White Paper : An Overview of Samsung KNOX
|
|
|
- Dale Shelton
- 10 years ago
- Views:
Transcription
1 : An Overview of Samsung KNOX April 2013 Enterprise Mobility Solutions Samsung Electronics Co., Ltd.
2 Contents Acronyms Android and the Enterprise Introducing Samsung KNOX Technology Overview 1. Platform Customizable Secure Boot TrustZone-based Integrity Measurement Architecture Enhancements for Android 2. lication lication Containers On-Device Data Encryption Virtual Private Network Support 3. Mobile Device Management 4. Theft Recovery Samsung KNOX for Government and High Use 1. Boot Attestation 2. Smartcard - CAC Support 3. Certification & Validations Summary About Samsung Electronics Co., Ltd
3 Acronyms AES BYOD CAC DAR DISA DIT DoD FIPS IPC MAC MDM NIST NSA ODE PKCS ROM SAFE SBU SE for Android SE Linux SRG TIMA VPN Advanced Encryption Standard Bring Your Own Device U.S. Common Access Card Data-at-Rest U.S. Defense Information Systems Agency Data-in-Transit U.S. Department of Defense Federal Information Processing Standard Inter Process Communication Mandatory Access Control Mobile Device Management National Institute of Standards and Technology (US) National Agency On Device Encryption Public Key Cryptography Standards Read-Only Memory Samsung For Enterprise Sensitive But Unclassified Enhancements for Android -Enhanced Linux Requirements Guide TrustZone-based Integrity Measurement Architecture Virtual Private Network 1 page
4 Samsung KNOX incorporates key technologies patented by the NSA Android and the Enterprise With over 75% of the smartphone market share as of 3Q , Android is currently the world s most popular smartphone platform. There are several factors behind Android s success: the open source aspect attracted early adopters and developers, while Google s services and the abundance of third party applications drove consumer adoption. The success of Android among consumers and the developer community has, however, not translated to the enterprise. An April 2012 survey by Gartner found that fewer than 10% of enterprises planned on deploying Android devices in the next 12 months. 2 The principal reasons cited were a perceived lack of security and limited management capability. As a global leader in Android smartphones, Samsung developed Samsung KNOX to provide a more compelling and secure enterprise experience. 1. IDC, Worldwide Quarterly Mobile Phone Tracker, Gartner, Magic Quadrant for Mobile Device Management Software, 2012 Introducing Samsung KNOX Enhanced lication lication Container On-Device Data Encryption Per-app VPN Google Android Platform Enhancements (SE) for Android TrustZone-based Integrity monitoring Customizable Secure Boot** Ultra -secure Operating System Defense & Government Ready *US DoD Mobile OS SRG US DoD CAC / PIV FIPS (DAR, DIT) Government Root of Trust 474+ IT Policies MDM APIs ActiveDirectory based Management Best-in-class Device Management * in process ** Customizable Secure Boot availability varies depending on hardware specification. Figure 1 Samsung KNOX Makes Android Enterprise-Ready Samsung KNOX is a new Android-based solution designed from the ground up with security in mind to address the perception of the current open source Android platform. Samsung KNOX retains full compatibility with Android and the Google ecosystem while integrating fundamental security and management enhancements. All of these advantages make Samsung KNOX the perfect choice for both regulated and general enterprise environments. Samsung KNOX incorporates key technologies patented by the National Agency (NSA) and leverages hardware-level features to provide enhanced security to protect the operating system and applications. In addition, Samsung KNOX has been submitted to the US Government and Department of Defense (DoD) for compliance with initiatives, requirements and standards for mobile device security to enable its use in government and other highly regulated enterprise environments. Finally, Samsung KNOX features one of the most comprehensive Mobile Device Management (MDM) capabilities available. Samsung KNOX, combined with its unique application container technology, enables enterprises to support both BYOD and Corporate-Liable models without compromising corporate security or employee privacy. 2 page
5 Samsung KNOX addresses security at the operating system level in a comprehensive, three-prong strategy Technology Overview This section describes the technical aspects of four key features of Samsung KNOX: 1. Platform 2. lication 3. Mobile Device Management 4. Theft Recovery 1. Platform... Android Framework Enhancements for Android Linux Kernel TrustZone-based Integrity Measurement Architecture (TIMA) Secure Boot Protects Customizable Secure Boot** Hardware TrustZone Figure 2 Samsung KNOX System Overview Samsung KNOX addresses security in a comprehensive, three-prong strategy: Customizable Secure Boot** TrustZone-based Integrity Measurement Architecture (TIMA) Enhancements for Android Samsung KNOX also takes full advantage of all available hardware elements to enhance this security posture. 1. Platform Customizable Secure Boot TrustZone-based Integrity Measurement Architecture Enhancements for Android Secure Boot is a procedure that prevents unauthorized operating systems and software from loading during the startup process. Firmware images (that is, operating systems and other system components) that are cryptographically signed by known, trusted authorities are considered as authorized firmware. Secure Boot is the first line of defense against malicious attacks on KNOX-based mobile devices. Secure Boot requires the device boot loader, kernel, and system software to be cryptographically signed by a key verified by the hardware. Secure Boot uses X.509 certificates and public keys which are embedded into the boot loader of the device. A secure hash of the certificates is fused into hardware Read-Only Memory (ROM) at the time of manufacture. The Secure Boot loader will only continue if the authorized secure signed binaries are present. Next, Secure Boot verifies the cryptographic signature of the Linux kernel and system image before handing control to the OS. The use of the industry standard X.509 certificates and keys provides a strong degree of robustness and confidence in the trusted boot scheme. By default, the root of trust is a Samsung-issued certificate. However, additional roots of trust can be provisioned at the factory; for example, an additional root of trust could be a government-issued (approved) certificate. 3 page
