DocumentCode
1846334
Title
iOS encryption systems: Deploying iOS devices in security-critical environments
Author
Teufl, Peter ; Zefferer, Thomas ; Stromberger, Christof ; Hechenblaikner, Christoph
Author_Institution
Institute for Applied Information Processing and Communications, Graz University of Technology, Inffeldgasse 16a, 8010 Graz, Austria
fYear
2013
fDate
29-31 July 2013
Firstpage
1
Lastpage
13
Abstract
The high usability of smartphones and tablets is embraced by consumers as well as the private and public sector. However, especially in the non-consumer area the factor security plays a decisive role for the platform selection process. All of the current companies within the mobile device sector added a wide range of security features to the initially consumer-oriented devices (Apple, Google, Microsoft), or have dealt with security as a core feature from the beginning (RIM, now Blackerry). One of the key security features for protecting data on the device or in device backups are the encryption systems, which are deployed in most current devices. However, even under the assumption that the systems are implemented correctly, there is a wide range of parameters, specific use cases, and weaknesses that need to be considered by the security officer. As the first part in a series of papers, this work analyzes the deployment of the iOS platform and its encryption systems within a security-critical context from a security officer´s perspective. Thereby, the different sub-systems, the influence of the developer, the applied configuration, and the susceptibility to various attacks are analyzed in detail. Based on these results we present a workflow that supports the security officer in analyzing the security of an iOS device and the installed applications within a security-critical context. This workflow is supported by various tools that were either developed by ourselves or are available from other sources.
Keywords
Context; Encryption; Malware; Mobile handsets; Bring-Your-Own-Device; Encryption; Mobile Device Management; Mobile Devices; Risk Analysis; Security Analysis; Smartphone Security; iOS;
fLanguage
English
Publisher
ieee
Conference_Titel
Security and Cryptography (SECRYPT), 2013 International Conference on
Conference_Location
Reykjavik, Iceland
Type
conf
Filename
7223165
Link To Document