ºô¯¸¾ÉÄý | ·|­ûµn¤J | ³sµ¸§Ú­Ì

­º­¶ Ãö©ó­Z°T ²£«~¬d¸ß «ÈªA±M°Ï ·|­û±M°Ï ·s»D±M°Ï ¤H¤~©Û¶Ò ¥þ¬Ù¾ÚÂI °ê¨¾°VÀx ±j©T«¬µ§¹q



­Z°T¹q¸£
±ý¬d¸ß¸ê°T

§ä¤£¨ìµª®×?

­Z°T¥Î¤ß´£¿ô¡G»P¥»­¶¬ÛÃö¸ê®Æ¬°¡u¨ä¥L°ÝÃD¡v¡u±M·~ª¾ÃÑ¡v¡C


³o¦³¤°»ò¥\¯à©O!!¹ï§Ú­Ì¤S¦³¤°»òÀ°§U?



 

1. ºK­n

¥»¤å´£¨Ñ²µu§ã­nªº BitLocker—ü Drive Encryption §Þ³N·§Æ[¡A³o¬O Microsoft Windows Vista ¤¤¥O¤H®¶¾Äªº¸ê®Æ«OÅ@·s¥\¯à¡C³Ì¥D­nªº¥Ø¼Ð¬O¬°¶i¶¥¨Ï¥ÎªÌ©M IT ¨t²ÎºÞ²z­û¡A´£¨Ñ¥»¥\¯à¥Í©R¶g´Áªº²`¤J±´°Q¡A¨ó§U¥L­ÌÁA¸Ñ BitLocker Drive Encryption ªº¥\¯à¤º®e¤Î¨ä³B²z¤é¯q¼W¥[¤§¸ê®Æ«OÅ@°ÝÃDªº¤è¦¡¡G¨Ò¦p¡A¥Ñ©ó¹q¸£µwÅé¿ò¥¢©Î¾DÅѦӾɭP¾÷±K¸ê°T¬ªÅS¡C

¥»¤å°²³]ŪªÌÁA¸Ñ¡u¥i«H¿à¥­¥x¼Ò²Õ¡v(Trusted Platform Module¡ATPM) §Þ³N¡C¦p»Ý¦³Ãö TPM §Þ³Nªº­I´º¸ê°T¡A½Ð°Ñ¾\ http://www.trustedcomputinggroup.org/ (­^¤å) ºô¯¸¤W©Ò´£¨Ñªº³W®æ»P¸ê®Æ¡C

¦^¨ì­¶­º¦^¨ì­¶­º

2. ᤮[

BitLocker—ü Drive Encryption ¬O Windows Vista Enterprise ©M Ultimate °w¹ï¥Î¤áºÝ¹q¸£¥H¤Î Windows Server "Longhorn" ¤¤©Ò´£¨Ñªº¸ê®Æ«OÅ@¥\¯à¡CBitLocker ¬O Microsoft ¦^À³«È¤á³Ì­¢¤Á»Ý¨D¤§¤@ªº²£«~¡G»P Windows §@·~¨t²Î¤¤¸Ñ¨M¤è®×±K¤Á¾ã¦X¡A¥H³B²z¦] PC µwÅé¿ò¥¢¡B¾DÅѩΤ£·í¸Ñ°£©e¥ô¦Ó¾É­P¸ê®Æ¥¢ÅѩάªÅSªº¯u¹ê«Â¯Ù¡C

BitLocker ¥i¨¾¤îÅѸé¥H¥t¤@­Ó§@·~¨t²Î¶}¾÷©Î°õ¦æ³nÅé§ðÀ»¤u¨ã¡A«I¤J Windows Vista ÀɮשM¨t²Î«OÅ@¡A©Î¬O¹ïÀx¦s¦b¨ü«OÅ@ºÏºÐ¾÷¤WªºÀÉ®×°õ¦æÂ÷½uÀ˵ø¡C

¦b²z·Qªº±¡ªp¤U¡A¦¹¥\¯à¨Ï¥Î¥i«H¿à¥­¥x¼Ò²Õ (TPM 1.2) «OÅ@¨Ï¥ÎªÌ¸ê®Æ¡A¨Ã½T«O°õ¦æ Windows Vista ªº PC ¤£·|¦b¨t²ÎÂ÷½u®É¾D¨ì«§ï¡CBitLocker ¥i¥H¬°¾÷°Ê©Ê¤Î¿ì¤½«Ç¥ø·~¸ê°T¤u§@¤H­û¡A¦b¨t²Î¿ò¥¢©Î¾DÅѮɥ[±j´£¨Ñ¸ê®Æ«OÅ@¡A¨Ã¥B¦b¸Ñ°£©e¥ô³o¨Ç¸ê²£®É½T¹ê§R°£¸ê®Æ¡C

BitLocker ¥[±jªº¸ê®Æ«OÅ@¥\¯àµ²¦X¤F¨â¤j¤l¥\¯à¡G§¹¾ãªººÏºÐ¾÷¥[±K¥H¤Î¦­´Á¶}¾÷¤¸¥óªº§¹¾ã©ÊÀˬd¡C

ºÏºÐ¾÷¥[±K¬O¥Hªý¤î¥¼±ÂÅv¨Ï¥ÎªÌ«I¤J¿ò¥¢©Î¾DÅѹq¸£¤W Windows ÀɮשM¨t²Î«OÅ@ªº¤è¦¡¨Ó«OÅ@¸ê®Æ¡C³oºØ«OÅ@¬O³z¹L¬°¾ã­Ó Windows ºÏºÐ°Ï¥[±Kªº¤è¦¡¹F¦¨¡C¦b BitLocker «OÅ@¤§¤U¡A©Ò¦³¨Ï¥ÎªÌ©M¨t²ÎÀɮ׳£·|¶i¦æ¥[±K¡A¥]¬A¥æ´«ÀɮשM¥ð¯vÀɮצb¤º¡C

¦­´Á¶}¾÷¤¸¥óªº§¹¾ã©ÊÀˬd¦³§U©ó½T«O¥u¦³¦b³o¨Ç¤¸¥ó¥¼¸g¤zÂZªº±¡ªp¤U¤~·|°õ¦æ¸ê®Æ¸Ñ±K¡A¨Ã½T«O¥[±KªººÏºÐ¾÷¦ì©ó­ì¥ýªº¹q¸£¤§¤¤¡C

BitLocker ±K¤Á¾ã¦X©ó Windows Vista ¤§¤¤¡A¬°¥ø·~´£¨ÑµL±µÁ_¡B¦w¥þ¦Ó¥B®e©öºÞ²zªº¸ê®Æ«OÅ@¸Ñ¨M¤è®×¡C¨Ò¦p¡ABitLocker ¤]¯à°÷µo´§¥ø·~­ì¦³ Active Directory ºô°ìªA°È°ò¦µ²ºcªº¥\®Ä¡A±q»·ºÝ©e¥I­×´_ª÷Æ_¡CBitLocker ¤]°t³Æ¦³ÄY­«·lÃa­×´_¥D±±¥x¡A±K¤Á¾ã¦X©ó¦­´Á¶}¾÷¤¸¥ó¤§¤¤¡A¥H´£¨Ñ¡u¹ê¦a¡v¸ê®ÆÂ^¨ú¡C

BitLocker ´£¨ÑÂê©w¥¿±`¶}¾÷µ{§Çªº¿ï¾Ü¡A¤@©w­n¨Ï¥ÎªÌ´£¨Ñ PIN (­Ó¤HÃѧO½X) ¤~¯à¸Ñ°£Âê©w¡AÃþ¦ü©ó´£´Ú¥d PIN ¡A©Î´¡¤J§tª÷Æ_§÷®Æªº USB §Ö°{ºÏºÐ¡C³o¨Ç¥~¥[ªº¦w¥þ©Ê±¹¬I¥i´£¨Ñ¦h­««Y¼ÆÅçÃÒ¡A½T«O¤@©w­n´£¨Ñ¥¿½Tªº PIN ©Î USB §Ö°{ºÏºÐ¡A¹q¸£¤~·|±Ò°Ê©Î±q¥ð¯vª¬ºA«ì´_¡C

BitLocker ´£¨ÑºëÆF¶i¦æ³]©w¤ÎºÞ²z¡A¨Ã³z¹L Windows Management Instrumentation (WMI) ¤¶­±´£¨Ñ§t«ü¥O½X¤ä´©ªºÂX¥R©Ê©MºÞ²z©Ê¡C¦¹¥~¡ABitLocker ·|¥[³t¾÷±K¸ê®Æ²M°£§@·~¡A²¤Æ¹q¸£¦^¦¬µ{§Ç¡C

¨C¤Ñ¨Ï¥Î¥H BitLocker «OÅ@ªº Windows Vista ¹q¸£¡A¨Ï¥ÎªÌ¥i¯à§¹¥þ¤£·|¹îı¡C¦Ó¥B¡A¦bµo¥Í¨u¨£ªº¨t²ÎÂê©w±¡ªp¤U (¤]³\¬O¦]¬°µwÅ饢±Ñ©Î¬Oª½±µ§ðÀ»©Ò³y¦¨ªºµ²ªG)¡ABitLocker ¤]´£¨Ñ²³æ¦Ó¦³®Ä²vªº­×´_³B²zµ{§Ç¡C³o¨Ç±¡ªp¤§¤¤¥]¬A±N§t§@·~¨t²ÎºÏºÐ°ÏªºµwºÐ²¾¦Ü¥t¤@³¡¹q¸£¡B§ó´«¥]§t TPM ªº¥D¾÷ªO¡A©Î¦­´Á¶}¾÷Àɮתº¸ê®Æ·l·´µ¥¨Æ¥ó¡C

BitLocker Drive Encryption¡G

¦b¨t²ÎÂ÷½u®É«OÅ@¸ê®Æ¡A¦]¬°¥¦·|¡G

¥[±K¾ã­Ó Windows ºÏºÐ°Ï¡A¥]¬A¨Ï¥ÎªÌ¸ê®Æ©M¨t²ÎÀɮסB¥ð¯vÀɮסB¤À­¶ÀɮסA¥H¤Î¼È¦sÀÉ¡C

¬°¨ó¤O¼t°ÓÀ³¥Îµ{¦¡´£¨Ñ«OÅ@³Ê¡C¨ó¤O¼t°ÓÀ³¥Îµ{¦¡·|¦]¬°¦w¸Ë¦b¤w¥[±KªººÏºÐ¾÷¤W¦Ó¦Û°Ê¨ü¯q¡C

½T«O¶}¾÷µ{§Ç§¹¾ã©Ê¡A¦]¬°¥¦·|¡G

´£¨ÑÀˬd¦­´Á¶}¾÷ÀÉ®×½T¹ê«O«ù§¹¾ã©Êªº¤èªk¡A½T«O³o¨ÇÀɮרS¦³¾D¨ì¥ô¦ó­×§ï§ó°Ê (¨Ò¦p¡A¥H¶}¾÷ºÏ°Ï¯f¬r©Î®Ú¥Ø¿ý®M¥ó)¡C

«OÅ@¨t²Î¡A¤£¨üÂ÷½u³nÅ骺«Iŧ¡G¥ô¦ó¨ä¥L¯à°÷±Ò°Ê¨t²Îªº³nÅé³£±NµLªk¦s¨ú«OÅ@¦¹ Windows ºÏºÐ°Ïªº®Ú¥Ø¿ýª÷Æ_¡C

¦b¾D¨ì«§ï®ÉÂê©w¨t²Î¡G¦pªG¥ô¦óºÊ±±¤UªºÀÉ®×¾D¨ì«§ï¡A¨t²Î±N¤£·|±Ò°Ê¡C¥Ñ©ó¨t²ÎµLªk¤@¦p©¹±`¦a±Ò°Ê¡A¥iĵ§i¨Ï¥ÎªÌÀɮפw¾D«§ï¡C

³z¹L¤U¦C¤è¦¡´î»´³]³Æ¦^¦¬¤u§@­t¾á¡G

ÁY´î¦bºÏºÐ¾÷¤W¥Ã¤[¦Ó¦w¥þ¦a§R°£ºÏºÐ¾÷¤W©Ò¦³¸ê®Æªº®É¶¡¡C¥u­n§R°£¦s¨úºÏºÐ¾÷©Ò»Ýªºª÷Æ_¡A§Y¥i±N¥[±KºÏºÐ°Ï¤Wªº¸ê®ÆÂàÅܬ°µL¥Î¸ê®Æ¡C

¥»¤å¥ó»¡©ú¥ø·~¹q¸£¤Wªº BitLocker Drive Encryption ¥Í©R¶g´Á¡A´y­z¦b¦UºØ¤£¦P¨Ï¥ÎªÌ®×¨Ò¤¤ªº³]©w¡BºÞ²z¤Î­×´_¥\¯à¤Î¬ÛÃöÁpªºª÷Æ_¡CWindows Vista ªº¶}µo¤u§@©|¥¼§¹¥þµ²§ô¡A¿Ã¹õÂ^¨úµe­±¡BAPI¡B¤å¦r©M¬yµ{³£¥i¯à·|Åܧó¡C

2.1 ¨t²ÎµwÅé¡B¶´Åé©M³nÅé»Ý¨D

­Y­n¨Ï¥Î BitLocker¡A¹q¸£¥²¶·º¡¨¬¤@²Õ¥Ñ BitLocker Windows Vista ¨t²Î¼Ð»x»Ý¨D©Ò«ü©wªº±ø¥ó¡C³o¨Ç»Ý¨Dªº´ú¸Õ·|ÀHªþ©ó Windows Development Kit (WDK) ¤¤¤@°_µo¦æ¡G

¨t²Î¥²¶·¨ã¦³ Trusted Platform Module (TPM) v1.21¡CTPM ´£¨Ñ¨t²Î¶}¾÷µ{§Ç§¹¾ã©Ê´ú¶q¤Î³ø§i¡C

TPM ´£¨Ñ¨t²Î¶}¾÷µ{§Ç§¹¾ã©Ê´ú¶q¤Î³ø§i¡C

¨t²Î¥²¶·¨ã¦³ v1.2 TCG (Trusted Computing Group) ¬Û®eªº BIOS1¡C

BIOS ·|«Ø¥ß OS ¶}¾÷¤§«eªº«H¿àÃì¡C

¨t²Î¥²¶·¥]§t TCG «ü©wªº Static Root Trust Measurement (SRTM) ¤ä´©

¨t²Î BIOS ¥²¶·¤ä´© USB ¤j«¬¦s©ñ¸Ë¸mÃþ§O2¡A¨ä¤¤¥]¬A¦b§@·~¨t²Î¤§«eªºÀô¹Ò¤¤¡A¦b§Ö°{ºÏºÐ¤WŪ¨ú¤Î¼g¤J¤p«¬Àɮתº¬ÛÃö¸ê°T¡C

¹q¸£¥²¶·¦Ü¤Ö¨ã¦³¨â­ÓºÏºÐ°Ï3¤~¯à¹B§@¡G

¡u§@·~¨t²Î (OS) ºÏºÐ°Ï¡v(©ÎºÙ¬°¶}¾÷ºÏºÐ°Ï) ¬O¥]§t Windows §@·~¨t²Î¤Î¨ä¤ä´©ÀɮתººÏºÐ°Ï¡A¥²¶·®æ¦¡¤Æ¬° NTFS¡C¦¹ºÏºÐ°Ï¤Wªº¸ê®Æ¨ü¨ì BitLocker ªº«OÅ@¡C

¡u¨t²ÎºÏºÐ°Ï¡v¬O¥]§t¯S©wµwÅéÀɮתººÏºÐ°Ï¡ABIOS ±Ò°Ê¥­¥x¥H«á¡A»Ý­n³o¨ÇÀɮפ~¯à¸ü¤J Windows ¹q¸£¡C­Y­nÅý BitLocker ¯à°÷¹B§@¡A¨t²ÎºÏºÐ°Ï¤£¥i¥H¥[±K¡B¥²¶·¤£¦P©ó§@·~¨t²ÎºÏºÐ°Ï¡A¨Ã¥B¥²¶·¥H NTFS ¶i¦æ®æ¦¡¤Æ¡C±zªº¨t²ÎºÏºÐ°Ï¥²¶·¦Ü¤Ö¦³ 1.5 GB ªºªÅ¶¡¡C¼g¤J¦¹ºÏºÐ°Ïªº¸ê®Æ (¥]¬AÃB¥~ªº¨Ï¥ÎªÌ¸ê®Æ) ¨Ã¤£¨ü BitLocker «OÅ@¡C

¥»¤å¤¤ªº¸ê°T¾A¥Î©ó§t BitLocker ªº Windows ª©¥»¡C¦øªA¾¹¯S©wªº¸ê°T¥]§t¦b¡Õ²Ä 3.5 ¸`¡A¦øªA¾¹¤Wªº BitLocker¡Ö¡C

¦^¨ì­¶­º¦^¨ì­¶­º

3. ¨t²Î³]­p

BitLocker ªº¥D­n¥Ø¼Ð¬O«OÅ@µwºÐ¤W§@·~¨t²ÎºÏºÐ°Ï¤Wªº¸ê®Æ¡C¬°¤F¹F¦¨³o¶µ¥Ø¼Ð¡ABitLocker ¨Ï¥Î v1.2 TPM ¦w¥þ©ÊµwÅé¡A¥H¨ó§U«O»Ù¥[±Kª÷Æ_ªº¦w¥þ¡A¨Ã¨¾¤î¹ï¨t²Î§¹¾ã©Ê©Î¨ä¥L¸ê®Æ¡BÀ³¥Îµ{¦¡¡BDLL ÀÉ¡A¥H¤ÎÀx¦s¦b§@·~¨t²ÎºÏºÐ°Ï¤WÀÉ®×µo°Êªº³nÅé§ðÀ»¡C

