Bob Adhar MD & Practice Manager, CISSP Nadia Vostrikov Software Support Engineer, MCP Randtronics...

27
Secure BYOD applications using hardware based security and Windows To Go Bob Adhar MD & Practice Manager, CISSP Nadia Vostrikov Software Support Engineer, MCP Randtronics Pty Ltd WCL315

Transcript of Bob Adhar MD & Practice Manager, CISSP Nadia Vostrikov Software Support Engineer, MCP Randtronics...

Page 1: Bob Adhar MD & Practice Manager, CISSP Nadia Vostrikov Software Support Engineer, MCP Randtronics Pty Ltd.

Secure BYOD applications using hardware based security and Windows To GoBob AdharMD & Practice Manager, CISSP Nadia VostrikovSoftware Support Engineer, MCP Randtronics Pty Ltd

WCL315

Page 2: Bob Adhar MD & Practice Manager, CISSP Nadia Vostrikov Software Support Engineer, MCP Randtronics Pty Ltd.

AgendaIntroductionBYOD and Windows to GoSecure Portable Workplace for Windows To GoManagement of SPW devicesDemoQ&A

Page 3: Bob Adhar MD & Practice Manager, CISSP Nadia Vostrikov Software Support Engineer, MCP Randtronics Pty Ltd.

Introduction

Page 4: Bob Adhar MD & Practice Manager, CISSP Nadia Vostrikov Software Support Engineer, MCP Randtronics Pty Ltd.

Randtronics & SPYRUS at a glance: Who we areRandtronics Pty LimitedAustralian company, HQ in North Ryde, NSW in operation for 12 yearsEncryption solutions for complex IT environmentsEncryption practice Distributor of SPYRUS technologies

SPYRUS, Inc.Manufacturer of portable hardware encryption devices Private corporation with HQ in San Jose, California20 year history of developing security solutionsMade In USA Product Focus

Page 5: Bob Adhar MD & Practice Manager, CISSP Nadia Vostrikov Software Support Engineer, MCP Randtronics Pty Ltd.

BYOD & Windows to Go

Page 6: Bob Adhar MD & Practice Manager, CISSP Nadia Vostrikov Software Support Engineer, MCP Randtronics Pty Ltd.

Market drivers for trusted BYOD & Mobility solutions

Trusted mobility solutions

Consumerisation of IT

MicrosoftWindows

To Go

Attacks from National

adversaries

Compliance & control Rise in attacks

& data breaches

Growth in cloud

computing

Work anywhereany time,

BYOD

Page 7: Bob Adhar MD & Practice Manager, CISSP Nadia Vostrikov Software Support Engineer, MCP Randtronics Pty Ltd.

Windows To Go, portable workplace

Microsoft ecosystem focus for enterprise customers supporting mobilityWindows 8 experience on any deviceCost effectiveLightweight solution in USB formatWorks in corporate environment of remote locationsEasy to useEasy to deploy and manage

Page 8: Bob Adhar MD & Practice Manager, CISSP Nadia Vostrikov Software Support Engineer, MCP Randtronics Pty Ltd.

Windows To Go use cases

ContractorsBring Your Own Device (at work)

Travel Light / Work from Home

Shared PCs

Page 9: Bob Adhar MD & Practice Manager, CISSP Nadia Vostrikov Software Support Engineer, MCP Randtronics Pty Ltd.

Secure Portable Workplace for Windows To Go

Page 10: Bob Adhar MD & Practice Manager, CISSP Nadia Vostrikov Software Support Engineer, MCP Randtronics Pty Ltd.

SPYRUS Secure Portable WorkplaceEncrypted USB drive boots Windows 8 OSPocket sized PC USB 3.0 and SSD performanceEasy provisioningZero footprint

Page 11: Bob Adhar MD & Practice Manager, CISSP Nadia Vostrikov Software Support Engineer, MCP Randtronics Pty Ltd.

Boots directly from USB

USB 3.0

& 2.0

Page 12: Bob Adhar MD & Practice Manager, CISSP Nadia Vostrikov Software Support Engineer, MCP Randtronics Pty Ltd.

Security featuresXTS-AES 256 full disk encryptionHardware encryption embedded into USBBased on Suite B cryptographic algorithmsDesigned for FIPS 140-2 Level 3 Optional BitLocker for double-layer encryption

Page 13: Bob Adhar MD & Practice Manager, CISSP Nadia Vostrikov Software Support Engineer, MCP Randtronics Pty Ltd.

USB 3.0 I/F

USB 3.0 to SATABridge Chip

SATA to NANDController NAND

Flash

ROSETTA Micro Security Chip &

SPYRUS security firmware

SPYRUS WTGFirmware

Developed by SPYRUS

Provided by 3rd party

Provided by NAND Manufacturer

Security Boundary

SATAI/F

NAND FlashI/F

SPW architecture

Page 14: Bob Adhar MD & Practice Manager, CISSP Nadia Vostrikov Software Support Engineer, MCP Randtronics Pty Ltd.

