DeviceCheck 框架 | Apple 开发者文档 原文标题:DeviceCheck | Apple Developer Documentation
内容概要总结
Apple 官方 DeviceCheck 框架总览页。DeviceCheck 由两部分组成:一是可从 App 内访问的框架接口,二是从你自己的服务器访问的 Apple 服务器接口。
在 App 中使用 DCDevice 类可获得一个令牌(token),该令牌用于在你的服务器上为每台设备设置和查询两个二进制位(two binary digits)的数据,同时保持用户隐私。例如可用它来识别已经使用过你所提供促销优惠的设备,或标记你判定为欺诈的设备。服务器到服务器(server-to-server)API 还能验证你收到的令牌确实来自 Apple 设备上你的 App。
App Attest 服务则用于应对被篡改后经 App Store 之外渠道分发的 App(可能加入游戏作弊、去广告、解锁付费内容等未授权功能):通过 DCAppAttestService 类在设备上生成一个特殊密码学密钥,并由 Apple 为该密钥的有效性作证,随后每次向服务器请求敏感数据时都可用该密钥来断言 App 的有效性。
文档强调:没有任何单一策略能消除所有欺诈,例如 App Attest 无法确切地指认一台操作系统已被攻陷的设备;DeviceCheck 服务提供的是可纳入整体风险评估的信息。
翻译内容
原文内容(English)
框架(Framework)
DeviceCheck
通过管理设备状态并断言 App 完整性,减少你的服务被欺诈性使用。
支持平台:iOS 11.0+、iPadOS 11.0+、Mac Catalyst 11.0+、macOS 10.15+、tvOS 11.0+、visionOS 1.0+、watchOS 9.0+
概述(Overview)
DeviceCheck 服务由两部分组成:一部分是你从 App 中访问的框架接口,另一部分是你从自己的服务器访问的 Apple 服务器接口。
在你的 App 中使用 DCDevice 类,你可以获得一个令牌(token),用于在你的服务器上为每台设备设置和查询两个二进制位(two binary digits)的数据,同时保持用户隐私。例如,你可能会用这些数据来识别已经使用过你所提供的促销优惠的设备,或标记你已判定为欺诈的设备。服务器到服务器(server-to-server)API 还允许你验证所收到的令牌确实来自 Apple 设备上你的 App。
有人可能修改你的 App 并在 App Store 之外分发,从而加入未授权的功能,例如游戏作弊、去除广告或访问付费内容。App Attest 服务为你的 App 提供了一种断言自身有效性的方式,使你的服务器能够更有把握地对敏感资源授予访问权限。你使用 DCAppAttestService 类在设备上生成一个特殊的密码学密钥,并让 Apple 为该密钥的有效性作证。之后,每当你向服务器请求敏感数据时,你都可以用该密钥来断言 App 的有效性。
没有任何单一策略能够消除所有欺诈。例如,App Attest 无法确切地指认一台操作系统已被攻陷的设备。相反,DeviceCheck 服务提供的是你可以纳入对某台设备整体风险评估的信息。
主题(Topics)
设备识别(Device identification)
- 访问和修改按设备存储的数据(Accessing and modifying per-device data) —— 使用来自你 App 的令牌,在 Apple 服务器上查询和修改每台设备两个二进制位的数据。
class DCDevice—— 对设备的一种表示,提供一个唯一的、经过认证的令牌。
App Attest
- 建立你 App 的完整性(Establishing your app’s integrity) —— 确保你的服务器收到的请求来自你 App 的合法实例。
- 验证连接到你的服务器的 App(Validating apps that connect to your server) —— 验证连接到你的服务器的连接来自你 App 的合法实例。
- 评估欺诈风险(Assessing fraud risk) —— 使用服务器到服务器的调用请求并分析风险数据。
- 准备使用 App Attest 服务(Preparing to use the app attest service) —— 在开发环境中测试你的实现,并逐步引导用户接入。
- Attestation 对象验证指南(Attestation Object Validation Guide) —— 使用本指南验证你对 attestation 对象验证流程的实现是否正确。
class DCAppAttestService—— 用于验证设备上运行着你 App 的实例的服务。- App Attest 环境(App Attest Environment) —— 使用 App Attest 服务来自我验证的 App 所处的环境。
错误(Errors)
struct DCError—— 表示 DeviceCheck 遇到错误时的类型。enum Code—— DeviceCheck 错误码。let DCErrorDomain: String—— 与 DeviceCheck API 相关错误的错误域。
Skip Navigation
Get Started
Platforms
Technologies
Community
Documentation
Downloads
Support
Sign in
Documentation
Swift
Language:
Swift
Objective-C
All Technologies
DeviceCheck
Device identification
Accessing and modifying per-device data
C
DCDevice
App Attest
Establishing your app’s integrity
Validating apps that connect to your server
Assessing fraud risk
Preparing to use the app attest service
Attestation Object Validation Guide
C
DCAppAttestService
T
App Attest Environment
Errors
S
DCError
E
DCError.Code
V
let DCErrorDomain: String
15 items were found. Tab back to navigate through them.
