GBDE: GEOM based disk encryption

Poul-Henning Kamp · 2003

The ever increasing mobility of computers has made protection of data on digital storage media an important requirement in a number of applications and situations. GBDE is a strong cryptographic facility for denying unauthorised access to data stored on a ‘‘cold’ ’ disk for decades and longer. GBDE operates on the disk(-partition) level allowing any type of file system or database to be protected. Asignificant focus has been put on the practical aspects in order to make itpossible to deploy GBDE in the real world. 1 1. Losing data left and right In the last couple of years, gentlemen of the press have repeatedly been able to expose how laptop computers containing highly sensitive or very valuable information have been lost to carelessness, theft and in some cases espionage. [THEREG] The scope of the problem is very hard to gauge, since it is not a subject which the involved persons and, in particular, institutions are at all keen on having exposed. However, a few data points have been uncovered, revealing that the U.S. Federal Bureau of Investigation loses, on average, one laptop every three days. [DOJ0227] When a computer is lost, stolen or misplaced, it is very often the case that the computer hardware represents a value which is insignificant compared to the value of the disk contents. More often than not, the only reason the press heard about it was that the material on the disk was ‘‘hot’ ’ enough to make the loss of control rattle people at government level. While it is easy to blame these incidents on ‘‘user error’’, as is generally done, doing so makes it a very hard problem to fix. Human nature being what it is, seems to remain just that. In the absence of technical counter measures, administrative measures have been applied, generally with abysmal results. In one case, a bureaucracy has handled the problem according to what could easily be

Read the paper · More papers on PaperTik