![]() |
|
Z°T¥Î¤ß´£¿ô¡G»P¥»¶¬ÛÃö¸ê®Æ¬°¡u¨ä¥L°ÝÃD¡v¡u±M·~ª¾ÃÑ¡v¡C |
![]() ³o¦³¤°»ò¥\¯à©O!!¹ï§Ṳ́S¦³¤°»òÀ°§U? ![]() |
¥»¤å´£¨Ñ²µu§ãnªº BitLocker—ü Drive Encryption §Þ³N·§Æ[¡A³o¬O Microsoft Windows Vista ¤¤¥O¤H®¶¾Äªº¸ê®Æ«OÅ@·s¥\¯à¡C³Ì¥Dnªº¥Ø¼Ð¬O¬°¶i¶¥¨Ï¥ÎªÌ©M IT ¨t²ÎºÞ²zû¡A´£¨Ñ¥»¥\¯à¥Í©R¶g´Áªº²`¤J±´°Q¡A¨ó§U¥LÌÁA¸Ñ BitLocker Drive Encryption ªº¥\¯à¤º®e¤Î¨ä³B²z¤é¯q¼W¥[¤§¸ê®Æ«OÅ@°ÝÃDªº¤è¦¡¡G¨Ò¦p¡A¥Ñ©ó¹q¸£µwÅé¿ò¥¢©Î¾DÅѦӾÉP¾÷±K¸ê°T¬ªÅS¡C
¥»¤å°²³]ŪªÌÁA¸Ñ¡u¥i«H¿à¥¥x¼Ò²Õ¡v(Trusted Platform Module¡ATPM) §Þ³N¡C¦p»Ý¦³Ãö TPM §Þ³NªºI´º¸ê°T¡A½Ð°Ñ¾\ http://www.trustedcomputinggroup.org/ (^¤å) ºô¯¸¤W©Ò´£¨Ñªº³W®æ»P¸ê®Æ¡C
BitLocker—ü Drive Encryption ¬O Windows Vista Enterprise ©M Ultimate °w¹ï¥Î¤áºÝ¹q¸£¥H¤Î Windows Server "Longhorn" ¤¤©Ò´£¨Ñªº¸ê®Æ«OÅ@¥\¯à¡CBitLocker ¬O Microsoft ¦^À³«È¤á³Ì¢¤Á»Ý¨D¤§¤@ªº²£«~¡G»P Windows §@·~¨t²Î¤¤¸Ñ¨M¤è®×±K¤Á¾ã¦X¡A¥H³B²z¦] PC µwÅé¿ò¥¢¡B¾DÅѩΤ£·í¸Ñ°£©e¥ô¦Ó¾ÉP¸ê®Æ¥¢ÅѩάªÅSªº¯u¹ê«Â¯Ù¡C
BitLocker ¥i¨¾¤îÅѸé¥H¥t¤@Ó§@·~¨t²Î¶}¾÷©Î°õ¦æ³nÅé§ðÀ»¤u¨ã¡A«I¤J Windows Vista ÀɮשM¨t²Î«OÅ@¡A©Î¬O¹ïÀx¦s¦b¨ü«OÅ@ºÏºÐ¾÷¤WªºÀÉ®×°õ¦æÂ÷½uÀ˵ø¡C
¦b²z·Qªº±¡ªp¤U¡A¦¹¥\¯à¨Ï¥Î¥i«H¿à¥¥x¼Ò²Õ (TPM 1.2) «OÅ@¨Ï¥ÎªÌ¸ê®Æ¡A¨Ã½T«O°õ¦æ Windows Vista ªº PC ¤£·|¦b¨t²ÎÂ÷½u®É¾D¨ì«§ï¡CBitLocker ¥i¥H¬°¾÷°Ê©Ê¤Î¿ì¤½«Ç¥ø·~¸ê°T¤u§@¤Hû¡A¦b¨t²Î¿ò¥¢©Î¾DÅѮɥ[±j´£¨Ñ¸ê®Æ«OÅ@¡A¨Ã¥B¦b¸Ñ°£©e¥ô³o¨Ç¸ê²£®É½T¹ê§R°£¸ê®Æ¡C
BitLocker ¥[±jªº¸ê®Æ«OÅ@¥\¯àµ²¦X¤F¨â¤j¤l¥\¯à¡G§¹¾ãªººÏºÐ¾÷¥[±K¥H¤Î¦´Á¶}¾÷¤¸¥óªº§¹¾ã©ÊÀˬd¡C
ºÏºÐ¾÷¥[±K¬O¥Hªý¤î¥¼±ÂÅv¨Ï¥ÎªÌ«I¤J¿ò¥¢©Î¾DÅѹq¸£¤W Windows ÀɮשM¨t²Î«OÅ@ªº¤è¦¡¨Ó«OÅ@¸ê®Æ¡C³oºØ«OÅ@¬O³z¹L¬°¾ãÓ Windows ºÏºÐ°Ï¥[±Kªº¤è¦¡¹F¦¨¡C¦b BitLocker «OÅ@¤§¤U¡A©Ò¦³¨Ï¥ÎªÌ©M¨t²ÎÀɮ׳£·|¶i¦æ¥[±K¡A¥]¬A¥æ´«ÀɮשM¥ð¯vÀɮצb¤º¡C
¦´Á¶}¾÷¤¸¥óªº§¹¾ã©ÊÀˬd¦³§U©ó½T«O¥u¦³¦b³o¨Ç¤¸¥ó¥¼¸g¤zÂZªº±¡ªp¤U¤~·|°õ¦æ¸ê®Æ¸Ñ±K¡A¨Ã½T«O¥[±KªººÏºÐ¾÷¦ì©óì¥ýªº¹q¸£¤§¤¤¡C
BitLocker ±K¤Á¾ã¦X©ó Windows Vista ¤§¤¤¡A¬°¥ø·~´£¨ÑµL±µÁ_¡B¦w¥þ¦Ó¥B®e©öºÞ²zªº¸ê®Æ«OÅ@¸Ñ¨M¤è®×¡C¨Ò¦p¡ABitLocker ¤]¯à°÷µo´§¥ø·~즳 Active Directory ºô°ìªA°È°ò¦µ²ºcªº¥\®Ä¡A±q»·ºÝ©e¥I×´_ª÷Æ_¡CBitLocker ¤]°t³Æ¦³ÄY«·lÃa×´_¥D±±¥x¡A±K¤Á¾ã¦X©ó¦´Á¶}¾÷¤¸¥ó¤§¤¤¡A¥H´£¨Ñ¡u¹ê¦a¡v¸ê®ÆÂ^¨ú¡C
BitLocker ´£¨ÑÂê©w¥¿±`¶}¾÷µ{§Çªº¿ï¾Ü¡A¤@©wn¨Ï¥ÎªÌ´£¨Ñ PIN (Ó¤HÃѧO½X) ¤~¯à¸Ñ°£Âê©w¡AÃþ¦ü©ó´£´Ú¥d PIN ¡A©Î´¡¤J§tª÷Æ_§÷®Æªº USB §Ö°{ºÏºÐ¡C³o¨Ç¥~¥[ªº¦w¥þ©Ê±¹¬I¥i´£¨Ñ¦h««Y¼ÆÅçÃÒ¡A½T«O¤@©wn´£¨Ñ¥¿½Tªº PIN ©Î USB §Ö°{ºÏºÐ¡A¹q¸£¤~·|±Ò°Ê©Î±q¥ð¯vª¬ºA«ì´_¡C
BitLocker ´£¨ÑºëÆF¶i¦æ³]©w¤ÎºÞ²z¡A¨Ã³z¹L Windows Management Instrumentation (WMI) ¤¶±´£¨Ñ§t«ü¥O½X¤ä´©ªºÂX¥R©Ê©MºÞ²z©Ê¡C¦¹¥~¡ABitLocker ·|¥[³t¾÷±K¸ê®Æ²M°£§@·~¡A²¤Æ¹q¸£¦^¦¬µ{§Ç¡C
¨C¤Ñ¨Ï¥Î¥H BitLocker «OÅ@ªº Windows Vista ¹q¸£¡A¨Ï¥ÎªÌ¥i¯à§¹¥þ¤£·|¹îı¡C¦Ó¥B¡A¦bµo¥Í¨u¨£ªº¨t²ÎÂê©w±¡ªp¤U (¤]³\¬O¦]¬°µwÅ饢±Ñ©Î¬Oª½±µ§ðÀ»©Ò³y¦¨ªºµ²ªG)¡ABitLocker ¤]´£¨Ñ²³æ¦Ó¦³®Ä²vªº×´_³B²zµ{§Ç¡C³o¨Ç±¡ªp¤§¤¤¥]¬A±N§t§@·~¨t²ÎºÏºÐ°ÏªºµwºÐ²¾¦Ü¥t¤@³¡¹q¸£¡B§ó´«¥]§t TPM ªº¥D¾÷ªO¡A©Î¦´Á¶}¾÷Àɮתº¸ê®Æ·l·´µ¥¨Æ¥ó¡C
BitLocker Drive Encryption¡G
• |
¦b¨t²ÎÂ÷½u®É«OÅ@¸ê®Æ¡A¦]¬°¥¦·|¡G
| ||||||
• |
½T«O¶}¾÷µ{§Ç§¹¾ã©Ê¡A¦]¬°¥¦·|¡G
| ||||||
• |
³z¹L¤U¦C¤è¦¡´î»´³]³Æ¦^¦¬¤u§@t¾á¡G
|
¥»¤å¥ó»¡©ú¥ø·~¹q¸£¤Wªº BitLocker Drive Encryption ¥Í©R¶g´Á¡A´yz¦b¦UºØ¤£¦P¨Ï¥ÎªÌ®×¨Ò¤¤ªº³]©w¡BºÞ²z¤Î×´_¥\¯à¤Î¬ÛÃöÁpªºª÷Æ_¡CWindows Vista ªº¶}µo¤u§@©|¥¼§¹¥þµ²§ô¡A¿Ã¹õÂ^¨úµe±¡BAPI¡B¤å¦r©M¬yµ{³£¥i¯à·|Åܧó¡C
Yn¨Ï¥Î BitLocker¡A¹q¸£¥²¶·º¡¨¬¤@²Õ¥Ñ BitLocker Windows Vista ¨t²Î¼Ð»x»Ý¨D©Ò«ü©wªº±ø¥ó¡C³o¨Ç»Ý¨Dªº´ú¸Õ·|ÀHªþ©ó Windows Development Kit (WDK) ¤¤¤@°_µo¦æ¡G
• |
¨t²Î¥²¶·¨ã¦³ Trusted Platform Module (TPM) v1.21¡CTPM ´£¨Ñ¨t²Î¶}¾÷µ{§Ç§¹¾ã©Ê´ú¶q¤Î³ø§i¡C
| ||||
• |
¨t²Î¥²¶·¨ã¦³ v1.2 TCG (Trusted Computing Group) ¬Û®eªº BIOS1¡C
| ||||
• |
¨t²Î BIOS ¥²¶·¤ä´© USB ¤j«¬¦s©ñ¸Ë¸mÃþ§O2¡A¨ä¤¤¥]¬A¦b§@·~¨t²Î¤§«eªºÀô¹Ò¤¤¡A¦b§Ö°{ºÏºÐ¤WŪ¨ú¤Î¼g¤J¤p«¬Àɮתº¬ÛÃö¸ê°T¡C | ||||
• |
¹q¸£¥²¶·¦Ü¤Ö¨ã¦³¨âӺϺаÏ3¤~¯à¹B§@¡G
|
¥»¤å¤¤ªº¸ê°T¾A¥Î©ó§t BitLocker ªº Windows ª©¥»¡C¦øªA¾¹¯S©wªº¸ê°T¥]§t¦b¡Õ²Ä 3.5 ¸`¡A¦øªA¾¹¤Wªº BitLocker¡Ö¡C
BitLocker ªº¥Dn¥Ø¼Ð¬O«OÅ@µwºÐ¤W§@·~¨t²ÎºÏºÐ°Ï¤Wªº¸ê®Æ¡C¬°¤F¹F¦¨³o¶µ¥Ø¼Ð¡ABitLocker ¨Ï¥Î v1.2 TPM ¦w¥þ©ÊµwÅé¡A¥H¨ó§U«O»Ù¥[±Kª÷Æ_ªº¦w¥þ¡A¨Ã¨¾¤î¹ï¨t²Î§¹¾ã©Ê©Î¨ä¥L¸ê®Æ¡BÀ³¥Îµ{¦¡¡BDLL ÀÉ¡A¥H¤ÎÀx¦s¦b§@·~¨t²ÎºÏºÐ°Ï¤WÀÉ®×µo°Êªº³nÅé§ðÀ»¡C
BitLocker ¥]§t¹ï«nªº¦´Á¶}¾÷¤¸¥ó¶i¦æ§¹¾ã©ÊÀˬd¡CBitLocker ¨Ï¥Î TPM¡A¦b¶}¾÷µ{§Ç¤§¤º¦¬¶°¨ÃÀx¦s¦hºØ¨Ó·½ªº´ú¶q¡A4¥H«Ø¥ß¤@ºØ¨t²Î¡u«ü¯¾¡v¡C°£«D¶}¾÷¨t²Î¾D¨ì«§ï¡A§_«h¡u«ü¯¾¡v·|«O«ù¤£ÅÜ¡CBitLocker ¦³¿à©ó TPM ®Ú¾Ú³o¨Ç´ú¶q¡A¨Ó¨î®Ú¥Ø¿ý¾÷±Kªº¦s¨ú¡C¤@¥¹ÃÒ©ú¶}¾÷µ{§Çªº§¹¾ã©Ê¤§«á¡ABitLocker ´N·|¨Ï¥Î TPM¡A¸Ñ°£¨ä¾l¸ê®ÆªºÂê©w¡CµM«á¨t²Î·|Ä~Äò±Ò°Ê¡A¦Ó¨t²Î«OÅ@´NÂà¦Ó¦¨¬°°õ¦æ¤¤§@·~¨t²Îªº³d¥ô¡C
[¹Ï 1] ¥Ü½dºÏºÐ°Ï¦p¦ó¥H§¹¾ãºÏºÐ°Ï¥[±Kª÷Æ_ (Full Volume Encryption Key¡AFVEK) ¬°ºÏºÐ°Ï¤º®e¥[±K¡A¸Óª÷Æ_¦AÂà¦Ó§Q¥ÎºÏºÐ°Ï¥Dnª÷Æ_ (Volume Master Key¡AVMK) ¥[±K¡C«O»Ù VMK ¦w¥þ¬O¥H¶¡±µ¤è¦¡«OÅ@ºÏºÐ°Ï¤Wªº¸ê®Æ¡G¥[¤WºÏºÐ°Ï¥Dnª÷Æ_¡A¥iÅý¨t²Î¦b«H¿àÃì¤W´åªºª÷Æ_¿ò¥¢©Î¾D¤J«I®É¡A»´©ö´N¯à«·s³]©wª÷Æ_¡C¦p¦¹¥i¸`¬Ù¸Ñ±K¤Î«·s¥[±K¾ãӺϺаϪº¶}¾P¡C
