Hash function
Definition
Frequently asked questions
What properties must a hash function have?
Three essential properties. It is deterministic: the same input always produces the same hash. It is one-way: you cannot retrieve the input from the hash. It resists collisions: it is practically impossible to find two different inputs producing the same hash. In addition there is the avalanche effect, which drastically changes the hash with the slightest modification.
Why sign the hash rather than the entire document?
For reasons of efficiency and security. Asymmetric cryptography operations are slow and operate on small amounts of data. The hash, of fixed length, faithfully represents the document regardless of its size. Signing the hash therefore amounts to signing the document, whether it is one page or a thousand.
Which algorithms are still considered secure?
The SHA-2 families, of which SHA-256 is the most widely used member, and SHA-3 are recommended. MD5 and SHA-1 should no longer be used for signatures: collisions have been produced in practice, for SHA-1 in 2017, which would make it possible to substitute one document for another without invalidating the signature.
Hashing and encryption, what is the difference?
Encryption is reversible: with the right key, you recover the original message. Hashing is not: the fingerprint does not allow you to reconstruct the document. The objectives also differ. Encryption protects confidentiality, hashing allows you to verify integrity. An electronic signature is based on the latter, not the former.
Related guides
Related terms
Ready to Put These Concepts Into Practice?
Certyneo allows you to create eIDAS-compliant signature envelopes in just a few clicks, without installation.