Loading...
「ツール」は右上に移動しました。
利用したサーバー: natural-voltaic-titanium
8いいね 456回再生

Hardwear.io NL 2023 | Dissecting The Modern Android Data Encryption Scheme - Maxime Bellom & Damiano

Following our research on the Titan M, the security chip made by Google for their Android smartphones, we received a request from someone who had broken their device and was asking how they could recover the data despite the main SoC being dead. This question aroused our curiosity, and gave us the opportunity to play the forensic role and investigate how we could attack user data encryption on Android. We ended up asking ourselves how strong this mechanism is, against attackers who have access to a wide range of software vulnerabilities. To answer that question, we exploited two powerful known vulnerabilities, one in the Boot ROM of a Mediatek SoC and one in the Titan M, to attack the two mechanisms behind credential validation and key derivation: Gatekeeper and Weaver.

In this talk, we present the logic behind the generation and storage of the keys for Android's user data encryption, called File-Based Encryption. Referencing the implementation in the AOSP (Android Open Source Project), we follow the steps performed by the system to generate the final encryption keys. Analyzing this process, we describe how elements from the file system, TEE and Secure Element (when present) are combined with the user's credentials, which still remain essential in the derivation. In two scenarios, one relying on TrustZone (and the Gatekeeper TA), and one relying on a security chip (implementing Weaver), we show strategies on how they can be attacked. In this context we use two known software vulnerabilities to build a PoC on a Samsung A22 and on a Pixel 3a, to highlight the difficulties that one may face with this task.

#hardwear_io #securechip
-------------------------------------------------------------------------------------------------------------------------------------------------------
Website: hardwear.io/
X : twitter.com/hardwear_io
LinkedIn: www.linkedin.com/company/hardwear.io-hardwaresecur…
Facebook: www.facebook.com/hardwear.io

コメント