Page 5 - Introduction; Purpose
XEROX WorkCentre 5735/5740/5745/5755/5765/5775/5790 Information Assurance Disclosure Paper Ver. 2.00, March 2011 Page 5 of 50 1. Introduction The WorkCentre 5735/5740/5745/5755/5765/5775/5790 multifunction systems are among the latest versions of Xerox copier and multifunction devices for the genera...
Page 6 - Device Description; Security-relevant Subsystems; Physical Partitioning
XEROX WorkCentre 5735/5740/5745/5755/5765/5775/5790 Information Assurance Disclosure Paper Ver. 2.00, March 2011 Page 6 of 50 2. Device Description This product consists of an in put document handler and scanner, marking engine including paper path, controller, and user interface. Figure 2-1 WorkCen...
Page 7 - Security Functions allocated to Subsystems
XEROX WorkCentre 5735/5740/5745/5755/5765/5775/5790 Information Assurance Disclosure Paper Ver. 2.00, March 2011 Page 7 of 50 P C I B u s O p tic a l in te rfa c e B ut to ns a nd D is pl ay P h y s ic a l e x te rn a l in te rf a c e B u tt o n a n d T O E i n te rn a l w ir in g (p ro p ri e ta ry...
Page 8 - Controller; Volatile Memory; Additional Information:
XEROX WorkCentre 5735/5740/5745/5755/5765/5775/5790 Information Assurance Disclosure Paper Ver. 2.00, March 2011 Page 8 of 50 Security Function Subsystem Security Management Controller Graphical User Interface Table 1 Security Functions allocated to Subsystems 2.2. Controller 2.2.1. Purpose The cont...
Page 9 - Media and Storage
XEROX WorkCentre 5735/5740/5745/5755/5765/5775/5790 Information Assurance Disclosure Paper Ver. 2.00, March 2011 Page 9 of 50 Non-Volatile Memory Type (Flash, EEPROM, etc) Size User Modifiable (Y/N) Function or Use Process to Sanitize Flash ROM 128MB N Single Board Controller (Boot code and system f...
Page 10 - External Connections; USB Ports; USB
XEROX WorkCentre 5735/5740/5745/5755/5765/5775/5790 Information Assurance Disclosure Paper Ver. 2.00, March 2011 Page 10 of 50 2.2.3. External Connections Figure 2-3 Back panel connections Interface Description / Usage FAX line 1, RJ-11 Supports FAX Modem T.30 protocol only FAX line 2, RJ-11 Support...
Page 11 - Fax Module; Volatile Memory Description; Non-Volatile Memory Description; Scanner
XEROX WorkCentre 5735/5740/5745/5755/5765/5775/5790 Information Assurance Disclosure Paper Ver. 2.00, March 2011 Page 11 of 50 USB Target port Direct-connect printing; Xerox diagnostic tools (PSW and CAT) and Xerox copier assistant Table 5 USB Ports 2.2. Fax Module 2.3.1. Purpose The embedded FAX se...
Page 13 - Marking Engine (also known as the Image; System Software Structure; Open-source components
XEROX WorkCentre 5735/5740/5745/5755/5765/5775/5790 Information Assurance Disclosure Paper Ver. 2.00, March 2011 Page 13 of 50 Table 8 User Interface memory components 2.6. Marking Engine (also known as the Image Output Terminal or IOT) 2.6.1. Purpose The Marking Engine performs copy/print paper fee...
Page 15 - Network Protocols
XEROX WorkCentre 5735/5740/5745/5755/5765/5775/5790 Information Assurance Disclosure Paper Ver. 2.00, March 2011 Page 15 of 50 2.7.3. Network Protocols Figure 2-5 is an interface diagram depicting the protocol stacks supported by the device, annotated according to the DARPA model. Figure 2-5 IPv4 Ne...
Page 16 - Logical Access; IPSec
XEROX WorkCentre 5735/5740/5745/5755/5765/5775/5790 Information Assurance Disclosure Paper Ver. 2.00, March 2011 Page 16 of 50 Figure 2-6 IPv6 Network Protocol Stack 2.8. Logical Access 2.8.1. Network Protocols The supported network protocols are listed in Appendix D and are implemented to industry ...
Page 17 - Ports
XEROX WorkCentre 5735/5740/5745/5755/5765/5775/5790 Information Assurance Disclosure Paper Ver. 2.00, March 2011 Page 17 of 50 device-initiated operations (like scanning) cannot assume the existence of the tunnel unless a print job (or other client initiated action) has been previously run since the...
Page 21 - IP Filtering
XEROX WorkCentre 5735/5740/5745/5755/5765/5775/5790 Information Assurance Disclosure Paper Ver. 2.00, March 2011 Page 21 of 50 2.8.2.13. Port 515, LPR This is the standard LPR printing port, which only supports IP printing. It is a configurable port, and may be explicitly enabled or disabled in the ...
Page 22 - System Access; Authentication Model
XEROX WorkCentre 5735/5740/5745/5755/5765/5775/5790 Information Assurance Disclosure Paper Ver. 2.00, March 2011 Page 22 of 50 3. System Access 3.1. Authentication Model The authentication model allows for both local and network authentication and authorization. In the local and network cases, authe...
Page 24 - Login and Authentication Methods; System Administrator Login [All product configurations]; Kerberos Authentication (Solaris or Windows 2000/Windows 2003); SMB Authentication (Windows NT 4 or Windows 2000/Windows 2003)
XEROX WorkCentre 5735/5740/5745/5755/5765/5775/5790 Information Assurance Disclosure Paper Ver. 2.00, March 2011 Page 24 of 50 3.2. Login and Authentication Methods There are a number of methods for different types of users to be authenticated. In addition, the connected versions of the product also...
