Windows Vista Forums
Vista Forums Home Join Vista Forums Windows 7 Forum Vista Tutorials Tags
Welcome to Windows Vista Forums. Our forum is dedicated to helping you find solutions with any problems, errors or issues you are experiencing with Windows Vista. The Vista forum also covers news and updates and has an extensive Windows Vista tutorial section that covers a wide range of tips and tricks.

Go Back   Vista Forums > Vista Newsgroups > Vista security

Vista - Vista: Multiple Startup Keys on one USB flash drive

Reply
 
Old 06-22-2006   #1 (permalink)
tavis


 
 

Vista: Multiple Startup Keys on one USB flash drive

If I have several startup keys (.FVE files) for different Vista machines on
one USB flash drive, how does each machine know which one is correct? Is the
filename recorded somewhere in the unencypted portion of the drive? Or does
it simple try all the possible .FVE files until it finds the lucky winner?

Thanks,

My System SpecsSystem Spec
Old 06-23-2006   #2 (permalink)
Jamie Hunter [MS]


 
 

Re: Vista: Multiple Startup Keys on one USB flash drive

Good question

There are a number of layers to the answer.
(1) The filename uses a GUID. Each key protector (refer to WMI interface) is
referenced by a GUID, these are the same GUID.
(2) The structure of the binary file contains both the GUID of the encrypted
volume and the GUID of the key protector.
(3) When decrypting the VMK, AES/CCM is used with 256-bit AES key. This is
an industry standard algorithm, that contains a nonce and a MAC (message
authentication check). If the startup key was wrong, then the MAC part of
the AES/CCM algorithm detects this and causes a failure.
(4) Should 1-3 fail, then the data would be decrypted incorrectly into
gibberish Thankfully 1-3 prevents (4).
-
Jamie Hunter [MS]

"tavis" <tavis@discussions.microsoft.com> wrote in message
news:8911F7D1-4300-4CFF-9421-CDF98F3ED857@microsoft.com...
> If I have several startup keys (.FVE files) for different Vista machines
> on
> one USB flash drive, how does each machine know which one is correct? Is
> the
> filename recorded somewhere in the unencypted portion of the drive? Or
> does
> it simple try all the possible .FVE files until it finds the lucky winner?
>
> Thanks,


My System SpecsSystem Spec
Old 07-11-2006   #3 (permalink)
=?Utf-8?B?dGF2aXM=?=


 
 

Re: Vista: Multiple Startup Keys on one USB flash drive

Thanks again, Jamie.

I must give credit to my very inquisitive and bright colleagues for these
questions.
;-)

"Jamie Hunter [MS]" wrote:

> Good question
>
> There are a number of layers to the answer.
> (1) The filename uses a GUID. Each key protector (refer to WMI interface) is
> referenced by a GUID, these are the same GUID.
> (2) The structure of the binary file contains both the GUID of the encrypted
> volume and the GUID of the key protector.
> (3) When decrypting the VMK, AES/CCM is used with 256-bit AES key. This is
> an industry standard algorithm, that contains a nonce and a MAC (message
> authentication check). If the startup key was wrong, then the MAC part of
> the AES/CCM algorithm detects this and causes a failure.
> (4) Should 1-3 fail, then the data would be decrypted incorrectly into
> gibberish Thankfully 1-3 prevents (4).
> -
> Jamie Hunter [MS]
>
> "tavis" <tavis@discussions.microsoft.com> wrote in message
> news:8911F7D1-4300-4CFF-9421-CDF98F3ED857@microsoft.com...
> > If I have several startup keys (.FVE files) for different Vista machines
> > on
> > one USB flash drive, how does each machine know which one is correct? Is
> > the
> > filename recorded somewhere in the unencypted portion of the drive? Or
> > does
> > it simple try all the possible .FVE files until it finds the lucky winner?
> >
> > Thanks,

>

My System SpecsSystem Spec
Reply

Thread Tools


Similar Threads
Thread Forum
Toggle Keys at Startup Tutorials
Mix-up of multiple product keys Vista installation & setup
Multiple Windows Systems on an USB Flash Drive Vista installation & setup
Selecting multiple files on a flash drive Vista General
Vista startup/locking issue - on multiple machines Vista General


Vista Forums is an independent web site and has not been authorized,
sponsored, or otherwise approved by Microsoft Corporation.
"Windows Vista", the Start Orb, and related materials are trademarks of Microsoft Corp.
© Designer Media Ltd

1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46