如何在应用内临时存储TouchID指纹,实现双人非机主身份验证?
Great question! Let’s break this down clearly, since there are some key iOS platform constraints you need to be aware of first.
Can This Requirement Be Implemented?
Yes—but with one critical prerequisite: both users' fingerprints must already be enrolled in the device's system-level TouchID/FaceID library.
iOS strictly restricts third-party apps from accessing, storing, or enrolling biometric data directly. All fingerprint/face data lives in the Secure Enclave, a hardware-level security module, and apps only get a "success/failure" signal from the LocalAuthentication framework—never raw biometric information. So you can't "temporarily store" fingerprints for non-owner verification, but you can work within system rules to build your desired flow.
Implementation Directions
1. Core Logic Overview
Since we can't distinguish between specific fingerprints, we'll rely on user配合 (user cooperation) to complete the initial two-step verification, then use secure local storage to track that the initial check was completed. For subsequent actions, any enrolled fingerprint will trigger the desired operation.
2. Step-by-Step Implementation
First Launch: Dual Verification Flow
- Initial State: Check secure storage (use Keychain, not UserDefaults) for a flag like
pairVerificationCompleted. If it doesn't exist, start the dual verification. - First User Check: Call the
LocalAuthenticationframework with a prompt like "First user: verify your fingerprint". On success, store a temporary flag (firstUserVerified = true) in Keychain. - Second User Check: Call the framework again with a prompt like "Second user: verify your fingerprint". On success, set the
pairVerificationCompletedflag totrueand clear the temporary flag. - Note: This relies on users following the prompts to use different fingerprints—since the system will accept any enrolled fingerprint, but you can guide users to complete the two distinct checks.
Post-Launch: Single Verification for Action Triggers
- When the app launches later or needs to trigger an action, first check if
pairVerificationCompletedistrue. - If yes, call
LocalAuthenticationwith a prompt like "Verify fingerprint to proceed". Any successful biometric check (from either enrolled user) will trigger your target operation.
3. Code Snippets
Basic Biometric Authentication Helper
import LocalAuthentication func authenticateUser(prompt: String, completion: @escaping (Bool) -> Void) { let context = LAContext() var authError: NSError? // Check if biometrics are supported guard context.canEvaluatePolicy(.deviceOwnerAuthenticationWithBiometrics, error: &authError) else { completion(false) return } // Trigger authentication context.evaluatePolicy(.deviceOwnerAuthenticationWithBiometrics, localizedReason: prompt) { success, _ in DispatchQueue.main.async { completion(success) } } }
Dual Verification Flow
// Assume you have a helper class for Keychain operations (KeychainHelper) func startPairVerification() { let keychain = KeychainHelper.shared guard !keychain.bool(forKey: "pairVerificationCompleted") else { setupPostVerificationActions() return } // First user verification authenticateUser(prompt: "First user: verify fingerprint") { [weak self] firstSuccess in guard firstSuccess else { // Handle failure (e.g., show retry prompt) return } // Second user verification self?.authenticateUser(prompt: "Second user: verify fingerprint") { secondSuccess in guard secondSuccess else { // Handle failure return } // Mark dual verification as complete keychain.set(true, forKey: "pairVerificationCompleted") self?.setupPostVerificationActions() } } } func setupPostVerificationActions() { // Proceed to your app's main flow or action trigger logic }
4. Security Notes
- Always use Keychain for storing verification flags: Keychain is encrypted and sandboxed, unlike UserDefaults which is plaintext and easily tampered with.
- Never attempt to store biometric data: This violates Apple's privacy policies and is technically impossible due to Secure Enclave restrictions.
- Add retry/timeout logic: Prevent users from getting stuck if they fail verification multiple times.
Important Note for "Non-Owner" Verification
If you want to allow users who haven't enrolled their fingerprint in the device's system library to verify, this is not possible. iOS biometric authentication only works with identities already registered at the system level—third-party apps can't implement custom biometric storage or verification.
内容的提问来源于stack exchange,提问作者Tomaž Polič

