https://www.sciencedirect.com/science/article/pii/S266628172100007X JavaScript is disabled on your browser. Please enable JavaScript to use all the features on this page. [1714863740] Skip to main content Skip to article Elsevier logo * Journals & Books * * Search RegisterSign in * View PDF * Download full issue Search ScienceDirect[ ] Elsevier Forensic Science International: Digital Investigation Volume 36, Supplement, April 2021, 301113 Forensic Science International: Digital Investigation Full Paper One key to rule them all: Recovering the master key from RAM to break Android's file-based encryption Author links open overlay panelTobias Gross, Marcel Busch, Tilo Muller Show more Share Cite https://doi.org/10.1016/j.fsidi.2021.301113Get rights and content Under a Creative Commons license open access Abstract As known for a decade, cold boot attacks can break software-based disk encryption when an attacker has physical access to a powered-on device, including Android smartphones. Raw memory images can be obtained by resetting a device and rebooting it with a malicious boot loader, or--on systems where this is not possible due to secure boot or restrictive BIOS settings--by a physical transplantation of RAM modules into a system under the control of the attacker. Based on the memory images of a device, different key recovery algorithms have been proposed in the past to break Full Disk Encryption (FDE), including BitLocker, dm-crypt, and also Android's FDE. With Google's switch from FDE to File-based Encryption (FBE) as the standard encryption method for recent Android devices, however, existing tools have been rendered ineffective. To close this gap, and to re-enable the forensic analysis of encrypted Android disks, given a raw memory image, we present a new key recovery method tailored for FBE. Furthermore, we extend The Sleuth Kit (TSK) to automatically decrypt file names and file contents when working on FBE-enabled EXT4 images, as well as the Plaso framework to extract events from encrypted EXT4 partitions. Last but not least, we argue that the recovery of master keys from FBE partitions was particularly easy due to a flaw in the key derivation method by Google. * Previous article in issue * Next article in issue Keywords Android EXT4 File-based encryption (FBE) Disk forensics Memory forensics Cold boot attacks Recommended articles Cited by (0) (c) 2021 The Authors. Published by Elsevier Ltd. Recommended articles No articles found. Article Metrics View article metrics Elsevier logo with wordmark * About ScienceDirect * Remote access * Shopping cart * Advertise * Contact and support * Terms and conditions * Privacy policy Cookies are used by this site. Cookie Settings All content on this site: Copyright (c) 2024 Elsevier B.V., its licensors, and contributors. All rights are reserved, including those for text and data mining, AI training, and similar technologies. For all open access content, the Creative Commons licensing terms apply. RELX group home page