45

PowerPoint Presentation · DHCP server Windows 8 client with Network Unlock Windows Server 2012 Computer boots DHCP request via the UEFI DHCP driver Returns IPv 4 address Vendor specific

  • Upload
    others

  • View
    5

  • Download
    0

Embed Size (px)

Citation preview

Page 1: PowerPoint Presentation · DHCP server Windows 8 client with Network Unlock Windows Server 2012 Computer boots DHCP request via the UEFI DHCP driver Returns IPv 4 address Vendor specific
Page 2: PowerPoint Presentation · DHCP server Windows 8 client with Network Unlock Windows Server 2012 Computer boots DHCP request via the UEFI DHCP driver Returns IPv 4 address Vendor specific
Page 3: PowerPoint Presentation · DHCP server Windows 8 client with Network Unlock Windows Server 2012 Computer boots DHCP request via the UEFI DHCP driver Returns IPv 4 address Vendor specific
Page 4: PowerPoint Presentation · DHCP server Windows 8 client with Network Unlock Windows Server 2012 Computer boots DHCP request via the UEFI DHCP driver Returns IPv 4 address Vendor specific
Page 5: PowerPoint Presentation · DHCP server Windows 8 client with Network Unlock Windows Server 2012 Computer boots DHCP request via the UEFI DHCP driver Returns IPv 4 address Vendor specific
Page 6: PowerPoint Presentation · DHCP server Windows 8 client with Network Unlock Windows Server 2012 Computer boots DHCP request via the UEFI DHCP driver Returns IPv 4 address Vendor specific
Page 7: PowerPoint Presentation · DHCP server Windows 8 client with Network Unlock Windows Server 2012 Computer boots DHCP request via the UEFI DHCP driver Returns IPv 4 address Vendor specific
Page 8: PowerPoint Presentation · DHCP server Windows 8 client with Network Unlock Windows Server 2012 Computer boots DHCP request via the UEFI DHCP driver Returns IPv 4 address Vendor specific
Page 9: PowerPoint Presentation · DHCP server Windows 8 client with Network Unlock Windows Server 2012 Computer boots DHCP request via the UEFI DHCP driver Returns IPv 4 address Vendor specific
Page 10: PowerPoint Presentation · DHCP server Windows 8 client with Network Unlock Windows Server 2012 Computer boots DHCP request via the UEFI DHCP driver Returns IPv 4 address Vendor specific
Page 12: PowerPoint Presentation · DHCP server Windows 8 client with Network Unlock Windows Server 2012 Computer boots DHCP request via the UEFI DHCP driver Returns IPv 4 address Vendor specific

On login screen

Powered offUser session

is open

M a ch i n e l i f e c yc l e

Page 13: PowerPoint Presentation · DHCP server Windows 8 client with Network Unlock Windows Server 2012 Computer boots DHCP request via the UEFI DHCP driver Returns IPv 4 address Vendor specific
Page 14: PowerPoint Presentation · DHCP server Windows 8 client with Network Unlock Windows Server 2012 Computer boots DHCP request via the UEFI DHCP driver Returns IPv 4 address Vendor specific

On login screen

Powered offUser session

is open

SysKey / BootKey

M a ch i n e l i f e c yc l e

Page 15: PowerPoint Presentation · DHCP server Windows 8 client with Network Unlock Windows Server 2012 Computer boots DHCP request via the UEFI DHCP driver Returns IPv 4 address Vendor specific

On login screen

Powered offUser session

is open

SysKey / BootKey

EFS

M a ch i n e l i f e c yc l e

Page 16: PowerPoint Presentation · DHCP server Windows 8 client with Network Unlock Windows Server 2012 Computer boots DHCP request via the UEFI DHCP driver Returns IPv 4 address Vendor specific

On login screen

Powered offUser session

is open

BitLocker

SysKey / BootKey

EFS

M a ch i n e l i f e c yc l e

Page 17: PowerPoint Presentation · DHCP server Windows 8 client with Network Unlock Windows Server 2012 Computer boots DHCP request via the UEFI DHCP driver Returns IPv 4 address Vendor specific
Page 18: PowerPoint Presentation · DHCP server Windows 8 client with Network Unlock Windows Server 2012 Computer boots DHCP request via the UEFI DHCP driver Returns IPv 4 address Vendor specific

