18.10.2015 Views

BATTLE OF SKM AND IUM

blackhat2015

blackhat2015

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

TRUSTLET INSTANCE GUID<br />

• Trustlets can also associate an Instance GUID with their process<br />

• The same Instance GUID can be used by multiple Trustlets (with different IDs), including Trustlets that are<br />

running on different partitions<br />

• Instance GUIDs are tied with Hyper-V Partition GUIDs<br />

• Allows a Trustlet on a child Hyper-V Partition to identify itself to <strong>SKM</strong>, as well as a Trustlet on the host partition<br />

to identify itself with <strong>SKM</strong><br />

• Can now use the Secure Storage facility<br />

• Instance GUID is set with SetTrustletInstance<br />

• This is then stored in the SKPROCESS structure at offset 0x10

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!