Knox Flag
   HOME

TheInfoList



OR:

Samsung Knox (stylized as SΛMSUNG Knox) is a proprietary security and management
framework A framework is a generic term commonly referring to an essential supporting structure which other things are built on top of. Framework may refer to: Computing * Application framework, used to implement the structure of an application for an op ...
pre-installed on most
Samsung Samsung Group (; stylised as SΛMSUNG) is a South Korean Multinational corporation, multinational manufacturing Conglomerate (company), conglomerate headquartered in the Samsung Town office complex in Seoul. The group consists of numerous a ...
mobile devices. Its primary purpose is to provide organizations with a toolset for managing work devices, such as employee mobile phones or
interactive kiosk An interactive kiosk is a computer terminal featuring specialized hardware and software that provides access to information and applications for communication, commerce, entertainment, or education. By 2010, the largest bill pay kiosk network ...
s.
Samsung Galaxy Samsung Galaxy (; stylized as SΛMSUNG Galaxy since 2015 (except Japan where it omitted the Samsung branding up until 2023), previously stylized as Samsung GALAXY; abbreviated as SG) is a series of computing, Android mobile computing and wear ...
hardware, as well as software such as Secure Folder and
Samsung Wallet Samsung Wallet (, or simply Wallet) is a digital wallet platform developed by Samsung. It is available for the Samsung Galaxy-exclusive One UI Android operating system, and was announced on February 9, 2022, at the February 2022 Samsung Unpa ...
, make use of the Knox framework. Knox's features fall within three categories: data security, device manageability, and
VPN Virtual private network (VPN) is a network architecture for virtually extending a private network (i.e. any computer network which is not the public Internet) across one or multiple other networks which are either untrusted (as they are not c ...
capability. Knox also provides web-based services for organizations to manage their devices. Organizations can customize their managed mobile devices by configuring various functions, including pre-loaded applications, settings, boot-up animations, home screens, and
lock screen A lock screen is a computer user interface element used by various operating systems. They regulate immediate access to a device by requiring the user to perform a certain action in order to receive access, such as entering a password, using a cer ...
s. Knox provides more granular control over the standard work profile to manage capabilities found only on Samsung devices. As of December 2020, organizations can use specific Samsung mobile device cameras as
barcode scanners A barcode reader or barcode scanner is an optical scanner that can read printed barcodes and send the data they contain to computer. Like a flatbed scanner, it consists of a light source, a lens, and a light sensor for translating optical impulses ...
, using Knox services to
capture Capture may refer to: Arts and entertainment * "Capture", a song by Simon Townshend * Capture (band), an Australian electronicore band previously known as Capture the Crown * ''Capture'' (TV series), a reality show Television episodes * "Chapter ...
and analyze the data.


Overview

Samsung Knox provides hardware and software security features that allow business and personal content to coexist on the same device. Knox integrates web services to assist organizations in managing fleets of mobile devices, which allows IT administrators to register new devices, identify a
unified endpoint management Unified endpoint management (UEM) is a class of software tools that provide a single management interface for mobile, PC and other devices. It is an evolution of, and replacement for, mobile device management (MDM) and enterprise mobility manageme ...
(UEM) system, define the organizational rules that govern the use of devices, and upgrade device
firmware In computing Computing is any goal-oriented activity requiring, benefiting from, or creating computer, computing machinery. It includes the study and experimentation of algorithmic processes, and the development of both computer hardware, h ...
over-the-air. Developers can integrate these features with their applications using Knox SDKs and REST APIs.


Services

Samsung Knox provides the following web-based services for organizations: * To manage mobile devices: Knox Suite, Knox Platform for Enterprise, Knox Mobile Enrollment, Knox Manage, and Knox E-FOTA. * To customize and rebrand devices: Knox Configure * To capture and analyze data: Knox Capture, Knox Peripheral Management, Knox Asset Intelligence Most services are registered and accessed through the Samsung Knox web consoles, with some accessed through the Samsung Knox SDK.


Knox Capture

Knox Capture uses a Samsung mobile device’s camera to capture all major barcode symbologies like UPC, Code 39, EAN, and QR. Through a web console, IT admins can manage the input, formatting, and output configuration of scanned barcode data, and associate a device app (for example, a web browser for QR data).


Knox Asset Intelligence

Knox Asset Intelligence helps organizations improve the management, productivity, and lifecycle of mobile devices. Through a web console, IT admins can monitor device battery management, app usage insights, comprehensive device tracking, and detailed Wi-Fi analytics.


Software


Container

When Samsung Knox debuted with the
Galaxy Note 3 The Samsung Galaxy Note 3 is an Android phablet smartphone produced by Samsung Electronics as part of the Samsung Galaxy Note series. The Galaxy Note 3 was unveiled on September 4, 2013, with its worldwide release beginning later in the month. ...
in 2013, it included a proprietary container feature that stored security-sensitive applications and data inside a protected execution environment. Device users could switch between personal and business applications by tapping a Knox icon in the lower-left corner of the device screen. The proprietary container, later called the Knox Workspace, was managed by organizations through a UEM system. Samsung then spun off consumer versions of the container feature, which did not require a UEM system to manage. These consumer versions included Personal Knox, later called My Knox starting in 2014. My Knox was replaced by Secure Folder in 2017. In 2018, Samsung partnered with
Google Google LLC (, ) is an American multinational corporation and technology company focusing on online advertising, search engine technology, cloud computing, computer software, quantum computing, e-commerce, consumer electronics, and artificial ...
to use its Android work profile to secure applications and data, and in 2019 deprecated the Knox Workspace container. Samsung continues to pre-install the Secure Folder on most flagship mobile devices, but consumers must enable it for use.


Samsung Real-Time Kernel Protection (RKP)

The Samsung RKP feature tracks
kernel Kernel may refer to: Computing * Kernel (operating system), the central component of most operating systems * Kernel (image processing), a matrix used for image convolution * Compute kernel, in GPGPU programming * Kernel method, in machine learnin ...
changes in real-time and prevents the phone from booting, as well as displaying a warning message about using "Unsecured" Samsung devices. This feature is analogous to Android
dm-verity The device mapper is a framework provided by the Linux kernel for mapping physical block devices onto higher-level ''virtual block devices''. It forms the foundation of the logical volume manager (LVM), software RAIDs and dm-crypt disk encrypti ...
/AVB and requires a signed
bootloader A bootloader, also spelled as boot loader or called bootstrap loader, is a computer program that is responsible for booting a computer and booting an operating system. If it also provides an interactive menu with multiple boot choices then it's o ...
.


Security Enhancements for Android (SE for Android)

Although Android phones are already protected from malicious code or exploits by SE for Android and other features, Samsung Knox provides periodic updates that check for patches to further protect the system.


Secure Boot

During Secure Boot, Samsung runs a pre-boot environment to check for a signature match on all
operating system An operating system (OS) is system software that manages computer hardware and software resources, and provides common daemon (computing), services for computer programs. Time-sharing operating systems scheduler (computing), schedule tasks for ...
(OS) elements before booting in the main kernel. If an unauthorized change is detected, the
e-fuse In computing, an eFuse (electronic fuse) is a microscopic fuse put into a computer chip. This technology was invented by IBM in 2004 to allow for the dynamic real-time reprogramming of chips. In the abstract, computer logic is generally "etched" ...
is tripped and the system's status changes from "Official" to "Custom".


Other features

Several other features that facilitate enterprise use are incorporated in Samsung Knox, including Samsung KMS (SKMS) for eSE NFC services,
Mobile device management Mobile device management (MDM) is the administration of mobile devices, such as smartphones, tablet computers, and laptops. MDM is usually implemented with the use of a third-party product that has management features for particular vendors of ...
(MDM), Knox Certificate Management (CEP), Single Sign-On (SSO),
One Time Password A one-time password (OTP), also known as a one-time PIN, one-time passcode, one-time authorization code (OTAC) or dynamic password, is a password that is valid for only one login session or transaction, on a computer system or other digital dev ...
(OTP), SIM PIN Management, Firmware-Over-The-Air (FOTA) and Virtual Private Network (VPN). Samsung has patched the kernel to prevent
root In vascular plants, the roots are the plant organ, organs of a plant that are modified to provide anchorage for the plant and take in water and nutrients into the plant body, which allows plants to grow taller and faster. They are most often bel ...
access from being granted to apps even after rooting was successful since the release of
Android Oreo Android Oreo ( codenamed Android O during development) is the eighth major release and the 15th version of the Android mobile operating system. It was initially unveiled as an alpha quality developer preview in March 2017 and later made ava ...
. This patch prevents unauthorized apps from changing the system and deters rooting.


