2021
DOI: 10.1109/access.2021.3052353
|View full text |Cite
|
Sign up to set email alerts
|

Forensics and Anti-Forensics of a NAND Flash Memory: From a Copy-Back Program Perspective

Abstract: This paper proposes a safe copy-back program operation in a NAND flash memory, which is targeting digital forensics for a variety of reasons. Due to the background management operation of the NAND flash memory, the original data is highly likely to remain without truly being deleted. We have carefully investigated the possibility of data exposure due to a copy-back program operation, among, frequently used management operations as such data exposure increases the possibility of privacy invasion. We propose a s… Show more

Help me understand this report

Search citation statements

Order By: Relevance

Paper Sections

Select...
2
2
1

Citation Types

0
14
0

Year Published

2021
2021
2023
2023

Publication Types

Select...
4
1

Relationship

2
3

Authors

Journals

citations
Cited by 9 publications
(14 citation statements)
references
References 31 publications
0
14
0
Order By: Relevance
“…Digital forensics is a generic term for forensic techniques used for investigation by analyzing digital evidence. Recently, in connection with IoT devices, there is abundant research on digital forensics for NAND flash memory [15][16][17][18][19][20][21], which poses new questions about what the target of digital forensics in NAND flash memory is. Before defining this, though, it is first necessary to digitally grasp the concept of what original data is.…”
Section: Original Data In Nand Flash Memorymentioning
confidence: 99%
See 1 more Smart Citation
“…Digital forensics is a generic term for forensic techniques used for investigation by analyzing digital evidence. Recently, in connection with IoT devices, there is abundant research on digital forensics for NAND flash memory [15][16][17][18][19][20][21], which poses new questions about what the target of digital forensics in NAND flash memory is. Before defining this, though, it is first necessary to digitally grasp the concept of what original data is.…”
Section: Original Data In Nand Flash Memorymentioning
confidence: 99%
“…For this reason, NAND flash memory performs various internal operations to extend life span and improve performance. Related to these internal actions, studies on the dangers of forensics have recently been raised [15][16][17][18][19][20][21].…”
Section: Introductionmentioning
confidence: 99%
“…Basically, NAND flash memory causes a significant amount of garbage collection because the program/read unit and the erase unit are different. Such garbage collection inevitably follows the propagation of the original data inside NAND flash memory [19]. In other words, if the original data exists in the validated block, there is a very high possibility that the original data is left as is in the plurality of invalidated blocks.…”
Section: B Secure Garbage Collectionmentioning
confidence: 99%
“…From a privacy point of view, garbage collection should be performed to prevent the spread of original data. Ahn was the first to propose this discussion and introduced a secure garbage collection method that prevents the spread of original data via a novel secure copy-back program [8,9,19].…”
Section: B Secure Garbage Collectionmentioning
confidence: 99%
“…In [10], [11], the authors discuss how to adapt acquisition and analysis techniques to recover accurate and relevant data from flash memory chips; however, this is under the implicit assumption that they are not damaged. In [12], the authors explain that due to their block-based structure, flash memories are becoming forensics targets but they mainly propose an anti-forensic technique. Although present in most IoT devices, SD cards are rarely considered in recent surveys dealing with IoT forensics [13]- [15], further increasing the potential value of our contribution of a systematic diagnostic forensic protocol for damaged SD cards.…”
Section: Introductionmentioning
confidence: 99%