SoK: Untangling File-based Encryption on Mobile Devices

11/24/2021
by   David Galindo, et al.
0

File-based encryption (FBE) schemes have been developed by software vendors to address security concerns related to data storage. While methods of encrypting data-at-rest may seem relatively straightforward, the main proponents of these technologies in mobile devices have nonetheless created seemingly different FBE solutions. As most of the underlying design decisions are described either at a high-level in whitepapers, or are accessible at a low-level by examining the corresponding source code (Android) or through reverse-engineering (iOS), comparisons between schemes and discussions on their relative strengths are scarce. In this paper, we propose a formal framework for the study of file-based encryption systems, focusing on two prominent implementations: the FBE scheme used in Android and Linux operating systems, as well as the FBE scheme used in iOS. Our proposed formal model and our detailed description of the existing algorithms are based on documentation of diverse nature, such as whitepapers, technical reports, presentations and blog posts, among others. Using our framework we validate the security of the existing key derivation chains, as well as the security of the overall designs, under widely-known security assumptions for symmetric ciphers, such as IND-CPA or INT-CTXT security, in the random-oracle model.

READ FULL TEXT

page 1

page 2

page 3

page 4

research
10/29/2020

Towards a certified reference monitor of the Android 10 permission system

Android is a platform for mobile devices that captures more than 85 tota...
research
07/16/2014

Security of OS-level virtualization technologies: Technical report

The need for flexible, low-overhead virtualization is evident on many fr...
research
02/22/2020

An Empirical Study of Android Security Bulletins in Different Vendors

Mobile devices encroach on almost every part of our lives, including wor...
research
02/08/2020

On the Insecurities of Mobile D2D File Sharing Applications

With more than 1.3 Billion in the cumulative number of downloads reporte...
research
03/30/2022

The Block-based Mobile PDE Systems Are Not Secure – Experimental Attacks

Nowadays, mobile devices have been used broadly to store and process sen...
research
11/22/2017

Implementation of an Android Framework for USB storage access without root rights

This bachelor thesis describes the implementation of an Android framewor...
research
02/21/2021

A Ransomware Classification Framework Based on File-Deletion and File-Encryption Attack Structures

Ransomware has emerged as an infamous malware that has not escaped a lot...

Please sign up or login with your details

Forgot password? Click here to reset