BitLocker, FileVault, dm-crypt, and TrueCrypt Encryption Key Crack via DRAM Cold Boot Attack with Program Source Code Download BitLocker的, FileVault ,德国马克,隐窝,并TrueCrypt加密密钥通过DRAM的裂缝冷开机攻击与计划源代码下载

A group of researchers in Princeton University have managed to prove and demonstrate that disk encryption mechanism used by BitLocker of Windows Vista; FileVault of MacOS X; dm-crypt of Linux, TrueCrypt and possibly other secure encryption software, can be cracked, hacked and defeated by imaging state of physical memory (DRAM modules) which still carry and retain traces of code bits, in what hackers called cold boot attack by dumping all data in memory to disk.一组研究人员在美国普林斯顿大学已成功地证明,表明磁盘加密机制,利用BitLocker的Windows Vista的; FileVault的MacOS下;德国马克,隐窝的Linux , TrueCrypt ,可能还有其他安全的加密软件,可以被破解,黑客入侵并打败由成像状态的物理内存( DRAM模块) ,其中仍保留痕迹的代码位,在什么所谓的黑客攻击冷启动倾倒所有的数据在内存到磁盘。

Princeton University Center for Information Technology Policy普林斯顿大学中心的信息技术政策 website网站 describes how the attack is possible:介绍了如何攻击是可能的:

Contrary to popular assumption, DRAMs used in most modern computers retain their contents for seconds to minutes after power is lost, even at operating temperatures and even if removed from a motherboard.相反,流行的假设,内存使用最现代化的电脑保留其内容秒后失去权力,甚至在工作温度,即使从主板。 Although DRAMs become less reliable when they are not refreshed, they are not immediately erased, and their contents persist sufficiently for malicious (or forensic) acquisition of usable full-system memory images.虽然内存变得不那么可靠时,他们没有更新,他们没有立即清除,并坚持其内容充分的恶意(或法医)购买实用全系统内存的图片。 We show that this phenomenon limits the ability of an operating system to protect cryptographic key material from an attacker with physical access.我们发现,这一现象限制了作业系统,以保护密钥材料从攻击者物理访问。 We use cold reboots to mount attacks on popular disk encryption systems - BitLocker, FileVault, dm-crypt, and TrueCrypt - using no special devices or materials.我们使用冷战重启发动攻击流行的磁盘加密系统-B itLocker的, F ileVault,德国马克,隐窝,并T rueCrypt-使用没有任何特殊设备或材料。 We experimentally characterize the extent and predictability of memory remanence and report that remanence times can be increased dramatically with simple techniques.实验的特点,我们的程度和可预见性的内存剩磁和报告说,剩磁时间可以大大增加简单的技术。 We offer new algorithms for finding cryptographic keys in memory images and for correcting errors caused by bit decay.我们提供了新的算法,找到密钥内存中的图像和改正错误所造成的衰变位。 Though we discuss several strategies for partially mitigating these risks, we know of no simple remedy that would eliminate them.虽然我们在讨论战略的若干部分减轻这些风险,我们知道,没有一个简单的补救措施,消除它们。

Video clip published by the team shows that it’s possible to remove a DIMM from one computer after power loss, transport and traffic the RAM module to another PC, aiding by a typical canned-air spray to lower its temperature to lengthen the time which the DIMM will keep the data, and then boot the computer unit using a specially designed microkernel, and finally dump all data on the RAM chip to physical disk.视频剪辑出版的球队表明,它可能把一个内存从一台计算机后,功率损耗,运输和交通的RAM模块到另一个电脑,帮助了一个典型的罐装空气喷雾降低温度,延长时间该内存将保留数据,然后启动计算机单位使用一个专门设计的微内核,并最终转储上的所有数据RAM芯片,以物理磁盘。 The amount of bad (decayed) data depended on both the time a DIMM spent unpowered and the temperature at which it was kept.数额坏(龋齿)的数据取决于双方的时间是DIMM花无动力和温度会上兑现。 Nonetheless, the researchers managed to successfully reconstruct 128-bit AES encryption keys within seconds, even if 10 percent of the key had already decayed out of memory.尽管如此,研究人员设法成功地重建的128位AES加密钥匙在几秒钟内,即使百分之十的关键已经腐烂的记忆。

The Princeton University team has also released the普林斯顿大学队也公布了 source code源代码 for some of the software utilities that is developed in the course of this research.对一些软件工具,这是发展过程中,这一研究成果。 These prototype applications are intended to illustrate the techniques described in the这些原型应用的目的是为了说明技术中描述 encryption keys cool boot attack加密密钥攻击凉爽开机 research paper, and should not be used for malicious or hacking attempt.研究论文,而不应被用于恶意或黑客企图。

The source code for applications released for free download include USB / PXE (源代码的应用推出免费下载包括配有USB / PXE技术( bios_memimage-1.0.tar.gz bios_memimage - 1.0.tar.gz ) and EFI Netboot ( )和电喷Netboot ( efi_memimage-1.0.tar.gz efi_memimage - 1.0.tar.gz ) memory imaging tools, AESKeyFinder ( )记忆体成像工具, AESKeyFinder ( aeskeyfind-1.0.tar.gz aeskeyfind - 1.0.tar.gz ) and RSAKeyFinder ( )和RSAKeyFinder ( rsakeyfind-1.0.tar.gz rsakeyfind - 1.0.tar.gz ) automatic key-finder tools, and AESFix ( )自动键查找工具,以及AESFix ( aesfix-1.0.1.tar.gz aesfix - 1.0.1.tar.gz ) error-correction utility for AES key schedules. )纠错工具, AES公司主要日程。