Page 26 - DDNS; System Accounts; Network Scanning [Multifunction models only]; Device log on
XEROX WorkCentre 5735/5740/5745/5755/5765/5775/5790 Information Assurance Disclosure Paper Ver. 2.00, March 2011 Page 26 of 50 3) The device sends an authentication request directly to the Domain Controller through the router using the IP address of the Domain Controller. 4) The Domain Controller re...
Page 27 - Diagnostics; Alternate Boot via Serial Port
XEROX WorkCentre 5735/5740/5745/5755/5765/5775/5790 Information Assurance Disclosure Paper Ver. 2.00, March 2011 Page 27 of 50 3.4. Diagnostics 3.4.1. Service [All product configurations] To access onboard diagnostics from the local user interface, Xerox service representatives must enter a unique 4...
Page 28 - Access; Communication Protocol
XEROX WorkCentre 5735/5740/5745/5755/5765/5775/5790 Information Assurance Disclosure Paper Ver. 2.00, March 2011 Page 28 of 50 3.4.4.1. Access The Xerox Service Technician must be authenticated twice: 1. The first password, called the PSW Lock Facility, is obtained by calling a Xerox service locatio...
Page 29 - Accessible Data
XEROX WorkCentre 5735/5740/5745/5755/5765/5775/5790 Information Assurance Disclosure Paper Ver. 2.00, March 2011 Page 29 of 50 3) The PSW will send a request for Diagnostic service and a password. 4) Assuming the password is authentic, the Marking Engine will either execute a Marking Engine diagnost...
Page 30 - Summary
XEROX WorkCentre 5735/5740/5745/5755/5765/5775/5790 Information Assurance Disclosure Paper Ver. 2.00, March 2011 Page 30 of 50 3.4.5. Summary As stated above, accessibility of customer documents, files or network resources is impossible via the PSW. In the extremely unlikely event that someone did s...
Page 31 - Security Aspects of; Audit Log
XEROX WorkCentre 5735/5740/5745/5755/5765/5775/5790 Information Assurance Disclosure Paper Ver. 2.00, March 2011 Page 31 of 50 4. Security Aspects of Selected Features 4.1. Audit Log The device maintains a security audit log. Recording of security audit log data can be enabled or disabled by the SA....
Page 39 - Xerox Standard Accounting
XEROX WorkCentre 5735/5740/5745/5755/5765/5775/5790 Information Assurance Disclosure Paper Ver. 2.00, March 2011 Page 39 of 50 Event ID Event description Entry Data 44 SW upgrade Device name Device serial number Completion Status (Success, Failed) 45 Cloning Device name Device serial number Completi...
Page 40 - Automatic Meter Reads
XEROX WorkCentre 5735/5740/5745/5755/5765/5775/5790 Information Assurance Disclosure Paper Ver. 2.00, March 2011 Page 40 of 50 On demand, the SA will be able to download a report that shows activity for all of the users. The SA can add, modify or remove users and their allocations at any point. An e...
Page 41 - Algorithm; User Behavior; Overwrite Timing
XEROX WorkCentre 5735/5740/5745/5755/5765/5775/5790 Information Assurance Disclosure Paper Ver. 2.00, March 2011 Page 41 of 50 4.5.1. Algorithm The overwrite mechanism for both IIO and ODIO conforms to the U.S. Department of Defense Directive 5200.28-M (Section 7, Part 2, paragraph 7-202 2 . The alg...
Page 42 - Responses to Known
XEROX WorkCentre 5735/5740/5745/5755/5765/5775/5790 Information Assurance Disclosure Paper Ver. 2.00, March 2011 Page 42 of 50 5. Responses to Known Vulnerabilities 5.1. Security @ Xerox (www.xerox.com/security) Xerox maintains an evergreen public web page that contains the latest security informati...
Page 43 - APPENDICES; Appendix A – Abbreviations
XEROX WorkCentre 5735/5740/5745/5755/5765/5775/5790 Information Assurance Disclosure Paper Ver. 2.00, March 2011 Page 43 of 50 6. APPENDICES 6.1. Appendix A – Abbreviations API Application Programming Interface AMR Automatic Meter Reads ASIC Application-Specific Integrated Circuit. This is a custom ...
Page 45 - Appendix B – Supported MIB; Support Definitions
XEROX WorkCentre 5735/5740/5745/5755/5765/5775/5790 Information Assurance Disclosure Paper Ver. 2.00, March 2011 Page 45 of 50 6.2. Appendix B – Supported MIB Objects NOTES : (1) The number of objects shown per MIB group represents the number of objects defined by the IETF standard for that MIB grou...
Page 48 - Appendix C –Standards
XEROX WorkCentre 5735/5740/5745/5755/5765/5775/5790 Information Assurance Disclosure Paper Ver. 2.00, March 2011 Page 48 of 50 6.3. Appendix C –Standards Controller Hardware PCI Specification (PCI Local Bus Specification Revision 2.1) 100 Megabit Ethernet (IEEE 802.3) Universal Serial Bus 1.1 Parall...
Page 50 - Appendix E – References
XEROX WorkCentre 5735/5740/5745/5755/5765/5775/5790 Information Assurance Disclosure Paper Ver. 2.00, March 2011 Page 50 of 50 6.4. Appendix E – References Kerberos FAQ http://www.nrl.navy.mil/CCS/people/kenh/kerberos- faq.html IP port numbers http://www.iana.org/assignments/port-numbers