6 Platform security of Samsung KNOX is the first line of defense against malicious attacks 1. Platform Customizable Secure Boot TrustZone-based Integrity Measurement Architecture Enhancements for Android Samsung KNOX utilizes SE for Android ( Enhancements for Android) to enforce Mandatory Access Control policies to isolate applications and data within the platform. SE for Android, however, relies on the assumption of OS kernel integrity. If the Linux kernel is compromised (by a perhaps as yet unknown future vulnerability), SE for Android security mechanisms could potentially be disabled and rendered ineffective. Samsung s TrustZone-based Integrity Measurement Architecture (TIMA) was developed to close this vulnerability. Introduced in Samsung KNOX as a unique feature on Samsung mobile devices, TIMA uses ARM TrustZone hardware and provides continuous integrity monitoring of the Linux kernel. The ARM TrustZone hardware effectively partitions memory and CPU resources into a secure and non-secure world. TIMA runs in the secure-world and cannot be disabled, while the SE for Android Linux kernel runs in the nonsecure world. TIMA is used along with Customizable Secure Boot** and SE for Android to form the first line of defense against malicious attacks on the kernel and core boot strap processes. When TIMA detects that the integrity of the kernel or the boot loader is violated, it takes a policy-driven action in response. One of the policy actions disables the kernel and powers down the device. 1. Platform Customizable Secure Boot TrustZone-based Integrity Measurement Architecture Enhancements for Android -Enhanced Linux (SE Linux) is a technology invented by the NSA in 2000 and has long been established as the standard for securing enterprise Linux assets. Samsung R&D teams have worked very closely with the NSA to port and integrate this technology into Android. This port of SE Linux to Android is commonly referred to as Enhancements for Android, or SE for Android. SE for Android provides an enhanced mechanism to enforce the separation of information based on confidentiality and integrity requirements. It incorporates a strong, flexible Mandatory Access Control (MAC) architecture into the major kernel subsystems and isolates applications and data into different domains. This architecture prevents a compromise in one domain from propagating to other domains or the underlying mobile operating system (OS). This additional security, on top of Linux, reduces threats of tampering and bypassing of application security mechanisms. It also minimizes the amount of damage that can be caused by malicious or flawed applications, as applications are provided the minimum amount of permission required for their task. SE for Android includes a set of security policy configuration files designed to meet common, generalpurpose security goals. Out of the box, Samsung KNOX is provisioned with a set of security policy configuration files designed to strengthen the core Android platform and meet general enterprise needs. Samsung KNOX offers management APIs that allow the default SE for Android policies to be replaced with stricter or enterprise-specific policies. These new policies can be pushed to the device. 4 page
7 White Paper Samsung KNOX provides Enterprises the ability to create and manage a secure container within their employee s personal mobile device 2. lication In addition to securing the platform, Samsung KNOX provides solutions to address the security needs of individual applications: lication Containers On-device Data Encryption Virtual Private Network Support 2. lication lication Containers On-device Data Encryption Virtual Private Network Support Samsung KNOX Container is a virtual Android environment within the mobile device, completed with its own home screen, launcher, applications, and widgets. Device Device s and Content (Mail, Calendar, Contacts, etc.) Samsung KNOX Container Figure 3 Samsung KNOX Container lications and data inside the container are isolated from applications outside the container, that is, applications outside the container cannot use Android inter-process communication (IPC) or data-sharing methods with applications inside the container. Likewise, applications inside the container generally do not have the ability to interact with applications or access data outside the container. However, some applications inside the container can be granted readonly access to data outside the container via a policy configuration. For example, photos taken from the camera inside the container won t be viewable from the Gallery outside the container in a user s personal area. Likewise, any contacts or bookmarks created outside the container won t be available inside the container. The same applies to calendar events and copying/pasting. 5 page
8 2. lication lication Containers On-device Data Encryption Virtual Private Network Support Shared Data Shared Data Shared Data Samsung KNOX Container Android Framework Figure 4 lication Isolation in Samsung KNOX This total isolation of applications and data within the container enables a powerful solution for the data leakage associated with the BYOD model. Data leakage occurs when a user sends sensitive or critical information outside of the corporate network via a personal account, social network site, or public cloud storage system. Samsung KNOX allows a Work container to be setup for corporate applications such as , calendar, browser, storage clients, and so on, and the container will ensure that any data downloaded from the enterprise, such as attachments and files, cannot be accessed by applications outside the container, All the data stored by applications inside the container are encrypted via strong encryption algorithms (AES-256). A password is required to gain access to applications inside the container. Samsung KNOX Container is deeply integrated into the native Android platform unlike other third party container solutions that are available via download from an app store. This deep integration enables a superior user experience that clearly separates the two environments to minimize user confusion, preserves the Android navigation paradigm in each environment for consistency, and provides a unified but privacyaware view of notifications and active applications for efficiency. Furthermore, the deep integration allows Samsung KNOX Container to execute at the system level and leverage additional security and isolation guarantees provided by Enhancements for Android. The enterprise can manage the container like any other IT asset using an MDM solution. Samsung KNOX supports many of the leading MDM solutions on the market. Container management is affected by setting policies in the same fashion as traditional MDM. Samsung KNOX Container includes a rich set of policies for authentication, data security, VPN, , application blacklisting, whitelisting, etc. 6 page
9 Samsung KNOX offers the most comprehensive support for an Enterprise virtual private network (VPN) found in any mobile device 2. lication lication Containers On-device Data Encryption Virtual Private Network Support The On-device Data Encryption (ODE) feature allows users and enterprise IT administrators to encrypt data on the entire device, as well as any configured Samsung KNOX Container. The ODE feature on Samsung devices uses a FIPS certified Advanced Encryption Standard (AES) cipher algorithm with a 256-bit key (AES-256) and offers the levels of security required by government and regulated industries such as healthcare and finance. The key utilized for this encryption is developed from a user-created passphrase using well-known key-derivation algorithms such as Password-Based Key Derivation Function 2 (PBKDF2). Container s lications Samsung KNOX Container ODE lication Settings, Preferences, Databases, etc. Internal Storage External SD Card Figure 5 On-Device Data Encryption in Samsung KNOX The encryption feature spans both internal storage (system partition and internal SD card) as well as any user-installed external SD card. Hardware acceleration is employed to speed up the encryption and decryption process and minimizes the impact of the overhead on the overall user experience. Encryption can be activated directly by the user via the Settings user interface, or remotely by the enterprise IT administrator as a policy setting using Exchange ActiveSync or an MDM system. The use of NIST-compliant algorithms for ODE in Samsung KNOX devices satisfies Federal data-at-rest (DAR) requirements. 7 page
