Android™ Requires Chilkat v11.6.0+
Android™
Verify a Password against an Argon2 Hash
Demonstrates Crypt2.Argon2VerifyPassword, which verifies a password against a PHC-format Argon2 hash string. The cost parameters are read from the hash string, so none need to be supplied.
Background. The method returns an integer:
1 if the password matched, 0 if it did not match, and -1 if the verification could not be performed at all (the hash string was invalid, its parameters were out of range, or an internal failure occurred, with the reason in LastErrorText). Always test for a match with == 1, never with != 0.Chilkat Android™ Downloads
// Important: Don't forget to include the call to System.loadLibrary
// as shown at the bottom of this code sample.
package com.test;
import android.app.Activity;
import com.chilkatsoft.*;
import android.widget.TextView;
import android.os.Bundle;
public class SimpleActivity extends Activity {
private static final String TAG = "Chilkat";
// Called when the activity is first created.
@Override
public void onCreate(Bundle savedInstanceState) {
super.onCreate(savedInstanceState);
CkCrypt2 crypt = new CkCrypt2();
// The password should come from a secure source rather than being hard-coded.
String password = "correct horse battery staple";
// A PHC-format Argon2 hash string previously produced by Argon2HashPassword. All cost options
// (variant, version, memory cost, iterations, parallelism, salt, hash length) are read from this
// string, so none need to be supplied.
String phcHash = "$argon2id$v=19$m=65536,t=3,p=1$c29tZXJhbmRvbXNhbHQ$3fJ7v1qKcVJ0lHqXjBQZ8mYm3sNTfSPRt0bqDl9kEyM";
// Verify the password. Pass an empty options string when no secret (pepper) or ad was used.
// The method returns one of three values: 1 = the password matched, 0 = it did not match, and
// -1 = the verification could not be performed (the hash string was invalid or unusable).
// Always test for a match with == 1.
int verifyResult = crypt.Argon2VerifyPassword(password,"",phcHash);
if (verifyResult == 1) {
Log.i(TAG, "The password is verified.");
}
else {
if (verifyResult == 0) {
Log.i(TAG, "The password does not match.");
}
else {
Log.i(TAG, "The verification could not be performed: " + crypt.lastErrorText());
}
}
}
static {
System.loadLibrary("chilkat");
// Note: If the incorrect library name is passed to System.loadLibrary,
// then you will see the following error message at application startup:
//"The application <your-application-name> has stopped unexpectedly. Please try again."
}
}