BlackBerry Workspaces security

BlackBerry Workspaces employs many advanced security features to ensure that your files are only accessed by those to whom you or your organization has granted permission.

Security features

Description

Key storage

Files downloaded to the device from the BlackBerry Workspaces server are encrypted using AES-256, with a unique key for each file.

The decryption key for the file is sent to the application separately from the file, as part of a file ‘license’ that includes all the access permissions for the file. This license is encrypted using the user's passcode.

File storage

When files are downloaded from the BlackBerry Workspaces server for viewing, they are cached in a secure cache on your device that is accessible only by the BlackBerry Workspaces app. This cache is not synchronized or backed up. The file is stored in the cache in encrypted form. The keys to decrypt the file are stored separately and are themselves stored in encrypted format.

Encryption

Files are encrypted using AES-256 (256 bit) and are downloaded to the device encrypted. A unique encryption key is generated for each file. This minimizes any security risk if a decryption key is somehow obtained. The decryption key (the file ‘license’) is encrypted by the user’s public key and downloaded from the server to the device in encrypted form. Keys for downloaded files are cached in the iOS device in encrypted form, in an area that is not backed up or synced by iOS, iCloud, or iTunes.

The file is decrypted in BlackBerry Workspaces app at the time the file is viewed; there is no clear text version of the file stored even in a temporary area. Further, for large files, the file is decrypted and displayed in blocks.

Data wipe

The private cache region used by the BlackBerry Workspaces app to store or cache files can be wiped on command by the organization administrator through the BlackBerry Workspaces administration console. The BlackBerry Workspaces app automatically wipes this cache if users enter an incorrect passcode 10 times in succession.

File transfer

Files and keys are always sent between the BlackBerry Workspaces servers and the devices in encrypted form and over an HTTPS (SSL) connection.

The connection between the application and the server uses the BlackBerry Workspaces RESTful API. This API requires that the device authenticate itself to the server before any requests are sent. If the authentication is successful, the device is given a unique secure session ID token (SSID) that must be sent with all subsequent requests.

App lock

The BlackBerry Workspaces app uses a 4-digit app lock code to unlock the application when first activated. The lock code can also be mandated (as a file permission) to open and view specific files, or if the application is idle for longer than 10 minutes.

Private cache

The application uses a private cache area to store files and licenses. This area is not accessible to other applications or iOS and is not backed up or synchronized by iTunes or iCloud.

Jailbreak

The BlackBerry Workspaces app does not open if it detects that the device has been jailbroken (software unlocked). The cache is wiped of all files and any signed-in users are signed out.

Authentication

The BlackBerry Workspaces app authenticates to the BlackBerry Workspaces server using either an email address or username password. In the case of email-based authentication, the server generates a deviceID value and sends a URL back to the device in an email addressed to the address it was given. The device uses this URL to authenticate the deviceID with the server and stores the deviceID in the application's secure container. This deviceID is used to request a unique secure session ID token (SSID) from the server; this token is used to authenticate the application to the server on each subsequent action.