commoncriteria / commoncriteria/PSD
PSD v5.0: Distributed TOE and secure extender deployments
Nobody has claimed this yet.
- Dominant language
- HTML
- Stars
- 0
- Forks
- 0
- PR merge metrics
- No merged PRs in 30d
Description
Summary
PSD v5.0 should preserve and explicitly clarify the distributed architecture already accepted under PSD v4.0, including the use of remote controllers.
This proposal is limited to the PSD TOE boundary, deployment model, operational-environment assumptions, and corresponding evaluation approach. It does not propose PQC, cryptographic requirements, VPN requirements, or any new cryptographic functionality in PSD v5.0.
Background
PSD v4.0 has already accepted distributed PSD architectures in which remote controllers provide user-facing control functions while the principal PSD functionality is located elsewhere. PSD v5.0 should not inadvertently exclude these established deployments through an interpretation that the user must be physically co-located with, or have direct visual access to, the central PSD appliance.
The purpose of this issue is to make that already accepted architecture explicit and technology-neutral.
Problem
The current wording may be interpreted as requiring local physical connection and visibility between the user, controller, PSD appliance, and protected computers. This prevents evaluation of otherwise security-equivalent architectures in which:
- The PSD is implemented as distributed components of one TOE.
- A console-side or computer-side extender is used over copper or fiber.
- The user operates the PSD through a remote controller, as already accepted under PSD v4.0.
- The console and/or protected computers are extended through a protected external connection.
A physical line-of-sight requirement is not, by itself, the relevant PSD security objective. The relevant requirements are that PSD-mediated separation, domain selection, trusted user indication, and the intended port/domain binding are maintained.
Supported distributed deployment models
The distributed PSD TOE option should expressly support either or both of the following deployment models:
-
Extended-console deployment: The user-facing console, including the remote controller, user peripherals, displays, and related console-side extender functions, is located remotely from the central PSD component.
-
Extended-host deployment: One or more computer-facing PSD interfaces, including related host-side extender functions, are located remotely from the central PSD component and connect to their assigned protected computers.
A deployment may use both models simultaneously. In all cases, the PSD shall continue to enforce the required separation and port/domain association between the user console, the PSD, and each protected computer.
Proposed direction
Add a deployment option allowing a distributed PSD TOE. The TOE may include a central PSD component and one or more console-side and/or computer-side extender or controller components.
The PP should permit the user to interact with a remote controller that is part of the TOE or is connected to the TOE through the evaluated deployment configuration. Consistent with PSD v4.0 accepted distributed architectures, the user need not have direct visual access to the central PSD appliance, provided that the controller provides the required trusted indication and domain-selection/control functions.
The PP should remain transport-neutral. It should allow the interconnection to use a dedicated controlled link, copper, fiber, or a separately protected network connection, without requiring PSD v5.0 to define or evaluate cryptographic transport protection.
Where transport protection is needed for a specific deployment, it may be provided by the operational environment or by separately evaluated components, such as a Network Device and VPN Gateway. Such protection is outside the scope of this PSD v5.0 change.
Protected deployment environment
All PSD components, console-side and host-side extenders, associated interfaces, and connecting media shall reside in a physically secure and appropriately controlled operational environment.
In particular:
- The central PSD component and each extender/controller component shall be protected from unauthorized physical access, substitution, modification, or connection of unauthorized devices.
- Console-side components shall reside within the protected environment applicable to the authorized user console.
- Host-side components shall reside within the protected environment applicable to their assigned protected computers.
- Each extended interface shall remain associated only with its intended PSD port and protected computer/domain; an extender or connection shall not provide an uncontrolled path between security domains.
- Copper, fiber, or packet-network transport used between distributed components shall be deployed and protected in accordance with the evaluated configuration and operational-environment assumptions.
- Where packet-network transport is used, any required network protection is provided by the operational environment and/or separately evaluated components. This PSD v5.0 proposal does not add cryptographic, VPN, or PQC requirements to the PSD.
Scope and constraints
This proposal does not change the PSD security model:
- User input associated with one selected domain shall not be delivered to another domain.
- Video, audio, USB, control, and other peripheral information from one domain shall not be exposed to another domain.
- An extended interface shall not become an unmanaged bypass around PSD mediation or isolation.
- The evaluated deployment shall identify the distributed PSD components, their intended ports/domains, and the interfaces used between them.
- Loss or disconnection of an extended interface shall not cause cross-domain transfer, an unsafe domain-selection state, or incorrect reassociation of peripherals or displays.
- The proposal does not add PQC, cryptographic algorithms, cryptographic protocol requirements, or cryptographic Evaluation Activities to PSD v5.0.
Requested PP changes
The Technical Community is requested to consider minimal updates to:
- The TOE overview and use cases, to recognize both extended-console and extended-host distributed PSD deployments.
- The operational-environment assumptions, to require physical and administrative protection of distributed PSD components, their interfaces, and the connecting transport.
- The trusted-path/user-interface provisions, to allow a remote controller to provide required user-visible indication and domain-selection functionality.
- The relevant Evaluation Activities, to verify that the evaluated configuration maintains correct port/domain association, domain separation, trusted user indication, and fail-safe behavior in each supported distributed deployment.
Evaluation considerations
For each supported distributed deployment, the evaluator should verify:
- The distributed components and their applicable ports/domains are identified in the evaluated configuration.
- The remote controller presents the required domain-selection and trusted user-indication functions.
- Each console-side and host-side extended interface remains associated with its intended PSD port and protected computer/domain.
- Domain separation is maintained across the distributed deployment.
- Loss or disconnection of an extended interface does not cause cross-domain transfer or an unsafe domain-selection state.
- Reconnection does not cause unintended domain selection, cross-domain communication, or incorrect association of user peripherals, displays, or protected computers.
The evaluation need not assess the cryptographic security of a network transport as part of PSD v5.0. Where a network transport is used, its security may be addressed through the operational environment and/or separately evaluated Network Device and VPN Gateway components.
Requested TC decision
Please confirm that PSD v5.0 will retain and clarify the PSD v4.0 accepted distributed-architecture model, including remote-controller use and extended-console and extended-host deployments, without introducing cryptography or PQC into PSD v5.0.
Following TC direction, a pull request can provide the minimal XML changes and associated Evaluation Activities.
Contributor guide
No contributing guide indexed for this repository
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
Research direction
No files or tests are named. Start by locating the PSD v5.0 XML sections for the TOE overview, deployment model, operational-environment assumptions, trusted path, and Evaluation Activities, then compare them with the accepted PSD v4.0 distributed architecture. Done means a minimal XML update covering remote controllers and extended-console or extended-host deployments without adding cryptography or PQC requirements.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- xml
- Domain
- distributed-systems, security
- Issue type
- Feature
- Difficulty
- 5/5
- Estimated time
- Over a week
- Activity status
- Active
- Clarity
- Mostly clear
- Newbie friendliness
- 35/100