Key Management for Transcrypt

Total Page:16

File Type:pdf, Size:1020Kb

Key Management for Transcrypt Key Management for Transcrypt by Abhijit Bagri DEPARTMENT OF COMPUTER SCIENCE & ENGINEERING INDIAN INSTITUTE OF TECHNOLOGY, KANPUR May 2007 i Key Management for TransCrypt A Thesis Submitted in Partial Fulfillment of the Requirements for the Degree of Master of Technology by Abhijit Bagri to the DEPARTMENT OF COMPUTER SCIENCE & ENGINEERING INDIAN INSTITUTE OF TECHNOLOGY,KANPUR May 2007 ii CERTIFICATE It is certified that the work contained in the thesis entitled " Key Management for 1ran- sCrypt" by Abhijit Bagri has been carried out under my supervision and that this work has not been submitted elsewhere for a degree. Dr. Rajat Moona Dr. Dheeraj Sanghi Department of Computer Science Department of Computer Science & Engineering, & Engineering, Indian Institute of Technology Kanpur, Indian Institute of Technology Kanpur, Kanpur-208016. Kanpur-208016. iii Abstract With data storage and processing snowballing into a necessity from being an efficient part of any business process or organization, the need for securing storage at various degrees of granularity is gaining considerable interest. The challenge in designing an encrypted filesys- tem stems from balancing performance, security perception, ease of usage and enterprise level deployability. Often, the most secure solutions may not even be the best solution either due to hit on performance or due to decreased usability. Further, narrowing the trust circle to exclude even hitherto trusted system administrators makes creating an encrypted filesystem a huge engineering exercise. In this thesis, we talk about key management issues in TransCrypt[21], an encrypted file system design with smallest trust circle to the best of our knowledge. We provide an entire architecture with utilities like secure key stores, and their management through libraries in- side and outside the kernel space. We provide enhancement of kernel CryptoAPI to include asymmetric cryptography, filesystem and file metadata management tools, and a communi- cation framework to authenticate genuine users through user-space key stores. We present a design that incorporates modularity, flexibility while providing a transparently operational encrypted filesystem. iv Dedicated to My lovely niece, Pari v Acknowledgements I would like to express my gratitude to my thesis supervisors Dr Dheeraj Sanghi and Dr Rajat Moona, without whose able guidance this work would not have been possible. I thank Dr Manindra Agarwal for his insights in the project. I would like to thank all the people who have been a part of TransCrypt group - Mohan Dhawan, Satyam Sharma, Deeptanshu Shukla, V Bhanu Chandra, Arun Raghuraman and Sainath Vellal. Intense discussions during TransCrypt meetings with these people have been a great learning experience, besides being instrumental in the conceptualization and implementation of this work. I would also like to thank Prabhu Goel Research Centre for Computer and Internet Security for partially supporting my thesis and providing me with excellent facilities and a highly flexible and open environment. Any of my endeavours at IIT Kanpur would not have been possible without the support of my friends, especially my wingmates, who have made my stay at IIT Kanpur a memorable one. I thank them for being with me at all times. Finally, I would like to thank my parents and my family for their affection and encour- agement to succeed in all my ventures. 1 Contents 1 Introduction 1 1.1Motivation..................................... 1 1.2ScopeofthisWork................................. 2 1.3OrganizationofThesis............................... 2 1.4AbbreviationsandDefinitions........................... 3 2 Related Work 4 2.1ApproachestoDesigningEncryptingFilesystems................ 4 2.2SurveyofEncryptedFilesystems......................... 5 2.2.1 MicrosoftEFSforWindows........................ 6 2.2.2 Cryptoloopanddm-crypt......................... 6 2.2.3 Cryptfs................................... 7 2.2.4 eCryptfs................................... 8 2.2.5 NCryptfs.................................. 9 2.2.6 CryptographicFileSystem(CFS).................... 9 2.2.7 TransparentCryptographicFileSystem(TCFS)............ 10 2.2.8 BestCrypt.................................. 10 2.2.9 SteganographicFileSystems....................... 