What is UserSig?
UserSig is a security signature designed by Tencent Cloud to prevent attackers from accessing your Tencent Cloud account.
Currently, Tencent Cloud services including TRTC, Chat, and MLVB all use this security mechanism. To use these services, you must pass in three parameters - SDKAppID, UserID, and UserSig - to the initialization or login API of the corresponding SDK.
SDKAppID identifies an application.
UserID identifies a user.
UserSig is a security signature generated based on SDKAppID and UserID using the HMAC SHA256 encryption algorithm. Attackers cannot use your Tencent Cloud traffic as long as they don’t have UserSig.
Generate UserSig for Demo Run
Generate UserSig on Client Side
1. Get the SDKAppID and SDKSecretKey
1. Sign in to the TRTC console.
2. Find your application or create a new one.
3. Copy the SDKAppID and SDKSecretKey on Basic Information. 2. Generate UserSig
We offer source code for generating UserSig on different platforms.
|
Web | | TRTC_Web/quick-demo-js/js/libs/generateTestUserSig.js |
iOS | | TRTC-API-Example-OC/Debug/GenerateTestUserSig.h |
macOS | | OCDemo/TRTCDemo/TRTC/GenerateTestUserSig.h |
Android | | TRTC-API-Example/Debug/src/main/java/com/tencent/trtc/debug/GenerateTestUserSig.java |
Windows (C++) | | TRTC-API-Example-C++/TRTC-API-Example-Qt/src/Util/defs.h |
Windows (C#) | | TRTC-API-Example-CSharp/TRTC-API-Example-CSharp/GenerateTestUserSig.cs |
Flutter | | TRTC-API-Example/lib/Debug/GenerateTestUserSig.dart |
We provide an open-source module called GenerateTestUserSig
in the TRTC SDK sample code. Set the three member variables of SDKAPPID, EXPIRETIME, and SDKSECRETKEY, and you will be able to call genTestUserSig()
to generate the UserSig and get started quickly.
Generate UserSig on TRTC Console
2. Select your application (SDKAppID) from the drop-down list. A SDKSecretKey will be generated automatically.
3. Input a UserID and click Generate.
Caution
Client-side UserSig generation is only suitable for debugging and demo scenarios. It’s not recommended for official launch because, when you include your SDKSecretKey in the client code (especially on the web), it can be easily decompiled and reversed engineered. If your key is leaked, attackers can steal your Tencent Cloud traffic.
The correct method is to deploy the UserSig generation code on your project server so that your application can request from your server a UserSig that is generated whenever one is needed.
Generate UserSig on Server Side for Production Environment
In a production environment, server-side UserSig generation offers stronger protection against key leakage because it is more difficult to hack a server than it is to reverse engineer an application. See below for detailed steps:
1. Before your application calls the initialization API of the SDK, request UserSig from your server.
2. Your server will generate a UserSig based on the SDKAppID, SDKSecretKey and UserID using the server code in the table below.
3. The server returns the UserSig to your application.
4. Your application sends the UserSig to the SDK through a specific API.
5. The SDK submits the SDKAppID, UserID and UserSig to the Tencent Cloud server for verification.
6. Tencent Cloud verifies the validity of the UserSig.
7. If the UserSig is valid, services will be provided to the TRTC SDK.
To simplify your implementation process, we provide UserSig
generation source code (new algorithm) in multiple languages.
|
Java | HMAC-SHA256 | | |
GO | HMAC-SHA256 | | |
PHP | HMAC-SHA256 | | |
Node.js | HMAC-SHA256 | | |
Python | HMAC-SHA256 | | |
C# | HMAC-SHA256 | | |
UserSig Generation Source Code Using the Legacy Algorithm
To simplify the signature genertaion process and facilitate your use of Tencent Cloud services, on July 19, 2019, TRTC switched from ECDSA-SHA256 to the new signature algorithm HMAC-SHA256. This means that all applications (SDKAppID) created on and after July 19, 2019 will use the new HMAC-SHA256 algorithm.
If your application (SDKAppID) was created before July 19, 2019, you can continue to use the old signature algorithm, whose source code can be downloaded below.
|
Java | ECDSA-SHA256 | |
C++ | ECDSA-SHA256 | |
GO | ECDSA-SHA256 | |
PHP | ECDSA-SHA256 | |
Node.js | ECDSA-SHA256 | |
C# | ECDSA-SHA256 | |
Python | ECDSA-SHA256 | |
Was this page helpful?