Perbandingan Bcrypt, Argon2, dan PBKDF2 pada Keamanan SIMPEG Berbasis Web
Abstrak
Password security is an important aspect of the web-based Employee Management Information System (SIMPEG) because this system contains user data and sensitive employee information. This study aims to compare the performance and security resilience of the Bcrypt, Argon2, and PBKDF2 algorithms using the SIMPEG authentication module. The method used is applied experimentation where the three algorithms are implemented in the registration and login processes, using a dataset of 200 synthetic passwords divided into four levels of complexity. Performance testing is based on hashing time, verification time, hash length, and resource usage. Security testing has been conducted with a dictionary attack simulation using Hashcat, NVIDIA RTX 3060 6 GB GPU, and a 5000-password wordlist. The test results show that the lowest hashing and verification times are for PBKDF2, which are 226.007 ms and 228.536 ms, followed by Bcrypt with 317.610 ms and 320.693 ms. Argon2 has the highest processing times with 1403.172 ms for hashing and 1198.050 ms for verification. However, Argon2 has the best resistance to dictionary attacks with a cracking time of 6 hours and 35 minutes and a hash rate of 19 H/s, better than Bcrypt and PBKDF2. Thus, Argon2 is recommended for SIMPEG with a higher priority on password security, while Bcrypt can be a more balanced alternative between security and performance.
Kata Kunci
Cari jurnal yang tepat untuk naskah Anda
MatchMind AI mencocokkan abstrak naskah Anda dengan ribuan jurnal terakreditasi dan menampilkan rekomendasi terbaik beserta alasannya.
Coba MatchMindLihat profil lengkap jurnal ini
Waktu review, biaya APC, statistik sitasi, indeksasi Scopus, dan banyak lagi.
Buka Jurnal Informatika: Jurnal Pengembangan ITArtikel ini juga tersedia di situs resmi jurnal.
