DeviceKey is the new two-factor authentication (2FA) method linked to your device, designed to replace temporary codes with the unlock method you already use every day on your phone.
At the time of activation, the app generates a pair of cryptographic keys on your device and saves them in the phone's secure enclave (the Secure Enclave on iPhone, the Keystore on Android). It is the same armored "compartment" used to store Face ID, Touch ID or fingerprint data: an area isolated from the rest of the operating system, specifically designed to store cryptographic keys.
The private key never leaves your device: it is not saved on Young Platform's servers, it is not exportable, it cannot be read even by you, and it is not copied into the phone's cloud backups. It remains permanently linked to that specific smartphone.
When you need to log in or authorise a transaction (a withdrawal, a password change, adding a withdrawal address...), Young Platform sends a signature request to your device. To complete it, you use the same screen unlock system — fingerprint, Face ID or PIN — that you use to unlock your phone. If the unlock is successful, the device signs the request with the private key stored in the enclave and sends it to Young Platform, which verifies it with the corresponding public key. No codes to copy, no dependence on the cellular network or a third-party app.
In practice, it works like your home banking: you approve transactions directly from the Young Platform app, using your phone's unlock, instead of opening an Authenticator app or waiting for an SMS.
Why it's more secure
- The private key cannot be intercepted, copied or stolen remotely: using it requires physical access to the unlocked device.
- There are no codes to read and type, so no OTP phishing or SIM swapping.
- Each request is linked to a specific transaction: you cannot "blindly" sign a transaction other than the one you are authorising.
Need help? Write to our support team: open a ticket at the link support.youngplatform.com/hc/en-gb/requests/new