Disk Encryption with SafeNet ProtectDrive

Strongest Data Security at the Lowest Cost of Ownership

ProtectDrive is a full-disk encryption solution that encrypts the entire hard drive of laptops, workstations and servers, as well as USB flash drives, to protect data in the case of the theft or loss of a hardware device.

ProtectDrive protects organizations against potentially devastating data breaches, and enables them to meet both corporate governance and industry-specific compliance needs.

ProtectDrive offers the strongest security; in fact it's deployed by governments around the world to protect not only their national security but also the privacy of their citizens.

ProtectDrive eliminates the need for costly proprietary administration by leveraging organizations' investments in Active Directory, an implementation of LDAP directory services by Microsoft to provide central authentication and authorization services.

SafeNet ProtectDrive is a key component of SafeNet’s comprehensive enterprise data protection solution to reduce the cost and complexity of regulatory compliance, data privacy, and information risk management.

  • Most Secure Full Disk Encryption
  • Ease of Deployment
  • Ease of Administration
  • Ease of Use
  • Strong Two-Factor Authentication
  • U.S. Government SmartBUY Approved

Hard Disk Encryption Quick Facts - ProtectDrive

ProtectDrive is hard disk encryption software for securing sensitive data. ProtectDrive provides pre-boot authentication and once installed, encrypts and decrypts data transparently. The pre-boot feature prevents unauthorized users from breaking into the operating system to access sensitive information.


Encryption

  • ProtectDrive performs low-level encryption, supporting industry proven algorithms such as DES, 3DES, IDEA and AES 128bit, 192bit and 256bit.
  • Users do not notice any impact to their day-to-day activities and are not required to learn or perform anything different. ProtectDrive does not introduce features that requires the user to be trained to operate.

Pre-boot Authentication

  • When a PC secured by ProtectDrive is switched on, the user must first authenticate to the device before gaining access to the operating system and all stored data. If the user is not able to enter a correct username/password, or valid PIN (in the token version), the PC will not boot the operating system and the user will not be able to log into the PC.
  • This ensures hackers cannot break into the operating system to access stored files in the clear.

  • Users are given three re-tries to enter the correct authentication information. After the third incorrect re-try, ProtectDrive will re-start the PC and enforce a one-minute lock out. During this lockout period, the PC will not respond to any user interaction. Once the lockout period is complete the user will be given one single retry to enter the correct credentials. Subsequent one-minute lockouts will occur after each single incorrect retry.

User Management

ProtectDrive integrates with the Windows user manager to provide seamless user administration and management. As users are added or removed from Windows, this is automatically synchronized with the ProtectDrive pre-boot authentication screen. Both local and domain user profiles are supported.


Password Management

User passwords are synchronized with the Windows password, unless this feature is explicitly switched off during installation of ProtectDrive.


Single sign-on

Pre-boot password or token login credentials can be set to automatically be passed on to the Windows post-boot authentication environment, enabling single sign-on to Windows.

Full drive/partial drive encryption

ProtectDrive can encrypt the full disk preventing access to all data, or dedicated sections of the hard drive. At all times, ProtectDrive encrypts all operating system files, including temporary and page files.


Multi-boot support

ProtectDrive secures systems that require a multi-boot environment.


Multiple users support

ProtectDrive can be configured to provide authenticated login and data security to over 200 different users on a single device. This eliminates the need for users to share accounts and passwords.


Pre-boot token support/Strong authentication

ProtectDrive easily enables configuration of tokens with X509 certificates to achieve ‘Strong Authentication’, also known as 'two-factor authentication'.

X509 certificate support

ProtectDrive can use the integrity of the X509 certificate on a token in combination with Public and Private Keys to strengthen pre-boot authentication.


Port protection

ProtectDrive can be configured to secure print and com ports, plus floppy drives from unauthorized extraction of data.


Hibernation support

ProtectDrive secures all files on the hard disk (including those in active memory) when the computing devices hibernation function automatically activates.


Large scale network installation

ProtectDrive can be easily remotely installed over large network infrastructures using remote with pre-definable security policies.


Silent installation

Silent installation enables deployment without the user being interrupted, or noticing.


Logging

ProtectDrive securely logs information on pre-boot events like successful/failed logins, and password changes.


Remote password recovery – Challenge/Response

ProtectDrive contains a recovery facility, allows the IT (help) desk to remotely recover user’s forgotten passwords, using a challenge/response mechanism. The basic procedure is;

  1. User is at the ProtectDrive pre-boot logon screen and has forgotten the password.
  2. The user enters their unique username and moves to the password field
  3. The user now presses SHIFT-F10 on the keyboard.
  4. The user is now taken to another screen that contains some configuration and cryptographic information.
  5. The user can now contact the central IT (help) desk for remote assistance.
  6. The IT (help) desk must firstly verify the user is authentic, according to the organizations security policy.
  7. Once verified the user can now read out the cryptographic info displayed.
  8. The help desk enters this info into the “RPAdmin” utility, on the diagnostic diskette.
  9. The utility will recover the user password, which is then given to the user.
  10. The user can now type the password into the ProtectDrive pre-boot screen.
  11. The user should then reset their password.