Enhancing Samsung devices with fundamental security and management updates, Knox also has its own container. 'The Knox Container' keeps company data, intelligence and important content safe and secure completely separate from personal content on any Samsung smart device. Knox is the perfect solution for both COPE and BYOD working models as it allows sensitive data to be safely encrypted away from unwarranted access.

Knox is a multi-layered technology built into both the hardware and software of Samsung’s latest devices. From the Hardware Root of Trust to the Android Framework, Knox constantly verifies the integrity of the device and detects any tampering, ensuring your data is more secure.

Security Enhancements for Android protect applications and data by strictly defining what each process is allowed to do, and what data it can access. SE for Android help to secure a device by using domains, rights, security policies and Mandatory Access Control.

Knox leverages a processor architecture known as ARM TrustZone. In TrustZone, there are two worlds: the Normal World, and the Secure World. Virtually all smartphone software as we know today still runs in Normal World. The Secure World is reserved for highly sensitive computations, and is used extensively by Knox for protecting confidential enterprise data.

Secure Boot prevents unauthorized bootloaders and kernels from being loaded onto the device. This means that your device has not been tampered with and the Knox container can be loaded.

Trusted Boot ensures that the bootloader and OS kernel are the originals from the factory. This is done by recording the original device measurements and consistently checking the device at the start up to make sure these measurements haven't changed.

Protect the business with a trusted end-to-end approach to security, complementing the device OS, backed by credentials and accreditations recognized worldwide. Over half the Fortune 100, including 100% of the F100 commercial banks, rely on Good powered by BlackBerry.

Samsung manufactures and configures its devices in its own factories, and has designed them so that all critical security mechanisms are anchored from the device chipset.

Booting components are always tested for integrity, while Run Time Protection blocks any code changes to the kernel, and ensures the integrity of the data in system partition.

If hacking or rooting is detected on the device, our one-time e-fuse blows, disallowing any user access and securing all data. Attestation allows IT admins to remotely check if a device is trustworthy.


