Digipass S3 is now DigipassONE. This section is currently being updated to reflect our new name.

Creating a Shareable ASM

Prev Next

If your system design requires your ASM to share keychain entries and app storage across multiple apps, use the following steps as a guide during implementation:

  1. Create the metadata and new AAID for your shareable authenticator.

  2. Implement the descriptor for this authenticator, e.g. SampleAuthnenticatorDescriptor.cpp

    1. Define the AAID

    2. Set aaidInfo.isShareable = true

  3. Implement a factory class, e.g. NNLSampleAuthenticatorDXFactory.mm and add a function for creating an instance, e.g. nnl::asmsdk::IAuthenticatorDescriptor * createSampleShareableInstance()

  4. Create an Access Group string for sharing and use it when storing items in the keychain:

    1. Get the value of the SharedGroupAccess entry from the application main bundle:
      NSString *groupName = [[NSBundle mainBundle].infoDictionary objectForKey:@"SharedAccessGroup"];

    2. Create a strSharedAccessGroup using Bundle SeedID and SharedGroupAccess, e.g.:
      strSharedAccessGroup = strBundleSeedID + "." + groupName;

    3. Add the corresponding attribute when storing data in the keychain, e.g.:
      [dict setObject:strSharedAccessGroup
      forKey:(__bridge id)kSecAttrAccessGroup];

Note the following additional design considerations:

  • Your authenticator must also be able to share biometric templates across apps.

  • You should implement locking to prevent corruption due to concurrent accesses.

  • Apps can be upgraded independently of each other, so it’s important to validate data consistency across versions.