Android Keystore, secure value of key

Viewed 5485

I'm currenlty investigating using the secured/improved Keystore introduced in Android 4.3.

I would like to store an encryption key inside this keystore, this key is used to encrypt a sqllite db and the values contained in my shared preferences.

When I take a look at the KeyStore Sample in the SDK I see the following:

public static final String ALIAS = "my_key"

If someone would be able to decompile my code they would be able to see the cleartext alias (= the key to retrieve the encryption key from the keystore) and hence they would be able to get a reference to my encryption key. How can I securly manage my ALIAS? or am I missing the point here?

2 Answers
Related