论文标题
物联网设备的安全性:NAND闪存无效区域上的透视法律/抗法敏问题
Security of IoT Device: Perspective Forensic/Anti-Forensic Issues on Invalid Area of NAND Flash Memory
论文作者
论文摘要
NAND基于闪存的物联网设备即使删除了数据,也可能仍会在无效区域留下原始个人数据。在本文中,我们提出了由NAND闪存引起的非管理块中保留的原始数据的法医问题,并引入了无效区域中此类数据的安全删除的方法。我们还提出了一种基于单元格信息执行的安全删除的验证技术,该技术是指个人数据与存储在块中的数据之间的差异。根据误差校正能力确定验证技术的通过/失败根据细胞计数信息确定。由于取消识别的法医问题是大数据行业的重要主题,因此严重隐私的威胁加上我们防止这些攻击的建议将是未来的至关重要的技术必需品。
NAND flash memory-based IoT device can potentially still leave behind original personal data in an invalid area even if the data has been deleted. In this paper, we raise the forensic issue of original data remaining in unmanaged blocks caused by NAND flash memory and introduce methods for secure deletion of such data in the invalid area. We also propose a verification technique for secure deletion that is performed based on cell count information, which refers to the difference in bits between personal data and data stored in the block. The pass/fail of the verification technique according to the cell count information is determined in consideration of error correction capabilities. With the forensic issue of de-identification being a vital theme in the big data industry, the threat of serious privacy breaches coupled with our proposal to prevent these attacks will prove to be critical technological necessities in the future.