Driver FixRecommendedSound, Wi-Fi or graphics acting up? Check drivers firstFind missing or outdated drivers fast.Check DriversOctober DealsAmazon USOctober deal check: compare before you payAmazon US: current deals, useful picks and tech finds.Check DealsWindows FixRecommendedWindows errors stealing your time? Find the fix fastScan stability, cleanup and performance issues.Fix Now×
Skip to content
World desk3 min

What Is a Cryptographic Hash Function? Definition and Security Properties

A cryptographic hash maps input of any length to a fixed-length digest. Learn how its three security properties differ and why digest size is not the whole security story.
Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

A cryptographic hash function takes an input bit string of any length and produces a fixed-length output called a hash value or digest. It is designed to make it computationally infeasible to find an input matching a chosen digest, find a second input matching a known input’s digest, or find any two different inputs with the same digest. These are distinct security properties, not a guarantee that collisions are mathematically impossible.

What a cryptographic hash function does

NIST defines a cryptographic hash function as a function that maps a bit string of arbitrary length to a fixed-length bit string and is expected to have collision resistance, preimage resistance, and second-preimage resistance. The output is a condensed representation of the input and depends on its contents. See NIST’s cryptographic hash function glossary and its hash function glossary.

As an Amazon Associate I earn from qualifying purchases.

Because the output has a fixed length while inputs can have arbitrary lengths, different inputs must be able to produce the same output in principle. A secure hash is designed to make finding such inputs computationally infeasible; it does not make collisions impossible.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Three security properties, three attacker goals

Preimage resistance

Given a digest, an attacker should find it computationally infeasible to find an input that produces that digest. NIST also calls this the one-way property. This does not mean every hash output is literally impossible to reverse; it describes the expected difficulty of finding a matching input.

Second-preimage resistance

Given a particular input, it should be computationally infeasible to find a different input with the same digest. The attacker is trying to match the hash of a known message.

Collision resistance

It should be computationally infeasible to find any two distinct inputs that produce the same digest. Unlike a second-preimage attack, the attacker is not required to match a specific input chosen in advance. NIST’s hash function glossary distinguishes these goals.

Is SHA-256 a cryptographic hash function?

Yes. SHA-256 is part of the SHA-2 family specified in NIST’s Secure Hash Standard, FIPS 180-4. It produces a 256-bit digest. That output size is not the same as saying every security property provides 256 bits of strength: NIST’s hash-functions guidance says collision-resistance strength is half the output size. For a 256-bit digest, that general estimate is 128 bits for collision resistance. See NIST’s Hash Functions project and its SP 800-107 Rev. 1 guidance.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

NIST also specifies SHA-3 and the SHAKE extendable-output functions in FIPS 202. SHA-2 and SHA-3 are standardized families; the appropriate choice depends on the required security property, output needs, and the standard or protocol an application must follow. FIPS 180-4’s NIST page records a March 7, 2023 planning note that the standard would be revised after two rounds of public comment, so consult that page for its current revision status.

Hashing is not encryption

A hash function produces a digest; hashing alone does not encrypt data or provide a reversible decryption operation. Encryption is intended to protect information so that an authorized party with the appropriate key can recover it. A digest is instead a fixed-length representation used in security mechanisms and protocols. Do not treat a hash as a way to keep a message confidential.

How hashes are used in protocols

Hash functions can represent message contents and serve as components in larger cryptographic algorithms and protocols. One concrete example is Certificate Transparency: IETF RFC 6962 defines a Merkle Tree Hash using SHA-256 and specifies a construction designed to require second-preimage resistance. This illustrates why an application’s required security property matters; the word “hash” alone does not explain the role or guarantees of a particular construction.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

What to consider when selecting a hash function

  • Security goal: Identify whether the application relies on preimage, second-preimage, or collision resistance.
  • Output and strength: Consider both digest length and the security strength associated with the property you need; output length alone is not a complete measure.
  • Output format: Determine whether the application needs a fixed-length digest or an extendable-output function such as SHAKE.
  • Applicable standard: Follow the specification or protocol requirements relevant to the implementation, including the SHA-2 standard in FIPS 180-4 or SHA-3 and SHAKE in FIPS 202.

Standards and transition guidance can change. For current information about the Secure Hash Standard and NIST’s SHA-1 transition guidance, consult the FIPS 180-4 page and NIST Hash Functions project page.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

Leave a Reply

Your email address will not be published. Required fields are marked *

Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

More from the Wire

  1. World desk4 min
    How to Spot an AI Voice Scam Before Sending MoneyDon’t rely on how a caller sounds. Pause, call back through a known number, and verify the emergency with another trusted person before sending money.
  2. Mountain View desk4 min
    Google’s SynthID Detector: How to Check AI-Generated Images, Video and AudioGoogle’s SynthID Detector looks for an embedded watermark in supported images, video and audio. Here is what its results do—and do not—show.
  3. Redmond desk20 min
    How to create a link to File or Folder in Windows 11Windows 11 gives you several ways to point to a file or folder without moving or duplicating it. You can create a desktop shortcut,…
Recommended PC Tool
Recommended PC Tool
Outdated Drivers Are Slowing You DownFree scan - exact matches
PC Slower Than It Used to Be?Free scan - under a minute

Two free Windows tools

One Free Minute Could Fix That PC

Before you go - each of these free tools takes about a minute and tackles what quietly slows a Windows PC down.

Special offer. View Outbyte info, uninstall instructions, EULA, and Privacy Policy.