1월 19, 2020

Samsung Knox File Encryption 1.0 - The first certified integrated Dual Data-at-Rest solution for mobile devices

Brian Wood

As more organizations look for data isolation capabilities, one of the key tools is encrypting data only until it is needed. This isn’t a new solution; it is the backbone of most security. The difference has always been in how easy (or hard) it is to deploy the encryption for the organization, and how hard it is to use once it has been deployed, especially on mobile devices. With Samsung Knox File Encryption, a Work Profile can have an independent layer of encryption, without the need to deploy additional components or change how users (or their applications) work.

 

What is Data-at-Rest?

Data-at-Rest (DAR) is simply encrypting data when it is stored. Samsung devices encrypt all user data by default, so when your mobile device is off, the data cannot be read (as plain text) until your password has been entered. DAR protection happens automatically, in the background, without the user needing to do anything different than to unlock the device.

 

So what is Dual Data-at-Rest?

So if DAR is encrypting all your files when they are written to storage, DualDAR is encrypting files twice, with two different keys. For example, encrypting an individual file (say by zipping the file and placing a password on it), on a device that already has all the files encrypted, is DualDAR. It provides additional protection on the protected file(s) when the system is running and the main DAR layer is unlocked.

 

If Dual Data-at-Rest is so great, why don’t we use it all the time?

As with any encryption solution, there are always 4 major questions:

  1. Do I have data to protect that needs the additional security?
  2. How hard is it to deploy?
  3. How hard will it be to use?
  4. What is the overhead of using the solution?

The first question is probably the most important. If you have data that should remain confidential most of the time, then it may be a high priority to add an encryption layer to that data. But this needs to be balanced with the rest of the questions. Many security solutions are difficult to deploy and maintain. Complicated deployments and a lot of administrator time means the solutions are unlikely to be used. Similarly, if the solution is hard for an end user, they will either try to ignore it (that is, not use it), or even actively work around it. Lastly, if the implementation slows down the system noticeably, or drains the battery faster, then users will come to the same conclusion that it is hard to use.

In most cases, while an organization may say the answer to the first question is that they should have the additional security on the data, the answers to deploying a solution to do so, in terms of additional overhead (both administrative and end user) are sufficient to mean the organization will not add the additional security.

 

The Samsung Knox File Encryption approach

The difference with Samsung Knox File Encryption is that the answers to the last three questions become:

  1. Easy
  2. Easy
  3. Not noticeable

This makes the answer to the first question more about the data security than it does about how to add the protection.

Samsung Knox File Encryption is a simple setting to be enabled in a Work Profile when it is deployed. The end user opens the Work Profile the same way they would normally, but all files inside the Work Profile are now automatically encrypted. For performance, Samsung has integrated with the hardware accelerated encryption engines already available on the device, so performance is fast and impacts on things like battery life are minimal.

 

What is the certification?

On December 9, 2019, the National Information Assurance Partnership (NIAP) certified Samsung Knox File Encryption 1.0 to the requirements in the PP-Module for File Encryption Version 1.0 and Protection Profile for Application Software Version 1.3. This certification means the Knox File Encryption components have been evaluated to meet US government requirements for functionality, including the encryption requirements for securing classified data.

 

Who would use this?

Samsung designed Knox File Encryption around the NSA requirements found in the Data-at-Rest Capability Package. While these requirements are specifically written for classified environments, Samsung focused on creating a simple solution that would be easy for anyone to use, not just the NSA. Any organization that has confidential data that may be stored on mobile devices should consider implementing our DualDAR encryption on their Work Profiles.

 

What next?

Browse the KPE White PaperWhitepaper Check the Knox Service Plugin Admin GuideAdmin Guide Review the Knox SDK Developer GuideDeveloper Guide Reach out to our Knox Partner Program

[아이콘] 닫기

삼성 Knox 시작하기

[아이콘] 여행가방
리셀러, 솔루션 공급업체 또는 서비스 공급업체이신가요?

지금 Knox 파트너가 되어 비즈니스 성장을 도모하세요.

[아이콘] 정보

시작할 Knox 제품 선택:

올인원 번들
Knox Suite
리브랜딩 및 맞춤 설정
Knox Configure
사기 및 도난 방지
Knox Guard
디바이스 보호 플랜
Samsung Care+ for Business
기타 제품 및 서비스

시작하기

[이미지] Knox Suite

기업용 모바일을 위한 일체형 솔루션 번들

  • 최대 30대의 디바이스에 제공되는 90일 무료 평가판을 사용해 보세요.
  • 회사 디바이스를 안전하게 보호, 배포, 관리 및 분석할 수 있는 완벽한 툴 모음입니다.
  • Knox Suite와 함께 제공되는 강력한 기능을 사용해 보세요.

Knox Suite에는 다음이 포함됩니다.:

Knox Mobile Enrollment 무료
Knox Manage
Knox E-FOTA
Knox Asset Intelligence
Knox Platform for Enterprise 무료
Knox Remote Support
Knox Capture
Knox Authentication Manager

시작하기

[이미지] Knox Configure 로고

삼성 디바이스를 리브랜딩하고 맞춤 설정하세요.

  • 최대 30대의 디바이스에 제공되는 90일 무료 평가판을 사용해 보세요.
  • 삼성 디바이스를 대량으로 구매하는 즉시 원격으로 구성하고 특정 요구 사항을 충족하도록 맞춤 구성합니다.
  • 디바이스를 일회성 배포를 위해 설정하거나 원하는 만큼 업데이트할 수 있습니다.

시작하기

[아이콘] Knox Guard 로고

삼성 디바이스를 위한 사기 및 도난 방지

  • 최대 30대의 디바이스에 제공되는 90일 무료 평가판을 사용해 보세요.
  • 원격으로 삼성 디바이스를 제어하여 금융 관련 위험성을 줄이고 자산을 보호하세요.
  • SIM 제어 및 디바이스 잠금 기능을 포함한 Knox Guard의 모든 기능을 사용해 보세요.

시작하기

[이미지] Samsung Care Plus For Business 로고

삼성 디바이스를 위한 디바이스 보호 플랜

  • 빠른 디바이스 수리 및 교체로 업무 중단을 최소화합니다. 시작하려면 삼성 영업팀에 문의하세요.
  • 한 곳에서 모든 디바이스 보증 범위 및 청구 정보를 확인하세요.
  • 이미 Samsung Care+ for Business를 구매하셨나요? Samsung Care+ for Business 콘솔에서 계정을 만들고 플랜을 활성화하세요.

기타 제품 및 서비스

[이미지] 기타 로고

고객의 고유한 요구 사항을 해결하는 최신 솔루션입니다.

  • Enterprise Tech Support를 통해 전담 계정 관리자로부터 효율적인 기술 지원을 받아보세요.
  • 삼성 소프트웨어 맞춤 설정 서비스를 사용하여 귀사를 위한 맞춤형 디바이스를 만들어 보십시오.
영업 팀에 문의