Paper 2026/1499

BF²: A Bloom-Filtered Brute-Force Framework for Multi-Target Password Recovery

Cansu Karakuzu Aslan, Hasso Plattner Institute, University of Potsdam
Wenzel Pünter, Hasso Plattner Institute, University of Potsdam
Christian Dörr, Hasso Plattner Institute, University of Potsdam
Abstract

Password-based authentication remains widespread, and large-scale sets of leaked hashes enable practical offline brute-force attacks. Multi-target attacks, which check candidates against large sets of hashes simultaneously, are particularly effective. Understanding the capabilities of low-cost platforms for such attacks is important to assess real-world password security risks. Therefore, we present BF², a modular and scalable FPGA–CPU framework that accelerates multi-target password recovery. BF² combines a password-candidate generator, a fully-pipelined NT hash core, a Bloom filter stage to filter non-matching candidates, and a multi-threaded host-side component that performs exact membership check using a perfect hash function. We implement BF² on the low-cost, \$199 NiteFury II board. With 16 parallel pipelines running at a 100 MHz clock frequency, our FPGA implementation generates $1.6\times10^9$ hashes/s. In our experiments, BF² demonstrates up to $7.5\times$ higher throughput than John the Ripper, and reduces power consumption by as much as $90\%$ compared to Hashcat on an RTX 5000.

Metadata
Available format(s)
PDF
Category
Implementation
Publication info
Published by the IACR in CIC 2026
Keywords
Brute-force attacksFPGA--CPU co-designBloom filterNT hash
Contact author(s)
cansu karakuzuaslan @ hpi de
wenzel puenter @ hpi de
christian doerr @ hpi de
History
2026-07-25: approved
2026-07-22: received
See all versions
Short URL
https://ia.cr/2026/1499
License
Creative Commons Attribution
CC BY

BibTeX

@misc{cryptoeprint:2026/1499,
      author = {Cansu Karakuzu Aslan and Wenzel Pünter and Christian Dörr},
      title = {{BF²}: A Bloom-Filtered Brute-Force Framework for Multi-Target Password Recovery},
      howpublished = {Cryptology {ePrint} Archive, Paper 2026/1499},
      year = {2026},
      url = {https://eprint.iacr.org/2026/1499}
}
Note: In order to protect the privacy of readers, eprint.iacr.org does not use cookies or embedded third party content.