There is a question that comes up constantly in Android security engineering, usually phrased something along the lines of: “how do I prove to my server that this AES key is hardware-backed?” The common answers to this question are often wrong in that they make you think you have a guarantee that you do not have.
The short answer is: you cannot prove an AES key...