Skip to content
EntityQ286896· pop 15· linked from 139 articles

funzione di hashing di password progettata da Niels Provos e David Mazières

Key facts

Cryptographic hash function.name
bcrypt
Cryptographic hash function.designers
Niels Provos, David Mazières
Cryptographic hash function.publish date
1999
Cryptographic hash function.derived from
Blowfish (cipher)
Cryptographic hash function.digest size
184 bits
Cryptographic hash function.rounds
variable via cost parameter

via Wikipedia infobox

Described at

bcrypt.dvi

usenix.org

playanimportantroleinthevastmajorityofuser- authenticationsystems. Thispaperdiscusseswaysofbuildingsystemsin whichpasswordsecuritykeepsupwithhardware speeds.Wepresenttwoalgorithmswithadaptable cost eksblow sh,ablockcipherwithapurposefully expensivekeyschedule,andbcrypt,arelatedhash function.Failingamajorbreakthroughincomplex- itytheory,thesealgorithmsshouldallowpassword- basedsystemstoadapttohardwareimprovements andremainsecure20yearsintothefuture. Therestofthepaperisorganizedasfollows.In Section2,wediscussrelatedworkonpasswordsecu- rity.InSection3,weexplaintherequirementsfora goodpasswordscheme.Section4presentseksblow- sh,a64-bitblockcipherthatletsuserstunethe costofthekeyschedule.Section5introducesthe variable-costbcryptpasswordhashingfunctionand describesourimplementationintheOpenBSDop- eratingsystem.Finally,Section6comparesbcrypt totwowidely-usedpasswordhashingfunctions. 2RelatedWork Passwordguessingattackscanbecategorizedby theamountofinteractiontheyrequirewithanau- thenticationsystem.Inon-lineattacks,theperpe- tratormustmakeuseofanauthenticationsystem tocheckeachguessofapassword.Ino -lineat- tacks,anattackerobtainsinformation suchasa passwordhash thatallowshimtocheckpassword guessesonhisown,withnofurtheraccesstothe system.On-lineattacksaregenerallyconsiderably slowerthano -lineones.Systemscandetecton- lineattacksfairlyeasilyanddefendagainstthemby slowingtherateofpasswordchecking.Incontrast, onceanattackerhasobtainedpasswordveri cation information,theonlyprotectionasystemhasfrom o -lineattacksisthecomputationalcostofchecking potentialpasswords. Techniquesformitigatingthethreatofo -linepass- wordguessinggenerallyaspiretooneoftwogoals limitingasystem& 39;ssusceptibilitytoo -lineattacks orincreasingtheircomputationalcost.Asasimple exampleoftheformer,manymodernUNIXsystems nowkeeppasswordhashessecretfromusers,stor- ingtheminaread-protectedshadowpassword le ratherthaninthestandardopenlyreadableone. Muchoftheworkonpreventingo -linepassword attackshascenteredaroundcommunicationover insecurenetworks.Ifcryptographicprotocolsrely onuser-chosenpasswordsaskeys,theymayopen themselvesuptoo -lineguessingattacks.Gong et.al.[7]suggestseveralprotocoldesigntricksto thwartpasswordguessingbynetworkattackers.Un- fortunately,theirmostinterestingproposalsrequire encryptionalgorithmswithunusualanddicultto achieveproperties. Severalpeoplehavedesignedsecurepasswordpro- tocolsthatletusersauthenticatethemselvesover insecurenetworkswithouttheneedtorememberor certifypublickeys.BellovinandMerritt[2,3] rst proposedtheidea,givingseveralconcreteproto- colsputativelyresistanttoo -lineguessingattacks. Patel[11]latercryptanalyzedthoseprotocols,but peoplehavesincecontinueddevelopingandre ning othersinthesamevein.Morerecentproposalssuch asSRP[16]showpromiseofbeingsecure. Ofcourse,evenasecurepasswordprotocolrequires someservercapableofvalidatinguserswithcorrect passwords.Anattackerwhoobtainsthatserver& 39;s secretstatecanmountano -lineguessingattack. Becausesecurepasswordprotocolsrequirepublic keycryptography[8],theydohaveatunablekey lengthparameter.However,thisparameterpri- marilycontrolsthedicultyofmountingo -line attackswithoutaserver& 39;ssecretstate;itonlyin- directlya ectsthecostofano -lineattackgiven thatstate.Tuningkeylengthtopreservepassword guessingcostswouldhaveotherunintendedconse- quences,forinstanceincreasingmessagesizesand costingserversunnecessarycomputation.Bycom- biningaschemelikeSRPwiththebcryptalgorithm presentedinthispaper,however,onecanvarythe costofguessingpasswordsindependentlyfrommost otherpropertiesoftheprotocol. Whateverprogressoccursinpreventingo -lineat- tacks,onecanneverrulethemoutentirely.Infact, thedecisiontohaveanopenlyreadablepassword lewasnotanoversightonthepartoftheUNIX systemdesigners[9].Rather,itwasareactionto thedicultyofkeepingthepassword lesecretin previoussystems,andtotherealizationthatasup- posedlysecretpassword lewouldneedtoresist o -lineguessinganyway.Thisrealizationremains equallytruetoday.Asidefromtheobviousissues

Excerpt from a page describing this subject · 40,000 chars · not written by Vinony

Article · Italiano

bcrypt è una funzione di hashing di password progettata da Niels Provos e , basata sulla cifratura Blowfish e presentata a USENIX nel 1999. Oltre a incorporare un salt per proteggere la password contro attacchi tabella arcobaleno, bcrypt è una funzione adattiva: col tempo, il conteggio dell'iterazione può essere aumentato per renderla più lenta, in modo da essere resistente ad attacchi di forza bruta anche con capacità computazionale crescente. La funzione bcrypt è l'algoritmo di hashing di password di default per BSD e altri sistemi, incluse alcune distribuzioni Linux come SUSE Linux. Il prefisso "$2a$" o "$2b$" (o "$2y$") in una stringa di hash in un file shadow password indica che quella stringa hash è un formato modulare di hash bcrypt. Il resto della stringa hash include il parametro costo, un sale 128-bit (codificato base64 con 22 caratteri), e 184 bit del valore hash risultante (codificato base64 con 31 caratteri). Il parametro costo specifica un conteggio iterativo di espansione della chiave in una potenza di due, che è un input dell'algoritmo di cifratura. Per esempio, il record shadow password $2a$10$N9qo8uLOickgx2ZMRZoMyeIjZAgcfl7p92ldGxad68LJZdL17lhWy specifica un parametro costo di 10, indicando 210 come turni di espansione della chiave. Il sale è N9qo8uLOickgx2ZMRZoMye e l'hash risultante è IjZAgcfl7p92ldGxad68LJZdL17lhWy. Per pratica standard, la password stessa dell'utente non è memorizzata. Sono presenti implementazioni di bcrypt per C, C#, Java, JavaScript, Perl, PHP, Python, Ruby e altri linguaggi.

Abstract from DBpedia / Wikipedia · CC BY-SA