Tencent / soter

A secure and quick biometric authentication standard and platform in Android held by Tencent.
Other
1.93k stars 205 forks source link

mate30手机上传ask时签名数据缺失 #67

Open huma8848888 opened 4 years ago

huma8848888 commented 4 years ago

使用mate30手机在soterdemo上测试发现,setRequest回调中的UploadRequest对象中缺失了签名数据 并且在部分mate30手机中发现mKeyJson中缺失cpuid,count等数据,请问官方是怎么回事

huma8848888 commented 4 years ago

P40PRO也发现了此问题,mKeyJsonSignature缺失

huma8848888 commented 4 years ago

经过测试,华为手机都存在此问题,测试的机器包括:mate20,mate30,P40,NOVA系列,都是存在ask上传时没有签名数据的情况,签名数据是从soter SDK中吐出的UploadRequest中获取的mKeyJsonSignature

huma8848888 commented 4 years ago

急急急,官方能解释一下是什么原因吗?后端依赖这个签名数据做校验

liuxb-tofu commented 4 years ago

没有签名字段参考https://github.com/Tencent/soter/wiki/%E5%AE%89%E5%85%A8%E6%8E%A5%E5%85%A5%E2%80%94%E2%80%94%E5%90%8E%E5%8F%B0#2%E8%AF%81%E4%B9%A6%E9%93%BE%E6%A0%BC%E5%BC%8F

https://github.com/Tencent/soter/wiki/%E5%90%8E%E5%8F%B0%E6%8E%A5%E5%8F%A3%E6%96%87%E6%A1%A3#api%E6%8E%A5%E5%8F%A3%E8%BE%93%E5%85%A5%E8%BE%93%E5%87%BA%E8%A7%84%E8%8C%83-1

缺失cpuid、count的问题有日志吗

huma8848888 commented 4 years ago

没有签名字段参考https://github.com/Tencent/soter/wiki/%E5%AE%89%E5%85%A8%E6%8E%A5%E5%85%A5%E2%80%94%E2%80%94%E5%90%8E%E5%8F%B0#2%E8%AF%81%E4%B9%A6%E9%93%BE%E6%A0%BC%E5%BC%8F

https://github.com/Tencent/soter/wiki/%E5%90%8E%E5%8F%B0%E6%8E%A5%E5%8F%A3%E6%96%87%E6%A1%A3#api%E6%8E%A5%E5%8F%A3%E8%BE%93%E5%85%A5%E8%BE%93%E5%87%BA%E8%A7%84%E8%8C%83-1

