Skip to content

NAND Flash

Definition

The type of non-volatile memory used in all modern mobile device storage. Data is written to pages grouped into blocks; erasure operates at the block level. NAND flash has a finite write endurance per cell, which drives the wear-leveling and garbage collection behaviors that affect forensic recovery.

Type
Non-volatile memory
Used in
Mobile device storage
Write unit
Page
Erase unit
Block
Key limitation
Finite write endurance per cell

Common questions

Why do wear-leveling and garbage collection complicate forensic recovery from NAND flash?+

Wear-leveling spreads writes across physical cells to extend the memory's lifespan, so a file's logical location does not correspond to a fixed physical address, and garbage collection can permanently erase blocks marked as deleted in the background, independent of any action by the examiner. Together they mean deleted data can vanish irretrievably before an examiner ever images the device.

Why can't a NAND flash chip simply overwrite data in place the way a hard drive can?+

NAND flash can only write to a page that has first been erased, and erasure happens at the coarser block level covering many pages at once. This mismatch is why flash storage relies on a flash translation layer to remap logical addresses to physical pages and periodically consolidate data through garbage collection.

Related terms

App Sandbox Container
An isolated directory assigned to each app on iOS under /var/mobile/Containers/Data/Application/<UUID>/. The container holds all of the app's Documents, Library, and tmp...
Bootloader
Firmware that runs immediately after power-on to verify, load, and hand control to the operating system. A locked bootloader refuses to execute...
Chip-Off Acquisition
A physical extraction method in which the flash memory chip is desoldered from the device's circuit board and read directly with specialised...
EDL Mode (Emergency Download Mode)
A Qualcomm diagnostic protocol embedded in the Primary Boot Loader (PBL) that activates before the main OS and accepts raw memory read...
File-Based Encryption (FBE)
An Android encryption model introduced in Android 7.0 in which each file is encrypted with a separate key derived from the user...
Full-Disk Encryption (FDE)
A storage protection model in which the entire partition is encrypted with a key derived from the user's passcode and hardware-bound identifiers....
iOS Keychain
A hardware-backed secure credential store on iOS devices that holds passwords, authentication tokens, and cryptographic keys. Keychain items are encrypted with keys...
Plist (Property List)
A structured data format native to Apple operating systems, available in XML and binary variants. iOS uses plist files to store app...
SQLite
A lightweight, serverless relational database engine used pervasively on both iOS and Android to store structured app data including messages, call logs,...
Wear-Leveling
A flash storage controller behavior that distributes write operations across all available memory cells to prevent premature failure of any single cell....

Explained in these topics

Your journey to becoming a forensic professional starts here.

Practice with mock tests, learn from structured notes, and get your questions answered by a global forensic community, all in one place.