KeystoreHelper

@RequiresApi(value = 23)
class KeystoreHelper(source)

Helper Android Keystore centralisé (AES-256-GCM).

Aucune permission manifest requise — le Keystore est un service système. Les clés ne quittent jamais le matériel sécurisé (TEE / StrongBox).

Enregistrement Koin :

single { KeystoreHelper() }

Clés sans biométrie

val config = KeystoreConfig.default("user_token")
val encrypted = keystoreHelper.encrypt(config, "mon_token_secret")
val plain = keystoreHelper.decrypt(config, encrypted)

Clés protégées par biométrie

Les clés KeystoreConfig.biometricProtected requièrent un Cipher déjà authentifié via BiometricPrompt.CryptoObject — un appel direct à encrypt/decrypt lèverait une android.security.keystore.UserNotAuthenticatedException.

Flux recommandé :

val config  = KeystoreConfig.biometricProtected("secure_key")
val cipher = keystoreHelper.createEncryptCipher(config) // avant la prompt

// Passer cipher à BiometricPrompt :
biometricPrompt.authenticate(
BiometricPrompt.CryptoObject(cipher),
cancellationSignal,
executor,
object : BiometricPrompt.AuthenticationCallback() {
override fun onAuthenticationSucceeded(result: BiometricPrompt.AuthenticationResult) {
val authenticatedCipher = result.cryptoObject!!.cipher!!
val encrypted = keystoreHelper.encrypt(authenticatedCipher, "secret")
}
}
)

// Déchiffrement :
val decryptCipher = keystoreHelper.createDecryptCipher(config, encrypted.iv)
biometricPrompt.authenticate(BiometricPrompt.CryptoObject(decryptCipher), ...)
// Dans onAuthenticationSucceeded :
val plain = keystoreHelper.decrypt(result.cryptoObject!!.cipher!!, encrypted)

Constructors

Link copied to clipboard
constructor()

Types

Link copied to clipboard
object Companion

Functions

Link copied to clipboard

Crée un Cipher initialisé en mode déchiffrement pour la clé config, en utilisant l'IV extrait de ivBase64.

Link copied to clipboard

Crée un Cipher initialisé en mode chiffrement pour la clé config.

Link copied to clipboard

Déchiffre data avec la clé identifiée par config. Retourne null si la clé n'existe pas.

fun decrypt(cipher: Cipher, data: EncryptedData): String

Déchiffre data avec un Cipher déjà initialisé (et authentifié si la clé est biométrique).

Link copied to clipboard

Supprime la clé identifiée par config.alias.

Link copied to clipboard
fun encrypt(config: KeystoreConfig, plaintext: String): EncryptedData

Chiffre plaintext avec la clé identifiée par config.

fun encrypt(cipher: Cipher, plaintext: String): EncryptedData

Chiffre plaintext avec un Cipher déjà initialisé (et authentifié si la clé est biométrique).

Link copied to clipboard

Génère ou retourne la clé existante pour config.

Link copied to clipboard

true si une clé existe pour cet alias.