The Block-based Mobile PDE Systems Are Not Secure – Experimental Attacks

03/30/2022
by   Niusen Chen, et al.
0

Nowadays, mobile devices have been used broadly to store and process sensitive data. To ensure confidentiality of the sensitive data, Full Disk Encryption (FDE) is often integrated in mainstream mobile operating systems like Android and iOS. FDE however cannot defend against coercive attacks in which the adversary can force the device owner to disclose the decryption key. To combat the coercive attacks, Plausibly Deniable Encryption (PDE) is leveraged to plausibly deny the very existence of sensitive data. However, most of the existing PDE systems for mobile devices are deployed at the block layer and suffer from deniability compromises. Having observed that none of existing works in the literature have experimentally demonstrated the aforementioned compromises, our work bridges this gap by experimentally confirming the deniability compromises of the block-layer mobile PDE systems. We have built a mobile device testbed, which consists of a host computing device and a flash storage device. Additionally, we have deployed both the hidden volume PDE and the steganographic file system at the block layer of the testbed and performed disk forensics to assess potential compromises on the raw NAND flash. Our experimental results confirm it is indeed possible for the adversary to compromise the block-layer PDE systems by accessing the raw NAND flash in practice. We also discuss potential issues when performing such attacks in real world.

READ FULL TEXT
research
01/30/2020

Towards Designing A Secure Plausibly Deniable System for Mobile Devices against Multi-snapshot Adversaries – A Preliminary Design

Mobile computing devices have been used broadly to store, manage and pro...
research
02/13/2018

Phishing Techniques in Mobile Devices

The rapid evolution in mobile devices and communication technology has i...
research
09/22/2021

SoK: Cryptographic Confidentiality of Data on Mobile Devices

Mobile devices have become an indispensable component of modern life. Th...
research
11/24/2021

SoK: Untangling File-based Encryption on Mobile Devices

File-based encryption (FBE) schemes have been developed by software vend...
research
05/10/2021

Physical Fault Injection and Side-Channel Attacks on Mobile Devices: A Comprehensive Survey

Today's mobile devices contain densely packaged system-on-chips (SoCs) w...
research
08/03/2018

DCert: Find the Leak in Your Pocket

Static data-flow analysis has proven its effectiveness in assessing secu...
research
04/08/2022

Perlustration on Mobile Forensics Tools

Nowadays many people store more information in cellphones rather than do...

Please sign up or login with your details

Forgot password? Click here to reset