The Experts below are selected from a list of 21 Experts worldwide ranked by ideXlab platform
Howard Chivers - One of the best experts on this subject based on the ideXlab platform.
-
Communications and Multimedia Security - Detecting hidden Encrypted volumes
Communications and Multimedia Security, 2010Co-Authors: Christopher Hargreaves, Howard ChiversAbstract:Hidden Encrypted volumes can cause problems in digital investigations since they provide criminal suspects with a range of opportunities for deceptive anti-forensics and a countermeasure to legislation written to force suspects to reveal decryption keys. This paper describes how hidden Encrypted volumes can be detected, and their size estimated. The paper shows how multiple copies of an Encrypted Container can be obtained from a single disk image of Windows Vista and Windows 7 systems using the Volume Shadow Copy feature, and how the changes between shadow copies can be visualised to detect hidden volumes. The visualisation assists in the presentation of this information to a court, and exposes patterns of change which allows the size and file system of the hidden volume to be determined.
-
Detecting Hidden Encrypted Volumes
2010Co-Authors: Christopher Hargreaves, Howard ChiversAbstract:Hidden Encrypted volumes can cause problems in digital investigations since they provide criminal suspects with a range of opportunities for deceptive anti-forensics and a countermeasure to legislation written to force suspects to reveal decryption keys. This paper describes how hidden Encrypted volumes can be detected, and their size estimated. The paper shows how multiple copies of an Encrypted Container can be obtained from a single disk image of Windows Vista and Windows 7 systems using the Volume Shadow Copy feature, and how the changes between shadow copies can be visualised to detect hidden volumes. The visualisation assists in the presentation of this information to a court, and exposes patterns of change which allows the size and file system of the hidden volume to be determined.
-
ARES - Recovery of Encryption Keys from Memory Using a Linear Scan
2008 Third International Conference on Availability Reliability and Security, 2008Co-Authors: Christopher Hargreaves, Howard ChiversAbstract:As Encrypted Containers are encountered more frequently the need for live imaging is likely to increase. However, an acquired live image of an open Encrypted file system cannot later be verified against any original evidence, since when the power is removed the decrypted contents are no longer accessible. This paper shows that if a memory image is also obtained at the same time as the live Container image, by the design of on-the-fly encryption, decryption keys can be recovered from the memory dump. These keys can then be used offline to gain access to the Encrypted Container file, facilitating standard, repeatable, forensic file system analysis. The recovery method uses a linear scan of memory to generate trial keys from all possible memory positions to decrypt the Container. The effectiveness of this approach is demonstrated by recovering TrueCrypt decryption keys from a memory dump of a Windows XP system.
Christopher Hargreaves - One of the best experts on this subject based on the ideXlab platform.
-
Communications and Multimedia Security - Detecting hidden Encrypted volumes
Communications and Multimedia Security, 2010Co-Authors: Christopher Hargreaves, Howard ChiversAbstract:Hidden Encrypted volumes can cause problems in digital investigations since they provide criminal suspects with a range of opportunities for deceptive anti-forensics and a countermeasure to legislation written to force suspects to reveal decryption keys. This paper describes how hidden Encrypted volumes can be detected, and their size estimated. The paper shows how multiple copies of an Encrypted Container can be obtained from a single disk image of Windows Vista and Windows 7 systems using the Volume Shadow Copy feature, and how the changes between shadow copies can be visualised to detect hidden volumes. The visualisation assists in the presentation of this information to a court, and exposes patterns of change which allows the size and file system of the hidden volume to be determined.
-
Detecting Hidden Encrypted Volumes
2010Co-Authors: Christopher Hargreaves, Howard ChiversAbstract:Hidden Encrypted volumes can cause problems in digital investigations since they provide criminal suspects with a range of opportunities for deceptive anti-forensics and a countermeasure to legislation written to force suspects to reveal decryption keys. This paper describes how hidden Encrypted volumes can be detected, and their size estimated. The paper shows how multiple copies of an Encrypted Container can be obtained from a single disk image of Windows Vista and Windows 7 systems using the Volume Shadow Copy feature, and how the changes between shadow copies can be visualised to detect hidden volumes. The visualisation assists in the presentation of this information to a court, and exposes patterns of change which allows the size and file system of the hidden volume to be determined.
