Skip to content

Key Management

Key Management Strategies

In Flutter mobile applications, secure key management is critical to protecting sensitive data such as encryption keys, API secrets, and user credentials. Poor key management practices can lead to vulnerabilities like data breaches, unauthorized access, or cryptographic weaknesses. This section covers best practices for managing encryption keys, including key derivation functions (KDFs) and secure storage strategies.


Key Derivation Functions (KDFs)

KDFs transform passwords or secrets into cryptographic keys, adding computational complexity to resist brute-force attacks. They are essential for deriving keys from user-provided passwords or other low-entropy inputs.

Common KDFs in Flutter

  1. PBKDF2 (Password-Based Key Derivation Function 2)
  2. Widely used for deriving keys from passwords.
  3. Requires a salt and iteration count to mitigate rainbow table attacks.
  4. Example:

    import 'package:crypto/crypto.dart';
    import 'package:dart:convert.dart';
    
    String deriveKey(String password, String salt) {
      final key = pbkdf2(password, salt, iterations: 100000, keyLength: 32);
      return base64Encode(key);
    }
    

  5. bcrypt

  6. Designed for password hashing, with built-in salting and work factor adjustment.
  7. Example:

    import 'package:bcrypt/bcrypt.dart';
    
    String hashPassword(String password) {
      return bcrypt.hashSync(password, rounds: 12);
    }
    

  8. Argon2

  9. Winner of the Password Hashing Competition (PHC), optimized for resistance to GPU/ASIC attacks.
  10. Use the argon2 package for Dart:
    import 'package:argon2/argon2.dart';
    
    Future<String> hashPassword(String password) async {
      final hash = await Argon2.hash(password, hashLength: 32);
      return hash;
    }
    

Best Practices

  • Always use a unique salt for each key derivation.
  • Adjust the iteration count/work factor based on device performance (e.g., higher values for production).
  • Avoid using KDFs for key encryption; use them only for deriving keys from passwords.

Secure Key Storage

Flutter apps must store cryptographic keys securely, leveraging platform-specific security features.

1. Flutter Secure Storage Plugin

  • A cross-platform library that abstracts Android Keystore and iOS Keychain.
  • Example:
    import 'package:secure_storage/secure_storage.dart';
    
    final storage = SecureStorage();
    await storage.write(key: 'encryption_key', value: 'base64_encoded_key');
    final String? key = await storage.read(key: 'encryption_key');
    

2. Platform-Specific Storage

  • Android: Use AndroidKeyStore for hardware-backed key storage.
  • iOS: Utilize Keychain Services for encrypted key storage.
  • Web: Avoid storing keys in plaintext; use Web Crypto API for in-memory encryption.

3. Avoid Plaintext Storage

  • Never store keys in SharedPreferences or other unencrypted storage.
  • Encrypt keys at rest using AES-256 or similar algorithms.

Key Rotation and Lifecycle Management

Keys should have a defined lifecycle, including rotation and secure deletion.

1. Key Rotation

  • Replace compromised or outdated keys with new ones.
  • Example workflow:
    1. Generate a new key using a KDF.
    2. Update the app to use the new key.
    3. Invalidate old keys (e.g., by marking them as expired).

2. Secure Deletion

  • Overwrite key memory locations with random data before deletion.
  • Use platform-specific APIs (e.g., SecureMemory on Android) to prevent memory dumps.

3. Key Management Systems (KMS)

  • For enterprise apps, integrate with cloud-based KMS (e.g., AWS KMS, Google Cloud KMS) to manage keys centrally.

Best Practices Summary

  • Derive keys using KDFs (PBKDF2, bcrypt, Argon2) to resist brute-force attacks.
  • Store keys in secure, platform-specific mechanisms (e.g., Keystore, Keychain).
  • Avoid hardcoded keys in source code; use environment variables or secure storage.
  • Encrypt keys at rest and rotate them periodically.
  • Leverage hardware-backed storage for high-security requirements.

Key Takeaways

  • Use KDFs like bcrypt or Argon2 to derive keys from passwords.
  • Store keys using Flutter's secure_storage plugin or platform-specific secure storage.
  • Rotate keys regularly and securely delete old keys to mitigate exposure.
  • Avoid plaintext storage and always encrypt keys at rest.
  • For enterprise apps, integrate with cloud-based KMS for centralized key management.