Hardware

Knox includes built-in hardware security features
ARM TrustZone ARM (stylised in lowercase as arm, formerly an acronym for Advanced RISC Machines and originally Acorn RISC Machine) is a family of RISC instruction set architectures (ISAs) for computer processors. Arm Holdings develops the ISAs and licen ...
(a technology similar to TPM) and a bootloader
ROM Rom, or ROM may refer to: Biomechanics and medicine * Risk of mortality, a medical classification to estimate the likelihood of death for a patient * Rupture of membranes, a term used during pregnancy to describe a rupture of the amniotic sac * ...
. Knox Verified Boot monitors and protects the phone during the booting process, along with Knox security built at a hardware level (introduced in Knox 3.3).


e-Fuse

Samsung Knox devices use an
e-fuse In computing, an eFuse (electronic fuse) is a microscopic fuse put into a computer chip. This technology was invented by IBM in 2004 to allow for the dynamic real-time reprogramming of chips. In the abstract, computer logic is generally "etched" ...
to indicate whether or not an "untrusted" (non-Samsung) boot path has ever been run. The e-Fuse will be set in any of the following cases: * The device boots with a non-Samsung signed bootloader, kernel, kernel initialization script, or data. * The device is rooted. * Custom firmware is detected on the device (such as non-Samsung Android releases). On Galaxy Book devices starting with the Galaxy Book 4, upgrading from one Windows version to another (from 22H2 to 23H2) will not set the e-Fuse, but upgrading to a higher edition (from Home to Pro) will. When set, the text "Set warranty bit: " appears. Once the e-fuse is set, a device can no longer create a Knox Workspace container or access the data previously stored in an existing Knox Workspace. In the United States, this information may be used by Samsung to deny warranty service to devices that have been modified in this manner. Voiding consumer warranties in this manner may be prohibited by the
Magnuson–Moss Warranty Act The Magnuson–Moss Warranty Act (P.L. 93-637) is a United States federal law ( ''et seq.''). Enacted in 1975, the federal statute governs warranties on consumer products. The law does not require any product to have a warranty (it may be sold " ...
of 1975, at least in cases where the phone's problem is not directly caused by rooting. In addition to voiding the warranty, tripping the e-fuse also prevents some Samsung-specific apps from running, such as Secure Folder,
Samsung Pay Samsung Pay (stylized as SΛMSUNG Pay) is a mobile payment and digital wallet service, operated by the South Korean company Samsung Electronics. It lets users make payments using compatible smartphones and other Samsung-produced devices, accesse ...
,
Samsung Health Samsung Health is a free application developed by Samsung Electronics that serves to track various aspects of daily life contributing to well being such as physical activity, diet, and sleep. Launched on 2 July 2012, with the then new Samsung ...
, and
Samsung Internet Samsung Internet is a Chromium-based web browser for Android smartphones developed by Samsung Electronics. It was first released in 2012 as a basic mobile browser for Samsung Galaxy devices. Samsung estimated that it had around 400 million mo ...
's secret mode (as well as certain Samsung apps preloaded on Galaxy Books). For some older versions of Knox, it may be possible to clear the e-fuse by flashing a custom firmware.


Samsung DeX

Options to manage
Samsung DeX Samsung DeX (stylized as SΛMSUNG DeX) is a feature included on some high-end Samsung Electronics, Samsung handheld devices that enables users to extend their device into a Desktop computer, desktop-like experience by connecting a Computer keyb ...
were added in Knox 3.3 to allow or restrict access using the Knox platform for added control and security.


Samsung Knox TIMA

Knox's TrustZone-based Integrity Measurement Architecture (TIMA) allows storage of keys in the container for
certificate Certificate may refer to: * Birth certificate * Marriage certificate * Death certificate * Gift certificate * Certificate of authenticity, a document or seal certifying the authenticity of something * Certificate of deposit, or CD, a financial p ...
signing using the TrustZone hardware platform.


