RussianPatents.com
|
Cloud service and system for execution of computer-aided legal expertise of cards with magnetic strips. RU patent 2517235. |
||||||||||||||||||||||
IPC classes for russian patent Cloud service and system for execution of computer-aided legal expertise of cards with magnetic strips. RU patent 2517235. (RU 2517235):
|
FIELD: physics, computation hardware. SUBSTANCE: invention relates to computer-aided legal expertise of cards with magnetic strip. Proposed system to this end consists of n APM for legal expertise of electronic data carriers. Note here that every APM comprises network connector, cloud service driver and allows the access to network. One o said APM makes a control server for storage and management of actual software for the entire APM system. Method of computer-aided legal expertise comprises reading the data off the cards with magnetic strip. Generation in APM memory of a large binary object as an info replica of the car with magnetic strip. Said large binary object is processed by APM hardware to generate summary of expertise conclusion. Note here that different APM integrated in the network are used for generation and processing of said large binary object. EFFECT: decreased resource intensity, comprehensive computer-aided legal expertise. 2 cl, 1 dwg
The proposed method and apparatus belong to the field of criminology and forensic expertise, namely, to cloud-based technologies to improve efficiency and economic efficiency of examination and expert research of the information carriers by the centralization of a number of operations. The proposed system allows: - high reliability quickly build a binary large object as an information copy of the electronic media (ENI)which acts as a card with magnetic strip, with quantitative and qualitative characteristics ENI are not changed, which is crucial to ensure the legal validity of the procedure results of forensic expertise; - to transfer part of the binary large object that identifies a card with magnetic strip and contains the data to be processed via the communication channels to the processing tools cloud service; - to transfer the results of processing via communication channels to customers and to form the final expert opinion. One of the clans of forensic computer examination (CE). At this stage of development EC - separate genus of legal expertise related to the class engineering expertise and conducted in order to: the status of the object as computer resources, identifying and examining his paintings trace in the investigated the crime, as well as gain access to computer information on data carriers with the subsequent comprehensive her study. These goals are submitted by generic tasks EC [1]. As information sources in this kind of expertise are ENI. The process of gathering evidence on crimes involving the use of computer tools that includes, first of all, detection, capture and seizure of computer data. Tactics of investigative actions on disclosing and investigation of crimes in the discussed case integral and directly depends on the tools and instruments. These technical tools should be used for searching and preliminary studies ENI, which may subsequently acquire the status of the physical evidence. Devices, equipment, equipment, tools, accessories, used for the collection and examination of evidence in proceedings, usually denoted as "forensic technique". The primary basis of the considered class criminalistic equipment are hardware-software tools, tricks and techniques from such branches of science and technology: computer engineering and programming, radio engineering and electronics, computer networks and telecommunications, cryptography and information security. Gradually criminalistic technique updated tools, techniques and methods specifically developed for research purposes and the disclosure of crimes in the sphere of computer information. At the moment standard technical-criminalistic equipment of gathering of computer information are the following tools [2]: - personal computer (PC)with enough speed and memory, capable of preliminary full physical copy of the investigated data carriers (including hard disks) pin Winchester appropriate capacity (often in removable variant); - mounted on the specified PC operating system Windows with a set of system and application tools (e.g Norton SystemWork); - file managers (including support MS DOS-sessions), advanced application software (MS Office, graphics packages (PhotoShop, CorelDraw) and other; - set a blank CD and/or CD-R; - the CD-RW to record on CD-disks; - the necessary cables mates (including the null modem cable); - set, CD and floppy disks (boot and service tools) to determine the configuration of the investigated the personal computer, its characteristics; - set the CD and diskette with program of viral diagnostics; - packaging material: hard boxes for packing seized system units and data carriers; anti-static bags for data carriers, plastic bags and canvas bags, paper, sealing connectors, glue, sticky tape; - auxiliary tools - electronic tester, screwdrivers, pliers and other (for example, to disable connectors, opening enclosures system units, removal of the hard drives). Funds research information stored in electronic form, should provide [3]: - technical access to the information contained in the object of study (drives on hard magnetic disks, magnetic disks and tape, magneto-optical disks, tape drives, optical disks, flash memory and other means of information storage); - fixation of information, not destroying and without changing the object of study (for example, hard drives, lab computers, recordable optical discs); - convert the information into a form