ANALYSIS OF TECHNICAL FEATURES OF DATA ENCRYPTION IMPLEMENTATION ON SD CARDS IN THE ANDROID SYSTEM
Leila Rzayeva, Abulkhair Imanberdi, Ivan Opirskyy, Oleh Harasymchuk, Gulnara A. Abitova · Scientific Journal of Astana IT University · 2025
This article provides a detailed analysis of data encryption mechanisms for removable storage devices in the Android operating system. Two main information protection technologies are examined: file-based encryption when using an SD card as portable storage and full-disk encryption when using a memory card as an extension of the device's internal storage (Adoptable Storage). The technical implementation features of each method are investigated, including the encryption algorithms used, the structure of encrypted data, and key storage mechanisms. The research was conducted using Sony Xperia XZ and Xiaomi Redmi 5 Plus devices, employing tools for working with file systems and encryption based on Linux and Android. The analysis has established that full-disk encryption is utilized the dm-crypt kernel module in plain mode with AES-256-CBC-ESSIV:SHA256 cipher. The partition encryption key is stored in the device's internal memory. File-based encryption employs the eCryptFS kernel module. The file structure includes information about the original file size, format marker, flags, number of extents, their size, and the encryption key. Comparative analysis has shown that Adoptable Storage mode provides more comprehensive data protection through full-disk encryption, while Portable Storage mode with file-based encryption offers greater flexibility in use but may be less secure due to the possibility of analyzing the file system structure and file metadata. Research has revealed the implementation of encryption mechanisms depends on the device manufacturer and Android operating system version. The research findings have practical significance for understanding the level of data protection using different modes of removable storage operation in the Android system and are useful for both developers and information security specialists, as well as ordinary users.