Security Magazine logo
search
cart
facebook twitter linkedin youtube
  • Sign In
  • Create Account
  • Sign Out
  • My Account
Security Magazine logo
  • NEWS
    • Security Newswire
    • Technologies & Solutions
  • MANAGEMENT
    • Leadership Management
    • Enterprise Services
    • Security Education & Training
    • Logical Security
    • Security & Business Resilience
    • Profiles in Excellence
  • PHYSICAL
    • Access Management
    • Fire & Life Safety
    • Identity Management
    • Physical Security
    • Video Surveillance
    • Case Studies (Physical)
  • CYBER
    • Cybersecurity News
    • More
  • BLOG
  • COLUMNS
    • Career Intelligence
    • Cyber Tactics
    • Cybersecurity Education & Training
    • Leadership & Management
    • Security Talk
  • EXCLUSIVES
    • Annual Guarding Report
    • Most Influential People in Security
    • The Security Benchmark Report
    • Top Guard and Security Officer Companies
    • Top Cybersecurity Leaders
    • Women in Security
  • SECTORS
    • Arenas / Stadiums / Leagues / Entertainment
    • Banking/Finance/Insurance
    • Construction, Real Estate, Property Management
    • Education: K-12
    • Education: University
    • Government: Federal, State and Local
    • Hospitality & Casinos
    • Hospitals & Medical Centers
    • Infrastructure:Electric,Gas & Water
    • Ports: Sea, Land, & Air
    • Retail/Restaurants/Convenience
    • Transportation/Logistics/Supply Chain/Distribution/ Warehousing
  • EVENTS
    • Industry Events
    • Webinars
    • Solutions by Sector
    • Security 500 Conference
  • MEDIA
    • Interactive Spotlight
    • Photo Galleries
    • Podcasts
    • Polls
    • Videos
      • Cybersecurity & Geopolitical Discussion
      • Ask Me Anything (AMA) Series
  • MORE
    • Call for Entries
    • Classifieds & Job Listings
    • Continuing Education
    • Newsletter
    • Sponsor Insights
    • Store
    • White Papers
  • EMAG
    • eMagazine
    • This Month's Content
    • Advertise
  • SIGN UP!
CybersecurityCybersecurity News

Expanding Trust in Mobile Devices

By Kathleen McGill
smartphone2-900px.jpg
April 21, 2020

For many people, their mobile device, serves as their primary computer in day-to-day life. Modern mobile devices offer a rich, flexible set of features and allow users to add new features just by downloading applications. Users can manage virtually every facet of their lives from their mobile devices — send emails, schedule appointments, make purchases and more. Mobile devices now account for 55% of the network device market share, and the World Advertising Research Center (WARC) predicts that, by 2025, 72% of internet users will access the web solely via smartphones. The Trusted Computing Group (TCG) is expanding trust in mobile devices to enhance security in users’ everyday lives.

A Growing Risk

The popularity and utility of mobile devices makes them attractive targets for attackers.Mobile devices have many of the same security vulnerabilities as laptops as well as other vulnerabilities unique to mobile architectures. In addition to re-using traditional laptop exploits, hackers can justify the resources to develop, deploy, and sell more sophisticated attacks. Powerful tools for password guessing, impersonation and side channel attacks are widely available on the Internet, giving minor criminals free or low-cost access to the same sophisticated tools used by crime syndicates and nation states.

Mobile device vulnerabilities create greater risk for users who rely on their devices for day-to-day activities. Stolen personal or identity data can cause a major breach of privacy. Any compromise of financial credentials, transactions, or other data can cost users both time and money. When mobile devices are used for business, attackers can leak intellectual property or sensitive security data, ultimately causing financial losses. Finally, disruption in availability of the mobile device or network, can range from inconvenient to debilitating.

Mobile devices, payment cards and payment information are some of the most common use cases for attacks. As the cashless society becomes more pervasive, more people will use mobile devices in lieu of cash or a physical credit card. Any mobile payment solution faces the technical challenge of optimizing the trade-offs in security and usability. Mobile payments are often made with devices that host an association with a credit card, debit card, or prepaid cash portal. These associations and any mobile payment transactions must be sufficiently secure to be viable solutions. They must also be easy to use in order to gain traction with users. Mobile banking popularity is also increasing, with growing demand for anytime and anywhere convenience. Similar to mobile payments, mobile banking applications require confidentiality and integrity to limit the risk of compromise to user finances.

