Data flow: Activating a BlackBerry Dynamics app when one is already activated on the device
This data flow describes how data travels when a BlackBerry Dynamics app (including the BlackBerry UEM Client) is already activated on a device and is used as an easy activation delegate to activate subsequent BlackBerry Dynamics apps.
- An administrator assigns one or more BlackBerry Dynamics apps to a user.
- The user installs the app on the device.
- The app performs the following actions:
- Queries the BlackBerry Dynamics NOC and identifies that another BlackBerry Dynamics app has already been registered and activated on the device.
- Requests the activation credentials from the previously activated BlackBerry Dynamics app.
- The user approves the activation request from the previously activated app on the device.
- The previously activated app sends the credentials through the BlackBerry Infrastructure to UEM.
- UEM sends the credentials request and the UEM URL through the BlackBerry Infrastructure to the previously activated app.
- The previously activated app returns the credentials and the URL to the new app.
- The new app completes the following actions:
- The app registers itself with the BlackBerry Dynamics NOC and receives an ID that UEM can later use to confirm with the BlackBerry Dynamics NOC that the app was successfully activated.
- Connects to UEM through the BlackBerry Infrastructure and establishes an end-to-end encrypted session with UEM using the EC-SPEKE protocol.
This session can be decrypted only by the UEM instance that issued the activation credentials.
- Sends the activation request through the secured session.
- UEM verifies the activation request and sends an encrypted activation response to the app. The activation response includes data required by the app to communicate with UEM, including a client certificate, master session key, list of BlackBerry Proxy instances, and trusted certificate authorities.