파일시스템
2011.03.17 13:41

$EFS Attribute

조회 수 1516 추천 수 0 댓글 0
?

단축키

Prev이전 문서

Next다음 문서

크게 작게 위로 아래로 댓글로 가기 인쇄 수정 삭제
?

단축키

Prev이전 문서

Next다음 문서

크게 작게 위로 아래로 댓글로 가기 인쇄 수정 삭제

$EFS Attribute

When NTFS encrypts file, it sets flag Encrypted (0x4000) for the file and creates $EFS attribute for the file where it stores DDFs and DDRs. This attribute has Attribute ID = 0x100 in NTFS and can be pretty lengthy, occupying from 0.5K to several kilobytes depending on number of DDFs and DRFs.

Here's an example of $EFS attribute with more details.

$EFS attribute size

Computer SID and user number. It specifies folder where EFS stores certificates. In order to get folder name EFS makes some manipulations:

5A56B378 1C365429 A851FF09 D040000 - data stored in $EFS,

78B3565A 2954361C 09FF15A8 000004D0 - reversed

2025018970-693384732-167712168-1232 - converte to decimal

S-1-5-21-2025018970-693384732-167712168-1232 - SID prefix added

So, the folder will be %User Profile%Application DataMicrosoftCryptoRSAS-1-5-21-2025018970-693384732-167712168-1232

Public key thumbprint

Private key GUID (also used as container name). This name EFS uses when it aquires context from CryptoAPI provider. If there's only one DDFin $EFS attribute, container name can be figured out from $EFS (this field), but as more users added to the file (more DDFs or DRFs), PK GUID is not stored for all of them and must be retrieved from certificate storage based on public key thumbprint.

Cryptographic provider name = Microsoft Base Cryptographic Provider v.1.0

User name, to whom current DDF or DRF belongs

Encrypted FEK. Usually FEK is 128-bit long (in case of DESX) but since it's encrypted with 1024-bit RSA key, its encrypted length is 1024 bits.

?

List of Articles
번호 분류 제목 글쓴이 날짜 조회 수
61 플래시메모리 USB메모리 master 2017.03.16 1063
60 Tri-backup 도입사례 9 admin 2014.12.12 156
59 Tri-backup 도입사례 8 admin 2014.12.12 133
58 Tri-backup 도입사례 7 admin 2014.12.12 128
57 Tri-backup 도입사례 6 admin 2014.12.12 127
56 Tri-backup 도입사례 5 admin 2014.12.12 129
55 Tri-backup 도입사례 4 admin 2014.12.12 124
54 Tri-backup 도입사례 2 admin 2014.12.12 136
53 Tri-backup 도입사례 10 admin 2014.12.12 177
52 Tri-backup 도입사례 1 admin 2014.12.12 161
51 Tr-Backup 도입사례 3 admin 2014.12.12 153
50 기타 SSD란 master 2017.03.14 1119
49 용산본사 SOLDERING WORKSTATION file master 2017.01.31 98
48 하드디스크 Seagate RS-232 adapter schematic admin 2011.03.16 1221
47 rom file admin 2008.11.20 237
46 ram file admin 2008.11.20 236
45 서버/레이드 RAID 1E admin 2011.03.30 1815
44 플래시메모리 Plextor PX-128M5PRO 128G SSD 복구 master 2017.03.28 528
43 pcb file admin 2008.11.20 233
42 기타 ONFI 란 admin 2013.06.28 2472
Board Pagination Prev 1 2 3 4 5 6 Next
/ 6