0% found this document useful (0 votes)
105 views16 pages

ISO IEC 10118-3-2004 Amd1-2006

This document provides an amendment to the International Standard ISO/IEC 10118-3:2004 regarding dedicated hash functions. Specifically, it defines Dedicated Hash Function 8, also known as SHA-224. The amendment includes the parameters, functions, constants, padding method, and description of the round function for SHA-224. It also adds test vectors for SHA-224 to validate implementations of the hash function.

Uploaded by

gamingfloppa055
Copyright
© © All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd
0% found this document useful (0 votes)
105 views16 pages

ISO IEC 10118-3-2004 Amd1-2006

This document provides an amendment to the International Standard ISO/IEC 10118-3:2004 regarding dedicated hash functions. Specifically, it defines Dedicated Hash Function 8, also known as SHA-224. The amendment includes the parameters, functions, constants, padding method, and description of the round function for SHA-224. It also adds test vectors for SHA-224 to validate implementations of the hash function.

Uploaded by

gamingfloppa055
Copyright
© © All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd
You are on page 1/ 16

INTERNATIONAL I S O/I E C

STANDARD 1 0 1 1 8 -3

Third edition
2004-03-01
AM E N D M E N T 1

2006-02-1 5

I n form ati on tech n ol og y — S ecu ri ty

tech n i q u es — H as h -fu n cti on s —

Part 3:
D ed i ca ted h as h -fu n cti on s

AMENDMENT 1 : Dedicated
Hash-Function 8 (SHA-224)
Technologies de l'information — Techniques de sécurité — Fonctions
de brouillage —
Partie 3: Fonctions de brouillage dédiées
AMENDEMENT 1: Fonction de brouillage dédiée 8 (SHA-224)

Reference number
ISO/IEC 1 01 1 8-3:2004/Amd.1 :2006(E)

© ISO/IEC 2006
I S O/I E C 1 0 1 1 8-3: 2 0 0 4/Am d . 1 : 2 0 0 6(E )

P D F d i s cl ai m er

This PDF file may contain embedded typefaces. In accordance with Adobe's licensing policy, this file may be printed or viewed but
shall not be edited unless the typefaces which are embedded are licensed to and installed on the computer performing the editing. In
downloading this file, parties accept therein the responsibility of not infringing Adobe's licensing policy. The ISO Central Secretariat
accepts no liability in this area.
Adobe is a trademark of Adobe Systems Incorporated.
Details of the software products used to create this PDF file can be found in the General Info relative to the file; the PDF-creation
parameters were optimized for printing. Every care has been taken to ensure that the file is suitable for use by ISO member bodies. In
the unlikely event that a problem relating to it is found, please inform the Central Secretariat at the address given below.

© ISO/IEC 2006
All rights reserved. Unless otherwise specified, no part of this publication may be reproduced or utilized in any form or by any means,
electronic or mechanical, including photocopying and microfilm, without permission in writing from either ISO at the address below or
ISO's member body in the country of the requester.
ISO copyright office
Case postale 56 • CH-1 21 1 Geneva 20
Tel. + 41 22 749 01 1 1
Fax + 41 22 749 09 47
E-mail copyright@iso.org
Web www.iso.org
Published in Switzerland

ii © ISO/IEC 2006 – All rights reserved


I S O/I E C 1 0 1 1 8-3: 2 0 0 4/Am d . 1 : 2 0 0 6(E )

F oreword

ISO (the International Organization for Standardization) and IEC (the International Electrotechnical
Commission) form the specialized system for worldwide standardization. National bodies that are members of
ISO or IEC participate in the development of International Standards through technical committees
established by the respective organization to deal with particular fields of technical activity. ISO and IEC
technical committees collaborate in fields of mutual interest. Other international organizations, governmental
and non-governmental, in liaison with ISO and IEC, also take part in the work. In the field of information
technology, ISO and IEC have established a joint technical committee, ISO/IEC JTC 1 .

International Standards are drafted in accordance with the rules given in the ISO/IEC Directives, Part 2.

The main task of the joint technical committee is to prepare International Standards. Draft International
Standards adopted by the joint technical committee are circulated to national bodies for voting. Publication as
an International Standard requires approval by at least 75 % of the national bodies casting a vote.

Attention is drawn to the possibility that some of the elements of this document may be the subject of patent
rights. ISO and IEC shall not be held responsible for identifying any or all such patent rights.

