WoW:Battle.net Mobile Authenticator Specification (source)
Revision as of 04:47, 15 August 2023
, 15 August 2023Move page script moved page Battle.net Mobile Authenticator Specification to WoW:Battle.net Mobile Authenticator Specification without leaving a redirect
(Created page with "{{source needed}} Technical description of the Battle.net Mobile Authenticator protocol: ==Server Communication== ===Authenticator Initialization=== ====Authenticator Init...") |
m (Move page script moved page Battle.net Mobile Authenticator Specification to WoW:Battle.net Mobile Authenticator Specification without leaving a redirect) |
||
| (5 intermediate revisions by 5 users not shown) | |||
| Line 1: | Line 1: | ||
{{Accuracy|Is this still current?}} | |||
{{source needed}} | {{source needed}} | ||
{{webapi}} | |||
Technical description of the [[Battle.net Mobile Authenticator]] protocol: | Technical description of the [[Battle.net Mobile Authenticator]] protocol: | ||
| Line 8: | Line 10: | ||
====Authenticator Initialization Request==== | ====Authenticator Initialization Request==== | ||
Initialization request is an HTTP POST request to | Initialization request is an HTTP POST request to | ||
* ''<nowiki>http://m.eu.mobileservice.blizzard.com/enrollment/enroll.htm</nowiki>'' (Europe) (old) | |||
* ''<nowiki>http://m.us.mobileservice.blizzard.com/enrollment/enroll.htm</nowiki>'' (North America) (old) | |||
* ''<nowiki>http://mobile-service.blizzard.com/enrollment/enroll.htm</nowiki>'' (new) | |||
with Content-type "application/octet-stream". | with Content-type "application/octet-stream". | ||
The plaintext of the request has the following format: | The plaintext of the request has the following format: | ||
{|class="darktable" | {| class="darktable" | ||
|- | |- | ||
!style="width:15%;" align="left"| function code | ! style="width:15%;" align="left" | function code | ||
!style="width:40%;" align="left"| response encryption key | ! style="width:40%;" align="left" | response encryption key | ||
!style="width:15%;" align="left"| region code | ! style="width:15%;" align="left" | region code | ||
!style="width:30%;" align="left"| mobile model | ! style="width:30%;" align="left" | mobile model | ||
|- | |- | ||
| 1 byte | | 1 byte | ||
| Line 41: | Line 44: | ||
19a250fa4cc1278d12855b5b25818d162c6e6ee2ab4a350d401d78f6ddb99711 | 19a250fa4cc1278d12855b5b25818d162c6e6ee2ab4a350d401d78f6ddb99711 | ||
e72626b48bd8b5b0b7f3acf9ea3c9e0005fee59e19136cdb7c83f2ab8b0a2a99 | e72626b48bd8b5b0b7f3acf9ea3c9e0005fee59e19136cdb7c83f2ab8b0a2a99 | ||
(big endian) and the public exponent is "0x101" (257). The resulting 128 encrypted bytes are sent to the server within the HTTP-POST-request. Europe and North America are using the same keys for RSA. | (big endian) and the public exponent is "0x101" (257). The resulting 128 encrypted bytes are sent to the server within the HTTP-POST-request. Europe and North America are using the same keys for RSA. | ||
====Authenticator Initialization Response==== | ====Authenticator Initialization Response==== | ||
The HTTP body of the response has the following format: | The HTTP body of the response has the following format: | ||
{|class="darktable" | {| class="darktable" | ||
|- | |- | ||
!style="width:40%;" align="left"| current server time | ! style="width:40%;" align="left" | current server time | ||
!style="width:60%;" align="left"| encrypted initialization data | ! style="width:60%;" align="left" | encrypted initialization data | ||
|- | |- | ||
| 8 bytes | | 8 bytes | ||
| Line 61: | Line 64: | ||
After decryption the initialization information has the following format: | After decryption the initialization information has the following format: | ||
{|class="darktable" | {| class="darktable" | ||
|- | |- | ||
!style="width:60%;" align="left"| secret key for code calculation | ! style="width:60%;" align="left" | secret key for code calculation | ||
!style="width:40%;" align="left"| authenticator serial number | ! style="width:40%;" align="left" | authenticator serial number | ||
|- | |- | ||
| 20 bytes | | 20 bytes | ||
| Line 70: | Line 73: | ||
|} | |} | ||
;Secret key for code calculation | ;Secret key for code calculation | ||
