Specifications

By default, the Enterprise Management Agent on the device can use all of these communication methods to connect to the
BlackBerry Device Service and obtain the latest updates that you made to IT policies, profiles, software configurations, or
IT administration commands.
By default, work apps on the device can also use any of these communication methods to access the resources in your
organization’s environment (for example, Microsoft ActiveSync servers, web servers, and content servers).
Related information
Controlling how work and personal apps connect to your organization's network, 57
Controlling the network connections that work and personal apps on BlackBerry PlayBook tablets can access, 71
Controlling app connections, 80
Types of encryption that devices use when
they connect to your organization's
resources
Devices and your organization’s resources use tunneling to encapsulate various types of encryption. Tunneling occurs
when data is encrypted using more than one layer of encryption. The type of encryption used depends on the type of
connection between the device and the resource.
For example, in a work Wi-Fi connection, the data that a device and the BlackBerry Device Service send between each
other is encrypted using SSL encryption. The data that the device and work wireless access point send to each other uses
Wi-Fi encryption (unless the work wireless access point is an open network). Because the device uses tunneling, the data
that the device sends to the BlackBerry Device Service is encrypted first by SSL encryption and then by Wi-Fi encryption as
it travels between the device and the wireless access point.
Encryption type Description
Wi-Fi encryption (IEEE 802.11) Encrypts the data that is sent between the device and wireless access point if
the wireless access point was set up to use Wi-Fi encryption.
VPN encryption Encrypts the data that is sent between the device and VPN server.
TLS encryption Encrypts the data that is sent between the device and BlackBerry Infrastructure.
Encrypts the data that is sent between the device and BlackBerry Device
Service. This type of encryption uses a client/server certificate.
SSL/TLS encryption Encrypts the data that is sent between the device and content server, web
server, or messaging server that uses Microsoft ActiveSync. The encryption for
this connection must be set up separately on each server and uses a separate
Security Technical Overview How devices connect to the BlackBerry Device Service
16