Overview
This module provides cryptographic hash functions (SHA-256) and extendable-output functions (SHAKE256) for key derivation, commitments, and deterministic randomness expansion in PVAC-HFHE.SHA-256
Sha256
SHA-256 hash state for incremental hashing.uint32_t[8]
Hash state (eight 32-bit words)
uint64_t
Total number of bytes processed
uint8_t[64]
Input buffer for the current block
size_t
Current position in buffer
Methods
init
Initializes the hash state.update
Processes data incrementally.const void*
Pointer to data to hash
size_t
Number of bytes to process
finish
Finalizes the hash and produces the digest.uint8_t[32]
Output buffer for 256-bit (32-byte) digest
Convenience functions
sha256_bytes
Computes SHA-256 hash of a single buffer.const void*
Input data
size_t
Input length in bytes
uint8_t[32]
Output digest
sha256_acc_u64
Accumulates a 64-bit integer into the hash in little-endian format.Sha256&
Hash state
uint64_t
Value to hash
SHAKE256
Shake256
SHAKE256 XOF (extendable-output function) state.uint64_t[25]
Keccak state (1600 bits)
size_t
Rate parameter (136 bytes for SHAKE256)
size_t
Current position in rate bytes
bool
True if in squeezing mode, false if absorbing
Methods
init
Initializes SHAKE256 state.absorb
Absorbs input data into the sponge.const uint8_t*
Input data
size_t
Input length in bytes
pad
Finalizes absorption and switches to squeezing mode.squeeze
Extracts output bytes from the XOF.uint8_t*
Output buffer
size_t
Number of bytes to extract
You can call
squeeze() multiple times to extract as much output as needed. The function automatically calls pad() if not already in squeezing mode.next_u64
Extracts the next 64-bit integer from the XOF.uint64_t
Next 64 bits of output
XofShake
XofShake
High-level wrapper for SHAKE256 with domain-separated seeding.Methods
init
Initializes XOF with a label and seed.const std::string&
Domain separation label (e.g., from
Dom namespace)const std::vector<uint64_t>&
Seed values in little-endian format
take_u64
Extracts the next 64-bit value.uint64_t
Next 64-bit value
bounded
Generates a uniformly random integer in the range [0, M).uint64_t
Upper bound (exclusive)
uint64_t
Uniformly random value in [0, M)
This function uses rejection sampling to ensure uniform distribution, avoiding modulo bias.
Utility functions
hex8
Converts binary data to hexadecimal string.const uint8_t*
Input data
size_t
Number of bytes
std::string
Hexadecimal string (lowercase)
Usage patterns
Computing public key digest
Deterministic random stream
Sampling without replacement
Commitment scheme
Security properties
SHA-256
- Collision resistance: ~128-bit security
- Preimage resistance: 256-bit security
- Second preimage resistance: 256-bit security
SHAKE256
- Security level: 256-bit (for 512-bit output)
- Collision resistance: 128-bit
- Uniformity: Output is computationally indistinguishable from random
Performance
- SHA-256: ~300-500 MB/s on modern CPUs
- SHAKE256: ~150-250 MB/s on modern CPUs
- Hardware acceleration (AES-NI, SHA extensions) not currently used
Related
- Types - Domain separation constants
- Random generation - Cryptographically secure random bytes
- Field operations - Used with deterministic randomness