Blackberry PRD-09695-004 Technical Overview - Page 4

BlackBerry Smart Card Reader, Authenticating a user using a smart card

Page 4 highlights

BlackBerry Smart Card Reader The BlackBerry® Smart Card Reader is an accessory that, when used in proximity to certain Bluetooth® enabled BlackBerry devices and computers, permits users to authenticate with their smart cards and log in to Bluetooth enabled BlackBerry devices and computers. The BlackBerry Smart Card Reader is designed to perform the following actions: • communicate with Bluetooth enabled BlackBerry devices and computers using Bluetooth technology version 1.1 and later and using the AES-256 encryption method (by default) on the application layer • create a reliable two-factor authentication environment for granting users access to the PKI applications on BlackBerry devices and computers • enable the wireless digital signing and encryption of wireless email messages sent from the BlackBerry device using the S/MIME Support Package for BlackBerry® smartphones • store all encryption keys in RAM only and never write the keys to flash memory Authenticating a user using a smart card The BlackBerry® Smart Card Reader permits you to use two-factor authentication, using a smart card, to require users to prove their identities to the BlackBerry devices or computers by two factors: • what they have (the smart card) • what they know (their smart card password) Integrating a smart card with existing secure messaging technology In addition to standard BlackBerry® encryption, you can extend secure messaging technology to offer an additional layer of security between the sender and the recipient of an email or PIN message. The S/MIME Support Package for BlackBerry® smartphones is designed so that users who send and receive S/MIME messages using their email applications can send and receive S/MIME protected messages using their BlackBerry devices. Users can sign, encrypt, and send S/MIME protected messages from their BlackBerry devices. BlackBerry devices can decrypt S/MIME-encrypted messages that they receive so that users can read the messages on their BlackBerry devices. To pair Bluetooth® enabled BlackBerry devices with the BlackBerry® Smart Card Reader, users must install a smart card driver, the BlackBerry Smart Card Reader driver on their BlackBerry devices, and, optionally, a smart card authenticator module. The S/MIME Support Package for BlackBerry smartphones supports smart card use and includes tools that users can use to download certificates and transfer them to the BlackBerry device for use with the S/MIME Support Package for BlackBerry smartphones. After the BlackBerry device and the BlackBerry Smart Card Reader establish a secure pairing, you can configure the S/MIME Force Smartcard Use IT policy rule to require the use of the smart card to sign, encrypt, or sign and encrypt S/MIME-protected messages on the BlackBerry device. 4

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34

BlackBerry Smart Card Reader
The BlackBerry® Smart Card Reader is an accessory that, when used in proximity to certain Bluetooth® enabled
BlackBerry devices and computers, permits users to authenticate with their smart cards and log in to Bluetooth
enabled BlackBerry devices and computers.
The BlackBerry Smart Card Reader is designed to perform the following actions:
communicate with Bluetooth enabled BlackBerry devices and computers using Bluetooth technology
version 1.1 and later and using the AES-256 encryption method (by default) on the application layer
create a reliable two-factor authentication environment for granting users access to the PKI applications
on BlackBerry devices and computers
enable the wireless digital signing and encryption of wireless email messages sent from the BlackBerry
device using the S/MIME Support Package for BlackBerry® smartphones
store all encryption keys in RAM only and never write the keys to flash memory
Authenticating a user using a smart card
The BlackBerry® Smart Card Reader permits you to use two-factor authentication, using a smart card, to require
users to prove their identities to the BlackBerry devices or computers by two factors:
what they have (the smart card)
what they know (their smart card password)
Integrating a smart card with existing secure messaging technology
In addition to standard BlackBerry® encryption, you can extend secure messaging technology to offer an additional
layer of security between the sender and the recipient of an email or PIN message. The S/MIME Support Package for
BlackBerry® smartphones is designed so that users who send and receive S/MIME messages using their email
applications can send and receive S/MIME protected messages using their BlackBerry devices. Users can sign,
encrypt, and send S/MIME protected messages from their BlackBerry devices. BlackBerry devices can decrypt
S/MIME-encrypted messages that they receive so that users can read the messages on their BlackBerry devices.
To pair Bluetooth® enabled BlackBerry devices with the BlackBerry® Smart Card Reader, users must install a smart
card driver, the BlackBerry Smart Card Reader driver on their BlackBerry devices, and, optionally, a smart card
authenticator module. The S/MIME Support Package for BlackBerry smartphones supports smart card use and
includes tools that users can use to download certificates and transfer them to the BlackBerry device for use with the
S/MIME Support Package for BlackBerry smartphones.
After the BlackBerry device and the BlackBerry Smart Card Reader establish a secure pairing, you can configure the
S/MIME Force Smartcard Use IT policy rule to require the use of the smart card to sign, encrypt, or sign and encrypt
S/MIME-protected messages on the BlackBerry device.
4