BitLocker ¥]§t¹ï­«­nªº¦­´Á¶}¾÷¤¸¥ó¶i¦æ§¹¾ã©ÊÀˬd¡CBitLocker ¨Ï¥Î TPM¡A¦b¶}¾÷µ{§Ç¤§¤º¦¬¶°¨ÃÀx¦s¦hºØ¨Ó·½ªº´ú¶q¡A4¥H«Ø¥ß¤@ºØ¨t²Î¡u«ü¯¾¡v¡C°£«D¶}¾÷¨t²Î¾D¨ì«§ï¡A§_«h¡u«ü¯¾¡v·|«O«ù¤£ÅÜ¡CBitLocker ¦³¿à©ó TPM ®Ú¾Ú³o¨Ç´ú¶q¡A¨Ó­­¨î®Ú¥Ø¿ý¾÷±Kªº¦s¨ú¡C¤@¥¹ÃÒ©ú¶}¾÷µ{§Çªº§¹¾ã©Ê¤§«á¡ABitLocker ´N·|¨Ï¥Î TPM¡A¸Ñ°£¨ä¾l¸ê®ÆªºÂê©w¡CµM«á¨t²Î·|Ä~Äò±Ò°Ê¡A¦Ó¨t²Î«OÅ@´NÂà¦Ó¦¨¬°°õ¦æ¤¤§@·~¨t²Îªº³d¥ô¡C

[¹Ï 1] ¥Ü½dºÏºÐ°Ï¦p¦ó¥H§¹¾ãºÏºÐ°Ï¥[±Kª÷Æ_ (Full Volume Encryption Key¡AFVEK) ¬°ºÏºÐ°Ï¤º®e¥[±K¡A¸Óª÷Æ_¦AÂà¦Ó§Q¥ÎºÏºÐ°Ï¥D­nª÷Æ_ (Volume Master Key¡AVMK) ¥[±K¡C«O»Ù VMK ¦w¥þ¬O¥H¶¡±µ¤è¦¡«OÅ@ºÏºÐ°Ï¤Wªº¸ê®Æ¡G¥[¤WºÏºÐ°Ï¥D­nª÷Æ_¡A¥iÅý¨t²Î¦b«H¿àÃì¤W´åªºª÷Æ_¿ò¥¢©Î¾D¤J«I®É¡A»´©ö´N¯à­«·s³]©wª÷Æ_¡C¦p¦¹¥i¸`¬Ù¸Ñ±K¤Î­«·s¥[±K¾ã­ÓºÏºÐ°Ïªº¶}¾P¡C

BitLocker ¤¤¤£¦P¥[±Kª÷Æ_¤§¶¡ªºÃö«Y

[¹Ï 1]¡G BitLocker ¤¤¤£¦P¥[±Kª÷Æ_¤§¶¡ªºÃö«Y¡C
¬d¬Ý§¹¾ã¤j¤pªº¼v¹³

¤@¥¹ BitLocker ÅçÃÒ¹L¨ü«OÅ@§@·~¨t²ÎºÏºÐ°Ïªº¦s¨úÅv­­¥H«á¡A¸ê®Æ¼g¤J¨ü«OÅ@ºÏºÐ°Ï©Î±q¤¤Åª¨ú¸ê®Æ®É¡A Windows Vista Àɮרt²Î°ïÅ|¤¤ªº¿z¿ï¾¹ÅX°Êµ{¦¡´N·|¦Û°Ê¥[±K¤Î¸Ñ±KºÏºÐ°Ï¡C·í¹q¸£¶i¤J¥ð¯v®É¡A¥ð¯vÀɮ׬O¥H¥[±K¤è¦¡Àx¦s¦b¨ü«OÅ@ªººÏºÐ°Ï¤¤¡C±q¥ð¯vª¬ºA«ì´_ªº³B²z¤è¦¡´X¥G»P¶}¾÷µ{§Ç§¹¥þ¬Û¦P¡G¦¹Àx¦sÀÉ®×·|¦b¹q¸£±q¥ð¯vª¬ºA«ì´_®É¸Ñ±K¡C¥[±K¤Î¸Ñ±K¹ï®Ä¯àªº­t­±¼vÅTÀ³¸Ó·¥¨ä¦³­­¡A¦Ó¥B¦b¤j³¡¤À±¡ªp¤U³£¬O¦Û°Ê°õ¦æ¡C

IT ¨t²ÎºÞ²z­û¥i¥H³z¹LºëÆF©Î¬O¥Ñ Windows Vista ªº Win32_EncryptableVolume Windows Management Instrumentation (WMI) ´£¨ÑªÌ¤½¶}ªº¤¶­±¡A¦b¥»¾÷©Î»·ºÝ³]©w BitLocker¡C¤¶­±¤¤¥]§tºÞ²z¥\¯à¡A¥i¶}©l¡B¼È°±¤ÎÄ~ÄòºÏºÐ°Ï¥[±K§@·~¡A¨Ã³]©w«OÅ@ºÏºÐ°Ï¥[±Kª÷Æ_ (FVEK) ªº¤è¦¡¡C

Windows Vista ¤Î Windows Server "Longhorn" ¤¤¦³¤@ºØºÞ²z«ü¥O½X (manage-bde.wsf)¡A´£¨Ñ IT ¨t²ÎºÞ²z­û²³æªº¤è¦¡ºÞ²z¤ÎÀˬdºÏºÐª¬ºA¡C³o­Ó«ü¥O½X¬O¥H¥i¥Îªº WMI ´£¨ÑªÌ¬°°ò¦¼¶¼g¦Ó¦¨¡A«Ü®e©ö´N¯à¥[¥H­×§ï¡A¥H¨ó§U°w¹ï¤£¦Pªº¥ø·~¨t²ÎºÞ²z»Ý¨D«Ø¥ß¦Û­q¸Ñ¨M¤è®×¡C

3.1 ¬[ºc¹Ï

[¹Ï 2] ¥Ü½d¾ãÅé BitLocker ¬[ºc¡A¥]¬A¨ä¤¤¦UºØ¤£¦Pªº¤l¤¸¥ó¡C¹Ï¤¤Åã¥Ü BitLocker ªº¨Ï¥ÎªÌ¼Ò¦¡©M®Ö¤ß¼Ò¦¡¤¸¥ó¡A¤Î¨ä»P§@·~¨t²Î¤£¦P¼h¦¸¾ã¦Xªº¤è¦¡¡C·í¤¤¯S§OÅã¥Ü¥X±±¨î TPM ªº¼Ò²Õ¡A¥]¬A Microsoft Management Console (MMC) ´O¤J¦¡ºÞ²z³æ¤¸¡BTPM ÅX°Êµ{¦¡¡A¥H¤ÎºÏºÐ¥[±K¼Ò²Õ¡C

¾ãÅé BitLocker ¬[ºc

[¹Ï 2]¡G¾ãÅé BitLocker ¬[ºc¡C
¬d¬Ý§¹¾ã¤j¤p¼v¹³

3.2 ¶}¾÷§Ç¦C¤¤ªºÅçÃÒ¼Ò¦¡

ªì¦¸³]©w BitLocker ®É¡A±z¥i¥H±q¼ÆºØÅçÃÒ¼Ò¦¡¿ï¾Ü¨ä¤¤¤@ºØ¡C¨C¦¸¨ü BitLocker «OÅ@ªº¨t²ÎºÏºÐ°Ï¤@±Ò°Ê¡AWindows Vista ¶}¾÷µ{¦¡½X³£·|®Ú¾ÚºÏºÐ°Ï«OÅ@³]©w¡A°õ¦æ¤@¨t¦C¨BÆJ¡C³o¨Ç¨BÆJ¥i¥H¥]¬Aµ{¦¡½X§¹¾ã©ÊÀˬd¡A¥H¤Î¥²¶·¥ý½T»{¤~¯à¸Ñ°£«OÅ@ºÏºÐ°ÏÂê©wªº¨ä¥LÅçÃÒ¨BÆJ¡C­Y­n¶i¦æ¨ä¥L¸ê®Æ«OÅ@¡ABitLocker ¥i¥H¨Ï¥Î­Ó¤HÃѧO½X (PIN)¡A©Î±Ò°Êª÷Æ_ (Àx¦s¦b¨C¦¸¹q¸£¶}¾÷³£¥²¶·´¡¤J¤§ USB §Ö°{ºÏºÐ¤Wªºª÷Æ_)¡C

¶i¦æ­×´_®É¡ABitLocker «h¨Ï¥Î­×´_ª÷Æ_ (¥Î¨Ó­×´_¦b BitLocker ºÏºÐ°Ï¤W¥[±K¤§¸ê®Æªºª÷Æ_)¡A©Î¨Ï¥Î­×´_±K½X (¼Æ¦r±K½X)¡A¦p [¹Ï 1] ©Ò¥Ü¡A¥H«KÅý±ÂÅv¨Ï¥ÎªÌ¦b¦w¥þ©Ê¡BµwºÐ©Î¨ä¥L¥¢±Ñªº±¡ªp¤U¡A¤´µM¯à°÷¦s¨ú¨t²Î¡C

Windows Vista ·|¨Ì¤U¦C¶¶§Ç´M§äª÷Æ_¡G

1.

¯Âª÷Æ_ (½Ð°Ñ¾\¡Õªþ¿ý¡Ö¤¤ªº¡u¦Wµü¸ÑÄÀ¡v) - ¤w¸g°±¥Î§¹¾ã©ÊÀˬd«OÅ@¡AºÏºÐ°Ï¥D­nª÷Æ_¥i¥H¦Û¥Ñ¨ú¥Î¡C¤£»Ý­n¥ô¦óÅçÃÒ (½Ð°Ñ¾\¡Õ²Ä 4.3.4.3 ¤p¸`¡Ö¦³Ãö°±¥Î«OÅ@¼Ò¦¡ªº»¡©ú¡A¥H¨ú±o¸Ô²Ó¸ê°T)¡C

2.

¤£»Ý­n¨Ï¥ÎªÌ°Ê§@ªºÅçÃÒ¡G

a. TPM - TPM ¶¶§Q¦aÅçÃÒ¦­´Á¶}¾÷¤¸¥ó¡A±N VMK ¶}«Ê¡C

b. TPM ©M±Ò°Êª÷Æ_ - TPM ¶¶§QÅçÃÒ¦­´Á¶}¾÷¤¸¥ó¡A¦Ó¥B¤w´¡¤J¥]§t±Ò°Êª÷Æ_ªº USB §Ö°{ºÏºÐ¡C

3.

»Ý­n¨Ï¥ÎªÌ°Ê§@ªºÅçÃÒ (§e²{µ¹¨Ï¥ÎªÌªº¤å¦r¼Ò¦¡¤¶­±)¡G

a. TPM ©M PIN - TPM ÅçÃÒ¦­´Á¶}¾÷¤¸¥ó½T¹êµL»~¡A¦¹¥~¡A¨Ï¥ÎªÌÁÙ¥²¶·¿é¤J¥¿½Tªº PIN¡A±Ò°Êµ{§Ç¤~¯àÄ~Äò¡A¦Ó±NºÏºÐ¾÷¸Ñ°£Âê©w¡CPIN ¤w¨ü¨ì«OÅ@§K©ó TCG ¬Û®eªº TPM¡u­«¡vÀ»¡C

b. ­×´_ª÷Æ_©M/©Î±Ò°Êª÷Æ_ - ¨Ï¥ÎªÌ·|¦¬¨ì´£¥Ü´¡¤J¦s©ñ­×´_ª÷Æ_©M/©Î±Ò°Êª÷Æ_ªº USB §Ö°{ºÏºÐ¡C

c. ­×´_±K½X - ¨Ï¥ÎªÌ¥²¶·¿é¤J¥¿½Tªº­×´_±K½X¡C

3.3 ¥~³¡ºÏºÐ°Ï

¥~³¡ºÏºÐ°Ï¤@¯ë¬O¦b¥t¤@³¡¤w±Ò¥Î BitLocker ¤§¹q¸£¤Wªº§@·~¨t²ÎºÏºÐ°Ï¡A¨Ã¤w¡u¶×¤J¡v¥Ø«e¹q¸£¤Wªº¥Ø«e Windows ¤¤¡C¶×¤J¥~³¡ºÏºÐ°Ï¬O§Ö³t¦Óª½±µªº­×´_µ{§Ç¡A¨Ò¦p¡A±q²{¦b¤w·lÃa¹q¸£¤W¥[±KªººÏºÐ­×´_¸ê°T¡C¦b³oºØºÏºÐ°Ï¤W°ß¤@¥i¥ÎªºÅçÃÒ§@·~´N¬O­×´_ (½Ð°Ñ¾\¡Õ²Ä 5 ¸`­×´_¡Ö¡A¥H¨ú±o¸Ô²Ó¸ê°T)¡C­×´_»Ý­n­×´_ª÷Æ_©Î­×´_±K½X¡C

3.4 ¦øªA¾¹¤Wªº BitLocker Drive Encryption

¹ïÀx¦s¦b¤£¦w¥þ©Î¦@¥ÎÀô¹Ò (¦p¤À¤½¥q¦aÂI) ¤¤ªº¦øªA¾¹¦Ó¨¥¡ABitLocker ¥i«OÃҨ㦳»P´£¨Ñµ¹¥Î¤áºÝ¹q¸£¤§¬Û¦P¼h¦¸ªº¸ê®Æ«OÅ@¡C³oºØ¦øªA¾¹¤W¥i¥Îªº¥~¥[¥\¯à·|¥[±K§@·~¨t²ÎºÏºÐ°Ï¡A¨Ã¥i³z¹L WMI ¦b IT ¨t²ÎºÞ²z­û·Q­n¦³ BitLocker «OÅ@ªº¥ô¦ó¸ê®ÆºÏºÐ°Ï¤W±Ò¥Î¡C

¦b¹w³]±¡ªp¤U¡ABitLocker Drive Encryption ¤£·|»P Windows Server "Longhorn" ¦P®É¦w¸Ë¡C½Ð¿ï¨ú [·s¼W¥\¯à (Add Features)]¡AµM«á±q²M³æ¿ï¶µ¤¤¿ï¨ú [BitLocker Drive Encryption]¡A±q InitialConfigurationTasks ¥\¯àªí¥[¤J BitLocker ¥\¯à¡C¦w¸Ë BitLocker ¥\¯à¥H«á¡A³]©w¤ÎºûÅ@§@·~§Y·|¨Ì·Ó¥»¤å¥óµy«á»¡©ú¯ë°õ¦æ¡C¦b¦øªA¾¹¤W¦w¸Ë BitLocker Drive Encryption ¤§«á¡A¥²¶·­«·s¶}¾÷¡CBitLocker ¥i¥H¨Ï¥Î WMI ±q»·ºÝ¥[¥H±Ò¥Î¡C

PIN ¤ä´©
¤@¯ë¨Ó»¡¡A¦b¦Ò¼{¨ì­«·s¶}¾÷³t«×¡A©Î¦]¤H¬°¤¶¤J¦ÓµLªk­«·s¶}¾÷ªº¦øªA¾¹¤W±Ò¥Î PIN ¥\¯à¨Ã¤£¬O³Ì¨Î§@ªk¡C¦b³\¦h¦øªA¾¹Àô¹Ò¤¤¡A°õ¦æ®É¶¡»P»·ºÝºÞ²z«D±`­«­n¡C

¦³¤@ºØ¥i¦æªº³¡¸p®×¨Ò¬O¡G¦b­û¤u¨C¦¸¤@¶}©l¤W¯Z´N¥²¶·¶}±Ò¦øªA¾¹ªº¤À¤½¥q¤¤¡A¶}±Ò BitLocker ©M PIN ¥\¯à¡C¦b¦¹±¡ªp¤U¡A­t³dªº¤H·|ª¾¹D¨Ã¦b¶}¾÷®É¿é¤J PIN¡C

±Ò°Êª÷Æ_¤ä´©
¤ä´©¦øªA¾¹ªº USB ±Ò°Êª÷Æ_¡A¦ý¥u¦³¦b¶}¾÷«á¤£¯d¦b¹q¸£¤¤¡A¤~¯à´£¤É¸ê®Æ«OÅ@¡C¦]¦¹¡A¨C¦¸¦øªA¾¹­«·s±Ò°Ê³£¥²¶·¤H¬°¤¶¤J¡A¤~¯à¹F¨ì³Ì¨Î¸ê®Æ«OÅ@§@¥Î¡C

3.4.1 ¸ê®ÆºÏºÐ°Ï

§@·~¨t²ÎºÏºÐ°Ï©M¨t²ÎºÏºÐ°Ï¥H¥~ªººÏºÐ°Ï¡A´NºÙ¬°¡u¸ê®ÆºÏºÐ°Ï¡v¡C¥u¦³¦b Windows Server "Longhorn" v1 ¤¤¡A¤~¤ä´©¸ê®ÆºÏºÐ°Ïªº BitLocker ¥[±K¡C

BitLocker ¬O³z¹L¥H¥[±K§@·~¨t²ÎºÏºÐ°Ïªº¬Û¦P¤è¦¡¶i¦æ¥[±K¨Ó«OÅ@ Windows Server "Longhorn" ¸ê®ÆºÏºÐ°Ï¡C§@·~¨t²Î·|¥H¤@¯ë¤è¦¡±¾¤W BitLocker «OÅ@ªº¸ê®ÆºÏºÐ°Ï¡C

