SequenceHash: multihashing for... Note

SequenceHash: multihashing for the rest of us

Multihashing, the process of combining multiple values into a single hash, is a critical but often misunderstood cryptographic task. Insecure multihashing implementations can lead to vulnerabilities, especially in areas like zero-knowledge proofs. Trail of Bits has introduced SequenceHash and SequenceMAC, new constructions designed to provide secure multihashing for a wide range of cryptographic hash functions. Unlike NIST's TupleHash, which is tied to Keccak, SequenceHash and SequenceMAC are hash-agnostic, working with functions like SHA256, BLAKE, and RIPEMD.These new constructs offer unambiguous input encoding, preventing manipulation of concatenated inputs. They also provide length-extension prevention, a crucial security feature for many hash functions. Additionally, SequenceHash and SequenceMAC incorporate optional customization strings for protocol binding to prevent replays. SequenceMAC, a keyed variant, offers similar security benefits for message authentication codes.SequenceHash employs a simplified fixed-length, 128-bit integer encoding for input byte counts, supporting streaming APIs with its length-suffix encoding. This approach aims for straightforward implementation and handles practical input sizes with a ${2}^{128}-1$ byte limit. The double-hashing construction, similar to HMAC, prevents length extension attacks and enables the keyed SequenceMAC mode. SequenceMAC addresses potential key pseudocollision issues found in HMAC by incorporating key metadata.Three initial implementations of SequenceHash and SequenceMAC are available in Rust, Go, and Python, along with comprehensive test vectors. These tools aim to simplify secure multihashing for developers. The ultimate goal is to provide a standardized, easy-to-use solution for this common cryptographic challenge.