Skip to main content
DROIDCCT: Cryptographic Compliance Test via Trillion-Scale Measurement
  1. publications
  2. Cybersecurity

DROIDCCT: Cryptographic Compliance Test via Trillion-Scale Measurement

Available Media Publication (PDF)
Conference Annual Computer Security Applications Conference (ACSAC) - 2025
Authors Daniel Moghimi , Alexandru-Cosmin Mihai , Borbala Benko ,
Citation BibTeX
BibTeX
@inproceedings{Moghimi2025DROIDCCT,
  title = {DROIDCCT: Cryptographic Compliance Test via Trillion-Scale Measurement},
  author = {Daniel Moghimi and Alexandru-Cosmin Mihai and Borbala Benko and Catherine Vlasov and Elie Bursztein and Kurt Thomas and László Siroki and Pedro Barbosa and Rémi Audebert},
  booktitle = {Annual Computer Security Applications Conference},
  year = {2025},
  organization = {IEEE}
}

DroidCCT examines how reliably Android devices implement the cryptographic operations exposed through Android Keystore. Its distributed testing framework gathers inputs, outputs, errors and timing observations across a broad range of devices.

The study analyzes trillions of samples from half a billion devices. It identifies differences in feature availability and reliability, along with weaknesses involving random parameters and timing side channels. The results show why a standard API alone cannot guarantee consistent cryptographic security across manufacturers and chipsets.

newsletter signup
newsletter signup