Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

iTechGuides is reader-supported. When you buy through links on our site, we may earn an affiliate commission. As an Amazon Associate I earn from qualifying purchases. Learn more

A cryptographic hash function takes a bit string of any length and produces a fixed-length output called a hash value or digest. It is designed to make three tasks computationally infeasible: recovering an input from its digest, finding a different input that matches a known input’s digest, and finding any two different inputs with the same digest.

What a cryptographic hash function does

NIST defines a cryptographic hash function as a function that maps a bit string of arbitrary length to a fixed-length bit string and is expected to provide collision resistance, preimage resistance, and second-preimage resistance. The output is called a digest or hash value. It is a condensed representation of the input and depends on the message’s contents.

Because the output has a fixed length while inputs can have arbitrary lengths, different inputs must be able to produce the same output in principle. A secure hash function is not required to make collisions mathematically impossible; it is designed to make finding them computationally infeasible.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Three security properties, three attacker goals

Preimage resistance

Given a target digest, an attacker should find it computationally infeasible to find an input that hashes to that digest. NIST also calls this the one-way property. It does not mean that every digest has only one possible input.

Second-preimage resistance

Given a particular input, an attacker should find it computationally infeasible to find a different input with the same digest. The attacker is matching a known input, not choosing any pair freely.

Collision resistance

An attacker should find it computationally infeasible to find any two distinct inputs that produce the same digest. Unlike a second-preimage attack, the attacker does not have to match a specified input.

These properties are related, but they describe different attack goals. Which one matters most depends on how a hash function is used.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Is SHA-256 a cryptographic hash function?

Yes. SHA-256 is a member of the SHA-2 family specified by NIST’s Secure Hash Standard, FIPS 180-4. It produces a 256-bit digest. That output length is not, by itself, a claim of 256-bit strength against every kind of attack.

NIST’s hash-functions guidance gives collision-resistance strength as half the output size in bits. On that general estimate, a 256-bit digest corresponds to 128-bit collision-resistance strength. Security strength depends on the property being considered and the application, not just the digest’s length.

How hashing differs from encryption

A hash function produces a digest; hashing alone is not an encryption operation and does not promise reversible decryption. Encryption is used when data must be protected so that an authorized party can recover it with the appropriate key. A digest instead serves as a fixed-length representation of input data, with security properties that make particular forms of manipulation or matching difficult.

Where hash functions are used

Hash functions can represent message contents and serve as components in cryptographic algorithms and protocols. For example, the IETF’s Certificate Transparency specification defines a Merkle Tree Hash construction using SHA-256. In that construction, the specification explains that the definition is designed to require second-preimage resistance.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

SHA-2, SHA-3, and SHAKE standards

NIST’s FIPS 180-4 specifies the Secure Hash Standard, which includes the SHA-2 family. FIPS 202 specifies SHA-3 hash functions and SHAKE extendable-output functions. SHAKE is useful where an application calls for an extendable-output function rather than a hash with one fixed digest length. Choosing among these standards depends on the security property, output needs, and requirements of the protocol or application.

NIST’s FIPS 180-4 page records a March 7, 2023 planning note that the standard would be revised after two rounds of public comment. Consult the current NIST page for the revision status when a project depends on the latest standard.

Official definitions and standards

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.