Publication
Decrypting messages: Extracting digital evidence from signal desktop for windows
datacite.subject.fos | Engenharia e Tecnologia | |
datacite.subject.sdg | 09:Indústria, Inovação e Infraestruturas | |
dc.contributor.author | Paulino, Gonçalo | |
dc.contributor.author | Negrão, Miguel | |
dc.contributor.author | Frade, Miguel | |
dc.contributor.author | Domingues, Patrício | |
dc.date.accessioned | 2025-07-21T13:26:44Z | |
dc.date.available | 2025-07-21T13:26:44Z | |
dc.date.issued | 2025-09 | |
dc.description | Article number - 301941 | |
dc.description.abstract | With growing concerns over the security and privacy of personal conversations, end-to-end encrypted instant messaging applications have become a key focus of forensic research. This study presents a detailed methodology along with an automated Python script for decrypting and analyzing forensic artifacts from Signal Desktop for Windows. The methodology is divided into two phases: i) decryption of locally stored data and ii) analysis and documentation of forensic artifacts. To ensure data integrity, the proposed approach enables retrieval without launching Signal Desktop, preventing potential alterations. Additionally, a reporting module organizes extracted data for forensic investigators, enhancing usability. Our approach is effective in extracting and analyzing encrypted Signal artifacts, providing a reliable method for forensic investigations. | eng |
dc.description.sponsorship | This work was partially by FCT/MCTES and EU funds under the project UIDB 04524/2020 and the project UIDB/EEA 50008/2020, Portugal. | |
dc.identifier.citation | Gonçalo Paulino, Miguel Negrão, Miguel Frade, Patrício Domingues, Decrypting messages: Extracting digital evidence from signal desktop for windows, Forensic Science International: Digital Investigation, Volume 54, 2025, 301941, ISSN 2666-2817, https://doi.org/10.1016/j.fsidi.2025.301941 | |
dc.identifier.doi | 10.1016/j.fsidi.2025.301941 | |
dc.identifier.issn | 2666-2817 | |
dc.identifier.uri | http://hdl.handle.net/10400.8/13730 | |
dc.language.iso | eng | |
dc.peerreviewed | yes | |
dc.publisher | Elsevier | |
dc.relation | Research Center in Informatics and Communications | |
dc.relation | Instituto de Telecomunicações | |
dc.relation.hasversion | https://www.sciencedirect.com/science/article/pii/S2666281725000800 | |
dc.relation.ispartof | Forensic Science International: Digital Investigation | |
dc.rights.uri | http://creativecommons.org/licenses/by/4.0/ | |
dc.subject | Digital forensics | |
dc.subject | Signal | |
dc.subject | Windows | |
dc.subject | Encryption | |
dc.subject | Electron | |
dc.subject | Instant messaging | |
dc.title | Decrypting messages: Extracting digital evidence from signal desktop for windows | eng |
dc.type | journal article | |
dspace.entity.type | Publication | |
oaire.awardTitle | Research Center in Informatics and Communications | |
oaire.awardTitle | Instituto de Telecomunicações | |
oaire.awardURI | info:eu-repo/grantAgreement/FCT/6817 - DCRRNI ID/UIDB%2F04524%2F2020/PT | |
oaire.awardURI | info:eu-repo/grantAgreement/FCT/6817 - DCRRNI ID/UIDP%2F50008%2F2020/PT | |
oaire.citation.title | Forensic Science International: Digital Investigation | |
oaire.citation.volume | 54 | |
oaire.fundingStream | 6817 - DCRRNI ID | |
oaire.fundingStream | 6817 - DCRRNI ID | |
oaire.version | http://purl.org/coar/version/c_970fb48d4fbd8a85 | |
person.familyName | Paulino | |
person.familyName | Cerdeira Negrão | |
person.familyName | Frade | |
person.familyName | Domingues | |
person.givenName | Gonçalo | |
person.givenName | Miguel | |
person.givenName | Miguel | |
person.givenName | Patrício | |
person.identifier | 1234758 | |
person.identifier.ciencia-id | 3B1A-36E2-B96B | |
person.identifier.ciencia-id | A512-9B28-1CEC | |
person.identifier.ciencia-id | AA15-6185-C477 | |
person.identifier.orcid | 0009-0001-1943-842X | |
person.identifier.orcid | 0000-0002-6540-3164 | |
person.identifier.orcid | 0000-0002-4405-7696 | |
person.identifier.orcid | 0000-0002-6207-6292 | |
person.identifier.rid | ABH-7711-2020 | |
person.identifier.scopus-author-id | 24468034000 | |
person.identifier.scopus-author-id | 13411315400 | |
project.funder.identifier | http://doi.org/10.13039/501100001871 | |
project.funder.identifier | http://doi.org/10.13039/501100001871 | |
project.funder.name | Fundação para a Ciência e a Tecnologia | |
project.funder.name | Fundação para a Ciência e a Tecnologia | |
relation.isAuthorOfPublication | 3af83f8a-1504-4f5f-ba24-f58c8dbeb61b | |
relation.isAuthorOfPublication | 27585414-d859-4dc0-9cac-72e03a4407a5 | |
relation.isAuthorOfPublication | 95a3fa7a-d37e-45e9-9acb-44c083582fea | |
relation.isAuthorOfPublication | b88ada5f-0d8b-4e55-ab0a-62aa82ea1388 | |
relation.isAuthorOfPublication.latestForDiscovery | 3af83f8a-1504-4f5f-ba24-f58c8dbeb61b | |
relation.isProjectOfPublication | 67435020-fe0d-4b46-be85-59ee3c6138c7 | |
relation.isProjectOfPublication | 91a8e212-cbb0-462f-b533-5ed3552e8067 | |
relation.isProjectOfPublication.latestForDiscovery | 67435020-fe0d-4b46-be85-59ee3c6138c7 |
Files
Original bundle
1 - 1 of 1
Loading...
- Name:
- Decrypting-messages--Extracting-digital-evi_2025_Forensic-Science-Internatio.pdf
- Size:
- 3.11 MB
- Format:
- Adobe Portable Document Format
License bundle
1 - 1 of 1
No Thumbnail Available
- Name:
- license.txt
- Size:
- 1.32 KB
- Format:
- Item-specific license agreed upon to submission
- Description: