This repository was archived by the owner on Apr 25, 2023. It is now read-only.
-
Notifications
You must be signed in to change notification settings - Fork 3
Expand file tree
/
Copy pathindex.html
More file actions
223 lines (189 loc) · 9.67 KB
/
Copy pathindex.html
File metadata and controls
223 lines (189 loc) · 9.67 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
142
143
144
145
146
147
148
149
150
151
152
153
154
155
156
157
158
159
160
161
162
163
164
165
166
167
168
169
170
171
172
173
174
175
176
177
178
179
180
181
182
183
184
185
186
187
188
189
190
191
192
193
194
195
196
197
198
199
200
201
202
203
204
205
206
207
208
209
210
211
212
213
214
215
216
217
218
219
220
221
222
223
<html lang="en">
<head>
<meta charset="utf-8">
<meta http-equiv="X-UA-Compatible" content="IE=edge">
<meta name="viewport" content="width=device-width, initial-scale=1">
<!-- The above 3 meta tags *must* come first in the head; any other head content must come *after* these tags -->
<title>SRP PHP Test</title>
<!-- Bootstrap -->
<link rel="stylesheet" href="https://maxcdn.bootstrapcdn.com/bootstrap/3.3.7/css/bootstrap.min.css" integrity="sha384-BVYiiSIFeK1dGmJRAkycuHAHRg32OmUcww7on3RYdg4Va+PmSTsz/K68vbdEjh4u" crossorigin="anonymous">
<!-- HTML5 shim and Respond.js for IE8 support of HTML5 elements and media queries -->
<!-- WARNING: Respond.js doesn't work if you view the page via file:// -->
<!--[if lt IE 9]>
<script src="https://oss.maxcdn.com/html5shiv/3.7.3/html5shiv.min.js"></script>
<script src="https://oss.maxcdn.com/respond/1.4.2/respond.min.js"></script>
<![endif]-->
<style type="text/css">
.doc_row {
margin-bottom: 20px;
}
.doc_row .col-sm-6 {
background-color: #eee;
border: 1px solid #ccc;
padding-top: 10px;
padding-bottom: 10px;
}
.doc_row .col-sm-12 {
border: 1px solid #ccc;
padding-top: 10px;
padding-bottom: 10px;
}
</style>
</head>
<body>
<div class="jumbotron">
<div class="container">
<h1>SRP Server (PHP) and Client (PHP, JS)</h1>
<p>Javascript Client and PHP Server/Client for Login over Secure Remote Password Protocol</p>
</div>
</div>
<div class="container">
A php and Javascript implementation of the <a href="http://srp.stanford.edu/design.html" target="_blank">secure-remote-passowrd protocol</a>.<br/>
It follows a protocol diagram is based on the functions of this project:<br/>
<a target="_blank" href="images/srp.pdf"><img src="images/srp.svg" class="img-responsive"></a>
</div>
<div class="container">
<h2>Classes</h2>
<h3>PHP</h3>
<code>require './php/lib/srp.php';<br/>$srp = new srp();</code><br/>
<h3>Javascript</h3>
<code><script type="text/javascript" src="js/vendor/bigint.js"></script><br/>
<script type="text/javascript" src="js/vendor/sha256.js"></script><br/>
<script type="text/javascript" src="js/srp.js"></script><br/>
<script type="text/javascript"><br/>
var srp = new srp();<br/>
</script>
</code>
<h3>Functions</h3>
<p>
the php and the javscript srp-Objects provides the same functions in a equal way.
</p>
<h4>Client functions</h4>
<div class="row doc_row">
<div class="col-sm-6">
generate Private key
</div>
<div class="col-sm-6">
generateX(s, username, password)
</div>
<div class="col-sm-12">
generate the clint Private key by a radom seed ('s' generate over getRandomSeed-method) and the user credentials ('username' and 'password')
</div>
</div>
<div class="row doc_row">
<div class="col-sm-6">
generate Password verifier
</div>
<div class="col-sm-6">
generateV(x)
</div>
<div class="col-sm-12">
generate the Password verifier by the private Key X. (s and V are send and stored by the server)
</div>
</div>
<div class="row doc_row">
<div class="col-sm-6">
generate Public ephemeral values
</div>
<div class="col-sm-6">
generateA(a)
</div>
<div class="col-sm-12">
generate the Public ephemeral value A by the private value 'a' ('a' generate over getRandomSeed-method)
</div>
</div>
<div class="row doc_row">
<div class="col-sm-6">
generate Session Key
</div>
<div class="col-sm-6">
generateS_Client(A, B, a, x)
</div>
<div class="col-sm-12">
generate the Session Key for the authentification
</div>
</div>
<h4>Shared functions (for client and server)</h4>
<div class="row doc_row">
<div class="col-sm-6">
generate random seed
</div>
<div class="col-sm-6">
getRandomSeed(length = 0)
</div>
<div class="col-sm-12">
generate a Randum Number. By default length 128 Bit
</div>
</div>
<div class="row doc_row">
<div class="col-sm-6">
generate auth Matcher1
</div>
<div class="col-sm-6">
generateM1(A, B, S)
</div>
<div class="col-sm-12">
generated by client to send so server for authentification.
