System and method for preserving electronically stored information

Inventors

Shirk, Eric S.

Assignees

BDO USA PC

Interested in licensing this patent?

MTEC can help explore whether this patent might be available for licensing for your application.

Publication Number

US-9098730-B2

Patent

Publication Date

2015-08-04

Expiration Date


Abstract

A system and method for collection of electronically stored information (ESI) from Windows based desktops and laptops is disclosed that are under the control of remote custodians. The system and method include an external persistent memory storage device and a software application tool that is loaded onto the persistent memory storage device. The external persistent memory storage device is connected to the computer system hosting the persistent memory storage device to be examined, for example, by way of a USB or Ethernet port. Once connected to the computer system hosting the persistent memory storage device to be examined, a Quick Start program, which, when opened, allows the required processing to be methodically performed. Documentation is provided for completing information regarding the chain of custody of the external persistent memory storage device. The documentation may be imprinted on a security receptacle for receiving the external persistent memory storage device. The security receptacle is configured to protect the persistent memory storage device from electrostatic discharge and to indicate if the bag or container was tampered with after it was sealed.

Core Innovation

A method and system are described for collecting electronically stored information of one or more source files including available deleted files stored on an internal persistent storage device in a target computer. The approach uses an external persistent memory storage device connected to the target computer, and a resident software application tool on the external device that is loaded into memory of the target computer to copy the source files and available deleted files and create an image defining one or more image files on the external persistent memory storage device. The created image is generated without changing any data or associated meta data stored on the source file.

The method verifies that the image file is an exact copy of the source files and available deleted files by determining hash value(s) of the one or more source files and available deleted files and determining hash value(s) of the one or more image files, then comparing the hash value(s). Based upon the comparison, the method determines that the image file(s) are an exact copy of the source files and available deleted files. The results are stored on the external persistent memory storage device in connection with the verified image.

After the image file is stored, the method disconnects the external persistent memory storage device from the target computer and secures the external persistent memory storage device in a sealable secure container for receiving the external persistent memory storage device. The container is configured to protect the external persistent memory storage device from electrostatic discharge and to indicate if the container has been tampered with after it has been sealed, supporting evidentiary integrity for the collected electronically stored information. The described workflow options include selectable evidence formats and recording partition-related information with the one or more image files to support completeness.

Claims Coverage

The provided content includes two independent method claims, each centered on creating and verifying a forensically verifiable image of source files including available deleted files onto an external persistent memory storage device using a resident software tool, with verification based on hash value comparisons and storage of results prior to sealing the device. Dependent claims add refinements such as user-visible instruction, selectable image formats, and partition identification/coverage checks.

Resident software imaging tool loaded into memory

loading a software application tool resident on the external persistent memory storage device into the memory of a target computer, said software application tool including instructions for causing said target computer to copy said one or more source files and available deleted files stored on said internal persistent storage device in target computer and create an image of said one or more source files and deleted files on said external persistent memory storage device defining one or more image files, wherein said image is created without changing any data or associated meta data stored on the source file

Hash-based verification of exact copy

verifying that said image file is an exact copy of said one or more source files and available deleted files by way of said software application tool comprising the steps of determining a hash value of said one or more source files and available deleted files; determining a hash value of said one or more image files; comparing the hash value of said one or more source files including available deleted files with said hash value of said one or more image files; based upon the comparison, determining that said one or more image files are an exact copy of said one or more source files and available deleted files

Sealable ESD-protective tamper-indicating container

securing said external persistent memory storage device with said image file from said target computer stored thereon in a sealable secure container for receiving the external persistent memory storage device, configured to protect the external persistent memory storage device from electrostatic discharge and to indicate if the container has been tampered with after it has been sealed

Storing verification results on the external persistent memory storage device

storing the results of step (c) in said external persistent memory storage device

Across the independent claims, the inventive coverage is directed to using a resident software application tool on the external persistent memory storage device loaded into RAM to create an image without changing data or associated meta data, verifying exact-copy status via determining and comparing hash values of the source files including available deleted files and the image files, and disconnecting and securing the external persistent memory storage device in a sealable secure container configured for electrostatic discharge protection and tamper indication. One independent claim additionally includes storing the verification results on the external persistent memory storage device.

Stated Advantages

Creates an image without changing any data or associated meta data stored on the source file.

Enables verification that the image file is an exact copy by determining and comparing hash value(s) of source files and image files.

Supports protecting the external persistent memory storage device from electrostatic discharge.

Supports indicating if the container has been tampered with after it has been sealed.

Documented Applications

Forensic collection of electronically stored information on Windows desktops/laptops/servers, including available deleted files, onto an external persistent memory device using a resident “Quick Start” tool loaded into RAM on a remote target computer.

Forensic expert handling of an authenticated image file, including workflow options for evidence format (Raw/Smart/E01) and partition-related recording to support completeness.

JOIN OUR MAILING LIST

Stay Connected with MTEC

Keep up with active and upcoming solicitations, MTEC news and other valuable information.