Another security challenge that impacts mobile devices is that consumers do not want to pay for security. The majority of users assume that their systems — laptops, mobile devices, or anything else — are secure.They often do not worry about the personal risk they incur by using mobile devices. As a result, there is a weak market justification for mobile handset manufacturers and mobile network operators to spend resources on enhanced mobile security.

TCG Addresses the Challenges

TCG addresses technical mobile security challenges by expanding traditional, effective security measures to mobile devices and ecosystems. In 2013, TCG published the Trusted Platform Module 2.0 Library Specification (TPM 2.0), ISO/IEC 11889. The TPM 2.0 is a secure cryptoprocessor and hardware root-of-trust that provides protected capabilities. It is a solution that protects against attacks of varying levels of sophistication. TCG published the TPM 2.0 Mobile Common Profile, the TPM 2.0 Mobile Command Response Buffer Interface, and the TPM 2.0 Mobile Reference Architecture to adapt the TPM 2.0 to modern mobile device architectures. This collection of specifications provides the core capabilities to enhance the trustworthiness of mobile devices.

Mobile security challenges go beyond mobile devices themselves. To cope with financial and other challenges, trusted computing and trusted networking technologies must also support mobile infrastructure systems. Mobile network and service providers require some assurance that mobile devices are healthy before they permit access to their services. Service providers do not want malicious or compromised users to disrupt other users’ security and privacy. Similar requirements exist within enterprise environments. TCG has published the Trusted Mobility Solution Use Cases Version 2.0 – Enterprise, Financial, & NFV, with much more detail on TCG technologies for a broad range of mobile ecosystem use cases. TCG has also published TCG Trusted Network Communications for Mobile Platforms, which describes solutions for network administrators to measure and assess mobile device integrity before granting devices access to network resources.

TCG also provides guidance on how TCG solutions can tackle more advanced security requirements. The Multiple Stakeholder Model proposes solutions for multiple stakeholders to coexist safely on the same mobile device. Runtime Integrity Preservation makes recommendations to ensure mobile device integrity during operation. These efforts confront some of the issues that mobile handset manufacturers and mobile network operators consider barriers to adopting trusted mobile solutions.

Mobile Security Collaboration

TCG is committed to the adoption of sound trusted computing technologies in the market. However, no organization can secure the mobile ecosystem alone, so TCG collaborates with other standards organizations. TCG has formal liaisons with GlobalPlatform, the European Telecommunications Standards Institute (ETSI) and the Alliance for Telecommunications Industry Solutions (ATIS). TCG also has informal collaborations with numerous other organizations including 3GPP, GSMA, IETF, IEEE, and SAE. Together, these organizations represent a broad set of mobile devices and networks. These collaborations ensure that standards are compatible and robust to multiple mobile technologies. It is easier for mobile device implementers and network managers to adopt trusted computing technologies when the applicable standards are coherent. 

In 2012, TCG and GlobalPlatform partnered to address growing mobile security challenges. GlobalPlatform’s Secure Element (SE) and Trusted Execution Environment (TEE) components are implemented in most mobile devices today. This partnership was originally focused on mobile topics, aligning TCG and GlobalPlatform specifications on mobile roots-of-trust and device architectures. For example, the TPM 2.0 Mobile Reference Architecture describes a Protected Environment to host a TPM Mobile. The two organizations cooperated to ensure that a GlobalPlatform TEE is a valid implementation of a TCG Protected Environment. These alignments enable mobile device designers, manufacturers and developers to build solutions that meet industry-wide standards.

TCG expects to expand its formal and informal collaborations to include more topics in the future, including Remote Attestation, Security Automation, 5G, and Network Function Virtualization.  TCG will continue its mission to enhance mobile ecosystem security so that users can safely leverage modern mobile capabilities.

 

 

 

 

 

KEYWORDS: cyber security mobile devices network security smartphone security

Share This Story

Looking for a reprint of this article?
From high-res PDFs to custom plaques, order your copy today!

Dr. Kathleen McGill is a member of the Senior Professional Staff in APL’s Asymmetric Operations Sector. She has contributed to the TCG Mobile Platform Work Group since 2011, became a MPWG Work Group co-chair in 2015, and received a TCG Key Contributor award in 2016. Her research at APL focuses on system security engineering, defensive cyber solutions and trusted computing technologies for desktop, server and mobile platforms.

Recommended Content

JOIN TODAY
To unlock your recommendations.

