Blackberry ENTERPRISE SOLUTION SECURITY - ENFORCING ENCRYPTION OF INTERNAL AND EXTERNAL FILE SYSTEMS ON DEVICES Betriebsanweisung Seite 1

Stöbern Sie online oder laden Sie Betriebsanweisung nach Software Blackberry ENTERPRISE SOLUTION SECURITY - ENFORCING ENCRYPTION OF INTERNAL AND EXTERNAL FILE SYSTEMS ON DEVICES herunter. Blackberry ENTERPRISE SOLUTION SECURITY - ENFORCING ENCRYPTION OF INTERNAL AND EXTERNAL FILE SYSTEMS ON DEVICES User guide Benutzerhandbuch

  • Herunterladen
  • Zu meinen Handbüchern hinzufügen
  • Drucken

Inhaltsverzeichnis

Seite 1 - Security Technical Overview

BlackBerry Enterprise SolutionVersion: 5.0 | Service Pack: 1Security Technical Overview

Seite 3 - Contents

Process flow: Turning on two-factor authentication using a smart cardWhen you or a user turns on two-factor authentication with the BlackBerry® Smart

Seite 4

Two-factor content protectionContent protection is designed to encrypt data on a BlackBerry® device when the BlackBerry device is locked. When you con

Seite 5

Protecting Bluetooth connections on a BlackBerry deviceBluetooth® wireless technology permits a Bluetooth enabled BlackBerry® device to open a wireles

Seite 6

Wi-Fi enabled BlackBerry devices16Wi-Fi® enabled BlackBerry® devices permit users with qualifying data plans to access BlackBerry services over a mobi

Seite 7

Type Descriptionhome Wi-Fi networks A home Wi-Fi network uses a single access point to provide Internet access througha broadband gateway. The broadba

Seite 8

Feature DescriptionBlackBerry transport layer encryption BlackBerry transport layer encryption is designed to encrypt messages that theBlackBerry devi

Seite 9

Feature Descriptionwireless software updates Wireless software updates permits users to update the BlackBerry® Device Softwarewithout using the BlackB

Seite 10

How an SSL connection between a Wi-Fi enabled BlackBerry device and the BlackBerryInfrastructure protects dataAn SSL connection between a Wi-Fi® enabl

Seite 11 - Overview

• SSL_DH_anon_WITH_3DES_EDE_CBC_SHA• SSL_RSA_EXPORT_WITH_RC4_40_MD5• SSL_DH_RSA_EXPORT_WITH_DES40_CBC_SHA• SSL_DHE_DSS_EXPORT_WITH_DES40_CBC_SHA• SSL_

Seite 12

Managing how a BlackBerry device connects to an enterprise Wi-Fi networkTo manage how a Wi-Fi® enabled BlackBerry® device connects to an enterprise Wi

Seite 13

Overview1BlackBerry Enterprise Solution securityThe BlackBerry® Enterprise Solution consists of various products and components that are designed to e

Seite 14

After you configure a VPN, the BlackBerry device can use a layer 2 security method to connect to the enterprise Wi-Fi network,and use the VPN to provi

Seite 15

Using a captive portal to connect to an enterprise Wi-Fi network or Wi-FihotspotA captive portal uses web-based authentication to permit a Wi-Fi® enab

Seite 16

• permit the user to specify the software token PIN• configure the RSA SecurID to automatically generate and send a software token PIN to a Wi-Fi® ena

Seite 17

Layer 2 security methods that a Wi-Fi enabled BlackBerrydevice supports17You can configure a Wi-Fi® enabled BlackBerry® device to use security methods

Seite 18 - New in this release

PSK protocolThe IEEE® 802.1X™ standard specifies the PSK protocol as an access control method for enterprise Wi-Fi® networks. You canalso use the PSK