¤@¥¹ BitLocker ÅçÃÒ¹L¨ü«OÅ@§@·~¨t²ÎºÏºÐ°Ïªº¦s¨úÅv¥H«á¡A¸ê®Æ¼g¤J¨ü«OÅ@ºÏºÐ°Ï©Î±q¤¤Åª¨ú¸ê®Æ®É¡A Windows Vista Àɮרt²Î°ïÅ|¤¤ªº¿z¿ï¾¹ÅX°Êµ{¦¡´N·|¦Û°Ê¥[±K¤Î¸Ñ±KºÏºÐ°Ï¡C·í¹q¸£¶i¤J¥ð¯v®É¡A¥ð¯vÀɮ׬O¥H¥[±K¤è¦¡Àx¦s¦b¨ü«OÅ@ªººÏºÐ°Ï¤¤¡C±q¥ð¯vª¬ºA«ì´_ªº³B²z¤è¦¡´X¥G»P¶}¾÷µ{§Ç§¹¥þ¬Û¦P¡G¦¹Àx¦sÀÉ®×·|¦b¹q¸£±q¥ð¯vª¬ºA«ì´_®É¸Ñ±K¡C¥[±K¤Î¸Ñ±K¹ï®Ä¯àªºt±¼vÅTÀ³¸Ó·¥¨ä¦³¡A¦Ó¥B¦b¤j³¡¤À±¡ªp¤U³£¬O¦Û°Ê°õ¦æ¡C
IT ¨t²ÎºÞ²zû¥i¥H³z¹LºëÆF©Î¬O¥Ñ Windows Vista ªº Win32_EncryptableVolume Windows Management Instrumentation (WMI) ´£¨ÑªÌ¤½¶}ªº¤¶±¡A¦b¥»¾÷©Î»·ºÝ³]©w BitLocker¡C¤¶±¤¤¥]§tºÞ²z¥\¯à¡A¥i¶}©l¡B¼È°±¤ÎÄ~ÄòºÏºÐ°Ï¥[±K§@·~¡A¨Ã³]©w«OÅ@ºÏºÐ°Ï¥[±Kª÷Æ_ (FVEK) ªº¤è¦¡¡C
Windows Vista ¤Î Windows Server "Longhorn" ¤¤¦³¤@ºØºÞ²z«ü¥O½X (manage-bde.wsf)¡A´£¨Ñ IT ¨t²ÎºÞ²zû²³æªº¤è¦¡ºÞ²z¤ÎÀˬdºÏºÐª¬ºA¡C³oÓ«ü¥O½X¬O¥H¥i¥Îªº WMI ´£¨ÑªÌ¬°°ò¦¼¶¼g¦Ó¦¨¡A«Ü®e©ö´N¯à¥[¥Hקï¡A¥H¨ó§U°w¹ï¤£¦Pªº¥ø·~¨t²ÎºÞ²z»Ý¨D«Ø¥ß¦Ûq¸Ñ¨M¤è®×¡C
[¹Ï 2] ¥Ü½d¾ãÅé BitLocker ¬[ºc¡A¥]¬A¨ä¤¤¦UºØ¤£¦Pªº¤l¤¸¥ó¡C¹Ï¤¤Åã¥Ü BitLocker ªº¨Ï¥ÎªÌ¼Ò¦¡©M®Ö¤ß¼Ò¦¡¤¸¥ó¡A¤Î¨ä»P§@·~¨t²Î¤£¦P¼h¦¸¾ã¦Xªº¤è¦¡¡C·í¤¤¯S§OÅã¥Ü¥X±±¨î TPM ªº¼Ò²Õ¡A¥]¬A Microsoft Management Console (MMC) ´O¤J¦¡ºÞ²z³æ¤¸¡BTPM ÅX°Êµ{¦¡¡A¥H¤ÎºÏºÐ¥[±K¼Ò²Õ¡C
ªì¦¸³]©w BitLocker ®É¡A±z¥i¥H±q¼ÆºØÅçÃÒ¼Ò¦¡¿ï¾Ü¨ä¤¤¤@ºØ¡C¨C¦¸¨ü BitLocker «OÅ@ªº¨t²ÎºÏºÐ°Ï¤@±Ò°Ê¡AWindows Vista ¶}¾÷µ{¦¡½X³£·|®Ú¾ÚºÏºÐ°Ï«OÅ@³]©w¡A°õ¦æ¤@¨t¦C¨BÆJ¡C³o¨Ç¨BÆJ¥i¥H¥]¬Aµ{¦¡½X§¹¾ã©ÊÀˬd¡A¥H¤Î¥²¶·¥ý½T»{¤~¯à¸Ñ°£«OÅ@ºÏºÐ°ÏÂê©wªº¨ä¥LÅçÃÒ¨BÆJ¡CYn¶i¦æ¨ä¥L¸ê®Æ«OÅ@¡ABitLocker ¥i¥H¨Ï¥ÎÓ¤HÃѧO½X (PIN)¡A©Î±Ò°Êª÷Æ_ (Àx¦s¦b¨C¦¸¹q¸£¶}¾÷³£¥²¶·´¡¤J¤§ USB §Ö°{ºÏºÐ¤Wªºª÷Æ_)¡C
¶i¦æ×´_®É¡ABitLocker «h¨Ï¥Î×´_ª÷Æ_ (¥Î¨Ó×´_¦b BitLocker ºÏºÐ°Ï¤W¥[±K¤§¸ê®Æªºª÷Æ_)¡A©Î¨Ï¥Î×´_±K½X (¼Æ¦r±K½X)¡A¦p [¹Ï 1] ©Ò¥Ü¡A¥H«KÅý±ÂÅv¨Ï¥ÎªÌ¦b¦w¥þ©Ê¡BµwºÐ©Î¨ä¥L¥¢±Ñªº±¡ªp¤U¡A¤´µM¯à°÷¦s¨ú¨t²Î¡C
Windows Vista ·|¨Ì¤U¦C¶¶§Ç´M§äª÷Æ_¡G
1. |
¯Âª÷Æ_ (½Ð°Ñ¾\¡Õªþ¿ý¡Ö¤¤ªº¡u¦Wµü¸ÑÄÀ¡v) - ¤w¸g°±¥Î§¹¾ã©ÊÀˬd«OÅ@¡AºÏºÐ°Ï¥Dnª÷Æ_¥i¥H¦Û¥Ñ¨ú¥Î¡C¤£»Ýn¥ô¦óÅçÃÒ (½Ð°Ñ¾\¡Õ²Ä 4.3.4.3 ¤p¸`¡Ö¦³Ãö°±¥Î«OÅ@¼Ò¦¡ªº»¡©ú¡A¥H¨ú±o¸Ô²Ó¸ê°T)¡C |
2. |
¤£»Ýn¨Ï¥ÎªÌ°Ê§@ªºÅçÃÒ¡G a. TPM - TPM ¶¶§Q¦aÅçÃÒ¦´Á¶}¾÷¤¸¥ó¡A±N VMK ¶}«Ê¡C b. TPM ©M±Ò°Êª÷Æ_ - TPM ¶¶§QÅçÃÒ¦´Á¶}¾÷¤¸¥ó¡A¦Ó¥B¤w´¡¤J¥]§t±Ò°Êª÷Æ_ªº USB §Ö°{ºÏºÐ¡C |
3. |
»Ýn¨Ï¥ÎªÌ°Ê§@ªºÅçÃÒ (§e²{µ¹¨Ï¥ÎªÌªº¤å¦r¼Ò¦¡¤¶±)¡G a. TPM ©M PIN - TPM ÅçÃÒ¦´Á¶}¾÷¤¸¥ó½T¹êµL»~¡A¦¹¥~¡A¨Ï¥ÎªÌÁÙ¥²¶·¿é¤J¥¿½Tªº PIN¡A±Ò°Êµ{§Ç¤~¯àÄ~Äò¡A¦Ó±NºÏºÐ¾÷¸Ñ°£Âê©w¡CPIN ¤w¨ü¨ì«OÅ@§K©ó TCG ¬Û®eªº TPM¡u«¡vÀ»¡C b. ×´_ª÷Æ_©M/©Î±Ò°Êª÷Æ_ - ¨Ï¥ÎªÌ·|¦¬¨ì´£¥Ü´¡¤J¦s©ñ×´_ª÷Æ_©M/©Î±Ò°Êª÷Æ_ªº USB §Ö°{ºÏºÐ¡C c. ×´_±K½X - ¨Ï¥ÎªÌ¥²¶·¿é¤J¥¿½Tªº×´_±K½X¡C |
¥~³¡ºÏºÐ°Ï¤@¯ë¬O¦b¥t¤@³¡¤w±Ò¥Î BitLocker ¤§¹q¸£¤Wªº§@·~¨t²ÎºÏºÐ°Ï¡A¨Ã¤w¡u¶×¤J¡v¥Ø«e¹q¸£¤Wªº¥Ø«e Windows ¤¤¡C¶×¤J¥~³¡ºÏºÐ°Ï¬O§Ö³t¦Óª½±µªº×´_µ{§Ç¡A¨Ò¦p¡A±q²{¦b¤w·lÃa¹q¸£¤W¥[±KªººÏºÐ×´_¸ê°T¡C¦b³oºØºÏºÐ°Ï¤W°ß¤@¥i¥ÎªºÅçÃÒ§@·~´N¬O×´_ (½Ð°Ñ¾\¡Õ²Ä 5 ¸`×´_¡Ö¡A¥H¨ú±o¸Ô²Ó¸ê°T)¡C×´_»Ýn×´_ª÷Æ_©Î×´_±K½X¡C
¹ïÀx¦s¦b¤£¦w¥þ©Î¦@¥ÎÀô¹Ò (¦p¤À¤½¥q¦aÂI) ¤¤ªº¦øªA¾¹¦Ó¨¥¡ABitLocker ¥i«OÃҨ㦳»P´£¨Ñµ¹¥Î¤áºÝ¹q¸£¤§¬Û¦P¼h¦¸ªº¸ê®Æ«OÅ@¡C³oºØ¦øªA¾¹¤W¥i¥Îªº¥~¥[¥\¯à·|¥[±K§@·~¨t²ÎºÏºÐ°Ï¡A¨Ã¥i³z¹L WMI ¦b IT ¨t²ÎºÞ²zû·Qn¦³ BitLocker «OÅ@ªº¥ô¦ó¸ê®ÆºÏºÐ°Ï¤W±Ò¥Î¡C
¦b¹w³]±¡ªp¤U¡ABitLocker Drive Encryption ¤£·|»P Windows Server "Longhorn" ¦P®É¦w¸Ë¡C½Ð¿ï¨ú [·s¼W¥\¯à (Add Features)]¡AµM«á±q²M³æ¿ï¶µ¤¤¿ï¨ú [BitLocker Drive Encryption]¡A±q InitialConfigurationTasks ¥\¯àªí¥[¤J BitLocker ¥\¯à¡C¦w¸Ë BitLocker ¥\¯à¥H«á¡A³]©w¤ÎºûÅ@§@·~§Y·|¨Ì·Ó¥»¤å¥óµy«á»¡©ú¯ë°õ¦æ¡C¦b¦øªA¾¹¤W¦w¸Ë BitLocker Drive Encryption ¤§«á¡A¥²¶·«·s¶}¾÷¡CBitLocker ¥i¥H¨Ï¥Î WMI ±q»·ºÝ¥[¥H±Ò¥Î¡C
PIN ¤ä´©
¤@¯ë¨Ó»¡¡A¦b¦Ò¼{¨ì«·s¶}¾÷³t«×¡A©Î¦]¤H¬°¤¶¤J¦ÓµLªk«·s¶}¾÷ªº¦øªA¾¹¤W±Ò¥Î PIN ¥\¯à¨Ã¤£¬O³Ì¨Î§@ªk¡C¦b³\¦h¦øªA¾¹Àô¹Ò¤¤¡A°õ¦æ®É¶¡»P»·ºÝºÞ²z«D±`«n¡C
¦³¤@ºØ¥i¦æªº³¡¸p®×¨Ò¬O¡G¦bû¤u¨C¦¸¤@¶}©l¤W¯Z´N¥²¶·¶}±Ò¦øªA¾¹ªº¤À¤½¥q¤¤¡A¶}±Ò BitLocker ©M PIN ¥\¯à¡C¦b¦¹±¡ªp¤U¡At³dªº¤H·|ª¾¹D¨Ã¦b¶}¾÷®É¿é¤J PIN¡C
±Ò°Êª÷Æ_¤ä´©
¤ä´©¦øªA¾¹ªº USB ±Ò°Êª÷Æ_¡A¦ý¥u¦³¦b¶}¾÷«á¤£¯d¦b¹q¸£¤¤¡A¤~¯à´£¤É¸ê®Æ«OÅ@¡C¦]¦¹¡A¨C¦¸¦øªA¾¹«·s±Ò°Ê³£¥²¶·¤H¬°¤¶¤J¡A¤~¯à¹F¨ì³Ì¨Î¸ê®Æ«OÅ@§@¥Î¡C
3.4.1 ¸ê®ÆºÏºÐ°Ï
§@·~¨t²ÎºÏºÐ°Ï©M¨t²ÎºÏºÐ°Ï¥H¥~ªººÏºÐ°Ï¡A´NºÙ¬°¡u¸ê®ÆºÏºÐ°Ï¡v¡C¥u¦³¦b Windows Server "Longhorn" v1 ¤¤¡A¤~¤ä´©¸ê®ÆºÏºÐ°Ïªº BitLocker ¥[±K¡C
BitLocker ¬O³z¹L¥H¥[±K§@·~¨t²ÎºÏºÐ°Ïªº¬Û¦P¤è¦¡¶i¦æ¥[±K¨Ó«OÅ@ Windows Server "Longhorn" ¸ê®ÆºÏºÐ°Ï¡C§@·~¨t²Î·|¥H¤@¯ë¤è¦¡±¾¤W BitLocker «OÅ@ªº¸ê®ÆºÏºÐ°Ï¡C
ª÷Æ_Ãì
«OÅ@¸ê®ÆºÏºÐ°Ïªºª÷Æ_»P«OÅ@§@·~¨t²ÎºÏºÐ°Ïª÷Æ_²@µLÃö«Y¡CYn¤¹³\¨t²Î¦Û°Ê±¾¤W³o¨ÇºÏºÐ°Ï¡A«OÅ@¸ê®ÆºÏºÐ°Ïªºª÷Æ_Ãì¤]n¥[±KÀx¦s¦b¥Ø«e¤w¶}¾÷ªººÏºÐ°Ï¤W¡C©ú½T¦a»¡¡A´N¬O¦b¥Ø«e¤w¶}¾÷ªººÏºÐ°Ïµn¿ý¤¤n¦³ External Wrapping Key (EWK)¡A³o¬O 256 ¦ì¤¸ AES ª÷Æ_¡A·|«OÅ@¸ê®ÆºÏºÐ°Ïªº VMK¡C¥Ñ©ó EWK ¬OÀx¦s¦b¥[±Kªº§@·~¨t²ÎºÏºÐ°Ï¤§¤º¡A¥¦°£¤F¨ü BitLocker «OÅ@¥~¡A¤]¨ü¨ì Windows Server "Longhorn" §@·~¨t²Î¥»¨ªº«OÅ@¡C¦pªG§@·~¨t²Î¶i¤J×´_¼Ò¦¡¡A¤@ª½¨ì§@·~¨t²ÎÂ÷¶}×´_¼Ò¦¡¡A³£¯à«O»Ù¸ê®ÆºÏºÐ°Ïªº¦w¥þ¡C
¦Û°Ê¸Ñ°£Âê©w
