BlackBerry Workspaces security
BlackBerry Workspaces employs many advanced security features to ensure that your files are only accessed by those to whom you or your organization has granted permission.
|
Security features |
Description |
|---|---|
|
Key storage |
Files downloaded to the device from the BlackBerry Workspaces server are encrypted using AES-256, with a unique key for each file. The decryption key for the file is sent to the application separately from the file, as part of a file ‘license’ that includes all the access permissions for the file. This license is encrypted using the user's passcodeif a passcode is enforced by the administrator, or another key. |
|
File storage |
When files are downloaded from the BlackBerry Workspaces server for viewing, they are cached in a secure cache on your device that is accessible only by the BlackBerry Workspaces app. This cache is not synchronized or backed up. The file is stored in the cache in encrypted form. The keys to decrypt the file are stored separately and are themselves stored in encrypted format. |
|
Encryption |
Files are encrypted using AES-256 (256 bit) and are downloaded to the device encrypted. A unique encryption key is generated for each file. This minimizes any security risk if a decryption key is somehow obtained. The decryption key (the file ‘license’) is encrypted by the user’s public key and downloaded from the server to the Android device in encrypted form. Keys for downloaded files are cached in the Android device in encrypted form, in an area that is not backed up or synced by Android. The file is decrypted in BlackBerry Workspaces app at the time the file is viewed; there is no clear text version of the file stored even in a temporary area. |
|
Data wipe |
The private cache region used by the BlackBerry Workspaces app to store or cache files can be wiped on command by the organization administrator through the BlackBerry Workspaces administration console. The BlackBerry Workspaces app automatically wipes this cache if users enter an incorrect passcode 10 times in succession. |
|
File transfer |
Files and keys are always sent between the BlackBerry Workspaces servers and the devices in encrypted form and over an HTTPS (SSL) connection. The connection between the application and the server uses the BlackBerry Workspaces RESTful API. This API requires that the device authenticate itself to the server before any requests are sent. If the authentication is successful, the device is given a unique secure session ID token (SSID) that must be sent with all subsequent requests. |
|
App lock |
The BlackBerry Workspaces app uses a 4-digit app lock code to unlock the application when first activated. The lock code can also be mandated (as a file permission) to open and view specific files, or if the application is idle for longer than 2 minutes. The BlackBerry Dynamics version of the app requests the user's BlackBerry Dynamics password according to the BlackBerry Dynamics policy in the BlackBerry UEM management console. |
|
Private cache |
The application uses a private cache area to store files and licenses. This area is not accessible to other applications or Android and is not backed up or synchronized. |
|
Root detection |
The BlackBerry Workspaces app does not open if it detects that the device has been rooted (software unlocked). The cache is wiped of all files and any users are signed out. |
|
Authentication |
The BlackBerry Workspaces app authenticates to the BlackBerry Workspaces server using either an email address or username password. The server sends a verification value to the user's email address and the user is prompted to enter the value to authenticate. The server generates a device ID based on the device's MAC address, which is stored in the application's secure container. This device ID is used to request a unique secure session ID (SSID) token, and this token is used to authenticate the application with the server on each subsequent action. |