
BlackBerry Enterprise Solution Security
Protecting stored data 24
When the user unlocks the BlackBerry device after a reset, the BlackBerry device
• uses the content protection key to decrypt the grand master key in flash memory
• stores the decrypted grand master key in RAM again
• re-establishes the wireless connection to the BlackBerry Infrastructure
• resumes serial bypass
• receives data from the BlackBerry Enterprise Server
Cleaning the BlackBerry device memory
By default, the BlackBerry device continually runs a standard Java garbage collection process to reclaim
BlackBerry device memory that is no longer referenced.
If secure garbage collection is turned on, the BlackBerry device performs the following additional actions:
• overwrites the memory reclaimed by the standard garbage collection process with zeroes
• periodically runs the memory cleaner program, which tells BlackBerry device applications to empty any
caches and free memory associated with unused, sensitive application data
• automatically overwrites the memory freed by the memory cleaner program when it runs
Any of the following conditions enable the BlackBerry device to perform secure garbage collection:
• content protection is turned on
• a program uses the RIM Cryptographic Application Programming Interface (Crypto API) to create a private
or symmetric key
• a third-party application turns on secure garbage collection by registering with the memory cleaner
• S/MIME Support Package is installed
• PGP Support Package is installed
Configuring memory cleaning
Users can configure the memory cleaner program to run when their BlackBerry devices are holstered or when
their BlackBerry devices remain idle for a configured period of time. Users can also manually run the memory
cleaner program on their BlackBerry devices or run specific registered memory cleaners in the BlackBerry device
Security options. If secure garbage collection is turned on, when the memory cleaner program runs, it invokes the
secure garbage collection process.
You can configure the memory cleaner program to run automatically when the
• user synchronizes the BlackBerry device with the desktop computer
• user locks the BlackBerry device
• BlackBerry device locks after a specified amount of idle time
• user changes the time or time zone on the BlackBerry device
See the Policy Reference Guide for more information.
www.blackberry.com
Kommentare zu diesen Handbüchern