Android AES Encryption Utility App

via Freelancer ·

Budget / Salary$30–250
TypeFreelance project
LocationRemote
Posted2 hours ago
I am looking for an experienced Android developer with strong cryptography and application-security knowledge to develop a professional Android app based on my existing web-based AES encryption tool (reference).

The app is primarily a text encryption/decryption utility using AES-256-GCM and PBKDF2-HMAC-SHA-256. The goal is to create a polished, reliable and trustworthy Android application with strong emphasis on cryptographic correctness, interoperability and user experience.

**Core Cryptography**

The app must support:

- AES-256-GCM encryption and decryption
- PBKDF2-HMAC-SHA-256 password-based key derivation
- Configurable PBKDF2 iteration count
- Secure random salt generation
- Secure random IV/nonce generation
- GCM authentication tag
- Optional AAD (Additional Authenticated Data)
- Raw AES-256 key mode
- Password-based encryption mode
- Base64 encoding/decoding
- Proper authentication and tamper detection
- Secure handling of passwords, keys and sensitive data

All cryptographic operations must use well-established Android/JVM cryptographic APIs or reputable cryptographic libraries. No custom cryptographic algorithms or insecure implementations.

**Universal Cryptographic Compatibility**

The app must use standard, universally interoperable AES-256-GCM and PBKDF2 implementations. It must not introduce proprietary encryption schemes, custom cryptographic behavior, or application-specific cryptographic formats that prevent interoperability with other standards-compliant tools and libraries.

**Features**

The app should include:

- Text encryption and decryption
- Password-based encryption
- Raw AES-256 key encryption/decryption
- AAD support
- Separate Salt / IV / Ciphertext / Tag / AAD fields
- Concatenated encrypted-data format
- Structured JSON format
- JSON import/export
- Base64 support
- Copy/paste functionality
- QR code generation and scanning
- Large text support
- Clear/reset functionality
- Password visibility controls
- Appropriate validation and error messages
- Clean presentation of cryptographic parameters

The exact functionality and behavior will be demonstrated through my existing web application.

**Internet Connectivity & Privacy**

Unlike a completely offline application, I am willing to allow limited internet connectivity where it provides genuine user or operational value.

The app may use internet access for:

- Crash and ANR reporting
- Anonymous/aggregated traffic and usage analysis
- Application update checks
- Mandatory update notifications
- Other essential UX or operational functionality, subject to approval

However, user-entered plaintext, passwords, encryption keys, ciphertext or AAD must never be transmitted to any server or third party.

No cloud storage or account system is required.

Analytics and crash reporting must be implemented in a privacy-conscious manner and must not collect or transmit sensitive cryptographic content.

**Mandatory Application Updates**

The app must support a mandatory update mechanism.

When a critical/new version is released, the application should be able to notify the user and, where configured, prevent continued use of the application until the required update is installed.

The developer should implement this securely and reliably, with appropriate handling for:

- Update availability
- Minimum supported app version
- Critical security updates
- Update prompts
- Failed/unavailable update scenarios

The exact update mechanism will be discussed during development.

**Monetization**

At launch, all app functionality will be completely free.

There will be:

- No Pro version
- No subscriptions
- No paid features
- No advertisements

The app may include a “Buy Me a Coffee / Support the Developer” option where users can voluntarily support the project using cryptocurrencies.

The donation functionality should be simple and non-intrusive.

**User Interface**

The application should have a:

- Modern
- Minimal
- Professional
- Security-focused
- Intuitive

interface.

The primary workflow should be extremely simple:

Enter text → Encrypt → Copy/Export

and:

Paste encrypted data → Decrypt → Read plaintext

Advanced cryptographic options should be available without making the basic workflow unnecessarily complicated.

**Security Requirements**

The developer must:

- Never log passwords, plaintext, keys or sensitive ciphertext
- Never transmit cryptographic data
- Avoid unnecessary permissions
- Minimize third-party dependencies
- Follow Android security best practices
- Properly handle sensitive data in memory where practical
- Prevent accidental data exposure through logs, intents and other Android components
- Use secure random number generation
- Use authenticated encryption correctly
- Properly handle GCM authentication failures
- Avoid implementing cryptographic primitives manually
- Avoid screenshots and screen recording all the time the app opens.

**Performance**

The application must remain responsive during:

- PBKDF2 key derivation
- AES encryption/decryption
- Large text processing
- QR generation/scanning

Cryptographic operations should not block the main UI thread.

**Testing & Interoperability**

The developer must thoroughly test:

- Correct encryption/decryption
- Wrong passwords
- Modified ciphertext
- Modified authentication tags
- Modified IVs
- Modified salts
- Modified AAD
- Invalid JSON/Base64
- Unicode and multilingual text
- Emojis and special characters
- Large inputs
- Android lifecycle/backgrounding
- Different Android versions

Most importantly, encrypted output must be tested against independent AES-256-GCM/PBKDF2 implementations and libraries to verify genuine interoperability.

**Analytics & Crash Reporting**

If analytics/crash-reporting services are used:

- They must not collect plaintext, passwords, keys or ciphertext.
- Sensitive application data must be excluded from logs and reports.
- The developer must clearly document what information is collected.
- Third-party SDKs should be kept to the minimum necessary.

**Deliverables**

- Complete Android Studio project
- Full source code
- Production-ready APK/AAB
- Play Store-ready application
- Complete implementation of all agreed features
- Analytics/crash reporting integration
- Mandatory update mechanism
- Crypto interoperability test suite
- Testing and bug fixing
- Basic technical/security documentation

**Developer Requirements**

Please apply only if you have strong experience in:

- Native Android development
- Kotlin/Java
- Android Studio
- Android application security
- AES-GCM
- PBKDF2
- Secure key handling
- Android cryptographic APIs
- Google Play deployment
- Crash/analytics integration

Cryptography/security experience is strongly preferred.

If you have previously developed encryption, password-management, wallet, authentication or privacy-focused applications, please provide examples.

**Proposal Requirements**

Please include:

1. Your Android development experience
2. Your cryptography/security experience
3. Relevant applications you have developed
4. Which APIs/libraries you would use for AES-256-GCM and PBKDF2 and why
5. How you would ensure cryptographic interoperability
6. Which crash-reporting/analytics approach you recommend
7. How you would prevent sensitive cryptographic data from being collected
8. Your approach to mandatory application updates
9. Estimated timeline
10. Fixed-price only

Please do not submit a generic proposal. I am looking for a developer who has carefully read these requirements and can demonstrate genuine understanding of Android security and cryptography.

Security, cryptographic correctness, interoperability and reliability are more important than simply delivering the application quickly.

If you have read the complete job description, please begin your proposal with:

“AES-256-GCM - Security & Interoperability First”
java android cryptography kotlin android studio
Apply on Freelancer →

Project sourced from Freelancer.com. Applications happen directly on the original platform — we never collect your data.