Overview
This section covers the prerequisites for using the Nok Nok Authenticator SDK for Android, followed by a quick outline for how to get started. The remainder of the document is devoted to the technical details necessary for authenticator development.
Supported Platforms
The Authenticator SDK for Android supports devices running Lollipop (version 5.0) and later.
The Authenticator SDK for Android supports the QSEE Trusted Execution Environment.
Prerequisites
Prerequisite software or tools that must be installed and configured:
Android Studio (latest release)
Java Development Kit 11
Android SDK r35 and later
What’s in the SDK?
The Authenticator SDK package contains the following folders and files:
Folder Name / File Name | Description |
|---|---|
ASMSDK | Folder containing all required Android libraries and javadoc API documentation for building a fully functional FIDO enabled authenticator. Also contains Android Studio projects for Sample ASM, a sample ASM service that demonstrates how to use the Authenticator SDK. |
licenses | Folder containing license files of 3rd party software used in the Authenticator SDK |
metadata | Folder containing AAID .json metadata files required for using Android-specific Authenticators. |
values | Folder containing localization strings |
version.txt | File containing the Authenticator SDK version information. |
Authenticator SDK Modules
The following table lists the modules provided with the Authenticator SDK:
Module Name | Description |
|---|---|
asmsdk | Common code for ASM |
asmsdk_uaf | UAF specific code for ASM |
common | Utilities and common code |
common_uaf | Utilities and common code for UAF |
Android Studio-specific modules are located in the <ASM_SDK_HOME>/android-studio/m2repository folder.
Outline for Authenticator Development
After using the App SDK to build Tutorial App, you are ready to work with the Authenticator SDK and begin creating your own FIDO authenticator. The authenticator development process consists of four parts:
Assemble the Prerequisites
Assemble the following materials and resources before starting:
Hardware and Software
You can develop using any platform compatible with Android Studio.
Review the list of prerequisites.
Expertise
It’s essential that you have familiarity with the following:
Android Development
The use of REST APIs
Prepare your Development Environment
Contact Nok Nok Support (support@noknok.com) for instructions on how to download the Authenticator SDK for Android.
Software Installation
Install Android Studio
Unpack the Authenticator SDK tarball
Familiarize Yourself with the Authenticator SDK
Review this Authenticator SDK Guide.
Open doc/javadoc/index.html to view the detailed API documentation you’ll refer to during development.
Review the Sample ASM source code to understand how an ASM works.
Build and Run Sample ASM
Create a new project in Android Studio, import the Sample ASM project, and build it
If necessary, resolve any dependency errors by importing any missing Android SDKs
You can run Tutorial App to observe the Sample ASM operating. Later on, you can replace the Sample ASM with your own code.
Loading the APKs and prefs
To use a standalone remote authenticator, add the following configuration
{ "useRemoteASM" : true }to res/raw/mfac_config.json in the Tutorial App project. Create mfac_config.json if it doesn't exist.
Install Tutorial App and the Sample ASM you built for your target Android test device or emulator.
Run Tutorial App and authenticate to verify end-to-end connectivity. Resolve any issues that arise between Tutorial App and the Server.
Creating your own FIDO Authenticator
This section describes the steps needed to create a custom ASM. The steps entail modifying existing text files, as well as creating your own code modules.
Modify the Manifest
The Manifest is a text file that defines entry points for handling incoming requests. Add a new activity to handle UI interaction, similar to com.MyASM.MyActivity in the Sample sources.
Modify the Matcher
The Matcher module handles all user interactions for performing user verification. Refer to the IMatcher javadocs and the MyMatcher sample for more information.
Modify the Descriptor
The Descriptor is a configuration file that specifies properties of the authenticator. Refer to IAuthenticatorDescriptor javadocs and the MyAuthenticatorDescriptor sample for more information.
Modify the Descriptor List
The Descriptor List specifies which authenticators the ASM implements. The descriptor class names are listed in asmdescriptors.json.