MirrorNest

Cryptographic ID

Attest the trustworthiness of a device using asymmetric cryptography

AndroidSicherheit & DatenschutzOpen Source

v0.5.7

52.2 MBgeprüft, sauber· 4 Downloads

Screenshots

Über

Cryptographic ID is an open-source Android application in the Security & Privacy category. It uses cryptographic keys and signatures for checking device state and demonstrating control of a private key. It is intended for people who need to verify a phone, assess a computer’s trusted state, or confirm that someone possesses a key shared through a secure channel.

On a phone, the software can generate a private key when the device is considered trustworthy. If the phone later creates a correct signature, that signature can indicate that it is the same phone associated with the key. Because the operating system can access the private key, the protection is weaker than a key held in a TPM2 and is only as strong as the phone itself. The same approach can help verify that a person controls a private key when their public key was provided in advance over a secure channel.

A related Linux use case relies on a private key hidden in the computer’s TPM2 and sealed to the computer’s current PCR state. For example, the key can be tied to PCR7 and the secure boot state, preventing a signature when the computer has booted an operating system signed by another vendor. The Linux implementation described for this purpose uses cryptographic-id-rs, and its asymmetric signatures allow the verification key to be shared openly.

As an Android security and privacy tool, Cryptographic ID fits a platform where phone identity and key possession can be checked through signed messages. Its open-source license provides the project’s stated licensing model for users and developers reviewing the software. MirrorNest distributes the official build by mirroring it directly on its own storage and scans the stored build for malware before publishing it.

Erfordert Android 7.0+

App-Berechtigungen

Direkt aus der Installationsdatei der App ausgelesen — der tatsächliche Zugriff, den sie anfordern kann, keine Vermutung.

  • Take pictures and record video
  • io.gitlab.cryptographic id.dynamic Receiver Not Exported Permission

Bewertungen

Noch keine Bewertungen — sei der Erste.

Bewertung abgeben

Melde dich an, um als verifiziertes Mitglied statt anonym zu posten.

Mehr in Sicherheit & Datenschutz