Writing

Iris squarepanensisleg. cstef, 6.i.2025

SquarePants Sponge Hashing

A quick explanation of the sponge hashing algorithm, notably used in SHA-3

4 min readcrypto

In 2007, the NIST (National Institue of Standards and Technology) announced a Cryptographic Hash Algorithm Competition, with the winner being awarded the grant to be standardized as the new SHA-3. It ended in 2012 with K​ECCAK being announced as the winner.

The function uses a sponge construction, but what the hell is even this thing? Let’s take a look!

We have a message 𝑀 as our input and the final hash 𝐻. We then have two β€œregisters”: π‘Ÿ and 𝑐, which both make up our state 𝑠. These two are initialized with 0s in them.

The message 𝑀 is first padded so that it can fit in exactly π‘˜βˆˆβ„• parts π‘šπ‘–, each of size π‘Ÿ. The process of β€œabsorption” is the following:

  1. XOR (denoted βŠ•) the message-part π‘šπ‘– with the register π‘Ÿ bit-by-bit

  2. Scramble the whole register 𝑠 (π‘Ÿ and 𝑐) altogether to produce a new state 𝑠′ by applying 𝑓 The function 𝑓 needs to generate a pseudo-random permutation of the bits in 𝑠

    Example permutation via f.
  3. Pass on the state to the next iteration

We can now β€œsqueeze” our sponge to extract the hash from it, by applying 𝑓 again and taking a small chunk β„Žπ‘– (π‘Ÿ bits) over and over until we have enough for our desired output length.

This whole process can be described with the following diagram:

Sponge construction algorithm, inspired by Keccak's diagram.

This whole process can also be modified to fit streaming needs, by combining both absorption and squeezing steps at each iteration.