- Practical Mobile Forensics(Third Edition)
- Rohit Tamma Oleg Skulkin Heather Mahalik Satish Bommisetty
- 291字
- 2021-06-30 19:33:10
The normal mode
When an iPhone is switched on, it is booted to its operating system; this mode is known as the normal mode. Most regular activities (calling, texting, and so on) performed on an iPhone will be run in the normal mode.
When an iPhone is turned on, internally, it goes through a secure boot chain, as shown in the following figure. This does not occur for jailbroken devices. Each step in the boot-up process contains software components that are cryptographically signed by Apple to ensure integrity.

The Boot ROM, known as the secure ROM, is read-only memory (ROM), and is the first significant code that runs on an iPhone (https://www.apple.com/business/docs/iOS_Security_Guide.pdf). An explanation of the boot process for iOS devices is defined in the following steps:
- The Boot ROM code contains the Apple root CA public key, which is used to verify the signature of the next stage before allowing it to load.
- When the iPhone is started, the application processor executes the code from the Boot ROM.
- The Boot ROM, in turn, verifies whether the Low Level Bootloader (LLB) is signed by Apple or not, and loads it.
- When LLB finishes its tasks, it verifies and loads the second-stage boot loader (iBoot). iBoot verifies and loads the iOS kernel.
- The iOS kernel, in turn, verifies and runs all the user applications, as shown in the preceding figure.
- The secure boot chain ensures that iOS runs only on validated Apple devices.
When an iOS device is in this state, it is possible to gain a part that is accessible to the user through forensic acquisition. Most often, this includes a logical acquisition, which will be discussed later in this chapter.
- 社會(huì)網(wǎng)絡(luò)分析方法在圖書(shū)情報(bào)領(lǐng)域的應(yīng)用研究
- 北大中文系第一課
- 檔案保護(hù)技術(shù)
- 高校圖書(shū)館門(mén)戶(hù)網(wǎng)站建設(shè)(谷臻小簡(jiǎn)·AI導(dǎo)讀版)
- 圖書(shū)館知識(shí)整合與知識(shí)服務(wù)研究:以西部社會(huì)科學(xué)院圖書(shū)館為例
- Hands-On Concurrency with Rust
- 混搭文綴
- 知中16·西南聯(lián)大的遺產(chǎn)
- 高校博物館發(fā)展研究:以上海地區(qū)為中心
- 校勘學(xué)釋例(中國(guó)文化叢書(shū)·經(jīng)典隨行)
- 區(qū)域科技情報(bào)的研究與實(shí)踐
- 顧頡剛?cè)a(bǔ)遺:顧頡剛?cè)?/a>
- 檔案修復(fù)與歷史資料的數(shù)字化:第六屆東亞史料研究編纂機(jī)構(gòu)聯(lián)席會(huì)議論文集
- 文獻(xiàn)價(jià)值:理論文獻(xiàn)學(xué)的價(jià)值論解讀
- 信息檢索與案例研究