Enginex0

TEESimulator-RS

v6.0.1-282guide

Software simulation for Android hardware-backed key pairs with key attestation | https://t.me/superpowers9

★1,909 stars
•Root Management•by Enginex0•GPL-3.0•Updated Jun 19, 2026
Platforms:
✓ Magisk✓ KernelSU
Download v6.0.1-282Starting download...GitHub Source
TEESimulator-RS-v6.0.1-282-Debug.zip

Overview

Maintained by Enginex0, TEESimulator-RS is a Rust implementation of the TEESimulator architecture designed to satisfy Android hardware-backed Key Attestation challenges.

Modern attestation verifies bootloader integrity cryptographically inside hardware secure enclaves. TEESimulator-RS intercepts key creation calls at the system keystore level, executing AOSP’s reference KeyMint Rust engine (kmr-ta) inside the daemon to produce cryptographically authentic attestation certificates using a user-supplied keybox.xml.


Technical Architecture & How It Works

In-Process KeyMint Routing

TEESimulator-RS injects a native Rust interception engine into Android’s keystore services:

  1. Binder Transaction Hooking: On Android 12+, the module hooks AIBinder_transact inside keystore2. When a declared target app requests key generation, transactions are routed to an in-process IKeyMintDevice handling kmr-ta.
  2. Selective App Scoping: Non-targeted applications (such as device biometric unlock, Widevine DRM, and FIDO credentials) bypass the simulator completely and talk directly to the real hardware TEE.
  3. Patch Level Harmonization: The module reads /data/adb/teesim/security_patch.txt to align the reported system, vendor, and boot security patch levels with current Play Integrity requirements.

Installation & Setup

  1. Flash the latest TEESimulator-RS-*.zip release in Magisk, KernelSU, or APatch.
  2. Reboot the device.
  3. Place your unrevoked keybox.xml file into:
    /data/adb/teesim/keybox.xml
  4. Define your targeted application packages inside:
    /data/adb/teesim/target.txt
  5. Changes are monitored live by the control process without requiring an additional reboot.

Troubleshooting & Common Issues

  • Attestation Returns Software-Only: If key attestation tools report software-only backing, verify that /data/adb/teesim/keybox.xml is present, readable, and contains valid RSA/EC private keys and certificate chains.
  • Daemon Recovery: If key operations hang due to corrupt profiles, restart the keystore daemon from a root shell (kill $(pidof keystore2)).

Frequently Asked Questions

What is the difference between TEESimulator and TEESimulator-RS?

TEESimulator-RS is an optimized rewrite in Rust developed by Enginex0. It maintains complete configuration and cryptographic compatibility with the original project while lowering memory overhead and improving hooking performance.

Will TEESimulator-RS work if I do not have a keybox.xml file?

No. Without a hardware-backed keybox.xml, the module cannot forge valid cryptographic signatures signed by Google's attestation root of trust, causing strict verification checks to fail.