DroidKey: A Practical Framework and Analysis Tool for API Key Security in Android Applications

dc.contributor.authorPiyumantha, K.
dc.contributor.authorSenanayake, J.
dc.contributor.authorWijayasiriwardhane, K.
dc.date.accessioned2025-11-18T07:01:33Z
dc.date.issued2025
dc.description.abstractThe reliance on mobile applications has amplified concerns about Application Programming Interface (API) key security in Android platforms. Serving as essential authentication mechanisms, API keys ensure secure communication with external services. However, insecure practices like hardcoding expose keys to reverse engineering and unauthorized use. This research introduces the DroidKey Analysis Tool, designed to evaluate vulnerabilities and guide developers toward secure practices. The tool integrates a comprehensive framework encompassing six security domains. The methodology combines a systematic literature review, expert feedback, and validation through controlled experiments and real-world app evaluations. Results highlight the effectiveness of DroidKey, with secure implementations, such as those of the "Sample Mobile App," achieving significantly higher security scores than their insecure counterparts. Assessments of 10 real-world banking apps further reveal widespread vulnerabilities, underscoring the tool's utility in addressing hardcoded keys and weak encryption. By leveraging industry-standard tools, the DroidKey Analysis Tool offers actionable insights to improve app security. Future enhancements, including real-time monitoring and expanded API key detection, are proposed to strengthen its functionality further. This research bridges the gap between theoretical security frameworks and practical applications, contributing to the advancement of Android app security.
dc.identifier.citationPiyumantha, K., Senanayake, J., & Wijayasiriwardhane, K. (2025). DroidKey: A practical framework and analysis tool for API key security in Android applications. International Research Conference on Smart Computing and Systems Engineering (SCSE 2025). Department of Industrial Management, Faculty of Science, University of Kelaniya, Sri Lanka. (P. 102).
dc.identifier.urihttp://repository.kln.ac.lk/handle/123456789/30424
dc.publisherDepartment of Industrial Management, Faculty of Science, University of Kelaniya, Sri Lanka.
dc.subjectAPI Key Security
dc.subjectAndroid Applications
dc.subjectKey Management
dc.subjectMobile Security
dc.subjectReverse Engineering Protection
dc.titleDroidKey: A Practical Framework and Analysis Tool for API Key Security in Android Applications
dc.typeArticle

Files

Original bundle

Now showing 1 - 1 of 1
Loading...
Thumbnail Image
Name:
SCSE Abstract Proceedings 2025-126.pdf
Size:
93.92 KB
Format:
Adobe Portable Document Format

License bundle

Now showing 1 - 1 of 1
Loading...
Thumbnail Image
Name:
license.txt
Size:
1.71 KB
Format:
Item-specific license agreed upon to submission
Description: