Závěrečná práce: Daniel Chromik: Operating system boot from fully encrypted device
Bakalářská práce
Operating system boot from fully encrypted device
Anotace
Cílem práce je popsat bootovací proces z kompletě zašifrovaného zařízení se Secure Bootem. Proces je popsán pro Operační Systémy Linux a Windows. Nejdřív je popsán "Early Boot Process" a Boot Loadery. Následně je popsáno co je potřeba na nainstalování Linuxu na kompletně zašifrovaném zařízení, i s ukázkou. Na konec jsou popsány existující způsoby na zašifrovaní Windows.
Abstract
The goal of this work is description of existing solutions for booting Linux and Windows from fully encrypted devices with Secure Boot. Before that, though, early bootprocess and bootloaders are described. A simple Linux distribution is then setup to boot from a fully encrypted device. And lastly, existing Windows encryption solutions are described.
Zadání práce
Study and describe early boot process and generic structure of a boot loader used in operating systems on the PC (Intel) platform. Focus on secure boot and requirements for Unified Extended Firmware Interface (UEFI) systems.
Describe required steps for booting an operating system directly from a fully encrypted block device.
Study open-source GRUB2 boot loader and its existing capabilities. Demonstrate installation and boot of some Linux distribution with LUKS encrypted system device and GRUB2 boot loader. (System must boot without the separate Linux boot partition and without the unencrypted initramdisk.) If possible, also use the secure boot UEFI system.
Study and describe possibilities of booting Windows operating system directly from the encrypted device and through the GRUB2 boot loader (focus on Windows 10). Try to experiment with LUKS encrypted disk as a boot device for Windows system. Try to modify (or at least describe needed steps) existing open-source boot loaders and drivers capable of booting Windows from encrypted devices (VeraCrypt, DiskCryptor).
Thesis outcomes will include:
- in-depth description of modern PC (secure) boot process and GRUB2 boot loader
- usable demonstration example of Linux boot from fully LUKS encrypted device
- proposal of changes needed for booting Windows system from LUKS device
9. 1. 2017 13:21, Ing. Milan Brož, Ph.D., učo 168968
Práce na příbuzné téma
Seznam prací, které mají shodná klíčová slova.
-
Authenticated and Resilient Disk Encryption
Ing. Milan Brož, Ph.D., učo 168968 -
Disk re-encryption in Linux
Bc. Stepan Yakimovich -
Bezpečnostní rysy OS X, Linux, Windows vs. Malware
Matej Obrtanec -
FileVault disk encryption in Linux environment
Mgr. Pavel Tobiáš, učo 422611 -
Argon2 security margin for disk encryption passwords
Mgr. Vojtěch Polášek -
Hardware-encrypted disks in Linux
Mgr. Štěpán Horáček -
Easydialogs pro Linux
Bc. Lukáš Šeděnka -
Generátory náhodných čísel v multiplatformním prostředí
Bc. Matej Harčár




