Blackberry ENTERPRISE SOLUTION SECURITY - SECURITY FOR DEVICES WITH BLUETOOTH WIRELESS TECHNOLOGY - TECHNICAL Guia de Instalação Página 1

Consulte online ou descarregue Guia de Instalação para Software Blackberry ENTERPRISE SOLUTION SECURITY - SECURITY FOR DEVICES WITH BLUETOOTH WIRELESS TECHNOLOGY - TECHNICAL. Blackberry ENTERPRISE SOLUTION SECURITY - SECURITY FOR DEVICES WITH BLUETOOTH WIRELESS TECHNOLOGY - TECHNICAL Installation guide Manual do Utilizador

  • Descarregar
  • Adicionar aos meus manuais
  • Imprimir

Resumo do Conteúdo

Página 1 - Device Software Version 4.5

BlackBerry Enterprise Solution Security Technical Overview for BlackBerry Enterprise Server Version 4.1 Service Pack 5 and BlackBerry Device Softwar

Página 2 - Contents

BlackBerry Enterprise Solution 10 Messaging server platform Messaging server storage location BlackBerry device storage location BlackBerry Enterpr

Página 3

BlackBerry Enterprise Solution 11 Profiles database stores an account record containing the field RIMCurrentEncryptionKeyText, which stores the mast

Página 4

BlackBerry Enterprise Solution 12 5. The BlackBerry Desktop Software uses the first 256 bits if it is generating the master encryption key using AE

Página 5

BlackBerry Enterprise Solution 13 Process for generating message keys on the BlackBerry Enterprise Server The BlackBerry Enterprise Server is design

Página 6 - Wireless security

BlackBerry Enterprise Solution 14 7. The DSA PRNG function generates 128 pseudo-random bits for use with Triple DES and 256 pseudo-random bits for

Página 7

BlackBerry Enterprise Solution 15 3. The locked BlackBerry device uses the ECC public key to encrypt data that it receives. Process for decrypting

Página 8 - New security features

BlackBerry Enterprise Solution 16 verifies that a BlackBerry message remains protected in transit to the BlackBerry Enterprise Server while the mess

Página 9 - BlackBerry encryption keys

BlackBerry Enterprise Solution 17 Standard BlackBerry message encryption Standard BlackBerry encryption is designed to encrypt messages that the Bla

Página 10

BlackBerry Enterprise Solution 18 Permitting third-party applications to encode BlackBerry device data The BlackBerry Enterprise Server and the Blac

Página 11

BlackBerry Enterprise Solution 19 The BlackBerry Enterprise Server is designed to maintain a constant, direct outbound TCP/IP connection to the wire

Página 12 - Message keys

BlackBerry Enterprise Solution Contents Wireless security...

Página 13

BlackBerry Enterprise Solution 20 The system administrator can install the BlackBerry Attachment Service on a remote computer and then place that co

Página 14 - Content protection keys

BlackBerry Enterprise Solution 21 with Triple DES to encrypt PIN messages, every BlackBerry device can decrypt every PIN message that it receives be

Página 15 - Grand master keys

BlackBerry Enterprise Solution 22 Turning off unsecured messaging The BlackBerry Enterprise Server administrator can turn off unsecured messaging to

Página 16

BlackBerry Enterprise Solution 23 The BlackBerry device is designed to use the BlackBerry MDS Connection Service, which resides on the BlackBerry En

Página 17

BlackBerry Enterprise Solution 24 algorithms to encrypt PGP messages. The BlackBerry Enterprise Server administrator can set the PGP Allowed Content

Página 18

BlackBerry Enterprise Solution 25 4. The BlackBerry Enterprise Server removes the standard BlackBerry encryption and sends the S/MIME-encrypted mes

Página 19

BlackBerry Enterprise Solution 26 Decrypting and reading messages on the BlackBerry device using Lotus Notes API 7.0 The BlackBerry® Enterprise Serv

Página 20 - PIN-to-PIN messaging

BlackBerry Enterprise Solution 27 The encrypted Notes .id password remains stored in the BlackBerry Enterprise Server for IBM Lotus Domino messaging

Página 21 - Text messaging

BlackBerry Enterprise Solution 28 Database Message storage method BlackBerry profiles • stores important configuration information for each BlackB

Página 22

BlackBerry Enterprise Solution 29 • external file encryption by encrypting specific files on the external memory device using AES The external file

Página 23 - PGP encryption

BlackBerry Enterprise Solution BlackBerry architecture component security ...

