19 |
20 |
--------------------------------------------------------------------------------
/app/proguard-rules.pro:
--------------------------------------------------------------------------------
1 | # Add project specific ProGuard rules here.
2 | # You can control the set of applied configuration files using the
3 | # proguardFiles setting in build.gradle.
4 | #
5 | # For more details, see
6 | # http://developer.android.com/guide/developing/tools/proguard.html
7 |
8 | # If your project uses WebView with JS, uncomment the following
9 | # and specify the fully qualified class name to the JavaScript interface
10 | # class:
11 | #-keepclassmembers class fqcn.of.javascript.interface.for.webview {
12 | # public *;
13 | #}
14 |
15 | # Uncomment this to preserve the line number information for
16 | # debugging stack traces.
17 | #-keepattributes SourceFile,LineNumberTable
18 |
19 | # If you keep the line number information, uncomment this to
20 | # hide the original source file name.
21 | #-renamesourcefileattribute SourceFile
22 |
--------------------------------------------------------------------------------
/app/src/main/res/drawable/ic_menu_share.xml:
--------------------------------------------------------------------------------
1 |
8 |
11 |
12 |
--------------------------------------------------------------------------------
/app/src/androidTest/java/com/example/kieun/biometricprompt/ExampleInstrumentedTest.java:
--------------------------------------------------------------------------------
1 | package com.example.kieun.biometricprompt;
2 |
3 | import android.content.Context;
4 |
5 | import androidx.test.InstrumentationRegistry;
6 | import androidx.test.runner.AndroidJUnit4;
7 |
8 | import org.junit.Test;
9 | import org.junit.runner.RunWith;
10 |
11 | import static org.junit.Assert.*;
12 |
13 | /**
14 | * Instrumented test, which will execute on an Android device.
15 | *
16 | * @see Testing documentation
17 | */
18 | @RunWith(AndroidJUnit4.class)
19 | public class ExampleInstrumentedTest {
20 | @Test
21 | public void useAppContext() {
22 | // Context of the app under test.
23 | Context appContext = InstrumentationRegistry.getTargetContext();
24 |
25 | assertEquals("com.example.kieun.biometricprompt", appContext.getPackageName());
26 | }
27 | }
28 |
--------------------------------------------------------------------------------
/app/src/main/res/layout/content_main.xml:
--------------------------------------------------------------------------------
1 |
2 |
10 |
11 |
19 |
20 |
--------------------------------------------------------------------------------
/README.md:
--------------------------------------------------------------------------------
1 | # Android Biometric Prompt Sample
2 | A sample app for demonstrating biometric prompt provided from Android P (API 28)
3 |
4 | Introduction
5 | ------------
6 | This sample demonstrates how you can use system provided biometric authentication.
7 |
8 | FingerprintManager is now deprecated and the apps need to implement the BiometricPrompt instead.
9 |
10 | This sample app implements challenge-response fashion of authentication for the online user authentication like FIDO.
11 |
12 | You can refer following reference documents for getting more detailed information [1].
13 |
14 | [1]: https://developer.android.com/reference/android/hardware/biometrics/package-summary
15 |
16 | Pre-requisites and limitation
17 | -----------------------------
18 | - Use Android Studio 3.2 to build this app (Android P)
19 | - Lack of method for checking biometric enrollment (issue reported)
20 | - Lack of method for checking face and iris feature on the device
21 |
22 | Screenshots
23 | -----------
24 |
--------------------------------------------------------------------------------
/app/src/main/res/layout/activity_main.xml:
--------------------------------------------------------------------------------
1 |
2 |
10 |
11 |
15 |
16 |
24 |
25 |
26 |
--------------------------------------------------------------------------------
/app/src/main/AndroidManifest.xml:
--------------------------------------------------------------------------------
1 |
2 |
4 |
5 |
6 |
7 |
15 |
19 |
20 |
21 |
22 |
23 |
24 |
25 |
26 |
27 |
--------------------------------------------------------------------------------
/app/build.gradle:
--------------------------------------------------------------------------------
1 | apply plugin: 'com.android.application'
2 |
3 | android {
4 | compileSdkVersion 30
5 | defaultConfig {
6 | applicationId "com.example.kieun.biometricprompt"
7 | minSdkVersion 23
8 | targetSdkVersion 29
9 | versionCode 2
10 | versionName "1.1"
11 | testInstrumentationRunner "androidx.test.runner.AndroidJUnitRunner"
12 | }
13 | buildTypes {
14 | release {
15 | minifyEnabled false
16 | proguardFiles getDefaultProguardFile('proguard-android.txt'), 'proguard-rules.pro'
17 | }
18 | }
19 | }
20 |
21 | dependencies {
22 | implementation fileTree(dir: 'libs', include: ['*.jar'])
23 | implementation 'androidx.appcompat:appcompat:1.0.2'
24 | implementation 'androidx.legacy:legacy-support-v4:1.0.0'
25 | implementation 'com.google.android.material:material:1.0.0'
26 | implementation 'androidx.constraintlayout:constraintlayout:1.1.3'
27 | implementation 'androidx.biometric:biometric:1.1.0-beta01'
28 | testImplementation 'junit:junit:4.12'
29 | androidTestImplementation 'androidx.test:runner:1.3.0-alpha01'
30 | androidTestImplementation 'androidx.test.espresso:espresso-core:3.2.0'
31 | }
32 |
--------------------------------------------------------------------------------
/app/src/main/res/layout/app_bar_main.xml:
--------------------------------------------------------------------------------
1 |
2 |
8 |
9 |
13 |
14 |
20 |
21 |
22 |
23 |
24 |
25 |
32 |
33 |
--------------------------------------------------------------------------------
/app/src/main/res/layout/nav_header_main.xml:
--------------------------------------------------------------------------------
1 |
2 |
14 |
15 |
22 |
23 |
29 |
30 |
35 |
36 |
37 |
--------------------------------------------------------------------------------
/app/src/main/res/drawable-v24/ic_launcher_foreground.xml:
--------------------------------------------------------------------------------
1 |
7 |
12 |
13 |
19 |
22 |
25 |
26 |
27 |
28 |
34 |
35 |
--------------------------------------------------------------------------------
/gradlew.bat:
--------------------------------------------------------------------------------
1 | @if "%DEBUG%" == "" @echo off
2 | @rem ##########################################################################
3 | @rem
4 | @rem Gradle startup script for Windows
5 | @rem
6 | @rem ##########################################################################
7 |
8 | @rem Set local scope for the variables with windows NT shell
9 | if "%OS%"=="Windows_NT" setlocal
10 |
11 | set DIRNAME=%~dp0
12 | if "%DIRNAME%" == "" set DIRNAME=.
