Blackberry ENTERPRISE SOLUTION SECURITY - SECURITY FOR DEVICES WITH BLUETOOTH WIRELESS TECHNOLOGY - TECHNICAL Installationsanleitung

Stöbern Sie online oder laden Sie Installationsanleitung nach Software Blackberry ENTERPRISE SOLUTION SECURITY - SECURITY FOR DEVICES WITH BLUETOOTH WIRELESS TECHNOLOGY - TECHNICAL herunter. Blackberry ENTERPRISE SOLUTION SECURITY - SECURITY FOR DEVICES WITH BLUETOOTH WIRELESS TECHNOLOGY - TECHNICAL Installation guide Benutzerhandbuch

  • Herunterladen
  • Zu meinen Handbüchern hinzufügen
  • Drucken

Inhaltsverzeichnis

Seite 1 - Device Software Version 4.5

BlackBerry Enterprise Solution Security Technical Overview for BlackBerry Enterprise Server Version 4.1 Service Pack 5 and BlackBerry Device Softwar

Seite 2 - Contents

BlackBerry Enterprise Solution 10 Messaging server platform Messaging server storage location BlackBerry device storage location BlackBerry Enterpr

Seite 3

BlackBerry Enterprise Solution 11 Profiles database stores an account record containing the field RIMCurrentEncryptionKeyText, which stores the mast

Seite 4

BlackBerry Enterprise Solution 12 5. The BlackBerry Desktop Software uses the first 256 bits if it is generating the master encryption key using AE

Seite 5

BlackBerry Enterprise Solution 13 Process for generating message keys on the BlackBerry Enterprise Server The BlackBerry Enterprise Server is design

Seite 6 - Wireless security

BlackBerry Enterprise Solution 14 7. The DSA PRNG function generates 128 pseudo-random bits for use with Triple DES and 256 pseudo-random bits for

Seite 7

BlackBerry Enterprise Solution 15 3. The locked BlackBerry device uses the ECC public key to encrypt data that it receives. Process for decrypting

Seite 8 - New security features

BlackBerry Enterprise Solution 16 verifies that a BlackBerry message remains protected in transit to the BlackBerry Enterprise Server while the mess

Seite 9 - BlackBerry encryption keys

BlackBerry Enterprise Solution 17 Standard BlackBerry message encryption Standard BlackBerry encryption is designed to encrypt messages that the Bla

Seite 10

BlackBerry Enterprise Solution 18 Permitting third-party applications to encode BlackBerry device data The BlackBerry Enterprise Server and the Blac

Seite 11

BlackBerry Enterprise Solution 19 The BlackBerry Enterprise Server is designed to maintain a constant, direct outbound TCP/IP connection to the wire

Seite 12 - Message keys

BlackBerry Enterprise Solution Contents Wireless security...

Seite 13

BlackBerry Enterprise Solution 20 The system administrator can install the BlackBerry Attachment Service on a remote computer and then place that co

Seite 14 - Content protection keys

BlackBerry Enterprise Solution 21 with Triple DES to encrypt PIN messages, every BlackBerry device can decrypt every PIN message that it receives be

Seite 15 - Grand master keys

BlackBerry Enterprise Solution 22 Turning off unsecured messaging The BlackBerry Enterprise Server administrator can turn off unsecured messaging to

Seite 16

BlackBerry Enterprise Solution 23 The BlackBerry device is designed to use the BlackBerry MDS Connection Service, which resides on the BlackBerry En

Seite 17

BlackBerry Enterprise Solution 24 algorithms to encrypt PGP messages. The BlackBerry Enterprise Server administrator can set the PGP Allowed Content

Seite 18

BlackBerry Enterprise Solution 25 4. The BlackBerry Enterprise Server removes the standard BlackBerry encryption and sends the S/MIME-encrypted mes

Seite 19

BlackBerry Enterprise Solution 26 Decrypting and reading messages on the BlackBerry device using Lotus Notes API 7.0 The BlackBerry® Enterprise Serv

Seite 20 - PIN-to-PIN messaging

BlackBerry Enterprise Solution 27 The encrypted Notes .id password remains stored in the BlackBerry Enterprise Server for IBM Lotus Domino messaging

Seite 21 - Text messaging

BlackBerry Enterprise Solution 28 Database Message storage method BlackBerry profiles • stores important configuration information for each BlackB

Seite 22

BlackBerry Enterprise Solution 29 • external file encryption by encrypting specific files on the external memory device using AES The external file

Seite 23 - PGP encryption

BlackBerry Enterprise Solution BlackBerry architecture component security ...

