Blackberry ENTERPRISE SOLUTION SECURITY - SECURITY FOR DEVICES WITH BLUETOOTH WIRELESS TECHNOLOGY - TECHNICAL Guide d'installation Page 1

Naviguer en ligne ou télécharger Guide d'installation pour Logiciel Blackberry ENTERPRISE SOLUTION SECURITY - SECURITY FOR DEVICES WITH BLUETOOTH WIRELESS TECHNOLOGY - TECHNICAL. Blackberry ENTERPRISE SOLUTION SECURITY - SECURITY FOR DEVICES WITH BLUETOOTH WIRELESS TECHNOLOGY - TECHNICAL Installation guide Manuel d'utilisatio

  • Télécharger
  • Ajouter à mon manuel
  • Imprimer

Résumé du contenu

Page 1 - Device Software Version 4.5

BlackBerry Enterprise Solution Security Technical Overview for BlackBerry Enterprise Server Version 4.1 Service Pack 5 and BlackBerry Device Softwar

Page 2 - Contents

BlackBerry Enterprise Solution 10 Messaging server platform Messaging server storage location BlackBerry device storage location BlackBerry Enterpr

Page 3

BlackBerry Enterprise Solution 11 Profiles database stores an account record containing the field RIMCurrentEncryptionKeyText, which stores the mast

Page 4

BlackBerry Enterprise Solution 12 5. The BlackBerry Desktop Software uses the first 256 bits if it is generating the master encryption key using AE

Page 5

BlackBerry Enterprise Solution 13 Process for generating message keys on the BlackBerry Enterprise Server The BlackBerry Enterprise Server is design

Page 6 - Wireless security

BlackBerry Enterprise Solution 14 7. The DSA PRNG function generates 128 pseudo-random bits for use with Triple DES and 256 pseudo-random bits for

Page 7

BlackBerry Enterprise Solution 15 3. The locked BlackBerry device uses the ECC public key to encrypt data that it receives. Process for decrypting

Page 8 - New security features

BlackBerry Enterprise Solution 16 verifies that a BlackBerry message remains protected in transit to the BlackBerry Enterprise Server while the mess

Page 9 - BlackBerry encryption keys

BlackBerry Enterprise Solution 17 Standard BlackBerry message encryption Standard BlackBerry encryption is designed to encrypt messages that the Bla

Page 10

BlackBerry Enterprise Solution 18 Permitting third-party applications to encode BlackBerry device data The BlackBerry Enterprise Server and the Blac

Page 11

BlackBerry Enterprise Solution 19 The BlackBerry Enterprise Server is designed to maintain a constant, direct outbound TCP/IP connection to the wire

Page 12 - Message keys

BlackBerry Enterprise Solution Contents Wireless security...

Page 13

BlackBerry Enterprise Solution 20 The system administrator can install the BlackBerry Attachment Service on a remote computer and then place that co

Page 14 - Content protection keys

BlackBerry Enterprise Solution 21 with Triple DES to encrypt PIN messages, every BlackBerry device can decrypt every PIN message that it receives be

Page 15 - Grand master keys

BlackBerry Enterprise Solution 22 Turning off unsecured messaging The BlackBerry Enterprise Server administrator can turn off unsecured messaging to

Page 16

BlackBerry Enterprise Solution 23 The BlackBerry device is designed to use the BlackBerry MDS Connection Service, which resides on the BlackBerry En

Page 17

BlackBerry Enterprise Solution 24 algorithms to encrypt PGP messages. The BlackBerry Enterprise Server administrator can set the PGP Allowed Content

Page 18

BlackBerry Enterprise Solution 25 4. The BlackBerry Enterprise Server removes the standard BlackBerry encryption and sends the S/MIME-encrypted mes

Page 19

BlackBerry Enterprise Solution 26 Decrypting and reading messages on the BlackBerry device using Lotus Notes API 7.0 The BlackBerry® Enterprise Serv

Page 20 - PIN-to-PIN messaging

BlackBerry Enterprise Solution 27 The encrypted Notes .id password remains stored in the BlackBerry Enterprise Server for IBM Lotus Domino messaging

Page 21 - Text messaging

BlackBerry Enterprise Solution 28 Database Message storage method BlackBerry profiles • stores important configuration information for each BlackB

Page 22

BlackBerry Enterprise Solution 29 • external file encryption by encrypting specific files on the external memory device using AES The external file

Page 23 - PGP encryption

BlackBerry Enterprise Solution BlackBerry architecture component security ...

