Secure Mobile Access with a Secure Isolated Environment
Trusted Client is Becrypt’s innovative answer to the IT Manager’s dilemma: how to provide secure but low-cost access to corporate networks. Trusted Client is an easy to use solution that transforms an unmanaged machine into a secure access point and, by providing cost effective and highly secure access for mobile workers, significantly reduces the risk of data loss and data leakage. Trusted Client is an invaluable tool that supports and enforces a comprehensive Information Assurance strategy. Trusted Client OverviewTrusted Client is a bootable trusted environment that typically resides on a USB flash drive, and allows employees to work securely from an unmanaged internet connected PC. It addresses the risks inherent in using an unmanaged PC, such as an employee’s home PC, to connect to an organisation’s secure network and data.
Trusted Client’s innovative use of technology creates a secure environment on the host PC: it does not user the host hard drive and operating system. This has to two key benefits; first, any malware on the host PC can not infect the network; secondly, corporate data cannot leak onto the host PC.
How it works Trusted Client has been designed with a modular approach to enable third party components to be built into the environment. It may be configured to include only pre-specified applications, and to restrict the user to approved IP destinations, ports, and protocols, such as the corporate intranet, virtual private network (VPN) or specific hosts. Once the configuration of Trusted Client has been decided, a single install file is created allowing an organisation to quickly and securely build devices that are unique to their needs. Next the Trusted Client device is built, this can be done by the end user themselves, or by an administrator or other central function. All that is required is a standard 1GB or greater USB memory stick, and the configuration of Trusted Client specific for your organisation, which may be held in a central secured zone for access by staff. To create the device, the end user or administrator sets up an initial username and password and inserts the USB memory stick. The Becrypt software then generates a unique 256bit AES encryption key and uses this to encrypt the device and copy the relevant files, producing the Trusted Client. The end user then can use the Trusted Client from an internet connected PC. They boot from the USB device, an authentication screen will be displayed, asking for username and password. After successful authentication, the device automatically decrypts and the device operating system is loaded creating a secure environment on the host machine. Trusted Client utilises standard browsers, Citrix and Microsoft Terminal Services, giving users a familiar user interface and offering easy integration with existing systems. The Trusted Client operating system has no access to the internal drives of the machine, allowing the user to work safely regardless of the malicious software that maybe present on the host. This feature also prevents any data from being leaked outside of the Trusted Client environment. If authentication fails, the device can not be booted and it can not be accessed as the whole device is encrypted. Trusted Client is quick to boot up and the encryption is completely transparent to the end user. The strong user authentication features include an embedded strong password generator, and the device can be configured to work with additional tokens, providing secondary authentication of any user. Should a password be forgotten, secure device recovery through a challenge/response processes is possible, ensuring that the original password is never compromised. Having completed their work session, the user simply shuts down the host PC and removes the Trusted Client USB device, no trace of session is left on the host PC. |

Trusted Client: secure mobile access you can trust from a PC you can't