10 MDM enables a company s IT department to monitor, control and administer all deployed mobile devices across multiple mobile service providers 2. lication lication Containers On-device Data Encryption Virtual Private Network Support Samsung KNOX offers a high level of comprehensive support for an enterprise virtual private network (VPN). This enables businesses to offer their employees an optimized, secure path to the enterprise intranet from their BYOD or corporate-issued device. Samsung KNOX VPN implementation offers broad support for the IPSec protocol suite: - Internet Key Exchange (IKE and IKEv2) - Triple DES (56/168-bit), AES (128/256-bit) encryption - Split tunneling mode - NSA Suite B Cryptography Samsung KNOX VPN is FIPS certified enabling its use in regulated environments like government, healthcare, finance, etc. Another distinguishing feature of Samsung KNOX VPN feature is the ability for enterprise IT administrators to configure, provision, and manage the use of VPN on a per-application basis. This capability allows the enterprise to automatically enforce the use of VPN only on a specific set of corporate applications. This has the benefit of ensuring that enterprise data is communicated on a secure connection while keeping the user s personal data from overloading the company s Internet connection. In addition, the per-app VPN feature allows personal-use applications to bypass the VPN and connect directly to the Internet, preserving the users privacy. Samsung KNOX Container Android Framework Corporate s Samsung KNOX VPN The per-app VPN capability is also available for applications within Samsung KNOX Container. Other features of Samsung KNOX VPN implementation include: - Up to 5 simultaneous VPN connections - RSA SecureID support for Cisco VPN gateways - Common Access Card (CAC) support for government use Internet Enterprise Figure 6 Per- VPN in Samsung KNOX 8 page
11 Samsung KNOX offers tamper-proof anti-theft capability combined with a theft recovery service 3. Mobile Device Management Mobile Device Management (MDM) enables the enterprise IT department to monitor, control, and administer all deployed mobile devices across multiple mobile service providers. Samsung KNOX builds upon Samsung s industry leading SAFE MDM capabilities by providing additional policies for security, enterprise integration, and enterprise applications such as asset tracking, remote control, and so on. Enterprise need Remote Management KNOX MDM Policy Groups*** WiFi Accounts Bluetooth Password Browser Limit Features and Functions Kiosk Mode lication permissions Firewall Secure Access to Enterprise Resources lication VPN Exchange Account Geo-fencing Location Real-time Device Status and Activity Device Inventory Manage Voice and Data Usage Roaming Phone Restrictions APN Settings Real-time Mobile User Support Remote Control Prevent Data Leakage Forwarding Container Management Integrity Management Enterprise Integration Single Sign-on Active Directory *** Availability of Samsung KNOX features may vary by MDM partners. Figure 7 KNOX MDM Policy Groups Specific MDM enhancements include: - Policies to comply with the US DoD Mobile OS Requirements Guide (MOS SRG) - Support for Samsung KNOX Container - Support for management via ActiveDirectory/Group Policy Manager - VPN and Wi-Fi Provisioning - Idle screen and lock screen configuration 9 page
12 4. Theft Recovery An undesirable consequence of the rapid growth of smartphones is the equally rapid rise in the theft of mobile devices. Over 40% of robberies in major metropolitan cities are smartphone related 3. Factors behind this phenomenon include the high resale value of the device, inability to disable the device when stolen, and the ability to sell the personal information on the device. Samsung KNOX includes a built-in anti-theft solution that provides both tracking and recovery services in the event of theft. The anti-theft capability is integrated into the device firmware and cannot be disabled even if the device is factory reset. Customer Center Internet Mobile Agent Android Framework Persistence Service Figure 8 Theft Recovery solution of Samsung KNOX The solution consists of two components the Persistence Service that resides in the device firmware, and the Mobile Agent that runs as an Android application. The Persistence Service is dormant until the user subscribes to the theft recovery service and installs the Mobile Agent via an installer. At this point the Persistence Service enables the device for tracking, and ensures that the Mobile Agent is always present, even if the device undergoes a factory reset. When a device is stolen, the user must first report the incident to the local law enforcement agency. The user must then contact the Theft Recovery Customer Center with the police case number assigned. Theft recovery personnel then transmit commands to the Mobile Agent to activate monitoring and tracking, and coordinate with law enforcement to recover the device. 3.CNBC, "The Top 10 Cities for Smartphone Theft and Loss," page
13 Samsung KNOX meets the requirements for FIPS Level 1 certification for both DAR and DIT Samsung KNOX for Government and High Use For government and DoD installations, KNOX provides additional security features, including: 1. Boot Attestation 2. Smartcard - CAC Support 3. Certification & Validations 1. Boot Attestation Samsung KNOX technology uses a Secure Boot protocol that requires the device boot loader, kernel, and system software to be cryptographically signed by a key whose root of trust is verified by the hardware. Commercially sold Samsung devices will have Samsung-issued root certificates. Government deployments generally require that government agencies be the custodian of the entire mobile device firmware including the root certificate. Samsung KNOX technology allows additional roots of trust to be provisioned at the factory. One of these additional roots of trust is reserved for government agencies or their trusted partners to create their own chain of trust. Note that only one root of trust can be active, and all commercially sold devices already have the Samsung root of trust activated. To enable government deployments, Samsung KNOX technology provides tools to government agencies to perform a one-time change of the root of trust from Samsung to the appropriate government agency (or its trusted security partner). This customizable aspect of Secure Boot is unique to Samsung KNOX and gives government entities control over their own approval and chain of trust. The Government can nominate one of its trusted security partners to generate audited, signed firmware images for use on Samsung KNOX devices. 11 page
