Skip to content

System on Chip (SoC)

Definition

A single integrated circuit that combines the application processor, GPU, memory controller, image signal processor, and often the secure enclave. The SoC model determines the encryption scheme, secure boot chain, and available hardware debugging interfaces.

Combines
Application processor, GPU, memory controller, image signal processor, secure enclave
Field
Mobile device forensics
Determines
Encryption scheme, secure boot chain, debug interfaces

Common questions

Why does the specific SoC model matter before attempting a chip-off or JTAG extraction?+

The SoC determines whether hardware debugging interfaces are exposed or fused off, what the secure boot chain requires to accept a modified bootloader, and whether encryption keys are bound to the secure enclave in a way that makes raw chip-off data unreadable without that specific hardware, so the extraction method must be matched to the exact SoC generation.

How does the secure enclave inside an SoC affect what a forensic tool can recover?+

Keys held in the secure enclave, a physically isolated region of the SoC, are generally not extractable through software or even most chip-off methods, so full-disk encryption tied to that enclave typically requires the device to be unlocked or exploited through a vetted vulnerability rather than bypassed at the storage-chip level.

Do two phones with the same SoC always support the same extraction techniques?+

Not necessarily; the manufacturer's firmware, security patch level, and specific secure boot configuration built on top of the same SoC can still close off a previously usable exploit or debugging path, so the SoC model narrows the possibilities but does not by itself confirm a technique will work.

Related terms

Baseband Processor
A separate processor that manages all radio functions: cellular calls, SMS, and data connections. It runs its own real-time OS and holds...
eMMC (Embedded MultiMediaCard)
A flash storage standard that packages NAND memory chips and a controller into one soldered module using a parallel interface. Common in...
Flash Translation Layer (FTL)
Firmware inside the flash storage controller that maps logical block addresses to physical NAND blocks and implements wear levelling. Deleted files may...
Secure Enclave / Trusted Execution Environment (TEE)
A hardware-isolated execution environment within the SoC that stores device-unique encryption keys and handles cryptographic operations. The encryption key never leaves this...
UFS (Universal Flash Storage)
A newer flash storage standard using a serial interface that allows simultaneous reads and writes. Faster than eMMC and common in flagship...

Explained in

Your journey to becoming a forensic professional starts here.

Practice with mock tests, learn from structured notes, and get your questions answered by a global forensic community, all in one place.