Bittium Tough Mobile™ 2 C - Highest Level of Security for Mobile Communications

For Ultimate End-to-End Security

Bittium Tough Mobile™ 2 C smartphone with Bittium Secure Suite™ device management and encryption software provides the highest level of privacy and security for people working in the security, authority or government sectors. Take mobile security into your own hands with the smartphone solution that has a unique hardware-based and multilayered security structure, hardened Android™ 11 operating system, and dual-boot functionality, running two completely separate and hardened operating systems on a single platform. Security settings can be configured with Bittium Secure Suite to Restricted, Confidential and beyond to meet the individual security needs of your organization. The complete solution is certified for CONFIDENTIAL level (NCSA-FI, TL III), and designed to be certified up to CONFIDENTIAL level by national security authorities.

Certified Security

Tough Mobile 2 C & Secure Suite certified for CONFIDENTIAL level

Two Operating Systems

Dual-boot for full data separation within one device.

Made in Finland

Designed and manufactured in Finland, manufacturing supervised by Bittium.

Long Lifespan

Military-grade durability, security updates provided longer than usually.

Security Built-In

Keep your data secured with multilayered security integrated in hardware and software of the Bittium Tough Mobile 2 C smartphone.

  • Dual-boot device with two operating systems and total data separation

  • Tamper-proofed to prevent data theft and hardware manipulation

  • Non-rootable device firmware

  • Disk encryption protected by secure element's authentication and security design

  • Secure boot with hardware and software integrity validation

  • Dedicated, tamper-proof secure element for user credentials and encryption keys

Two Operating Systems in One Device

Both operating systems support Multicontainer feature

Dual-boot functionality provides two completely separate operating systems with full data separation within one device.

  • Personal use with hardened Android™ 11, where e.g. social media applications are freely available
  • Confidential use with hardened Bittium Secure OS, allowing demanding authority and use cases

User can quickly switch between the two operating systems with dual-boot functionality.

Excellent usability and quick two-factor authentication with NFC token* and admin configurable authentication interval.

*Yubikey 5 NFC by Yubico included in the sales package

Android is a trademark of Google LLC

Bittium Secure Suite™ for Complete Mobile Security

Bittium Tough Mobile 2 C always requires Bittium Secure Suite. It is an advanced software product with a full set of services for secure communications. It requires installation of a server software, which is provided either as a dedicated IT service or hosted by the customer.

Bittium Secure Suite™

  • Configuration of security parameters and other settings
  • Audit logs for security related events
  • Remote wipe of device
  • Remote attestation
  • Application whitelisting support
  • Bittium SafeMove® MDM support
  • Bittium SafeMove® Mobile VPN to encrypt data in transit
  • Hardened password policy
  • Multicontainer feature

Several Isolated and Secure Containers with Multicontainer Feature

Both operating systems are supported with the Multicontainer feature and Bittium Secure Suite

  • Prevents data contamination between applications/services located in containers
  • Uses classified data and services from several separate organizations as each container isolates applications, data and network traffic from all other containers
  • Isolates also personal applications, data and network traffic from work data
  • Services in containers can connect to isolated back-ends via container-specific VPN tunnels
  • Services within the containers are protected and managed with Bittium Secure Suite

Bittium Secure Call™ - Application for Encrypted End-to-End Communication

  • Designed for enterprise, government and other professional users
  • Available for Android™ and Windows platforms
  • Supports deployment in commercial and private networks with no dependency on public Internet or cloud services
  • Can be deployed and fully managed by the user organization
  • Bittium Secure Suite™ offers device management and the use of an additional VPN layer to provide dual encryption for secured communication
  • Covers end-to-end encrypted voice and video calls, group calls, messages with attachments (picture, voice memo, video, contacts, voice messages), group messaging, and a feature that destroys messages after a predefined time
  • Centralized contact directory

Professional and Powerful

  • Dual-OS
  • Hardened Android™ 11 (Personal mode)
  • Bittium Secure OS (Secure mode)
  • Qualcomm® Snapdragon™ 670 chipset
  • Dedicated hardware secure element
  • Global connectivity
  • Dual SIM
  • Embedded 3000mAh battery
  • 12MP autofocus rear-facing and 5MP front-facing cameras
  • High-quality speakers
  • Multi-microphone active noise cancellation
  • MIL-STD-810G shock and drop resistant
  • IP67 water and dust resistant