14 White Paper 2. Smartcard CAC Support The United States Department of Defense (US DoD) has mandated the use of Public Key Infrastructure (PKI) certificates for employees to sign documents digitally, encrypt and decrypt messages, and establish secure online network connections. In compliance with DoD regulations, Samsung KNOX allows the PKI certificates to be stored securely on the mobile device (software certificates) or be retrieved from a CAC (hardware certificates). Samsung KNOX provides applications access to the hardware certificates on the CAC via standardsbased Public Key Cryptography Standards (PKCS) APIs. This enables the use of the CAC card by the browser, application, and VPN client as well as other custom government applications. In addition, Samsung KNOX allows the lock screen to be secured by the CAC card, providing an additional level of device security. lications Enhanced for CAC-support VPN Client Lock Screen PKCS #11 Organization SA M PL E Browser Active Duty John Doe Social Number Age of birth JAN09 Issue Date Expiration Date 2013JAN JUN09 Smart Card Interface CAC Card Android Framework CAC Reader Figure 9 Samsung KNOX Support for CAC 3. Certification & Validations FIPS Certification DISA MOS SRG Compliance Issued by the National Institute of Standards and Technology (NIST), the Federal Information Processing Standard (FIPS) is a US security standard that helps ensure companies that collect, store, transfer, share and disseminate sensitive but unclassified (SBU) information and controlled unclassified information (CUI) can make informed purchasing decisions when choosing devices to use in their workplace. Samsung KNOX meets the requirements for FIPS Level 1 certification for both data-at-rest (DAR) and data-in-transit (DIT). The Samsung KNOX support for DIT covers the following: - Web browser (HTTPS) - (S/MIME) - IPSec VPN 3. Certification & Validations The Defense Information Systems Agency (DISA) is an agency within the US DoD that publishes Requirements Guides (SRGs) as processes to improve the security of DoD information systems. In 2012, DISA published the Mobile Operating System SRG to specify the security requirements that commercially available mobile devices should meet in order to be deployed within the DoD. FIPS Certification DISA MOS SRG Compliance 12 page Samsung KNOX complies with the June, 2012 version of the SRG specification.
15 Summary Reasons cited by CIOs for the poor acceptance of Android in the enterprise stem primarily from concerns over the current state of security in the platform, as well as the lack of management policies. For example, attacks against mobile devices and especially Android devices have been increasing at an alarming rate: In their 2012 Q2 Threats Report, McAfee, a leading security technology company, has discovered nearly 13,000 different types of mobile malware in 2012, up from 2,000 in They also announced that Android malware reports nearly doubled in Q compared to Q Trend Micro, in their 5 Predictions for 2013 and Beyond report for small/medium businesses (SMBs), estimates that the number of malicious and high-risk Android applications will increase three-fold from about 350,000 in 2012 to more than 1 million in Furthermore, as more and more employees are bringing their own devices to work (BYOD), IT adminis trators are concerned about the increased risk to corporate data and network resources: In a survey of 500 leading British CIOs by Virgin Media Business, 51% indicated their secure IT network was breached due to employees using personal services. In addition, smaller businesses experienced 25% less breaches of security compared to larger organizations. With its multi-tiered security model and industry-leading device management capability, Samsung KNOX fully addresses the shortcomings of the open source Android platform for broad enterprise adoption. The enhanced security at the operating system level provided by Secure Boot**, Enhancements for Android, and TIMA protect against malware attacks and hacking. Samsung KNOX Container allows enterprises embracing the BYOD trend to create a secure zone in the employee s device for corporate applications. Access to corporate data and network resources can be restricted to applications within the container. The rich set of MDM policies enables IT administrators to better manage their employees devices and offer improved support by being able to remotely configure various features including Wi-Fi, VPN and page
16 About Samsung Electronics Co., Ltd. Samsung Electronics Co., Ltd. is a global leader in technology, opening new possibilities for people everywhere. Through relentless innovation and discovery, we are transforming the worlds of televisions, smartphones, personal computers, printers, cameras, home appliances, LTE systems, medical devices, semiconductors and LED solutions. We employ 236,000 people across 79 countries with annual sales exceeding KRW 201 trillion. To discover more, please visit For more information about Samsung KNOX, Visit Copyright 2013 Samsung Electronics Co. Ltd. All rights reserved. Samsung is a registered trademark of Samsung Electronics Co. Ltd. Specifications and designs are subject to change without notice. Non-metric weights and measurements are approximate. All data were deemed correct at time of creation. Samsung is not liable for errors or omissions. All brand, product, service names and logos are trademarks and/or registered trademarks of their respective owners and are hereby recognized and acknowledged. Samsung Electronics Co., Ltd. 416, Maetan 3-dong, Yeongtong-gu Suwon-si, Gyeonggi-do , Korea 14 page
White Paper : An Overview of Samsung KNOX
: An Overview of Samsung KNOX June 2013 Enterprise Mobility Solutions Samsung Electronics Co., Ltd. Contents Acronyms Android and the Enterprise Introducing Samsung KNOX Technology Overview 1. Platform
White Paper : An Overview of Samsung KNOX
: An Overview of Samsung KNOX September 2013 Enterprise Mobility Solutions Samsung Electronics Co., Ltd. Contents Acronyms Android and the Enterprise Introducing Samsung KNOX Technology Overview 1. Platform
White Paper: An Overview of the Samsung KNOX TM 2.0 Platform
: An Overview of the Samsung KNOX TM 2.0 Platform March 2014 Enterprise Mobility Solutions Samsung Electronics Co., Ltd. Contents Acronyms Introducing the Samsung KNOX 2.0 Platform What's New in the KNOX
White Paper: Samsung KNOX Value Propostion in the BYOD/COPE Market
: September 2013 Enterprise Mobility Solutions Samsung Electronics Co., Ltd. Contents Acronyms 1 BYOD and COPE: The New Norm? 2 What 2 Introducing Samsung KNOX 3 An Overview of KNOX Security 4 Secure Boot
In-Depth Look at Capabilities: Samsung KNOX and Android for Work
In-Depth Look at Capabilities: Samsung KNOX and Android for Work Silent Install Using the Samsung KNOX Workspace Mobile Device Management (MDM) APIs, IT admins can install and enable applications automatically.
