Forensic Flash Memory Acquisition via Boot Loader Analysis
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional methods for acquiring forensic data from smart devices often compromise data integrity due to reliance on kernel vulnerabilities, custom recovery methods, or hardware-based approaches like JTAG, which are increasingly hindered by security measures such as secure boot and the deactivation of JTAG ports, making it difficult to collect evidentiary data without damaging the device.
Innovation Solution
A forensic data acquisition apparatus and method that activates only the boot loader and USB module of a smart device, analyzing flash memory read commands and partition information to generate a dump image, ensuring data integrity through a firmware update mode, which supports multiple smart device models and verifies data integrity using hash values.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If conventional rooting methods based on kernel vulnerabilities are used, then data acquisition is possible, but data integrity is compromised due to system and data falsification during rooting
Solution Approach 1:
The patent applies preliminary action by entering the device into a special mode (download mode or firmware update mode) before data acquisition. This preliminary state change allows the forensic apparatus to communicate with the flash memory directly through the boot loader without requiring rooting, thus preserving data integrity while enabling data acquisition.
Solution Approach 2:
The boot loader serves as an intermediary component that the forensic apparatus utilizes to access flash memory data. Instead of directly rooting the system or using compromised methods, the patent leverages the boot loader's existing functionality in special modes to mediate between the forensic tool and the flash memory, achieving data acquisition without falsification.
2Ease of operation
If custom recovery image replacement is used, then user data area accessibility is improved, but integrity of dump images cannot be guaranteed
Solution Approach 1:
The patent extracts the data acquisition function from the custom recovery image and performs it directly through the boot loader in special modes. By taking out the need for custom recovery image flashing and using the existing boot loader's flash memory read commands, the method achieves both accessibility and integrity without the integrity compromises of custom recovery methods.
3Reliability
If JTAG port method is used, then hardware-based data acquisition is possible, but the method becomes ineffective when JTAG port is deactivated for security
Solution Approach 1:
The patent replaces the mechanical/hardware-based JTAG approach with a software-based communication method through the boot loader and USB interface. Instead of relying on physical JTAG ports that can be deactivated, the system uses software commands sent via USB to control flash memory reading, providing adaptability to security measures while maintaining data acquisition capability.
4Adaptability or versatility
If chip-off method is used, then data acquisition is possible when device is damaged, but data may not be acquired when no power failure or fault occurs
Solution Approach 1:
The patent enables the device to serve itself by utilizing its own boot loader and existing firmware update mechanisms to facilitate data acquisition. The device's normal operational components (boot loader, USB module) are leveraged to allow forensic data extraction without requiring external damage or power failures, making the method reliable and consistent across different device states.
Data Source
AI summary
Forensic data acquisition apparatus and method. The forensic data acquisition apparatus according to an embodiment includes a command analysis unit for activating a boot loader and a Universal Serial Bus (USB) module of a smart device and analyzing a format of a flash memory read command based on results of analysis of the boot loader, a partition information analysis unit for analyzing partition information of flash memory in compliance with the flash memory read command, and a data acquisition unit for generating a dump image by dumping data stored in the flash memory based on the flash memory read command and the partition information, and for acquiring forensic data based on the dump image.