Seite 19 - Keys on a BlackBerry device

Process flow: Authenticating a Wi-Fi enabled BlackBerry device with an enterprise Wi-Finetwork using the IEEE 802.1X standardIf you configured a wirel

Seite 20

PEAP authenticationPEAP authentication permits a Wi-Fi® enabled BlackBerry® device to authenticate with an authentication server and access anenterpri

Seite 21 - Device transport keys

EAP-FAST authenticationEAP-FAST authentication uses PAC to open a TLS connection to a Wi-Fi® enabled BlackBerry® device and verify the supplicantcrede

Seite 22

• EAP-TTLS authentication• PEAP authentication• PSK authenticationFor more information about AES-CCMP and TKIP, visit www.ieee.org/portal/site.EAP aut

Seite 23

Protecting a third-party application on a BlackBerry device18Creating a third-party application for a BlackBerry deviceA developer can create a third-

Seite 24 - 4.0 or later

Security features of the BlackBerry Enterprise SolutionFeature Descriptiondata protection The BlackBerry® Enterprise Solution is designed to protect d

Seite 25

• User Authenticator API, which permits the registration of drivers so that a user can unlock the BlackBerry device using two-factor authenticationYou

Seite 26 - Message keys

Permitting a third-party application to encode data on a BlackBerry deviceA developer can use the Transcoder API to create an encoding scheme for data

Seite 27 - Content protection keys

RIM Cryptographic API19The RIM® Cryptographic API that is on a BlackBerry® device and in the BlackBerry® Java® Development Environment consistsof a Ja

Seite 28

The RIM Cryptographic API supports the ECIES algorithm, with an unlimited key length (160 bits to 571 bits for seeding), as theasymmetric stream encry

Seite 29 - Principal encryption keys

Key generation algorithms that the RIM Cryptographic API supportsAlgorithm Key length (bits) TypeDiffie-Hellman 512 to 4096 discrete logarithmDSA 512

Seite 30 - PIN encryption keys

Cipher suites for the key establishment algorithm that the RIM Cryptographic API supportsDirect mode SSL Direct mode TLS WTLSDH_anon DH_anon RSA® _768

Seite 31

Limitations of RIM Cryptographic API support for cipher suites for the keyestablishment algorithmThe RIM® Cryptographic API implementation of the TLS

Seite 32

Related resources20Resource InformationBlackBerry Enterprise Server Featureand Technical Overview• understanding BlackBerry® Enterprise Server archite

Seite 33

Resource InformationEnforcing Encryption of Internal andExternal File Systems on BlackBerryDevices Technical Overview• understanding which data items

Seite 34

Glossary213GPPThird Generation Partnership ProjectAESAdvanced Encryption StandardAES-CCMPAdvanced Encryption Standard Counter Mode CBCMAC ProtocolANSI

Seite 35

Architecture: BlackBerry Enterprise SolutionThe BlackBerry® Enterprise Solution consists of various components that permit you to extend your organiza

Seite 36

BlackBerry inter-process protocol encryption encrypts communication between BlackBerry® Enterprise Solution componentsto prevent other parties from vi

Seite 37

code-signing keysCode-signing keys are the keys that are stored on media cards that sign files so that a user can install and run the files ona BlackB

Seite 38

EAPExtensible Authentication ProtocolEAPoLExtensible Authentication Protocol over LANEAP-FASTExtensible Authentication Protocol Flexible Authenticatio

Seite 39 - BlackBerry device

ECMQVElliptic Curve Menezes-Qu-VanstoneECNRElliptic Curve Nyberg RueppelEDEEncryption-Decryption-EncryptionEDGEEnhanced Data Rates for Global Evolutio

Seite 40

General Services AdministrationGSMGlobal System for Mobile communications®HMACkeyed-hash message authentication codeHTTPHypertext Transfer ProtocolHTT

Seite 41 - BlackBerry device memory

IT policy ruleAn IT policy rule permits you to customize and control the actions that BlackBerry devices, BlackBerry enabled devices, theBlackBerry® D