Server use this method to rebuild and verify receive M1.
</div>
</div>
<div class="row doc_row">
<div class="col-sm-6">
generate auth Matcher2
</div>
<div class="col-sm-6">
generateM2(A, M1, S)
</div>
<div class="col-sm-12">
generated by server to send so client for authentification.
Client use this method to rebuild and verify receive M2.
</div>
</div>
<div class="row doc_row">
<div class="col-sm-6">
generate the shared secred session-Key
</div>
<div class="col-sm-6">
generateK(S)
</div>
<div class="col-sm-12">
generate the shared secred session-Key by the S value
</div>
</div>
<h4>Server functions</h4>
<div class="row doc_row">
<div class="col-sm-6">
generate Public ephemeral values
</div>
<div class="col-sm-6">
generateB(b, v)
</div>
<div class="col-sm-12">
generate the Public ephemeral value B by the private value b (b generate over getRandomSeed-method) and the Password verifier.
</div>
</div>
<div class="row doc_row">
<div class="col-sm-6">
generate Session key
</div>
<div class="col-sm-6">
generateS_Server(A, B, b, v)
</div>
<div class="col-sm-12">
generate the Session Key fpr the authentification
</div>
</div>
</div>
<div class="container">
<h2>Examples</h2>
<ul>
<li>A simple Javascript Client vor registration and login (<a target="_blank" href="client.html">Demo</a> | <a target="_blank" href="https://raw.githubusercontent.com/falkmueller/srp/master/client.html">Source</a>)</li>
<li>A simple PHP Client vor registration and login (<a target="_blank" href="client.php">Demo</a> | <a target="_blank" href="https://raw.githubusercontent.com/falkmueller/srp/master/client.php">Source</a>)</li>
<li>A demo PHP Login Server (only for example, store Data only temporary in Session) (<a target="_blank" href="https://raw.githubusercontent.com/falkmueller/srp/master/server.php">Source</a>)</li>
<li>A PHP Test Script with all functions in use (<a target="_blank" href="https://raw.githubusercontent.com/falkmueller/srp/master/test.php">Source</a>)</li>
<li>A js Test Script with all functions in use (<a target="_blank" href="https://raw.githubusercontent.com/falkmueller/srp/master/test.html">Source</a>)</li>
</ul>
</div>
<a href="https://github.com/falkmueller/srp" target="_blank" class="github-corner" aria-label="View source on Github"><svg width="80" height="80" viewBox="0 0 250 250" style="fill:#70B7FD; color:#fff; position: absolute; top: 0; border: 0; right: 0;" aria-hidden="true"><path d="M0,0 L115,115 L130,115 L142,142 L250,250 L250,0 Z"></path><path d="M128.3,109.0 C113.8,99.7 119.0,89.6 119.0,89.6 C122.0,82.7 120.5,78.6 120.5,78.6 C119.2,72.0 123.4,76.3 123.4,76.3 C127.3,80.9 125.5,87.3 125.5,87.3 C122.9,97.6 130.6,101.9 134.4,103.2" fill="currentColor" style="transform-origin: 130px 106px;" class="octo-arm"></path><path d="M115.0,115.0 C114.9,115.1 118.7,116.5 119.8,115.4 L133.7,101.6 C136.9,99.2 139.9,98.4 142.2,98.6 C133.8,88.0 127.5,74.4 143.8,58.0 C148.5,53.4 154.0,51.2 159.7,51.0 C160.3,49.4 163.2,43.6 171.4,40.1 C171.4,40.1 176.1,42.5 178.8,56.2 C183.1,58.6 187.2,61.8 190.9,65.4 C194.5,69.0 197.7,73.2 200.1,77.6 C213.8,80.2 216.3,84.9 216.3,84.9 C212.7,93.1 206.9,96.0 205.4,96.6 C205.1,102.4 203.0,107.8 198.3,112.5 C181.9,128.9 168.3,122.5 157.7,114.1 C157.9,116.9 156.7,120.9 152.7,124.9 L141.0,136.5 C139.8,137.7 141.6,141.9 141.8,141.8 Z" fill="currentColor" class="octo-body"></path></svg></a>
</body>
</html>