13 | set APP_BASE_NAME=%~n0
14 | set APP_HOME=%DIRNAME%
15 |
16 | @rem Add default JVM options here. You can also use JAVA_OPTS and GRADLE_OPTS to pass JVM options to this script.
17 | set DEFAULT_JVM_OPTS=
18 |
19 | @rem Find java.exe
20 | if defined JAVA_HOME goto findJavaFromJavaHome
21 |
22 | set JAVA_EXE=java.exe
23 | %JAVA_EXE% -version >NUL 2>&1
24 | if "%ERRORLEVEL%" == "0" goto init
25 |
26 | echo.
27 | echo ERROR: JAVA_HOME is not set and no 'java' command could be found in your PATH.
28 | echo.
29 | echo Please set the JAVA_HOME variable in your environment to match the
30 | echo location of your Java installation.
31 |
32 | goto fail
33 |
34 | :findJavaFromJavaHome
35 | set JAVA_HOME=%JAVA_HOME:"=%
36 | set JAVA_EXE=%JAVA_HOME%/bin/java.exe
37 |
38 | if exist "%JAVA_EXE%" goto init
39 |
40 | echo.
41 | echo ERROR: JAVA_HOME is set to an invalid directory: %JAVA_HOME%
42 | echo.
43 | echo Please set the JAVA_HOME variable in your environment to match the
44 | echo location of your Java installation.
45 |
46 | goto fail
47 |
48 | :init
49 | @rem Get command-line arguments, handling Windows variants
50 |
51 | if not "%OS%" == "Windows_NT" goto win9xME_args
52 |
53 | :win9xME_args
54 | @rem Slurp the command line arguments.
55 | set CMD_LINE_ARGS=
56 | set _SKIP=2
57 |
58 | :win9xME_args_slurp
59 | if "x%~1" == "x" goto execute
60 |
61 | set CMD_LINE_ARGS=%*
62 |
63 | :execute
64 | @rem Setup the command line
65 |
66 | set CLASSPATH=%APP_HOME%\gradle\wrapper\gradle-wrapper.jar
67 |
68 | @rem Execute Gradle
69 | "%JAVA_EXE%" %DEFAULT_JVM_OPTS% %JAVA_OPTS% %GRADLE_OPTS% "-Dorg.gradle.appname=%APP_BASE_NAME%" -classpath "%CLASSPATH%" org.gradle.wrapper.GradleWrapperMain %CMD_LINE_ARGS%
70 |
71 | :end
72 | @rem End local scope for the variables with windows NT shell
73 | if "%ERRORLEVEL%"=="0" goto mainEnd
74 |
75 | :fail
76 | rem Set variable GRADLE_EXIT_CONSOLE if you need the _script_ return code instead of
77 | rem the _cmd.exe /c_ return code!
78 | if not "" == "%GRADLE_EXIT_CONSOLE%" exit 1
79 | exit /b 1
80 |
81 | :mainEnd
82 | if "%OS%"=="Windows_NT" endlocal
83 |
84 | :omega
85 |
--------------------------------------------------------------------------------
/.idea/codeStyles/Project.xml:
--------------------------------------------------------------------------------
1 |
2 |
3 |
4 |
5 |
6 |
7 |
8 |
9 |
10 | xmlns:android
11 |
12 | ^$
13 |
14 |
15 |
16 |
17 |
18 |
19 |
20 |
21 | xmlns:.*
22 |
23 | ^$
24 |
25 |
26 | BY_NAME
27 |
28 |
29 |
30 |
31 |
32 |
33 | .*:id
34 |
35 | http://schemas.android.com/apk/res/android
36 |
37 |
38 |
39 |
40 |
41 |
42 |
43 |
44 | .*:name
45 |
46 | http://schemas.android.com/apk/res/android
47 |
48 |
49 |
50 |
51 |
52 |
53 |
54 |
55 | name
56 |
57 | ^$
58 |
59 |
60 |
61 |
62 |
63 |
64 |
65 |
66 | style
67 |
68 | ^$
69 |
70 |
71 |
72 |
73 |
74 |
75 |
76 |
77 | .*
78 |
79 | ^$
80 |
81 |
82 | BY_NAME
83 |
84 |
85 |
86 |
87 |
88 |
89 | .*
90 |
91 | http://schemas.android.com/apk/res/android
92 |
93 |
94 | ANDROID_ATTRIBUTE_ORDER
95 |
96 |
97 |
98 |
99 |
100 |
101 | .*
102 |
103 | .*
104 |
105 |
106 | BY_NAME
107 |
108 |
109 |
110 |
111 |
112 |
113 |
--------------------------------------------------------------------------------
/gradlew:
--------------------------------------------------------------------------------
1 | #!/usr/bin/env sh
2 |
3 | ##############################################################################
4 | ##
5 | ## Gradle start up script for UN*X
6 | ##
7 | ##############################################################################
8 |
9 | # Attempt to set APP_HOME
10 | # Resolve links: $0 may be a link
11 | PRG="$0"
12 | # Need this for relative symlinks.
