Security Magazine logo
  • Sign In
  • Create Account
  • Sign Out
  • My Account
  • NEWS
  • MANAGEMENT
  • PHYSICAL
  • CYBER
  • BLOG
  • COLUMNS
  • EXCLUSIVES
  • SECTORS
  • EVENTS
  • MEDIA
  • MORE
  • EMAG
  • SIGN UP!
cart
facebook twitter linkedin youtube
  • NEWS
  • Security Newswire
  • Technologies & Solutions
  • MANAGEMENT
  • Leadership Management
  • Enterprise Services
  • Security Education & Training
  • Logical Security
  • Security & Business Resilience
  • Profiles in Excellence
  • PHYSICAL
  • Access Management
  • Fire & Life Safety
  • Identity Management
  • Physical Security
  • Video Surveillance
  • Case Studies (Physical)
  • CYBER
  • Cybersecurity News
  • More
  • COLUMNS
  • Cyber Tactics
  • Leadership & Management
  • Security Talk
  • Career Intelligence
  • Leader to Leader
  • Cybersecurity Education & Training
  • EXCLUSIVES
  • Annual Guarding Report
  • Most Influential People in Security
  • The Security Benchmark Report
  • The Security Leadership Issue
  • Top Guard and Security Officer Companies
  • Top Cybersecurity Leaders
  • Women in Security
  • SECTORS
  • Arenas / Stadiums / Leagues / Entertainment
  • Banking/Finance/Insurance
  • Construction, Real Estate, Property Management
  • Education: K-12
  • Education: University
  • Government: Federal, State and Local
  • Hospitality & Casinos
  • Hospitals & Medical Centers
  • Infrastructure:Electric,Gas & Water
  • Ports: Sea, Land, & Air
  • Retail/Restaurants/Convenience
  • Transportation/Logistics/Supply Chain/Distribution/ Warehousing
  • EVENTS
  • Industry Events
  • Webinars
  • Solutions by Sector
  • Security 500 Conference
  • MEDIA
  • Videos
  • Podcasts
  • Polls
  • Photo Galleries
  • Videos
  • Cybersecurity & Geopolitical Discussion
  • Ask Me Anything (AMA) Series
  • MORE
  • Call for Entries
  • Classifieds & Job Listings
  • Continuing Education
  • Newsletter
  • Sponsor Insights
  • Store
  • White Papers
  • EMAG
  • eMagazine
  • This Month's Content
  • Advertise
Security Magazine logo
search
cart
facebook twitter linkedin youtube
  • Sign In
  • Create Account
  • Sign Out
  • My Account
Security Magazine logo
  • NEWS
    • Security Newswire
    • Technologies & Solutions
  • MANAGEMENT
    • Leadership Management
    • Enterprise Services
    • Security Education & Training
    • Logical Security
    • Security & Business Resilience
    • Profiles in Excellence
  • PHYSICAL
    • Access Management
    • Fire & Life Safety
    • Identity Management
    • Physical Security
    • Video Surveillance
    • Case Studies (Physical)
  • CYBER
    • Cybersecurity News
    • More
  • BLOG
  • COLUMNS
    • Cyber Tactics
    • Leadership & Management
    • Security Talk
    • Career Intelligence
    • Leader to Leader
    • Cybersecurity Education & Training
  • EXCLUSIVES
    • Annual Guarding Report
    • Most Influential People in Security
    • The Security Benchmark Report
    • The Security Leadership Issue
    • Top Guard and Security Officer Companies
    • Top Cybersecurity Leaders
    • Women in Security
  • SECTORS
    • Arenas / Stadiums / Leagues / Entertainment
    • Banking/Finance/Insurance
    • Construction, Real Estate, Property Management
    • Education: K-12
    • Education: University
    • Government: Federal, State and Local
    • Hospitality & Casinos
    • Hospitals & Medical Centers
    • Infrastructure:Electric,Gas & Water
    • Ports: Sea, Land, & Air
    • Retail/Restaurants/Convenience
    • Transportation/Logistics/Supply Chain/Distribution/ Warehousing
  • EVENTS
    • Industry Events
    • Webinars
    • Solutions by Sector
    • Security 500 Conference
  • MEDIA
    • Videos
      • Cybersecurity & Geopolitical Discussion
      • Ask Me Anything (AMA) Series
    • Podcasts
    • Polls
    • Photo Galleries
  • MORE
    • Call for Entries
    • Classifieds & Job Listings
    • Continuing Education
    • Newsletter
    • Sponsor Insights
    • Store
    • White Papers
  • EMAG
    • eMagazine
    • This Month's Content
    • Advertise
  • SIGN UP!
CybersecurityCybersecurity News

Expanding Trust in Mobile Devices

By Kathleen McGill
smartphone2-900px.jpg
April 21, 2020

For many people, their mobile device, serves as their primary computer in day-to-day life. Modern mobile devices offer a rich, flexible set of features and allow users to add new features just by downloading applications. Users can manage virtually every facet of their lives from their mobile devices — send emails, schedule appointments, make purchases and more. Mobile devices now account for 55% of the network device market share, and the World Advertising Research Center (WARC) predicts that, by 2025, 72% of internet users will access the web solely via smartphones. The Trusted Computing Group (TCG) is expanding trust in mobile devices to enhance security in users’ everyday lives.

