แฮช/การเข้ารหัส
PBKDF2 Hash + Verify
ได้คีย์จาก PBKDF2 (RFC 8018) โดยใช้รหัสผ่าน, HMAC-SHA1/256/384/512 พร้อมปรับจำนวนรอบได้
PBKDF2 (RFC 8018) applies HMAC to a password and salt repeatedly to deliberately slow down computation — it's the oldest of the standardized algorithms for password hashing and encryption key derivation.
How to use it
- Derive: enter a password, pick an HMAC algorithm (SHA-1/256/384/512), and set the iteration count to get a derived key of the requested length.
- Verify: paste a password and an existing PBKDF2 hash to check whether they match, without recomputing it manually.
- More iterations means slower, more secure computation — tune the value to your server's response-time budget.
Common uses
- Deriving an encryption key from a user's password for a file container or a custom protocol.
- Checking a PBKDF2 implementation for compatibility across programming languages (the parameters must match exactly).
- Hashing passwords in systems that require a FIPS-compliant algorithm (PBKDF2 is NIST-approved).
Things to keep in mind
Unlike bcrypt and Argon2, PBKDF2 isn't memory-hard — it only requires CPU time, so it's less resistant to attacks on GPUs with many parallel compute units.
The recommended iteration count rises over time in NIST and OWASP guidance as hardware gets faster — check against current recommendations periodically.
บทความเกี่ยวกับเครื่องมือนี้: PBKDF2: มาตรฐานการยืดคีย์ที่เก่าแก่ที่สุด
คำถามที่พบบ่อย
PBKDF2 ต่างจาก bcrypt หรือ Argon2 อย่างไรในการแฮชรหัสผ่าน?
PBKDF2 ใช้ฟังก์ชันแฮช HMAC ซ้ำ ๆ เพื่อทำให้บรูทฟอร์สช้าลง แต่ต่างจาก bcrypt หรือ Argon2 ตรงที่ไม่ต้องใช้หน่วยความจำมาก จึงเจาะด้วย GPU ได้ถูกกว่าเชิงเปรียบเทียบ มันยังใช้กันแพร่หลายและได้รับการรับรอง FIPS แต่ระบบใหม่มักนิยม Argon2 มากกว่า
จำนวนรอบควบคุมอะไร และควรตั้งสูงแค่ไหน?
จำนวนรอบกำหนดว่าแฮชพื้นฐานถูกใช้กี่ครั้ง โดยแลกความเร็วกับความทนทานต่อบรูทฟอร์สโดยตรง คำแนะนำปัจจุบันแนะนำหลายแสนรอบสำหรับ SHA-256 และควรเพิ่มขึ้นตามเวลาเมื่อฮาร์ดแวร์เร็วขึ้น
ทำไม PBKDF2 ถึงต้องมี salt?
Salt ช่วยให้รหัสผ่านที่เหมือนกันได้ผลลัพธ์ต่างกัน ป้องกันไม่ให้ผู้โจมตีใช้ตาราง rainbow ที่คำนวณไว้ล่วงหน้า และบังคับให้ต้องโจมตีแต่ละแฮชแยกกัน
ฟังก์ชันแฮชพื้นฐานที่ PBKDF2 ใช้มีความสำคัญหรือไม่?
สำคัญ การใช้งานแบบเก่ามักใช้ HMAC-SHA1 เป็นค่าเริ่มต้น — ในโครงสร้าง HMAC นี่ไม่ใช่ช่องโหว่ร้ายแรง แต่คำแนะนำสมัยใหม่ระบุชัดเจนให้ใช้ HMAC-SHA256 หรือแข็งแกร่งกว่าเพื่อระยะขอบความปลอดภัยที่มากกว่าโดยแทบไม่เสียความเร็ว
PBKDF2 ถูกใช้ที่ไหนอีกนอกจากการเก็บรหัสผ่าน?
PBKDF2 ถูกใช้อย่างแพร่หลายในการสร้างคีย์เข้ารหัสเชิงรหัสลับจากรหัสผ่าน — เช่น ใน WPA2/WPA3 สำหรับ Wi-Fi และในรูปแบบคอนเทนเนอร์ไฟล์เข้ารหัสจำนวนมาก