/
Navigator is ready
Framework
DeviceCheck
Reduce fraudulent use of your services by managing device state and asserting app integrity.
iOS 11.0+
iPadOS 11.0+
Mac Catalyst 11.0+
macOS 10.15+
tvOS 11.0+
visionOS 1.0+
watchOS 9.0+
Overview
The DeviceCheck services consist of both a framework interface that you access from your app and an Apple server interface that you access from your own server.
Using the DCDevice class in your app, you can get a token that you use on your server to set and query two binary digits of data per device, while maintaining user privacy. For example, you might use this data to identify devices that have already taken advantage of a promotional offer that you provide, or to flag a device that you’ve determined to be fraudulent. The server-to-server APIs also let you verify that the token you receive comes from your app on an Apple device.
Someone who modifies your app and distributes it outside the App Store can add unauthorized features like game cheats, ad removal, or access to premium content. The App Attest service gives your app a way to assert its validity so that your server can more confidently provide access to sensitive resources. You use the DCAppAttestService class to generate a special cryptographic key on the device, and have Apple attest to the validity of that key. You then use that key to assert the validity of your app whenever you request sensitive data from your server.
No single policy can eliminate all fraud. For example, App Attest can’t definitively pinpoint a device with a compromised operating system. Instead, the DeviceCheck services provide information that you can integrate into an overall risk assessment for a given device.
Topics
Device identification
Accessing and modifying per-device data
Use a token from your app to query and modify two per-device binary digits stored on an Apple server.
class DCDevice
A representation of a device that provides a unique, authenticated token.
App Attest
Establishing your app’s integrity
Ensure that requests your server receives come from legitimate instances of your app.
Validating apps that connect to your server
Verify that connections to your server come from legitimate instances of your app.
Assessing fraud risk
Request and analyze risk data using server-to-server calls.
Preparing to use the app attest service
Test your implementation in a development environment and onboard users gradually.
Attestation Object Validation Guide
Use this guide to validate your implementation of verifying the attestation object verification process.
class DCAppAttestService
A service that you use to validate the instance of your app running on a device.
App Attest Environment
The environment for an app that uses the App Attest service to validate itself.
Errors
struct DCError
A type that indicates when DeviceCheck encounters an error.
enum Code
DeviceCheck error codes.
let DCErrorDomain: String
The error domain for errors associated with DeviceCheck APIs.
Current page is DeviceCheck
Apple
Developer
Documentation
Platforms
iOS
iPadOS
macOS
tvOS
visionOS
watchOS
Tools
Swift
SwiftUI
Swift Playground
TestFlight
Xcode
Xcode Cloud
SF Symbols
Topics & Technologies
Accessibility
Accessories
App Extension
App Store
Audio & Video
Augmented Reality
Design
Distribution
Education
Fonts
Games
Health & Fitness
In-App Purchase
Localization
Maps & Location
Machine Learning & AI
Open Source
Security
Safari & Web
Resources
Documentation
Tutorials
Downloads
Forums
Videos
Support
Support Articles
Contact Us
Bug Reporting
System Status
Account
Apple Developer
App Store Connect
Certificates, IDs, & Profiles
Feedback Assistant
Programs
Apple Developer Program
Apple Developer Enterprise Program
App Store Small Business Program
MFi Program
News Partner Program
Video Partner Program
Security Bounty Program
Security Research Device Program
Events
Meet with Apple
Apple Developer Centers
App Store Awards
Apple Design Awards
Apple Developer Academies
WWDC
To submit feedback on documentation, visit Feedback Assistant.
Select a color scheme preference
Light
Dark
Auto
English
简体中文
日本語
한국어
Español
Deutsch
Français
Italiano
Português
Copyright © 2026 Apple Inc. All rights reserved.Terms of UsePrivacy PolicyAgreements and Guidelines