No part of this documentation may be
reproduced or processed, copied,
distributed by a retrieval system in
any form (print, photocopies or any
other means) except for personal use
without prior written consent of
Utimaco Safeware AG.
Utimaco Safeware AG reserves the
right to modify or supplement the
documentation at any time without
previous announcement. Utimaco
Safeware AG is not liable for
misprints and damage resulting from
this.
CryptoServer and SafeGuard are
registered marks of
Utimaco Safeware AG.
Windows, Windows NT, Windows
2000, Windows XP, Windows 2003
Server and Windows CE are
registered marks of Microsoft
Corporation.
Patents rights of Ascom Tech Ltd.
given in EP, JP, US. IDEA is a
Trademark of Ascom, Tech Ltd.
All other brand and product names
mentioned in this manual are marks of
the respective owners and are
recognized as such.
Microsoft, Windows, and the Windows
logo are trademarks or registered
trademarks of Microsoft Corporation in
the United States and/or other countries.
Our knowledge database provides answers to many typical questions
about the SafeGuard product range, including its functionality,
implementation, administration and troubleshooting.
pмййзкн
Link to support area: http://www.utimaco.com/myutimaco
To access the public area of the knowledge database you can logon as a
guest user. To access the restricted area of the knowledge database you
need a valid software maintenance agreement. Our support staff
continually adds to the contents of both areas, and keeps them up to date
on an on-going basis.
Advanced support services and telephone support
For customers with a valid maintenance contract, qualified support staff is
available to provide advice and assistance. To receive a contract offer
tailored to your specific needs, please contact your Utimaco sales partner.
We hope you understand that some enquiries from customers without a
maintenance agreement may require several working days to process. In
urgent cases, please contact the Utimaco sales partner from whom you
bought your licenses or software subscription.
Personal computers often contain personal data, confidential and
company information or other sensitive data.
The danger caused by the theft of notebooks should not be
underestimated. Highly sensitive client information on a sales
representative’s notebook could fall into the hands of a competitor,
resulting in serious damage for the company.
SafeGuard Easy is the ideal way to safeguard against such risks without
spending too much time on implementing security measures.
How does SafeGuard Easy protect workstations against unauthorized
access? The program’s most important security features are its drive
encryption and boot protection, which are used to prevent access to a
workstation via an external data medium.
The biggest benefits of SafeGuard Easy are that the program
simply but effectively protects the confidentiality of stored data
N
ñÅ
can be implemented quickly
is very user-friendly
offers a security concept suitable for many different application
areas.
SafeGuard Easy is easy to install. For this reason, it is particularly well
suited for stand-alone systems and mobile units such as notebooks.
N
NKN`Йенк~д=лЙЕмкбну=СмеЕнбзел
Encryption
SafeGuard Easy uses online encryption to protect the confidentiality of
data that is stored on hard disks, floppy disks and removable media in a
simple and effective manner. Here, "online" means that the data is
decrypted, when it is read and loaded into RAM, and then automatically
encrypted again when it is saved. The key is not saved on the hard disk or
PC. It is determined again, from the user’s SafeGuard Easy password,
each time the PC is switched on.
SafeGuard Easy encrypts not only the entire contents of hard disks, but
also the contents of removable media such as floppy disks, ZIP or JAZ
disks or USB memory sticks. This allows secure data medium exchange
to be implemented within the company, while simultaneously protecting
the contents of mobile data media against unauthorized access. It also
provides an effective way of preventing the unauthorized importing of data
such as unlicensed software or viruses via removable media, since users
without the appropriate authorization cannot use plain text media.
Different algorithms can be selected to encrypt floppy disks, removable
media and the individual partitions on hard disks. The algorithms that can
be used for this purpose include AES, Rijndael, XOR, STEALTH-40, IDEA,
BLOWFISH, DES and 3DES.
O
Access control with Pre-Boot Authentication (PBA) and boot
protection
Pre-Boot Authentication is an additional central security function in
SafeGuard Easy. PBA ensures that only the SafeGuard Easy user who is
registered on the system can log onto it.
N
ñÅ
When the hard disk is encrypted, any attempt to boot the computer from
another data medium, such as a system floppy disk, a CD-ROM or another
hard disk, will fail: the hard disk remains blocked. In fact, this means that
the system actually does boot, but it is not possible to read the encrypted
data on the hard disk.
