Windows Vista Forums
Vista Forums Home Join Vista Forums Donate Vista Tutorials Tags

Welcome to Vista Forums we are your forum to discuss Windows Vista x64 and x86 systems. Whether you need help or just want to post an idea you have on Vista, this is the forum for you.
Register at Vista forums...the world biggest Windows Vista resource Join Vista Forums Now

Go Back   Vista Forums > Vista Newsgroups > Vista security

BitLocker: SmartCard support?

Closed Thread
 
Thread Tools Display Modes
Old 07-10-2006   #1 (permalink)
=?Utf-8?B?dGF2aXM=?=
Guest


 

BitLocker: SmartCard support?

Will BitLocker ever support keys stored on Smartcards to encrypt the VMK?

This would be a more secure way to carry the startup key around than by USB,
since the .BEK file is simply a hidden file, easily copied if the USB key is
used to share everyday data.

(Note that Federal Agencies have HSPD-12 to contend with, and will be
adverse to managing both USB keys and PIV cards at the same time!)

It also provides a way to uniquely identify and account for startup on a
user-by-user basis, whereas currently there is only one startup key per
machine, so multiple users of one laptop must carry the same startup key.

It would seem that storing keys on someone's smartcard isn't a big deal,
until you realize what is necessary to track who has which startup key for
which laptop, scaled across the enterprise of laptops.

And could an actual audit log be securely managed in the pre-boot
environment, tracking who actually started up the machine and when, and
somehow making this log available to the event logs on the running OS?

I did notice some interesting things about manage-bde - I can actually make
several startup-key protectors for a single machine. For a multi-user
machine, this could be used to assign a different startup key to each user.
If one user no longer requires access to the machine, their key protector
metadata could be deleted, leaving the others unchanged. Seems like an
enterprise management nightmare, though...

Thanks!
Old 07-11-2006   #2 (permalink)
Jamie Hunter [MS]
Guest


 

Re: BitLocker: SmartCard support?

You are correct that Smart Cards is more ideal then a USB key. We have to
provide universal pre-boot Smart Card support (unlike specific 3rd party
solutions, we cannot have hard-coded support for a limited set of
providers), but we are working on this for a future version. You've
identified frequent requests, but there is a limit on what we can provide
for the first version.

The WMI interface is very rich in it's capabilities. I'm sure we'll see some
custom administration solutions coming out that takes advantage of it, such
as the multiple key support.

-
Jamie Hunter [MS]

"tavis" <tavis@discussions.microsoft.com> wrote in message
news:CA83F735-56EE-4FE9-91CE-C6B1DD06A5AD@microsoft.com...
> Will BitLocker ever support keys stored on Smartcards to encrypt the VMK?
>
> This would be a more secure way to carry the startup key around than by
> USB,
> since the .BEK file is simply a hidden file, easily copied if the USB key
> is
> used to share everyday data.
>
> (Note that Federal Agencies have HSPD-12 to contend with, and will be
> adverse to managing both USB keys and PIV cards at the same time!)
>
> It also provides a way to uniquely identify and account for startup on a
> user-by-user basis, whereas currently there is only one startup key per
> machine, so multiple users of one laptop must carry the same startup key.
>
> It would seem that storing keys on someone's smartcard isn't a big deal,
> until you realize what is necessary to track who has which startup key for
> which laptop, scaled across the enterprise of laptops.
>
> And could an actual audit log be securely managed in the pre-boot
> environment, tracking who actually started up the machine and when, and
> somehow making this log available to the event logs on the running OS?
>
> I did notice some interesting things about manage-bde - I can actually
> make
> several startup-key protectors for a single machine. For a multi-user
> machine, this could be used to assign a different startup key to each
> user.
> If one user no longer requires access to the machine, their key protector
> metadata could be deleted, leaving the others unchanged. Seems like an
> enterprise management nightmare, though...
>
> Thanks!


Closed Thread

Thread Tools
Display Modes


Similar Threads
Thread Thread Starter Forum Replies Last Post
Toshiba Tecra M5 BIOS support for Bitlocker in TPM mode? matthewj9 Vista security 6 02-08-2008 06:23 AM
Smartcard support in MS Windows Vista Vladimir Kiesner Vista security 3 02-19-2007 02:50 PM
Bitlocker and Smartcard authentification Detlev Rackow Vista security 2 01-23-2007 02:26 PM
EFS with Smartcard Lukas Dvorak Vista security 2 01-23-2007 02:11 PM
TPM support for bitlocker terrell Vista General 0 06-13-2006 12:25 PM








Vistax64.com is an independent web site and has not been authorized,
sponsored, or otherwise approved by Microsoft Corporation.
"Windows Vista", the Start Orb, and related materials are trademarks of Microsoft Corp.
© Designer Media 2005-2008

1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50