Data flow: Accessing an application or content server using BlackBerry Secure Connect Plus
    BlackBerry Secure Connect Plus
This data flow describes how data travels when an app on a device that is configured to use 
BlackBerry Secure Connect Plus
 accesses an application or content server in your organization.This data flow does not apply to 
BlackBerry
        Dynamics
 apps in the work space on Android Enterprise
 devices or Samsung Knox Workspace
 devices. For more information see, Data flow: Sending and receiving work data from a BlackBerry Dynamics app on an Android device using BlackBerry Secure Connect Plus
- The user opens an app to access work data from a content or application server behind your organization's firewall.- ForAndroid Enterprisedevices, all work space apps except those you choose to restrict useBlackBerry Secure Connect Plus.
- ForSamsung Knox Workspacedevices, you specify whether all work space apps or only specified work apps useBlackBerry Secure Connect Plus.
- ForiOSdevices, you specify whether all apps or only specified apps useBlackBerry Secure Connect Plus.
 
- The device sends a requests through a TLS tunnel, over port 443, to theBlackBerry Infrastructureto request a secure tunnel to the work network. The signal is encrypted by default using FIPS-140 certified Certicom libraries. The signaling tunnel is encrypted end-to-end.
- BlackBerry Secure Connect Plusreceives the request from theBlackBerry Infrastructurethrough port 3101.
- The device andBlackBerry Secure Connect Plusnegotiate the tunnel parameters and establish a secure tunnel for the device through theBlackBerry Infrastructure. The tunnel is authenticated and encrypted end-to-end with DTLS.
- The app uses the tunnel to connect to the application or content server using standard IPv4 protocols (TCP and UDP).
- BlackBerry Secure Connect Plustransfers the IP data to and from your organization's network.BlackBerry Secure Connect Plusencrypts and decrypts traffic using FIPS-140 certified Certicom libraries.
- The app receives and displays the data on the device.
- As long as the tunnel is open, supported apps use it to access network resources. When the tunnel is no longer the best available method to connect to your organization's network,BlackBerry Secure Connect Plusterminates it.