DocumentCode
739679
Title
A Systematic Assessment of the Security of Full Disk Encryption
Author
Muller, Tilo ; Freiling, Felix C.
Author_Institution
Department of Computer Science, Friedrich-Alexander-University Erlangen-Nuremberg, Germany
Volume
12
Issue
5
fYear
2015
Firstpage
491
Lastpage
503
Abstract
Organizations as well as private users frequently report the loss and theft of mobile devices such as laptops and smartphones. The threat of data exposure in such scenarios can be mitigated by protection mechanisms based on encryption. Full disk encryption (FDE) is an effective method to protect data against unauthorized access. FDE can generally be classified into software- and hardware-based solutions. We assess the practical security that users can expect from these FDE solutions regarding physical access threats. We assume that strong cryptography like AES cannot be broken but focus on vulnerabilities arising from practical FDE implementations. We present the results of a comprehensive and systematic comparison of the security of software- and hardware-based FDE. Thereby, we exhibit attacks on widespread FDE standards in many common scenarios and different system configurations. As a result, we show that neither software- nor hardware-based FDE provides perfect security, nor is one clearly superior to the other.
Keywords
Drives; Encryption; Portable computers; Random access memory; Smart phones; Cold Boot / DMA / Evil Maid / Hot Plug Attacks; Full Disk Encryption; Full disk encryption; Physical Access Threats; Self-Encrypting Drives; cold boot/DMA/evil maid/hot plug attacks; physical access threats; self-encrypting drives;
fLanguage
English
Journal_Title
Dependable and Secure Computing, IEEE Transactions on
Publisher
ieee
ISSN
1545-5971
Type
jour
DOI
10.1109/TDSC.2014.2369041
Filename
6951337
Link To Document