Página 24 - S/MIME encryption

BlackBerry Enterprise Solution 30 Item Description calendar • subject • location • organizer • attendees • notes included in the appointmen

Página 25

BlackBerry Enterprise Solution 31 Protected storage of master encryption keys on a locked BlackBerry device If the BlackBerry Enterprise Server admi

Página 26

BlackBerry Enterprise Solution 32 • periodically runs the memory cleaner application, which tells BlackBerry device applications to empty any cache

Página 27 - Protecting stored data

BlackBerry Enterprise Solution 33 BlackBerry architecture component security The BlackBerry Enterprise Server consists of services that provide func

Página 28

BlackBerry Enterprise Solution 34 BlackBerry Enterprise Server The BlackBerry Enterprise Server is designed to establish a secure, two-way link betw

Página 29

BlackBerry Enterprise Solution 35 Configuration option Recommendations shield your Microsoft SQL Server installation from Internet based attacks •

Página 30

BlackBerry Enterprise Solution 36 Configuration option Recommendations Use a secure file system • Use NTFS for the Microsoft SQL Server because it

Página 31

BlackBerry Enterprise Solution 37 Protecting the BlackBerry Enterprise Solution connections The BlackBerry Enterprise Server is designed to communic

Página 32

BlackBerry Enterprise Solution 38 Step Action Description 3 The BlackBerry Enterprise Server sends a challenge string to the BlackBerry Infrastru

Página 33 - BlackBerry Infrastructure

BlackBerry Enterprise Solution 39 Scenario Result The connection between the BlackBerry Enterprise Server and the BlackBerry Infrastructure termina

Página 34 - Messaging server

BlackBerry Enterprise Solution Controlling BlackBerry device behavior using IT policy rules ...

Página 35

BlackBerry Enterprise Solution 40 For more information about the BlackBerry Router protocol and the authentication process, see “Masking operation p

Página 36

BlackBerry Enterprise Solution 41 Step Action Description 6 The BlackBerry Enterprise Server sends data to the BlackBerry device. If wireless PIM

Página 37 - SRP authentication

BlackBerry Enterprise Solution 42 Security measure Description The BlackBerry device initiates inbound connections using the BlackBerry Router to a

Página 38

BlackBerry Enterprise Solution 43 2. The BlackBerry Desktop Software implementation of the secure channel technology uses the shared secret passwor

Página 39

BlackBerry Enterprise Solution 44 message, the BlackBerry MDS Services security protocol encrypts and decrypts data that the BlackBerry device and t

Página 40

BlackBerry Enterprise Solution 45 HTTPS protocol BlackBerry MDS encryption method Description Handheld mode TLS/SSL TLS and WTLS key establishment

Página 41 - TCP/IP connection

BlackBerry Enterprise Solution 46 Authentication process for requests for wireless software upgrades When the BlackBerry Infrastructure sends a wire

Página 42

BlackBerry Enterprise Solution 47 segmented network architecture, the system administrator can place the BlackBerry Enterprise Solution components i

Página 43 - BlackBerry MDS connections

BlackBerry Enterprise Solution 48 Accessing the BlackBerry Infrastructure Wi-Fi enabled BlackBerry devices can connect directly to the BlackBerry In

Página 44

BlackBerry Enterprise Solution 49 Enterprise Wi-Fi network security technology Wi-Fi enabled BlackBerry device implementation Layer 2 security Set

