Skip to main content

NVME Opal Bitlocker drives

Thread needs solution

I would like to make use of my Self-Encrypting drive (Evo 970 plus). Does any have any experiences? Can I backup current windows installation, reinstall windows 10 just to enable bitlocker hardware encryption and then can I restore my backup version? So that I do not need to install all my apps and data files manually.

I know bitlocker creates small preboot partition for the purpose unlocking bitlocker. So I most likely can not restore full partitions. But if I do file restore, could it work?

If this is no way possible, it would be nice to have this feature added to ATI.

0 Users found this helpful

Jarmo, welcome to these public User Forums.

Assuming that you have Windows 10 Pro which includes BitLocker, then you simply need to enable this for your OS drive C: in the BitLocker Control Panel.  There is no need to do any restore - which wouldn't work as Acronis does not backup BitLocker encrypted drives where the encryption is locked!

As with any significant change, you should make a backup of the drive before starting.

Note: after encrypting the drive, you need to make Acronis rescue media with BitLocker support included and understand how to use this to manually unlock you drive from the WinPE offline environment.

I don't have any experience with Self-Encrypting drives. I don't know if there is anything that could be added to WinPE to make the drive unlock.

I can suggest removing the drive from the computer and connecting it to another computer with True Image installed in Windows. If the drive is unlocked, you can try restoring the entire drive from within Windows. Then see if it will work when put back in the original computer.

Thank you for your replies.

There is two kinds of bitlocker encryption methods: software which Steve descripes and which make things somewhat slower. The other is hardware OPAL encryption. Bitlocker implementation requires reinstalling windows.

Therefore it would be nice either of these options

- ATI implements sedutil feature (sedutil.com) in its preboot environment. That means ATI can activate OPAL, lock/unlock disk and set OPAL encryption password for the partition which is user enters at the boot time.

- ATI could restore from original non-OPAL windows system disk to new OPAL encrypted system disk where OPAL encryption is activated before old system is migrated to the disk. ATI should be able to handle slightly changed partition and boot process.

Jarmo,

I have found some interesting facts about Opal encryption that you and others need to be aware of. 

First, TCG Opal hardware based encryption can only be implemented on a Legacy MBR booted device.  Currently there exists a mechanism to do so on Linux and I am not sure about doing so on Windows at this  point.

Second, researchers at Radboud University have found that TCG Opal encryption on Samsung and Crucial SSD disks can be hacked relatively easily.  You can read about that at the link below:

TCG Opal Encryption hack

Enchantech: This is no longer relevant. There problems with Samsung and Crucial disks were solved long ago by firmware patches and newer drive models. OPAL is by far the best way to encrypt SSD drive.

It is also very simple. TCG Opal can be implement on every SSD supporting it in a computer with tpm module. 

Jarmo,

I understand about the tech and where it stands currently.  Your OP asks about restore of a True Image backup of files and folders to an TCG Opal hardware encrypted disk.  I have never performed or attempted such an exercise but my sense is that you could do that as long as the disk is unlocked. 

Hardware encryption is different than the software encryption offered by Bitlocker and others and does offer a performance advantage.  Having said all of that, support for encryption in True Image is provided by Acronis own encryption technique.  Bitlocker support is via command line only in the Recovery boot media.  There is no official Hardware encryption support in the True Image product at this time.