Google Play Integrity Trust Architecture

Token 不是本地布尔值:Google 负责签发与验证环境声明,业务后端负责请求绑定和分级决策

Google Play Integrity standard request trust architecture An app warms a standard token provider, binds an action digest to a token request, receives a signed encrypted token, and forwards it to a backend that asks Google Play to decode and verify verdicts before making a business decision. DEVELOPER APP PROCESS ANDROID + GOOGLE PLAY ON DEVICE DEVELOPER BACKEND GOOGLE PLAY BACKEND prepare(projectNumber) protected cache 1. canonical SHA-256 2. requestHash 3. evaluate signals 4. encrypted token 5. token + original business request 6. decodeIntegrityToken 7. verified JSON verdict 9. policy action allow / limit / remediate / challenge / review / deny Cloud project link, package configuration, optional verdicts and quota App Startup / Warm-upprepare StandardIntegrityTokenProviderdo this before the critical action Protected Business Actionlogin / payment / score / redeem Stable Request Serializercritical params + session + transaction IDrequestHash contains a digest, not secrets App Transportopaque signed + encrypted tokenclient must not decode or trust itself Standard Token ProviderGoogle Play services prepares partial statesmart caching lowers critical-path latency Protected On-device Statecached attestation material / Play stateimplementation details remain platform-ownedcache is not a developer-issued trust ticket Integrity Token Requestpackage context + requestHashStandard requests receive replay mitigation Signal Assessmentapp / device / account / environmentPlay records + OS/OEM trust + boot stateexact attestation implementation is abstracted Integrity Token Gatewayservice account + playintegrity scopenever expose credentials to the app Binding and Verdict Checkspackage + requestHash + timestampapp / device / license / environmentUNEVALUATED is not a clean verdict BUSINESS POLICY ENGINE Play Console + Cloud Linkproject / package / verdict optionstest responses / reporting / quota Decode + Verify APIGoogle-managed verification pathrepeated token use clears verdict values Verified Verdict PayloadrequestDetails / appIntegritydeviceIntegrity / accountDetailsenvironmentDetails when enabled VERDICT GROUPS requestDetails: binding + freshness appIntegrity: binary identity deviceIntegrity: trust tier accountDetails: Play license environmentDetails: access / Protect Standard path: low-latency on-demand requests, requestHash content binding, Google-managed decode and automatic replay mitigation. Classic path: fresh assessment for infrequent high-value actions; developer nonce design and server-side replay tracking remain mandatory. Security boundary: a valid verdict proves selected environment properties for one request; it does not prove the human, intent or transaction legitimacy.

先验证请求绑定

  • 服务端先核对 package、requestHash/nonce 和时间窗口
  • 绑定失败时,后面的“设备完整”标签没有业务意义
  • 序列化必须稳定,并覆盖真正影响结果的关键参数

Verdict 不是设备 ID

  • App、设备、许可和环境是不同维度的声明
  • 标签为空或 UNEVALUATED 表示未评估,不是低风险
  • 证明结果应贴近受保护动作,不应长期缓存复用

业务后端仍是决策者

  • Google 验证 Token,业务后端解释金额、账号与历史风险
  • 低风险放行,中风险修复或追加认证,高风险复核
  • 无 GMS、网络故障和旧设备需要显式降级策略