Samsung Telecommunications America. Samsung KNOX : KNOX Glossary of Terms and Acronyms
Samsung Telecommunications America Samsung KNOX : KNOX Glossary of Terms and Acronyms Copyright Notice Copyright 2013, Samsung Electronics. All rights reserved. Document Information This document was created
Samsung Mobile Security
Samsung Mobile Security offering enhanced core capabilities for enterprise mobility Samsung Enterprise Mobility Enterprise-ready Mobility management for your business Samsung Mobile Security offers enterprise
White Paper: An Overview of the Samsung KNOX TM Platform
: An Overview of the Samsung KNOX TM Platform March 2015 Enterprise Mobility Solutions Samsung Electronics Co., Ltd. Contents Samsung KNOX Platform 2 Technology Overview 3 Platform Security 3 Hardware
Flyer 1. Meet evolving enterprise mobility challenges with Samsung KNOX
Flyer 1 Meet evolving enterprise mobility challenges with Samsung KNOX Solve today s dynamic enterprise mobility demands with the right solution platform Enterprise Mobility Trends The growth of enterprise
White Paper: An Overview of the Samsung KNOX TM Platform
: An Overview of the Samsung KNOX TM Platform June 2015 Enterprise Mobility Solutions Samsung Electronics Co., Ltd. Contents Samsung KNOX Platform 2 Technology Overview 3 Platform Security 3 Hardware Root
Samsung KNOX 2. UK Government EUD Guidance Whitepaper
Samsung KNOX 2 UK Government EUD Guidance Whitepaper December 2014 Copyright Notice Copyright 2014 Samsung Electronics Co. Ltd. All rights reserved. Samsung is a registered trademark of Samsung Electronics
Android security maximized by Samsung KNOX. Safeguard enterprise mobility with tightly integrated security, compliance, and control features
Android security maximized by Samsung KNOX Safeguard enterprise mobility with tightly integrated security, compliance, and control features Contents Google Android Lollipop 3 Samsung KNOX 3 KNOX is always
Samsung KNOX User Guide KNOX for Consumers Edition
Samsung KNOX User Guide KNOX for Consumers Edition Version 1.3 Jan 07, 2015 Copyright Notice Copyright 2013 Samsung Electronics Co. Ltd. All rights reserved. Samsung is a registered trademark of Samsung
Whitepaper: Samsung KNOX TM Security Solution
Whitepaper: Samsung KNOX TM Security Solution March 2016 Samsung Research America Samsung Electronics Co., Ltd. Contents Section 1: BYOD and mobile security 3 Section 2: Background: What s in a smartphone?
Mobile App Containers: Product Or Feature?
ANALYST BRIEF Mobile App Containers: Product Or Feature? APPLE AND SAMSUNG HAVE TAKEN BIG STEPS WITH CONTAINERIZATION Author Andrew Braunberg Overview Secure workspaces, or containers, used for isolating
UNCLASSIFIED. Trademark Information
SAMSUNG KNOX ANDROID 1.0 SECURITY TECHNICAL IMPLEMENTATION GUIDE (STIG) OVERVIEW Version 1, Release 1 3 May 2013 Developed by Samsung Electronics Co., Ltd.; Fixmo, Inc.; and General Dynamics C4 Systems,
Security Guide. BlackBerry Enterprise Service 12. for ios, Android, and Windows Phone. Version 12.0
Security Guide BlackBerry Enterprise Service 12 for ios, Android, and Windows Phone Version 12.0 Published: 2015-02-06 SWD-20150206130210406 Contents About this guide... 6 What is BES12?... 7 Key features
PULSE SECURE FOR GOOGLE ANDROID
DATASHEET PULSE SECURE FOR GOOGLE ANDROID Product Overview In addition to enabling network and resource access for corporate managed mobile devices, many enterprises are implementing a Bring Your Own Device
Ensuring the security of your mobile business intelligence
IBM Software Business Analytics Cognos Business Intelligence Ensuring the security of your mobile business intelligence 2 Ensuring the security of your mobile business intelligence Contents 2 Executive
Samsung SED Security in Collaboration with Wave Systems
Samsung SED Security in Collaboration with Wave Systems Safeguarding sensitive data with enhanced performance, robust security, and manageability Samsung Super-speed Drive Secure sensitive data economically
Samsung SDS. Enterprise Mobility Management
Samsung SDS Enterprise Mobility Samsung SDS Enterprise Mobility Faster and Safer Samsung SDS Enterprise Mobility provides stronger security for enterprise mobility without Compromising usability of mobile
White Paper: An Overview of the Samsung KNOX TM Platform
: An Overview of the Samsung KNOX TM Platform September 2015 Enterprise Mobility Solutions Samsung Electronics Co., Ltd. Contents Samsung KNOX Platform 2 Technology Overview 3 Platform Security 3 Hardware
BlackBerry Enterprise Service 10. Secure Work Space for ios and Android Version: 10.1.1. Security Note
BlackBerry Enterprise Service 10 Secure Work Space for ios and Android Version: 10.1.1 Security Note Published: 2013-06-21 SWD-20130621110651069 Contents 1 About this guide...4 2 What is BlackBerry Enterprise
WIND RIVER SECURE ANDROID CAPABILITY
WIND RIVER SECURE ANDROID CAPABILITY Cyber warfare has swiftly migrated from hacking into enterprise networks and the Internet to targeting, and being triggered from, mobile devices. With the recent explosion
The ForeScout Difference
The ForeScout Difference Mobile Device Management (MDM) can help IT security managers secure mobile and the sensitive corporate data that is frequently stored on such. However, ForeScout delivers a complete
Xperia TM. Read about how Xperia TM devices can be administered in a corporate IT environment
