Windows IT Pro is the authoritative and independent resource for windows nt, windows 2000, windows 2003, windows xp. Features a collection of resources and magazines for windows IT professionals.
  
  
  Advanced Search 


June 2007

Vista's BitLocker Drive Encryption

Lock down your data when you shut down your laptop
RSS
Subscribe to Windows IT Pro | See More Security Articles Here | Reprints | Or get the Monthly Online Pass—only $5.95 a month!

One of the key themes of Windows Vista is security. An important Vista security feature is the enhanced protection against malware through the new Microsoft Internet Explorer (IE) phishing filter and the newly built-in spyware scanner Windows Defender and Malicious Software Removal Tool (MSRT). Equally important is the brand new architecture for better honoring the principle of least privilege —the Vista feature referred to as User Account Control (UAC).

Another key Vista security feature is BitLocker Drive Encryption (BDE). Before I explain how BDE works, let me tell you how your organization can benefit from BDE. Be aware that BDE is available only in the Vista Enterprise and Vista Ultimate editions.

What BDE Can Do
BDE can better isolate the data on your Windows client computers and protect it from theft when the clients are offline (i.e., when the OS is shut down). Despite the BitLocker Drive Encryption name, BDE ensures that all the data on the volume is in an encrypted state when the Vista system is powered off. As such, BDE offers protection against the theft of the confidential corporate data that employees often carry around on their laptop computers.

It’s important to stress that BDE offers only offline protection:When someone gains online (local or network) access to a BDE-protected volume and the OS authorizes that person or process to access the data, data is transparently decrypted and unprotected as needed by the user or process. BDE nicely complements the other data protection and encryption technologies Microsoft offers:Encrypting File System (EFS) and Rights Management Services (RMS). Enterprises that want encrypted file sharing should look at EFS, which is bundled with Windows 2000 and later OS versions and has been significantly enhanced in Vista. Enterprises that want permanent protection and encryption of data, even when the data is removed from a protected volume (BDE) or folder (EFS) and attached to, for example, a Microsoft Outlook email message, must look at RMS —the RMS client is also bundled with Vista.

Because BDE uses a filter driver for encrypting and decrypting data (after the initial encryption), BDE has a minimal impact on system performance. During my lab tests, I noticed a 10 to 15 percent performance hit on my BDE-enabled Vista system. Initial BDE encryption takes about 1 minute per gigabyte on an average Vista computer system (Intel Pentium 4 with 1GB of memory).

BDE protection for a Windows volume is never enabled by default and must always be turned on manually. Also, BDE not only protects a volume’s user data and Windows system files but also the hibernation file, the page file, and the temporary files. In the initial Vista release, only the system boot volume can be BDE-protected. At the time of writing, Microsoft planned to support BDE protection of different volumes in the upcoming Vista Service Pack 1 (SP1) and Windows Longhorn Server.

BDE also makes the OS itself more resilient in the face of attacks. BDE includes a file integrity checking feature that automatically assesses the status of boot files such as the BIOS, Master Boot Records (MBRs), and the NTFS boot sector when the system boots and before the OS starts. If a hacker has inserted malicious code in one of the boot files or has modified one of them, BDE will detect it and block the OS from starting. Microsoft refers to this feature as the static root of trust measurement for early boot components. This feature is available only on computer systems that have a Trusted Platform Module (TPM)1. 2 chip —a special security chip that I explain in more detail below. BDE also provides a recovery mechanism that allows selected administrators to regain access to the encrypted BDE volume when the OS can’t start due to a boot file integrity error.

BDE can also offer pre-OS multifactor authentication. Before Vista starts, BDE can prompt users to authenticate by providing a secret that’s stored on a USB token and/or by entering a PIN. Preboot authentication protects Windows from attacks that attempt to bypass OS-level access checks and get to the data on a Windows-protected volume by booting from a Linux CD-ROM or floppy disk.

Finally, though this isn’t the most compelling reason for using BDE —BDE can speed up the process of decommissioning computers. Enterprises often invest considerable time and effort in erasing old computers’ hard disks. . But you need only erase the BDE decryption keys on a BDE-protected volume to make the data completely useless.

Before we go further, I want to remind you that BDE isn’ t available in all Vista versions. It’s only included in the Vista Enterprise and Vista Ultimate editions —the two versions that target high-end home and business users. For a good overview of the different Vista editions and their features, have a look at http://www.microsoft.com/windowsvista/getready/editions/default.mspx. To write this article, I used the release to manufacturing (RTM)version of Vista Ultimate.

