Key facts
- Cryptographic hash function.name
- bcrypt
- Cryptographic hash function.designers
- Niels Provos, David Mazières
- Cryptographic hash function.publish date
- 1999
- Cryptographic hash function.derived from
- Blowfish (cipher)
- Cryptographic hash function.digest size
- 184 bits
- Cryptographic hash function.rounds
- variable via cost parameter
via Wikipedia infobox
Described at
bcrypt.dvi
usenix.org →playanimportantroleinthevastmajorityofuser- authenticationsystems. Thispaperdiscusseswaysofbuildingsystemsin whichpasswordsecuritykeepsupwithhardware speeds.Wepresenttwoalgorithmswithadaptable cost eksblow sh,ablockcipherwithapurposefully expensivekeyschedule,andbcrypt,arelatedhash function.Failingamajorbreakthroughincomplex- itytheory,thesealgorithmsshouldallowpassword- basedsystemstoadapttohardwareimprovements andremainsecure20yearsintothefuture. Therestofthepaperisorganizedasfollows.In Section2,wediscussrelatedworkonpasswordsecu- rity.InSection3,weexplaintherequirementsfora goodpasswordscheme.Section4presentseksblow- sh,a64-bitblockcipherthatletsuserstunethe costofthekeyschedule.Section5introducesthe variable-costbcryptpasswordhashingfunctionand describesourimplementationintheOpenBSDop- eratingsystem.Finally,Section6comparesbcrypt totwowidely-usedpasswordhashingfunctions. 2RelatedWork Passwordguessingattackscanbecategorizedby theamountofinteractiontheyrequirewithanau- thenticationsystem.Inon-lineattacks,theperpe- tratormustmakeuseofanauthenticationsystem tocheckeachguessofapassword.Ino -lineat- tacks,anattackerobtainsinformation suchasa passwordhash thatallowshimtocheckpassword guessesonhisown,withnofurtheraccesstothe system.On-lineattacksaregenerallyconsiderably slowerthano -lineones.Systemscandetecton- lineattacksfairlyeasilyanddefendagainstthemby slowingtherateofpasswordchecking.Incontrast, onceanattackerhasobtainedpasswordveri cation information,theonlyprotectionasystemhasfrom o -lineattacksisthecomputationalcostofchecking potentialpasswords. Techniquesformitigatingthethreatofo -linepass- wordguessinggenerallyaspiretooneoftwogoals limitingasystem& 39;ssusceptibilitytoo -lineattacks orincreasingtheircomputationalcost.Asasimple exampleoftheformer,manymodernUNIXsystems nowkeeppasswordhashessecretfromusers,stor- ingtheminaread-protectedshadowpassword le ratherthaninthestandardopenlyreadableone. Muchoftheworkonpreventingo -linepassword attackshascenteredaroundcommunicationover insecurenetworks.Ifcryptographicprotocolsrely onuser-chosenpasswordsaskeys,theymayopen themselvesuptoo -lineguessingattacks.Gong et.al.[7]suggestseveralprotocoldesigntricksto thwartpasswordguessingbynetworkattackers.Un- fortunately,theirmostinterestingproposalsrequire encryptionalgorithmswithunusualanddicultto achieveproperties. Severalpeoplehavedesignedsecurepasswordpro- tocolsthatletusersauthenticatethemselvesover insecurenetworkswithouttheneedtorememberor certifypublickeys.BellovinandMerritt[2,3] rst proposedtheidea,givingseveralconcreteproto- colsputativelyresistanttoo -lineguessingattacks. Patel[11]latercryptanalyzedthoseprotocols,but peoplehavesincecontinueddevelopingandre ning othersinthesamevein.Morerecentproposalssuch asSRP[16]showpromiseofbeingsecure. Ofcourse,evenasecurepasswordprotocolrequires someservercapableofvalidatinguserswithcorrect passwords.Anattackerwhoobtainsthatserver& 39;s secretstatecanmountano -lineguessingattack. Becausesecurepasswordprotocolsrequirepublic keycryptography[8],theydohaveatunablekey lengthparameter.However,thisparameterpri- marilycontrolsthedicultyofmountingo -line attackswithoutaserver& 39;ssecretstate;itonlyin- directlya ectsthecostofano -lineattackgiven thatstate.Tuningkeylengthtopreservepassword guessingcostswouldhaveotherunintendedconse- quences,forinstanceincreasingmessagesizesand costingserversunnecessarycomputation.Bycom- biningaschemelikeSRPwiththebcryptalgorithm presentedinthispaper,however,onecanvarythe costofguessingpasswordsindependentlyfrommost otherpropertiesoftheprotocol. Whateverprogressoccursinpreventingo -lineat- tacks,onecanneverrulethemoutentirely.Infact, thedecisiontohaveanopenlyreadablepassword lewasnotanoversightonthepartoftheUNIX systemdesigners[9].Rather,itwasareactionto thedicultyofkeepingthepassword lesecretin previoussystems,andtotherealizationthatasup- posedlysecretpassword lewouldneedtoresist o -lineguessinganyway.Thisrealizationremains equallytruetoday.Asidefromtheobviousissues
Excerpt from a page describing this subject · 40,000 chars · not written by Vinony
Article · 日本語
bcrypt(ビー・クリプト)はとDavid Mazièresによって設計された1999年にUSENIXにて公開された、Blowfish暗号を基盤としたパスワードハッシュ化関数である。レインボーテーブル攻撃に対抗するためにソルトを組み込んでいる以外に、bcryptは適応的な特性を備えている。計算能力が増えたとしてもブルートフォース攻撃に耐えられるように、繰り返し回数を増やして速度を落とせるようになっている。 bcryptはOpenBSDのデフォルトのパスワードハッシュアルゴリズムとして利用されているほか、SUSE LinuxなどのLinuxディストリビューションを含む他のシステムでも利用されている。 bcryptはC、C++、C#、Go、Java、JavaScript、Elixir、Perl、PHP、Python、Ruby、その他の言語による実装がある。
Abstract from DBpedia / Wikipedia · CC BY-SA