• DocumentCode
    739679
  • Title

    A Systematic Assessment of the Security of Full Disk Encryption

  • Author

    Muller, Tilo ; Freiling, Felix C.

  • Author_Institution
    Department of Computer Science, Friedrich-Alexander-University Erlangen-Nuremberg, Germany
  • Volume
    12
  • Issue
    5
  • fYear
    2015
  • Firstpage
    491
  • Lastpage
    503
  • Abstract
    Organizations as well as private users frequently report the loss and theft of mobile devices such as laptops and smartphones. The threat of data exposure in such scenarios can be mitigated by protection mechanisms based on encryption. Full disk encryption (FDE) is an effective method to protect data against unauthorized access. FDE can generally be classified into software- and hardware-based solutions. We assess the practical security that users can expect from these FDE solutions regarding physical access threats. We assume that strong cryptography like AES cannot be broken but focus on vulnerabilities arising from practical FDE implementations. We present the results of a comprehensive and systematic comparison of the security of software- and hardware-based FDE. Thereby, we exhibit attacks on widespread FDE standards in many common scenarios and different system configurations. As a result, we show that neither software- nor hardware-based FDE provides perfect security, nor is one clearly superior to the other.
  • Keywords
    Drives; Encryption; Portable computers; Random access memory; Smart phones; Cold Boot / DMA / Evil Maid / Hot Plug Attacks; Full Disk Encryption; Full disk encryption; Physical Access Threats; Self-Encrypting Drives; cold boot/DMA/evil maid/hot plug attacks; physical access threats; self-encrypting drives;
  • fLanguage
    English
  • Journal_Title
    Dependable and Secure Computing, IEEE Transactions on
  • Publisher
    ieee
  • ISSN
    1545-5971
  • Type

    jour

  • DOI
    10.1109/TDSC.2014.2369041
  • Filename
    6951337