Android and iOS

Reducing the lifetime of secrets in memory

Key lifecycles, signatures, encryption and application data.

Keys and cryptography1 min readEditorial methods

Encrypted data may become plaintext when used. Unnecessary copies and long lifetimes broaden exposure.

Evaluation approach

Retrieve secrets only when needed. Reduce logs, crash-report copies and immutable strings, accounting for platform memory management.

Application example

Keep key material within the transaction lifecycle instead of a long-lived global object.

Limits and considerations

Clearing one buffer in managed memory does not guarantee deletion of every copy.

What does zeroing actually cover?

Earlier copies can survive clearing a buffer. Avoid creating unnecessary strings, logs and long-lived references in the first place.

Checks and decisions

  • Shorten lifetimes
  • Reduce copies
  • Review diagnostics

Sources

The primary references above provide the technical basis. Example workflows and evaluation suggestions are this publication’s explanations, not independent test results for a particular product.