ª÷Æ_Ãì
«OÅ@¸ê®ÆºÏºÐ°Ïªºª÷Æ_»P«OÅ@§@·~¨t²ÎºÏºÐ°Ïª÷Æ_²@µLÃö«Y¡C­Y­n¤¹³\¨t²Î¦Û°Ê±¾¤W³o¨ÇºÏºÐ°Ï¡A«OÅ@¸ê®ÆºÏºÐ°Ïªºª÷Æ_Ãì¤]­n¥[±KÀx¦s¦b¥Ø«e¤w¶}¾÷ªººÏºÐ°Ï¤W¡C©ú½T¦a»¡¡A´N¬O¦b¥Ø«e¤w¶}¾÷ªººÏºÐ°Ïµn¿ý¤¤­n¦³ External Wrapping Key (EWK)¡A³o¬O 256 ¦ì¤¸ AES ª÷Æ_¡A·|«OÅ@¸ê®ÆºÏºÐ°Ïªº VMK¡C¥Ñ©ó EWK ¬OÀx¦s¦b¥[±Kªº§@·~¨t²ÎºÏºÐ°Ï¤§¤º¡A¥¦°£¤F¨ü BitLocker «OÅ@¥~¡A¤]¨ü¨ì Windows Server "Longhorn" §@·~¨t²Î¥»¨­ªº«OÅ@¡C¦pªG§@·~¨t²Î¶i¤J­×´_¼Ò¦¡¡A¤@ª½¨ì§@·~¨t²ÎÂ÷¶}­×´_¼Ò¦¡¡A³£¯à«O»Ù¸ê®ÆºÏºÐ°Ïªº¦w¥þ¡C

¦Û°Ê¸Ñ°£Âê©w
¦Û°Ê¸Ñ°£Âê©w¥i¥H¦b¶}¾÷´Á¶¡Åý¸ê®ÆºÏºÐ°Ï¦Û°Ê¸Ñ°£Âê©w¡A¦Ó¤ð»Ý¤H¬°¤¶¤J¡C±Ò¥Î¦Û°Ê¸Ñ°£Âê©w·|¦V¤w¶}¾÷§@·~¨t²Îªºµn¿ý»{¥i¸ê®ÆºÏºÐ°Ï EWK ªº¯Â¤å¦r½Æ¥»¡C¨S¦³¶¶§Q¦a¦s¨ú¤w¥[±Kªº§@·~¨t²ÎºÏºÐ°Ï¡A´N¤£¯à¦s¨ú¸ê®ÆºÏºÐ°Ï¤Wªº¸ê®Æ¡C²Ä¤@¦¸¹Á¸Õ±q Windows Ū¨ú©Î¬d¸ß¸ê®ÆºÏºÐ°Ï¡A·|³y¦¨±qµn¿ýŪ¨ú EWK ±N¨ä VMK ¸Ñ±K¡C§Y¨Ï§@·~¨t²ÎºÏºÐ°Ï¤W¤wÃö³¬ BitLocker¡ABitLocker ¤]·|²M°£§@·~¨t²ÎºÏºÐ°Ïµn¿ý¤¤ªº¥ô¦óª÷Æ_¸ê®Æ¡C¦b³o¨Ç±ø¥ó¤§¤U¡A¨Ï¥ÎªÌ¥²¶·´£¨Ñª÷Æ_¡A¥H¦s¨ú¸ê®ÆºÏºÐ°Ï¡C

¨t²ÎªººÞ²z­û¥i¥H¨Ï¥Î¥i½s¼g«ü¥O½Xªº WMI ¤¶­±¡A±Ò¥Î©Î°±¥Î¦U¨t²Îªº¦Û°Ê¸Ñ°£Âê©w¡C¬°¤F«O«ù¸ê®ÆºÏºÐ°Ïªº°ª«×«OÅ@¡A°£«D§@·~¨t²ÎºÏºÐ°Ï¤w±Ò¥Î BitLocker ¨Ã¶i¦æ¥[±K¡A§_«h¨S¦³¤H¯à°÷±Ò¥Î¦Û°Ê¸Ñ°£Âê©w¡C

ÂO¶°³]©w
BitLocker ¤£¤ä´© v1 ¤¤»PÂO¶°³]©w¬ÛÃöÁpªº¸ê®ÆºÏºÐ°Ï¡C

­×´_
¸ê®ÆºÏºÐ°Ï­×´_Ãþ¦ü©ó§@·~¨t²ÎºÏºÐ°Ï­×´_¡C±z¥²¶·¦b¥¢±Ñ¥H«e (³Ì¦n¬O¦b³]©w®É)¡A¥ý±N EWK ½Æ¥»Àx¦s¦b¨ä¥L´CÅé¤W¡C¦pªG¸ê®ÆºÏºÐ°Ï·l·´¡B²¾¨ì·sªº¥­¥x¤W¡A©Î¬O§@·~¨t²ÎºÏºÐ°ÏµLªkÂ^¨ú¨Ñ¦Û°Ê¸Ñ°£Âê©wªº EWK¡A«h¨Ï¥ÎªÌ¥²¶·´¡¤J§t EWK ½Æ¥»ªº´CÅé¡C

¸ê®ÆºÏºÐ°Ïªº­×´_¬O¥Ñ¤¶­±©M WMI ´£¨ÑªÌ¥[¥H¤ä´©¡C¸ê®ÆºÏºÐ°Ï¬O¥HÃþ¦ü BitLocker ¥Î¤áºÝª©¥»¤¤ªº¥~³¡ºÏºÐ°Ï¨Ó¹ï«Ý¡C¥u¦³¦b§@·~¨t²ÎºÏºÐ°Ïµn¿ý¤¤ªº EWK ¿ò¥¢©Î·l·´®É¡A¤~»Ý­«·s±N¸ê®ÆºÏºÐ°Ïôµ²¦Ü¥­¥x¤W¡C

3.5 ¨t²Î«Â¯Ù

¥H°ª¼hªº¨¤«×¨Ó¬Ý¡A¹ï BitLocker ªº«Â¯Ù¥i¥H¤À¬°¨â¤jÃþ¡G¹ï¥­¥xªº«Â¯Ù¥H¤Î¦]¨t²Î¨Ï¥Î¤è¦¡¦Ó³y¦¨ªº«Â¯Ù¡C¨C¤@ºØ«Â¯Ù³£¥i¥H³z¹L¨Ï¥ÎªÌ¯à°÷¬°«OÅ@¨t²Î±Ä¨úªº¯S©w°Ê§@¦Ó±o¨ìÓV½w¡C

²Ä¤@ºØ«Â¯Ù«üªº¬O¹ï BitLocker ©Ò¹B§@¤§¥­¥xªº«Â¯Ù¡CBitLocker ¹ï¨C¤@ºØ¤£¦PªºÅçÃÒ¼Ò¦¡³£¦³¯S©wªºµwÅé»Ý¨D¡C­Y­nÓV½w³oÃþ«Â¯Ù¡A¦Ó¥B­n¹ê»Ú¹F¨ì³Ì°ª¦w¥þ©Ê§Q¯q¡A«h¥²¶·²Å¦X©Ò¿ï¨úÅçÃÒ¼Ò¦¡ªº³o¨Ç»Ý¨D¡C¨Ò¦p¡A¦pªG¨Ï¥Î TPM+PIN ÅçÃÒ¼Ò¦¡¡A¨Ï¥ÎªÌ¥²¶·½T©w©Ò¨Ï¥Îªº¥­¥x¬O¹B¥Î»P TCG »Ý¨D§¹¥þ¬Û®eªº TPM 1.2 ª©¡C

¦]¨t²Î¨Ï¥Î±¡§Î¦Ó²£¥Íªº¼ç¦b«Â¯Ù¥i¥HÂǥѤU¦C³Ì¨Î¹ê§@¤èªk¦ÓÓV½w¡A·í¤¤»¡©ú¤F¨t²ÎÀ³¸Ó¦p¦ó³]©w¡A¥H¤Î¥¿½Tªº¨Ï¥ÎªÌ§@ªk¡C¨Ï¥ÎªÌÀ³¸Ó½T«O©w´Á¤U¸ü¤@¯ë³nÅé§ó·s¡A¨Ã¦w¸Ë¥i«OÅ@¨t²Î§K©ó¾D¨ü§ðÀ»ªº¦w¥þ©Ê³nÅé (¨Ò¦p¡G¨¾¤õÀð¡B¨¾¬r¡B¨¾¶¡¿Ò³nÅéµ¥µ¥)¡C¦¹¥~¡A¹ï©ó²£«~ªº¤é±`¨Ï¥Î¡A¾A·í¨Ï¥Î³Ì¨Î¤ÆªºÅçÃÒ§@·~¤Î­×´_¾÷¨î¤]¥i¥HÓV½w³oÃþ«Â¯Ù¡C¨Ò¦p¡A½T«O¾A·í³B²z±Ò°Êª÷Æ_ (¤]´N¬O¡A¤£­nÀH®É±Nª÷Æ_¯d¦b¾÷¾¹¸Ì)¡A¥H¨¾¤î¸ê®Æ¿ò¥¢©Î¾D¥¼±ÂÅv¨Ï¥ÎªÌ¦s¨ú¡A³£¯àÓV½w¹ï¸ê®Æ«O±Kªº«Â¯Ù¡C

¦^¨ì­¶­º¦^¨ì­¶­º

4. ¨t²Î¥Í©R¶g´Á

BitLocker ¨t²Î¥Í©R¶g´Á¤¤¦³¥|¤j­n¯À¡A¦p [¹Ï 3] ©Ò¥Ü¡C

BitLocker Drive Encryption ¥Í©R¶g´Á

[¹Ï 3]¡G BitLocker Drive Encryption ¥Í©R¶g´Á¡C

1.

¦w¸Ë¡GBitLocker ¤D¦w¸Ë¦¨ Windows Vista ªº¤@³¡¤À¡C

2.

ªì©l¤Æ¡GBitLocker ¥\¯à¤wªì©l¤Æ¨Ã¤w¶}±Ò¡C

3.

¤é±`¨Ï¥Î¡G¤é±`¨Ï¥Îªº±¡§Î¨Ì²Ä 2 ¶¥¬q©Ò¿ï¨úªº¿ï¶µ¦Ó©w¡A¥i¯à¨ã¦³¤£¦P¼h¦¸ªº«OÅ@¡C

4.

¹q¸£¨O´«¡G¤w±Ò¥Î BitLocker ¥\¯àªº¹q¸£»Ý­n¨O´«/¤É¯Å/­«·s³¡¸p¡C

¤U­±¦U¸`±N»¡©ú¤W­z¦UºØ­n¯À¡A¨Ã³z¹L­Ó®×ÄÄ­z³Ì±`¨£ªº BitLocker ¥[­È®×¨Ò¡C¸Ô²Óªº¬[ºc¹Ï½Ð°Ñ¾\¡Õ²Ä 3.2 ¸`¡Ö¡C

4.1 ¦w¸Ë

BitLocker ¬OÄÝ©ó Windows Vista ªº¤@³¡¤À¡A·|¦b¦w¸Ë Enterprise ©M Ultimate ª© OS ´Á¶¡¦Û°Ê¶i¦æ¦w¸Ë5 (½Ðª`·N¡A¥¦¤£·|¦Û°Ê¶}±Ò)¡C¦Ü©ó Windows Server "Longhorn"¡A±z¥²¶·¿ï¾Ü¦w¸Ë BitLocker Drive Encryption ¥\¯à¡C¦b§@·~¨t²Î¦w¸Ë´Á¶¡¡A·|¦³¤U¦C BitLocker ¨BÆJ (¥Î¤áºÝ©Î¦øªA¾¹³£¬Û¦P)¡G

1.

¦w¸Ë¾A·íªº BitLocker ÀɮסC

2.

Àˬd TPM/BIOS ªºª©¥»¬O§_¥¿½T¡C

3.

¦w¸Ë TPM ©M BitLocker ÅX°Êµ{¦¡¡C

4.2 ªì©l¤Æ

¦w¸Ë§@·~¨t²Î¨Ã¶i¦æªì©l³]©w¤§«á¡A¨t²ÎºÞ²z­ûÀH®É³£¥i¥H¨Ï¥Î Windows Vista ±±¨î¥x¡Aªì©l¤Æ©M¶}±Ò BitLocker ¥\¯à¡C³]©w§@·~¤¤¦³¨â­Ó¨BÆJ¡G

1.

³]©w TPM (¨C³¡¹q¸£¥u»Ý­n¶i¦æ¤@¦¸)¡C

2.

³]©w BitLocker (¨C­Ó§@·~¨t²Î¥u»Ý­n¶i¦æ¤@¦¸)¡C

³o¨â­Ó¨BÆJ³£»Ý­n¥»¾÷¨t²ÎºÞ²zÅv­­¡C¨S¦³¨t²ÎºÞ²zÅv­­ªº¨Ï¥ÎªÌ¥i¥H¦] BitLocker ¸ê®Æ«OÅ@¦ÓÀò¯q¡A¦ý¤£¯à¶}±Ò©ÎÃö³¬ BitLocker¡C

¥ø·~³¡¸p¡A¥]¬A Active Directory ³]©w¡BBitLocker ­ì«h¡A¤Î¥H«ü¥O½X¦w¸Ë³£·|¦b²Ä 4.2.3 ¸`¤¤°Q½×¡C

4.2.1 TPM ªì©l¤Æ

¨Ï¥Î¡uTPM ªì©l¤ÆºëÆF¡v©Î°õ¦æ¸g¹L¯S§O³]­p¥H¶i¦æªì©l¤Æªº«ü¥O½X¡Aªì©l¤Æ±zªº TPM¡C¡uTPM ªì©l¤ÆºëÆF¡v¥i¥H³z¹L TPM Management Console ºëÆF¦s¨ú¡A«áªÌ¬O¿í´` [¦w¥þ©Ê±±¨î¥x (Security Control Panel)] ¤¤ªº³sµ²¥[¥H±Ò°Ê¡C

¦b³o¨âºØ±¡ªp¤U¡Aªì©l¤Æ TPM6 ¥]§t¤U¦C¨BÆJ¡G

1.

¦pªG TPM ©|¥¼¶}±Ò¡A½Ð¶}±Ò TPM¡C®Ú¾Ú¹q¸£»s³y°Óªº±¡ªp¡A¶}±Ò¤èªk¦U¦³¤£¦P¡C

2.

Àˬd¹ê»Ú¦s¦bª¬ºA (¨t²ÎºÞ²z­û¥²¶·¿Ë¦Û¦b¥D±±¥x«e°õ¦æ§@·~)¡C

a. °£«D OEM ´£¨Ñ´À¥N©Êªº»·ºÝ³¡¸p¸Ñ¨M¤è®×

3.

µn¤J¦^¨ì Windows Vista¡C

4.

Àˬd TPM ¤§¤º¬O§_¦³­I®Ñª÷Æ_ (¥Ñ OEM ´£¨Ñªºª÷Æ_)¡C

5.

«Ø¥ß TPM ¨t²ÎºÞ²z±K½X¡A³]©w TPM ªº¾Ö¦³ªÌ¡C

6.

©e¥I TPM ¨t²ÎºÞ²z±K½Xµ¹ Active Directory (AD) ¨Ã/©ÎÀx¦s¦¨ÀɮסC

a. ½Ðª`·N¡A¦pªG¨t²ÎºÞ²z­û¤w³]©w¸s²Õ­ì«h (GP) ¨Ó°õ¦æµo§G¡AAD µo§G·|¥Ñ¨t²Î¦Û°Ê°õ¦æ¡C

¥t¥~Á٤䴩 TPM ªº»·ºÝªì©l¤Æ7¡CBitLocker ªº TPM ªA°È¤¸¥ó·|Åã¥ÜºÞ²z API¡A¤¹³\¥H«ü¥O½X°õ¦æªì©l¤Æµ{§Ç - ¥]¬A³]©w¾Ö¦³ªÌ¤Î«Ø¥ß TPM ¨t²ÎºÞ²z±K½X¡C

TPM ªì©l¤Æ§@·~§Y¤w§¹¦¨¡C±N TPM ªì©l¤Æ¤§«á¡A¥»¾÷¨t²ÎºÞ²z­û§Y¥iªì©l¤Æ BitLocker¡C

4.2.2 ¶}±Ò BitLocker Drive Encryption

­Y­n¶}±Ò Windows Vista ªº BitLocker Drive Encryption ¥\¯à¡A½Ð¨Ï¥Î¸Ó¥\¯àªººëÆF©Î«ü¥O½X¡C

¦b [Windows Vista ¸ê°T¦w¥þ¤¤¤ß] ­±ªO¤¤±Ò°Ê¡uBitLocker ³]©wºëÆF¡v¡A±N·|±a±z³v¨B§¹¦¨¤U¦C¨BÆJ¡G

1.

±Ò¥Î Windows Vista ºÏºÐ°Ïªº BitLocker 6¡C

2.

¿ï¾Ü­×´_¤èªk¡C

3.

«ö¤@¤U [¶}±Ò BitLocker—ü (Turn On BitLocker—ü)] ³sµ²¡AÄ~Äò¶i¦æºÏºÐ°Ï¥[±K§@·~¡C¥[±K§@·~´Á¶¡¡ABitLocker ·|¦bÅã¥Ü­I´º¥[±K¶i«×¦C©M¨t²Î§X¹Ï¥Ü¡C

¡uBitLocker ³]©wºëÆF¡v¤¹³\¥»¾÷¨t²ÎºÞ²z­û±Ò¥Î BitLocker¡C¨t²ÎºÞ²z­û¥i¨Ï¥Î¦¹ºëÆF«ü©w¥[±Kª÷Æ_ªº«OÅ@¤è¦¡¡A¨Ã¶}©l°õ¦æ¥]§t Windows Vista ªººÏºÐ°Ï¥[±K§@·~¡C

¡uBitLocker ³]©wºëÆF¡vªº¾ã­Ó¬yµ{Åã¥Ü©ó¤U­±ªº [¹Ï 4] ¤¤¡C¥»¹Ï¥Øªº¦bÅã¥Üµe­±ªº¶¶§Ç¡A¦Ó¤£¦bÅã¥Ü¨C¤@­Ó¿Ã¹õÂ^¨úµe­±¡C¨C¤@­Ó¿Ã¹õÂ^¨úµe­±¤U­±³£¦³»¡©ú¡C

BitLocker ³]©wºëÆF UI ¬yµ{

[¹Ï 4]¡G BitLocker ³]©wºëÆF UI ¬yµ{¡C
¬d¬Ý§¹¾ã¤j¤p¼v¹³

±Ò°Ê¿ï¶µ

±Ò°ÊÅçÃҿﶵ¥]¬A¡G

¶È TPM (²¤¹Lµe­± 2a ©M 2b)¡F

TPM+PIN (¨Ï¥Îµe­± 2a¡A¦ý¤£¥Î 2b)¡F

TPM+±Ò°Êª÷Æ_ (¨Ï¥Îµe­± 2b¡A¦ý¤£¥Î 2a)¡A©Î¬O

¦b¥¼±Ò¥Î TPM ªº¹q¸£¤W¡A¶È±Ò°Êª÷Æ_ (¨Ï¥Îµe­± 2b)¡C

½Ðª`·N¡APIN ©M±Ò°Êª÷Æ_¤£¯àµ²¦X¹B§@¡C

«Ø¥ß±Ò°Ê PIN
µe­± 2a ´£¨Ñ¥i¿é¤J 4 ¦Ü 20 ¦ì¼Æ PIN ªº¿ï¶µ¡F¨C¦¸­«·s±Ò°Ê³£¥²¶·¿é¤J PIN¡F³o¼Ë´N·|¬°¥[±KªººÏºÐ°Ï¦h³]¤@¹DÅçÃÒ«OÅ@Ãö¥d¡C½Ð°Ñ¾\¡Õ²Ä 4.3.2 ¸`¡Ö¡A¥H¨ú±o§ó¸Ô²Ó¸ê°T¡Cºô°ì¨t²ÎºÞ²z­û¥i¥H¨Ï¥Î¸s²Õ­ì«h¡A­n¨D©Î¤£¤¹³\«Ø¥ß PIN¡C

«Ø¥ß¨ÃÀx¦s±Ò°Êª÷Æ_
µe­± 2b ´£¨Ñ¥i«Ø¥ß±Ò°Êª÷Æ_¡A¨ÃÀx¦s¦b USB §Ö°{ºÏºÐ¤Wªº¿ï¶µ¡F¨C¦¸­«·s±Ò°Ê¡A³s±µ°ð³£¥²¶·¦³±Ò°Êª÷Æ_¡F³o¼Ë´N·|¬°§@·~¨t²ÎºÏºÐ°Ï¦h³]¤@¹DÅçÃÒ«OÅ@Ãö¥d¡C½Ð°Ñ¾\¡Õ²Ä 4.3.2 ¸`¡Ö¡A¥H¨ú±o§ó¸Ô²Ó¸ê°T¡Cºô°ì¨t²ÎºÞ²z­û¥i¥H¨Ï¥Î¸s²Õ­ì«h¡A­n¨D©Î¤£¤¹³\±Ò°Êª÷Æ_¡C

­×´_¿ï¶µ

¥»¾÷¨t²ÎºÞ²z­û¥i¥H³]©w­×´_¾÷¨î¡A¦b¤£¤Ó¥i¯àµo¥Í°ÝÃDªº±¡ªp¤U¡A¥R¤Àµo´§¨Ï¥Î«K§Q©Ê (½Ð°Ñ¾\¡Õ²Ä 5 ¸`¨t²Î­×´_¡Ö¡A¥H¨ú±o¸Ô²Ó¸ê°T)¡C

¨Ï¥Î­×´_±K½X
µe­± 3 ´£¨Ñ¥i«Ø¥ß­×´_±K½Xªº¿ï¶µ¡C½Ð°Ñ¾\¡Õ²Ä 5 ¸`¨t²Î­×´_¡Ö¡A¥H¨ú±o¦b¸ê®Æ­×´_ª¬ªp¤U¦p¦ó¨Ï¥Î­×´_±K½Xªº¬ÛÃö¸ê°T¡Cºô°ì¨t²ÎºÞ²z­û¥i¥H¨Ï¥Î¸s²Õ­ì«h¡A­n¨D©Î¤£¤¹³\«Ø¥ß­×´_±K½X¡C¹w³]­È¬O­n¨D­×´_±K½X¡C

Àx¦s­×´_±K½X
µe­± 4 ´£¨Ñ¦h­ÓÀx¦s­×´_±K½Xªº¿ï¶µ¡A¨ä¤¤¥]¬AÅã¥Ü±K½X¡B±N¤§Àx¦s¦¨ÀɮסB¤Î/©Î¦C¦Lµ¥¥\¯à¡C½Ð°Ñ¾\¡Õ²Ä 5 ¸`¨t²Î­×´_¡Ö¡A¥H¨ú±o¦b¸ê®Æ­×´_ª¬ªp¤U¦p¦ó¨Ï¥Î­×´_±K½Xªº¬ÛÃö¸ê°T¡Cºô°ì¨t²ÎºÞ²z­û¥i¥H¨Ï¥Î¸s²Õ­ì«h¡A­n¨D©Î¤£¤¹³\«Ø¥ß­×´_±K½X¡C¹w³]­È¬O­n¨D­×´_±K½X¡C

±N­×´_±K½XÀx¦s¦Ü USB ºÏºÐªº¿ï¶µ
µe­± 4a ´£¨Ñ¥i±N­×´_±K½X¥H¤å¦rÀÉÀx¦s¦Ü USB §Ö°{ºÏºÐªº¿ï¶µ¡C¦¹¥~¡A¦pªG¸s²Õ­ì«h¤¹³\¡AÁÙ·|«Ø¥ß­×´_ª÷Æ_ (¬Û·í©ó¤H¤u¥iŪ¨ú­×´_±K½Xªº¾÷¾¹¥iŪ¨úª÷Æ_)¡A¨ÃÀx¦s¦Ü USB §Ö°{ºÏºÐ¤W¡C½Ð°Ñ¾\¡Õ²Ä 5 ¸`¨t²Î­×´_¡Ö¡A¥H¨ú±o¦b¸ê®Æ­×´_ª¬ªp¤U¦p¦ó¨Ï¥Î­×´_±K½Xªº¬ÛÃö¸ê°T¡Cºô°ì¨t²ÎºÞ²z­û¥i¥H¨Ï¥Î¸s²Õ­ì«h¡A­n¨D©Î¤£¤¹³\«Ø¥ß­×´_ª÷Æ_¡C

Åã¥Ü­×´_±K½Xªº¿ï¶µ
µe­± 4b ´£¨Ñ¨Ï¥ÎªÌ¥iÅã¥Ü­×´_±K½Xªº¿ï¶µ¡C

¦C¦L­×´_±K½Xªº¿ï¶µ
µe­± 4c ´£¨Ñ¨Ï¥ÎªÌ¥i¦C¦L­×´_±K½Xªº¿ï¶µ¡C

±N­×´_±K½XÀx¦s¦Ü¸ê®Æ§¨ªº¿ï¶µ
µe­± 4d ´£¨Ñ¥i±N­×´_±K½X (¤Î¨ä¬ÛÃöÁp­×´_ª÷Æ_) ¥HÀÉ®×Àx¦s¦Ü¸ê®Æ§¨ (¦pºô¸ô¦@¥Î¤Wªº¸ê®Æ§¨) ªº¿ï¶µ¡Cºô°ì¨t²ÎºÞ²z­û¥i¥H¨Ï¥Î¸s²Õ­ì«h¡A­n¨D©Î¤£¤¹³\±N­×´_ª÷Æ_Àx¦s¦Ü¸ê®Æ§¨¡A©Î³]©w©Ò¨Ï¥Îªº¹w³]¸ê®Æ§¨¸ô®|¡C

µL­×´_¾÷¨îĵ§i
µe­± 5 Åã¥Üĵ§i¡A´£¿ô¨Ï¥ÎªÌ¡A¦pªG¨S¦³¿ï¾Ü­×´_¾÷¨î¡A«h¦b¨S¦³­×´_¾÷¨î¤U¥i¯à·|¾É­P¸ê®Æ¥Ã¤[¿ò¥¢¡C³o­Ó¹ï¸Ü¤è¶ô¥i¥H¥Ñºô°ì¨t²ÎºÞ²z­û³z¹L¸s²Õ­ì«h¥[¥H°±¥Î¡C

¥[±K§@·~¤w´Nºü¥i¥H¶}©lªº³qª¾
µe­± 6 ´£¨Ñ¥i¶}©l¶i¦æºÏºÐ°Ï¥[±K§@·~ªº³qª¾¡C³o¶µªì©lºÏºÐ°Ï¥[±K§@·~©Ò»Ýªá¶Oªº®É¶¡»PºÏºÐ°Ïªº¤j¤p¦³ª½±µÃö«Y¡C¦ý¬O¡A¥[±K§@·~¬O¦b­I´º¤¤°õ¦æ¡A¥H«K¦bºÏºÐ°Ï¶i¦æ¥[±K®É¡AÅý¹q¸£Ä~Äò¨Ñ¤H¨Ï¥Î¡C°£¦¹¤§¥~¡A¨t²ÎºÞ²z­û¥i¥HÀH®É¼È°±¨Ã«ì´_¥[±K§@·~¡C¥[±K§@·~·|¦Û°Ê¼È°±¡AÅý¹q¸£Ãö¾÷©Î¥ð¯v¡A¦Ó¥B¥i¥H¦b¹q¸£­«·s¶}±Ò®É¡AÄ~Äò¶i¦æ¥[±K§@·~¡C

¥»¾÷¨t²ÎºÞ²z­û¥Ø«e¤£»Ý­n¨Ï¥Îµe­± 6 ¨Ó¶}©l¥[±K - ¥»¾÷¨t²ÎºÞ²z­û¥i¥Hµy«á¦A¶}±Ò³o¶µ¥\¯à¡AºÏºÐ°Ï´N·|¦b¤U¤@¦¸­«·s¶}¾÷®É¡A±Ò°ÊºÏºÐ°Ï¥[±K¡CBitLocker ¤]¥i¥H¥Ñ¥»¾÷¨t²ÎºÞ²z­ûÀH®É¥[¥HÃö³¬¡C

¨Ï¥ÎªÌ¤¶­±¤ä´©

1.

¦b [±±¨î¥x] ªº [¦w¥þ©Ê] °Ï°ì¤¤¨µÄý¦Ü BitLocker ¶µ¥Ø¡A¥H¶}±Ò BitLocker—ü¡C

«ö¤@¤U [¶}±Ò BitLocker—ü (Turn On BitLocker—ü)]¡A¥H°õ¦æ¡uBitLocker ³]©wºëÆF¡v¡C

«Ø¥ß­×´_ª÷Æ_©M/©Î­×´_±K½X¡A§@¬°³]©wµ{§Çªº¤@³¡¤À¡A²¤¹L©Ò¦³¨ä¥L¿ï¶µ¡C

2.

¥²­n®É¡A±z¥i¥H¨µÄý¦Ü¬Û¦Pªº±±¨î¥x¶µ¥Ø¡A¥HÃö³¬ BitLocker—ü¡C

«ü¥O½X¤ä´©8

1.

¨Ï¥Î ProtectKeyWithTPM¡A«OÅ@ TPM ºÏºÐ°Ï¥[±Kª÷Æ_ªº¦w¥þ¡C

2.

«Ø¥ß­×´_ blob¡C

¨Ï¥Î ProtectKeyWithExternalKey «Ø¥ß­×´_ª÷Æ_¡C

¨Ï¥Î ProtectKeyWithNumericalPassword «Ø¥ß­×´_±K½X¡C

3.

¨Ï¥Î Encrypt ¥[±KºÏºÐ°Ï¡C

4.

¨Ï¥Î GetConversionStatus «ü¥ÜºÏºÐ¾÷¤w¸g§¹¾ã¥[±K¡C

5.

¨Ï¥Î GetProtectionStatus ½T©w¤w¶}±Ò BitLocker «OÅ@¡C

6.

[¨Ï¥Î Decrypt ±NºÏºÐ°Ï¸Ñ±K¡A¨ÃÃö³¬ BitLocker «OÅ@]¡C

4.2.3 ¥ø·~³¡¸p

BitLocker ¤ä´©¥H«ü¥O½X°õ¦æ¡A¦Ó¥B»´©ö´N¯à»P Active Directory ©M¸s²Õ­ì«h§Þ³N¾ã¦X¡C¦b¥ø·~³¡¸p¤¤¡AIT ¨t²ÎºÞ²z­û»Ý¿í´`¤U¦C¨BÆJ¡G

1.

³v¨B¶i¦æ¤U¦C¨BÆJ¡A·Ç³Æ Active Directory ¨Ñ BitLocker (TPM ©M­×´_) ª÷Æ_¨Ï¥Î¡G

BitLocker ©Ò¨Ï¥Îªºª÷Æ_¥i¥HÀx¦s¦b Active Directory ¤¤ (TPM ª÷Æ_©M/©Î­×´_ª÷Æ_)¡C

¨ã³Æ TPM ©M BitLocker ÄݩʤΪ«¥óªº©µ¦ù¬[ºc (¤£¾A¥Î©ó Windows Server "Longhorn")¡C

³]©w TPM ©M BitLocker ­×´_¸ê°Tµ²ºcª«¥ó¤WªºÅv­­

§ä¥X¥]§t¬[ºc©µ¦ùªº«ü¥O½X¡A¦W¬° Add-WriteACEs.vbs¡C

«ü¥O½X·|°²³]¤w³]©w±q°ª¼hºô°ìª«¥óÄ~©ÓÅv­­¦Ü¥Ø¼Ð¹q¸£ª«¥ó¡C¦pªG¶¥¼h¬[ºc¤¤ªº¥ô¦ó®e¾¹¤£¤¹³\±q¤÷¶µÄ~©ÓªºÅv­­¥Í®Ä¡A±NµLªkµø»Ý­n³]©wÅv­­¡C

¦b©R¥O´£¥Ü¤U°õ¦æ«ü¥O½X Add-WriteACEs.vbs¡C

2.

³]©w»P BitLocker ¬ÛÃöªº¸s²Õ­ì«h¡C

³]©w¸s²Õ­ì«h¡A¥H±Ò¥Î±q BitLocker ©M TPM ­×´_¸ê°T³Æ¥÷¦Ü Active Directory ªº§@·~¡C

³]©w­ì«h¡A¥H°õ¦æ¤U¦C¦U¶µ¡G

«Ø¥ß­n±Ò¥Î/°±¥Î/¿ï¥Îªº¦w¥þ©Ê®×¨Ò¡C

­n±Ò¥Î/°±¥Î/¿ï¥Îªº­×´_¾÷¨îµ¥¡C

­×§ï¹w³]­È - ¥ç§Y¡G¤@¤Á³£¥i¥H¿ï¥Î¡A¥u¦³­×´_±K½X°£¥~¡A¥¦¬O±j¨î©Êªº¡CºëÆF³]©wªº¸s²Õ­ì«h³]©w¨S¦³«ü¥O½X¤ä´©¡C

³]©w¥[±K»PÅçÃÒ­ì«h (¨Ò¦p¡AºÏºÐ°Ïªº¥[±K¤èªk)¡C

3.

¦b¥Î¤áºÝ¹q¸£¤W¦w¸Ë Windows Vista¡C

4.

BitLocker ¦w¸Ëµ{¦¡¡G

¥H«ü¥O½X°õ¦æªº TPM ªì©l¤Æ¡C

Àx¦s¦Ü Active Directory ªº TPM ¾Ö¦³ªÌ±K½X¡C

»·ºÝ°õ¦æªº«ü¥O½X¡A¥H³]©w BitLocker ­ì«h¡A±N­×´_±K½XÀx¦s¦Ü AD¡C

5.