¦Û°Ê¸Ñ°£Âê©w¥i¥H¦b¶}¾÷´Á¶¡Åý¸ê®ÆºÏºÐ°Ï¦Û°Ê¸Ñ°£Âê©w¡A¦Ó¤ð»Ý¤H¬°¤¶¤J¡C±Ò¥Î¦Û°Ê¸Ñ°£Âê©w·|¦V¤w¶}¾÷§@·~¨t²Îªºµn¿ý»{¥i¸ê®ÆºÏºÐ°Ï EWK ªº¯Â¤å¦r½Æ¥»¡C¨S¦³¶¶§Q¦a¦s¨ú¤w¥[±Kªº§@·~¨t²ÎºÏºÐ°Ï¡A´N¤£¯à¦s¨ú¸ê®ÆºÏºÐ°Ï¤Wªº¸ê®Æ¡C²Ä¤@¦¸¹Á¸Õ±q Windows Ū¨ú©Î¬d¸ß¸ê®ÆºÏºÐ°Ï¡A·|³y¦¨±qµn¿ýŪ¨ú EWK ±N¨ä VMK ¸Ñ±K¡C§Y¨Ï§@·~¨t²ÎºÏºÐ°Ï¤W¤wÃö³¬ BitLocker¡ABitLocker ¤]·|²M°£§@·~¨t²ÎºÏºÐ°Ïµn¿ý¤¤ªº¥ô¦óª÷Æ_¸ê®Æ¡C¦b³o¨Ç±ø¥ó¤§¤U¡A¨Ï¥ÎªÌ¥²¶·´£¨Ñª÷Æ_¡A¥H¦s¨ú¸ê®ÆºÏºÐ°Ï¡C
¨t²ÎªººÞ²zû¥i¥H¨Ï¥Î¥i½s¼g«ü¥O½Xªº WMI ¤¶±¡A±Ò¥Î©Î°±¥Î¦U¨t²Îªº¦Û°Ê¸Ñ°£Âê©w¡C¬°¤F«O«ù¸ê®ÆºÏºÐ°Ïªº°ª«×«OÅ@¡A°£«D§@·~¨t²ÎºÏºÐ°Ï¤w±Ò¥Î BitLocker ¨Ã¶i¦æ¥[±K¡A§_«h¨S¦³¤H¯à°÷±Ò¥Î¦Û°Ê¸Ñ°£Âê©w¡C
ÂO¶°³]©w
BitLocker ¤£¤ä´© v1 ¤¤»PÂO¶°³]©w¬ÛÃöÁpªº¸ê®ÆºÏºÐ°Ï¡C
×´_
¸ê®ÆºÏºÐ°Ï×´_Ãþ¦ü©ó§@·~¨t²ÎºÏºÐ°Ï×´_¡C±z¥²¶·¦b¥¢±Ñ¥H«e (³Ì¦n¬O¦b³]©w®É)¡A¥ý±N EWK ½Æ¥»Àx¦s¦b¨ä¥L´CÅé¤W¡C¦pªG¸ê®ÆºÏºÐ°Ï·l·´¡B²¾¨ì·sªº¥¥x¤W¡A©Î¬O§@·~¨t²ÎºÏºÐ°ÏµLªkÂ^¨ú¨Ñ¦Û°Ê¸Ñ°£Âê©wªº EWK¡A«h¨Ï¥ÎªÌ¥²¶·´¡¤J§t EWK ½Æ¥»ªº´CÅé¡C
¸ê®ÆºÏºÐ°Ïªº×´_¬O¥Ñ¤¶±©M WMI ´£¨ÑªÌ¥[¥H¤ä´©¡C¸ê®ÆºÏºÐ°Ï¬O¥HÃþ¦ü BitLocker ¥Î¤áºÝª©¥»¤¤ªº¥~³¡ºÏºÐ°Ï¨Ó¹ï«Ý¡C¥u¦³¦b§@·~¨t²ÎºÏºÐ°Ïµn¿ý¤¤ªº EWK ¿ò¥¢©Î·l·´®É¡A¤~»Ý«·s±N¸ê®ÆºÏºÐ°Ïôµ²¦Ü¥¥x¤W¡C
¥H°ª¼hªº¨¤«×¨Ó¬Ý¡A¹ï BitLocker ªº«Â¯Ù¥i¥H¤À¬°¨â¤jÃþ¡G¹ï¥¥xªº«Â¯Ù¥H¤Î¦]¨t²Î¨Ï¥Î¤è¦¡¦Ó³y¦¨ªº«Â¯Ù¡C¨C¤@ºØ«Â¯Ù³£¥i¥H³z¹L¨Ï¥ÎªÌ¯à°÷¬°«OÅ@¨t²Î±Ä¨úªº¯S©w°Ê§@¦Ó±o¨ìÓV½w¡C
²Ä¤@ºØ«Â¯Ù«üªº¬O¹ï BitLocker ©Ò¹B§@¤§¥¥xªº«Â¯Ù¡CBitLocker ¹ï¨C¤@ºØ¤£¦PªºÅçÃÒ¼Ò¦¡³£¦³¯S©wªºµwÅé»Ý¨D¡CYnÓV½w³oÃþ«Â¯Ù¡A¦Ó¥Bn¹ê»Ú¹F¨ì³Ì°ª¦w¥þ©Ê§Q¯q¡A«h¥²¶·²Å¦X©Ò¿ï¨úÅçÃÒ¼Ò¦¡ªº³o¨Ç»Ý¨D¡C¨Ò¦p¡A¦pªG¨Ï¥Î TPM+PIN ÅçÃÒ¼Ò¦¡¡A¨Ï¥ÎªÌ¥²¶·½T©w©Ò¨Ï¥Îªº¥¥x¬O¹B¥Î»P TCG »Ý¨D§¹¥þ¬Û®eªº TPM 1.2 ª©¡C
¦]¨t²Î¨Ï¥Î±¡§Î¦Ó²£¥Íªº¼ç¦b«Â¯Ù¥i¥HÂǥѤU¦C³Ì¨Î¹ê§@¤èªk¦ÓÓV½w¡A·í¤¤»¡©ú¤F¨t²ÎÀ³¸Ó¦p¦ó³]©w¡A¥H¤Î¥¿½Tªº¨Ï¥ÎªÌ§@ªk¡C¨Ï¥ÎªÌÀ³¸Ó½T«O©w´Á¤U¸ü¤@¯ë³nÅé§ó·s¡A¨Ã¦w¸Ë¥i«OÅ@¨t²Î§K©ó¾D¨ü§ðÀ»ªº¦w¥þ©Ê³nÅé (¨Ò¦p¡G¨¾¤õÀð¡B¨¾¬r¡B¨¾¶¡¿Ò³nÅéµ¥µ¥)¡C¦¹¥~¡A¹ï©ó²£«~ªº¤é±`¨Ï¥Î¡A¾A·í¨Ï¥Î³Ì¨Î¤ÆªºÅçÃÒ§@·~¤Î×´_¾÷¨î¤]¥i¥HÓV½w³oÃþ«Â¯Ù¡C¨Ò¦p¡A½T«O¾A·í³B²z±Ò°Êª÷Æ_ (¤]´N¬O¡A¤£nÀH®É±Nª÷Æ_¯d¦b¾÷¾¹¸Ì)¡A¥H¨¾¤î¸ê®Æ¿ò¥¢©Î¾D¥¼±ÂÅv¨Ï¥ÎªÌ¦s¨ú¡A³£¯àÓV½w¹ï¸ê®Æ«O±Kªº«Â¯Ù¡C
BitLocker ¨t²Î¥Í©R¶g´Á¤¤¦³¥|¤jn¯À¡A¦p [¹Ï 3] ©Ò¥Ü¡C
[¹Ï 3]¡G BitLocker Drive Encryption ¥Í©R¶g´Á¡C
1. |
¦w¸Ë¡GBitLocker ¤D¦w¸Ë¦¨ Windows Vista ªº¤@³¡¤À¡C |
2. |
ªì©l¤Æ¡GBitLocker ¥\¯à¤wªì©l¤Æ¨Ã¤w¶}±Ò¡C |
3. |
¤é±`¨Ï¥Î¡G¤é±`¨Ï¥Îªº±¡§Î¨Ì²Ä 2 ¶¥¬q©Ò¿ï¨úªº¿ï¶µ¦Ó©w¡A¥i¯à¨ã¦³¤£¦P¼h¦¸ªº«OÅ@¡C |
4. |
¹q¸£¨O´«¡G¤w±Ò¥Î BitLocker ¥\¯àªº¹q¸£»Ýn¨O´«/¤É¯Å/«·s³¡¸p¡C |
¤U±¦U¸`±N»¡©ú¤Wz¦UºØn¯À¡A¨Ã³z¹LÓ®×ÄÄz³Ì±`¨£ªº BitLocker ¥[ȮרҡC¸Ô²Óªº¬[ºc¹Ï½Ð°Ñ¾\¡Õ²Ä 3.2 ¸`¡Ö¡C
BitLocker ¬OÄÝ©ó Windows Vista ªº¤@³¡¤À¡A·|¦b¦w¸Ë Enterprise ©M Ultimate ª© OS ´Á¶¡¦Û°Ê¶i¦æ¦w¸Ë5 (½Ðª`·N¡A¥¦¤£·|¦Û°Ê¶}±Ò)¡C¦Ü©ó Windows Server "Longhorn"¡A±z¥²¶·¿ï¾Ü¦w¸Ë BitLocker Drive Encryption ¥\¯à¡C¦b§@·~¨t²Î¦w¸Ë´Á¶¡¡A·|¦³¤U¦C BitLocker ¨BÆJ (¥Î¤áºÝ©Î¦øªA¾¹³£¬Û¦P)¡G
1. |
¦w¸Ë¾A·íªº BitLocker ÀɮסC |
2. |
Àˬd TPM/BIOS ªºª©¥»¬O§_¥¿½T¡C |
3. |
¦w¸Ë TPM ©M BitLocker ÅX°Êµ{¦¡¡C |
¦w¸Ë§@·~¨t²Î¨Ã¶i¦æªì©l³]©w¤§«á¡A¨t²ÎºÞ²zûÀH®É³£¥i¥H¨Ï¥Î Windows Vista ±±¨î¥x¡Aªì©l¤Æ©M¶}±Ò BitLocker ¥\¯à¡C³]©w§@·~¤¤¦³¨âÓ¨BÆJ¡G
1. |
³]©w TPM (¨C³¡¹q¸£¥u»Ýn¶i¦æ¤@¦¸)¡C |
2. |
³]©w BitLocker (¨CÓ§@·~¨t²Î¥u»Ýn¶i¦æ¤@¦¸)¡C |
³o¨âÓ¨BÆJ³£»Ýn¥»¾÷¨t²ÎºÞ²zÅv¡C¨S¦³¨t²ÎºÞ²zÅvªº¨Ï¥ÎªÌ¥i¥H¦] BitLocker ¸ê®Æ«OÅ@¦ÓÀò¯q¡A¦ý¤£¯à¶}±Ò©ÎÃö³¬ BitLocker¡C
¥ø·~³¡¸p¡A¥]¬A Active Directory ³]©w¡BBitLocker ì«h¡A¤Î¥H«ü¥O½X¦w¸Ë³£·|¦b²Ä 4.2.3 ¸`¤¤°Q½×¡C |
4.2.1 TPM ªì©l¤Æ
¨Ï¥Î¡uTPM ªì©l¤ÆºëÆF¡v©Î°õ¦æ¸g¹L¯S§O³]p¥H¶i¦æªì©l¤Æªº«ü¥O½X¡Aªì©l¤Æ±zªº TPM¡C¡uTPM ªì©l¤ÆºëÆF¡v¥i¥H³z¹L TPM Management Console ºëÆF¦s¨ú¡A«áªÌ¬O¿í´` [¦w¥þ©Ê±±¨î¥x (Security Control Panel)] ¤¤ªº³sµ²¥[¥H±Ò°Ê¡C
¦b³o¨âºØ±¡ªp¤U¡Aªì©l¤Æ TPM6 ¥]§t¤U¦C¨BÆJ¡G
1. |
¦pªG TPM ©|¥¼¶}±Ò¡A½Ð¶}±Ò TPM¡C®Ú¾Ú¹q¸£»s³y°Óªº±¡ªp¡A¶}±Ò¤èªk¦U¦³¤£¦P¡C |
2. |
Àˬd¹ê»Ú¦s¦bª¬ºA (¨t²ÎºÞ²zû¥²¶·¿Ë¦Û¦b¥D±±¥x«e°õ¦æ§@·~)¡C a. °£«D OEM ´£¨Ñ´À¥N©Êªº»·ºÝ³¡¸p¸Ñ¨M¤è®× |
3. |
µn¤J¦^¨ì Windows Vista¡C |
4. |
Àˬd TPM ¤§¤º¬O§_¦³I®Ñª÷Æ_ (¥Ñ OEM ´£¨Ñªºª÷Æ_)¡C |
5. |
«Ø¥ß TPM ¨t²ÎºÞ²z±K½X¡A³]©w TPM ªº¾Ö¦³ªÌ¡C |
6. |
©e¥I TPM ¨t²ÎºÞ²z±K½Xµ¹ Active Directory (AD) ¨Ã/©ÎÀx¦s¦¨ÀɮסC a. ½Ðª`·N¡A¦pªG¨t²ÎºÞ²zû¤w³]©w¸s²Õì«h (GP) ¨Ó°õ¦æµo§G¡AAD µo§G·|¥Ñ¨t²Î¦Û°Ê°õ¦æ¡C |
¥t¥~Á٤䴩 TPM ªº»·ºÝªì©l¤Æ7¡CBitLocker ªº TPM ªA°È¤¸¥ó·|Åã¥ÜºÞ²z API¡A¤¹³\¥H«ü¥O½X°õ¦æªì©l¤Æµ{§Ç - ¥]¬A³]©w¾Ö¦³ªÌ¤Î«Ø¥ß TPM ¨t²ÎºÞ²z±K½X¡C
TPM ªì©l¤Æ§@·~§Y¤w§¹¦¨¡C±N TPM ªì©l¤Æ¤§«á¡A¥»¾÷¨t²ÎºÞ²zû§Y¥iªì©l¤Æ BitLocker¡C
4.2.2 ¶}±Ò BitLocker Drive Encryption
Yn¶}±Ò Windows Vista ªº BitLocker Drive Encryption ¥\¯à¡A½Ð¨Ï¥Î¸Ó¥\¯àªººëÆF©Î«ü¥O½X¡C
¦b [Windows Vista ¸ê°T¦w¥þ¤¤¤ß] ±ªO¤¤±Ò°Ê¡uBitLocker ³]©wºëÆF¡v¡A±N·|±a±z³v¨B§¹¦¨¤U¦C¨BÆJ¡G
1. |
±Ò¥Î Windows Vista ºÏºÐ°Ïªº BitLocker 6¡C |
2. |
¿ï¾Ü×´_¤èªk¡C |
3. |
«ö¤@¤U [¶}±Ò BitLocker—ü (Turn On BitLocker—ü)] ³sµ²¡AÄ~Äò¶i¦æºÏºÐ°Ï¥[±K§@·~¡C¥[±K§@·~´Á¶¡¡ABitLocker ·|¦bÅã¥ÜI´º¥[±K¶i«×¦C©M¨t²Î§X¹Ï¥Ü¡C |
¡uBitLocker ³]©wºëÆF¡v¤¹³\¥»¾÷¨t²ÎºÞ²zû±Ò¥Î BitLocker¡C¨t²ÎºÞ²zû¥i¨Ï¥Î¦¹ºëÆF«ü©w¥[±Kª÷Æ_ªº«OÅ@¤è¦¡¡A¨Ã¶}©l°õ¦æ¥]§t Windows Vista ªººÏºÐ°Ï¥[±K§@·~¡C
¡uBitLocker ³]©wºëÆF¡vªº¾ãÓ¬yµ{Åã¥Ü©ó¤U±ªº [¹Ï 4] ¤¤¡C¥»¹Ï¥Øªº¦bÅã¥Üµe±ªº¶¶§Ç¡A¦Ó¤£¦bÅã¥Ü¨C¤@ӿùõÂ^¨úµe±¡C¨C¤@ӿùõÂ^¨úµe±¤U±³£¦³»¡©ú¡C |
±Ò°Ê¿ï¶µ
±Ò°ÊÅçÃҿﶵ¥]¬A¡G
• |
¶È TPM (²¤¹Lµe± 2a ©M 2b)¡F |
• |
TPM+PIN (¨Ï¥Îµe± 2a¡A¦ý¤£¥Î 2b)¡F |
• |
TPM+±Ò°Êª÷Æ_ (¨Ï¥Îµe± 2b¡A¦ý¤£¥Î 2a)¡A©Î¬O |
• |
¦b¥¼±Ò¥Î TPM ªº¹q¸£¤W¡A¶È±Ò°Êª÷Æ_ (¨Ï¥Îµe± 2b)¡C |
½Ðª`·N¡APIN ©M±Ò°Êª÷Æ_¤£¯àµ²¦X¹B§@¡C
«Ø¥ß±Ò°Ê PIN
µe± 2a ´£¨Ñ¥i¿é¤J 4 ¦Ü 20 ¦ì¼Æ PIN ªº¿ï¶µ¡F¨C¦¸«·s±Ò°Ê³£¥²¶·¿é¤J PIN¡F³o¼Ë´N·|¬°¥[±KªººÏºÐ°Ï¦h³]¤@¹DÅçÃÒ«OÅ@Ãö¥d¡C½Ð°Ñ¾\¡Õ²Ä 4.3.2 ¸`¡Ö¡A¥H¨ú±o§ó¸Ô²Ó¸ê°T¡Cºô°ì¨t²ÎºÞ²zû¥i¥H¨Ï¥Î¸s²Õì«h¡An¨D©Î¤£¤¹³\«Ø¥ß PIN¡C
«Ø¥ß¨ÃÀx¦s±Ò°Êª÷Æ_
µe± 2b ´£¨Ñ¥i«Ø¥ß±Ò°Êª÷Æ_¡A¨ÃÀx¦s¦b USB §Ö°{ºÏºÐ¤Wªº¿ï¶µ¡F¨C¦¸«·s±Ò°Ê¡A³s±µ°ð³£¥²¶·¦³±Ò°Êª÷Æ_¡F³o¼Ë´N·|¬°§@·~¨t²ÎºÏºÐ°Ï¦h³]¤@¹DÅçÃÒ«OÅ@Ãö¥d¡C½Ð°Ñ¾\¡Õ²Ä 4.3.2 ¸`¡Ö¡A¥H¨ú±o§ó¸Ô²Ó¸ê°T¡Cºô°ì¨t²ÎºÞ²zû¥i¥H¨Ï¥Î¸s²Õì«h¡An¨D©Î¤£¤¹³\±Ò°Êª÷Æ_¡C
×´_¿ï¶µ
¥»¾÷¨t²ÎºÞ²zû¥i¥H³]©w×´_¾÷¨î¡A¦b¤£¤Ó¥i¯àµo¥Í°ÝÃDªº±¡ªp¤U¡A¥R¤Àµo´§¨Ï¥Î«K§Q©Ê (½Ð°Ñ¾\¡Õ²Ä 5 ¸`¨t²Î×´_¡Ö¡A¥H¨ú±o¸Ô²Ó¸ê°T)¡C
¨Ï¥Î×´_±K½X
µe± 3 ´£¨Ñ¥i«Ø¥ß×´_±K½Xªº¿ï¶µ¡C½Ð°Ñ¾\¡Õ²Ä 5 ¸`¨t²Î×´_¡Ö¡A¥H¨ú±o¦b¸ê®Æ×´_ª¬ªp¤U¦p¦ó¨Ï¥Î×´_±K½Xªº¬ÛÃö¸ê°T¡Cºô°ì¨t²ÎºÞ²zû¥i¥H¨Ï¥Î¸s²Õì«h¡An¨D©Î¤£¤¹³\«Ø¥ß×´_±K½X¡C¹w³]ȬOn¨D×´_±K½X¡C
Àx¦s×´_±K½X
µe± 4 ´£¨Ñ¦hÓÀx¦s×´_±K½Xªº¿ï¶µ¡A¨ä¤¤¥]¬AÅã¥Ü±K½X¡B±N¤§Àx¦s¦¨ÀɮסB¤Î/©Î¦C¦Lµ¥¥\¯à¡C½Ð°Ñ¾\¡Õ²Ä 5 ¸`¨t²Î×´_¡Ö¡A¥H¨ú±o¦b¸ê®Æ×´_ª¬ªp¤U¦p¦ó¨Ï¥Î×´_±K½Xªº¬ÛÃö¸ê°T¡Cºô°ì¨t²ÎºÞ²zû¥i¥H¨Ï¥Î¸s²Õì«h¡An¨D©Î¤£¤¹³\«Ø¥ß×´_±K½X¡C¹w³]ȬOn¨D×´_±K½X¡C
±N×´_±K½XÀx¦s¦Ü USB ºÏºÐªº¿ï¶µ
µe± 4a ´£¨Ñ¥i±N×´_±K½X¥H¤å¦rÀÉÀx¦s¦Ü USB §Ö°{ºÏºÐªº¿ï¶µ¡C¦¹¥~¡A¦pªG¸s²Õì«h¤¹³\¡AÁÙ·|«Ø¥ß×´_ª÷Æ_ (¬Û·í©ó¤H¤u¥iŪ¨ú×´_±K½Xªº¾÷¾¹¥iŪ¨úª÷Æ_)¡A¨ÃÀx¦s¦Ü USB §Ö°{ºÏºÐ¤W¡C½Ð°Ñ¾\¡Õ²Ä 5 ¸`¨t²Î×´_¡Ö¡A¥H¨ú±o¦b¸ê®Æ×´_ª¬ªp¤U¦p¦ó¨Ï¥Î×´_±K½Xªº¬ÛÃö¸ê°T¡Cºô°ì¨t²ÎºÞ²zû¥i¥H¨Ï¥Î¸s²Õì«h¡An¨D©Î¤£¤¹³\«Ø¥ß×´_ª÷Æ_¡C
Åã¥Ü×´_±K½Xªº¿ï¶µ
µe± 4b ´£¨Ñ¨Ï¥ÎªÌ¥iÅã¥Ü×´_±K½Xªº¿ï¶µ¡C
¦C¦L×´_±K½Xªº¿ï¶µ
µe± 4c ´£¨Ñ¨Ï¥ÎªÌ¥i¦C¦L×´_±K½Xªº¿ï¶µ¡C
±N×´_±K½XÀx¦s¦Ü¸ê®Æ§¨ªº¿ï¶µ
µe± 4d ´£¨Ñ¥i±N×´_±K½X (¤Î¨ä¬ÛÃöÁp×´_ª÷Æ_) ¥HÀÉ®×Àx¦s¦Ü¸ê®Æ§¨ (¦pºô¸ô¦@¥Î¤Wªº¸ê®Æ§¨) ªº¿ï¶µ¡Cºô°ì¨t²ÎºÞ²zû¥i¥H¨Ï¥Î¸s²Õì«h¡An¨D©Î¤£¤¹³\±N×´_ª÷Æ_Àx¦s¦Ü¸ê®Æ§¨¡A©Î³]©w©Ò¨Ï¥Îªº¹w³]¸ê®Æ§¨¸ô®|¡C
µL×´_¾÷¨îĵ§i
µe± 5 Åã¥Üĵ§i¡A´£¿ô¨Ï¥ÎªÌ¡A¦pªG¨S¦³¿ï¾Ü×´_¾÷¨î¡A«h¦b¨S¦³×´_¾÷¨î¤U¥i¯à·|¾ÉP¸ê®Æ¥Ã¤[¿ò¥¢¡C³oÓ¹ï¸Ü¤è¶ô¥i¥H¥Ñºô°ì¨t²ÎºÞ²zû³z¹L¸s²Õì«h¥[¥H°±¥Î¡C
¥[±K§@·~¤w´Nºü¥i¥H¶}©lªº³qª¾
µe± 6 ´£¨Ñ¥i¶}©l¶i¦æºÏºÐ°Ï¥[±K§@·~ªº³qª¾¡C³o¶µªì©lºÏºÐ°Ï¥[±K§@·~©Ò»Ýªá¶Oªº®É¶¡»PºÏºÐ°Ïªº¤j¤p¦³ª½±µÃö«Y¡C¦ý¬O¡A¥[±K§@·~¬O¦bI´º¤¤°õ¦æ¡A¥H«K¦bºÏºÐ°Ï¶i¦æ¥[±K®É¡AÅý¹q¸£Ä~Äò¨Ñ¤H¨Ï¥Î¡C°£¦¹¤§¥~¡A¨t²ÎºÞ²zû¥i¥HÀH®É¼È°±¨Ã«ì´_¥[±K§@·~¡C¥[±K§@·~·|¦Û°Ê¼È°±¡AÅý¹q¸£Ãö¾÷©Î¥ð¯v¡A¦Ó¥B¥i¥H¦b¹q¸£«·s¶}±Ò®É¡AÄ~Äò¶i¦æ¥[±K§@·~¡C
¥»¾÷¨t²ÎºÞ²zû¥Ø«e¤£»Ýn¨Ï¥Îµe± 6 ¨Ó¶}©l¥[±K - ¥»¾÷¨t²ÎºÞ²zû¥i¥Hµy«á¦A¶}±Ò³o¶µ¥\¯à¡AºÏºÐ°Ï´N·|¦b¤U¤@¦¸«·s¶}¾÷®É¡A±Ò°ÊºÏºÐ°Ï¥[±K¡CBitLocker ¤]¥i¥H¥Ñ¥»¾÷¨t²ÎºÞ²zûÀH®É¥[¥HÃö³¬¡C
¨Ï¥ÎªÌ¤¶±¤ä´©
1. |
¦b [±±¨î¥x] ªº [¦w¥þ©Ê] °Ï°ì¤¤¨µÄý¦Ü BitLocker ¶µ¥Ø¡A¥H¶}±Ò BitLocker—ü¡C
| ||||
2. |
¥²n®É¡A±z¥i¥H¨µÄý¦Ü¬Û¦Pªº±±¨î¥x¶µ¥Ø¡A¥HÃö³¬ BitLocker—ü¡C |
«ü¥O½X¤ä´©8
1. |
¨Ï¥Î ProtectKeyWithTPM¡A«OÅ@ TPM ºÏºÐ°Ï¥[±Kª÷Æ_ªº¦w¥þ¡C | ||||
2. |
«Ø¥ß×´_ blob¡C
| ||||
3. |
¨Ï¥Î Encrypt ¥[±KºÏºÐ°Ï¡C | ||||
4. |
¨Ï¥Î GetConversionStatus «ü¥ÜºÏºÐ¾÷¤w¸g§¹¾ã¥[±K¡C | ||||
5. |
¨Ï¥Î GetProtectionStatus ½T©w¤w¶}±Ò BitLocker «OÅ@¡C | ||||
6. |
[¨Ï¥Î Decrypt ±NºÏºÐ°Ï¸Ñ±K¡A¨ÃÃö³¬ BitLocker «OÅ@]¡C |
4.2.3 ¥ø·~³¡¸p
BitLocker ¤ä´©¥H«ü¥O½X°õ¦æ¡A¦Ó¥B»´©ö´N¯à»P Active Directory ©M¸s²Õì«h§Þ³N¾ã¦X¡C¦b¥ø·~³¡¸p¤¤¡AIT ¨t²ÎºÞ²zû»Ý¿í´`¤U¦C¨BÆJ¡G
1. |
³v¨B¶i¦æ¤U¦C¨BÆJ¡A·Ç³Æ Active Directory ¨Ñ BitLocker (TPM ©M×´_) ª÷Æ_¨Ï¥Î¡G
| ||||||||||||
2. |
³]©w»P BitLocker ¬ÛÃöªº¸s²Õì«h¡C
| ||||||||||||
3. |
¦b¥Î¤áºÝ¹q¸£¤W¦w¸Ë Windows Vista¡C | ||||||||||||
4. |
BitLocker ¦w¸Ëµ{¦¡¡G
| ||||||||||||
5. |
¨Ï¥Î¨t²ÎºÞ²z¤u¨ã¡AÀˬd½]®Ö°O¿ýÀÉ¡A¥H¶¶§Q¥[±K¡C |
¨Ï¥Î¶È TPM ÅçÃÒ¥B¤w±Ò¥Î BitLocker ªº¨t²Î¥i¥H¹³¨ä¥L¥ô¦ó¨t²Î¤@¼Ë¨Ï¥Î¡C¨Ï¥ÎªÌ±Ò°Ê Windows¡A¨Ã¥B±µ¨ì´£¥Ü¡An¨D¿é¤J¨äºô°ì¨Ï¥ÎªÌ¦WºÙ©M±K½X¡A³o¬O¤@¯ëªºµn¤J¸gÅç¡C°£«D±µ¨ì¦³Ãö¸Ó¥\¯àªº³qª¾¡A§_«h¥L̤£·|¹îı¨ì¹q¸£¤W¥t¥~¥[¤F¤@¼h«OÅ@¡C
¦b³]©w¬°¼W±j¦¡¦w¥þ©Ê®×¨Òªº¨t²Î¤W¡A¥i¯à·|n¨D¨Ï¥ÎªÌ¿é¤J PIN¡A©Î´¡¤J USB §Ö°{ºÏºÐ¡A¥H«K±Ò°Ê Windows Vista (¦p»Ý¸Ô²Ó¸ê°T¡A½Ð°Ñ¾\¡Õ²Ä 4.3.2 ¸`¼W±j¦¡«OÅ@¨Ï¥Î®×¨Ò¡Ö)¡C¦b¦¹±¡ªp¤U¡A·|ק勵±`¶}¾÷©Î«ì´_¬yµ{¡A¥H«Kµo¥X´£¥Ü¨ú±oÃB¥~ªº¦w¥þ©Ê»Ý¨D¡C
4.3.1 BitLocker Drive Encryption °ò¥»®×¨Ò
³o¬O¤Wz»¡©úªº°ò¥»®×¨Ò¡C¥¦ªºÀuÂI¬O¥¦¬O³Ìª½±µ¤F·íªº¨Ï¥Î¼Ò¦¡¡C¹q¸£¥]§t¬Û®eªº TPM (1.2 ª©¡A¨ã³Æ BIOS ¤ä´©)¡A¦Ó¥B¦³¨âӺϺаϡG(1) ¨t²ÎºÏºÐ°Ï©M (2) §@·~¨t²ÎºÏºÐ°Ï¡Aªþ¤ä´© BitLocker Drive Encryption ªº Windows ª©¥»¡C