Xperia TM in Business Mobile Device Management Read about how Xperia TM devices can be administered in a corporate IT environment Device management clients Xperia TM T3 Exchange ActiveSync The my Xperia
Ensuring the security of your mobile business intelligence
IBM Software Business Analytics Cognos Business Intelligence Ensuring the security of your mobile business intelligence 2 Ensuring the security of your mobile business intelligence Contents 2 Executive
ForeScout MDM Enterprise
Highlights Features Automated real-time detection of mobile Seamless enrollment & installation of MDM agents on unmanaged Policy-based blocking of unauthorized Identify corporate vs. personal Identify
Symantec App Center. Mobile Application Management and Protection. Data Sheet: Mobile Security and Management
Mobile Application Management and Protection Data Sheet: Mobile Security and Management Overview provides integrated mobile application and device management capabilities for enterprise IT to ensure data
Mobile First Government
Mobile First Government An analysis of NIST and DISA requirements for the adoption of commercially available mobility platforms by government agencies August 2013 415 East Middlefield Road Mountain View,
Windows Phone 8.1 Mobile Device Management Overview
Windows Phone 8.1 Mobile Device Management Overview Published April 2014 Executive summary Most organizations are aware that they need to secure corporate data and minimize risks if mobile devices are
Addressing NIST and DOD Requirements for Mobile Device Management (MDM) Essential Capabilities for Secure Mobility. www.maas360.
MaaS360.com > White Paper Addressing NIST and DOD Requirements for Mobile Device Management (MDM) Essential Capabilities for Secure Mobility www.maas360.com 1 Copyright 2014 Fiberlink Communications Corporation.
Security Technical. Overview. BlackBerry Enterprise Service 10. BlackBerry Device Service Solution Version: 10.2
BlackBerry Enterprise Service 10 BlackBerry Device Service Solution Version: 10.2 Security Technical Overview Published: 2014-09-10 SWD-20140908123239883 Contents 1 About BlackBerry Device Service solution
An Overview of Samsung KNOX Active Directory and Group Policy Features
C E N T R I F Y W H I T E P A P E R. N O V E M B E R 2013 An Overview of Samsung KNOX Active Directory and Group Policy Features Abstract Samsung KNOX is a set of business-focused enhancements to the Android
Kaspersky Security for Mobile Administrator's Guide
Kaspersky Security for Mobile Administrator's Guide APPLICATION VERSION: 10.0 SERVICE PACK 1 Dear User, Thank you for choosing our product. We hope that you will find this documentation useful and that
Data Loss Prevention Whitepaper. When Mobile Device Management Isn t Enough. Your Device Here. Good supports hundreds of devices.
Data Loss Prevention Whitepaper When Mobile Device Management Isn t Enough Your Device Here. Good supports hundreds of devices. Contents Shifting Security Landscapes 3 Security Challenges to Enterprise
Deploying iphone and ipad Security Overview
Deploying iphone and ipad Security Overview ios, the operating system at the core of iphone and ipad, is built upon layers of security. This enables iphone and ipad to securely access corporate services
Complying with PCI Data Security
Complying with PCI Data Security Solution BRIEF Retailers, financial institutions, data processors, and any other vendors that manage credit card holder data today must adhere to strict policies for ensuring
Addressing NIST and DOD Requirements for Mobile Device Management
Addressing NIST and DOD Requirements for Mobile Device Management Whitepaper 2013 ForeScout Technologies, Inc. All rights reserved. Call Toll-Free: 1.866.377.8771 www.forescout.com Contents 1. OVERVIEW
Xperia TM. Read about how Xperia TM devices can be administered in a corporate IT environment
peria TM in Business Mobile Device Management Read about how peria TM devices can be administered in a corporate IT environment Device management clients March 2015 Exchange ActiveSync The my peria service
BlackBerry 10.3 Work and Personal Corporate
GOV.UK Guidance BlackBerry 10.3 Work and Personal Corporate Published Contents 1. Usage scenario 2. Summary of platform security 3. How the platform can best satisfy the security recommendations 4. Network
Guideline on Safe BYOD Management
CMSGu2014-01 Mauritian Computer Emergency Response Team CERT-MU SECURITY GUIDELINE 2011-02 Enhancing Cyber Security in Mauritius Guideline on Safe BYOD Management National Computer Board Mauritius Version
Security Considerations for DirectAccess Deployments. Whitepaper
Security Considerations for DirectAccess Deployments Whitepaper February 2015 This white paper discusses security planning for DirectAccess deployment. Introduction DirectAccess represents a paradigm shift
Guidance End User Devices Security Guidance: Apple ios 7
GOV.UK Guidance End User Devices Security Guidance: Apple ios 7 Updated 10 June 2014 Contents 1. Changes since previous guidance 2. Usage Scenario 3. Summary of Platform Security 4. How the Platform Can
Norton Mobile Privacy Notice
Effective: April 12, 2016 Symantec and the Norton brand have been entrusted by consumers around the world to protect their computing devices and most important digital assets. This Norton Mobile Privacy
Windows Phone 8 Security Overview
Windows Phone 8 Security Overview This white paper is part of a series of technical papers designed to help IT professionals evaluate Windows Phone 8 and understand how it can play a role in their organizations.
