Rancang Bangun Password Manager Berbasis Web Menggunakan Framework Django Dan Enkripsi Fernet
DOI:
https://doi.org/10.29408/jit.v9i2.35065Keywords:
Password Manager, Django, Fernet Encryption, PBKDF2, Zero-Knowledge, Web SecurityAbstract
Most prior password manager studies rely on basic encryption without strong key derivation and have not consistently implemented a zero-knowledge architecture, leaving encrypted user data potentially accessible to service providers or third parties. This research contributes by designing and building a web-based password manager that integrates three security layers within a unified Django ecosystem: PBKDF2 key derivation with 100,000 SHA-256 iterations, hardware-based unique random salt per user (os.urandom), and authenticated Fernet encryption (AES-128-CBC + HMAC-SHA256). The novelty of this research lies in the strict enforcement of the zero-knowledge principle, where the master password is never stored in the database, making credentials inaccessible even to system administrators. The combination of personalized salt and PBKDF2 also ensures that two users sharing an identical master password always produce distinct encryption keys — a feature not found in existing Django-based implementations. Black Box Testing across ten functional and security scenarios yielded a 100% success rate, covering CRUD operations, unauthorized access rejection, ciphertext tampering detection, and cross-user salt uniqueness verification. The results demonstrate that integrating PBKDF2, unique salt, and Fernet within the Django framework produces a transparent, secure credential storage system resilient to brute force attacks, rainbow table attacks, and database-level data manipulation.
References
[1] N. Weckwerth, B. Xia, and J. Zhang, “Password Manager Security,” pp. 1–11, 2020.
[2] R. Holthouse, S. Owens, and S. Bhunia, “The 23andMe Data Breach : Analyzing Credential Stuffing Attacks , Security Vulnerabilities , and Mitigation Strategies”.
[3] A. Cherry, K. Barmpis, and S. F. Shahandashti, “The Emperor is Now Clothed : A Secure Governance Framework for Web User Authentication through Password Managers ⋆,” 2024.
[4] I. Contributors, “Cryptography Documentation,” 2026.
[5] J. Kim, M. Song, M. Seo, Y. Jin, S. Shin, and J. Kim, “P ASS RE FINDER -FL : Privacy-Preserving Credential Stuffing Risk Prediction via Graph-Based Federated Learning for Representing Password Reuse between Websites ⋆”.
[6] S. F. Manullang and J. Sembiring, “Implementasi Kriptografi Pengamanan Data File Dokumen Menggunakan Algoritma Advanced Encryption Standard Mode Chiper Block Chaining,” pp. 87–95, 2001.
[7] C. Computing and S. Id, “Enhanced File Transfer Security in Django Web Applications with TOTP-Based Multi-Factor Authentication and Blowfish / AES Encryption on AWS Cloud”.
[8] Z. Li, W. He, D. Akhawe, and D. Song, “The Emperor ’ s New Password Manager : Security Analysis of Web-based Password Managers,” 2014.
[9] A. A. S. Alqahtani, “Key Derivation : A Dynamic PBKDF2 Model for Modern Cryptographic Systems,” 2025.
[10] A. Sha-, N. Sitorus, J. Sharon, G. Sinaga, and S. L. Samosir, “Analisis Kinerja Algoritma Hash pada Keamanan Data : Perbandingan,” vol. 2, no. 2, 2024.
[11] P. A. Cabarcos, K. Security, and P. Mayer, “A Longitudinal Study on the Usability of Password Managers for Novice Users This paper is included in the Proceedings of the Twenty-First Symposium on Usable Privacy and Security .,” 2025.
[12] A. A. S. Alqahtani, “Key Derivation : A Dynamic PBKDF2 Model for Modern Cryptographic Systems,” 2025.
[13] M. Ridwan and A. R. Yusuf, “Framework Bootstrap Untuk Pengelolaan Data Akademik Dan Administrasi,” vol. 2, no. 2, pp. 112–124, 2025.
[14] D. F. Sari, A. M. Sari, I. Janah, and J. S. Asri, “Analisis Komparasi Algoritma Hash ( Md5 , SHA-2 , SHA-3 , SHA-512 ) Dan Teknik Salting Untuk Peningkatan Keamanan Data,” vol. 6, no. 1, pp. 7379–7384, 2026.
[15] S. Salamatian, W. Huleihel, A. Beirami, A. Cohen, and M. Muriel, “Centralized vs Decentralized Targeted Brute-Force Attacks : Guessing with Side-Information,” pp. 1–14, 2017.
[16] A. H. Jaya, A. Rosyidi, P. Studi, M. Informatika, and S. Indonesia, “Implementasi Aes-256 Dalam Aplikasi Manajemen Password Menggunakan Bahasa Pemrograman Java Berbasis,” no. November 2024, pp. 1187–1196.
[17] N. F. Aprilia, D. Mafazi, A. R. Muchtar, K. Afif, A. Rohim, and N. Ilham, “Penerapan Algoritma AES untuk Enkripsi pada Halaman Register serta Penerapan AES untuk Deskripsi pada Halaman Login Website,” vol. 1, no. April, pp. 75–82, 2023.
[18] E. Adventure, “Pengujian black box pada Website dengan Metode Robustness Testing,” vol. 3, no. 2, pp. 93–96, 2022.
[19] S. Informatika, U. Majalengka, F. Recognation, and S. Keamanan, “4 1234,” vol. 7, no. 1, pp. 205–215, 2024.
[20] R. Rahman, A. Yosua, and N. Leksona, “Serangan Man-In-The-Middle ( MITM ) di Jaringan Publik : Studi dan Solusi Simulasi Serangan Password Cracking Menggunakan Hydra,” vol. 1, no. 4, pp. 2145–2156, 2025.
Downloads
Published
How to Cite
Issue
Section
License
Copyright (c) 2026 Infotek: Jurnal Informatika dan Teknologi

This work is licensed under a Creative Commons Attribution 4.0 International License.
Semua tulisan pada jurnal ini menjadi tanggung jawab penuh penulis. Jurnal Infotek memberikan akses terbuka terhadap siapapun agar informasi dan temuan pada artikel tersebut bermanfaat bagi semua orang. Jurnal Infotek ini dapat diakses dan diunduh secara gratis, tanpa dipungut biaya sesuai dengan lisense creative commons yang digunakan.
Jurnal Infotek is licensed under a Creative Commons Attribution 4.0 International License.
Statistik Pengunjung


