Acronis vmProtect 8 FIPS140-2 Certified?
I would like to know if when I choose the option to enable a password and encrypt my archive with AES 192 bit encryption if I can tell my auditors that Acronis is FIP140-2 certified.

- Log in to post comments


Hi Sajan,
From what I have discovered the FIPS 140-2 certification implies special testing by a certified lab where modules of the program are verified. We have not yet submitted our AES encryption modules for such validation and thus we cannot say officially that it is FIPS 140-2 compliant. Here are some details of our implementation which might be useful:
The AES cryptographic algorithm operates in the Cipher-block chaining (CBC) mode and uses a randomly generated key with a user-defined size of 128, 192 or 256 bits. The larger the key size, the longer it will take for the program to encrypt the archive and the more secure your data will be.
The encryption key is then encrypted with AES-256 using a SHA-256 hash of the password as a key. The password itself is not stored anywhere on the disk or in the backup file; the password hash is used for verification purposes. With this two-level security, the backup data is protected from any unauthorized access, but recovering a lost password is not possible.
Thank you.
--
Best regards,
Vasily
Acronis vmProtect Program Manager
- Log in to post comments