A Growing Risk

The popularity and utility of mobile devices makes them attractive targets for attackers.Mobile devices have many of the same security vulnerabilities as laptops as well as other vulnerabilities unique to mobile architectures. In addition to re-using traditional laptop exploits, hackers can justify the resources to develop, deploy, and sell more sophisticated attacks. Powerful tools for password guessing, impersonation and side channel attacks are widely available on the Internet, giving minor criminals free or low-cost access to the same sophisticated tools used by crime syndicates and nation states.

Mobile device vulnerabilities create greater risk for users who rely on their devices for day-to-day activities. Stolen personal or identity data can cause a major breach of privacy. Any compromise of financial credentials, transactions, or other data can cost users both time and money. When mobile devices are used for business, attackers can leak intellectual property or sensitive security data, ultimately causing financial losses. Finally, disruption in availability of the mobile device or network, can range from inconvenient to debilitating.

Mobile devices, payment cards and payment information are some of the most common use cases for attacks. As the cashless society becomes more pervasive, more people will use mobile devices in lieu of cash or a physical credit card. Any mobile payment solution faces the technical challenge of optimizing the trade-offs in security and usability. Mobile payments are often made with devices that host an association with a credit card, debit card, or prepaid cash portal. These associations and any mobile payment transactions must be sufficiently secure to be viable solutions. They must also be easy to use in order to gain traction with users. Mobile banking popularity is also increasing, with growing demand for anytime and anywhere convenience. Similar to mobile payments, mobile banking applications require confidentiality and integrity to limit the risk of compromise to user finances.

Another security challenge that impacts mobile devices is that consumers do not want to pay for security. The majority of users assume that their systems — laptops, mobile devices, or anything else — are secure.They often do not worry about the personal risk they incur by using mobile devices. As a result, there is a weak market justification for mobile handset manufacturers and mobile network operators to spend resources on enhanced mobile security.

TCG Addresses the Challenges

TCG addresses technical mobile security challenges by expanding traditional, effective security measures to mobile devices and ecosystems. In 2013, TCG published the Trusted Platform Module 2.0 Library Specification (TPM 2.0), ISO/IEC 11889. The TPM 2.0 is a secure cryptoprocessor and hardware root-of-trust that provides protected capabilities. It is a solution that protects against attacks of varying levels of sophistication. TCG published the TPM 2.0 Mobile Common Profile, the TPM 2.0 Mobile Command Response Buffer Interface, and the TPM 2.0 Mobile Reference Architecture to adapt the TPM 2.0 to modern mobile device architectures. This collection of specifications provides the core capabilities to enhance the trustworthiness of mobile devices.

Mobile security challenges go beyond mobile devices themselves. To cope with financial and other challenges, trusted computing and trusted networking technologies must also support mobile infrastructure systems. Mobile network and service providers require some assurance that mobile devices are healthy before they permit access to their services. Service providers do not want malicious or compromised users to disrupt other users’ security and privacy. Similar requirements exist within enterprise environments. TCG has published the Trusted Mobility Solution Use Cases Version 2.0 – Enterprise, Financial, & NFV, with much more detail on TCG technologies for a broad range of mobile ecosystem use cases. TCG has also published TCG Trusted Network Communications for Mobile Platforms, which describes solutions for network administrators to measure and assess mobile device integrity before granting devices access to network resources.

TCG also provides guidance on how TCG solutions can tackle more advanced security requirements. The Multiple Stakeholder Model proposes solutions for multiple stakeholders to coexist safely on the same mobile device. Runtime Integrity Preservation makes recommendations to ensure mobile device integrity during operation. These efforts confront some of the issues that mobile handset manufacturers and mobile network operators consider barriers to adopting trusted mobile solutions.

