Samsung Knox Explained

Knox
Logo Size:240px
Developer:Samsung Group
Latest Release Version:3.10
Latest Release Date:[1]
Operating System:Android and Tizen

Samsung Knox is a proprietary security and management framework pre-installed on most Samsung mobile devices. Its primary purpose is to provide organizations with a toolset for managing work devices, such as employee mobile phones or interactive kiosks.[2] Samsung Galaxy hardware, as well as software such as Secure Folder and Samsung Wallet, make use of the Knox framework.[3] [4]

Knox's features fall within three categories: data security, device manageability, and VPN capability.[5] Knox also provides web-based services for organizations to manage their devices. Organizations can customize their managed mobile devices by configuring various functions, including pre-loaded applications, settings, boot-up animations, home screens, and lock screens.[6]

Knox provides more granular control over the standard work profile to manage capabilities found only on Samsung devices.[7] As of December 2020, organizations can use specific Samsung mobile device cameras as barcode scanners, using Knox services to capture and analyze the data.[8]

Overview

Samsung Knox provides hardware and software security features that allow business and personal content to coexist on the same device. Knox integrates web services to assist organizations in managing fleets of mobile devices, which allows IT administrators to register new devices, identify a Unified Endpoint Management (UEM) system, define the organizational rules that govern the use of devices, and upgrade device firmware over-the-air.[9] Developers can integrate these features with their applications using Knox SDKs and REST APIs.[10]

Services

Samsung Knox provides the following web-based services for organizations:

Most services are registered and accessed through the Samsung Knox web consoles,[15] with some accessed through the Samsung Knox SDK.[16]

Knox Capture

Knox Capture uses a Samsung mobile device’s camera to capture all major barcode symbologies like UPC, Code 39, EAN, and QR. Through a web console, IT admins can manage the input, formatting, and output configuration of scanned barcode data, and associate a device app (for example, an Internet browser for QR data).[17]

Knox Asset Intelligence

Knox Asset Intelligence helps organizations improve the management, productivity, and lifecycle of mobile devices. Through a web console, IT admins can monitor device battery management, app usage insights, comprehensive device tracking, and detailed Wi-Fi analytics.[18]

Software

Container

When Samsung Knox debuted with the Galaxy Note 3 in 2013, it included a proprietary container feature that stored security-sensitive applications and data inside a protected execution environment.[19] Device users could switch between personal and business applications by tapping a Knox icon in the lower-left corner of the device screen.[20] The proprietary container, later called the Knox Workspace, was managed by organizations through a UEM system.[21]

Samsung then spun off consumer versions of the container feature, which did not require a UEM system to manage. These consumer versions included Personal Knox, later called My Knox starting in 2014. My Knox was replaced by Secure Folder in 2017.[22]

In 2018, Samsung partnered with Google to use its Android work profile to secure applications and data, and in 2019 deprecated the Knox Workspace container.[23] Samsung continues to pre-install the Secure Folder on most flagship mobile devices, but consumers must enable it for use.[24]

Samsung Real-Time Kernel Protection (RKP)

The Samsung RKP feature tracks kernel changes in real-time and prevents the phone from booting, as well as displaying a warning message about using "Unsecured" Samsung devices.[25] This feature is analogous to Android dm-verity/AVB and requires a signed bootloader.[26]

Security Enhancements for Android (SE for Android)

Although Android phones are already protected from malicious code or exploits by SE for Android and other features, Samsung Knox provides periodic updates that check for patches to further protect the system.[27]

Secure Boot

During Secure Boot, Samsung runs a pre-boot environment to check for a signature match on all operating system (OS) elements before booting in the main kernel. If an unauthorized change is detected, the e-fuse is tripped and the system's status changes from "Official" to "Custom".[28]

Other features

Several other features that facilitate enterprise use are incorporated in Samsung Knox, including Samsung KMS (SKMS) for eSE NFC services, Mobile device management (MDM), Knox Certificate Management (CEP), Single Sign-On (SSO), One Time Password (OTP), SIM PIN Management, Firmware-Over-The-Air (FOTA)[29] and Virtual Private Network (VPN).[30] [31] [32] [33]

Samsung has patched the kernel to prevent root access from being granted to apps even after rooting was successful since the release of Android Oreo. This patch prevents unauthorized apps from changing the system and deters rooting.[34]

Hardware

Knox includes built-in hardware security features ARM TrustZone (a technology similar to TPM) and a bootloader ROM.[35] Knox Verified Boot monitors and protects the phone during the booting process, along with Knox security built at a hardware level (introduced in Knox 3.3).[36]

e-Fuse

Samsung Knox devices use an e-fuse to indicate whether or not an "untrusted" (non-Samsung) boot path has ever been run. The e-Fuse will be set in any of the following cases:

On Galaxy Book devices starting with the Galaxy Book 4, upgrading from one Windows version to another (from 22H2 to 23H2) will not set the e-Fuse, but upgrading to a higher edition (from Home to Pro) will.

