Contents

Ⅰ . Product Overview

Ⅱ . Device Eligibility & Verification

Ⅲ . Support and Maintenance

Ⅳ . Appendix Product Overview Ⅰ. Product Overview What is Knox Guard?

Knox Guard is a cloud-based service that allows service providers(telcos, insurance, microfinance, etc.) to remotely control and lock Samsung devices to reduce fraud or theft risks

Device Financing and Device Insurance Device Logistics Subsidy Payment default Not lost, but sold Device robbery Aggressive promotions are Some people may abuse the High-volume theft can occur during needed to attract more insurance coverage and sell their transport and warehousing of devices, subscribers, but they can pose phones on the grey market or at the retail outlets financial risks

 Send payment reminders  Lock devices that are reported lost  Protect devices as soon as or stolen manufactured  Lock devices or block other SIM This ensures that the devices will not From factory to warehouse to store cards with granular restrictions function and become unusable by anyone  Release devices from KG once  Silently install your payment app safely arrived at your store

 Protected by H/W based Knox security

4 Ⅰ. Product Overview

Samsung Knox Guard

Device Financing and Subsidy 1 Deterrence of overdue payment

Device Insurance 2 Deterrence of fraudulent theft & loss claims

Device Logistics 3 Deterrence of device robbery in transit

5 Ⅰ. Product Overview

Aggressive promotions are needed to attract more subscribers, but they can pose financial risks

Knox Guard can help reduce the risk by lowering the device fraud rate

6 Ⅰ. Product Overview Installment plans involve cost due to overdue payment

A high fraud rate generates upfront fees to balance cost and profit

Device seller’s profit loss To offset the loss due to overdue payment, $ device sellers have adopted a large upfront fee

→ A barrier for consumers when choosing a device

Subscriber’s overdue payment

Reducing payment defaults can allow to convert the saved cost into a promotional budget

7 Ⅰ. Product Overview lower overdue payment risk and upfront fee

• Send notifications or remind delinquent customers of their overdue subscription status • Restrict device usage or remotely lock devices • Install your payment app to all subscriber devices so that it becomes handy to make payment

Send Remind Lock notification periodically device

By severity

App Payment

Dismissible Non-dismissible * The payment app gets installed from the initial setup.

8 Ⅰ. Product Overview Prevent drop-off subsidy products during the contract

• Apply SIM-card based restrictions when unauthorized SIM card is inserted into the device, or authorized SIM card is removed from the device.

Carrier A Carrier B NO SIM SIM SIM

Available restrictions:

• Lock device • Restrict incoming/outgoing calls • Restrict SMS/MMS/RCS

• Restrict SIM data usage

• Available to control based on MCC/MNC/IMSI number

• Further SIM card validation by verifying network registration No Usage Usage Restriction Restricted Restricted

e.g.) A device subsidized from Carrier A 9 Ⅰ. Product Overview Expand to Low-Cost markets and make users continue to use their devices. • Unlock whenever user does pay with PAYG Lock

POST PAID Lock if they DON’T pay

1 Month 2 Months 3 Months 4 Months 5 Months Sign up for subscription PAID UNPAID UNPAID UNPAID PAID

PRE PAID Unlock if they DO pay

Offline lock timer is set for the period of payment credits and running regardless of online or offline. 10 Ⅰ. Product Overview

Samsung Knox Guard

Device Financing and Subsidy 1 Deterrence of overdue payment

Device Insurance 2 Deterrence of fraudulent theft & loss claims

Device Logistics 3 Deterrence of device robbery in transit

11 Ⅰ. Product Overview

Some people may abuse the insurance coverage and sell their phones on the grey market

Knox Guard can minimize their motivation by locking down lost or stolen devices

12 Ⅰ. Product Overview Lack of protection in Theft & Loss Protection sales

Insurance companies are willing to increase their sales with Theft & Loss Protection product.

The loss & theft protection segment is expected fastest growing segment over the forecast period.

Every year, approximately 70 million theft cases are reported globally.

Minimizing false claims & allow insurance companies to aggressively promote Theft & Loss protection product

13 Ⅰ. Product Overview Maybe the phone is not lost, but sold

There can be cases where a user claims for a lost device, which is actually not lost but sold on grey market

“I lost my “I want to sell this phone” phone”

or CARRIER GREY MARKET

14 Ⅰ. Product Overview Minimize motivation by locking the devices

Once a device-loss claim has been made, Knox will lock that device. This ensures that if the claim was fraudulent and the device is resold on the grey market, it will not function.

•No access to device by anyone, anywhere

• “I lost my phone” CARRIER LOCK Knox security platform guarding against hackers disabling the lock

→ No motivation to sell or buy the device

15 Ⅰ. Product Overview

Samsung Knox Guard

Device Financing and Subsidy 1 Deterrence of overdue payment

2 Device Insurance Deterrence of fraudulent theft & loss claims

Device Logistics 3 Deterrence of device robbery in transit

16 Ⅰ. Product Overview

High-volume theft can occur during transport and warehousing of devices, or at the retail outlets

Knox Guard can have all devices protected until they safely arrive at the retail store, so there is no reason to steal Samsung devices

17 Ⅰ. Product Overview

Protected Samsung The devices remain protected Release them from devices as soon as from factory Knox Guard when they manufactured to warehouse to store safely arrive at your stores

18 Ⅰ. Product Overview Best Practice

Best Practice from Latin America

One of our partner in Latin America got 10K devices ($1.5M) stolen during logistics. Fortunately they were able to activate Knox Guard. 5K devices ($0.9M) were found in a week. The criminals abandoned the devices since they found those devices are locked and cannot be sold even in gray market

19 Device Eligibility & Verification Ⅱ. Device Eligibility & Verification Device Requirement

Samsung Galaxy (/tablets) With OS or greater

21 Ⅱ. Device Eligibility & Verification Device Ownership Verification - Overview The ownership of devices must be verified in order to be available for Knox Guard

Bluetooth or Wi-Fi Direct

Master device Target device (KDA application)

and Bulk /or On-the-Spot

• Verified by KDP1)-participating resellers that devices were purchased from • Verified by KG customers

• Device IDs must be uploaded by the participating resellers • Each target device must be connected via Wi-Fi Direct or before enrollment to use in Knox Guard Bluetooth with Knox Deployment App2) on a master device

• Designed for a large number of devices • Designed for a small number of devices

• Devices are immediately enrolled

1) Knox Deployment Program 2) Available on Play

22 Ⅱ. Device Eligibility & Verification Device Ownership Verification – Details (Bulk) KDP-participating resellers upload device IDs in bulk for their customers

2 Upload device IDs

Automated API / Manual

Knox Reseller Portal

Purchase devices from 3-1 Sync device IDs from RP 1 participating resellers - Provide Knox Customer ID - Get Knox Reseller ID

4 Devices automatically KDP- 5 Customer enrolled / configured, Participating End Users (IT admin) Knox Guard out of the box Resellers Customer Portal

3 Submit Reseller ID, accept device ID uploads, 4 Deploy devices to end users and select devices to assign a profile

23 Ⅱ. Device Eligibility & Verification Device Ownership Verification - Details (On the Spot) Customers can verify any devices immediately using the Knox Deployment App

With Knox Deployment App Target Device(s) Download/install 2 the Knox Deployment App* from Prepare 1 6 Enrolled master device

Upload Master 5 Device ID End Device Customer 4 Connect each target 3 Sign in with device via Bluetooth/W-Fi IT Admin’s credential Direct into Samsung account during initial setup process on the device settings and select a profile Knox Guard

• Knox Deployment App (https://play.google.com/store/apps/details?id=com.samsung.android.knox.enrollment) 24 Support and Maintenance

25 Ⅲ. Support and Maintenance Technical Support & Maintenance

Service Level Agreement-based technical support service is provided

• 24x7 access to online support ticketing system Technical (through Knox Guard Customer Portal) Technical • Online access to FAQ, documentation, Support • Unlimited number of support requests Resources* troubleshooting guide and so on Requests • Local language supported (Ticketing) • SLA-based first response time

Severity Level First Response Time Severity 1 Business critical errors 2 Business Hours Software • Code fixes and maintenance releases Severity 2 Sporadic issues 4 Business Hours Update Severity 3 Low-impact issues 1 Business Day Severity 4 Technical inquiries 2 Business Days

26 Ⅲ. Support and Maintenance KG-enabled Device Warranty Service

Device Warranty Service for Knox Guard-enabled Devices may be Limited

• Knox Guard-enabled Samsung mobile devices can be warranted for the warranty period from the date of purchase against defects in quality and materials under normal use • However, for locked devices, warranty service may be limited since Samsung Authorized Service Samsung Centers may not be able to alter or reset devices which are locked by IT admins (End Customers) with Authorized Service Center Knox Guard