Mobile Security Collaboration

TCG is committed to the adoption of sound trusted computing technologies in the market. However, no organization can secure the mobile ecosystem alone, so TCG collaborates with other standards organizations. TCG has formal liaisons with GlobalPlatform, the European Telecommunications Standards Institute (ETSI) and the Alliance for Telecommunications Industry Solutions (ATIS). TCG also has informal collaborations with numerous other organizations including 3GPP, GSMA, IETF, IEEE, and SAE. Together, these organizations represent a broad set of mobile devices and networks. These collaborations ensure that standards are compatible and robust to multiple mobile technologies. It is easier for mobile device implementers and network managers to adopt trusted computing technologies when the applicable standards are coherent. 

In 2012, TCG and GlobalPlatform partnered to address growing mobile security challenges. GlobalPlatform’s Secure Element (SE) and Trusted Execution Environment (TEE) components are implemented in most mobile devices today. This partnership was originally focused on mobile topics, aligning TCG and GlobalPlatform specifications on mobile roots-of-trust and device architectures. For example, the TPM 2.0 Mobile Reference Architecture describes a Protected Environment to host a TPM Mobile. The two organizations cooperated to ensure that a GlobalPlatform TEE is a valid implementation of a TCG Protected Environment. These alignments enable mobile device designers, manufacturers and developers to build solutions that meet industry-wide standards.

TCG expects to expand its formal and informal collaborations to include more topics in the future, including Remote Attestation, Security Automation, 5G, and Network Function Virtualization.  TCG will continue its mission to enhance mobile ecosystem security so that users can safely leverage modern mobile capabilities.

 

 

 

 

 

KEYWORDS: cyber security mobile devices network security smartphone security

Share This Story

Looking for a reprint of this article?
From high-res PDFs to custom plaques, order your copy today!

Dr. Kathleen McGill is a member of the Senior Professional Staff in APL’s Asymmetric Operations Sector. She has contributed to the TCG Mobile Platform Work Group since 2011, became a MPWG Work Group co-chair in 2015, and received a TCG Key Contributor award in 2016. Her research at APL focuses on system security engineering, defensive cyber solutions and trusted computing technologies for desktop, server and mobile platforms.

Recommended Content

JOIN TODAY
To unlock your recommendations.

Already have an account? Sign In

  • Security's Top Cybersecurity Leaders 2024

    Security's Top Cybersecurity Leaders 2024

    Security magazine's Top Cybersecurity Leaders 2024 award...
    Security Enterprise Services
    By: Security Staff
  • cyber brain

    The intersection of cybersecurity and artificial intelligence

    Artificial intelligence (AI) is a valuable cybersecurity...
    Security Enterprise Services
    By: Pam Nigro
  • artificial intelligence AI graphic

    Assessing the pros and cons of AI for cybersecurity

    Artificial intelligence (AI) has significant implications...
    Cybersecurity Education & Training
    By: Charles Denyer
Subscribe For Free!
  • Security eNewsletter & Other eNews Alerts
  • eMagazine Subscriptions
  • Manage My Preferences
  • Online Registration
  • Mobile App
  • Subscription Customer Service

Security’s Top 5 – 2024 Year in Review

Security’s Top 5 – 2024 Year in Review

Middle East Escalation, Humanitarian Law and Disinformation – Episode 25

Middle East Escalation, Humanitarian Law and Disinformation – Episode 25

The Money Laundering Machine: Inside the global crime epidemic - Episode 24

The Money Laundering Machine: Inside the global crime epidemic - Episode 24

More Videos

Sponsored Content

Sponsored Content is a special paid section where industry companies provide high quality, objective, non-commercial content around topics of interest to the Security audience. All Sponsored Content is supplied by the advertising company and any opinions expressed in this article are those of the author and not necessarily reflect the views of Security or its parent company, BNP Media. Interested in participating in our Sponsored Content section? Contact your local rep!

close
  • Crisis Response Team
    Sponsored byEverbridge

    Automate or Fall Behind – Crisis Response at the Speed of Risk

  • Perimeter security
    Sponsored byAMAROK

    Why Property Security is the New Competitive Advantage

  • Duty of Care
    Sponsored byAMAROK

    Integrating Technology and Physical Security to Advance Duty of Care

Popular Stories

White post office truck

Department of Labor Sues USPS Over Texas Whistleblower Termination

Internal computer parts

Critical Software Vulnerabilities Rose 37% in 2024

Coding

AI Emerges as the Top Concern for Security Leaders

Person working on laptop

Governance in the Age of Citizen Developers and AI

patient at healthcare reception desk

Almost Half of Healthcare Breaches Involved Microsoft 365

2025 Security Benchmark banner

Events

June 24, 2025

Inside a Modern GSOC: How Anthropic Benchmarks Risk Detection Tools for Speed and Accuracy

For today's security teams, making informed decisions in the first moments of a crisis is critical.

