Solved

Creating an online activation system

Posted on 2006-07-03
10
223 Views
Last Modified: 2012-05-05
Hi, I want to implement an online activation system for my application. I want to write it myself so I have full control over changing it, if it gets hacked etc.

My application is a Windows app. The user will click a button, and an encrypted string will be sent to my web app, which will decrypt it and then lookup the data in a database and then send an encrypted string back to the sender. The windows end is no problem, it's the web app where I need advice. I am not sure what technologies to use to achieve this. I want it to be as secure as possible to limit hacking. I was thinking of writing a web service (soap server) as the web app. Would this be the best way to go?

Also, the database? This will have about 30 thousand records initially and it needs to be secure. Would MySQL be a good option?

I am most familiar with Delphi 7, but I can easily adapt to any other language.

Thanks. Best regards,
Gary
0
Comment
Question by:GaryHandley
10 Comments
 
LVL 12

Accepted Solution

by:
Ivanov_G earned 84 total points
ID: 17033525
Web Service is good enough. Maybe you can think of XML parameters (encrypted of course)

<REQ>
  <LICENCE>asjdfh120949asjlhfjakl</LICENCE>
  <DATE>....</DATE>
</REQ>

and the response in similar way.

MySQL does not offer a consistensy with all the needed feature in development phrase. You can have a look at PostgreSQL - it is more like a real database - triggers, transactions, etc ... and syntax similar to PL/SQL. One disadvantage is if you have Full-Text-Search which is faster in MySQL
0
 
LVL 3

Assisted Solution

by:Ubethatway
Ubethatway earned 83 total points
ID: 17034697
The simplest option, IMO, would simple be to use a TCP connection to pass the encryped string. As long as you have your DB server behind a firewall, and its access is restricted to your server app, then security shouldnt be an issue. Also, i would have thought that if you passed the right information to the server app in your encrypted string, you wouldnt need a full-text-search (if you set up you primary keys properly etc).

Hope that helps, Mark
0
 
LVL 17

Assisted Solution

by:TheRealLoki
TheRealLoki earned 83 total points
ID: 17047930
any HTTP server that supports SSL is fine.
even Indy has a demo that does this (there is also just a simple Indy TCP SSL demo)
http://www.indyproject.org/Sockets/Demos/index.en.aspx
At the server end, you can use whatever you want. mysql will be fine for this.
0
Free Tool: Port Scanner

Check which ports are open to the outside world. Helps make sure that your firewall rules are working as intended.

One of a set of tools we are providing to everyone as a way of saying thank you for being a part of the community.

 

Expert Comment

by:BlakeyUK
ID: 17269588
Hi,

I had a similar question a short time ago and a person called Workshop Alex gave me an excellent and detailed explanation of options available.

It may help you.

http://www.experts-exchange.com/Programming/Programming_Languages/Delphi/Q_21936302.html#17224561

Best Regards
Blake

0
 

Expert Comment

by:GaryBytes
ID: 18265414
Hi, the question has not been answered, but please split the points between Ivanov_G , Ubetthatway and BlakeUK.

There are no options for me to accept answers, perhaps because the question is old.

Gary
0
 
LVL 14

Expert Comment

by:cwwkie
ID: 18269480
0
 

Expert Comment

by:GaryBytes
ID: 18274661
If you want to ask a question about my account please e-mail me directly.
Gary
0
 

Expert Comment

by:GaryBytes
ID: 18290918
If anyone is reading the solution to this, please ignore the accepted answer. "cwwkie" ignored my request on points spread, so it is misleading. In fact this thread should be deleted as it will likely put people on the wrong track if they have a similar issue.

Gary
0

Featured Post

Free Tool: ZipGrep

ZipGrep is a utility that can list and search zip (.war, .ear, .jar, etc) archives for text patterns, without the need to extract the archive's contents.

One of a set of tools we're offering as a way to say thank you for being a part of the community.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

Title # Comments Views Activity
How to convert wav to mp3 in delphi 9 221
code issue 8 153
Can Viruses spread while transferring Binary data with Winsock 2 86
Dev express lookupcombo 3 34
Objective: - This article will help user in how to convert their numeric value become words. How to use 1. You can copy this code in your Unit as function 2. than you can perform your function by type this code The Code   (CODE) The Im…
Creating an auto free TStringList The TStringList is a basic and frequently used object in Delphi. On many occasions, you may want to create a temporary list, process some items in the list and be done with the list. In such cases, you have to…
This video shows how to quickly and easily add an email signature for all users on Exchange 2016. The resulting signature is applied on a server level by Exchange Online. The email signature template has been downloaded from: www.mail-signatures…
Finds all prime numbers in a range requested and places them in a public primes() array. I've demostrated a template size of 30 (2 * 3 * 5) but larger templates can be built such 210  (2 * 3 * 5 * 7) or 2310  (2 * 3 * 5 * 7 * 11). The larger templa…

808 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question