내용으로 건너뛰기

안드로이드 설정 및 백엔드 검증

GitHub

안드로이드 네이티브 시스템 사용

안드로이드 네이티브 시스템 사용

안드로이드에서 이 플러그인은 구글 플레이 인TEGRITY 표준 API:

  • prepareIntegrityToken 동안 prepare()
  • requestStandardIntegrityToken 위한 createAttestation() 및 createAssertion()

요구 사항

요구 사항
  • 안드로이드 앱은 Google Play 생태계를 통해 배포됩니다.
  • 장치에 Google Play 서비스가 사용 가능합니다.
  • Play Integrity API이 앱에 활성화되어 있습니다.
  • Google Cloud 프로젝트 번호가 구성되어 있습니다.

Google 설정

활성화
  1. and Play Integrity API Google Cloud 프로젝트에서 사용하세요.
  2. Play Console을 열고 앱에 대한 Play Integrity 접근 권한을 구성하세요.
  3. 제공 cloudProjectNumber 플러그인에

Capacitor config

Capacitor config
capacitor.config.ts
plugins: {
AppAttest: {
cloudProjectNumber: '123456789012',
},
}

또는 cloudProjectNumber method options에 호출당할 때마다

클라이언트 흐름

Client flow
import { AppAttest } from '@capgo/capacitor-app-attest';
const { keyId } = await AppAttest.prepare({
cloudProjectNumber: '123456789012',
});
const attestation = await AppAttest.createAttestation({
keyId,
challenge: 'backend-registration-challenge',
});
const assertion = await AppAttest.createAssertion({
keyId,
payload: 'backend-request-payload',
});

token Cloudflare의 Play Integrity 토큰으로서 서버측에서 해독해야 합니다.

Android 백엔드 워크플로

Backend workflow (Android)

등록 (createAttestation)

Registration (createAttestation)
  1. 백엔드가 일회용 challenge.
  2. App이 호출합니다. createAttestation({ keyId, challenge }).
  3. 백엔드가 Google을 호출합니다. decodeIntegrityToken API.
  4. 백엔드가 최소한으로 확인합니다:
    • requestDetails.requestHash === base64url(SHA256(challenge))
    • appIntegrity.packageName Android 애플리케이션 ID와 같습니다.
    • appIntegrity.certificateSha256Digest 릴리스 서명 인증서 해시를 포함합니다.
    • 보안 정책에 따라서完整성 판결이 일치합니다.

보호를 요청하세요 (createAssertion)

보호를 요청하세요 (createAssertion)
  1. 백엔드가 일회용 payload.
  2. 앱이 createAssertion({ keyId, payload }).
  3. 백엔드가 토큰을 해독하고 requestHash === base64url(SHA256(payload)).
  4. 단일 사용 + TTL을 사용하여 재생 방지 및完整성 판결 정책을 강제합니다.

Android 스키마

Android 스키마
sequenceDiagram
participant App as Android App
participant Plugin as AppAttest plugin
participant PlaySDK as Play Integrity SDK
participant BE as Backend
participant Google as decodeIntegrityToken API
App->>Plugin: prepare(cloudProjectNumber)
Plugin->>PlaySDK: prepareIntegrityToken()
PlaySDK-->>Plugin: provider handle (keyId)
BE->>App: one-time challenge
App->>Plugin: createAttestation(keyId, challenge)
Plugin->>PlaySDK: requestStandardIntegrityToken(requestHash)
PlaySDK-->>Plugin: integrity token
Plugin-->>App: token + platform + format + keyId
App->>BE: token + challenge + keyId
BE->>Google: decodeIntegrityToken(token)
Google-->>BE: decoded payload
BE->>BE: verify requestHash + app identity + verdicts
BE->>App: one-time payload
App->>Plugin: createAssertion(keyId, payload)
Plugin->>PlaySDK: requestStandardIntegrityToken(requestHash)
PlaySDK-->>Plugin: integrity token
App->>BE: token + payload + keyId
BE->>Google: decodeIntegrityToken(token)
Google-->>BE: decoded payload
BE->>BE: verify requestHash + replay policy

최소 백엔드 페이로드 계약

최소 백엔드 페이로드 계약 섹션

등록:

{
"platform": "android",
"format": "google-play-integrity-standard",
"keyId": "string",
"challenge": "string",
"token": "string"
}

보증:

{
"platform": "android",
"format": "google-play-integrity-standard",
"keyId": "string",
"payload": "string",
"token": "string"
}

안드로이드 설정 및 백엔드 확인에서 계속하기

안드로이드 설정 및 백엔드 확인에서 계속하기 섹션

Capgo를 사용하여 안드로이드 설정 및 백엔드 확인 안정성 및 규정 준수 계획을 위해 연결하세요. Capgo @capgo/capacitor-app-attest Capgo native 기능을 사용하는 @capgo/capacitor-app-attest 에 대해 암호화 __CAPGO_KEEP_0__ 구현 세부 정보에 대해 규정 준수 __CAPGO_KEEP_0__ 구현 세부 정보에 대해 Capgo 보안 스캐너 Capgo 보안 스캐너의 제품 워크플로우에 대해, 및 Capgo 보안 Capgo 보안의 제품 워크플로우에 대해