-
ARES - Recovery of Encryption Keys from Memory Using a Linear Scan
2008 Third International Conference on Availability Reliability and Security, 2008Co-Authors: Christopher Hargreaves, Howard ChiversAbstract:As Encrypted Containers are encountered more frequently the need for live imaging is likely to increase. However, an acquired live image of an open Encrypted file system cannot later be verified against any original evidence, since when the power is removed the decrypted contents are no longer accessible. This paper shows that if a memory image is also obtained at the same time as the live Container image, by the design of on-the-fly encryption, decryption keys can be recovered from the memory dump. These keys can then be used offline to gain access to the Encrypted Container file, facilitating standard, repeatable, forensic file system analysis. The recovery method uses a linear scan of memory to generate trial keys from all possible memory positions to decrypt the Container. The effectiveness of this approach is demonstrated by recovering TrueCrypt decryption keys from a memory dump of a Windows XP system.
Müller Wilmuth - One of the best experts on this subject based on the ideXlab platform.
-
Security overlay for distributed Encrypted Containers
2015Co-Authors: Patzer F., Jakoby A., Kresken Thomas, Müller WilmuthAbstract:Storage services enable a high potential for time and location independent access to information particularly combined with smart mobile devices. In combination with corporate and local storage, those services can be a powerful extension to available storage in enterprise or governmental environments. In contrast, common secure storage strategies like Encrypted partitions or disks are static and remotely inaccessible, but are comfortable to use in a local scenario. However, storing sensitive data on public servers is not an option due to the possibility that an unauthorized third party can access it. Generally security policies like corporate compliance prohibit those services explicitly. Thus, sensitive data has to be Encrypted to allow its storage on public servers. The paper at hand describes a security overlay using a trusted environment to build a distributed virtual Encrypted Container that supports OTFE (on-the-fly encryption). For this purpose, an easily extendable security overlay is introduced where each file or data set is Encrypted independently. The overlay provides a hierarchical key structure, which hierarchically controls access to uploaded data and maps the data structure at the same time. Additionally, the directory structures and the meta-data are protected against unauthorized access. Therefore, the presented concept enables the creation of a deniable distributed file system that can enable an implementation to make strong security promises. The trusted environment can be provided by a device called CyphWay®, which has been developed at the Fraunhofer IOSB and presented at ICCWS 2014. The device guaranties that cryptographic keys are only available within a Hardware Security Module. Thus, the whole key structure and the keys themselves are protected even against the user devices, which is important regarding potentially insecure mobile platforms. Unlike several Encrypted Container solutions the presented system allows to distribute Encrypted data over a huge number of divergent publically available storage services, like cloud storages. In addition, it is possible to combine those storages with private or corporate storage
-
Protecting sensitive data in a distributed and mobile environment
2015Co-Authors: Patzer F., Jakoby A., Kresken Thomas, Müller WilmuthAbstract:The Cloud and other publically available storage services enable a high potential for time and location independent access to information particularly combined with smart mobile devices. Especially law enforcement agencies, like the police, require such possibilities to access information related to an investigation at any time from any place. However, storing sensitive data on public servers isn’t an option for law enforcement agencies due to the possibility of unauthorized access to these data by third parties. To allow the storage of sensitive data on public servers in the Cloud, it has to be Encrypted so that the cloud providers and possible attackers do not gain access to that information. At the Fraunhofer IOSB a device called CyphWay® has been developed and presented at ICCWS 2014, which makes sure that sensitive publicly stored data are protected by encryption. This device guaranties that encryption and decryption keys are only available within a specific trusted and protected hardware module. The access to those keys is controlled by a specially designed key management system. The paper at hand describes a security concept using such a trusted environment to build a secure and distributed file system for Encrypted data. For this purpose, each file or data set is Encrypted independently. The resulting system provides a hierarchical key structure, which controls access to uploaded data and maps the data structure at the same time. The goals of this system are to protect every publicly stored data through encryption and to provide a hierarchical access control. By decoupling the data structure from the actual data and by encrypting the meta-data, unauthorized observers will not be able to see meta-information like directory contents or directory structures. Therefore, the presented technique enables the creation of a deniable distributed file system. Unlike several Encrypted Container solutions the presented system allows to distribute Encrypted data over a huge number of divergent publically available storage services, like cloud storages. In addition, it is possible to combine those storages with own private or corporal storage. The key management system implements naturally an access control system and, additionally, allows the allocation of temporary access rights to other users to share data
Patzer F. - One of the best experts on this subject based on the ideXlab platform.
