10월 18, 2021

Common Criteria smartphone certification: How Samsung Knox is leading the way

Brian Wood

If you’re not an IT leader in federal government, chances are you may never have heard of Common Criteria. But whoever you are, Common Criteria has a big effect on the security of the products you buy. Everyone who sells information technology solutions to security-sensitive public sector organizations must build their products based on the requirements in Common Criteria. And in today’s world of proliferating cyber security threats, it’s increasingly viewed as benchmark all enterprises look to in evaluating their mobile technology.

Over the past decade, Samsung has committed to Common Criteria’s process of continuous mobile security elevation — not just by building our devices and Knox security platform to align with Common Criteria, but by participating in the process and contributing our expertise. Here’s an overview of Common Criteria, why it’s important for the security of mobile devices and how Samsung has supported its evolution.

 

What is Common Criteria?

Let’s skip all the buzzwords and get to the point: With Common Criteria, experts get together — typically coordinated by a government agency — to define what it means for a particular type of product to be “secure.” Then, anyone who wants to sell a product can go to an independent testing lab and say, “My product X is secure. Please verify this.” The result is good for the customer, as it provides a “third-party validation” of the vendor claims.

This process — the setting of requirements, independent review of vendor devices and validation of conformance — lets buyers trust that evaluated products are secure independent of any vendor claims. The level of trust in the Common Criteria process is so high that 30 governments around the world have agreed to accept Common Criteria evaluations as valid, regardless of where the evaluation was done. While Common Criteria is especially popular in the public sector, it has knock-on effects for everyone who buys a product.

Here’s an example of how the process works. In Common Criteria, a set of defined security requirements is called a Protection Profile. Many of these Protection Profiles have been created, but an essential one for Samsung is called the Protection Profile for Mobile Device Fundamentals (PP_MD), which covers things like smartphones and tablets. The requirements for Mobile Devices under Common Criteria add up to 241 pages.

On just one of those pages, there are requirements about how smartphones must generate cryptographic keys using a random number generator. It’s not a big section, just three points — a short but sweet list of requirements for making high-quality cryptographic keys. But it is essential, because if you aren’t making your cryptographic keys from truly random numbers, you may have a huge security flaw: All your encryption could be useless if the keys are easy to guess. (Don’t laugh — this has happened many times in the past.) If a programmer writing smartphone software calls just any random number function they find, you could end up with weak keys, and poor security. Common Criteria gets rid of the trust element (“We trust that Samsung will do a good job”) and replaces it with independently defined criteria and independent testing.

For general-purpose smartphones, we focus on the three most applicable Common Criteria Protection Profiles. The basis for all our validations is Mobile Device Fundamentals, which takes a holistic look at a mobile device and how it will be used. In addition, we also validate our products against the VPN Client and File Encryption Protection Profiles.

 

Samsung and Common Criteria

Samsung has been an active, leading participant in the Common Criteria process in the U.S. (through the U.S. National Information Assurance Partnership) and within the international community. When it comes to security for mobile devices, we’ve helped to define the requirements and write the standards.

But Samsung’s participation and input isn’t limited to mobile. We were also an active participant in defining Common Criteria specifications for Data-at-Rest, which applies to all sorts of devices. Samsung actively participates in more than 10 Common Criteria technical communities in the United States and abroad.

Thanks to our early participation in the mobile device technical community more than eight years ago, Samsung was the first mobile device vendor to be certified under Common Criteria for Mobile Device Fundamentals, starting with the Galaxy S4 and Android 4.4. Since then, Samsung has garnered more Common Criteria certifications than any other mobile vendor.

In addition to certifying Samsung devices, Samsung has worked with Google and the open source community to enhance the Android Open Source Project (AOSP) to meet Common Criteria requirements for security. Our contribution of the intellectual property around Mandatory Access Controls, for example, helps Android phones meet Common Criteria requirements.

Why are we so involved in Common Criteria, when most of our consumer end users haven’t even heard of the program? Because we believe Common Criteria sets a high bar for security — not just for government customers, but for everyone. And everyone deserves a secure device.

By working to provide consumer devices with defense-grade security, we make everyone more secure.