Memory architectureBOOT PARTITION (CLEAR)

ToughBoot™ Loader

Windows To Go PARTITION (ENCRYPTED)

Applications

User Utilities

OS BOOT PARTITION

OPERATIONAL PARTITION

Windows Boot Loader

ReadOnly(opt)

USER DATA PARTITION(Optional)

Data

Windows 8 OS

Page 15: Bob Adhar MD & Practice Manager, CISSP Nadia Vostrikov Software Support Engineer, MCP Randtronics Pty Ltd.

Boot from Secure Portable Workplace

Demo

Page 16: Bob Adhar MD & Practice Manager, CISSP Nadia Vostrikov Software Support Engineer, MCP Randtronics Pty Ltd.

Provisioning SPW devicesMust use SPYRUS tools for provisioningFrom 64-bit PC with Windows 8 EnterpriseWindows 8 Enterprise WIMSPYRUS WTGCreatorPowershell scriptsUp to 8 units at a time

Page 17: Bob Adhar MD & Practice Manager, CISSP Nadia Vostrikov Software Support Engineer, MCP Randtronics Pty Ltd.

SPYRUS WTG CreatorCreate clear & encrypted compartmentInitialise boot loader & encryptionGenerate encryption keysSet passwordLoad Enterprise WIM imageSetup Microsoft BitLocker keyJoin domain

Page 18: Bob Adhar MD & Practice Manager, CISSP Nadia Vostrikov Software Support Engineer, MCP Randtronics Pty Ltd.

Provisioning USB’s with SPYRUS WTG CreatorDemo

Page 19: Bob Adhar MD & Practice Manager, CISSP Nadia Vostrikov Software Support Engineer, MCP Randtronics Pty Ltd.

Management of SPW devices

Page 20: Bob Adhar MD & Practice Manager, CISSP Nadia Vostrikov Software Support Engineer, MCP Randtronics Pty Ltd.

Management of OS & applicationsDeploy custom WIM imagesUse your existing infrastructureSystem Centre Configuration Manager or 3rd partyInventory softwareDeploy applications, updates, patches as normal

Configure user & system settings with group policiesFolder redirection & data synchronisation

Page 21: Bob Adhar MD & Practice Manager, CISSP Nadia Vostrikov Software Support Engineer, MCP Randtronics Pty Ltd.

SPYRUS Enterprise Management SystemSPW device managementDisable/Enable devices Destroy device remotelyOffline use enforced by policyPassword complexityAudit log & device status

Secured with SPYRUS HSMTwo-factor authentication for administrators

Page 22: Bob Adhar MD & Practice Manager, CISSP Nadia Vostrikov Software Support Engineer, MCP Randtronics Pty Ltd.

SEMS architecture

SEMSClient

SEMSWindows

Domain Controller

AdminConsoleAccess

Page 23: Bob Adhar MD & Practice Manager, CISSP Nadia Vostrikov Software Support Engineer, MCP Randtronics Pty Ltd.

SEMS management of SPW devices

Demo

Page 24: Bob Adhar MD & Practice Manager, CISSP Nadia Vostrikov Software Support Engineer, MCP Randtronics Pty Ltd.

SPW & WTG: Bridging the gapHigh fidelity BYOD & Mobility experience with defence grade data protection

A Secure Bootable Portable PCin your pocket

Boot, Compute, and Scoot

Page 25: Bob Adhar MD & Practice Manager, CISSP Nadia Vostrikov Software Support Engineer, MCP Randtronics Pty Ltd.

Contact Details• [email protected][email protected]

• www.Randtronics.com• Ph: +612 8873 1999• Product Enquiries :

[email protected]

Page 26: Bob Adhar MD & Practice Manager, CISSP Nadia Vostrikov Software Support Engineer, MCP Randtronics Pty Ltd.

Developer Network

Resources for Developers

http://msdn.microsoft.com/en-au/

Learning

Virtual Academy

http://www.microsoftvirtualacademy.com/

TechNet

Resources

Sessions on Demand

http://channel9.msdn.com/Events/TechEd/Australia/2013

Resources for IT Professionals

http://technet.microsoft.com/en-au/

Page 27: Bob Adhar MD & Practice Manager, CISSP Nadia Vostrikov Software Support Engineer, MCP Randtronics Pty Ltd.

© 2013 Microsoft Corporation. All rights reserved. Microsoft, Windows and other product names are or may be registered trademarks and/or trademarks in the U.S. and/or other countries.The information herein is for informational purposes only and represents the current view of Microsoft Corporation as of the date of this presentation. Because Microsoft must respond to changing market conditions, it should not be interpreted to be a commitment on the part of Microsoft, and Microsoft cannot guarantee the accuracy of any information provided after the date of this presentation. MICROSOFT MAKES NO WARRANTIES, EXPRESS, IMPLIED OR STATUTORY, AS TO THE INFORMATION IN THIS PRESENTATION.