User guide

4. The BlackBerry Messaging Agent on the BlackBerry Enterprise Server decrypts the cached password for the Notes .id
file and validates the password that the device sent. If the BlackBerry Messaging Agent can verify the password, the
BlackBerry Messaging Agent uses the password to encrypt the message using Notes encryption.
5. The BlackBerry Enterprise Server sends the encrypted email message to the messaging server so that the messaging
server can deliver it to the recipient.
Data flow: Receiving an IBM Notes encrypted message
1. A user uses the IBM Notes application on the user’s computer to encrypt a message using the password for the
Notes .id file.
2. The BlackBerry Enterprise Server performs the following actions:
a retrieves the Notes encrypted message from the messaging server
b encrypts the Notes encrypted message using BlackBerry transport layer encryption
c sends the encrypted message to the BlackBerry device
3. The device decrypts the message using BlackBerry transport layer encryption and stores the message without
decrypting the Notes encryption.
4. The user tries to open the Notes encrypted message on the device.
5. The BlackBerry Messaging Agent on the BlackBerry Enterprise Server decrypts the cached password for the Notes .id
file and uses the password to decrypt the message. If the BlackBerry Messaging Agent does not have the password,
from the menu in the messages application, the user must select More, More All, or Open Attachment to send the
decrypted message to the device.
6. The BlackBerry Enterprise Server deletes the decrypted password from the BlackBerry Messaging Agent memory
cache and sends the decrypted message to the device.
Security Technical Overview Extending messaging security to a device
126