Page 5 - Introduction; Purpose
XEROX WorkCentre 3550 Information Assurance Disclosure Paper 5 Ver. 1.3, March 2011 Page 5 of 32 1. Introduction The WorkCentre 3550 multifunction systems are among the latest versions of Xerox copier and multifunction devices for the general office. 1.1. Purpose The purpose of this document is to d...
Page 6 - Device Description
XEROX WorkCentre 3550 Information Assurance Disclosure Paper 6 Ver. 1.3, March 2011 Page 6 of 32 2. Device Description This product consists of an input document handler and scanner, marking engine including paper path, controller, and user interface. Figure 2-1 WorkCentre Multifunction System Docum...
Page 7 - Security-relevant Subsystems; Physical Partitioning
XEROX WorkCentre 3550 Information Assurance Disclosure Paper 7 Ver. 1.3, March 2011 Page 7 of 32 2.1. Security-relevant Subsystems 2.1.1. Physical Partitioning The security-relevant subsystems of the product are partitioned as shown in Figure 2-2. Figure 2-2 System functional block diagram
Page 8 - Security Functions allocated to Subsystems
XEROX WorkCentre 3550 Information Assurance Disclosure Paper 8 Ver. 1.3, March 2011 Page 8 of 32 2.1.2. Security Functions allocated to Subsystems Security Function Subsystem System Authentication Controller Graphical User Interface Network Authentication Controller Graphical User Interface Cryptogr...
Page 9 - Controller
XEROX WorkCentre 3550 Information Assurance Disclosure Paper 9 Ver. 1.3, March 2011 Page 9 of 32 2.2. Controller 2.2.1. Purpose The controller provides both network and direct-connect external interfaces, and enables copy, print, email, network scan and LanFAX functionality. Network scanning and Lan...
Page 10 - External Connections; USB Ports
XEROX WorkCentre 3550 Information Assurance Disclosure Paper 10 Ver. 1.3, March 2011 Page 10 of 32 2.2.3. External Connections Table 3 Controller External Connections Figure 2-3 Back panel connections 2.2.4. USB Ports The WorkCentre 3550 contains a host connector for a USB flash drive, enabling prin...
Page 11 - Scanner
XEROX WorkCentre 3550 Information Assurance Disclosure Paper 11 Ver. 1.3, March 2011 Page 11 of 32 2.3 Fax Module 2.3.1. Purpose The embedded FAX service uses the installed embedded fax card to send and receive images over the telephone interface. 2.3.2. Hardware The fax card connects directly to th...
Page 12 - Marking Engine (also known as the Image
XEROX WorkCentre 3550 Information Assurance Disclosure Paper 12 Ver. 1.3, March 2011 Page 12 of 32 2.5. Local User Interface (LUI) 2.5.1. Purpose The LUI detects hard button actuations, and provides text and graphical prompts to the user. Images are not transmitted to or stored in the LUI. The Start...
Page 13 - System Software Structure; Open-source components
XEROX WorkCentre 3550 Information Assurance Disclosure Paper 13 Ver. 1.3, March 2011 Page 13 of 32 2.7. System Software Structure 2.7.1. Open-source components Open-source components in the connectivity layer implement high-level protocol services. The security-relevant connectivity layer components...
Page 14 - Network Protocols
XEROX WorkCentre 3550 Information Assurance Disclosure Paper 14 Ver. 1.3, March 2011 Page 14 of 32 2.7.3. Network Protocols Figure 2- is an interface diagram depicting the protocol stacks supported by the device, annotated according to the DARPA model. Figure 2-4 IPv4 Network Protocol Stack
Page 15 - Logical Access
XEROX WorkCentre 3550 Information Assurance Disclosure Paper 15 Ver. 1.3, March 2011 Page 15 of 32 Figure 2-5 IPv6 Network Protocol Stack 2.8. Logical Access 2.8.1. Network Protocols The supported network protocols are listed in Appendix C and are implemented to industry standard specifications (i.e...
