6월 30, 2020

Samsung products approved as independent cryptographic layers for DAR CP

Brian Wood

One of the most important security measures for any data, especially on a mobile device, is data encryption. The Data-at-Rest Capability Package (DAR CP) defines a high bar for ensuring data is encrypted not just once, but twice, to meet the needs for protecting classified data as part of the Commercial Solutions for Classified (CSfC) program. A key component for any solution to meet the requirements of the DAR CP is to have independent cryptographic layers for protecting the stored data.

Samsung devices supporting Samsung Knox File Encryption have now been approved as meeting this requirement for independent layers natively, without the need for third-party cryptography.

What is the DAR CP?

As part of the CSfC program, the National Security Agency (NSA) has created several Capability Packages. These are requirements that must be met for any solution that will handle data that is classified, and so are outlines for how the group should approach building said solution. Components that can be used to meet the requirements of Capability Packages must be approved by the NSA to be listed on the Components List site. The DAR CP is specifically focused on the storage of classified data on the local device.

The DAR CP provides many different possible solutions based on the devices in question, though for mobile devices, the expected configuration is called PE/FE (or PF) for Platform Encryption/File Encryption. The Platform Encryption would be considered the outer layer, while the File Encryption would be considered the inner layer. In normal operations, the outer layer would be unlocked say at boot, while the inner layer would remain locked until the user would need to access the classified data, and locked again once access is no longer needed.

In addition to the requirements about encryption algorithms, key sizes and device configuration, the DAR CP also mandates that each layer of data encryption be cryptographically independent.

What does it mean to be cryptographically independent?

Cryptographic independence for the NSA means that each layer performing the encryption must be implemented using different methods and most importantly, different cryptographic modules. Further, the cryptographic modules cannot just be copies of the same module embedded into a different method of handling the encryption. This is meant to ensure that a potential vulnerability in one module would not also be found in the second module, providing confidence that there is at least one layer that is not compromised.

The most common method for handling independence is through manufacturer diversity. In practice this means that the customer would need to purchase and integrate two programs from separate vendors, once for each layer. For example, on a PC, the customer could implement a Full Disk Encryption solution for the outer layer and then some sort of file encryption for the inner layer (such as encrypted ZIP files). The key point though, would be that the two layers would come from two different vendors, using two different cryptographic modules.

What is the Samsung solution?

The Samsung solution, meeting the PF configuration in the DAR CP, is based on components that are evaluated as part of the Protection Profile for Mobile Device Fundamentals 3.1 (PP_MD_V3.1 or MDFPP) and as part of the PP-Module for File Encryption 1.0 (MOD_FE_V1.0).

The outer layer (PE component) is the File-Based Encryption evaluated as part of the PP_MD_V3.1 evaluation, which encrypts the entire user data partition. The inner layer (FE component) is the Samsung Knox File Encryption product which is part of a Work Profile. When enabled, all data stored within the Work Profile is encrypted, and then is passed to the file system for encryption by the outer layer. All encryption happens automatically, without any user intervention.

How is Samsung cryptographically independent?

The Samsung design to provide both layers was specifically targeted to meet the requirements of the DAR CP, including cryptographic independence. The outer layer of encryption is handled by a hardware storage encryption module that is part of the System-on-Chip (SoC). The inner layer of encryption is handled by a kernel cryptographic module. The inner layer was specifically chosen to be separate and independent of the outer layer.

The outer layer, as part of the SoC, is maintained by the hardware provider (such as Samsung Semiconductor or Qualcomm, depending on the device model), while the kernel cryptographic module is maintained by Samsung Research.

What does this mean for Samsung devices?

On June 5, 2020 the NSA provided CSfC Independent Layer Approval for devices that have Android 9 and Android 10 and Samsung Knox File Encryption v1.0 (for Android 9) and v1.2 (for Android 10). This means that with the appropriate devices and configuration, a customer can use a Samsung device with no additional software, and meet the requirements of the DAR CP.

 

Who would use this?

