Device for examining electronic pocket books

FIELD: forensic examination of electronic information carriers and, in particular, technology for accessing password-protected information, contained in electronic pocket-books.

SUBSTANCE: in accordance to the invention, code generation block generates a code series, which is injected into electronic pocket-book being examined. Visual control block receives and analyzes information from the screen of electronic pocket-book. Signal from visual control block is received at control block. If the signal from visual control block indicates a wrong password, control block outputs a command to code generation block to generate next code series. If the signal from visual control block indicates correct password, control block outputs a signal which is received by indication block.

EFFECT: possible automation of selection of password for accessing information contained in electronic pocket-books which do not have external interface.

3 dwg


The invention relates to criminology and forensics, namely the use of electronic means to improve the effectiveness and objectivity of the examination and expert studies electronic media by automating a number of operations.

The proposed device allows high reliability to quickly gain access to confidential password information stored in the memory admitted to a forensic examination of electronic notebooks (ESC), with quantitative and qualitative characteristics ask not change, which is crucial to ensure the validity of the results of forensic examination.

One of the genera of forensic examination is computer-technical expertise. At this stage of the development of computer-technical expertise - self kind of legal expertise relating to class engineering expertise and conducted in order to: determine the status of the object as computer tools, identifying and examining its trace pattern in the investigated crime, as well as access to computer information on the media data, and then its comprehensive study. These goals are represented by generic tasks CED [1].

When solving problems of computer-technical expertise often who the hiccups the need for access to information, contained in a closed, password-e memory.

Known software and hardware and software for access to information classified password stored on your computer's hard disks, notebooks, mobile terminals, cellular and organizer:

- software-hardware complex for access to information stored on hard drives PC-3000 [2];

- software-hardware complex for access to information stored in the address books of mobile communication terminals Uni box [3];

- software complex Encase [4] and others

Currently, the problem of access to information, closed the password will be solved by connecting studied engineering with the standard means of interfacing to the device (usually a computer)that feed on its input code combinations with the aim to find the password (search method).

However, in some models etc (PIMS) external interface that does not allow you to use standard tools mates.

However, the task of examination such ESC is very serious and in some cases has important social results.

Because during examinations is not permitted to change the quantitative and qualitative characteristics of the evidence, etc can explore the destructive method and, consequently, there is no possibility of retrieval of memory chips to conduct their research outside of ask. Especially that used in ezk chips are custom (non-standard) and die. So the only way is manual search.

The existing technology of access contained in the memory etc information is to generate a set of codes, which presumably password, serial input these codes from the keyboard etc and visual inspection of labels displayed on the screen etc. Assuming mismatch password entered code combination displays type : "PASSWORD is INCORRECT. REPEAT INPUT". After that you enter the following code combination. Provided matches the password entered code combination displays, with the meaning "PASSWORD ACCEPTED". Display labels in the first and second cases for different models etc may differ in content (but not meaning), language, etc. But in any case, the displayed labels in the first and second cases are different from each other and a priori known (see technical description etc, which is public information).

The described technology access to information contained in the memory received for review etc, has a number of disadvantages:

<> manual search is associated with the need for long-term engagement expert to unproductive (from the point of view of direct examination);

quality manual operations associated with operator fatigue, i.e. decreases with time;

- documentation of the process difficult.

An object of the invention is the provision of opportunities for automation of the process of selection code combination, which is the password.

The problem is solved in that a device, consisting of:

- block code generation,

block mates

block visual control,

- control unit,

- display unit.

The block of code generation is to construct a sequence of code combinations, claiming password to access the information stored in etc. It is a device having a control input, the service exit and n information outputs, where n is the number of buttons on the keyboard etc. The control signal on the control input, the block code generation generates code combination representing a sequence of non-overlapping in time of the pulses on m≤n) information outputs. The sequence of control signals on the control input, leads to the formation of placentas the activity of different code combinations, the order of which is determined by the algorithm code combinations or dictionary code combinations.