13 | while [ -h "$PRG" ] ; do
14 | ls=`ls -ld "$PRG"`
15 | link=`expr "$ls" : '.*-> \(.*\)$'`
16 | if expr "$link" : '/.*' > /dev/null; then
17 | PRG="$link"
18 | else
19 | PRG=`dirname "$PRG"`"/$link"
20 | fi
21 | done
22 | SAVED="`pwd`"
23 | cd "`dirname \"$PRG\"`/" >/dev/null
24 | APP_HOME="`pwd -P`"
25 | cd "$SAVED" >/dev/null
26 |
27 | APP_NAME="Gradle"
28 | APP_BASE_NAME=`basename "$0"`
29 |
30 | # Add default JVM options here. You can also use JAVA_OPTS and GRADLE_OPTS to pass JVM options to this script.
31 | DEFAULT_JVM_OPTS=""
32 |
33 | # Use the maximum available, or set MAX_FD != -1 to use that value.
34 | MAX_FD="maximum"
35 |
36 | warn () {
37 | echo "$*"
38 | }
39 |
40 | die () {
41 | echo
42 | echo "$*"
43 | echo
44 | exit 1
45 | }
46 |
47 | # OS specific support (must be 'true' or 'false').
48 | cygwin=false
49 | msys=false
50 | darwin=false
51 | nonstop=false
52 | case "`uname`" in
53 | CYGWIN* )
54 | cygwin=true
55 | ;;
56 | Darwin* )
57 | darwin=true
58 | ;;
59 | MINGW* )
60 | msys=true
61 | ;;
62 | NONSTOP* )
63 | nonstop=true
64 | ;;
65 | esac
66 |
67 | CLASSPATH=$APP_HOME/gradle/wrapper/gradle-wrapper.jar
68 |
69 | # Determine the Java command to use to start the JVM.
70 | if [ -n "$JAVA_HOME" ] ; then
71 | if [ -x "$JAVA_HOME/jre/sh/java" ] ; then
72 | # IBM's JDK on AIX uses strange locations for the executables
73 | JAVACMD="$JAVA_HOME/jre/sh/java"
74 | else
75 | JAVACMD="$JAVA_HOME/bin/java"
76 | fi
77 | if [ ! -x "$JAVACMD" ] ; then
78 | die "ERROR: JAVA_HOME is set to an invalid directory: $JAVA_HOME
79 |
80 | Please set the JAVA_HOME variable in your environment to match the
81 | location of your Java installation."
82 | fi
83 | else
84 | JAVACMD="java"
85 | which java >/dev/null 2>&1 || die "ERROR: JAVA_HOME is not set and no 'java' command could be found in your PATH.
86 |
87 | Please set the JAVA_HOME variable in your environment to match the
88 | location of your Java installation."
89 | fi
90 |
91 | # Increase the maximum file descriptors if we can.
