VPN and secure communications

Encrypted communications managed from the EMM

The VPN is not an application the user opens when they remember to. It is a policy: it is distributed, activated, monitored and revoked from the EMM console, with certificates from the organisation's PKI and without the device being able to send traffic outside the tunnel.

Soldier operating a satellite communications antenna in the field
Modes of operation

Always-on and per-app

Always-on VPN

The tunnel is established when the device boots and is maintained without user intervention. With the lockdown option, no application can communicate unless the tunnel is active. This is the default configuration for devices handling sensitive information.

Per-app VPN

Each application (or group) uses its own tunnel to the network segment assigned to it. This allows tactical messaging, email and management applications to reach different resources without exposing them to one another.

Technology

Knox VPN framework and protocols

On Galaxy devices, the Knox VPN framework allows the EMM to configure tunnels at system and container level, chain tunnels and apply per-app rules with guarantees that the standard Android API does not provide.

Protocols commonly used in defence and public administration deployments: IPsec/IKEv2 with certificate-based authentication and approved cipher suites, and TLS for application access scenarios. WireGuard is considered only as an option to be evaluated in each project according to its fit with the requirements of the accreditation authority.

The VPN concentrator and client are selected per project: [VPN PRODUCT TO BE DEFINED]. Blindium validates the combination during the pilot.

  • IPsec/IKEv2 X.509 certificate authentication, approved cipher suites, periodic re-authentication.
  • TLS 1.2/1.3 Application access and App Tunnel; mutual TLS with a device certificate.
  • WireGuard Option under evaluation. Lightweight and auditable, pending fit with accreditation requirements.
App Device Outer tunnel Inner tunnel Gateway A Gateway B Internal resources Configured from the EMM
fig.Dual tunnel: independent outer and inner layers
Closed and classified networks

Dual layer: two independent tunnels

CSfC-style approaches (the NSA's Commercial Solutions for Classified programme) rely on two independent layers of encryption, with components from different vendors, so that the compromise of one layer does not expose the traffic. The device establishes an outer tunnel to the access gateway and an inner tunnel to the destination segment.

Samsung SDS EMM supports dual VPN chaining on Galaxy devices and distributes the configuration and certificates for both layers. The manufacturer states its membership of the CSfC programme; in Spain, this architecture is adapted to the CCN requirements for each classification level.

  • Segmentation Internal resources reachable only through the tunnel assigned to each application.
  • No exposure No internal service is published on the Internet; the gateway accepts only clients with a valid certificate.
  • Revocation A lost device loses access when its certificate is revoked from the EMM.
Organisation perimeter EMM console EMM server Database SDS Private Push PKI / Directory SIEM App and firmware repository VPN gateway Managed devices Internet no dependency
fig.Access to internal resources through a gateway
Deliverables

What is documented in a communications project

  • Flow matrix: application, tunnel, destination segment, port and protocol.
  • Certificate profile: template, renewal cycle, revocation and root of trust.
  • VPN configuration exported from the EMM, versioned as a baseline.
  • Test plan: tunnel failure, traffic blocking, network change, revocation.
  • Operating procedure for the control centre.
Next step

Free MDM/EMM continuity assessment (45 minutes)

A technical session with a specialist to review your situation and return an actionable recommendation. No obligation.

  • Current architecture and number of devices
  • Data criticality and network or cloud constraints
  • Integration with Samsung Knox and mixed fleets
  • Transition options and deployment model (on-prem, hybrid or cloud)