The Next Wave

The Next Wave

External hardware is the next sidekick for smartphone security isolation

Originally designed as consumer devices, smartphones have become vital elements of both our personal and professional lives. Unfortunately, as sources and repositories of our most sensitive data, smartphones have quickly become a primary attack surface for hackers, cybercriminals and foreign spies. According to recent media stories of American intelligence reports, even the President of the United States is not safe from mobile espionage.1 As a result, smartphone makers have implemented security isolation within both the operating system (OS) and hardware, partitioning the device’s apps and core processes as a means of limiting the potential damage caused by malware. Despite attempts to insulate critical data and functions from malicious outsiders, vulnerabilities at the heart of these mobile devices continue to chip away at an organization’s ability to protect its most important digital assets. The solution to this intractable problem may come from an unlikely source: external mobile hardware.

Wave 1: Isolation via the Operating System

Since the release of the app stores for both iOS (App Store) and Android (Android Market, now Google Play) in 2008, smartphone makers have implemented sandboxing as a means of security isolation, both for backend analysis while screening apps as well as for app isolation while running. A sandbox is an app’s restricted space within the OS, acting as the environment for code execution and data storage while also limiting the app’s access to system files and resources. App permissions controlled by the user grant access to the device features outside of the sandbox, including the user’s contacts, the device’s location, its cameras and its microphones.

For Android, each app runs with a distinct user identity, with the OS enforcing security between apps and the system at the process level. For iOS, each app runs as the same non-privileged user identity but is assigned a unique home directory for its files.

Unfortunately, as hackers began to turn their attention to smartphones as an entry point for attack, exploiting and fooling sandboxes became the name of the game. Common techniques to bypass different sandboxes have included delaying the execution of malware in order to remain undetected during inspection, grabbing malicious code after initial installation and abusing the user’s acceptance of app permissions. Examples of mobile malware families using these and other techniques to bypass sandbox protections go back for years, from DroidDream (packaged inside legitimate applications) to, more recently, Skygofree and Pegasus. Once their work is complete, the attacker achieves root access, meaning total control over the device and its data.

Wave 2: Isolation via the Processor

In response to the in-the-wild proliferation of increasingly intrusive forms of mobile malware like rootkits and remote access Trojans (RATs), smartphone makers began implementing isolation even lower in the stack, at the hardware/firmware levels. One technique, the trusted execution environment (TEE), is now prevalent on virtually all modern smartphones. A TEE is an isolated execution environment— typically containing security-critical code, data and processes— that runs independently of the main, user-facing OS.

Approaches for establishing a TEE vary between platforms, manufacturers and models. Most Android smartphones offer some version of ARM’s TrustZone technology, which consists of two virtual processors: a “secure” world for the security subsystem and a “nonsecure” world for everything else. Apple, on the other hand, uses the Secure Enclave, a coprocessor that is isolated from the main processor and runs its own microkernel. In both cases, the TEE is relegated to the same application processor or system on a chip (SoC) running non-secure software, a necessity of the smartphone’s place as a consumer device valued more for its functionality and size than its security.

Unfortunately, the concept of TEE is based on a flawed assumption: that the application processor or coprocessor hosting the TEE cannot be bypassed by software—in other words, that any malware on a user’s smartphone cannot access or modify the code, data or processes that exist within the trusted portion of the TEE. An emerging series of threats from the hardware and firmware underpinning smartphones are poised to shatter this assumption.

Firmware bugs. Flaws in the design and implementation of the firmware that is shipped with hardware – like the QuadRooter vulnerabilities affecting Android devices built using Qualcomm chipsets— can allow an attacker to trigger privilege escalation in order to gain root access.

Supply chain attacks. Stealth actors have taken to disrupting chips at the factory and in transit, usually by manipulating the firmware controlling the chips. Such was the case with the batch of Android devices that shipped with Loki malware, essentially giving an attacker the ability to take total control of the device.

Speculative execution flaws. Nearly every type of processor in every commercial device uses speculative execution—an optimization technique in which tasks are performed based on predicted (speculative) instructions—as a way of preventing delays. This technique’s flaws, including the well-publicized Meltdown and Spectre vulnerabilities, allows a rogue process to access what was thought to be the isolated and protected memory of apps and the OS, exposing a device’s most sensitive information, including passwords, digital keys and more.

At the end of the day, commercial phones are by design, open systems, which makes protecting against vulnerabilities in their architecture and underlying hardware, especially as the basis for isolating important data and processes, a futile proposition. Without the ability to separate security logic and software from malware on the same processor or SoC, an organization exposes itself to the risk of capture and control of its most valuable digital resources.

Wave 3: Isolation via External Hardware

Chip-based exploits are on the rise, yet smartphone makers cannot deliver isolation any lower in the stack. Consequently, external mobile processing is the logical next wave for organizations looking to truly isolate their most valuable information.

Imagine a tiny mobile computer packed in a familiar form factor, like a smartphone case or watch. Using this device, you can do things like authenticate to your organization’s online services, securely communicate with approved peers and, for enterprise use cases such as Assured Identity, optionally transmit sensor data back to a central server for processing. Most importantly, because the device operates independently of your smartphone and does not run third party code (using code signing and other advanced techniques), malware does not have an entry point for attack. This is the future of smartphone security isolation.

