You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

连接ID06(ISO-DEV)后出现Missing required entitlement错误的原因

解决iOS NFC连接PIV卡时的"Missing required entitlement"错误

你遇到的核心问题是NFC权限配置不完整,导致应用虽然能检测到卡片,但无法正常与ISO7816类型的PIV卡交互,最终会话失效。从错误日志和配置来看,主要有两处关键配置错误:

1. 修正Entitlements权限配置

当前你的.entitlements文件只声明了TAG和NDEF格式的NFC读取权限,但PIV卡属于ISO7816智能卡,需要添加对应的权限才能进行连接和APDU命令交互。

修改你的.entitlements文件,将ISO7816加入com.apple.developer.nfc.readersession.formats数组:

<?xml version="1.0" encoding="UTF-8"?>
<!DOCTYPE plist PUBLIC "-//Apple//DTD PLIST 1.0//EN" "http://www.apple.com/DTDs/PropertyList-1.0.dtd">
<plist version="1.0">
<dict>
    <key>com.apple.developer.nfc.readersession.formats</key>
    <array>
        <string>TAG</string>
        <string>NDEF</string>
        <string>ISO7816</string> <!-- 添加这一行 -->
    </array>
</dict>
</plist>

2. 修正Info.plist中的PIV卡AID

PIV卡(ID06)的正确应用标识符(AID)是A0000001160200000006,你当前配置的A000000116071不符合标准,会导致无法正确选择PIV应用。修改Info.plist中的com.apple.developer.nfc.readersession.iso7816.select-identifiers数组:

<?xml version="1.0" encoding="UTF-8"?>
<!DOCTYPE plist PUBLIC "-//Apple//DTD PLIST 1.0//EN" "http://www.apple.com/DTDs/PropertyList-1.0.dtd">
<plist version="1.0">
<dict>
    <key>NFCReaderUsageDescription</key>
    <string>Need NFC to scan PIV cards</string> <!-- 建议描述更明确 -->
    <key>com.apple.developer.nfc.readersession.iso7816.select-identifiers</key>
    <array>
        <string>A0000001160200000006</string> <!-- 修正为正确的PIV AID -->
    </array>
</dict>
</plist>

3. 重新验证证书与配置文件

完成上述修改后,执行以下步骤确保配置生效:

  • 登录Apple开发者门户,确认你的App ID已启用NFC Tag Reading功能,且包含ISO7816相关权限;
  • 删除本地的Provisioning Profile,重新下载最新的配置文件;
  • 清理Xcode缓存(Product > Clean Build Folder),然后重新构建并安装应用到设备。

代码层面的小优化

另外,你的代码中在connectToTag的completionHandler里,即使系统日志显示权限错误,仍会执行后续的APDU命令发送逻辑。建议在该回调中严格判断error,避免无效操作:

[session connectToTag:tag completionHandler:^(NSError * _Nullable error) {
    if (error != nil) {
        NSLog(@"Connection error: %@", error);
        [session invalidateSessionWithErrorMessage:@"Connection failed due to missing permissions"];
        return;
    }
    
    // 后续逻辑...
}];

完成以上修改后,应用应该能正常连接PIV卡并执行APDU命令,不会再出现权限缺失导致的会话失效问题。

内容的提问来源于stack exchange,提问作者user688291

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.23 00:50:55