Notable security mentions

In June 2014, the
Defense Information Systems Agency The Defense Information Systems Agency (DISA), known as the Defense Communications Agency (DCA) until 1991, is a United States Department of Defense (DoD) combat support agency. It is composed of military, federal civilians, and contractors. D ...
's (DISA) list of approved products for
sensitive but unclassified Sensitive But Unclassified (SBU) is a designation of information in the Federal government of the United States, United States federal government that, though unclassified, often requires FIPS 140-2#Level 2, strict controls over its distribution ...
use included five Samsung devices. In October 2014, a security researcher discovered that Samsung Knox stores
PINs A pin is a device, typically pointed, used for fastening objects or fabrics together. Pins can have the following sorts of body: *a shaft of a rigid inflexible material meant to be inserted in a slot, groove, or hole (as with pivots, hinges, an ...
in plain text rather than storing salted and
hashed The Hashid (; Musnad: 𐩢𐩦𐩵𐩣) is a tribal confederation in Yemen. It is the second or third largest – after Bakil and, depending on sources, Madh'hij
PINs and processing them by
obfuscated code In software development, obfuscation is the practice of creating source or machine code that is intentionally difficult for humans or computers to understand. Similar to obfuscation in natural language, code obfuscation may involve using unnece ...
. In October 2014, the
National Security Agency The National Security Agency (NSA) is an intelligence agency of the United States Department of Defense, under the authority of the director of national intelligence (DNI). The NSA is responsible for global monitoring, collection, and proces ...
(NSA) approved
Samsung Galaxy Samsung Galaxy (; stylized as SΛMSUNG Galaxy since 2015 (except Japan where it omitted the Samsung branding up until 2023), previously stylized as Samsung GALAXY; abbreviated as SG) is a series of computing, Android mobile computing and wear ...
devices for use in a program for quickly deploying commercially available technologies. Approved products include
Galaxy S4 The Samsung Galaxy S4 is an Android smartphone produced by Samsung Electronics as the fourth smartphone of the Samsung Galaxy S series and was first shown publicly on March 14, 2013, at Samsung Mobile Unpacked in New York City. It is the succe ...
,
Galaxy S5 The Samsung Galaxy S5 is an Android-based smartphone unveiled, produced, released and marketed by Samsung Electronics as part of the Samsung Galaxy S series. Unveiled on 24 February 2014 at Mobile World Congress in Barcelona, Spain, it was relea ...
,
Galaxy S6 The Samsung Galaxy S6 is a line of Android-based smartphones manufactured, released and marketed by Samsung Electronics. Succeeding the Samsung Galaxy S5, the S6 was not released as a singular model, but instead in two variations unveiled and ...
,
Galaxy S7 The Samsung Galaxy S7, Samsung Galaxy S7 Edge and Samsung Galaxy S7 Active were Android-based smartphones manufactured, released and marketed by Samsung Electronics. The S7 series served as the successor to the Galaxy S6, S6 Edge, S6 Edge+ and ...
,
Galaxy Note 3 The Samsung Galaxy Note 3 is an Android phablet smartphone produced by Samsung Electronics as part of the Samsung Galaxy Note series. The Galaxy Note 3 was unveiled on September 4, 2013, with its worldwide release beginning later in the month. ...
, and Galaxy Note 10.1 2014. In May 2016, Israeli researchers Uri Kanonov and Avishai Wool found three vulnerabilities in specific versions of Knox. In December 2017, Knox received "strong" ratings in 25 of 28 categories in a
Gartner Gartner, Inc. is an American research and advisory firm focusing on business and technology topics. Gartner provides its products and services through research reports, conferences, and consulting. Its clients include large corporations, gover ...
publication comparing device security strength of various platforms.


See also

*
SafetyNet API SafetyNet consists of several application programming interfaces (APIs) offered by the Google Play Services to support security sensitive applications and enforce Digital rights management, DRM. Currently, these APIs include device integrity verifi ...
*
Intel Management Engine The Intel Management Engine (ME), also known as the Intel Manageability Engine, is an autonomous subsystem that has been incorporated in virtually all of Intel's processor chipsets since 2008. It is located in the Platform Controller Hub of m ...


References


External links

* {{Samsung Electronics Hardware restrictions Mobile device management Knox Mobile security Enterprise software