- The user contacts your organization's IT department to activate the BlackBerry device.
- You create a temporary activation password for the user account and communicate the password to the user. The password applies to the user account only.
- To activate the BlackBerry device over the wireless network, the user opens the activation application on the BlackBerry device and types the appropriate email address and activation password.
- The BlackBerry device sends an activation request message to the email account. The message contains information about the BlackBerry device, such as routing information and the public keys for the BlackBerry device.
- The BlackBerry® Enterprise Server sends the BlackBerry
device an activation response that contains routing information about the BlackBerry Enterprise Server and the public keys for the BlackBerry Enterprise Server.
The BlackBerry Enterprise Server and BlackBerry device establish a device transport key. The BlackBerry Enterprise Server and BlackBerry device confirm knowledge of the device transport key to each other. If the confirmation is successful, the activation proceeds and further communication between the BlackBerry Enterprise Server and BlackBerry device is encrypted.
The BlackBerry Enterprise Server sends the appropriate service books (for example, the messaging service book, wireless calendar service book, browser service book, and other service books) to the BlackBerry device. The user can now send messages from and receive messages on the BlackBerry device.
- If the user account is configured for wireless synchronization, and if wireless backup and wireless calendar synchronization on the BlackBerry device are turned on, the BlackBerry Enterprise Server sends user data to the BlackBerry device.
- You click a user account, and then click Resend IT Policy.
- The BlackBerry® Policy Service reads the current IT policy settings for the user account from the BlackBerry Configuration Database to determine which IT policy to send to the BlackBerry device.
- The BlackBerry Dispatcher encrypts the IT policy data packet using the device transport key of the BlackBerry device, compresses the content, and sends it to the BlackBerry Router for delivery to the BlackBerry device.
- The BlackBerry Router sends the encrypted IT policy data packet to the wireless network over port 3101. The wireless network verifies that the PIN belongs to a valid BlackBerry device that is registered with the wireless network.
Process flow: Authenticating data on a BlackBerry device without connecting to the BlackBerry Infrastructure
- A user connects a BlackBerry® device to a computer that the BlackBerry® Device Manager is running on.
- The BlackBerry Router uses a unique authentication protocol to verify that the user is a valid BlackBerry device user.
The authentication sequence uses the same authentication information for the BlackBerry® Enterprise Server and BlackBerry device that the SRP authentication sequence uses to validate the BlackBerry Enterprise Server before permitting it to connect to the BlackBerry® Infrastructure. The BlackBerry Router cannot access the value of the device transport key of the BlackBerry device and BlackBerry Enterprise Server.
- The BlackBerry device and BlackBerry Router use the BlackBerry Device Manager to send data to each other over the physical connection, behind the firewall. All the data that the BlackBerry device and BlackBerry Enterprise Server send to each other is compressed and encrypted. This data bypasses the wireless network.