92 | if [ "$cygwin" = "false" -a "$darwin" = "false" -a "$nonstop" = "false" ] ; then
93 | MAX_FD_LIMIT=`ulimit -H -n`
94 | if [ $? -eq 0 ] ; then
95 | if [ "$MAX_FD" = "maximum" -o "$MAX_FD" = "max" ] ; then
96 | MAX_FD="$MAX_FD_LIMIT"
97 | fi
98 | ulimit -n $MAX_FD
99 | if [ $? -ne 0 ] ; then
100 | warn "Could not set maximum file descriptor limit: $MAX_FD"
101 | fi
102 | else
103 | warn "Could not query maximum file descriptor limit: $MAX_FD_LIMIT"
104 | fi
105 | fi
106 |
107 | # For Darwin, add options to specify how the application appears in the dock
108 | if $darwin; then
109 | GRADLE_OPTS="$GRADLE_OPTS \"-Xdock:name=$APP_NAME\" \"-Xdock:icon=$APP_HOME/media/gradle.icns\""
110 | fi
111 |
112 | # For Cygwin, switch paths to Windows format before running java
113 | if $cygwin ; then
114 | APP_HOME=`cygpath --path --mixed "$APP_HOME"`
115 | CLASSPATH=`cygpath --path --mixed "$CLASSPATH"`
116 | JAVACMD=`cygpath --unix "$JAVACMD"`
117 |
118 | # We build the pattern for arguments to be converted via cygpath
119 | ROOTDIRSRAW=`find -L / -maxdepth 1 -mindepth 1 -type d 2>/dev/null`
120 | SEP=""
121 | for dir in $ROOTDIRSRAW ; do
122 | ROOTDIRS="$ROOTDIRS$SEP$dir"
123 | SEP="|"
124 | done
125 | OURCYGPATTERN="(^($ROOTDIRS))"
126 | # Add a user-defined pattern to the cygpath arguments
127 | if [ "$GRADLE_CYGPATTERN" != "" ] ; then
128 | OURCYGPATTERN="$OURCYGPATTERN|($GRADLE_CYGPATTERN)"
129 | fi
130 | # Now convert the arguments - kludge to limit ourselves to /bin/sh
131 | i=0
132 | for arg in "$@" ; do
133 | CHECK=`echo "$arg"|egrep -c "$OURCYGPATTERN" -`
134 | CHECK2=`echo "$arg"|egrep -c "^-"` ### Determine if an option
135 |
136 | if [ $CHECK -ne 0 ] && [ $CHECK2 -eq 0 ] ; then ### Added a condition
137 | eval `echo args$i`=`cygpath --path --ignore --mixed "$arg"`
138 | else
139 | eval `echo args$i`="\"$arg\""
140 | fi
141 | i=$((i+1))
142 | done
143 | case $i in
144 | (0) set -- ;;
145 | (1) set -- "$args0" ;;
146 | (2) set -- "$args0" "$args1" ;;
147 | (3) set -- "$args0" "$args1" "$args2" ;;
148 | (4) set -- "$args0" "$args1" "$args2" "$args3" ;;
149 | (5) set -- "$args0" "$args1" "$args2" "$args3" "$args4" ;;
150 | (6) set -- "$args0" "$args1" "$args2" "$args3" "$args4" "$args5" ;;
151 | (7) set -- "$args0" "$args1" "$args2" "$args3" "$args4" "$args5" "$args6" ;;
152 | (8) set -- "$args0" "$args1" "$args2" "$args3" "$args4" "$args5" "$args6" "$args7" ;;
153 | (9) set -- "$args0" "$args1" "$args2" "$args3" "$args4" "$args5" "$args6" "$args7" "$args8" ;;
154 | esac
155 | fi
156 |
157 | # Escape application args
158 | save () {
159 | for i do printf %s\\n "$i" | sed "s/'/'\\\\''/g;1s/^/'/;\$s/\$/' \\\\/" ; done
160 | echo " "
161 | }
162 | APP_ARGS=$(save "$@")
163 |
164 | # Collect all arguments for the java command, following the shell quoting and substitution rules
165 | eval set -- $DEFAULT_JVM_OPTS $JAVA_OPTS $GRADLE_OPTS "\"-Dorg.gradle.appname=$APP_BASE_NAME\"" -classpath "\"$CLASSPATH\"" org.gradle.wrapper.GradleWrapperMain "$APP_ARGS"
166 |
167 | # by default we should be in the correct project dir, but when run from Finder on Mac, the cwd is wrong
168 | if [ "$(uname)" = "Darwin" ] && [ "$HOME" = "$PWD" ]; then
169 | cd "$(dirname "$0")"
170 | fi
171 |
172 | exec "$JAVACMD" "$@"
173 |
--------------------------------------------------------------------------------
/app/src/main/res/drawable/ic_launcher_background.xml:
--------------------------------------------------------------------------------
1 |
2 |
7 |
10 |
15 |
20 |
25 |
30 |
35 |
40 |
45 |
50 |
55 |
60 |
65 |
70 |
75 |
80 |
85 |
90 |
95 |
100 |
105 |
110 |
115 |
120 |
125 |
130 |
135 |
140 |
145 |
150 |
155 |
160 |
165 |
170 |
171 |
--------------------------------------------------------------------------------
/LICENSE:
--------------------------------------------------------------------------------
1 | Apache License
2 | Version 2.0, January 2004
3 | http://www.apache.org/licenses/
4 |
5 | TERMS AND CONDITIONS FOR USE, REPRODUCTION, AND DISTRIBUTION
6 |
7 | 1. Definitions.
8 |
9 | "License" shall mean the terms and conditions for use, reproduction,
10 | and distribution as defined by Sections 1 through 9 of this document.
11 |
12 | "Licensor" shall mean the copyright owner or entity authorized by
13 | the copyright owner that is granting the License.
14 |
15 | "Legal Entity" shall mean the union of the acting entity and all
16 | other entities that control, are controlled by, or are under common
17 | control with that entity. For the purposes of this definition,
18 | "control" means (i) the power, direct or indirect, to cause the
19 | direction or management of such entity, whether by contract or
20 | otherwise, or (ii) ownership of fifty percent (50%) or more of the
21 | outstanding shares, or (iii) beneficial ownership of such entity.
22 |
23 | "You" (or "Your") shall mean an individual or Legal Entity
24 | exercising permissions granted by this License.
25 |
26 | "Source" form shall mean the preferred form for making modifications,
27 | including but not limited to software source code, documentation
28 | source, and configuration files.
29 |
30 | "Object" form shall mean any form resulting from mechanical
31 | transformation or translation of a Source form, including but
32 | not limited to compiled object code, generated documentation,
33 | and conversions to other media types.
