Skip Navigation

Data flow: Sending and receiving work data using
BlackBerry Secure Connect Plus

This data flow describes how data travels when an app on a device that is configured to use
BlackBerry Secure Connect Plus
accesses an application or content server in your organization.
Diagram showing the steps and components mentioned in the following data flow.
  1. The user opens an app to access work data from a content or application server behind your organization's firewall.
    • On
      Android Enterprise
      , and
      Samsung Knox Workspace
      devices, all work apps can use
      BlackBerry Secure Connect Plus
      .
    • On
      iOS
      devices, you specify whether all apps or only specified apps can use
      BlackBerry Secure Connect Plus
      .
  2. The device determines that a secure IP tunnel is the most direct, cost-efficient method available to connect to the application or content server to retrieve the data and sends a requests through a TLS tunnel, over port 443, to the
    BlackBerry Infrastructure
    for a secure tunnel to the work network. By default, the signal is encrypted using FIPS-140 certified Certicom libraries. The signaling tunnel is encrypted end-to-end.
  3. BlackBerry Secure Connect Plus
    receives the request from the
    BlackBerry Infrastructure
    through port 3101.
  4. The device and
    BlackBerry Secure Connect Plus
    negotiate the tunnel parameters and establish a secure tunnel for the device through the
    BlackBerry Infrastructure
    . The tunnel is authenticated and encrypted end-to-end with DTLS.
  5. The app uses the tunnel to connect to the application or content server using standard IPv4 protocols (TCP and UDP).
  6. BlackBerry Secure Connect Plus
    transfers the IP data to and from your organization's network.
    BlackBerry Secure Connect Plus
    encrypts and decrypts traffic using FIPS-140 certified Certicom libraries.
  7. The app receives and displays the data on the device.
  8. As long as the tunnel is open, supported apps use it to access network resources. When the tunnel is no longer the best available method to connect to your organization's network,
    BlackBerry Secure Connect Plus
    terminates it.
    For
    iOS
    devices, if you configure per-app VPN for
    BlackBerry Secure Connect Plus
    , the tunnel eventually terminates when none of the configured apps are in use.