When PBA is implemented on a workstation along with the Boot protection
option, the workstation cannot been booted with an external data medium
unless the user knows the correct SafeGuard Easy user data.
P
NKOlнЬЙк=лЙЕмкбну=СмеЕнбзел
Support for Lenovo’s (IBM’s) ThinkVantage technologies - Client
Security Solution (CSS) 8.10 and Rescue and Recovery 4.20
SafeGuard Easy already supports earlier versions of Lenovo’s
ThinkVantage technologies. The current version of SafeGuard Easy is still
compatible to Lenovo’s Client Security Solution (CSS) and Rescue and
Recovery (RnR).
Rescue and Recovery (RnR): SafeGuard Easy supports Lenovo’s
Rescue and Recovery. This means customers can use this efficient
backup and recovery method along with SafeGuard Easy encrypted
operating system partitions. This functionality is unique amongst disk
encryption products. Backups from encrypted SafeGuard Easy
systems can be stored on any disk drive used by RnR. Therefore, in
an emergency, a system can be restored by loading a backup from CD/
DVD, a network drive, a second internal hard disk or a USB hard disk
or stick.
TCPA/TPM support (ESS chip/CSS): SafeGuard Easy is the first
hard disk encryption product to use the security chips, specified by the
Trusted Computing Group (TCG), that are nowadays integrated in the
latest notebooks. Among other things, SafeGuard Easy uses these
chips to secure the link between the client and administration server,
and also to generate random numbers. Naturally, SafeGuard Easy’s
Secure Auto Logon (SAL or SSO) function can also be used to provide
optimum integration in the ESS chip infrastructure.
Certification to FIPS 140-2 Level 1
SafeGuard Easy now complies with the guidelines of FIPS 140-2 Level 1
(FIPS= Federal Information Processing Standard) certification set out by
the American National Institute of Standards and Technology (NIST). NIST
defines the security criteria for encryption products used by the American
government.
SafeGuard® Easy is already certified in accordance with the Common
Criteria standard, Evaluation Assurance Level 3 (EAL 3).
Q
Optional two-factor authentication in the Pre-Boot phase
SafeGuard Easy can be configured in such a way that only users with an
appropriate token can access the PC. Besides being used in Pre-Boot
Authentication (PBA), the token can also, of course, be used at operatingsystem level for other, certificate-based applications, via the PKCS#11 or
CSP standard. Furthermore, the token can also be used by the SafeGuard
Easy administrator to log on to the administration programs. SafeGuard
Easy users who have forgotten their password or token can be helped by
a central help desk.
SafeGuard Easy supports
various Aladdin eTokens
Verisign USB token
RSA SecurID 800 token
Biometric logon with Lenovo Fingerprint Sensor
In addition to logon with USB token (RSA, Aladdin), SafeGuard Easy also
supports logon via "fingerprint" in the pre-boot authentication phase. The
benefit of using a fingerprint is that a user does not have to remember
SafeGuard Easy passwords or the PIN for a USB token. They can identify
themselves to a Lenovo notebook, for example, simply by passing their fin
ger over the sensor that is installed on it.
N
ñÅ
-
Hibernation (Suspend to Disk) support
This is especially useful for mobile device users who usually avoid booting
by simply "pausing" and then later "restoring" their current work session,
because these options are provided by modern operating systems. In
contrast to most other hard disk encryption products, SafeGuard Easy
supports use of hibernation mode, even encrypting the generated image
data in order to store it securely on the hard disk. This provides round-theclock security, reduces power consumption and saves users time, in
comparison with normal boot procedures that are currently in use.
Compatibility with Absolute’s Computrace software
When Computrace is installed, a stolen computer can report its location via
a network. SafeGuard Easy has been prepared to ensure it is compatible
with Computrace. This compatibility with SafeGuard Easy means that this
feature also works with encrypted hard disks.
R
Full compatibility requires a version of Computrace Software that, at
present (12/2008)) has not yet been released by Absolute Software.
Web Self Help
SafeGuard Easy’s Self-Help enables an ordinary user to help themselves
if they forget their SafeGuard Easy password. This will lead to an overall
decrease in the number of help desk calls that are solely due to forgotten
passwords, and therefore the help desk personnel will have more time to
work on more complex support cases. There are also various solutions for
Challenge/Response in a purely software or cryptobased variant.
