Skip to content
#federated learning Review Open access

On-Device Privacy and Zero-Knowledge Storage in Mobile Applications: A Review with Attention to Cross-Platform React Native Development

Sep 2026 · Journal of Engineering Research and Reports · 0 citations
Advanced Malware Detection Techniques

Abstract

Mobile applications hold the most intimate data that most people generate—messages, health signals, finances, locations, and journals—and the architectural question of where such data live in plaintext has become the defining privacy decision of app design. On-device privacy names one pole of the answer: data is processed, stored, and protected where it originates, and services are designed so that servers hold ciphertext they cannot read, an architecture popularly called zero-knowledge storage. This review synthesizes the research literature relevant to building such applications, with specific attention to the cross-platform reality in which much of the mobile ecosystem, prominently React Native applications, is actually built. It first fixes terminology, distinguishing the cryptographic meaning of zero knowledge from the architectural marketing usage, and organizes the threat models—curious servers, device compromise, network adversaries, and legal compulsion—against which designs are meaningfully compared. It then reviews the platform security foundations, hardware-backed keystores, trusted execution, biometric gating, and their documented limits; encrypted local storage, from key derivation through database encryption to searchable and oblivious techniques and their leakage trade-offs; end-to-end encrypted synchronization and the protocol lineage that made forward secrecy deployable; and on-device privacy-preserving computation, including local inference, differential privacy, and federated learning, with the attack literature that bounds their guarantees. The cross-platform layer receives dedicated treatment: the JavaScript runtime, bridge architecture, dependency supply chain, and the misuse findings of the mobile security measurement literature as they bear on React Native designs. The review closes with the recurring gaps—usable key recovery, metadata protection, and verification of zero-knowledge claims—and identifies directions for research and practice.

Read PDF

Similar papers

#machine learning Review Open access Oct 2014

Software development in startup companies: A systematic mapping study

The results indicate that software engineering work practices are chosen opportunistically, adapted and configured to provide value under the constrains imposed by the startup context.

Nicolò Paternoster, Carmine Giardino, M. Unterkalmsteiner et al. · 394 citations · ⚡54
#machine learning Review Open access Jun 2014

Why Early-Stage Software Startups Fail: A Behavioral Framework

This state-of-practice investigation was performed using a literature review followed by a multiple-case study approach and presents how inconsistency between managerial strategies and execution can lead to failure by means of a behavioral framework.

Carmine Giardino, Xiaofeng Wang, P. Abrahamsson · 175 citations · ⚡19
#machine learning Review Open access Oct 2016

“Failures” to be celebrated: an analysis of major pivots of software startups

This study conducts a case survey study based on the secondary data of the major pivots happened in 49 software startups, and demonstrates that customer need pivot is the most common among all pivot types.

Sohaib Shahid Bajwa, Xiaofeng Wang, Anh Nguyen-Duc et al. · 127 citations · ⚡15
#machine learning Review Open access May 2016

Key Challenges in Software Startups Across Life Cycle Stages

It is found that what perceived as biggest challenges by software startups do vary across different life cycle stages, even though its significance decreases when the learning focuses of the startups move from problem to solution and their products mature.

Xiaofeng Wang, Henry Edison, Sohaib Shahid Bajwa et al. · 62 citations · ⚡6

Related blog posts

Microsoft Research Blog Sep 30, 2026

Forecasting space weather risks on power grids

Extreme space-weather events can damage power systems on Earth and degrade GPS accuracy and satellite operations. A new machine learning system can predict where damage is likely to occur 30-60 minutes before a storm arrives. The post Forecasting space weather risks on power grids appeared first on Microsoft Research.

We use cookies to run the site and, with your consent, for analytics and to show ads. See our Cookie Policy.