Overview
Developed by beakthoven, TrickyStoreOSS is an open-source, GPLv3-licensed implementation of Keystore HAL interception for rooted Android devices.
When banking applications and Google Play Integrity demand hardware-backed security, Android invokes the Keystore HAL to generate an attestation certificate chain verifying boot state. TrickyStoreOSS intercepts these requests inside system daemons, forging valid attestation chains signed by a legitimate user-provided keybox.xml to fulfill MEETS_STRONG_INTEGRITY.
Technical Architecture & How It Works
Native Keystore Service Hooking
TrickyStoreOSS operates at the system service boundary:
- Binder Transaction Interception: Injects hooks into Android’s
keystore2service daemon on Android 12+ (and legacykeystoreon Android 10–11). - Keybox Substitution: When an application specified in
target.txtinitiates hardware key generation, TrickyStoreOSS synthesizes an X.509 certificate chain using the private keys and Google-issued attestation certificates stored inkeybox.xml. - Root of Trust Spoofing: Injects verified boot flags (
Verified, locked bootloader) into the ASN.1 attestation extension structure before returning the response to the caller. - Immediate Configuration Synchronization: Automatically detects filesystem write events on
/data/adb/tricky_store/, updating internal memory buffers without requiring device reboots.
Installation & Setup
- Uninstall any existing proprietary TrickyStore installations.
- Download and flash the latest
TrickyStoreOSS-*.ziprelease in Magisk, KernelSU, or APatch. - Reboot your device.
- Place an unrevoked hardware keybox at:
/data/adb/tricky_store/keybox.xml - Specify target packages in:
/data/adb/tricky_store/target.txt
Configuration & Usage
Inside /data/adb/tricky_store/:
- Target Declarations (
target.txt): List the package names requiring forged attestation (e.g.,com.google.android.gmsand banking apps). - Patch Level (
security_patch.txt): Specify an optionalYYYY-MM-DDdate string to override the security patch level reported inside attestation extensions.
Troubleshooting & Common Issues
- Attestation Revoked: If Google blacklists your keybox serial number, attestation immediately fails. Replace
/data/adb/tricky_store/keybox.xmlwith an active, unrevoked keybox bundle. - Biometric Authentication Fails: Ensure system biometric framework packages (
com.android.settings,android) are not included intarget.txt.
Frequently Asked Questions
Why was TrickyStoreOSS created?
TrickyStoreOSS was authored by beakthoven as a completely transparent, GPLv3-licensed cleanroom rewrite of the proprietary TrickyStore module, eliminating closed-source blobs while matching feature parity.
Can I run TrickyStore and TrickyStoreOSS together?
No. Both modules hook the same Keystore HAL service entry points and utilize the same /data/adb/tricky_store/ directory structure. You must uninstall the proprietary TrickyStore module before installing TrickyStoreOSS.