Page 16 - Ports
XEROX WorkCentre 3550 Information Assurance Disclosure Paper 16 Ver. 1.3, March 2011 Page 16 of 32 device-initiated operations (like scanning) cannot assume the existence of the tunnel unless a print job (or other client initiated action) has been previously run since the last boot at either end of ...
Page 20 - IP Filtering
XEROX WorkCentre 3550 Information Assurance Disclosure Paper 20 Ver. 1.3, March 2011 Page 20 of 32 2.8.2.15. Port 636, sLDAP This is the standard LDAP port when using SSL for address book queries in the Scan to Email feature. 2.8.2.16. Port 1124, Network Scan Utility This port supports the Xerox Net...
Page 21 - System Access; Authentication Model; Login and Authentication Methods; System Administrator Login [All product configurations]
XEROX WorkCentre 3550 Information Assurance Disclosure Paper 21 Ver. 1.3, March 2011 Page 21 of 32 3. System Access 3.1. Authentication Model The authentication model allows for the following: • Local Authentication: Provides access to the scan to network and scan to email services. User account inf...
Page 24 - System Accounts; Network Scanning [Multifunction models only]; Diagnostics
XEROX WorkCentre 3550 Information Assurance Disclosure Paper 24 Ver. 1.3, March 2011 Page 24 of 32 3.3. System Accounts 3.3.1. Printing [Multifunction models only] The device may be set up to connect to a print queue maintained on a remote print server. The login name and password are sent to the pr...
Page 25 - Security Aspects of; SMart eSolutions; Meter Assistant
XEROX WorkCentre 3550 Information Assurance Disclosure Paper 25 Ver. 1.3, March 2011 Page 25 of 32 4. Security Aspects of Selected Features 4.1. SMart eSolutions SMart eSolutions provides the ability to automatically send data to Xerox to be used for billing (Meter Assistant) and toner replenishment...
Page 26 - Responses to Known
XEROX WorkCentre 3550 Information Assurance Disclosure Paper 26 Ver. 1.3, March 2011 Page 26 of 32 5. Responses to Known Vulnerabilities 5.1. Security @ Xerox (www.xerox.com/security) Xerox maintains an evergreen public web page that contains the latest security information pertaining to its product...
Page 27 - APPENDICES; Appendix A – Abbreviations
XEROX WorkCentre 3550 Information Assurance Disclosure Paper 27 Ver. 1.3, March 2011 Page 27 of 32 6. APPENDICES 6.1. Appendix A – Abbreviations API Application Programming Interface AMR Automatic Meter Reads ASIC Application-Specific Integrated Circuit. This is a custom integrated circuit that is u...
Page 29 - Appendix B – Supported MIB Objects
XEROX WorkCentre 3550 Information Assurance Disclosure Paper 29 Ver. 1.3, March 2011 Page 29 of 32 6.2. Appendix B – Supported MIB Objects NOTES : (1) The number of objects shown per MIB group represents the number of objects defined by the IETF standard for that MIB group. It does not represent the...
Page 31 - Appendix C –Standards
XEROX WorkCentre 3550 Information Assurance Disclosure Paper 31 Ver. 1.3, March 2011 Page 31 of 32 6.3. Appendix C –Standards Controller Software Function RFC/Standard Internet Protocol 950 Internet standard subnetting procedure 919 Broadcasting internet datagrams 922 Transmission Control Protocol (...
Page 32 - Appendix E – References
XEROX WorkCentre 3550 Information Assurance Disclosure Paper 32 Ver. 1.3, March 2011 Page 32 of 32 Portable Document Format Reference Manual Version 1.3 6.4. Appendix E – References Kerberos FAQ http://www.nrl.navy.mil/CCS/people/kenh/kerberos-faq.html IP port numbers http://www.iana.org/assignments...