References
Android Attestation
- Android Key Attestation — Developer Guide: Docs
- Android Key and ID Attestation — AOSP Spec and Schema: Docs
- Remote Key Provisioning — AOSP Source: Source
- Remote Key Provisioning — AOSP Docs: Docs
- Android Device Certification Overview — Compatibility: Docs
- Android 14 Compatibility Definition Document — CDD: Docs
- Android Keystore and StrongBox Overview: Docs
- Android Keystore — Extraction Prevention: Docs
- Android Keystore — StrongBox KeyMint: Docs
- Android Keystore —
KeyProperties: API Docs - Android Emulator — Command Line and Headless Usage: Docs
- Android Keystore Implementer Reference — Rollback Resistance: Docs
- Android Keystore2 Stability Fix — Post‑Android 16: Source
- Android Attestation Libraries — Legacy: GitHub Repo: google/android-key-attestation
- Android Attestation Libraries — Current: GitHub Repo: android/keyattestation
- Android Security Bulletin — Vulnerability Advisories: Website
iOS App Attest
- Apple Device Integrity Overview — DeviceCheck / App Attest: Docs
- Apple Server Validation Guide — DeviceCheck / App Attest: Docs
- Apple Attestation Object Validation — App Attest Format: Docs
- Apple App Attest Setup and Requirements: Docs
- Apple Fraud Risk Assessment — App Attest Receipt: Docs
- Apple Secure Enclave: Docs
- Apple Version and Build Number Primer: Website
Libraries and Tooling
- Signum — Kotlin Multiplatform Crypto/PKI Toolkit: Website • Proivder Docs • Attestation Docs
- Ktor — HTTP Client/Server Framework: Website
- Spring — JVM Framework: Website
- Kotlin — Programming Language: Website
- Spring Boot External Configuration Loader: Docs
- iOS App Attest Helper Library: GitHub Repo: veehaitch/devicecheck-appattest
- AuthCheckKit — Multiplatform Authentication Capabilities Check: GitHub Repo: a-sit-plus/AuthCheckKit
Legacy Projects
- WARDEN — Legacy Server‑Side Verifier for Mobile Attestation: GitHub Repo: a-sit-plus/warden • Website • Instance Creation API Docs
- WARDEN‑roboto — Legacy Android Attestation Utilities and Parsers: GitHub Repo: a-sit-plus/warden-roboto
Background and Research
- Android Platform Security Model: Paper
- The Sybil Attack — Foundational Concept for Identity Fraud: Paper (PDF)
- CBOR (IETF): RFC 7049
- COSE (IETF): RFC 8152
- Cloud Pricing Reference — GCP Compute Engine: Website
- Android Accessibility Abuse: Website
- Digitales Amt Repackaging: GitHub Repo: eGovPatchesAT/id-austria
- Leaked Keyboxes — Gray/Black Market Sources: Analysis • “VIP Keybox” Pricing