我应该使用什么列类型/长度将 Bcrypt 散列密码存储在数据库中?

本教程将介绍我应该使用什么列类型/长度将 Bcrypt 散列密码存储在数据库中?的处理方法,这篇教程是从别的地方看到的,然后加了一些国外程序员的疑问与解答,希望能对你有所帮助,好了,下面开始学习吧。

我应该使用什么列类型/长度将 Bcrypt 散列密码存储在数据库中? 教程 第1张

问题描述

I want to store a hashed password (using BCrypt) in a database. What would be a good type for this, and which would be the correct length? Are passwords hashed with BCrypt always of same length?

EDIT

Example hash:

$2a$10$KssILxWNR6k62B7yiX0GAe2Q7wwHlrzhF3LqtVvpyvHZf0MwvNfVu

After hashing some passwords, it seems that BCrypt always generates 60 character hashes.

EDIT 2

Sorry for not mentioning the implementation. I am using jBCrypt.

解决方案

The modular crypt format for bcrypt consists of

    $2$, $2a$ or $2y$ identifying the hashing algorithm and format

    a two digit value denoting the cost parameter, followed by $

    a 53 characters long base-64-encoded value (they use the alphabet ., /, 09, AZ, az that is different to the standard Base 64 Encoding alphabet) consisting of:

      22 characters of salt (effectively only 128 bits of the 132 decoded bits)

      31 characters of encrypted output (effectively only 184 bits of the 186 decoded bits)

Thus the total length is 59 or 60 bytes respectively.

As you use the 2a format, you’ll need 60 bytes. And thus for MySQL I’ll recommend to use the CHAR(60) BINARYor BINARY(60) (see The and Collations for information about the difference).

CHAR is not binary safe and equality does not depend solely on the byte value but on the actual collation; in the worst case A is treated as equal to a. See The _bin and binary Collations for more information.

好了关于我应该使用什么列类型/长度将 Bcrypt 散列密码存储在数据库中?的教程就到这里就结束了,希望趣模板源码网找到的这篇技术文章能帮助到大家,更多技术教程可以在站内搜索。