EMUI 8.0 Security Technical White Paper
Total Page:16
File Type:pdf, Size:1020Kb
EMUI 8.0 Security Technical White Paper Issue 1.0 Date 2017-10-31 HUAWEI TECHNOLOGIES CO., LTD. Copyright © Huawei Technologies Co., Ltd. 2017. All rights reserved. No part of this document may be reproduced or transmitted in any form or by any means without prior written consent of Huawei Technologies Co., Ltd. Trademarks and Permissions and other Huawei trademarks are trademarks of Huawei Technologies Co., Ltd. All other trademarks and trade names mentioned in this document are the property of their respective holders. Notice The purchased products, services and features are stipulated by the contract made between Huawei and the customer. All or part of the products, services and features described in this document may not be within the purchase scope or the usage scope. Unless otherwise specified in the contract, all statements, information, and recommendations in this document are provided "AS IS" without warranties, guarantees or representations of any kind, either express or implied. The information in this document is subject to change without notice. Every effort has been made in the preparation of this document to ensure accuracy of the contents, but all statements, information, and recommendations in this document do not constitute a warranty of any kind, express or implied. Huawei Technologies Co., Ltd. Address: Huawei Industrial Base Bantian, Longgang Shenzhen 518129 People's Republic of China Website: http://www.huawei.com PSIRT Email: [email protected] Issue 1.0 (2017-10-31) Huawei Proprietary and Confidential i Copyright © Huawei Technologies Co., Ltd. EMUI 8.0 Security Technical White Paper Contents Contents 1 Overview ......................................................................................................................................... 1 2 Hardware Security ........................................................................................................................ 3 Secure Boot......................................................................................................................................................................... 3 Hardware Encryption/Decryption Engine ........................................................................................................................... 4 HUK ................................................................................................................................................................................... 4 Device Attestation Key Pair ................................................................................................................................................ 4 Hardware RNG ................................................................................................................................................................... 4 TEE ..................................................................................................................................................................................... 4 Secure Storage* .................................................................................................................................................................. 5 TUI* ................................................................................................................................................................................... 5 Fingerprint Authentication .................................................................................................................................................. 5 3 System Security ............................................................................................................................. 7 Integrity Protection ............................................................................................................................................................. 7 Kernel Security ................................................................................................................................................................... 7 System Software Upgrade .................................................................................................................................................. 8 4 Data Security .................................................................................................................................. 9 Lock Screen Passcode Protection ....................................................................................................................................... 9 File System Encryption ....................................................................................................................................................... 9 SD Card Lock and Encryption* ........................................................................................................................................ 10 Secure Erasure .................................................................................................................................................................. 11 5 Application Security ................................................................................................................... 12 Application Signature ....................................................................................................................................................... 12 Application Sandbox ........................................................................................................................................................ 12 Runtime Memory Protection ............................................................................................................................................ 13 Secure Input ...................................................................................................................................................................... 13 Application Threat Detection ............................................................................................................................................ 13 Malicious Website Detection ............................................................................................................................................ 13 Traffic Management.......................................................................................................................................................... 13 6 Cyber Security ............................................................................................................................. 15 VPN .................................................................................................................................................................................. 15 SSL/TLS ........................................................................................................................................................................... 15 Issue 1.0 (2017-10-31) Huawei Proprietary and Confidential ii Copyright © Huawei Technologies Co., Ltd. EMUI 8.0 Security Technical White Paper Contents WPA/WPA2 ...................................................................................................................................................................... 15 Secure Wi-Fi Detection ..................................................................................................................................................... 15 7 Communication Security ........................................................................................................... 16 Defense Against Rogue Base Stations* ............................................................................................................................ 16 Block and Filter ................................................................................................................................................................ 16 Text Message Encryption .................................................................................................................................................. 17 Device Interconnection Security ....................................................................................................................................... 17 8 Payment Security......................................................................................................................... 18 Huawei Pay ....................................................................................................................................................................... 18 Secure Keys* .................................................................................................................................................................... 20 Payment Protection Center ............................................................................................................................................... 21 Protecting SMS Verification Codes .................................................................................................................................. 21 9 Internet Cloud Service Security ............................................................................................... 23 Huawei ID......................................................................................................................................................................... 23 Code Scanning Login ......................................................................................................................................................