Unlock instant, AI-driven research and patent intelligence for your innovation.

A method for offline parsing of dpapi encrypted data

An encrypted data, offline technology, applied in the field of data encryption and decryption, can solve the problems of data cannot be decrypted, the read-only of evidence is destroyed, and DPAPI encrypted data cannot be decrypted.

Active Publication Date: 2017-01-04
XIAMEN MEIYA PICO INFORMATION
View PDF3 Cites 1 Cited by
  • Summary
  • Abstract
  • Description
  • Claims
  • Application Information

AI Technical Summary

Problems solved by technology

This method directly depends on the target source operating system. If the system is damaged and cannot be started, the data cannot be decrypted, and the data source is easily polluted during the operation, destroying the read-only nature of the evidence.
[0004] In addition, although there is a domestic patent that proposes the decryption of DPAPI encrypted data in the user storage area, this method can analyze the encrypted data at the user account level, but it needs to know the SID and plaintext password corresponding to the user login account in advance, otherwise it cannot be decrypted. The method is only for the encrypted data in the DPAPI user storage area, and cannot decrypt the DPAPI encrypted data in the system storage area, that is, the local system level.

Method used

the structure of the environmentally friendly knitted fabric provided by the present invention; figure 2 Flow chart of the yarn wrapping machine for environmentally friendly knitted fabrics and storage devices; image 3 Is the parameter map of the yarn covering machine
View more

Image

Smart Image Click on the blue labels to locate them in the text.
Viewing Examples
Smart Image
  • A method for offline parsing of dpapi encrypted data
  • A method for offline parsing of dpapi encrypted data
  • A method for offline parsing of dpapi encrypted data

Examples

Experimental program
Comparison scheme
Effect test

Embodiment Construction

[0009] In order to describe the technical content, structural features, achieved goals and effects of the present invention in detail, the following will be described in detail in conjunction with the embodiments and accompanying drawings.

[0010] One. The abbreviations and key terms involved in the present invention are defined and explained:

[0011] DPAPI: (Data Protection Application Programming Interface)

[0012] Encryption function CryptProtectData: encryption interface provided by Microsoft Windows operating system;

[0013] Decryption function CryptUnprotectData: the decryption interface provided by Microsoft Windows operating system;

[0014] DPAPI encryption block: data encrypted with the encryption function CryptProtectData;

[0015] Pbkdf2 operation: an encryption algorithm based on iterative complexity to ensure password security (Password-BasedKey Derivation Function2), first of all, it needs to select a traditional encryption algorithm, usually a one-way has...

the structure of the environmentally friendly knitted fabric provided by the present invention; figure 2 Flow chart of the yarn wrapping machine for environmentally friendly knitted fabrics and storage devices; image 3 Is the parameter map of the yarn covering machine
Login to View More

PUM

No PUM Login to View More

Abstract

The invention discloses a method of off-line analyzing DPAPI (Data Protection Application Programming Interface) enciphered data. The method comprises the steps that S1, equipment data source to be analyzed is loaded, and a disk Windows operating system partition of the equipment data source to be analyzed is determined; S2, a system account master key file, a System file and a Security file are obtained; S3, a DPAPI encryption block of a file to be decoded is obtained by scanning a DPAPI encryption block characteristic value; S4, the System file and the Security file are analyzed to obtain a Pbkdf2 secret key cleartext; S5, key information needed for decoding the system account master key file is obtained, and a master key cleartext is obtained by using a Pbkdf2 secret key to decode the system account master key file; S6, data cleartext is obtained by using a master key to decode the DPAPI encryption block. The method of off-line analyzing the DPAPI enciphered data has the beneficial effects that an operating system where a target data source is located is not relied on, a user name and a password of a computer are not needed to be known, the decryption is performed on enciphered data of a DPAPI system storage region, and the requirements of read only operation and cross-platform decryption on evidence sources are met.

Description

technical field [0001] The invention relates to the field of data encryption and decryption, in particular to a method for offline analysis of DPAPI encrypted data. Background technique [0002] The Windows operating system of Microsoft Corporation in the United States is currently the most popular PC operating system, and its data security has always attracted much attention. Starting from Windows 2000, Microsoft has provided a set of easy-to-use system-level data protection interfaces (DataProtection Application Programming Interface, or DPAPI, including the encryption function CryptProtectData and the decryption function CryptUnprotectData), providing data protection services for applications and operating systems. The salient feature of this group of interfaces is that the encryption and decryption operations must be performed on the same computer, and the key generation, storage and use are completed within the operating system, eliminating the management of application...

Claims

the structure of the environmentally friendly knitted fabric provided by the present invention; figure 2 Flow chart of the yarn wrapping machine for environmentally friendly knitted fabrics and storage devices; image 3 Is the parameter map of the yarn covering machine
Login to View More

Application Information

Patent Timeline
no application Login to View More
Patent Type & Authority Patents(China)
IPC IPC(8): H04L29/06H04L9/06
Inventor 苏再添吴少华林艺滨
Owner XIAMEN MEIYA PICO INFORMATION