How BDE Works
BDE is a hybrid cryptographic application that combines the functions and features of several cryptographic primitives. BDE uses a symmetric encryption scheme for encrypting BDE-protected volumes and digital signature technology to check the integrity of the boot files.

Figure 1 shows the BDE architecture and operation. The encrypted symmetric encryption key (also referred to as the Full Volume Encryption Key —FVEK)and the boot files are stored on a special system volume. BDE can access the symmetric encryption key and thus decrypt the BDE-protected volume only if the user can provide a valid PIN or other secret that ’s stored on a USB token or TPM chip at system startup. (Remember the pre-OS authentication I mentioned above.)

   Previous  [1]  2  3  Next 


Reader Comments

You must log on before posting a comment.

If you don't have a username & password, please register now.




Top Viewed ArticlesView all articles
Friday at PASS Europe 2006

Kevin talks about the closing day of the event and shares a funny Microsoft film. ...

Windows Mobile: What Went Wrong?

Paul discusses the evolution of Windows Mobile and why he thinks the platform is probably doomed. ...

More fun TechEd 2005 Resources

Kevin points out some more TechEd resources ...


Related Articles What You Need to Know About Windows Vista SP1

Security Whitepapers Protecting (You and) Your Data with Exchange Server 2007

Extended Validation SSL Certificates

Unauthorized applications: Taking back control

Related Events Check out our list of Free Email Newsletters!

Security eBooks Spam Fighting and Email Security for the 21st Century

Understanding and Leveraging Code Signing Technologies

A Guide to Windows Certification and Public Keys

Related Security Resources Become a VIP member of the Windows IT Pro community!
Get it all with the VIP CD and VIP access. A $500+ value for only $279!

Subscribe to Windows IT Pro!
Solve your toughest technical problems with our experts and access 10,000 + articles online. 30% off

Monthly Online Pass - Only $5.95!
Get instant access to 10,000+ articles from Windows IT Pro Magazine!

TechNet Virtual Labs
Evaluate and test Microsoft's newest products.

Job Openings in IT


ADS BY GOOGLE SPONSORED LINKS FEATURED LINKS

Microsoft Exchange & Windows Connections event returns to Las Vegas Nov 10 - 13
Connections returns to Las Vegas for this exciting event where each attendee will receive SQL Server 2008 standard with 1 CAL. Co-located with Microsoft ASP.NET, SQL Server, and SharePoint Connections with over 250 in-depth sessions.

Free Online Event! Virtualization:Get the Facts!
Register now and attend this free, live in-depth online conference on November 13 and 20, 2008, produced by Windows IT Pro. All registrants are eligible to receive a complimentary one-year digital subscription to Windows IT Pro (a $49.95 value)!

Check Out Hyper-V Video on ITTV
Watch Karen Forster's interview on Hyper-V's performance on ITTV.net.

Ease Your Scripting Pains with the Flexibility of PowerShell!
Join MVP Paul Robichaux on December 11, 2008 at 11:00 AM EDT as he equips you with PowerShell basics in 3 introductory lessons, each followed by a live Q&A session—all on your own computer!

PASS Community Summit 2008 in Seattle on Nov 18-21
The don’t-miss event for Microsoft SQL Server Professionals. Register now and you’ll enjoy top-notch Microsoft and Community speakers and more.



Solving PST Management Problems
In this white paper, read about the top PST issues and how to administer local/network PST Files.

Get Protected -- Data Protection Manager 2007
Protect your virtualized environment with Data Protection Manager

Order Your SQL Fundamentals CD Today!
Learn how to use SQL Server, understand Office integration techniques and dive into the essentials of SQL Express and Visual Basic with this free SQL Fundamentals CD.
Windows IT Pro Home Register FAQ for Windows WinInfo News
Europe Edition About Us Contact Us/Customer Service Media Kit Affiliates / Licensing  
SQL Server Magazine Office & SharePoint Pro Windows Dev Pro IT Job Hound ITTV
IT Library Technology Resource Directory Connected Home Windows Excavator Windows SuperSite 
 
 Windows IT Pro is a Division of Penton Media Inc.
 Copyright © 2008 Penton Media, Inc., All rights reserved. Terms and Use | Privacy Statement | Reprints and Licensing