Unique Hardware-Based Privacy Mode

Privacy mode allows use of the device while protecting from

  • Ambient listening by disconnecting microphones from the phone

  • Bluetooth sniffing by disabling Bluetooth

  • Camera spying by disabling device cameras

  • Sensor-based spying by reducing sensor accuracy

Three Variants Available - Based on the Same Hardware, Different Levels of Security

Additional Info

Security Highlights

Bittium Secure Operating System

  • Dual boot; full data and secure element separation
  • Secure data folder for classified documents and other data files. Data available when screen lock is open.
  • Excellent usability and quick two-factor authentication with NFC token and admin configurable authentication interval, available in Secure and Personal modes
  • Hardened, configurable and restricted cellular network security (call, SMS/MMS, IMS, VoLTE, aGPS, SIM application toolkit)
  • Hardened Linux kernel
  • Secured local connectivity (Bluetooth/WiFi/NFC/USB)
  • Automatic system cleanup of secure data
  • Device can be configured to be used only in Bittium Secure OS Confidential mode, using full device storage capacity
  • Always on VPN
  • Secure shutdown after lost network connectivity based on configurable time

Advanced security features

  • Hardened Android™ 11 operating system
  • Hardened Bittium Secure operating system
  • All data in the device is encrypted with AES-256 encryption (including the memory card, when used in adoptable storage mode)
  • Dedicated secure element (chipset) for storing security keys and providing functionality for encryption and user authentication
  • Backup battery allowing monitoring of the device security and tamper detection at all times, even when the main battery has ran out
  • Hardware-based Privacy Mode preventing ambient listening and spying of user/user environment
  • Hardware tamper detection preventing data theft and device implanting attempts
  • Secure boot, device HW and SW integrity check during boot
  • Disabled debug interfaces preventing attacks against device security
  • Device OS rollback prevention – not possible to use older device firmware for attacking the device
  • Die shield sensor in secure element to protect from physical intrusion and electromagnetic signal sniffing
  • Environmental attack protection in secure element preventing e.g. cryo/cold attacks and power glitch attacks
  • Application permission control – users can allow only trusted applications to access
  • User originated fast wipe of device data

Bittium Secure Suite™

  • Configuration of security parameters and other settings
  • Audit logs for security related events
  • Remote wipe of device
  • Remote attestation
  • Application whitelisting support
  • Bittium SafeMove® MDM support
  • Bittium SafeMove® Mobile VPN to encrypt data in transit
  • Hardened password policy
  • Both operating systems support Multicontainer feature
  • Notifications between Secure and Personal modes
Device Specifications

Two operating systems

  • Hardened Bittium Secure OS for CONFIDENTIAL level use
  • Hardened Android™ 11 for Personal use
  • Both operating systems support Multicontainer feature

Chipset                             
Qualcomm® Snapdragon™ 670


Memory
4GB RAM / 64GB eMMC. MicroSD expansion slot up to 256GB


Display

  • 5.2” Full HD sunlight readable
  • Glove & wet usable capacitive touchscreen

Imaging & video

  • 12MP autofocus rear-facing and 5MP front-facing cameras
  • 4K and Full HD video

Audio

  • High-quality front-facing dual speakers (109dB@5cm SPL)
  • Multi-microphone active noise cancellation

Physical buttons

  • Privacy mode activation
  • Emergency button (programmable, use as emergency button requires a separate application providing the functionality)
  • PTT/PTV (programmable, use as PTT/PTV button requires a separate application providing the functionality)
  • Power/wake-up
  • Volume up and down

LTE and bands

  • 3GPP Rel 12
  • Dual SIM dual VOLTE (DSDV)
  • IMS, VoLTE, CA
  • FDD bands: 1, 2, 3, 4, 5, 7, 8, 12, 13, 14, 17, 20, 25, 26, 28, 29, 30, 66
  • TDD bands: 38, 39, 40 (34, 41 optional)

UMTS/HSPA bands
B1, B2, B4, B5, B8


GSM/GPRS/EDGE bands
850/900/1800/1900 MHz


Complementary radios

  • Wi-Fi 802.11 a/b/g/n/ac (2.4 and 5 Ghz)
  • BT5.0, NFC

*U-NII-3 Wi-Fi channels are not supported

Accessories

 

FAQ

General

Question:
Does Bittium Tough Mobile 2 C differ from a regular smartphone?

Answer:
Bittium Tough Mobile 2 C differs from a standard off-the-shelf smartphone as it is designed for secure use.

For example, it has a dedicated secure element storing encryption keys and performing cryptographic operations. The Android based operating system’s security is hardened by Bittium to utilize the dedicated hardware secure element.

It has a mechanical and electrical concept that has been designed to provide a long lifespan for the device. Bittium will also provide software security updates longer than what is usual for regular consumer smartphones.

It has dual-boot functionality, running two completely separate and hardened operating systems on a single platform: Confidential and Personal. This unique dual-boot functionality enables both personal and professional use with high-level information security on a single device, eliminating the need for carrying two separate devices.

The phone also has a unique hardware-based privacy mode for disabling microphones, cameras, Bluetooth, and reducing sensor sensitivity with a touch of a button.


Question:
Who can buy the phones and where?

Answer:
Bittium Tough Mobile 2 C is available for enterprise and government customers. The customers will also need the Bittium Secure Suite server, which is installed in their IT infrastructure. Please contact us for more information.


Question:
Where are the phones manufactured?

Answer:
Tough Mobile 2 C smartphones are designed and manufactured in Finland. Manufacturing is supervised by Bittium and can be audited for certification purposes.


Question:
Can Tough Mobile 2 C be used in commercial networks?

Answer:
Yes, Tough Mobile 2 C can be used in commercial networks as well as in private networks.


Question:
In which countries can I use Tough Mobile 2?

Answer:
Tough Mobile 2 can be used globally and it supports the majority of the used cellular bands. For additional details of the supported bands, please see the supported bands in the Tough Mobile 2 datasheet or in this website’s Additional Info - Device Specifications section.


Question:
What does Tough Mobile 2 C’s "long lifespan" mean?

Answer:
The phone has a mechanical and electrical concept that has been designed to provide a long lifespan for the device. For example, it has military-grade durability (MIL-STD-810G) and in addition, Bittium provides operating system and software security updates longer than what is usually provided for regular smartphones, minimum until year 2026.


Question:
Can I use any Android application with Tough Mobile 2 C?

Answer:
Yes, Tough Mobile 2 C is verified by Google and it is compatible with all Android applications available for Android 11.


Question:

Can Tough Mobile 2 C be customized?

Answer:
Yes, Tough Mobile 2 C can be customized to meet the security needs of different companies and organizations, further enhancing the smartphone usability. Please contact us for further details.


Question:
Can I get Tough Mobile 2 C without Google Mobile Services?

Answer:
Yes. Although Personal mode operating system always includes Google Mobile Services, with Bittium Secure Suite it is possible to disable the Personal mode, leaving only Bittium Secure operating system without Google Mobile Services in use.


Question:
When using the Tough Mobile 2 C without Google Mobile Services and Google Play, am I able to install applications?

Answer:
With Bittium Secure Suite software product and its back-end server you can install approved Android applications through the Application Library.


Question:
Can I receive further details about mobile security and specific product features?

Answer:
All publicly available product information is on our website. More detailed technical information, training and dedicated customer support is available for B2B customers under Non-Disclosure-Agreement (NDA). 


Question:
What is the difference between the two operating systems in Tough Mobile 2 C?

Answer:
Operating system in the Confidential mode is completely separated and hardened for secure use, and it’s intended for ultimate, government-level secure communications.

Hardened Android operating system in the Personal mode is for personal use where e.g. Google services and other social media applications are freely available.

This unique dual-boot functionality enables both personal and professional use with high-level information security on a single device, eliminating the need for carrying two separate devices. The user can switch between the two different modes with dual-boot functionality.


Question:
What does Tough Mobile 2 C sales box include?

Answer:
Bittium Tough Mobile 2 C sales box includes: embedded 3000 mAh Li-Ion battery, charger with EU or UK plug, USB-C cable, stereo headset, SIM tray tool, user guide, Secure Suite and NFC Dongle.


