Preprint has been submitted for publication in journal
Preprint / Version 1

Design and Development of a Password Manager With Multi-Layer Encryption Built With Rust and TypeScript

Rancang Bangun Password Manager Dengan Enkripsi Multi-Layer Berbasis Rust dan Typescript

##article.authors##

DOI:

https://doi.org/10.21070/ups.11686

Keywords:

Password Manager, Argon2, ChaCha20-Poly1305, Rust, Enkripsi Multi-Layer

Abstract

The increasing reliance of society on digital services amplifies the risk to personal data security due to the use of weak passwords. Large-scale data breach incidents prove that traditional authentication is vulnerable to brute-force attacks. Although password manager applications are available, some still have security vulnerabilities server-side protection. This research proposes the design and development of a web-based password manager application that implements Zero-Knowledge principles with a multi-layer encryption scheme. The system is developed using Rust and TypeScript programming languages. The implemented cryptographic approach utilizes the Argon2id algorithm for the key derivation process, which is resistant to GPU brute-force attacks, and XChaCha20-Poly1305 for symmetric data encryption. All cryptographic computations are performed entirely on the client side using a Rust WebAssembly module. This design ensures that only the ciphertext, nonce, and salt are sent to the database, while the Master Password and encryption keys never leave the user's local device memory.

Downloads

Download data is not yet available.

References

R. A. Oliveira and H. M. N. da S. Oliveira, “From RockYou to RockYou2024: Analyzing Password Patterns Across Generations, Their Use in Industrial Systems and Vulnerability to Password Guessing Attacks,” Journal of Internet Services and Applications, vol. 16, no. 1, pp. 43–57, 2025, doi: 10.5753/jisa.2025.5041.

W. Y. Aditama, I. R. Hikmah, and D. F. Priambodo, “Analisis Komparatif Keamanan Aplikasi Pengelola Kata Sandi Berbayar Lastpass, 1Password, dan Keeper Berdasarkan ISO/IEC 25010,” Jurnal Teknologi Informasi dan Ilmu Komputer, vol. 10, no. 4, p. 857, 2023, doi: 10.25126/jtiik.20231036544.

E. Chatzoglou, V. Kampourakis, Z. Tsiatsikas, G. Karopoulos, and G. Kambourakis, “Keep Your Memory Dump Shut: Unveiling Data Leaks in Password Managers,” in IFIP Advances in Information and Communication Technology, 2024, pp. 61–75. doi: 10.1007/978-3-031-65175-5_5.

H. Setiawan, R. Dijaya, J. Mojopahit, and B. Sidoarjo, Buku Ajar Audit Sistem Informasi di Era Digital: Teori, Praktik, dan Tren Terkini Diterbitkan oleh UMSIDA PRESS. 2024.

V. Navalino, A. F. Wadjdi, Y. Asnar, R. Agus, and G. Gultom, “Securing the Internet of Battlefield Things with ChaCha20- Poly1305 Encryption Architecture for Resource-Constrained Devices,” vol. 42, no. 2, pp. 547–555, 2024.

A. Cherry, “A Secure Password Manager Governance Framework for Web User Authentication,” no. April, 2024.

M. Shirvanian, C. R. Price, M. Jubur, N. Saxena, S. Jarecki, and H. Krawczyk, “A hidden-password online password manager,” Proceedings of the ACM Symposium on Applied Computing, vol. 20, pp. 1683–1686, 2021, doi: 10.1145/3412841.3442131.

H. Padalia, H. Patel, A. Deshmukh, M. Patil, A. Kumar, and N. Kumar Nrip, “A Study on Password Manager: Users’ Perspective,” in 2023 International Conference on Computational Intelligence for Information, Security and Communication Applications (CIISCA), Bengaluru, India: IEEE, Jun. 2023, pp. 72–75. doi: 10.1109/CIISCA59740.2023.00024.

