beakthoven

TrickyStoreOSS

v3.1.0guide

Open source alternative to proprietary Tricky Store module

★1,438 stars
•Root Management•by beakthoven•GPL-3.0•Updated Aug 25, 2026
Platforms:
✓ Magisk✓ KernelSU
Download v3.1.0Starting download...GitHub Source
Tricky-Store-OSS-v3.1.0-172-41383f5-Release.zip

Overview

Developed by beakthoven, TrickyStoreOSS is an open-source, GPLv3-licensed implementation of Keystore HAL interception for rooted Android devices.

When banking applications and Google Play Integrity demand hardware-backed security, Android invokes the Keystore HAL to generate an attestation certificate chain verifying boot state. TrickyStoreOSS intercepts these requests inside system daemons, forging valid attestation chains signed by a legitimate user-provided keybox.xml to fulfill MEETS_STRONG_INTEGRITY.


Technical Architecture & How It Works

Native Keystore Service Hooking

TrickyStoreOSS operates at the system service boundary:

  1. Binder Transaction Interception: Injects hooks into Android’s keystore2 service daemon on Android 12+ (and legacy keystore on Android 10–11).
  2. Keybox Substitution: When an application specified in target.txt initiates hardware key generation, TrickyStoreOSS synthesizes an X.509 certificate chain using the private keys and Google-issued attestation certificates stored in keybox.xml.
  3. Root of Trust Spoofing: Injects verified boot flags (Verified, locked bootloader) into the ASN.1 attestation extension structure before returning the response to the caller.
  4. Immediate Configuration Synchronization: Automatically detects filesystem write events on /data/adb/tricky_store/, updating internal memory buffers without requiring device reboots.

Installation & Setup

  1. Uninstall any existing proprietary TrickyStore installations.
  2. Download and flash the latest TrickyStoreOSS-*.zip release in Magisk, KernelSU, or APatch.
  3. Reboot your device.
  4. Place an unrevoked hardware keybox at:
    /data/adb/tricky_store/keybox.xml
  5. Specify target packages in:
    /data/adb/tricky_store/target.txt

Configuration & Usage

Inside /data/adb/tricky_store/:

  • Target Declarations (target.txt): List the package names requiring forged attestation (e.g., com.google.android.gms and banking apps).
  • Patch Level (security_patch.txt): Specify an optional YYYY-MM-DD date string to override the security patch level reported inside attestation extensions.

Troubleshooting & Common Issues

  • Attestation Revoked: If Google blacklists your keybox serial number, attestation immediately fails. Replace /data/adb/tricky_store/keybox.xml with an active, unrevoked keybox bundle.
  • Biometric Authentication Fails: Ensure system biometric framework packages (com.android.settings, android) are not included in target.txt.

Frequently Asked Questions

Why was TrickyStoreOSS created?

TrickyStoreOSS was authored by beakthoven as a completely transparent, GPLv3-licensed cleanroom rewrite of the proprietary TrickyStore module, eliminating closed-source blobs while matching feature parity.

Can I run TrickyStore and TrickyStoreOSS together?

No. Both modules hook the same Keystore HAL service entry points and utilize the same /data/adb/tricky_store/ directory structure. You must uninstall the proprietary TrickyStore module before installing TrickyStoreOSS.