I'm working on a app for Android that makes use of files encrypted with AES. I want to provide the user with the ability to scan their fingerprint to decrypt instead of providing their password.
From what I've understood, it's possible to store persistent data in Android's keystore. So my initial idea was to store the password for the file in the keystore and then use a successful fingerprint auth to retrieve this password. Problem is, I haven't been able to figure out how to first auth using a fingeprint and then only return the password if the fingerprint auth succeeded. Is this possible?
I imagine local auth is useless in this case considering I need unique data to encrypt/decrypt the file?
Or is there another way to do this?