Página 45

BlackBerry Enterprise Solution Encryption algorithms that the BlackBerry device supports for use with layer 2 security methods ...83 EAP authenticatio

Página 46 - WAP gateway connections

BlackBerry Enterprise Solution 50 After an authentication server permits the supported Wi-Fi enabled BlackBerry device to access the enterprise Wi-F

Página 47

BlackBerry Enterprise Solution 51 Authentication method Description Wi-Fi enabled BlackBerry device implementation Using IEEE 802.11i with PSK Sm

Página 48

BlackBerry Enterprise Solution 52 the authentication server certificate. For the supported Wi-Fi enabled BlackBerry devices to trust the authenticat

Página 49

BlackBerry Enterprise Solution 53 users must authenticate with the WLAN Login application browser using login credentials that the system administra

Página 50

BlackBerry Enterprise Solution 54 For more information, see the BlackBerry Smart Card Reader Security Technical Overview. Binding the smart card to

Página 51

BlackBerry Enterprise Solution 55 Field Description Initialized indicates whether the BlackBerry device is authenticated with and bound to the sma

Página 52 - Fi hotspots

BlackBerry Enterprise Solution 56 Creating new IT policy rules to control custom applications Create new IT policy rules to control custom applicati

Página 53

BlackBerry Enterprise Solution 57 The BlackBerry Enterprise Server administrator can define the following types of criteria: • specific, permitted

Página 54

BlackBerry Enterprise Solution 58 connection. BlackBerry devices and the BlackBerry Desktop Software can use CHAP to send a challenge and subsequent

Página 55

BlackBerry Enterprise Solution 59 How the BlackBerry device protects its operating system and the BlackBerry Device Software Each time a user turns

Página 56

BlackBerry Enterprise Solution 6 This document describes the security features of the BlackBerry® Enterprise Solution and provides an overview of th

Página 57

BlackBerry Enterprise Solution 60 • specify whether or not applications, including third-party applications, on the BlackBerry device can initiate

Página 58

BlackBerry Enterprise Solution 61 Each third-party application requires authorization to run on the BlackBerry device. MIDlets (applications that us

Página 59 - Software

BlackBerry Enterprise Solution 62 Remotely resetting the password of a content protected BlackBerry device The remote password reset cryptographic p

Página 60

BlackBerry Enterprise Solution 63 IT policy rule Description Secure Wipe if Low Battery Set this IT policy rule to require that, if the BlackBerry

Página 61 - • the signature is invalid

BlackBerry Enterprise Solution 64 do not exist on the BlackBerry device (in other words, if there is no connection between the BlackBerry Enterprise

Página 62

BlackBerry Enterprise Solution 65 Related resources Resource Information BlackBerry Enterprise Server Feature and Technical Overview • BlackBerry

Página 63

BlackBerry Enterprise Solution 66 Resource Information Garbage Collection in the BlackBerry Java Development Environment • cleaning BlackBerry dev

Página 64

BlackBerry Enterprise Solution 67 Resource Information Visit www.blackberry.com/security. • information about BlackBerry Solution security www.bla

Página 65 - Related resources

BlackBerry Enterprise Solution 68 Appendix A: RIM Crypto API Interface The RIM Crypto API on the BlackBerry device and in the BlackBerry JDE provid

Página 66

BlackBerry Enterprise Solution 69 Key agreement scheme algorithms Algorithm Key length (bits) Type DH 512 to 4096 discrete logarithm KEA 1024 di

Página 67 - Resource Information

BlackBerry Enterprise Solution 7 Concept Description BlackBerry Enterprise Solution implementation authenticity enables the message recipient to

Página 68 - • a key generation protocol

BlackBerry Enterprise Solution 70 Code Digest length (bits) RIPEMD-128, 160 128, 160 www.blackberry.com

Página 69

BlackBerry Enterprise Solution 71 Appendix B: TLS and WTLS standards that the RIM Crypto API supports The TLS and WTLS protocol cipher suite compone

