• DocumentCode
    1846334
  • Title

    iOS encryption systems: Deploying iOS devices in security-critical environments

  • Author

    Teufl, Peter ; Zefferer, Thomas ; Stromberger, Christof ; Hechenblaikner, Christoph

  • Author_Institution
    Institute for Applied Information Processing and Communications, Graz University of Technology, Inffeldgasse 16a, 8010 Graz, Austria
  • fYear
    2013
  • fDate
    29-31 July 2013
  • Firstpage
    1
  • Lastpage
    13
  • Abstract
    The high usability of smartphones and tablets is embraced by consumers as well as the private and public sector. However, especially in the non-consumer area the factor security plays a decisive role for the platform selection process. All of the current companies within the mobile device sector added a wide range of security features to the initially consumer-oriented devices (Apple, Google, Microsoft), or have dealt with security as a core feature from the beginning (RIM, now Blackerry). One of the key security features for protecting data on the device or in device backups are the encryption systems, which are deployed in most current devices. However, even under the assumption that the systems are implemented correctly, there is a wide range of parameters, specific use cases, and weaknesses that need to be considered by the security officer. As the first part in a series of papers, this work analyzes the deployment of the iOS platform and its encryption systems within a security-critical context from a security officer´s perspective. Thereby, the different sub-systems, the influence of the developer, the applied configuration, and the susceptibility to various attacks are analyzed in detail. Based on these results we present a workflow that supports the security officer in analyzing the security of an iOS device and the installed applications within a security-critical context. This workflow is supported by various tools that were either developed by ourselves or are available from other sources.
  • Keywords
    Context; Encryption; Malware; Mobile handsets; Bring-Your-Own-Device; Encryption; Mobile Device Management; Mobile Devices; Risk Analysis; Security Analysis; Smartphone Security; iOS;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Security and Cryptography (SECRYPT), 2013 International Conference on
  • Conference_Location
    Reykjavik, Iceland
  • Type

    conf

  • Filename
    7223165