Amendment 1 to ISO/IEC 1 01 1 8-3: 2004 was prepared by Joint Technical Committee ISO/IEC JTC 1 ,
Information technology, Subcommittee SC 27, IT Security techniques.
Amendment 1 to ISO/IEC 1 01 1 8-3:2004 was written to serve two purposes.

First, with the inclusion of Dedicated Hash-Function 8 (SHA-224), ISO/IEC 1 01 1 8-3:2004 now includes the
complete family of SHA hash-functions. The description of SHA-224 is given in Clause 1 4. Test vectors for
SHA-224 are given in A.8.

Second, it was noted that there were implementations of SHA-384 and SHA-51 2 in the field which correctly
reproduced the test vector examples in ISO/IEC 1 01 1 8-3:2004, yet still failed for inputs containing bytes that
were not standard ASCII codes. In order to perform comprehensive testing of the SHA-224, SHA-256, SHA-
384 and SHA-51 2 hash-functions, an extended set of test vectors is included for ISO/IEC 1 01 1 8-3:2004 as a
part of this amendment. This additional test vector information is given in A.9.

© ISO/IEC 2006 – All rights reserved iii


I S O/I E C 1 0 1 1 8-3: 2 0 0 4/Am d . 1 : 2 0 0 6(E )

I n form ati on tech n ol og y — S ecu ri ty tech n i q u e s —

H as h -fu n cti on s —

Part 3:
D ed i cated h as h -fu n cti on s

AMENDMENT 1 : Dedicated Hash-Function 8 (SHA-224)

Page 22

Add the following after Figure 6.

14 D ed i cated H as h -F u n cti on 8 (S H A-2 2 4)

In this clause we specify a padding method, an initialising value, and a round-function for use in the general
model for hash-functions described in ISO/IEC 1 01 1 8-1 :2000. The padding method, initialising value and
round-function specified here, when used in the above general model, together define Dedicated Hash-
Function 8. This dedicated hash-function can be applied to all data strings D containing at most 2 64 -1 bits.

The ISO/IEC hash-function identifier for Dedicated Hash-Function 8 is equal to 38 (hexadecimal).

NOTE Dedicated Hash-Function 8 defined in this clause is commonly called SHA-224, [2].

1 4. 1 Param eters , fu n cti on s an d con s tan ts

1 4. 1 . 1 P aram ete rs

For this hash-function L1 = 51 2, L 2 = 256 and LH = 224.

1 4. 1 . 2 B yte ord e ri n g con ven ti on

The byte ordering convention for this hash-function is the same as that for the hash-function of clause 1 0.

1 4. 1 . 3 F u n cti on s

The functions for this hash-function are the same as those for the hash-function of clause 1 0.

1 4. 1 . 4 C on stan ts

The constants for this hash-function are the same as those for the hash-function of clause 1 0.

© ISO/IEC 2006 – All rights reserved 1


I S O/I E C 1 0 1 1 8-3: 2 0 0 4/Am d . 1 : 2 0 0 6(E )

1 4. 1 . 5 I n i ti al i s i n g val u e

For this round-function the initialising value, IV, shall always be the following 256-bit string, represented here
as a sequence of eight words Y0 , Y1 , Y2 , Y3 , Y4 , Y5, Y6 , Y7 in a hexadecimal representation, where Y0
represents the left-most 32 of the 256 bits:

Y0 = c1 0 5 9ed8
Y1 = 3 67 cd5 0 7
Y2 = 3 0 7 0 dd1 7
Y3 = f7 0 e5 93 9
Y4 = ffc0 0 b3 1
Y5 = 68 5 8 1 5 1 1
Y6 = 64 f98 fa7
Y7 = befa4 fa4

NOTE These values are the low order 32-bits of the values specified in 1 2.1 .5.

1 4. 2 Pad d i n g m eth od

The padding method to be used with this hash-function shall be the same as the padding method defined in
1 0.2.

1 4. 3 D es cri pti on of th e rou n d -fu n cti on

The round-function to be used with this hash-function shall be the same as the round-function defined in 1 0.3.

The final 224-bit hash is obtained by truncating the SHA-256-based hash output to its left-most 224 bits.

Page 23, Annex A

In the first line, replace “Dedicated Hash-Functions 1 -7” by “Dedicated Hash-Functions 1 -8”.

Page 77

Add the following after A.7.9.

