DROIDCCT: Cryptographic Compliance Test via Trillion-Scale Measurement

Fuente: arXiv
Saved in:
Bibliographic Details
Main Authors: Moghimi, Daniel, Mihai, Alexandru-Cosmin, Benko, Borbala, Vlasov, Catherine, Bursztein, Elie, Thomas, Kurt, Siroki, Laszlo, Barbosa, Pedro, Audebert, Remi
Format: Preprint
Published: 2026
Subjects:
Online Access:
Tags: Add Tag
No Tags, Be the first to tag this record!
_version_ 1866909993193701376
author Moghimi, Daniel
Mihai, Alexandru-Cosmin
Benko, Borbala
Vlasov, Catherine
Bursztein, Elie
Thomas, Kurt
Siroki, Laszlo
Barbosa, Pedro
Audebert, Remi
author_facet Moghimi, Daniel
Mihai, Alexandru-Cosmin
Benko, Borbala
Vlasov, Catherine
Bursztein, Elie
Thomas, Kurt
Siroki, Laszlo
Barbosa, Pedro
Audebert, Remi
contents We develop DroidCCT, a distributed test framework to evaluate the scale of a wide range of failures/bugs in cryptography for end users. DroidCCT relies on passive analysis of artifacts from the execution of cryptographic operations in the Android ecosystem to identify weak implementations. We collect trillions of samples from cryptographic operations of Android Keystore on half a billion devices and apply severalanalysis techniques to evaluate the quality of cryptographic output from these devices and their underlying implementations. Our study reveals several patterns of bugs and weakness in cryptographic implementations from various manufacturers and chipsets. We show that the heterogeneous nature of cryptographic implementations results in non-uniform availability and reliability of various cryptographic functions. More importantly, flaws such as the use of weakly-generated random parameters, and timing side channels may surface across deployments of cryptography. Our results highlight the importance of fault- and side-channel-resistant cryptography and the ability to transparently and openly test these implementations.
format Preprint
id arxiv_https___arxiv_org_abs_2601_11745
institution arXiv
publishDate 2026
record_format arxiv
spellingShingle DROIDCCT: Cryptographic Compliance Test via Trillion-Scale Measurement
Moghimi, Daniel
Mihai, Alexandru-Cosmin
Benko, Borbala
Vlasov, Catherine
Bursztein, Elie
Thomas, Kurt
Siroki, Laszlo
Barbosa, Pedro
Audebert, Remi
Cryptography and Security
We develop DroidCCT, a distributed test framework to evaluate the scale of a wide range of failures/bugs in cryptography for end users. DroidCCT relies on passive analysis of artifacts from the execution of cryptographic operations in the Android ecosystem to identify weak implementations. We collect trillions of samples from cryptographic operations of Android Keystore on half a billion devices and apply severalanalysis techniques to evaluate the quality of cryptographic output from these devices and their underlying implementations. Our study reveals several patterns of bugs and weakness in cryptographic implementations from various manufacturers and chipsets. We show that the heterogeneous nature of cryptographic implementations results in non-uniform availability and reliability of various cryptographic functions. More importantly, flaws such as the use of weakly-generated random parameters, and timing side channels may surface across deployments of cryptography. Our results highlight the importance of fault- and side-channel-resistant cryptography and the ability to transparently and openly test these implementations.
title DROIDCCT: Cryptographic Compliance Test via Trillion-Scale Measurement
topic Cryptography and Security
url https://arxiv.org/abs/2601.11745