bcrypt
Sign in to savebcrypt is a password-hashing function designed by Niels Provos and David Mazières. It is based on the Blowfish cipher and presented at USENIX in 1999. Besides incorporating a salt to protect against rainbow table attacks, bcrypt is an adaptive function: over time, the iteration count can be increased to make it slower, so it remains resistant to brute-force search attacks even with increasing computation power.
Key facts
- Cryptographic hash function.name
- bcrypt
- Cryptographic hash function.designers
- Niels Provos, David Mazières
- Cryptographic hash function.publish date
- 1999
- Cryptographic hash function.derived from
- Blowfish (cipher)
- Cryptographic hash function.digest size
- 184 bits
- Cryptographic hash function.rounds
- variable via cost parameter
via Wikipedia infobox
Described at
bcrypt.dvi
usenix.org →playanimportantroleinthevastmajorityofuser- authenticationsystems. Thispaperdiscusseswaysofbuildingsystemsin whichpasswordsecuritykeepsupwithhardware speeds.Wepresenttwoalgorithmswithadaptable cost eksblow sh,ablockcipherwithapurposefully expensivekeyschedule,andbcrypt,arelatedhash function.Failingamajorbreakthroughincomplex- itytheory,thesealgorithmsshouldallowpassword- basedsystemstoadapttohardwareimprovements andremainsecure20yearsintothefuture. Therestofthepaperisorganizedasfollows.In Section2,wediscussrelatedworkonpasswordsecu- rity.InSection3,weexplaintherequirementsfora goodpasswordscheme.Section4presentseksblow- sh,a64-bitblockcipherthatletsuserstunethe costofthekeyschedule.Section5introducesthe variable-costbcryptpasswordhashingfunctionand describesourimplementationintheOpenBSDop- eratingsystem.Finally,Section6comparesbcrypt totwowidely-usedpasswordhashingfunctions. 2RelatedWork Passwordguessingattackscanbecategorizedby theamountofinteractiontheyrequirewithanau- thenticationsystem.Inon-lineattacks,theperpe- tratormustmakeuseofanauthenticationsystem tocheckeachguessofapassword.Ino -lineat- tacks,anattackerobtainsinformation suchasa passwordhash thatallowshimtocheckpassword guessesonhisown,withnofurtheraccesstothe system.On-lineattacksaregenerallyconsiderably slowerthano -lineones.Systemscandetecton- lineattacksfairlyeasilyanddefendagainstthemby slowingtherateofpasswordchecking.Incontrast, onceanattackerhasobtainedpasswordveri cation information,theonlyprotectionasystemhasfrom o -lineattacksisthecomputationalcostofchecking potentialpasswords. Techniquesformitigatingthethreatofo -linepass- wordguessinggenerallyaspiretooneoftwogoals limitingasystem& 39;ssusceptibilitytoo -lineattacks orincreasingtheircomputationalcost.Asasimple exampleoftheformer,manymodernUNIXsystems nowkeeppasswordhashessecretfromusers,stor- ingtheminaread-protectedshadowpassword le ratherthaninthestandardopenlyreadableone. Muchoftheworkonpreventingo -linepassword attackshascenteredaroundcommunicationover insecurenetworks.Ifcryptographicprotocolsrely onuser-chosenpasswordsaskeys,theymayopen themselvesuptoo -lineguessingattacks.Gong et.al.[7]suggestseveralprotocoldesigntricksto thwartpasswordguessingbynetworkattackers.Un- fortunately,theirmostinterestingproposalsrequire encryptionalgorithmswithunusualanddicultto achieveproperties. Severalpeoplehavedesignedsecurepasswordpro- tocolsthatletusersauthenticatethemselvesover insecurenetworkswithouttheneedtorememberor certifypublickeys.BellovinandMerritt[2,3] rst proposedtheidea,givingseveralconcreteproto- colsputativelyresistanttoo -lineguessingattacks. Patel[11]latercryptanalyzedthoseprotocols,but peoplehavesincecontinueddevelopingandre ning othersinthesamevein.Morerecentproposalssuch asSRP[16]showpromiseofbeingsecure. Ofcourse,evenasecurepasswordprotocolrequires someservercapableofvalidatinguserswithcorrect passwords.Anattackerwhoobtainsthatserver& 39;s secretstatecanmountano -lineguessingattack. Becausesecurepasswordprotocolsrequirepublic keycryptography[8],theydohaveatunablekey lengthparameter.However,thisparameterpri- marilycontrolsthedicultyofmountingo -line attackswithoutaserver& 39;ssecretstate;itonlyin- directlya ectsthecostofano -lineattackgiven thatstate.Tuningkeylengthtopreservepassword guessingcostswouldhaveotherunintendedconse- quences,forinstanceincreasingmessagesizesand costingserversunnecessarycomputation.Bycom- biningaschemelikeSRPwiththebcryptalgorithm presentedinthispaper,however,onecanvarythe costofguessingpasswordsindependentlyfrommost otherpropertiesoftheprotocol. Whateverprogressoccursinpreventingo -lineat- tacks,onecanneverrulethemoutentirely.Infact, thedecisiontohaveanopenlyreadablepassword lewasnotanoversightonthepartoftheUNIX systemdesigners[9].Rather,itwasareactionto thedicultyofkeepingthepassword lesecretin previoussystems,andtotherealizationthatasup- posedlysecretpassword lewouldneedtoresist o -lineguessinganyway.Thisrealizationremains equallytruetoday.Asidefromtheobviousissues
Excerpt from a page describing this subject · 40,000 chars · not written by Vinony
Wikidata facts
Show 4 more facts
- maximum size or capacity
- 72
- Stack Exchange tag
- stackoverflow.com/tags/bcrypt
- publication date
- 1999-00-00
- described at URL
- www.usenix.org/legacy/event/usenix99/provos/provos.pdf
Sources (1)
via Wikidata · CC0
~13 min read
Article
15 sectionsContents
- Background
- Description
- Versioning history
- Algorithm
- Expensive key setup
- Expand key
- User input
- Comparison to other password hashing algorithms
- Criticisms
- Maximum password length
- Password hash truncation
- Base64 encoding alphabet
- See also
- References
- External links
bcrypt is a password-hashing function designed by Niels Provos and David Mazières. It is based on the Blowfish cipher and presented at USENIX in 1999. Besides incorporating a salt to protect against rainbow table attacks, bcrypt is an adaptive function: over time, the iteration count can be increased to make it slower, so it remains resistant to brute-force search attacks even with increasing computation power.
The bcrypt function is the default password hash algorithm for OpenBSD, and was the default for some Linux distributions such as SUSE Linux.