11.08.2016 Views

Behind the Scenes with iOS Security

2aCt1ji

2aCt1ji

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

Filesystem Data Protection<br />

Overview<br />

File blocks are encrypted using AES-XTS <strong>with</strong> 128-bit keys<br />

Each file on <strong>the</strong> user partition is encrypted using a unique random key chosen by SEP<br />

Raw file keys are never exposed to <strong>the</strong> AP<br />

• Wrapped <strong>with</strong> a key from <strong>the</strong> user keybag for long-term storage<br />

• Wrapped <strong>with</strong> an ephemeral key while in use, bound to boot session

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!