Tuesday, January 08, 2013

Secure Hash Algorithms (SHA-1 and SHA-256)

Secure Hash Algorithms (SHA-1 and SHA-256)

Secure Hash Algorithms, a form of symmetric encryption, is also included in VIA processors based on the ‘Esther' core.

Implementing the SHA-1 and SHA-256 variants of secure hash, the VIA Padlock SHA engine can deliver real-time data encryption peaking at 5 gigabits per second.

This algorithm is again endorsed and used at all levels of the U.S. Government and operates by compressing the data needed and encrypting it into message digests. Each message digest is created so that the information inside is computationally infeasible to be read by an outside party.

Table: An example of the message digests produced by SHA-1:

Original String SHA-1 Hash Digest
Hello World z7R8yBtZz0+eqead7UEYzPvVFjw=
VB L1SHP0uzGbMUpT4z0zlAdEzfPE=
Vb e0cnhoZRmuoC/Ed51RrW71x1CDw=
Vb e3Pa1F6tMmhPGUfGg1nrfdV31+1=
VB gzt6my3YlrzJiTiucvqBTgM6LtM=

By studying the contents of each SHA-1 secure hash digest it becomes immediately evident that a change of character case on the same word produces a completely different encrypted message.

In fact a change of just one bit within a message causes a completely different secure hash message digest to be created. This allows easy detection of message manipulation, as a message cannot be decrypted, altered even slightly and re-encrypted without producing an entirely different message digest. This is why most governments and organizations in the world now use a implementation of the secure hash algorithm.

SHA-256 is a more secure version of SHA-1, using a 256bit hash algorithm (SHA-1 uses a 160 bit algorithm), and is currently considered completely unbreakable.

Despite this advantage, SHA-1 and SHA-256 secure hash algorithms suffer from one drawback: they all require enormous consumption of processor cycles in the computation of digests, especially when a high throughput is required.

However, VIA has solved this problem by integrating the computation of secure hash algorithms SHA-1 and SHA-256 directly onto the processor die.

By incorporating secure hash into the VIA PadLock Security Engine, VIA has effectively shifted the computational process of large-scale number crunching away from the main processor to the PadLock engine.

Thus, a developer can include real-time secure hash encryption in their applications without worrying that the process will significantly affect other applications or processes running concurrently.


No comments: