Click here to close now.



Welcome!

Mobile IoT Authors: Scott Allen, Pat Romanski, Philippe Abdoulaye, Dana Gardner, Liz McMillan

Related Topics: Release Management , Mobile IoT, Microservices Expo, Containers Expo Blog, Agile Computing, @CloudExpo

Release Management : Blog Feed Post

Android Encrypted Databases

Encryption as a security topic is perhaps the weakest link in that community

The Android development community, as might be expected, is a pretty vibrant community with a lot of great contributors helping people out. Since Android is largely based upon Java, there is a lot of skills reusability between the Java client dev community and the Android Dev community.

As I mentioned before, encryption as a security topic is perhaps the weakest link in that community at this time. Perhaps, but since that phone/tablet could end up in someone else’s hands much more easily than your desktop or even laptop, it is something that needs a lot more attention from business developers.

When I set out to write my first complex app for Android, I determined to report back to you from time-to-time about what needed better explanation or intuitive solutions. Much has been done in the realm of “making it easier”, except for security topics, which still rank pretty low on the priority list. So using encrypted SQLite databases is the topic of this post. If you think it’s taking an inordinate amount of time for me to complete this app, consider that I’m doing it outside of work. This blog was written during work hours, but all of the rest of the work is squeezed into two hours a night on the nights I’m able to dedicate time. Which is far from every night.

For those of you who are not developers, here’s the synopsis so you don’t have to paw through code with us: It’s not well documented, but it’s possible, with some caveats. I wouldn’t use this method for large databases that need indexes over them, but for securing critical data it works just fine. At the end I propose a far better solution that is outside the purview of app developers and would pretty much have to be implemented by the SQLite team.

Okay, only developers left? Good.

In my research, there were very few useful suggestions for designing secure databases. They fall into three categories:

  1. Use the NDK to write a variant of SQLite that encrypts at the file level. For most Android developers this isn’t an option, and I’m guessing the SQLite team wouldn’t be thrilled about you mucking about with their database – it serves a lot more apps than yours.
  2. Encrypt the entire SD card through the OS and then store the DB there. This one works, but slows the function of the entire tablet/phone down because you’ve now (again) mucked with resources used by other apps. I will caveat that if you can get your users to do this, it is the currently available solution that allows indices over encrypted data.
  3. Use one of several early-beta DB encryption tools. I was uncomfortable doing this with production systems. You may feel differently, particularly after some of them have matured.

I didn’t like any of these options, so I did what we’ve had to do in the past when a piece of data was so dangerous in the wrong hands it needed encrypting. I wrote an interface to the DB that encrypts and decrypts as data is inserted and removed. In Android the only oddity you won’t find in other Java environments – or you can more easily get around in other Java environments – is filling list boxes from the database. For that I had to write a custom provider that took care of on-the-fly decryption and insertion to the list.

My solution follows. There are a large varieties of ways that you could solve this problem in Java, this one is where I went because

  1. I don’t have a lot of rows for any given table.
  2. The data does not need to be indexed.

If either of these items is untrue for your implementation, you’ll either have to modify this implementation or find an alternate solution.

So first the encryption handler. Note that in this sample, I chose to encode encrypted arrays of bytes as Strings. I do not guarantee this will work for your scenario, and suggest you keep them as arrays of bytes until after decryption. Also note that this sample was built from a working one by obfuscating what the actual source did and making some modifications for simplification of example. It was not tested after the final round of simplification, but should be correct throughout.

package com.company.monitor;

import javax.crypto.Cipher;
import javax.crypto.spec.SecretKeySpec;

import android.util.Base64;

public class DBEncryptor {
private static byte[] key;
private static String cypherType = cypherType;

public DBEncryptor(String localPass) {

// save the encoded key for future use
// - note that this keeps it in memory, and is not strictly safe
key = encode(localPass.getBytes()).getBytes();
String keyCopy = new String(key);
while(keyCopy.length() < 16)
keyCopy = keyCopy + keyCopy;

byte keyA[] = keyCopy.getBytes();
if(keyA.length > 16)
key = System.arraycopy(keyA, 0, key, 0, 16);
}

public String encode(byte [] s) {

return Base64.encodeToString(s, Base64.URL_SAFE);
}

public byte[] decode(byte[] s) {
return Base64.decode(s, Base64.URL_SAFE);
}


public byte[] getKey() {
// return a copy of the key.
return key.clone();
}

public String encrypt(String toEncrypt) throws Exception {

//Create your Secret Key Spec, which defines the key transformations
SecretKeySpec skeySpec = new SecretKeySpec(key, cypherType);

//Get the cipher
Cipher cipher = Cipher.getInstance(cypherType);

//Initialize the cipher
cipher.init(Cipher.ENCRYPT_MODE, skeySpec);

//Encrypt the string into bytes
byte[ ] encryptedBytes = cipher.doFinal(toEncrypt.getBytes());

//Convert the encrypted bytes back into a string
String encrypted = encode(encryptedBytes);

return encrypted;
}

public String decrypt(String encryptedText) throws Exception {

// Get the secret key spec
SecretKeySpec skeySpec = new SecretKeySpec(key, cypherType);

// create an AES Cipher
Cipher cipher = Cipher.getInstance(cypherType);

// Initialize it for decryption
cipher.init(Cipher.DECRYPT_MODE, skeySpec);

// Get the decoded bytes
byte[] toDecrypt = decode(encryptedText.getBytes());

// And finally, do the decryption.
byte[] clearText = cipher.doFinal(toDecrypt);

return new String(clearText);
}
}

So what we are essentially doing is base-64 encoding the string to be encrypted, and then encrypting the base-64 value using standard Java crypto classes. We simply reverse the process to decrypt a string. Note that this class is also useful if you’re storing values in the Properties file and wish them to be encrypted, since it simply operates on strings.

The value you pass in to create the key needs to be something that is unique to the user or tablet. When it comes down to it, this is your password, and should be treated as such (hence why I changed the parameter name to localPass).

For seasoned Java developers, there’s nothing new on Android at this juncture. We’re just encrypting and decrypting data.

Next it does leave the realm of other Java platforms because the database is utilizing SQLite, which is not generally what you’re writing Java to outside of Android. Bear with me while we go over this class.

The SQLite database class follows. Of course this would need heavy modification to work with your database, but the skeleton is here. Note that not all fields have to be encrypted. You can mix and match, no problems at all. That is one of the things I like about this solution, if I need an index for any reason, I can create an unencrypted field of a type other than blob and index on it.

package com.company.monitor;

import android.content.ContentValues;
import android.content.Context;
import android.database.Cursor;
import android.database.sqlite.SQLiteDatabase;
import android.database.sqlite.SQLiteDatabase.CursorFactory;
import android.database.sqlite.SQLiteOpenHelper;

public class DBManagernames extends SQLiteOpenHelper {
public static final String TABLE_NAME = "Map";
public static final String COLUMN_ID = "_id";
public static final String COLUMN_LOCAL = "Local";
public static final String COLUMN_WORLD = "World";


private static int indexId = 0;
private static int indexLocal = 1;
private static int indexWorld = 2;

private static final String DATABASE_NAME = "Mappings.db";
private static final int DATABASE_VERSION = 1;

// SQL statement to create the DB
private static final String DATABASE_CREATE = "create table "
+ TABLE_NAME + "(" + COLUMN_ID
+ " integer primary key autoincrement, " + COLUMN_LOCAL
+ " BLOB not null, " + COLUMN_WORLD +" BLOB not null);";

public DBManagernames(Context context, CursorFactory factory) {
super(context, DATABASE_NAME, factory, DATABASE_VERSION);

}

@Override
public void onCreate(SQLiteDatabase db) {
db.execSQL(DATABASE_CREATE);


}

@Override
public void onUpgrade(SQLiteDatabase db, int oldVersion, int newVersion) {
// TODO Auto-generated method stub
// Yeah, this isn't implemented in production yet either. It's low on the list, but definitely "on the list"

}

// Assumes DBEncryptor was used to convert the fields of name before calling insert
public void insertToDB(DBNameMap name) {
ContentValues cv = new ContentValues();

cv.put(COLUMN_LOCAL, name.getName().getBytes());
cv.put(COLUMN_WORLD, name.getOtherName().getBytes());

getWritableDatabase().insert(TABLE_NAME, null, cv);
}

// returns the encrypted values to be manipulated with the decryptor.   
public DBNameMap readFromDB(Integer index) {

