
BlackBerry Enterprise Solution
30
Process for encrypting files stored in external memory on the BlackBerry device
When the BlackBerry device user stores a file in external memory for the first time after the BlackBerry Enterprise
Server administrator turns on or the BlackBerry device user turns on mass storage mode, the BlackBerry
device decrypts the external memory file encryption key and uses it to automatically encrypt the stored file.
For more information, see
Enforcing Encryption of Internal and External File Systems on BlackBerry Devices
Technical Overview
.
Protected storage of user data on a locked BlackBerry device
If content protection is turned on, BlackBerry device content is always protected with the 256-bit AES encryption
algorithm. Content protection of BlackBerry device user data is designed to perform the following actions:
•
use 256-bit AES to encrypt stored data when the BlackBerry device is locked
•
use an ECC public key to encrypt data that the BlackBerry device receives when it is locked
When the BlackBerry Enterprise Server administrator or a BlackBerry device user turns on content protection on
the BlackBerry device, the BlackBerry device uses content protection to encrypt user data items, including the
following:
Item
Description
AutoText
all text that automatically replaces the text a BlackBerry device user types
BlackBerry Browser
•
content that web sites or third-party applications push to the
BlackBerry device
•
web sites that the user saves on the BlackBerry device
•
browser cache
calendar
•
subject
•
location
•
organizer
•
attendees
•
notes included in the appointment or meeting request
contacts (in the address book)
all information except the contact title and category
Note
: Set the Force Include Address Book In Content Protection IT policy
rule to True to prevent the BlackBerry device user from turning off the
Include Address Book option on the BlackBerry device. The BlackBerry
device permits the Caller ID and Bluetooth Address Book transfer features
to work when content protection is turned on and the BlackBerry device is
locked.
•
subject
•
email addresses
•
message body
•
attachments
memo list
•
title
•
information included in the body of the note
RSA SecurID Library
the contents of the .sdtid file seed stored in flash memory
tasks
•
subject
•
information included in the body of the task
www.blackberry.com