27 Appendix Ⅳ. Appendix Stakeholders and Responsibilities

End Customer Purchase Sign up · Devices from Knox Deployment · For Knox Reseller Portal Program participating resellers - Sign the Knox Deployment ( for bulk device verification ) Program Participation Agreement Licenses from Knox resellers - Create a Knox Reseller ID

Sign up Resell Carrier · For samsungknox.com Knox Deployment · Devices to B2B customers · For Knox Guard Program Licenses to them together, optionally - Sign the License Agreement Participating Resellers - Create a Knox Customer ID or Upload · Devices to Samsung server via Knox Provide Reseller Portal or Knox Reseller API · Its Knox Customer ID to resellers for verification and add their Knox Reseller IDs to KG for verification

Financial Service Administer Approve Provider · Remote Device Control for · Customer/reseller registration Devices with Installment Plans

29 Ⅳ. Appendix How to onboard KG

1. Go to Samsung Knox portal and enroll with Samsung account. 2. Verify Samsung account, Add company information and Agree to Samsung Knox agreements. 3. Go to Knox guard page and click ‘GET FREE TRIAL’ and accept KG T&. https://www.samsungknox.com/knox-guard

4. Once KG admin approved your request, then ‘LAUNCH’ button will be displayed on Dashboard.

30 Ⅳ. Appendix KG Feature list

Features Details Customer Benefits

• As an IT admin, I want to lock/unlock device depending on end user’s payment status and Remote Lock customize the message shown on lock screen.

• As an IT admin, I want to make device locked automatically if the device becomes offline for pre- Device lock Offline Lock • Reduce financial risk configured period of time.

• As an IT admin, I want to prevent to use of stolen/missing devices by applying auto-lock. Auto Lock *If auto lock is applied, the devices get automatically locked once it turned on

• As an IT admin, I want to send customized notification to inform customers with overdue Overdue Message payment or give proper guidance (e.g. Customer Support) . *Overdue message can be sent to the locked device (The message is displayed over the lock screen) • Reduce financial risk Messaging • As an IT admin, I want to enable full screen-sized message periodically on scheduled time. (e.g. Reminder every 3 seconds except weekend or every 1 hour from 9 am to 6 pm)

• As an IT admin, I want to lock device or apply restrictions such as calls/SMS/MMS/RCS/Data usage SIM Control when the device has non-allowed SIM card. • Additional device Advanced controllability to reduce controls • As an IT admin, I want to install a corporate application to be easily accessed on lock screen* for financial risk Application Install payment or customer support, and block its uninstallation by end user. * Access app from lock screen is available from Q OS

• As an IT admin, I want to show customized enrollment notice on completion of enrollment, every Enrollment Message • Prevent fraudulent resold device reboot , every SIM card change or always dismissible.

• As an IT admin, I want to force end user to accept custom EULA (End User License Agreement) Basic Setting Customize EULA during enrollment process. • Customizable settings Customize Icon • As an IT admin, I want to customize notification icon.

31 Ⅳ. Appendix Ensure lock and restrictions are not disabled by hackers

Malicious users are prevented from disabling Knox’s fraud/theft deterrence capabilities

Hardware-backed Security IMEI Tamper Proof

Knox runs device restrictions such as locking Knox restrictions are unaffected by any inside the TrustZone, to protect them from unauthorized device IMEI modification by being compromised by malware/ leveraging its own secure device identifier assigned to each device

Unauthorized Firmware Blocking Network Bypass Proof

Any malicious attempt to replace or modify Knox has ability to restrict device usage even the official Samsung software binary is when devices stay offline maliciously for a long completely blocked while Knox restrictions are time. Also, Knox’s over-the-air restrictions up and running cannot be bypassed by on-device network firewall or routing (e.g. VPN/Proxy)

32 Ⅳ. Appendix Unmatched security

: Fully supported, : Partially supported, : Not supported

Hardware based solution Feature Software based solution (e.g. Knox)

IMEI falsification protection

Data safety powered by hardware security (Status information of device, PIN, etc.)

TrustZone-based security

Unofficial binary flashing blocking*

Network bypass proof

Device lock on Android GO

APK disable blocking

Timely Support for potential issue

* Unofficial binary(custom ROM) flashing is the most common way to root devices 33 End of Document