You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Android设备密钥对生成失败:LSKF未配置问题求助

部分Android设备密钥对生成失败问题排查求助

部分Android设备在生成密钥对时失败,抛出异常:java.security.ProviderException: Failed to generate key pair.,根源错误为Failed to handle super encryption.、Failed to super encrypt with LskfBound key.、LSKF is not setup for the user.。重置锁屏PIN/密码无法解决该问题。

注:LSKF即锁屏知识因子,指解锁设备的PIN/密码。

完整异常栈(三星S21,Android 14)

java.security.ProviderException: Failed to generate key pair.
    ...
    at android.view.View.performClick(View.java:8043) ~[na:0.0]
    at android.widget.TextView.performClick(TextView.java:17816) ~[na:0.0]
    at com.google.android.material.button.MaterialButton.performClick(MaterialButton.java:1218) ~[na:0.0]
    at android.view.View.performClickInternal(View.java:8020) ~[na:0.0]
    at android.view.View.-$$Nest$mperformClickInternal(Unknown Source:0) ~[na:0.0]
    at android.view.View$PerformClick.run(View.java:31850) ~[na:0.0]
    at android.os.Handler.handleCallback(Handler.java:958) ~[na:0.0]
    at android.os.Handler.dispatchMessage(Handler.java:99) ~[na:0.0]
    at android.os.Looper.loopOnce(Looper.java:230) ~[na:0.0]
    at android.os.Looper.loop(Looper.java:319) ~[na:0.0]
    at android.app.ActivityThread.main(ActivityThread.java:8893) ~[na:0.0]
    at java.lang.reflect.Method.invoke(Native Method) ~[na:0.0]
    at com.android.internal.os.RuntimeInit$MethodAndArgsCaller.run(RuntimeInit.java:608) ~[na:0.0]
    at com.android.internal.os.ZygoteInit.main(ZygoteInit.java:1103) ~[na:0.0]
 Caused by: android.security.KeyStoreException: Keystore not initialized (internal Keystore code: 3 message: system/security/keystore2/src/security_level.rs:701: In generate_key. 10012
 
 Caused by:
 0: system/security/keystore2/src/security_level.rs:209
 1: system/security/keystore2/src/security_level.rs:186: Failed to handle super encryption.
 2: system/security/keystore2/src/super_key.rs:758: Failed to super encrypt with LskfBound key.
 3: system/security/keystore2/src/super_key.rs:718: LSKF is not setup for the user.
 4: Error::Rc(r#UNINITIALIZED))
    at android.security.KeyStore2.getKeyStoreException(KeyStore2.java:399) ~[na:0.0]
    at android.security.KeyStoreSecurityLevel.handleExceptions(KeyStoreSecurityLevel.java:60) ~[na:0.0]
    at android.security.KeyStoreSecurityLevel.generateKey(KeyStoreSecurityLevel.java:161) ~[na:0.0]
    at android.security.keystore2.AndroidKeyStoreKeyPairGeneratorSpi.generateKeyPair(AndroidKeyStoreKeyPairGeneratorSpi.java:651) ~[na:0.0]
 24 common frames omitted

故障设备信息

  • 已设置强生物识别(指纹)
  • 已设置高复杂度字符串密码(PASSWORD_COMPLEXITY_HIGH)

密钥生成相关参数

setUserAuthenticationRequired(true)
setUserAuthenticationParameters(0,KeyProperties.AUTH_BIOMETRIC_STRONG)
setUserConfirmationRequired(false)
setDigests(KeyProperties.DIGEST_SHA256, KeyProperties.DIGEST_SHA512)

问题特征与已尝试动作

  • 该错误在生成RSA和EC密钥时均会出现;配置仅SHA256及基于时间的密钥认证 fallback,无效。
  • 无法直接访问故障设备,在多厂商测试设备上尝试移除并重新设置锁屏验证因子,甚至在部分旧设备上设置指纹后移除PIN保留指纹数据,均未复现该问题。
  • 为密钥生成流程添加针对不同密钥类型(RSA、EC)、哈希算法(SHA256、SHA512)及认证超时(单次使用、基于时间)的重试逻辑,故障设备上所有变体均触发错误。

求助

是否有用户遇到相同问题?能否复现该问题?盼提供解决方案或排查思路。

内容的提问来源于stack exchange,提问作者pHagi

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.26 18:35:35