Page 24 - S/MIME encryption

BlackBerry Enterprise Solution 30 Item Description calendar • subject • location • organizer • attendees • notes included in the appointmen

Page 25

BlackBerry Enterprise Solution 31 Protected storage of master encryption keys on a locked BlackBerry device If the BlackBerry Enterprise Server admi

Page 26

BlackBerry Enterprise Solution 32 • periodically runs the memory cleaner application, which tells BlackBerry device applications to empty any cache

Page 27 - Protecting stored data

BlackBerry Enterprise Solution 33 BlackBerry architecture component security The BlackBerry Enterprise Server consists of services that provide func

Page 28

BlackBerry Enterprise Solution 34 BlackBerry Enterprise Server The BlackBerry Enterprise Server is designed to establish a secure, two-way link betw

Page 29

BlackBerry Enterprise Solution 35 Configuration option Recommendations shield your Microsoft SQL Server installation from Internet based attacks •

Page 30

BlackBerry Enterprise Solution 36 Configuration option Recommendations Use a secure file system • Use NTFS for the Microsoft SQL Server because it

Page 31

BlackBerry Enterprise Solution 37 Protecting the BlackBerry Enterprise Solution connections The BlackBerry Enterprise Server is designed to communic

Page 32

BlackBerry Enterprise Solution 38 Step Action Description 3 The BlackBerry Enterprise Server sends a challenge string to the BlackBerry Infrastru

Page 33 - BlackBerry Infrastructure

BlackBerry Enterprise Solution 39 Scenario Result The connection between the BlackBerry Enterprise Server and the BlackBerry Infrastructure termina

Page 34 - Messaging server

BlackBerry Enterprise Solution Controlling BlackBerry device behavior using IT policy rules ...

Page 35

BlackBerry Enterprise Solution 40 For more information about the BlackBerry Router protocol and the authentication process, see “Masking operation p

Page 36

BlackBerry Enterprise Solution 41 Step Action Description 6 The BlackBerry Enterprise Server sends data to the BlackBerry device. If wireless PIM

Page 37 - SRP authentication

BlackBerry Enterprise Solution 42 Security measure Description The BlackBerry device initiates inbound connections using the BlackBerry Router to a

Page 38

BlackBerry Enterprise Solution 43 2. The BlackBerry Desktop Software implementation of the secure channel technology uses the shared secret passwor

Page 39

BlackBerry Enterprise Solution 44 message, the BlackBerry MDS Services security protocol encrypts and decrypts data that the BlackBerry device and t

Page 40

BlackBerry Enterprise Solution 45 HTTPS protocol BlackBerry MDS encryption method Description Handheld mode TLS/SSL TLS and WTLS key establishment

Page 41 - TCP/IP connection

BlackBerry Enterprise Solution 46 Authentication process for requests for wireless software upgrades When the BlackBerry Infrastructure sends a wire

Page 42

BlackBerry Enterprise Solution 47 segmented network architecture, the system administrator can place the BlackBerry Enterprise Solution components i

Page 43 - BlackBerry MDS connections

BlackBerry Enterprise Solution 48 Accessing the BlackBerry Infrastructure Wi-Fi enabled BlackBerry devices can connect directly to the BlackBerry In

Page 44

BlackBerry Enterprise Solution 49 Enterprise Wi-Fi network security technology Wi-Fi enabled BlackBerry device implementation Layer 2 security Set