Samsung designed Knox File Encryption around the NSA requirements found in the Data-at-Rest Capability Package, built on top of the encryption already provided by default. While these requirements are specifically written for classified environments, Samsung focused on creating a simple solution that would be easy for anyone to use, not just the NSA. Any organization that has confidential data that may be stored on mobile devices should consider implementing encryption on the Work Profile.

 

What next?

Find out how Samsung Knox’s DualDAR works - Browse the KPE White PaperWhitepaper See how IT admins configure DualDAR - Check the Knox Service Plugin Admin GuideAdmin Guide See how apps can configure DualDAR - Review the Knox SDK Developer GuideDeveloper Guide Contact us for more info - Reach out to our Knox Partner Program

[아이콘] 닫기

삼성 Knox 시작하기

[아이콘] 여행가방
리셀러, 솔루션 공급업체 또는 서비스 공급업체이신가요?

지금 Knox 파트너가 되어 비즈니스 성장을 도모하세요.

[아이콘] 정보

시작할 Knox 제품 선택:

올인원 번들
Knox Suite
리브랜딩 및 맞춤 설정
Knox Configure
사기 및 도난 방지
Knox Guard
디바이스 보호 플랜
Samsung Care+ for Business
기타 제품 및 서비스

시작하기

[이미지] Knox Suite

기업용 모바일을 위한 일체형 솔루션 번들

  • 최대 30대의 디바이스에 제공되는 90일 무료 평가판을 사용해 보세요.
  • 회사 디바이스를 안전하게 보호, 배포, 관리 및 분석할 수 있는 완벽한 툴 모음입니다.
  • Knox Suite와 함께 제공되는 강력한 기능을 사용해 보세요.

Knox Suite에는 다음이 포함됩니다.:

Knox Mobile Enrollment 무료
Knox Manage
Knox E-FOTA
Knox Asset Intelligence
Knox Platform for Enterprise 무료
Knox Remote Support
Knox Capture
Knox Authentication Manager

시작하기

[이미지] Knox Configure 로고

삼성 디바이스를 리브랜딩하고 맞춤 설정하세요.

  • 최대 30대의 디바이스에 제공되는 90일 무료 평가판을 사용해 보세요.
  • 삼성 디바이스를 대량으로 구매하는 즉시 원격으로 구성하고 특정 요구 사항을 충족하도록 맞춤 구성합니다.
  • 디바이스를 일회성 배포를 위해 설정하거나 원하는 만큼 업데이트할 수 있습니다.

시작하기

[아이콘] Knox Guard 로고

삼성 디바이스를 위한 사기 및 도난 방지

  • 최대 30대의 디바이스에 제공되는 90일 무료 평가판을 사용해 보세요.
  • 원격으로 삼성 디바이스를 제어하여 금융 관련 위험성을 줄이고 자산을 보호하세요.
  • SIM 제어 및 디바이스 잠금 기능을 포함한 Knox Guard의 모든 기능을 사용해 보세요.

시작하기

[이미지] Samsung Care Plus For Business 로고

삼성 디바이스를 위한 디바이스 보호 플랜

  • 빠른 디바이스 수리 및 교체로 업무 중단을 최소화합니다. 시작하려면 삼성 영업팀에 문의하세요.
  • 한 곳에서 모든 디바이스 보증 범위 및 청구 정보를 확인하세요.
  • 이미 Samsung Care+ for Business를 구매하셨나요? Samsung Care+ for Business 콘솔에서 계정을 만들고 플랜을 활성화하세요.

기타 제품 및 서비스

[이미지] 기타 로고

고객의 고유한 요구 사항을 해결하는 최신 솔루션입니다.

  • Enterprise Tech Support를 통해 전담 계정 관리자로부터 효율적인 기술 지원을 받아보세요.
  • 삼성 소프트웨어 맞춤 설정 서비스를 사용하여 귀사를 위한 맞춤형 디바이스를 만들어 보십시오.
영업 팀에 문의