Master encryption keys
The BlackBerry® Enterprise Server and the BlackBerry device each store a copy of the unique master encryption key of the
BlackBerry device.
Only the BlackBerry Enterprise Server and the BlackBerry device know the value of the master encryption key. When you
activate a BlackBerry device over the wireless network, the BlackBerry Enterprise Server and the BlackBerry device use an
authenticated link to communicate the value of the master encryption key.
For a user to send and receive messages on the BlackBerry device, the BlackBerry Enterprise Server and the BlackBerry
device must store matching copies of the master encryption key of the BlackBerry device. If the stored keys do not match,
the following actions occur:
• the BlackBerry Enterprise Server and the BlackBerry device must delete messages that they receive from each other
because they cannot decrypt them
• the BlackBerry device requires the user to generate a new master encryption key
Standard message encryption
The BlackBerry® Enterprise Solution uses a symmetric key encryption algorithm to protect data in transit between the
BlackBerry device and BlackBerry® Enterprise Server. This standard BlackBerry encryption, which is designed to provide
strong security, protects data in transit to the BlackBerry Enterprise Server when the message data is outside the
organization's firewall.
Standard BlackBerry encryption is designed to encrypt messages that the BlackBerry device sends or that the BlackBerry
Enterprise Server forwards to the BlackBerry device
• from the time the user sends an email message or PIN message from the BlackBerry device to when the BlackBerry
Enterprise Server receives the message
• from the time the BlackBerry Enterprise Server receives a message to when the user opens the decrypted message on
the BlackBerry device.
Before the BlackBerry device sends a message it compresses the message and then encrypts the message using the master
encryption key, which is unique to that BlackBerry device. The BlackBerry device does not use the master encryption key in
the compression process.
When the BlackBerry Enterprise Server receives the message from the BlackBerry device, the BlackBerry Dispatcher decrypts
the message using the master encryption key for the BlackBerry device, and then decompresses the message.
Feature and Technical Overview
BlackBerry Enterprise Solution security
33
Comentários a estes Manuais