Question:
How long will the security updates be available?

Answer:
Bittium Tough Mobile 2 C is guaranteed to have a long life cycle and support for security updates. Device security updates will be available minimum until year 2026.

Security

Question:
What does "highest level of security" mean?

Answer:
Highest level of security means that the device has been designed to meet even the highest governmental grade security requirements.

Tough Mobile 2 C has been designed for ultra secure use, starting from tamper-proofed mechanics to always-on security monitoring of electronics and hardened software solutions utilizing the Android 11 operating system.

Security is always based on hardware originated tamper-proof security solutions.

Smartphone’s unique HW security solutions and multilayered security structure are reinforced with the dual-boot functionality, running two completely separate and hardened operating systems on a single platform: Confidential and Personal.

Highest security also means that the device has been designed and manufactured by a trusted vendor in Finland.


Question:
What does Tough Mobile 2 C's “multilayered security” mean?

Answer:
Tough Mobile 2 C's security is built in layers, both in hardware and software.

The security built in the hardware protects data at rest. Security starts from the design and manufacturing of the device, including a hardware secure element that for example stores all authentication data and encryption keys. For software-based security, Tough Mobile 2 C always comes with Bittium Secure Suite™ full set of services for securing the data in transit.


Question:
What does Tough Mobile 2 C’s dedicated hardware secure element do?

Answer:
The hardware secure element provides for example user authentication services for Android, stores device encryption keys and provides cryptographic operations. If the Android OS becomes compromised with malware with access to everything, it still would not be able to access the contents of the secure element.

Secure element also controls the tamper detection feature of the device – even if the device’s main battery has run out. The secure element is powered by its own backup battery.


Question:
How is data in Tough Mobile 2 C encrypted?

Answer:
All data in Tough Mobile 2 C is encrypted with AES-256 encryption. Tough Mobile 2 C supports also encryption for data in SD cards. Data in transit is encrypted with Bittium SafeMove® Mobile VPN included in Bittium Secure Suite.


Question:
How is Tough Mobile 2 C tamper-proofed?

Answer:
Tough Mobile 2 C’s secure element detects if someone is trying to for example drill, open, disassemble, or precision cut the device. If tampering is detected, the secure element cryptographically erases all data from the device, even if the main battery has ran out of power. The secure element is powered by its own rechargeable backup battery.


Question:
How is Tough Mobile 2 C protected from unwanted hardware implants?

Answer:
Tough Mobile 2 C is tamper-proofed, which means that the phone detects if it is dismantled or the SIM slot is opened. For security reasons all data is cryptographically erased in case of dismantling. When the SIM slot is opened, device locks instantly and only the device’s original user can dismiss notification of SIM slot opening by authenticating to the device and continue using the device.


Question:
How is Tough Mobile 2 C protected from malicious firmware?

Answer:
Tough Mobile 2 C can be used only with Bittium signed firmware delivered by Bittium. Device utilizes secure/trusted boot, OS rollback prevention and the device is non-rootable. In each start up the device checks firmware and hardware integrity. For additional security layer, Bittium Secure Suite can be used to remotely attest the device firmware and hardware.


Question:
What does Bittium Secure Suite provide and how can I take it into use with Tough Mobile 2 C?

Answer:
Bittium Secure Suite is an advanced software product that complements Tough Mobile 2 C with a full set of services for secure communications, including MDM, VPN, remote attestation and application whitelisting. It is available for both private and public organizations, and requires installation of a back-end server, which is provided either as a dedicated IT service or hosted by the customer.

Please contact us to start a trial.


Question:
Is VPN included with Tough Mobile 2 C?

Answer:
Tough Mobile 2 C is always complemented with Bittium Secure Suite software which has Bittium SafeMove® Mobile VPN client software pre-installed to secure data in transit. Please contact us for more information and for starting a trial with Tough Mobile 2 C and Secure Suite.

Tough Mobile 2 C device supports also any 3rd party VPN solutions supported by Android 11.


Question:
What does the Multicontainer solution do?