 

Additional security measures from Samsung

Common Criteria serves as a common base for defining security capabilities, but our security-focused smartphones go far beyond the basic requirements. For example, with the hardware encryption capabilities built into Samsung Knox, devices can support longer encryption keys for higher security while still maintaining a high level of user performance.

Another example is Samsung Knox Vault, a security component that goes beyond TrustZone to help protect your most critical data. While Common Criteria allows the possibility of something like Knox Vault, it is not a mandatory requirement. But because we believe the security functionality provided by Knox Vault is so important, Samsung independently certifies Knox Vault under Common Criteria. The security of Knox Vault in our newest hardware has been tested and certified by an independent, third-party under Common Criteria.

IT managers who need Common Criteria certification can rely on Samsung’s full commitment to keep delivering secure, fully certified devices. Samsung continues to build on top of the components of our smartphones and tablets — hardware and software — to create a holistic security posture, enhancing our overall security for all our customers.

 

If you’re not quite sure which mobile tools are right for your agency, browse Samsung’s versatile, reliable range of defense-grade mobile solutions protected by government-ready security.

[아이콘] 닫기

삼성 Knox 시작하기

[아이콘] 여행가방
리셀러, 솔루션 공급업체 또는 서비스 공급업체이신가요?

지금 Knox 파트너가 되어 비즈니스 성장을 도모하세요.

[아이콘] 정보

시작할 Knox 제품 선택:

올인원 번들
Knox Suite
리브랜딩 및 맞춤 설정
Knox Configure
사기 및 도난 방지
Knox Guard
디바이스 보호 플랜
Samsung Care+ for Business
기타 제품 및 서비스

시작하기

[이미지] Knox Suite

기업용 모바일을 위한 일체형 솔루션 번들

  • 최대 30대의 디바이스에 제공되는 90일 무료 평가판을 사용해 보세요.
  • 회사 디바이스를 안전하게 보호, 배포, 관리 및 분석할 수 있는 완벽한 툴 모음입니다.
  • Knox Suite와 함께 제공되는 강력한 기능을 사용해 보세요.

Knox Suite에는 다음이 포함됩니다.:

Knox Mobile Enrollment 무료
Knox Manage
Knox E-FOTA
Knox Asset Intelligence
Knox Platform for Enterprise 무료
Knox Remote Support
Knox Capture
Knox Authentication Manager

시작하기

[이미지] Knox Configure 로고

삼성 디바이스를 리브랜딩하고 맞춤 설정하세요.

  • 최대 30대의 디바이스에 제공되는 90일 무료 평가판을 사용해 보세요.
  • 삼성 디바이스를 대량으로 구매하는 즉시 원격으로 구성하고 특정 요구 사항을 충족하도록 맞춤 구성합니다.
  • 디바이스를 일회성 배포를 위해 설정하거나 원하는 만큼 업데이트할 수 있습니다.

시작하기

[아이콘] Knox Guard 로고

삼성 디바이스를 위한 사기 및 도난 방지

  • 최대 30대의 디바이스에 제공되는 90일 무료 평가판을 사용해 보세요.
  • 원격으로 삼성 디바이스를 제어하여 금융 관련 위험성을 줄이고 자산을 보호하세요.
  • SIM 제어 및 디바이스 잠금 기능을 포함한 Knox Guard의 모든 기능을 사용해 보세요.

시작하기

[이미지] Samsung Care Plus For Business 로고

삼성 디바이스를 위한 디바이스 보호 플랜

  • 빠른 디바이스 수리 및 교체로 업무 중단을 최소화합니다. 시작하려면 삼성 영업팀에 문의하세요.
  • 한 곳에서 모든 디바이스 보증 범위 및 청구 정보를 확인하세요.
  • 이미 Samsung Care+ for Business를 구매하셨나요? Samsung Care+ for Business 콘솔에서 계정을 만들고 플랜을 활성화하세요.

기타 제품 및 서비스

[이미지] 기타 로고

고객의 고유한 요구 사항을 해결하는 최신 솔루션입니다.

  • Enterprise Tech Support를 통해 전담 계정 관리자로부터 효율적인 기술 지원을 받아보세요.
  • 삼성 소프트웨어 맞춤 설정 서비스를 사용하여 귀사를 위한 맞춤형 디바이스를 만들어 보십시오.
영업 팀에 문의