A. 8 D ed i cated H as h -F u n cti on 8

A. 8 . 1 E xam pl e 1

In this example the data-string is the empty string, i.e., the string of length zero.

The hash-code is the following 224-bit string.

d1 4 a0 2 8 c 2 a3 a2 bc9 4 7 61 0 2 bb 2 8 8 2 3 4 c4 1 5 a2 b0 1 f 8 2 8 ea62 a c5 b3 e4 2 f

2 © ISO/IEC 2006 – All rights reserved


I S O/I E C 1 0 1 1 8-3: 2 0 0 4/Am d . 1 : 2 0 0 6(E )

A. 8 . 2 E xam pl e 2

In this example the data-string consists of a single byte, namely the ASCII-coded version of the letter ‘a’.

The hash-code is the following 224-bit string.

abd3 7 5 3 4 c7 d9a2 ef b94 65 de9 3 1 cd7 0 5 5 ffdb8 8 7 9 5 63 ae98 0 7 8 d6d6d5

A. 8 . 3 E xam pl e 3

In this example the data-string is the three-byte string consisting of the ASCII-coded version of ‘abc’. This is
equivalent to the bit-string: ‘01 1 00001 01 1 0001 0 01 1 0001 1 ’.

After the padding process, the single 1 6-word block derived from the data-string is as follows.

61 62 63 8 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0
00000000 00000000 00000000 00000000 00000000 00000000 00000000 00000018

