Forensic Flash Memory Acquisition via Boot Loader Analysis

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional methods for acquiring forensic data from smart devices often compromise data integrity due to reliance on kernel vulnerabilities, custom recovery methods, or hardware-based approaches like JTAG, which are increasingly hindered by security measures such as secure boot and the deactivation of JTAG ports, making it difficult to collect evidentiary data without damaging the device.

Innovation Solution

A forensic data acquisition apparatus and method that activates only the boot loader and USB module of a smart device, analyzing flash memory read commands and partition information to generate a dump image, ensuring data integrity through a firmware update mode, which supports multiple smart device models and verifies data integrity using hash values.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If conventional rooting methods based on kernel vulnerabilities are used, then data acquisition is possible, but data integrity is compromised due to system and data falsification during rooting

Engineering Contradiction:
Improvedata integrityVSAvoiddata acquisition capability
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent applies preliminary action by entering the device into a special mode (download mode or firmware update mode) before data acquisition. This preliminary state change allows the forensic apparatus to communicate with the flash memory directly through the boot loader without requiring rooting, thus preserving data integrity while enabling data acquisition.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The boot loader serves as an intermediary component that the forensic apparatus utilizes to access flash memory data. Instead of directly rooting the system or using compromised methods, the patent leverages the boot loader's existing functionality in special modes to mediate between the forensic tool and the flash memory, achieving data acquisition without falsification.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Ease of operation

If custom recovery image replacement is used, then user data area accessibility is improved, but integrity of dump images cannot be guaranteed

Engineering Contradiction:
Improveuser data area accessibilityVSAvoidintegrity of dump images
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent extracts the data acquisition function from the custom recovery image and performs it directly through the boot loader in special modes. By taking out the need for custom recovery image flashing and using the existing boot loader's flash memory read commands, the method achieves both accessibility and integrity without the integrity compromises of custom recovery methods.

Inventive Principle:
Principle #2Taking out (Extraction)

3Reliability

If JTAG port method is used, then hardware-based data acquisition is possible, but the method becomes ineffective when JTAG port is deactivated for security

Engineering Contradiction:
Improvedata acquisition capabilityVSAvoidcompatibility with security measures
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent replaces the mechanical/hardware-based JTAG approach with a software-based communication method through the boot loader and USB interface. Instead of relying on physical JTAG ports that can be deactivated, the system uses software commands sent via USB to control flash memory reading, providing adaptability to security measures while maintaining data acquisition capability.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

4Adaptability or versatility

If chip-off method is used, then data acquisition is possible when device is damaged, but data may not be acquired when no power failure or fault occurs

Engineering Contradiction:
Improvedata acquisition under fault conditionsVSAvoiddata acquisition consistency
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent enables the device to serve itself by utilizing its own boot loader and existing firmware update mechanisms to facilitate data acquisition. The device's normal operational components (boot loader, USB module) are leveraged to allow forensic data extraction without requiring external damage or power failures, making the method reliable and consistent across different device states.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS9891862B2Forensic data acquisition apparatus and method for guaranteeing integrity of flash memory in smart device
Publication Date: 2018.02.13 ELECTRONICS & TELECOMM RES INST
  • US9891862B2 patent drawing
  • US9891862B2 patent drawing
  • US9891862B2 patent drawing

AI summary

Forensic data acquisition apparatus and method. The forensic data acquisition apparatus according to an embodiment includes a command analysis unit for activating a boot loader and a Universal Serial Bus (USB) module of a smart device and analyzing a format of a flash memory read command based on results of analysis of the boot loader, a partition information analysis unit for analyzing partition information of flash memory in compliance with the flash memory read command, and a data acquisition unit for generating a dump image by dumping data stored in the flash memory based on the flash memory read command and the partition information, and for acquiring forensic data based on the dump image.