SELinux is set up to default-deny, which means that every single access for| Android Open Source Project
The Android Keystore system lets you store cryptographic keys in a container| Android Developers