34 |
35 | "Work" shall mean the work of authorship, whether in Source or
36 | Object form, made available under the License, as indicated by a
37 | copyright notice that is included in or attached to the work
38 | (an example is provided in the Appendix below).
39 |
40 | "Derivative Works" shall mean any work, whether in Source or Object
41 | form, that is based on (or derived from) the Work and for which the
42 | editorial revisions, annotations, elaborations, or other modifications
43 | represent, as a whole, an original work of authorship. For the purposes
44 | of this License, Derivative Works shall not include works that remain
45 | separable from, or merely link (or bind by name) to the interfaces of,
46 | the Work and Derivative Works thereof.
47 |
48 | "Contribution" shall mean any work of authorship, including
49 | the original version of the Work and any modifications or additions
50 | to that Work or Derivative Works thereof, that is intentionally
51 | submitted to Licensor for inclusion in the Work by the copyright owner
52 | or by an individual or Legal Entity authorized to submit on behalf of
53 | the copyright owner. For the purposes of this definition, "submitted"
54 | means any form of electronic, verbal, or written communication sent
55 | to the Licensor or its representatives, including but not limited to
56 | communication on electronic mailing lists, source code control systems,
57 | and issue tracking systems that are managed by, or on behalf of, the
58 | Licensor for the purpose of discussing and improving the Work, but
59 | excluding communication that is conspicuously marked or otherwise
60 | designated in writing by the copyright owner as "Not a Contribution."
61 |
62 | "Contributor" shall mean Licensor and any individual or Legal Entity
63 | on behalf of whom a Contribution has been received by Licensor and
64 | subsequently incorporated within the Work.
65 |
66 | 2. Grant of Copyright License. Subject to the terms and conditions of
67 | this License, each Contributor hereby grants to You a perpetual,
68 | worldwide, non-exclusive, no-charge, royalty-free, irrevocable
69 | copyright license to reproduce, prepare Derivative Works of,
70 | publicly display, publicly perform, sublicense, and distribute the
71 | Work and such Derivative Works in Source or Object form.
72 |
73 | 3. Grant of Patent License. Subject to the terms and conditions of
74 | this License, each Contributor hereby grants to You a perpetual,
75 | worldwide, non-exclusive, no-charge, royalty-free, irrevocable
76 | (except as stated in this section) patent license to make, have made,
77 | use, offer to sell, sell, import, and otherwise transfer the Work,
78 | where such license applies only to those patent claims licensable
79 | by such Contributor that are necessarily infringed by their
80 | Contribution(s) alone or by combination of their Contribution(s)
81 | with the Work to which such Contribution(s) was submitted. If You
82 | institute patent litigation against any entity (including a
83 | cross-claim or counterclaim in a lawsuit) alleging that the Work
84 | or a Contribution incorporated within the Work constitutes direct
85 | or contributory patent infringement, then any patent licenses
86 | granted to You under this License for that Work shall terminate
87 | as of the date such litigation is filed.
88 |
89 | 4. Redistribution. You may reproduce and distribute copies of the
90 | Work or Derivative Works thereof in any medium, with or without
91 | modifications, and in Source or Object form, provided that You
92 | meet the following conditions:
93 |
94 | (a) You must give any other recipients of the Work or
95 | Derivative Works a copy of this License; and
96 |
97 | (b) You must cause any modified files to carry prominent notices
98 | stating that You changed the files; and
99 |
100 | (c) You must retain, in the Source form of any Derivative Works
101 | that You distribute, all copyright, patent, trademark, and
102 | attribution notices from the Source form of the Work,
103 | excluding those notices that do not pertain to any part of
104 | the Derivative Works; and
105 |
106 | (d) If the Work includes a "NOTICE" text file as part of its
107 | distribution, then any Derivative Works that You distribute must
108 | include a readable copy of the attribution notices contained
109 | within such NOTICE file, excluding those notices that do not
110 | pertain to any part of the Derivative Works, in at least one
111 | of the following places: within a NOTICE text file distributed
112 | as part of the Derivative Works; within the Source form or
113 | documentation, if provided along with the Derivative Works; or,
114 | within a display generated by the Derivative Works, if and
115 | wherever such third-party notices normally appear. The contents
116 | of the NOTICE file are for informational purposes only and
117 | do not modify the License. You may add Your own attribution
118 | notices within Derivative Works that You distribute, alongside
119 | or as an addendum to the NOTICE text from the Work, provided
120 | that such additional attribution notices cannot be construed
121 | as modifying the License.
122 |
123 | You may add Your own copyright statement to Your modifications and
124 | may provide additional or different license terms and conditions
125 | for use, reproduction, or distribution of Your modifications, or
126 | for any such Derivative Works as a whole, provided Your use,
127 | reproduction, and distribution of the Work otherwise complies with
128 | the conditions stated in this License.
129 |
130 | 5. Submission of Contributions. Unless You explicitly state otherwise,
131 | any Contribution intentionally submitted for inclusion in the Work
132 | by You to the Licensor shall be under the terms and conditions of
133 | this License, without any additional terms or conditions.
134 | Notwithstanding the above, nothing herein shall supersede or modify
135 | the terms of any separate license agreement you may have executed
136 | with Licensor regarding such Contributions.
137 |
138 | 6. Trademarks. This License does not grant permission to use the trade
139 | names, trademarks, service marks, or product names of the Licensor,
140 | except as required for reasonable and customary use in describing the
141 | origin of the Work and reproducing the content of the NOTICE file.
