I want to update the app in a long time.
However, Google Play rejected the app for the following reasons.
(Remediation for Unsafe Encryption Mode Usage - support.google.com/faqs/answer/10046138)
The rejected code is as follows.
public SecretKeySpec generateKey(int keySize) {
Date date = new Date();
Random rand = new Random(date.getTime());
byte[] aesKeyData = new byte[keySize];
rand.nextBytes(aesKeyData);
SecretKeySpec aesKeySpec = new SecretKeySpec(aesKeyData, "AES" );
return aesKeySpec;
}
public byte[] encrypt(byte[] data, SecretKey key)
throws NoSuchAlgorithmException, NoSuchPaddingException,
InvalidKeyException, IllegalBlockSizeException, BadPaddingException {
Cipher cipher = Cipher.getInstance("AES/ECB/PKCS5Padding"); //here
cipher.init(Cipher.ENCRYPT_MODE, key);
byte[] outputBytes = cipher.doFinal(data);
return outputBytes;
}
public byte[] decrypt(byte[] data, SecretKey key)
throws NoSuchAlgorithmException, NoSuchPaddingException,
InvalidKeyException, IllegalBlockSizeException, BadPaddingException {
Cipher cipher = Cipher.getInstance("AES/ECB/PKCS5Padding"); //here
cipher.init(Cipher.DECRYPT_MODE, key);
byte[] outputBytes = cipher.doFinal(data);
return outputBytes;
}
This is the problem part. (i guess...)
Cipher.getInstance("AES/ECB/PKCS5Padding")
If I change this part to the following, I expect the problem to be solved.
Cipher.getInstance("AES/GCM/NoPadding")
However,
existing app users have encrypted data using "AES/ECB/PKCS5Padding".
So, after decrypting with "AES/ECB/PKCS5Padding" in the newly distributed app,
user data need to encrypt it with a new algorithm.
In this case, my new app should contain the existing algorithm that is rejected in Google Play.
Then, I guess, Google Play will do the same reject.
What should I do to solve this problem?