EDBT 2026 Demo / reviewers in the wild / expert
Aya Fukami
dblp:210/3254
· DBLP profile ↗
4ranked-venue papers
3as first author
4since 2021 · last 2025
0000-0002-6393-5888ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 3 · 2 first-author · 3 since 2021Systems, architecture and hardware · 1 · 1 first-author · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2025 | Poor Sanitization Practices and Questionable Digital Evidence: A Comprehensive Study of Scope and Impact of Recycled NAND Flash ChipsabstractIn digital forensics, the provenance of data being used as digital evidence in court is frequently challenged. This is often done to raise doubts about whether the possession of some piece of illegal data was intentional. However, there may also be situations where the provenance of data is legitimately questioned, such as in the case of second-hand devices that were not well sanitized. This may also lead to the disclosure of personal or corporate data. While poor sanitization practices have already been observed for second-hand hard disk drives, this has not yet been reported for new storage devices based on flash technology. Based on insights into the second-hand chip market in certain countries, we report on the results of the first large-scale study on the effects of chip reuse for USB flash drives. We provide clear evidence of poor sanitization practices for USB flash drives from the low-cost market that were sold as new. More specifically, we forensically analyzed 1211 low-cost USB flash drives and were able to recover non-trivial data on a total of 76 devices (6%). Furthermore, we forensically analyzed 435 high-cost USB flash drives on which we could not find any evidence of chip recycling in this market sector. Janine Schneider, Aya Fukami, Immanuel Lautner, Maximilian Eichhorn, Denise Moussa, Julian Wolf 0003, Nicole Scheler, Dominic Deuber, Felix C. Freiling, Jaap Haasnoot, Hans Henseler, Simon Malik, Holger Morgenstern, Martin Westman |
IEEE Trans. Dependable Secur. Comput. | 2 |
| 2024 | Keyless Entry: Breaking and Entering eMMC RPMB with EMFIabstractThe Replay Protected Memory Block (RPMB) in modern storage systems provides a secure area where data integrity is ensured by authentication. This block is used in digital devices to store pivotal information that must be safeguarded against modification by potential attackers. This paper targets the authentication scheme of the RPMB in three different eMMCs from a major manufacturer. A glitch was injected by sending an electromagnetic pulse to the target chip. RPMB authentication was successfully glitched and the information stored in two target eMMCs was overwritten with arbitrary data, without affecting the integrity of other data. Aya Fukami, Richard Buurke |
WISEC | 1 |
| 2023 | Data Sanitization on eMMCsabstractData sanitization of modern digital devices is an important issue given that electronic wastes are being recycled and repurposed. The embedded Multi Media Card (eMMC), one of the NAND flash memory-based commodity devices, is one of the popularly recycled products in the current recycling ecosystem. We analyze a repurposed devices and evaluate its sanitization practice. Data from the formerly used device can still be recovered, which may lead to an unintentional leakage of sensitive data such as personally identifiable information (PII). Since the internal storage of an eMMC is the NAND flash memory, sanitization practice of the NAND flash memory-based systems should apply to the eMMC. However, proper sanitize operation is obviously not always performed in the current recycling ecosystem. We discuss how data stored in eMMC and other flash memory-based devices need to be deleted in order to avoid the potential data leakage. We also review the NAND flash memory data sanitization schemes and discuss how they should be applied in eMMCs. Aya Fukami, Francesco Regazzoni 0001, Zeno J. M. H. Geradts |
ASP-DAC | 1 |
| 2022 | Experimental Evaluation of e.MMC Data RecoveryabstractIn this paper, we explore the data recovery procedures from e∙MMCs. The e∙MMC is one of the “managed” flash memory devices that are popularly used in modern digital devices as their storage media. The e∙MMC, which consists of flash memory and the flash memory controller, optimizes the data input/output between the host device and the non-volatile memory through its standardized protocol. Its standardized structure and protocol makes forensic physical data acquisition simpler than handling the raw flash memory. However, its secure data purging features, such as Secure Erase and Sanitize, make data recovery from e∙MMC a challenging task. In this research, we investigate inside the e∙MMCs, and evaluate advanced data recovery procedures. By reverse engineering the structures of e∙MMCs and accessing the internal flash memory, we discover that securely erased data is still recoverable from the internal flash memory. In some models, more than 99% of the securely erased data can still be recoverable by accessing the flash memory inside the e∙MMCs. The data extraction method, along with experimental data recovery evaluation, will be explored in this paper. Aya Fukami, Sasha Sheremetov, Francesco Regazzoni 0001, Zeno J. M. H. Geradts, Cees T. A. M. de Laat |
IEEE Trans. Inf. Forensics Secur. | 1 |