Technical Support Technical Support
SafenSoft
Solutions chevron-down
Products chevron-down
Projects chevron-down
Partners chevron-down
About us chevron-down

SoftControl DeCrypt

SoftControl DeCrypt provides full disk encryption for ATM hard drives, preventing the information stored on the drive from being used to compromise self-service devices or banking systems.
Trial version

Overview

SoftControl DeCrypt is a full disk encryption solution that generates the decryption key based on the hardware configuration of the device and its connected peripherals.

The solution protects ATMs against the following attack scenarios:

  • Bypassing endpoint protection by deleting security-related files from an offline hard drive after booting from external media.
  • Reverse engineering ATM software from a stolen hard drive to prepare targeted attacks.
  • Using a stolen hard drive to attack the payment processing infrastructure by exploiting certificates for connecting to payment application servers and other sensitive information stored on the drive.

Features

Hardware binding

Encryption keys are generated based on the parameters of the system hardware and connected peripheral devices.

Fast decryption

The system partition is decrypted automatically before the operating system starts.

Manual password entry

If critical hardware configuration changes are detected, the encrypted partition can be unlocked using a recovery password defined during encryption.

Device blacklists

Specific devices can be excluded from key generation if they require an extended initialization time.

Strong encryption

AES-256 encryption provides a 256-bit encryption key and 14 encryption rounds for maximum protection.

Remote management and monitoring

The centralized management server provides remote administration and event monitoring, including operating system startup events, recovery password usage, and other security events.

Using parameters of system hardware and connected peripheral (USB) devices as encryption and decryption key components eliminates the operational limitations typical of self-service terminal, including ATMs, payment kiosks, and information kiosks:

  • No possibility for local password entry during system startup.
  • Inability to use the device's TPM (Trusted Platform Module) for storing the disk decryption key. Writing encryption keys to the TPM may overwrite certificates required by specialized ATM hardware (cash dispenser, cash acceptor, PIN pad, card reader), resulting in device malfunction.

Why SoftControl DeCrypt

  • Russian-developed solution included in the Unified Register of Russian Software (Entry No. 19585, dated October 17, 2023).
  • Client module available for both Windows and Linux operating systems.
  • Proven reliability through extensive enterprise deployments, penetration testing, and security audits.
  • Part of the integrated SafenSoft security platform, providing comprehensive protection and centralized event monitoring.
  • Technical support with SLA.

Pilot project

SafenSoft offers product evaluations and pilot projects to validate that SoftControl DeCrypt meets the customer's technical and security requirements. Pilot deployments are performed within the customer's infrastructure and typically run for at least one month, continuing until the solution is ready for full-scale deployment. During the pilot project, customer specialists receive training under the SafenSoft Certified Engineer program and are awarded a personalized certification upon successful completion.

Trial version