PHP crypt()Functions


PHP String 参考手册PHP String Reference Manual

Definition and Usage

The crypt() function returns a string encrypted using DES, Blowfish, or MD5 algorithms.

The behavior of this function differs on different operating systems, and some operating systems support more than one algorithm type. During installation, PHP checks what algorithms are available and which algorithm to use.

The exact algorithm depends on the format and length of the salt parameter. Salt can make encryption more secure by increasing the number of strings generated by a specific string combined with a specific encryption method.

Here are some constants that are used with the crypt() function. These constant values are set by PHP at installation time.

Constants:

  • [CRYPT_SALT_LENGTH] - Default encryption length. With standard DES encryption, the length is 2.
  • [CRYPT_STD_DES] - Standard DES-based encryption has a 2-character salt from the alphabet "./0-9A-Za-z". Using invalid characters in the salt will cause the function to fail.
  • [CRYPT_EXT_DES] - Extended DES-based encryption has a 9-character salt, consisting of 1 underscore, followed by 4 bytes of iteration count and 4 bytes of salt. These are encoded as printable characters, 6 bits per character, least significant character first. Values 0 to 63 are encoded as "./0-9A-Za-z". Using invalid characters in the salt will cause the function to fail.
  • [CRYPT_MD5] - MD5 encryption has a 12-character salt, starting with $1$.
  • [CRYPT_BLOWFISH] - Blowfish encryption has a salt starting with $2a$, $2x$, or $2y$, a two-digit cost parameter "$", and 22 characters from the alphabet "./0-9A-Za-z". Using characters outside the alphabet will cause the function to return a string of length 0. The "$" parameter is the base-2 logarithm of the iteration count for the Blowfish-based hashing algorithm and must be in the range 04-31. Values outside this range will cause the function to fail.
  • [CRYPT_SHA_256] - SHA-256 encryption has a 16-character salt, starting with $5$.If the salt string starts with "rounds=<N>$", the numeric value of N is used to indicate the number of times the hashing loop is executed, similar to the cost parameter in Blowfish. The default number of rounds is 5000, the minimum is 1000, and the maximum is 999,999,999. Any value of N outside this range will be converted to the nearest boundary value.
  • [CRYPT_SHA_512] - SHA-512 encryption has a 16-character salt, starting with $6$.If the salt string starts with "rounds=<N>$", the numeric value of N is used to indicate the number of times the hashing loop is executed, similar to the cost parameter in Blowfish. The default number of rounds is 5000, the minimum is 1000, and the maximum is 999,999,999. Any value of N outside this range will be converted to the nearest boundary value.

On systems where this function supports multiple algorithms, the constants above are set to "1" if supported, otherwise set to "0".

Notes:There is no corresponding decryption function. The crypt() function uses a one-way algorithm.


Syntax

crypt(str,salt)

Parameters Description
str Required. Specifies the string to be encoded.
salt Optional. A string used to increase the number of encoded characters, making the encoding more secure. If the salt parameter is not provided, a random one is generated each time the function is called.

Technical Details

Return Value: Returns the encrypted string, or if it fails, returns a string of fewer than 13 characters that is guaranteed to be different from the salt.
PHP Version: 4+
Changelog: In PHP 5.3.7, $2x$ and $2y$ Blowfish modes were added to handle potential high-bit attacks.

In PHP 5.3.2, the constants SHA-256 and SHA-512 were added.

As of PHP 5.3.2, Blowfish returns a "failure" string ("*0" or "*1") on invalid rounds, rather than falling back to DES.

As of PHP 5.3.0, PHP bundles its own MD5 encryption implementation, standard DES implementation, extended DES implementation, and Blowfish algorithm. If the system does not support the above algorithms, PHP's bundled algorithm implementation will be used.


Examples

Example 1

<?php $hashed_password = crypt('mypassword'); //Automatically generate salt /*You should use the complete result returned by crypt() as the salt for password verification, to avoid problems caused by using different hashing algorithms. (As mentioned above, password hashes based on the standard DES algorithm use a 2-character salt, while hashes based on the MD5 algorithm use a 12-character salt.)*/ if (hash_equals($hashed_password, crypt($user_input, $hashed_password))) { echo "Password verified!"; } ?>

Example 2

Using htpasswd for crypt() encryption:

<?php //Setting a password $password = 'mypassword'; //Get the hash value using an automatic salt $hash = crypt($password); ?>

Example 1

In this example, we use different hash types:

<?php if (CRYPT_STD_DES == 1) { echo 'Standard DES: ' . crypt('rasmuslerdorf', 'rl') . "\n"; } if (CRYPT_EXT_DES == 1) { echo 'Extended DES: ' . crypt('rasmuslerdorf', '_J9..rasm') . "\n"; } if (CRYPT_MD5 == 1) { echo 'MD5: ' . crypt('rasmuslerdorf', '$1$rasmusle$') . "\n"; } if (CRYPT_BLOWFISH == 1) { echo 'Blowfish: ' . crypt('rasmuslerdorf', '$2a$07$usesomesillystringforsalt$') . "\n"; } if (CRYPT_SHA256 == 1) { echo 'SHA-256: ' . crypt('rasmuslerdorf', '$5$rounds=5000$usesomesillystringforsalt$') . "\n"; } if (CRYPT_SHA512 == 1) { echo 'SHA-512: ' . crypt('rasmuslerdorf', '$6$rounds=5000$usesomesillystringforsalt$') . "\n"; } ?>

The code above outputs the following (depending on the operating system):

Standard DES: rl.3StKT.4T8M
Extended DES: _J9..rasmBYk8r9AiWNc
MD5:          $1$rasmusle$rISCgZzpwk3UhDidwXvin0
Blowfish:     $2a$07$usesomesillystringfore2uDLvp1Ii2e./U9C8sBjqp8I90dH6hi
SHA-256:      $5$rounds=5000$usesomesillystri$KqJWpanXZHKq2BOB43TSaYhEWsQ1Lr5QNyPCDH/Tp.6
SHA-512:      $6$rounds=5000$usesomesillystri$D4IrlXatmP7rx3P3InaxBeoomnAihCKRVQP22JZ6EY47Wc6BkroIuUUBOov1i.S5KPgErtP/EN5mcO.ChWQW21



PHP String 参考手册PHP String Reference Manual Other Extensions