Page 45

BlackBerry Enterprise Solution Encryption algorithms that the BlackBerry device supports for use with layer 2 security methods ...83 EAP authenticatio

Page 46 - WAP gateway connections

BlackBerry Enterprise Solution 50 After an authentication server permits the supported Wi-Fi enabled BlackBerry device to access the enterprise Wi-F

Page 47

BlackBerry Enterprise Solution 51 Authentication method Description Wi-Fi enabled BlackBerry device implementation Using IEEE 802.11i with PSK Sm

Page 48

BlackBerry Enterprise Solution 52 the authentication server certificate. For the supported Wi-Fi enabled BlackBerry devices to trust the authenticat

Page 49

BlackBerry Enterprise Solution 53 users must authenticate with the WLAN Login application browser using login credentials that the system administra

Page 50

BlackBerry Enterprise Solution 54 For more information, see the BlackBerry Smart Card Reader Security Technical Overview. Binding the smart card to

Page 51

BlackBerry Enterprise Solution 55 Field Description Initialized indicates whether the BlackBerry device is authenticated with and bound to the sma

Page 52 - Fi hotspots

BlackBerry Enterprise Solution 56 Creating new IT policy rules to control custom applications Create new IT policy rules to control custom applicati

Page 53

BlackBerry Enterprise Solution 57 The BlackBerry Enterprise Server administrator can define the following types of criteria: • specific, permitted

Page 54

BlackBerry Enterprise Solution 58 connection. BlackBerry devices and the BlackBerry Desktop Software can use CHAP to send a challenge and subsequent

Page 55

BlackBerry Enterprise Solution 59 How the BlackBerry device protects its operating system and the BlackBerry Device Software Each time a user turns

Page 56

BlackBerry Enterprise Solution 6 This document describes the security features of the BlackBerry® Enterprise Solution and provides an overview of th

Page 57

BlackBerry Enterprise Solution 60 • specify whether or not applications, including third-party applications, on the BlackBerry device can initiate

Page 58

BlackBerry Enterprise Solution 61 Each third-party application requires authorization to run on the BlackBerry device. MIDlets (applications that us

Page 59 - Software

BlackBerry Enterprise Solution 62 Remotely resetting the password of a content protected BlackBerry device The remote password reset cryptographic p

Page 60

BlackBerry Enterprise Solution 63 IT policy rule Description Secure Wipe if Low Battery Set this IT policy rule to require that, if the BlackBerry

Page 61 - • the signature is invalid

BlackBerry Enterprise Solution 64 do not exist on the BlackBerry device (in other words, if there is no connection between the BlackBerry Enterprise

Page 62

BlackBerry Enterprise Solution 65 Related resources Resource Information BlackBerry Enterprise Server Feature and Technical Overview • BlackBerry

Page 63

BlackBerry Enterprise Solution 66 Resource Information Garbage Collection in the BlackBerry Java Development Environment • cleaning BlackBerry dev

Page 64

BlackBerry Enterprise Solution 67 Resource Information Visit www.blackberry.com/security. • information about BlackBerry Solution security www.bla

Page 65 - Related resources

BlackBerry Enterprise Solution 68 Appendix A: RIM Crypto API Interface The RIM Crypto API on the BlackBerry device and in the BlackBerry JDE provid

Page 66

BlackBerry Enterprise Solution 69 Key agreement scheme algorithms Algorithm Key length (bits) Type DH 512 to 4096 discrete logarithm KEA 1024 di

Page 67 - Resource Information

BlackBerry Enterprise Solution 7 Concept Description BlackBerry Enterprise Solution implementation authenticity enables the message recipient to

Page 68 - • a key generation protocol

BlackBerry Enterprise Solution 70 Code Digest length (bits) RIPEMD-128, 160 128, 160 www.blackberry.com

Page 69

BlackBerry Enterprise Solution 71 Appendix B: TLS and WTLS standards that the RIM Crypto API supports The TLS and WTLS protocol cipher suite compone

