BATTLE OF SKM AND IUM
blackhat2015
blackhat2015
Create successful ePaper yourself
Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.
TRUSTLET INSTANCE GUID<br />
• Trustlets can also associate an Instance GUID with their process<br />
• The same Instance GUID can be used by multiple Trustlets (with different IDs), including Trustlets that are<br />
running on different partitions<br />
• Instance GUIDs are tied with Hyper-V Partition GUIDs<br />
• Allows a Trustlet on a child Hyper-V Partition to identify itself to <strong>SKM</strong>, as well as a Trustlet on the host partition<br />
to identify itself with <strong>SKM</strong><br />
• Can now use the Secure Storage facility<br />
• Instance GUID is set with SetTrustletInstance<br />
• This is then stored in the SKPROCESS structure at offset 0x10