Self Help is also available as separate add-on.
Password rules
SafeGuard Easy offers a multitude of options for implementing special
password rules in the PBA such as a configurable list of forbidden
passwords, extended rules for special characters, UID etc., to provide
even better functionality for implementing pre-defined corporate rules.
Auditing in the PBA and operating system
SafeGuard Easy also logs events involving security issues, such as failed
logon attempts, in the Pre-Boot phase, and later passes on these log
entries to the Windows Event Log for evaluation. Alternatively (via an
additional component) they can be transferred to a central server, and
evaluated there. As a result, attacks can be recognized more quickly and
statuses diagnosed more easily.
Optional central administration database
In addition to its functions for reliably distributing configuration files,
SafeGuard Easy includes a dedicated, central administration software
system. This is responsible for system kernel backups, the distribution of
configuration data and the integration of offline clients.
SafeGuard Easy uses a Microsoft Access or Microsoft SQL Server
database as the default database type for saving information about
SafeGuard Easy clients. With the "Remote Administration" module, which
is also available, it is possible to configure a specific individual client over
the network.
S
Same user password for SafeGuard Easy and Windows
(password synchronization)
For many support staff, calls from users who have forgotten their password
are part of everyday life. The rule is: the fewer passwords a user needs to
remember, the less work there is for support staff. SafeGuard Easy’s
password functionality helps reduce the number of user calls because the
software can be configured to make the Windows and SafeGuard Easy
password the same ("synchronized") with just one mouse click. After
successful synchronization, a user can then use the same password to log
on to SafeGuard Easy in Pre-Boot Authentication and to the operating
system.
Secure Wake-On-LAN support
SafeGuard Easy’s Pre-Boot authentication offers the best-possible
protection against attacks from hackers. However, maximum security is
also needed when distributing software via Wake-On-LAN when active
hard disk encryption is in operation, and so SafeGuard Easy offers a range
of functions for that purpose.
Secure remote administration (Challenge/Response)
Helpdesk staff can help users who have forgotten their password. The
Challenge/Response procedure is secure and ideal for mobile users, since
it does not require a PC to have a direct online link with the help desk.
N
ñÅ
Challenge/response for PDA
SafeGuard Easy users who have forgotten their passwords or token can
quickly return to work with help from a central help desk. Helpdesk staff
can also carry out their work on an entirely mobile basis, using a PDA
(Pocket PC), so they are no longer dependent on having access to a PC.
Windows Installer-based installation
As the installation procedure is fully compliant with the current Windows
Installer (MSI) standard it can be distributed and installed easily and
efficiently in Windows networks.
T
Integrated boot manager (Twinboot)
Today, it is a frequent requirement that a notebook’s hard disk is split into
a private, unprotected partition, managed by the user, and an encrypted
partition that is managed by the user’s company. SafeGuard Easy
provides an integrated boot manager for this purpose, with which
configurations of this kind, or similar ones, can be implemented easily and
securely, from one central point. In this way the company data remains
protected and the user has absolute freedom on their private partition,
even when it comes to choosing the operating system.
Removable media encryption covers USB memory media
SafeGuard Easy supports the current generation of Plug and Play memory
cards (USB memory sticks), so they can also be used for secure data
exchange. In addition, it is possible to temporarily switch encryption for a
particular diskette drive or removable media disk drive on or off, separately
from the others.
Flexible user management during Pre-Boot Authentication
When a user is logging on, SafeGuard Easy can also add an additional
message, specified by the administrator, that informs the user of legal
requirements, ownership of the device, or similar.
Companies use SafeGuard Easy’s configuration files if a large number of
clients are to use the same SafeGuard Easy configuration. In this situation
the "old" configuration files can be imported to provide an easy way of
reusing settings and keys during an upgrade without having to type them
in again.
Emergency boot from diskette and CD
Nowadays, PC systems are usually equipped with CD/DVD drives instead
of diskette drives. SafeGuard Easy has taken these hardware
developments into account and now also accepts CDs as emergency boot
devices, alongside floppies. Boot media are supported for both MS DOS
and Windows PE.
U
Loading...
+ 514 hidden pages
You need points to download manuals.
1 point = 1 manual.
You can buy points or you can get point for every manual you upload.