accessible for perception by the expert (software for search and visualization of information). These tasks are solved jointly by technical means and software security research. Thus, we can conclude that the method of solution of any task in computer expertise will need to be updated when a new generation of hardware or new versions of the software [4, 5]. Thanks to availability of highly qualified specialists in the leading expert organizations are mastered technology of carrying out of practical works on carrying out forensic examinations ENI. For this is the whole complex of specific non-standard work, designed and mastered the appropriate tools. The result of corresponding works are AWP (software or hardware-software systems) for all the specific types of work. Methodical developments and automation, accumulating knowledge and experience unique high quality experts, allow to increase the level of solution of questions EC small forces on the ground, by assigning these tasks, small group or individual staff experts. One such workplace is a system SCAN. Automated workplace PROPLAN for computerized examination is a specialized hardware and software complex for automation of activities of the expert and his work place at the EC. The technical part of the complex consists of: - the stand for research of information media, - personal electronic computer (PC) for data processing research and preparation of an expert opinion. The software part of the complex consists of a set of General and special software (OMO and CMO). As CMO used "Professional system for solution of research tasks and Logical Analysis of computer media" ("PROPLAN"). The main disadvantage of the specified workstation is unable to connect ENI new types introduced since its inception, and the impossibility of modernization to eliminate this drawback due to the limited number of codes trap that corresponds to the maximum number of the connected external devices. This disadvantage is fixed in the arm to conduct forensic examinations ENI [6]. AWP for forensics examinations ENI consists of stand for research ENI and the PC for data research and preparation of an expert opinion. The stand for investigation of ENI consists of a managed switch that enables the coupling of electronic media and the PC on information tyres and tyres control, and variable voltage source. Implemented with the help of the given workstation the way examination cards with magnetic strip, is the following: - read data from cards with magnetic strip; - form in memory arm to conduct forensics electronic media BLOB as an information copy ENI (which acts as a card with magnetic strip; - spend processing BLOB hardware workstation using special software for answers to the questions raised before the expert; - form the final expert opinion. The main disadvantage of the specified workstation is the need for all software, potentially expert for expert examination of all possible variants ENI. The specificity of forensic activity does not allow to plan the admission to the examination of the different types of ENI. In this regard, the software is used only occasionally, in a particular area of expertise of a particular type ENI, for example, magnetic stripe cards, may not be for a long time, which is a disadvantage especially for software with a one year license. Installing and configuring necessary software for each examination take significant time and reduce the efficiency of work of expert forensic, which is especially critical when doing research outside of laboratory conditions (directly at the scene). This workstation and the described method is chosen as the prototype. The aim of the invention is to create opportunities examination cards with magnetic stripe through the use of hardware and software systems from multiple workstation that will reduce capacity and increase efficiency of computer forensics. Summary of the invention: 1 System consisting of N workstation to conduct forensic examinations of electronic media, is different because every workstation contains the hardware connection to a network (network connector), software network connection (driver cloud service) and has the ability to reach the network; one of the AWS system is the managing server for storing and maintaining a database of relevant software all workstation system. 2 Method of conducting a computer forensic forensic expertise cards with magnetic strip, which contains: - read data from cards with magnetic strip; - formation in memory arm to conduct forensic examinations of electronic media of the BLOB as an information copy ENI (which acts as a card with magnetic strip; - carrying out processing of BLOB hardware workstation using special software for answers to the questions raised before the expert; - formation of summary expert opinions, notable for the formation of a binary large object and its processing are different workstation, United in a network, for which: - pass part of the binary large object that identifies a card with magnetic strip and contains the data to be processed via the communication channels for examination means a cloud service; - pass the examination results via communication channels to the consumer for the formation of the final expert opinion. List of figures: Figure 1 - diagram of the System for conducting a computer forensic forensic expertise magnetic stripe cards. Shows the main elements of the system and links between them. This goal is achieved by the fact that the System for conducting a computer forensic forensic expertise cards with magnetic stripe consists of a network of at least two arm to conduct forensic examinations ENI 1, each of which consists of: - PC 2 for the