缺失cpuid、count的问题有日志吗

华为mate30 5G手机 证书链格式ask: {"certs":["-----BEGIN CERTIFICATE-----\nMIIEWzCCA0WgAwIBAgIBATALBgkqhkiG9w0BAQswHTEbMBkGA1UEAxMSSHVhd2Vp\nIEtleVN0b3JlICAgMB4XDTIwMDcwNjAzMjAwOFoXDTMwMDcwNjAzMjAwOFowGjEY\nMBYGA1UEAxMPQSBLZXltYXN0ZXIgS2V5MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8A\nMIIBCgKCAQEAn1t0Phg9jIKsPlL8oAuVMl\/cUMjzDP4nG73BB2pd6A+qLjec6zda\nGJEWdVyqNVCpgcFOqLtCpQaoxEeU122\/ggbrWby4xYczvy1H1H0SYCGHNG5eYFqj\nFOo3BaCEIG5p81BQOZzRakoiPE52k\/Jk220dEKziPkJSYN8kaZ0fzL9QDhAUdxjR\nRmWD+iV6t0DQwQmrubmXcV7DNcQxE5YlkMlWh5ftzgcJN9SvCIzkGxh\/7Vs0jt+a\nrPx99fCvrOcSiMAleA1tRbhpdfoGDHvNEXuxWpKOqez7F5eAivgsW4xlO6r19Gz3\nQzmqOMFi8iCREQq\/QpUqwbdKKRatk2alEQIDAQABo4IBqzCCAacwCwYDVR0PBAQD\nAgAAMAgGA1UdHwQBADCCAWEGCisGAQQB1nkCAREEggFRMIIBTQIBAgoBAQIBAwoB\nAQR4eyJjcHVfaWQiOiJIVUFXRUlfSFdUQVNfZjk2NGUwY2EtOWU0OS00NzY3LWJj\nM2YtZTkzNmQ4NTk1ZGUyLTU2ZWVmN2UxIiwiY291bnRlciI6MTIyLCJ1aWQiOiIx\nMDQwMSIsInJzYV9wc3Nfc2FsdGxlbiI6MzJ9BAAwe7+DdwIFAL+FPQgCBgFzIiNZ\nz7+FRWUEYzBhMRswGQQUY29tLnd1YmEucGFzc3BvcnRzZGsCAQExQgRAZTI2NGE0\nYTE2ZDQwY2Y5MWU4ZmMzMzc1NmI2ZjIwN2EyNmI2M2FiM2NmMzA4ZTY3MWFjMWYx\nYTYxYTI2NjU0NTBGoQkxBwIFAP8BAAGiAwIBAaMEAgIIAKUFMQMCAQSmBTEDAgED\nv4FIBQIDAQABv4U+AwIBAL+FQQUCAwGGoL+FQgUCAwMVFTApBgkrBgEEAY9bHgIB\nAQAEGTAXAgEAogMBAQG\/gUgLMAmhBwMFAAaAAIAwCwYJKoZIhvcNAQELA4IBAQAe\nUZ3P2XOFGzeux5tEApBTZbzk0UzbCQDQpxNXbNDM8mDAUSyo6Z9ZypEVAoJ31LwG\naiMK+LXxqWYRacugDxcKtGkJs9+s5dABk+Lz46cUonE5T3i0E7L87CCfzhgWAWry\no2CiKQwXlUZThcsw7Kx0lUfdPU\/KiuVAPVyHVy8gcd7k50VUHM238MLWUV9nuCOB\n5evwC+ZU0UIeBzytSUVnpC1hjOGfFzo0loAm31sAMvmtsvLuNfYIkXfpIlt4Uitv\nR86XiDyCHyh78KTnR3kazFGFREuOfx\/jxb18PVDHplv\/KYIMt09mUF\/ygck7KIYo\nEBYilYdxAc1xXJWOJ29k\n-----END CERTIFICATE-----\n","-----BEGIN CERTIFICATE-----\nMIIEQDCCAyigAwIBAgIQIBkQExADOE0tiVGQV2p72zANBgkqhkiG9w0BAQsFADBc\nMQswCQYDVQQGEwJDTjEPMA0GA1UECgwGSHVhd2VpMRMwEQYDVQQLDApIdWF3ZWkg\nQ0JHMScwJQYDVQQDDB5IdWF3ZWkgQ0JHIE1vYmlsZSBFcXVpcG1lbnQgQ0EwHhcN\nMTkxMDEzMDIwMzM4WhcNMjkxMDEwMDIwMzM4WjBvMQswCQYDVQQGEwJDTjEPMA0G\nA1UECgwGSHVhd2VpMRMwEQYDVQQLDApIdWF3ZWkgQ0JHMTowOAYDVQQDDDFIVUFX\nRUlfSFdUQVNfZjk2NGUwY2EtOWU0OS00NzY3LWJjM2YtZTkzNmQ4NTk1ZGUyMIIB\nIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEA0dSs7nIAL1Ua7WHX5PpZHmnt\nJEFpLHOmzJ+vMxQSK3yqxZeByykqkSnYedga33am2smgooVbbFj3Lj8xamYKqo09\nVRjHVXssO5Kf9QeWbAk2FPbQlzZN0\/Wlcf22keczVvA0DkHAYC06a7Xn+rhxjEU0\nId7BHmcbRbINlGCyghYKtywYJOacB4K+z57QtFlarJ75pg019S8VNRhdYFsL30