The following are (hexadecimal representations of) the successive values of the variables Y0, Y1 , Y2, Y3, Y4,
Y5, Y6, Y7.
init: c1 0 5 9ed8 3 67 cd5 0 7 3 0 7 0 dd1 7 f7 0 e5 93 9 ffc0 0 b3 1 68 5 8 1 5 1 1 64 f98 fa7 befa4 fa4
0 0 e96b2 da c1 0 5 9ed8 3 67 cd5 0 7 3 0 7 0 dd1 7 0434225e ffc0 0 b3 1 68 5 8 1 5 1 1 64 f98 fa7
1 c2 0 dab6b 0 e96b2 da c1 0 5 9ed8 3 67 cd5 0 7 9cab4 1 6f 0434225e ffc0 0 b3 1 68 5 8 1 5 1 1
2 ab1 1 3 b7 a c2 0 dab6b 0 e96b2 da c1 0 5 9ed8 8 2 1 7 7 fe8 9cab4 1 6f 0434225e ffc0 0 b3 1
3 8 2 5 3 cc1 a ab1 1 3 b7 a c2 0 dab6b 0 e96b2 da 8 3 4 6b2 7 d 8 2 1 7 7 fe8 9cab4 1 6f 0434225e
4 0 8 a0 dc0 c 8 2 5 3 cc1 a ab1 1 3 b7 a c2 0 dab6b 0 5 b5 5 7 db 8 3 4 6b2 7 d 8 2 1 7 7 fe8 9cab4 1 6f
5 b2 ca3 a91 0 8 a0 dc0 c 8 2 5 3 cc1 a ab1 1 3 b7 a 8 98 dc7 bb 0 5 b5 5 7 db 8 3 4 6b2 7 d 8 2 1 7 7 fe8
6 0 b6b90 2 3 b2 ca3 a91 0 8 a0 dc0 c 8 2 5 3 cc1 a a2 e4 91 4 7 8 98 dc7 bb 0 5 b5 5 7 db 8 3 4 6b2 7 d
7 f0 9d1 1 6d 0 b6b90 2 3 b2 ca3 a91 0 8 a0 dc0 c 7 a8 4 1 2 0 d a2 e4 91 4 7 8 98 dc7 bb 0 5 b5 5 7 db
8 ed6fa63 3 f0 9d1 1 6d 0 b6b90 2 3 b2 ca3 a91 c0 3 7 faad 7 a8 4 1 2 0 d a2 e4 91 4 7 8 98 dc7 bb
9 5 5 e6a3 67 ed6fa63 3 f0 9d1 1 6d 0 b6b90 2 3 aae5 0 0 91 c0 3 7 faad 7 a8 4 1 2 0 d a2 e4 91 4 7
10 0 8 1 7 e8 2 b 5 5 e6a3 67 ed6fa63 3 f0 9d1 1 6d c8 c5 3 a2 c aae5 0 0 91 c0 3 7 faad 7 a8 4 1 2 0 d
11 17142334 0 8 1 7 e8 2 b 5 5 e6a3 67 ed6fa63 3 dd4 c7 be9 c8 c5 3 a2 c aae5 0 0 91 c0 3 7 faad
12 fc4 f0 2 3 e 17142334 0 8 1 7 e8 2 b 5 5 e6a3 67 8 7 bea5 1 a dd4 c7 be9 c8 c5 3 a2 c aae5 0 0 91
13 be3 1 690 2 fc4 f0 2 3 e 17142334 0 8 1 7 e8 2 b 65 1 4 1 1 2 5 8 7 bea5 1 a dd4 c7 be9 c8 c5 3 a2 c
14 1 d8 0 d1 7 8 be3 1 690 2 fc4 f0 2 3 e 17142334 4 5 4 5 f5 3 a 65 1 4 1 1 2 5 8 7 bea5 1 a dd4 c7 be9
15 9f3 4 1 a4 5 1 d8 0 d1 7 8 be3 1 690 2 fc4 f0 2 3 e 6a61 c4 1 1 4 5 4 5 f5 3 a 65 1 4 1 1 2 5 8 7 bea5 1 a
16 0 f3 2 4 db9 9f3 4 1 a4 5 1 d8 0 d1 7 8 be3 1 690 2 0 6c8 0 d6a 6a61 c4 1 1 4 5 4 5 f5 3 a 65 1 4 1 1 2 5
