3 ms·
The only secure way of doing it is to somehow crypotgraphically sign it. You'd have to trade that DB lookup with CPU cycles for a signature validation. For ex
by borplk 4y ago
The only secure way of doing it is to somehow crypotgraphically sign it.
You'd have to trade that DB lookup with CPU cycles for a signature validation.
For example you can use HMAC.
You send the UUID and HMAC-of-UUID to the client.
The client sends back UUID + HMAC-of-UUID.
You re-calculate HMAC-of-UUID-provided-by-client (using your secret key).
If the calculated HMAC matches the HMAC provided by the client you have confirmation that the UUID was issued by you. Because without the secret key the client can't calculate the correct HMAC for a random or modified UUID.