IMPLEMENTATION OF PASSWORD HASHING USING BCRYPT IN A WEB-BASED LOGIN SYSTEM
Keywords:
BCrypt, Password Hashing, Login System, Data Security, PHP, Web-Based SystemAbstract
The evolution of web-based systems has heightened the need for authentication mechanisms capable of safeguarding user data and credentials. A persistent issue in login system development is the storage of passwords in plaintext, which increases the risk of misuse should the database be accessed by unauthorized parties. This study aims to implement the BCrypt algorithm as a password hashing method within a PHP-based web login system. An experimental research methodology was employed, utilizing an approach involving direct implementation and testing, supported by a literature review on password security, hashing, BCrypt, and user authentication. Implementation involved using the `password_hash()` function with the `PASSWORD_BCRYPT` algorithm to generate password hashes prior to database storage, while the `password_verify()` function was used for the verification process. Testing was conducted across several scenarios: registration, logging in with a correct password, logging in with an incorrect password, and testing the same password across different hashing operations. The results demonstrate that BCrypt successfully converts passwords into hash values, ensuring that original passwords are not stored directly in the database. Correct passwords were successfully verified, granting user access, whereas incorrect passwords were rejected. Furthermore, identical passwords yielded different hash values due to the use of salts. Based on these findings, BCrypt serves as a viable password security method for web-based login systems, offering superior protection compared to plaintext password storage.
References
[1] Nugroho Dwi Aji, Tomi Tri Sujaka, Husain, Ondi Asroni, and Kurniadin Abd. Latif, “Analisis Dan Implementasi Algoritma Bcrypt Dengan Affine Cipher Untuk Pengamanan Password Pada Aplikasi Web,” Cyber Secur. dan Forensik Digit., vol. 8, no. 1, pp. 1–9, 2025, doi: 10.14421/csecurity.2025.8.1.5076.
[2] N. Jannah, L. Istianah, M. Tahir, and K. Kunci, “Implementasi Cryptography Based Multilayer Authentication pada Sistem Login Berbasis Web Menggunakan Bcrypt Hashing dan One Time Password (OTP) STATUS ARTIKEL,” Surabaya J. Sist. Cerdas dan Rekayasa, vol. 8, no. 1, pp. 2656–7504, 2026.
[3] A. Saputra and R. Kurniati, “Aplikasi Penjualan Udang Pepai Berbasis Web Dengan Keamanan Hash Password Menggunakan Algoritma Bcrypt,” JATI (Jurnal Mhs. Tek. Inform., vol. 10, no. 1, pp. 726–733, 2026, doi: 10.36040/jati.v10i1.16883.
[4] S. Erdi, P. Sohidin, H. Prasetyo Utomo, and A. Ahmadi, “Penerapan Algoritma Bcrypt untuk Pengamanan Password pada Sistem Informasi Akademik (SIAK) (Studi Kasus : Universitas Langlangbuana),” Infosecure, vol. 6, no. 2, pp. 1–5, 2025, [Online]. Available: https://jurnal-pasca.unla.ac.id/infosecure/article/view/v6n2_01
[5] R. M. Liauren, B. Zaman, and S. Bahri, “Implementasi Algortima Aes Dan Bcrypt Untuk Pengamanan Data Pengguna Pada Website Jahitku,” KHARISMA Tech, vol. 20, no. 1, pp. 57–71, 2025, doi: 10.55645/kharismatech.v20i1.535.
[6] G. D. M. Zulma, H. B. Seta, and T. Yuniati, “Implementasi Algoritma Aes Dan Bcrypt Untuk Pengamanan File Dokumen,” Inform. J. Ilmu Komput., vol. 18, no. 2, p. 163, 2022, doi: 10.52958/iftk.v18i2.4667.
[7] A. Rahayu, G. Abdillah, and H. Ashaury, “Pengamanan Menggunakan Algoritma Aes (Advanced Encryption Standard) Dan Bcrypt (Blowfish Crypt) Pada File Dokumen,” JATI (Jurnal Mhs. Tek. Inform., vol. 8, no. 6, pp. 11627–11634, 2024, doi: 10.36040/jati.v8i6.11498.
[8] M. M. Subagio, R. Mumpuni, and A. L. Nurlaili, “Design of Web-Based Decision Support System Using AHP and bcrypt Security,” bit-Tech, vol. 8, no. 3, pp. 3987–3998, 2026, doi: 10.32877/bt.v8i3.3769.
[9] R Dermawan, and R Rahman, “Penerapan Keamanan Hashing Password Pada Sistem Penjualan Bibbi Shop Berbasis Web,” vol. 1, no. 2, pp. 66–69, 2025.
[10] N. Ramadani and E. maiyana, “Perancangan dan Implementasi Sistem Informasi Perpustakaan BerbasisWeb Menggunakan Framework Laravel untuk Optimalisasi PengelolaanBuku dan Transaksi Peminjaman,” Neotech J. Inf. Technol. Innov., vol. 1, no. 01, pp. 01–17, 2026.
[11] T. Mary and N. Febriyani, “Peningkatan Keamanan Sistem Informasi Berbasis Laravel 12 dengan Rate Limiting dan Role-Based Access Control (RBAC),” J. Teknol. Dan Sist. Inf. Bisnis, vol. 7, no. 3, pp. 473–481, 2025, doi: 10.47233/jteksis.v7i3.1976.
[12] I. Q. Lubis and A. Zulherry, “Implementasi keamanan website dari serangan Cross Site Request Forgery menggunakan algoritma HMAC-SHA256 pada framework Laravel,” Hello World J. Ilmu Komput., vol. 5, no. 1, pp. 47–58, 2026.
[13] G. Maulana and U. I. Indragiri, “Analisis Keamanan Sistem Autentikasi Login Berbasis Framework Laravel,” vol. 1, no. 1, pp. 18–25, 2026.
[14] A. Fitriyani, H. Lubis, Y. Yaddarabullah, and R. Sari, “Keamanan Sistem Login Menggunakan Multifactor Authentication dan Algoritma Hashing,” J. Inf. Syst. Informatics Comput., vol. 9, no. 2, p. 263, 2025, doi: 10.52362/jisicom.v9i2.2137.
[15] D. Febrian et al., “Implementation of Bcrypt Algorithm on Website-Based Hashing Generator Using Laravel Framework,” J. Inf. Syst. Informatics Comput., vol. 7, no. 2, p. 199, 2023, doi: 10.52362/jisicom.v7i2.1130.



