Skip to content

Data Protection Classes (iOS)

Definition

iOS encrypts each file under one of four protection classes that control when the file's encryption key is available: Complete (key available only when unlocked), Complete Unless Open (key available unless just booted), Until First User Authentication (key available after first unlock since reboot), and No Protection (key always available). Forensic acquisition tools that access data after a first unlock exploit the third class.

Platform
iOS file encryption system
Classes
Complete, Complete Unless Open, Until First Unlock, No Protection
Weakest to forensics
Until First User Authentication
Trigger
Key availability tied to device lock/boot state

Common questions

Why do forensic acquisition tools specifically target devices in an after-first-unlock (AFU) state?+

Files protected under Until First User Authentication become decryptable in memory as soon as the device is unlocked once after boot and stay that way until the next reboot, so an AFU device yields far more recoverable data than a device that has never been unlocked since power-on (BFU), even without the passcode being re-entered.

Does a strong passcode protect data assigned to the weakest protection class equally well as data in the Complete class?+

No, once a device transitions to the AFU state after first unlock, files under Until First User Authentication remain accessible to forensic tools without re-entering the passcode, while Complete-class files re-lock every time the screen locks, so passcode strength matters far less for lower-protection-class data after that initial unlock.

Related terms

APFS (Apple File System)
The default file system on iOS devices since iOS 10.3. Features include 64-bit inode numbers, copy-on-write metadata, file-level encryption using per-file keys,...
App Sandbox (iOS)
The iOS isolation mechanism combining UNIX file permissions, signed entitlements, and TrustedBSD mandatory access control. Each app is confined to a container...
Ext4
The fourth extended file system, the default Linux file system used for the userdata partition on most Android devices before widespread F2FS...
F2FS (Flash-Friendly File System)
A log-structured file system designed for NAND flash, used on the userdata partition of many modern Android devices including Samsung Galaxy and...
UID-Based Sandbox (Android)
Android's application isolation model in which each installed app receives a unique Linux user ID at install time. The app's private data...

Explained in

Your journey to becoming a forensic professional starts here.

Practice with mock tests, learn from structured notes, and get your questions answered by a global forensic community, all in one place.