We are using aws client for our connection layer. aws-sdk is using "BKS" Keystore and writing it file into the file system.
Below is the class of sdk which is managing Keystore in file system.
We are looking for one more layer of protection which will help us in protecting our Keystore on rooted devices. So we are looking for that solution which will help us in protecting our Private keys and client certs which reside in Keystore.