Blackberry PRD-10459-035 Administration Guide - Page 14

Configuring security options

Page 14 highlights

Administration Guide Configuring security options Configuring security options 2 How the BlackBerry Enterprise Solution encrypts data on the transport layer The BlackBerry® Enterprise Solution uses a symmetric key encryption algorithm (Triple DES or AES) to protect all data that the BlackBerry® Enterprise Server and a BlackBerry device send between them. The BlackBerry Enterprise Solution uses the symmetric key encryption algorithm to create message keys and master encryption keys, and uses those encryption keys to encrypt all data that the BlackBerry device sends or receives, while the data travels between the BlackBerry device and the BlackBerry Enterprise Server. This data encryption process occurs automatically and is designed to verify that a message that a user sends from a BlackBerry device, which is outside the organization's firewall, remains protected on the transport layer until the BlackBerry Enterprise Server receives the message. Symmetric key encryption algorithms that the BlackBerry Enterprise Solution uses Encryption type AES Description • uses the AES algorithm to encrypt and decrypt all of the data that the BlackBerry Enterprise Server and BlackBerry devices that are associated with the BlackBerry Enterprise Server send between each other • designed to use a longer encryption key to provide a better combination of security and performance than Triple DES • designed to protect user data and encryption keys from traditional attacks and side-channel attacks • requires BlackBerry® Desktop Software version 4.0 or later and BlackBerry® Device Software version 4.0 or later Change the encryption type 1. In the BlackBerry® Manager, in the left pane, click a BlackBerry® Enterprise Server. 2. On the Server Configuration tab, click Edit Properties. 3. Click General. 4. In the Security section, click Encryption Algorithm. 12

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122

Configuring security options
2
How the BlackBerry Enterprise Solution encrypts data on the transport layer
The BlackBerry® Enterprise Solution uses a symmetric key encryption algorithm (Triple DES or AES) to protect all data that the
BlackBerry® Enterprise Server and a BlackBerry device send between them.
The BlackBerry Enterprise Solution uses the symmetric key encryption algorithm to create message keys and master encryption
keys, and uses those encryption keys to encrypt all data that the BlackBerry device sends or receives, while the data travels
between the BlackBerry device and the BlackBerry Enterprise Server.
This data encryption process occurs automatically and is designed to verify that a message that a user sends from a BlackBerry
device, which is outside the organization's firewall, remains protected on the transport layer until the BlackBerry Enterprise Server
receives the message.
Symmetric key encryption algorithms that the BlackBerry Enterprise Solution uses
Encryption type
Description
AES
uses the AES algorithm to encrypt and decrypt all of the data that the
BlackBerry Enterprise Server and BlackBerry devices that are associated with
the BlackBerry Enterprise Server send between each other
designed to use a longer encryption key to provide a better combination of
security and performance than Triple DES
designed to protect user data and encryption keys from traditional attacks and
side-channel attacks
requires BlackBerry® Desktop Software version 4.0 or later and BlackBerry®
Device Software version 4.0 or later
Change the encryption type
1.
In the BlackBerry® Manager, in the left pane, click a BlackBerry® Enterprise Server.
2.
On the
Server Configuration
tab, click
Edit Properties
.
3.
Click
General
.
4.
In the
Security
section, click
Encryption Algorithm
.
Administration Guide
Configuring security options
12