Installation guide

BlackBerry Enterprise Solution 9
Feature Software versions supported Description
The BlackBerry Enterprise
Solution allows
administrators to apply an
encoding scheme to
BlackBerry data using
transcoder application
code.
BlackBerry Enterprise
Server Version 4.1 SP5 or
later
BlackBerry Device Software
Version 4.5 or later
Third-party application developers
can create encoding schemes that
encrypt, convert, or otherwise change the
format of BlackBerry device data.
BlackBerry encryption keys
By default, the BlackBerry Enterprise Solution generates the master encryption key and message key that the
BlackBerry Enterprise Server and BlackBerry devices use to encrypt and decrypt all data traffic between them.
The BlackBerry Enterprise Server administrator can also enable the BlackBerry device to generate and use the
content protection key to encrypt BlackBerry device user data while the BlackBerry device is locked, and
generate and use the grand master key to encrypt the master encryption key while the BlackBerry device is
locked.
Encryption key relationships on the BlackBerry device
Master encryption keys
The master encryption key is unique to the BlackBerry device. To send and receive messages, the master
encryption key stored on the BlackBerry Enterprise Server and on the BlackBerry device must match. If the
stored keys do not match, the BlackBerry device and the BlackBerry Enterprise Server cannot decrypt and must
therefore discard messages that they receive.
Where master encryption keys are stored
The BlackBerry Configuration Database, the messaging server, and the BlackBerry device flash memory store
encryption keys, including the current BlackBerry device master encryption key.
www.blackberry.com