Specifications
How devices are designed to prevent BlackBerry Runtime for Android
apps from accessing work data and apps
BlackBerry Balance devices running BlackBerry 10 classify Android apps as personal apps and as such, they can be
installed only in the personal space on devices. You cannot deploy or approve Android apps for installation in the work
space. Android apps can access only personal data that is located in the personal space. Android apps do not have access
to the work apps or work data that are located in the work space.
How the BlackBerry Device Service and devices
protect work and personal data and apps
BlackBerry Balance devices running BlackBerry 10 protect work data by encrypting the files stored in the work space.
Devices can also protect personal data by encrypting the files stored in the personal space if you or a user requires. Devices
can also encrypt the files stored on media cards that are inserted in devices; only personal data can be saved to media
cards. Devices encrypt only the contents of files; file and directory names are not encrypted.
You can protect work data on devices further by requiring password protection and controlling when devices wipe their
work space.
Related information
Protecting data, 92
How devices protect work data
BlackBerry Balance devices running BlackBerry 10 encrypt data stored in the work file system using XTS-AES-256.
A device randomly generates an encryption key to encrypt the contents of a file. The file encryption keys are protected by a
hierarchical system of encryption keys as follows:
• The device encrypts the file encryption key with the work domain key and stores the encrypted file encryption key as a
metadata attribute of the file
• The work domain key is a randomly generated key that is stored in the file system metadata and is encrypted using the
work master key
• The work master key is also randomly generated. The work master key is stored in NVRAM on the device and is
encrypted with the system master key
• The system master key is stored in the replay protected memory block on the device
• The replay protected memory block is encrypted with a key that is embedded in the processor when the processor is
manufactured
The file encryption keys, the work domain key, the work master key, and the system master key are generated using the
BlackBerry OS Cryptographic Kernel, which received FIPS 140-2 certification for the BlackBerry 10 OS.
Security Technical
Overview
Using BlackBerry Balance to secure BlackBerry 10 devices in your organization’s environment for work
use and personal use
49