2018/03/01 by Gunnar Alendal, Geir Olav Dyrkolbotn, Stefan Axelsson · 1 citation
Computer Science · #Digital and Cyber Forensics #Advanced Malware Detection Techniques #User Authentication and Security Systems
paper · pdf · doi:10.1016/j.diin.2018.01.008
openalex publication_date 2018/03/01 · openalex created_date 2025/10/10 · openalex updated_date 2026/08/02
The acquisition of data from mobile phones have been a mainstay of criminal digital forensics for a number of years now. However, this forensic acquisition is getting more and more difficult with the increasing security level and complexity of mobile phones (and other embedded devices). In addition, it is often difficult or impossible to get access to design specifications, documentation and source code. As a result, the forensic acquisition methods are also increasing in complexity, requiring an ever deeper understanding of the underlying technology and its security mechanisms. Forensic acquisition techniques are turning to more offensive solutions to bypass security mechanisms, through security vulnerabilities. Common Criteria mode is a security feature that increases the security level of Samsung devices, and thus make forensic acquisition more difficult for law enforcement. With no access to design documents or source code, we have reverse engineered how the Common Criteria mode is actually implemented and protected by Samsung's secure bootloader. We present how this security mode is enforced, security vulnerabilities therein, and how the discovered security vulnerabilities can be used to circumvent Common Criteria mode for further forensic acquisition.