{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,7,2]],"date-time":"2026-07-02T16:32:07Z","timestamp":1783009927735,"version":"3.54.5"},"publisher-location":"Cham","reference-count":55,"publisher":"Springer International Publishing","isbn-type":[{"value":"9783030687335","type":"print"},{"value":"9783030687342","type":"electronic"}],"license":[{"start":{"date-parts":[[2021,1,1]],"date-time":"2021-01-01T00:00:00Z","timestamp":1609459200000},"content-version":"tdm","delay-in-days":0,"URL":"http:\/\/www.springer.com\/tdm"},{"start":{"date-parts":[[2021,1,1]],"date-time":"2021-01-01T00:00:00Z","timestamp":1609459200000},"content-version":"vor","delay-in-days":0,"URL":"http:\/\/www.springer.com\/tdm"}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2021]]},"DOI":"10.1007\/978-3-030-68734-2_2","type":"book-chapter","created":{"date-parts":[[2021,2,9]],"date-time":"2021-02-09T01:14:09Z","timestamp":1612833249000},"page":"23-43","update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":5,"title":["Make Remote Forensic Investigations Forensic Again: Increasing the Evidential Value of Remote Forensic Investigations"],"prefix":"10.1007","author":[{"given":"Marcel","family":"Busch","sequence":"first","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Florian","family":"Nicolai","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Fabian","family":"Fleischer","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Christian","family":"R\u00fcckert","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Christoph","family":"Safferling","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Felix","family":"Freiling","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"297","published-online":{"date-parts":[[2021,2,7]]},"reference":[{"key":"2_CR1","unstructured":"Android Open Source Project: Using reference boards. https:\/\/source.android.com\/setup\/build\/devices. Accessed 15 Sept 2020"},{"key":"2_CR2","unstructured":"BoringSSL. https:\/\/boringssl.googlesource.com\/boringssl\/. Accessed 15 Sept 2020"},{"key":"2_CR3","unstructured":"Genode Operating System Framework. https:\/\/genode.org\/. Accessed 15 Sept 2020"},{"key":"2_CR4","unstructured":"German Federal Constitutional Court BVerfGE 120, pp. 274, p. 318\u2013319; Handyside v. The United Kingdom, 24 ECHR (Ser. A) 23 at para. 49 (1976)"},{"key":"2_CR5","unstructured":"Lorraine v. Markel American Insurance Company, 2007, United States District Court for the District of Maryland, 241 F.R.D. 534 (D. Md. 2007)"},{"key":"2_CR6","unstructured":"Open Portable Trusted Execution Environment. https:\/\/www.op-tee.org. Accessed 15 Sept 2020"},{"key":"2_CR7","unstructured":"RFC5246 - The Transport Layer Security (TLS) Protocol Version 1.2. https:\/\/tools.ietf.org\/html\/rfc5246. Accessed 15 Sept 2020"},{"key":"2_CR8","unstructured":"Skinner v. Ry. Labor Executives\u2019 Ass\u2019n, 489 U.S. 602, 629 n. 9 (1989)"},{"key":"2_CR9","unstructured":"R. v. Oakes. 1 SCR 103 (1986)"},{"key":"2_CR10","unstructured":"Security enclave processor for a system on a chip (2012). https:\/\/patents.google.com\/patent\/US8832465B2\/en. Accessed 15 Sept 2020"},{"key":"2_CR11","doi-asserted-by":"crossref","unstructured":"Abeyratne, R.: More structure, more deference: proportionality in Hong Kong. In: Yap, P.J. (ed.) Proportionality in Asia (2019)","DOI":"10.1017\/9781108862950.003"},{"key":"2_CR12","unstructured":"ARM: Arm\u00aeR architecture reference manual Armv8, for Armv8-A architecture profile documentation. https:\/\/developer.arm.com\/docs\/ddi0487\/latest. Accessed 15 Sept 2020"},{"key":"2_CR13","unstructured":"ARM: ARM security technology: Building a secure system using trustzone technology (2008). https:\/\/static.docs.arm.com\/genc009492\/c\/PRD29-GENC-009492C_trustzone_security_whitepaper.pdf. Accessed 