BitLocker Drive Encryption ªº¥Dn¥\¯à (¦p [¹Ï 5] ©Ò¥Ü) ¬O«OÅ@µwºÐ§@·~¨t²ÎºÏºÐ°Ï¤Wªº¨Ï¥ÎªÌ¸ê®Æ¡CYn¹F¦¨¦¹¥Ø¼Ð¡AºÏºÐ°Ï¥²¶·¥H§¹¾ãºÏºÐ°Ï¥[±Kª÷Æ_ (Full Volume Encryption Key¡AFVEK) ¶i¦æ¥[±K¡A³o¥Ã»·³£¬O¥HºÏºÐ°Ï¥Dnª÷Æ_ (Volume Master Key¡AVMK) ¶i¦æ¥[±K¡A¦¹ª÷Æ_¤SÂà¥Ñ TPM ¶i¦æ¥[±K¡C
³oºØ®×¨Ò¥i¥H¥Ñ¥»¾÷¨t²ÎºÞ²zû¨Ï¥Î [Windows Vista ±±¨î¥x¦w¥þ©Ê] µe±¥[¥H±Ò¥Î©Î°±¥Î¡CÃö³¬ BitLocker ·|±NºÏºÐ°Ï¸Ñ±K¡A¨Ã²¾°£©Ò¦³ª÷Æ_¡C·sªºª÷Æ_±N¦bµy«á«·s¶}±Ò BitLocker «á«Ø¥ß¡C
·í¥»¾÷¨t²ÎºÞ²zû¶}±Ò BitLocker ®É¡A±j¯P«Øij«Ø¥ß×´_±K½X©Î×´_ª÷Æ_¡C¨S¦³×´_ª÷ìC©Î×´_±K½X¡A¤w¥[±KºÏºÐ¾÷¤Wªº©Ò¦³¸ê®Æ¥i¯à³£µLªk¦s¨ú¡A¦Ó¥B¤@¥¹¥X¤F®t¿ù¡A¤]µLªk×´_¡I |
4.3.2 ¼W±j¦¡«OÅ@¨Ï¥Î®×¨Ò
¹q¸£¾Ö¦³ªÌ·Qn¹ï¨t²Î¤Wªº¸ê®Æ¨Ï¥ÎÂù««OÅ@¡C
¦p [¹Ï 6] ©Ò¥Ü¡ABitLocker ´£¨Ñ¨âºØ¦h«Y¼Æ«OÅ@¿ï¶µ¡GTPM ´£¨Ñ»P¤U¦C¤GªÌ¨Ã¦sªº¨t²Î§¹¾ã©Ê¦]¯À¡G(1) PIN (¨Ï¥ÎªÌª¾¹Dªº)¡A©Î (2) Àx¦s¦b USB §Ö°{ºÏºÐ¤WªºÃB¥~ª÷Æ_ (¨Ï¥ÎªÌ¾Ö¦³ªº)¡C¨Ï¥ÎÀx¦s¦b USB §Ö°{ºÏºÐ¤Wªºª÷Æ_¡A¦³¤@¶µ³Ì«nªºÀuÂI¡A´N¬O¦b³oÃþ®×¨Ò¤¤¡A¨Ã«D©Ò¦³ª÷Æ_¸ê®Æ³£¦b¥»¾÷¹q¸£¤W¡C
4.3.2.1 PIN ÅçÃÒ
PIN ÅçÃҮרÒ9ªºÀuÂI¬O¡G´£¨ÑÂù«Y¼ÆÅçÃÒ¡A¯ÊÂI¬O¡G¨C¦¸¶}¾÷³£»Ýn PIN¡C¦b¦¹ÅçÃҮרҤ¤¡A¨t²ÎºÞ²zû·|¦b¶}±Ò BitLocker ®É³]©w PIN¡CBitLocker ¨Ï¥Î SHA-256 Âø´ê³B²z¨Ï¥ÎªÌ«ü©wªº PIN¡A¦ÓÂø´êªº«e 160 Ӧ줸³£¥Î§@¬°¶Ç°eµ¹ TPM ¥H±K«Ê VMK ªº±ÂÅv¸ê®Æ¡C²{¦b VMK ¬O¦P®É¥H TPM ©M PIN ¥[¥H«OÅ@¡CYn¶}«Ê VMK¡A¨t²Î·|n¨D¨Ï¥Î¦b¨C¦¸¹q¸£«·s¶}¾÷©Î±q¥ð¯vª¬ºA«·s±Ò°Ê®É¿é¤J PIN¡C
¨Ï¥ÎªÌ¤¶±¤ä´©
1. |
¦b [±±¨î¥x] ªº [¦w¥þ©Ê] °Ï°ì¤¤¡A¨µÄý¦Ü BitLocker ¶µ¥Ø¥H¶}±Ò BitLocker¡A¨Ã±Ò¥Î PIN ¤ä´©10¡C
| ||||||
2. |
³z¹L BitLocker ±±¨î¥x¶µ¥Ø¤¤ªº¡uºÞ²zª÷Æ_¡v³sµ²¡A«³]©ÎÅܧó PIN¡C |
«ü¥O½X¤ä´©
a) Yn±Ò¥Î PIN ÅçÃÒ
1. |
¨Ï¥Î ProtectKeyWithTPMAndPIN «OÅ@ TPM ºÏºÐ°Ï¥[±Kª÷Æ_ªº¦w¥þ¡A¨Ã¥H PIN ÅçÃÒ¥[±j¨ä¦w¥þ©Ê¡C
| ||||
2. |
«Ø¥ß×´_ blob¡G
| ||||
3. |
¨Ï¥Î Encrypt ¥[±KºÏºÐ°Ï¡C | ||||
4. |
¨Ï¥Î GetConversionStatus «ü¥ÜºÏºÐ¾÷¤w¸g§¹¾ã¥[±K¡C | ||||
5. |
¨Ï¥Î GetProtectionStatus ½T©w¤w¶}±Ò BitLocker «OÅ@¡C |
b) Yn°±¥Î PIN ÅçÃÒ
1. |
¨Ï¥Î ¨Ï¥Î Decrypt ±NºÏºÐ°Ï¸Ñ±K¡A¨ÃÃö³¬ BitLocker «OÅ@¡C |
2. |
¨Ï¥Î DeleteKeyProtector ²¾°£ TPM ¥[ PIN ÅçÃÒ blob¡C |
3. |
[¦A¦¸¨Ï¥Î ProtectKeyWithTPMAndPIN «·s«Ø¥ß TPM ¥[ PIN blob (¥i¯à¨Ï¥Î¤£¦Pªº PIN)]¡C |
¤@¯ë¨Ó»¡¡A¦b¦Ò¼{¨ì«·s¶}¾÷³t«×¡A©Î¦]¤H¬°¤z¹w¦ÓµLªk«·s¶}¾÷ªº¦øªA¾¹¤W±Ò¥Î PIN ¥\¯à¨Ã¤£¬O³Ì¨Î¹ê§@¤èªk¡C¦³¤@ºØ¥i¦æªº³¡¸p®×¨Ò¬O¡G¦bû¤u¨C¦¸¶}©l¤W¯Z³£¥²¶·¶}±Ò¦øªA¾¹ªº¤À¤½¥q¤¤¡A¶}±Ò BitLocker ©M PIN ¥\¯à¡C¦b¦¹®×¨Ò¤¤¡At³dªº¤H·|ª¾¹D¨Ã¦b¶}¾÷®É¿é¤J PIN¡C
4.3.2.2 ±Ò°Êª÷Æ_ÅçÃÒ
Âù«Y¼Æª÷Æ_«OÅ@®×¨Ò´£¨Ñ¨âÓÅçÃÒ«Y¼Æ¡C¦¹®×¨Ò¥i¥[¥H±Ò¥Î©Î°±¥Î¡A±q [Windows Vista ±±¨î¥x¦w¥þ©Ê] µe±¶}©l¡AµM«á¨Ï¥ÎÀH«áªº [«Ø¥ß±Ò°Êª÷Æ_ (Create Startup Key)] ¤u§@µe± (½Ð°Ñ¾\¡Õ²Ä 4.2.2 ¸`¡Ö¤¤ªºµe± 2b)¡C¦b¦¹®×¨Ò¤¤¡A±Ò°Êª÷Æ_¬OÀx¦s¦b¥ô¦ó BIOS ¦CÁ|ªºÀx¦s¸Ë¸m¤W (¨Ò¦p¡A¥~±¾¦¡ USB §Ö°{ºÏºÐ)¡A¦Ó¥B¨Ï¥ÎªÌ¥²¶·¦b¨C¦¸¹q¸£¶}¾÷®É¡A±N¸Ó¸Ë¸m´¡¤J¹q¸£11¡CÁöµM¦s©ñ±Ò°Êª÷Æ_ªº USB §Ö°{ºÏºÐ¥²¶·¦b¶}±Ò¹q·½¤@ª½¨ì¶}¾÷®É´¡¤J¹q¸£¤¤¡A¦ý¤]À³¸Ó¦b Windows µn¤J§¹¦¨«á²¾°£¡C
¨Ï¥ÎªÌ¤¶±¤ä´©
1. |
¦b [±±¨î¥x] ªº [¦w¥þ©Ê] °Ï°ì¤¤¨µÄý¦Ü BitLocker ¶µ¥Ø¡A¥H¶}±Ò BitLocker ¨Ã±Ò¥Î±Ò°Êª÷Æ_¤ä´©¡C
| ||||||||
2. |
³z¹L BitLocker ±±¨î¥x¶µ¥Ø¤¤ªº [ºÞ²zª÷Æ_ (Manage Keys)] ³sµ²¡A½Æ»s±Ò°Êª÷Æ_¡C |
«ü¥O½X¤ä´©
a) Yn±Ò¥Î±Ò°Êª÷Æ_ÅçÃÒ
1. |
¨Ï¥Î ProtectKeyWithTPMAndStartupKey «OÅ@ TPM ºÏºÐ°Ï¥[±Kª÷Æ_ªº¦w¥þ¡A¨Ã¥H±Ò°Êª÷Æ_ÅçÃÒ¥[±j¨ä¦w¥þ©Ê¡C
| ||||
2. |
«Ø¥ß×´_ blob¡C
| ||||
3. |
¨Ï¥Î Encrypt ¥[±KºÏºÐ°Ï¡C | ||||
4. |
¨Ï¥Î GetConversionStatus «ü¥ÜºÏºÐ¾÷¤w¸g§¹¾ã¥[±K¡C | ||||
5. |
¨Ï¥Î GetProtectionStatus ½T©w¤w¶}±Ò BitLocker «OÅ@¡C |
a) Yn°±¥Î±Ò°Êª÷Æ_ÅçÃÒ
1. |
¨Ï¥Î Decrypt ±NºÏºÐ°Ï¸Ñ±K¡A¨ÃÃö³¬ BitLocker «OÅ@¡C |
2. |
¨Ï¥Î DeleteKeyProtector ²¾°£ TPM ©M±Ò°Êª÷Æ_ÅçÃÒ blob¡C |
3. |
[¦A¦¸¨Ï¥Î ProtectKeyWithTPMAndStartupKey «·s«Ø¥ß TPM ©M±Ò°Êª÷Æ_ blob (¥i¯à¨Ï¥Î¤£¦Pªº±Ò°Êª÷Æ_)]¡C |
4.3.3 ¶È±Ò°Êª÷Æ_¨Ï¥Î®×¨Ò
¹q¸£¾Ö¦³ªÌ¥i¯àn«OÅ@¤£¥]§t v1.2 TPM ¤§¹q¸£¤Wªº¸ê®Æ¡C¦b³oºØ®×¨Ò¤¤¡A¹q¸£¾Ö¦³ªÌÄ@·N¦b¨C¦¸¹q¸£±Ò°Ê©Î¥ð¯v«á«ì´_®É¡An¨D¹q¸£¨Ï¥ÎªÌ¡A´¡¤J¥]§t±Ò°Êª÷Æ_ªº USB §Ö°{ºÏºÐ¡C½Ðª`·N¡A¨Ï¥Î¶È±Ò°Êª÷Æ_®×¨Òªº¨t²Î¦w¥þ©Ê³]©wÀɱN»P¨Ï¥Î TPM ªº¨t²Î«OÅ@¤£¦P¡A¦]¬°¦b«D TPM ¨t²Î¤W¤£·|ÅçÃÒ¦´Á¶}¾÷¤¸¥óªº§¹¾ã©Ê¡C
³oºØ®×¨Ò·|³z¹L Windows ¤¤ BitLocker ±±¨î¥x¶µ¥Ø¶}±Ò©ÎÃö³¬¡C¥»¾÷¨t²ÎºÞ²zû¥²¶·¦b¶}±Ò BitLocker—ü ®É¡A¨Ï¥ÎºëÆF¨Ó«Ø¥ß±Ò°Êª÷Æ_¡C³oºØ®×¨Ò¤]¥i¥H³z¹L«ü¥O½X¥[¥H±Ò¥Î¡CÃö³¬³oºØ®×¨Ò·|±j¢ºÏºÐ°Ï¸Ñ±K¡A¨Ã²¾°£©Ò¦³ª÷Æ_¡F¦pªG±N¨Ó«·s±Ò¥Î³oºØ®×¨Ò¡A´N¥²¶·«·s«Ø¥ßª÷Æ_¡C
¨t²Î²£¥Í±Ò°Êª÷Æ_¥H«á¡A¨Ï¥ÎªÌ´¡¤J USB §Ö°{ºÏºÐ¡AµM«á¨t²Î±N±Ò°Êª÷Æ_Àx¦s¦b¸Ó¸Ë¸m¤W¡C¹q¸£µwºÐ¥²¶·¦³¨t²ÎºÏºÐ°Ï©M§@·~¨t²ÎºÏºÐ°Ï (¦p»Ý¦³Ãö¸Ó»Ý¨Dªº¸Ô²Ó¸ê°T¡A½Ð°Ñ¾\¡Õ²Ä 2.1 ¸`¨t²ÎµwÅé¡B¶´Åé©M³nÅé»Ý¨D¡Ö)¡C²{¦b¡A¨C¦¸±q¨ü BitLocker «OÅ@ªººÏºÐ°Ï¤¤±Ò°Ê¹q¸£®É¡A¹q¸£¤¤´N¥²¶·¦³¸Ó¸Ë¸m¡C¨Ï¥ÎªÌ´¡¤J USB §Ö°{ºÏºÐ¡A¨Ã¶}±Ò¹q¸£¡C¹q¸£¶}¾÷¡A±Ò°Ê§@·~¨t²Î¡AµM«á¨Ï¥ÎªÌ´N¥i¥H¶}©l¥¿±`¨Ï¥Î¨t²Î¡C
¨Ï¥ÎªÌ¥i¥H¨Ï¥Î BitLocker ±±¨î¥x¶µ¥Ø¡A«Ø¥ß±Ò°Êª÷Æ_³Æ¥÷½Æ¥»¡C¦b¿ò¥¢¥~³¡¸Ë¸mªº±¡ªp¤U¡AºÏºÐ°Ï¥²¶·¨Ï¥Î×´_ª÷Æ_©Î×´_±K½X¶i¦æ×´_¡AµM«á¥²¶·¦A²£¥Í·sªº±Ò°Êª÷Æ_¡C¨ä¥L¤]¨Ï¥Î±Ò°Êª÷Æ_ªº©Ò¦³ºÏºÐ°Ï³£¥²¶·¸g¹LÃþ¦üªºµ{§Ç¡A¥H½T«O¥¼±ÂÅvªº¨Ï¥ÎªÌ¤£·|¨Ï¥Î¿ò¥¢ªº±Ò°Êª÷Æ_¡C
¨Ï¥ÎªÌ¤¶±¤ä´©
1. |
