CELLUON PICOPRO Pico projector User Manual Software Security Procedures

CELLUON, INC. Pico projector Software Security Procedures

Contents

User Manual Software Security Procedures

SoftwareSecurityDeclaration
Model:TCLPICOPRO
ThisdeviceisfullycompliantwiththerequirementofKDB594280D02UNIIDeviceSecurityv01r01.
SOFTWARESECURITYDESCRIPTION
General
Description
1.Describehowanysoftware/firmware
updatewillbeobtained,downloaded,
and installed.
CelluonintroducenewSWthathas
securedsignthroughCelluonwebsite.
Celluonproductcanonlydownloadthe
codeandinstall.
2.Describealltheradiofrequency
parameters thataremodifiedbyany
software/firmware withoutany
hardwarechanges.Arethese parameters
insomewaylimited,suchthat,
itwillnotexceedtheauthorized
parameters?
Alltheradiofrequencyparametersare
Transmitpower,operatingchannel,
modulationtypebutthoseauthorized
parametersarefixed.
3.Arethereanyauthenticationprotocols
in placetoensurethatthesourceofthe
software/firmwareislegitimate?Ifso,
describeindetails;ifnot,explainhow
the softwareissecuredfrom
modification.
CelluonSWinourproductrunsa
validationduringtheSWupgradeprocess
toensuretheSW’slegitimate,unaltered,
anddownloadedcorrectlybyproprietary
loadvalidation.
4.Arethereanyverificationprotocolsin
place toensurethatthe
software/firmwareislegitimate?Ifso,
describeindetails.
CelluonSWcontainsMD5signatureand
containsplatformtypeimbeddedin
header.
5.Describe,ifany,encryptionmethods
used.
CelluonSWsarenotencryptedbutare
compressed.
6.Foradevicethatcanbeconfiguredas
a masterandclient(withactiveor
passive scanning),explainhowthe
deviceensures complianceforeach
mode?Inparticularif thedeviceactsas
masterinsomebandof operationand
clientinanother;howis compliance
ensuredineachbandof operation?
Thedeviceisonlyaslaver.

ThirdParty
Access
Control
1.Howareunauthorized software/
firmware changesprevented? TheSWhassecuresignedcodethatonly
releasedbyCelluon.Anychangescheck
thesecuresignedcode.
SOFTWARESECURITYDESCRIPTION
ThirdParty
Access
Control
2.Isitpossibleforthirdpartiestoload
device driversthatcouldmodifytheRF
parameters,countryofoperationor
other parameterswhichimpactdevice
compliance?Ifso,describeprocedures
to ensurethatonlyapproveddriversare
loaded.
No,theproductsarenotallowany
changesbyanyuser.Itisaproprietary
system.Thememorymaps,SW
algorithmsarenotpublished.
3.Explainifanythirdpartieshavethe
capabilitytooperateaUSsolddeviceon
anyotherregulatorydomain,
frequencies, orinanymannerthatisin
violationofthe certification
Thisislockedintothemanufacturing
dataandcannotbechanged.
4.Whatpreventsthirdpartiesfrom
loading nonUSversionsofthe
software/firmware onthedevice?
TheconfigurationforUSislocatedin
securearea,socannotbechangedany
loadingsnonUSversionsofSW/
firmware.
5.Formodulardevices,describehow
authenticationisachievedwhenused
with differenthosts.
Thisisnotamodulardevice.
User
Configuration
Guide
1.TowhomistheUIaccessible?
(Professional installer,enduser,other.) TheUIisnotaccessibleexceptCelluon.
a)Whatparametersareviewableto
the professionalinstaller/enduser? Allparametersarehidden.
b)Whatparametersareaccessibleor
modifiabletotheprofessionalinstaller?
Notsupportparametersaccessand
modify.
i) Aretheparametersin someway
limited,sothat theinstallerswillnot
enterparametersthat exceedthose
authorized?
Notsupportparametersaccessand
modify.
ii) Whatcontrolsexistthat theuser
cannotoperate thedeviceoutsideits
authorizationintheU.S.?
Theradiosareconfiguredat
manufacturingtobeUSonlyandthe
configurationcannotbechangedbyany
SWupdatefortheproduct.
c)Whatconfigurationoptionsare
availabletotheenduser?
Notsupportanyconfigurationoption.
i) Aretheparametersin someway
limited,sothat theinstallerswillnot
enterparametersthat exceedthose
authorized?
Notsupportparametersaccessand
modify.
ii) Whatcontrolsexistthat theuser
cannotoperate thedeviceoutsideits
authorizationintheU.S.?
Theradiosareconfiguredat
manufacturingtobeUSonlyandthe
configurationcannotbechangedbyany
SWupdatefortheproduct.
d)Isthecountrycodefactoryset?Can
itbechangedintheUI?
Yes,thecountrycodeisfactoryset.
ItdoesnotsupporttheUImenu.
SOFTWARESECURITYDESCRIPTION
User
Configuration
Guide
i) Ifso,whatcontrolsexist toensure
thatthedevice canonlyoperate
withinits authorizationintheU.S.?
Theradiosareconfiguredat
manufacturingtobeUSonlyandthe
configurationcannotbechangedbyany
SWupdatefortheproduct.
e)Whatarethedefaultparameters
when thedeviceisrestarted? Theproductgoestoadefault(approved)
Txchannelandpowerlevelbasedon
factorycountrysetting.
2.Cantheradiobeconfiguredinbridge
or meshmode?Ifyes,anattestation
maybe required.Furtherinformationis
availablein KDBPublication905462D02.
No,can’tconfigurebridgeormeshmode.
3.Foradevicethatcanbeconfiguredas
a masterandclient(withactiveor
passive scanning)Ifthisisuser
configurable, describewhatcontrols
existtoensure compliance.
Theproductisaslaveonly.

Navigation menu