MOBILE FORENSICS

Android Keystore and Security Architecture

Modern Android devices protect cryptographic keys using specialised security mechanisms. The Android Keystore forms a central component of the security architecture and has a direct impact on the scope of an IT forensic investigation.

Android Keystore
Trusted Execution Environment (TEE)
StrongBox Keystore
Hardware-based key storage
Cryptographic certificates
Authentication mechanisms
Biometric authorisations
Secure Boot and other security features

TECHNICAL BACKGROUND

Technical Fundamentals

The Android keystore is used to securely generate and manage cryptographic keys. Depending on the device, these keys are protected either by software or by hardware.

Key components include, amongst others:

  • Android Keystore
  • Trusted Execution Environment (TEE)
  • StrongBox Keystore
  • Hardware-based key storage
  • Cryptographic certificates
  • Authentication mechanisms
  • Biometric authorisations
  • Secure Boot and other security features

The specific implementation varies depending on the manufacturer, chipset and version of Android.

OUR APPROACH

This is how your examination will be carried out

A transparent process – from the initial enquiry to the handover of the report.

1
Before each examination, the device’s security architecture is assessed. This involves analysing the keystore system, the available hardware security features and the version of Android in use. The results are documented in a transparent manner using recognised IT forensic tools and manual checks.
2
LanCologne produces expert reports for private individuals, as well as for companies and solicitors. Our reports have already been used in court proceedings. In some cases, we have been directly commissioned to produce IT forensic reports. Upon request, we can provide anonymised or redacted sample reports or extracts.

TYPICAL QUESTIONS

When is this analysis required?

  • What security measures does the device use?
  • Are keys stored using hardware-based storage?
  • Is StrongBox available?
  • What are the implications for data backup?
  • What are the technical limitations of the analysis?

LIMITATIONS & CONCLUSION

What you should know

Hardware-based security mechanisms make it considerably more difficult to access protected keys. Which data can be analysed depends, amongst other things, on the device model, the Android version, the security status and the extraction method selected.

The Android keystore and its associated security architecture form the foundation for the protection of sensitive data on Android devices. In the field of IT forensics, an understanding of these mechanisms is essential in order to properly assess the possibilities and limitations of an investigation.

CUSTOMER REVIEWS

What our customers say

4.8 out of 5 stars on Trustpilot · 54 reviews

★★★★★

“The highest standards of professionalism, prompt service and excellent communication. They made the seemingly impossible a reality. This is what genuine customer service is all about – unrivalled in Germany!”

idalein

Verified review on Trustpilot

★★★★★

“Very helpful advice, excellent responsiveness and communication. My problem was completely resolved and the lost data was recovered. I’m very satisfied and, of course, relieved!”

Layla Pankratz

Verified review on Trustpilot

★★★★★

“My problem was sorted out professionally and quickly; everyone I spoke to was always friendly, and I can still get in touch if I have any questions – I’m very grateful for that!”

a woman from Cologne

Verified review on Trustpilot

Enquire now – free initial consultation

Would you like to have the security architecture of an Android device professionally examined? LanCologne can assist you with an objective IT forensic analysis and comprehensive expert documentation.

FREQUENTLY ASKED QUESTIONS

Frequently Asked Questions

Click on a question to see the answer.

What is the Android keystore?
A system for the secure generation and storage of cryptographic keys.
What is a Trusted Execution Environment (TEE)?
A specially protected hardware area for the secure processing of sensitive data.
What is StrongBox?
An additional hardware-based security component on supported devices.
Does the keystore affect IT forensics?
Yes. He has a say in which cryptographically protected data can be accessed technically.
Could an expert report be drawn up on this matter?
Yes. The technical findings are documented and assessed in a way that is easy to follow.