¨Ï¥Î¨t²ÎºÞ²z¤u¨ã¡AÀˬd½]®Ö°O¿ýÀÉ¡A¥H¶¶§Q¥[±K¡C

4.3 ¤é±`¨Ï¥Î

¨Ï¥Î¶È TPM ÅçÃÒ¥B¤w±Ò¥Î BitLocker ªº¨t²Î¥i¥H¹³¨ä¥L¥ô¦ó¨t²Î¤@¼Ë¨Ï¥Î¡C¨Ï¥ÎªÌ±Ò°Ê Windows¡A¨Ã¥B±µ¨ì´£¥Ü¡A­n¨D¿é¤J¨äºô°ì¨Ï¥ÎªÌ¦WºÙ©M±K½X¡A³o¬O¤@¯ëªºµn¤J¸gÅç¡C°£«D±µ¨ì¦³Ãö¸Ó¥\¯àªº³qª¾¡A§_«h¥L­Ì¤£·|¹îı¨ì¹q¸£¤W¥t¥~¥[¤F¤@¼h«OÅ@¡C

¦b³]©w¬°¼W±j¦¡¦w¥þ©Ê®×¨Òªº¨t²Î¤W¡A¥i¯à·|­n¨D¨Ï¥ÎªÌ¿é¤J PIN¡A©Î´¡¤J USB §Ö°{ºÏºÐ¡A¥H«K±Ò°Ê Windows Vista (¦p»Ý¸Ô²Ó¸ê°T¡A½Ð°Ñ¾\¡Õ²Ä 4.3.2 ¸`¼W±j¦¡«OÅ@¨Ï¥Î®×¨Ò¡Ö)¡C¦b¦¹±¡ªp¤U¡A·|­×§ï¥¿±`¶}¾÷©Î«ì´_¬yµ{¡A¥H«Kµo¥X´£¥Ü¨ú±oÃB¥~ªº¦w¥þ©Ê»Ý¨D¡C

4.3.1 BitLocker Drive Encryption °ò¥»®×¨Ò

³o¬O¤W­z»¡©úªº°ò¥»®×¨Ò¡C¥¦ªºÀuÂI¬O¥¦¬O³Ìª½±µ¤F·íªº¨Ï¥Î¼Ò¦¡¡C¹q¸£¥]§t¬Û®eªº TPM (1.2 ª©¡A¨ã³Æ BIOS ¤ä´©)¡A¦Ó¥B¦³¨â­ÓºÏºÐ°Ï¡G(1) ¨t²ÎºÏºÐ°Ï©M (2) §@·~¨t²ÎºÏºÐ°Ï¡Aªþ¤ä´© BitLocker Drive Encryption ªº Windows ª©¥»¡C

¥H TPM «OÅ@¡A¦s¨ú¤w±Ò¥Î BitLocker Drive Encryption ªººÏºÐ°Ï

[¹Ï 5]¡G¥H TPM «OÅ@¡A¦s¨ú¤w±Ò¥Î BitLocker Drive Encryption ªººÏºÐ°Ï¡C
¬d¬Ý§¹¾ã¤j¤p¼v¹³

BitLocker Drive Encryption ªº¥D­n¥\¯à (¦p [¹Ï 5] ©Ò¥Ü) ¬O«OÅ@µwºÐ§@·~¨t²ÎºÏºÐ°Ï¤Wªº¨Ï¥ÎªÌ¸ê®Æ¡C­Y­n¹F¦¨¦¹¥Ø¼Ð¡AºÏºÐ°Ï¥²¶·¥H§¹¾ãºÏºÐ°Ï¥[±Kª÷Æ_ (Full Volume Encryption Key¡AFVEK) ¶i¦æ¥[±K¡A³o¥Ã»·³£¬O¥HºÏºÐ°Ï¥D­nª÷Æ_ (Volume Master Key¡AVMK) ¶i¦æ¥[±K¡A¦¹ª÷Æ_¤SÂà¥Ñ TPM ¶i¦æ¥[±K¡C

³oºØ®×¨Ò¥i¥H¥Ñ¥»¾÷¨t²ÎºÞ²z­û¨Ï¥Î [Windows Vista ±±¨î¥x¦w¥þ©Ê] µe­±¥[¥H±Ò¥Î©Î°±¥Î¡CÃö³¬ BitLocker ·|±NºÏºÐ°Ï¸Ñ±K¡A¨Ã²¾°£©Ò¦³ª÷Æ_¡C·sªºª÷Æ_±N¦bµy«á­«·s¶}±Ò BitLocker «á«Ø¥ß¡C

·í¥»¾÷¨t²ÎºÞ²z­û¶}±Ò BitLocker ®É¡A±j¯P«Øij«Ø¥ß­×´_±K½X©Î­×´_ª÷Æ_¡C¨S¦³­×´_ª÷ìC©Î­×´_±K½X¡A¤w¥[±KºÏºÐ¾÷¤Wªº©Ò¦³¸ê®Æ¥i¯à³£µLªk¦s¨ú¡A¦Ó¥B¤@¥¹¥X¤F®t¿ù¡A¤]µLªk­×´_¡I

4.3.2 ¼W±j¦¡«OÅ@¨Ï¥Î®×¨Ò

¹q¸£¾Ö¦³ªÌ·Q­n¹ï¨t²Î¤Wªº¸ê®Æ¨Ï¥ÎÂù­««OÅ@¡C

¦p [¹Ï 6] ©Ò¥Ü¡ABitLocker ´£¨Ñ¨âºØ¦h«Y¼Æ«OÅ@¿ï¶µ¡GTPM ´£¨Ñ»P¤U¦C¤GªÌ¨Ã¦sªº¨t²Î§¹¾ã©Ê¦]¯À¡G(1) PIN (¨Ï¥ÎªÌª¾¹Dªº)¡A©Î (2) Àx¦s¦b USB §Ö°{ºÏºÐ¤WªºÃB¥~ª÷Æ_ (¨Ï¥ÎªÌ¾Ö¦³ªº)¡C¨Ï¥ÎÀx¦s¦b USB §Ö°{ºÏºÐ¤Wªºª÷Æ_¡A¦³¤@¶µ³Ì­«­nªºÀuÂI¡A´N¬O¦b³oÃþ®×¨Ò¤¤¡A¨Ã«D©Ò¦³ª÷Æ_¸ê®Æ³£¦b¥»¾÷¹q¸£¤W¡C

¦s¨ú¦³¼W±j¦¡«OÅ@¥B¤w±Ò¥Î BitLocker ªººÏºÐ°Ï

[¹Ï 6]¡G¥H¼W±j¦¡«OÅ@¡A¦s¨ú¤w±Ò¥Î BitLocker ªººÏºÐ°Ï¡C
¬d¬Ý§¹¾ã¤j¤p¼v¹³

4.3.2.1 PIN ÅçÃÒ
PIN ÅçÃҮרÒ9ªºÀuÂI¬O¡G´£¨ÑÂù«Y¼ÆÅçÃÒ¡A¯ÊÂI¬O¡G¨C¦¸¶}¾÷³£»Ý­n PIN¡C¦b¦¹ÅçÃҮרҤ¤¡A¨t²ÎºÞ²z­û·|¦b¶}±Ò BitLocker ®É³]©w PIN¡CBitLocker ¨Ï¥Î SHA-256 Âø´ê³B²z¨Ï¥ÎªÌ«ü©wªº PIN¡A¦ÓÂø´êªº«e 160 ­Ó¦ì¤¸³£¥Î§@¬°¶Ç°eµ¹ TPM ¥H±K«Ê VMK ªº±ÂÅv¸ê®Æ¡C²{¦b VMK ¬O¦P®É¥H TPM ©M PIN ¥[¥H«OÅ@¡C­Y­n¶}«Ê VMK¡A¨t²Î·|­n¨D¨Ï¥Î¦b¨C¦¸¹q¸£­«·s¶}¾÷©Î±q¥ð¯vª¬ºA­«·s±Ò°Ê®É¿é¤J PIN¡C

¨Ï¥ÎªÌ¤¶­±¤ä´©

1.

¦b [±±¨î¥x] ªº [¦w¥þ©Ê] °Ï°ì¤¤¡A¨µÄý¦Ü BitLocker ¶µ¥Ø¥H¶}±Ò BitLocker¡A¨Ã±Ò¥Î PIN ¤ä´©10¡C

«ö¤@¤U [¶}±Ò BitLocker—ü (Turn On BitLocker—ü)]¡A¥H°õ¦æ¡uBitLocker ³]©wºëÆF¡v¡C

«Ø¥ß­×´_ª÷Æ_©M/©Î­×´_±K½X¡A§@¬°³]©wµ{§Çªº¤@³¡¤À¡C

¨Ï¥Î [¬O§_«Ø¥ß PIN¡H (Create PIN?)] ¹ï¸Ü¤è¶ô¡A¥H±Ò¥Î PIN ÅçÃÒ ([¹Ï 4] ¤¤ªºµe­± 2a)¡A¨Ã«Ø¥ß PIN¡C

2.

³z¹L BitLocker ±±¨î¥x¶µ¥Ø¤¤ªº¡uºÞ²zª÷Æ_¡v³sµ²¡A­«³]©ÎÅܧó PIN¡C

«ü¥O½X¤ä´©

a) ­Y­n±Ò¥Î PIN ÅçÃÒ

1.

¨Ï¥Î ProtectKeyWithTPMAndPIN «OÅ@ TPM ºÏºÐ°Ï¥[±Kª÷Æ_ªº¦w¥þ¡A¨Ã¥H PIN ÅçÃÒ¥[±j¨ä¦w¥þ©Ê¡C

½Ðª`·N¡A§Y¨Ï¤w¦³¶È TPM ÅçÃÒ blob¡A©Î¤w¶}±Ò BitLocker «OÅ@¡A¤]¥i¥H¨Ï¥Î³o­Ó¤èªk¡C

2.

«Ø¥ß­×´_ blob¡G

¨Ï¥Î ProtectKeyWithExternalKey «Ø¥ß­×´_ª÷Æ_¡C

¨Ï¥Î ProtectKeyWithNumericalPassword «Ø¥ß­×´_±K½X¡C

3.

¨Ï¥Î Encrypt ¥[±KºÏºÐ°Ï¡C

4.

¨Ï¥Î GetConversionStatus «ü¥ÜºÏºÐ¾÷¤w¸g§¹¾ã¥[±K¡C

5.

¨Ï¥Î GetProtectionStatus ½T©w¤w¶}±Ò BitLocker «OÅ@¡C

b) ­Y­n°±¥Î PIN ÅçÃÒ

1.

¨Ï¥Î ¨Ï¥Î Decrypt ±NºÏºÐ°Ï¸Ñ±K¡A¨ÃÃö³¬ BitLocker «OÅ@¡C

2.

¨Ï¥Î DeleteKeyProtector ²¾°£ TPM ¥[ PIN ÅçÃÒ blob¡C

3.

[¦A¦¸¨Ï¥Î ProtectKeyWithTPMAndPIN ­«·s«Ø¥ß TPM ¥[ PIN blob (¥i¯à¨Ï¥Î¤£¦Pªº PIN)]¡C

¤@¯ë¨Ó»¡¡A¦b¦Ò¼{¨ì­«·s¶}¾÷³t«×¡A©Î¦]¤H¬°¤z¹w¦ÓµLªk­«·s¶}¾÷ªº¦øªA¾¹¤W±Ò¥Î PIN ¥\¯à¨Ã¤£¬O³Ì¨Î¹ê§@¤èªk¡C¦³¤@ºØ¥i¦æªº³¡¸p®×¨Ò¬O¡G¦b­û¤u¨C¦¸¶}©l¤W¯Z³£¥²¶·¶}±Ò¦øªA¾¹ªº¤À¤½¥q¤¤¡A¶}±Ò BitLocker ©M PIN ¥\¯à¡C¦b¦¹®×¨Ò¤¤¡A­t³dªº¤H·|ª¾¹D¨Ã¦b¶}¾÷®É¿é¤J PIN¡C

4.3.2.2 ±Ò°Êª÷Æ_ÅçÃÒ

Âù«Y¼Æª÷Æ_«OÅ@®×¨Ò´£¨Ñ¨â­ÓÅçÃÒ«Y¼Æ¡C¦¹®×¨Ò¥i¥[¥H±Ò¥Î©Î°±¥Î¡A±q [Windows Vista ±±¨î¥x¦w¥þ©Ê] µe­±¶}©l¡AµM«á¨Ï¥ÎÀH«áªº [«Ø¥ß±Ò°Êª÷Æ_ (Create Startup Key)] ¤u§@µe­± (½Ð°Ñ¾\¡Õ²Ä 4.2.2 ¸`¡Ö¤¤ªºµe­± 2b)¡C¦b¦¹®×¨Ò¤¤¡A±Ò°Êª÷Æ_¬OÀx¦s¦b¥ô¦ó BIOS ¦CÁ|ªºÀx¦s¸Ë¸m¤W (¨Ò¦p¡A¥~±¾¦¡ USB §Ö°{ºÏºÐ)¡A¦Ó¥B¨Ï¥ÎªÌ¥²¶·¦b¨C¦¸¹q¸£¶}¾÷®É¡A±N¸Ó¸Ë¸m´¡¤J¹q¸£11¡CÁöµM¦s©ñ±Ò°Êª÷Æ_ªº USB §Ö°{ºÏºÐ¥²¶·¦b¶}±Ò¹q·½¤@ª½¨ì¶}¾÷®É´¡¤J¹q¸£¤¤¡A¦ý¤]À³¸Ó¦b Windows µn¤J§¹¦¨«á²¾°£¡C

¨Ï¥ÎªÌ¤¶­±¤ä´©

1.

¦b [±±¨î¥x] ªº [¦w¥þ©Ê] °Ï°ì¤¤¨µÄý¦Ü BitLocker ¶µ¥Ø¡A¥H¶}±Ò BitLocker ¨Ã±Ò¥Î±Ò°Êª÷Æ_¤ä´©¡C

«ö¤@¤U [¶}±Ò BitLocker—ü (Turn On BitLocker—ü)]¡A¥H°õ¦æ¡uBitLocker ³]©wºëÆF¡v¡C

«Ø¥ß­×´_ª÷Æ_©M/©Î­×´_±K½X¡A§@¬°³]©wµ{§Çªº¤@³¡¤À¡C

¨Ï¥Î [«Ø¥ß±Ò°Êª÷Æ_¡A¥H¥[±j¦w¥þ©Ê (Create a startup key for added security)] ¹ï¸Ü¤è¶ô¡A¥[¤J±Ò°Êª÷Æ_¡C

½Ð°Ñ¾\¡Õ²Ä 4.2.2 ¸`¡Ö¤¤ªºµe­± 2b¡A¥H¨ú±o¸Ô²Ó¸ê°T¡C

2.

³z¹L BitLocker ±±¨î¥x¶µ¥Ø¤¤ªº [ºÞ²zª÷Æ_ (Manage Keys)] ³sµ²¡A½Æ»s±Ò°Êª÷Æ_¡C

«ü¥O½X¤ä´©

a) ­Y­n±Ò¥Î±Ò°Êª÷Æ_ÅçÃÒ

1.

¨Ï¥Î ProtectKeyWithTPMAndStartupKey «OÅ@ TPM ºÏºÐ°Ï¥[±Kª÷Æ_ªº¦w¥þ¡A¨Ã¥H±Ò°Êª÷Æ_ÅçÃÒ¥[±j¨ä¦w¥þ©Ê¡C

½Ðª`·N¡A§Y¨Ï¤w¦³¶È TPM ÅçÃÒ blob¡A©Î¤w¶}±Ò BitLocker «OÅ@¡A¤]¥i¥H¨Ï¥Î³o­Ó¤èªk¡C

2.

«Ø¥ß­×´_ blob¡C

¨Ï¥Î ProtectKeyWithExternalKey «Ø¥ß­×´_ª÷Æ_¡C

¨Ï¥Î ProtectKeyWithNumericalPassword «Ø¥ß­×´_±K½X¡C

3.

¨Ï¥Î Encrypt ¥[±KºÏºÐ°Ï¡C

4.

¨Ï¥Î GetConversionStatus «ü¥ÜºÏºÐ¾÷¤w¸g§¹¾ã¥[±K¡C

5.

¨Ï¥Î GetProtectionStatus ½T©w¤w¶}±Ò BitLocker «OÅ@¡C

a) ­Y­n°±¥Î±Ò°Êª÷Æ_ÅçÃÒ

1.

¨Ï¥Î Decrypt ±NºÏºÐ°Ï¸Ñ±K¡A¨ÃÃö³¬ BitLocker «OÅ@¡C

2.

¨Ï¥Î DeleteKeyProtector ²¾°£ TPM ©M±Ò°Êª÷Æ_ÅçÃÒ blob¡C

3.

