파일시스템
2011.03.17 13:41

$EFS Attribute

조회 수 1515 추천 수 0 댓글 0
?

단축키

Prev이전 문서

Next다음 문서

크게 작게 위로 아래로 댓글로 가기 인쇄 수정 삭제
?

단축키

Prev이전 문서

Next다음 문서

크게 작게 위로 아래로 댓글로 가기 인쇄 수정 삭제

$EFS Attribute

When NTFS encrypts file, it sets flag Encrypted (0x4000) for the file and creates $EFS attribute for the file where it stores DDFs and DDRs. This attribute has Attribute ID = 0x100 in NTFS and can be pretty lengthy, occupying from 0.5K to several kilobytes depending on number of DDFs and DRFs.

Here's an example of $EFS attribute with more details.

$EFS attribute size

Computer SID and user number. It specifies folder where EFS stores certificates. In order to get folder name EFS makes some manipulations:

5A56B378 1C365429 A851FF09 D040000 - data stored in $EFS,

78B3565A 2954361C 09FF15A8 000004D0 - reversed

2025018970-693384732-167712168-1232 - converte to decimal

S-1-5-21-2025018970-693384732-167712168-1232 - SID prefix added

So, the folder will be %User Profile%Application DataMicrosoftCryptoRSAS-1-5-21-2025018970-693384732-167712168-1232

Public key thumbprint

Private key GUID (also used as container name). This name EFS uses when it aquires context from CryptoAPI provider. If there's only one DDFin $EFS attribute, container name can be figured out from $EFS (this field), but as more users added to the file (more DDFs or DRFs), PK GUID is not stored for all of them and must be retrieved from certificate storage based on public key thumbprint.

Cryptographic provider name = Microsoft Base Cryptographic Provider v.1.0

User name, to whom current DDF or DRF belongs

Encrypted FEK. Usually FEK is 128-bit long (in case of DESX) but since it's encrypted with 1024-bit RSA key, its encrypted length is 1024 bits.

?

  1. NTFS Optimization

    Date2011.03.17 Category파일시스템 Byadmin Views9388
    Read More
  2. NTFS vs FAT

    Date2011.03.17 Category파일시스템 Byadmin Views4183
    Read More
  3. Data Integrity and Recoverability with NTFS

    Date2011.03.17 Category파일시스템 Byadmin Views1489
    Read More
  4. NTFS Sparse Files (NTFS5 only)

    Date2011.03.17 Category파일시스템 Byadmin Views1659
    Read More
  5. Issues with EFS

    Date2011.03.17 Category파일시스템 Byadmin Views1475
    Read More
  6. $EFS Attribute

    Date2011.03.17 Category파일시스템 Byadmin Views1515
    Read More
  7. EFS Internals

    Date2011.03.17 Category파일시스템 Byadmin Views112680
    Read More
  8. Using EFS

    Date2011.03.17 Category파일시스템 Byadmin Views1588
    Read More
  9. EFS - Encrypting File System

    Date2011.03.17 Category파일시스템 Byadmin Views1564
    Read More
  10. NTFS Compressed Files

    Date2011.03.17 Category파일시스템 Byadmin Views1480
    Read More
  11. NTFS Multiple Data Streams

    Date2011.03.17 Category파일시스템 Byadmin Views1389
    Read More
  12. NTFS 시스템 파일

    Date2011.03.17 Category파일시스템 Byadmin Views1560
    Read More
  13. NTFS 파일속성

    Date2011.03.17 Category파일시스템 Byadmin Views1313
    Read More
  14. NTFS MFT 분석

    Date2011.03.17 Category파일시스템 Byadmin Views1434
    Read More
  15. NTFS 파티션 부트섹터

    Date2011.03.17 Category파일시스템 Byadmin Views2072
    Read More
  16. NTFS 기초

    Date2011.03.17 Category파일시스템 Byadmin Views1087
    Read More
  17. 레이드란?

    Date2011.03.17 Category서버/레이드 Byadmin Views1077
    Read More
  18. 맥사용시 주요장애원인과 대처

    Date2011.03.17 Category매킨토시 Byadmin Views1532
    Read More
  19. ATA/ATAPI-5 — the fifth revision of the ATA standard released in 2000

    Date2011.03.16 Category하드디스크 Byadmin Views1163
    Read More
  20. ATA/ATAPI-6 — the sixth revision of the ATA standard released in 2001

    Date2011.03.16 Category하드디스크 Byadmin Views1103
    Read More
Board Pagination Prev 1 2 3 4 5 6 Next
/ 6