15 Sept 2020"},{"key":"2_CR14","doi-asserted-by":"publisher","unstructured":"Azab, A.M., et al.: Hypervision across worlds: real-time kernel protection from the arm trustzone secure world. In: Proceedings of the 2014 ACM SIGSAC Conference on Computer and Communications Security, pp. 90\u2013102. CCS 2014. Association for Computing Machinery, New York (2014). https:\/\/doi.org\/10.1145\/2660267.2660350","DOI":"10.1145\/2660267.2660350"},{"key":"2_CR15","unstructured":"Barak, A.: Proportionality - Constitutional Rights and their Limitations, pp. 181\u2013208, Concerning the Legal Sources See pp. 211\u2013241. Cambridge University Press, Cambridge (2012)"},{"key":"2_CR16","unstructured":"Casey, E.: Digital Evidence and Computer Crime - Forensic Science, Computers and the Internet, 3rd edn. Academic Press, Cambridge (2011). http:\/\/www.elsevierdirect.com\/product.jsp?isbn=9780123742681. Accessed 15 Sept 2020"},{"key":"2_CR17","doi-asserted-by":"crossref","unstructured":"Cohen-Eliya, M., Porat, I.: Proportionality and Constitutional Culture. Cambridge University Press, Cambridge (2013)","DOI":"10.1017\/CBO9781139134996"},{"key":"2_CR18","unstructured":"Cupa, B.: Trojan horse resurrected - on the legality of the use of government spyware. In: Webster, C., William, R. (eds.) Living in Surveillance Societies: The state of Surveillance: Proceedings of LiSS Conference, vol. 3. pp. 419\u2013428. CreateSpace Independent Publishing Platform (2013)"},{"key":"2_CR19","unstructured":"Dent, A.W.: Secure boot and image authentication (2019). https:\/\/www.qualcomm.com\/media\/documents\/files\/secure-boot-and-image-authentication-technical-overview-v2-0.pdf. Accessed 15 Sept 2020"},{"key":"2_CR20","unstructured":"Dewald, A., et al.: Analyse und vergleich von BckR2D2-I und II. In: Suri, N., Waidner, M. (eds.) Sicherheit 2012: Sicherheit, Schutz und Zuverl\u00e4ssigkeit, Beitr\u00e4ge der 6. Jahrestagung des Fachbereichs Sicherheit der Gesellschaft f\u00fcr Informatik e.V. (GI), 7.-9. M\u00e4rz 2012 in Darmstadt. LNI, vol. P-195, pp. 47\u201358. GI (2012). https:\/\/dl.gi.de\/20.500.12116\/18287. Accessed 15 Sept 2020"},{"key":"2_CR21","unstructured":"European Telecommunications Standards Institute: Handover interface for the lawful interception of telecommunications traffic (1999). https:\/\/www.etsi.org\/deliver\/etsi_ts\/101600_101699\/101671\/03.11.01_60\/ts_101671v031101p.pdf. Accessed 15 Sept 2020"},{"key":"2_CR22","unstructured":"European Union, Directorate-General for Internal Policies: Legal frameworks for hacking by law enforcement: Identification, evaluation and comparison of practices (2017). http:\/\/www.europarl.europa.eu\/supporting-analyses. Accessed 15 Sept 2020"},{"key":"2_CR23","unstructured":"Freiling, F., Safferling, C., R\u00fcckert, C.: Quellen-TK\u00dc und Online-Durchsuchung als neue Ma\u00dfnahmen f\u00fcr die Strafverfolgung: Rechtliche und technische Herausforderungen. Juristische Rundschau 2018, 9\u201322 (2018)"},{"key":"2_CR24","doi-asserted-by":"publisher","unstructured":"Fr\u00f6wis, M., Gottschalk, T., Haslhofer, B., R\u00fcckert, C., Pesch, P.: Safeguarding the evidential value of forensic cryptocurrency investigations. Forensic Sci. Int. Digital Invest. https:\/\/doi.org\/10.1016\/j.fsidi.2019.200902","DOI":"10.1016\/j.fsidi.2019.200902"},{"key":"2_CR25","unstructured":"Garfinkel, T., Rosenblum, M., et al.: A virtual machine introspection based architecture for intrusion detection. In: Ndss. vol. 3, pp. 191\u2013206. Citeseer (2003)"},{"key":"2_CR26","unstructured":"GlobalPlatform: TEE sockets API specification v1.0.1 (2017). https:\/\/globalplatform.org\/specs-library\/tee-sockets-api-specification-v1-0-1\/. Accessed 15 Sept 2020"},{"key":"2_CR27","unstructured":"Goodison, S.E., Davis, R.C., Jackson, B.A.: Digital evidence and the US criminal justice system: identifying technology and other needs to more effectively acquire and utilize digital evidence, pp. 9\u201310. RAND Corporation (2015). www.jstor.org\/stable\/10.7249\/j.ctt15sk8v3. Accessed 15 Sept 2020"},{"key":"2_CR28","unstructured":"Google: Protected confirmation (2020). https:\/\/source.android.com\/security\/protected-confirmation. Accessed 15 Sept 2020"},{"key":"2_CR29","unstructured":"Google Widevine: Widevine - leading content protection for media (2019). https:\/\/www.widevine.com\/. Accessed 15 Sept 2020"},{"key":"2_CR30","unstructured":"Grabenwarter, C.: ECHR - Commentary, Art. 8 para. 3, 4, 28 (2014)"},{"key":"2_CR31","doi-asserted-by":"publisher","first-page":"S12","DOI":"10.1016\/j.diin.2013.06.002","volume":"10","author":"J Grover","year":"2013","unstructured":"Grover, J.: Android forensics: automated data collection and reporting from a mobile device. Digital Invest. 10, S12\u2013S20 (2013)","journal-title":"Digital Invest."},{"key":"2_CR32","doi-asserted-by":"crossref","unstructured":"Guerra, M., Taubmann, B., Reiser, H.P., Yalew, S., Correia, M.: Introspection for ARM TrustZone with the ITZ library. In: 2018 IEEE International Conference on Software Quality, Reliability and Security (QRS), pp. 123\u2013134. IEEE (2018)","DOI":"10.1109\/QRS.2018.00026"},{"key":"2_CR33","unstructured":"Hayton, R.: The benefits of trusted user interface (TUI) (2019). https:\/\/www.trustonic.com\/news\/blog\/benefits-trusted-user-interface\/. Accessed 15 Sept 2020"},{"key":"2_CR34","doi-asserted-by":"crossref","unstructured":"Hebbal, Y., Laniepce, S., Menaud, J.M.: Virtual machine introspection: techniques and applications. In: 2015 10th International Conference on Availability, Reliability and Security, pp. 676\u2013685. IEEE (2015)","DOI":"10.1109\/ARES.2015.43"},{"key":"2_CR35","unstructured":"Huawei Technologies: Emui 8.0 security technical white paper (2017). https:\/\/consumer-img.huawei.com\/content\/dam\/huawei-cbg-site\/en\/mkt\/legal\/privacy-policy\/EMUI 8.0 Security Technology White Paper.pdf. Accessed 15 Sept 2020"},{"key":"2_CR36","unstructured":"Lengyel, T.K., Kittel, T., Eckert, C.: Virtual machine introspection with Xen on ARM. In: Workshop on Security in highly connected IT systems (SHCIS) (2015)"},{"key":"2_CR37","unstructured":"Lumme, M., Eloranta, J., Jokinen, H.: Interception system and method (1999). https:\/\/patents.google.com\/patent\/US20020049913. Accessed 15 Sept 2020"},{"key":"2_CR38","unstructured":"Maras, M.H.: Computer Forensics, 2nd edn. Jones & Bartlett Learning, Burlington (2015)"},{"key":"2_CR39","unstructured":"Marquis-Boire, M., Marczak, B., Guarnieri, C., Scott-Railton, J.: For their eyes only. The commercialization of digital spying. Citizen Lab report, September 2013. https:\/\/citizenlab.org\/storage\/finfisher\/final\/fortheireyesonly.pdf. Accessed 15 Sept 2020"},{"key":"2_CR40","doi-asserted-by":"publisher","first-page":"37","DOI":"10.1080\/09332480.2016.1156365","volume":"29","author":"C Neumann","year":"2016","unstructured":"Neumann, C., Kaye, D., Jackson, G., Reyna, V., Ranadive, A.: Presenting quantitative and qualitative information on forensic science evidence in the courtroom. Chance 29, 37\u201343 (2016)","journal-title":"Chance"},{"key":"2_CR41","doi-asserted-by":"crossref","unstructured":"Payne, B.D.: Simplifying virtual machine introspection using LibVMI. Sandia report, pp. 43\u201344 (2012)","DOI":"10.2172\/1055635"},{"key":"2_CR42","unstructured":"Qualcomm: Qualcomm mobile security (2018). https:\/\/www.qualcomm.com\/solutions\/mobile-computing\/features\/security. Accessed 15 Sept 2020"},{"key":"2_CR43","doi-asserted-by":"crossref","unstructured":"Rueckert, C.: Cryptocurrencies and fundamental rights. J. Cybersecur. 5, 6 (2019)","DOI":"10.1093\/cybsec\/tyz004"},{"key":"2_CR44","unstructured":"Samsung: Trustonic for KNOX (2015). https:\/\/news.samsung.com\/global\/samsung-and-trustonic-launch-trustonic-for-knox-delivering-a-whole-new-level-of-trust-enhanced-experiences-on-samsung-mobile-devices. Accessed 15 Sept 2020"},{"key":"2_CR45","unstructured":"Samsung: Samsung TEEGRIS (2020). https:\/\/developer.samsung.com\/teegris\/overview.html. Accessed 15 Sept 2020"},{"key":"2_CR46","doi-asserted-by":"publisher","unstructured":"Samuel, J., Mathewson, N., Cappos, J., Dingledine, R.: Survivable key compromise in software update systems. In: Proceedings of the 17th ACM Conference on Computer and Communications Security, CCS 2010, Chicago, Illinois, USA, 4\u20138 October 2010, pp. 61\u201372 (2010). https:\/\/doi.org\/10.1145\/1866307.1866315","DOI":"10.1145\/1866307.1866315"},{"key":"2_CR47","unstructured":"Sieber, U., von zur M\u00fchlen, N. (eds.): Access to Telecommunication Data in Criminal Justice. A Comparative Analysis of European Legal Orders. Duncker & Humblot, Berlin (2016)"},{"key":"2_CR48","unstructured":"Strossen, N.: The fourth amendment in the balance: accurately setting the scales through the least intrusive alternative analysis. 63 NYUL Rev. 1173 (1988)"},{"key":"2_CR49","doi-asserted-by":"publisher","first-page":"S112","DOI":"10.1016\/j.diin.2014.03.014","volume":"11","author":"J St\u00fcttgen","year":"2014","unstructured":"St\u00fcttgen, J., Cohen, M.: Robust Linux memory acquisition with minimal target impact. Digital Invest. 11, S112\u2013S119 (2014)","journal-title":"Digital Invest."},{"issue":"12","key":"2_CR50","doi-asserted-by":"publisher","first-page":"2547","DOI":"10.1109\/TIFS.2015.2467356","volume":"10","author":"H Sun","year":"2015","unstructured":"Sun, H., Sun, K., Wang, Y., Jing, J.: Reliable and trustworthy memory acquisition on smartphones. IEEE Trans. Inf. Forensics Secur. 10(12), 2547\u20132561 (2015)","journal-title":"IEEE Trans. Inf. Forensics Secur."},{"issue":"3\u20134","key":"2_CR51","doi-asserted-by":"publisher","first-page":"175","DOI":"10.1016\/j.diin.2011.10.003","volume":"8","author":"J Sylve","year":"2012","unstructured":"Sylve, J., Case, A., Marziale, L., Richard, G.G.: Acquisition and analysis of volatile memory from android devices. Digital Invest. 8(3\u20134), 175\u2013184 (2012)","journal-title":"Digital Invest."},{"key":"2_CR52","doi-asserted-by":"publisher","first-page":"S67","DOI":"10.1016\/j.diin.2018.04.013","volume":"26","author":"B Taubmann","year":"2018","unstructured":"Taubmann, B., Alabduljaleel, O., Reiser, H.P.: DroidKex: fast extraction of ephemeral TLS keys from the memory of Android apps. Digital Invest. 26, S67\u2013S76 (2018)","journal-title":"Digital Invest."},{"key":"2_CR53","doi-asserted-by":"crossref","unstructured":"Thing, V.L., Ng, K.Y., Chang, E.C.: Live memory forensics of mobile phones. Digital Invest. 7, S74\u2013S82 (2010)","DOI":"10.1016\/j.diin.2010.05.010"},{"key":"2_CR54","unstructured":"WikiLeaks: Spyfiles 4. https:\/\/wikileaks.org\/spyfiles4\/. Accessed 15 Sept 2020"},{"issue":"1","key":"2_CR55","first-page":"205","volume":"129","author":"LB Winter","year":"2017","unstructured":"Winter, L.B.: Remote computer searches under Spanish law: the proportionality principle and the protection of privacy. Zeitschrift f\u00fcr die gesamte Strafrechtswissenschaft 129(1), 205\u2013231 (2017)","journal-title":"Zeitschrift f\u00fcr die gesamte Strafrechtswissenschaft"}],"container-title":["Lecture Notes of the Institute for Computer Sciences, Social Informatics and Telecommunications Engineering","Digital Forensics and Cyber