The algorithm code combinations can implement any of the known methods full or truncated search. The exhaustive search involves the formation of a sequence of code combinations containing all possible code combinations with a length not more than the maximum password length in the investigated model etc. The truncated search involves the formation of a sequence of code combinations containing all possible combinations under the given constraints, for example: the length of the combination, the composition used for password characters, and other typical variant of a truncated brute - force search various combinations of initials and dates of birth of the owner etc.

The dictionary can contain an arbitrary number of set of code combinations.

The connection unit is designed to provide a physical connection information output unit generating code outputs keyboard etc and agreeing levels of stress. In the simplest case, the connection unit is a set of conductors connecting the information outputs of the block code generation with pads keyboard etc without compromising their integrity or contacts of the keyboard connector, available from many is their models etc.

The control unit is designed to generate control signals for generating block codes. It is a device with two inputs and two outputs, performing the function of the shaper pulse-triggered inputs.

Block visual control is designed to monitor the status indicator ESC and represents a sensitive element that distinguishes the intensity (brightness) of a glow or color (for example, photodiode with lens). He must distinguish between the indicator etc corresponding to display messages about right and wrong password.

The display unit is designed to generate a signal (sound and/or light) about the end of the process of guessing a password and is a device that generates an audible and/or visual signal on the trigger signal received at its input from the output of the control unit.

The proposed solution can be used for all kinds of ask, however, due to the fact that the problem is the most difficult to resolve in the field etc without interface, particular importance is a practical solution concerning ESC types:

CitizenED-87PCL, ED-7200RX, ED-7600RX, ED-7700RX, ED-8700RX, ED-9000, ED-6200SP EDT-6800, RX-2700II, RX-3200, RX-3400II, RX-4100, RX-5000, RX-5500, RX-5640, RX-5740,RX-6600, RX-7000, RX-9600, RX-7000, MB-165RA, AX-1200, AX-200
CasioBN 10, 20 BN, SF-3990, SF-4300 (A, B), SF-4600 (RS, B, C), SF-4900 (RS, B, C), SF-4980ER, SF-4985ER, SF-4990, SF-5580, SF-5780, SF-5800RS, SF-5980, SF-6990, SF-7100SY, SF-7200SY, SF-7990, SF-8000, SF-8350R, CSF-4450 (A), CSF-4650 (A), CSF-7950, DC-7500RS, DC-7800RS, DC-8500RS, DC-9500RS
SharpZQ-150, ZQ-170, ZQ M202R, ZQ M402R, ZQ-470, ZQ-570, Language Teacher EGR 3300, EGR 5300T
EctacoER-486T, ER-586T, ER-586HT, EGR-5300T, ER-2200T, ER-3000
CanonDM-2400CR, DM-2500CR

Variant of practical implementation of the device shown in figure 1, where we have introduced the following notation:

1 is a block mates

2 - block code generation,

3 is a block visual control,

4 is a control block

5 is a block display.

Information outputs (n) block code generation 2 is connected to the inputs of the connection unit 1, the service exit a block of code generation 2 is connected to the second input of the control unit 4, to the first input of which is connected the output of block visual control 3, the first and second outputs of the control unit 4 is connected to the input of the display unit 5 and unit-code generation 2, respectively, the outputs of the connection unit 1 is designed to connect to the analyzed digital notebook, and the input unit visual inspection 3 is an optical element that takes an image from the screen of the indicator studied etc.

<> The proposed device operates as follows.

After power etc on her screen displays "ENTER PASSWORD". Manually ESC enter any code combination. If it is a password (an unlikely event), the screen displayed some attesting to the label "A", and further the procedure of expert research already does not require a password; if you entered the code combination is not a password, the screen displays some attesting to the label "B". The content and appearance of the labels "a" and "B" for different types etc may be different, but known from the technical description (instructions) to ask, which is public (can be found in the shop or on the manufacturer's website). Block visual inspection 3 is positioned relative to the screen etc so that when the first label of the output signal was absent, and when the second - attended. Then no signal at the output of block visual inspection 3 after the filing of a code combination from the output generating block codes 2 through the interface unit 1 on ESC will meet the goals of access to confidential password information stored in the memory etc. Therefore, no signal at the output of block visual inspection 3 after the filing of a code combination with the ode generating block codes 2 through the interface unit 1 on ask is for the control unit 4 a command to the completion of the generation procedure codes.

The block code generation 2 generates codes either by brute force or a truncated search, constraints which can be the maximum or the fixed-length code combination, the register used symbols can also be used brute force and dictionary.

The completion of the search (rules stop are: 1) the end of the dictionary, 2) selection of the password) may be accompanied by a sound or light signal generated by the display unit 5 by the command of the control unit 4.

Figure 2 presents the timing diagram explaining the operation of the device, where u1signals at the output 2 of the control unit 4, u21-u2nsignals on the information output unit generating codes 2, u3signals at the service entrance generating block codes 2, u4signals at the output of block visual inspection 3, u5signals on output 1 control unit 4.

At time t1corresponding to the beginning of the operation of the device, at the output 2 of the control unit 4 is formed pulse (see figure u1(t)), whose potential for generating block codes 2 is a command to start forming the code sequence. The block code generation 2 generates a sequence of pulses, which with its information outputs via the connection unit 1 is supplied to ask and provides the procedure n the Bohr first code combination (see graphics u21(t)-u2n(t)). The pulse code sequence received at the i-th output of the keyboard etc from the i-th information output generating block codes 2 through the interface unit 1, in the information sense is equivalent to a single pressing of the corresponding i-th key of the keyboard etc. For example, if the 1st information output unit generating code 2 is connected via the connection unit 1 with the output of the keyboard etc corresponding to the key "A", then the pulse on the chart u21(t) is equivalent to pressing "A" on the keyboard etc. Latest pulse code sequence (pulse "INPUT") corresponds to pressing the "ENTER" on the keyboard etc. The result on the screen ask the message "INCORRECT PASSWORD. REPEAT INPUT", resulting in output block visual control, a signal is generated indicative of the status indicator in the controlled area (see graph u4(t)). The rear edge of the pulse, the INPUT at time t2provides forms a short gate pulse at the service entrance of a block code generation 2 (see figure u3(t)), during which the control unit 4 analyzes the level of the signal received at its first input from the output of block visual inspection 3. The high level signal at the output of block visual inspection 3 leads to the formation of at the moment time is Yeni t 3at the output 2 of the control unit 4 of the pulse (see graphs u1(t) and u4(t)), runs the block of code generation 2 on the formation of the following sequence of pulses, which through the connection unit 1 is supplied to ask and provides the procedure of the second set of code combinations. The procedure is repeated up until the moment of existence stranovogo pulse at the second output generating block codes 2 will not be read from the output of block visual control 3 signal low level (time t4), resulting in a first output control unit 4 will be formed as a triggering signal for the display unit 5 (see graph u5(t)), status (enable sound and/or light signal) to indicate the completion of the procedure of selection of the password.

The algorithm of the control unit shown in figure 3.

The proposed device will provide a radical improvement potential expertise:

- by automating the recovery process increases the efficiency of the process;

- performance of an expert search using technical devices provides related work elements of the supply chain and the ability to document the action.


A device for providing access to confidential password information contained in electronic notebooks (ESC), characterized in that it contains the interface block, the outputs of which are connected to the studied etc, and the inputs to the data outputs of the generating block codes, with the official release of which to the second input control unit receives the gate pulse during which the control unit analyzes the signal received at its first input block visual inspection, which contains an optical element that takes an image from the screen etc, the control unit generates a second output pulse at the input generating block codes and which is the command for forming a code sequence, if the signal from block visual inspection indicates an incorrect password, and generates a first output signal at the input of the display unit, if the signal from block visual inspection indicates the correct password.


