How Android Strongbox and Open Standards Enable the Future of High-Assurance Digital Credentials
Digital credentials make it easy to securely store and share your identity, prove who you are, and access critical public and private services—all from your smartphone. From national electronic IDs (eIDs) and mobile driver’s licenses (mDLs) to banking logins, digital identity is rapidly shifting from physical plastic cards to privacy-preserving, hardware-backed mobile wallets.
For governments and credential issuers, deploying digital IDs sometimes requires certified hardware security guarantees on the underlying device. Our whitepaper details the security requirements and how Android's architecture supports high-assurance credentials.
To meet accelerating global demand for these credentials, we are expanding our hardware ecosystem initiative: Android Ready SE will become the Android Digital Credential Alliance. This alliance broadens our work across the digital credential value chain—from silicon providers to government issuers—to ensure seamless integration and compliance.
Android provides a universal, hardware-backed keystore foundation built directly into the platform to enable the future of digital credentials securely and at global scale. For use cases with elevated security requirements—such as national eIDs—Android Strongbox provides, on devices with capable hardware, dedicated, tamper-resistant silicon designed to support compliance with stringent global security and privacy frameworks. This enables governments, commercial wallet implementors, and third-party developers to deploy high-assurance digital credentials alongside everyday mobile credentials—built on open, cross-platform standards.
How Android Builds a Chain of Trust
A trusted digital credential is not just an encrypted file on a phone; it is the cryptographic result of a multi-stage Chain of Trust. Android’s platform-centric architecture establishes four verifiable links that wallet applications and relying parties build upon:
- Establish Trust with Hardware Key Attestation:
Trust begins at device manufacturing. Using Android Key Attestation and Remote Key Provisioning (RKP), the device generates a cryptographic verifiable certificate chain. Credential issuers can remotely verify that the device is running genuine Android software and that private keys reside inside certified hardware before any credential data is provisioned. - Strongbox for Tamper-Resistant Device Binding:
Once platform integrity is proven, keypairs generated inside Strongbox cryptographically bind the credential to the physical device. Strongbox executes inside a dedicated, physically isolated Secure Element (SE) certified at least at Common Criteria EAL4+ with AVA_VAN.5, providing high security assurance against physical attacks. - Privacy-Preserving Presentment with Auth-Bound Keys:
Empowering users with granular control of their data. Through auth-bound keys, Strongbox gates credential release behind explicit human presence. Using hardware-enforced authentication tokens (HATs) from on-device biometric sensors or PIN/passcode verification, digital credentials cannot be validly presented without user authentication (such as biometric verification or PIN/passcode). - Authorizing Actions and Verifying Intent:
Beyond visual identity checks, the credential private key can sign application-specific transaction payloads. This enables hardware-backed cryptographic authorization for high-value operations, such as approving transactions or signing digital records.
Growing Ecosystem Adoption: Powering Wallets at Scale
A core strength of Android’s architecture is platform openness: secure hardware protection is a native platform capability available to every wallet. To turn open standards into turnkey implementations, Google founded and actively contributes to the Multipaz project - an open-source, cross-platform digital credential SDK supporting:
- Issuance and presentation protocols (OpenID4VCI, OpenID4VP)
- Credential formats (ISO/IEC 18013-5 mDL, W3C/IETF SD-JWT VC)
- Zero-Knowledge Proofs with Longfellow-ZKP (which also help address age assurance)
The SDK backs these standards natively with Android Keystore and StrongBox hardware security. This serves as a foundational component for Google Wallet and the European Digital Identity Wallet (EUDIW) reference implementation.
Ecosystem Acceleration: Introducing the Android Digital Credential Alliance
To meet the accelerating global demand for high-assurance digital credentials—driven by mandates like eIDAS 2.0 and national eID programs worldwide—we are expanding our hardware ecosystem initiative: Android Ready SE is going to become the Android Digital Credential Alliance.
Since its launch in March 2021, Android Ready SE has united leading Secure Element (SE) and SoC vendors around pre-validated, open-source applets, including Strongbox KeyMint and Weaver. This collaborative effort significantly lowered integration barriers for device makers and scaled certified, tamper-resistant hardware across hundreds of millions of Android devices.
Building on this proven silicon foundation, the Android Digital Credential Alliance broadens its scope across the entire digital identity value chain:
- End-to-End Ecosystem Alignment: Deepening technical collaboration across SoC providers, SE vendors, OEMs, wallet developers, and government issuers to ensure seamless integration from silicon to user experience.
- Streamlined Regulatory Compliance: Establishing shared testing frameworks, reference architectures, and security evaluations to help partners achieve Common Criteria EAL4+/AVA_VAN.5 across components and eIDAS High assurance with minimal friction.
- Broadening Device Availability: Partnering with OEMs and silicon providers to expand certified Strongbox implementations across a wider range of device tiers, ensuring citizens everywhere can securely and privately store their digital credentials on device.
We invite silicon vendors, device manufacturers, and wallet implementers to join the Android Digital Credential Alliance as we collaborate on defining the future of secure, mobile-first identity. To learn more, please reach out to your primary Google point of contact.
A Universal Foundation for Global Partners
Whether you are a government agency digitizing national identity documents, a regulatory body evaluating mobile platform assurance, or an app developer building next-generation digital services, Android provides the open tools to build with confidence:
- For Security Evaluators & Regulators: Read our comprehensive technical whitepaper, High Assurance Digital Credentials on Android: A Framework for Hardware-Backed Security, which outlines Android's split-certification approach to natively support Digital Credentials globally.
- For Wallet Builders & Developers:
- Explore the Android Keystore & Strongbox Developer Documentation to integrate hardware-backed keys directly into your application.
- Follow the hands-on Multipaz Utopia Wholesale Codelab to build and issue privacy-preserving digital credentials from scratch.
We look forward to continuing our collaborations with governments, standards bodies, and open-source communities worldwide to make digital identity secure, private, and accessible for everyone.