Skip to main content

Overview

This module provides cryptographic hash functions (SHA-256) and extendable-output functions (SHAKE256) for key derivation, commitments, and deterministic randomness expansion in PVAC-HFHE.

SHA-256

Sha256

SHA-256 hash state for incremental hashing.
uint32_t[8]
Hash state (eight 32-bit words)
uint64_t
Total number of bytes processed
uint8_t[64]
Input buffer for the current block
size_t
Current position in buffer

Methods

init

Initializes the hash state.
Example:

update

Processes data incrementally.
const void*
Pointer to data to hash
size_t
Number of bytes to process
Example:

finish

Finalizes the hash and produces the digest.
uint8_t[32]
Output buffer for 256-bit (32-byte) digest
Example:

Convenience functions

sha256_bytes

Computes SHA-256 hash of a single buffer.
const void*
Input data
size_t
Input length in bytes
uint8_t[32]
Output digest
Example:

sha256_acc_u64

Accumulates a 64-bit integer into the hash in little-endian format.
Sha256&
Hash state
uint64_t
Value to hash
Example:

SHAKE256

Shake256

SHAKE256 XOF (extendable-output function) state.
uint64_t[25]
Keccak state (1600 bits)
size_t
Rate parameter (136 bytes for SHAKE256)
size_t
Current position in rate bytes
bool
True if in squeezing mode, false if absorbing

Methods

init

Initializes SHAKE256 state.
Example:

absorb

Absorbs input data into the sponge.
const uint8_t*
Input data
size_t
Input length in bytes
Example:
Do not call absorb() after calling squeeze(). The function will abort if called in squeezing mode.

pad

Finalizes absorption and switches to squeezing mode.
Example:

squeeze

Extracts output bytes from the XOF.
uint8_t*
Output buffer
size_t
Number of bytes to extract
Example:
You can call squeeze() multiple times to extract as much output as needed. The function automatically calls pad() if not already in squeezing mode.

next_u64

Extracts the next 64-bit integer from the XOF.
uint64_t
Next 64 bits of output
Example:

XofShake

XofShake

High-level wrapper for SHAKE256 with domain-separated seeding.

Methods

init

Initializes XOF with a label and seed.
const std::string&
Domain separation label (e.g., from Dom namespace)
const std::vector<uint64_t>&
Seed values in little-endian format
Example:

take_u64

Extracts the next 64-bit value.
uint64_t
Next 64-bit value
Example:

bounded

Generates a uniformly random integer in the range [0, M).
uint64_t
Upper bound (exclusive)
uint64_t
Uniformly random value in [0, M)
Example:
This function uses rejection sampling to ensure uniform distribution, avoiding modulo bias.

Utility functions

hex8

Converts binary data to hexadecimal string.
const uint8_t*
Input data
size_t
Number of bytes
std::string
Hexadecimal string (lowercase)
Example:

Usage patterns

Computing public key digest

Deterministic random stream

Sampling without replacement

Commitment scheme

Security properties

SHA-256

  • Collision resistance: ~128-bit security
  • Preimage resistance: 256-bit security
  • Second preimage resistance: 256-bit security

SHAKE256

  • Security level: 256-bit (for 512-bit output)
  • Collision resistance: 128-bit
  • Uniformity: Output is computationally indistinguishable from random

Performance

  • SHA-256: ~300-500 MB/s on modern CPUs
  • SHAKE256: ~150-250 MB/s on modern CPUs
  • Hardware acceleration (AES-NI, SHA extensions) not currently used