Seite 42

MIDPMobile Information Device ProfileMMSMultimedia Messaging ServiceMS-CHAPMicrosoft Challenge Handshake Authentication ProtocolNATnetwork address tra

Seite 43

PFSPerfect Forward Secrecypersistent store in flash memoryThe persistent store in flash memory stores data for a BlackBerry device. By default, third-

Seite 44

RFCRequest for CommentsRIM signing authority systemThe RIM® signing authority system is a collection of servers that sign the boot ROM code for a Blac

Seite 45

SRP authenticationSRP authentication is an authentication method that the BlackBerry® Enterprise Server and BlackBerry® Infrastructure useto authentic

Seite 46

Component DescriptionBlackBerry Administration Service The BlackBerry Administration Service is a BlackBerry® Enterprise Servercomponent that connects

Seite 47

WLANwireless local area networkWPAWi-Fi Protected AccessWTLSWireless Transport Layer SecuritySecurity Technical OverviewGlossary138

Seite 48

Provide feedback22To provide feedback on this deliverable, visit www.blackberry.com/docsfeedback.Security Technical OverviewProvide feedback139

Seite 49

Legal notice23©2009 Research In Motion Limited. All rights reserved. BlackBerry®, RIM®, Research In Motion®, SureType®, SurePress™ andrelated trademar

Seite 50

HEREBY EXCLUDED. YOU MAY ALSO HAVE OTHER RIGHTS THAT VARY BY STATE OR PROVINCE. SOME JURISDICTIONSMAY NOT ALLOW THE EXCLUSION OR LIMITATION OF IMPLIED

Seite 51

thereto. Your use of Third Party Products and Services shall be governed by and subject to you agreeing to the terms of separatelicenses and other agr

Seite 52

Component DescriptionBlackBerry Device Software The BlackBerry Device Software consists of applications on a BlackBerry device thatpermit the user to

Seite 53

Component DescriptionBlackBerry® MDS Studio The BlackBerry MDS Studio can be used by your organization's developers to createBlackBerry MDS Runti

Seite 54 - Device Software

Component DescriptionBlackBerry® Smart Card Reader The BlackBerry Smart Card Reader controls access to your organization's sensitivecommunication

Seite 55

New in this release2This document describes the security features that the BlackBerry® Enterprise Server version 5.0 SP1, BlackBerry® DesktopSoftware

Seite 56

Keys on a BlackBerry device3The BlackBerry® Enterprise Solution generates keys that are designed to protect the data that is stored on a BlackBerry de

Seite 57

SWD-847262-1028044248-001

Seite 58

Key DescriptionECC public key The ECC public key encrypts the stored data that the BlackBerry device receiveswhen the BlackBerry device is locked.ephe

Seite 59

State Descriptionpending A pending device transport key is the device transport key that the BlackBerryEnterprise Solution generates to replace the cu

Seite 60

A BlackBerry device stores the device transport keys in a key store database in flash memory. The key store database is designedto prevent a potential

Seite 61

If a user activates the BlackBerry device over the wireless network, the BlackBerry® Enterprise Server and BlackBerry devicenegotiate to select the st

Seite 62

For more information about the ECMQV key exchange algorithm, see NIST: Special Publication 800-56: Recommendation onKey Establishment schemes, Draft 2

Seite 63

To generate the device transport key, the BlackBerry Desktop Software performs the following actions:1. prompts the user to move the cursor2. uses the

Seite 64

c. uses the SHA-1 function to hash the 256 bitsd. generates the device transport key of the BlackBerry device using the first 128 bits of the hashMess

Seite 65

8. uses the pseudo-random bits with AES encryption or Triple DES encryption to generate the message keyFor more information about the DSA PRNG functio

Seite 66 - Integration Service

Process flow: Turning on content protection using a BlackBerry Enterprise ServerYou can turn on content protection using a BlackBerry® Enterprise Serv

Seite 67

The content protection key is a semi-permanent key that uses AES-256 encryption. If the user changes the BlackBerry devicepassword, the BlackBerry dev

Seite 68

Contents1 Overview...

