Title :
A Systematic Assessment of the Security of Full Disk Encryption
Author :
Muller, Tilo ; Freiling, Felix C.
Author_Institution :
Department of Computer Science, Friedrich-Alexander-University Erlangen-Nuremberg, Germany
Abstract :
Organizations as well as private users frequently report the loss and theft of mobile devices such as laptops and smartphones. The threat of data exposure in such scenarios can be mitigated by protection mechanisms based on encryption. Full disk encryption (FDE) is an effective method to protect data against unauthorized access. FDE can generally be classified into software- and hardware-based solutions. We assess the practical security that users can expect from these FDE solutions regarding physical access threats. We assume that strong cryptography like AES cannot be broken but focus on vulnerabilities arising from practical FDE implementations. We present the results of a comprehensive and systematic comparison of the security of software- and hardware-based FDE. Thereby, we exhibit attacks on widespread FDE standards in many common scenarios and different system configurations. As a result, we show that neither software- nor hardware-based FDE provides perfect security, nor is one clearly superior to the other.
Keywords :
Drives; Encryption; Portable computers; Random access memory; Smart phones; Cold Boot / DMA / Evil Maid / Hot Plug Attacks; Full Disk Encryption; Full disk encryption; Physical Access Threats; Self-Encrypting Drives; cold boot/DMA/evil maid/hot plug attacks; physical access threats; self-encrypting drives;
Journal_Title :
Dependable and Secure Computing, IEEE Transactions on
DOI :
10.1109/TDSC.2014.2369041