KeyCustody class

How a device custodies its private key material — maintainer policy input, mirroring attestation. See docs/design-notes/mobile-key-custody-profile.md.

Constructors

KeyCustody({required KeyCustodyTier tier, String? signingAlg, String? keyAgreementCurve})
const
KeyCustody.fromJson(Map<String, dynamic> json)
Read this payload from a decoded JSON object.
factory

Properties

hashCode → int
The hash code for this object.
no setterinherited
keyAgreementCurve → String?
Curve of the holder's keyAgreement key, e.g. P-256 (hardware-custodiable on mobile) or X25519 (not).
final
runtimeType → Type
A representation of the runtime type of the object.
no setterinherited
signingAlg → String?
JOSE alg of the holder's signing key, e.g. ES256 (hardware-custodiable on mobile) or EdDSA (not).
final
tier → KeyCustodyTier
hardware: the key is non-exportable in the secure keystore (iOS Secure Enclave / Android StrongBox) and every signing / key-agreement operation runs in-chip — achievable only with P-256. software: the key is held in app memory during use, stored hardware-wrapped at rest. Maintainers MAY apply stricter policy (shorter sessions, more frequent step-up) to software-tier devices.
final

Methods

noSuchMethod(Invocation invocation) → dynamic
Invoked when a nonexistent method or property is accessed.
inherited
toJson() → Map<String, dynamic>
Serialize to a JSON-encodable map, omitting absent members.
toString() → String
A string representation of this object.
inherited

Operators

operator ==(Object other) → bool
The equality operator.
inherited