Original Link: http://www.anandtech.com/show/6789/samsung-announces-knox-security-container-for-enterprise-byod
Samsung Announces SAFE with KNOX - Security Container for Enterprise BYODby Brian Klug on February 25, 2013 3:00 AM EST
I talked with Anand about his impressions of the Note 8 after reading his hands on piece, and one thing that struck me was a mention of how Samsung was going to aggressively go after the enterprise market in the USA for a few reasons. First, a lot of its marketing has focused on SAFE (SAmsung For Enterprise) which is a combination of improved EAS (Exchange ActiveSync) policies, and improved MDM (Mobile Device Management) integration with more toggles and sliders for IT Admins in enterprise roles. Second, because once you win the enterprise market you're guaranteed some market loyalty and a long tail of sales thanks to the slower pace of enterprise acquisition and certification. I didn't really appreciate the full meaning of just how much Samsung was going after the enterprise business until I learned about their plans for another product geared at enterprise policy enforcement, called KNOX, and Samsung truly wants to be the one who KNOX.
KNOX builds on SAFE by basically adding two parts - a fully secure boot chain, and a new container based sandbox for Android. The idea is for Samsung to both become desirable for enterprise businesses, and enable even greater BYOD (Bring Your Own Device) functionality by shipping a single SKU that can easily be attached to an enterprise login and managed. At the same time, the container model means that consumers bringing their devices to a particular business and then leaving won't lose anything other than the container data if they leave and have their devices wiped remotely. The result is a win-win in theory for IT Admins who want more control over the devices being brought into the fray, and employees who don't want to lose personal data in the case of a device wipe, or have privacy concerns from the control IT Admins have over the platform.
First is that secure platform story, which begins with secure boot chain which only boots signed code, then SE Android (Security Enhanced Linux for Android), and TrustZone Integrity Monitoring (TIMA). Samsung will have more information about the hardware and software level for KNOX available in a whitepaper later this week. There are some obvious interesting implications to say the least for what this will mean for enthusiast users who want to run their own arbitrary third party ROMs on devices, especially since the secure boot chain will ship enabled in markets targeted for KNOX and on "iconic devices" at the high end to make them BYOD-capable.
The second part is the secure, enterprise-controlled container, which exposes itself as an application icon or shortcut in Android, and takes you into another instance of Android which is completely sandboxed or containered from the user's side. Admins then get complete control over the container, including what apps exist inside, all while maintaining the same Android UI and platform. Email, browser, contacts, calendars, and so on exist inside the container sanitized from the personal outside Android.
KNOX will include certification for FIPS 140-2 (DAR, DIT), Government Root of Trust, US DOD CAC/PIV, and US DOD Mobile OS SRG on applicable devices. In addition KNOX includes more IT policies for MDM APIs, and ActiveDirectory based management for enterprises who don't have an MDM solution or don't want to use Exchange.
The rest of the story is really one of timing and focus. Samsung says it is targeting KNOX heavily at the US market, and obviously compliance with so many federal and government security standards makes that much obvious. Timing wise, KNOX will ship on "iconic devices" in Q2 2013.