# SP-050 Mobile Security Architecture

Status: draft. Release 26.02. Modified 2026-02-24. Licence: CC BY-SA 4.0.

Scope: Comprehensive mobile security architecture pattern covering certificate pinning, secure enclave usage, biometric authentication, mobile payment security (PCI DSS scope), application integrity, and data privacy for enterprise iOS and Android deployments. Bridges OWASP MASVS, PCI DSS, and NIST 800-53 with practical architecture guidance for native, hybrid, and cross-platform mobile applications.
Use when: Enterprise mobile banking and financial services applications requiring PCI DSS compliance and strong authentication. Healthcare mobile applications handling PHI under HIPAA or patient data under GDPR.
Not when: Simple content-consumption apps with no sensitive data processing or user authentication -- the overhead of enclave-backed cryptography and integrity checks is disproportionate.

## Controls (38, NIST SP 800-53 ids)
- Critical (8): CM-14, IA-02, IA-07, SC-08, SC-12, SC-13, SC-28, SI-07
- Important (17): AC-03, AC-04, AC-06, AU-02, CM-07, CM-08, IA-05, PM-25, PT-02, PT-04, SA-08, SA-11, SC-04, SC-17, SC-23, SI-06, SR-03
- Standard (13): AC-07, AC-17, AT-02, AU-12, CM-06, IA-12, MP-06, RA-05, SA-22, SC-07, SI-02, SI-10, SR-04

## What each critical control mitigates (8)
- CM-14 Signed Components: T-MS-002, T-MS-006, T-MS-007
- IA-02 User Identification And Authentication: T-MS-004
- IA-07 Cryptographic Module Authentication: T-MS-003, T-MS-004
- SC-08 Transmission Integrity: T-MS-001, T-MS-002
- SC-12 Cryptographic Key Establishment And Management: T-MS-003, T-MS-005, T-MS-007, T-MS-012
- SC-13 Use Of Cryptography: T-MS-001, T-MS-003
- SC-28 Protection of Information at Rest: T-MS-003, T-MS-005, T-MS-008, T-MS-012
- SI-07 Software And Information Integrity: T-MS-002, T-MS-006, T-MS-007

## Threats and the controls that mitigate them (12)
- T-MS-001 Man-in-the-middle attack intercepting mobile app traffic via rogue Wi-Fi or compromised carrier: SC-08, SC-17, SC-13, SC-23
- T-MS-002 Certificate pinning bypass using proxy tools or compromised device trust store: SC-17, SC-08, SI-07, CM-14
- T-MS-003 Cryptographic key extraction from device storage or memory: SC-12, SC-13, IA-07, SC-28
- T-MS-004 Biometric authentication bypass via presentation attack or API hooking: IA-02, IA-07, SI-06, AC-07
- T-MS-005 Payment cardholder data leakage through insecure local storage or logging: SC-28, AU-02, AC-03, SC-12
- T-MS-006 Reverse engineering of application binary to extract business logic or credentials: SI-07, CM-14, SA-11, CM-07
- T-MS-007 Jailbreak or root exploitation undermining platform security guarantees: SI-06, SI-07, CM-14, SC-12
- T-MS-008 Sensitive data leakage via screenshots, clipboard, keyboard cache, or device backups: SC-04, AC-04, SC-28, CM-07
- T-MS-009 Insecure inter-process communication exploited via malicious app on same device: AC-04, SC-07, SI-10, AC-03
- T-MS-010 Supply chain attack via compromised third-party mobile SDK or dependency: SR-03, SR-04, SA-11, CM-08
- T-MS-011 Location tracking and device fingerprinting enabling user surveillance: PM-25, PT-02, PT-04, AC-06
- T-MS-012 Offline device exposure when lost or stolen with sensitive data cached locally: SC-28, SC-12, AC-07, MP-06

## More
- The critical controls and what each mitigates, as JSON (a few KB): /api/v1/patterns/SP-050/crosswalk?emphasis=critical
- The same for every control, with its clauses in a framework: /api/v1/patterns/SP-050/crosswalk?framework={framework id}. Framework ids are listed in /llms.txt
- The pattern's prose, examples and references as JSON, 31 KB: /api/v1/patterns/SP-050
- Page for people: /patterns/sp-050/
- Related: SP-003 Privacy Mobile Device Pattern; SP-024 iPhone Pattern; SP-026 PCI Full Environment; SP-029 Zero Trust Architecture; SP-032 Modern Authentication; SP-033 Passkey Authentication; SP-039 Client-Side Encryption and Data Privacy

This card, the API and the page are generated from one file. Checking one against another adds no evidence.