SQLiteDatabase db = getReadableDatabase();
DBNameMap hnm = new DBNameMap();
Cursor cur = null;
try {
cur = db.query(TABLE_NAME, null, "_id='"+index.toString() +"'", null, null, null, COLUMN_ID);
// cursors connsistently return before the first element. Move to the first.
cur.moveToFirst();
byte[] name = cur.getBlob(indexLocal);
byte [] othername = cur.getBlob(indexWorld);

hnm = new DBNameMap(new String(name), new String(othername), false);
} catch(Exception e) {
System.out.println(e.toString());
// Do nothing - we want to return the empty host name map.
}
return hnm;

}

// NOTE: This routine assumes "String name" is the encrypted version of the string.   
public DBNameMap getFromDBByName(String name) {
SQLiteDatabase db = getReadableDatabase();
Cursor cur = null;
String check = null;
try {
// Note - the production version of this routine actually uses the "where" field to get the correct
// element instead of looping the table. This is here for your debugging use.
cur = db.query(TABLE_NAME, null, null, null, null, null, null);
for(cur.moveToFirst();(!cur.isLast());cur.moveToNext()) {
check = new String(cur.getBlob(indexLocal));
if(check.equals(name))
return new DBNameMap(check, new String(cur.getBlob(indexWorld)), false);

}
if(cur.isLast())
return new DBNameMap();

return new DBNameMap(cur.getString(indexLocal), cur.getString(indexWorld), false);
} catch(Exception e) {
System.out.println(e.toString());
return new DBNameMap();
}

}


// used by our list adapter - coming next in the blog.
public Cursor getCursor() {
try {

return getReadableDatabase().query(TABLE_NAME, null, null, null, null, null, null);
} catch(Exception e) {
System.out.println(e.toString());
return null;
}
}

// This is used in our list adapter for mapping to fields.
public String[] listColumns() {
return new String[] {COLUMN_LOCAL};
}


}

I am not including the DBNameMap class, as it is a simple container that has two string fields and maps one name to another.

Finally, we have the List Provider. Android requires that you populate lists with a provider, and has several base ones to work with. The problem with the SimpleCursorAdapter is that it assumes an unencrypted database, and we just invested a ton of time making the DB encrypted. There are several possible solutions to this problem, and I present the one I chose here. I extended ResourceCursorAdapter and implemented decryption right in the routines, leaving not much to do in the list population section of my activity but to assign the correct adapter.

package com.company.monitor;

import android.content.Context;
import android.database.Cursor;
import android.view.LayoutInflater;
import android.view.View;
import android.view.ViewGroup;
import android.widget.ResourceCursorAdapter;
import android.widget.TextView;

public class EncryptedNameAdapter extends ResourceCursorAdapter {

private String pw;

public EncryptedHostNameAdapter(Context context, int layout, Cursor c,
boolean autoRequery) {
super(context, layout, c, autoRequery);
}

public EncryptedHostNameAdapter(Context context, int layout, Cursor c,
int flags) {
super(context, layout, c, flags);
}

// This class must know what the encryption key is for the DB before filling the list,
// so this call must be made before the list is populated. The first call after the constructor works.
public void setPW(String pww) {
pw = pww;
}


@Override
public View newView(Context context, Cursor cur, ViewGroup parent) {
LayoutInflater li = (LayoutInflater) context.getSystemService(Context.LAYOUT_INFLATER_SERVICE);
return li.inflate(R.layout.my_list_entry, parent, false);
}

@Override
public void bindView(View arg0, Context arg1, Cursor arg2) {
// Get an encryptor/decryptor for our data.
DBEncryptor enc = new DBEncryptor(pw);

// Get the TextView we're placing the data into.
TextView tvLocal = (TextView)arg0.findViewById(R.id.list_entry_name);
// Get the bytes from the cursor
byte[] bLocal = arg2.getBlob(arg2.getColumnIndex(DBManagerNames.COLUMN_LOCAL ));
// Convert bytes to a string
String local = new String(bSite);

try {
// decrypt the string
local = enc.decrypt(local);
} catch(Exception e) {
System.out.println(e.toString());

// local holds the encrypted version at this point, fix it.

// We’ll return an empty string for simplicity
local = new String();  
}
tvSite.setText(local);
}

}

The EncryptedNameAdapter can be set as the source for any listbox just like most examples set an ArrayAdapter as the source. Of course, it helps if you’ve put some data in the database first Winking smile.

That’s it for this time. There’s a lot more going on with this project, and I’ll present my solution for SSL certificate verification some time in the next couple of weeks, but for now if you need to encrypt some fields of a database, this is one way to get it done. Ping me on any of the social media outlets or here in the comments if you know of a more elegant/less resource intensive solution, always up for learning more.

