authenticating high scores sent from a Java applet

I have written a Java game.  It communicates with a high score server in order to upload and download high scores.

Is there a cryptographic method for ensuring that high scores can be sent only from the applet?  I don't believe this possible, so please only post if you have a positive response!

many thanks,
John Brewer
CJ_SConnect With a Mentor Commented:
In the java applet you can query the current location of the webpage the applet is on. Use the Netscape.JSObject .* import library. (It comes also with IE4 and above).
Then you create a package in your applet, including the current location you just retrieved, and send it to the server. The server then checks whether the current domain (from the location) is the same domain as the server is from.

Depends on the way you send the data. If you send it in a package, you can also add another field containing a variable that it came from the applet. Next to that you can also use an algorithm to make the data unreadable. Hackers can always crack it, for example by grabbing the data being sent and copying it, and then adjusting it. They will also need to know what the package looks like, but that's easily cracked. It's really hard to make something that is truly valid...

johnbrewer1980Author Commented:
CJ S: I already have some encryption to prevent simple cracking, but need a foolproof solution.  I really doubt that there is one, but if anybody's tellin' then i'm listening.  Thanks anyhow
There is no such thing as a fool proof encryption scheme. You just have to balance the amount of time you are willing to spend implementing a scheme with the time someone would be willing to spend trying to crack your scheme.

There is no foolproof scheme as indicated by Z_Beeblebrox. Especially not because the packages you are sending can easily be grabbed and ripped apart. Those packages can then be rebuilt by the user, and send it each and every time.

johnbrewer1980Author Commented:
Okay then, what's the best method for ensuring that nobody monkeys around with the high scores?
Checking the referrer on the server, you should check where the data came from. What kind of server application do you use?
johnbrewer1980Author Commented:
I just use an ASP script.  The java applet communicates via http requests.
Okay, you can check some of the server variables...for example the url the request came from:


here's a full list of servervariables:
> "but need a foolproof solution"

then why?:

> "in order to upload and download high scores."

I understand download "the latest"

I have no clue why anyone would want all clients to perform uploads of information about everybody.

I suggest dumping the upload piece, and use a different process for providing such function (alternative upload, ftp, server-side code (that can be triggered by an event, perhaps from within the applet)) - anything on client is all too hackable.
johnbrewer1980Author Commented:
Well, everybody has to update their highscore.  I can't think of any other way.
Well, scoring managed server side.
How many people per update?
Perhaps some simple mechanism where you only have to ensure one person only gets score updated, and cannot update another. Use of keys, passwords can help control.

Also convoluted scoring mechanism (hard to replicate - which increases level of difficulty in manipulating)

If audience high enough, knock off the ones who try to cheat, with appropriate warnings.  Anything on client has to be considered compromised.

Depending on nature of game, can it be run offline from web/phone/server, it should have as few pieces on client as possible. It should do stuff, then check in with server before doing more. Server tracks progress and checks for cheating.
johnbrewer1980Author Commented:
I'm not sure if any of the above apply, so I'll enlarge on the problem.

The game is a java applet.  Upon finishing a game, the user uploads a highscore and initials.  I just want to help make sure that nobody can just decide to upload an invalid score.

sorry for the confusion (&thanks for the help)
