TrueCrypt decryption key extraction method, terminal equipment and storage medium
The invention relates to a TrueCrypt decryption key extraction method, terminal equipment and a storage medium, and the method comprises the steps: firstly extracting all TrueCrypt.exe process information from a memory mirror image, and forming a process information set K; the method comprises the f...
Gespeichert in:
Hauptverfasser: | , , , |
---|---|
Format: | Patent |
Sprache: | chi ; eng |
Schlagworte: | |
Online-Zugang: | Volltext bestellen |
Tags: |
Tag hinzufügen
Keine Tags, Fügen Sie den ersten Tag hinzu!
|
container_end_page | |
---|---|
container_issue | |
container_start_page | |
container_title | |
container_volume | |
creator | SHAO BINGYANG SHEN CHANGDA LAN CHAOXIANG HUANG ZHIWEI |
description | The invention relates to a TrueCrypt decryption key extraction method, terminal equipment and a storage medium, and the method comprises the steps: firstly extracting all TrueCrypt.exe process information from a memory mirror image, and forming a process information set K; the method comprises the following steps of: firstly, checking content formats of a K2 field, a masterkeydata field and a SectorSize field in a CRYPTOINFO structure of each element in the K in sequence, and taking the content of the masterkeydata field of the residual elements in the K as a master key of a TrueCrypt.exe process after the elements which do not meet requirements are removed. The encryption mode of the encryption container needs to be depended on, the master key of the encryption data of the encryption container can be extracted without knowing the password of the encryption container, and meanwhile the requirement for decryption of the evidence source is met.
本发明涉及一种TrueCrypt解密密钥提取方法、终端设备及存储介质,该方法中,首先从内存镜像中提取所有TrueCrypt.exe进程 |
format | Patent |
fullrecord | <record><control><sourceid>epo_EVB</sourceid><recordid>TN_cdi_epo_espacenet_CN114372277A</recordid><sourceformat>XML</sourceformat><sourcesystem>PC</sourcesystem><sourcerecordid>CN114372277A</sourcerecordid><originalsourceid>FETCH-epo_espacenet_CN114372277A3</originalsourceid><addsrcrecordid>eNqNyrsKwjAYhuEuDqLew--uQ1shswTFSRC6l5B8amhzMPkD9u494AU4PbzwzqtLlwpkmiKTgf5og6cBE-HJSelvOvA9mA0xkrNejYRHsdHBMylvKHNI6ob3Zmxxy2p2VWPG6ueiWh8PnTxtEUOPHJWGB_fyXNe7VjSNEPv2n-cFOnw4Yw</addsrcrecordid><sourcetype>Open Access Repository</sourcetype><iscdi>true</iscdi><recordtype>patent</recordtype></control><display><type>patent</type><title>TrueCrypt decryption key extraction method, terminal equipment and storage medium</title><source>esp@cenet</source><creator>SHAO BINGYANG ; SHEN CHANGDA ; LAN CHAOXIANG ; HUANG ZHIWEI</creator><creatorcontrib>SHAO BINGYANG ; SHEN CHANGDA ; LAN CHAOXIANG ; HUANG ZHIWEI</creatorcontrib><description>The invention relates to a TrueCrypt decryption key extraction method, terminal equipment and a storage medium, and the method comprises the steps: firstly extracting all TrueCrypt.exe process information from a memory mirror image, and forming a process information set K; the method comprises the following steps of: firstly, checking content formats of a K2 field, a masterkeydata field and a SectorSize field in a CRYPTOINFO structure of each element in the K in sequence, and taking the content of the masterkeydata field of the residual elements in the K as a master key of a TrueCrypt.exe process after the elements which do not meet requirements are removed. The encryption mode of the encryption container needs to be depended on, the master key of the encryption data of the encryption container can be extracted without knowing the password of the encryption container, and meanwhile the requirement for decryption of the evidence source is met.
本发明涉及一种TrueCrypt解密密钥提取方法、终端设备及存储介质,该方法中,首先从内存镜像中提取所有TrueCrypt.exe进程</description><language>chi ; eng</language><subject>CALCULATING ; COMPUTING ; COUNTING ; ELECTRIC DIGITAL DATA PROCESSING ; PHYSICS</subject><creationdate>2022</creationdate><oa>free_for_read</oa><woscitedreferencessubscribed>false</woscitedreferencessubscribed></display><links><openurl>$$Topenurl_article</openurl><openurlfulltext>$$Topenurlfull_article</openurlfulltext><thumbnail>$$Tsyndetics_thumb_exl</thumbnail><linktohtml>$$Uhttps://worldwide.espacenet.com/publicationDetails/biblio?FT=D&date=20220419&DB=EPODOC&CC=CN&NR=114372277A$$EHTML$$P50$$Gepo$$Hfree_for_read</linktohtml><link.rule.ids>230,308,780,885,25563,76318</link.rule.ids><linktorsrc>$$Uhttps://worldwide.espacenet.com/publicationDetails/biblio?FT=D&date=20220419&DB=EPODOC&CC=CN&NR=114372277A$$EView_record_in_European_Patent_Office$$FView_record_in_$$GEuropean_Patent_Office$$Hfree_for_read</linktorsrc></links><search><creatorcontrib>SHAO BINGYANG</creatorcontrib><creatorcontrib>SHEN CHANGDA</creatorcontrib><creatorcontrib>LAN CHAOXIANG</creatorcontrib><creatorcontrib>HUANG ZHIWEI</creatorcontrib><title>TrueCrypt decryption key extraction method, terminal equipment and storage medium</title><description>The invention relates to a TrueCrypt decryption key extraction method, terminal equipment and a storage medium, and the method comprises the steps: firstly extracting all TrueCrypt.exe process information from a memory mirror image, and forming a process information set K; the method comprises the following steps of: firstly, checking content formats of a K2 field, a masterkeydata field and a SectorSize field in a CRYPTOINFO structure of each element in the K in sequence, and taking the content of the masterkeydata field of the residual elements in the K as a master key of a TrueCrypt.exe process after the elements which do not meet requirements are removed. The encryption mode of the encryption container needs to be depended on, the master key of the encryption data of the encryption container can be extracted without knowing the password of the encryption container, and meanwhile the requirement for decryption of the evidence source is met.
