GrapheneOS 在 Android 17 基础上构建了一套多层防护系统,用于防止数据从锁定设备中被非法提取[1]。该系统包含磁盘加密、安全元素速率限制、硬件内存标记、USB 防护和自动重启计时器等防御功能[1]。
在安全元素的速率限制方面,该系统规定密码输入失败 10 次后延迟 4 小时,失败 15 次后延迟 41 天,仅允许最多 20 次尝试[1]。同时,密码字符限制从 16 个提升至 128 个,并支持高熵骰子短语[1]。指纹解锁的尝试次数则从 20 次下调至 5 次[1]。此外,GrapheneOS 配备了锁定设备自动重启计时器,可设置范围为 10 分钟至 72 小时,默认为 18 小时[1]。
GrapheneOS 目前仅支持 Pixel 设备,但将通过与摩托罗拉合作在 2027 年扩展到其他设备[1]。值得注意的是,GrapheneOS 自 2021 年 6 月起已部署锁定设备自动重启功能,Apple 和 Google 分别在 iOS 18.1 和 Android 16 中添加了类似功能[1]。
GrapheneOS has unveiled a comprehensive security framework designed to prevent unauthorized data access on locked devices, building on Android 17 with enhanced defensive mechanisms [1]. The system implements disk encryption, secure element rate limiting, hardware memory tagging, USB protection, and automatic restart timers to create multiple barriers against extraction attempts [1].
The secure element now enforces progressive delays following failed unlock attempts: a 4-hour lockout after 10 failures, extending to 41 days after 15 failures, with a maximum of 20 total attempts permitted [1]. To strengthen credential security, GrapheneOS has increased the maximum password length from 16 to 128 characters and added support for high-entropy dice phrases [1]. Biometric authentication has also been tightened, reducing the number of fingerprint unlock attempts from 20 to 5 [1]. Users can configure an automatic restart timer for locked devices ranging from 10 minutes to 72 hours, with a default setting of 18 hours [1].
GrapheneOS has been deploying the automatic restart feature on locked devices since June 2021, predating similar implementations by major competitors; Apple and Google subsequently introduced comparable functionality in iOS 18.1 and Android 16 respectively [1]. Currently, GrapheneOS operates exclusively on Pixel devices, but the platform plans to expand its support through a partnership with Motorola Mobility, with new device compatibility expected by 2027 [1].