Windows Vista -Understanding Bitlocker Drive Encryption


Bitlocker Drive Encryption in Windows Vista


A very common threat to the security of Windows based systems have been offline attacks. Attacks that happen in order to steal the data from a system while the system is offline, or in the shutdown state, are termed as offline attacks.

The most likely victims of offline attacks are stolen laptops, or physically insecure systems. In case a laptop with Windows XP operating system protected with good password protection is stolen, the offline attack can be performed on this system by any of the following ways –

1.      By detaching the hard disk from the system, attaching it as a slave disk to another system for which the attacker has an administrative access on the primary disk

2.     By installing a fresh copy of another operating system on the available space on the existing hard disk, gaining administrative control on the new operating system (on drive d:), thereby gaining administrative access to drive c:, on which the original operating system with data is.

3.     By booting the system with a Linux or other bootable disks (floppies or CDs) and running tools in order to change the administrative password on c: partition.

Notice, that in any of the above mentioned scenarios, the attacker needs to change the boot configuration of the hard disk on which the operating system with data resides.

To combat all the above common threats to information security, Microsoft has introduced a new security feature in the upcoming Windows Vista operating system. This feature is basically a hardware provided feature that is enabled through the operating system.

The Trusted Computing Group (TCG) ( now ships various certified laptops with a hardware chip installed on the motherboard, known as the TPM (Trusted Platform Module). TPM version 1.2 enabled systems provides the ability to store keys, password and even cryptographic keys in the form of certificates on the installed TPM chip.

In a Windows Vista system, the administrator has the ability to turn on ‘Bit locker Drive Encryption’ form the Security section in the Control Panel.

Bitlocker Drive Encryption consists of two parts –

1.       Secure Startup

a.       Is used to protect the boot configuration of the system volume from any changes.

b.      When turned on, the process generates two types of keys –

                                                               i.      Startup Key – This key is created after encrypting the existing boot configuration of the system volume. It is created and stored on the TPM chip on the mother board, and is used to match the key generated after checking the boot configuration every time the system starts up. If the boot configuration remains unchanged, the key generated every time the system starts, matches the key stored inside the TPM and system starts without any prompts and the process is transparent to the user.

                                                             ii.      Recovery Key – This key is generated for the administrator to store at another location which may be a USB Flash disk, a network drive or the active directory profile of the user. This key is used when the boot configuration of the system volume is accidently changed after enabling secure startup. When the system starts up and generates the key for the new boot configuration, it will not match the key stored in the TPM chip as the boot configuration was changed. In this case, the system enters into the ‘Recovery Mode’ where it prompts the user for a recovery key. In case the user is an authorized one (and has not stolen this laptop), he must have the recovery key provided to him at the time of enabling secure startup. This is a long numerical key that can be entered on the system by using the F1-F10 keys for (1-0 respectively) during this time, or can be provided through the USB disk in which the recovery key was stored.


2.       Full Volume Encryption – This feature ensures that in case the attacker tries to mount this system as another volume using Linux operating system, or tires to access the system drive by making it a slave volume of another system, or by booting from another operating system volume in a dual boot system, he is not able to extract the data out of this volume. Once the Full Volume Encryption is enabled on the Windows Vista volume, it makes renders it incapable of being mounted through any other OS volume. Even in case of a dual boot system with Windows XP installed on drive C: and Windows Vista (with FVE enabled) on drive d:, and the attacker gains admin access to Windows Vista on drive c:, he will not be able to gain any access to data in drive d:. This happens because as soon as the attacker double-clicks drive d: to browse through it, he only gets a message box telling that the “drive is inaccessible. Do you want to format it now?”  So the only option he is left with is to format and reuse the drive which keeps the confidentiality of the data inside the Windows Vista system.



22 thoughts on “Windows Vista -Understanding Bitlocker Drive Encryption”

  1. Acer extensa 5210 battery Acer extensa 5220 battery Acer extensa 5620g battery Acer tm00741 battery Acer tm00751 battery Acer travelmate 5710 battery Acer travelmate 5720g battery Acer travelmate 7520g battery Asus a22-700 battery Asus a22-p701 battery Asus eee pc 1000 battery Asus eee pc 1000h battery Asus eee pc 701 battery Asus eee pc 900 battery Asus eee pc 901 battery Asus eee pc 904 battery Dell latitude d410 battery Dell latitude d420 battery Dell latitude d430 battery Dell latitude d610 battery Dell latitude d810 battery Dell vostro 1310 battery Dell vostro 1320 battery Dell vostro 1510 battery Dell vostro 1520 battery Dell vostro 2510 battery Hp f2024 battery Hp f2024a battery Hp f2024b battery Hp f2111 battery Hp pavilion dv2133 battery Hp pavilion dv3000 battery Hp pavilion dv3500 battery Hp pavilion n5130 battery Hp pavilion n5140 battery Hp pavilion n5150 battery Hp pavilion n5170 battery Hp pavilion n5190 battery Hp pavilion n5200 battery