preparation and storage of methodical instructions, data research and preparation of an expert opinion (see figure 1); - Stand for research ENI 3; Network connector 4. PC 2 is a device that enables I/o, storage and processing of data through the use of General and special software. PC 2, members of different workstation to conduct forensic examinations ENI 1, depending on the software may perform one or more of three roles: Arm the expert forensic; - managing server; - a hardware device, which implements a cloud service. The stand for investigation of ENI 3 is a device that can read the information contained on the card with magnetic strip. Network connector 4 is a device that provides for PC 2 technical possibility of access to the network. Entrance Stand for research ENI 3.1 is the input of the System for conducting a computer forensic forensic expertise cards with magnetic strip, the output of each Stand for research ENI 3.i connected to the input of the PC is 2 years, the output of which is through the Network Connector 4.i connected to the Network 5. The principle of operation of the System for conducting a computer forensic forensic expertise cards with magnetic strip, is the following. Using the Stand for research ENI 3, shall read the information contained on the magnetic strip of the card and generate a PC 2.1 a copy of its information in the form of the BLOB. Using the driver cloud service, part of a binary large object that identifies a card with magnetic strip, via the communication channels are transmitted to the control server that stores and maintains a database of relevant software all workstation system. PANG 2.2., included in the arm to conduct forensic examinations ENI 1.2 role of the Manager of the server that receives the transferred data and specifies the address of the workstation to conduct forensic examinations ENI 1.3, has the software for processing the information, contained on the card with magnetic stripe, identifiable data, and sends a specific address through the network at arm to conduct forensic examinations ENI 1.1, which, having received the address, using the driver cloud service, transfers part of a binary large object that identifies a card with magnetic strip and contains the data to be processed via the communication channels for processing means a cloud service, which is arm to conduct forensic examinations ENI 1.3. AWP for forensics examinations ENI 1.3, using appropriate software, processes the information and sends the results of processing via communication channels APM 1.1, where the form of the final expert opinion. In the particular case, when a Cloud service is implemented on the Host server, the system may consist of two arm. Thus, the purpose of the invention is achieved. LIST OF LITERATURE 1. Zubaha B.C., A.I. Usov, Saenko CENTURY, Volkov GA, White S.L., Semikolenova A.I. General provisions on the appointment and the production of computer and technical expertise: Methodical recommendations. - M: state forensic science center of the Ministry of internal Affairs of Russia, 2000. - 65 C., 6 Il., bibliographer., Mgr. 2. Sheludchenko V. Technical-criminalistical means and methods of gathering the computer information/Materials of all-Russian interdepartmental seminar. - Belgorod: the Ministry of internal Affairs of the Russian Federation, 2002. - P.205-207. 3. Kopytin A.V., Marshall astray freight, Fedotov ET forensics to PMMU/Materials of all-Russian interdepartmental seminar. - Kazan: the Ministry of internal Affairs of the Republic of Tatarstan, 2004. - C.115. 4. Ikov D., Sager K., Popstar U. Computer crimes. The guide to combating cybercrime. Lane. from English. Vigorovea and Hon. - M: Mir, 1999. 6. Automated working place for conducting forensic examinations electronic media. Patent RF №2297664 from 20.04.2007. 1. The system for conducting a computer forensic forensic expertise cards with magnetic strip, consisting of N Automated working places (AWP) to conduct forensic examinations of electronic media of 1, each of which consists of personal computers (PC) 2, Stand for research of electronic media of 3, and the outputs of the Stand for study of electronic media of 3 connected to the inputs, PC 2, characterized in that each workstation 1 contains a Network connector, 4 connected to PC 2 where you installed the driver cloud service, the outputs of the Network connectors 4.i connected to the Network 5; PC 2 one workstation 1 system is the managing server for storing and maintaining a database of relevant software all AWS system, PC 2, at least one workstation 1 system contains software for the examination of magnetic stripe cards. 2. The way of conducting computer forensic forensic expertise cards with magnetic strip, which contains: read data from cards with magnetic strip; creation of in-memory arm to conduct forensic examinations of electronic media of the BLOB as an information copy ENI (which acts as a card with magnetic strip; the treatment of the BLOB hardware workstation using the software for answers to the questions raised before the expert; the formation of the final expert opinion, characterized in that formation of the BLOB and its processing are different workstation, United in a network, for which: give the part of the binary large object that identifies a card with magnetic strip and contains the data to be processed via the communication channels for examination means a cloud service; transmit the examination results via communication channels to the consumer for the formation of the final expert opinion.
|
© 2013-2014 Russian business network RussianPatents.com - Special Russian commercial information project for world wide. Foreign filing in English. |