On login screen

Powered offUser session

is open

BitLocker

SysKey / BootKey

EFS

DPAPI

M a ch i n e l i f e c yc l e

Page 19: PowerPoint Presentation · DHCP server Windows 8 client with Network Unlock Windows Server 2012 Computer boots DHCP request via the UEFI DHCP driver Returns IPv 4 address Vendor specific

On login screen

Powered offUser session

is open

BitLocker

SysKey / BootKey

EFS

DPAPI

LSASS

M a ch i n e l i f e c yc l e

Page 20: PowerPoint Presentation · DHCP server Windows 8 client with Network Unlock Windows Server 2012 Computer boots DHCP request via the UEFI DHCP driver Returns IPv 4 address Vendor specific

On login screen

Powered offUser session

is open

BitLocker

SysKey / BootKey

EFS

DPAPI

LSASS

.NET ProtectedMemory, ...

M a ch i n e l i f e c yc l e

Page 21: PowerPoint Presentation · DHCP server Windows 8 client with Network Unlock Windows Server 2012 Computer boots DHCP request via the UEFI DHCP driver Returns IPv 4 address Vendor specific
Page 22: PowerPoint Presentation · DHCP server Windows 8 client with Network Unlock Windows Server 2012 Computer boots DHCP request via the UEFI DHCP driver Returns IPv 4 address Vendor specific

On login screen

Powered offUser session

is open

BitLocker

SysKey / BootKey

EFS

DPAPI

LSASS

.NET ProtectedMemory, ...

CryptoAPI and CNG

M a ch i n e l i f e c yc l e

Page 23: PowerPoint Presentation · DHCP server Windows 8 client with Network Unlock Windows Server 2012 Computer boots DHCP request via the UEFI DHCP driver Returns IPv 4 address Vendor specific

On login screen

Powered offUser session

is open

BitLocker

SysKey / BootKey

EFS

DPAPI

LSASS

.NET ProtectedMemory, ...

Machine Key

CryptoAPI and CNG

M a ch i n e l i f e c yc l e

Page 24: PowerPoint Presentation · DHCP server Windows 8 client with Network Unlock Windows Server 2012 Computer boots DHCP request via the UEFI DHCP driver Returns IPv 4 address Vendor specific

On login screen

Powered offUser session

is open

BitLocker

SysKey / BootKey

EFS

DPAPI

LSASS

.NET ProtectedMemory, ...

Machine Key

CryptoAPI and CNG

SMB

M a ch i n e l i f e c yc l e

Page 25: PowerPoint Presentation · DHCP server Windows 8 client with Network Unlock Windows Server 2012 Computer boots DHCP request via the UEFI DHCP driver Returns IPv 4 address Vendor specific
Page 26: PowerPoint Presentation · DHCP server Windows 8 client with Network Unlock Windows Server 2012 Computer boots DHCP request via the UEFI DHCP driver Returns IPv 4 address Vendor specific

On login screen

Powered offUser session

is open

BitLocker

SysKey / BootKey

EFS

DPAPI

LSASS

.NET ProtectedMemory, ...

Machine Key

CryptoAPI and CNG

SMB

Group Policy Prefs

M a ch i n e l i f e c yc l e

Page 27: PowerPoint Presentation · DHCP server Windows 8 client with Network Unlock Windows Server 2012 Computer boots DHCP request via the UEFI DHCP driver Returns IPv 4 address Vendor specific

On login screen

Powered offUser session

is open

BitLocker

SysKey / BootKey

EFS

DPAPI

LSASS

.NET ProtectedMemory, ...

Machine Key

CryptoAPI and CNG

SMB

Schannel

Group Policy Prefs

M a ch i n e l i f e c yc l e

Page 28: PowerPoint Presentation · DHCP server Windows 8 client with Network Unlock Windows Server 2012 Computer boots DHCP request via the UEFI DHCP driver Returns IPv 4 address Vendor specific

On login screen

Powered offUser session

is open

BitLocker

SysKey / BootKey

EFS

DPAPI

LSASS

.NET ProtectedMemory, ...

Machine Key

CryptoAPI and CNG

SMB

Schannel

Group Policy Prefs

Windows CardSpace

M a ch i n e l i f e c yc l e

Page 29: PowerPoint Presentation · DHCP server Windows 8 client with Network Unlock Windows Server 2012 Computer boots DHCP request via the UEFI DHCP driver Returns IPv 4 address Vendor specific

On login screen

Powered offUser session

is open

BitLocker

SysKey / BootKey

EFS

DPAPI

LSASS

.NET ProtectedMemory, ...