Crime"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/978-3-030-68734-2_2","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2021,4,24]],"date-time":"2021-04-24T19:56:40Z","timestamp":1619294200000},"score":1,"resource":{"primary":{"URL":"https:\/\/link.springer.com\/10.1007\/978-3-030-68734-2_2"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2021]]},"ISBN":["9783030687335","9783030687342"],"references-count":55,"URL":"https:\/\/doi.org\/10.1007\/978-3-030-68734-2_2","relation":{},"ISSN":["1867-8211","1867-822X"],"issn-type":[{"value":"1867-8211","type":"print"},{"value":"1867-822X","type":"electronic"}],"subject":[],"published":{"date-parts":[[2021]]},"assertion":[{"value":"7 February 2021","order":1,"name":"first_online","label":"First Online","group":{"name":"ChapterHistory","label":"Chapter History"}},{"value":"ICDF2C","order":1,"name":"conference_acronym","label":"Conference Acronym","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"International Conference on Digital Forensics and Cyber Crime","order":2,"name":"conference_name","label":"Conference Name","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"Boston, MA","order":3,"name":"conference_city","label":"Conference City","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"USA","order":4,"name":"conference_country","label":"Conference Country","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"2020","order":5,"name":"conference_year","label":"Conference Year","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"15 October 2020","order":7,"name":"conference_start_date","label":"Conference Start Date","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"16 October 2020","order":8,"name":"conference_end_date","label":"Conference End Date","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"11","order":9,"name":"conference_number","label":"Conference Number","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"icdf2c2020","order":10,"name":"conference_id","label":"Conference ID","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"http:\/\/d-forensics.org\/","order":11,"name":"conference_url","label":"Conference URL","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"Double-blind","order":1,"name":"type","label":"Type","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"Confyplus","order":2,"name":"conference_management_system","label":"Conference Management System","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"35","order":3,"name":"number_of_submissions_sent_for_review","label":"Number of Submissions Sent for Review","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"11","order":4,"name":"number_of_full_papers_accepted","label":"Number of Full Papers Accepted","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"4","order":5,"name":"number_of_short_papers_accepted","label":"Number of Short Papers Accepted","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"31% - The value is computed by the equation \"Number of Full Papers Accepted \/ Number of Submissions Sent for Review * 100\" and then rounded to a whole number.","order":6,"name":"acceptance_rate_of_full_papers","label":"Acceptance Rate of Full Papers","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"4.7","order":7,"name":"average_number_of_reviews_per_paper","label":"Average Number of Reviews per Paper","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"No","order":9,"name":"external_reviewers_involved","label":"External Reviewers Involved","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"Due to COVID 19 pandemic teh conference was held virtually.","order":10,"name":"additional_info_on_review_process","label":"Additional Info on Review Process","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}}]}}