You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Android 13人脸识别解锁时SetUnlockedDeviceRequired引发应用启动卡顿问题

解决方案:Android 13上面部解锁后SetUnlockedDeviceRequired导致应用卡住问题

可能原因

Android 13对生物识别解锁后的密钥库状态同步逻辑做了调整,面部解锁的认证信号可能未及时传递给密钥库,导致应用尝试访问时因权限不足卡住;或是Xamarin.Android绑定层对Android 13的SetUnlockedDeviceRequired参数处理存在兼容性问题。

具体修复步骤

1. 调整密钥生成参数

在创建KeyGenParameterSpec时,补充用户认证相关参数,确保密钥库能识别面部解锁的认证状态:

using Android.Security.Keystore;
using AndroidX.Biometric;

// 密钥生成示例
var keyAlias = "YourKeyAlias";
var keyGenSpec = new KeyGenParameterSpec.Builder(
    keyAlias,
    KeyStorePurpose.Encrypt | KeyStorePurpose.Decrypt)
    .SetBlockModes(KeyProperties.BlockModeGcm)
    .SetEncryptionPaddings(KeyProperties.EncryptionPaddingNone)
    .SetKeySize(256)
    .SetUnlockedDeviceRequired(true)
    // 针对Android 13添加:要求用户认证(适配面部解锁)
    .SetUserAuthenticationRequired(true)
    // 设置认证有效期为永久(直到设备重新锁定)
    .SetUserAuthenticationValidityDurationSeconds(-1)
    // 允许生物识别认证(包含面部)
    .SetUserAuthenticationAllowed(true)
    .Build();

var keyGenerator = KeyGenerator.GetInstance(KeyProperties.KeyAlgorithmAes, "AndroidKeyStore");
keyGenerator.Init(keyGenSpec);
keyGenerator.GenerateKey();

2. 延迟密钥库访问时机

面部解锁后系统需要短暂时间同步密钥库状态,可通过监听设备解锁广播避免提前访问:

private BroadcastReceiver _unlockReceiver;

protected override void OnCreate(Bundle savedInstanceState)
{
    base.OnCreate(savedInstanceState);
    // 注册解锁广播
    _unlockReceiver = new UnlockReceiver();
    RegisterReceiver(_unlockReceiver, new IntentFilter(Intent.ActionUserUnlocked));
}

private class UnlockReceiver : BroadcastReceiver
{
    public override void OnReceive(Context context, Intent intent)
    {
        if (intent.Action == Intent.ActionUserUnlocked)
        {
            // 此处执行密钥库访问逻辑
            AccessKeyStore();
        }
    }
}

protected override void OnDestroy()
{
    base.OnDestroy();
    UnregisterReceiver(_unlockReceiver);
}

3. 捕获密钥库访问异常并处理

在访问密钥库的代码块中添加异常捕获,根据错误码针对性处理:

private void AccessKeyStore()
{
    try
    {
        var keyStore = KeyStore.GetInstance("AndroidKeyStore");
        keyStore.Load(null);
        var secretKey = (SecretKey)keyStore.GetKey("YourKeyAlias", null);
        // 执行加密/解密操作
    }
    catch (KeyStoreException e)
    {
        if (e.ErrorCode == KeyStoreException.KeyNotAvailable)
        {
            // 设备未解锁,触发重新认证流程
            TriggerBiometricAuthentication();
        }
        // 处理其他异常
    }
}

// 触发生物识别认证示例
private void TriggerBiometricAuthentication()
{
    var promptInfo = new BiometricPrompt.PromptInfo.Builder()
        .SetTitle("请验证身份")
        .SetSubtitle("需要验证身份以访问密钥")
        .SetAllowedAuthenticators(BiometricManager.Authenticators.BiometricWeak | BiometricManager.Authenticators.DeviceCredential)
        .Build();

    var biometricPrompt = new BiometricPrompt(this, new MainThreadExecutor(), new BiometricCallback());
    biometricPrompt.Authenticate(promptInfo);
}

private class BiometricCallback : BiometricPrompt.AuthenticationCallback
{
    public override void OnAuthenticationSucceeded(BiometricPrompt.AuthenticationResult result)
    {
        base.OnAuthenticationSucceeded(result);
        // 认证成功后再次访问密钥库
        AccessKeyStore();
    }
}

4. 更新Xamarin.Android版本

确保使用最新稳定版的Xamarin.Android(至少13.0以上),修复绑定层对Android 13 API的兼容性问题。

5. 主动验证设备解锁状态

在访问密钥库前先检查设备是否处于解锁状态:

var devicePolicyManager = (DevicePolicyManager)GetSystemService(Context.DevicePolicyService);
var isUnlocked = !devicePolicyManager.IsDeviceLocked;
if (!isUnlocked)
{
    // 触发解锁/认证流程
    TriggerBiometricAuthentication();
    return;
}
// 访问密钥库
AccessKeyStore();

内容的提问来源于stack exchange,提问作者deepika

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.17 08:53:32