-
Security overlay for distributed Encrypted Containers
2015Co-Authors: Patzer F., Jakoby A., Kresken Thomas, Müller WilmuthAbstract:Storage services enable a high potential for time and location independent access to information particularly combined with smart mobile devices. In combination with corporate and local storage, those services can be a powerful extension to available storage in enterprise or governmental environments. In contrast, common secure storage strategies like Encrypted partitions or disks are static and remotely inaccessible, but are comfortable to use in a local scenario. However, storing sensitive data on public servers is not an option due to the possibility that an unauthorized third party can access it. Generally security policies like corporate compliance prohibit those services explicitly. Thus, sensitive data has to be Encrypted to allow its storage on public servers. The paper at hand describes a security overlay using a trusted environment to build a distributed virtual Encrypted Container that supports OTFE (on-the-fly encryption). For this purpose, an easily extendable security overlay is introduced where each file or data set is Encrypted independently. The overlay provides a hierarchical key structure, which hierarchically controls access to uploaded data and maps the data structure at the same time. Additionally, the directory structures and the meta-data are protected against unauthorized access. Therefore, the presented concept enables the creation of a deniable distributed file system that can enable an implementation to make strong security promises. The trusted environment can be provided by a device called CyphWay®, which has been developed at the Fraunhofer IOSB and presented at ICCWS 2014. The device guaranties that cryptographic keys are only available within a Hardware Security Module. Thus, the whole key structure and the keys themselves are protected even against the user devices, which is important regarding potentially insecure mobile platforms. Unlike several Encrypted Container solutions the presented system allows to distribute Encrypted data over a huge number of divergent publically available storage services, like cloud storages. In addition, it is possible to combine those storages with private or corporate storage
-
Protecting sensitive data in a distributed and mobile environment
2015Co-Authors: Patzer F., Jakoby A., Kresken Thomas, Müller WilmuthAbstract:The Cloud and other publically available storage services enable a high potential for time and location independent access to information particularly combined with smart mobile devices. Especially law enforcement agencies, like the police, require such possibilities to access information related to an investigation at any time from any place. However, storing sensitive data on public servers isn’t an option for law enforcement agencies due to the possibility of unauthorized access to these data by third parties. To allow the storage of sensitive data on public servers in the Cloud, it has to be Encrypted so that the cloud providers and possible attackers do not gain access to that information. At the Fraunhofer IOSB a device called CyphWay® has been developed and presented at ICCWS 2014, which makes sure that sensitive publicly stored data are protected by encryption. This device guaranties that encryption and decryption keys are only available within a specific trusted and protected hardware module. The access to those keys is controlled by a specially designed key management system. The paper at hand describes a security concept using such a trusted environment to build a secure and distributed file system for Encrypted data. For this purpose, each file or data set is Encrypted independently. The resulting system provides a hierarchical key structure, which controls access to uploaded data and maps the data structure at the same time. The goals of this system are to protect every publicly stored data through encryption and to provide a hierarchical access control. By decoupling the data structure from the actual data and by encrypting the meta-data, unauthorized observers will not be able to see meta-information like directory contents or directory structures. Therefore, the presented technique enables the creation of a deniable distributed file system. Unlike several Encrypted Container solutions the presented system allows to distribute Encrypted data over a huge number of divergent publically available storage services, like cloud storages. In addition, it is possible to combine those storages with own private or corporal storage. The key management system implements naturally an access control system and, additionally, allows the allocation of temporary access rights to other users to share data
Jakoby A. - One of the best experts on this subject based on the ideXlab platform.
