DocumentCode
1567022
Title
Recovery of Encryption Keys from Memory Using a Linear Scan
Author
Hargreaves, Christopher ; Chivers, Howard
Author_Institution
Cranfield Univ., Shrivenham
fYear
2008
Firstpage
1369
Lastpage
1376
Abstract
As encrypted containers are encountered more frequently the need for live imaging is likely to increase. However, an acquired live image of an open encrypted file system cannot later be verified against any original evidence, since when the power is removed the decrypted contents are no longer accessible. This paper shows that if a memory image is also obtained at the same time as the live container image, by the design of on-the-fly encryption, decryption keys can be recovered from the memory dump. These keys can then be used offline to gain access to the encrypted container file, facilitating standard, repeatable, forensic file system analysis. The recovery method uses a linear scan of memory to generate trial keys from all possible memory positions to decrypt the container. The effectiveness of this approach is demonstrated by recovering TrueCrypt decryption keys from a memory dump of a Windows XP system.
Keywords
cryptography; storage management; system recovery; decryption key; encrypted container file; encryption key recovery; forensic file system analysis; linear memory scan; live memory image; memory dump; open encrypted file system; Availability; Containers; Cryptography; File systems; Forensics; Hard disks; Packaging machines; Read-write memory; Security; Universal Serial Bus; Digital Evidence; Encryption; Forensic Computing; Live Forensics;
fLanguage
English
Publisher
ieee
Conference_Titel
Availability, Reliability and Security, 2008. ARES 08. Third International Conference on
Conference_Location
Barcelona
Print_ISBN
978-0-7695-3102-1
Type
conf
DOI
10.1109/ARES.2008.109
Filename
4529504
Link To Document