142 |
143 | 7. Disclaimer of Warranty. Unless required by applicable law or
144 | agreed to in writing, Licensor provides the Work (and each
145 | Contributor provides its Contributions) on an "AS IS" BASIS,
146 | WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or
147 | implied, including, without limitation, any warranties or conditions
148 | of TITLE, NON-INFRINGEMENT, MERCHANTABILITY, or FITNESS FOR A
149 | PARTICULAR PURPOSE. You are solely responsible for determining the
150 | appropriateness of using or redistributing the Work and assume any
151 | risks associated with Your exercise of permissions under this License.
152 |
153 | 8. Limitation of Liability. In no event and under no legal theory,
154 | whether in tort (including negligence), contract, or otherwise,
155 | unless required by applicable law (such as deliberate and grossly
156 | negligent acts) or agreed to in writing, shall any Contributor be
157 | liable to You for damages, including any direct, indirect, special,
158 | incidental, or consequential damages of any character arising as a
159 | result of this License or out of the use or inability to use the
160 | Work (including but not limited to damages for loss of goodwill,
161 | work stoppage, computer failure or malfunction, or any and all
162 | other commercial damages or losses), even if such Contributor
163 | has been advised of the possibility of such damages.
164 |
165 | 9. Accepting Warranty or Additional Liability. While redistributing
166 | the Work or Derivative Works thereof, You may choose to offer,
167 | and charge a fee for, acceptance of support, warranty, indemnity,
168 | or other liability obligations and/or rights consistent with this
169 | License. However, in accepting such obligations, You may act only
170 | on Your own behalf and on Your sole responsibility, not on behalf
171 | of any other Contributor, and only if You agree to indemnify,
172 | defend, and hold each Contributor harmless for any liability
173 | incurred by, or claims asserted against, such Contributor by reason
174 | of your accepting any such warranty or additional liability.
175 |
176 | END OF TERMS AND CONDITIONS
177 |
178 | APPENDIX: How to apply the Apache License to your work.
179 |
180 | To apply the Apache License to your work, attach the following
181 | boilerplate notice, with the fields enclosed by brackets "[]"
182 | replaced with your own identifying information. (Don't include
183 | the brackets!) The text should be enclosed in the appropriate
184 | comment syntax for the file format. We also recommend that a
185 | file or class name and description of purpose be included on the
186 | same "printed page" as the copyright notice for easier
187 | identification within third-party archives.
188 |
189 | Copyright [yyyy] [name of copyright owner]
190 |
191 | Licensed under the Apache License, Version 2.0 (the "License");
192 | you may not use this file except in compliance with the License.
193 | You may obtain a copy of the License at
194 |
195 | http://www.apache.org/licenses/LICENSE-2.0
196 |
197 | Unless required by applicable law or agreed to in writing, software
198 | distributed under the License is distributed on an "AS IS" BASIS,
199 | WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
200 | See the License for the specific language governing permissions and
201 | limitations under the License.
202 |
--------------------------------------------------------------------------------
/app/src/main/java/com/example/kieun/biometricprompt/MainActivity.java:
--------------------------------------------------------------------------------
1 | package com.example.kieun.biometricprompt;
2 |
3 | import android.annotation.SuppressLint;
4 | import android.os.Build;
5 | import android.os.Bundle;
6 | import android.os.Handler;
7 | import android.os.Looper;
8 | import android.security.keystore.KeyGenParameterSpec;
9 | import android.security.keystore.KeyProperties;
10 | import android.util.Base64;
11 | import android.util.Log;
12 | import android.view.Menu;
13 | import android.view.MenuItem;
14 | import android.view.View;
15 | import android.widget.Toast;
16 |
17 | import androidx.annotation.NonNull;
18 | import androidx.annotation.Nullable;
19 | import androidx.appcompat.app.ActionBarDrawerToggle;
20 | import androidx.appcompat.app.AppCompatActivity;
21 | import androidx.appcompat.widget.Toolbar;
22 | import androidx.biometric.BiometricManager;
23 | import androidx.biometric.BiometricPrompt;
24 | import androidx.core.view.GravityCompat;
25 | import androidx.drawerlayout.widget.DrawerLayout;
26 |
27 | import com.google.android.material.floatingactionbutton.FloatingActionButton;
28 | import com.google.android.material.navigation.NavigationView;
29 | import com.google.android.material.snackbar.Snackbar;
30 |
31 | import java.security.KeyPair;
32 | import java.security.KeyPairGenerator;
33 | import java.security.KeyStore;
34 | import java.security.PrivateKey;
35 | import java.security.PublicKey;
36 | import java.security.Signature;
