Závěrečná práce: Guruprasad Bidare Venkatesh: Bitlocker Full Disk Encryption
Diplomová práce
Bitlocker Full Disk Encryption
Anotace
V současném moderním světě informační éry, informační bezpečnosti hraje zásadní roli při ochraně důvěrnosti citlivých osob informace. Bezpečnost informací hraje důležitou roli při zajišťování informací jako schopnosti útoku a protivníka se v průběhu let značně zvýšily. Bezpečnost jakýkoli informační systém může být klasifikován jako bezpečnost během komunikace / doprava, bezpečnost při zpracování a …více
Abstract
In the current modern world of information era, Information security plays a vital role in protecting the confidentiality of the sensitive information. The information security has a major role to play in securing the information as the attack surface and adversary capabilities have increased enormously over the years. The security of any information system can be classified as security during communication …více
Klíčová slova
Storage Security BitLocker Full Disk Encryption (FDE) Self Encrypting Drives (SED) threat model attacks Authentication Key Management Opal standard open source tool. • Storage Security Storage security is a branch of security technology which aims at providing security to data at rest. • Full Disk Encryption FDE Full Disk Encryption (FDE) is the technology to encrypt the entire disk content including the Operating System partition. • Self Encrypting Drives SED Self Encrypting Drives (SEDs) are special type of hard drives with in-built hardware based encryption module. • Trusted Computing Group TCG TCG is the international technical forum formulating the specifications for storage security technology. • Opal Opal is the storage security specification for SEDs to provide security for data at rest formulated by TCG. • BitLocker The BitLocker is a software tool fromWindows Operating System to provide the storage security for data in hard drives/Removable Drives. • Serial Advanced Technology Attachment SATA SATA is the high speed serial communication technology to connect a hard drive with a Central Processing Unit (CPU) of a system. • Symmetric Encryption A type of encryption where in the same key will used for encryption and decryption and pre-shared between sender and receiver. v • Block Modes of encryption -Atype of encryption where in source data is encrypted in terms of blocks of bits viz. 128bits 256bit or 512bits etc . • Cipher Block Chain Mode CBC mode A type of encryption mode wherein encryption of current block of plain text depends on the previous cipher text block . The first block of plain text will be encrypted using a prefixed InitializationVector (IV) bits. • Xor-encrypt-xor (XEX) A type of tweakable encryption mode for disk encryption wherein a combination of the sector address and index of the block within the sector are used for encryption. • XEX-based tweaked-code book mode with cipher text stealing (XTS) Cipher text stealing provides XEX support for sectors with size not divisible by block size for example 520-byte sectors and 16-byte blocks. • CBC XTS A type of encryption mode which is a combination of CBC encryption mode with XTS features. • Basic Input Output System (BIOS) BIOS is a program running from a non-volatile memory responsible for initializing the system hardware and providing its essential interface to Operating System. • Unified Extensible Firmware Interface (UEFI) UEFI is an advanced version of BIOS which supports more number of peripherals provides option of dynamic programming through external interface with user friendly graphical features.Zadání práce
Study and describe Bitlocker Full Disk Encryption (FDE) and hardware-based self-encrypting drives (SED). [4,5]
Study and analyse existing and legacy Bitlocker options (system encryption, Bitlocker on Go, eDrive).
Describe the Bitlocker authentication process and key management in Windows 10. [7,8,9]
Investigate possibility to use self-encrypting drives supporting the OPAL standard [3] with Windows (Bitlocker eDrive). [1,2]
Define threat models and attacks to disk encryption in the Bitlocker and Bitlocker eDrive context. [4,5,6]
Evaluate open-source tool that enable access to the Bitlocker drive format on Linux (or Windows). If possible, try to improve the tool (Windows 10 compatibility, etc).
Thesis outcomes will include:
- description of Bitlocker architecture and key management,
- practical experiment with Bitlocker eDrive (SED),
- definitions of threat models for deploying disk encryption,
- evaluation of open-source tool for Bitlocker access.
14. 12. 2017 22:23, Ing. Milan Brož, Ph.D., učo 168968
- Zadáno/změněno 5. 2. 2018 16:01, Helena Kryštofová
- Záznam založen 21. 11. 2017 13:47, Jana Zemanová, učo 9619
- Zveřejnit od 14. 12. 2017 10:01, Helena Kryštofová
- Práce převzata 14. 12. 2017 10:01, Helena Kryštofová
Práce na příbuzné téma
Seznam prací, které mají shodná klíčová slova.
-
Authenticated and Resilient Disk Encryption
Ing. Milan Brož, Ph.D., učo 168968 -
Security analysis of passwords and keys managers
Mgr. Matúš Dugáček -
Perspektivní prostředky pro elektronické bankovnictví
Ing. JUDr. Pavla Hnilicová -
Metody kontroly a omezení přístupu k ICT v knihovnách
Mgr. Lucie Májková -
Zneužívání internetového bankovnictví: mediální analýza
Mgr. Anna Růžičková -
Geo-spatial data security in distributed environment
Rajesh Kumar -
Oko jako biometrický identifikátor
Ing. Hung Son Ha Trinh -
E-government a jeho ústavní aspekty
Mgr. Dominik Ullman




