Comparative Analysis of Smart Lock Breaching Methods and Their Forensic Examination in Ukraine and the USA

Authors

  • Roman Pidnebennyi

DOI:

https://doi.org/10.32353/khrife.1.2025.12

Keywords:

smart locks; forensic examination; digital hacking; physical hacking; security; forensic analysis.

Abstract

The development of technology has contributed to changes in methods of securing residential and commercial premises. Smart locks have become an integral part of the modern security market and have attracted the attention not only of property owners and security companies but also of criminals. The key methods of smart lock hacking used in Ukraine and the USA are examined, as well as the differences in forensic examination approaches to such crimes in these countries. A comparative analysis of physical, mechanical, and digital attacks has been conducted, outlining new challenges in the forensic examination of electronic locks and proposing recommendations for improving forensic research in this field. Modern security systems, including smart locks, combine mechanical and electronic technologies. At the same time, they are somewhat vulnerable, making them attractive to cybercriminals and traditional methods of physical hacking. The lack of a unified approach to forensic examination of such crimes in Ukraine and the USA creates difficulties in law enforcement activities. The purpose of this article is to explore the methods of smart lock hacking, compare the peculiarities of forensic examinations of such hacks in Ukraine and the USA, and propose measures to improve the investigation of such crimes. To achieve the stated goal, the method of comparative analysis, the traceological method of examining traces of hacking, the analysis of digital evidence, and vulnerability testing methods (fuzzing, reverse engineering of lock software) were applied.

References

Consumer Cyber Readiness Report (2024) / Aspen Digital : website. URL: https://www.aspendigital.org/report/2024-consumer-cyber-readiness-report/.

Adaramola, O. O., Odigbo, Ch. S., Elelegwu, D., Chen, L. (2025). Safeguarding Smart Homes: A Digital Security and Digital Forensics Approach / ResearchGate : web-site. DOI: 10.13140/RG.2.2.19403.30240.

Ayers, R., Brothers, S., Jansen, W. (2014). NIST Special Publication 800-101. Rev. 1. Guidelines on Mobile Device Forensics. U. S. Department of Commerce ; NIST. DOI: 10.6028/NIST.SP.800-101r1.

Berrios, J., Mosher, E., Benzo, S., Grajeda, C., Baggili, I. (2023). Factorizing 2FA: Forensic analysis of two-factor authentication applications. Forensic Science International: Digital Investigation. Vol. 45. Suppl. Art. 301569. DOI: 10.1016/j.fsidi.2023.301569.

Bilous, V. V., Shepitko, V. Yu. (2019). Tekhnichni zasoby profilaktyky / V. Yu. Shepitko, V. A. Zhuravel, V. O. Konovalova ta in. Kryminalistyka [Criminalistics ] : pidruchnyk. U 2 t. T. 1 ; za red. V. Yu. Shepitka. Kharkiv [in Ukrainian].

Black Hat USA 2019 (Mandalay Bay / Las Vegas) (2019) / Black Hat : website. URL: https://www.blackhat.com/us-19/.

Black Hat USA 2021 (Mandalay Bay / Las Vegas + Virtual) (2021) / Black Hat : website. URL: https://www.blackhat.com/us-21/.

Black Hat USA 2023 (Mandalay Bay / Las Vegas + Virtual) (2023) / Black Hat : website. URL: https://www.blackhat.com/us-23/.

Black Hat / DEF CON 2024: Latest Insights on Security and AI. ISMG Compendium Showcases More Than 50 Interviews on Threats, Emerging Solutions (2024) / Bank Info Security : website. URL: https://www.bankinfosecurity.com/black-hatdef-con-2024-latest-insights-on-securityai-a-26283.

Caballero-Gil, C., Álvarez, R., Hernández-Goya, C., Molina-Gil, J. (2024). Research on smart-locks cybersecurity and vulnerabilities. Wireless Networks. Vol. 30. DOI: 10.1007/s11276-023-03376-8.

Cheremnova, A. I., Bielik, L. S. (2023). Tsyfrova informatsiia yak ob’iekt ekspertnoho doslidzhennia v umovakh didzhytalizatsii: problemy ta perspektyvy rozvytku [Digital Information as an Object of Expert Research in the Context of Digitalization: Problems and Development Prospects]. Kryminalistyka i sudova ekspertyza. Vyp. 68. DOI: 10.33994/kndise.2023.68.06 [in Ukrainian].

Cybersecurity Subteam Recommendations (2023) / National Institute of Standards and Techno logy : website. URL: https://surl.li/fkkmcm.

Dashevskyi, S., La Spina, F. (2023). Old Code Dies Hard: Finding New Vulnerabilities in Old Third-Party Software Components and the Importance of Having SBoM for IoT / OT Devices / Black Hat Europe 2023. URL: https://i.blackhat.com/EU-23/Presentations/EU-23-Dashevskyi-Old_code_ dies_hard.pdf.

Dufeniuk, O. M. (2024). Maibutnie 3D kryminalistyky: innovatsii, yaki zminiuiut praktyku dosudovoho rozsliduvannia [The Future of 3d Forensic Science: Innovations That Change the Practice of Pre-Trial Investigation]. Yurydychnyi naukovyi elektronnyi zhurnal. № 3. DOI: 10.32782/25240374/2024-3/110 [in Ukrainian].

Federal Bureau of Investigation. Internet Crime Report 2023 (2023) / Internet Crime Complaint Center. URL: https://www.ic3.gov/annualreport/reports/2023_ic3report. pdf.