Seite 24 - S/MIME encryption

BlackBerry Enterprise Solution 30 Item Description calendar • subject • location • organizer • attendees • notes included in the appointmen

Seite 25

BlackBerry Enterprise Solution 31 Protected storage of master encryption keys on a locked BlackBerry device If the BlackBerry Enterprise Server admi

Seite 26

BlackBerry Enterprise Solution 32 • periodically runs the memory cleaner application, which tells BlackBerry device applications to empty any cache

Seite 27 - Protecting stored data

BlackBerry Enterprise Solution 33 BlackBerry architecture component security The BlackBerry Enterprise Server consists of services that provide func

Seite 28

BlackBerry Enterprise Solution 34 BlackBerry Enterprise Server The BlackBerry Enterprise Server is designed to establish a secure, two-way link betw

Seite 29

BlackBerry Enterprise Solution 35 Configuration option Recommendations shield your Microsoft SQL Server installation from Internet based attacks •

Seite 30

BlackBerry Enterprise Solution 36 Configuration option Recommendations Use a secure file system • Use NTFS for the Microsoft SQL Server because it

Seite 31

BlackBerry Enterprise Solution 37 Protecting the BlackBerry Enterprise Solution connections The BlackBerry Enterprise Server is designed to communic

Seite 32

BlackBerry Enterprise Solution 38 Step Action Description 3 The BlackBerry Enterprise Server sends a challenge string to the BlackBerry Infrastru

Seite 33 - BlackBerry Infrastructure

BlackBerry Enterprise Solution 39 Scenario Result The connection between the BlackBerry Enterprise Server and the BlackBerry Infrastructure termina

Seite 34 - Messaging server

BlackBerry Enterprise Solution Controlling BlackBerry device behavior using IT policy rules ...

Seite 35

BlackBerry Enterprise Solution 40 For more information about the BlackBerry Router protocol and the authentication process, see “Masking operation p

Seite 36

BlackBerry Enterprise Solution 41 Step Action Description 6 The BlackBerry Enterprise Server sends data to the BlackBerry device. If wireless PIM

Seite 37 - SRP authentication

BlackBerry Enterprise Solution 42 Security measure Description The BlackBerry device initiates inbound connections using the BlackBerry Router to a

Seite 38

BlackBerry Enterprise Solution 43 2. The BlackBerry Desktop Software implementation of the secure channel technology uses the shared secret passwor

Seite 39

BlackBerry Enterprise Solution 44 message, the BlackBerry MDS Services security protocol encrypts and decrypts data that the BlackBerry device and t

Seite 40

BlackBerry Enterprise Solution 45 HTTPS protocol BlackBerry MDS encryption method Description Handheld mode TLS/SSL TLS and WTLS key establishment

Seite 41 - TCP/IP connection

BlackBerry Enterprise Solution 46 Authentication process for requests for wireless software upgrades When the BlackBerry Infrastructure sends a wire

Seite 42

BlackBerry Enterprise Solution 47 segmented network architecture, the system administrator can place the BlackBerry Enterprise Solution components i

Seite 43 - BlackBerry MDS connections

BlackBerry Enterprise Solution 48 Accessing the BlackBerry Infrastructure Wi-Fi enabled BlackBerry devices can connect directly to the BlackBerry In

Seite 44

BlackBerry Enterprise Solution 49 Enterprise Wi-Fi network security technology Wi-Fi enabled BlackBerry device implementation Layer 2 security Set

