【24h】

Vulnerability Analysis of iPhone 6

机译:iPhone 6的漏洞分析

获取原文

摘要

Apple claims that iPhone 6, which is equipped with iOS 8.0 and later version, is secure enough to prevent a user's private data from law enforcement or malicious intruders. In pre-iOS 8.0 operating systems, a user's data were only encrypted by hardware-based keys, which can be obtained by Apple. But in iOS 8.0 and later version, the private data on the iPhone are protected by a secret key that is protected by the user's passcode, which the Apple does not hold. In this paper, supported by real-life experiments, we demonstrate that several vulnerabilities of iPhone 6 with iOS 8, which are brought by ordinary user operations, can lead to the leakage of the private data. Then we conduct vulnerability analysis and give the reasons that cause these vulnerabilities from a technical perspective. Meanwhile, experiments of forging attack aiming at iPhone 6 Touch ID are conducted.
机译:Apple声称,iPhone 6配备IOS 8.0及更高版本的版本,足以防止用户的私人数据来自执法或恶意入侵者。 在IOS 8.0预操作系统中,用户的数据仅被基于硬件的密钥加密,可以由Apple获得。 但在iOS 8.0及更高版本中,iPhone上的私有数据受到由用户密码保护的秘密密钥保护,Apple不会持有该密钥。 在本文中,通过现实生活实验支持,我们展示了普通用户操作带来的iPhone 6的几种漏洞,可以导致私有数据的泄漏。 然后,我们进行漏洞分析,并提供从技术角度导致这些漏洞的原因。 同时,进行了针对iPhone 6触摸ID的锻造攻击的实验。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号