August 27, 2025

Risk Mitigation as a Competitive Edge

In today’s volatile environment, a robust risk management strategy isn’t just a requirement—it’s a foundation for organizational resilience. From cyber threats to climate disruptions, the ability to anticipate, withstand, and adapt to disruption is becoming a hallmark of industry leaders.

View All Submit An Event

Products

Security Culture: A How-to Guide for Improving Security Culture and Dealing with People Risk in Your Organisation

Security Culture: A How-to Guide for Improving Security Culture and Dealing with People Risk in Your Organisation

See More Products

Related Articles

  • cyber-attack

    More than 8.4 million DDoS Attacks Targeted IT Infrastructures, Cloud, Mobile Networks & IoT Devices in 2019

    See More
  • cyber attack

    Research reveals rise in sophisticated attacks against mobile devices

    See More
  • SEC0919-Mobile-Feat-slide1_900px

    Managing security on mobile devices through mobile certificate management

    See More

Events

View AllSubmit An Event
  • March 6, 2025

    Why Mobile Device Response is Key to Managing Data Risk

    ON DEMAND: Most organizations and their associating operations have the response and investigation of computers, cloud resources, and other endpoint technologies under lock and key. 
  • September 3, 2024

    From DDoS Protection to WAAP: How Layered Protection Enhances Your Cybersecurity Strategy

    ON DEMAND: By participating in the webinar, attendees will gain enhanced knowledge of cyber threats and understand the current spectrum of cyber threats facing businesses.
View AllSubmit An Event
×

Sign-up to receive top management & result-driven techniques in the industry.

Join over 20,000+ industry leaders who receive our premium content.

SIGN UP TODAY!
  • RESOURCES
    • Advertise
    • Contact Us
    • Store
    • Want More
  • SIGN UP TODAY
    • Create Account
    • eMagazine
    • eNewsletter
    • Customer Service
    • Manage Preferences
  • SERVICES
    • Marketing Services
    • Reprints
    • Market Research
    • List Rental
    • Survey/Respondent Access
  • STAY CONNECTED
    • LinkedIn
    • Facebook
    • YouTube
    • X (Twitter)
  • PRIVACY
    • PRIVACY POLICY
    • TERMS & CONDITIONS
    • DO NOT SELL MY PERSONAL INFORMATION
    • PRIVACY REQUEST
    • ACCESSIBILITY

Copyright ©2025. All Rights Reserved BNP Media.

Design, CMS, Hosting & Web Development :: ePublishing

Security Magazine logo
search
cart
facebook twitter linkedin youtube
  • Sign In
  • Create Account
  • Sign Out
  • My Account
Security Magazine logo
  • NEWS
    • Security Newswire
    • Technologies & Solutions
  • MANAGEMENT
    • Leadership Management
    • Enterprise Services
    • Security Education & Training
    • Logical Security
    • Security & Business Resilience
    • Profiles in Excellence
  • PHYSICAL
    • Access Management
    • Fire & Life Safety
    • Identity Management
    • Physical Security
    • Video Surveillance
    • Case Studies (Physical)
  • CYBER
    • Cybersecurity News
    • More
  • BLOG
  • COLUMNS
    • Cyber Tactics
    • Leadership & Management
    • Security Talk
    • Career Intelligence
    • Leader to Leader
    • Cybersecurity Education & Training
  • EXCLUSIVES
    • Annual Guarding Report
    • Most Influential People in Security
    • The Security Benchmark Report
    • The Security Leadership Issue
    • Top Guard and Security Officer Companies
    • Top Cybersecurity Leaders
    • Women in Security
  • SECTORS
    • Arenas / Stadiums / Leagues / Entertainment
    • Banking/Finance/Insurance
    • Construction, Real Estate, Property Management
    • Education: K-12
    • Education: University
    • Government: Federal, State and Local
    • Hospitality & Casinos
    • Hospitals & Medical Centers
    • Infrastructure:Electric,Gas & Water
    • Ports: Sea, Land, & Air
    • Retail/Restaurants/Convenience
    • Transportation/Logistics/Supply Chain/Distribution/ Warehousing
  • EVENTS
    • Industry Events
    • Webinars
    • Solutions by Sector
    • Security 500 Conference
  • MEDIA
    • Videos
      • Cybersecurity & Geopolitical Discussion
      • Ask Me Anything (AMA) Series
    • Podcasts
    • Polls
    • Photo Galleries
  • MORE
    • Call for Entries
    • Classifieds & Job Listings
    • Continuing Education
    • Newsletter
    • Sponsor Insights
    • Store
    • White Papers
  • EMAG
    • eMagazine
    • This Month's Content
    • Advertise
  • SIGN UP!