
BlackBerry Enterprise Solution
28
Protecting stored data
Protecting stored messages on the messaging server
The IBM Lotus Domino server and the Microsoft Exchange server perform all message storage and specific user
data storage in their environments. In the Novell GroupWise server environment, the Post-Office Agent where a
user’s messaging account resides stores messages and user data.
Messaging server
Message storage location
IBM Lotus Domino server
IBM Lotus Domino databases within the IBM Lotus Domino environment
Microsoft Exchange server
Hidden folders in Microsoft Exchange mailboxes that are associated with a
user
Storing message and user data in IBM Lotus Domino databases
The BlackBerry Enterprise Server creates and uses the following IBM Lotus Domino databases to manage
BlackBerry device messages:
Database
Message storage method
BlackBerry state
Stores an entry that establishes a connection between each original message in a
user’s IBM Lotus Notes Inbox and the same message on that user’s BlackBerry device
Each BlackBerry device user has a uniquely named BlackBerry state database.
BlackBerry profiles
•
stores important configuration information for each BlackBerry device user,
including the BlackBerry device identification information and master encryption
key
•
stores a link to a user’s BlackBerry state database and stores other information
that the BlackBerry Enterprise Server uses to manage the flow of messages to
and from the BlackBerry device
IT policy signing and storage on the BlackBerry device
An IT policy is a collection of one or more IT policy rules. An IT administration command is a function that the
BlackBerry Enterprise Server administrator can send over the wireless network to immediately control access to
or change ownership information on the BlackBerry device.
After the BlackBerry Enterprise Server installation process creates the BlackBerry Configuration Database, the
BlackBerry Enterprise Server generates a unique private and public key pair to authenticate the IT policy and the
IT administration commands, and digitally signs the Default IT policy before automatically sending it and the IT
policy public key to the BlackBerry device.
The BlackBerry device stores the digitally signed IT policy and the IT policy public key in the NV store in flash
memory, binding the IT policy to that particular BlackBerry device. The NV store persists in flash memory and can
only be overwritten by the BlackBerry device operating system. Third-party application code cannot write to the
NV store.
The BlackBerry Enterprise Server stores the IT policy private key in the BlackBerry Configuration Database. The
BlackBerry Enterprise Server uses the IT policy private key to sign all IT policy packets that it sends to the
BlackBerry device. The BlackBerry device uses the IT policy public key in the NV store to authenticate the digital
signature on the IT policy.
Application password encryption and storage on the BlackBerry device
A BlackBerry device user can use the Password Keeper tool to create and store all of the passwords that they
might use to gain access to applications and web sites on the BlackBerry device. This means that a BlackBerry
www.blackberry.com