BlackBerry Bridge Security Overview

BrightPoint GB

BrightPoint GB

Device Lifecycle Services.

Delivered.

Plan. Market. Customize. Move. Recycle.

More...
Samsung Galaxy S III

Samsung Galaxy S III

Designed For Humans

Inspired By Nature

This sleek and innovative smartphone has the enhanced intelligence to make everyday life easier.

More...
BlackBerry Curve 9320

BlackBerry Curve 9320

Socially Connected

3G capable

Featuring all of the core messaging and social features to keep you connected.

More...
HTC One X

HTC One X

Technology Leader

Quad Core Android 4.0

Perfect for gaming, watching videos and surfing the net

More...
HTC One V

HTC One V

Iconic Design

A great all-rounder

ImageSense technology, Beats Audio, wireless media streaming, cloud storage and more...

More...
ZTE Tania

ZTE Tania

Windows Phone Mango

Fully equipped

Great for business and pleasure

More...
BlackBerry Bold 9790

BlackBerry Bold 9790

BlackBerry OS7

Powerful & Fully Featured

Smooth performance for browsing the web, running apps, working with documents, and enjoying multimedia

More...
HTC Sensation XL

HTC Sensation XL

Feel every beat

With Beats Audio

A multimedia superstar with Beats earphones included.

More...
HTC Titan

HTC Titan

Unlike anything you've ever held before

Office on the move

Windows Phone 7.5 (Mango). With a 4.7-inch screen and big virtual keyboard, the Titan is perfect for both work and play.

More...
HTC Radar

HTC Radar

Real time close

Windows Phone 7.5 (Mango)

Pull all your contacts and social networks together into one place to stay connected with friends and share instantly.

More...
BlackBerry Bold 9900

BlackBerry Bold 9900

Slim yet powerful

Touch and Type in harmony

The Bold 9900 is RIM's thinnest BlackBerry smartphone yet and as lightweight and durable as it is feature-packed.

More...
ZTE Libra

ZTE Libra

Affordable Android

WiFi hotspot, Exchange email, Google Maps and much, much more all at an attractive price.

More...
ZTE MF30/MF60

ZTE MF30/MF60

Portable Internet

USB & WiFi for Windows and Mac

High speed, portable Internet access in your pocket.

More...
Motorola Defy +

Motorola Defy +

Lifeproof

Faster, smarter, richer

Scratch, dust and water-resistant. 1GHz processor, 5MP camera and great pre-loaded apps.

More...
BlackBerry Curve 9380

BlackBerry Curve 9380

BlackBerry OS7

The 1st all-touch Curve

Easily capture and share your favourite moments with family, friends and colleagues.

More...
Samsung Galaxy S2

Samsung Galaxy S2

Faster. Slimmer. Brighter.

Prepare yourself for the Galaxy S II, Samsung's thinnest smartphone.

More...
HTC Sensation XE

HTC Sensation XE

With Beats Audio

Designed to impress

With custom Beats headphones, engineered to deliver extraordinary sound.

More...
ZTE Skate

ZTE Skate

Affordable Android

WiFi hotspot, Exchange email, Google Maps and much, much more all at an attractive price.

More...
HTC Explorer

HTC Explorer

A design that fits your lifestyle

Keep in touch with the people who matter

Jump right into what's most important to you thanks to an improved lockscreen design.

More...
ZTE Tureis

ZTE Tureis

Full Qwerty 2.6-inch touchscreen

Android Gingerbread

Business and social features in a slim package.

More...
Frontpage Slideshow (standalone) | Copyright © 2006-2011 JoomlaWorks Ltd.

