Xuanshu

End-to-end security solutions for mobile, PC, and IoT applications

Xuanshu combines a security SDK embedded in mobile, PC, and IoT applications with dedicated backend services. Built around white-box cryptography, it protects applications before, during, and after execution, even in untrusted environments.

Take Application Security Further

White-Box Protection for On-Device Keys and Data

White-box cryptography makes keys difficult to extract even when the complete code is exposed. It safeguards keys and data during computation, storage, and transmission, using TLS channels and E2E content to provide dual encryption. It is suitable for protecting sensitive data, device identities, and API keys.

Virtualized High-Security Runtime Environment

It builds a highly secure virtualized runtime environment on mobile devices, maximizing the security of critical code execution.

Native Code Protection & Encryption Obfuscation

It checks and ensures the integrity of native code, uses compiler plug-ins to introduce obfuscation logic, and hardens the code.

Mobile Application Access Control

Each instance is isolated at the application access level. Only authorized, legitimate mobile applications are allowed to invoke, access, and use the instance. Unauthorized apps, counterfeit apps, malicious third-party applications, and cross-application access and invocation are prohibited.

Device Environment Security Detection

It assesses risks in the mobile application runtime environment in real time and comprehensively identifies high-risk scenarios, including root/jailbreak, emulator spoofing, dynamic debugging, app cloning and tampering, application signature issues, and memory integrity issues.

Full Lifecycle Management for Xuanshu Instances

Each instance has a unique identifier and can be centrally managed through the backend.

Four-Layer Integrated Security Architecture

End-to-End Key Security from Storage to Computation

By combining white-box cryptography with hardware security capabilities, it mitigates key exposure risks across memory, code and device environments.

Conventional solution Xuanshu

Core algorithm structure

Standard black-box algorithm

Key runtime state

Keys run in plaintext in memory
Keys are exposed during computation

Attack resistance

Only defends against black-box attacks; fails immediately once the device is rooted

Reverse-engineering difficulty

Crackable by skilled hackers in 1–3 days

Device compatibility

Requires TEE hardware
Low-end devices receive limited protection

Six-Tier Key Protection Framework

From hardware-secured key storage to business key protection, it isolates critical risks at every layer, ensuring keys at each level remain within the trusted boundary.

Hardware Secure Storage Key (Optional)

Prevent key extraction at the physical layer

Natively generated by mobile device chips (Android TEE / iOS Secure Enclave), acting as the trust foundation for all security mechanisms.

Security Across Every Platform

Xuanshu supports applications across mobile, PC, and IoT platforms, including Android, iOS, HarmonyOS NEXT, Windows, macOS, Linux, and RTOS, delivering consistent application security across devices and business scenarios.

Android

iOS

HarmonyOS NEXT

RTOS

Windows

macOS

Linux

Compliance with International & Chinese National Cryptographic Standards

It covers Chinese national cryptographic algorithms (SM2 and SM4) as well as mainstream international algorithms (RSA, AES, and general-purpose algorithms based on ECC) to support data protection and secure access across diverse business scenarios.

  • GM/T 0002 – SM4 Block Cipher Algorithm
  • GM/T 0003 – SM2 Elliptic-Curve Public-Key Cryptographic Algorithm
  • GM/T 0009 – SM2 Cryptographic Algorithm Application Specification
  • GM/T 0010 – SM2 Cryptographic Message Syntax Specification
  • GM/T 0015 – Digital Certificate Format Based on SM2
  • GM/T 0028-2014 – Security Requirements for Cryptographic Modules
  • GM/T 0105-2021 – Design Guide for Software-Based Random Number Generators
  • RFC 8017 PKCS #1 – RSA Cryptography Specifications v2.2
  • FIPS PUB 197 – Advanced Encryption Standard (AES)

Tell Us What You’re Building

Whether you’re exploring our capabilities, evaluating a use case, or planning an SDK integration, we’d love to hear from you.

CONTACT US DIRECTLY trusafe@gi-de.com

Elevate Your Product Security

Access Xuanshu development resources and integrate critical security capabilities into your products.

Download the SDK