首页 | 官方网站   微博 | 高级检索  
     

FileVault2加密分区离线解密技术及其取证应用
引用本文:蓝朝祥,沈长达,钱镜洁.FileVault2加密分区离线解密技术及其取证应用[J].信息网络安全,2014(9):211-213.
作者姓名:蓝朝祥  沈长达  钱镜洁
作者单位:厦门市美亚柏科信息股份有限公司,福建厦门361008
摘    要:苹果公司推出OS X 10.3(Panther)系统时,引入了FileVault磁盘加密功能。在最新发布的OS X Lion 系统中,引入了全新加密方式FileVault2。FileVault2使用全磁盘、AES-XTS 128加密来帮助保护数据安全。针对当前大部分的取证软件都不支持对经过FileVault2加密的磁盘进行数据解析问题,文章首先讨论了FileVault2的加密原理,接着提出了离线解密的方法,并在此基础上设计了FileVault2取证工具,使得加密磁盘摆脱了目标数据源对Mac OS系统的依赖,能够在没有Mac OS系统的环境下对经过FileVault2加密的磁盘进行取证。实践表明此离线解密方法丰富了加密数据的取证项。

关 键 词:加密磁盘  加密  解密

The Method of Decrypting FileVault2 Oflfine and Applications in Forensics
LAN Chao-xiang,SHEN Chang-da,QIAN Jing-jie.The Method of Decrypting FileVault2 Oflfine and Applications in Forensics[J].Netinfo Security,2014(9):211-213.
Authors:LAN Chao-xiang  SHEN Chang-da  QIAN Jing-jie
Affiliation:(Xiamen Meiya Pico Information Co.,Ltd., Xiamen Fujian 361008, China)
Abstract:Apple launched OS X 10.3 (Panther) system, the introduction of a FileVault disk encryption feature. In the latest release of OS X Lion system, the introduction of a new encryption FileVault2. FileVault2 uses full disk, AES-XTS 128 encryption to help keep data secure. Given that most of forensic soft can’t achieve forensics quickly on FileVault2 encrypting disk. This paper ifrst discusser encrypting principles of the FileVault2, then puts the FileVault2 decryption method oflfine. And on this basis, designs the decrypting FileVault2 tools, which works independent of the operating system on the target data source and able to in the absence of Mac OS system environment through FileVault2 encrypted disk forensics. Practice shows that offline decryption method enriches the evidence items.
Keywords:encrypting disk  encrypt  decrypt
本文献已被 维普 等数据库收录!
设为首页 | 免责声明 | 关于勤云 | 加入收藏

Copyright©北京勤云科技发展有限公司    京ICP备09084417号-23

京公网安备 11010802026262号