Secure BYOD data access for enterprises using trusted-computing companion devices
Solving the BYOD paradox: enterprise-grade data security on any employee device.
The Challenge
Bring-your-own-device (BYOD) poses a fundamental paradox for enterprises: how do you secure data when you no longer control the device? A BYOD roll-out gives employees free choice of device type, operating system and configuration, and it is impossible to universally secure such a diverse device set — portable software-only solutions are susceptible to rooting attacks, while fully defined hardware stacks (like Samsung KNOX) are no longer BYOD because the device is fully specified.
The Solution
The SECD project addressed this problem by defining a hardware-hardened, tamper-proof companion device based on state-of-the-art Trusted Computing principles. The companion device serves applications “locally” to the employee’s own device over the web, augmented by secure web extensions made available in a trusted enterprise web browser. Beyond serving applications, the device caches encrypted data, mediates network connections, and provides enhanced multi-factor authentication for user identity.
Outcomes
The solution was evaluated across a number of companion-device form factors, including SIM card, USB dongle and MiFi solutions. With SECD, employers retain total control of their data while employees access it flexibly from whatever device they choose — resolving the BYOD paradox rather than working around it. NquiringMinds led the collaborative R&D consortium with Impleo Professional Services and the University of Oxford.
TODO: capture formal outcomes, deliverables and any follow-on exploitation.

Features
Hardware-hardened, tamper-proof companion device built on Trusted Computing principles.
Serves enterprise applications locally to any employee device over web, with secure web extensions in a trusted enterprise browser.
Encrypted data caching, network-connection mediation and enhanced multi-factor authentication on the companion device.
SIM card, USB dongle and MiFi.
Keeps the enterprise in total control of its data without constraining the employee's device choice — BYOD without the security compromise.
Benefits
Demonstrated a route for enterprises to retain total control of corporate data on unmanaged BYOD estates (project design goal; delivered as collaborative R&D).
Multi-form-factor evaluation (SIM/USB/MiFi) de-risking productisation choices (delivered evaluation).
