Data at rest on the mobile device is encrypted by using a digest of the PIN as the encryption key. There are four locations in the MEP client library where encryption and decryption must occur. In these locations, the MEP library will invoke encrypt/decrypt callback methods that perform the tasks.