10 2.3Summary...................................... 11 3 TransCrypt Architecture 12 3.1TransCryptFeatures................................ 12 3.1.1 Per-fileEncryption,Per-userAccessControl............... 12 2 3.1.2 BlockLevelEncryption........................... 12 3.1.3 NovelCryptographyScheme........................ 13 3.1.4 MultipleTransparentAuthenticationOptions.............. 13 3.1.5 MinimumAdminTrust.......................... 14 3.1.6 DataRecoveryAgent........................... 14 3.1.7 Integrity................................... 14 3.2TheTransCryptArchitecture........................... 15 3.2.1 CryptographicMetadata.......................... 15 3.2.2 FilesystemCreation,Mounting...................... 15 3.2.3 Filelifecycle................................. 15 3.2.3.1 Creation............................. 15 3.2.3.2 Opening............................. 16 3.2.3.3 Read/Write............................ 16 3.2.3.4 ChangingPermissions...................... 16 3.2.4 UserSpaceModules............................ 17 3.3SecurityFramework................................ 18 3.3.1 Physical Access to the System . ..................... 18 3.3.2 SuperuserUnderMinimalTrust..................... 19 3.3.3 EnhancedSecuritythroughFSK..................... 19 3.3.4 Concurrent Access by Multiple Users . .............. 19 3.3.5 SecurePKS................................. 20 4 Kernel Crypto API 21 4.1TransCrypt’sCryptographicRequirementsintheKernel............ 21 4.2PKCS#1compliance................................ 22 4.2.1 EncryptionusingPublicKey....................... 23 4.2.1.1 Version1.5Padding....................... 23 4.2.1.2 OAEPPadding......................... 23 4.2.2 DecryptionusingPrivateKey....................... 25 4.2.2.1 DecodingVersion1.5Padding................. 25 3 4.2.2.2 DecodingOAEPpadding.................... 25 4.2.3 SigningUsingPrivateKey......................... 26 4.2.3.1 Version1.5Encoding...................... 26 4.2.3.2 PSSEncoding.......................... 27 4.2.4 VerificationUsingPublicKey....................... 29 4.2.4.1 VerificationforVersion1.5Encoding............. 29 4.2.4.2 VerificationforPSSEncoding................. 29 4.2.5 OptionsusedinPKCS#1Version2.1Implementation......... 30 4.2.5.1 MaskGeneratingFunction................... 31 4.3CryptoAPI..................................... 31 4.4KeyringInfrastructure............................... 32 5 Daemon and Private Key Store 33 5.1PKSOptions.................................... 33 5.1.1 ServicesOfferedbythePKS....................... 33 5.1.2 PKSLimitations.............................. 34 5.1.3 CandidatesforPKS............................ 34 5.2TransCryptDaemon................................ 35 5.3CommunicationProtocol.............................. 35 5.3.1 CommunicationInterfaces......................... 36 5.3.2 PacketHeaders............................... 37 5.3.3 Packet-StructureandHandling..................... 37 5.4ProtocolEnhancements.............................. 41 6 Putting Things Together 44 6.1ACLBasedChanges................................ 44 6.2ChangesintheSuperblock............................. 45 6.2.1 Utility for Filesystem Creation . ..................... 46 6.2.2 Filesystem Mounting Utility . ..................... 47 6.3ModificationsintheKernel............................ 47 6.3.1 Mounting.................................. 47 4 6.3.2 FileCreation................................ 48 6.3.3 OpeningaFile............................... 49 6.3.4 Reading/WritingaFile.......................... 49 6.4UsingTransCrypt................................. 49 6.4.1 SettingUp................................. 49 6.4.2 CreatingaTransCryptPartitionandMounting............. 50 6.4.3 FileLifecycle................................ 50 7 Future Work and Conclusions 51 7.1FutureWork.................................... 51 7.2Conclusions..................................... 52 Bibliography 53 5 List of Figures 3.1 SchematicTransCryptArchitecture........................ 17 4.1 Schematic description of OAEP Encoding Scheme. lHash is hash of label L. PS is padding strong of zero octets. Figure adapted from [19] ............ 24 4.2 Schematic description of PSS encoding scheme. Figure from [19] ........ 28 5.1 TransCryptHeader................................. 38 5.2 TCPT PKT REPLY CERTPackets........................ 