← Back to plugin index

Scrypt Password Hash

Description
Password hash plugin that uses scrypt for hashing. Scrypt is a key derivation function designed to be computationally expensive and memory-hard, making it resistant to brute-force attacks.

The configuration allows tuning of the algorithm's parameters (N, r, p). Tuning these parameters correctly is crucial to ensure both strong security and reasonable performance on the target hardware.

It is recommended to perform benchmark tests with this plugin on the actual hardware of the productive system to determine the highest possible parameters (security) while still ensuring a good user experience, e.g. acceptable authentication times.

The configuration defaults are based on the latest security recommendations, without taking specific hardware characteristics into account.

Security note: The scrypt algorithm is no longer recommended for password hashing. Use "Argon2id Password Hash" instead.

Type name
ScryptPasswordHash
Class
com.airlock.iam.core.misc.util.password.hash.ScryptPasswordHash
May be used by
Properties
Iterations Exponent (N) (iterationsExponent)
Description
Controls the overall computational and memory cost. The exponent is used to compute the number of iterations (2N). The value must be less than 128 * r / 8, where r is the block size.

The number of iterations is stored together with the hash value. That means this value can be increased or decreased without losing backward compatibility.

Attributes
Integer
Optional
Default value
17
Block Size (r) (blockSize)
Description
Fine-tunes sequential memory read size and performance.

The default value should be suitable for most applications. If a higher cost for brute-force attacks is desired, consider adjusting the iteration exponent (N) instead.

This value is not stored with the hash value. Changing it will break compatibility with existing hashes. Use the "Combined Password Hash" to allow for a transition from an old value to a new value.

Attributes
Integer
Optional
Default value
8
Parallelization Parameter (p) (parallelizationParameter)
Description
Affects CPU cost and how many independent threads can be used.

Must be a positive integer less than or equal to (231-1) / (128 * r * 8), where r is the block size.

The default value should be suitable for most applications. If a higher cost for brute-force attacks is desired, consider adjusting the iteration exponent (N) instead.

This value is not stored with the hash value. Changing it will break compatibility with existing hashes. Use the "Combined Password Hash" to allow for a transition from an old value to a new value.

Attributes
Integer
Optional
Default value
1
YAML Template (with default values)

type: ScryptPasswordHash
id: ScryptPasswordHash-xxxxxx
displayName: 
comment: 
properties:
  blockSize: 8
  iterationsExponent: 17
  parallelizationParameter: 1