Bitlocker encrypted partition data damage recovery method, electronic equipment and computer program product
Through the method of searching and decrypting the keys in the full disk, the number of backup blocks of the Bitlocker encrypted partition is determined and the recovery operation is performed, which solves the problem of Bitlocker encrypted data corruption and cannot be restored, and improves data recovery efficiency.
Patent Information
- Application Number
- CN202510085816.7
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Priority Date
- 2024-12-30
- Filing Date
- 2025-01-20
- Publication Date
- 2025-05-30
AI Technical Summary
When Bitlocker encrypted data is damaged or corrupted, it cannot be effectively restored, resulting in the loss of private data in the user partition.
Obtain Bitlocker data block information through a full disk search, parse the remaining Bitlocker data blocks at the start bit of the disk, traverse the decryption key, determine the number of backup blocks in the encrypted partition, and perform recovery operations according to the policy.
Improve the efficiency of data corruption recovery of Bitlocker encrypted partitions, ensure reliable data recovery, and solve the problem of data loss.
Smart Images

Figure BDA0005250113360000071 
Figure BDA0005250113360000081 
Figure BDA0005250113360000091
Abstract
Description
Technical Field
[0001] This application relates to the field of data recovery and computer forensics security, and particularly to a method for recovering damaged BitLocker encrypted partition data, an electronic device, and a computer program product. Background Art
[0002] BitLocker is a full-disk data encryption mechanism introduced in Windows operating systems since VISTA, aiming to protect users' private data to address data leakage issues. BitLocker uses a hierarchical key approach to encrypt data on the disk and can use different encryption algorithms to encrypt intermediate keys, including: passwords, recovery keys, startup keys, TPM, domain SIDs, etc.
[0003] BitLocker can borrow TPM to help protect the Windows operating system and user data. TPM is a microchip built into the computer. TPM is usually installed on the motherboard of a desktop computer or a portable computer and communicates with the rest of the system through a hardware bus. It is used to store encrypted information such as encryption keys. Information stored on the TPM is more secure, avoiding external software attacks and physical theft. BitLocker can also be used without TPM. To use BitLocker on a computer without TPM, the default behavior of the BitLocker setup wizard must be changed by using group policies or BitLocker must be configured by using a script. Store the required encryption key in an external encrypted drive and use the drive to unlock the data stored on the volume.
[0004] BitLocker can effectively protect users' private data. However, once the BitLocker encrypted data is damaged or destroyed, such as by accidental formatting operations, etc., it often leads to the complete loss of all private data in the user partition and cannot be decrypted and recovered. Summary of the Invention
[0005] This application provides a method for recovering damaged BitLocker encrypted partition data, an electronic device, a computer storage medium, and a computer program product, which are used to improve the retrieval efficiency of data.
[0006] In a first aspect, this application provides a method for recovering damaged BitLocker encrypted partition data. In combination with some embodiments of the first aspect, in some embodiments, it includes:
[0007] Select a target disk, obtain the sector size of the target disk, and perform a full-disk search according to the set search keyword;
[0008] Perform start bit determination based on the results of the full-disk search, parse and obtain the Bitlocker data block information remaining in the disk start bit according to the determination result, and add the Bitlocker data block information as an element to the predefined set M;
[0009] Traverse the decryption set M, decrypt the element Mi in the set M according to the decryption password input by the user and obtain the Bitlocker key FVEK. If decryption fails, discard the element Mi, add the key FVEK as an element to the predefined set M', and continue to decrypt the next element Mi+1 until the entire set M is traversed;
[0010] Traverse and parse the set M', parse the elements in the set M', determine the number of backup blocks of the Bitlocker encrypted partition, and perform a recovery operation according to the number of backup blocks of the Bitlocker encrypted partition and the corresponding policy. If it is determined that the set M' is empty, the recovery process ends.
[0011] The performing start bit determination based on the results of the full-disk search and parsing the Bitlocker data block information remaining in the disk start bit according to the determination result includes:
[0012] For the position hit_offset corresponding to the results of the full-disk search, if hit_offset % SECTOR_SIZE == 0, there is Bitlocker data block information remaining at the position hit_offset, and parse and obtain the Bitlocker data block information.
