16 oct. 2007

Cryptographie Matériel : X-Wall® LX

X-Wall® LX Protect Your Data; Safeguard Your Privacy
Product Overview

The X-Wall LX ASIC ensures privacy and confidentiality of data and credentials stored on hard drives without degrading system performance. A cryptographic system-controller ASIC operating at the physical layer, the X-Wall LX microchip performs “real-time” encryption of the entire hard disk (including the boot sector and operating system) at 1.6 Giga bit per second using Federal Government certified DES/TDES algorithms. In contrast to software solutions, no password is ever stored on the hard drive or held in machine memory. X-Wall's unique design also completely eliminates any dependency on operating systems or device drivers while functioning automatically and transparently, thereby eliminating user intervention.

Key Features
- Automatic transparent encryption guarantees user acceptance and enforces compliance with security policies
- Real-time encryption at 1.6Gbit/sec maintains full system performance
- Government-certified DES and TDES algorithms assure high level security
- Encryption key lengths from 40-bit to 192-bit
- Compatible with all IDE hard drives
- Compatible with all operating system and requiring no additional device drivers
- Small form factor with low power consumption (<>
Description
The X-Wall® LX chip resides between the IDE host controller and the IDE hard drive. Incorporating both a host and target interface for IDE Ultra DMA drives, X-Wall® LX acts as a host controller to the hard drive and as a hard drive to the controller. X-Wall® LX intercepts and translates IDE commands and encrypts all data in real-time. All data written to the hard drive, including the boot sector, operating system, temp and swap files, is automatically and transparently encrypted. Attempts to circumvent security by booting from a floppy disk or by removing the hard drive to be read on a different machine would prove futile since the entire content of the hard drive is encrypted.
Operation
The X-Wall Secure Key stores and protects the "Secret key" used by the X-Wall® microchip to encrypt data. The correct X-Wall Secure Key must be inserted into the special key socket (present on X-Wall® finished products) at system boot up to authenticate the user and authorize the operating system to load before granting access to data stored on the hard drive.
Don't like the Secure Key?
We understand you might have preference over using other authentication devices for authentication. Attempt to replace the external key token is possible with some level of system engineering efforts. Please note, the current X-Wall SE/LX version has a hardwired interface which communicates directly to the external key token upon boot up. One can easily emulate the interface (protocol) such that BIOS PIN/Password and/or any other third party authentication device makers such as Smartcard or Fingerprint can function with X-Wall SE/LX to replace the external key token. Please contact us for an in depth engineering architecture.
Product List
X-Wall® Encryption Strength NIST & CSE Certified 100% hardware Cipher Engine Maximum Throughput Ultra ATA hard disk support Ultra ATA hard disk compliance Protocol & Interface support up to Package
LX-40 40-bit DES 1.6Gbit/sec > 137GB 66,100,133 ATA 6,Mode 6 transfer 128-pin LQFP
LX-64 64-bit DES 1.6Gbit/sec > 137GB 66,100,133 ATA 6,Mode 6 transfer 128-pin LQFP
LX-128 128-bit TDES 1.6Gbit/sec > 137GB 66,100,133 ATA 6,Mode 6 transfer 128-pin LQFP
LX-192 192-bit TDES 1.6Gbit/sec > 137GB 66,100,133 ATA 6,Mode 6 transfer 128-pin LQFP
Specifications
- Compatible with all operating systems including MS Windows, Mac OS, Linux, BSD, Unix, SCO Unix and Solaris - 1.6 Giga bit per second throughput - Encryption key lengths vary by chip model from 40-bit to 192-bit. All chips are pin to pin compatible - Compatible with all Ultra DMA 66/100/133 hard drives - Compatible with all motherboards with standard IDE interface - 128-pin LQFP small form factor package - All four (4) chips are pin to pin compatible - Dimensions: 14x14mm, 1.4mm thickness - Power requirement: +3.0V to +3.6V - Operating temperature: 0 degrees C to +70 degrees C - Storage temperature: -55 degrees C to +125 degrees C

Chez Microsoft on prend la sécurité très au sérieux !!!

Message d'erreur : Votre mot de passe doit comporter 18 770 caractères au minimum et ne peut être identique à l'un de vos 30 689 mots de passe précédents Merci Bill !!! Numéro d'article : 276304 Dernière mise à jour : lundi 11 juillet 2005 Version : 3.1

15 oct. 2007

FDE : Full Drive Encryption

Hard FDE - Encryption Matériel
  • Seagate Momentus 5400 FDE.2 - fiche technique : ici
  • Dlock Pci Card http://www.dlock.com.tw/
  • Compusec PCI Card http://www.ce-infosys.com/english/products/compusec_hsm.html
Soft FDE - Encryption complète logicielle
  • PGP® CryptoEx (End Of Life) - http://www.glueckkanja.com - http://www.pgp.com/company/cryptoex.html
  • Checkpoinnt Pointsec - http://www.checkpoint.com/products/datasecurity/pc/index.html
  • Securstar DriveCrypt Plus Pack - http://www.securstar.com/products_drivecryptpp.php
  • Compusec - http://www.ce-infosys.com/english/downloads/free_compusec/index.html

FDE : Full Drive Encryption Versus FL : File Level

FDE = Full Drive Encryption > Protection intégrale des données au moyen de chiffrement matériel intégré dans le disque dur FLE = File Level Encryption > Protection selective de certaine information au moyen de logiciels spécialisés
"File Level vs. Full Drive Encryption" Solutions for Protecting Data at Rest By Bill Bosen As organizations struggle to implement encryption for stored data, one critical question frequently surfaces - Which encryption method is best for our organization, file-level encryption or full-drive encryption? The amount of protection provided by these two approaches differs greatly, as does the management and user burden and the ability to meet legislative requirements.