Component |
Infrastructure Required |
A single server can support these four components for 2000 smartphones: |
Enterprise Console
Compliance Service
Self-Service Portal
Device Management Gateway |
- Microsoft Windows 2003 Server Standard, SP1, .NET Framework Version 2.0
- IIS
- Dual CPU, at least 2.8GHZ, 4GB RAM, 10 GB free disk space
- One Ethernet Network Adaptor
|
Database |
Microsoft SQL Server 2000, SP4 |
EAS Access Manager |
Installed as a Plug-in on existing ISA Server or an ISAPI filter running on an Exchange 2003 Front-End Server. The following is required for ISA implementation:
- Microsoft ISA Server 2004 Enterprise / 2006 Enterprise
- Microsoft Windows Server 2003 Standard, SP1, .NET Framework Version 2.0
- Dual CPU, at least 2.8GHZ, 2GB RAM, 250MB free disk space
- Two Network Adaptors: Corporate LAN & Carrier Data Network (via Internet)
|
Smartphone Security Client |
Provisioning, Remediation and EAS Synchronization over Cellular Carrier Data Network for many popular smartphones.
- Palm OS® 5.x
- Windows Mobile® 5
- Windows Mobile® 6
|
On-Device Security:
- Real-time enforcement of device/configuration settings and user authentication
- Real-time, on-the-fly data encryption of policy-specified files, databases, and removable media (e.g., SD cards)
- Transparent 7x24 data protection designed to minimize intrusiveness for end-users, reduce application and device latency, and optimize device battery life
- FIPS 140-2 certified encryption (AES128/196/256 and Triple DES)
- Policy controlled use of multi-media resources (including camera and voice recording)
- Policy controlled use of and/or encryption of SD cards and other removable media
- Policy controlled use of communication services including WiFi, Bluetooth®, infrared (IR) and SMS
Device & Application Management:
- Self-service, over-the-air (OTA) device registration and provisioning, as well as configuration and application access
- Device data deletion (data wipe) policies based on extended device inactivity, password failure thresholds, and OTA administrative actions
- Device software image locking that prevents applications from being installed or uninstalled—thereby improving compliance and reducing Help Desk headaches
- Application blacklisting that can block specific applications from being used (e.g., web browsers)
- Patent-pending “Trusted Application” architecture that prevents viruses, Trojan horses, etc., from accessing protected data
- Self-service portal for resetting forgotten passwords
Exchange ActiveSync Network Access Control:
- Microsoft Exchange synchronization with only registered, approved, and compliant devices
- Silent, OTA remediation of devices that do not meet current security policy requirements
Web-Based Enterprise Console:
- Policy, systems, and administrative management with Individualized administrative logins to Trust Digital Enterprise Console
- Group policy management that assigns specific Active Directory groups to particular on-device security policy
- Help Desk for decommissioning, remote unlock, remote wipe, and remote interactive diagnostics
- Reporting of device compliance status and Exchange Active Sync activity
Device Management:
- Automate OTA on-device security policy, software deployments, and updates—including third-party software