TeraMail File Encryption Control for TeraKey
Authentication and Administrative Control for TeraKey Users
TeraMail provides the authenticated user and administrative control interface used by the TeraKey application.
When TeraKey is running on a Windows computer, TeraMail operates within the TeraKey application frame. It verifies the user's identity with the TeraCryption service and provides TeraKey with the authenticated user, Company, Group, session, and permission information required to determine whether encryption and decryption functions can be enabled.
Logging into TeraMail does not automatically give someone the ability to use TeraKey encryption on that computer—even if that person is an authorized TeraKey user on another computer.
Two Different Roles — User Verification and Administrative Control
TeraMail performs two distinct functions when working with TeraKey.
For the TeraKey User
TeraMail authenticates the person using the computer and provides verified information to TeraKey as part of the authorization process for encryption and decryption.
For the TeraKey Administrator
TeraMail provides the administrative interface for creating users and Groups, assigning permissions, controlling TeraKey installation authorization, managing security options, and configuring how authorized users work with encrypted files.
How TeraMail Verifies a TeraKey User
When a user starts TeraKey, TeraMail requests the user's username and private password and verifies those credentials with the TeraCryption service.
If two-factor verification has been enabled by the administrator, TeraCryption also sends a verification code to the user's registered phone or email. After successful verification, TeraMail opens within the TeraKey application frame.
But successful TeraMail authentication is only one part of the TeraKey authorization process.
The User Must Also Match the TeraKey Installation
TeraKey verifies whether the user currently authenticated through TeraMail is the same authorized user whose credentials were established when TeraKey was installed on that computer.
If a different person signs into TeraMail, that person can still use TeraMail for authorized message communications.
TeraKey encryption and decryption, however, remain disabled.
The My TeraKey and Share Group folders also do not appear in Windows Explorer.
This remains true even if the person signing in is an authorized TeraKey user on another computer.
Being a TeraKey user does not automatically authorize a person to use TeraKey encryption on every computer where TeraKey is installed.
More Than a Username and Password
After the user has been verified, TeraMail creates a session ID that becomes part of the process used to obtain authorization to encrypt and decrypt files. TeraMail also provides TeraKey with the authenticated Company, Group, and User identification obtained from the TeraCryption service. These additional values provide another level of verification designed to prevent unauthorized or fraudulent requests from attempting to use TeraKey encryption or decryption without a valid authenticated TeraMail session.
What TeraKey Receives From the Authenticated Session
Verified User Identity
Identifies the authenticated TeraKey user.
Company Identity
Associates the user with the authorized company environment.
Group Information
Identifies the security Groups associated with the authenticated user.
Session Identification
Provides session information used as part of the authorization process for encryption and decryption.
User Permissions
Determines which TeraKey functions the authenticated user is permitted to perform.
TeraMail therefore does more than provide a login screen.
It establishes the authenticated control session used by TeraKey to determine whether its protected file functions can be made available to the user.
TeraMail Provides the TeraKey Administrator Control Console
TeraMail also provides the administrative interface used to configure the TeraKey security environment.
An administrator must successfully complete the required identity verification before TeraMail makes its security administration functions available.
Once authenticated as an administrator, TeraMail provides access to the Users and Groups administration areas used to create users, establish Groups, assign users to those Groups, and configure granular permissions governing the use of encrypted files.
Control Users and Groups
The administrator determines which users belong to which security Groups.
TeraMail provides a graphical Group-management interface that allows the administrator to assign users to Groups using drag-and-drop actions.
This allows the company's TeraKey environment to reflect departments, projects, customers, confidential work areas, or other organizational security requirements.
Control File Permissions
TeraMail provides the administrator with the user table and the permissions used to manage how authorized users work with encrypted files.
For example, the administrator can determine whether a user is permitted to become the owner of encrypted files.
The administrator therefore controls not simply who can authenticate, but the security permissions assigned to each authorized user.
Control Where TeraKey Can Be Installed
Being an authorized TeraKey user does not automatically give a person permission to install and use TeraKey on another computer.
The administrator controls TeraKey installation authorization.
For example, an employee may be authorized to install and use TeraKey on a company desktop computer but not be authorized to install TeraKey on a home computer unless the administrator specifically permits it in the user's TeraMail record.
The administrator can also control installation of TeraKey Client applications. If a TeraKey Client user uninstalls the application and later attempts to reinstall it, administrator approval can be required before the reinstallation is permitted.
User authorization and computer authorization are separate controls.
Protect Unattended TeraKey Sessions
The administrator can control whether TeraMail remains logged in after a period of mouse inactivity.
Automatic logout can be used to help prevent another person from using an authenticated TeraMail/TeraKey session when the authorized user leaves the computer unattended.
This gives the organization another administrative control over how authenticated TeraKey sessions are maintained.
Control TeraKey Cloud Storage Options
TeraMail also provides administrative control over TeraKey cloud-storage options.
Depending on the organization's configuration, the administrator can control options including:
My TeraKey Cloud Storage
Allow the My TeraKey folder to be stored in the cloud so encrypted files can be restored if the local folder is lost or becomes unavailable.
Shared Group Cloud Storage
Store shared encrypted files in cloud-based Group folders.
Previous Encrypted File Management
Control whether previous encrypted files are moved to the trash when newer files are saved.
These options allow the administrator to configure how TeraKey users interact with the organization's authorized storage environment.
TeraMail Connects Identity, Permissions and TeraKey
TeraMail for TeraKey brings user authentication and administrative security controls together within the TeraKey environment.
For the user, TeraMail establishes the authenticated session and provides the verified identity, Company, Group, session, and permission information used by TeraKey.
For the administrator, TeraMail provides the control interface for managing users, Groups, permissions, installation authorization, session behavior, and storage options.
The result is a clear separation between three things:
-
Being able to log into TeraMail.
-
Being authorized to use TeraKey on a particular computer.
-
Being permitted to perform specific TeraKey functions.
Only when the required identity and authorization conditions are satisfied are the corresponding TeraKey functions made available.
