Forensic Analysis of Nintendo Switch

Document
Contributors
Degree granting institution: British Columbia Institute of Technology
Thesis advisor: Lvovski, Ilia
Abstract
Modern gaming consoles contain highly critical forensic evidence within proprietary non-volatile memory structures. Standard forensic acquisition interfaces are frequently omitted entirely from these encrypted hardware environments. A forensically sound data acquisition workflow was specifically developed for the Nintendo Switch console. A hardware-based Tegra processor vulnerability was exploited to physically bypass the secure boot chain. Custom bootloader payloads were injected to acquire the raw internal NAND memory bit-stream. These encrypted virtual volumes were subsequently reassembled and completely decrypted utilizing the NxNandManager software.
Subject (Topical)

Refine your search

Number of pages
41 pages
Type
Form
Language
Course
FSCT 8622
Rights

This license enables reusers to copy and distribute the material in any medium or format in unadapted form only, for noncommercial purposes only, and only so long as attribution is given to the creator. CC BY-NC-ND includes the following elements: BY: credit must be given to the creator. NC: Only noncommercial uses of the work are permitted. ND: No derivatives or adaptations of the work are permitted. https://creativecommons.org/licenses/by-nc-nd/4.0/