When set, the text "Set warranty bit: " appears. Once the e-fuse is set, a device can no longer create a Knox Workspace container or access the data previously stored in an existing Knox Workspace.[37] In the United States, this information may be used by Samsung to deny warranty service to devices that have been modified in this manner.[38] Voiding consumer warranties in this manner may be prohibited by the Magnuson–Moss Warranty Act of 1975, at least in cases where the phone's problem is not directly caused by rooting.[39] In addition to voiding the warranty, tripping the e-fuse also prevents some Samsung-specific apps from running, such as Secure Folder, Samsung Pay, Samsung Health, and Samsung Browser's secret mode (as well as certain Samsung apps preloaded on Galaxy Books). For some older versions of Knox, it may be possible to clear the e-fuse by flashing a custom firmware.[40]

Samsung DeX

Options to manage Samsung DeX were added in Knox 3.3 to allow or restrict access using the Knox platform for added control and security.[41]

Samsung Knox TIMA

Knox's TrustZone-based Integrity Measurement Architecture (TIMA) allows storage of keys in the container for certificate signing using the TrustZone hardware platform.[42]

Notable security mentions

In June 2014, the Defense Information Systems Agency's (DISA) list of approved products for sensitive but unclassified use included five Samsung devices.

In October 2014, a security researcher discovered that Samsung Knox stores PINs in plain text rather than storing salted and hashed PINs and processing them by obfuscated code.[43]

In October 2014, the U.S National Security Agency (NSA) approved Samsung Galaxy devices for use in a program for quickly deploying commercially available technologies. Approved products include Galaxy S4, Galaxy S5, Galaxy S6, Galaxy S7, Galaxy Note 3, and Galaxy Note 10.1 2014.[44]

In May 2016, Israeli researchers Uri Kanonov and Avishai Wool found three vulnerabilities in specific versions of Knox.[45]

In December 2017, Knox received "strong" ratings in 25 of 28 categories in a Gartner publication comparing device security strength of various platforms.[46]

