Suppr超能文献

数字取证分析提升安卓用户隐私保护

Digital Forensic Analysis to Improve User Privacy on Android.

机构信息

Platform Tech Team, WINS Co., Ltd., Seongnam 13487, Korea.

Department of Artificial Intelligence Convergence Network, Ajou University, Suwon 16499, Korea.

出版信息

Sensors (Basel). 2022 May 24;22(11):3971. doi: 10.3390/s22113971.

Abstract

The Android platform accounts for 85% of the global smartphone operating-system market share, and recently, it has also been installed on Internet-of-Things (IoT) devices such as wearable devices and vehicles. These Android-based devices store various personal information such as user IDs, addresses, and payment information and device usage data when providing convenient functions to users. Insufficient security for the management and deletion of data stored in the device can lead to various cyber security threats such as personal information leakage and identity theft. Therefore, research on the protection of personal information stored in the device is very important. However, there is a limitation that the current research for protection of personal information on the existing Android platform was only conducted on Android platform 6 or lower. In this paper, we analyze the deleted data remaining on the device and the possibility of recovery to improve user privacy for smartphones using Android platforms 9 and 10. The deleted data analysis is performed based on three data deletion scenarios: data deletion using the app's own function, data deletion using the system app's data and cache deletion function, and uninstallation of installed apps. It demonstrates the potential user privacy problems that can occur when using Android platforms 9 and 10 due to the leakage of recovered data. It also highlights the need for improving the security of personal user information by erasing the traces of deleted data that remain in the journal area and directory entry area of the filesystem used in Android platforms 9 and 10.

摘要

安卓平台占据了全球智能手机操作系统市场 85%的份额,最近,它也被安装在物联网(IoT)设备上,如可穿戴设备和车辆。这些基于安卓的设备在为用户提供便利功能的同时,存储了各种个人信息,如用户 ID、地址和支付信息以及设备使用数据。设备中存储的数据在管理和删除方面的安全性不足,可能导致各种网络安全威胁,如个人信息泄露和身份盗用。因此,研究设备中存储的个人信息保护非常重要。然而,目前对现有安卓平台上的个人信息保护的研究仅限于安卓 6 或更低版本。在本文中,我们分析了设备上残留的已删除数据及其恢复的可能性,以提高使用安卓 9 和 10 平台的智能手机的用户隐私。已删除数据的分析基于三种数据删除场景:使用应用程序自身功能删除数据、使用系统应用程序的数据和缓存删除功能删除数据,以及卸载已安装的应用程序。它展示了由于恢复数据的泄露,在使用安卓 9 和 10 时可能出现的潜在用户隐私问题。它还强调了需要通过擦除安卓 9 和 10 中使用的文件系统的日志区域和目录项区域中残留的已删除数据痕迹来提高个人用户信息的安全性。

https://cdn.ncbi.nlm.nih.gov/pmc/blobs/3a14/9182858/5b5123ea16e8/sensors-22-03971-g001.jpg

文献AI研究员

20分钟写一篇综述,助力文献阅读效率提升50倍。

立即体验

用中文搜PubMed

大模型驱动的PubMed中文搜索引擎

马上搜索

文档翻译

学术文献翻译模型,支持多种主流文档格式。

立即体验