39 5.3 TCPT PKT EST SESSPacket........................... 40 5.4 TCPT PKT KEY ACQ and TCPT PKT KEY RESPPackets......... 41 5.5 CommunicationProtocolbetweenkernel,daemonandPKS........... 42 5.6 Unified Key Acquisition Packet, TCPT PKT ES KA and unified reply packet, TCPT PKT RESP KA............................... 43 1 Chapter 1 Introduction 1.1 Motivation Data security has become a very important issue with growing dependence on storage systems and increasing reliance on the internet for communication. Millions of dollars have been reported to be lost due to security breaches [16]. The key factors of interest for a deployment of a storage solution are security, performance and usability. Further, administering networks and storage over thousands of systems spread over em- ployees in companies with large headcounts is an increasingly difficult task. With growing number of outsourcing industries, such usage conditions are becoming very common. These industries
Recommended publications
  • Stackable File Systems As a Security Tool
    Stackable File Systems as a Security Tool Erez Zadok Computer Science Department, Columbia University [email protected] CUCS-036-99 Abstract Programmers often prefer to use existing system security services, such as file system security, rather than im- plement their own in an application. Traditional Unix security is generally considered inadequate and few operating systems offer enhanced security features such as ACLs[24] or immutable files[12]. Additional file system security features are always sought, but implementing them is a difficult task because modifying and porting existing file systems is costly or not possible. We advocate adding new security features using stackable file systems. As a starting point, we propose a portable, stackable template called the wrapper file system or Wrapfs, a minimal file system from which a wide range of file systems can be prototyped. A developer can modify a copy of the template and add only that which is necessary to achieve the desired functionality. The Wrapfs template takes care of kernel internals, freeing the developer from the details of operating system internals. Wrapfs imposes an overhead of only 5–7%. This paper describes the design, implementation, and porting of Wrapfs. We discuss several prototype file sys- tems written using Wrapfs that illustrate the ease with which security features can be implemented. The examples demonstrate security features such as encryption, access control, intrusion detection, intrusion avoidance, and analy- sis. 1 Introduction Security has become and integral part of computing in recent years. To provide the strongest possible security to users, security solutions sometimes consume a large amount of resources, and may inconvenience their users too much.
    [Show full text]
  • A Steganographic File System for the Linux Kernel
    A Steganographic File System for the Linux Kernel by Ashley Morgan Anderson The University of Exeter COM3401 Individual Project 11th August 2007 Abstract Encryption is all around us these days, yet the security of private data on home computers is overlooked by many. The presence of cipher-text — in some instances — can make things worse, therefore the only way to overcome this is to hide the data. The Ancient Greeks knew about this risk and as such fabricated some of the most ingenious methods of steganography ever used. However, steganography has come along way in the last 3000 years, and is more important today than ever before (due to tightening restrictions governing encryption). This paper looks at how different mediums have been used to ensure messages and data remain private, as well as proposing a new file system which takes care of hiding files for the user. Whilst not the first, it does include many unique features which are intended to provide a more natural interface. I certify that all material in this project which is not my own work has been identified. ...................................... A.M. Anderson Contents 1 Introduction 1 2 Background 2 2.1 Steganography . 2 2.2 File Systems . 4 2.3 Steganographic File Systems . 6 3 Design 11 3.1 Implemented Design . 11 3.2 Potential Driver Types . 13 3.3 Initial File System . 15 3.4 Encryption . 15 3.5 A Discarded Design . 16 4 Development 17 4.1 The Tools . 17 4.2 The Process . 18 5 Testing 19 5.1 Progressive . 19 5.2 Forensic Analysis .