¦b [±±¨î¥x] ªº [¦w¥þ©Ê] °Ï°ì¤¤¨µÄý¦Ü BitLocker ¶µ¥Ø¡A¥H¶}±Ò BitLocker ¨Ã±Ò¥Î±Ò°Êª÷Æ_¤ä´©¡C
| ||||
2. |
«Ø¥ß¨ÃÀx¦s±Ò°Êª÷Æ_¡A§@¬° BitLocker ³]©wºëÆFªº¤@³¡¤À¡C
| ||||
3. |
Àx¦s¤w«Ø¥ßªº±Ò°Êª÷Æ_§@¬°ª÷Æ_ºÞ²zºëÆFªº¤@³¡¤À¡C | ||||
4. |
¿é¤J±Ò°Êª÷Æ_§@¬°¶}¾÷µ{§Çªº¤@³¡¤À¡C |
«ü¥O½X¤ä´©
a) Yn±Ò¥Î¶È±Ò°Êª÷Æ_ÅçÃÒ
1. |
¨Ï¥Î ProtectKeyWithExternalKey «Ø¥ß±Ò°Êª÷Æ_¡A¥Î§@¬°µL¬Û®e TPM ªº¹q¸£ªº±Ò°Êª÷Æ_¡C
| ||||
2. |
¨Ï¥Î SaveExternalKeyToFile ±N¥]§t±Ò°Êª÷Æ_ªºÀÉ®×¼g¤J USB §Ö°{ºÏºÐ©Î¨ä¥L¦ì¸m¡C | ||||
3. |
¨Ï¥Î«Ø¥ß×´_ blob¡C
| ||||
4. |
¨Ï¥Î Encrypt ¥[±KºÏºÐ°Ï¡C | ||||
5. |
¨Ï¥Î GetConversionStatus «ü¥ÜºÏºÐ¾÷¤w¸g§¹¾ã¥[±K¡C | ||||
6. |
¨Ï¥Î GetProtectionStatus ½T©w¤w¶}±Ò BitLocker «OÅ@¡C | ||||
7. |
¨Ï¥Î UnlockWithExternalKey ¸Ñ°£Âê©w¦³±Ò°Êª÷Æ_ªººÏºÐ°Ï¡C |
a) Yn°±¥Î¶È±Ò°Êª÷Æ_ÅçÃÒ
1. |
¨Ï¥Î Decrypt ±NºÏºÐ°Ï¸Ñ±K¡A¨ÃÃö³¬ BitLocker «OÅ@¡C |
2. |
¨Ï¥Î GetKeyProtectors ¦C¥X¤w¬°ºÏºÐ°Ï«Ø¥ßªº±Ò°Êª÷Æ_¡C |
3. |
¨Ï¥Î DeleteKeyProtector ²¾°£»P¤w«Ø¥ß±Ò°Êª÷Æ_¬ÛÃöÁpªº±Ò°Êª÷Æ_ÅçÃÒ blob¡C |
4. |
[¦A¦¸¨Ï¥Î ProtectKeyWithExternalKey ¥H«Ø¥ß·sªº±Ò°Êª÷Æ_]¡C |
4.3.4 ¨t²ÎºÞ²z
¥»¾÷¨t²ÎºÞ²zû±±¨îµÛ BitLocker Drive Encryption ªº¦UÓ¼h±¡C¨t²ÎºÞ²zû¥i¥Hª½±µ¦b Windows ¸ê°T¦w¥þ¤¤¤ß±Ò¥Î©Î°±¥Î³o¶µ¥\¯à¡C
4.3.4.1 ª÷Æ_ºÞ²z¨Ï¥ÎªÌ¸gÅç
ºÏºÐ°Ï¤@¥¹¸g¹L¥[±K¨Ã¥H BitLocker ¶i¦æ«OÅ@¤§«á¡AºÞ²zª÷Æ_¨Ï¥ÎªÌ¤¶±´N·|¤¹³\¥»¾÷©Mºô°ì¨t²ÎºÞ²zû½Æ»sª÷Æ_¤Î«³] PIN¡C¤¶±¤¤¶ÈÅã¥Ü¦b BitLocker ³]©w®É©Ò«Ø¥ßª÷Æ_ªº³sµ²¡C
ºÞ²zª÷Æ_ªº¬yµ{¤¹³\¨t²ÎºÞ²zû¦s¨ú¤U¦Cª÷Æ_ºÞ²z¿ï¶µ¡G
• |
½Æ»s×´_±K½X
| ||||||
• |
½Æ»s±Ò°Êª÷Æ_
| ||||||
• |
«³] PIN¡C |
4.3.4.2 ³]©w»PºÞ²z
Windows ¸ê°T¦w¥þ¤¤¤ß´£¨Ñ BitLocker ¥\¯àª¬ºA¥H¤Î±Ò¥Î©Î°±¥Î BitLocker ªº¯à¤O¡A¥t¥~¤]´£¨Ñ³]©w¥\¯à¡A¦p¡Õ²Ä 4.2 ¸`¡Ö¤¤©Ò¥Ü¡C¦pªG¥Ñ©ó³Ìªñªº¦w¸Ë©Î¸Ñ°£¦w¸Ën¨D¡A¦ÓP BitLocker ¥D°Ê¥[±K©Î¸Ñ±K¸ê®Æ¡A´N·|Åã¥Ü¶i«×ª¬ºA¡C
¨t²ÎºÞ²zû¤]¥i¥H±q¸ê°T¦w¥þ¤¤¤ß¦s¨ú TPM ºÞ²z¥D±±¥x¡A¥HºÞ²z TPM¡C
IT ¨t²ÎºÞ²zû¥i¨Ï¥Î©R¥O¦CºÞ²z¤u¨ã (manage-bde.wsf)¡A±q»·ºÝ°õ¦æ«ü¥O½X¥\¯à¡C
4.3.4.3 ¹q¸£¤É¯Å¡G°±¥Î«OÅ@¨Ï¥Î®×¨Ò
¦b¬Y¨Ç±¡ªp¤U¡A¨t²ÎºÞ²zû¥i¯à·|»Ýn¼È®É°±¥Î BitLocker¡A¨Ò¦p¡G
1. |
¦b¤£n¨D¨Ï¥ÎªÌ¿é¤J (¨Ò¦p PIN ©Î±Ò°Êª÷Æ_) ¤§¤U¡A±N¹q¸£«·s¶}¾÷¥H¶i¦æºûÅ@¡C | ||||||
2. |
¦b¤£Ä²µo BitLocker ×´_¤§¤U¡A¶i¦æ«nªº¦´Á¶}¾÷¤¸¥ó¤É¯Å¡C
| ||||||
3. |
¦b¤£Ä²µo BitLocker ×´_¤U¡A¶i¦æ¥D¾÷ªO¤É¯Å©Î§ó´«©Î²¾°£ TPM¡C | ||||||
4. |
¦b¤£Ä²µo BitLocker ×´_¤U¡AÃö³¬/°±¥Î¡A©Î²M°£ TPM¡C | ||||||
5. |
¦b¤£Ä²µo BitLocker ×´_¤U¡A±N¨ü BitLocker «OÅ@ªººÏºÐ°Ï²¾¦Ü¥t¤@³¡¹q¸£¡C | ||||||
6. |
¿ò¥¢©Ò¦³×´_ blob ¦Ó¥²¶·¦bIJµo BitLocker ×´_¤§«e¡A¦w¥þ¦a«Ø¥ß·sªº×´_ blob¡C |
§Ú̱N³o¨Ç®×¨Ò²ÎºÙ¬°¡u¹q¸£¤É¯Å®×¨Ò¡v¡C³oºØ®×¨Ò¥i¥H³z¹L Windows ¤¤ªº BitLocker ±±¨î¥x±Ò¥Î/°±¥Î¡C¤w±Ò¥Î BitLocker ªº¹q¸£¤É¯Å¥u»Ý¤Ö¼Æ´XÓ¨BÆJ¡G
1. |
³z¹L¶i¤J°±¥Î¼Ò¦¡¡A¼È®ÉÃö³¬ BitLocker¡C | ||
2. |
±N¨t²Î¤É¯Å¡C
| ||
3. |
¶}±Ò BitLocker - ¤£»Ýn¥[±K§@·~¡A¦p¤U©Òz¡C |
±j¢ BitLocker ¶i¤J°±¥Î¼Ò¦¡·|ÅýºÏºÐ°Ï«O«ù¬°¥[±K¡A¦ýºÏºÐ°Ï¥Dnª÷Æ_±N¥i¦Û¥Ñ¥Î©óºÏºÐ¤W¡A¨Ï¥ÎÀx¦s¦bµwºÐ¤Wªº¹ïºÙ¦¡¯Âª÷Æ_¶i¦æ¥[±K¡C¯à°÷¨Ï¥Î¯Âª÷Æ_ªí¥Ü·|Ãö³¬¥Ñ BitLocker ©Ò´£¨Ñªº¸ê®Æ«OÅ@¡A¦ý¥i½T«O¦b¥ô¦ó±ø¥ó¤U¡A©Ò¦³«áÄò¹q¸£¶}¾÷³£¯à¦¨¥\¡A¦Ó¤ð»Ý¦A¥Ñ¨Ï¥ÎªÌ¶i¦æ¿é¤J¡C«·s±Ò¥Î BitLocker ®É¡A¯Âª÷Æ_´N·|±qºÏºÐ°Ï¤¤²¾°£¡ABitLocker «OÅ@¤]·|¦A«×¶}±Ò¡C¦¹¥~¡AVMK ¤]·|«·s«Ø¥ßª÷Æ_¨Ã«·s¶i¦æ¥[±K¡C
±N¨ü«OÅ@ªººÏºÐ°Ï (¹êÅéºÏºÐ) ²¾¦Ü¥t¤@³¡¤w±Ò¥Î TPM ªº¹q¸£¨Ã¤£»Ýn¥ô¦ó¨ä¥L¨BÆJ¡A¦]¬°«OÅ@ºÏºÐ°Ï¥Dnª÷Æ_ªºª÷Æ_¬OÀx¦s¦b¥»¾÷ºÏºÐ¤W¡A§¹¥þµL¸·¡C
¤½¶}ºÏºÐ°Ï¥Dnª÷Æ_¡A§Y¨Ï¥u¬O«Üµu¼Èªº´Á¶¡¡A¤]·|²£¥Í¦w¥þ©Ê·ÀI¡A¦]¬°¦b¯Âª÷Æ_¤½¶}³o¨Çª÷Æ_®É¡A§ðÀ»ªÌ¥i¯à·|¨ú±oºÏºÐ°Ï¥Dnª÷Æ_©M FVEK¡C
¤µ¤é¡A¦³³\¦hÓ¤H¹q¸£³£¬O¥Ñ²Ä¤@Ó¾Ö¦³ªÌ©Î¨Ï¥ÎªÌ¥H¥~ªº¤H«½Æ¨Ï¥Î¡C¦b¥ø·~Àô¹Ò¤U¡A¹q¸£¥i¥H«·s³¡¸p¦Ü¨ä¥L³¡ªù¡A¤]¥i¯à¬O¦b¼Ð·Ç¹q¸£µwÅé§ó·s¶g´Áµ{§Ç¤U¥á¥X¤½¥q¡C
IT ³¡ªù¥i¯à·|°õ¦æ¤@¶µ©Î¦h¶µ¦w¥þ©Ê³Wµ{¡A¦b¾÷¾¹²¾¥X©Î¥á¥X¤½¥q¤§«e«OÅ@©Î§R°£¾÷¾¹¤Wªº¸ê®Æ¡CBitLocker ¥i¥H¦b¾÷¾¹«·s³¡¸p¥H«e¡A¤j´T´£¤É¨ä¦w¥þ©Ê¡C
IT ¤Hû¥i¥H¿ï¾ÜÃö³¬ BitLocker¡AÅý¹q¸£ (¤]³\¥]¬A¨ä¤¤¤@¨Ç¸ê®Æ) ¤´µM¥i§@¨ä¥L¥Î³~¡A¤]¥i¥H°õ¦æ¡u¦w¥þ¸Ñ°£©e¥ô¡v¸`¬Ù®É¶¡¡A¦ÓÅý¸ê®Æ¥Ã»·³B©ó¥[±Kª¬ºA¡Aµ´¹ïµLªk¥[¥HÂ^¨ú¡C
4.4.1 Ãö³¬ BitLocker Drive Encryption
¥»¾÷¨t²ÎºÞ²zû¥i¥H¦b Windows ¸ê°T¦w¥þ¤¤¤ß¤§¤ºÃö³¬³o¶µ¥\¯à¡CBitLocker ´£¨Ñ¨âºØ¸Ñ°£¦w¸Ë¼Ò¦¡¡G
• |
BitLocker °±¥Î - «O¯d¥[±K¡C³oӿﶵÅý¸ê®Æ¦bµwºÐ¤W«O«ù¬°¥[±Kª¬ºA¡A¦ý²¾°£ TPM µwÅé¨Ì¿à (¶i¤J°±¥Î¼Ò¦¡§Y¥i²¾°£¡A½Ð°Ñ¾\¡Õ²Ä 4.3.4.3 ¤p¸`¡Ö)¡C |
• |
BitLocker Ãö³¬ - ²¾°£¥[±K¡C³oӿﶵ·|±N Windows ¤À³Îªº«OÅ@¥þ³¡²¾°£¡A¨Ã±N¸ê®Æ¸Ñ±K (³z¹LÃö³¬ BitLocker ªº¤è¦¡)¡C |
¨Ï¥ÎªÌ¤¶±¤ä´©
1. |
¦b [±±¨î¥x] ªº [¦w¥þ©Ê] °Ï°ì¤¤¨µÄý¦Ü BitLocker ¶µ¥Ø¡A¥H¶}±Ò BitLocker ¨Ã±Ò¥Î±Ò°Êª÷Æ_¤ä´©¡C |
2. |
«ö¤@¤U [Ãö³¬ BitLocker—ü (Turn Off BitLocker—ü)]¡A¥HÃö³¬ BitLocker—ü¡C |
«ü¥O½X¤ä´©
1. |
¨Ï¥Î Decrypt ±NºÏºÐ°Ï¸Ñ±K¡A¨ÃÃö³¬ BitLocker «OÅ@¡C |
Ãö³¬ BitLocker ¤§«á¡A¥i¥H¦bµwÅé«·s®æ¦¡¤Æ¥H«e¡A²¾Âà³\¦h¦³¥Îªº¸ê®Æ¡C
4.4.2 ¦w¥þ¸Ñ°£©e¥ô
¦w¥þ¸Ñ°£©e¥ô«üªº¬O§R°£¯S©wºÏºÐ°Ï¤Wªºª÷Æ_ blob¡C¨S¦³ª÷Æ_ blob¡A¸ê®Æ´NµLªk¸Ñ±K12¡C
³o¶µµ{§Ç¤¤¥]§t¨âÓ¨BÆJ¡G
1. |
