Parameters that the BBM Enterprise key exchange uses
| Parameter | Description |
|---|---|
| A, B | The two key exchange participants (A initiator, B recipient) |
| XA, XB | Versions of X belonging to A and B |
| PINAB | BlackBerry PIN value for A and B |
| VersionAB | The highest supported protocol version by each party |
| SAB | Public portion of EC-SPEKE exchange values |
| S'AB | Private portion of EC-SPEKE exchange values |
| KsignAB | Public portion of signing key |
| K'signAB | Private portion of signing key |
| KencAB | Public portion of encryption key |
| K'encAB | Private portion of encryption key |
| Kenc | Symmetric encryption key protecting the confidentiality of the key exchange |
| Kmac | Symmetric key protecting the integrity of the key exchange |
| nonce | Initialization Vector nonce associated with encryption using Kenc |
| ENCMAC {Kenc, Kmac, IV} (data) | Symmetric encryption with Kenc followed by the addition of a MAC of the ciphertext with Kmac |
| DECMAC {Kenc, Kmac, IV} (data) | The inverse of ENCMAC: verification of the MAC with Kmac, followed by decryption of the authenticated ciphertext using Kenc |
| KDF (aux, secret) | A standard KDF function |
| EC-SPEKE-GEN (secret) | Generates a non-deterministic key pair based on a shared secret |
| EC-DH (private, public) | Generates a raw shared secret with ECDH |
| EC-GEN () | Generates a new random Elliptic Curve key pair |
| Kproof | A symmetric key used for proving possession of the private key |
| EC-SIGN {secret} (data) | A public key signature on a hash using ECDSA |
| MAC {secret} (data) | Calculates a MAC keyed with secret on data |
| T3, T4 | Message authentication tags for messages #3 and #4 |
| SSAB | The EC-SPEKE shared secret value between A and B |
| F | The prefix value used for cryptographic separation between usages of the same key between different BBM applications, protocol versions, and sessions |
| S | Shared secrets, shared in-band out-of-band (for details, see Key exchange process) |
| || | Indicates concatenation |
| (X, Y) | Indicates separation of concatenated values |