Seite 69

Process flow: Generating a principal encryption keyWhen you or a user turns on content protection for device transport keys on a BlackBerry® device fo

Seite 70

Encrypting data that the BlackBerry Enterprise Server anda BlackBerry device send to each other4To encrypt data that is in transit between the BlackBe

Seite 71

A traditional attack tries to exploit data that a cryptographic system stores or transmits. The potentially malicious user tries todetermine the key o

Seite 72

The BlackBerry device masks the round keys with random values and any S-Box masks that the AES algorithm requires to work.Round keys are subkeys that

Seite 73

b. decrypts the email message using the message keyc. decompresses the email messaged. displays the email message to the userProcess flow: Sending an

Seite 74

Managing BlackBerry Enterprise Solution security5Using an IT policy to manage BlackBerry Enterprise Solution securityYou can use an IT policy to contr

Seite 75

Sending an IT policy over the wireless networkIf your organization's environment includes C++ based BlackBerry® devices that are running BlackBer

Seite 76

IT administration command Description• require the BlackBerry device to return to its factory default settings when itreceives this command• specify w

Seite 77

e. uses K to decrypt the content protection keyf. permanently deletes K5. The BlackBerry device performs the following actions:a. selects d randomlyb.

Seite 78

Using a segmented network architecture to prevent the spread of malwareTo help prevent the spread of malware in your organization’s network, you can u

Seite 79

Using IT policy rules to manage BlackBerry Enterprise Solution security... 33Sendi

Seite 80

Best practice DescriptionControl which application on theBlackBerry device can use the GPSfeature.Consider preventing a third-party application or pre

Seite 81

BlackBerry device memory6The BlackBerry® device memory consists of various sections that store user data and sensitive information such as keys. Third

Seite 82

To change when the memory cleaner application runs, you can use IT policies or the BlackBerry device user can turn on or turnoff the memory cleaner ap

Seite 83

Deleting all device data from the BlackBerry device memoryA BlackBerry® device is designed to permanently delete the following data from the NV store,

Seite 84

• You click the Remove user data from current device option in the BlackBerry Administration Service after you connect theBlackBerry device to the Bla

Seite 85

Process flow: Deleting all device data from a BlackBerry deviceThe following actions occur when you or a user delete all device data.1. The BlackBerry

Seite 86

Scrubbing the BlackBerry device heap in RAM when deleting all BlackBerry device dataTo overwrite the BlackBerry® device heap that is in RAM for a Blac

Seite 87

Scrubbing the user files on a BlackBerry device when deleting all BlackBerry device dataIf a BlackBerry® device supports a partition of flash memory t

Seite 88

Protecting data on a BlackBerry device7Encrypting user data on a locked BlackBerry deviceIf you or a BlackBerry® device user turns on content protecti

Seite 89

The BlackBerry device uses the BlackBerry device password to generate an ephemeral key that the BlackBerry device uses toencrypt the content protectio

Seite 90

Process flow: Generating an encryption key for a media card... 5

Seite 91 - S/MIME encryption algorithms

Encrypting the device transport key on a locked BlackBerry deviceIf you turn on content protection for device transport keys, a BlackBerry® device use

Seite 92

Resetting a BlackBerry device password when content protection is turnedonIf you or a user turns on content protection for a BlackBerry® device that i

Seite 93

Uppercase parameters represent elliptic curve points. Lowercase parameters represent scalars. The elliptic curve group operationsare additive.Paramete

Seite 94

• generate random passwords that are designed to improve password strength• copy passwords and paste them into an application or password prompt for a

Seite 95

How the BlackBerry Attachment Service protects data on a BlackBerry deviceA BlackBerry® device uses the BlackBerry Attachment Service to process an at

