User login

Latest News

Data Security

Blackberry Wireless Data Security

End-to-End Encryption

The BlackBerry Enterprise Solution offers two transport encryption options, Advanced Encryption Standard (AES) and Triple Data Encryption Standard (Triple DES)*, for all data transmitted between BlackBerry® Enterprise Server and BlackBerry SmartPhones.

Private encryption keys are generated in a secure, two-way authenticated environment and are assigned to each BlackBerry SmartPhone user. Each secret key is stored only in the user's secure enterprise account (i.e., Microsoft® Exchange, IBM® Lotus® Domino® or Novell® GroupWise®) and on their BlackBerry SmartPhone and can be regenerated wirelessly by the user.

Data sent to the BlackBerry SmartPhone is encrypted by BlackBerry Enterprise Server (BES) using the private key retrieved from the user's mailbox. For deployments where there is not BES installed the carriers BIS can be utilized. The encrypted information travels securely across the network to the SmartPhone where it is decrypted with the key stored there.
Data remains encrypted in transit and is never decrypted outside of the corporate firewall.

Blackberry Wireless Data Security Diagram

RSA SecurID Two-Factor Authentication

BlackBerry MDS Services on BlackBerry Enterprise Server support RSA SecurID® authentication, providing organizations with additional authorization when users access application data or corporate intranets on their BlackBerry smartphones. BlackBerry MDS Services utilize RSA ACE/Agent® Authorization API 5.0 to interface to RSA ACE Servers®. Users are prompted for their Username and Token Passcode when navigating to a site or application requiring authorization.

HTTPS Secure Data Access

BlackBerry MDS Services act as a secure gateway between the wireless network and corporate intranets and the Internet. They leverage the BlackBerry AES or Triple DES* encryption transport and also enable HTTPS connections to application servers.

BlackBerry smartphones support HTTPS communication in one of two modes, depending on corporate security requirements:

Proxy Mode

An SSL/TLS connection is created between BlackBerry Enterprise Server and the application server on behalf of BlackBerry smartphones. Data from the application server is then AES or Triple DES* encrypted and sent over the wireless network to BlackBerry smartphones.

End-to-End Mode

Data is encrypted over SSL/TLS for the entire connection between BlackBerry SmartPhones and the application server, making End-to-End Mode connections most appropriate for applications where only the transaction end-points are trusted.