本发明涉及一种TrueCrypt解密密钥提取方法、终端设备及存储介质,该方法中,首先从内存镜像中提取所有TrueCrypt.exe进程</description><subject>CALCULATING</subject><subject>COMPUTING</subject><subject>COUNTING</subject><subject>ELECTRIC DIGITAL DATA PROCESSING</subject><subject>PHYSICS</subject><fulltext>true</fulltext><rsrctype>patent</rsrctype><creationdate>2022</creationdate><recordtype>patent</recordtype><sourceid>EVB</sourceid><recordid>eNqNyrsKwjAYhuEuDqLew--uQ1shswTFSRC6l5B8amhzMPkD9u494AU4PbzwzqtLlwpkmiKTgf5og6cBE-HJSelvOvA9mA0xkrNejYRHsdHBMylvKHNI6ob3Zmxxy2p2VWPG6ueiWh8PnTxtEUOPHJWGB_fyXNe7VjSNEPv2n-cFOnw4Yw</recordid><startdate>20220419</startdate><enddate>20220419</enddate><creator>SHAO BINGYANG</creator><creator>SHEN CHANGDA</creator><creator>LAN CHAOXIANG</creator><creator>HUANG ZHIWEI</creator><scope>EVB</scope></search><sort><creationdate>20220419</creationdate><title>TrueCrypt decryption key extraction method, terminal equipment and storage medium</title><author>SHAO BINGYANG ; SHEN CHANGDA ; LAN CHAOXIANG ; HUANG ZHIWEI</author></sort><facets><frbrtype>5</frbrtype><frbrgroupid>cdi_FETCH-epo_espacenet_CN114372277A3</frbrgroupid><rsrctype>patents</rsrctype><prefilter>patents</prefilter><language>chi ; eng</language><creationdate>2022</creationdate><topic>CALCULATING</topic><topic>COMPUTING</topic><topic>COUNTING</topic><topic>ELECTRIC DIGITAL DATA PROCESSING</topic><topic>PHYSICS</topic><toplevel>online_resources</toplevel><creatorcontrib>SHAO BINGYANG</creatorcontrib><creatorcontrib>SHEN CHANGDA</creatorcontrib><creatorcontrib>LAN CHAOXIANG</creatorcontrib><creatorcontrib>HUANG ZHIWEI</creatorcontrib><collection>esp@cenet</collection></facets><delivery><delcategory>Remote Search Resource</delcategory><fulltext>fulltext_linktorsrc</fulltext></delivery><addata><au>SHAO BINGYANG</au><au>SHEN CHANGDA</au><au>LAN CHAOXIANG</au><au>HUANG ZHIWEI</au><format>patent</format><genre>patent</genre><ristype>GEN</ristype><title>TrueCrypt decryption key extraction method, terminal equipment and storage medium</title><date>2022-04-19</date><risdate>2022</risdate><abstract>The invention relates to a TrueCrypt decryption key extraction method, terminal equipment and a storage medium, and the method comprises the steps: firstly extracting all TrueCrypt.exe process information from a memory mirror image, and forming a process information set K; the method comprises the following steps of: firstly, checking content formats of a K2 field, a masterkeydata field and a SectorSize field in a CRYPTOINFO structure of each element in the K in sequence, and taking the content of the masterkeydata field of the residual elements in the K as a master key of a TrueCrypt.exe process after the elements which do not meet requirements are removed. The encryption mode of the encryption container needs to be depended on, the master key of the encryption data of the encryption container can be extracted without knowing the password of the encryption container, and meanwhile the requirement for decryption of the evidence source is met.
本发明涉及一种TrueCrypt解密密钥提取方法、终端设备及存储介质,该方法中,首先从内存镜像中提取所有TrueCrypt.exe进程</abstract><oa>free_for_read</oa></addata></record> |
fulltext | fulltext_linktorsrc |
identifier | |
ispartof | |
issn | |
language | chi ; eng |
recordid | cdi_epo_espacenet_CN114372277A |
source | esp@cenet |
subjects | CALCULATING COMPUTING COUNTING ELECTRIC DIGITAL DATA PROCESSING PHYSICS |
title | TrueCrypt decryption key extraction method, terminal equipment and storage medium |
url | https://sfx.bib-bvb.de/sfx_tum?ctx_ver=Z39.88-2004&ctx_enc=info:ofi/enc:UTF-8&ctx_tim=2025-01-12T23%3A10%3A26IST&url_ver=Z39.88-2004&url_ctx_fmt=infofi/fmt:kev:mtx:ctx&rfr_id=info:sid/primo.exlibrisgroup.com:primo3-Article-epo_EVB&rft_val_fmt=info:ofi/fmt:kev:mtx:patent&rft.genre=patent&rft.au=SHAO%20BINGYANG&rft.date=2022-04-19&rft_id=info:doi/&rft_dat=%3Cepo_EVB%3ECN114372277A%3C/epo_EVB%3E%3Curl%3E%3C/url%3E&disable_directlink=true&sfx.directlink=off&sfx.report_link=0&rft_id=info:oai/&rft_id=info:pmid/&rfr_iscdi=true |