Seite 96

code for a BlackBerry device during the manufacturing process, uses an RSA® public key to sign the boot ROM code. The processoris configured during th

Seite 97

Protecting the data that the BlackBerry Enterprise Solutionstores in your organization's environment8Where the BlackBerry Enterprise Server store

Seite 98 - Bluetooth connections

• name of each BlackBerry® Enterprise Server• unique SRP authentication keys and unique SRP IDs, or UIDs, that each BlackBerry Enterprise Server uses

Seite 99

Best practice DescriptionMicrosoft SQL Server permits the sa account and, in some cases, other user accountsto access operating system calls based on

Seite 100 - Two-factor authentication

Best practice Description• Use Microsoft SQL Server Management Studio to change the account that isassociated with a Microsoft SQL Server service, if

Seite 101 - Two-factor content protection

What happens to data that is not delivered because a BlackBerry device is not available on the wireless network...

Seite 102

Protecting communication with a BlackBerry device9Opening a direct connection between a BlackBerry device and a BlackBerryRouterA BlackBerry® Router a

Seite 103 - Types of Wi-Fi networks

Closing a direct connection between a BlackBerry device and BlackBerry RouterIf a user disconnects a BlackBerry® device from a computer that hosts the

Seite 104

Because the BlackBerry Router protocol can proceed past the point that it detects corrupted data, the BlackBerry Router protocolis unsuccessful at com

Seite 105

b. sends RD and a device transport key identifier (KeyID) to the BlackBerry Enterprise Server3. The BlackBerry Router performs the following actions:a

Seite 106 - Infrastructure

d. sends yB to the BlackBerry device9. One of the following actions occurs:• The BlackBerry Enterprise Server and BlackBerry device open an authentica

Seite 107

Best practice: Protecting unsecured wireless messaging on the BlackBerrydeviceUnsecured wireless messaging includes SMS text messages, MMS messages, a

Seite 108

Best practice DescriptionRequire a user to verify whether the userwants to send a message.Consider configuring the BlackBerry device so that the user

Seite 109

The BlackBerry MDS security protocol uses a session key to authenticate data that the BlackBerry device sends to the BlackBerryMDS Integration Service

Seite 110

The BlackBerry MDS security protocol uses AES-128 in CBC mode with PKCS #5 padding to encrypt and decrypt data that aBlackBerry device and BlackBerry

Seite 111

What happens to data that is not delivered to a BlackBerry deviceWhat happens to data that is not delivered because the connection between a BlackBerr

Seite 112

Updating the BlackBerry Device Software from an update web site...

Seite 113 - WEP encryption

Protecting BlackBerry Enterprise Solutioncommunications in your organization's environment10How a BlackBerry Enterprise Server and the BlackBerry

Seite 114 - IEEE 802.1X standard

How the BlackBerry Enterprise Solution protects a TCP/IP connection between a BlackBerryEnterprise Server and the BlackBerry InfrastructureAfter a Bla

Seite 115 - LEAP authentication

If the BlackBerry Infrastructure rejects the challenge response, the authentication process is not successful. The BlackBerryInfrastructure and BlackB

Seite 116 - EAP-TTLS authentication

Messaging server DescriptionThe BlackBerry Enterprise Server connects to a user’s mailbox in a highly securemanner using the trusted application key.

Seite 117 - EAP-SIM authentication

Process flow: Authenticating the application loader tool or Roxio Media Manager with theBlackBerry Desktop Software using the BlackBerry inter-process

Seite 118 - CCKM with

Activating a BlackBerry device11When a user activates a BlackBerry® device, the BlackBerry® Enterprise Solution authenticates the user and associates

Seite 119

4. The BlackBerry Enterprise Server and BlackBerry device use the initial key establishment protocol to generate a devicetransport key and verify it.