Machine Key

CryptoAPI and CNG

SMB

Schannel

Group Policy Prefs

Windows CardSpace

M a ch i n e l i f e c yc l e

Page 30: PowerPoint Presentation · DHCP server Windows 8 client with Network Unlock Windows Server 2012 Computer boots DHCP request via the UEFI DHCP driver Returns IPv 4 address Vendor specific

On login screen

Powered offUser session

is open

BitLocker

SysKey / BootKey

EFS

DPAPI

LSASS

.NET ProtectedMemory, ...

Machine Key

CryptoAPI and CNG

SMB

Schannel

Group Policy Prefs

Windows CardSpace

M a ch i n e l i f e c yc l e

Page 31: PowerPoint Presentation · DHCP server Windows 8 client with Network Unlock Windows Server 2012 Computer boots DHCP request via the UEFI DHCP driver Returns IPv 4 address Vendor specific

On login screen

Powered offUser session

is open

BitLocker

SysKey / BootKey

EFS

DPAPI

LSASS

.NET ProtectedMemory, ...

Machine Key

CryptoAPI and CNG

SMB

Schannel

Group Policy Prefs

Windows CardSpace

M a ch i n e l i f e c yc l e

Page 32: PowerPoint Presentation · DHCP server Windows 8 client with Network Unlock Windows Server 2012 Computer boots DHCP request via the UEFI DHCP driver Returns IPv 4 address Vendor specific

Name TypeProtected

assets

Open

questions

Importance

for futureTotal Research Tools

Support for

recent versions?Total

Resulting

priorityRank

Windows Data Protection

API (DPAPI)OS 5 4 4 80 3 3 3 27 53 1

PrioritiesDescription Adding factors Diminushing factors

Page 33: PowerPoint Presentation · DHCP server Windows 8 client with Network Unlock Windows Server 2012 Computer boots DHCP request via the UEFI DHCP driver Returns IPv 4 address Vendor specific
Page 34: PowerPoint Presentation · DHCP server Windows 8 client with Network Unlock Windows Server 2012 Computer boots DHCP request via the UEFI DHCP driver Returns IPv 4 address Vendor specific
Page 35: PowerPoint Presentation · DHCP server Windows 8 client with Network Unlock Windows Server 2012 Computer boots DHCP request via the UEFI DHCP driver Returns IPv 4 address Vendor specific
Page 36: PowerPoint Presentation · DHCP server Windows 8 client with Network Unlock Windows Server 2012 Computer boots DHCP request via the UEFI DHCP driver Returns IPv 4 address Vendor specific
Page 37: PowerPoint Presentation · DHCP server Windows 8 client with Network Unlock Windows Server 2012 Computer boots DHCP request via the UEFI DHCP driver Returns IPv 4 address Vendor specific
Page 38: PowerPoint Presentation · DHCP server Windows 8 client with Network Unlock Windows Server 2012 Computer boots DHCP request via the UEFI DHCP driver Returns IPv 4 address Vendor specific

DHCP serverWindows 8 client with

Network Unlock

Windows Server 2012

Computer boots

DHCP request via the UEFI DHCP driver

Returns IPv4 address

Vendor specific DHCP broadcast containing a network and a session key.Both keys are encrypted using the public key of the network Unlock certificate.

Server recognises the request anddecrypts the message with its private key.

Server returns the network key encrypted with the session key via a specific DHCP reply

Decrypts the network key andstarts the computer if it matches

Page 39: PowerPoint Presentation · DHCP server Windows 8 client with Network Unlock Windows Server 2012 Computer boots DHCP request via the UEFI DHCP driver Returns IPv 4 address Vendor specific
Page 40: PowerPoint Presentation · DHCP server Windows 8 client with Network Unlock Windows Server 2012 Computer boots DHCP request via the UEFI DHCP driver Returns IPv 4 address Vendor specific
Page 42: PowerPoint Presentation · DHCP server Windows 8 client with Network Unlock Windows Server 2012 Computer boots DHCP request via the UEFI DHCP driver Returns IPv 4 address Vendor specific
Page 43: PowerPoint Presentation · DHCP server Windows 8 client with Network Unlock Windows Server 2012 Computer boots DHCP request via the UEFI DHCP driver Returns IPv 4 address Vendor specific
Page 44: PowerPoint Presentation · DHCP server Windows 8 client with Network Unlock Windows Server 2012 Computer boots DHCP request via the UEFI DHCP driver Returns IPv 4 address Vendor specific