Four Ways 3D Printing May Threaten Security (2018) / RAND Corporation : website. URL: https://www.rand.org/pubs/articles/2018/four-ways-3d-printing-maythreaten-security.html.

Garland, L., Neyaz, A., Varol, C., & Shashidhar, N. K. (2024). Investigating Digital Forensic Artifacts Generated from 3D Prin ting Slicing Software: Windows and Linux Analysis. Electronics. 2024. Vol. 13 (14). DOI: 10.3390/electronics13142864.

Hill, G. (2014). 3-D Printed Skeleton Key Can Open Almost Any Lock in Seconds / Security Today : website. URL: https://securityto-day.com/articles/2014/09/03/3d-printedskeleton-key-can-open-almost-any-lockin-seconds.aspx.

Hrabovskyi, H., Oparii, A., Kuznietsov, R. (2019). Osoblyvosti ekspertnoho doslidzhennia slidiv znariad zlomu [Features of Expert Research on Traces of Hacking Tools]. Molodyi vchenyi. № 8 (72). DOI: 10.32839/2304-5809/2019-8-72-61 [in Ukrainian].

Hutchinson, Sh., Yoon, Y. H., Shantaram, N., & Karabiyik, U. (2020). Internet of Things Forensics in Smart Homes: Design, Implementation, and Analysis of Smart Home Laboratory. 2020 ASEE Virtual Annual Conference Content Access. DOI: 10.18260/1-2--34868.

Kent, K., Chevalier, S., Grance, T., Dang, H. (2006). Guide to Integrating Forensic Techniques into Incident Response. Recommendations of the National Institute of Standards and Technology. SP 800-86. U. S. Department of Commerce ; Technology Administration ; NIST. URL: https://surl.gd/bfuxct.

Kerrison, S. (2022). IoT Droplocks: Wireless Fingerprint Theft Using Hacked Smart Locks. ArXiv. DOI: 10.48550/arX-iv.2208.13343.

Kopcha, V. V., Fridmanskyi, R. M., Kopcha, N. V. (2022). Pravove doslidzhennia slidiv na mistsi zlochynu: yaki spryiaiut efektyvnomu rozkryttiu i poperedzhenniu zlochyniv [Legal investigation of crime trace tracks: facilitating effective detection and prevention of crimes]. Naukovyi visnyk Uzhhorodskoho Natsionalnoho Universytetu. Seriia Pravo. Vyp. 72. Ch. 2. DOI: 10.24144/2307-3322.2022.72.67 [in Ukrainian].

Kuznietsov, R. V., Yevsieiev, P. O. (2022). Osoblyvosti trasolohichnoho doslidzhennia dynamichnykh slidiv znariad zlamu [Features of tracelogical study of dynamic traces of breaking tools]. Analitychno-porivnialne pravoznavstvo. № 4. DOI: 10.24144/27886018.2022.04.61 [in Ukrainian].

Ollam, D. (2010). Practical Lock Picking: A Physical Penetration Tester’s Training Guide. Syngress.

Osawa, Y., Higuchi, S. (2023). A Manufacturer’s Post-Shipment Approach to Fend-Off IoT Malware in Home Appliances / Black Hat USA 2023. URL: https://i.blackhat.com/BH-US-23/Presentations/US-23-Osawa-Higuchi-A-Manufacturers-Post-Shipment-Approach.pdf.

Santos, D. dos, Guiot, S., Dashevskyi, S., Amri, A., Kerro, O. (2023). Route to Bugs: Analyzing the Security of BGP Message Parsing / Black Hat USA 2023. URL: https://i.blackhat.com/BH-US-23/Presentations/US-23-dosSantos-Route-to-BugsAnalyzing-the-Security-of-BGP.pdf.

Shepitko, V. Yu., Konovalova, V. O., Zhuravel, V. A. ta in. (2008). Kryminalistyka [Criminalistics] : pidruchnyk / za red. V. Yu. Shepitka. 4-te vyd., pererob. i dopov. Kharkiv. URL: https://law.sspu.edu.ua/ files/documents/books/library/17/shepitko.pdf [in Ukrainian].

Smith, S. W., Oorschot, P. C. van. (2019). The Internet of Things: Security Challenges. IEEE Security and Privacy Magazine. Art. 17(5):7-9. DOI: 10.1109/MSEC.2019.2925918.

Winkelmann, A. (2022). Unauthorized Smart Lock Access. Ethical Hacking of Smart Lock Systems. Stockholm, Sweden. URL: https://kth.diva-portal.org/smash/get/diva2%3A1749555/FULLTEXT01.pdf.

Yakymenko, R. V. (2018). Shchodo vazhlyvosti etapu porivnialnoho doslidzhennia konformnykh slidiv na detaliakh mekhanichnykh suvaldnykh zamkiv [On the Importance of the Stage of Comparative Study of Conformal Traces on the Details of Mechanical Lever Locks]. Kryminalistyka i sudova ekspertyza. Vyp. 63. Ch. 1. URL: https://digest.kndise.gov.ua/wp-content/ uploads/2021/06/2018_1.pdf [in Ukrainian].

Published

2025-06-15

How to Cite

Pidnebennyi, R. (2025). Comparative Analysis of Smart Lock Breaching Methods and Their Forensic Examination in Ukraine and the USA. Theory and Practice of Forensic Science and Criminalistics, 38(1), 182–199. https://doi.org/10.32353/khrife.1.2025.12