[0013] The attributes in the predefined sets M and M' include: the start offset start_offset of the encryption / decryption metadata block on the disk, the encrypted volume size volume_size, the start position metablock_offset1 of the encrypted volume metadata block 1, the start position metablock_offset2 of the encrypted volume metadata block 2, the start position metablock_offset3 of the encrypted volume metadata block 3, and the encrypted Bitlocker decryption key FVEKbitlocker_vmk.
[0014] The parsing the elements in the set M' and determining the number of backup blocks of the Bitlocker encrypted partition includes:
[0015] Analyze the element M’i in the parsing set M’, obtain the corresponding key FVEKi, continue the analysis, and judge the element M’i+1 in the parsing set M’. Perform a consistency check on the key FVEKi+1 corresponding to M’i+1 and the key FVEKi corresponding to M’i. If they are consistent, they are regarded as a set of backup keys for the same Bitlocker encrypted partition; then continue to judge the next element M’i+2, and repeat the above comparison process until the judgment fails.
[0016] Determine the number of backup blocks of the Bitlocker encrypted partition according to the above judgment result.
[0017] The performing a recovery operation according to the number of backup blocks of the Bitlocker encrypted partition and the corresponding policy includes:
[0018] When the number of backup blocks of the Bitlocker encrypted partition is 3, calculate the starting partition offset address of the Bitlocker encrypted partition. The partition starting offset address is M1.start_offset - M1.metablock_offsetN, where M1 is the first element in this calculation stage and N is the minimum value of the metadata backup block.
[0019] When the number of backup blocks of the Bitlocker encrypted partition is 2, and the backup blocks are M1 and M2 respectively, the calculation method is as follows:
[0020] For M1, calculate M1.start_offset - M1.metablock_offset1, M1.start_offset - M1.metablock_offset2, M1.start_offset - M1.metablock_offset3;
[0021] For M2, calculate M2.start_offset - M2.metablock_offset1, M2.start_offset - M2.metablock_offset2, M2.start_offset - M2.metablock_offset3;
[0022] Calculate the starting partition offset address of the Bitlocker encrypted partition according to the above two sets of calculation results.
[0023] When the number of backup blocks of the Bitlocker encrypted partition is 1, calculate M1.start_offset - M1.metablock_offset1, M1.start_offset - M1.metablock_offset2, and M1.start_offset - M1.metablock_offset3 according to element M1, and calculate the starting position offset address of the Bitlocker encrypted partition based on the above three sets of results.
[0024] Finally, use the key FVEK to decrypt the area of size M1.volume_size starting from the partition starting offset address and store it as the recovered image.
[0025] In a second aspect, an embodiment of the present application provides an electronic device, which includes: one or more processors and a memory; the memory is coupled to the one or more processors, and the memory is used to store computer program code, and the computer program code includes computer instructions, and the one or more processors call the computer instructions to cause the electronic device to execute the method described in the first aspect and any possible implementation manner in the first aspect.
[0026] In a third aspect, an embodiment of the present application provides a computer-readable storage medium, including instructions, when the above instructions run on an electronic device, causing the above electronic device to execute the method described in the first aspect and any possible implementation manner in the first aspect.
[0027] In a fourth aspect, an embodiment of the present application provides a computer program product, when the above computer program product runs on an electronic device, causing the electronic device to execute the method described in the first aspect and any possible implementation manner in the first aspect.
[0028] The present application conducts in-depth research on the VMK structure and the Bitlocker data encryption logic, and proposes a method for searching for the Bitlocker decryption key based on in-memory data. This method can scan all valid Bitlocker encryption keys in the memory and is actually used for data decryption, solving the forensics problem. Description of the Drawings
[0029] Figure 1 is the algorithm flowchart of the BITLOCKER encryption process;
[0030] Figure 2 is the disk structure diagram of the encrypted BITLOCKER encrypted partition;
[0031] Figure 3 is the flowchart of the method for recovering damaged data in the Bitlocker encrypted partition. Detailed implementation manners
[0032] In order to make the objectives, technical solutions and advantages of the present application clearer and more understandable, the following further detailed descriptions will be made in conjunction with specific solutions.
[0033] The terms used in the following embodiments of the present application are only for the purpose of describing specific embodiments, and are not intended to limit the present application. As used in the specification and appended claims of the present application, the singular forms "a", "an", "the", "above-mentioned", "said", and "this" are also intended to include the plural forms, unless the context clearly indicates otherwise. It should also be understood that the term "and / or" used in the present application refers to any or all possible combinations including one or more of the listed items.
[0034] Hereinafter, the terms "first" and "second" are only used for descriptive purposes, and cannot be construed as implying or suggesting relative importance or implicitly indicating the quantity of the indicated technical features. Thus, the features defined with "first" and "second" may explicitly or implicitly include one or more of such features. In the description of the embodiments of the present application, unless otherwise specified, the meaning of "a plurality" is two or more.
[0035] In the present application, the VMK key of Bitlocker drive encryption is the abbreviation of Volume Master Key. In the encryption process of Bitlocker, the FVEK key used to encrypt the original disk data is also stored on the encrypted disk. In order to prevent unauthorized access to the FVEK key, Bitlocker uses the volume master key (VMK key) to encrypt the FVEK key. In the hierarchical key management of Bitlocker disk drive encryption, the VMK key belongs to the second layer of encryption key.
[0036] Bitlocker provides multiple encryption mechanisms to encrypt the VMK key, and one or more ciphertext data of the VMK key after different encryption methods are stored in the encrypted data volume.
[0037] The algorithm description of the BITLOCKER encryption process is as Figure 1 shown:
[0038] (1) Encrypt the original data with the FVEK encryption key. In the process of data protection, first use the full volume encryption key (FVEK) to encrypt the original data. The FVEK is generated during the Bitlocker encryption process, which ensures the security and integrity of the data when stored. By encrypting the original data, users can effectively prevent unauthorized access and thus protect sensitive information from being leaked.
[0039] (2) Encrypt the FVEK key using the VMK encryption key and store the encrypted ciphertext on the encrypted disk. The volume master key (VMK) is used to encrypt the FVEK. The VMK is an intermediate key that is responsible for protecting the FVEK so that the original data can be securely accessed when needed. The encrypted FVEK ciphertext is stored on the encrypted disk. In this way, even if the physical medium is stolen, attackers cannot easily access the data because they need to decrypt the VMK to obtain the FVEK.
[0040] (3) Encrypt the VMK key using the password entered by the user or the recovery key and store the encrypted ciphertext on the encrypted disk. The system requires the user to enter a password or use a recovery key to encrypt the VMK. This step ensures that only authorized users can access the VMK, thereby indirectly protecting the FVEK and the original data. The encrypted VMK ciphertext is also stored on the encrypted disk, providing a multi-level protection mechanism for data security. In this way, even if the user forgets the password, the recovery key can be used as a security measure to restore access rights.
[0041] When Bitlocker enables encryption, the starting part of the encrypted partition is used to store the Bitlocker encrypted volume header and the metadata information related to encryption and decryption. Although Bitlocker Drive Encryption implements full-disk data encryption services, in the actual encrypted data, the Bitlocker encrypted volume header (FVE VOLUME HEADER) and the encryption and decryption metadata block information (META BLOCK) are still stored in plain text. The structure diagram of the encrypted BITLOCKER encrypted partition disk is as follows Figure 2 as shown.
[0042] The structure definition and schematic values of the Bitlocker encrypted volume header (FVE VOLUME HEADER) are shown in Table 1-1.
[0043] Table 1-1
[0044]
[0045]
[0046] The Bitlocker encryption and decryption metadata block information (META BLOCK) stores encrypted keys such as the VMK and FVEK. In the Bitlocker encrypted drive, three backups are saved. The specific structure definition is shown in Table 1-2.
