Software Full Drive Encryption

Cigent Software Full Drive Encryption (SW FDE) safeguards sensitive data from power-off through system boot, aligning with the NSA CSfC DAR capability package requirements for the inner encryption layer.

Schedule a Demo

DAR Protection for Mission Data

Cigent Software FDE delivers the inner layer protection in the CSfC for DAR architecture, complementing hardware encryption and Pre-Boot Authentication (PBA). Built with separate quantum-resistant AES 256-bit cryptographic libraries and distinct key management, it provides independence from the outer protection layer and meets NSA guidance for layered, resilient encryption.

This software-based encryption operates after the outer hardware layer is unlocked, adding a second boundary with its own credentials and optional Multi-Factor Authentication (MFA). Cigent Software FDE scales across laptops, servers, vehicles, and edge devices, enabling agencies to maintain compliance and operational assurance wherever data resides.

Advanced Boot Protection

Cigent enforces authentication before the operating system loads, ensuring encryption keys remain isolated from OS-level vulnerabilities. This pre-boot protection prevents adversaries from exploiting compromised operating systems to gain access to encrypted data.

Multi-Factor Authentication

Access to encrypted drives can be configured to require smart cards, providing a true multi-factor model that requires both possession of the card and knowledge of the associated PIN. MFA ensures that only verified users can unlock and access sensitive data.

Administration at Scale

Cigent FDE can be deployed across large fleets using standard enterprise software-distribution tools. Administrators can preconfigure passwords, define authorized users, and enable self-enrollment through MSI installation flags, simplifying rollout without requiring a separate management console.

Extensive Platform Coverage

Cigent Software Full Drive Encryption supports systems across PCs, mobile workstations, and servers from leading OEM platforms, including Dell, Getac, Panasonic, and others. It also extends protection to non-traditional compute environments, including vehicles, unmanned systems (UxV), and industrial control systems (ICS).

Cigent Protection

Understanding CSfC for DAR Protection

Hardware Full Drive Encryption (HW FDE) combined with PBA. This is the outer layer of the dual-layer encryption approach mandated by the Commercial Solutions for Classified (CSfC) Data-at-Rest (DAR) program and provides the first layer of defense. It includes:

  • AES-256 Hardware Full Drive Encryption
    Utilizing NSA-validated cryptography. Encryption keys are not stored in TPM or in aggregate, preventing interception or compromise.
  • Pre-Boot Authentication (PBA)
    Providing a separate and secure environment to unlock drive encryption, PBA prevents an adversary from compromising the OS to access data.

How Cigent FDE Protects your Data

Cigent Software Full Disk Encryption safeguards sensitive data from power-off through system boot. Cigent SW FDE operates independently of the hardware and protects data at rest with strong cryptographic controls and multi-factor authentication.

  • Power-Off Protection
    When the device is powered off, all data on the drive remains encrypted and unreadable.
  • Boot-Time Enforcement
    Upon power-on, the SW FDE requires authentication before the operating system loads, enforcing access control before any data is decrypted.
  • Two-Factor Access Control
    Access to encrypted data can be configured to require smart card authentication, combining possession of a physical credential with PIN-based verification.
  • Transparent Data Access
    After authentication, encryption runs transparently. Data is decrypted when accessed and encrypted when written, without impacting the user experience.

The Cigent Advantage

Cigent solutions were designed and developed with and for US Intelligence and Defense communities. All employees, including Cigent software development, are based in the US. The team includes multiple personnel with TS/SCI clearance with decades of data protection and operational experience to support your requirements.

Cigent solutions have been tested and validated by leading Federal agencies including MITRE, NIST, NSA, NIAP, the Air Force, Cyber Resilience of Weapon Systems (CROWS), and NSSIF (UK) and are deployed across US Intelligence agencies, US Defense services, and the defense industrial base.

eBook

Protect Your Data at Rest

Cigent is prepared to support your mission, navigating the complex compliance requirements to protect data at the edge. Its solutions were developed for and with US Federal agencies with deep expertise in data protection. Read our extensive eBook to learn more.

The Latest from Cigent

View All

Frequently Asked Questions

Still have Questions?

Learn how to secure mission-critical and classified data across the battlespace.

Download eBook

Cigent’s Federal Data Protection Solutions are second to none

Learn more about how Cigent can help you achieve your mission and protect data at rest and data on the edge from all forms of attack.

Schedule a Demo