Multihashing - combining multiple values into a single hash - is often done incorrectly by naive concatenation, producing ambiguous inputs and enabling attacks (notably in Fiat-Shamir-based zero-knowledge proofs and commitment schemes). SequenceHash is a hash-agnostic multihashing construction that provides unambiguous input encoding, length-extension resistance, built-in customization strings, and a keyed mode called SequenceMAC. It mirrors TupleHash’s guarantees but is not limited to Keccak/SHA3: it works with SHA2, BLAKE, RIPEMD, and other secure hash functions. The specification is open source, part of the Community Cryptography Specification Project, and comes with Rust, Go, and Python implementations plus extensive test vectors.
Technically, SequenceHash encodes each input with a fixed 128-bit byte-length suffix (enabling streaming APIs), then uses a double-hash structure to prevent length-extension attacks and to support a keyed SequenceMAC similar to HMAC but with metadata to avoid certain key-pseudocollision issues. Customization strings are applied only to the outer hash so the inner hash can be reused across different contexts. The 128-bit length limit far exceeds practical hash-input limits and simplifies cross-platform implementation. Security depends on the chosen underlying hash; SequenceHash does not restore broken hashes but standardizes safe multihashing for a broad set of modern hash functions.
Summary generated by AI from the linked article. hn.today is not affiliated with Hacker News or Y Combinator.