Seite 45

BlackBerry Enterprise Solution Encryption algorithms that the BlackBerry device supports for use with layer 2 security methods ...83 EAP authenticatio

Seite 46 - WAP gateway connections

BlackBerry Enterprise Solution 50 After an authentication server permits the supported Wi-Fi enabled BlackBerry device to access the enterprise Wi-F

Seite 47

BlackBerry Enterprise Solution 51 Authentication method Description Wi-Fi enabled BlackBerry device implementation Using IEEE 802.11i with PSK Sm

Seite 48

BlackBerry Enterprise Solution 52 the authentication server certificate. For the supported Wi-Fi enabled BlackBerry devices to trust the authenticat

Seite 49

BlackBerry Enterprise Solution 53 users must authenticate with the WLAN Login application browser using login credentials that the system administra

Seite 50

BlackBerry Enterprise Solution 54 For more information, see the BlackBerry Smart Card Reader Security Technical Overview. Binding the smart card to

Seite 51

BlackBerry Enterprise Solution 55 Field Description Initialized indicates whether the BlackBerry device is authenticated with and bound to the sma

Seite 52 - Fi hotspots

BlackBerry Enterprise Solution 56 Creating new IT policy rules to control custom applications Create new IT policy rules to control custom applicati

Seite 53

BlackBerry Enterprise Solution 57 The BlackBerry Enterprise Server administrator can define the following types of criteria: • specific, permitted

Seite 54

BlackBerry Enterprise Solution 58 connection. BlackBerry devices and the BlackBerry Desktop Software can use CHAP to send a challenge and subsequent

Seite 55

BlackBerry Enterprise Solution 59 How the BlackBerry device protects its operating system and the BlackBerry Device Software Each time a user turns

Seite 56

BlackBerry Enterprise Solution 6 This document describes the security features of the BlackBerry® Enterprise Solution and provides an overview of th

Seite 57

BlackBerry Enterprise Solution 60 • specify whether or not applications, including third-party applications, on the BlackBerry device can initiate

Seite 58

BlackBerry Enterprise Solution 61 Each third-party application requires authorization to run on the BlackBerry device. MIDlets (applications that us

Seite 59 - Software

BlackBerry Enterprise Solution 62 Remotely resetting the password of a content protected BlackBerry device The remote password reset cryptographic p

Seite 60

BlackBerry Enterprise Solution 63 IT policy rule Description Secure Wipe if Low Battery Set this IT policy rule to require that, if the BlackBerry

Seite 61 - • the signature is invalid

BlackBerry Enterprise Solution 64 do not exist on the BlackBerry device (in other words, if there is no connection between the BlackBerry Enterprise

Seite 62

BlackBerry Enterprise Solution 65 Related resources Resource Information BlackBerry Enterprise Server Feature and Technical Overview • BlackBerry

Seite 63

BlackBerry Enterprise Solution 66 Resource Information Garbage Collection in the BlackBerry Java Development Environment • cleaning BlackBerry dev

Seite 64

BlackBerry Enterprise Solution 67 Resource Information Visit www.blackberry.com/security. • information about BlackBerry Solution security www.bla

Seite 65 - Related resources

BlackBerry Enterprise Solution 68 Appendix A: RIM Crypto API Interface The RIM Crypto API on the BlackBerry device and in the BlackBerry JDE provid

Seite 66

BlackBerry Enterprise Solution 69 Key agreement scheme algorithms Algorithm Key length (bits) Type DH 512 to 4096 discrete logarithm KEA 1024 di

Seite 67 - Resource Information

BlackBerry Enterprise Solution 7 Concept Description BlackBerry Enterprise Solution implementation authenticity enables the message recipient to

Seite 68 - • a key generation protocol

BlackBerry Enterprise Solution 70 Code Digest length (bits) RIPEMD-128, 160 128, 160 www.blackberry.com

Seite 69

BlackBerry Enterprise Solution 71 Appendix B: TLS and WTLS standards that the RIM Crypto API supports The TLS and WTLS protocol cipher suite compone

