TrueCrypt decryption key extraction method, terminal equipment and storage medium

The invention relates to a TrueCrypt decryption key extraction method, terminal equipment and a storage medium, and the method comprises the steps: firstly extracting all TrueCrypt.exe process information from a memory mirror image, and forming a process information set K; the method comprises the f...

Ausführliche Beschreibung

Gespeichert in:
Bibliographische Detailangaben
Hauptverfasser: SHAO BINGYANG, SHEN CHANGDA, LAN CHAOXIANG, HUANG ZHIWEI
Format: Patent
Sprache:chi ; eng
Schlagworte:
Online-Zugang:Volltext bestellen
Tags: Tag hinzufügen
Keine Tags, Fügen Sie den ersten Tag hinzu!
container_end_page
container_issue
container_start_page
container_title
container_volume
creator SHAO BINGYANG
SHEN CHANGDA
LAN CHAOXIANG
HUANG ZHIWEI
description The invention relates to a TrueCrypt decryption key extraction method, terminal equipment and a storage medium, and the method comprises the steps: firstly extracting all TrueCrypt.exe process information from a memory mirror image, and forming a process information set K; the method comprises the following steps of: firstly, checking content formats of a K2 field, a masterkeydata field and a SectorSize field in a CRYPTOINFO structure of each element in the K in sequence, and taking the content of the masterkeydata field of the residual elements in the K as a master key of a TrueCrypt.exe process after the elements which do not meet requirements are removed. The encryption mode of the encryption container needs to be depended on, the master key of the encryption data of the encryption container can be extracted without knowing the password of the encryption container, and meanwhile the requirement for decryption of the evidence source is met. 本发明涉及一种TrueCrypt解密密钥提取方法、终端设备及存储介质,该方法中,首先从内存镜像中提取所有TrueCrypt.exe进程
format Patent
fullrecord <record><control><sourceid>epo_EVB</sourceid><recordid>TN_cdi_epo_espacenet_CN114372277A</recordid><sourceformat>XML</sourceformat><sourcesystem>PC</sourcesystem><sourcerecordid>CN114372277A</sourcerecordid><originalsourceid>FETCH-epo_espacenet_CN114372277A3</originalsourceid><addsrcrecordid>eNqNyrsKwjAYhuEuDqLew--uQ1shswTFSRC6l5B8amhzMPkD9u494AU4PbzwzqtLlwpkmiKTgf5og6cBE-HJSelvOvA9mA0xkrNejYRHsdHBMylvKHNI6ob3Zmxxy2p2VWPG6ueiWh8PnTxtEUOPHJWGB_fyXNe7VjSNEPv2n-cFOnw4Yw</addsrcrecordid><sourcetype>Open Access Repository</sourcetype><iscdi>true</iscdi><recordtype>patent</recordtype></control><display><type>patent</type><title>TrueCrypt decryption key extraction method, terminal equipment and storage medium</title><source>esp@cenet</source><creator>SHAO BINGYANG ; SHEN CHANGDA ; LAN CHAOXIANG ; HUANG ZHIWEI</creator><creatorcontrib>SHAO BINGYANG ; SHEN CHANGDA ; LAN CHAOXIANG ; HUANG ZHIWEI</creatorcontrib><description>The invention relates to a TrueCrypt decryption key extraction method, terminal equipment and a storage medium, and the method comprises the steps: firstly extracting all TrueCrypt.exe process information from a memory mirror image, and forming a process information set K; the method comprises the following steps of: firstly, checking content formats of a K2 field, a masterkeydata field and a SectorSize field in a CRYPTOINFO structure of each element in the K in sequence, and taking the content of the masterkeydata field of the residual elements in the K as a master key of a TrueCrypt.exe process after the elements which do not meet requirements are removed. The encryption mode of the encryption container needs to be depended on, the master key of the encryption data of the encryption container can be extracted without knowing the password of the encryption container, and meanwhile the requirement for decryption of the evidence source is met. 本发明涉及一种TrueCrypt解密密钥提取方法、终端设备及存储介质,该方法中,首先从内存镜像中提取所有TrueCrypt.exe进程</description><language>chi ; eng</language><subject>CALCULATING ; COMPUTING ; COUNTING ; ELECTRIC DIGITAL DATA PROCESSING ; PHYSICS</subject><creationdate>2022</creationdate><oa>free_for_read</oa><woscitedreferencessubscribed>false</woscitedreferencessubscribed></display><links><openurl>$$Topenurl_article</openurl><openurlfulltext>$$Topenurlfull_article</openurlfulltext><thumbnail>$$Tsyndetics_thumb_exl</thumbnail><linktohtml>$$Uhttps://worldwide.espacenet.com/publicationDetails/biblio?FT=D&amp;date=20220419&amp;DB=EPODOC&amp;CC=CN&amp;NR=114372277A$$EHTML$$P50$$Gepo$$Hfree_for_read</linktohtml><link.rule.ids>230,308,780,885,25563,76318</link.rule.ids><linktorsrc>$$Uhttps://worldwide.espacenet.com/publicationDetails/biblio?FT=D&amp;date=20220419&amp;DB=EPODOC&amp;CC=CN&amp;NR=114372277A$$EView_record_in_European_Patent_Office$$FView_record_in_$$GEuropean_Patent_Office$$Hfree_for_read</linktorsrc></links><search><creatorcontrib>SHAO BINGYANG</creatorcontrib><creatorcontrib>SHEN CHANGDA</creatorcontrib><creatorcontrib>LAN CHAOXIANG</creatorcontrib><creatorcontrib>HUANG ZHIWEI</creatorcontrib><title>TrueCrypt decryption key