BBM Enterprise algorithms and functions

To protect the connection between BBM Enterprise users during a chat, BBM Enterprise users exchange public signing and encryption keys using an in-band or out-of-band shared secret and EC-SPEKE. For details, see Key exchange process. These keys are then used to encrypt and digitally sign messages between the devices. BBM Enterprise uses the following algorithms that are based on NIST standards with 256-bit equivalent security:
  • EC-SPEKE: securely exchanges a symmetric key by protecting the exchange with a password
  • KDF: securely derives message keys from shared secrets
  • One-Pass DH: using one user’s private key and another user’s public key, derives a new shared secret between the users
The algorithms and associated key strengths that BBM Enterprise implements are:
  • AES-256 for symmetric encryption
  • ECDSA with NIST curve P-521 for signing
  • One-Pass ECDH with NIST curve P-521 for symmetric key agreement
  • SHA2-512 for hashing and key derivation
  • SHA2-256-128 HMAC for message authentication codes
BBM Enterprise voice and video calling uses SRTP media streaming and implements the following algorithms and associated key strengths:
  • AES-256 in GCM mode for symmetric encryption
  • 112-bit salting keys
  • BBM Enterprise messaging for symmetric key transfer
  • SHA1 80-bit tag for message authentication and integrity