If your system design requires your ASM to share keychain entries and app storage across multiple apps, use the following steps as a guide during implementation:
Create the metadata and new AAID for your shareable authenticator.
Implement the descriptor for this authenticator, e.g. SampleAuthnenticatorDescriptor.cpp
Define the AAID
Set aaidInfo.isShareable = true
Implement a factory class, e.g. NNLSampleAuthenticatorDXFactory.mm and add a function for creating an instance, e.g. nnl::asmsdk::IAuthenticatorDescriptor * createSampleShareableInstance()
Create an Access Group string for sharing and use it when storing items in the keychain:
Get the value of the SharedGroupAccess entry from the application main bundle:
NSString *groupName = [[NSBundle mainBundle].infoDictionary objectForKey:@"SharedAccessGroup"];Create a strSharedAccessGroup using Bundle SeedID and SharedGroupAccess, e.g.:
strSharedAccessGroup = strBundleSeedID + "." + groupName;Add the corresponding attribute when storing data in the keychain, e.g.:
[dict setObject:strSharedAccessGroup
forKey:(__bridge id)kSecAttrAccessGroup];
Note the following additional design considerations:
Your authenticator must also be able to share biometric templates across apps.
You should implement locking to prevent corruption due to concurrent accesses.
Apps can be upgraded independently of each other, so it’s important to validate data consistency across versions.