²¾°£ºÏºÐ°Ï¤W©Ò¦³«D×´_ª÷Æ_ blob¡C³o¼Ë¥i¥H±j¢¨Ï¥ÎªÌ¦b¤U¦¸¶}¾÷®É¡A³v¨B°õ¦æ×´_µ{§Ç¡A¨Ã´£¨Ñ×´_ª÷Æ_©Î×´_±K½X¡C³oºØ§@ªk³Qµø¬°¥i«ì´_ªº¦w¥þ¸Ñ°£©e¥ô¡C¦¹ªk¥i¥H¥Î¨ÓÂê©wn¶i¦æ·h¹Bªº¾÷¾¹¡C |
2. |
²¾°£©Ò¦³¥i¥Îªºª÷Æ_ blob¡A¥]¬AÀx¦s¦b AD ¤¤ªº×´_¸ê®Æ¡C¸ê®Æ±N¥Ã»·¥[±K¡AºÏºÐ°Ï¥i¥H«·s®æ¦¡¤Æ¡A¦Ó¤£·|¦M¤Î¦b¨ü BitLocker «OÅ@¤§ºÏºÐ°Ï¤¤ªº¸ê®Æ¡C³o¬O¥Ã¤[©Êªº¦w¥þ¸Ñ°£©e¥ô¡C¥u¦³¦b¥Ã»·³£¤£¦A·Qn©Î¤£¦A»Ýn³o¨Ç¸ê®Æ®É¡A¤~±Ä¥Î³oºØ§@ªk¡CºÏºÐ¾÷±NµLªk×´_¡C |
¦w¥þ¸Ñ°£©e¥ô¥i¥H³z¹L°õ¦æºÞ²z¶¥¼h«ü¥O½X¨Ó¹F¦¨¡A«ü¥O½X·|²¾°£ºÏºÐ¤Wªº©Ò¦³ª÷Æ_ (v1 ¤¤¨S¦³¨Ï¥ÎªÌ¤¶±¤ä´©¥i¥Î)¡C
«ü¥O½X¤ä´©
1. |
¨Ï¥Î GetKeyProtectors ¨ú±o©Ò¦³¡uTPM¡v¡B¡uTPM ¥[ PIN¡v©M¡uTPM ¥[±Ò°Êª÷Æ_¡vÃþ«¬ªºª÷Æ_«OÅ@¸Ë¸m¤§ÃѧO½X [Yn¶i¦æ¥Ã¤[©Ê¦w¥þ¸Ñ°£©e¥ô¡A½Ð¨ú±o©Ò¦³ª÷Æ_«OÅ@¸Ë¸mÃѧO½X¡A¥]¬A×´_ÃѧO½X]¡C |
2. |
[¶i¦æ¥Ã¤[©Ê¦w¥þ¸Ñ°£©e¥ô] «Ø¥ß¤£ã¨Ï¥Îªº×´_±K½X blob 13(±Ë±ó¹ê»Úªº×´_±K½X)¡A¨Ï¥Î ProtectKeyWithNumericalPassword ¤ÎÀH¾÷²£¥Íªº±K½X§Ç¦C¨Ó«Ø¥ß¡C |
3. |
¨Ï¥Î DeleteKeyProtector ²¾°£©Ò¦³»P¤Wzµ{§Ç©Ò§ä¨ì¤§ÃѧO½X¬ÛÃöÁpªº¥i¨Ï¥Îª÷Æ_«OÅ@¸Ë¸m¡C |
4. |
[¶i¦æ¥Ã¤[©Ê¦w¥þ¸Ñ°£©e¥ô] ¦b TPM ¾÷¾¹¤W¡A¨Ï¥Î TPM WMI ´£¨ÑªÌ¨ç¼Æ Win32_TPM.Clear ²M°£ TPM¡C |
³o¬O¨³³t¦Ó¦³®Äªº¤è¦¡¡AÅýºÏºÐ°Ï¤Wªº¸ê®ÆµLªk¨ú¥Î¡C
¦bµo¥Íª¬ªpªº±¡§Î¤U (¦pªGºÏºÐ°Ïªºª÷Æ_µLªk¥Ñ BitLocker ¦Û°Ê¨ú±o)¡A¥[±KºÏºÐ°Ï¤Wªº¸ê®Æ¥i³z¹L¥u»Ý³Ì§C³]©wªº¦³®Äµ{§Ç¥[¥H×´_¡C¦³´XºØ±¡ªp¥i¯à·|IJµo×´_¡G
1. |
±N¨ü BitLocker «OÅ@ªººÏºÐ¾÷²¾¤J·s¹q¸£¤¤¡C |
2. |
¥D¾÷ªO¤É¯Å¬°·s«~ (§t·sªº TPM)¡C |
3. |
Ãö³¬/°±¥Î¡A©Î²M°£ TPM¡C |
4. |
«nªº¦´Á¶}¾÷¤¸¥ó¤É¯Å¡A¨Ï±o TPM µLªk³q¹LÅçÃÒ¡C |
5. |
¦b¤w±Ò¥Î PIN ÅçÃҮɿò§Ñ PIN¡C |
6. |
¦b¤w±Ò¥Î±Ò°Êª÷Æ_ÅçÃҮɡA¿ò¥¢¨ä¤¤¥]§t±Ò°Êª÷Æ_ªº¥~±¾¦¡ USB §Ö°{ºÏºÐ¡C |
7. |
±N®à¤W«¬©Î½¥¤W«¬¹q¸£«·s³¡¸pµ¹¥ø·~¤¤¨ä¥L³¡ªù/û¤u (¨Ò¦p¡Aµ¹¨ã¦³¤£¦P¦w¥þÅv©Î¤£¦Pª¾±¡»Ýnªº¨Ï¥ÎªÌ)¡A¦b³q¹L¼f¹î¥i¨Ñ¤£¦P¦w¥þÅv¼h¯Å¨Ï¥Î¤§«e¡A»Ýn×´_¸ê®Æ¡C |
8. |
®à¤W«¬¹q¸£´N¦a«·s¤À¬£¤u§@ (¨Ò¦p¡A¥Ñ IT ¨t²ÎºÞ²zû±q»·ºÝ«·s¦w¸Ë§@·~¨t²Î) ¦Ó¨S¦³¿ò¥¢¨ü«OÅ@ªº¸ê®Æ¡C |
IT ¨t²ÎºÞ²zû¥i¥H¨Ï¥Î¸s²Õì«h¡A¿ï¾Ün¨D¡B©Úµ´¦óºØ×´_¤èªk¡A©Î¬OÅý±Ò¥Î BitLocker ªº¨Ï¥ÎªÌ¿ï¥Î¡C×´_±K½X¥i¥HÀx¦s¦b Active Directory ¤¤¡A¦Ó¨t²ÎºÞ²zû¥i¥HÅý³o¦¨¬°¥²n¡B¸T¤î©Î¥i¿ï¥Î¿ï¶µ (¤À§O¹ï¹q¸£ªº¨CӨϥΪ̶i¦æ)¡C½Ð°Ñ¾\¡Õ²Ä 4.2.3 ¸`¡Ö¡A·í¤¤¦³»¡©ú Active Directory ³]©w¨BÆJ¡C¦¹¥~¡A×´_¸ê®Æ¤]¥i¥HÀx¦s¦b¥ô¦ó¥~±¾¦¡ USB §Ö°{ºÏºÐ¡C
¦b BitLocker ¤¤¡A×´_¥]§t¤F¥HÀx¦s¦b USB §Ö°{ºÏºÐ¤Wªº×´_ª÷Æ_¡A©Î¥H±q×´_±K½X©Òl¥Í±K½X½sĶª÷Æ_¥[±Kªº¥Dnª÷Æ_ blob ½Æ¥»¸Ñ±K¡CTPM »P¥ô¦ó×´_®×¨Ò³£µLÃö¡A¦]¦¹¦pªG TPM µLªk³q¹L¶}¾÷¤¸¥óÅçÃÒ¡B¬G»Ù©Î®ø¥¢¡A³£¥i¥H¶i¦æ×´_¡C
Yn×´_ºÏºÐ°Ï¡A¨Ï¥ÎªÌ¥i¥H¨Ï¥Î¦bªì©l¤Æ®É³]©wªº¥ô¦ó×´_¾÷¨î¡C¨Ï¥ÎªÌ¥i¥H¨Ï¥Î×´_±K½X©Î×´_ª÷Æ_ (¬Û·í©ó×´_±K½Xªº¾÷¾¹¥iŪ¨ú¶µ¥Ø)¡C
5.2.1 ×´_±K½X
×´_±K½X¬O 48 ¦ì¼ÆÀH¾÷²£¥Íªº¼Æ¦r¡A¦b BitLocker ³]©w®É«Ø¥ß¡C±Ò¥Î BitLocker ¤§«á¡A¥i¥H¶i¦æºÞ²z©M½Æ»s¡C×´_±K½X¥i¥H³z¹L¤¶±¦C¦L©M/©ÎÀx¦s¦¨ÀɮסA¥H³Æ±N¨Ó¨Ï¥Î¡C
ºô°ì¨t²ÎºÞ²zû¥i¥H³]©w¸s²Õì«h¡A¦Û°Ê²£¥Í×´_±K½X¡AµM«á BitLocker ¤@±Ò°Ê¡A´N¦Û°Ê³Æ¥÷¦Ü Active Directory¡C¦Ó¥B¡Aºô°ì¨t²ÎºÞ²zûÁÙ¥i¥H¿ï¾Üªý¤î BitLocker ¬°ºÏºÐ¾÷¥[±K¡A°£«D¹q¸£¤w³s±µ¨ìºô¸ô¤W¡A¦Ó¥B¤w¦¨¥\³Æ¥÷ Active Directory ªº×´_±K½X¡C
¨Ï¥ÎªÌ¤¶±¤ä´©
1. |
¦b [±±¨î¥x] ªº [¦w¥þ©Ê] °Ï°ì¤¤¨µÄý¦Ü BitLocker—ü ¶µ¥Ø¡A¥H¶}±Ò BitLocker—ü ¨Ã±Ò¥Î×´_±K½X¡C
| ||
2. |
Àx¦s¡BÀ˵ø¡A¤Î/©Î¦C¦L×´_±K½X¡A§@¬° BitLocker—ü ³]©wºëÆFªº¤@³¡¤À14
| ||
3. |
Àx¦s¤Î/©Î¦C¦L¤w«Ø¥ßªº×´_±K½X½Æ¥»¡A§@¬°ª÷Æ_ºÞ²z¤¶±ªº¤@³¡¤À¡C | ||
4. |
¿é¤J×´_±K½X¡A§@¬° Windows ¤§«e¤å¦r¼Ò¦¡×´_¤¶±ªº¤@³¡¤À¡C |
«ü¥O½X¤ä´©
a) Yn±Ò¥Î×´_±K½X
1. |
¨Ï¥Î ProtectKeyWithNumericalPassword «Ø¥ß×´_±K½X¡C
| ||||
2. |
¨Ï¥Î GetKeyProtectorNumericalPassword Â^¨ú©Ò«Ø¥ß×´_±K½X blob ªº¼Æ¦r±K½X¤º®e¡C | ||||
3. |
¨Ï¥Î UnlockWithNumericalPassword ¸Ñ°£Âê©w¦³×´_±K½XªººÏºÐ°Ï¡C |
b) Yn°±¥Î×´_ª÷Æ_
1. |
¨Ï¥Î GetKeyProtectors ¦C¥X¤w¬°ºÏºÐ°Ï«Ø¥ßªº×´_±K½X¡C |
2. |
¨Ï¥Î DeleteKeyProtector ²¾°£»P¤w«Ø¥ß×´_±K½X¬ÛÃöÁpªº¼Æ¦r±K½XÅçÃÒ blob¡C |
5.2.2 ×´_ª÷Æ_
×´_ª÷Æ_¥i¥H¦b BitLocker ³]©w®É«Ø¥ß¨ÃÀx¦s¦Ü¥~±¾¦¡ USB §Ö°{ºÏºÐ15¡A¦Ó¥B¥¦¥i¥H¦b±Ò¥Î BitLocker ¤§«á¶i¦æºÞ²z¤Î½Æ»s¡C¹q¸£±Ò°Ê®É¡A¨Ï¥ÎªÌ³z¹L±N¥]§t×´_ª÷Æ_ªº USB §Ö°{ºÏºÐ´¡¤J¹q¸£¤¤¡A¨ú±o§@·~¨t²ÎºÏºÐ°Ïªº¦s¨úÅv¡A¦Ó¤£¥²²z·| TPM ªºª¬ºA¡C
¨Ï¥ÎªÌ¤¶±¤ä´©
1. |
¦b [±±¨î¥x] ªº [¦w¥þ©Ê] °Ï°ì¤¤¨µÄý¦Ü BitLocker—ü ¶µ¥Ø¡A¥H¶}±Ò BitLocker—ü ¨Ã±Ò¥Î×´_ª÷Æ_¡C
| ||
2. |
«Ø¥ß¤ÎÀx¦s×´_±K½X¡A§@¬° BitLocker—ü ³]©wºëÆFªº¤@³¡¤À16
| ||
3. |
»s§@¤w«Ø¥ß×´_ª÷Æ_ªº½Æ¥»¡A§@¬°ª÷Æ_ºÞ²zºëÆFªº¤@³¡¤À¡C | ||
4. |
¿é¤J×´_ª÷Æ_¡A§@¬° Windows ¤§«e¤å¦r¼Ò¦¡×´_¤¶±ªº¤@³¡¤À¡C |
«ü¥O½X¤ä´©
a) Yn±Ò¥Î×´_ª÷Æ_
1. |
¨Ï¥Î ProtectKeyWithExternalKey «Ø¥ß×´_ª÷Æ_¡C |
2. |
¨Ï¥Î SaveExternalKeyToFile ±N¥]§t×´_ª÷Æ_ªºÀÉ®×¼g¤J¥i´¡¤Jªº USB §Ö°{ºÏºÐ©Î¨ä¥L¦ì¸m¡C |
3. |
¨Ï¥Î GetKeyKeyProtector ExternalKey Â^¨ú¤w«Ø¥ß×´_ª÷Æ_ blob ªºª÷Æ_¤º®e¡C |
4. |
¨Ï¥Î UnlockWithExternalKey ¸Ñ°£Âê©w¨Ï¥Î×´_ª÷Æ_ªººÏºÐ°Ï¡C |
b) Yn°±¥Î×´_ª÷Æ_
1. |
¨Ï¥Î GetKeyProtectors ¦C¥X¤w¬°ºÏºÐ°Ï«Ø¥ßªº×´_ª÷Æ_¡C |
2. |
¨Ï¥Î DeleteKeyProtector ²¾°£»P¤w«Ø¥ß×´_ª÷Æ_¬ÛÃöÁpªºÅçÃÒ blob¡C |
BitLocker °±¥Î
¦b¡u°±¥Î¼Ò¦¡¡v¤¤¡A·|°±¥ÎºÏºÐ°Ï¤Wªº BitLocker «OÅ@¡A¨Ã¥[±KºÏºÐ°Ï¡A¦ý¥Î¨Ó¥[±K§@·~¨t²ÎºÏºÐ°Ïªº FVEK ¥i³z¹L¡u¯Âª÷Æ_¡v¦Û¥Ñ¦a¨Ï¥Î¡CÁöµM¤w¶i¦æ¤F¥[±K¡A¦ý¸ê®Æ«OÅ@¤w¦³®Ä¦a°±¥Î¡C
