Crypto-Officer Role .............................................................................................................................16
User Role.............................................................................................................................................16
This document may be freely reproduced and distributed whole and intact including this Copyright Notice.
Page 4 of 23
Non-Proprietary Security Policy, Version 1.0 June 15, 2007
0 Introduction
0.1 Purpose
This is a non-proprietary Cryptographic Module Security Policy for the VSX 3000, VSX 5000, and VSX 7000s
from Polycom, Inc.. This Security Policy describes how the VSX 3000, VSX 5000, and VSX 7000s meet the
security requirements of FIPS 140-2 and how to run the module in a secure FIPS 140-2 mode. This policy was
prepared as part of the Level 1 FIPS 140-2 validation of the module.
FIPS 140-2 (Federal Information Processing Standards Publication 140-2 – Security Requirements for Cryptographic Modules) details the U.S. Government requirements for cryptographic modules. More information
about the FIPS 140-2 standard and validation program is available on the National Institute of Standards and
Technology (NIST) Cryptographic Module Validation Program (CMVP) website at: http://csrc.nist.gov/cryptval/
The VSX 3000, VSX 5000, and VSX 7000s are referred to in this document as the VSX systems, the hardware
modules, the cryptographic modules, or the modules.
0.2 References
This document deals only with operations and capabilities of the module in the technical terms of a FIPS 140-2
cryptographic module security policy. More information is available on the module from the following sources:
• The Polycom website (http://polycom.com) contains information on the full line of products from Polycom.
• The CMVP website (http://csrc.nist.gov/cryptval/) contains contact information for answers to technical or
sales-related questions for the module.
0.3 Document Organization
The Security Policy document is one document in a FIPS 140-2 Submission Package. In addition to this document,
the Submission Package contains:
• Vendor Evidence document
• Finite State Machine
• Other supporting documentation as additional references
This Security Policy and the other validation submission documentation were produced by Corsec Security, Inc.
under contract to Polycom. With the exception of this Non-Proprietary Security Policy, the FIPS 140-2 Validation
Documentation is proprietary to Polycom and is releasable only under appropriate non-disclosure agreements. For
access to these documents, please contact Polycom.
This document may be freely reproduced and distributed whole and intact including this Copyright Notice.
Page 5 of 23
Non-Proprietary Security Policy, Version 1.0 June 15, 2007
1 VSX 3000, VSX 5000, and VSX 7000s
1.1 Overview
Founded in 1990, Polycom is the only company delivering end-to-end rich media collaborative applications for
voice, video, data and the web. Polycom has a wide range of products from desktop and mobile personal systems to
room systems to the network core. Polycom’s full range of high-quality voice and video communications endpoints,
video management software, web conferencing software, and multipoint conferencing enable organizations of all
sizes to increase productivity and agility. Polycom delivers business value by cutting costs, simplifying system
management, fostering real time collaboration and decision making, and improving relationships with employees,
customers and partners.
The Polycom VSX products are state of the art video-conferencing nodes. These systems provide videoconferencing facilities using all the popular telecommunication protocols such as H.320 H.323, and Session
Initiation Protocol (SIP) and include support of Integrated Services Digital Network (ISDN), Primary rate and Basic
rate as well as serial interfaces for V.35, RS-499 and RS-530.
1.2 Module Specifications
The VSX systems feature a variety of models ranging from desktop systems (VSX 3000) to set top appliance
systems (VSX 5000, VSX 7000s) to rack mounted systems (VSX 7000e, VSX 8000). All of the models provide
top-performance video processing and feature high-performance BSP-15 processors from Equator with 128 MB
SDRAM.
The VSX 3000 is an all-in-one desktop system that includes built-in camera, LCD screen, speakers, and
microphone. This model interfaces with an Internet Protocol (IP) network with LAN cable and to ISDN S/T lines
with BRI cables, and includes a separate power supply connector. The VSX 3000 is pictured below:
Figure 1 - VSX 3000
The VSX 5000 is an entry-level compact set-top system with built in camera as shown below in Figure 2. The VSX
5000 supports an external microphone for audio input, and can be connected to an IP network with a LAN cable. A
monitor either VGA or NTSC/PAL can be connected to the VSX 5000 using the supplied audio/video cables, and a
separate power cable connects the device to its power supply.
This document may be freely reproduced and distributed whole and intact including this Copyright Notice.
Page 6 of 23
Non-Proprietary Security Policy, Version 1.0 June 15, 2007
Figure 2 - VSX 5000
The VSX 7000s is another set-top appliance which provides for a mechanical pan, tilt, zoom camera. The VSX
7000s supports H.323 networks with a internal NIC support 10/100mbps.. The VSX 7000 supports a subwoofer into
which the optional Network Interface Card to support ISDN, V.35, RS-499 or RS-530 interfaces. . The VSX 7000s
uses an external microphone array and has an internal audio reproduction system. The VSX 7000s is standard with
dual video display output support and can support VGA, S-video or composite as the main monitor and the same
options for the 2nd monitor when the main monitor is not VGA.
Figure 3 - VSX 7000s
The VSX 7000e and VSX 8000 models are rack-mounted systems as depicted in Figure 4 and Figure 5 below. The
VSX 7000e is a video component system designed for medium-sized conferencing rooms, while the VSX 8000
system is a compact component system for custom integrators. These models support connections with monitors the
same as the VSX 7000s and third-party cameras through standard S-video interfaces. The VSX 7000e and VSX
8000 models provide connections for external audio input and output, LAN ports, telephone jacks, and power
supplies. There is an internal slot in the chassis to support ISDN, V.35, RS-499 or RS-530 interfaces.