Data and device encryption

Layered encryption, with keys under the organisation's control

Encryption protects what policy cannot prevent: a lost device, an intercepted network, a retired disk. Blindium configures encryption at rest and in transit from the EMM, with validated cryptographic modules and key and certificate management integrated with the agency's PKI.

Service member working at a cyber defence station
Data at rest

Device encryption and Knox DualDAR

Every managed device applies file-based disk encryption, with hardware-protected keys bound to the user's credential. The EMM makes it mandatory and checks its status in every compliance cycle.

Knox DualDAR adds a second, independent layer over the work container: separate keys, its own lock policy and a cryptographic module that can be Samsung's or an approved third-party module. The inner layer remains encrypted while the container is locked, even when the device is in use. This is the mechanism Samsung documents for military communications scenarios with dual encryption.

Knox hardware Device encryption Key 1 DualDAR (2nd layer) Key 2 Work container Data
fig.Two layers of encryption at rest with independent keys
Data in transit

Keys, certificates and validated modules

Encryption in transit

IPsec/IKEv2 VPN or TLS with approved cipher suites and mutual TLS between the device and the EMM server. No cleartext channels.

Key and certificate management

Issuance, renewal and revocation of device and user certificates from the corporate PKI through the EMM. Hardware-backed key store.

Validated cryptographic modules

The manufacturer states that its cryptographic module is FIPS 140-2 validated; on Galaxy devices, Samsung maintains FIPS 140-2 and 140-3 validated modules. The applicable CMVP certificate is verified in each project.

Spanish framework

CPSTIC, ENS and qualified products

The CPSTIC catalogue (Catálogo de Productos y Servicios de Seguridad TIC) of the Spanish National Cryptologic Centre (CCN) lists the products qualified and approved for use in public administration and in systems handling classified information. Whether a product is listed in the catalogue, and in which category, is an objective purchasing criterion.

The Esquema Nacional de Seguridad (ENS) requires, in the High category, encryption of information on portable devices and in communications, using accredited algorithms and products. The CCN-STIC guides for mobile devices set out specific configurations.

In each proposal Blindium indicates which component is qualified in CPSTIC, which holds Common Criteria or FIPS certification and which is presented as aligned without certification. No qualification is claimed that does not appear in the catalogue.

  • CPSTIC The CCN catalogue. The category and the qualified version of the product are checked.
  • ENS High-category controls op.exp, mp.eq and mp.com as the configuration reference.
  • CCN-STIC Secure configuration guides for mobile devices and fleet management.
06Operation 05VPN 04Apps and container 03EMM policies 02Enrolment 01Hardware
fig.Regulatory references applicable to the device
Lifecycle

Secure wipe and device lifecycle

  1. Onboarding

    Mandatory encryption enabled before any data is loaded. Certificates issued by the PKI. Verification of the cryptographic module and firmware version.

  2. Operation

    Automatic certificate renewal, compliance checks and rotation of container keys according to policy.

  3. Loss or compromise

    Immediate cryptographic erasure (key destruction), certificate revocation and lock. The command and its confirmation are logged.

  4. Retirement

    Verified secure wipe, removal from Knox and from the inventory, retirement certificate for the file.

Next step

Free MDM/EMM continuity assessment (45 minutes)

A technical session with a specialist to review your situation and return an actionable recommendation. No obligation.

  • Current architecture and number of devices
  • Data criticality and network or cloud constraints
  • Integration with Samsung Knox and mixed fleets
  • Transition options and deployment model (on-prem, hybrid or cloud)