信息网络安全 ›› 2014, Vol. 14 ›› Issue (9): 211-213.doi: 10.3969/j.issn.1671-1122.2014.09.049

• Orginal Article • Previous Articles     Next Articles

The Method of Decrypting FileVault2 Offline and Applications in Forensics

LAN Chao-xiang, SHEN Chang-da, QIAN Jing-jie   

  1. Xiamen Meiya Pico Information Co.,Ltd., Xiamen Fujian 361008, China
  • Received:2014-08-06 Online:2014-09-01

Abstract: Apple launched OS X 10.3 (Panther) system, the introduction of a FileVault disk encryption feature. In the latest release of OS X Lion system, the introduction of a new encryption FileVault2. FileVault2 uses full disk, AES-XTS 128 encryption to help keep data secure. Given that most of forensic soft can’t achieve forensics quickly on FileVault2 encrypting disk. This paper first discusser encrypting principles of the FileVault2, then puts the FileVault2 decryption method offline. And on this basis, designs the decrypting FileVault2 tools, which works independent of the operating system on the target data source and able to in the absence of Mac OS system environment through FileVault2 encrypted disk forensics. Practice shows that offline decryption method enriches the evidence items.

Key words: encrypting disk, encrypt, decrypt