37 | import java.security.SignatureException;
38 | import java.security.spec.ECGenParameterSpec;
39 | import java.util.UUID;
40 | import java.util.concurrent.Executor;
41 |
42 | public class MainActivity extends AppCompatActivity
43 | implements NavigationView.OnNavigationItemSelectedListener {
44 | private static final String TAG = MainActivity.class.getName();
45 |
46 | private String mToBeSignedMessage;
47 |
48 | // Unique identifier of a key pair
49 | private static final String KEY_NAME = UUID.randomUUID().toString();
50 |
51 | @Override
52 | protected void onCreate(Bundle savedInstanceState) {
53 | super.onCreate(savedInstanceState);
54 | setContentView(R.layout.activity_main);
55 | Toolbar toolbar = findViewById(R.id.toolbar);
56 | setSupportActionBar(toolbar);
57 |
58 | FloatingActionButton fab = findViewById(R.id.fab);
59 | fab.setOnClickListener(new View.OnClickListener() {
60 | @SuppressLint("WrongConstant")
61 | @Override
62 | public void onClick(View view) {
63 | Snackbar.make(view, "Replace with your own action", Snackbar.LENGTH_LONG)
64 | .setAction("Action", null).show();
65 | }
66 | });
67 |
68 | DrawerLayout drawer = findViewById(R.id.drawer_layout);
69 | ActionBarDrawerToggle toggle = new ActionBarDrawerToggle(
70 | this, drawer, toolbar, R.string.navigation_drawer_open, R.string.navigation_drawer_close);
71 | drawer.addDrawerListener(toggle);
72 | toggle.syncState();
73 |
74 | NavigationView navigationView = findViewById(R.id.nav_view);
75 | navigationView.setNavigationItemSelectedListener(this);
76 | }
77 |
78 | @Override
79 | public void onBackPressed() {
80 | DrawerLayout drawer = findViewById(R.id.drawer_layout);
81 | if (drawer.isDrawerOpen(GravityCompat.START)) {
82 | drawer.closeDrawer(GravityCompat.START);
83 | } else {
84 | super.onBackPressed();
85 | }
86 | }
87 |
88 | @Override
89 | public boolean onCreateOptionsMenu(Menu menu) {
90 | // Inflate the menu; this adds items to the action bar if it is present.
91 | getMenuInflater().inflate(R.menu.main, menu);
92 | return true;
93 | }
94 |
95 | @Override
96 | public boolean onOptionsItemSelected(MenuItem item) {
97 | // Handle action bar item clicks here. The action bar will
98 | // automatically handle clicks on the Home/Up button, so long
99 | // as you specify a parent activity in AndroidManifest.xml.
100 | int id = item.getItemId();
101 |
102 | //noinspection SimplifiableIfStatement
103 | if (id == R.id.action_settings) {
104 | return true;
105 | }
106 |
107 | return super.onOptionsItemSelected(item);
108 | }
109 |
110 | @Override
111 | public boolean onNavigationItemSelected(MenuItem item) {
112 | // Handle navigation view item clicks here.
113 | int id = item.getItemId();
114 |
115 | if (id == R.id.nav_register) {
116 | if (canAuthenticateWithStrongBiometrics()) { // Check whether this device can authenticate with biometrics
117 | Log.i(TAG, "Try registration");
118 | // Generate keypair and init signature
119 | Signature signature;
120 | try {
121 | KeyPair keyPair = generateKeyPair(KEY_NAME, true);
122 | // Send public key part of key pair to the server, this public key will be used for authentication
123 | mToBeSignedMessage = Base64.encodeToString(keyPair.getPublic().getEncoded(), Base64.URL_SAFE) +
124 | ":" +
125 | KEY_NAME +
126 | ":" +
127 | // Generated by the server to protect against replay attack
128 | "12345";
129 |
130 | signature = initSignature(KEY_NAME);
131 | } catch (Exception e) {
132 | throw new RuntimeException(e);
133 | }
134 |
135 | // Create biometricPrompt
136 | showBiometricPrompt(signature);
137 | } else {
138 | // Cannot use biometric prompt
139 | Toast.makeText(this, "Cannot use biometric", Toast.LENGTH_SHORT).show();
140 | }
141 | } else if (id == R.id.nav_authenticate) {
142 | if (canAuthenticateWithStrongBiometrics()) { // Check whether this device can authenticate with biometrics
143 | Log.i(TAG, "Try authentication");
144 |
145 | // Init signature
146 | Signature signature;
147 | try {
148 | // Send key name and challenge to the server, this message will be verified with registered public key on the server
149 | mToBeSignedMessage = KEY_NAME +
150 | ":" +
151 | // Generated by the server to protect against replay attack
152 | "12345";
153 | signature = initSignature(KEY_NAME);
154 | } catch (Exception e) {
155 | throw new RuntimeException(e);
156 | }
157 |
158 | // Create biometricPrompt
159 | showBiometricPrompt(signature);
160 | } else {
161 | // Cannot use biometric prompt
162 | Toast.makeText(this, "Cannot use biometric", Toast.LENGTH_SHORT).show();
163 | }
164 | }
165 |
166 | DrawerLayout drawer = findViewById(R.id.drawer_layout);
167 | drawer.closeDrawer(GravityCompat.START);
168 | return true;
169 | }
170 |
171 | private void showBiometricPrompt(Signature signature) {
172 | BiometricPrompt.AuthenticationCallback authenticationCallback = getAuthenticationCallback();
173 | BiometricPrompt mBiometricPrompt = new BiometricPrompt(this, getMainThreadExecutor(), authenticationCallback);
174 |