Already have an account? Sign In

  • Iintegration and use of emerging tools

    Future Proof Your Security Career with AI Skills

    AI’s evolution demands security leaders master...
    Career Intelligence
    By: Jerry J. Brennan and Joanne R. Pollock
  • The 2025 Security Benchmark Report

    The 2025 Security Benchmark Report

    The 2025 Security Benchmark Report surveys enterprise...
    The Security Benchmark Report
    By: Rachelle Blair-Frasier
  • The Most Influential People in Security 2025

    Security’s Most Influential People in Security 2025

    Security Magazine’s 2025 Most Influential People in...
    Most Influential People in Security
    By: Security Staff
Manage My Account
  • Security Newsletter
  • eMagazine Subscriptions
  • Manage My Preferences
  • Online Registration
  • Mobile App
  • Subscription Customer Service

More Videos

Sponsored Content

Sponsored Content is a special paid section where industry companies provide high quality, objective, non-commercial content around topics of interest to the Security audience. All Sponsored Content is supplied by the advertising company and any opinions expressed in this article are those of the author and not necessarily reflect the views of Security or its parent company, BNP Media. Interested in participating in our Sponsored Content section? Contact your local rep!

close
  • critical event management
    Sponsored byEverbridge

    Why a Unified View Across IT, Continuity, and Security Makes or Breaks Crisis Response

  • Charlotte Star Room
    Sponsored byAMAROK

    In an Uncertain Economy, Security Is a Necessity - Not an Afterthought

  • Sureview screen
    Sponsored bySureView Systems

    The Evolution of Automation in the Command Center

Popular Stories

Cybersecurity trends of 2025

3 Top Cybersecurity Trends from 2025

Red laptop

Security Leaders Discuss SitusAMC Cyberattack

Green code

Logitech Confirms Data Breach, Security Leaders Respond

Neon human and android hands

65% of the Forbes AI 50 List Leaked Sensitive Information

The Louvre

After the Theft: Why Camera Upgrades Should Begin With a Risk Assessment

Top Cybersecurity Leaders

Events

September 18, 2025

Security Under Fire: Insights on Active Shooter Preparedness and Recovery

ON DEMAND: In today’s complex threat environment, active shooter incidents demand swift, coordinated and well-informed responses.

December 11, 2025

Responding to Evolving Threats in Retail Environments

Retail security professionals are facing an increasingly complex array of security challenges — everything from organized retail crime to evolving cyber-physical threats and public safety concerns.

View All Submit An Event

Products

Security Culture: A How-to Guide for Improving Security Culture and Dealing with People Risk in Your Organisation

Security Culture: A How-to Guide for Improving Security Culture and Dealing with People Risk in Your Organisation

See More Products

Related Articles

  • cyber-attack

    More than 8.4 million DDoS Attacks Targeted IT Infrastructures, Cloud, Mobile Networks & IoT Devices in 2019

    See More
  • cyber attack

    Research reveals rise in sophisticated attacks against mobile devices

    See More
  • Unisys Security Index Reveals Global Consumer Confidence in Security of Mobile Devices

    See More

Related Products

See More Products
  • 150952519X.jpg

    Intelligence in An Insecure World, 3rd Edition

  • GSEC.jpg

    GSEC GIAC Security Essentials Certification All-In-One Exam Guide, 2E

  • Hospitality Security: Managing Security in Today's Hotel, Lodging, Entertainment, and Tourism Environment

See More Products

Events

View AllSubmit An Event
  • December 12, 2011

    Mobile Surveillance Applications

    Do you know what apps are available to you for your mobile devices to increase you Axis effectiveness? Here's a chance to find out. In this webinar session we'll update you on what is out there for camera viewing software along with our reviews. We'll also look at the Axis Product Selector tool and several other applications that are available today.
View AllSubmit An Event
×

Sign-up to receive top management & result-driven techniques in the industry.

Join over 20,000+ industry leaders who receive our premium content.

SIGN UP TODAY!
  • RESOURCES
    • Advertise
    • Contact Us
    • Store
    • Want More
  • SIGN UP TODAY
    • Create Account
    • eMagazine
    • Newsletter
    • Customer Service
    • Manage Preferences
  • SERVICES
    • Marketing Services
    • Reprints
    • Market Research
    • List Rental
    • Survey/Respondent Access
  • STAY CONNECTED
    • LinkedIn
    • Facebook
    • YouTube
    • X (Twitter)
  • PRIVACY
    • PRIVACY POLICY
    • TERMS & CONDITIONS
    • DO NOT SELL MY PERSONAL INFORMATION
    • PRIVACY REQUEST
    • ACCESSIBILITY

Copyright ©2025. All Rights Reserved BNP Media.

Design, CMS, Hosting & Web Development :: ePublishing