While this product category of high-security, independent-processing devices is not yet mainstream, it will be defined by a few hallmarks going forward:

Convenient form factor. Users will be able to conveniently carry, charge and interact with the device. For familiarity, a smartphone case, watch or key fob make sense as form factors. Considerations must be made for housing the electronic components, maintaining battery life, gathering user input (via touchscreen or buttons) and adding LEDs or other elements for notifying users. Wired or wireless communication to the smartphone, which is treated as untrusted in the threat model, can enable unique and compelling functionality.

Trusted, secure, closed processing environment. The processor will be designed to only run specific firmware, and strict authentication practices will ensure that only validated and trusted firmware runs on the device. A hardware root of trust (HRoT), based on a unique hardware ID and private key, both generated and stored in silicon, that become associated with a digital certificate during a secure provisioning process, will serve as the basis for firmware authentication during all boot, runtime and update processes.

High-security architecture. A closed/controlled public key infrastructure (PKI) with a known trust issuer will be used to ensure that secure, end-to-end encrypted communication to and from the device only occurs with its integrated cloud infrastructure (for reporting, policy management and firmware updates) and other trusted entities.

Extensibility. In addition to core processing and communications, additional components, such as GPS modules, sensors, audio equipment, etc., should be available and easily added to the device, depending on the required applications. For example, built-in behavioral and biometric sensors can be leveraged for continuous multi-factor authentication (CMFA) solutions.

The path of external hardware isolation will unlock the door to exciting opportunities for enterprises and government agencies looking to take back control over their most important information. Now is the time to break free from the mobile vulnerable ecosystem and give critical services the security they deserve.

This article originally appeared in the January/February 2019 issue of Security Today.

Featured

  • Cutting Retail Losses

    Retail is still a more complex and dynamic security vertical in modern society. Inherent challenges with in-store and distribution center operations are primarily due to constantly shifting consumer buying trends. Retailers must show daily flexibility to keep workers, meet sales goals and attract customers while maintaining safe and efficient operations. Retail is an intricate web of interconnected elements. Read Now

  • The Key to Wellbeing in the Office

    A few years ago, all we saw in the news was the ‘great resignation.’ Now we have another ‘great’ to deal with. According to CBRE, 2023 was the start of the ‘great return’ as office workers returned to their normal offices after working from home. The data shows that two-thirds of all U.S office buildings were more than 90% leased as of Q2 2023. Read Now

  • Failed Cybersecurity Controls Costing U.S. Businesses $30 Billion Yearly

    Panaseer recently released ControlWatch and the Continuous Controls Battle: Panaseer 2025 Security Leaders Report examining the cost of cybersecurity control failures and the impact of growing personal liability for security failings on security leaders. The report analyzes the findings of a survey of 400 security decision makers (SDMs) across the US and UK. It shows that security leaders feel under increasing pressure to provide assurances around cybersecurity, exposing them to greater personal risk – yet many lack the data and resources to accurately report and close cybersecurity gaps. Read Now

  • The Business Case for Video Analytics: Understanding the Real ROI

    For security professionals who may be hesitant to invest in video analytics, now's the time to reconsider. In a newly released Omdia report commissioned by BriefCam (now Milestone Systems), the research firm uncovered a compelling story: more than 85% of North American and European organizations that use video analytics achieve a return on investment within just one year. The study, which surveyed 140 end users across multiple industries, demonstrates that security technology is no longer just for security — it's a cross-organizational tool that delivers measurable business value far beyond traditional safety applications. Read Now

Featured Cybersecurity

Webinars

New Products

  • Mobile Safe Shield

    Mobile Safe Shield

    SafeWood Designs, Inc., a manufacturer of patented bullet resistant products, is excited to announce the launch of the Mobile Safe Shield. The Mobile Safe Shield is a moveable bullet resistant shield that provides protection in the event of an assailant and supplies cover in the event of an active shooter. With a heavy-duty steel frame, quality castor wheels, and bullet resistant core, the Mobile Safe Shield is a perfect addition to any guard station, security desks, courthouses, police stations, schools, office spaces and more. The Mobile Safe Shield is incredibly customizable. Bullet resistant materials are available in UL 752 Levels 1 through 8 and include glass, white board, tack board, veneer, and plastic laminate. Flexibility in bullet resistant materials allows for the Mobile Safe Shield to blend more with current interior décor for a seamless design aesthetic. Optional custom paint colors are also available for the steel frame. 3

  • Luma x20

    Luma x20

    Snap One has announced its popular Luma x20 family of surveillance products now offers even greater security and privacy for home and business owners across the globe by giving them full control over integrators’ system access to view live and recorded video. According to Snap One Product Manager Derek Webb, the new “customer handoff” feature provides enhanced user control after initial installation, allowing the owners to have total privacy while also making it easy to reinstate integrator access when maintenance or assistance is required. This new feature is now available to all Luma x20 users globally. “The Luma x20 family of surveillance solutions provides excellent image and audio capture, and with the new customer handoff feature, it now offers absolute privacy for camera feeds and recordings,” Webb said. “With notifications and integrator access controlled through the powerful OvrC remote system management platform, it’s easy for integrators to give their clients full control of their footage and then to get temporary access from the client for any troubleshooting needs.” 3

  • HD2055 Modular Barricade

    Delta Scientific’s electric HD2055 modular shallow foundation barricade is tested to ASTM M50/P1 with negative penetration from the vehicle upon impact. With a shallow foundation of only 24 inches, the HD2055 can be installed without worrying about buried power lines and other below grade obstructions. The modular make-up of the barrier also allows you to cover wider roadways by adding additional modules to the system. The HD2055 boasts an Emergency Fast Operation of 1.5 seconds giving the guard ample time to deploy under a high threat situation. 3