
BitLocker Drive Encryption Overview
Windows BitLocker BitLocker Drive Encryption is a full disk encryption feature included with Microsoft's Windows 7 Ultimate, Windows Vista Ultimate, Windows Vista Enterprise, Windows Server 2008 and Windows 7 Ultimate Beta operating systems.
Drive encryption protects data by preventing unauthorized users from breaking Windows file and system protection on lost, stolen or inappropriately decommissioned computers. This protection is achieved by encrypting the entire Windows volume; with BitLocker all user and system files are encrypted including the swap and hibernation files. Windows BitLocker Drive Encryption supports 128-bit and 256-bit encryption keys. In addition, BitLocker supports a Diffuser algorithm to help protect the system against ciphertext manipulation attacks, a class of attacks in which changes are made to the encrypted data in an attempt to discover patterns or weaknesses. You can read the white paper on the Elephant Diffuser algorithm here.
A Trusted Platform Module (TPM) is a microchip that is built into a computer. It is used to store cryptographic information, such as encryption keys. Information stored on the TPM can be more secure from external software attacks and physical theft.
BitLocker uses the TPM to help protect the Windows operating system and user data and helps to ensure that a computer is not tampered with, even if it is left unattended, lost, or stolen.
BitLocker can also be used without a TPM. To use BitLocker on a computer without a TPM, you must change the default behavior of the BitLocker setup wizard by using Group Policy, or configure BitLocker by using a script (See below). When BitLocker is used without a TPM, the required encryption keys are stored on a USB flash drive that must be presented to unlock the data stored on a volume.
Your data is protected by encrypting the entire Windows operating system volume.
If the computer is equipped with a compatible TPM, BitLocker uses the TPM to lock the encryption keys that protect the data. As a result, the keys cannot
be accessed until the TPM has verified the state of the computer. Encrypting the entire volume protects all of the data, including the operating system itself, the Windows registry, temporary files, and the hibernation file. Because the keys needed to decrypt data remain locked by the TPM, an attacker cannot read the data just by removing your hard disk and installing it in another computer.
During the startup process, the TPM releases the key that unlocks the encrypted partition only after comparing a hash of important operating system configuration values with a snapshot taken earlier. This verifies the integrity of the Windows startup process. The key is not released if the TPM detects that your Windows installation has been tampered with.
By default, the BitLocker setup wizard is configured to work seamlessly with the TPM. An administrator can use Group Policy or a script to enable additional features and options.
For enhanced security, you can combine the use of a TPM with either a PIN entered by the user or a startup key stored on a USB flash drive.
On computers without a compatible TPM, BitLocker can provide encryption, but not the added security of locking keys with the TPM. In this case, the user is required to create a startup key that is stored on a USB flash drive.
FREE ALTERNATIVE TO BITLOCKER BUY WINDOWS VISTA BUY WINDOWS 7
|
|
This method is for using Bitlocker without a TPM supported motherboard. Follow the steps below to enable Bitlocker with a USB dongle which will act as
your key for decrypting the chosen encrypted hardrives.
1. Click on the Start Button and key in gpedit.msc in the search box and hit Enter.
2. Navigate through: Computer Policy, Administrative Templates, Windows Components and BitLocker Drive Encryption.
3. Right click on Control Panel Setup: Enable advanced startup options and select Properties.
4. checkbox ALLOW BITLOCKER WITHOUT A COMPATIBLE TPM
5. Dropdownbox, REQUIRE STARTUP KEY WITH TPM
6. REQUIRE STARTUP PIN with TPM (for extra security)
7. Click: NEXT SETTING
8. Configure encryption method: ENABLED
9. Drop down: AES 256bit with Diffuser (highest security)
10. NEXT SETTING
11. Prevent memory overwrite on restart: DISABLED
12. NEXT SETTING
13. Configure TPM platform validation profile: NOT USED IF YOU HAVE NO TPM
14. APPLY
15. Click the start button, control panel, security, Bitlocker Drive Encryption (will take time to load)
16. Turn on bitlocker for your harddrives you wish to encrypt.
17. You will be asked to use a USB flash drive to store your encrytion key. This will require
you to have the USB key inserted in a USB port every time you start up your computer.
DO NOT LOOSE IT, KEEP IT SECURE! DO NOT LET IT GET INTO THE WRONG HANDS.