[0047] Table 1-2
[0048]
[0049] This application aims to recover damaged partitions and defines two related sets of information for this purpose. The first set M represents the Bitlocker encryption / decryption metadata block information retrieved from the disk. This set can be defined using mathematical set notation, i.e.:
[0050] Set M = {M1, M2, M3,..., Mn}
[0051] Each element Mi here represents an independent metadata block and contains some key attributes.
[0052] Specifically, each element Mi in the set contains the following attributes:
[0053] start_offset: This is the starting offset of the encryption / decryption metadata block on the disk. It indicates the position of the metadata block in the disk file system and is usually expressed in bytes.
[0054] volume_size: This attribute represents the size of the encrypted volume. It defines the space occupied by the entire encrypted volume and is also usually in bytes.
[0055] metablock_offset1: This is the starting position of the first metadata block in the encrypted volume. This position is crucial for the decryption process as it points to the information stored in the metadata block.
[0056] metablock_offset2: Similar to the first metadata block, this is the starting position of the second metadata block in the encrypted volume. It may contain different or supplementary information from the first metadata block.
[0057] metablock_offset3: This is the starting position of the third metadata block in the encrypted volume. This position is also important and may be used to store additional metadata or configuration information.
[0058] bitlocker_vmk: This is the encrypted Bitlocker decryption key, i.e., FVEK (Full Volume Encryption Key). This key is crucial for recovering and decrypting the data of the encrypted volume.
[0059] The second set represents the set of encrypted volume header information searched from the disk, i.e.:
[0060] The set V = {V1, V2, V3, …, Vn}, where V is a data structure and each element Vi in it represents the header information of an encrypted volume. This header information is searched from the disk and may be used to recover or analyze the data of the encrypted volume. Each element Vi in the set contains the following attributes:
[0061] start_offset:
[0062] Definition: It represents the starting offset of the encrypted volume header on the disk.
[0063] Function: This value indicates the specific position of the encrypted volume header on the physical disk, facilitating subsequent data reading and processing.
[0064] backup_sector:
[0065] Definition: It represents the backup sector number of the encrypted volume.
[0066] Function: The backup sector can be used to recover data or as redundant information in case the main sector is damaged.
[0067] bitlocker_guid:
[0068] Definition: This is a globally unique identifier (GUID) used to identify a specific Bitlocker encrypted volume.
[0069] Function: Through the GUID, different encrypted volumes can be uniquely identified and managed, avoiding confusion.
[0070] metablock_offset1, metablock_offset2, metablock_offset3:
[0071] Definition: These attributes represent the starting positions of different encrypted volume metadata blocks.
[0072] Function: The metadata block contains important information related to the encrypted volume (such as keys, status, etc.). These offsets indicate how to locate these metadata blocks, facilitating the access and decryption processes.
[0073] The set V provides the necessary information for processing and analyzing encrypted volumes through the attributes of its respective elements. This information is not only used to identify and locate encrypted data but also supports data recovery and security management. Among them, both the set V and the set M are sorted in ascending order by the size of start_offset.
[0074] In this embodiment, the method for recovering damaged Bitlocker encrypted partition data is as follows:
[0075] Step S1: The user needs to specify a target disk as the object of operation, obtain the sector size SECTOR_SIZE of the target disk. The sector size is the basic unit for data storage on the disk, usually 512 bytes or 4096 bytes. Set the search keyword as -FVE-FS-, and perform a full-disk search. By setting this keyword, the system can locate metadata or information blocks related to Bitlocker encrypted volumes during the full-disk search; jump to Step S2.
[0076] Step S2: For the search result position hit_offset, if hit_offset % SECTOR_SIZE == 0, this condition checks whether hit_offset is an integer multiple of the sector size. In the disk, data is usually aligned by sectors. If hit_offset is an integer multiple of the sector size, it means this position is a legal sector start position and may contain valid data. Therefore, when the condition holds, there is Bitlocker encryption / decryption metadata block information remaining at the current hit_offset position on the disk. Then, parse the Bitlocker encryption / decryption metadata block information. The parsed content includes encryption / decryption keys, volume information, status, etc., which are key information related to Bitlocker encryption; add the above key information to the Bitlocker encryption / decryption metadata block set M for subsequent recovery use; otherwise, discard the result; jump to Step S3; Through the verification and parsing of the search results in Step S2, it is ensured that only valid Bitlocker encryption / decryption metadata block information is collected into set M. This process is an important link in the data recovery process, which can effectively improve the accuracy and reliability of subsequent operations.
[0077] Step S3: The user needs to provide a password or recovery key for decryption. As described in the above BITLOCKER encryption process algorithm, this decryption password or recovery key is a security credential set by the user to protect the encrypted volume. Receive the decryption password or recovery key of the Bitlocker encrypted partition input by the user, and decrypt any element Mi in the Bitlocker encryption / decryption metadata block set M searched in Step S2, and determine whether the user's password or key information can decrypt effectively. If not, discard the element Mi. If it can, add the obtained FVEK of Bitlocker and related information of the metadata block after decryption to the new Bitlocker encryption / decryption metadata block set M', and jump to Step S4.
[0078] Step S4: For the Bitlocker encryption / decryption metadata block information set M' obtained in Step S3, if the set M' is not empty, jump to Step S5; otherwise, this recovery process method ends.
[0079] Step S5: parse the element M'i in the set M', obtain the corresponding key FVEKi, continue parsing, judge the element M'i+1 in the parsed set M', and make a consistency judgment on the key FVEKi+1 corresponding to M'i+1 and the key FVEKi corresponding to M'i. If they are consistent, they are regarded as a set of backup keys for the same Bitlocker encrypted partition; then continue to judge the next element M'i+2, and repeat the above comparison process until the judgment fails. Determine the number of backup metadata blocks of the Bitlocker encrypted partition based on the above judgment results. Jump to step S6.
[0080] Step S6: For the result obtained in step S5 and the Bitlocker metadata structure, refer to the above Table 1-1 and Table 1-2. There are 3 metadata backup blocks in total. Therefore, the number of backup metadata blocks of the same group of Bitlocker encrypted partitions can only be 3, 2, and 1. 3 means that all three backup blocks exist; 2 means that one of the backup blocks is overwritten by other data; 1 means that two of the backup blocks are overwritten by other data. If there are 3, jump to step S7; if there are 2, jump to step S9; if there is 1, jump to step S11.
[0081] Step S7: When all three backup blocks exist, the starting partition offset address of the Bitlocker encrypted partition is calculated. Assuming that the three elements are M1, Mi and Mj, the calculation formula is as follows:
[0082] Starting partition offset address = 1.start_offset-M1.metablock_offsetN, where M1.start_offset is the starting offset address of the first backup block, M1.metablock_offsetN is the metadata block offset address associated with the backup block, and N is the minimum value in the metadata backup block. This means that the minimum value of the metadata block offset address in the three backup blocks needs to be found during calculation, and this value is subtracted from the starting offset address of M1. Jump to step S8.
[0083] Step S8: Use FVEK to decrypt the area of M1.volume_size from the partition start offset address and store the restored image; at this point, the decryption and recovery process of this group of damaged Bitlocker is completed; remove the current Bitlocker encrypted metadata block and jump to step S4;
[0084] Step S9: When one of the backup blocks is overwritten by other data, assuming that the elements of the Bitlocker metadata block in this group are M1 and Mi, six groups of offsets are calculated. The calculation method is as follows:
[0085] For M1,
[0086] M1.start_offset - M1.metablock_offset1,
[0087] M1.start_offset - M1.metablock_offset2,
[0088] M1.start_offset - M1.metablock_offset3;
[0089] For Mi,
[0090] Mi.start_offset - Mi.metablock_offset1,
[0091] Mi.start_offset - Mi.metablock_offset2,
[0092] Mi.start_offset - Mi.metablock_offset3; where M1.start_offset is the starting offset address of the first backup block, M1.metablock_offset1, M1.metablock_offset2, M1.metablock_offset3 are the metadata block offset addresses related to the backup block; Mi.start_offset is the starting offset address of the second backup block, and Mi.metablock_offset1, Mi.metablock_offset2, Mi.metablock_offset3 are the metadata block offset addresses related to this backup block. After the calculation, jump to step S10;
[0093] Step S10: Obtain the two sets of results calculated in step S9. Among them, the values with equal calculation results are the starting offset addresses of the partitions of this group of Bitlocker encrypted partitions, and then jump to step S8;
[0094] Step S11: If two of the backup blocks are overwritten by other data, the calculation method is as follows:
[0095] M1.start_offset - M1.metablock_offset1,
[0096] M1.start_offset - M1.metablock_offset2,
[0097] M1.start_offset - M1.metablock_offset3,
[0098] According to the above, three groups of possible starting position offset addresses of the BitLocker encrypted partition are obtained. For each group of partition starting position offset addresses, attempts are made to decrypt and recover, and jump to step S8.
