EN
TR
Evaluation of Password Hashing Competition Finalists: Performance, Security, Compliance Mapping, and Post-Quantum Readiness
Öz
Password hashes and key derivation functions (KDFs) are central to authentication and cryptographic security schemes crafted to defend user credentials from brute-force attacks and unauthorized access. Password hashing algorithms, for example PBKDF2, bcrypt, or scrypt, are very popular today, but are lacking in the face of modern hardware acceleration, parallel processing, and advanced cryptanalytic attacks. To contest these shortcomings, the Password Hashing Competition (PHC) was started in 2013 and had 22 candidates for functions for hashing passwords. After thorough evaluation, 9 finalists were selected based on how secure, fast, memory-friendly, flexible, and efficient these functions were. This study evaluates the nine PHC finalists—Argon2, battcrypt, Catena, Lyra2, MAKWA, Parallel, POMELO, Pufferfish, and yescrypt—through survey findings and performance benchmarks. We have evaluated these functions from an architectural standpoint and studied their security features, memory hardness, performance trade-off, and practical usage. We also compare these finalists with traditional password hashing functions to highlight their advantages and limitations. We also investigate the post-quantum assumption for password hashing – the effectiveness of these functions against quantum assaults, their position in a new cryptography set, and the role of peppering as an additional security measure. In addition, we perform a comprehensive compliance mapping of the PHC finalists against major global standards and regulations such as NIST SP 800-63B, OWASP ASVS, PCI DSS, GDPR, KVKK, and ISO/IEC 27001, highlighting their practical suitability for secure deployment in regulated environments. Finally, we provide usage recommendations for these functions for web authentication, KDFs, and embedded platforms. This paper serves as a reference for researchers, developers, and security engineers, while also introducing a compliance-aware, post-quantum-ready framework that bridges cryptographic design with regulatory and deployment needs.
Anahtar Kelimeler
Etik Beyan
Ethics committee approval was not required for this study because there was no study on animals or humans.
Kaynakça
- Álvarez R, Zamora A. 2017. Using spritz as a password-based key derivation function. In: Int Joint Conf SOCO’16-CISIS’16-ICEUTE’16: San Sebastián, Spain, October 19th-21st, 2016 Proceedings 11, pp: 518-525.
- Alwen J, Gazi P, Kamath C, Klein K, Osang G, Pietrzak K, Rybár M. 2018. On the memory-hardness of data-independent password-hashing functions. In: Proceedings of the 2018 on Asia Conf Comp Commun Secur, pp: 51-65.
- Andrade ER, Simplicio MA, Barreto PS, dos Santos PC. 2016. Lyra2: Efficient password hashing with high security against time-memory trade-offs. IEEE Trans Comput, 65(10): 3096-3108.
- Anonymous. 2025. PHC string format. URL: https://github.com/P-H-C/phc-string-format/blob/master/phc-sf-spec.md (accessed date: April 1, 2025).
- Aumasson JP. 2013. Password hashing: the future is now, Kudelski Security, Switzerland, pp: 1-10.
- Backendal M, Clermont S, Fischlin M, Günther F. 2025. Key derivation functions without a grain of salt. In Annual Int Conf Theory Appl Cryptogr Tech, pp: 393-426.
- Bellovin SM, Merritt M. 1993. Augmented encrypted key exchange: A password-based protocol secure against dictionary attacks and password file compromise. In: Proc of the 1st ACM Conf Computer Commun Secur, pp: 244-250.
- Blocki J, Harsha B, Zhou S. 2018. On the economics of offline password cracking. In: 2018 IEEE Symp Secur Privacy (SP), pp: 853-871.
Ayrıntılar
Birincil Dil
İngilizce
Konular
Bilgi Güvenliği Yönetimi, Bilgi Sistemleri (Diğer)
Bölüm
Araştırma Makalesi
Erken Görünüm Tarihi
12 Kasım 2025
Yayımlanma Tarihi
15 Kasım 2025
Gönderilme Tarihi
4 Nisan 2025
Kabul Tarihi
26 Eylül 2025
Yayımlandığı Sayı
Yıl 2025 Cilt: 8 Sayı: 6
APA
Ulutas, E., & Celiktas, B. (2025). Evaluation of Password Hashing Competition Finalists: Performance, Security, Compliance Mapping, and Post-Quantum Readiness. Black Sea Journal of Engineering and Science, 8(6), 1841-1855. https://doi.org/10.34248/bsengineering.1670109
AMA
1.Ulutas E, Celiktas B. Evaluation of Password Hashing Competition Finalists: Performance, Security, Compliance Mapping, and Post-Quantum Readiness. BSJ Eng. Sci. 2025;8(6):1841-1855. doi:10.34248/bsengineering.1670109
Chicago
Ulutas, Erdem, ve Baris Celiktas. 2025. “Evaluation of Password Hashing Competition Finalists: Performance, Security, Compliance Mapping, and Post-Quantum Readiness”. Black Sea Journal of Engineering and Science 8 (6): 1841-55. https://doi.org/10.34248/bsengineering.1670109.
EndNote
Ulutas E, Celiktas B (01 Kasım 2025) Evaluation of Password Hashing Competition Finalists: Performance, Security, Compliance Mapping, and Post-Quantum Readiness. Black Sea Journal of Engineering and Science 8 6 1841–1855.
IEEE
[1]E. Ulutas ve B. Celiktas, “Evaluation of Password Hashing Competition Finalists: Performance, Security, Compliance Mapping, and Post-Quantum Readiness”, BSJ Eng. Sci., c. 8, sy 6, ss. 1841–1855, Kas. 2025, doi: 10.34248/bsengineering.1670109.
ISNAD
Ulutas, Erdem - Celiktas, Baris. “Evaluation of Password Hashing Competition Finalists: Performance, Security, Compliance Mapping, and Post-Quantum Readiness”. Black Sea Journal of Engineering and Science 8/6 (01 Kasım 2025): 1841-1855. https://doi.org/10.34248/bsengineering.1670109.
JAMA
1.Ulutas E, Celiktas B. Evaluation of Password Hashing Competition Finalists: Performance, Security, Compliance Mapping, and Post-Quantum Readiness. BSJ Eng. Sci. 2025;8:1841–1855.
MLA
Ulutas, Erdem, ve Baris Celiktas. “Evaluation of Password Hashing Competition Finalists: Performance, Security, Compliance Mapping, and Post-Quantum Readiness”. Black Sea Journal of Engineering and Science, c. 8, sy 6, Kasım 2025, ss. 1841-55, doi:10.34248/bsengineering.1670109.
Vancouver
1.Erdem Ulutas, Baris Celiktas. Evaluation of Password Hashing Competition Finalists: Performance, Security, Compliance Mapping, and Post-Quantum Readiness. BSJ Eng. Sci. 01 Kasım 2025;8(6):1841-55. doi:10.34248/bsengineering.1670109