European Consortium Wants Open-Source Alternative to Google Play Integrity

European Tech Firms Launch Open-Source UnifiedAttestation to Replace Google Play Integrity for De-Googled Android Devices
Photo: slashdot.org

European Tech Firms Launch Open-Source UnifiedAttestation to Replace Google Play Integrity for De-Googled Android Devices

A newly formed European industry consortium, spearheaded by German company Volla Systeme GmbH, is developing an open-source alternative to Google’s proprietary Play Integrity API. This API currently verifies device security and integrity, determining whether sensitive apps—such as those for banking, digital wallets, identity verification, and government services—can run on Android smartphones. The system is tied exclusively to Google’s ecosystem and services, effectively excluding custom ROMs and Google-free operating systems like /e/OS from Murena, Iodé from France, Apostrophy (Dot) from Switzerland, and others based on the Android Open Source Project (AOSP).

The consortium criticizes this setup as creating structural dependency on Google, raising concerns over data sovereignty and a ‘security paradox’ where trustworthiness is assessed by the very entity users seek to avoid. To address these issues, the group is creating ‘UnifiedAttestation,’ a modular, decentralized solution with three core elements: an OS-level service that apps can query to confirm security compliance, a decentralized validation mechanism that avoids single-point central authority reliance, and an open test suite for publicly evaluating and certifying OS-device combinations.

Participants include Murena, Iodé, Apostrophy, and Volla, with expressed interest from additional European and Asian manufacturers, the UBports Foundation, and Scandinavian government app developers as early adopters. The initiative aims to foster transparent, verifiable trust through mutual or competitive checks among companies, ultimately promoting greater digital sovereignty in Europe by reducing reliance on a single U.S. corporation’s control over mobile security standards. This effort builds on prior discussions about challenges in using de-Googled devices for secure payments and NFC functions.

Leave a Reply

Your email address will not be published. Required fields are marked *