extraction method, terminal equipment and storage medium</title><description>The invention relates to a TrueCrypt decryption key extraction method, terminal equipment and a storage medium, and the method comprises the steps: firstly extracting all TrueCrypt.exe process information from a memory mirror image, and forming a process information set K; the method comprises the following steps of: firstly, checking content formats of a K2 field, a masterkeydata field and a SectorSize field in a CRYPTOINFO structure of each element in the K in sequence, and taking the content of the masterkeydata field of the residual elements in the K as a master key of a TrueCrypt.exe process after the elements which do not meet requirements are removed. The encryption mode of the encryption container needs to be depended on, the master key of the encryption data of the encryption container can be extracted without knowing the password of the encryption container, and meanwhile the requirement for decryption of the evidence source is met. 本发明涉及一种TrueCrypt解密密钥提取方法、终端设备及存储介质,该方法中,首先从内存镜像中提取所有TrueCrypt.exe进程</description><subject>CALCULATING</subject><subject>COMPUTING</subject><subject>COUNTING</subject><subject>ELECTRIC DIGITAL DATA PROCESSING</subject><subject>PHYSICS</subject><fulltext>true</fulltext><rsrctype>patent</rsrctype><creationdate>2022</creationdate><recordtype>patent</recordtype><sourceid>EVB</sourceid><recordid>eNqNyrsKwjAYhuEuDqLew--uQ1shswTFSRC6l5B8amhzMPkD9u494AU4PbzwzqtLlwpkmiKTgf5og6cBE-HJSelvOvA9mA0xkrNejYRHsdHBMylvKHNI6ob3Zmxxy2p2VWPG6ueiWh8PnTxtEUOPHJWGB_fyXNe7VjSNEPv2n-cFOnw4Yw</recordid><startdate>20220419</startdate><enddate>20220419</enddate><creator>SHAO BINGYANG</creator><creator>SHEN CHANGDA</creator><creator>LAN CHAOXIANG</creator><creator>HUANG ZHIWEI</creator><scope>EVB</scope></search><sort><creationdate>20220419</creationdate><title>TrueCrypt decryption key extraction method, terminal equipment and storage medium</title><author>SHAO BINGYANG ; SHEN CHANGDA ; LAN CHAOXIANG ; HUANG ZHIWEI</author></sort><facets><frbrtype>5</frbrtype><frbrgroupid>cdi_FETCH-epo_espacenet_CN114372277A3</frbrgroupid><rsrctype>patents</rsrctype><prefilter>patents</prefilter><language>chi ; eng</language><creationdate>2022</creationdate><topic>CALCULATING</topic><topic>COMPUTING</topic><topic>COUNTING</topic><topic>ELECTRIC DIGITAL DATA PROCESSING</topic><topic>PHYSICS</topic><toplevel>online_resources</toplevel><creatorcontrib>SHAO BINGYANG</creatorcontrib><creatorcontrib>SHEN CHANGDA</creatorcontrib><creatorcontrib>LAN CHAOXIANG</creatorcontrib><creatorcontrib>HUANG ZHIWEI</creatorcontrib><collection>esp@cenet</collection></facets><delivery><delcategory>Remote Search Resource</delcategory><fulltext>fulltext_linktorsrc</fulltext></delivery><addata><au>SHAO BINGYANG</au><au>SHEN CHANGDA</au><au>LAN CHAOXIANG</au><au>HUANG ZHIWEI</au><format>patent</format><genre>patent</genre><ristype>GEN</ristype><title>TrueCrypt decryption key extraction method, terminal equipment and storage medium</title><date>2022-04-19</date><risdate>2022</risdate><abstract>The invention relates to a TrueCrypt decryption key extraction method, terminal equipment and a storage medium, and the method comprises the steps: firstly extracting all TrueCrypt.exe process information from a memory mirror image, and forming a process information set K; the method comprises the following steps of: firstly, checking content formats of a K2 field, a masterkeydata field and a SectorSize field in a CRYPTOINFO structure of each element in the K in sequence, and taking the content of the masterkeydata field of the residual elements in the K as a master key of a TrueCrypt.exe process after the elements which do not meet requirements are removed. The encryption mode of the encryption container needs to be depended on, the master key of the encryption data of the encryption container can be extracted without knowing the password of the encryption container, and meanwhile the requirement for decryption of the evidence source is met. 本发明涉及一种TrueCrypt解密密钥提取方法、终端设备及存储介质,该方法中,首先从内存镜像中提取所有TrueCrypt.exe进程</abstract><oa>free_for_read</oa></addata></record>
fulltext fulltext_linktorsrc
identifier
ispartof
issn
language chi ; eng
recordid cdi_epo_espacenet_CN114372277A
source esp@cenet
subjects CALCULATING
COMPUTING
COUNTING
ELECTRIC DIGITAL DATA PROCESSING
PHYSICS
title TrueCrypt decryption key extraction method, terminal equipment and storage medium
url https://sfx.bib-bvb.de/sfx_tum?ctx_ver=Z39.88-2004&ctx_enc=info:ofi/enc:UTF-8&ctx_tim=2025-01-12T23%3A10%3A26IST&url_ver=Z39.88-2004&url_ctx_fmt=infofi/fmt:kev:mtx:ctx&rfr_id=info:sid/primo.exlibrisgroup.com:primo3-Article-epo_EVB&rft_val_fmt=info:ofi/fmt:kev:mtx:patent&rft.genre=patent&rft.au=SHAO%20BINGYANG&rft.date=2022-04-19&rft_id=info:doi/&rft_dat=%3Cepo_EVB%3ECN114372277A%3C/epo_EVB%3E%3Curl%3E%3C/url%3E&disable_directlink=true&sfx.directlink=off&sfx.report_link=0&rft_id=info:oai/&rft_id=info:pmid/&rfr_iscdi=true