PHP password_hash() Function

PHP 密码散列算法PHP Password Hashing Algorithms

The password_hash() function is used to create a hash of a password.

PHP Version Requirements: PHP 5 >= 5.5.0, PHP 7

Syntax

string password_hash ( string $password , int $algo [, array $options ] )

password_hash() uses a sufficiently strong one-way hashing algorithm to create a hash of a password. password_hash() is compatible with crypt(). Therefore, password hashes created by crypt() can also be used with password_hash().

Currently supported algorithms:

  • PASSWORD_DEFAULT- Uses the bcrypt algorithm (default in PHP 5.5.0). Note that this constant will change as PHP adds newer, stronger algorithms. Therefore, the length of the result generated using this constant may change in the future. Therefore, the column in the database that stores the result can exceed 60 characters (preferably 255 characters).
  • PASSWORD_BCRYPT- UseCRYPT_BLOWFISHthe algorithm to create a hash. This will produce a hash compatible with using "$2y$" prefix.crypt()The result will be a 60-character string, or FALSE on failure.FALSE。
  • PASSWORD_ARGON2I- Use the Argon2 hashing algorithm to create a hash.

Options supported by PASSWORD_BCRYPT:

  • salt (string) - Manually provide a salt for hashing the password. This avoids automatically generating a salt.

    If this value is omitted, password_hash() will automatically generate a random salt for each password hash. This is an intentional mode of operation.

    Note: The salt option has been deprecated as of PHP 7.0.0. It is now better to simply use the default generated salt.

  • cost (integer) - Represents the cost used by the algorithm. Examples of cost values can be found on the crypt() page.

    When omitted, the default value is 10. This cost is a good baseline, but you may increase this value depending on your hardware.

Options supported by PASSWORD_ARGON2I:

  • memory_cost (integer) - The maximum memory (in bytes) to be used when calculating the Argon2 hash. Default value:PASSWORD_ARGON2_DEFAULT_MEMORY_COST。

  • time_cost (integer) - The maximum time to be used when calculating the Argon2 hash. Default value:PASSWORD_ARGON2_DEFAULT_TIME_COST。

  • threads (integer) - The maximum number of threads to be used when calculating the Argon2 hash. Default value:PASSWORD_ARGON2_DEFAULT_THREADS。

Parameter description:

  • password: A hash value created by password_hash().

  • algo: A password algorithm constant used to indicate the algorithm when hashing the password.

  • options: An associative array containing options. Currently two options are supported: salt, the salt (interference string) added when hashing the password, and cost, used to indicate the number of recursive layers of the algorithm. Examples of these two values can be found on the crypt() page.

    When omitted, a random salt and the default cost will be used.

Return Value

Returns the hashed password, or FALSE on failure.

Examples

Example 1

<?php /** * We want to hash the password using the default algorithm * Currently BCRYPT, which produces a 60-character result. * * Please note that over time, the default algorithm may change, * so the storage space needed should exceed 60 characters (255 is fine).*/ echo password_hash("rasmuslerdorf", PASSWORD_DEFAULT); ?>

The output is:

$2y$10$.vGA1O9wmRjrwAVXD98HNOgsNpDczlqm3Jq7KnEd1rVAGv3Fykk1a

Example 2

<?php /** * In this case, we increase the cost for BCRYPT to 12. * Note that we have switched to, which will always produce 60 characters.*/ $options = [ 'cost' => 12, ]; echo password_hash("rasmuslerdorf", PASSWORD_BCRYPT, $options); ?>

The output is:

$2y$12$QjSH496pcT5CEbzjD/vtVeH03tfHKFy36d4J0Ltp3lRtee9HDxY3K

Example 3

Example of manually setting the salt value

<?php /** * Note that the salt here is randomly generated. * Never use a fixed salt, or a salt that is not randomly generated. * * In most cases, you can let password_hash generate a random salt for you automatically.*/ $options = [ 'cost' => 11, 'salt' => mcrypt_create_iv(22, MCRYPT_DEV_URANDOM), ]; echo password_hash("rasmuslerdorf", PASSWORD_BCRYPT, $options); ?>

The output is:

$2y$11$q5MkhSBtlsJcNEVsYh64a.aCluzHnGog7TQAKVmQwO9C8xb.t89F.

Example 4

Example of password_hash() for finding the optimal cost

<?php /** * This example benchmarks the server to test how high a cost the server can handle. * You can set the highest value without significantly slowing down the server. * 8-10 is a good baseline; the higher the better if the server is fast enough. * The following code targets ≤ 50 milliseconds, * suitable for systems handling interactive logins.*/ $timeTarget = 0.05; //50 milliseconds $cost = 8; do { $cost++; $start = microtime(true); password_hash("test", PASSWORD_BCRYPT, ["cost" => $cost]); $end = microtime(true); } while (($end - $start) < $timeTarget); echo "Appropriate Cost Found: " . $cost; ?>

The output is:

Appropriate Cost Found: 10

Example 5

Example using Argon2:

<?php echo 'Argon2 hash: ' . password_hash('rasmuslerdorf', PASSWORD_ARGON2I); ?>

The output is:

Argon2 hash: $argon2i$v=19$m=1024,t=2,p=2$YzJBSzV4TUhkMzc3d3laeg$zqU/1IN0/AogfP4cmSJI1vc8lpXRW9/S0sYY2i2jHT0

PHP 密码散列算法PHP Password Hashing Algorithms

Other Extensions