{ "id": "sha256-r31-prefix-v1", "status": "frontier-experiment", "algorithm": "sha256", "primitive": "SHA-256", "specification": "FIPS 180-4", "specification_url": "https://nvlpubs.nist.gov/nistpubs/FIPS/NIST.FIPS.180-4.pdf", "rounds": 31, "full_rounds": 64, "round_count_unit": "compression rounds", "round_selection": "Execute indices 0 through 30, inclusive, on every padded block.", "digest_bits": 256, "attack_class": "ordinary-collision", "message_domain": "All finite byte strings with bit length less than 2^64; no chosen IV, free-start state, or digest truncation.", "block_bits": 512, "word_bits": 32, "padding": "FIPS 180-4: append 0x80, zero bytes to 56 modulo 64, then 64-bit BIG-endian original bit length.", "initialization": "Use the standard fixed IV from the specification once at the start of the complete message.", "schedule": "Use the standard message-word selection/expansion and constants at their original indices; do not renumber phases.", "feed_forward": "After each reduced compression, add every working state word to the incoming chaining state modulo 2^32. Preserve the full standard state and serialize in standard order.", "digest_encoding": "Big-endian standard chaining-state order; all digest words.", "reference_implementation": "verifier/hash_functions.py:digest", "relation": { "preconditions": [ "m0 and m1 satisfy the message domain", "m0 is not byte-for-byte equal to m1" ], "postcondition": "The two complete sha256-r31 hashes are byte-for-byte equal." }, "out_of_scope": [ "compression-only or free-start collisions", "near-collisions or output truncation", "changing the IV, padding, round range, or output width", "implementation/side-channel attacks" ] }