Page 70 - RIPEMD-128, 160 128, 160

BlackBerry Enterprise Solution 72 Symmetric algorithms that the RIM Crypto API supports Direct mode SSL Direct mode TLS WTLS RC4 40 RC4 40 RC5 4

Page 71

BlackBerry Enterprise Solution 73 Appendix C: Previous version of wired master encryption key generation Each time a BlackBerry Enterprise Server or

Page 72

BlackBerry Enterprise Solution 74 Appendix D: BlackBerry device wipe process A BlackBerry device wipe is designed to delete and overwrite the BlackB

Page 73

BlackBerry Enterprise Solution 75 4. Clears all bytes to 0xFF (1111 11112). 5. Writes 0x55 to each byte (0x0101 01012). 6. Clears all bytes to 0x

Page 74

BlackBerry Enterprise Solution 76 Appendix E: Ephemeral AES encryption key derivation process The BlackBerry device uses an ephemeral 256-bit AES en

Page 75

BlackBerry Enterprise Solution 77 Appendix F: Power and electromagnetic side-channel attacks and countermeasures The BlackBerry device implementatio

Page 76

BlackBerry Enterprise Solution 78 How the AES algorithm creates S-Box tables The BlackBerry device permutes each AES S-Box entry randomly and masks

Page 77

BlackBerry Enterprise Solution 79 Appendix G: BlackBerry Router protocol When the BlackBerry Enterprise Server and the BlackBerry device use the Bla

Page 78

BlackBerry Enterprise Solution 8 Feature Description control BlackBerry device and BlackBerry Desktop Software functionality • Send wireless comma

Page 79

BlackBerry Enterprise Solution 80 device. The attacker must send master encryption key value (s) to the BlackBerry Enterprise Server, which requires

Page 80

BlackBerry Enterprise Solution 81 If the BlackBerry device accepts yB, the BlackBerry Enterprise Server and the BlackBerry device open an authentica

Page 81

BlackBerry Enterprise Solution 82 Appendix H: Enterprise Wi-Fi security methods that the BlackBerry device supports EAP authentication methods that

Page 82

BlackBerry Enterprise Solution 83 Authentication method Description BlackBerry device implementation EAP-TTLS EAP-TTLS is designed to extend EAP-

Page 83

BlackBerry Enterprise Solution 84 Protocol Description Wi-Fi enabled BlackBerry device implementation TKIP TKIP is • part of the IEEE 802.11i ent

Page 84 - • WEP and TKIP

BlackBerry Enterprise Solution 85 VPN solution on the Wi-Fi enabled BlackBerry device The Wi-Fi enabled BlackBerry device has a built-in VPN client

Page 85

BlackBerry Enterprise Solution 86 • RSA_WITH_RC4_128_MD5 • RSA_WITH_3DES_EDE_CBC_SHA • RSA_WITH_AES_128_CBC_SHA • RSA_WITH_AES_256_CBC_SHA • TL

Page 86 - • RSA_WITH_AES_256_CBC_SHA

BlackBerry Enterprise Solution 87 Appendix J: RSA SecurID software token tokencode generation process 1. An administrator uses the RSA Authenticati

Page 87

BlackBerry Enterprise Solution 88 3. The BlackBerry device receives B and verifies that B is a valid public key. 4. The BlackBerry device performs

Page 88 - BlackBerry device remotely

BlackBerry Enterprise Solution 89 Protocol process When the BlackBerry Enterprise Server administrator sends the Set a Password and Lock Handheld IT

Page 89 - Protocol process

BlackBerry Enterprise Solution 9 Feature Software versions supported Description The BlackBerry Enterprise Solution allows administrators to apply

Page 90

BlackBerry Enterprise Solution 90 Part number: 17930884 Version 2 ©2008 Research In Motion Limited. All rights reserved. BlackBerry®, RIM®, Research

Page 91

BlackBerry Enterprise Solution 91 Prior to subscribing for, installing, or using any Third Party Products and Services, it is your responsibility to

Commentaires sur ces manuels

Pas de commentaire