Protected Storage Of User Data On A Locked Blackberry Device - Blackberry ENTERPRISE SOLUTION SECURITY - ENTERPRISE SOLUTION - SECURITY TECHNICAL Overview

Table of Contents

Advertisement

BlackBerry Enterprise Solution
Process for encrypting files stored in external memory on the BlackBerry device
When the BlackBerry device user stores a file in external memory for the first time after the BlackBerry Enterprise
Server administrator turns on or the BlackBerry device user turns on mass storage mode, the BlackBerry
device decrypts the external memory file encryption key and uses it to automatically encrypt the stored file.
For more information, see Enforcing Encryption of Internal and External File Systems on BlackBerry Devices
Technical Overview.

Protected storage of user data on a locked BlackBerry device

If content protection is turned on, BlackBerry device content is always protected with the 256-bit AES encryption
algorithm. Content protection of BlackBerry device user data is designed to perform the following actions:
use 256-bit AES to encrypt stored data when the BlackBerry device is locked
use an ECC public key to encrypt data that the BlackBerry device receives when it is locked
When the BlackBerry Enterprise Server administrator or a BlackBerry device user turns on content protection on
the BlackBerry device, the BlackBerry device uses content protection to encrypt user data items, including the
following:
Item
AutoText
BlackBerry Browser
calendar
contacts (in the address book)
email
memo list
RSA SecurID Library
tasks
www.blackberry.com
Description
all text that automatically replaces the text a BlackBerry device user types
content that web sites or third-party applications push to the
BlackBerry device
web sites that the user saves on the BlackBerry device
browser cache
subject
location
organizer
attendees
notes included in the appointment or meeting request
all information except the contact title and category
Note: Set the Force Include Address Book In Content Protection IT policy
rule to True to prevent the BlackBerry device user from turning off the
Include Address Book option on the BlackBerry device. The BlackBerry
device permits the Caller ID and Bluetooth Address Book transfer features
to work when content protection is turned on and the BlackBerry device is
locked.
subject
email addresses
message body
attachments
title
information included in the body of the note
the contents of the .sdtid file seed stored in flash memory
subject
information included in the body of the task
30

Advertisement

Table of Contents
loading
Need help?

Need help?

Do you have a question about the ENTERPRISE SOLUTION SECURITY - ENTERPRISE SOLUTION - SECURITY TECHNICAL and is the answer not in the manual?

This manual is also suitable for:

Enterprise server 4.1

Table of Contents