Seite 120

Enrolling certificates on a BlackBerry device over thewireless network12You can configure the BlackBerry® Enterprise Server to permit a BlackBerry dev

Seite 121

9. The BlackBerry Enterprise Server sends the certificate chain to the BlackBerry device.10. The BlackBerry MDS Connection Service sends a status upda

Seite 122 - RIM Cryptographic API

9. The BlackBerry Enterprise Server sends the certificate chain to the BlackBerry device.10. The BlackBerry MDS Connection Service sends a status upda

Seite 123

Creating two-factor authentication methods...

Seite 124

8. The BlackBerry Enterprise Server sends the certificate chain to the BlackBerry device.9. The BlackBerry MDS Connection Service sends a status updat

Seite 125

Protecting BlackBerry Device Software updates13Protecting BlackBerry Device Software updates over the wireless networkYou can update the BlackBerry® D

Seite 126

• requires the user to type the BlackBerry device password before the BlackBerry Device Software update process can backup or restore user data• requi

Seite 127 - Related resources

During the update process, a BlackBerry device activates itself automatically over the wireless network so that the user can usea computer that is out

Seite 128

Process flow: Generating a BlackBerry services key that protects cryptographic services dataThe BlackBerry® device uses an ephemeral AES-256 encryptio

Seite 129 - Glossary

Process flow: Restoring cryptographic services data using the BlackBerry Desktop Manageror BlackBerry Application Web Loader1. After the update proces

Seite 130

Extending messaging security to a BlackBerry device14If your organization's messaging environment supports highly secure messaging technology suc

Seite 131

Key DescriptionPGP public key The PGP Support Package for BlackBerry smartphones uses the PGP public key ofthe recipient to encrypt outgoing email mes

Seite 132

The PGP public key of the recipient indicates which encryption algorithm the recipient’s email application supports, and theBlackBerry device is desig

Seite 133

Process flow: Receiving a PGP encrypted messageIf a recipient installs the PGP® Support Package for BlackBerry® smartphones on a BlackBerry device, th

Seite 134

EAP authentication methods that a Wi-Fi enabled BlackBerry device supports... 113LEA

Seite 135

The BlackBerry device user uses the S/MIME private key to decrypt S/MIME-protected messages on the BlackBerry device andto sign, encrypt, and send S/M

Seite 136

Item DescriptionS/MIME private key When a user sends a signed email message or signed PIN message from a BlackBerrydevice, the BlackBerry device hashe

Seite 137

Process flow: Sending an email message using S/MIME encryptionIf a sender installs the S/MIME Support Package for BlackBerry® smartphones on a BlackBe

Seite 138

Process flow: Receiving an S/MIME-encrypted email messageIf a recipient installs the S/MIME Support Package for BlackBerry® smartphones, the BlackBerr

Seite 139

In BlackBerry Enterprise Server version 5.0 or later and BlackBerry® Device Software version 5.0 or later, a BlackBerry deviceuser can encrypt message

Seite 140

The BlackBerry Messaging Agent deletes the Lotus Notes .id file and the plain-text password when the BlackBerry® EnterpriseServer cannot decrypt a mes

Seite 141 - Provide feedback

Process flow: Receiving an IBM Lotus Notes encrypted message1. A user uses the IBM® Lotus Notes® application on the user’s computer to encrypt a messa

Seite 142 - Legal notice

Process flow: Viewing an attachment in a PGP encrypted message or S/MIME-encryptedmessageThe S/MIME Allowed Encrypted Attachment Mode IT policy rule o

Seite 143

Configuring two-factor authentication and protectingBluetooth connections15BlackBerry Smart Card ReaderThe BlackBerry® Smart Card Reader is an accesso

Seite 144

To control how a BlackBerry device can use an Advanced Security SD card, you can use the Force Smart Card Two-FactorAuthentication IT policy rule, For

Kommentare zu diesen Handbüchern

Keine Kommentare