bcrypt
Sign in to savebcrypt is a password-hashing function designed by Niels Provos and David Mazières. It is based on the Blowfish cipher and presented at USENIX in 1999. Besides incorporating a salt to protect against rainbow table attacks, bcrypt is an adaptive function: over time, the iteration count can be increased to make it slower, so it remains resistant to brute-force search attacks even with increasing computation power.
Key facts
- Cryptographic hash function.name
- bcrypt
- Cryptographic hash function.designers
- Niels Provos, David Mazières
- Cryptographic hash function.publish date
- 1999
- Cryptographic hash function.derived from
- Blowfish (cipher)
- Cryptographic hash function.digest size
- 184 bits
- Cryptographic hash function.rounds
- variable via cost parameter
via Wikipedia infobox
Described at
bcrypt.dvi
usenix.org →playanimportantroleinthevastmajorityofuser- authenticationsystems. Thispaperdiscusseswaysofbuildingsystemsin whichpasswordsecuritykeepsupwithhardware speeds.Wepresenttwoalgorithmswithadaptable cost eksblow sh,ablockcipherwithapurposefully expensivekeyschedule,andbcrypt,arelatedhash function.Failingamajorbreakthroughincomplex- itytheory,thesealgorithmsshouldallowpassword- basedsystemstoadapttohardwareimprovements andremainsecure20yearsintothefuture. Therestofthepaperisorganizedasfollows.In Section2,wediscussrelatedworkonpasswordsecu- rity.InSection3,weexplaintherequirementsfora goodpasswordscheme.Section4presentseksblow- sh,a64-bitblockcipherthatletsuserstunethe costofthekeyschedule.Section5introducesthe variable-costbcryptpasswordhashingfunctionand describesourimplementationintheOpenBSDop- eratingsystem.Finally,Section6comparesbcrypt totwowidely-usedpasswordhashingfunctions. 2RelatedWork Passwordguessingattackscanbecategorizedby theamountofinteractiontheyrequirewithanau- thenticationsystem.Inon-lineattacks,theperpe- tratormustmakeuseofanauthenticationsystem tocheckeachguessofapassword.Ino -lineat- tacks,anattackerobtainsinformation suchasa passwordhash thatallowshimtocheckpassword guessesonhisown,withnofurtheraccesstothe system.On-lineattacksaregenerallyconsiderably slowerthano -lineones.Systemscandetecton- lineattacksfairlyeasilyanddefendagainstthemby slowingtherateofpasswordchecking.Incontrast, onceanattackerhasobtainedpasswordveri cation information,theonlyprotectionasystemhasfrom o -lineattacksisthecomputationalcostofchecking potentialpasswords. Techniquesformitigatingthethreatofo -linepass- wordguessinggenerallyaspiretooneoftwogoals limitingasystem& 39;ssusceptibilitytoo -lineattacks orincreasingtheircomputationalcost.Asasimple exampleoftheformer,manymodernUNIXsystems nowkeeppasswordhashessecretfromusers,stor- ingtheminaread-protectedshadowpassword le ratherthaninthestandardopenlyreadableone. Muchoftheworkonpreventingo -linepassword attackshascenteredaroundcommunicationover insecurenetworks.Ifcryptographicprotocolsrely onuser-chosenpasswordsaskeys,theymayopen themselvesuptoo -lineguessingattacks.Gong et.al.[7]suggestseveralprotocoldesigntricksto thwartpasswordguessingbynetworkattackers.Un- fortunately,theirmostinterestingproposalsrequire encryptionalgorithmswithunusualanddicultto achieveproperties. Severalpeoplehavedesignedsecurepasswordpro- tocolsthatletusersauthenticatethemselvesover insecurenetworkswithouttheneedtorememberor certifypublickeys.BellovinandMerritt[2,3] rst proposedtheidea,givingseveralconcreteproto- colsputativelyresistanttoo -lineguessingattacks. Patel[11]latercryptanalyzedthoseprotocols,but peoplehavesincecontinueddevelopingandre ning othersinthesamevein.Morerecentproposalssuch asSRP[16]showpromiseofbeingsecure. Ofcourse,evenasecurepasswordprotocolrequires someservercapableofvalidatinguserswithcorrect passwords.Anattackerwhoobtainsthatserver& 39;s secretstatecanmountano -lineguessingattack. Becausesecurepasswordprotocolsrequirepublic keycryptography[8],theydohaveatunablekey lengthparameter.However,thisparameterpri- marilycontrolsthedicultyofmountingo -line attackswithoutaserver& 39;ssecretstate;itonlyin- directlya ectsthecostofano -lineattackgiven thatstate.Tuningkeylengthtopreservepassword guessingcostswouldhaveotherunintendedconse- quences,forinstanceincreasingmessagesizesand costingserversunnecessarycomputation.Bycom- biningaschemelikeSRPwiththebcryptalgorithm presentedinthispaper,however,onecanvarythe costofguessingpasswordsindependentlyfrommost otherpropertiesoftheprotocol. Whateverprogressoccursinpreventingo -lineat- tacks,onecanneverrulethemoutentirely.Infact, thedecisiontohaveanopenlyreadablepassword lewasnotanoversightonthepartoftheUNIX systemdesigners[9].Rather,itwasareactionto thedicultyofkeepingthepassword lesecretin previoussystems,andtotherealizationthatasup- posedlysecretpassword lewouldneedtoresist o -lineguessinganyway.Thisrealizationremains equallytruetoday.Asidefromtheobviousissues
Excerpt from a page describing this subject · 40,000 chars · not written by Vinony
Article · Français
bcrypt est une fonction de hachage créée par et . Elle est basée sur l'algorithme de chiffrement Blowfish et a été présentée lors de USENIX en 1999. En plus de l'utilisation d'un sel pour se protéger des attaques par table arc-en-ciel (rainbow table), bcrypt est une fonction adaptative, c'est-à-dire que l'on peut augmenter le nombre d'itérations pour la rendre plus lente. Ainsi elle continue à être résistante aux attaques par force brute malgré l'augmentation de la puissance de calcul. Blowfish est un algorithme de chiffrement par bloc notable pour sa phase d'établissement de clef relativement coûteuse. bcrypt utilise cette propriété et va plus loin. Provos et Mazières ont conçu un nouvel algorithme d'établissement des clefs nommé Eksblowfish (pour Expensive Key Schedule Blowfish). Dans cet algorithme, une première phase consiste à créer les sous-clefs grâce à la clef et au sel. Ensuite un certain nombre de tours de l'algorithme standard blowfish sont appliqués avec alternativement le sel et la clef. Chaque tour commence avec l'état des sous-clefs du tour précédent. Cela ne rend pas l'algorithme plus puissant que la version standard de blowfish, mais on peut choisir le nombre d'itérations ce qui le rend arbitrairement lent et contribue à dissuader les attaques par table arc-en-ciel et par force brute. Le nombre d'itérations doit être une puissance de deux, c'est un paramètre de l'algorithme et ce nombre est codé dans le résultat final. Après la première implémentation dans OpenBSD, cet algorithme s'est généralisé et est maintenant disponible dans un grand nombre de langages (C, C++, C#, Delphi, Elixir, Go, JavaScript, Java, Python, Ruby, Perl, PHP 5.3+, etc.).
Abstract from DBpedia / Wikipedia · CC BY-SA