[0099] The above embodiments can scan all valid BitLocker encryption keys in the memory and actually use them for data decryption, solving the problem of forensic evidence collection.
[0100] In the above embodiments, they can be implemented in whole or in part by software, hardware, firmware, or any combination thereof. When implemented using software, they can be implemented in whole or in part in the form of a computer program product. The computer program product includes one or more computer instructions. When the computer program instructions are loaded and executed on a computer, the processes or functions described in the embodiments of the present application are generated in whole or in part. The computer can be a general-purpose computer, a special-purpose computer, a computer network, or other programmable devices. The computer instructions can be stored in a computer-readable storage medium, or transmitted from one computer-readable storage medium to another computer-readable storage medium. For example, the computer instructions can be transmitted from one website, computer, server, or data center to another website, computer, server, or data center in a wired (such as coaxial cable, optical fiber, digital subscriber line) or wireless (such as infrared, wireless, microwave, etc.) manner. The computer-readable storage medium can be any available medium that the computer can access or a data storage device such as a server or data center that includes one or more integrated available media. The available medium can be a magnetic medium (such as a floppy disk, hard disk, magnetic tape), an optical medium (such as a DVD), or a semiconductor medium (such as a solid-state drive), etc.
[0101] Those of ordinary skill in the art can understand all or part of the processes in the methods of the above embodiments. These processes can be completed by relevant hardware instructed by a computer program. The program can be stored in a computer-readable storage medium. When the program is executed, it can include the processes of the above method embodiments. The aforementioned storage medium includes: ROM or random access memory RAM, magnetic disks, or optical discs and other media that can store program codes.
[0102] The above are the preferred embodiments of the present application. It does not limit the protection scope of the present application accordingly. Therefore, all equivalent changes made according to the structure, shape, and principle of the present application should be covered within the protection scope of the present application.
Claims
1. A method for recovering damaged data from a Bitlocker encrypted partition, characterized by: Select a target disk, obtain the sector size of the target disk, and perform a full disk search according to a set search keyword; Performing a start position judgment according to the result of the full disk search, parsing and obtaining the Bitlocker data block information remaining at the start position of the disk according to the judgment result, and adding the Bitlocker data block information as an element to a predefined set M; Traverse the decryption set M, decrypt the element Mi in the set M according to the decryption password entered by the user and obtain the Bitlocker key FVEK. If decryption is not possible, discard the element Mi, add the key FVEK as an element to the predefined set M', and continue to decrypt the next element Mi+1 until the entire set M is traversed; Traverse the parsing set M', parse the elements in the set M', determine the number of backup blocks of the Bitlocker encrypted partition, perform a recovery operation according to the number of backup blocks of the Bitlocker encrypted partition and the corresponding policy, and if it is determined that the set M' is empty, the recovery process ends.
2. A method for recovering damaged data from a Bitlocker encrypted partition according to claim 1, characterized in that: The performing of starting position determination according to the result of the full disk search and parsing the Bitlocker data block information remaining at the starting position of the disk according to the determination result comprises: For the position hit_offset corresponding to the result of the full disk search, if hit_offset%SECTOR_SIZE==0, the position hit_offset has Bitlocker data block information remaining, and the Bitlocker data block information is obtained by parsing.