Answer:
Both operating systems support Multicontainer feature, enabling the use of several secure, isolated workspaces within one operating system, preventing data contamination between applications/services located in container workspaces. With Multicontainer, it is possible to use classified data and services from several separate organizations as each container workspace isolates applications, data and network traffic from all other workspace containers.

You can switch between the different workspaces by swiping sideways from the home screen.

Services within the workspaces are protected and managed with Bittium Secure Suite. Services in workspace containers can connect to isolated back-ends via container-specific VPN tunnels, providing unique data-in-transit protection for each workspace.


Question:
How can I enable the Multicontainer solution?

Answer:
Multicontainer solution is enabled with the Bittium Secure Suite back-end system as each container uses its own VPN tunnel and server environment for isolating and encrypting data in transit. Please contact us to get the complete solution for your organization.


Question:
How can I create a single container in Tough Mobile 2 C?

Answer:
Multicontainer solution is enabled and controlled with Bittium Secure Suite back-end system.


Question:
What does the hardware-based Privacy Mode mean and how does it work?

Answer:
With Privacy Mode you can prevent eavesdropping and spying through device by disabling microphones, Bluetooth, cameras and reducing sensor accuracy on the device at the hardware-level. Privacy Mode can be activated/deactivated by pressing and holding the privacy button, which is the topmost button on the right-hand side of the phone. A green indicator light starts blinking on the front side of the phone when Privacy Mode is active.


Question:
How can I make encrypted calls with Tough Mobile 2 C?

Answer:
Making encrypted calls is possible with dedicated secure voice applications, for example Bittium Secure Call, which are available from Bittium and its solution partners. Please contact us for more information.


Question:
How is Tough Mobile 2 C’s operating system hardened?

Answer:
For example, Tough Mobile 2 C’s security/encryption key management, user authentication and true random number generation are moved from Android to Bittium hardware-based secure element. If you would like to discuss what additional hardenings have been made, please contact us.


Question:
How can I quickly erase all my data from the phone in emergency situations?

Answer:
Tough Mobile 2 C is provided with a Fast Wipe functionality to erase all data in emergency situations. User can trigger Fast Wipe from drop-down menu by pressing the red Fast Wipe icon and giving the device PIN.


Question:
How do I get security updates to Tough Mobile 2 C?

Answer:
All Tough Mobile 2 C updates are delivered Over-The-Air (OTA).

Bittium Secure Suite allows full control over which devices are updated, when, and with which firmware. The OTA delivery can also be protected by VPN. Bittium can also provide its customers with professional service tools for local updates.


Question:
Can Tough Mobile 2 C be security certified for national security purposes?

Answer:
Yes, Tough Mobile 2 C has been designed to be certified for national security purposes. CONFIDENTIAL level approvals has been achieved for example in Finland (NCSA-FI, TL III). Device and manufacturing audits are possible for certification purposes.

Technical

Question:
How can I activate the Emergency button?

Answer:
Use of the emergency button requires a separate application providing the functionality. When the suitable application supporting Bittium emergency button has been installed, go to Settings → Buttons → Emergency Button Function and select Emergency application from the list.


Question:
How can I activate the Push-To-Talk button?

Answer:
Use of the PTT/PTV button requires a separate application providing the functionality. When the suitable application supporting Bittium PTT button has been installed, go to Settings → Buttons → PTT Button Function and select PTT application from the list.


Question:
What does “MIL-STD-810G” mean?

Answer:
MIL-STD-810G is a US military standard that defines a broad set of environmental (such as shock, vibration, temperature, humidity) requirements for mobile devices that are designed for use in harsh environments. Tough Mobile 2 C has been tested against the MIL-STD-810G shock and drop standards.


Question:
What does “IP67 water and dust resistant” mean?

Answer:
IP67 level water and dust resistant means that the device is built to be protected from dust and is operational after being submerged in 1 meter of water for 30 minutes. IP67 does not mean that device is designed to be used underwater.


Question:
Does the device support dual-SIM functionality?

Answer:
Yes, Tough Mobile 2 C supports Dual SIM Dual Standby and has dual nano-SIM slots.


Question:
Can the internal memory/storage be expanded?

Answer:
Yes, Tough Mobile 2 C has a combined nano-SIM/MicroSD expansion slot which can be used to provide up to 256GB of additional memory/storage.


