MOBILE FORENSICS
File-Based Encryption (FBE) and Full Disk Encryption (FDE)
Device encryption is one of the most important security mechanisms in modern Android devices. It is of central importance to IT forensics, as it largely determines which data can be extracted and analysed. Since Android 7, File-Based Encryption (FBE) has been the predominant method, whilst older devices often use Full Disk Encryption (FDE).
TECHNICAL BACKGROUND
Technical Fundamentals
With Full Disk Encryption (FDE), the entire user storage is encrypted using a single key. The data can only be accessed once the device has been unlocked.
The more modern File-Based Encryption (FBE) encrypts files using different keys. This allows certain system areas to be used even before the system is first unlocked (Direct Boot).
Key terms:
- •Full Disk Encryption (FDE)
- •File-Based Encryption (FBE)
- •Direct Boot
- •Device-Encrypted (DE) Storage
- •Credential-Encrypted (CE) Storage
- •Hardware-based key management
- •Trusted Execution Environment (TEE)
The data that is available depends, amongst other things, on the Android version, the device model and whether the device is unlocked.
OUR APPROACH
This is how your examination will be carried out
A transparent process – from the initial enquiry to the handover of the report.
TYPICAL QUESTIONS
When is this analysis required?
- ✔Does the device use FBE or FDE?
- ✔What data is available before the device is unlocked?
- ✔Which sections are only decrypted once the user has logged in?
- ✔What are the implications for data backup?
- ✔What are the limitations of forensic analysis?
LIMITATIONS & CONCLUSION
What you should know
Active device encryption can significantly restrict access to data. Without appropriate authentication or supported extraction methods, certain information may not be accessible. These technical limitations are clearly set out in the expert report.
FBE and FDE have a significant impact on the scope of an Android forensic investigation. Correctly identifying the encryption method used is therefore an essential part of any professional analysis.
CUSTOMER REVIEWS
What our customers say
4.8 out of 5 stars on Trustpilot · 54 reviews
“The highest standards of professionalism, prompt service and excellent communication. They made the seemingly impossible a reality. This is what genuine customer service is all about – unrivalled in Germany!”
idalein
Verified review on Trustpilot
“Very helpful advice, excellent responsiveness and communication. My problem was completely resolved and the lost data was recovered. I’m very satisfied and, of course, relieved!”
Layla Pankratz
Verified review on Trustpilot
“My problem was sorted out professionally and quickly; everyone I spoke to was always friendly, and I can still get in touch if I have any questions – I’m very grateful for that!”
a woman from Cologne
Verified review on Trustpilot
Enquire now – free initial consultation
Would you like to have an encrypted Android device examined by professionals? LanCologne can assist you with an objective IT forensic analysis and comprehensive expert documentation.
RELATED TOPICS
You might also be interested in
FREQUENTLY ASKED QUESTIONS
Frequently Asked Questions
Click on a question to see the answer.