Evaluation of password hashing competition finalists: performance, security, compliance mapping, and post-quantum readiness

dc.authorid0009-0007-4263-5396
dc.authorid0000-0003-2865-6370
dc.contributor.authorUlutaş, Erdemen_US
dc.contributor.authorÇeliktaş, Barışen_US
dc.date.accessioned2025-11-21T07:00:09Z
dc.date.available2025-11-21T07:00:09Z
dc.date.issued2025-11-15
dc.departmentIşık Üniversitesi, Lisansüstü Eğitim Enstitüsü, Siber Güvenlik Yüksek Lisans Programıen_US
dc.departmentIşık University, School of Graduate Studies, Master’s Program in Cybersecurityen_US
dc.departmentIşık Üniversitesi, Mühendislik ve Doğa Bilimleri Fakültesi, Bilgisayar Mühendisliği Bölümüen_US
dc.departmentIşık University, Faculty of Engineering and Natural Sciences, Department of Computer Engineeringen_US
dc.description.abstractPassword hashes and key derivation functions (KDFs) are central to authentication and cryptographic security schemes crafted to defend user credentials from brute-force attacks and unauthorized access. Password hashing algorithms, for example PBKDF2, bcrypt, or scrypt, are very popular today, but are lacking in the face of modern hardware acceleration, parallel processing, and advanced cryptanalytic attacks. To contest these shortcomings, the Password Hashing Competition (PHC) was started in 2013 and had 22 candidates for functions for hashing passwords. After thorough evaluation, 9 finalists were selected based on how secure, fast, memory-friendly, flexible, and efficient these functions were. This study evaluates the nine PHC finalists—Argon2, battcrypt, Catena, Lyra2, MAKWA, Parallel, POMELO, Pufferfish, and yescrypt—through survey findings and performance benchmarks. We have evaluated these functions from an architectural standpoint and studied their security features, memory hardness, performance tradeoff, and practical usage. We also compare these finalists with traditional password hashing functions to highlight their advantages and limitations. We also investigate the post-quantum assumption for password hashing – the effectiveness of these functions against quantum assaults, their position in a new cryptography set, and the role of peppering as an additional security measure. In addition, we perform a comprehensive compliance mapping of the PHC finalists against major global standards and regulations such as NIST SP 800-63B, OWASP ASVS, PCI DSS, GDPR, KVKK, and ISO/IEC 27001, highlighting their practical suitability for secure deployment in regulated environments. Finally, we provide usage recommendations for these functions for web authentication, KDFs, and embedded platforms. This paper serves as a reference for researchers, developers, and security engineers, while also introducing a complianceaware, post-quantum-ready framework that bridges cryptographic design with regulatory and deployment needs.en_US
dc.description.versionPublisher's Versionen_US
dc.identifier.citationUlutaş, E. & Çeliktaş, B. (2025). Evaluation of password hashing competition finalists: performance, security, compliance mapping, and post-quantum readiness. Black Sea Journal of Engineering and Science, 8(6), 1841-1855. doi:https://doi.org/10.34248/bsengineering.1670109en_US
dc.identifier.doi10.34248/bsengineering.1670109
dc.identifier.endpage1855
dc.identifier.issn2619 – 8991
dc.identifier.issue6
dc.identifier.startpage1841
dc.identifier.trdizinid1359469
dc.identifier.urihttps://hdl.handle.net/11729/6788
dc.identifier.urihttps://doi.org/10.34248/bsengineering.1670109
dc.identifier.urihttps://search.trdizin.gov.tr/tr/yayin/detay/1359469
dc.identifier.volume8
dc.indekslendigikaynakTR-Dizinen_US
dc.indekslendigikaynakSobiaden_US
dc.institutionauthorUlutaş, Erdemen_US
dc.institutionauthorÇeliktaş, Barışen_US
dc.institutionauthorid0009-0007-4263-5396
dc.institutionauthorid0000-0003-2865-6370
dc.language.isoenen_US
dc.peerreviewedYesen_US
dc.publicationstatusPublisheden_US
dc.publisherKaryay Karadeniz Yayımcılık Ve Organizasyon Ticaret Limited Şirketien_US
dc.relation.ispartofBlack Sea Journal of Engineering and Scienceen_US
dc.relation.publicationcategoryMakale - Ulusal Hakemli Dergi - Öğrencien_US
dc.relation.publicationcategoryMakale - Ulusal Hakemli Dergi - Kurum Öğretim Elemanıen_US
dc.rightsinfo:eu-repo/semantics/openAccessen_US
dc.subjectPassword hashingen_US
dc.subjectKey derivationen_US
dc.subjectSecurityen_US
dc.subjectPerformanceen_US
dc.subjectQuantum resistanceen_US
dc.subjectComplianceen_US
dc.titleEvaluation of password hashing competition finalists: performance, security, compliance mapping, and post-quantum readinessen_US
dc.typeArticleen_US
dspace.entity.typePublicationen_US

Dosyalar

Orijinal paket
Listeleniyor 1 - 1 / 1
Yükleniyor...
Küçük Resim
İsim:
Evaluation_of_password_hashing_competition_finalists_performance_security_compliance_mapping_and_post_quantum_readiness.pdf
Boyut:
727.15 KB
Biçim:
Adobe Portable Document Format
Lisans paketi
Listeleniyor 1 - 1 / 1
Küçük Resim Yok
İsim:
license.txt
Boyut:
1.17 KB
Biçim:
Item-specific license agreed upon to submission
Açıklama: