Data flow: Sending and receiving work data from a BlackBerry
Dynamics app on an Android device using BlackBerry Secure Connect Plus
BlackBerry
Dynamics
app on an Android
device using BlackBerry Secure Connect Plus
This data flow describes how data travels when a
BlackBerry
Dynamics
app on an Android Enterprise
or Samsung Knox Workspace
device uses BlackBerry Secure Connect Plus
.If you are using
BlackBerry Secure Connect Plus
with BlackBerry
Dynamics
apps on an Android Enterprise
device, it is recommended that you restrict BlackBerry
Dynamics
apps from using BlackBerry Secure Connect Plus
to avoid network latency. You can't restrict specific apps on Samsung Knox Workspace
devices.If you are using
BlackBerry Secure Connect Plus
with BlackBerry
Dynamics
apps on an Android Enterprise
device or a Samsung Knox Workspace
device, it is recommended that you configure BlackBerry UEM
not to send BlackBerry
Dynamics
app data through the BlackBerry Dynamics NOC
to reduce network latency.- The user opens aBlackBerry Dynamicsapp to access work data.
- The device sends a request through a TLS tunnel, over port 443, to theBlackBerry Infrastructureto request a secure tunnel to the work network. The signal is encrypted by default using FIPS-140 certifiedCerticomlibraries. The signaling tunnel is encrypted end to end.
- BlackBerry Secure Connect Plusreceives the request from theBlackBerry Infrastructurethrough port 3101.
- The device andBlackBerry Secure Connect Plusnegotiate the tunnel parameters and establish a secure tunnel for the device through theBlackBerry Infrastructure. The tunnel is authenticated and encrypted end to end with DTLS.
- BlackBerry Secure Connect Plusestablishes a connection withBlackBerry Proxy.
- TheBlackBerry Dynamicsapp establishes a connection toBlackBerry Proxyusing theBlackBerry Secure Connect Plustunnel.
- BlackBerry Proxyauthenticates with theBlackBerry Dynamicsapp using its server certificate.BlackBerry Proxyvalidates the app using a MAC keyed with a session key known only toBlackBerry Proxyand the app.
- When the secure connection is established betweenBlackBerry Proxyand the app, work data can travel between the device and application or content servers behind the firewall using theBlackBerry Secure Connect Plustunnel toBlackBerry Proxy.BlackBerry Secure Connect Plusencrypts and decrypts traffic using FIPS-140 certified Certicom libraries.