Encryption disk
Full disk and hidden OS in EFI
v1.2
Revisions
N Date Name Comment
1.2 28-mar-17 kavsrf Hidden OS. Simplified
1.1 28-feb-17 kavsrf Hidden OS. Developer way.
1.0 28-jan-17 kavsrf Started.
Encryption disk..............................................................................................................................1
Full disk and hidden OS in EFI..................................................................................................1
v1.1.............................................................................................................................................1
1 Full disk encryption....................................................................................................................1
1.1 Boot from local hard disk....................................................................................................1
1.1.1 Final disk structure........................................................................................................1
1.1.2 Installation scenario (It is proposal)..............................................................................1
1.1.3 Developer way. To test PoC..........................................................................................2
2 Hidden OS installation................................................................................................................2
2.1 Installation in addition to already encrypted OS..................................................................2
2.1.1 Prepare disk state..........................................................................................................2
2.1.2 Final disk state..............................................................................................................2
2.1.3 Installation scenario......................................................................................................3
2.1.4 Developer way..............................................................................................................4
3 Exit actions..................................................................................................................................6
3.1 Action string rules................................................................................................................6
4 Platform and/or TPM locked......................................................................................................6
1 Full disk encryption
1.1 Boot from local hard disk
1.1.1 Final disk structure
GPT S62 Part1 Part2 … PartN VeraCrypt loader part GPT
Open Encrypted Open
1.1.2 Installation scenario (It is proposal).
Create separate volume for VeraCrypt boot loader only. MS Windows loader and others starts
from encrypted volume.
Create and save S62 with master keys. (test phase)
disk_encryption_v1_2.odt 28 March 2017 1