Encryption Keys on Hardware Token


BestCrypt Volume Encryption can store encryption keys for volumes on hardware Aladdin eToken R2 and PRO removable devices connected to USB port. Detailed information about the devices is available on Aladdin Web site: http://www.aladdin.com.

When eToken supporting drivers are installed, BestCrypt Volume Encryption enables option Use Aladdin eToken to store encryption key in the dialog window appeared when you encrypt volume. If you choose the option, you will have to enter passphrase for the eToken you have inserted. The following picture shows the dialog window.


Encrypt Volume

If encryption key for volume is stored on eToken, accessing such encrypted volume will require a concrete eToken connected to USB port and entering an appropriate passphrase. Encrypted data cannot be accessed without any of these Two Factors: without knowing passphrase for the eToken or without eToken device itself.

BestCrypt Volume Encryption has a functionality allowing the user to backup encryption keys from one eToken to another, change passphrase for eToken and completely delete encryption keys from eToken. Read more detail about the functions in Managing Keys on Hardware Token article.


eToken with encryption key for volume is required only for mounting the volume. After that you can remove the eToken from USB port and continue normal work with mounted volume. The volume can be dismounted at any time by running Volume->Dismount Encrypted Volume command. The way of managing eTokens is chosen to minimize advertizing your use of eToken, besides of this, it minimizes risk of loosing eToken device.


See also: