<<

      

  

    

     

       

             

 

 On login User session Powered off screen is open Machine lifecycle   

  

   On login User session Powered off screen is open Machine lifecycle SysKey / BootKey On login User session Powered off screen is open Machine lifecycle SysKey / BootKey EFS On login User session Powered off screen is open Machine lifecycle SysKey / BootKey EFS

BitLocker  

 

  

  On login User session Powered off screen is open Machine lifecycle SysKey / BootKey EFS

BitLocker DPAPI On login User session Powered off screen is open Machine lifecycle SysKey / BootKey EFS

BitLocker DPAPI

LSASS On login User session Powered off screen is open Machine lifecycle SysKey / BootKey EFS

BitLocker DPAPI

LSASS .NET ProtectedMemory, ...  

  

   On login User session Powered off screen is open Machine lifecycle SysKey / BootKey EFS

BitLocker DPAPI

LSASS .NET ProtectedMemory, ... CryptoAPI and CNG On login User session Powered off screen is open Machine lifecycle SysKey / BootKey EFS

BitLocker DPAPI

LSASS .NET ProtectedMemory, ... CryptoAPI and CNG

Machine Key On login User session Powered off screen is open Machine lifecycle SysKey / BootKey EFS

BitLocker DPAPI

LSASS .NET ProtectedMemory, ... CryptoAPI and CNG

Machine Key SMB   

   

  On login User session Powered off screen is open Machine lifecycle SysKey / BootKey EFS

BitLocker DPAPI

LSASS .NET ProtectedMemory, ... CryptoAPI and CNG

Machine Key SMB

Group Policy Prefs On login User session Powered off screen is open Machine lifecycle SysKey / BootKey EFS

BitLocker DPAPI

LSASS .NET ProtectedMemory, ... CryptoAPI and CNG

Machine Key SMB

Group Policy Prefs

Schannel On login User session Powered off screen is open Machine lifecycle SysKey / BootKey EFS

BitLocker DPAPI

LSASS .NET ProtectedMemory, ... CryptoAPI and CNG

Machine Key SMB

Group Policy Prefs

Schannel

Windows CardSpace On login User session Powered off screen is open Machine lifecycle SysKey / BootKey EFS

BitLocker DPAPI

LSASS .NET ProtectedMemory, ... CryptoAPI and CNG

Machine Key SMB

Group Policy Prefs

Schannel

Windows CardSpace On login User session Powered off screen is open Machine lifecycle SysKey / BootKey EFS

BitLocker DPAPI

LSASS .NET ProtectedMemory, ... CryptoAPI and CNG

Machine Key SMB

Group Policy Prefs

Schannel

Windows CardSpace On login User session Powered off screen is open Machine lifecycle SysKey / BootKey EFS

BitLocker DPAPI

LSASS .NET ProtectedMemory, ... CryptoAPI and CNG

Machine Key SMB

Group Policy Prefs

Schannel

Windows CardSpace      

Description Adding factors Diminushing factors Priorities Protected Open Importance Support for Resulting Name Type Total Research Tools Total Rank assets questions for future recent versions? priority Windows Data Protection OS 5 4 4 80 3 3 3 27 53 1 API (DPAPI)

  

  

 

    

 

  

 

  

   

  Windows 8 Windows client with DHCP server 2012 Network Unlock

Computer boots

DHCP request via the UEFI DHCP driver Returns IPv4 address

Vendor specific DHCP broadcast containing a network and a session key. Both keys are encrypted using the public key of the network Unlock certificate.

Server recognises the request and decrypts the message with its private key.

Server returns the network key encrypted with the session key via a specific DHCP reply

Decrypts the network key and starts the computer if it matches  

 

 

 

  

 

  

 

  