has Critical Functions |
TE10.24.01, TE10.24.02 |
2 |
|
Uses Authentication |
TE04.43.01, TE04.43.02, TE04.44.01, TE04.44.02, TE04.45.01, TE04.45.02, TE04.45.03, TE04.47.01, TE04.48.01, TE04.50.01, TE04.50.02, TE04.51.01, TE04.51.02, TE04.52.01, TE04.53.01, TE04.54.01, TE04.54.02, TE04.54.03, TE04.55.01, TE04.55.02 |
20 |
|
Uses Role-Based Authentication |
TE04.37.01, TE04.37.02, TE04.38.01, TE04.38.02 |
4 |
|
Has Default Authentication Data |
TE04.45.03 |
1 |
|
Has Degraded Mode |
TE02.26.01, TE02.26.02, TE02.26.03, TE02.26.04, TE02.26.05, TE02.28.01, TE02.28.02, TE02.30.01, TE02.30.02 |
9 |
|
Has EFT |
TE07.81.01, TE07.81.02, TE07.81.03 |
3 |
|
Has Trusted Channel |
TE03.16.01, TE03.18.01, TE03.18.02, TE03.19.01, TE03.19.02, TE03.19.03, TE03.19.04, TE03.20.01, TE03.21.01, TE03.22.01, TE09.21.01, TE09.21.04 |
12 |
|
Uses Multi-Factor Authentication |
TE04.59.01, TE09.24.01, TE09.24.02 |
3 |
|
Allows Operator to Change Roles |
TE04.38.01, TE04.38.02, TE04.42.01, TE04.42.02, TE04.42.03, TE04.42.04 |
6 |
|
Uses Digital Signature Integrity |
TE05.05.04 |
1 |
|
Has Maintenance Role |
TE04.07.01, TE04.07.02, TE04.07.03 |
3 |
|
Has Additional Mitigations |
TE12.01.01, TE12.02.01, TE12.04.01, TE12.04.02, TE12.04.03 |
5 |
|
Supports Sensitive Data I/O |
TE09.13.01, TE09.13.02, TE09.13.03, TE09.18.01, TE09.18.02, TE09.19.01 |
6 |
|
Has Tamper Seals |
TE07.27.01, TE07.48.01, TE07.48.02, TE07.63.01 |
4 |
|
Has CVE |
TE11.38.03 |
1 |
|
Total number of TEs affected by the supplemental filter properties |
192 |
||
Note: The total number of the TEs affected by the supplemental filter properties is not the sum of the numbers in the column of “Number of Affected TEs” (i.e., 218) because some TEs are affected by multiple filter properties and so appear multiple times in Table 9.