Kaspersky KryptoStorage is a system for the cryptographic protection of confidential data stored on PC from unauthorized access.
The application is intended to protect the user’s confidential data against unauthorized access and to prevent data leakage when the operating system saves system information to disk or when the user’s files are not wiped.
Transparent encryption is used to encrypt information.
The transparent encryption is a mechanism which enables the storage of information in the encrypted form inside of a protected object. The protected data is processed in the following way: the data is automatically decrypted in RAM when requested and the uploaded data is encrypted. Data is encrypted with the 128-bit AES algorithm. The algorithm is approved by the international cryptography community and represents a cryptographic standard. AES is approved by the U.S. National Institute of Standards and Technology (Standards and Technology (NIST) Federal Information Processing Standards (FIPS) PUB 197 26.11.2001).
The main functions of the application are listed below.
Protecting Data
With the application you can:
* create single protected NTFS virtual folders to store confidential data;
* create protected virtual volumes (the protected containers) to store confidential data;
* protect all data on disk volumes, including the system and the boot volumes, on Flash drives, and other USB Mass Storage devices;
The protection of system disk allows you to keep the following confidential:
* RAM contents which are saved to a hard disk when the system hibernates;
* crash dump data which is saved to a hard disk when a fatal error occurs;
* data of temporary files and swap files.
Handling protected data
With the application, you can:
* delimit access to protected information using password authorization;
* store protected objects inside other protected objects with any nesting depth;
* prevent accidental or intended deletion of protected objects by limiting access to these objects;
* use protected folders, containers and volumes which are located on the user’s computer;
* move protected objects together with the physical carrier to another computer where the application is installed. At the same time the objects can be used;
* wipe files and folders.