Overview
Developed by qwq233, OhMyKeymint is an advanced attestation interception framework written in Rust for modern Android versions (Android 12+).
As Google transitioned from legacy Keymaster HIDL services to AIDL-based Keystore 2.0 (keystore2), the mechanisms used by applications to request hardware-backed key attestations were redesigned. OhMyKeymint hooks directly into the keystore2 process, allowing users to define flexible, programmatically generated KeyMint profiles that satisfy Play Integrity while preserving device hardware keys for standard biometric authentication.
Technical Architecture & How It Works
Keystore 2.0 Daemon Hooking
OhMyKeymint operates within the system keystore process address space:
- Binder Transaction Interception: Hooks Android’s
android.system.keystore2AIDL interface within thekeystore2daemon. - Selective Policy Evaluation: When a client application calls
generateKeywith attestation parameters, OhMyKeymint consults its TOML configuration to determine whether the calling UID matches a declared target. - KeyMint Simulation: Intercepted requests are redirected to an authentic software KeyMint instance, signing the resulting certificate chain with configured credentials.
Installation & Setup
- Verify your device runs Android 12 or newer on a 64-bit platform.
- Download the latest
OhMyKeymint-*.ziprelease. - Flash the module in your root manager (Magisk, KernelSU, or APatch).
- Reboot the device.
Configuration & Usage
Configure target packages and profiles in:
/data/adb/ohmykeymint/config.toml
Review the sample configuration in the repository documentation to define package names and security patch levels.
Troubleshooting & Common Issues
- Keystore Daemon Crashing: If the keystore daemon restarts repeatedly, verify that your
config.tomlcontains valid TOML syntax and that no other keystore hooks are conflicting.
Frequently Asked Questions
Why does OhMyKeymint require Android 12 or higher?
OhMyKeymint is specifically architected to hook Android's Keystore 2.0 system daemon (keystore2) and its AIDL KeyMint HAL interfaces. Devices on Android 11 and older use the legacy C++ keystore daemon and HIDL Keymaster HAL, which are not targeted by this engine.
How do I configure target applications in OhMyKeymint?
Configuration is managed in /data/adb/ohmykeymint/config.toml, where you can define application package names, spoofed security patch levels, and keybox credential parameters.
