Repository logo
 
Publication

Decrypting messages: Extracting digital evidence from signal desktop for windows

datacite.subject.fosEngenharia e Tecnologia
datacite.subject.sdg09:Indústria, Inovação e Infraestruturas
dc.contributor.authorPaulino, Gonçalo
dc.contributor.authorNegrão, Miguel
dc.contributor.authorFrade, Miguel
dc.contributor.authorDomingues, Patrício
dc.date.accessioned2025-07-21T13:26:44Z
dc.date.available2025-07-21T13:26:44Z
dc.date.issued2025-09
dc.descriptionArticle number - 301941
dc.description.abstractWith growing concerns over the security and privacy of personal conversations, end-to-end encrypted instant messaging applications have become a key focus of forensic research. This study presents a detailed methodology along with an automated Python script for decrypting and analyzing forensic artifacts from Signal Desktop for Windows. The methodology is divided into two phases: i) decryption of locally stored data and ii) analysis and documentation of forensic artifacts. To ensure data integrity, the proposed approach enables retrieval without launching Signal Desktop, preventing potential alterations. Additionally, a reporting module organizes extracted data for forensic investigators, enhancing usability. Our approach is effective in extracting and analyzing encrypted Signal artifacts, providing a reliable method for forensic investigations.eng
dc.description.sponsorshipThis work was partially by FCT/MCTES and EU funds under the project UIDB 04524/2020 and the project UIDB/EEA 50008/2020, Portugal.
dc.identifier.citationGonçalo Paulino, Miguel Negrão, Miguel Frade, Patrício Domingues, Decrypting messages: Extracting digital evidence from signal desktop for windows, Forensic Science International: Digital Investigation, Volume 54, 2025, 301941, ISSN 2666-2817, https://doi.org/10.1016/j.fsidi.2025.301941
dc.identifier.doi10.1016/j.fsidi.2025.301941
dc.identifier.issn2666-2817
dc.identifier.urihttp://hdl.handle.net/10400.8/13730
dc.language.isoeng
dc.peerreviewedyes
dc.publisherElsevier
dc.relationResearch Center in Informatics and Communications
dc.relationInstituto de Telecomunicações
dc.relation.hasversionhttps://www.sciencedirect.com/science/article/pii/S2666281725000800
dc.relation.ispartofForensic Science International: Digital Investigation
dc.rights.urihttp://creativecommons.org/licenses/by/4.0/
dc.subjectDigital forensics
dc.subjectSignal
dc.subjectWindows
dc.subjectEncryption
dc.subjectElectron
dc.subjectInstant messaging
dc.titleDecrypting messages: Extracting digital evidence from signal desktop for windowseng
dc.typejournal article
dspace.entity.typePublication
oaire.awardTitleResearch Center in Informatics and Communications
oaire.awardTitleInstituto de Telecomunicações
oaire.awardURIinfo:eu-repo/grantAgreement/FCT/6817 - DCRRNI ID/UIDB%2F04524%2F2020/PT
oaire.awardURIinfo:eu-repo/grantAgreement/FCT/6817 - DCRRNI ID/UIDP%2F50008%2F2020/PT
oaire.citation.titleForensic Science International: Digital Investigation
oaire.citation.volume54
oaire.fundingStream6817 - DCRRNI ID
oaire.fundingStream6817 - DCRRNI ID
oaire.versionhttp://purl.org/coar/version/c_970fb48d4fbd8a85
person.familyNamePaulino
person.familyNameCerdeira Negrão
person.familyNameFrade
person.familyNameDomingues
person.givenNameGonçalo
person.givenNameMiguel
person.givenNameMiguel
person.givenNamePatrício
person.identifier1234758
person.identifier.ciencia-id3B1A-36E2-B96B
person.identifier.ciencia-idA512-9B28-1CEC
person.identifier.ciencia-idAA15-6185-C477
person.identifier.orcid0009-0001-1943-842X
person.identifier.orcid0000-0002-6540-3164
person.identifier.orcid0000-0002-4405-7696
person.identifier.orcid0000-0002-6207-6292
person.identifier.ridABH-7711-2020
person.identifier.scopus-author-id24468034000
person.identifier.scopus-author-id13411315400
project.funder.identifierhttp://doi.org/10.13039/501100001871
project.funder.identifierhttp://doi.org/10.13039/501100001871
project.funder.nameFundação para a Ciência e a Tecnologia
project.funder.nameFundação para a Ciência e a Tecnologia
relation.isAuthorOfPublication3af83f8a-1504-4f5f-ba24-f58c8dbeb61b
relation.isAuthorOfPublication27585414-d859-4dc0-9cac-72e03a4407a5
relation.isAuthorOfPublication95a3fa7a-d37e-45e9-9acb-44c083582fea
relation.isAuthorOfPublicationb88ada5f-0d8b-4e55-ab0a-62aa82ea1388
relation.isAuthorOfPublication.latestForDiscovery3af83f8a-1504-4f5f-ba24-f58c8dbeb61b
relation.isProjectOfPublication67435020-fe0d-4b46-be85-59ee3c6138c7
relation.isProjectOfPublication91a8e212-cbb0-462f-b533-5ed3552e8067
relation.isProjectOfPublication.latestForDiscovery67435020-fe0d-4b46-be85-59ee3c6138c7

Files

Original bundle
Now showing 1 - 1 of 1
Loading...
Thumbnail Image
Name:
Decrypting-messages--Extracting-digital-evi_2025_Forensic-Science-Internatio.pdf
Size:
3.11 MB
Format:
Adobe Portable Document Format
License bundle
Now showing 1 - 1 of 1
No Thumbnail Available
Name:
license.txt
Size:
1.32 KB
Format:
Item-specific license agreed upon to submission
Description: