
BlackBerry Enterprise Solution
9
BlackBerry encryption keys
By default, the BlackBerry Enterprise Solution generates the master encryption key and message key that the
BlackBerry Enterprise Server and BlackBerry devices use to encrypt and decrypt all data traffic between them.
The BlackBerry Enterprise Server administrator can also enable the BlackBerry device to generate and use the
content protection key to encrypt BlackBerry device user data while the BlackBerry device is locked, and
generate and use the grand master key to encrypt the master encryption key while the BlackBerry device is
locked.
Encryption key relationships on the BlackBerry device
Master encryption keys
The master encryption key is unique to the BlackBerry device. To send and receive messages, the master
encryption key stored on the BlackBerry Enterprise Server and on the BlackBerry device must match. If the
stored keys do not match, the BlackBerry device and the BlackBerry Enterprise Server cannot decrypt and must
therefore discard messages that they receive.
Where master encryption keys are stored
The BlackBerry Configuration Database, the messaging server, and the BlackBerry device flash memory store
encryption keys, including the current BlackBerry device master encryption key.
Messaging server platform
Messaging server
storage location
BlackBerry device
storage location
BlackBerry Enterprise
Server storage location
IBM® Lotus® Domino®
the BlackBerry profiles
database
a key store database in
flash memory
the BlackBerry
Configuration Database
Microsoft® Exchange
the computer email
application user mailbox
a key store database in
flash memory
the BlackBerry
Configuration Database
Novell® GroupWise®
not stored
a key store database in
flash memory
the BlackBerry
Configuration Database
The BlackBerry Configuration Database stores master encryption keys alongside the BlackBerry device user data
that they protect. The BlackBerry Configuration Database, the messaging server, and the BlackBerry device flash
www.blackberry.com