BlackBerry Bridge

The BlackBerry Bridge software is a free application available in the BlackBerry App World that needs to be installed onto compatible BlackBerry Smartphones (running device software version 5.0 or 6.0) in order to enable them to pair via Bluetooth with the new BlackBerry PlayBook tablet so that email, contacts and calendar information stored on the Smartphone can then be managed from the PlayBook.
The BlackBerry Bridge software is preinstalled on devices running version 6.1 of the software or later.
The Bridge software also allows you to access files stored on the Smartphone's media card and also browse the Internet via the Smartphone's cellular data connection.

The Bridge feature is available to Smartphones that have been activated against a BlackBerry Enterprise Server (BES) and also for devices using the BlackBerry Internet Service (BIS).

In this article I will outline the security measures utilised by the solution for those administrators who may need to know more about the application before being able to allow users to deploy PlayBooks in their BlackBerry infrastructure.

Pairing

The link between the BlackBerry PlayBook and the Smartphone is established via Bluetooth. A barcode is generated by the Bridge software on the PlayBook that can be scanned using the camera on the Smartphone which establishes the Bluetooth connection. A connection can also be created manually by typing in a Bluetooth PIN on the Smartphone generated by the PlayBook.
Once paired via Bluetooth, the Bridge software uses the ECDH algorithm to further encrypt the data connection over and above the level of security provided by the Bluetooth protocol, incidentally the same level of encryption as used by the government-approved BlackBerry Smartcard Reader accessory.

When reconnecting to a Smartphone that requires a password, the password must be typed on the PlayBook.

Architecture

The file system on the PlayBook is divided into "work" and "personal" areas, each being isolated from the other. The tablet operating system identifies which applications fall into which category and only those applications can access their respective storage areas: only work applications can access the work storage; and only personal applications can access the personal storage.

Work data consists of all email messages, calendar entries and attachments that are exchanged between the Smartphone and a BES, as well as any data that is associated with a work application, such as Documents To Go.
When the Bridge connection is established, the tablet creates an encrypted file system using 256-bit AES encryption and the key generated by the Bridge software on the Smartphone.

No work data is stored permanently on the PlayBook, rather the tablet uses the Smartphone's device memory to store data, and any data stored temporarily on the PlayBook is erased when the Bridge connection is closed along with the encryption key.

NOTE - Data stored on a Smartphone that is activated with a BlackBerry Internet Service (BIS) account is considered personal data.

Personal data is not encrypted.

BlackBerry Enterprise Server

The default option on the BlackBerry Enterprise Server is to allow use of the Bridge software. Should you wish to disable use of the Bridge software from the BES, or restrict its use to specific users via IT Policy, additional IT Policy rules must first be imported into the BES server. These policy definitions are free to download from the BlackBerry web site - http://blog.brightpointuk.co.uk/rim-releases-two-it-policies-blackberry-...

Applications

By default all applications on the PlayBook run in personal mode. Some applications may be capable of running in work mode, personal mode, or both.
An application such as Documents To Go can work in both work and personal mode. When the Bridge connection is closed, it will run in personal mode. When being used to view an attachment to a work email over the Bridge connection, then it is running in work mode.

Work applications are grouped together on the Tablet under the Bridge Control Panel.

Applications running in work mode cannot exchange information with applications running in personal mode and vice versa.

Work applications CAN view but cannot change files stored in personal storage in some situations: for example a picture taken by the user could be attached to a work email.

Applications can only run in work mode when the Bridge connection is active.

Work applications can access the Smartphone's cellular connection and its connection via the BES to the corporate internal network, therefore the Bridge Browser could be used to navigate a company intranet, for example.
(It is not possible to access a WiFi connection when the browser is running in work mode).

It is not possible for users to designate applications installed by themselves as work applications.

The following applications can only run in personal mode:

  • Twitter
  • Facebook
  • YouTube
  • Maps
  • Any application installed by the user

Miscellaneous

The Bridge connection can be configured to close automatically in the event that that user does not interact with the tablet for a pre-defined period of time.

Detailed information on the security mechanisms and encryption algorithms are available in the BlackBerry PlayBook Technical Security Overview, available on the FTP site here