Intel i7-9700F 3.00GHz CPU configuration with NVIDIA GeForce RTX 2080 Ti (8,000 passwords per second).The search speed increases considerably when using a computer with a powerful GPU. In most cases, the brute-force can be performed offline or online.įor devices with a security update before 2021, offline brute-forcing is possible at the search speed of about 250 passwords per second on an average office computer. The brute-force speed depends on the date of the security update installed on the phone. If the password is unknown, it can be brute-forced. It’s important to note that knowledge of the phone lock password is required for successful decryption. Instead, it is a decrypted full file system, including both main user and PrivateSpace data, if the latter has been activated by the owner. These schemes are tied to specific processors and differ by the set of hardware keys used.ĭue to the FBE encryption scheme, the final result of the extraction is not a full physical encrypted extraction. PrivateSpace is usually used by the phone owner to keep sensitive data there.įor different models, the manufacturer uses 4 different encryption schemes. In addition to the encryption of standard user data, many Huawei devices offer the option to create an additional protected space titled PrivateSpace, which is encrypted in the same way as the main data but with a separate set of keys. Huawei implements a file-based encryption (FBE) scheme with the usage of hardware keys. Naturally, all Huawei devices use memory encryption. Additionally, the device connection process prior to extraction became more advanced in 2021. The current extraction method in Oxygen Forensic® Detective can even be used with updates installed after the company became aware of the vulnerabilities and took steps to amend them. This means that those vulnerabilities cannot be fixed or removed with a firmware update. The support capability is determined not by the exact device model but rather by the processor and operating system version (Android OS 9 and 10 versions are supported).Ĭurrently, data from devices on the following processors can be extracted: Kirin 659, 710, 710F, 810, 820, 960, 970, 980, 985, 990, and 990 5G.ĭuring the extraction procedure, the vulnerabilities in the processor firmware are exploited. Among them, there are popular models like Huawei P30 Pro, as well as massively distributed models like Honor 9 and Honor 10. Oxygen Forensic® Detective supports a wide range of Huawei devices. The second quarter of 2020 marked the first time that Huawei emerged as the market leader in terms of total smartphones shipped, with the Chinese smartphone vendor accounting for 20 percent of the market. While Huawei’s popularity can mostly be seen in China’s mobile phone market, they are also used in over 170 countries. Honor is a mass-market brand but also produced with very good hardware. Huawei models get all the new hardware and are mostly in the top segment of Android smartphones. Huawei produces smartphones based on this processor family, as well as under the Honor brand. Physical extraction from Huawei devices on Kirin chipsets remains one of the most popular extraction methods in forensic solutions.
0 Comments
Leave a Reply. |
AuthorWrite something about yourself. No need to be fancy, just an overview. ArchivesCategories |