175 | // Set prompt info
176 | BiometricPrompt.PromptInfo promptInfo = new BiometricPrompt.PromptInfo.Builder()
177 | .setDescription("Description")
178 | .setTitle("Title")
179 | .setSubtitle("Subtitle")
180 | .setNegativeButtonText("Cancel")
181 | .build();
182 |
183 | // Show biometric prompt
184 | if (signature != null) {
185 | Log.i(TAG, "Show biometric prompt");
186 | mBiometricPrompt.authenticate(promptInfo, new BiometricPrompt.CryptoObject(signature));
187 | }
188 | }
189 |
190 | private BiometricPrompt.AuthenticationCallback getAuthenticationCallback() {
191 | // Callback for biometric authentication result
192 | return new BiometricPrompt.AuthenticationCallback() {
193 | @Override
194 | public void onAuthenticationError(int errorCode, @NonNull CharSequence errString) {
195 | Log.e(TAG, "Error code: " + errorCode + "error String: " + errString);
196 | super.onAuthenticationError(errorCode, errString);
197 | }
198 |
199 | @Override
200 | public void onAuthenticationSucceeded(@NonNull BiometricPrompt.AuthenticationResult result) {
201 | Log.i(TAG, "onAuthenticationSucceeded");
202 | super.onAuthenticationSucceeded(result);
203 | if (result.getCryptoObject() != null &&
204 | result.getCryptoObject().getSignature() != null) {
205 | try {
206 | Signature signature = result.getCryptoObject().getSignature();
207 | signature.update(mToBeSignedMessage.getBytes());
208 | String signatureString = Base64.encodeToString(signature.sign(), Base64.URL_SAFE);
209 | // Normally, ToBeSignedMessage and Signature are sent to the server and then verified
210 | Log.i(TAG, "Message: " + mToBeSignedMessage);
211 | Log.i(TAG, "Signature (Base64 Encoded): " + signatureString);
212 | Toast.makeText(getApplicationContext(), mToBeSignedMessage + ":" + signatureString, Toast.LENGTH_SHORT).show();
213 | } catch (SignatureException e) {
214 | throw new RuntimeException();
215 | }
216 | } else {
217 | // Error
218 | Toast.makeText(getApplicationContext(), "Something wrong", Toast.LENGTH_SHORT).show();
219 | }
220 | }
221 |
222 | @Override
223 | public void onAuthenticationFailed() {
224 | super.onAuthenticationFailed();
225 | }
226 | };
227 | }
228 |
229 | private KeyPair generateKeyPair(String keyName, boolean invalidatedByBiometricEnrollment) throws Exception {
230 | KeyPairGenerator keyPairGenerator = KeyPairGenerator.getInstance(KeyProperties.KEY_ALGORITHM_EC, "AndroidKeyStore");
231 |
232 | KeyGenParameterSpec.Builder builder = new KeyGenParameterSpec.Builder(keyName,
233 | KeyProperties.PURPOSE_SIGN)
234 | .setAlgorithmParameterSpec(new ECGenParameterSpec("secp256r1"))
235 | .setDigests(KeyProperties.DIGEST_SHA256,
236 | KeyProperties.DIGEST_SHA384,
237 | KeyProperties.DIGEST_SHA512)
238 | // Require the user to authenticate with a biometric to authorize every use of the key
239 | .setUserAuthenticationRequired(true);
240 |
241 | // Generated keys will be invalidated if the biometric templates are added more to user device
242 | if (Build.VERSION.SDK_INT >= 24) {
243 | builder.setInvalidatedByBiometricEnrollment(invalidatedByBiometricEnrollment);
244 | }
245 |
246 | keyPairGenerator.initialize(builder.build());
247 |
248 | return keyPairGenerator.generateKeyPair();
249 | }
250 |
251 | @Nullable
252 | private KeyPair getKeyPair(String keyName) throws Exception {
253 | KeyStore keyStore = KeyStore.getInstance("AndroidKeyStore");
254 | keyStore.load(null);
255 | if (keyStore.containsAlias(keyName)) {
256 | // Get public key
257 | PublicKey publicKey = keyStore.getCertificate(keyName).getPublicKey();
258 | // Get private key
259 | PrivateKey privateKey = (PrivateKey) keyStore.getKey(keyName, null);
260 | // Return a key pair
261 | return new KeyPair(publicKey, privateKey);
262 | }
263 | return null;
264 | }
265 |
266 | @Nullable
267 | private Signature initSignature (String keyName) throws Exception {
268 | KeyPair keyPair = getKeyPair(keyName);
269 |
270 | if (keyPair != null) {
271 | Signature signature = Signature.getInstance("SHA256withECDSA");
272 | signature.initSign(keyPair.getPrivate());
273 | return signature;
274 | }
275 | return null;
276 | }
277 |
278 | private Executor getMainThreadExecutor() {
279 | return new MainThreadExecutor();
280 | }
281 |
282 | private static class MainThreadExecutor implements Executor {
283 | private final Handler handler = new Handler(Looper.getMainLooper());
284 |
285 | @Override
286 | public void execute(@NonNull Runnable r) {
287 | handler.post(r);
288 | }
289 | }
290 |
291 | /**
292 | * Indicate whether this device can authenticate the user with strong biometrics
293 | * @return true if there are any available strong biometric sensors and biometrics are enrolled on the device, if not, return false
294 | */
295 | private boolean canAuthenticateWithStrongBiometrics() {
296 | return BiometricManager.from(this).canAuthenticate(BiometricManager.Authenticators.BIOMETRIC_STRONG) == BiometricManager.BIOMETRIC_SUCCESS;
297 | }
298 | }
299 |
--------------------------------------------------------------------------------