    [Show full text]
  • Cryptographic File Systems Performance: What You Don't Know Can Hurt You Charles P
    Cryptographic File Systems Performance: What You Don't Know Can Hurt You Charles P. Wright, Jay Dave, and Erez Zadok Stony Brook University Appears in the proceedings of the 2003 IEEE Security In Storage Workshop (SISW 2003) Abstract interact with disks, caches, and a variety of other com- plex system components — all having a dramatic effect Securing data is more important than ever, yet cryp- on performance. tographic file systems still have not received wide use. In this paper we perform a real world performance One barrier to the adoption of cryptographic file systems comparison between several systems that are used is that the performance impact is assumed to be too high, to secure file systems on laptops, workstations, and but in fact is largely unknown. In this paper we first moderately-sized file servers. We also emphasize multi- survey available cryptographic file systems. Second, programming workloads, which are not often inves- we perform a performance comparison of a representa- tigated. Multi-programmed workloads are becoming tive set of the systems, emphasizing multiprogrammed more important even for single user machines, in which workloads. Third, we discuss interesting and counterin- Windowing systems are often used to run multiple appli- tuitive results. We show the overhead of cryptographic cations concurrently. We expect cryptographic file sys- file systems can be minimal for many real-world work- tems to become a commodity component of future oper- loads, and suggest potential improvements to existing ating systems. systems. We have observed not only general trends with We present results from a variety of benchmarks, an- each of the cryptographic file systems we compared but alyzing the behavior of file systems for metadata op- also anomalies based on complex interactions with the erations, raw I/O operations, and combined with CPU operating system, disks, CPUs, and ciphers.
    [Show full text]
  • Hello Marte OS Using an Emulator Daniel Sangorrin [email protected]
    Hello MaRTE OS using an emulator Daniel Sangorrin [email protected] 2009-3-4 Revision History Revision 1.3 2009-3-4 Revised by: dsl Add mtools for mounting the images. Update installation instructions referencing INSTALL file. Revision 1.2 2007-6-15 Revised by: dsl Added the process to create a FAT16 image file for QEMU Revision 1.1 2007-6-9 Revised by: dsl Updated to MaRTE OS v1.6 snapshot This document tries to introduce people to MaRTE OS in a very simple way. Table of Contents 1. Preface........................................................................................................................................................................2 1.1. Feedback.........................................................................................................................................................2 2. Let’s see MaRTE OS running!.................................................................................................................................2 2.1. Install the emulator QEMU............................................................................................................................2 2.2. ...and run these MaRTE OS Demos! ..............................................................................................................2 3. Hello MaRTE! ...........................................................................................................................................................3 3.1. The compiler GNAT-GPL ..............................................................................................................................3
    [Show full text]
  • Linux Based Live CD on Optical Disks
    Pobrane z czasopisma Annales AI- Informatica http://ai.annales.umcs.pl Data: 26/09/2021 15:23:08 Annales UMCS Annales UMCS Informatica AI 5 (2006) 29-36 Informatica Lublin-Polonia Sectio AI http://www.annales.umcs.lublin.pl/ Linux based Live CD on optical disks 1 2* Michał Chromiak , Andrzej Góźdź 1Institute of Mathematics, Maria Curie-Skłodowska University, Pl. M.Curie-Skłodowskiej 1, 20-031 Lublin, Poland 2Institute of Physics, Maria Curie-Skłodowska University, Pl. M.Curie-Skłodowskiej 1, 20-031 Lublin, Poland Abstract We present an introduction to LiveCD system remastering based on a prospective UnionFS filesystem. 1. Introduction Regarding increasing popularity of the LiveCD distributions1 of a Linux system we compile the essential knowledge of how the LiveCD works (based on many rather scattered documents [1-8]) to facilitate preparation of the specialized distributions of systems based on this idea. We describe one of the most efficient ways of system architecture managing using UnionFS. All steps of the procedure were tested using laptops which have often more exotic hardware than desktopUMCS computers. The possibility of booting a PC from a CD/DVD ROM has raised several possibilities, including the most important one, namely, the possibility of running the required system or programs independently of the actual operational system, configuration, and resources of the PC. The self-configuring CD/DVD ROMs can be also useful for administrative purposes and as the rescue disks. The LiveCD distributions allow for cheap and effective use of the PCs as the special servers, routers and other active elements over the network. This idea of the LiveCD systems is based on the possibility opened by the El Torito extension to the standard ISO 9660 system and the Linux kernel capabilities.
