Bitlocker and Smartcard authentification

Posted: 12-29-2006, 11:19 PM
Hello,

our technical account manager suggested to me to look into Bitlocker as
a possible reason to do on early migration for notebooks. We do
currently use Safeguard Easy and Safeboot for driveencryption.

These products allow the use of smartcards and Aladdin tokens to
authenticate both against the drive encryption prior to the O/S-boot and
against the operation system at logon.

For several reasons, I would prefer a smartcard-authentification over
the current TPM/Pin-system.

Among these reasons are:

- Our current standard laptops have no TPM, and we use them for appx. 4
years based on our accounting procedures. Thus, changing to a
TPM-bearing model would change our hardwarebase over a period of more
than 4 years.
- Our notebooks are often pooled among several users. The current
authentification procedure authentificates single users and allows us to
differentiate which notebook belongs to which pool, as each user has 2
factors which are unique to him, and we can allow one or more
credentials on each machine. The TPM-based approach sets a common
factor: Posession of the chassis with the TPM which is the "posession
factor" and a common secret which all pooling employees share among
them. The TPM-based approach is more designed with the idea of dedicated
machines in mind.

Is there a chance that a smartcard-operated authentification might be
implemented into the security system of Bitlocker?

Regards,

Detlev
Reply With Quote

Responses to "Bitlocker and Smartcard authentification"

Paul Adare
Guest
Posts: n/a
 
Re: Bitlocker and Smartcard authentification
Posted: 12-30-2006, 12:29 AM
In article <uwr2N$5KHHA.3564@TK2MSFTNGP02.phx.gbl>, in the
microsoft.public.windows.vista.security news group, Detlev
Rackow <detlev.rackow@gmx.de> says...
> Is there a chance that a smartcard-operated authentification might be
> implemented into the security system of Bitlocker?
>
Not any time soon, no.

--
Paul Adare - MVP Virtual Machines
Waiting for a bus is about as thrilling as fishing,
with the similar tantalisation that something,
sometime, somehow, will turn up. George Courtauld

Reply With Quote
 
LinkBack Thread Tools Display Modes
Reply


Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On


Similar Threads
Thread Thread Starter Forum Replies Last Post
DOMAIN LOGIN: Authentification server unavailable in remote location Louis Windows Vista Administration 0 02-21-2007 02:45 AM
BitLocker: SmartCard support? tavis Windows Vista Security 1 07-11-2006 07:08 PM
Authentification from a SAM base with WMI Mika Windows XP WMI 0 04-25-2006 04:27 PM
help with smartcard and windows xp venom2733 Windows XP Embedded 3 10-15-2003 04:02 PM
Logon with Smartcard Rene Windows XP Security & Administration 0 07-08-2003 02:24 PM


1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59 60 61 62 63 64 65 66 67 68 69 70 71 72 73 74 75 76 77 78 79 80 81 82 83 84 85 86 87 88 89 90