Android Password De/Encryption with Keystore

SebastianSchlundSebastianSchlund DEMember ✭✭
edited February 2016 in Xamarin.Android

I´m trying to implement a Password encryption with the Android Keystore in Xamarin. I found that tutorial for implementing it in java I tryed my best to convert the important parts into c#. My Problem now is that everything works fine, no errors. But i get an array of 256 0 (which is the number of entrys i put encypted into the Stream for decryption)back in the "values" list after decrypting... I should get about 6 bytes back. The appname is also shown in the aliaslist, so the key should be there.

class Security:ISecurity
        readonly KeyStore _keyStore;
        private readonly string _alias = "appname";
        private Locale local = Locale.Germany;
        private String encryptedText;
        private FileHelperLocal _helper = new FileHelperLocal();
        private byte[] vals;
        private List<Java.Lang.Object> aliaslist;
        public Security()
            _keyStore = KeyStore.GetInstance("AndroidKeyStore");
            aliaslist = new List<Java.Lang.Object>();
            var alias = _keyStore.Aliases();
            while (alias.HasMoreElements)
        public async void SaveCredential(string userName, String password)
            KeyStore.PrivateKeyEntry privateKeyEntry = (KeyStore.PrivateKeyEntry)_keyStore.GetEntry(_alias, null);
            var publicKey = privateKeyEntry.Certificate.PublicKey;//

            Cipher input = Cipher.GetInstance("RSA/ECB/PKCS1Padding", "AndroidOpenSSL");
            input.Init(CipherMode.EncryptMode, publicKey);//

        MemoryStream outputStream = new MemoryStream();
        CipherOutputStream cipherOutputStream = new CipherOutputStream(
                outputStream, input);

        vals = outputStream.ToArray();

    public byte[] GetCredential()
        string[] credentials = new string[2];
        KeyStore.PrivateKeyEntry privateKeyEntry = (KeyStore.PrivateKeyEntry)_keyStore.GetEntry(_alias, null);
        var privateKey = privateKeyEntry.PrivateKey;//

        Cipher output = Cipher.GetInstance("RSA/ECB/PKCS1Padding", "AndroidOpenSSL");
        output.Init(CipherMode.EncryptMode, privateKey);

        CipherInputStream cipherInputStream = new CipherInputStream(
                new MemoryStream(vals), output);

        List<byte> values = new List<byte>();

        int nextByte;
        while ((nextByte = cipherInputStream.Read()) != -1)

        return  values;

    public void RemoveCredential(string userName)

    private void createNewKey()
        if (!_keyStore.ContainsAlias(_alias))
            Calendar start = Calendar.GetInstance(local);
            Calendar end = Calendar.GetInstance(local);
            end.Add(CalendarField.Year, 1);
            KeyPairGeneratorSpec spec = new KeyPairGeneratorSpec.Builder(Xamarin.Forms.Forms.Context)
                    .SetSubject(new X500Principal("CN=Sample Name, O=Android Authority"))
            KeyPairGenerator generator = KeyPairGenerator.GetInstance("RSA", "AndroidKeyStore");

            KeyPair keyPair = generator.GenerateKeyPair();


  • KyleRobitailleKyleRobitaille USUniversity ✭✭
    edited August 2017

    I know this is a bit old now, but were you ever able to figure out what the problem was? I'm running into the exact same issue. To me it looks like CipherInputStream isn't writing to the memory stream correctly.

Sign In or Register to comment.