论文标题
NAND基于NAND闪存的存储中数据删除漏洞的调查
Investigation of Data Deletion Vulnerabilities in NAND Flash Memory Based Storage
论文作者
论文摘要
半导体NAND基于闪存的内存技术主导了电子非易失性存储媒体市场。尽管NAND Flash具有优于常规磁性HDD的卓越性能和可靠性,但它具有某些数据安全漏洞。这样的漏洞可以使媒体上存储的敏感信息暴露于安全风险。因此,有必要详细研究NAND Flash的数据安全性漏洞背后用于关键应用中的基本原因。在本文中,研究了商业NAND Flash媒体中不可靠的数据删除/消毒问题,以及导致这种脆弱性的根本原因。基于详尽的软件恢复实验(多个迭代)已在商用NAND闪存存储介质(8 GB和16 GB)上针对不同类型的文件系统(NTFS和FAT)以及OS特定的删除/擦除指令进行。对于基于Windows和Linux的DELETE/ERASE命令,获得了100%的数据恢复。在基于软件的恢复实验的帮助下,还可以观察到性能增强技术的逆效应,例如磨损水平,不良块管理等。
Semiconductor NAND Flash based memory technology dominates the electronic Non-Volatile storage media market. Though NAND Flash offers superior performance and reliability over conventional magnetic HDDs, yet it suffers from certain data-security vulnerabilities. Such vulnerabilities can expose sensitive information stored on the media to security risks. It is thus necessary to study in detail the fundamental reasons behind data-security vulnerabilities of NAND Flash for use in critical applications. In this paper, the problem of unreliable data-deletion/sanitization in commercial NAND Flash media is investigated along with the fundamental reasons leading to such vulnerabilities. Exhaustive software based data recovery experiments (multiple iterations) has been carried out on commercial NAND Flash storage media (8 GB and 16 GB) for different types of filesystems (NTFS and FAT) and OS specific delete/Erase instructions. 100 % data recovery is obtained for windows and linux based delete/Erase commands. Inverse effect of performance enhancement techniques like wear levelling, bad block management etc. is also observed with the help of software based recovery experiments.