17 ffe7 0 1 2 b 0 f3 2 4 db9 9f3 4 1 a4 5 1 d8 0 d1 7 8 b7 b60 1 f4 0 6c8 0 d6a 6a61 c4 1 1 4 5 4 5 f5 3 a
18 62 93 2 ab8 ffe7 0 1 2 b 0 f3 2 4 db9 9f3 4 1 a4 5 7 63 b62 7 a b7 b60 1 f4 0 6c8 0 d6a 6a61 c4 1 1
19 5 2 0 7 d8 67 62 93 2 ab8 ffe7 0 1 2 b 0 f3 2 4 db9 7 fbba93 6 7 63 b62 7 a b7 b60 1 f4 0 6c8 0 d6a
20 0 7 d5 5 ccb 5 2 0 7 d8 67 62 93 2 ab8 ffe7 0 1 2 b 9ba5 a6ea 7 fbba93 6 7 63 b62 7 a b7 b60 1 f4
21 dece98 a4 0 7 d5 5 ccb 5 2 0 7 d8 67 62 93 2 ab8 2 93 ffb5 d 9ba5 a6ea 7 fbba93 6 7 63 b62 7 a
22 e62 a8 1 2 e dece98 a4 0 7 d5 5 ccb 5 2 0 7 d8 67 2 8 fe0 fd9 2 93 ffb5 d 9ba5 a6ea 7 fbba93 6
23 5 7 2 0 6fb8 e62 a8 1 2 e dece98 a4 0 7 d5 5 ccb c7 60 8 4 ea 2 8 fe0 fd9 2 93 ffb5 d 9ba5 a6ea
24 6a6abcf0 5 7 2 0 6fb8 e62 a8 1 2 e dece98 a4 b2 61 4 c5 e c7 60 8 4 ea 2 8 fe0 fd9 2 93 ffb5 d
25 93 7 5 1 4 f0 6a6abcf0 5 7 2 0 6fb8 e62 a8 1 2 e b4 2 ec2 1 c b2 61 4 c5 e c7 60 8 4 ea 2 8 fe0 fd9
26 8 2 af3 ffb 93 7 5 1 4 f0 6a6abcf0 5 7 2 0 6fb8 be6f67 60 b4 2 ec2 1 c b2 61 4 c5 e c7 60 8 4 ea
27 eca3 bcd5 8 2 af3 ffb 93 7 5 1 4 f0 6a6abcf0 1 dccbb1 0 be6f67 60 b4 2 ec2 1 c b2 61 4 c5 e
28 2 d1 5 7 6c4 eca3 bcd5 8 2 af3 ffb 93 7 5 1 4 f0 0 1 64 1 92 9 1 dccbb1 0 be6f67 60 b4 2 ec2 1 c
29 fe3 c8 65 8 2 d1 5 7 6c4 eca3 bcd5 8 2 af3 ffb fc4 b3 6c5 0 1 64 1 92 9 1 dccbb1 0 be6f67 60
30 0 d7 cce0 7 fe3 c8 65 8 2 d1 5 7 6c4 eca3 bcd5 a4 a4 a3 a4 fc4 b3 6c5 0 1 64 1 92 9 1 dccbb1 0
31 cce1 95 1 d 0 d7 cce0 7 fe3 c8 65 8 2 d1 5 7 6c4 4 be94 7 5 c a4 a4 a3 a4 fc4 b3 6c5 0 1 64 1 92 9
32 0 9b7 62 5 7 cce1 95 1 d 0 d7 cce0 7 fe3 c8 65 8 0 ccddd8 6 4 be94 7 5 c a4 a4 a3 a4 fc4 b3 6c5
33 f8 2 7 7 67 e 0 9b7 62 5 7 cce1 95 1 d 0 d7 cce0 7 db1 1 6db7 0 ccddd8 6 4 be94 7 5 c a4 a4 a3 a4
34 e4 a0 bb4 8 f8 2 7 7 67 e 0 9b7 62 5 7 cce1 95 1 d 994 e2 bac db1 1 6db7 0 ccddd8 6 4 be94 7 5 c
35 d8 bb1 0 4 1 e4 a0 bb4 8 f8 2 7 7 67 e 0 9b7 62 5 7 5 b7 3 0 abb 994 e2 bac db1 1 6db7 0 ccddd8 6

