Title
A new model for forensic data extraction from encrypted mobile devices
Abstract
In modern criminal investigations, mobile devices are seized at every type of crime scene, and the data on those devices often becomes critical evidence in the case. Various mobile forensic techniques have been established and evaluated through research in order to extract possible evidence data from devices over the decades. However, as mobile devices become essential tools for daily life, security and privacy concerns grow, and modern smartphone vendors have implemented multiple types of security protection measures - such as encryption - to guard against unauthorized access to the data on their products. This trend makes forensic acquisition harder than before, and data extraction from those devices for criminal investigation is becoming a more challenging task. Today, mobile forensic research focuses on identifying more invasive techniques, such as bypassing security features, and breaking into target smartphones by exploiting their vulnerabilities. In this paper, we explain the increased encryption and security protection measures in modern mobile devices and their impact on traditional forensic data extraction techniques for law enforcement purposes. We demonstrate that in order to overcome encryption challenges, new mobile forensic methods rely on bypassing the security features and exploiting system vulnerabilities. A new model for forensic acquisition is proposed. The model is supported by a legal framework focused on the usability of digital evidence obtained through vulnerability exploitation.
Year
DOI
Venue
2021
10.1016/j.fsidi.2021.301169
Forensic Science International: Digital Investigation
Keywords
DocType
Volume
Mobile forensics,Encryption,Vulnerability exploitation
Journal
38
ISSN
Citations 
PageRank 
2666-2817
0
0.34
References 
Authors
11
3
Name
Order
Citations
PageRank
Aya Fukami100.34
Radina Stoykova212.07
Zeno J. M. H. Geradts300.34