摘要:在这个信息技术发展的时代,用户通常将各种电子文档保存在所使用计算机的磁盘上,其中包括很多重要的机密文档以及含有敏感信息的文档。因此,如何确保磁盘上数据的机密性显得尤为重要。
TrueCrypt磁盘加密软件是目前应用非常广泛的采用OTFE(On-The-Fly Encryption)技术进行磁盘加密的软件系统。该技术能够保证数据在装载和储存前被自动进行快速加解密而不需要用户的干预。软件同时还采用虚拟磁盘技术使用高强度密码算法对用户敏感数据进行保护。
本文首先介绍了TrueCrypt磁盘加密软件的基本思想、总体架构和工作流程,并对其中相关的数据加密算法和数字摘要算法进行了阐述。
接着通过实例,说明了如何使用TrueCrypt软件。
最后,本文分析了TrueCrypt磁盘加密软件的安全机制,并对其安全性做了评估,给出了基于口令猜证的攻击方法,并提出了使用该软件的建议。
关键词:信息安全、磁盘加密、TrueCrypt软件、安全机制、口令攻击
Abstract:In this era of information technology development, the user will usually have a variety of electronic documents stored on computer disk, which includes many important confidential documents and documents containing sensitive information. Therefore, how to ensure the confidentiality of data on the disk is particularly important.
TrueCrypt disk encryption software is very widely used OTFE (On-The-Fly Encryption) technology, disk encryption software. The technology can ensure data is automatically loaded and stored before the fast encryption without user intervention. Software also uses the virtual disk technology uses high-strength cryptographic algorithms to protect sensitive data to users.
This paper introduces the TrueCrypt disk encryption software, the basic idea of the overall architecture and workflow, and one of the relevant data encryption algorithm and digital digest algorithm described.
Then through the example, explained how to use TrueCrypt the software.
Finally, the paper analyzes the TrueCrypt disk encryption software, security, and its security assessment done, given the card based password guessing attack, and made the same recommendation to use the software.
Keywords:Information Security; Disk encryption;TrueCrypt Software; Security; Password attacks