I am examining a SanDisk Memory Stick Pro Duo which was recovered during an investigation. On examination I was given a timescale that the investigatiion team were interested in.
One file which is particularly of interest is the RORequest.rop file. The file itself is showing as an "Empty File". My question is, what is the purpose of the file which was located in the System\Licence Transfer directory.
Thanks
Jim
The first search hit on Google suggests that it is to do with DRM.
http//
The first search hit on Google suggests that it is to do with DRM.
http//
www.patents.com/Method-transferring-digital-rights-protected-content-using-USB-or-memory-cards/EP1635545/en-EP/
Thanks Alex, I've googled the file name and saw that post. I should have mentioned that in my original post, apologies. I am curious as to why the file would be written to the disk. What was the user doing for this to happen?
From the Exif data it appears that the card was fitted to a Sony Ericsson handset, but the only files on the card are either picture files or movies taken by the user or sent by others to him. None appear to have anything to do with DRM. The handset itself has not been recovered.
Thanks again
Has the card been used a lot? Are you looking at deleted data as well as live?
The way I read the patent, that file will be created when moving DRM protected material from a computer to the mobile, it doesn't suggest that the request file is then deleted, so it may be remaining from a previous transaction, so the fact that you're seeing the RORequest file but no .dcf (or .ro) files isn't that strange (if I remember correctly, .dcf files do have a signature, perhaps it would be worth carving for them?)
I suppose the other possibility is that the transaction failed? RORequest was generated but the request was denied (i'm not an expert in this DRM format, so I'm not sure if this would be possible or not!)
I hope that gives you some avenues to explore!