Securing Patient Data in Today s Mobilized Healthcare Industry. A Good Technology Whitepaper
Securing Patient Data in Today s Mobilized Healthcare Industry Securing Patient Data in Today s Mobilized Healthcare Industry 866-7-BE-GOOD good.com 2 Contents Executive Summary The Role of Smartphones
USER TRAINING. Enterprise Mobility Solutions October 23, 2013
USER TRAINING Enterprise Mobility Solutions October 23, 2013 Using Samsung KNOX Samsung KNOX is a new Android-based platform designed specifically to overcome the shortcomings of the current open source
Release Notes. KNOX Premium SDK. Version 2.5
Release Notes Premium SDK 2.5 September 2015 Copyright Notice Copyright 2015 Samsung Electronics Co. Ltd. All rights reserved. Samsung is a registered trademark of Samsung Electronics Co. Ltd. Samsung
Securing Corporate Email on Personal Mobile Devices
Securing Corporate Email on Personal Mobile Devices Table of Contents The Impact of Personal Mobile Devices on Corporate Security... 3 Introducing LetMobile Secure Mobile Email... 3 Solution Architecture...
IBM MobileFirst Protect: Secure & Manage your mobile enterprise
IBM MobileFirst Protect: Secure & Manage your mobile enterprise SolutionsConnect Vietnam March 2015 Stephen Downie Growth Markets, Unified Endpoint Management 1 Digital and mobile technologies are making
TCS Hy5 Presidio Your Mobile Environment, Your Way Configure, Secure, Deploy. Mobility Solutions
TCS Hy5 Presidio Your Mobile Environment, Your Way Configure, Secure, Deploy Mobility Solutions The growth of in-house and third-party enterprise mobile applications; device diversity across ios, Android,
Copyright 2013, 3CX Ltd. http://www.3cx.com E-mail: [email protected]
Manual Copyright 2013, 3CX Ltd. http://www.3cx.com E-mail: [email protected] Information in this document is subject to change without notice. Companies names and data used in examples herein are fictitious
Analysis of advanced issues in mobile security in android operating system
Available online atwww.scholarsresearchlibrary.com Archives of Applied Science Research, 2015, 7 (2):34-38 (http://scholarsresearchlibrary.com/archive.html) ISSN 0975-508X CODEN (USA) AASRC9 Analysis of
What We Do: Simplify Enterprise Mobility
What We Do: Simplify Enterprise Mobility AirWatch by VMware is the global leader in enterprise-grade mobility solutions across every device, every operating system and every mobile deployment. Our scalable
Today s Best Practices: How smart business is protecting enterprise data integrity and employee privacy on popular mobile devices. Your Device Here.
Securing Business Mobility Today s Best Practices: How smart business is protecting enterprise data integrity and employee privacy on popular mobile devices Your Device Here. Good supports hundreds of
Feature List for Kaspersky Security for Mobile
Feature List for Kaspersky Security for Mobile Contents Overview... 2 Simplified Centralized Deployment... 2 Mobile Anti-Malware... 3 Anti-Theft / Content Security... Error! Bookmark not defined. Compliance
Working Together Managing and Securing Enterprise Mobility WHITE PAPER. Larry Klimczyk Digital Defence P: 222.333.4444
Working Together Managing and Securing Enterprise Mobility WHITE PAPER Larry Klimczyk Digital Defence P: 222.333.4444 Contents Executive Summary... 3 Introduction... 4 Security Requirements... 5 Authentication...
ipad in Business Security
ipad in Business Security Device protection Strong passcodes Passcode expiration Passcode reuse history Maximum failed attempts Over-the-air passcode enforcement Progressive passcode timeout Data security
Security Technical. Overview. BlackBerry Enterprise Server for Microsoft Exchange. Version: 5.0 Service Pack: 4
BlackBerry Enterprise Server for Microsoft Exchange Version: 5.0 Service Pack: 4 Security Technical Overview Published: 2014-01-17 SWD-20140117135425071 Contents 1 New in this release...10 2 Overview...
MobileIron and Samsung Value Proposition
MobileIron and Samsung Value Proposition Focused on customer success 4000+ 24x7 200+ 97% customers globally Operating globally of Fortune 500 / Global 2000 customer support satisfaction 8 of top 10 global
Healthcare Compliance Solutions
Privacy Compliance Healthcare Compliance Solutions Trust and privacy are essential for building meaningful human relationships. Let Protected Trust be your Safe Harbor The U.S. Department of Health and
BYOD Guidance: BlackBerry Secure Work Space
GOV.UK Guidance BYOD Guidance: BlackBerry Secure Work Space Published 17 February 2015 Contents 1. About this guidance 2. Summary of key risks 3. Secure Work Space components 4. Technical assessment 5.
F i g u r e 1. Worldwide Business Use of Smartphones 2012-2016
S O L U T I O N S P O T L I G H T Securing Android for the Enterprise December 2013 By Ian Song and Charles Reed Anderson Sponsored by Samsung This Solution Spotlight focuses on providing clarity to confusion
GO!Enterprise MDM Device Application User Guide Installation and Configuration for Android
GO!Enterprise MDM Device Application User Guide Installation and Configuration for Android GO!Enterprise MDM for Android, Version 3.x GO!Enterprise MDM for Android 1 Table of Contents GO!Enterprise MDM
Securing Mobile Apps in a BYOD World
SAP Thought Leadership Paper Mobile App Security Securing Mobile Apps in a BYOD World Protecting Apps Makes You More Responsive to Demands for Enterprise Mobility Table of Contents 4 The Mobile App Tsunami
Guidance End User Devices Security Guidance: Apple OS X 10.9
GOV.UK Guidance End User Devices Security Guidance: Apple OS X 10.9 Published 23 January 2014 Contents 1. Changes since previous guidance 2. Usage Scenario 3. Summary of Platform Security 4. How the Platform
How To Protect Your Mobile Devices From Security Threats
Back to the Future: Securing your Unwired Enterprise By Manoj Kumar Kunta, Global Practice Leader - Security Back to the Future: Securing your Unwired Enterprise The advent of smartphones and tablets has
Cisco Trust Anchor Technologies
Data Sheet Cisco Trust Anchor Technologies Overview Cisco Trust Anchor Technologies provide the foundation for trustworthy systems across Cisco. The Cisco Trust Anchor and a Secure Boot check of signed
Kony Mobile Application Management (MAM)
Kony Mobile Application Management (MAM) Kony s Secure Mobile Application Management Feature Brief Contents What is Mobile Application Management? 3 Kony Mobile Application Management Solution Overview
Deploy secure, corporate access for mobile device users with the Junos Pulse Mobile Security Suite
WHITE PAPER Mobile Device Security in the Enterprise Deploy secure, corporate access for mobile device users with the Junos Pulse Mobile Security Suite Copyright 2010, Juniper Networks, Inc. Table of Contents
The Changing Role of the CIO. An IDC InfoBrief, sponsored by Samsung Canada March 2014
An IDC InfoBrief, sponsored by Samsung Canada March 2014 The Changing Role of the CIO What s most important today? 60% of Top IT Executives identify Improving Staff Productivity as their biggest IT priority
MOBILITY & INTERCONNECTIVITY. Features SECURITY OF INFORMATION TECHNOLOGIES
MOBILITY & INTERCONNECTIVITY Features SECURITY OF INFORMATION TECHNOLOGIES Frequent changes to the structure of enterprise workforces mean that many are moving away from the traditional model of a single
ios Security Decoded Dave Test Classroom and Lab Computing Penn State ITS Feedback - http://j.mp/psumac33
ios Security Decoded Dave Test Classroom and Lab Computing Penn State ITS Feedback - http://j.mp/psumac33 Why care about ios Security? 800M 800 million ios devices activated 130 million in last year 98%
Welcome! Thank you! mobco about mobile samsung about devices mobileiron about mobile IT accellion on mobile documents hands-on devices and race karts
Welcome! Thank you! mobco about mobile samsung about devices mobileiron about mobile IT accellion on mobile documents hands-on devices and race karts 2013 mobco MobileIron Hendrik Van De Velde Your regional
Chris Boykin VP of Professional Services
5/30/12 Chris Boykin VP of Professional Services Future Com! 20 years! Trusted Advisors! Best of brand partners! Brand name customers! 1000 s of solutions delivered!! 1 5/30/12 insight to the future, bringing
SENSE Security overview 2014
SENSE Security overview 2014 Abstract... 3 Overview... 4 Installation... 6 Device Control... 7 Enrolment Process... 8 Authentication... 9 Network Protection... 12 Local Storage... 13 Conclusion... 15 2
APPENDIX B1 - FUNCTIONALITY AND INTEGRATION REQUIREMENTS RESPONSE FORM FOR A COUNTY HOSTED SOLUTION
APPENDIX B1 - FUNCTIONALITY AND INTEGRATION REQUIREMENTS RESPONSE FORM FOR A COUNTY HOSTED SOLUTION Response Code: Offeror should place the appropriate letter designation in the Availability column according
An Overview of Samsung KNOX Active Directory-based Single Sign-On
C E N T R I F Y W H I T E P A P E R. S E P T E M B E R 2013 An Overview of Samsung KNOX Active Directory-based Single Sign-On Abstract Samsung KNOX is a set of business-focused enhancements to the Android
Security Guide. BES12 Cloud
Security Guide BES12 Cloud Published: 2015-08-20 SWD-20150812133927242 Contents Security features of BES12 Cloud...4 How BES12 Cloud protects data stored in BlackBerry data centers...4 How BES12 Cloud
Windows Phone 8.1 in the Enterprise
Windows Phone 8.1 in the Enterprise Version 1.4 MobileIron 415 East Middlefield Road Mountain View, CA 94043 USA Tel. +1.650.919.8100 Fax +1.650.919.8006 [email protected] Introduction 3 Why Windows
M-Shield mobile security technology
Technology for Innovators TM M-Shield mobile security technology making wireless secure Overview As 3G networks are successfully deployed worldwide, opportunities are arising to deliver to end-users a
CHOOSING AN MDM PLATFORM
CHOOSING AN MDM PLATFORM Where to Start the Conversation Whitepaper 2 Choosing an MDM Platform: Where to Start the Conversation There are dozens of MDM options on the market, each claiming to do more than
COMMONWEALTH OF PENNSYLVANIA DEPARTMENT S OF PUBLIC WELFARE, INSURANCE AND AGING
COMMONWEALTH OF PENNSYLVANIA DEPARTMENT S OF PUBLIC WELFARE, INSURANCE AND AGING INFORMATION TECHNOLOGY STANDARD Name Of Standard: Mobile Device Standard Domain: Security Date Issued: 09/07/2012 Date Revised:
Longmai Mobile PKI Solution
Longmai Mobile PKI Solution A quick Solution to External and Internal fraud in Insurance Industry Putting the client at the center of modernization Contents 1. INTRODUCTION... 3 1.1 Challenges... 3 1.2
End User Devices Security Guidance: Apple OS X 10.10
GOV.UK Guidance End User Devices Security Guidance: Apple OS X 10.10 Published Contents 1. Changes since previous guidance 2. Usage scenario 3. Summary of platform security 4. How the platform can best
Choosing an MDM Platform
Whitepaper Choosing an MDM Platform Where to Start the Conversation 2 Choosing an MDM Platform: Where to Start the Conversation There are dozens of MDM options on the market, each claiming to do more than
