Page 1
Lexmark Print Cryption TM (Firmware Versions 1.3.2a and 1.3.2i) FIPS 140-2 Non-Proprietary Security Policy Level 1 Validation Version 1.15 May, 2010 © Copyright 2009 Lexmark International Inc. This do...
Page 2
Table of Contents INTRODUCTION......................................................................................................................... PURPOSE............................................
Page 3
Introduction Purpose This is a non-proprietary Cryptographic Module Security Policy for the Lexmark Print Cryption TM from Lexmark International Inc. This Security Policy describes how the Lexmark Pri...
Page 4
LEXMARK PRINTCRYPTIONTM Overview The Lexmark Print Cryption TM is an option for the Lexmark printers that enable the transfer and printing of encrypted print jobs. This new Lexmark technology offers a...
Page 5
Printer Model Processor Part Number E460 ARM9 P/N 34S0700 T650 IBM 750CL P/N 30G0100 T652 IBM 750CL P/N 30G0210 T654 IBM 750CL P/N 30G0310 C734 IBM 750CL P/N 25C0350 C736 IBM 750CL P/N 25A0450 W850 IB...
Page 6
Operating System: Lexmark proprietary ver. 2.6 based on the Linux operating system. Section Section Title Level 1 Cryptographic Module Specification 1 2 Cryptographic Module Ports and Interfaces 1 3 R...
Page 7
Within the physical cryptographic boundary are the following components: • A CPU which executes the module binaries • FLASH memory storage which stores the module binaries • Volatile memory consisting...
Page 8
Since all of the module’s services are server processes, the logical interfaces of the module are network port and API calls, which provide the only means of accessing the module’s services. Data inpu...
Page 9
Logical Interface of the Module Module Physical Port FIPS 140-2 Logical Interface Network Port Network (Ethernet 10/100) Port Data Input Interface USB Port Parallel Port (optional) Network Port Networ...
Page 10
Service Description Input Output CSP Type of Access to CSP menu (HTTP) which has an LPC log page Table 4 – Crypto Officer Services, Descriptions, CSPs User Role Users utilize the cryptographic functio...
Page 11
Cryptographic Key Management The module implements the following FIPS-Approved algorithms. Algorithm IBM750CL Certificate ARM9 Certificate AES ECB, CBC mode decryption – FIPS 197 Certificate #1209 Cer...
Page 12
Access Control Policy User functionalities have read/write access to the AES Session Key and RSA public key. AES Session key is used to decrypt the data for printing. RSA public key is used for AES Se...
Page 13
• RSA Sign/Verify and Encrypt/Decrypt pair-wise consistency check • SHA-1 KAT • X9.31 RNG KAT The module implements the following Conditional self-tests: • Continuous RNG Test for X9.31 PRNG • Continu...
Page 14
Design Assurance Source code and associated documentation files are managed and recorded using the MLS. MLS is a version control system that stores multiple revisions of the same file with a revisiona...
Page 15
OPERATION IN FIPS MODE The Print Cryption meets Level 1 requirements for FIPS 140-2. The sections below describe how to place and keep the module in FIPS-Approved mode of operation. Initial Setup The ...
Page 16
instructions on installing the software. The setup executable, once launched, will: a. Ask for confirmation of the End-User License Agreement. b. Present a small README, which explains that after inst...
Page 17
Uses can select the AES encryption key length, block length and mode using the printer property. 1. Open the printer folder, right click on the desired printer and select Properties. 2. Navigate to Po...
Page 18
Users must choose the key size and block size approved in FIPS PUB 197 standard. FIPS approved key and block sizes, and mode of operation are as follows: • Key Length: 128, 192, or 256 bit. • Block Le...
Page 19
Users can see the key size, block length, and mode been used for encryption from the Log Viewer program. Page 19 of 20 © Copyright 2009 Lexmark International Inc. This document may be freely reproduce...
Page 20
ACRONYMS AESSD AES Session Daemon ANSI American National Standards Institute API Application Programming Interface ASIC Application Specific Integrated Circuit CMVP Cryptographic Module Validation Pro...