SecurityLevelConstraint

@Immutable
sealed class SecurityLevelConstraint : Constraint

Configuration for validating the attestationSecurityLevel and keyMintSecurityLevel fields in an Android attestation certificate.

Inheritors

Types

Link copied to clipboard
object Companion
Link copied to clipboard
@Immutable
data object CONSISTENT : SecurityLevelConstraint

Checks that the attestationSecurityLevel is equal to the keyMintSecurityLevel, regardless of security level.

Link copied to clipboard

Checks that the keyMintSecurityLevel matches the security level claimed by the certificate. this constraint may be used in conjunction with other security level constraints. e.g. it may be combined with STRICT to verify that the keyMintSecurityLevel is precisely SecurityLevel.STRONG_BOX and that the security level matches the value claimed by the Google-signed certificate.

Link copied to clipboard
@Immutable
data object NOT_SOFTWARE : SecurityLevelConstraint

Checks that the attestationSecurityLevel is equal to the keyMintSecurityLevel, and that this security level is not SecurityLevel.SOFTWARE.

Link copied to clipboard
@Immutable
data class STRICT(val expectedVal: SecurityLevel) : SecurityLevelConstraint

Checks that both the attestationSecurityLevel and keyMintSecurityLevel match the expected value.

Properties

Link copied to clipboard
open override val label: String

Fixed label, suitable for logging or metrics.

Functions

Link copied to clipboard
open override fun check(description: KeyDescription, certPath: KeyAttestationCertPath): Constraint.Result

Verifies that description satisfies this Constraint.

Link copied to clipboard