-
Security overlay for distributed Encrypted Containers
2015Co-Authors: Patzer F., Jakoby A., Kresken Thomas, Müller WilmuthAbstract:Storage services enable a high potential for time and location independent access to information particularly combined with smart mobile devices. In combination with corporate and local storage, those services can be a powerful extension to available storage in enterprise or governmental environments. In contrast, common secure storage strategies like Encrypted partitions or disks are static and remotely inaccessible, but are comfortable to use in a local scenario. However, storing sensitive data on public servers is not an option due to the possibility that an unauthorized third party can access it. Generally security policies like corporate compliance prohibit those services explicitly. Thus, sensitive data has to be Encrypted to allow its storage on public servers. The paper at hand describes a security overlay using a trusted environment to build a distributed virtual Encrypted Container that supports OTFE (on-the-fly encryption). For this purpose, an easily extendable security overlay is introduced where each file or data set is Encrypted independently. The overlay provides a hierarchical key structure, which hierarchically controls access to uploaded data and maps the data structure at the same time. Additionally, the directory structures and the meta-data are protected against unauthorized access. Therefore, the presented concept enables the creation of a deniable distributed file system that can enable an implementation to make strong security promises. The trusted environment can be provided by a device called CyphWay®, which has been developed at the Fraunhofer IOSB and presented at ICCWS 2014. The device guaranties that cryptographic keys are only available within a Hardware Security Module. Thus, the whole key structure and the keys themselves are protected even against the user devices, which is important regarding potentially insecure mobile platforms. Unlike several Encrypted Container solutions the presented system allows to distribute Encrypted data over a huge number of divergent publically available storage services, like cloud storages. In addition, it is possible to combine those storages with private or corporate storage
-
Protecting sensitive data in a distributed and mobile environment
2015Co-Authors: Patzer F., Jakoby A., Kresken Thomas, Müller WilmuthAbstract:The Cloud and other publically available storage services enable a high potential for time and location independent access to information particularly combined with smart mobile devices. Especially law enforcement agencies, like the police, require such possibilities to access information related to an investigation at any time from any place. However, storing sensitive data on public servers isn’t an option for law enforcement agencies due to the possibility of unauthorized access to these data by third parties. To allow the storage of sensitive data on public servers in the Cloud, it has to be Encrypted so that the cloud providers and possible attackers do not gain access to that information. At the Fraunhofer IOSB a device called CyphWay® has been developed and presented at ICCWS 2014, which makes sure that sensitive publicly stored data are protected by encryption. This device guaranties that encryption and decryption keys are only available within a specific trusted and protected hardware module. The access to those keys is controlled by a specially designed key management system. The paper at hand describes a security concept using such a trusted environment to build a secure and distributed file system for Encrypted data. For this purpose, each file or data set is Encrypted independently. The resulting system provides a hierarchical key structure, which controls access to uploaded data and maps the data structure at the same time. The goals of this system are to protect every publicly stored data through encryption and to provide a hierarchical access control. By decoupling the data structure from the actual data and by encrypting the meta-data, unauthorized observers will not be able to see meta-information like directory contents or directory structures. Therefore, the presented technique enables the creation of a deniable distributed file system. Unlike several Encrypted Container solutions the presented system allows to distribute Encrypted data over a huge number of divergent publically available storage services, like cloud storages. In addition, it is possible to combine those storages with own private or corporal storage. The key management system implements naturally an access control system and, additionally, allows the allocation of temporary access rights to other users to share data