Commit 46f8c89a authored by Sammy Haddad's avatar Sammy Haddad
Browse files

Removing TOE term

parent b4522489
Loading
Loading
Loading
Loading
+9 −18
Original line number Diff line number Diff line
@@ -1662,7 +1662,6 @@ REFERENCE: ACC_PKI_DM_04

    b) the documentation of zeroization methods employed.


- REFERENCE: ACC_PKI_DM_08

  - OBJECTIVE: Verify the product cannot export private or symmetric keys in plaintext form.
@@ -1675,7 +1674,6 @@ REFERENCE: ACC_PKI_DM_04

  - EVIDENCE: The documentation of supported export methods.


## 6.9 Availability protection

## 6.10 Impact minimisation
@@ -2202,7 +2200,6 @@ REFERENCE: ACC_PKI_LOG_01

The assessment criteria specified in CEN/CLC JT013090:2026 (CEN/CLC prEN 40000-1-3) [\[2\]](#_ref_2) shall be met for the product


# Annex A (informative): Relationship between the present document and the requirements of EU Regulation (EU) 2024/2847 – the Cyber Resilience Act

The present document has been prepared in response to the Commission's standardisation request C(2025)618 [\[i.3\]](#_ref_i.3) to provide, in additions to its other uses, one voluntary means of conforming to the essential requirements of Regulation (EU) 2024/2847 [\[i.1\]](#_ref_i.1) known as the Cyber Resilience Act (CRA).
@@ -3618,7 +3615,7 @@ The risk are then calculated and their applicability defined using the matrixes

  <tr>
    <td>T.MITM</td>
    <td>A Remote attacker may exploit interactions between the TOE and the ITS-S to expose or tamper sensitive TOE or user data</td>
    <td>A Remote attacker may exploit interactions between the Product and the ITS-S to expose or tamper sensitive product or user data</td>
    <td>Keys <br> Certificates <br> Station registration data <br> Trust lists <br> Misbehaviour detection </td>
    <td>Integrity, Availability, Confidentiality</td>
    <td>NA</td>
@@ -3691,7 +3688,7 @@ The risk are then calculated and their applicability defined using the matrixes

  <tr>
    <td>T.DOS</td>
    <td>A Remote attacker disables communication between the TOE and the ITS-S station</td>
    <td>A Remote attacker disables communication between the product and the ITS-S station</td>
    <td>PKI services </td>
    <td>Integrity, Availability</td>
    <td>NA</td>
@@ -3828,7 +3825,7 @@ The risk are then calculated and their applicability defined using the matrixes

  <tr>
    <td>T.PrivateKeys</td>
    <td>A Local attacker or Rogue user disclose or tamper to the TOE secrets i.e. Data encryption key or CA private keys </td>
    <td>A Local attacker or Rogue user disclose or tamper to the product secrets i.e. Data encryption key or CA private keys </td>
    <td>Keys </td>
    <td>Integrity, Availability, Confidentiality</td>
    <td>NA</td>
@@ -3850,7 +3847,7 @@ The risk are then calculated and their applicability defined using the matrixes

  <tr>
    <td>T.Logs_Tampering</td>
    <td>A Local attacker or Rogue user tries to modify the TOE's Log File in order to hide its activities </td>
    <td>A Local attacker or Rogue user tries to modify the product's Log File in order to hide its activities </td>
    <td>Logs and Configuration </td>
    <td>Integrity, Availability, Confidentiality</td>
    <td>NA</td>
@@ -3931,7 +3928,7 @@ The risk are then calculated and their applicability defined using the matrixes

  <tr>
    <td>T.Logs_Disclosure</td>
    <td>A Local attacker or Rogue user tries to gain access to the TOE's Log File in order to gain sensitive information on the TOE's security status and functions as well as other C-ITS stations</td>
    <td>A Local attacker or Rogue user tries to gain access to the product's Log File in order to gain sensitive information on the product's security status and functions as well as other C-ITS stations</td>
    <td>Logs and Configuration </td>
    <td>Integrity, Availability, Confidentiality</td>
    <td>NA</td>
@@ -3953,7 +3950,7 @@ The risk are then calculated and their applicability defined using the matrixes

  <tr>
    <td>T.Configuration_Tampering</td>
    <td>A Local attacker or Rogue user tries to modify the TOE's Certificate Policy configuration data and therefore compromise the integrity of the TOE's applications or communication security</td>
    <td>A Local attacker or Rogue user tries to modify the product's Certificate Policy configuration data and therefore compromise the integrity of the product's applications or communication security</td>
    <td>Logs and Configuration </td>
    <td>Integrity, Availability, Confidentiality</td>
    <td>NA</td>
@@ -3978,7 +3975,7 @@ The risk are then calculated and their applicability defined using the matrixes

  <tr>
    <td>T.Stored_Certificates_Tampering</td>
    <td>A Local attacker or Rogue user tries to modify stored CA Certificates Enrolment Credential (EC) Authorization Ticket (AT) TLM certificate content and therefore compromise the confidentiality or integrity of the TOE's communications</td>
    <td>A Local attacker or Rogue user tries to modify stored CA Certificates Enrolment Credential (EC) Authorization Ticket (AT) TLM certificate content and therefore compromise the confidentiality or integrity of the product's communications</td>
    <td>Certificates</td>
    <td>Integrity, Availability</td>
    <td>NA</td>
@@ -4001,7 +3998,7 @@ The risk are then calculated and their applicability defined using the matrixes

  <tr>
    <td>T.Administrators_Impersonation</td>
    <td>An attacker (Remote attacker Local attacker or Rogue user) may gain access to TOE information by impersonating an authorized user or via privilege escalation of the TOE and thus disclose or manipulate TOE assets</td>
    <td>An attacker (Remote attacker Local attacker or Rogue user) may gain access to product information by impersonating an authorized user or via privilege escalation of the product and thus disclose or manipulate product assets</td>
    <td>Keys <br> Certificates <br> Station registration data <br> CA Network addresses <br> Policies <br> Trust lists <br> PKI services <br> Misbehaviour detection</td>
    <td>Integrity, Availability, Confidentiality</td>
    <td>NA</td>
@@ -4024,7 +4021,7 @@ The risk are then calculated and their applicability defined using the matrixes

  <tr>
    <td>T.Software_Tampering</td>
    <td>A Local or Remote attacker tries to modify the TOE's software and therefore compromise the integrity of the TOE's applications </td>
    <td>A Local or Remote attacker tries to modify the product's software and therefore compromise the integrity of the product's applications </td>
    <td> PKI services </td>
    <td>Integrity, Availability</td>
    <td>NA</td>
@@ -4043,15 +4040,9 @@ The risk are then calculated and their applicability defined using the matrixes
    <td>UC4</td>
  </tr>



</Table>
</div>





# Annex C (Informative) Relationship between the present document and any related ETSI standards (if any, e.g. EN 303 645)

Add reference to mappings for eIDAS and C-ITS from each of ETSI TC ESI and ETSI TC ITS (WG5)