- Product Name :
- DocumentBroker Server Version 3
- Version of TOE :
- 03-11
- Product Type :
- Document Management System
- Certification No. :
- C0158
- Date :
- 2008-04-25
- Version of Common Criteria:
- 3.1
- Conformance Claim :
- EAL1 Augmented with ASE_OBJ.2, ASE_REQ.2, ASE_SPD.1
- PP Identifier :
- None
- Vendor :
- Hitachi, Ltd.
-
- POC :
- Masahiro Naruse
- Division :
- Integrated System Department Application Platform Software Software Division
- Phone :
- +81-45-826-8339
- E-mail :

- Evaluation Facility :
- Mizuho Information & Research Institute, Inc. Center for Evaluation of Information Security
PRODUCT DESCRIPTION
Description of TOE
TOE is one of the software products making up a document management system built on a relational database (RDBMS). TOE functions as a server of the document management system and accesses information stored in the database in response to requests from clients. Because TOE is middleware, no interface is being provided to end users (general users).
TOE security functions
Access control function:
In the document space that TOE provides, for identified and authenticated
sessions, the creation of objects and operations on objects that exist
under TOE management are permitted on either a user identifier or group
identifier basis. Also, the authority to change the access control information
used for determining access is limited to sessions that have a specific
user identifier or group identifier.
Security functional requirements
This TOE implements the following security functional requirements.
| Security audit | Non-repudiation of origin/receipt | Cryptographic functionality | Access control |
| Data authentication | Export data protection | Information flow control | Import data protection |
| Internal transfer data protection | Residual information protection | Rollback | Stored data integrity |
| Transfer data confidentiality | Transfer data integrity | Identification and authentication | Security management |
| Privacy Control | Security functionality protection | Resource utilisation management | TOE access control |
| Trusted path/channels |


