Rancang Bangun Password Manager Berbasis Web Menggunakan Framework Django Dan Enkripsi Fernet

Authors

  • Widarmawati Waruwu Universitas Bina Sarana Informatika
  • Yusnia Budiarti Universitas Bina Sarana Informatika
  • Mutiara Nazwah Universitas Bina Sarana Informatika
  • Angga Wibowo Saputro Universitas Bina Sarana Informatika
  • Diwan Mardianus Laia Universitas Bina Sarana Informatika

DOI:

https://doi.org/10.29408/jit.v9i2.35065

Keywords:

Password Manager, Django, Fernet Encryption, PBKDF2, Zero-Knowledge, Web Security

Abstract

Most prior password manager studies rely on basic encryption without strong key derivation and have not consistently implemented a zero-knowledge architecture, leaving encrypted user data potentially accessible to service providers or third parties. This research contributes by designing and building a web-based password manager that integrates three security layers within a unified Django ecosystem: PBKDF2 key derivation with 100,000 SHA-256 iterations, hardware-based unique random salt per user (os.urandom), and authenticated Fernet encryption (AES-128-CBC + HMAC-SHA256). The novelty of this research lies in the strict enforcement of the zero-knowledge principle, where the master password is never stored in the database, making credentials inaccessible even to system administrators. The combination of personalized salt and PBKDF2 also ensures that two users sharing an identical master password always produce distinct encryption keys — a feature not found in existing Django-based implementations. Black Box Testing across ten functional and security scenarios yielded a 100% success rate, covering CRUD operations, unauthorized access rejection, ciphertext tampering detection, and cross-user salt uniqueness verification. The results demonstrate that integrating PBKDF2, unique salt, and Fernet within the Django framework produces a transparent, secure credential storage system resilient to brute force attacks, rainbow table attacks, and database-level data manipulation.

References

[1] N. Weckwerth, B. Xia, and J. Zhang, “Password Manager Security,” pp. 1–11, 2020.

[2] R. Holthouse, S. Owens, and S. Bhunia, “The 23andMe Data Breach : Analyzing Credential Stuffing Attacks , Security Vulnerabilities , and Mitigation Strategies”.

[3] A. Cherry, K. Barmpis, and S. F. Shahandashti, “The Emperor is Now Clothed : A Secure Governance Framework for Web User Authentication through Password Managers ⋆,” 2024.

[4] I. Contributors, “Cryptography Documentation,” 2026.

[5] J. Kim, M. Song, M. Seo, Y. Jin, S. Shin, and J. Kim, “P ASS RE FINDER -FL : Privacy-Preserving Credential Stuffing Risk Prediction via Graph-Based Federated Learning for Representing Password Reuse between Websites ⋆”.

[6] S. F. Manullang and J. Sembiring, “Implementasi Kriptografi Pengamanan Data File Dokumen Menggunakan Algoritma Advanced Encryption Standard Mode Chiper Block Chaining,” pp. 87–95, 2001.

[7] C. Computing and S. Id, “Enhanced File Transfer Security in Django Web Applications with TOTP-Based Multi-Factor Authentication and Blowfish / AES Encryption on AWS Cloud”.

[8] Z. Li, W. He, D. Akhawe, and D. Song, “The Emperor ’ s New Password Manager : Security Analysis of Web-based Password Managers,” 2014.

[9] A. A. S. Alqahtani, “Key Derivation : A Dynamic PBKDF2 Model for Modern Cryptographic Systems,” 2025.

[10] A. Sha-, N. Sitorus, J. Sharon, G. Sinaga, and S. L. Samosir, “Analisis Kinerja Algoritma Hash pada Keamanan Data : Perbandingan,” vol. 2, no. 2, 2024.

[11] P. A. Cabarcos, K. Security, and P. Mayer, “A Longitudinal Study on the Usability of Password Managers for Novice Users This paper is included in the Proceedings of the Twenty-First Symposium on Usable Privacy and Security .,” 2025.

[12] A. A. S. Alqahtani, “Key Derivation : A Dynamic PBKDF2 Model for Modern Cryptographic Systems,” 2025.

[13] M. Ridwan and A. R. Yusuf, “Framework Bootstrap Untuk Pengelolaan Data Akademik Dan Administrasi,” vol. 2, no. 2, pp. 112–124, 2025.

[14] D. F. Sari, A. M. Sari, I. Janah, and J. S. Asri, “Analisis Komparasi Algoritma Hash ( Md5 , SHA-2 , SHA-3 , SHA-512 ) Dan Teknik Salting Untuk Peningkatan Keamanan Data,” vol. 6, no. 1, pp. 7379–7384, 2026.

[15] S. Salamatian, W. Huleihel, A. Beirami, A. Cohen, and M. Muriel, “Centralized vs Decentralized Targeted Brute-Force Attacks : Guessing with Side-Information,” pp. 1–14, 2017.

[16] A. H. Jaya, A. Rosyidi, P. Studi, M. Informatika, and S. Indonesia, “Implementasi Aes-256 Dalam Aplikasi Manajemen Password Menggunakan Bahasa Pemrograman Java Berbasis,” no. November 2024, pp. 1187–1196.

[17] N. F. Aprilia, D. Mafazi, A. R. Muchtar, K. Afif, A. Rohim, and N. Ilham, “Penerapan Algoritma AES untuk Enkripsi pada Halaman Register serta Penerapan AES untuk Deskripsi pada Halaman Login Website,” vol. 1, no. April, pp. 75–82, 2023.

[18] E. Adventure, “Pengujian black box pada Website dengan Metode Robustness Testing,” vol. 3, no. 2, pp. 93–96, 2022.

[19] S. Informatika, U. Majalengka, F. Recognation, and S. Keamanan, “4 1234,” vol. 7, no. 1, pp. 205–215, 2024.

[20] R. Rahman, A. Yosua, and N. Leksona, “Serangan Man-In-The-Middle ( MITM ) di Jaringan Publik : Studi dan Solusi Simulasi Serangan Password Cracking Menggunakan Hydra,” vol. 1, no. 4, pp. 2145–2156, 2025.

Downloads

Published

21-07-2026

How to Cite

Waruwu, W., Budiarti, Y., Nazwah, M., Saputro, A. W., & Laia, D. M. (2026). Rancang Bangun Password Manager Berbasis Web Menggunakan Framework Django Dan Enkripsi Fernet. Infotek: Jurnal Informatika Dan Teknologi, 9(2), 537–548. https://doi.org/10.29408/jit.v9i2.35065

Similar Articles

<< < 4 5 6 7 8 9 10 11 12 13 > >> 

You may also start an advanced similarity search for this article.