## Proofs of security for the Unix password hashing algorithm (2000)

Venue: | Proceedings of Advances in Cryptology—ASIACRYPT 2000, volume 1976 of Lecture |

Citations: | 10 - 0 self |

### BibTeX

@INPROCEEDINGS{Wagner00proofsof,

author = {David Wagner and Ian Goldberg},

title = {Proofs of security for the Unix password hashing algorithm},

booktitle = {Proceedings of Advances in Cryptology—ASIACRYPT 2000, volume 1976 of Lecture},

year = {2000},

publisher = {Springer-Verlag}

}

### Years of Citing Articles

### OpenURL

### Abstract

. We give the rst proof of security for the full Unix password hashing algorithm (rather than of a simplied variant). Our results show that it is very good at extracting almost all of the available strength from the underlying cryptographic primitive and provide good reason for condence in the Unix construction. 1 Introduction This paper examines the security of the Unix password hashing algorithm, the core of the Unix password authentication protocol [14]. Although the algorithm has been conjectured cryptographically secure, after two decades and deployment in millions of systems worldwide it still has not been proven to resist attack. In this paper, we provide the rst practical proof of security (under some reasonable cryptographic assumptions) for the Unix algorithm. The hashing algorithm is a fairly simple application of DES, perhaps the bestknown block cipher available to the public. Since DES has seen many man-years of analysis, in an ideal world we might hope for a pr...

### Citations