Seite 70 - RIPEMD-128, 160 128, 160

BlackBerry Enterprise Solution 72 Symmetric algorithms that the RIM Crypto API supports Direct mode SSL Direct mode TLS WTLS RC4 40 RC4 40 RC5 4

Seite 71

BlackBerry Enterprise Solution 73 Appendix C: Previous version of wired master encryption key generation Each time a BlackBerry Enterprise Server or

Seite 72

BlackBerry Enterprise Solution 74 Appendix D: BlackBerry device wipe process A BlackBerry device wipe is designed to delete and overwrite the BlackB

Seite 73

BlackBerry Enterprise Solution 75 4. Clears all bytes to 0xFF (1111 11112). 5. Writes 0x55 to each byte (0x0101 01012). 6. Clears all bytes to 0x

Seite 74

BlackBerry Enterprise Solution 76 Appendix E: Ephemeral AES encryption key derivation process The BlackBerry device uses an ephemeral 256-bit AES en

Seite 75

BlackBerry Enterprise Solution 77 Appendix F: Power and electromagnetic side-channel attacks and countermeasures The BlackBerry device implementatio

Seite 76

BlackBerry Enterprise Solution 78 How the AES algorithm creates S-Box tables The BlackBerry device permutes each AES S-Box entry randomly and masks

Seite 77

BlackBerry Enterprise Solution 79 Appendix G: BlackBerry Router protocol When the BlackBerry Enterprise Server and the BlackBerry device use the Bla

Seite 78

BlackBerry Enterprise Solution 8 Feature Description control BlackBerry device and BlackBerry Desktop Software functionality • Send wireless comma

Seite 79

BlackBerry Enterprise Solution 80 device. The attacker must send master encryption key value (s) to the BlackBerry Enterprise Server, which requires

Seite 80

BlackBerry Enterprise Solution 81 If the BlackBerry device accepts yB, the BlackBerry Enterprise Server and the BlackBerry device open an authentica

Seite 81

BlackBerry Enterprise Solution 82 Appendix H: Enterprise Wi-Fi security methods that the BlackBerry device supports EAP authentication methods that

Seite 82

BlackBerry Enterprise Solution 83 Authentication method Description BlackBerry device implementation EAP-TTLS EAP-TTLS is designed to extend EAP-

Seite 83

BlackBerry Enterprise Solution 84 Protocol Description Wi-Fi enabled BlackBerry device implementation TKIP TKIP is • part of the IEEE 802.11i ent

Seite 84 - • WEP and TKIP

BlackBerry Enterprise Solution 85 VPN solution on the Wi-Fi enabled BlackBerry device The Wi-Fi enabled BlackBerry device has a built-in VPN client

Seite 85

BlackBerry Enterprise Solution 86 • RSA_WITH_RC4_128_MD5 • RSA_WITH_3DES_EDE_CBC_SHA • RSA_WITH_AES_128_CBC_SHA • RSA_WITH_AES_256_CBC_SHA • TL

Seite 86 - • RSA_WITH_AES_256_CBC_SHA

BlackBerry Enterprise Solution 87 Appendix J: RSA SecurID software token tokencode generation process 1. An administrator uses the RSA Authenticati

Seite 87

BlackBerry Enterprise Solution 88 3. The BlackBerry device receives B and verifies that B is a valid public key. 4. The BlackBerry device performs

Seite 88 - BlackBerry device remotely

BlackBerry Enterprise Solution 89 Protocol process When the BlackBerry Enterprise Server administrator sends the Set a Password and Lock Handheld IT

Seite 89 - Protocol process

BlackBerry Enterprise Solution 9 Feature Software versions supported Description The BlackBerry Enterprise Solution allows administrators to apply

Seite 90

BlackBerry Enterprise Solution 90 Part number: 17930884 Version 2 ©2008 Research In Motion Limited. All rights reserved. BlackBerry®, RIM®, Research

Seite 91

BlackBerry Enterprise Solution 91 Prior to subscribing for, installing, or using any Third Party Products and Services, it is your responsibility to

Kommentare zu diesen Handbüchern

Keine Kommentare