© ISO/IEC 2006 – All rights reserved 3


I S O/I E C 1 0 1 1 8-3: 2 0 0 4/Am d . 1 : 2 0 0 6(E )

36 2 a2 e3 2 f4 d8 bb1 0 4 1 e4 a0 bb4 8 f8 2 7 7 67 e 2 2 e1 5 c5 9 5 b7 3 0 abb 994 e2 bac db1 1 6db7


37 0 d2 7 5 ca8 2 a2 e3 2 f4 d8 bb1 0 4 1 e4 a0 bb4 8 f6c3 93 8 2 2 2 e1 5 c5 9 5 b7 3 0 abb 994 e2 bac
38 7 90 2 3 69c 0 d2 7 5 ca8 2 a2 e3 2 f4 d8 bb1 0 4 1 d9f8 c2 e0 f6c3 93 8 2 2 2 e1 5 c5 9 5 b7 3 0 abb
39 f3 c8 0 2 8 8 7 90 2 3 69c 0 d2 7 5 ca8 2 a2 e3 2 f4 0 0 e3 a7 bb d9f8 c2 e0 f6c3 93 8 2 2 2 e1 5 c5 9
40 4 8 3 bba4 d f3 c8 0 2 8 8 7 90 2 3 69c 0 d2 7 5 ca8 f0 a8 1 98 c 0 0 e3 a7 bb d9f8 c2 e0 f6c3 93 8 2
41 d7 5 d4 d2 6 4 8 3 bba4 d f3 c8 0 2 8 8 7 90 2 3 69c fcecdcd4 f0 a8 1 98 c 0 0 e3 a7 bb d9f8 c2 e0
42 0 7 4 4 b61 8 d7 5 d4 d2 6 4 8 3 bba4 d f3 c8 0 2 8 8 0 3 1 8 6faa fcecdcd4 f0 a8 1 98 c 0 0 e3 a7 bb
43 9cce9f0 1 0 7 4 4 b61 8 d7 5 d4 d2 6 4 8 3 bba4 d a5 6f6bbf 0 3 1 8 6faa fcecdcd4 f0 a8 1 98 c
44 a3 7 0 1 bd9 9cce9f0 1 0 7 4 4 b61 8 d7 5 d4 d2 6 af1 bef5 f a5 6f6bbf 0 3 1 8 6faa fcecdcd4
45 1 3 1 d4 c0 9 a3 7 0 1 bd9 9cce9f0 1 0 7 4 4 b61 8 ecb7 7 e1 b af1 bef5 f a5 6f6bbf 0 3 1 8 6faa
46 fb3 7 7 7 d9 1 3 1 d4 c0 9 a3 7 0 1 bd9 9cce9f0 1 1 d60 1 f4 4 ecb7 7 e1 b af1 bef5 f a5 6f6bbf
47 8 4 7 ea0 0 e fb3 7 7 7 d9 1 3 1 d4 c0 9 a3 7 0 1 bd9 5 0 3 a7 b95 1 d60 1 f4 4 ecb7 7 e1 b af1 bef5 f
48 aaa693 4 7 8 4 7 ea0 0 e fb3 7 7 7 d9 1 3 1 d4 c0 9 5 eeb993 0 5 0 3 a7 b95 1 d60 1 f4 4 ecb7 7 e1 b
49 5 0 5 caf2 8 aaa693 4 7 8 4 7 ea0 0 e fb3 7 7 7 d9 ce695 8 93 5 eeb993 0 5 0 3 a7 b95 1 d60 1 f4 4
50 67 5 e0 b0 2 5 0 5 caf2 8 aaa693 4 7 8 4 7 ea0 0 e c2 2 dd7 5 f ce695 8 93 5 eeb993 0 5 0 3 a7 b95
51 abd2 60 99 67 5 e0 b0 2 5 0 5 caf2 8 aaa693 4 7 1 4 0 9c3 f8 c2 2 dd7 5 f ce695 8 93 5 eeb993 0
52 0 df98 5 7 a abd2 60 99 67 5 e0 b0 2 5 0 5 caf2 8 2 d8 64 d9f 1 4 0 9c3 f8 c2 2 dd7 5 f ce695 8 93
53 3 0 8 b8 7 99 0 df98 5 7 a abd2 60 99 67 5 e0 b0 2 0 2 5 2 4 f0 2 2 d8 64 d9f 1 4 0 9c3 f8 c2 2 dd7 5 f
54 90 9cc0 5 9 3 0 8 b8 7 99 0 df98 5 7 a abd2 60 99 6f2 a4 4 4 a 0 2 5 2 4 f0 2 2 d8 64 d9f 1 4 0 9c3 f8
55 8 d2 5 bd94 90 9cc0 5 9 3 0 8 b8 7 99 0 df98 5 7 a 1 2 7 3 c62 2 6f2 a4 4 4 a 0 2 5 2 4 f0 2 2 d8 64 d9f
56 f3 2 1 4 1 da 8 d2 5 bd94 90 9cc0 5 9 3 0 8 b8 7 99 1 7 7 1 ed3 f 1 2 7 3 c62 2 6f2 a4 4 4 a 0 2 5 2 4 f0 2
57 8 ce2 4 3 95 f3 2 1 4 1 da 8 d2 5 bd94 90 9cc0 5 9 f5 2 f66a6 1 7 7 1 ed3 f 1 2 7 3 c62 2 6f2 a4 4 4 a
58 0 7 bcd8 4 6 8 ce2 4 3 95 f3 2 1 4 1 da 8 d2 5 bd94 1 4 9db5 4 7 f5 2 f66a6 1 7 7 1 ed3 f 1 2 7 3 c62 2
59 62 2 d5 e5 b 0 7 bcd8 4 6 8 ce2 4 3 95 f3 2 1 4 1 da b6f4 c63 0 1 4 9db5 4 7 f5 2 f66a6 1 7 7 1 ed3 f
60 c693 fc7 a 62 2 d5 e5 b 0 7 bcd8 4 6 8 ce2 4 3 95 1 3 dfb8 8 9 b6f4 c63 0 1 4 9db5 4 7 f5 2 f66a6
61 5 5 d1 c7 60 c693 fc7 a 62 2 d5 e5 b 0 7 bcd8 4 6 7 e7 3 0 e0 0 1 3 dfb8 8 9 b6f4 c63 0 1 4 9db5 4 7
62 fd8 90 3 1 b 5 5 d1 c7 60 c693 fc7 a 62 2 d5 e5 b 5 5 4 8 9ee6 7 e7 3 0 e0 0 1 3 dfb8 8 9 b6f4 c63 0
63 62 0 3 de4 a fd8 90 3 1 b 5 5 d1 c7 60 c693 fc7 a 2 aedb1 b3 5 5 4 8 9ee6 7 e7 3 0 e0 0 1 3 dfb8 8 9

The following eight words Y0 , Y1 , Y2 , Y3, Y4, Y5, Y6, Y7 represent the output of the final iteration of the round-
function.

