FEATURES OF THE EXAMINATION OF THE ISOLATED PROFILE (“SECOND SPACE”) ON MOBILE DEVICES IN CYBERCRIME INVESTIGATIONS

Authors

  • Zarina Irekovna KHARISOVA Ufa University of Science and Technologies

DOI:

https://doi.org/10.33184/pravgos-2026.3.13

Keywords:

isolated profile, second space, digital evidence, Android OS, cybercrime investigation, forensics, data isolation, anti-forensics techniques, forensic examination protocol, mobile device examination

Abstract

When investigating cybercrimes and other criminal acts committed via information and telecommunication technologies, investigators often need to examine mobile devices. However, the presence of a “second space” feature (a hidden, isolated user profile) can lead to the loss of critical digital evidence. The practical significance of this study lies in identifying data isolation mechanisms implemented by leading mobile device manufacturers (e.g., Samsung Secure Folder, MIUI (Xiaomi) Second Space, and Magic UI Private Mode (Huawei/Honor)). The purpose of this study is to examine the specifics of detecting and examining hidden workspaces in mobile devices actively exploited by criminals for illicit goals. The research employed a combination of general (description, generalization, and comparison), general scientific (analysis, synthesis), and specific scientific (cybernetic, systems analysis, and comparative legal) methods of cognition. General and general scientific methods were used to examine the technical architecture of isolated profiles within the Android OS and develop a generalized framework for mobile device forensic protocols. Meanwhile, specific scientific methods were applied to analyze empirical data and identify technical and forensic characteristics across various isolated environment architectures in mobile devices. Results: the study proposes forensic guidelines for examining isolated mobile device profiles, encompassing the detection of “second space” indicators and the procedure for securing digital evidence.

Author Biography

Zarina Irekovna KHARISOVA , Ufa University of Science and Technologies

Doctor of Sciences (Law), Candidate of Technical Sciences, Associate Professor of the Department of Criminalistics

References

Криминалистика : учебник / Т.В. Аверьянова, Р.С. Белкин, Ю.Г. Корухов, Е.Р. Россинская. – Москва : Норма: ИНФРА-М, 2026. – 928 с.

Tiwari M. Technical Challenges of Encryption in Mobile Forensics / M. Tiwari, S. Thapaliya // International Journal of Multidisciplinary and Innovative Research. – 2025. – Vol. 12 (6). – P. 178–183.

Patel B. A Survey on Mobile Digital Forensic: Taxonomy, Tools, and Challenges / B. Patel, P. Mann // Security and Privacy. – 2025. – Vol. 8 (2). – P. 470–478.

Heasley J.S. Anti-forensics for Mobile Devices: Exploring Apps Encountered by Digital Forensic Investigators : diss. Master of Science degree / J.S. Heasley. – West Lafayette (Purdue University Graduate School), 2025. – 107 p.

Fakhriansyah A. Development of Xiaomi Product Mobile Forensic Acquisition Framework on Second Space Features Based on SNI/ISO 27037:2014 / A. Fakhriansyah, A. Luthfi // Jurnal Infotel. – 2024. – Vol. 16 (2). – P. 255–272.

Liu H. Safeguarding user security and privacy: seeing through communications and obfuscating network activities : diss. Doctor of Philosophy degree / H.Liu. – Edinburgh (Institute of Computing Systems Architecture), 2023. – 197 p.

Максимович А.Б. Средства сотовой связи как объект криминалистического исследования : дис. … канд. юрид. наук : 12.00.12 / А.Б. Максимович. – Москва, 2018. – 251 с.

Скобелин С. Ю. Возможности получения криминалистически значимой информации при осмотре мобильных средств связи и пределы ограничения конституционных прав граждан на тайну переписки / С. Ю. Скобелин // Преступность в сфере информационных и телекоммуникационных технологий: проблемы предупреждения, раскрытия и расследования преступлений. – 2017. – № 1. – С. 89–98.

Третьякова Е.И. Мобильный телефон как источник криминалистически значимой информации / Е.И. Третьякова // Вестник Уральского финансово-юридического института. – 2018. – № 3 (13). – С. 49–51.

Коновалов С.Г. Содействие обвиняемого в разблокировке его смартфона: допустимо ли принуждение? / С.Г. Коновалов // Закон. – 2025. – № 2. – С. 69–80.

Особенности проведения проверки сообщений о преступлениях, совершаемых с использованием информационно-телекоммуникационных технологий / В.С. Латыпов, Э.Д. Нугаева, З.И. Харисова, Т.С. Соколова. – Москва : Мир науки, 2026. – 85 с.

Расследование мошенничеств, совершаемых с использованием мобильной связи : учебное пособие / О.П. Грибунов, М.В. Старичков, А.А. Шаевич и др. – Иркутск : Восточно-Сибирский институт Министерства внутренних дел РФ, 2018. – 44 с.

Головчанский А.В. Технико-криминалистическое обеспечение производства следственных действий, связанных с изъятием и осмотром мобильных средств сотовой связи / А.В. Головчанский // Преступность в сфере информационных и телекоммуникационных технологий: проблемы предупреждения, раскрытия и расследования преступлений. – 2015. – № 1. – С. 118–123.

Song S. Forensic recovery via chip-transplantation in Samsung smartphones / S. Song, Y. Hongseok, E. Lee // Forensic Science International: Digital Investigation. – 2025. – Vol. 53 (1). – P. 301926–301936.

Published

2026-10-02

How to Cite

[1]
ХАРИСОВА , З.И. 2026. FEATURES OF THE EXAMINATION OF THE ISOLATED PROFILE (“SECOND SPACE”) ON MOBILE DEVICES IN CYBERCRIME INVESTIGATIONS. The rule-of-law state: theory and practice. 22, 3(85) (Oct. 2026), 110–118. DOI:https://doi.org/10.33184/pravgos-2026.3.13.

Issue

Section

CRIMINAL LAW SCIENCES