BitLocker ±Ò¥Î (©Î¶}±Ò)
¦bºÏºÐ°Ï¤W±Ò¥Î BitLocker «OÅ@®É¡AºÏºÐ°Ï¤Wªº¸ê®Æ·|¦b¼g¤J®É¥[±K¡A¦Ó¦bŪ¨ú®É¸Ñ±K¡C¹q¸£±Ò°Ê®É¡A»Ýn¥Ñ¡uTPM¡v(µ²¦X¡u±Ò°Êª÷Æ_¡v©Î¡uPIN¡v¡AY¦³¦¹³]©w®É) ÅçÃÒ«nªº¦´Á¶}¾÷¤¸¥ó¦¨¥\¡B¿é¤J¡u×´_±K½X¡v¡A©Î´¡¤J¥]§t¡u×´_ª÷Æ_¡vªº USB §Ö°{ºÏºÐ¡A¤~¯à¸Ñ±K VMK ¨Ã¦s¨úºÏºÐ°Ï¡C
BitLocker Ãö³¬
¦b¦¹¼Ò¦¡¤U¡AºÏºÐ°Ï¤Wªº«OÅ@¤wÃö³¬¡AºÏºÐ°Ï¥¼¥[±K¡A¦Ó BitLocker «OÅ@¨Ã¥¼µo¥Í§@¥Î¡C³o¬O¨ã¦³¼Ð·Ç¯Â¤å¦rÀɮ׮榡ªººÏºÐ°Ï¡C
Blob
¤G¶i¦ì¤j«¬ª«¥ó¡F¥ô¦ó¥H±K½X½sĶºtºâªk«OÅ@ªº¸ê®Æ¡C¨Ò¦p¡AVMK ¬O±K«Ê¦Ü TPM¡A¦ý¥Ñ TPM_Seal §@·~¶Ç¦^©Ò±o¨ìªº blob ¨ä¹ê¬OÀx¦s¦bºÏºÐ¤W¡C¦P¼Ë¦a¡AVMK ¥i¥H¥Ñ¡u¯Âª÷Æ_¡v¡B¡u±Ò°Êª÷Æ_¡v©Î¡u×´_ª÷Æ_¡v¶i¦æ¥[±K¡A¨Ã¥H blob Àx¦s©óºÏºÐ¤W¡C
¯Âª÷Æ_
µL»ÙêÀx¦s¦bºÏºÐ°Ï¤Wªºª÷Æ_¡C¦¹ª÷Æ_¬O¦b¤w°±¥Î BitLocker «OÅ@¦ÓºÏºÐ°Ï¤´µM«O«ù¥[±K®É¡A¥Î¨Ó¦Û¥Ñ¦s¨ú VMK¡A¦AÂà¦Ó¦s¨ú FVEK¡C½Ð°Ñ¾\ BitLocker °±¥Î¡C
FVEK
§¹¾ãºÏºÐ°Ï¥[±Kª÷Æ_¡F¯S©wºtºâªkªºª÷Æ_¡A¥Î¨Ó¥[±K (¤]¥i¥H¥Î¨Ó´²§G) ºÏºÐ°Ï¤Wªº¸ê®Æ¡C¥Ø«e³oÓª÷Æ_¥i¥H¦Û 128 ¦ì¤¸¨ì 512 ¦ì¤¸¤£µ¥¡C¥Î¦bºÏºÐ°Ï¤Wªº¹w³]¥[±Kºtºâªk¬O AES 128 ¦ì¤¸ªþÂX´²¾¹¡C
§@·~¨t²ÎºÏºÐ°Ï
¥]§t§@·~¨t²Î (¨Ò¦p¡AWindows Vista) ªººÏºÐ°Ï¡A¥i¥Ñ¹q¸£ªº¶}¾÷ºÞ²zµ{¦¡¸ü¤J¡C³oӺϺаϱN¥Ñ BitLocker ¥[¥H«OÅ@¡C
¥Ã¤[©Ê¦w¥þ¸Ñ°£©e¥ô
³z¹L²¾°£¸Ñ±K©Î×´_ºÏºÐ©Ò»Ýªº¥þ³¡ª÷Æ_¸ê®Æ¡A¢¨Ï¨ü BitLocker «OÅ@ºÏºÐ°ÏµLªk×´_ªºµ{§Ç¡C
PIN
Ó¤HÃѧO½X¡F³o¬O¨t²ÎºÞ²zû«ü©wªº¾÷±KÈ¡A¥²¶·¦b¨C¦¸¹q¸£±Ò°Ê (©Î¥Ñ¥ð¯v«ì´_) ®É¿é¤J¡CPIN ¥i¥H¦³ 4 ¨ì 20 ¦ì¼Æ¡A¦b¤º³¡±N©Ò¿é¤J Unicode ¦r¤¸Àx¦s¬° 256 ¦ì¤¸Âø´ê¡C³oÓȥû·³£¤£·|¥H¥ô¦ó§Î¦¡©Î¦]¥ô¦ó²z¥ÑÅã¥Üµ¹¨Ï¥ÎªÌ¡CPIN ¬O¥Î¨Óµ²¦X TPM ÅçÃÒ¡A´£¨Ñ¥t¥~¤@¶µ«OÅ@n¯À¡C
¥i×´_ªº¦w¥þ¸Ñ°£©e¥ô
ÂǥѲ¾°£¬°ºÏºÐ¸Ñ±K©Ò»Ýªº¥»¾÷ª÷Æ_ blob (¦Ó¤£¬O×´_ blob)¡A ¢¨Ï¨t²Î¶i¦æ×´_¼Ò¦¡ªºµ{§Ç¡C
×´_ª÷Æ_
¥Î¨Ó×´_¦b BitLocker ºÏºÐ°Ï¤W¥[±Kªº¸ê®Æ¡C³oÓª÷Æ_ªº¥[±K±¡§Î»P¡u±Ò°Êª÷Æ_¡v¬Û·í¡C¦pªG¦³×´_ª÷Æ_¥i¥Î¡A×´_ª÷Æ_¥i±N VMK ¸Ñ±K¡AµM«á VMK ¦AÂà¦Ó±N FVEK ¸Ñ±K¡C
×´_±K½X
¥H 48 ¦ì¼Æ²Õ¦¨¦Ó¤À¦¨ 8 ²Õªº¼Æ¦r±K½X¡C¨C²Õ 6 ¦ì¼Æ¬O¥ý¥Ñ mod-11 ¶i¦æÀˬd¡A¦AÀ£ÁY¦¨¹ïÀ³ªº 16 ¦ì¤¸±K½X¸ê®Æ¡C±K½X¸ê®Æªº½Æ¥»¬OÀx¦s¦b¥Ñ VMK ¥[±KªººÏºÐ¤W¡A¦]¦¹×´_±K½X¥i¥H¥Ñ¨t²ÎºÞ²zû¦b¸ü¤J Windows Vista ¤§«á¥[¥HÂ^¨ú¡C
±Ò°Êª÷Æ_
Àx¦s¦b USB §Ö°{ºÏºÐªºª÷Æ_¡A¥²¶·¦b¨C¦¸¹q¸£±Ò°Ê®É´¡¤J¡C±Ò°Êª÷Æ_¬O¥Î¨Óµ²¦X TPM ÅçÃÒ¡A´£¨Ñ¥t¥~¤@¶µ«OÅ@«Y¼Æ¡C
¨t²ÎºÏºÐ°Ï
¹q¸£±Ò°Ê®É¡A²Ä¤@Ó¦s¨úªººÏºÐ°Ï¡C³oӺϺаϥ]§t¥²»Ý¸ü¤J Windows ¤§¤¤ªº¯S©wµwÅéÀɮסA¥]¬A¹q¸£ªº¶}¾÷ºÞ²zµ{¦¡ (¥H¨Ñ¸ü¤J¦hºØ§@·~¨t²Î)¡C¤@¯ë¨Ó»¡¡A¨t²ÎºÏºÐ°Ï¥i¥H¬O¡A¦ý¨Ã¤£¤@©w¬O¡A»P§@·~¨t²Î (¶}¾÷) ºÏºÐ°Ï¬Û¦PªººÏºÐ°Ï¡C¦ý¬O¡AYn BitLocker ¹B§@¡A¨t²ÎºÏºÐ°Ï¥²¶·»P§@·~¨t²ÎºÏºÐ°Ï¤£¦P¡A¦Ó¥B¤£¥i¥[±K¡C
TPM
¥i«H¿à¥¥x¼Ò²Õ¡A¥Ñ Trusted Computing Group ©w¸q¡CTPM ¬O¦w¥þ©ÊµwÅé¡A¥i´£¨Ñ«H¿àªºµwÅé®Ú¥Ø¿ý¡A¥iµo´§¥\®Ä¡A´£¨Ñ¦UºØ¤£¦Pªº¥[±KªA°È¡CTPM v1.2 ·f°t¬Û®eªº BIOS ¤É¯Å¡A©Ò´£¨ÑªººÏºÐ¥[±K¨ã¦³¦´Á¶}¾÷¤¸¥óªº§¹¾ã©ÊÀˬd¥\¯à¡A¥iÅçÃÒ«nªº¦´Á¶}¾÷¤¸¥ó¡A¨Ã´£¨ÑµL»Ùꪺ±Ò°Ê¸gÅç¡C
VMK
ºÏºÐ°Ï¥Dnª÷Æ_¡G¥Î¨Ó¥[±K FVEK ªºª÷Æ_¡C
1 | ¦ý¶È±Ò°Êª÷Æ_ªº±¡ªp°£¥~¡A½Ð°Ñ¾\¡Õ²Ä 4.3.3 ¸`¡Ö¥H¨ú±o¸Ô²Ó¸ê°T |
2 | ¦p»Ý¸Ô²Ó¸ê°T¡A½Ð°Ñ¾\ USB ¤j«¬¦s©ñÃþ§O¶È¤j¶q¶Ç¿é¡A¥H¤Î USB ¤j«¬¦s©ñÃþ§O UFI ©R¥O³W®æ¡A¥i¥H¦Û http://www.usb.org/developers/devclass_docs#approved ¤U¸ü |
3 | ¦b¥»¤å¥ó¤¤¡A¡uºÏºÐ°Ï¡v·N«üµwºÐ¤WªºÀx¦s°Ï°ì¡CºÏºÐ°Ï¬O¨Ï¥ÎÀɮרt²Î (¦p NTFS) ¶i¦æ®æ¦¡¤Æ¡A¨Ã¨ã¦³«ü©wªººÏºÐ¾÷¥N¸¹¡CºÏºÐ°Ï»P¡uºÏºÐ¤À³Î¡v¤£¦P¡A«áªÌ¬O¥Nªí¹êÅéºÏºÐªº¤@³¡¤À¡A·|¦p¹ê»Ú°Ï¹jªººÏºÐ¯ë¹B§@¡CµwºÐ¾÷¤Wªº¨C¤@ӺϺФÀ³Î³£¥i¥H¦³¤@ӺϺаϡA©Î¬O¦hӺϺаϥi¥H¸ó¦hӺϺФÀ³Î¡C |
4 | ¹w³]ªº TPM ¥¥xÅçÃÒ³]©wÀɯà½T«O VMK ¤£¦] Core Root of Trust of Measurement (CRTM)¡BBIOS¡A¥H¤Î¥¥x©µ¦ù (PCR 0)¡BOption ROM Code (PCR 2)¡B¥D¶}¾÷°O¿ý (MBR) µ{¦¡½X (PCR 4)¡BNTFS ¶}¾÷ºÏ°Ï (PCR 8)¡BNTFS ±Ò°Ê°Ï (PCR 9) ¤Î¶}¾÷ºÞ²zµ{¦¡ (PCR 10) Åܧó¦Ó¨ü¤zÂZ¡C¦P®É¤]¨Ï¥Î PCR 11 (BitLocker ¦s¨ú±±¨î)¡C |
5 | «e±³¹¸`¤¤©Ò´£¤Îªº¨âӺϺаϳ]¸m¬O¥ý¨M±ø¥ó¡C |
6 | ³o¸Ì©Ò¦Cºô§}´£¨Ñ¸Ô²Óªº³v¨B«ü¥Ü¡Ghttp://www.microsoft.com/downloads/details.aspx?FamilyID=311f4be8-9983-4ab0-9685-f1bfec1e7d62&DisplayLang=en |
7 | ³q±`¥²¶·¿Ë¦Û¦b¹q¸£«e°õ¦æ¡A¤~¯àªì©l¤Æ¹q¸£ªº TPM¡C¦ý¬O¡A°²¦p¹q¸£±À¥X®É´N¤w¶}±Ò TPM¡A«h¤£»Ýn¿Ë¦Û¶}±Ò |
8 | ¥»¸`©Ò´£¤Îªº¤èªk¦WºÙ¬O³z¹L BitLocker Windows Management Instrumentation (WMI) ´£¨ÑªÌ Win32_EncryptableVolume ¥[¥H¤½¶}¡C¨C¤@Ó¥i¥H¥Ñ Windows Vista ÃѧOªººÏºÐ°Ï³£¬O Win32_EncryptedVolume ´£¨ÑªÌÃþ§Oªº°õ¦æÓÅé¡C |
9 | ½Ðª`·N¡APIN ÅçÃÒ¤£¯à»P±Ò°Êª÷Æ_µ²¦X¹B§@¡C |
10 | Windows Vista ¤¤¨ã¦³¤U¦C¦w¥þ©Ê¥\¯à¡G¦b¶}±Ò BitLocker «OÅ@¤§«á¡AY¨S¦³¥ý±NºÏºÐ¸Ñ±K¨ÃÃö³¬ BitLocker¡A±NµLªk¥[¤J PIN¡C¦b«Ø¥ß PIN ¨Ã¶}±Ò BitLocker «OÅ@¥H«á¡A°ß¦³³z¹L±NºÏºÐ¸Ñ±K¡A¤~¯à²¾°£ PIN |
11 | ½Ðª`·N¡A±Ò°Êª÷Æ_ÅçÃÒµLªk»P PIN ÅçÃÒµ²¦X¹B§@ |
12 | ¸ê®Æ·|¥Ã»·«O«ù¬°¥[±Kª¬ºA¡A»P°ò¦±K½X½sĶºtºâªk (¨ã¦³ 128 ©Î 256 ¦ì¤¸ª÷Æ_ªº AES) ¤@¼Ë¦w¥þ¡C |
13 | ¦]¬° DeleteKeyProtector ¤£·|²¾°£©Ò¦³ª÷Æ_«OÅ@¸Ë¸m¡A©Ò¥H³o¬O¥²nªº¡C |
14 | ¶}±Ò BitLocker «OÅ@¤§«á¡A¥²¶·¥ý¥[±KºÏºÐ¨ÃÃö³¬ BitLocker¡A¤~¯à·s¼W¡BÅܧó¡A©Î²¾°£×´_±K½X¡C |
15 | ©Ò¦³¥i¦CÁ| BIOS ´CÅé¡C |
16 | ¶}±Ò BitLocker «OÅ@¤§«á¡A¥²¶·¥ý¥[±KºÏºÐ¨ÃÃö³¬ BitLocker¡A¤~¯à·s¼W¡BÅܧó¡A©Î²¾°£×´_ª÷Æ_¡C |