[¦A¦¸¨Ï¥Î ProtectKeyWithTPMAndStartupKey ­«·s«Ø¥ß TPM ©M±Ò°Êª÷Æ_ blob (¥i¯à¨Ï¥Î¤£¦Pªº±Ò°Êª÷Æ_)]¡C

4.3.3 ¶È±Ò°Êª÷Æ_¨Ï¥Î®×¨Ò

¹q¸£¾Ö¦³ªÌ¥i¯à­n«OÅ@¤£¥]§t v1.2 TPM ¤§¹q¸£¤Wªº¸ê®Æ¡C¦b³oºØ®×¨Ò¤¤¡A¹q¸£¾Ö¦³ªÌÄ@·N¦b¨C¦¸¹q¸£±Ò°Ê©Î¥ð¯v«á«ì´_®É¡A­n¨D¹q¸£¨Ï¥ÎªÌ¡A´¡¤J¥]§t±Ò°Êª÷Æ_ªº USB §Ö°{ºÏºÐ¡C½Ðª`·N¡A¨Ï¥Î¶È±Ò°Êª÷Æ_®×¨Òªº¨t²Î¦w¥þ©Ê³]©wÀɱN»P¨Ï¥Î TPM ªº¨t²Î«OÅ@¤£¦P¡A¦]¬°¦b«D TPM ¨t²Î¤W¤£·|ÅçÃÒ¦­´Á¶}¾÷¤¸¥óªº§¹¾ã©Ê¡C

³oºØ®×¨Ò·|³z¹L Windows ¤¤ BitLocker ±±¨î¥x¶µ¥Ø¶}±Ò©ÎÃö³¬¡C¥»¾÷¨t²ÎºÞ²z­û¥²¶·¦b¶}±Ò BitLocker—ü ®É¡A¨Ï¥ÎºëÆF¨Ó«Ø¥ß±Ò°Êª÷Æ_¡C³oºØ®×¨Ò¤]¥i¥H³z¹L«ü¥O½X¥[¥H±Ò¥Î¡CÃö³¬³oºØ®×¨Ò·|±j­¢ºÏºÐ°Ï¸Ñ±K¡A¨Ã²¾°£©Ò¦³ª÷Æ_¡F¦pªG±N¨Ó­«·s±Ò¥Î³oºØ®×¨Ò¡A´N¥²¶·­«·s«Ø¥ßª÷Æ_¡C

¨t²Î²£¥Í±Ò°Êª÷Æ_¥H«á¡A¨Ï¥ÎªÌ´¡¤J USB §Ö°{ºÏºÐ¡AµM«á¨t²Î±N±Ò°Êª÷Æ_Àx¦s¦b¸Ó¸Ë¸m¤W¡C¹q¸£µwºÐ¥²¶·¦³¨t²ÎºÏºÐ°Ï©M§@·~¨t²ÎºÏºÐ°Ï (¦p»Ý¦³Ãö¸Ó»Ý¨Dªº¸Ô²Ó¸ê°T¡A½Ð°Ñ¾\¡Õ²Ä 2.1 ¸`¨t²ÎµwÅé¡B¶´Åé©M³nÅé»Ý¨D¡Ö)¡C²{¦b¡A¨C¦¸±q¨ü BitLocker «OÅ@ªººÏºÐ°Ï¤¤±Ò°Ê¹q¸£®É¡A¹q¸£¤¤´N¥²¶·¦³¸Ó¸Ë¸m¡C¨Ï¥ÎªÌ´¡¤J USB §Ö°{ºÏºÐ¡A¨Ã¶}±Ò¹q¸£¡C¹q¸£¶}¾÷¡A±Ò°Ê§@·~¨t²Î¡AµM«á¨Ï¥ÎªÌ´N¥i¥H¶}©l¥¿±`¨Ï¥Î¨t²Î¡C

¨Ï¥ÎªÌ¥i¥H¨Ï¥Î BitLocker ±±¨î¥x¶µ¥Ø¡A«Ø¥ß±Ò°Êª÷Æ_³Æ¥÷½Æ¥»¡C¦b¿ò¥¢¥~³¡¸Ë¸mªº±¡ªp¤U¡AºÏºÐ°Ï¥²¶·¨Ï¥Î­×´_ª÷Æ_©Î­×´_±K½X¶i¦æ­×´_¡AµM«á¥²¶·¦A²£¥Í·sªº±Ò°Êª÷Æ_¡C¨ä¥L¤]¨Ï¥Î±Ò°Êª÷Æ_ªº©Ò¦³ºÏºÐ°Ï³£¥²¶·¸g¹LÃþ¦üªºµ{§Ç¡A¥H½T«O¥¼±ÂÅvªº¨Ï¥ÎªÌ¤£·|¨Ï¥Î¿ò¥¢ªº±Ò°Êª÷Æ_¡C

¨Ï¥ÎªÌ¤¶­±¤ä´©

1.

¦b [±±¨î¥x] ªº [¦w¥þ©Ê] °Ï°ì¤¤¨µÄý¦Ü BitLocker ¶µ¥Ø¡A¥H¶}±Ò BitLocker ¨Ã±Ò¥Î±Ò°Êª÷Æ_¤ä´©¡C

«ö¤@¤U [¶}±Ò BitLocker—ü (Turn On BitLocker—ü)]¡A¥H°õ¦æ¡uBitLocker ³]©wºëÆF¡v¡C

«Ø¥ß­×´_ª÷Æ_©M/©Î­×´_±K½X¡A§@¬°³]©wµ{§Çªº¤@³¡¤À¡C

2.

«Ø¥ß¨ÃÀx¦s±Ò°Êª÷Æ_¡A§@¬° BitLocker ³]©wºëÆFªº¤@³¡¤À¡C

½Ð°Ñ¾\¡Õ²Ä 4.2.2 ¸`¡Ö¤¤ªºµe­± 2b¡A¥H¨ú±o¸Ô²Ó¸ê°T¡C

3.

Àx¦s¤w«Ø¥ßªº±Ò°Êª÷Æ_§@¬°ª÷Æ_ºÞ²zºëÆFªº¤@³¡¤À¡C

4.

¿é¤J±Ò°Êª÷Æ_§@¬°¶}¾÷µ{§Çªº¤@³¡¤À¡C

«ü¥O½X¤ä´©

a) ­Y­n±Ò¥Î¶È±Ò°Êª÷Æ_ÅçÃÒ

1.

¨Ï¥Î ProtectKeyWithExternalKey «Ø¥ß±Ò°Êª÷Æ_¡A¥Î§@¬°µL¬Û®e TPM ªº¹q¸£ªº±Ò°Êª÷Æ_¡C

§Y¨Ï¤w¦³±Ò°Êª÷Æ_ blob¡A©Î¤w¶}±Ò BitLocker «OÅ@¡A¤]¥i¥H¨Ï¥Î³o­Ó¤èªk¡C

2.

¨Ï¥Î SaveExternalKeyToFile ±N¥]§t±Ò°Êª÷Æ_ªºÀÉ®×¼g¤J USB §Ö°{ºÏºÐ©Î¨ä¥L¦ì¸m¡C

3.

¨Ï¥Î«Ø¥ß­×´_ blob¡C

¨Ï¥Î ProtectKeyWithExternalKey «Ø¥ß­×´_ª÷Æ_¡C

¨Ï¥Î ProtectKeyWithNumericalPassword «Ø¥ß­×´_±K½X¡C

4.

¨Ï¥Î Encrypt ¥[±KºÏºÐ°Ï¡C

5.

¨Ï¥Î GetConversionStatus «ü¥ÜºÏºÐ¾÷¤w¸g§¹¾ã¥[±K¡C

6.

¨Ï¥Î GetProtectionStatus ½T©w¤w¶}±Ò BitLocker «OÅ@¡C

7.

¨Ï¥Î UnlockWithExternalKey ¸Ñ°£Âê©w¦³±Ò°Êª÷Æ_ªººÏºÐ°Ï¡C

a) ­Y­n°±¥Î¶È±Ò°Êª÷Æ_ÅçÃÒ

1.

¨Ï¥Î Decrypt ±NºÏºÐ°Ï¸Ñ±K¡A¨ÃÃö³¬ BitLocker «OÅ@¡C

2.

¨Ï¥Î GetKeyProtectors ¦C¥X¤w¬°ºÏºÐ°Ï«Ø¥ßªº±Ò°Êª÷Æ_¡C

3.

¨Ï¥Î DeleteKeyProtector ²¾°£»P¤w«Ø¥ß±Ò°Êª÷Æ_¬ÛÃöÁpªº±Ò°Êª÷Æ_ÅçÃÒ blob¡C

4.

[¦A¦¸¨Ï¥Î ProtectKeyWithExternalKey ¥H«Ø¥ß·sªº±Ò°Êª÷Æ_]¡C

4.3.4 ¨t²ÎºÞ²z

¥»¾÷¨t²ÎºÞ²z­û±±¨îµÛ BitLocker Drive Encryption ªº¦U­Ó¼h­±¡C¨t²ÎºÞ²z­û¥i¥Hª½±µ¦b Windows ¸ê°T¦w¥þ¤¤¤ß±Ò¥Î©Î°±¥Î³o¶µ¥\¯à¡C

4.3.4.1 ª÷Æ_ºÞ²z¨Ï¥ÎªÌ¸gÅç

ºÏºÐ°Ï¤@¥¹¸g¹L¥[±K¨Ã¥H BitLocker ¶i¦æ«OÅ@¤§«á¡AºÞ²zª÷Æ_¨Ï¥ÎªÌ¤¶­±´N·|¤¹³\¥»¾÷©Mºô°ì¨t²ÎºÞ²z­û½Æ»sª÷Æ_¤Î­«³] PIN¡C¤¶­±¤¤¶ÈÅã¥Ü¦b BitLocker ³]©w®É©Ò«Ø¥ßª÷Æ_ªº³sµ²¡C

ºÞ²zª÷Æ_ªº¬yµ{¤¹³\¨t²ÎºÞ²z­û¦s¨ú¤U¦Cª÷Æ_ºÞ²z¿ï¶µ¡G

½Æ»s­×´_±K½X

Åã¥Ü­×´_±K½X¨Ã¤¹³\¨Ï¥ÎªÌ¦C¦L¡C

±N­×´_±K½X©M­×´_ª÷Æ_Àx¦s (½Æ»s) ¦Ü USB §Ö°{ºÏºÐ¡C

±N­×´_±K½X©M­×´_ª÷Æ_Àx¦s (½Æ»s) ¦Ü¸ê®Æ§¨¡C

½Æ»s±Ò°Êª÷Æ_

±N±Ò°Êª÷Æ_Àx¦s¦Ü¥~±¾¦¡ USB §Ö°{ºÏºÐ¡C

­«³] PIN¡C

4.3.4.2 ³]©w»PºÞ²z

Windows ¸ê°T¦w¥þ¤¤¤ß´£¨Ñ BitLocker ¥\¯àª¬ºA¥H¤Î±Ò¥Î©Î°±¥Î BitLocker ªº¯à¤O¡A¥t¥~¤]´£¨Ñ³]©w¥\¯à¡A¦p¡Õ²Ä 4.2 ¸`¡Ö¤¤©Ò¥Ü¡C¦pªG¥Ñ©ó³Ìªñªº¦w¸Ë©Î¸Ñ°£¦w¸Ë­n¨D¡A¦Ó­P BitLocker ¥D°Ê¥[±K©Î¸Ñ±K¸ê®Æ¡A´N·|Åã¥Ü¶i«×ª¬ºA¡C

¨t²ÎºÞ²z­û¤]¥i¥H±q¸ê°T¦w¥þ¤¤¤ß¦s¨ú TPM ºÞ²z¥D±±¥x¡A¥HºÞ²z TPM¡C

IT ¨t²ÎºÞ²z­û¥i¨Ï¥Î©R¥O¦CºÞ²z¤u¨ã (manage-bde.wsf)¡A±q»·ºÝ°õ¦æ«ü¥O½X¥\¯à¡C

4.3.4.3 ¹q¸£¤É¯Å¡G°±¥Î«OÅ@¨Ï¥Î®×¨Ò

¦b¬Y¨Ç±¡ªp¤U¡A¨t²ÎºÞ²z­û¥i¯à·|»Ý­n¼È®É°±¥Î BitLocker¡A¨Ò¦p¡G

1.

¦b¤£­n¨D¨Ï¥ÎªÌ¿é¤J (¨Ò¦p PIN ©Î±Ò°Êª÷Æ_) ¤§¤U¡A±N¹q¸£­«·s¶}¾÷¥H¶i¦æºûÅ@¡C

2.

¦b¤£Ä²µo BitLocker ­×´_¤§¤U¡A¶i¦æ­«­nªº¦­´Á¶}¾÷¤¸¥ó¤É¯Å¡C

¦w¸Ë¥t¤@­Ó§@·~¨t²Î¥i¯à·|Åܧó¶}¾÷ºÞ²zµ{¦¡¡C

­«·s¤À³ÎºÏºÐ¥i¯à·|ÅܧóºÏºÐ¤À³Îªí¡C

¨ä¥LÅܧó¥Ñ TPM ÅçÃÒ¤§¶}¾÷¤¸¥óªº¨t²Î¤u§@¡C

3.

¦b¤£Ä²µo BitLocker ­×´_¤U¡A¶i¦æ¥D¾÷ªO¤É¯Å©Î§ó´«©Î²¾°£ TPM¡C

4.

¦b¤£Ä²µo BitLocker ­×´_¤U¡AÃö³¬/°±¥Î¡A©Î²M°£ TPM¡C

5.

¦b¤£Ä²µo BitLocker ­×´_¤U¡A±N¨ü BitLocker «OÅ@ªººÏºÐ°Ï²¾¦Ü¥t¤@³¡¹q¸£¡C

6.

¿ò¥¢©Ò¦³­×´_ blob ¦Ó¥²¶·¦bIJµo BitLocker ­×´_¤§«e¡A¦w¥þ¦a«Ø¥ß·sªº­×´_ blob¡C

§Ú­Ì±N³o¨Ç®×¨Ò²ÎºÙ¬°¡u¹q¸£¤É¯Å®×¨Ò¡v¡C³oºØ®×¨Ò¥i¥H³z¹L Windows ¤¤ªº BitLocker ±±¨î¥x±Ò¥Î/°±¥Î¡C¤w±Ò¥Î BitLocker ªº¹q¸£¤É¯Å¥u»Ý¤Ö¼Æ´X­Ó¨BÆJ¡G

1.

³z¹L¶i¤J°±¥Î¼Ò¦¡¡A¼È®ÉÃö³¬ BitLocker¡C

2.

±N¨t²Î¤É¯Å¡C

¤É¯Å BIOS ©Î¦w¸Ë Service Pack¡C

3.

¶}±Ò BitLocker - ¤£»Ý­n¥[±K§@·~¡A¦p¤U©Ò­z¡C

±j­¢ BitLocker ¶i¤J°±¥Î¼Ò¦¡·|ÅýºÏºÐ°Ï«O«ù¬°¥[±K¡A¦ýºÏºÐ°Ï¥D­nª÷Æ_±N¥i¦Û¥Ñ¥Î©óºÏºÐ¤W¡A¨Ï¥ÎÀx¦s¦bµwºÐ¤Wªº¹ïºÙ¦¡¯Âª÷Æ_¶i¦æ¥[±K¡C¯à°÷¨Ï¥Î¯Âª÷Æ_ªí¥Ü·|Ãö³¬¥Ñ BitLocker ©Ò´£¨Ñªº¸ê®Æ«OÅ@¡A¦ý¥i½T«O¦b¥ô¦ó±ø¥ó¤U¡A©Ò¦³«áÄò¹q¸£¶}¾÷³£¯à¦¨¥\¡A¦Ó¤ð»Ý¦A¥Ñ¨Ï¥ÎªÌ¶i¦æ¿é¤J¡C­«·s±Ò¥Î BitLocker ®É¡A¯Âª÷Æ_´N·|±qºÏºÐ°Ï¤¤²¾°£¡ABitLocker «OÅ@¤]·|¦A«×¶}±Ò¡C¦¹¥~¡AVMK ¤]·|­«·s«Ø¥ßª÷Æ_¨Ã­«·s¶i¦æ¥[±K¡C

±N¨ü«OÅ@ªººÏºÐ°Ï (¹êÅéºÏºÐ) ²¾¦Ü¥t¤@³¡¤w±Ò¥Î TPM ªº¹q¸£¨Ã¤£»Ý­n¥ô¦ó¨ä¥L¨BÆJ¡A¦]¬°«OÅ@ºÏºÐ°Ï¥D­nª÷Æ_ªºª÷Æ_¬OÀx¦s¦b¥»¾÷ºÏºÐ¤W¡A§¹¥þµL¸·¡C

¤½¶}ºÏºÐ°Ï¥D­nª÷Æ_¡A§Y¨Ï¥u¬O«Üµu¼Èªº´Á¶¡¡A¤]·|²£¥Í¦w¥þ©Ê­·ÀI¡A¦]¬°¦b¯Âª÷Æ_¤½¶}³o¨Çª÷Æ_®É¡A§ðÀ»ªÌ¥i¯à·|¨ú±oºÏºÐ°Ï¥D­nª÷Æ_©M FVEK¡C

4.4 ¹q¸£¨O´«

¤µ¤é¡A¦³³\¦h­Ó¤H¹q¸£³£¬O¥Ñ²Ä¤@­Ó¾Ö¦³ªÌ©Î¨Ï¥ÎªÌ¥H¥~ªº¤H­«½Æ¨Ï¥Î¡C¦b¥ø·~Àô¹Ò¤U¡A¹q¸£¥i¥H­«·s³¡¸p¦Ü¨ä¥L³¡ªù¡A¤]¥i¯à¬O¦b¼Ð·Ç¹q¸£µwÅé§ó·s¶g´Áµ{§Ç¤U¥á¥X¤½¥q¡C

IT ³¡ªù¥i¯à·|°õ¦æ¤@¶µ©Î¦h¶µ¦w¥þ©Ê³Wµ{¡A¦b¾÷¾¹²¾¥X©Î¥á¥X¤½¥q¤§«e«OÅ@©Î§R°£¾÷¾¹¤Wªº¸ê®Æ¡CBitLocker ¥i¥H¦b¾÷¾¹­«·s³¡¸p¥H«e¡A¤j´T´£¤É¨ä¦w¥þ©Ê¡C

IT ¤H­û¥i¥H¿ï¾ÜÃö³¬ BitLocker¡AÅý¹q¸£ (¤]³\¥]¬A¨ä¤¤¤@¨Ç¸ê®Æ) ¤´µM¥i§@¨ä¥L¥Î³~¡A¤]¥i¥H°õ¦æ¡u¦w¥þ¸Ñ°£©e¥ô¡v¸`¬Ù®É¶¡¡A¦ÓÅý¸ê®Æ¥Ã»·³B©ó¥[±Kª¬ºA¡Aµ´¹ïµLªk¥[¥HÂ^¨ú¡C

4.4.1 Ãö³¬ BitLocker Drive Encryption

¥»¾÷¨t²ÎºÞ²z­û¥i¥H¦b Windows ¸ê°T¦w¥þ¤¤¤ß¤§¤ºÃö³¬³o¶µ¥\¯à¡CBitLocker ´£¨Ñ¨âºØ¸Ñ°£¦w¸Ë¼Ò¦¡¡G

BitLocker °±¥Î - «O¯d¥[±K¡C³o­Ó¿ï¶µÅý¸ê®Æ¦bµwºÐ¤W«O«ù¬°¥[±Kª¬ºA¡A¦ý²¾°£ TPM µwÅé¨Ì¿à (¶i¤J°±¥Î¼Ò¦¡§Y¥i²¾°£¡A½Ð°Ñ¾\¡Õ²Ä 4.3.4.3 ¤p¸`¡Ö)¡C

BitLocker Ãö³¬ - ²¾°£¥[±K¡C³o­Ó¿ï¶µ·|±N Windows ¤À³Îªº«OÅ@¥þ³¡²¾°£¡A¨Ã±N¸ê®Æ¸Ñ±K (³z¹LÃö³¬ BitLocker ªº¤è¦¡)¡C

¨Ï¥ÎªÌ¤¶­±¤ä´©

1.

