KeyProtection.Builder.SetRandomizedEncryptionRequired(Boolean) Method
Definition
Important
Some information relates to prerelease product that may be substantially modified before it’s released. Microsoft makes no warranties, express or implied, with respect to the information provided here.
Sets whether encryption using this key must be sufficiently randomized to produce different ciphertexts for the same plaintext every time.
[Android.Runtime.Register("setRandomizedEncryptionRequired", "(Z)Landroid/security/keystore/KeyProtection$Builder;", "", ApiSince=23)]
public Android.Security.Keystore.KeyProtection.Builder SetRandomizedEncryptionRequired(bool required);
[<Android.Runtime.Register("setRandomizedEncryptionRequired", "(Z)Landroid/security/keystore/KeyProtection$Builder;", "", ApiSince=23)>]
member this.SetRandomizedEncryptionRequired : bool -> Android.Security.Keystore.KeyProtection.Builder
Parameters
- required
- Boolean
Returns
- Attributes
Remarks
Sets whether encryption using this key must be sufficiently randomized to produce different ciphertexts for the same plaintext every time. The formal cryptographic property being required is indistinguishability under chosen-plaintext attack (IND-CPA). This property is important because it mitigates several classes of weaknesses due to which ciphertext may leak information about plaintext. For example, if a given plaintext always produces the same ciphertext, an attacker may see the repeated ciphertexts and be able to deduce something about the plaintext.
By default, IND-CPA is required.
When IND-CPA is required: transformation which do not offer IND-CPA, such as symmetric ciphers using ECB mode or RSA encryption without padding, are prohibited;; in transformations which use an IV, such as symmetric ciphers in GCM, CBC, and CTR block modes, caller-provided IVs are rejected when encrypting, to ensure that only random IVs are used Before disabling this requirement, consider the following approaches instead:; If you are generating a random IV for encryption and then initializing a Cipher using the IV, the solution is to let the Cipher generate a random IV instead. This will occur if the Cipher is initialized for encryption without an IV. The IV can then be queried via Cipher.getIV(); If you are generating a non-random IV (e.g., an IV derived from something not fully random, such as the name of the file being encrypted, or transaction ID, or password, or a device identifier), consider changing your design to use a random IV which will then be provided in addition to the ciphertext to the entities which need to decrypt the ciphertext; If you are using RSA encryption without padding, consider switching to padding schemes which offer IND-CPA, such as PKCS#1 or OAEP.
Portions of this page are modifications based on work created and shared by the Android Open Source Project and used according to terms described in the Creative Commons 2.5 Attribution License.