UT\nnsRTvNgnU10auEEZsX\/Do\/U\/RA9B28i9tazn\/\/+dfp2K5wcnQH3z2GZtwvKWq\/91\nnKMemiufn5kgVBehc9i0aW3pGm999gn+kKs84ayhyVmepcHfWDEu+C584zJ4hwID\nAQABo4HqMIHnMB8GA1UdIwQYMBaAFDXT2UhPcFFNI7Ey1dXdJSHOBS7dMB0GA1Ud\nDgQWBBS2SSzLCEt1V2J9\/5v94PQg9PbCNjARBglghkgBhvhCAQEEBAMCBsAwCwYD\nVR0PBAQDAgTwMGYGA1UdHwRfMF0wW6BZoFeGVWh0dHA6Ly9jcGtpLWNhd2ViLmh1\nYXdlaS5jb20vY3BraS9zZXJ2bGV0L2NybEZpbGVEb3duLmNybD9jZXJ0eXBlPTQm\neWVhcj0vY3JsMjAxOS5jcmwwHQYDVR0lBBYwFAYIKwYBBQUHAwEGCCsGAQUFBwMC\nMA0GCSqGSIb3DQEBCwUAA4IBAQA2AkO6xgJZhtHR4+J9hdkv\/cUy1fwakUjRWYuY\n\/H9K15TeNVRC72aaa4RHlDy2\/Frs7hke\/4PhWE2A+2o1NTjRcTtACqhEuH3IAZTk\n67Ayi7tT6pSyxioNFLU4frmh\/uxUfnYuxtx37nMCiT7bcAOmyyHaSF4Vzw4WXhAl\n6VRz6J\/+XrNh8d1iOul4mXchbHykqKipJsYeh30cq65ezxbdcUMmy80X19QPbipA\nBSDySyBubgDlvQQL4hmfZ8XcWYlHfvjxXyIVZ7oMR\/pHYuNv5vAxEUVDJ+9qSvlK\nnatSlrwXyRyiJ7ZTqWZqt1nscSLOtgzmx85nMpLzddm0zSCf\n-----END CERTIFICATE-----\n","-----BEGIN CERTIFICATE-----\nMIIE9jCCAt6gAwIBAgIIGLiVkB1V\/dowDQYJKoZIhvcNAQELBQAwUDELMAkGA1UE\nBhMCQ04xDzANBgNVBAoMBkh1YXdlaTETMBEGA1UECwwKSHVhd2VpIENCRzEbMBkG\nA1UEAwwSSHVhd2VpIENCRyBSb290IENBMB4XDTE3MDgyMTExMTE1NFoXDTM3MDgx\nNjExMTE1NFowXDELMAkGA1UEBhMCQ04xDzANBgNVBAoMBkh1YXdlaTETMBEGA1UE\nCwwKSHVhd2VpIENCRzEnMCUGA1UEAwweSHVhd2VpIENCRyBNb2JpbGUgRXF1aXBt\nZW50IENBMIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAzFwCSSlfQ\/sM\nyGs534kxNYPWFWSlNsduoSXHHDYmDqHoRON7dw256Ly4vQfz+YLcTqGh8Zkaqh+9\nlOb5Qj2N0dxrPqyxa8kMNdqtWyMRQC2JGrd1+stOVOTJ1zjsxABpL+9BOjO43Q4J\nsZH9xLK\/Y7ObSCZPd+fKGLzw2SxjC031n40w0M2tAyKMqnPoxhWT7xJbZO1vXX1r\niBFVCbGYHviA0nJm7YIyepxvfvzELdp9c+IMNYSzvHQrpHMkHJxobiDnw289rZLK\n5RYuWxhzWaD5tafWeAgH8wqr7a8Z75f+4ZESkYWvQu\/glyDAAUPn+\/pQX2S3OSp2\nj9UZtNQHTQIDAQABo4HHMIHEMB8GA1UdIwQYMBaAFKrE03lH6G4ja+\/wqWwicz16\nGWmhMB0GA1UdDgQWBBQ109lIT3BRTSOxMtXV3SUhzgUu3TAPBgNVHRMBAf8EBTAD\nAQH\/MA4GA1UdDwEB\/wQEAwIBBjBhBgNVHR8EWjBYMFagVKBShlBodHRwOi8vY3Br\naS1jYXdlYi5odWF3ZWkuY29tL2Nwa2kvc2VydmxldC9jcmxGaWxlRG93bi5jcmw\/\nY2VydHlwZT0xJi9yb290Y3JsLmNybDANBgkqhkiG9w0BAQsFAAOCAgEAW\/ZYMPfM\nsxWoPUaG2rOk4FmdL8Jz2cxWKOIUvmG6qQ\/4ITWthYJOS3SjTbDyhwQM6tPBCl67\nHlMhqgfstUTqU1byT7QneBmG4XndfyjlTs3yC3TRkfr4ySV21mddTvNMU2BCJtJQ\nTqISeLvjxLKwxX\/syBRB5S2MdWQLPLaU2jvCWGM\/qHoI3u5FVoCmtrgx\/tncK1g\/\nJ\/8PRD4fYt4S2VpQqIzvqvoZSEdQuuP5FETTEo9Glc7UyDh4heqZovwDdla54E4i\nAtq09w4yYhqz1w3eis3csZFoUUKm9sLCXxDS9WFBYNtOnckmyu9uoJ8z2Sx2E\/2c\nEF8DcbM9LB19BpR4PEEV6tXTNOD6doHJ9igF22UvHrWgiLHWcfTl7LLhfVxZuugE\n9GfJSKEID8WaKYxbR\/FiwJfLXC4\/mTtGevmV\/NVKrMZ8t4WjXJCbSNQzvS4rZZ4W\n43yyXzlMJDDaQCujKNt5BcgyLKeT5QjY7I8fy33ODIZF8muYnpwE9iBYOy7BRyvV\nucN2p9uYJlfIvrHy4KZ2ik0jjcljlMqjDvmulnjPB+2OukKwoL2Hg+zKBVkfnIMF\nWpddI3wLQMJYfb7AnWyd1Dp\/LvMJass3bLFV0dSmFe9NMB\/\/EcyVeqKLFA3SRNqa\n0uVSOEYODEFGUT6oeTs6DvM+96q7tKi\/Jt8=\n-----END