  2. Ibm thinkpad r51 battery Ibm thinkpad t20 battery Ibm thinkpad t21 battery Ibm thinkpad t22 battery Ibm thinkpad t23 battery Ibm thinkpad t42 battery Ibm thinkpad t43 battery Ibm thinkpad x20 battery Ibm thinkpad x200 battery Ibm thinkpad x21 battery Ibm thinkpad x22 battery Ibm thinkpad x23 battery Ibm thinkpad X40 battery Ibm thinkpad x41 battery Ibm thinkpad x60 battery Ibm thinkpad x60s battery Ibm thinkpad z60t battery Ibm thinkpad z61t battery Msi bty-s11 battery Msi bty-s12 battery Msi wind u100 battery Msi wind u90 battery Sony pcga-bp2r battery Sony pcga-bpz51 battery Sony pcga-bpz51a battery Sony vgp-bpl5a battery Sony vgp-bps5 battery Sony vgp-bps5a battery Toshiba pa3123u-1brs battery Toshiba pa3178u-1bas battery Toshiba pa3178u-1brs battery Toshiba pa3211u-1bas battery Toshiba pa3211u-1brs battery Toshiba pa3479u-1brs battery Toshiba pa3480u-1brs battery Toshiba pa3591u-1bas battery Toshiba pa3634u-1bas battery Toshiba pa3635u-1bam battery Toshiba pa3635u-1brm battery Toshiba pa3638u-1bap battery Toshiba pabas117 battery Toshiba pabas118 battery hp 510 adapter hp 530 adapter

  3. Toshiba pa3285u-3brs Battery Asus a32-f3 Battery Asus f3 Battery Toshiba pa3285u-3bas Battery Dell d620 Adapter Acer as07b41 Battery Acer aspire 5500 Battery Acer aspire 9300 series Battery laptop ac adapter laptop ac adapters Apple a1185 Battery Apple a1185 black Battery Apple a1185 white Battery Asus a42-a4 Battery Asus a42-v6 Battery Clevo d400 Battery Clevo d470w Battery laptop battery laptop batteries Compaq dv4000 Battery Compaq dv6000 Battery Compaq dv6500 Battery Compaq presario v4000 Battery Dell 1501 Battery Dell 6400 Battery Dell d620 Battery Dell d630 Battery Dell d820 Battery Dell d830 Battery Dell e1505 Battery Dell gd761 Battery Dell gk479 Battery Dell inspiron 1000 Battery Dell inspiron 1520 Battery Dell inspiron 6400 Battery Dell inspiron 1521 Battery Dell inspiron 6400 Battery Dell inspiron 1720 Battery Dell inspiron 500m Battery Dell inspiron 6000 Battery Dell inspiron 9300 Battery Dell inspiron 9400 Battery Dell kd476 Battery Dell kr-onx511 Battery Dell latitude d620 Battery

  4. Dell latitude d630 Battery Dell latitude d810 Battery Dell latitude d820 Battery Dell latitude d830 Battery Dell vostro 1000 Battery Dell vostro 1500 Battery Dell vostro 1700 Battery Dell wr050 Battery Dell xps m1210 Battery Dell xps m1330 Battery Dell xps m140 Battery Dell xps m1530 Battery Dell xps m1730 Battery Hp 510 Battery Hp 530 Battery Hp dv2000 Battery Hp dv6000 Battery Hp dv6500 Battery Hp dv9000 Battery Sony vgp-bps2b Battery Toshiba pa3285u-1bas Battery Toshiba pa3285u-1brs Battery Sony vgp-bps5a Battery Toshiba pa3356u Battery Toshiba pa3356u-3bas Battery laptop battery laptop batteries Toshiba pa3399u-1bas Battery Toshiba pa3399u-1brs Battery Toshiba pa3399u-2bas Battery Toshiba pa3533u-1bas Battery Toshiba pa3533u-1brs Battery Toshiba pa3534u-1bas Battery Hp nc6100 Battery Hp nc6120 Battery Hp nc6200 Battery Hp nc6400 Battery Hp nc8230 Battery Hp nx6100 Battery Hp nx6120 Battery Hp pavilion dv2000 Battery Hp pavilion dv6000 Battery Hp pavilion tx2000 Battery Ibm thinkpad r60 Battery Ibm thinkpad t40 Battery Ibm thinkpad t42 Battery

Leave a Comment

Fill in your details below or click an icon to log in: Logo

You are commenting using your account. Log Out / Change )

Twitter picture

You are commenting using your Twitter account. Log Out / Change )

Facebook photo

You are commenting using your Facebook account. Log Out / Change )

Google+ photo

You are commenting using your Google+ account. Log Out / Change )

Connecting to %s