Client to Server Authentication in C++ using sockets

Viewed 23442

I'm implementing a login/authentication system for my little server-client program. I'm wondering how to go about this, and I was hoping to get some great tips/advice from Stack Overflow as always. This is how I imagine I'll do it.

  • Client connects to the server.
  • Server sends a 'token' to the Client (based on time probably and whatever)
  • Client returns the username and a sha1 encrypted password, along with the token.
  • Server receives them and authenticates the user to the credentials in the server-side database.
  • The token is now verified and the user is signed in with the token.

Is this at all a secure way of doing it? I figured the client also sends a serial key or some such to form a serial / token pair, so that another client cannot fake the same token (though the token is generated by the server-side).

Implementation details aren't required, as I am capable of doing the implementation.

My question would, rather, two questions:

  • What ways are there to achieve a login/authentication system with sockets
  • What ways are there to secure my client-to-server connection
  • EDIT: I forgot to ask, as this is a C++ question, are there any libraries that can assist in encryption/authentication?

Security is an issue for me, so I want to be sure I do it right.

Maybe some background information. It's a game server, a person logs in with his account and is taken to a 'Lobby', where he can pick a 'World Server' to play on. The world server is a separate process running (possibly) on a different machine in the same network.

For that reason, I want to have a concept of a session in this, the user logs in and a session is generated, the login server relays the session to the world server the user picks, so that world server knows that the user is actually logged in.

I reckon the client will have to confirm the session to the world server and all that, but I'll worry about that later.

Sincerely, Jesse

2 Answers
Related