Full text
53 International Journal of Advance and Applied Research www.ijaar.co.in ISSN – 2347-7075 Impact Factor – 8.141 Peer Reviewed Bi-Monthly Vol. 6 No. 38 September - October - 2025 Cloud storage Password Security using Hashing and Salt Functionality Mrs. Manisha Balkrushna Sonawane1 & Mrs. Rohini Prabhakar Pagar2 1&2Assistant Professor, Department of Computer Science, K. K Wagh, Arts Commerce and Science College, Pimpalgaon Baswant Corresponding Author –Mrs. Manisha Balkrushna Sonawane DOI - 10.5281/zenodo.17309908 Abstract: In cloud computing, securing user data is paramount, especially when it comes to storing sensitive information like passwords. Storing plain text passwords in cloud databases is highly insecure and vulnerable to cyber-attacks. This paper proposes a secure method for storing user passwords by converting them into hash values using a salted hashing technique. The process involves generating a unique salt for each user, appending it to the plain text password, and hashing the combined string using a cryptographic hash function. This ensures that even if the cloud database is compromised, the attacker cannot easily retrieve the original passwords. The methodology also includes a secure login process where the user's input password is hashed with the same salt and compared to the stored hash for authentication. This approach significantly enhances the security of user accounts in cloud environments. Keywords: Cloud Computing, Password Security, Salted hashing, Cryptographic Hash Function Introduction: With the increasing adoption of cloud computing, the security of user data has become a critical concern. One of the most vulnerable aspects of cloud systems is the storage of user credentials, particularly passwords. Storing passwords in plain text or using weak encryption methods exposes users to significant risks, such as data breaches and unauthorized access. To address this issue, this paper introduces a secure password storage mechanism using salted hashing. The process involves adding a unique salt to each user's password before hashing it, making it computationally infeasible for attackers to reverse-engineer the original password. This method ensures that even if the cloud database is compromised, the stored passwords remain secure. The paper also discusses the implementation of this technique in a cloud environment and its effectiveness in preventing password-related attacks. Related Work: Several studies have explored methods for securely storing passwords in cloud environments. Traditional methods like MD5 and SHA-1 have been found vulnerable to brute-force and rainbow table attacks. More recent approaches, such as bcrypt, Argon2, and PBKDF2, incorporate salting and key stretching to enhance security. Salting involves adding a random string to the password before hashing, ensuring that even identical passwords produce different hash
IJAAR Vol. 6 No. 38 ISSN – 2347-7075 Mrs. Manisha Balkrushna Sonawane & Mrs. Rohini Prabhakar Pagar 54 values. Key stretching increases the computational cost of hashing, making bruteforce attacks more difficult. Previous research has demonstrated the effectiveness of these techniques in mitigating password-related vulnerabilities. However, the integration of salted hashing into cloud-based systems remains an area of active research. This paper builds on existing work by proposing a practical implementation of salted hashing for cloud user authentication. 1. Introduction to bcrypt and Salt: Password security is a critical concern in cloud computing, where user credentials must be stored securely to prevent unauthorized access. Traditional hashing methods like MD5 and SHA-1 are vulnerable to brute-force and rainbow table attacks. To address these vulnerabilities, modern cryptographic techniques such as bcrypt combined with salt have become industry standards for secure password storage. 2. bcrypt: A Secure Password Hashing Algorithm: bcrypt is a key derivation function designed specifically for password hashing. It incorporates: Salt: A random string added to each password before hashing to prevent rainbow table attacks. Work Factor (Cost Factor): Adjustable computational complexity to slow down brute-force attacks. Adaptive Hashing: Automatically increases security as hardware improves. Advantages of bcrypt: ✔ Built-in Salting – bcrypt automatically generates and stores a unique salt for each password. ✔ Future-Proof – The work factor can be increased to maintain security against evolving threats. 3. The Role of Salt in Password Security: Salt is a randomly generated string appended to a password before hashing. It ensures: Uniqueness: Even if two users have the same password, their hashes will differ due to different salts. Rainbow Table Resistance: Attackers cannot use precomputed hash tables to reverseengineer passwords. Brute-Force Mitigation: Each password requires individual cracking attempts. How bcrypt Uses Salt: 1. During Registration: o User submits a plain-text password (e.g., "mypassword123"). o bcrypt generates a unique salt (e.g., "$2a$10$N9qo8uLOickgx2ZMRZoMy "). o The password and salt are combined and hashed (e.g., hash = bcrypt("mypassword123"+ salt)). o The hash + salt is stored in the database.
IJAAR Vol. 6 No. 38 ISSN – 2347-7075 Mrs. Manisha Balkrushna Sonawane & Mrs. Rohini Prabhakar Pagar 55 2. During Login: • User enters their password. • The system retrieves the stored salt from the database. • bcrypt rehashes the input password with the same salt. • If the new hash matches the stored hash, authentication succeeds. 3. Comparison with Other Hashing Methods: Brute-Force Resistance: bcrypt's adjustable cost factor slows down attacks. Rainbow Table Immunity: Unique salts prevent precomputed hash attacks. Database Breach Protection: Even if hackers access hashes, they cannot reverse them. 4. Security Analysis: Brute-Force Resistance: bcrypt's adjustable cost factor slows down attacks. Rainbow Table Immunity: Unique salts prevent precomputed hash attacks. Database Breach Protection: Even if hackers access hashes, they cannot reverse them. 5. Implementation in Cloud Environments: Cloud providers (AWS, Azure, GCP) recommend bcrypt for: User Authentication Services (e.g., AWS Cognito, Firebase Auth). Database Security (e.g., encrypting passwords in MongoDB, PostgreSQL). Serverless Functions (e.g., AWS Lambda for password hashing).
IJAAR Vol. 6 No. 38 ISSN – 2347-7075 Mrs. Manisha Balkrushna Sonawane & Mrs. Rohini Prabhakar Pagar 56 6. Challenges and Future Work: Performance Overhead: bcrypt is slower than SHA-256, but this is intentional for security. Quantum Computing Threats: Future research may explore postquantum hashing algorithms. Multi-Factor Integration: Combining bcrypt with OTP or biometrics for enhanced security. Methodology: The proposed methodology for secure password storage and authentication in cloud computing involves the following steps: User Registration: o The user creates an account and provides a plain text password. o The backend system generates a unique salt using a cryptographically secure function like gensalt(). o The salt is appended to the plain text password, and the combined string is hashed using a secure hash function (e.g., bcrypt). o The hash and salt are stored in the cloud database. User Login: o During login, the user enters their password. o The backend retrieves the stored salt for the user from the database. o The salt is appended to the input password, and the combined string is hashed using the same hash function. o The resulting hash is compared to the stored hash. If they match, the user is authenticated. Security Measures: o Use of strong cryptographic hash functions resistant to collision attacks. o Unique salts for each user to prevent rainbow table attacks. o Secure storage of salts and hashes in the cloud database. o Implementation of rate limiting and account lockout mechanisms to prevent bruteforce attacks. Cloud Integration: o The hashing and salting process is implemented on the backend server. o The cloud database stores only the hashes and salts, ensuring that plain text passwords are never exposed. Conclusion: The proposed salted hashing technique provides a robust solution for securely storing user passwords in cloud environments. By generating unique salts for each user and hashing the combined passwordsalt string, the method ensures that even if the cloud database is compromised, the original passwords remain protected. The implementation of this technique in cloud systems significantly enhances security and mitigates the risks associated with passwordrelated attacks. Future work could explore the integration of advanced cryptographic techniques, such as multi-factor authentication and zeroknowledge proofs, to further strengthen cloud security.
IJAAR Vol. 6 No. 38 ISSN – 2347-7075 Mrs. Manisha Balkrushna Sonawane & Mrs. Rohini Prabhakar Pagar 57 The use of salted hashing in cloud computing not only protects user data but also builds trust in cloudbased services. As cloud adoption continues to grow, the importance of robust security measures cannot be overstated. This paper demonstrates that salted hashing is a practical and effective solution for securing user passwords in cloud environments. By adopting this approach, cloud service providers can ensure the confidentiality and integrity of user data, even in the face of sophisticated cyber-attacks. Acknowledgement: The authors would like to thank the developers of cryptographic libraries and cloud platforms for providing the tools necessary to implement secure password storage mechanisms. Special thanks to the research community for their contributions to the field of cloud security. This work was supported by my College teachers Team and my Friends. We are grateful to our colleagues and peers for their valuable feedback and suggestions during the preparation of this paper. Their insights have greatly contributed to the quality and depth of this research. We also acknowledge the support of our families and friends, who have encouraged us throughout this project. Finally, we extend our gratitude to the open-source community for developing and maintaining the cryptographic libraries used in this research. Their efforts have made it possible to implement secure and efficient password storage solutions in cloud environments. This work would not have been possible without their contributions. References: 1. Stallings, W. (2017). Cryptography and Network Security: Principles and Practice. Pearson. 2. Paar, C., & Pelzl, J. (2010). Understanding Cryptography: A Textbook for Students and Practitioners. Springer. 3. Provos, N., & Mazieres, D. (1999). "A Future-Adaptable Password Scheme." Proceedings of the USENIX Annual Technical Conference. 4. Biryukov, A., & Khovratovich, D. (2015). "Argon2: The Memory-Hard Function for Password Hashing." IACR Cryptology ePrint Archive. 5. OWASP Foundation. (2021). "Password Storage Cheat Sheet." Retrieved from https://owasp.org/www-project-cheatsheets/. 6. NIST.(2020). "Digital Identity Guidelines: Authentication andLifecycle Management." Special Publication 800-63B. 7. Krawczyk,H.(2016). "Salted Password Hashing - Doing it Right." Cryptography Engineering. 8. Ferguson, N., Schneier, B., & Kohno, T. (2010). Cryptography Engineering: Design Principles and Practical Applications. Wiley. 9. Percival,C.(2009). "Stronger Key Derivation via Sequential MemoryHard Functions." BSDCan Conference.