Insights Topic

Android

Browse Attomus insight related to android, with a focus on programme delivery, operational judgement, and professional execution in demanding environments.

Topic summary

1 related insight

Use this topic page to move quickly through the most relevant Attomus thinking without losing the wider context across the full insights section.

What Android's Keystore Actually Does with AES Keys (and What It Doesn't)

There is a question that comes up constantly in Android security engineering, usually phrased something along the lines of: “how do I prove to my server that this AES key is hardware-backed?” The common answers to this question are often wrong in that they make you think you have a guarantee that you do not have. The short answer is: you cannot prove an AES key’s hardware provenance to a server directly. The certificate chain mechanism that makes remote attestation possible for asymmetric keys does not exist for symmetric keys. If you are building a system that depends upon being able to remotely attest an AES key’s provenance, you need to redesign the system, not find a better API call.

Read article