¦b [±±¨î¥x] ªº [¦w¥þ©Ê] °Ï°ì¤¤¨µÄý¦Ü BitLocker ¶µ¥Ø¡A¥H¶}±Ò BitLocker ¨Ã±Ò¥Î±Ò°Êª÷Æ_¤ä´©¡C

2.

«ö¤@¤U [Ãö³¬ BitLocker—ü (Turn Off BitLocker—ü)]¡A¥HÃö³¬ BitLocker—ü¡C

«ü¥O½X¤ä´©

1.

¨Ï¥Î Decrypt ±NºÏºÐ°Ï¸Ñ±K¡A¨ÃÃö³¬ BitLocker «OÅ@¡C

Ãö³¬ BitLocker ¤§«á¡A¥i¥H¦bµwÅé­«·s®æ¦¡¤Æ¥H«e¡A²¾Âà³\¦h¦³¥Îªº¸ê®Æ¡C

4.4.2 ¦w¥þ¸Ñ°£©e¥ô

¦w¥þ¸Ñ°£©e¥ô«üªº¬O§R°£¯S©wºÏºÐ°Ï¤Wªºª÷Æ_ blob¡C¨S¦³ª÷Æ_ blob¡A¸ê®Æ´NµLªk¸Ñ±K12¡C

³o¶µµ{§Ç¤¤¥]§t¨â­Ó¨BÆJ¡G

1.

²¾°£ºÏºÐ°Ï¤W©Ò¦³«D­×´_ª÷Æ_ blob¡C³o¼Ë¥i¥H±j­¢¨Ï¥ÎªÌ¦b¤U¦¸¶}¾÷®É¡A³v¨B°õ¦æ­×´_µ{§Ç¡A¨Ã´£¨Ñ­×´_ª÷Æ_©Î­×´_±K½X¡C³oºØ§@ªk³Qµø¬°¥i«ì´_ªº¦w¥þ¸Ñ°£©e¥ô¡C¦¹ªk¥i¥H¥Î¨ÓÂê©w­n¶i¦æ·h¹Bªº¾÷¾¹¡C

2.

²¾°£©Ò¦³¥i¥Îªºª÷Æ_ blob¡A¥]¬AÀx¦s¦b AD ¤¤ªº­×´_¸ê®Æ¡C¸ê®Æ±N¥Ã»·¥[±K¡AºÏºÐ°Ï¥i¥H­«·s®æ¦¡¤Æ¡A¦Ó¤£·|¦M¤Î¦b¨ü BitLocker «OÅ@¤§ºÏºÐ°Ï¤¤ªº¸ê®Æ¡C³o¬O¥Ã¤[©Êªº¦w¥þ¸Ñ°£©e¥ô¡C¥u¦³¦b¥Ã»·³£¤£¦A·Q­n©Î¤£¦A»Ý­n³o¨Ç¸ê®Æ®É¡A¤~±Ä¥Î³oºØ§@ªk¡CºÏºÐ¾÷±NµLªk­×´_¡C

¦w¥þ¸Ñ°£©e¥ô¥i¥H³z¹L°õ¦æºÞ²z¶¥¼h«ü¥O½X¨Ó¹F¦¨¡A«ü¥O½X·|²¾°£ºÏºÐ¤Wªº©Ò¦³ª÷Æ_ (v1 ¤¤¨S¦³¨Ï¥ÎªÌ¤¶­±¤ä´©¥i¥Î)¡C

«ü¥O½X¤ä´©

1.

¨Ï¥Î GetKeyProtectors ¨ú±o©Ò¦³¡uTPM¡v¡B¡uTPM ¥[ PIN¡v©M¡uTPM ¥[±Ò°Êª÷Æ_¡vÃþ«¬ªºª÷Æ_«OÅ@¸Ë¸m¤§ÃѧO½X [­Y­n¶i¦æ¥Ã¤[©Ê¦w¥þ¸Ñ°£©e¥ô¡A½Ð¨ú±o©Ò¦³ª÷Æ_«OÅ@¸Ë¸mÃѧO½X¡A¥]¬A­×´_ÃѧO½X]¡C

2.

[¶i¦æ¥Ã¤[©Ê¦w¥þ¸Ñ°£©e¥ô] «Ø¥ß¤£­ã¨Ï¥Îªº­×´_±K½X blob 13(±Ë±ó¹ê»Úªº­×´_±K½X)¡A¨Ï¥Î ProtectKeyWithNumericalPassword ¤ÎÀH¾÷²£¥Íªº±K½X§Ç¦C¨Ó«Ø¥ß¡C

3.

¨Ï¥Î DeleteKeyProtector ²¾°£©Ò¦³»P¤W­zµ{§Ç©Ò§ä¨ì¤§ÃѧO½X¬ÛÃöÁpªº¥i¨Ï¥Îª÷Æ_«OÅ@¸Ë¸m¡C

4.

[¶i¦æ¥Ã¤[©Ê¦w¥þ¸Ñ°£©e¥ô] ¦b TPM ¾÷¾¹¤W¡A¨Ï¥Î TPM WMI ´£¨ÑªÌ¨ç¼Æ Win32_TPM.Clear ²M°£ TPM¡C

³o¬O¨³³t¦Ó¦³®Äªº¤è¦¡¡AÅýºÏºÐ°Ï¤Wªº¸ê®ÆµLªk¨ú¥Î¡C

¦^¨ì­¶­º¦^¨ì­¶­º

5. ¨t²Î­×´_

¦bµo¥Íª¬ªpªº±¡§Î¤U (¦pªGºÏºÐ°Ïªºª÷Æ_µLªk¥Ñ BitLocker ¦Û°Ê¨ú±o)¡A¥[±KºÏºÐ°Ï¤Wªº¸ê®Æ¥i³z¹L¥u»Ý³Ì§C³]©wªº¦³®Äµ{§Ç¥[¥H­×´_¡C¦³´XºØ±¡ªp¥i¯à·|IJµo­×´_¡G

1.

±N¨ü BitLocker «OÅ@ªººÏºÐ¾÷²¾¤J·s¹q¸£¤¤¡C

2.

¥D¾÷ªO¤É¯Å¬°·s«~ (§t·sªº TPM)¡C

3.

Ãö³¬/°±¥Î¡A©Î²M°£ TPM¡C

4.

­«­nªº¦­´Á¶}¾÷¤¸¥ó¤É¯Å¡A¨Ï±o TPM µLªk³q¹LÅçÃÒ¡C

5.

¦b¤w±Ò¥Î PIN ÅçÃҮɿò§Ñ PIN¡C

6.

¦b¤w±Ò¥Î±Ò°Êª÷Æ_ÅçÃҮɡA¿ò¥¢¨ä¤¤¥]§t±Ò°Êª÷Æ_ªº¥~±¾¦¡ USB §Ö°{ºÏºÐ¡C

7.

±N®à¤W«¬©Î½¥¤W«¬¹q¸£­«·s³¡¸pµ¹¥ø·~¤¤¨ä¥L³¡ªù/­û¤u (¨Ò¦p¡Aµ¹¨ã¦³¤£¦P¦w¥þÅv­­©Î¤£¦Pª¾±¡»Ý­nªº¨Ï¥ÎªÌ)¡A¦b³q¹L¼f¹î¥i¨Ñ¤£¦P¦w¥þÅv­­¼h¯Å¨Ï¥Î¤§«e¡A»Ý­n­×´_¸ê®Æ¡C

8.

®à¤W«¬¹q¸£´N¦a­«·s¤À¬£¤u§@ (¨Ò¦p¡A¥Ñ IT ¨t²ÎºÞ²z­û±q»·ºÝ­«·s¦w¸Ë§@·~¨t²Î) ¦Ó¨S¦³¿ò¥¢¨ü«OÅ@ªº¸ê®Æ¡C

5.1 ­×´_³]©w

IT ¨t²ÎºÞ²z­û¥i¥H¨Ï¥Î¸s²Õ­ì«h¡A¿ï¾Ü­n¨D¡B©Úµ´¦óºØ­×´_¤èªk¡A©Î¬OÅý±Ò¥Î BitLocker ªº¨Ï¥ÎªÌ¿ï¥Î¡C­×´_±K½X¥i¥HÀx¦s¦b Active Directory ¤¤¡A¦Ó¨t²ÎºÞ²z­û¥i¥HÅý³o¦¨¬°¥²­n¡B¸T¤î©Î¥i¿ï¥Î¿ï¶µ (¤À§O¹ï¹q¸£ªº¨C­Ó¨Ï¥ÎªÌ¶i¦æ)¡C½Ð°Ñ¾\¡Õ²Ä 4.2.3 ¸`¡Ö¡A·í¤¤¦³»¡©ú Active Directory ³]©w¨BÆJ¡C¦¹¥~¡A­×´_¸ê®Æ¤]¥i¥HÀx¦s¦b¥ô¦ó¥~±¾¦¡ USB §Ö°{ºÏºÐ¡C

5.2 ­×´_®×¨Ò

¦b BitLocker ¤¤¡A­×´_¥]§t¤F¥HÀx¦s¦b USB §Ö°{ºÏºÐ¤Wªº­×´_ª÷Æ_¡A©Î¥H±q­×´_±K½X©Ò­l¥Í±K½X½sĶª÷Æ_¥[±Kªº¥D­nª÷Æ_ blob ½Æ¥»¸Ñ±K¡CTPM »P¥ô¦ó­×´_®×¨Ò³£µLÃö¡A¦]¦¹¦pªG TPM µLªk³q¹L¶}¾÷¤¸¥óÅçÃÒ¡B¬G»Ù©Î®ø¥¢¡A³£¥i¥H¶i¦æ­×´_¡C

­Y­n­×´_ºÏºÐ°Ï¡A¨Ï¥ÎªÌ¥i¥H¨Ï¥Î¦bªì©l¤Æ®É³]©wªº¥ô¦ó­×´_¾÷¨î¡C¨Ï¥ÎªÌ¥i¥H¨Ï¥Î­×´_±K½X©Î­×´_ª÷Æ_ (¬Û·í©ó­×´_±K½Xªº¾÷¾¹¥iŪ¨ú¶µ¥Ø)¡C

5.2.1 ­×´_±K½X

­×´_±K½X¬O 48 ¦ì¼ÆÀH¾÷²£¥Íªº¼Æ¦r¡A¦b BitLocker ³]©w®É«Ø¥ß¡C±Ò¥Î BitLocker ¤§«á¡A¥i¥H¶i¦æºÞ²z©M½Æ»s¡C­×´_±K½X¥i¥H³z¹L¤¶­±¦C¦L©M/©ÎÀx¦s¦¨ÀɮסA¥H³Æ±N¨Ó¨Ï¥Î¡C

ºô°ì¨t²ÎºÞ²z­û¥i¥H³]©w¸s²Õ­ì«h¡A¦Û°Ê²£¥Í­×´_±K½X¡AµM«á BitLocker ¤@±Ò°Ê¡A´N¦Û°Ê³Æ¥÷¦Ü Active Directory¡C¦Ó¥B¡Aºô°ì¨t²ÎºÞ²z­ûÁÙ¥i¥H¿ï¾Üªý¤î BitLocker ¬°ºÏºÐ¾÷¥[±K¡A°£«D¹q¸£¤w³s±µ¨ìºô¸ô¤W¡A¦Ó¥B¤w¦¨¥\³Æ¥÷ Active Directory ªº­×´_±K½X¡C

¨Ï¥ÎªÌ¤¶­±¤ä´©

1.

¦b [±±¨î¥x] ªº [¦w¥þ©Ê] °Ï°ì¤¤¨µÄý¦Ü BitLocker—ü ¶µ¥Ø¡A¥H¶}±Ò BitLocker—ü ¨Ã±Ò¥Î­×´_±K½X¡C

«ö¤@¤U [¶}±Ò BitLocker—ü (Turn On BitLocker—ü)]¡A¥H°õ¦æ BitLocker—ü ³]©wºëÆF¡C

2.

Àx¦s¡BÀ˵ø¡A¤Î/©Î¦C¦L­×´_±K½X¡A§@¬° BitLocker—ü ³]©wºëÆFªº¤@³¡¤À14

½Ð°Ñ¾\¡Õ²Ä 4.2.2 ¸`¡Ö¤¤ªºµe­± 4¡A¥H¨ú±o¸Ô²Ó¸ê°T¡C

3.

Àx¦s¤Î/©Î¦C¦L¤w«Ø¥ßªº­×´_±K½X½Æ¥»¡A§@¬°ª÷Æ_ºÞ²z¤¶­±ªº¤@³¡¤À¡C

4.

¿é¤J­×´_±K½X¡A§@¬° Windows ¤§«e¤å¦r¼Ò¦¡­×´_¤¶­±ªº¤@³¡¤À¡C

«ü¥O½X¤ä´©

a) ­Y­n±Ò¥Î­×´_±K½X

1.

¨Ï¥Î ProtectKeyWithNumericalPassword «Ø¥ß­×´_±K½X¡C

§Y¨Ï¤w¦³­×´_ª÷Æ_ blob¡A©Î¤w¶}±Ò BitLocker «OÅ@¡A¤]¥i¥H¨Ï¥Î³o­Ó¤èªk¡C

­Y¤w±Ò¥Î Active Directory ³Æ¥÷¡A©Î¸s²Õ­ì«h­n¨D Active Directory ³Æ¥÷¡A³o­Ó¤è¦¡¤]·|±N­×´_±K½XÀx¦s¦Ü Active Directory¡C

2.

¨Ï¥Î GetKeyProtectorNumericalPassword Â^¨ú©Ò«Ø¥ß­×´_±K½X blob ªº¼Æ¦r±K½X¤º®e¡C

3.

¨Ï¥Î UnlockWithNumericalPassword ¸Ñ°£Âê©w¦³­×´_±K½XªººÏºÐ°Ï¡C

b) ­Y­n°±¥Î­×´_ª÷Æ_

1.

¨Ï¥Î GetKeyProtectors ¦C¥X¤w¬°ºÏºÐ°Ï«Ø¥ßªº­×´_±K½X¡C

2.

¨Ï¥Î DeleteKeyProtector ²¾°£»P¤w«Ø¥ß­×´_±K½X¬ÛÃöÁpªº¼Æ¦r±K½XÅçÃÒ blob¡C

5.2.2 ­×´_ª÷Æ_

­×´_ª÷Æ_¥i¥H¦b BitLocker ³]©w®É«Ø¥ß¨ÃÀx¦s¦Ü¥~±¾¦¡ USB §Ö°{ºÏºÐ15¡A¦Ó¥B¥¦¥i¥H¦b±Ò¥Î BitLocker ¤§«á¶i¦æºÞ²z¤Î½Æ»s¡C¹q¸£±Ò°Ê®É¡A¨Ï¥ÎªÌ³z¹L±N¥]§t­×´_ª÷Æ_ªº USB §Ö°{ºÏºÐ´¡¤J¹q¸£¤¤¡A¨ú±o§@·~¨t²ÎºÏºÐ°Ïªº¦s¨úÅv­­¡A¦Ó¤£¥²²z·| TPM ªºª¬ºA¡C

¨Ï¥ÎªÌ¤¶­±¤ä´©

1.

¦b [±±¨î¥x] ªº [¦w¥þ©Ê] °Ï°ì¤¤¨µÄý¦Ü BitLocker—ü ¶µ¥Ø¡A¥H¶}±Ò BitLocker—ü ¨Ã±Ò¥Î­×´_ª÷Æ_¡C

«ö¤@¤U [¶}±Ò BitLocker—ü (Turn On BitLocker—ü)]¡A¥H°õ¦æ¡uBitLocker ³]©wºëÆF¡v¡C

2.

«Ø¥ß¤ÎÀx¦s­×´_±K½X¡A§@¬° BitLocker—ü ³]©wºëÆFªº¤@³¡¤À16

½Ð°Ñ¾\¡Õ²Ä 4.2.2 ¸`¡Ö¤¤ªºµe­± 4¡A¥H¨ú±o¸Ô²Ó¸ê°T¡C

3.

»s§@¤w«Ø¥ß­×´_ª÷Æ_ªº½Æ¥»¡A§@¬°ª÷Æ_ºÞ²zºëÆFªº¤@³¡¤À¡C

4.

¿é¤J­×´_ª÷Æ_¡A§@¬° Windows ¤§«e¤å¦r¼Ò¦¡­×´_¤¶­±ªº¤@³¡¤À¡C

«ü¥O½X¤ä´©

a) ­Y­n±Ò¥Î­×´_ª÷Æ_

1.

¨Ï¥Î ProtectKeyWithExternalKey «Ø¥ß­×´_ª÷Æ_¡C

2.

¨Ï¥Î SaveExternalKeyToFile ±N¥]§t­×´_ª÷Æ_ªºÀÉ®×¼g¤J¥i´¡¤Jªº USB §Ö°{ºÏºÐ©Î¨ä¥L¦ì¸m¡C

3.

¨Ï¥Î GetKeyKeyProtector ExternalKey Â^¨ú¤w«Ø¥ß­×´_ª÷Æ_ blob ªºª÷Æ_¤º®e¡C

4.

¨Ï¥Î UnlockWithExternalKey ¸Ñ°£Âê©w¨Ï¥Î­×´_ª÷Æ_ªººÏºÐ°Ï¡C

b) ­Y­n°±¥Î­×´_ª÷Æ_

1.

¨Ï¥Î GetKeyProtectors ¦C¥X¤w¬°ºÏºÐ°Ï«Ø¥ßªº­×´_ª÷Æ_¡C

2.

¨Ï¥Î DeleteKeyProtector ²¾°£»P¤w«Ø¥ß­×´_ª÷Æ_¬ÛÃöÁpªºÅçÃÒ blob¡C

¦^¨ì­¶­º¦^¨ì­¶­º

ªþ¿ý

¦Wµü¸ÑÄÀ

BitLocker °±¥Î
¦b¡u°±¥Î¼Ò¦¡¡v¤¤¡A·|°±¥ÎºÏºÐ°Ï¤Wªº BitLocker «OÅ@¡A¨Ã¥[±KºÏºÐ°Ï¡A¦ý¥Î¨Ó¥[±K§@·~¨t²ÎºÏºÐ°Ïªº FVEK ¥i³z¹L¡u¯Âª÷Æ_¡v¦Û¥Ñ¦a¨Ï¥Î¡CÁöµM¤w¶i¦æ¤F¥[±K¡A¦ý¸ê®Æ«OÅ@¤w¦³®Ä¦a°±¥Î¡C

BitLocker ±Ò¥Î (©Î¶}±Ò)
¦bºÏºÐ°Ï¤W±Ò¥Î BitLocker «OÅ@®É¡AºÏºÐ°Ï¤Wªº¸ê®Æ·|¦b¼g¤J®É¥[±K¡A¦Ó¦bŪ¨ú®É¸Ñ±K¡C¹q¸£±Ò°Ê®É¡A»Ý­n¥Ñ¡uTPM¡v(µ²¦X¡u±Ò°Êª÷Æ_¡v©Î¡uPIN¡v¡A­Y¦³¦¹³]©w®É) ÅçÃÒ­«­nªº¦­´Á¶}¾÷¤¸¥ó¦¨¥\¡B¿é¤J¡u­×´_±K½X¡v¡A©Î´¡¤J¥]§t¡u­×´_ª÷Æ_¡vªº USB §Ö°{ºÏºÐ¡A¤~¯à¸Ñ±K VMK ¨Ã¦s¨úºÏºÐ°Ï¡C

BitLocker Ãö³¬
¦b¦¹¼Ò¦¡¤U¡AºÏºÐ°Ï¤Wªº«OÅ@¤wÃö³¬¡AºÏºÐ°Ï¥¼¥[±K¡A¦Ó BitLocker «OÅ@¨Ã¥¼µo¥Í§@¥Î¡C³o¬O¨ã¦³¼Ð·Ç¯Â¤å¦rÀɮ׮榡ªººÏºÐ°Ï¡C

Blob
¤G¶i¦ì¤j«¬ª«¥ó¡F¥ô¦ó¥H±K½X½sĶºtºâªk«OÅ@ªº¸ê®Æ¡C¨Ò¦p¡AVMK ¬O±K«Ê¦Ü TPM¡A¦ý¥Ñ TPM_Seal §@·~¶Ç¦^©Ò±o¨ìªº blob ¨ä¹ê¬OÀx¦s¦bºÏºÐ¤W¡C¦P¼Ë¦a¡AVMK ¥i¥H¥Ñ¡u¯Âª÷Æ_¡v¡B¡u±Ò°Êª÷Æ_¡v©Î¡u­×´_ª÷Æ_¡v¶i¦æ¥[±K¡A¨Ã¥H blob Àx¦s©óºÏºÐ¤W¡C

¯Âª÷Æ_
µL»ÙêÀx¦s¦bºÏºÐ°Ï¤Wªºª÷Æ_¡C¦¹ª÷Æ_¬O¦b¤w°±¥Î BitLocker «OÅ@¦ÓºÏºÐ°Ï¤´µM«O«ù¥[±K®É¡A¥Î¨Ó¦Û¥Ñ¦s¨ú VMK¡A¦AÂà¦Ó¦s¨ú FVEK¡C½Ð°Ñ¾\ BitLocker °±¥Î¡C

FVEK
§¹¾ãºÏºÐ°Ï¥[±Kª÷Æ_¡F¯S©wºtºâªkªºª÷Æ_¡A¥Î¨Ó¥[±K (¤]¥i¥H¥Î¨Ó´²§G) ºÏºÐ°Ï¤Wªº¸ê®Æ¡C¥Ø«e³o­Óª÷Æ_¥i¥H¦Û 128 ¦ì¤¸¨ì 512 ¦ì¤¸¤£µ¥¡C¥Î¦bºÏºÐ°Ï¤Wªº¹w³]¥[±Kºtºâªk¬O AES 128 ¦ì¤¸ªþÂX´²¾¹¡C

§@·~¨t²ÎºÏºÐ°Ï
¥]§t§@·~¨t²Î (¨Ò¦p¡AWindows Vista) ªººÏºÐ°Ï¡A¥i¥Ñ¹q¸£ªº¶}¾÷ºÞ²zµ{¦¡¸ü¤J¡C³o­ÓºÏºÐ°Ï±N¥Ñ BitLocker ¥[¥H«OÅ@¡C

¥Ã¤[©Ê¦w¥þ¸Ñ°£©e¥ô
³z¹L²¾°£¸Ñ±K©Î­×´_ºÏºÐ©Ò»Ýªº¥þ³¡ª÷Æ_¸ê®Æ¡A­¢¨Ï¨ü BitLocker «OÅ@ºÏºÐ°ÏµLªk­×´_ªºµ{§Ç¡C

PIN
­Ó¤HÃѧO½X¡F³o¬O¨t²ÎºÞ²z­û«ü©wªº¾÷±K­È¡A¥²¶·¦b¨C¦¸¹q¸£±Ò°Ê (©Î¥Ñ¥ð¯v«ì´_) ®É¿é¤J¡CPIN ¥i¥H¦³ 4 ¨ì 20 ¦ì¼Æ¡A¦b¤º³¡±N©Ò¿é¤J Unicode ¦r¤¸Àx¦s¬° 256 ¦ì¤¸Âø´ê¡C³o­Ó­È¥Ã»·³£¤£·|¥H¥ô¦ó§Î¦¡©Î¦]¥ô¦ó²z¥ÑÅã¥Üµ¹¨Ï¥ÎªÌ¡CPIN ¬O¥Î¨Óµ²¦X TPM ÅçÃÒ¡A´£¨Ñ¥t¥~¤@¶µ«OÅ@­n¯À¡C

¥i­×´_ªº¦w¥þ¸Ñ°£©e¥ô
ÂǥѲ¾°£¬°ºÏºÐ¸Ñ±K©Ò»Ýªº¥»¾÷ª÷Æ_ blob (¦Ó¤£¬O­×´_ blob)¡A ­¢¨Ï¨t²Î¶i¦æ­×´_¼Ò¦¡ªºµ{§Ç¡C

­×´_ª÷Æ_
¥Î¨Ó­×´_¦b BitLocker ºÏºÐ°Ï¤W¥[±Kªº¸ê®Æ¡C³o­Óª÷Æ_ªº¥[±K±¡§Î»P¡u±Ò°Êª÷Æ_¡v¬Û·í¡C¦pªG¦³­×´_ª÷Æ_¥i¥Î¡A­×´_ª÷Æ_¥i±N VMK ¸Ñ±K¡AµM«á VMK ¦AÂà¦Ó±N FVEK ¸Ñ±K¡C

­×´_±K½X
¥H 48 ¦ì¼Æ²Õ¦¨¦Ó¤À¦¨ 8 ²Õªº¼Æ¦r±K½X¡C¨C²Õ 6 ¦ì¼Æ¬O¥ý¥Ñ mod-11 ¶i¦æÀˬd¡A¦AÀ£ÁY¦¨¹ïÀ³ªº 16 ¦ì¤¸±K½X¸ê®Æ¡C±K½X¸ê®Æªº½Æ¥»¬OÀx¦s¦b¥Ñ VMK ¥[±KªººÏºÐ¤W¡A¦]¦¹­×´_±K½X¥i¥H¥Ñ¨t²ÎºÞ²z­û¦b¸ü¤J Windows Vista ¤§«á¥[¥HÂ^¨ú¡C

±Ò°Êª÷Æ_
Àx¦s¦b USB §Ö°{ºÏºÐªºª÷Æ_¡A¥²¶·¦b¨C¦¸¹q¸£±Ò°Ê®É´¡¤J¡C±Ò°Êª÷Æ_¬O¥Î¨Óµ²¦X TPM ÅçÃÒ¡A´£¨Ñ¥t¥~¤@¶µ«OÅ@«Y¼Æ¡C

¨t²ÎºÏºÐ°Ï
¹q¸£±Ò°Ê®É¡A²Ä¤@­Ó¦s¨úªººÏºÐ°Ï¡C³o­ÓºÏºÐ°Ï¥]§t¥²»Ý¸ü¤J Windows ¤§¤¤ªº¯S©wµwÅéÀɮסA¥]¬A¹q¸£ªº¶}¾÷ºÞ²zµ{¦¡ (¥H¨Ñ¸ü¤J¦hºØ§@·~¨t²Î)¡C¤@¯ë¨Ó»¡¡A¨t²ÎºÏºÐ°Ï¥i¥H¬O¡A¦ý¨Ã¤£¤@©w¬O¡A»P§@·~¨t²Î (¶}¾÷) ºÏºÐ°Ï¬Û¦PªººÏºÐ°Ï¡C¦ý¬O¡A­Y­n BitLocker ¹B§@¡A¨t²ÎºÏºÐ°Ï¥²¶·»P§@·~¨t²ÎºÏºÐ°Ï¤£¦P¡A¦Ó¥B¤£¥i¥[±K¡C

TPM
¥i«H¿à¥­¥x¼Ò²Õ¡A¥Ñ Trusted Computing Group ©w¸q¡CTPM ¬O¦w¥þ©ÊµwÅé¡A¥i´£¨Ñ«H¿àªºµwÅé®Ú¥Ø¿ý¡A¥iµo´§¥\®Ä¡A´£¨Ñ¦UºØ¤£¦Pªº¥[±KªA°È¡CTPM v1.2 ·f°t¬Û®eªº BIOS ¤É¯Å¡A©Ò´£¨ÑªººÏºÐ¥[±K¨ã¦³¦­´Á¶}¾÷¤¸¥óªº§¹¾ã©ÊÀˬd¥\¯à¡A¥iÅçÃÒ­«­nªº¦­´Á¶}¾÷¤¸¥ó¡A¨Ã´£¨ÑµL»Ùꪺ±Ò°Ê¸gÅç¡C

VMK
ºÏºÐ°Ï¥D­nª÷Æ_¡G¥Î¨Ó¥[±K FVEK ªºª÷Æ_¡C

*
1 ¦ý¶È±Ò°Êª÷Æ_ªº±¡ªp°£¥~¡A½Ð°Ñ¾\¡Õ²Ä 4.3.3 ¸`¡Ö¥H¨ú±o¸Ô²Ó¸ê°T
2 ¦p»Ý¸Ô²Ó¸ê°T¡A½Ð°Ñ¾\ USB ¤j«¬¦s©ñÃþ§O¶È¤j¶q¶Ç¿é¡A¥H¤Î USB ¤j«¬¦s©ñÃþ§O UFI ©R¥O³W®æ¡A¥i¥H¦Û http://www.usb.org/developers/devclass_docs#approved ¤U¸ü
3 ¦b¥»¤å¥ó¤¤¡A¡uºÏºÐ°Ï¡v·N«üµwºÐ¤WªºÀx¦s°Ï°ì¡CºÏºÐ°Ï¬O¨Ï¥ÎÀɮרt²Î (¦p NTFS) ¶i¦æ®æ¦¡¤Æ¡A¨Ã¨ã¦³«ü©wªººÏºÐ¾÷¥N¸¹¡CºÏºÐ°Ï»P¡uºÏºÐ¤À³Î¡v¤£¦P¡A«áªÌ¬O¥Nªí¹êÅéºÏºÐªº¤@³¡¤À¡A·|¦p¹ê»Ú°Ï¹jªººÏºÐ¯ë¹B§@¡CµwºÐ¾÷¤Wªº¨C¤@­ÓºÏºÐ¤À³Î³£¥i¥H¦³¤@­ÓºÏºÐ°Ï¡A©Î¬O¦h­ÓºÏºÐ°Ï¥i¥H¸ó¦h­ÓºÏºÐ¤À³Î¡C
4 ¹w³]ªº TPM ¥­¥xÅçÃÒ³]©wÀɯà½T«O VMK ¤£¦] Core Root of Trust of Measurement (CRTM)¡BBIOS¡A¥H¤Î¥­¥x©µ¦ù (PCR 0)¡BOption ROM Code (PCR 2)¡B¥D¶}¾÷°O¿ý (MBR) µ{¦¡½X (PCR 4)¡BNTFS ¶}¾÷ºÏ°Ï (PCR 8)¡BNTFS ±Ò°Ê°Ï (PCR 9) ¤Î¶}¾÷ºÞ²zµ{¦¡ (PCR 10) Åܧó¦Ó¨ü¤zÂZ¡C¦P®É¤]¨Ï¥Î PCR 11 (BitLocker ¦s¨ú±±¨î)¡C
5 «e­±³¹¸`¤¤©Ò´£¤Îªº¨â­ÓºÏºÐ°Ï³]¸m¬O¥ý¨M±ø¥ó¡C
6 ³o¸Ì©Ò¦Cºô§}´£¨Ñ¸Ô²Óªº³v¨B«ü¥Ü¡Ghttp://www.microsoft.com/downloads/details.aspx?FamilyID=311f4be8-9983-4ab0-9685-f1bfec1e7d62&DisplayLang=en
7 ³q±`¥²¶·¿Ë¦Û¦b¹q¸£«e°õ¦æ¡A¤~¯àªì©l¤Æ¹q¸£ªº TPM¡C¦ý¬O¡A°²¦p¹q¸£±À¥X®É´N¤w¶}±Ò TPM¡A«h¤£»Ý­n¿Ë¦Û¶}±Ò
8 ¥»¸`©Ò´£¤Îªº¤èªk¦WºÙ¬O³z¹L BitLocker Windows Management Instrumentation (WMI) ´£¨ÑªÌ Win32_EncryptableVolume ¥[¥H¤½¶}¡C¨C¤@­Ó¥i¥H¥Ñ Windows Vista ÃѧOªººÏºÐ°Ï³£¬O Win32_EncryptedVolume ´£¨ÑªÌÃþ§Oªº°õ¦æ­ÓÅé¡C
9 ½Ðª`·N¡APIN ÅçÃÒ¤£¯à»P±Ò°Êª÷Æ_µ²¦X¹B§@¡C
10 Windows Vista ¤¤¨ã¦³¤U¦C¦w¥þ©Ê¥\¯à¡G¦b¶}±Ò BitLocker «OÅ@¤§«á¡A­Y¨S¦³¥ý±NºÏºÐ¸Ñ±K¨ÃÃö³¬ BitLocker¡A±NµLªk¥[¤J PIN¡C¦b«Ø¥ß PIN ¨Ã¶}±Ò BitLocker «OÅ@¥H«á¡A°ß¦³³z¹L±NºÏºÐ¸Ñ±K¡A¤~¯à²¾°£ PIN
11 ½Ðª`·N¡A±Ò°Êª÷Æ_ÅçÃÒµLªk»P PIN ÅçÃÒµ²¦X¹B§@
12 ¸ê®Æ·|¥Ã»·«O«ù¬°¥[±Kª¬ºA¡A»P°ò¦±K½X½sĶºtºâªk (¨ã¦³ 128 ©Î 256 ¦ì¤¸ª÷Æ_ªº AES) ¤@¼Ë¦w¥þ¡C
13 ¦]¬° DeleteKeyProtector ¤£·|²¾°£©Ò¦³ª÷Æ_«OÅ@¸Ë¸m¡A©Ò¥H³o¬O¥²­nªº¡C
14 ¶}±Ò BitLocker «OÅ@¤§«á¡A¥²¶·¥ý¥[±KºÏºÐ¨ÃÃö³¬ BitLocker¡A¤~¯à·s¼W¡BÅܧó¡A©Î²¾°£­×´_±K½X¡C
15 ©Ò¦³¥i¦CÁ| BIOS ´CÅé¡C
16 ¶}±Ò BitLocker «OÅ@¤§«á¡A¥²¶·¥ý¥[±KºÏºÐ¨ÃÃö³¬ BitLocker¡A¤~¯à·s¼W¡BÅܧó¡A©Î²¾°£­×´_ª÷Æ_¡C


ª©Åv«Å§i:¥»ºô­¶©Ò´£¨Ñ¤§¸ê°T,ª©Åv¬ÒÄݸê®Æ¨Ó·½ºô¯¸©Î­Ó¤H,¦p¦³¬ÛÃöºÃ°Ý,½Ð»P§Ú­Ì³sµ¸