Página 70 - RIPEMD-128, 160 128, 160

BlackBerry Enterprise Solution 72 Symmetric algorithms that the RIM Crypto API supports Direct mode SSL Direct mode TLS WTLS RC4 40 RC4 40 RC5 4

Página 71

BlackBerry Enterprise Solution 73 Appendix C: Previous version of wired master encryption key generation Each time a BlackBerry Enterprise Server or

Página 72

BlackBerry Enterprise Solution 74 Appendix D: BlackBerry device wipe process A BlackBerry device wipe is designed to delete and overwrite the BlackB

Página 73

BlackBerry Enterprise Solution 75 4. Clears all bytes to 0xFF (1111 11112). 5. Writes 0x55 to each byte (0x0101 01012). 6. Clears all bytes to 0x

Página 74

BlackBerry Enterprise Solution 76 Appendix E: Ephemeral AES encryption key derivation process The BlackBerry device uses an ephemeral 256-bit AES en

Página 75

BlackBerry Enterprise Solution 77 Appendix F: Power and electromagnetic side-channel attacks and countermeasures The BlackBerry device implementatio

Página 76

BlackBerry Enterprise Solution 78 How the AES algorithm creates S-Box tables The BlackBerry device permutes each AES S-Box entry randomly and masks

Página 77

BlackBerry Enterprise Solution 79 Appendix G: BlackBerry Router protocol When the BlackBerry Enterprise Server and the BlackBerry device use the Bla

Página 78

BlackBerry Enterprise Solution 8 Feature Description control BlackBerry device and BlackBerry Desktop Software functionality • Send wireless comma

Página 79

BlackBerry Enterprise Solution 80 device. The attacker must send master encryption key value (s) to the BlackBerry Enterprise Server, which requires

Página 80

BlackBerry Enterprise Solution 81 If the BlackBerry device accepts yB, the BlackBerry Enterprise Server and the BlackBerry device open an authentica

Página 81

BlackBerry Enterprise Solution 82 Appendix H: Enterprise Wi-Fi security methods that the BlackBerry device supports EAP authentication methods that

Página 82

BlackBerry Enterprise Solution 83 Authentication method Description BlackBerry device implementation EAP-TTLS EAP-TTLS is designed to extend EAP-

Página 83

BlackBerry Enterprise Solution 84 Protocol Description Wi-Fi enabled BlackBerry device implementation TKIP TKIP is • part of the IEEE 802.11i ent

Página 84 - • WEP and TKIP

BlackBerry Enterprise Solution 85 VPN solution on the Wi-Fi enabled BlackBerry device The Wi-Fi enabled BlackBerry device has a built-in VPN client

Página 85

BlackBerry Enterprise Solution 86 • RSA_WITH_RC4_128_MD5 • RSA_WITH_3DES_EDE_CBC_SHA • RSA_WITH_AES_128_CBC_SHA • RSA_WITH_AES_256_CBC_SHA • TL

Página 86 - • RSA_WITH_AES_256_CBC_SHA

BlackBerry Enterprise Solution 87 Appendix J: RSA SecurID software token tokencode generation process 1. An administrator uses the RSA Authenticati

Página 87

BlackBerry Enterprise Solution 88 3. The BlackBerry device receives B and verifies that B is a valid public key. 4. The BlackBerry device performs

Página 88 - BlackBerry device remotely

BlackBerry Enterprise Solution 89 Protocol process When the BlackBerry Enterprise Server administrator sends the Set a Password and Lock Handheld IT

Página 89 - Protocol process

BlackBerry Enterprise Solution 9 Feature Software versions supported Description The BlackBerry Enterprise Solution allows administrators to apply

Página 90

BlackBerry Enterprise Solution 90 Part number: 17930884 Version 2 ©2008 Research In Motion Limited. All rights reserved. BlackBerry®, RIM®, Research

Página 91

BlackBerry Enterprise Solution 91 Prior to subscribing for, installing, or using any Third Party Products and Services, it is your responsibility to

Comentários a estes Manuais

Sem comentários