Professional Documents
Culture Documents
TABLE of CONTENTS
Section 1
ADMINISTRATORS OVERVIEW 1.0 Introduction 1.1 About This Guide iLANE 2.0 2.1 2.2 CONNECTIVITY iLane Components iLane Connections iLane and the Internet
3 3 3 5 5 5 8 9 9 9 11 11 11 12 13 15 15 15 16 16 17
Section 2
Section 3
iLANE SECURITY 3.0 Authentication 3.1 Encryption BLACKBERRY ENTERPRISE SERVER (BES) SETTINGS 4.0 iLane and BES: Introduction 4.1 Required IT Configurations / Policies 4.2 Using BES Application Control Policies 4.3 BlackBerry Settings for Your End Users MAINTAINING A SECURE ENVIRONMENT 5.0 iLane Installations and Upgrades 5.1 Controlling Bluetooth Access 5.2 iLane and Your Network 5.3 If an iLane is Lost or Stolen APPENDIX: TYPICAL BES SCREEN SHOTS
Section 4
Section 5
Section 6
Due to continuous advancements, all information is subject-to-change. Please consult my.ilane.com for revisions.
DOC-00047-01 (2-3-09)
ADMINISTRATORS OVERVIEW
SECTION
1.0 Introduction
This guide explains how network administrators and other IT professionals can prepare for adding iLane to a corporate email environment such as those operating under a BlackBerry Enterprise Server (BES). You will learn how iLane communications are managed and safely transported, both within a vehicle and beyond to the Internet. With a good understanding of a few basic IT policy requirements and recommendations for integrating iLane, you can help ensure successful setup of your iLane users.
ADMINISTRATORS OVERVIEW
DISCLAIMER
While every effort has been made to ensure that all information published and provided in support of iLane is accurate, complete and up-to-date, IMS can accept no liability for possible errors or omissions. Due to continuing research, please note that all iLane information is subject to change without notice.
COPYRIGHT NOTICE
No part of this guide or other IMS publications may be reproduced, transmitted, transcribed, stored in a retrieval system, or translated into any language in any form or by any means without prior written permission of IMS.
iLANE CONNECTIVITY
SECTION
(running iLane Platform firmware) the iLane headset the iLane Gateway software application installed on a users BlackBerry
A NOTE ABOUT BLUETOOTH COMPATIBILITY
The original iLane Platform firmware (v1.0.5) released in Fall 2008 is optimized for use with the iLane headset, the BlueAnt Z9i. As other compatible Bluetooth hands-free audio systems or Bluetooth-enabled vehicles complete testing and are verified for use with iLane, they are added to the Bluetooth Compatibility List at my.iLane.com. Please consult this list if you are interested in using your own Bluetooth audio device with iLane.
iLANE CONNECTIVITY
Since messages flow directly between iLane and the smartphone without passing through any additional servers, the driver receives iLane communications securely and without delay.
iLane Admin Guide
iLANE CONNECTIVITY
When the user first sets up their iLane system, the two Bluetooth wireless connections are established between 1) iLane and the users BlackBerry and 2) iLane and the iLane headset. In this pairing process, iLane is discoverable only by Bluetooth devices within range of the iLane transceiver. This pairing mode is possible only under certain conditions:
if you have a new iLane, or if you have done a Factory Reset on
As shown in Figure 1, all communications between iLane and the headset use the industry-standard Bluetooth Hands-Free Profile (HFP). This profile is also used for audio and call status exchanges between iLane and the BlackBerry.
THE SERIAL PORT PROFILE (BETWEEN iLANE AND THE BLACKBERRY ONLY)
As shown in Figure 1, a Bluetooth Serial Port Profile (SPP) is used between iLane and the BlackBerry. This additional profile enables the secure exchange of messages and other information which iLane reads aloud and manages using a voice-based interface. After authentication, AES-256 transport level encryption is applied to information within the SPP link. The BlackBerrys access to the SPP interface is established and controlled by the iLane Gateway application.
iLANE CONNECTIVITY
news and The Weather Network forecasts available with a paid iLane subscription
iLANE SECURITY
SECTION
3.0 Authentication
iLANE GATEWAY AUTHENTICATION
iLane Gateway, the software application installed on every iLane users BlackBerry, is a digitally signed and validated application. This status grants iLane Gateway access to the required RIMcontrolled APIs.
BLACKBERRY AUTHENTICATION
Every iLane users BlackBerry is associated with a registered iLane account on my.iLane.com. This association is based on the email address and phone number configured on the BlackBerry. The manager of an iLane account can approve or deny the use of specific email addresses and phone numbers with a given iLane.
iLANE DEVICE AUTHENTICATION
Public key cryptography with device-unique key pairs authenticates each iLane device. This approach ensures that all access to iLane Gateway is controlled through the Bluetooth SPP link. Any device lacking the complementary portion of the asymmetric key cannot use the SPP link to reach iLane Gateway on the smartphone.
3.1 Encryption
During any iLane session, two secure tunnels prevent eavesdroppingone tunnel is between iLane and the smartphone, and one is between iLane and the my.iLane.com server. Each tunnel is authenticated using RSA and encrypted using AES256, and does not rely on existing Bluetooth encryption.
This section specifies how to configure your BES policies for successful iLane setup and/or operation. See also Section 6, Appendix.
11
BLUETOOTH (IT)
Enable Bluetooth
Bluetooth technology is used for communications between iLane and the smartphone.
Enable pairing
As part of the iLane setup procedure, the smartphone must be paired to iLane. This establishes the secure Bluetooth link between the two devices.
12
See also 5.1, Controlling Bluetooth Access on page 15 for an example of how application control policies are used.
13
CONNECTIONS
Enable Bluetooth
Bluetooth technology is used for communications between iLane and the smartphone.
USER DATA
14
This section describes general security parameters over the life of iLane.
15
16
This section repeats the required BES settings as discussed in Section 4, but with the typical text you will likely see.
NOTE: Your text, displays and prompts may not be exactly as shown.
17
18
2009 Intelligent Mechatronic Systems Inc. All rights reserved. iLane and its related marks, logos, slogans, images and symbols are the exclusive property and trademarks of Intelligent Mechatronic Systems Inc. Patents Pending. Intelligent Mechatronic Systems Inc. 161 Roger Street Waterloo, ON N2J 1B1 Canada TECHNICAL SUPPORT: help@iLane.com 1-866-818-6637 GENERAL INQUIRIES: iLane@intellimec.com
www.iLane.com
Bluetooth is a registered trademark of Bluetooth SIG, Inc.