From 0da25a69f3e7e2e6d2c51c9f067156f53f08f758 Mon Sep 17 00:00:00 2001
From: Kevin Hufnagle
+ Note: Only a small number of devices running Android N
+ support hardware-level key attestation; all other devices running Android N
+ use software-level key attestation instead. Before you verify the properties
+ of a device's hardware-backed keys in a production-level environment, you
+ should make sure that the device supports hardware-level key attestation. To
+ do so, you should check that the attestation certificate chain contains a root
+ certificate that is signed by the Google attestation root key and that the
+ attestationSecurityLevel element within the key
+ description data structure is set to the TrustedEnvironment security
+ level.
+
For more information, see the Key Attestation diff --git a/docs/html/preview/features/key-attestation.jd b/docs/html/preview/features/key-attestation.jd index 98b8340496d24..5be6dfa370633 100644 --- a/docs/html/preview/features/key-attestation.jd +++ b/docs/html/preview/features/key-attestation.jd @@ -21,6 +21,19 @@ page.keywords="android N", "security", "TEE", "hardware-backed", "keystore", "ce interpret the schema of the attestation certificate's extension data.
+
+ Note: Only a small number of devices running Android N
+ support hardware-level key attestation; all other devices running Android N
+ use software-level key attestation instead. Before you verify the properties
+ of a device's hardware-backed keys in a production-level environment, you
+ should make sure that the device supports hardware-level key attestation. To
+ do so, you should check that the attestation certificate chain contains a root
+ certificate that is signed by the Google attestation root key and that the
+ attestationSecurityLevel element within the key description data structure
+ is set to the TrustedEnvironment security level.
+
- Note: Although it is possible to attest keys that are +
+ Warning: Although it is possible to attest keys that are
stored in the Android system—that is, if the
attestationSecurity value is set to Software—you
cannot trust these attestations if the Android system becomes compromised.