CERTIFICATE-----\n","-----BEGIN CERTIFICATE-----\nMIIFZDCCA0ygAwIBAgIIYsLLTehAXpYwDQYJKoZIhvcNAQELBQAwUDELMAkGA1UE\nBhMCQ04xDzANBgNVBAoMBkh1YXdlaTETMBEGA1UECwwKSHVhd2VpIENCRzEbMBkG\nA1UEAwwSSHVhd2VpIENCRyBSb290IENBMB4XDTE3MDgyMTEwNTYyN1oXDTQyMDgx\nNTEwNTYyN1owUDELMAkGA1UEBhMCQ04xDzANBgNVBAoMBkh1YXdlaTETMBEGA1UE\nCwwKSHVhd2VpIENCRzEbMBkGA1UEAwwSSHVhd2VpIENCRyBSb290IENBMIICIjAN\nBgkqhkiG9w0BAQEFAAOCAg8AMIICCgKCAgEA1OyKm3Ig\/6eibB7Uz2o93UqGk2M7\n84WdfF8mvffvu218d61G5M3Px54E3kefUTk5Ky1ywHvw7Rp9KDuYv7ktaHkk+yr5\n9Ihseu3a7iM\/C6SnMSGt+LfB\/Bcob9Abw95EigXQ4yQddX9hbNrin3AwZw8wMjEI\nSYYDo5GuYDL0NbAiYg2Y5GpfYIqRzoi6GqDz+evLrsl20kJeCEPgJZN4Jg00Iq9k\n++EKOZ5Jc\/Zx22ZUgKpdwKABkvzshEgG6WWUPB+gosOiLv++inu\/9blDpEzQZhjZ\n9WVHpURHDK1YlCvubVAMhDpnbqNHZ0AxlPletdoyugrH\/OLKl5inhMXNj3Re7Hl8\nWsBWLUKp6sXFf0dvSFzqnr2jkhicS+K2IYZnjghC9cOBRO8fnkonh0EBt0evjUIK\nr5ClbCKioBX8JU+d4ldtWOpp2FlxeFTLreDJ5ZBU4\/\/bQpTwYMt7gwMK+MO5Wtok\nUx3UF98Z6GdUgbl6nBjBe82c7oIQXhHGHPnURQO7DDPgyVnNOnTPIkmiHJh\/e3vk\nVhiZNHFCCLTip6GoJVrLxwb9i4q+d0thw4doxVJ5NB9OfDMV64\/ybJgpf7m3Ld2y\nE0gsf1prrRlDFDXjlYyqqpf1l9Y0u3ctXo7UpXMgbyDEpUQhq3a7txZQO\/17luTD\noA6Tz1ADavvBwHkCAwEAAaNCMEAwDgYDVR0PAQH\/BAQDAgEGMA8GA1UdEwEB\/wQF\nMAMBAf8wHQYDVR0OBBYEFKrE03lH6G4ja+\/wqWwicz16GWmhMA0GCSqGSIb3DQEB\nCwUAA4ICAQC1d3TMB+VHZdGrWJbfaBShFNiCTN\/MceSHOpzBn6JumQP4N7mxCOwd\nRSsGKQxV2NPH7LTXWNhUvUw5Sek96FWx\/+Oa7jsj3WNAVtmS3zKpCQ5iGb08WIRO\ncFnx3oUQ5rcO8r\/lUk7Q2cN0E+rF4xsdQrH9k2cd3kAXZXBjfxfKPJTdPy1XnZR\/\nh8H5EwEK5DWjSzK1wKd3G\/Fxdm3E23pcr4FZgdYdOlFSiqW2TJ3Qe6lF4GOKOOyd\nWHkpu54ieTsqoYcuMKnKMjT2SLNNgv9Gu5ipaG8Olz6g9C7Htp943lmK\/1Vtnhgg\npL3rDTsFX\/+ehk7OtxuNzRMD9lXUtEfok7f8XB0dcL4ZjnEhDmp5QZqC1kMubHQt\nQnTauEiv0YkSGOwJAUZpK1PIff5GgxXYfaHfBC6Op4q02ppl5Q3URl7XIjYLjvs9\nt4S9xPe8tb6416V2fe1dZ62vOXMMKHkZjVihh+IceYpJYHuyfKoYJyahLOQXZykG\nK5iPAEEtq3HPfMVF43RKHOwfhrAH5KwelUA\/0EkcR4Gzth1MKEqojdnYNemkkSy7\naNPPT4LEm5R7sV6vG1CjwbgvQrWCgc4nMb8ngdfnVF7Ydqjqi9SAqUzIk4+Uf0ZY\n+6RY5IcHdCaiPaWIE1xURQ8B0DRUURsQwXdjZhgLN\/DKJpCl5aCCxg==\n-----END CERTIFICATE-----\n"],"cpu_id":"","uid":-1,"counter":-1}

这里面没有cpuid,uid和counter