Overview
Maintained by Enginex0, TEESimulator-RS is a Rust implementation of the TEESimulator architecture designed to satisfy Android hardware-backed Key Attestation challenges.
Modern attestation verifies bootloader integrity cryptographically inside hardware secure enclaves. TEESimulator-RS intercepts key creation calls at the system keystore level, executing AOSP’s reference KeyMint Rust engine (kmr-ta) inside the daemon to produce cryptographically authentic attestation certificates using a user-supplied keybox.xml.
Technical Architecture & How It Works
In-Process KeyMint Routing
TEESimulator-RS injects a native Rust interception engine into Android’s keystore services:
- Binder Transaction Hooking: On Android 12+, the module hooks
AIBinder_transactinsidekeystore2. When a declared target app requests key generation, transactions are routed to an in-processIKeyMintDevicehandlingkmr-ta. - Selective App Scoping: Non-targeted applications (such as device biometric unlock, Widevine DRM, and FIDO credentials) bypass the simulator completely and talk directly to the real hardware TEE.
- Patch Level Harmonization: The module reads
/data/adb/teesim/security_patch.txtto align the reported system, vendor, and boot security patch levels with current Play Integrity requirements.
Installation & Setup
- Flash the latest
TEESimulator-RS-*.ziprelease in Magisk, KernelSU, or APatch. - Reboot the device.
- Place your unrevoked
keybox.xmlfile into:/data/adb/teesim/keybox.xml - Define your targeted application packages inside:
/data/adb/teesim/target.txt - Changes are monitored live by the control process without requiring an additional reboot.
Troubleshooting & Common Issues
- Attestation Returns Software-Only: If key attestation tools report software-only backing, verify that
/data/adb/teesim/keybox.xmlis present, readable, and contains valid RSA/EC private keys and certificate chains. - Daemon Recovery: If key operations hang due to corrupt profiles, restart the keystore daemon from a root shell (
kill $(pidof keystore2)).
Frequently Asked Questions
What is the difference between TEESimulator and TEESimulator-RS?
TEESimulator-RS is an optimized rewrite in Rust developed by Enginex0. It maintains complete configuration and cryptographic compatibility with the original project while lowering memory overhead and improving hooking performance.
Will TEESimulator-RS work if I do not have a keybox.xml file?
No. Without a hardware-backed keybox.xml, the module cannot forge valid cryptographic signatures signed by Google's attestation root of trust, causing strict verification checks to fail.