3. A method for recovering damaged data from a Bitlocker encrypted partition according to claim 2, characterized in that: The attributes in the predefined sets M and M' include: the starting offset start_offset of the encryption and decryption metadata block on the disk, the encrypted volume size volume_size, the starting position metablock_offset1 of the encrypted volume metadata block 1, the starting position metablock_offset2 of the encrypted volume metadata block 2, the starting position metablock_offset3 of the encrypted volume metadata block 3, and the encrypted Bitlocker decryption key FVEKbitlocker_vmk.
4. A method for recovering damaged data from a Bitlocker encrypted partition according to claim 1, characterized in that: The parsing of the elements in the set M' to determine the number of backup blocks of the Bitlocker encrypted partition includes: Parse the element M'i in the set M', obtain the corresponding key FVEKi, continue parsing, judge the element M'i+1 in the parsed set M', and make a consistency judgment on the key FVEKi+1 corresponding to M'i+1 and the key FVEKi corresponding to M'i. If they are consistent, they are regarded as a set of backup keys for the same Bitlocker encrypted partition; then continue to judge the next element M'i+2, and repeat the above comparison process until the judgment fails. The number of backup blocks of the Bitlocker encrypted partition is determined based on the above determination result.
5. A method for recovering damaged data from a Bitlocker encrypted partition according to claim 4, characterized in that: The performing of the recovery operation according to the number of backup blocks of the Bitlocker encrypted partition and the corresponding strategy comprises: When the number of backup blocks of the Bitlocker encrypted partition is 3, the starting partition offset address of the Bitlocker encrypted partition is calculated, and the partition starting offset address is M1.start_offset-M1.metablock_offsetN, where M1 is the first element of the calculation stage and N is the minimum value of the metadata backup block.
6. A method for recovering damaged data from a Bitlocker encrypted partition according to claim 4, characterized in that: The performing of the recovery operation according to the number of backup blocks of the Bitlocker encrypted partition and the corresponding strategy comprises: When the number of backup blocks of the Bitlocker encrypted partition is 2, and the backup blocks are M1 and M2 respectively, the calculation method is as follows: For M1, calculate M1.start_offset-M1.metablock_offset1, M1.start_offset-M1.metablock_offset2, M1.start_offset-M1.metablock_offset3; For M2, calculate M2.start_offset-M2.metablock_offset1, M2.start_offset-M2.metablock_offset2, M2.start_offset-M2.metablock_offset3; The partition start offset address of the Bitlocker encrypted partition is calculated based on the above two sets of calculation results.
7. A method for recovering damaged data from a Bitlocker encrypted partition according to claim 4, characterized in that: The performing of the recovery operation according to the number of backup blocks of the Bitlocker encrypted partition and the corresponding strategy comprises: When the number of backup blocks of the Bitlocker encrypted partition is 1, M1.start_offset-M1.metablock_offset1, M1.start_offset-M1.metablock_offset2, and M1.start_offset-M1.metablock_offset3 are calculated according to element M1, and the starting position offset address of the Bitlocker encrypted partition is calculated according to the above three groups of results.
8. A method for recovering damaged data in a Bitlocker encrypted partition according to any one of claims 5 to 7, characterized in that: Using the key FVEK, the area of M1.volume_size is decrypted starting from the partition start offset address and stored as the restored image.
9. An electronic device, characterized in that: The electronic device comprises: one or more processors and a memory; the memory is coupled to the one or more processors, the memory is used to store computer program code, the computer program code comprises computer instructions, and the one or more processors call the computer instructions to enable the electronic device to execute the Bitlocker encrypted partition data damage recovery method as described in any one of claims 1-8.
10. A computer program product, characterized in that When the computer program product is run on an electronic device, the electronic device is enabled to execute the Bitlocker encrypted partition data damage recovery method as described in any one of claims 1 to 8.