能否在Delphi应用中调用Windows Hello身份认证以保护敏感数据?
Delphi中调用Windows Hello身份认证的实现方法
完全可以在Delphi应用程序中调用Windows Hello,实现PIN码或指纹验证,以此保护敏感数据或功能的访问权限。
实现方式
- 直接调用Windows原生的WinRT API:利用
Windows.Security.Credentials.UI命名空间下的UserConsentVerifier类,Delphi XE8及后续版本原生支持WinRT接口调用,无需额外依赖。 - 第三方组件:也可使用封装好的Delphi安全组件库,但原生API调用更轻量、可控。
核心步骤与代码示例
步骤说明
- 先检查当前设备是否支持Windows Hello(如是否配置指纹传感器、设置PIN码)
- 发起身份验证请求,自定义提示文本
- 根据验证结果执行对应逻辑(放行敏感操作/拒绝访问)
代码示例
uses Winapi.Windows, Winapi.Messages, System.SysUtils, System.Variants, System.Classes, Vcl.Graphics, Vcl.Controls, Vcl.Forms, Vcl.Dialogs, Vcl.StdCtrls, WinRT.Windows.Security.Credentials.UI; procedure TForm1.VerifyHelloBtnClick(Sender: TObject); var LDeviceStatus: UserConsentVerifierAvailability; LVerifyResult: UserConsentVerificationResult; begin // 检查设备Windows Hello支持状态 LDeviceStatus := UserConsentVerifier.CheckAvailabilityAsync.GetResults; case LDeviceStatus of UserConsentVerifierAvailability_Available: begin // 发起身份验证请求 LVerifyResult := UserConsentVerifier.RequestVerificationAsync('请验证身份以访问敏感数据').GetResults; case LVerifyResult of UserConsentVerificationResult_Verified: ShowMessage('验证通过,可访问敏感内容'); UserConsentVerificationResult_Denied: ShowMessage('验证被拒绝,无法访问'); UserConsentVerificationResult_DeviceNotPresent, UserConsentVerificationResult_DisabledByPolicy, UserConsentVerificationResult_NotConfiguredForUser: ShowMessage('Windows Hello当前不可用'); end; end; else ShowMessage('设备不支持Windows Hello'); end; end;
注意事项
- 项目目标平台需设置为Windows 10/11(WinRT API仅适配这些系统版本)
- 应用无需管理员权限,但用户需提前在系统中配置好Windows Hello(PIN/指纹)
- 验证弹窗为系统原生样式,和你截图中密码管理器的效果一致
你提供的截图展示了密码管理器调用Windows Hello的验证界面,上述代码执行后会弹出相同风格的系统级验证窗口,支持PIN、指纹等验证方式。
内容的提问来源于stack exchange,提问作者davepaul12
相关产品推荐
相关产品推荐

