Secure authentication without using HTTPS

В. Ю. Филимошин, Л. З. Давлеткиреева · International journal of open information technologies · 2017

The purpose of this article is to present a secure authentication algorithm for web resources without using HTTPS. The main idea of the algorithm is to avoid transferring a password in open way. So the password is presented to the server hashed and encrypted. If someone manages to intercept and decrypt the password hash, he will receive only a salted password hash and won't be able to receive the initial password. Some implementation results of the algorithm written in PHP are described to demonstrate how to protect the password from being compromised. The article could be useful for web developers.

Read the paper · More papers on PaperTik