A study on the decryption methods of telegram X and BBM-Enterprise databases in mobile and PC. (December 2020)
- Record Type:
- Journal Article
- Title:
- A study on the decryption methods of telegram X and BBM-Enterprise databases in mobile and PC. (December 2020)
- Main Title:
- A study on the decryption methods of telegram X and BBM-Enterprise databases in mobile and PC
- Authors:
- Kim, Giyoon
Park, Myungseo
Lee, Sehoon
Park, Younjai
Lee, Insoo
Kim, Jongsung - Abstract:
- Abstract: Instant messenger (IM) apps, which store a variety of behavioral information about users, such as secret chats, group chats, and file sharing, are important tools for digital forensics investigation. Messenger apps on mobile devices store user-friendly data, but data collection can be difficult due to various constraints. PC messenger data, on the other hand, can be collected relatively easily, but tend to be less informative than data from mobile messengers. Most messengers are cross-platform, supporting both mobile devices and PCs, and providing synchronization services, a situation which can overcome the constraints of data extraction for evidence acquisition. This allows for complementary interaction when extracting data generated by the use of IMs. However, some IMs encrypt their data for protection against external threats. The use of encryption can effectively protect the user's data, but poses a significant challenge to digital forensics, in which data should be decrypted to be used as evidence. Such IMs normally use a combination of key derivation functions and cryptographic algorithms to encrypt data. It is therefore necessary to identify the relationships between the functions used for encryption, in order to decrypt IM data, so that it can be used as evidence, and to determine the secret values used for generating keys. In this paper, we propose methods for acquiring user data, including conversation history protected by encryption by analyzing theAbstract: Instant messenger (IM) apps, which store a variety of behavioral information about users, such as secret chats, group chats, and file sharing, are important tools for digital forensics investigation. Messenger apps on mobile devices store user-friendly data, but data collection can be difficult due to various constraints. PC messenger data, on the other hand, can be collected relatively easily, but tend to be less informative than data from mobile messengers. Most messengers are cross-platform, supporting both mobile devices and PCs, and providing synchronization services, a situation which can overcome the constraints of data extraction for evidence acquisition. This allows for complementary interaction when extracting data generated by the use of IMs. However, some IMs encrypt their data for protection against external threats. The use of encryption can effectively protect the user's data, but poses a significant challenge to digital forensics, in which data should be decrypted to be used as evidence. Such IMs normally use a combination of key derivation functions and cryptographic algorithms to encrypt data. It is therefore necessary to identify the relationships between the functions used for encryption, in order to decrypt IM data, so that it can be used as evidence, and to determine the secret values used for generating keys. In this paper, we propose methods for acquiring user data, including conversation history protected by encryption by analyzing the Telegram X and BBM-Enterprise apps that perform in various mobile and PC operating environments. Both applications encrypt their databases using an SQLite extension module called SQLCipher. In order to decrypt these databases, we identified the parameters of SQLCipher, and derived a Passphrase, the main secret. In addition, We validated our approach by conducting an experiment to decrypt the encrypted databases of Telegram X and BBM-Enterprise. Highlights: The administration personal information method of instant messenger is different for each manufacturer. Telegram X, Unigram, BBM-Enterprise(Android), BBM-Enterprise(iOS), and BBM-Enterprise(Mac) encrypt whole user data generating by conversation. The password used for encryption is verified using the authenticator contained in the messenger-generated data. Encrypted Telegram X, Unigram, BBM-Enterprise(Android), BBM-Enterprise(iOS), and BBM-Enterprise(Mac) private data are encrypted /decrypted based on randomly generated password. … (more)
- Is Part Of:
- Forensic science international. Volume 35(2020)
- Journal:
- Forensic science international
- Issue:
- Volume 35(2020)
- Issue Display:
- Volume 35, Issue 2020 (2020)
- Year:
- 2020
- Volume:
- 35
- Issue:
- 2020
- Issue Sort Value:
- 2020-0035-2020-0000
- Page Start:
- Page End:
- Publication Date:
- 2020-12
- Subjects:
- Telegram X -- Unigram -- BBM-Enterprise -- Database decryption -- Instant messenger
- Journal URLs:
- http://www.sciencedirect.com/ ↗
- DOI:
- 10.1016/j.fsidi.2020.300998 ↗
- Languages:
- English
- ISSNs:
- 2666-2817
- Deposit Type:
- Legaldeposit
- View Content:
- Available online (eLD content is only available in our Reading Rooms) ↗
- Physical Locations:
- British Library DSC - BLDSS-3PM
British Library HMNTS - ELD Digital store - Ingest File:
- 19415.xml