    [Show full text]
  • Comparison of Disk Encryption Software 1 Comparison of Disk Encryption Software
    Comparison of disk encryption software 1 Comparison of disk encryption software This is a technical feature comparison of different disk encryption software. Background information Name Developer First released Licensing Maintained? ArchiCrypt Live Softwaredevelopment Remus ArchiCrypt 1998 Proprietary Yes [1] BestCrypt Jetico 1993 Proprietary Yes BitArmor DataControl BitArmor Systems Inc. 2008-05 Proprietary Yes BitLocker Drive Encryption Microsoft 2006 Proprietary Yes Bloombase Keyparc Bloombase 2007 Proprietary Yes [2] CGD Roland C. Dowdeswell 2002-10-04 BSD Yes CenterTools DriveLock CenterTools 2008 Proprietary Yes [3][4][5] Check Point Full Disk Encryption Check Point Software Technologies Ltd 1999 Proprietary Yes [6] CrossCrypt Steven Scherrer 2004-02-10 GPL No Cryptainer Cypherix (Secure-Soft India) ? Proprietary Yes CryptArchiver WinEncrypt ? Proprietary Yes [7] cryptoloop ? 2003-07-02 GPL No cryptoMill SEAhawk Proprietary Yes Discryptor Cosect Ltd. 2008 Proprietary Yes DiskCryptor ntldr 2007 GPL Yes DISK Protect Becrypt Ltd 2001 Proprietary Yes [8] cryptsetup/dmsetup Christophe Saout 2004-03-11 GPL Yes [9] dm-crypt/LUKS Clemens Fruhwirth (LUKS) 2005-02-05 GPL Yes DriveCrypt SecurStar GmbH 2001 Proprietary Yes DriveSentry GoAnywhere 2 DriveSentry 2008 Proprietary Yes [10] E4M Paul Le Roux 1998-12-18 Open source No e-Capsule Private Safe EISST Ltd. 2005 Proprietary Yes Dustin Kirkland, Tyler Hicks, (formerly [11] eCryptfs 2005 GPL Yes Mike Halcrow) FileVault Apple Inc. 2003-10-24 Proprietary Yes FileVault 2 Apple Inc. 2011-7-20 Proprietary
    [Show full text]
  • Joseph Migga Kizza Fourth Edition
    Computer Communications and Networks Joseph Migga Kizza Guide to Computer Network Security Fourth Edition Computer Communications and Networks Series editor A.J. Sammes Centre for Forensic Computing Cranfield University, Shrivenham Campus Swindon, UK The Computer Communications and Networks series is a range of textbooks, monographs and handbooks. It sets out to provide students, researchers, and nonspecialists alike with a sure grounding in current knowledge, together with comprehensible access to the latest developments in computer communications and networking. Emphasis is placed on clear and explanatory styles that support a tutorial approach, so that even the most complex of topics is presented in a lucid and intelligible manner. More information about this series at http://www.springer.com/series/4198 Joseph Migga Kizza Guide to Computer Network Security Fourth Edition Joseph Migga Kizza University of Tennessee Chattanooga, TN, USA ISSN 1617-7975 ISSN 2197-8433 (electronic) Computer Communications and Networks ISBN 978-3-319-55605-5 ISBN 978-3-319-55606-2 (eBook) DOI 10.1007/978-3-319-55606-2 Library of Congress Control Number: 2017939601 # Springer-Verlag London 2009, 2013, 2015 # Springer International Publishing AG 2017 This work is subject to copyright. All rights are reserved by the Publisher, whether the whole or part of the material is concerned, specifically the rights of translation, reprinting, reuse of illustrations, recitation, broadcasting, reproduction on microfilms or in any other physical way, and transmission or information storage and retrieval, electronic adaptation, computer software, or by similar or dissimilar methodology now known or hereafter developed. The use of general descriptive names, registered names, trademarks, service marks, etc.
