語言

IdentityCredential.AuthKeysNeedingCertification 屬性

定義

會收到一組需要認證的動態驗證金鑰。

public abstract System.Collections.Generic.ICollection<Java.Security.Cert.X509Certificate> AuthKeysNeedingCertification { [Android.Runtime.Register("getAuthKeysNeedingCertification", "()Ljava/util/Collection;", "GetGetAuthKeysNeedingCertificationHandler", ApiSince=30)] get; }
[<get: Android.Runtime.Register("getAuthKeysNeedingCertification", "()Ljava/util/Collection;", "GetGetAuthKeysNeedingCertificationHandler", ApiSince=30)>]
member this.AuthKeysNeedingCertification : System.Collections.Generic.ICollection<Java.Security.Cert.X509Certificate>

屬性值

一組用於動態認證金鑰且需要發行者認證的 X.509 憑證。 這個值不可能為零值。

屬性

備註

此方法已被取代。 改用 java.security.KeyStore 搭配 Android 硬體支援的 keystore。

會收到一組需要認證的動態驗證金鑰。

當認證的動態驗證金鑰數量不足時,無論是因為金鑰數量增加、一把或多把金鑰已達使用量,或金鑰接近到期日,此方法會產生替換金鑰與憑證並退回給發行者認證。 發行憑證及相關的靜態認證資料必須透過 storeStaticAuthenticationData(X509Certificate,byte[])回傳給身份憑證。 每個認證金鑰的私密部分從未離開過安全的硬體。

每張 X.509 憑證皆由 CredentialKey 簽署。 CredentialKey 的憑證鏈可透過 getCredentialKeyCertificateChain() 方法取得。

若實作為功能版本 202101 或更新,每個 X.509 憑證包含一個 X.509 擴充檔名,OID 為 1.3.6.1.4.1.1129.2.1.26,該擴充包含一個以 DER 編碼的八位元組字串,包含包含 CBOR 位元組,並包含以下 CDDL:

ProofOfBinding = [
  "ProofOfBinding",
  bstr,              // Contains SHA-256(ProofOfProvisioning)
]

此 CBOR 使發行者能確定其回傳發行者簽署資料的憑證的確切狀態。

詳見PackageManager.FEATURE_IDENTITY_CREDENTIAL_HARDWARE已知的功能版本。

Android 參考資料。android.security.identity.IdentityCredential.getAuthKeysNeedingCertification

本頁部分內容為基於 Open Source Project 所創建與分享的作品,並依授權條款所描述的使用進行修改。

適用於