See also

Notes and References

  1. Web site: Samsung Knox 3.10 released . Samsung Knox Team . 6 November 2023 . 23 July 2024.
  2. Web site: January 15, 2021. Secure mobile platform and solutions. live. https://web.archive.org/web/20201223152220/https://www.samsungknox.com/en. December 23, 2020. January 15, 2021. Samsung Knox.
  3. Web site: Samsung Wallet Apps . 2023-10-04 . The Official Samsung Galaxy Site . en.
  4. Web site: Secure Folder . 2023-10-04 . Samsung Knox . en.
  5. Web site: Samsung Knox Feature Summary. 2021-01-06. docs.samsungknox.com.
  6. Web site: 2020-01-07. 8 Steps to Customizing Mobile Devices With Knox Configure. 2021-01-06. Samsung Business Insights. en-US.
  7. Web site: App Container Knox Platform for Enterprise White Paper . 2021-01-07 . docs.samsungknox.com.
  8. Web site: Miller. Matthew. Samsung Galaxy XCover Pro: Microsoft Teams Walkie Talkie experiences and Knox Capture release. 2021-01-06. ZDNet. en.
  9. Web site: Knox for Enterprise Mobility. 2021-01-06. Samsung Knox. en.
  10. Web site: Knox Developer Documentation. 2021-01-06. docs.samsungknox.com.
  11. Web site: Knox for Device Customization. 2021-01-06. Samsung Knox. en.
  12. Web site: Knox Capture. 2021-01-06. Samsung Knox. en.
  13. Web site: Peripherals Overview. 2021-06-28. Samsung Knox. en.
  14. Web site: Knox Asset Intelligence. 2021-06-28. Samsung Knox. en.
  15. Web site: Samsung Knox Documentation Ecosystem. 2021-01-06. docs.samsungknox.com.
  16. Web site: Samsung Knox Developer Documentation. 2021-06-28. docs.samsungknox.com.
  17. Web site: Samsung Knox Capture. 2021-06-28. docs.samsungknox.com.
  18. Web site: Samsung Knox Asset Intelligence. 2021-06-28. docs.samsungknox.com.
  19. Web site: 2013-09-04. New Samsung Galaxy Note 3 software features explained. 2021-01-07. Android Authority. en-US. 2021-01-09. https://web.archive.org/web/20210109195313/https://www.androidauthority.com/samsung-galaxy-note-3-software-features-explained-261976/. dead.
  20. Web site: Ziegler. Chris. 2013-02-25. Samsung Knox: a work phone inside your personal phone (hands-on). 2021-01-07. The Verge. en.
  21. Web site: Evaluating top MDMs for Android and iOS. 2021-01-07. SearchMobileComputing. en.
  22. Web site: 2017-06-02. Samsung discontinues My Knox, urges users to switch to Secure Folder. 2021-01-07. Android Authority. en-US.
  23. Web site: What's new in Knox 3.4?. 2021-01-07. Samsung Knox. en.
  24. Web site: What is the Secure Folder and how do I use it?. 2021-01-07. Samsung uk. en-GB.
  25. News: How we cracked Samsung's DoD- and NSA-certified Knox. en. ZDNet.
  26. Web site: Samsung RKP.
  27. Web site: What is SE for Android? Samsung Support Philippines. 2021-01-04. Samsung ph. en-PH.
  28. 2018-03-01. Forensics acquisition — Analysis and circumvention of samsung secure boot enforced common criteria mode. Digital Investigation. en. 24. S60–S67. 10.1016/j.diin.2018.01.008. 1742-2876. 11250/2723051. free. Alendal . Gunnar . Dyrkolbotn . Geir Olav . Axelsson . Stefan .
  29. Web site: Samsung Enterprise Firmware-over-the-air.
  30. Web site: Samsung SSO.
  31. Web site: Samsung CEP.
  32. Web site: Samsung OTP.
  33. Web site: Samsung Knox VPN.
  34. Web site: Disable DEFEX Security to Root Samsung Galaxy Devices on Oreo. 13 October 2018 .
  35. Web site: Root of Trust Knox Platform for Enterprise Whitepaper. docs.samsungknox.com. 2018-11-13.
  36. Web site: vTZ: Virtualizing ARM TrustZone.
  37. Web site: Ning. Peng. 2013-12-04. About CF-Auto-Root. dead. https://archive.today/20150905231541/https://www.samsungknox.com/en/blog/about-cf-auto-root#selection-1275.0-1281.168. 2015-09-05. Samsung. The sole purpose of this fuse-burning action is to memorize that a kernel or critical initialization scripts or data that is not under Samsung's control has been put on the device. Once the e-fuse bit is burned, a Samsung KNOX-enabled device can no longer create a KNOX Container or access the data previously stored in an existing KNOX Container..
  38. Web site: Just how does Knox warranty void efuse burning work?. 2021-01-05. XDA Developers Forums. 28 June 2016 . en-US.
  39. News: Companies Can't Legally Void the Warranty for Jailbreaking or Rooting Your Phone. Koebler. Jason. 2016-08-17. Motherboard. 2018-10-27.
  40. Web site: Disable Knox on Samsung Galaxy Devices [4 Ways] Android More]. 2020-12-14. AndroidMore. en-US. 2021-01-05. https://web.archive.org/web/20210105215421/https://androidmore.com/disable-samsung-knox/. dead.
  41. Web site: Samsung DeX Apps & Services Samsung IN. 2021-01-04. Samsung India. en-IN.
  42. Web site: Samsung TIMA Keystores.
  43. News: NSA-Approved Samsung Knox Stores PIN in Cleartext. Mimoso. Michael. 2014-10-24. Threatpost. 2018-10-27.
  44. News: NSA approves Samsung Knox devices for government use. Ribeiro. John. 2014-10-21. PCWorld. 2018-10-27.
  45. News: Samsung Knox isn't as secure as you think it is. Forrest. Conner. 2016-05-31. TechRepublic. 2018-10-27.
  46. Web site: Introduction Knox Platform for Enterprise Whitepaper. docs.samsungknox.com. 2018-11-13.