Question:
Does the device support external keyboard and display?

Answer:
Yes, Tough Mobile 2 C supports external keyboards and displays via its USB-C connector in Personal mode only.


Question:
How can I take screenshots with Tough Mobile 2 C?

Answer:
You can take screenshots by pressing and holding the Power button until pop-up menu appears. From pop-up menu select “Screenshot”. If containers are enabled, taking screenshots is disabled by default.


Question:
What is the battery size/life for the device?

Answer:
Tough Mobile 2 C has a 3000mAh embedded battery. Due to the device’s highly optimized power management, it will provide up to 460h standby time and up to 20h talk times. Actual results may vary depending on usage and environmental factors.

To make your battery last longer, you have multiple options.

Turn off tethering and hotspots when you’re not using them, go to Settings -> Network & Internet -> Hotspot & tethering -> Wi-Fi hotspot.

Turn off your Wi-Fi and Wi-Fi scanning when you are not using them, go to Settings -> Network & Internet -> Wi-Fi.

Turn off your Bluetooth when you are not using it, go to Settings -> Connected devices -> Connection preferences -> Bluetooth.

Turn off location when it is not necessary, go to Settings -> Security & location -> Location. Note that some applications and features don’t work without location services.

Turn off Google apps automatic downloads and updates;

go to Google Play -> Settings -> App download preference -> Ask me every time.
go to Google Play -> Settings -> Auto-Update apps -> Don’t auto-update apps.


Question:
Which charger plugs are provided with the phone?

Answer:
Bittium can provide Tough Mobile 2 C with either EU, UK or US charger plugs.


Question:
How can I activate the Recovery mode?

Answer:
Make sure the device is powered off.

Press ‘volume up’ button and keep it pressed -> press the ‘power’ button shortly and release it.

You should now enter the screen where you see an Android robot icon and text ‘no command’.

-> Release ‘volume up’ key -> press the ‘power’ key, keep it pressed and press shortly ‘volume up’ key -> release ‘power’ key.

You should now enter the recovery menu where you can perform a factory reset. Use volume up and down keys for navigation, ‘power’ key for menu item selection.

Note: If ‘power’ key is pressed over 10s, the phone will automatically restart.  Start over from the beginning if this happens.

Support

Question:
How long is the product warranty?

Answer:
Product warranty for Bittium Tough Mobile 2 C is one (1) year, including all accessories provided in the sales box, against defects in materials or workmanship. If the device is found to be defective within the one year warranty period, Bittium will repair or replace it with a new or refurbished device, at its option, at no charge to the customer, except as set forth below.

This warranty does not cover cosmetic damage, or device failure caused by liquid damages, or damage due to misuse, abuse, negligence, accident, modification or disassembly of any part of the device. The warranty does not cover damage due to improper operation or maintenance, connection to improper voltage supply, or attempted repair by anyone other than a facility authorized by Bittium to service this Tough Mobile 2 C.


Question:
Can the product warranty be extended?

Answer:
Yes, private and public organizations can purchase Extended Warranty for additional 12-36 months. Please contact us for more information.


Question:
How do I update the software on my Tough Mobile 2?

Answer:
All Tough Mobile 2 C updates are delivered Over-The-Air (OTA).

Bittium Secure Suite allows full control over which devices are updated, when and with which firmware. The OTA delivery can also be protected by VPN. Bittium can also provide its customers with professional service tools for local updates.


Question:
How can I change the battery?

Answer:
Bittium offers a replacement service if there is a need to replace the battery. Distributors and partners, please visit the Bittium Tough Mobile Support Portal for Partners to submit service requests. If you do not have an account for the Support Portal, please fill the Bittium Tough Mobile Support Request Form to make your service request.


Question:
Who can I contact for product support and maintenance?

Answer:
Please first read through all the FAQ and Support information on the Tough Mobile 2 C webpage.

If your problem is not solved, distributors and partners please visit the Bittium Tough Mobile Support Portal for Partners to submit error reports, support requests, service requests, and feature requests. If you don’t have an account for the Support Portal, please fill the Bittium Tough Mobile Support Request Form to make your support request.