Increased Information Flow Needs for High-Assurance Composite Evaluations

  • Authors:
  • Paul A. Karger;Helmut Kurth

  • Affiliations:
  • -;-

  • Venue:
  • IWIA '04 Proceedings of the Second IEEE International Information Assurance Workshop (IWIA'04)
  • Year:
  • 2004

Quantified Score

Hi-index 0.00

Visualization

Abstract

Four Common Criteria Certification agencies fromFrance, Germany, the Netherlands and the UK have developeda concept of composite evaluations in which softwareevaluators would not receive the full hardware EvaluationTechnical Report (ETR), but instead would onlyreceive an abbreviated ETR-lite. While ETR-lite is acceptableat low assurance levels, this paper argues thatat high assurance levels, such an abbreviated report violatesthe basic principles of systems engineering and highassurance evaluation, and demonstrates that serious undetectedsecurity vulnerabilities can be the result. Thepaper recommends that additional information flow betweenhardware evaluators and software developers andevaluators is crucial for high assurance evaluation to succeed.