Y 0 = c1 0 5 9ed8 » 62 0 3 de4 a = 2 3 0 97 d2 2
Y 1 = 3 67 cd5 0 7 » fd8 9 0 3 1 b = 3 4 0 5 d8 2 2
Y 2 = 3 0 7 0 dd1 7 » 5 5 d1 c7 60 = 8 64 2 a4 7 7
Y 3 = f7 0 e5 93 9 » c693 fc7 a = bda2 5 5 b3
Y 4 = ffc0 0 b3 1 » 2 aedb1 b3 = 2 aadbce4
Y 5 = 68 5 8 1 5 1 1 » 5 5 4 8 9ee6 = bda0 b3 f7
Y 6 = 64 f98 fa7 » 7 e7 3 0 e0 0 = e3 6c9da7
Y 7 = befa4 fa4 » 1 3 dfb8 8 9 = ad2 5 f7 2 d

The hash value is the following 224-bit string.

2 3 0 97 d2 2 3 4 0 5 d8 2 2 8 64 2 a4 7 7 bda2 5 5 b3 2 aadbce4 bda0 b3 f7 e3 6c9da7

4 © ISO/IEC 2006 – All rights reserved


I S O/I E C 1 0 1 1 8-3: 2 0 0 4/Am d . 1 : 2 0 0 6(E )

A. 8 . 4 E xam pl e 4

In this example the data-string is the 1 4-byte string consisting of the ASCII-coded version of
‘message digest’
The hash-code is the following 224-bit string.
2 cb2 1 c8 3 ae2 f0 0 4 d e7 e8 1 c3 c 7 0 1 9cbcb 65 b7 1 ab6 5 6b2 2 d6d 0 c3 9b8 eb

A. 8 . 5 E xam pl e 5

In this example the data-string is the 62-byte string consisting of the ASCII-coded version of
‘ABCDEFGHIJKLMNOPQRSTUVWXYZabcdefghijklmnopqrstuvwxyz01 23456789’
The hash-code is the following 224-bit string.
bff7 2 b4 f cb7 d7 5 e5 63 2 90 0 ac 5 f90 d2 1 9 e0 5 e97 a7 bde7 2 e7 4 0 db3 93 d9

A. 8 . 6 E xam pl e 6

In this example the data-string is the 80-byte string consisting of the ASCII-coded version of eight repetitions
of
‘1 234567890’
The hash-code is the following 224-bit string.
b5 0 aecbe 4 e9bb0 b5 7 bc5 f3 ae 7 60 a8 e0 1 db2 4 f2 0 3 fb3 cdcd1 3 1 4 8 0 4 6e

A. 8 . 7 E xam pl e 7

In this example the data-string is the 56-byte string consisting of the ASCII-coded version of
‘abcdbcdecdefdefgefghfghighijhijkijkljklmklmnlmnomnopnopq’
After the padding process, the following two 1 6-word blocks are derived from the data-string.
61 62 63 64 62 63 64 65 63 64 65 66 64 65 6667 65 6667 68 6667 68 69 67 68 696a 68 696a6b
696a6b6c 6a6b6c6d 6b6c6d6e 6c6d6e6f 6d6e6f7 0 6e6f7 0 7 1 8 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0

00000000 00000000 00000000 00000000 00000000 00000000 00000000 00000000


0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 c0

The following are (hexadecimal representations of) the successive values of the variables Y0, Y1 , Y2, Y3, Y4,
Y5, Y6, Y7 in the first block process.
init: c1 0 5 9ed8 3 67 cd5 0 7 3 0 7 0 dd1 7 f7 0 e5 93 9 ffc0 0 b3 1 68 5 8 1 5 1 1 64 f98 fa7 befa4 fa4
0 0 e96b2 be c1 0 5 9ed8 3 67 cd5 0 7 3 0 7 0 dd1 7 0 4 3 4 2 2 4 2 ffc0 0 b3 1 68 5 8 1 5 1 1 64 f98 fa7
1 5 1 d1 7 d7 b 0 e96b2 be c1 0 5 9ed8 3 67 cd5 0 7 2 f8 ea3 d4 0 4 3 4 2 2 4 2 ffc0 0 b3 1 68 5 8 1 5 1 1
2 ff1 cbd7 f 5 1 d1 7 d7 b 0 e96b2 be c1 0 5 9ed8 7 9a8 96fa 2 f8 ea3 d4 0 4 3 4 2 2 4 2 ffc0 0 b3 1
3 2 4 bcc0 4 7 ff1 cbd7 f 5 1 d1 7 d7 b 0 e96b2 be 1 f60 7 95 a 7 9a8 96fa 2 f8 ea3 d4 04342242
4 7 d5 6a6ac 2 4 bcc0 4 7 ff1 cbd7 f 5 1 d1 7 d7 b de3 95 2 8 6 1 f60 7 95 a 7 9a8 96fa 2 f8 ea3 d4
5 7 4 5 beb1 1 7 d5 6a6ac 2 4 bcc0 4 7 ff1 cbd7 f d8 63 d1 3 2 de3 95 2 8 6 1 f60 7 95 a 7 9a8 96fa
6 0 dd4 1 5 7 3 7 4 5 beb1 1 7 d5 6a6ac 2 4 bcc0 4 7 2 e60 d3 2 3 d8 63 d1 3 2 de3 95 2 8 6 1 f60 7 95 a
7 9a2 5 4 1 fd 0 dd4 1 5 7 3 7 4 5 beb1 1 7 d5 6a6ac 0 8 d2 b3 4 8 2 e60 d3 2 3 d8 63 d1 3 2 de3 95 2 8 6