A. Daftardar, B. Reagen, and S. Garg, “SZKP: A Scalable Accelerator Architecture for Zero-Knowledge Proofs,” in Proceedings of the 2024 International Conference on Parallel Architectures and Compilation Techniques, Long Beach CA USA: ACM, Oct. 2024, pp. 271–283. doi: 10.1145/3656019.3676898.

Haroon Rashid Hammood Al Dallal and Wijdan Noaman Marzoog Al Mukhtar, “A QR Code Used for Personal Information Based On Multi-Layer Encryption System,” Int. J. Interact. Mob. Technol., vol. 17, no. 09, pp. 44–56, May 2023, doi: 10.3991/ijim.v17i09.38777.

A. Sharma, S. Sharma, S. R. Tanksalkar, S. Torres-Arias, and A. Machiry, “Rust for Embedded Systems: Current State and Open Problems,” in Proceedings of the 2024 on ACM SIGSAC Conference on Computer and Communications Security, Salt Lake City UT USA: ACM, Dec. 2024, pp. 2296–2310. doi: 10.1145/3658644.3690275.

P. P. Ray, “An Overview of WebAssembly for IoT: Background, Tools, State-of-the-Art, Challenges, and Future Directions,” Future Internet, vol. 15, no. 8, p. 275, Aug. 2023, doi: 10.3390/fi15080275.

S. Islam, “JavaScript alternative (TypeScript) and its effectiveness in web development”.

Y. Duan, D. Wang, and Y. Fu, “Security Analysis of Master-Password-Protected Password Management Protocols”.

K. Divya and P. S. Uma Priyadarsini, “Securing IoMT data with Algorand blockchain, XChaCha20-Poly1305 encryption, and decentralized storage alternatives,” Scientific Reports, vol. 15, no. 1, pp. 1–20, 2025, doi: 10.1038/s41598-025-08527-9.

A. A. S. AlQahtani, “Key Derivation: A Dynamic PBKDF2 Model for Modern Cryptographic Systems,” Cryptography, vol. 9, no. 2, 2025, doi: 10.3390/cryptography9020039.

S. Eum, H. Kim, M. Song, and H. Seo, “Optimized Implementation of Argon2 Utilizing the Graphics Processing Unit,” Applied Sciences (Switzerland), vol. 13, no. 16, 2023, doi: 10.3390/app13169295.

T. O. Oladoyinbo, “The Importance Of Data Encryption Algorithm In Data Security,” vol. 11, no. 2, pp. 10–16, 2024, doi: 10.9790/0050-11021016.

M. Golinelli, F. Bonomi, and B. Crispo, “The Nonce-nce of Web Security: An Investigation of CSP Nonces Reuse,” Lecture Notes in Computer Science (including subseries Lecture Notes in Artificial Intelligence and Lecture Notes in Bioinformatics), vol. 14399 LNCS, pp. 459–475, 2024, doi: 10.1007/978-3-031-54129-2_27.

V. Björkén and T. Gustafsson, “Evaluating the Effectiveness of LSTM-Based Password Generation versus Traditional Password Cracking Techniques on RockYou: Reassessing an Old Dataset with New Tools,” vol. TRITA – EE, no. 2025:0000, 2025.

A. Atadoga, O. A. Farayola, and B. S. Ayinla, “a Comparative Review of Data Encryption,” vol. 5, no. 2, pp. 447–460, 2024, doi: 10.51594/csitrj.v5i2.807.

A. Maspupah, “Literature Review: Advantages and Disadvantages of Black Box and White Box Testing Methods,” Jurnal Techno Nusa Mandiri, vol. 21, no. 2, pp. 151–162, 2024, doi: 10.33480/techno.v21i2.5776.

A. S. Lubis and M. P. A. Ginting, “Pengujian Aplikasi Berbasis Web Data SKA Menggunakan Metode Black Box Testing,” Cosmic Jurnal Teknik, vol. 1, no. 1, pp. 41–48, 2024.

Posted

2026-08-12