And please, if you find an error, it was likely introduced in the transition to something I was willing to throw out here publicly, but let me know so others don’t have problems. I’ve done my best not to introduce any, but always get a bit paranoid if I changed it after my last debug session – and I did to simplify and sanitize.

Read the original blog entry...

More Stories By Don MacVittie

Don MacVittie is currently a Senior Solutions Architect at StackIQ, Inc. He is also working with Mesamundi on D20PRO, and is a member of the Stacki Open Source project. He has experience in application development, architecture, infrastructure, technical writing, and IT management. MacVittie holds a B.S. in Computer Science from Northern Michigan University, and an M.S. in Computer Science from Nova Southeastern University.

@ThingsExpo Stories
Basho Technologies has announced the latest release of Basho Riak TS, version 1.3. Riak TS is an enterprise-grade NoSQL database optimized for Internet of Things (IoT). The open source version enables developers to download the software for free and use it in production as well as make contributions to the code and develop applications around Riak TS. Enhancements to Riak TS make it quick, easy and cost-effective to spin up an instance to test new ideas and build IoT applications. In addition to...
IoT is rapidly changing the way enterprises are using data to improve business decision-making. In order to derive business value, organizations must unlock insights from the data gathered and then act on these. In their session at @ThingsExpo, Eric Hoffman, Vice President at EastBanc Technologies, and Peter Shashkin, Head of Development Department at EastBanc Technologies, discussed how one organization leveraged IoT, cloud technology and data analysis to improve customer experiences and effi...
Internet of @ThingsExpo has announced today that Chris Matthieu has been named tech chair of Internet of @ThingsExpo 2016 Silicon Valley. The 6thInternet of @ThingsExpo will take place on November 1–3, 2016, at the Santa Clara Convention Center in Santa Clara, CA.
Presidio has received the 2015 EMC Partner Services Quality Award from EMC Corporation for achieving outstanding service excellence and customer satisfaction as measured by the EMC Partner Services Quality (PSQ) program. Presidio was also honored as the 2015 EMC Americas Marketing Excellence Partner of the Year and 2015 Mid-Market East Partner of the Year. The EMC PSQ program is a project-specific survey program designed for partners with Service Partner designations to solicit customer feedbac...
The cloud promises new levels of agility and cost-savings for Big Data, data warehousing and analytics. But it’s challenging to understand all the options – from IaaS and PaaS to newer services like HaaS (Hadoop as a Service) and BDaaS (Big Data as a Service). In her session at @BigDataExpo at @ThingsExpo, Hannah Smalltree, a director at Cazena, provided an educational overview of emerging “as-a-service” options for Big Data in the cloud. This is critical background for IT and data profession...
"There's a growing demand from users for things to be faster. When you think about all the transactions or interactions users will have with your product and everything that is between those transactions and interactions - what drives us at Catchpoint Systems is the idea to measure that and to analyze it," explained Leo Vasiliou, Director of Web Performance Engineering at Catchpoint Systems, in this SYS-CON.tv interview at 18th Cloud Expo, held June 7-9, 2016, at the Javits Center in New York Ci...
Ask someone to architect an Internet of Things (IoT) solution and you are guaranteed to see a reference to the cloud. This would lead you to believe that IoT requires the cloud to exist. However, there are many IoT use cases where the cloud is not feasible or desirable. In his session at @ThingsExpo, Dave McCarthy, Director of Products at Bsquare Corporation, will discuss the strategies that exist to extend intelligence directly to IoT devices and sensors, freeing them from the constraints of ...
Connected devices and the industrial internet are growing exponentially every year with Cisco expecting 50 billion devices to be in operation by 2020. In this period of growth, location-based insights are becoming invaluable to many businesses as they adopt new connected technologies. Knowing when and where these devices connect from is critical for a number of scenarios in supply chain management, disaster management, emergency response, M2M, location marketing and more. In his session at @Th...
Extracting business value from Internet of Things (IoT) data doesn’t happen overnight. There are several requirements that must be satisfied, including IoT device enablement, data analysis, real-time detection of complex events and automated orchestration of actions. Unfortunately, too many companies fall short in achieving their business goals by implementing incomplete solutions or not focusing on tangible use cases. In his general session at @ThingsExpo, Dave McCarthy, Director of Products...
