Research Article

Evaluation of Password Hashing Competition Finalists: Performance, Security, Compliance Mapping, and Post-Quantum Readiness

Volume: 8 Number: 6 November 15, 2025
EN TR

Evaluation of Password Hashing Competition Finalists: Performance, Security, Compliance Mapping, and Post-Quantum Readiness

Abstract

Password hashes and key derivation functions (KDFs) are central to authentication and cryptographic security schemes crafted to defend user credentials from brute-force attacks and unauthorized access. Password hashing algorithms, for example PBKDF2, bcrypt, or scrypt, are very popular today, but are lacking in the face of modern hardware acceleration, parallel processing, and advanced cryptanalytic attacks. To contest these shortcomings, the Password Hashing Competition (PHC) was started in 2013 and had 22 candidates for functions for hashing passwords. After thorough evaluation, 9 finalists were selected based on how secure, fast, memory-friendly, flexible, and efficient these functions were. This study evaluates the nine PHC finalists—Argon2, battcrypt, Catena, Lyra2, MAKWA, Parallel, POMELO, Pufferfish, and yescrypt—through survey findings and performance benchmarks. We have evaluated these functions from an architectural standpoint and studied their security features, memory hardness, performance trade-off, and practical usage. We also compare these finalists with traditional password hashing functions to highlight their advantages and limitations. We also investigate the post-quantum assumption for password hashing – the effectiveness of these functions against quantum assaults, their position in a new cryptography set, and the role of peppering as an additional security measure. In addition, we perform a comprehensive compliance mapping of the PHC finalists against major global standards and regulations such as NIST SP 800-63B, OWASP ASVS, PCI DSS, GDPR, KVKK, and ISO/IEC 27001, highlighting their practical suitability for secure deployment in regulated environments. Finally, we provide usage recommendations for these functions for web authentication, KDFs, and embedded platforms. This paper serves as a reference for researchers, developers, and security engineers, while also introducing a compliance-aware, post-quantum-ready framework that bridges cryptographic design with regulatory and deployment needs.

Keywords

Ethical Statement

Ethics committee approval was not required for this study because there was no study on animals or humans.

References

  1. Álvarez R, Zamora A. 2017. Using spritz as a password-based key derivation function. In: Int Joint Conf SOCO’16-CISIS’16-ICEUTE’16: San Sebastián, Spain, October 19th-21st, 2016 Proceedings 11, pp: 518-525.
  2. Alwen J, Gazi P, Kamath C, Klein K, Osang G, Pietrzak K, Rybár M. 2018. On the memory-hardness of data-independent password-hashing functions. In: Proceedings of the 2018 on Asia Conf Comp Commun Secur, pp: 51-65.
  3. Andrade ER, Simplicio MA, Barreto PS, dos Santos PC. 2016. Lyra2: Efficient password hashing with high security against time-memory trade-offs. IEEE Trans Comput, 65(10): 3096-3108.
  4. Anonymous. 2025. PHC string format. URL: https://github.com/P-H-C/phc-string-format/blob/master/phc-sf-spec.md (accessed date: April 1, 2025).
  5. Aumasson JP. 2013. Password hashing: the future is now, Kudelski Security, Switzerland, pp: 1-10.
  6. Backendal M, Clermont S, Fischlin M, Günther F. 2025. Key derivation functions without a grain of salt. In Annual Int Conf Theory Appl Cryptogr Tech, pp: 393-426.
  7. Bellovin SM, Merritt M. 1993. Augmented encrypted key exchange: A password-based protocol secure against dictionary attacks and password file compromise. In: Proc of the 1st ACM Conf Computer Commun Secur, pp: 244-250.
  8. Blocki J, Harsha B, Zhou S. 2018. On the economics of offline password cracking. In: 2018 IEEE Symp Secur Privacy (SP), pp: 853-871.

Details

Primary Language

English

Subjects

Information Security Management, Information Systems (Other)

Journal Section

Research Article

Early Pub Date

November 12, 2025

Publication Date

November 15, 2025

Submission Date

April 4, 2025

Acceptance Date

September 26, 2025

Published in Issue

Year 2025 Volume: 8 Number: 6

APA
Ulutas, E., & Celiktas, B. (2025). Evaluation of Password Hashing Competition Finalists: Performance, Security, Compliance Mapping, and Post-Quantum Readiness. Black Sea Journal of Engineering and Science, 8(6), 1841-1855. https://doi.org/10.34248/bsengineering.1670109
AMA
1.Ulutas E, Celiktas B. Evaluation of Password Hashing Competition Finalists: Performance, Security, Compliance Mapping, and Post-Quantum Readiness. BSJ Eng. Sci. 2025;8(6):1841-1855. doi:10.34248/bsengineering.1670109
Chicago
Ulutas, Erdem, and Baris Celiktas. 2025. “Evaluation of Password Hashing Competition Finalists: Performance, Security, Compliance Mapping, and Post-Quantum Readiness”. Black Sea Journal of Engineering and Science 8 (6): 1841-55. https://doi.org/10.34248/bsengineering.1670109.
EndNote
Ulutas E, Celiktas B (November 1, 2025) Evaluation of Password Hashing Competition Finalists: Performance, Security, Compliance Mapping, and Post-Quantum Readiness. Black Sea Journal of Engineering and Science 8 6 1841–1855.
IEEE
[1]E. Ulutas and B. Celiktas, “Evaluation of Password Hashing Competition Finalists: Performance, Security, Compliance Mapping, and Post-Quantum Readiness”, BSJ Eng. Sci., vol. 8, no. 6, pp. 1841–1855, Nov. 2025, doi: 10.34248/bsengineering.1670109.
ISNAD
Ulutas, Erdem - Celiktas, Baris. “Evaluation of Password Hashing Competition Finalists: Performance, Security, Compliance Mapping, and Post-Quantum Readiness”. Black Sea Journal of Engineering and Science 8/6 (November 1, 2025): 1841-1855. https://doi.org/10.34248/bsengineering.1670109.
JAMA
1.Ulutas E, Celiktas B. Evaluation of Password Hashing Competition Finalists: Performance, Security, Compliance Mapping, and Post-Quantum Readiness. BSJ Eng. Sci. 2025;8:1841–1855.
MLA
Ulutas, Erdem, and Baris Celiktas. “Evaluation of Password Hashing Competition Finalists: Performance, Security, Compliance Mapping, and Post-Quantum Readiness”. Black Sea Journal of Engineering and Science, vol. 8, no. 6, Nov. 2025, pp. 1841-55, doi:10.34248/bsengineering.1670109.
Vancouver
1.Erdem Ulutas, Baris Celiktas. Evaluation of Password Hashing Competition Finalists: Performance, Security, Compliance Mapping, and Post-Quantum Readiness. BSJ Eng. Sci. 2025 Nov. 1;8(6):1841-55. doi:10.34248/bsengineering.1670109

                            24890