Can you elaborate?
A typical way to do this is to use TLS, verify certificates, and have a password for the client.
https://en.wikipedia.org/wiki/Fallacies_of_distributed_compu...
(But of course these fallacies are so well known exactly because programmers have proven their inability to reliably internalize them...)