Hardware root key Container KEK Managed app (wrapped DEK) Personal app (own key)
⚠ Couldn't load the 3D engineThree.js failed to load from the CDN. Check your connection and reload.

MDM Work Container: Key Hierarchy & Crypto-Shred Wipe

This simulator visualizes the security architecture behind enterprise mobile device management (MDM) and mobile application management (MAM): a hardware-anchored root key derives a container key-encryption key, which wraps a separate data-encryption key for every managed app, while personal apps keep their own unrelated keys entirely outside the container boundary. A rogue-access simulation shows app-sandboxing blocking a personal app from reaching container data, and the remote-wipe control demonstrates crypto-shredding — the real technique behind "remote wipe," where deleting one key instantly and irreversibly destroys every managed app's data without touching a single byte of ciphertext.