Overview of Rescue Procedures
BestCrypt Volume Encryption provides the user with a number of procedures
to avoid loosing of encrypted data in accidental cases. For example, because
of damaging physical sectors where critical data is stored (like encrypted
volume headers).
Recovering encrypted data is possible if the user has
Rescue File for the volume. BestCrypt Volume
Encryption always creates and updates Rescue File (rescue.rsc) in the
folder where the software is installed. Information inside Rescue File
is encrypted exactly in the same way as on volumes, so there is no risk
that someone not knowing proper passwords can use the file. Since the
folder where the software is installed can also be encrypted or even
stored on damaged disk, BestCrypt Volume Encryption suggests the user
should use commands from Rescue menu to
copy Rescue File to safe place.
Several accidental situations are possible:
- Boot/System volume is encrypted. If physical damage of the volume occurs,
it will be impossible to boot computer. BestCrypt Volume Encryption suggests
the user should create Rescue Bootable CD or Floppy Disk.
The bootable disk contains Rescue File and special recovering program that starts
just after booting computer from the disk. The recovering program displays
information about volumes and after confirmation starts decrypting process.
- Regular volume is encrypted. In this case it is possible to run BestCrypt
Volume Encryption program, select damaged volume in the main window of the program
and run the Rescue->Decrypt Volume using Rescue File
command. The program allows using Rescue File located on any disk.
- Another kind of problems can also occur. BestCrypt Volume Encryption can store
encryption key on hardware USB token device (Aladdin eToken). If you lose the
token, it will be impossible to access the volume. So it is strongly recommended
to copy keys stored on the token you use in everyday work to another token and
keep the backup token in a safe place. Command
Rescue->Hardware Token->Backup Encryption Keys to other
Token is added for that purpose.
Note that Rescue File stores information in encrypted form. If you
forget password for some volume, it will be impossible to decrypt the volume
using Rescue File.