: Secret key generated by the server for calculation of the authenticator codes. Refer to [[#Code Calculation|code calculation section]] for the usage of this key. The key ''MUST'' be stored within the authenticator as long as it is linked to a Battle.net account and ''MUST'' kept secret. | : Secret key generated by the server for calculation of the authenticator codes. Refer to [[#Code Calculation|code calculation section]] for the usage of this key. The key ''MUST'' be stored within the authenticator as long as it is linked to a Battle.net account and ''MUST'' kept secret. | ||
;Authenticator serial number | ;Authenticator serial number | ||
: Serial number of the authenticator used for linking it to a Battle.net account. It has the format "EU-1234-5678-9012" or "US-1234-5678-9012". The number seems to be simply incremented by the server for every initialization request. There should be no way to calculate the secret key corresponding to this serial number. The serial number ''SHOULD'' be stored together with the secret key. Though it isn't any longer possible to link a single authenticator to more than one Battle.net account at a time<ref>Blizzard Entertainment: Battle.net Blog: [http://us.battle.net/sc2/en/blog/882513 Battle.net Authenticator Change] (Oct 7, 2010)</ref>, but maybe the support will ask for the serial number if there is a problem with the authenticator. | : Serial number of the authenticator used for linking it to a Battle.net account. It has the format "EU-1234-5678-9012" or "US-1234-5678-9012". The number seems to be simply incremented by the server for every initialization request. There should be no way to calculate the secret key corresponding to this serial number. The serial number ''SHOULD'' be stored together with the secret key. Though it isn't any longer possible to link a single authenticator to more than one Battle.net account at a time<ref>Blizzard Entertainment: Battle.net Blog: [http://us.battle.net/sc2/en/blog/882513 Battle.net Authenticator Change] (Oct 7, 2010)</ref>, but maybe the support will ask for the serial number if there is a problem with the authenticator. | ||
| Line 79: | Line 82: | ||
====Authenticator Time Synchronization Request==== | ====Authenticator Time Synchronization Request==== | ||
Synchronization request is simply an HTTP GET request to | Synchronization request is simply an HTTP GET request to | ||
:* ''<nowiki>http://m.eu.mobileservice.blizzard.com/enrollment/time.htm</nowiki>'' (Europe) | :* ''<nowiki>http://m.eu.mobileservice.blizzard.com/enrollment/time.htm</nowiki>'' (Europe) (old) | ||
:* ''<nowiki>http://m.us.mobileservice.blizzard.com/enrollment/time.htm</nowiki>'' (North America) | :* ''<nowiki>http://m.us.mobileservice.blizzard.com/enrollment/time.htm</nowiki>'' (North America) (old) | ||
:* ''<nowiki>http://mobile-service.blizzard.com/enrollment/time.htm</nowiki>'' (new) | |||
====Authenticator Time Synchronization Response==== | ====Authenticator Time Synchronization Response==== | ||
The HTTP body of the response has the following format: | The HTTP body of the response has the following format: | ||
{|class="darktable" | {| class="darktable" | ||
|- | |- | ||
!align="left"| current server time | ! align="left" | current server time | ||
|- | |- | ||
| 8 bytes | | 8 bytes | ||
|} | |} | ||
;Current server time | ;Current server time | ||
: Milliseconds since midnight, January 1, 1970 UTC (like | : Milliseconds since midnight, January 1, 1970 UTC (like returned by System.currentTimeMillis() in Java), big endian format. | ||
| Line 132: | Line 136: | ||
{{elink|site=Google.com|link=http://webcache.googleusercontent.com/search?q=cache:_jPFKes8ymMJ:bnetauth.freeportal.us/+bnetauth&cd=2&hl=en&ct=clnk&gl=us&client=firefox-a&source=www.google.com|desc=Web cache of defunct <tt>bnetauth.freeportal.us</tt>}} | {{elink|site=Google.com|link=http://webcache.googleusercontent.com/search?q=cache:_jPFKes8ymMJ:bnetauth.freeportal.us/+bnetauth&cd=2&hl=en&ct=clnk&gl=us&client=firefox-a&source=www.google.com|desc=Web cache of defunct <tt>bnetauth.freeportal.us</tt>}} | ||
{{elink|site=github.com|link=https://github.com/Adys/python-bna|desc=Code for open source python implementation of authenticator}} | {{elink|site=github.com|link=https://github.com/Adys/python-bna|desc=Code for open source python implementation of authenticator}} | ||
[[Category: | {{elink|site=github.com|link=https://github.com/krtek4/php-bma|desc=Code for open source PHP implementation of authenticator}} | ||
[[Category:Web API]] | |||