    [Show full text]
  • The DENX U-Boot and Linux Guide (DULG) for M28evk
    The DENX U-Boot and Linux Guide (DULG) for m28evk Table of contents: • 1. Abstract • 2. Introduction ♦ 2.1. Copyright ♦ 2.2. Disclaimer ♦ 2.3. Availability ♦ 2.4. Credits ♦ 2.5. Translations ♦ 2.6. Feedback ♦ 2.7. Conventions • 3. Embedded Linux Development Kit ♦ 3.1. ELDK Availability ♦ 3.2. ELDK Getting Help ♦ 3.3. Supported Host Systems ♦ 3.4. Supported Target Architectures ♦ 3.5. Installation ◊ 3.5.1. Product Packaging ◊ 3.5.2. Downloading the ELDK ◊ 3.5.3. Initial Installation ◊ 3.5.4. Installation and Removal of Individual Packages ◊ 3.5.5. Removal of the Entire Installation ♦ 3.6. Working with ELDK ◊ 3.6.1. Switching Between Multiple Installations ♦ 3.7. Mounting Target Components via NFS ♦ 3.8. Rebuilding ELDK Components ◊ 3.8.1. ELDK Source Distribution ◊ 3.8.2. Rebuilding Target Packages ◊ 3.8.3. Rebuilding ELDT Packages ♦ 3.9. ELDK Packages ◊ 3.9.1. List of ELDT Packages ◊ 3.9.2. List of Target Packages ♦ 3.10. Rebuilding the ELDK from Scratch ◊ 3.10.1. ELDK Build Process Overview ◊ 3.10.2. Setting Up ELDK Build Environment ◊ 3.10.3. build.sh Usage ◊ 3.10.4. Format of the cpkgs.lst and tpkgs.lst Files • 4. System Setup ♦ 4.1. Serial Console Access ♦ 4.2. Configuring the "cu" command ♦ 4.3. Configuring the "kermit" command ♦ 4.4. Using the "minicom" program ♦ 4.5. Permission Denied Problems ♦ 4.6. Configuration of a TFTP Server ♦ 4.7. Configuration of a BOOTP / DHCP Server ♦ 4.8. Configuring a NFS Server • 5. Das U-Boot ♦ 5.1. Current Versions ♦ 5.2.
    [Show full text]
  • Safezone Browser Download Cent Safezone Browser Download Cent
    safezone browser download cent Safezone browser download cent. NOT REGISTERED YET? RETRIEVE YOUR PERNUM FOR BETA TESTERS--> PLEASE ENTER YOUR REGISTERED EMAIL. Your PERNUM will be sent to your registered email account. REQUEST PASSWORD FOR BETA TESTERS--> PLEASE ENTER YOUR PERNUM. Your temporary password will be sent to your registered email account. RESET YOUR MASTER PIN FOR BETA TESTERS--> PLEASE ENTER YOUR REGISTERED EMAIL AND SAFEZONE PASSWORD. RESET YOUR MASTER PIN FOR BETA TESTERS--> YOUR REQUEST HAS BEEN RECEIVED. An email has been sent to our Support Team and they will contact you at your registered email for assistance. Please allow up to 48 hours for a response, emails are processed in the order they are received. SET UP YOUR MASTER PIN FOR BETA TESTERS--> PLEASE ENTER YOUR REGISTERED EMAIL AND SAFEZONE PASSWORD. SET UP YOUR MASTER PIN FOR BETA TESTERS--> Your SafeZone Pass is protected by two-step authentication. For every login process, or if you need to change your profile data, you need a one- time pin which has been randomly generated from your 6-digit Master Pin. SET UP YOUR MASTER PIN FOR BETA TESTERS--> Oops! There is already a Master PIN set up for this account. Please either login using your existing Master PIN or you may reset your Master PIN. SET UP YOUR MASTER PIN FOR BETA TESTERS--> Your Master Pin has been set up successfully! Let us test your first One-Time Pin, which is randomly generated from your Master Pin. Please enter the matching digits of your Master Pin: SafeZone APK. SafeZone app is only available at organizations using the SafeZone solution .
