Difference between revisions of "BitLocker Disk Encryption"
From Forensics Wiki
(New page: BitLocker, introduced with Microsoft's Windows Vista, is a program for full volume encryption. == Indicator == Drives protected with BitLocker will have a different signature t...) |
m (double "they have") |
||
| (5 intermediate revisions by 2 users not shown) | |||
| Line 1: | Line 1: | ||
| − | BitLocker | + | BitLocker is a [[Microsoft]] [[Full Volume Encryption]] solution first included with the Enterprise and Ultimate editions of [[Windows|Windows Vista]]. |
== Indicator == | == Indicator == | ||
| − | Drives protected with BitLocker will have a different signature than the standard [[NTFS]] header. Instead, they have in their first sector | + | Drives protected with BitLocker will have a different signature than the standard [[NTFS]] header. Instead, they have in their first sector: <pre>EB 52 90 2D 46 56 45 2D 46 53 2D</pre> or, in ASCII, <pre>eR -FVE-FS-</pre> |
== Algorithm == | == Algorithm == | ||
The program uses either 128 or 256 [[AES]] with an elephant diffuser. See the links section for full details. | The program uses either 128 or 256 [[AES]] with an elephant diffuser. See the links section for full details. | ||
| + | |||
| + | == Recovery Keys == | ||
| + | |||
| + | == See Also == | ||
| + | [[Defeating Whole Disk Encryption]] | ||
== External Links == | == External Links == | ||
| + | * Conducting forensic analysis on BitLocker protected volumes was discussed in the paper [http://jessekornblum.com/research/papers/bitlocker.pdf Implementing BitLocker for Forensic Analysis]. | ||
* [http://en.wikipedia.org/wiki/BitLocker_Drive_Encryption Wikipedia entry on BitLocker] | * [http://en.wikipedia.org/wiki/BitLocker_Drive_Encryption Wikipedia entry on BitLocker] | ||
* [http://technet2.microsoft.com/WindowsVista/en/library/c61f2a12-8ae6-4957-b031-97b4d762cf311033.mspx?mfr=true Microsoft's Step by Step Guide] | * [http://technet2.microsoft.com/WindowsVista/en/library/c61f2a12-8ae6-4957-b031-97b4d762cf311033.mspx?mfr=true Microsoft's Step by Step Guide] | ||
Revision as of 13:11, 17 September 2008
BitLocker is a Microsoft Full Volume Encryption solution first included with the Enterprise and Ultimate editions of Windows Vista.
Contents |
Indicator
Drives protected with BitLocker will have a different signature than the standard NTFS header. Instead, they have in their first sector:EB 52 90 2D 46 56 45 2D 46 53 2Dor, in ASCII,
eR -FVE-FS-
Algorithm
The program uses either 128 or 256 AES with an elephant diffuser. See the links section for full details.
Recovery Keys
See Also
Defeating Whole Disk Encryption
External Links
- Conducting forensic analysis on BitLocker protected volumes was discussed in the paper Implementing BitLocker for Forensic Analysis.
- Wikipedia entry on BitLocker
- Microsoft's Step by Step Guide
- Microsoft Technical Overview
- Microsoft FAQ
- Microsoft Description of the Encryption Algorithm