The BlackBerry Enterprise Server and BlackBerry device establish a master encryption key. The BlackBerry Enterprise Server
and BlackBerry device confirm knowledge of the master encryption key to each other. If the confirmation is successful, the
activation proceeds and further communication between the BlackBerry Enterprise Server and BlackBerry device is
encrypted.
The BlackBerry Enterprise Server sends the IT policy to the BlackBerry device. If the BlackBerry device cannot accept the IT
policy, the activation process does not complete.
The BlackBerry Enterprise Server sends the appropriate service books (for example, the messaging service book, wireless
calendar service book, browser service book, and other service books) to the BlackBerry device. The user can now send
messages from and receive messages on the BlackBerry device.
6. If the user account is configured for wireless synchronization, and if wireless backup and wireless calendar synchronization
on the BlackBerry device are turned on, the BlackBerry Enterprise Server sends user data to the BlackBerry device.
Process flow: Resending an IT policy to a BlackBerry device manually
1. Click a user account, and then click Resend IT Policy.
2. The BlackBerry Policy Service reads the current IT policy settings for the user account from the BlackBerry Configuration
Database to determine which IT policy to send to the BlackBerry device.
The BlackBerry Policy Service prepares to send the IT policy using the GME protocol by adding the unique identifier and
BlackBerry® Enterprise Server version.
The BlackBerry Policy Service adds the unique key that the BlackBerry Domain uses to sign IT policy data packets to the IT
policy data packet.
The BlackBerry Policy Service sends the IT policy data packet to the BlackBerry Dispatcher.
3. The BlackBerry Dispatcher encrypts the IT policy data packet using the master encryption key of the BlackBerry device,
compresses the content, and sends it to the BlackBerry Router for delivery to the BlackBerry device.
4. The BlackBerry Router sends the encrypted IT policy data packet to the wireless network over port 3101. The wireless network
verifies that the PIN belongs to a valid BlackBerry device that is registered with the wireless network.
Process flow: Authenticating data on a BlackBerry device without connecting to the
BlackBerry Infrastructure
1. A user connects a BlackBerry® device to a computer that the BlackBerry® Device Manager is running on.
2. The BlackBerry Router uses a unique authentication protocol to verify that the user is a valid BlackBerry device user.
The authentication sequence uses the same authentication information for the BlackBerry® Enterprise Server and BlackBerry
device that the SRP authentication sequence uses to validate the BlackBerry Enterprise Server before permitting it to connect
to the BlackBerry® Infrastructure. The BlackBerry Router cannot access the value of the master encryption key of the
BlackBerry device and BlackBerry Enterprise Server.
Feature and Technical Overview
BlackBerry device management process flows
92
Kommentare zu diesen Handbüchern