DroidCCT examines how reliably Android devices implement the cryptographic operations exposed through Android Keystore. Its distributed testing framework gathers inputs, outputs, errors and timing observations across a broad range of devices.
The study analyzes trillions of samples from half a billion devices. It identifies differences in feature availability and reliability, along with weaknesses involving random parameters and timing side channels. The results show why a standard API alone cannot guarantee consistent cryptographic security across manufacturers and chipsets.