    [Show full text]
  • Bestcrypt Base User Manual
    BestCrypt Base User Manual Introduction • Introduction • BestCrypt Base Overview • HIPAA Compliance • Main Features 2 Introduction BestCrypt Base is an encryption software developed for small offices with local networks. Most offices do not usually have specially educated administrators to configure network, nor employees have experience of working with security software. BestCrypt Base has been designed to make the encryption process easy for everyone. Getting computers encrypted in a small business local network often becomes a challenge. On the one hand it is good if the encryption software has features of enterprise products such as central storage of recovery data and transparent encryption on users' computers. On the other hand, it would be better if central administration of encryption software for small offices were as simplified as possible. Ideally, a server should not be an expensive upmarket hardware, deployment should be simple, admin's console should be easy to use and require minimum attention. BestCrypt Base software combines features of encryption solutions for enterprise networks with interface simplicity of home software. There is a Key Server in the local network that helps in case of emergency and provides many of the functions proper to enterprise software. The Key Server may be a regular Windows computer or a cheap old computer without hard drive or/ and an operating system. How is it possible? Take a look at BestCrypt Base. It is a user-friendly software made to gurantee the security of your small business. See also: BestCrypt Base overview Main features 3 BestCrypt Base Overview The Introduction article states that BestCrypt Base is designed for small networks with computer users who are not specially trained as Network Administrators.
    [Show full text]
  • Bestcrypt Container Encryption User Manual
    BestCrypt Container Encryption User Manual Introduction • Why do you need BestCrypt? • Benefits of BestCrypt • BestCrypt Requirements • BestCrypt Specifications and Limitations 2 Why do you need BestCrypt? BestCrypt is oriented to a wide range of users. Whether you are in business and work with an accounts database, or you are a developer who is designing a new product, or you keep your private correspondence on your computer, you will appreciate a security system that restricts access to your data. With the advent of mass storage systems, a tremendous amount of information can be carried conveniently on even a small notebook computer. What happens to all this information if the computer is stolen at an airport? Suppose someone gains access to your computer without your knowledge. Do you know if your data has been copied and given to someone else? The main advantage of BestCrypt is that it is the most powerful, proven protection tool, based on cutting-edge technology, and available now for public use. Its mathematical basis was developed by outstanding scientists to keep all kinds of classified governmental documents and letters in deep secrecy. BestCrypt has a strong, built-in encryption scheme and contains no "backdoor". A "backdoor" is a feature that allows authorities with legal permission to bypass protection and to access data without the permission of the owner. Many commercial and government-certified systems contain backdoors, but not BestCrypt. The only way to access the data secured by BestCrypt is to have the correct password. 3 Benefits of BestCrypt Strong Security Once written to a BestCrypt file (container), data is never stored in an ‘open’ condition.
    [Show full text]
  • Guide to Computer Forensics and Investigations Fourth Edition
    Guide to Computer Forensics and Investigations Fourth Edition Chapter 6 Working with Windows and DOS Systems Objectives • Explain the purpose and structure of file systems • Describe Microsoft file structures • Explain the structure of New Technology File System (NTFS) disks • List some options for decrypting drives encrypted with whole disk encryption Guide to Computer Forensics and Investigations 2 Objectives (continued) • Explain how the Windows Registry works • Describe Microsoft startup tasks • Describe MS-DOS startup tasks • Explain the purpose of a virtual machine Guide to Computer Forensics and Investigations 3 Understanding File Systems • File system – Gives OS a road map to data on a disk • Type of file system an OS uses determines how data is stored on the disk • A file system is usually directly related to an OS • When you need to access a suspect’s computer to acquire or inspect data – You should be familiar with the computer’s platform Guide to Computer Forensics and Investigations 4 Understanding the Boot Sequence • Complementary Metal Oxide Semiconductor (CMOS) – Computer stores system configuration and date and time information in the CMOS • When power to the system is off • Basic Input/Output System (BIOS) – Contains programs that perform input and output at the hardware level Guide to Computer Forensics and Investigations 5 Understanding the Boot Sequence (continued) • Bootstrap process – Contained in ROM, tells the computer how to proceed – Displays the key or keys you press to open the CMOS setup screen • CMOS should
    [Show full text]