There are several IoTs: the Industrial Internet, Consumer Wearables, Wearables and Healthcare, Supply Chains, and the movement toward Smart Grids, Cities, Regions, and Nations. There are competing communications standards every step of the way, a bewildering array of sensors and devices, and an entire world of competing data analytics platforms. To some this appears to be chaos. In this power panel at @ThingsExpo, moderated by Conference Chair Roger Strukhoff, Bradley Holt, Developer Advocate a...
The Internet of Things will challenge the status quo of how IT and development organizations operate. Or will it? Certainly the fog layer of IoT requires special insights about data ontology, security and transactional integrity. But the developmental challenges are the same: People, Process and Platform and how we integrate our thinking to solve complicated problems. In his session at 19th Cloud Expo, Craig Sproule, CEO of Metavine, will demonstrate how to move beyond today's coding paradigm ...
Apixio Inc. has raised $19.3 million in Series D venture capital funding led by SSM Partners with participation from First Analysis, Bain Capital Ventures and Apixio’s largest angel investor. Apixio will dedicate the proceeds toward advancing and scaling products powered by its cognitive computing platform, further enabling insights for optimal patient care. The Series D funding comes as Apixio experiences strong momentum and increasing demand for its HCC Profiler solution, which mines unstruc...
SYS-CON Events has announced today that Roger Strukhoff has been named conference chair of Cloud Expo and @ThingsExpo 2016 Silicon Valley. The 19th Cloud Expo and 6th @ThingsExpo will take place on November 1-3, 2016, at the Santa Clara Convention Center in Santa Clara, CA. "The Internet of Things brings trillions of dollars of opportunity to developers and enterprise IT, no matter how you measure it," stated Roger Strukhoff. "More importantly, it leverages the power of devices and the Interne...
In addition to all the benefits, IoT is also bringing new kind of customer experience challenges - cars that unlock themselves, thermostats turning houses into saunas and baby video monitors broadcasting over the internet. This list can only increase because while IoT services should be intuitive and simple to use, the delivery ecosystem is a myriad of potential problems as IoT explodes complexity. So finding a performance issue is like finding the proverbial needle in the haystack.
Machine Learning helps make complex systems more efficient. By applying advanced Machine Learning techniques such as Cognitive Fingerprinting, wind project operators can utilize these tools to learn from collected data, detect regular patterns, and optimize their own operations. In his session at 18th Cloud Expo, Stuart Gillen, Director of Business Development at SparkCognition, discussed how research has demonstrated the value of Machine Learning in delivering next generation analytics to imp...
Whether your IoT service is connecting cars, homes, appliances, wearable, cameras or other devices, one question hangs in the balance – how do you actually make money from this service? The ability to turn your IoT service into profit requires the ability to create a monetization strategy that is flexible, scalable and working for you in real-time. It must be a transparent, smoothly implemented strategy that all stakeholders – from customers to the board – will be able to understand and comprehe...
The cloud market growth today is largely in public clouds. While there is a lot of spend in IT departments in virtualization, these aren’t yet translating into a true “cloud” experience within the enterprise. What is stopping the growth of the “private cloud” market? In his general session at 18th Cloud Expo, Nara Rajagopalan, CEO of Accelerite, explored the challenges in deploying, managing, and getting adoption for a private cloud within an enterprise. What are the key differences between wh...
The IoT is changing the way enterprises conduct business. In his session at @ThingsExpo, Eric Hoffman, Vice President at EastBanc Technologies, discussed how businesses can gain an edge over competitors by empowering consumers to take control through IoT. He cited examples such as a Washington, D.C.-based sports club that leveraged IoT and the cloud to develop a comprehensive booking system. He also highlighted how IoT can revitalize and restore outdated business models, making them profitable ...
IoT offers a value of almost $4 trillion to the manufacturing industry through platforms that can improve margins, optimize operations & drive high performance work teams. By using IoT technologies as a foundation, manufacturing customers are integrating worker safety with manufacturing systems, driving deep collaboration and utilizing analytics to exponentially increased per-unit margins. However, as Benoit Lheureux, the VP for Research at Gartner points out, “IoT project implementers often ...
When people aren’t talking about VMs and containers, they’re talking about serverless architecture. Serverless is about no maintenance. It means you are not worried about low-level infrastructural and operational details. An event-driven serverless platform is a great use case for IoT. In his session at @ThingsExpo, Animesh Singh, an STSM and Lead for IBM Cloud Platform and Infrastructure, will detail how to build a distributed serverless, polyglot, microservices framework using open source tec...