IMPORTANT : This is a machine translated page which is provided "as is" without warranty. 重要说明:这是一台机器翻译网页这是“原样”提供,无保修。 Machine translation may be difficult to understand.机器翻译可能很难理解。 Please refer to请参阅 original English article英文原文的文章 whenever possible.只要有可能。

Share and contribute or get technical support and help at共享和贡献或获得技术支持和帮助 My Digital Life Forums 我的数字生活论坛 .



One Response to “BitLocker, FileVault, dm-crypt, and TrueCrypt Encryption Key Crack via DRAM Cold Boot Attack with Program Source Code Download”一个响应的“ BitLocker的, FileVault ,德国马克,隐窝,并TrueCrypt加密密钥通过DRAM的裂缝冷开机攻击与计划源代码下载”

  1. Marcos Sartori马科斯萨托利
    July 24th, 2008 06:59 2008年七月24日6时59
    1

    The solution I think is putting the keys in the low-memory, so the keys are over written as the computer boots!该解决方案我认为这是把钥匙在低记忆体,所以把钥匙是在书面的计算机靴子!

    I really do not know how large the memory chunk has to be in order to record such key, though if 1/2 KB (512 Bytes) is enough, the adress where bios loades the MBR would be nice!我真的不知道如何大的内存块,必须以记录等关键,但如果1 / 2 kB的( 512字节)是不够的,地址在那里的BIOS loades的MBR将是太好了!

    Other neat places might be the adress of the BIOS IDT (Interrupt Description Table), as it’s not needed any longer as the kernel enters PMod!其他干净的地方可能是地址的BIOS的IDT (中断描述表) ,因为它不需要任何再为核心进入PMod !

Leave a Reply留下一个回复

You can use these tags: <a href="" title=""> <abbr title=""> <acronym title=""> <b> <blockquote cite=""> <cite> <code> <del datetime=""> <em> <i> <q cite=""> <strike> <strong> 您可以使用这些标签: href="" title="">的<a <abbr title=""> <acronym title="">的<b> <blockquote cite=""> <cite>的<code> “删除日期时间= “ ” “的<em> <i> <q cite=""> <strike>的<strong>

Subscribe without commenting订阅没有评论


Custom Search

New Articles新文章

Incoming Search Terms for the Article收到的搜索字词的文章

truecrypt crack truecrypt裂纹 - - crack truecrypt 裂纹truecrypt - - truecrypt vs FileVault truecrypt与FileVault - - cracking truecrypt 打击truecrypt - - brute force truecrypt 蛮力truecrypt - - truecrypt brute force truecrypt蛮力 - - dm-crypt 德国马克,隐窝 - - truecrypt cracker truecrypt饼干 - - truecrypt bruteforce truecrypt bruteforce - - bitlocker download BitLocker的下载 - - download bitlocker 下载BitLocker的 - - truecrypt vs bitlocker 与BitLocker的truecrypt - - key cracker 关键饼干 - - bitlocker crack BitLocker的裂纹 - - filevault vs truecrypt filevault与truecrypt - - truecrypt cold boot attack truecrypt冷开机攻击 - - bruteforce truecrypt bruteforce truecrypt - - truecrypt cracked truecrypt破获 - - truecrypt cracking truecrypt开裂 - - truecrypt attack truecrypt攻击 - - truecrypt bitlocker truecrypt BitLocker的 - - bitlocker vs truecrypt BitLocker的与truecrypt - - dm-crypt windows 德国马克,隐窝窗口 - - crack truecrypt password 裂纹truecrypt密码 - - dm-crypt vs truecrypt 德国马克,隐窝与truecrypt - - dmcrypt dmcrypt - - truecrypt password cracker truecrypt密码破解 - - crack bitlocker BitLocker的裂纹 - - aeskeyfind aeskeyfind - - filevault cracker filevault饼干 - - can truecrypt be cracked 可以truecrypt被破解 - - truecrypt cold boot truecrypt冷启动 - - crack filevault 裂纹filevault - - truecrypt vs truecrypt队 - - dm-crypt gui 德国马克,隐窝贵 - - truecrypt versus bitlocker 与BitLocker的truecrypt - - crack dm-crypt 裂纹马克,隐窝 - - dm-crypt truecrypt 德国马克,隐窝truecrypt - - encryption cracker 加密破解 - - encryption cracking princeton 加密破解普林斯顿 - - cracking bitlocker 破解BitLocker的 - - cracking truecrypt password 打击truecrypt密码 - - truecrypt password cracking truecrypt密码破解 - - BitLocker BitLocker的 - - lost bitlocker key 失去了BitLocker的关键 - - crack truecrypt disk 裂纹truecrypt磁盘 - - dm-crypt or truecrypt 德国马克,隐窝或truecrypt - - bitlocker lost key BitLocker的损失关键 - - truecrypt princeton truecrypt普林斯顿 - - crack windows mobile encryption 裂纹的Windows Mobile加密 - -