Specifications
Feature Description
Protection of application data using
sandboxing
The BlackBerry 10 OS and PlayBook OS use sandboxing to separate and restrict
the capabilities and permissions of apps that run on the device. Each
application process runs in its own sandbox.
The BlackBerry 10 OS and PlayBook OS evaluate the requests that an app's
processes make for memory outside of its sandbox.
Protection of resources The BlackBerry 10 OS and PlayBook OS use adaptive partitioning to allocate
resources that are not used by apps during typical operating conditions and to
make sure that resources are available to apps during times of peak operating
conditions.
Management of permissions to access
capabilities
The BlackBerry 10 OS and PlayBook OS evaluate every request that an app
makes to access a capability on the device.
Verification of the boot ROM code The device verifies that the boot ROM code is permitted to run on the device.
Hardware root of trust for BlackBerry
devices
Research In Motion ensures the integrity of BlackBerry device hardware and makes sure that counterfeit devices cannot
connect to the BlackBerry Infrastructure and use BlackBerry services.
From the beginning of the product lifecycle, RIM integrates security into every major component of the product design of
devices so that it is very difficult to remove or bypass this security. RIM has enhanced its end-to-end manufacturing model
to securely connect the supply chain, RIM manufacturing partners, the BlackBerry Infrastructure, and devices, which
allows RIM to build trusted devices anywhere in the world.
The RIM manufacturing security model prevents counterfeit devices from impersonating authentic devices and makes sure
that only genuine BlackBerry devices can connect to the BlackBerry Infrastructure. The BlackBerry Infrastructure uses
device authentication to cryptographically prove the identity of the device that attempts to register with it. The device uses
its hardware-based ECC 521-bit key pair to verify the integrity of itself and the boot ROM. After the boot ROM is verified, the
device verifies the software stack. After the verification process is complete and the device is determined to be authentic,
the device tries to register with the BlackBerry Infrastructure. Only devices that are manufactured by RIM and complete
the self-verification process can register with the BlackBerry Infrastructure.
Architecture: BlackBerry Device Service
The BlackBerry Device Service consists of various components that are designed to help you perform the following actions:
Security Technical Overview About BlackBerry Device Service solution security
9