© ISO/IEC 2006 – All rights reserved 5


I S O/I E C 1 0 1 1 8-3: 2 0 0 4/Am d . 1 : 2 0 0 6(E )

8 3 1 4 0 e90 9 9a2 5 4 1 fd 0 dd4 1 5 7 3 7 4 5 beb1 1 95 dfd7 0 7 0 8 d2 b3 4 8 2 e60 d3 2 3 d8 63 d1 3 2


9 b2 95 4 92 5 3 1 4 0 e90 9 9a2 5 4 1 fd 0 dd4 1 5 7 3 0 5 ef5 e3 d 95 dfd7 0 7 0 8 d2 b3 4 8 2 e60 d3 2 3
10 b2 a8 7 4 fb b2 95 4 92 5 3 1 4 0 e90 9 9a2 5 4 1 fd 9dcaf1 1 8 0 5 ef5 e3 d 95 dfd7 0 7 0 8 d2 b3 4 8
11 1 1 6ce4 4 d b2 a8 7 4 fb b2 95 4 92 5 3 1 4 0 e90 9 0 e6d5 66a 9dcaf1 1 8 0 5 ef5 e3 d 95 dfd7 0 7
12 5 ff93 4 9a 1 1 6ce4 4 d b2 a8 7 4 fb b2 95 4 92 5 0 8 eb3 3 0 5 0 e6d5 66a 9dcaf1 1 8 0 5 ef5 e3 d
13 7 fa9d65 d 5 ff93 4 9a 1 1 6ce4 4 d b2 a8 7 4 fb 4 65 7 cf1 7 0 8 eb3 3 0 5 0 e6d5 66a 9dcaf1 1 8
14 0 0 6b1 b1 6 7 fa9d65 d 5 ff93 4 9a 1 1 6ce4 4 d 0 8 d0 9e8 d 4 65 7 cf1 7 0 8 eb3 3 0 5 0 e6d5 66a
15 b3 0 1 c98 a 0 0 6b1 b1 6 7 fa9d65 d 5 ff93 4 9a 6fbefa1 d 0 8 d0 9e8 d 4 65 7 cf1 7 0 8 eb3 3 0 5
16 e62 3 ecc0 b3 0 1 c98 a 0 0 6b1 b1 6 7 fa9d65 d 2 b3 f8 5 9c 6fbefa1 d 0 8 d0 9e8 d 4 65 7 cf1 7
17 d92 4 4 a7 8 e62 3 ecc0 b3 0 1 c98 a 0 0 6b1 b1 6 e66d8 d9c 2 b3 f8 5 9c 6fbefa1 d 0 8 d0 9e8 d
18 99c7 2 7 2 6 d92 4 4 a7 8 e62 3 ecc0 b3 0 1 c98 a b2 6a4 0 9c e66d8 d9c 2 b3 f8 5 9c 6fbefa1 d
19 ab0 cbed2 99c7 2 7 2 6 d92 4 4 a7 8 e62 3 ecc0 0 1 0 d7 c65 b2 6a4 0 9c e66d8 d9c 2 b3 f8 5 9c
20 7 8 0 62 8 7 8 ab0 cbed2 99c7 2 7 2 6 d92 4 4 a7 8 5 67 8 a94 9 0 1 0 d7 c65 b2 6a4 0 9c e66d8 d9c
21 d7 c5 c5 d5 7 8 0 62 8 7 8 ab0 cbed2 99c7 2 7 2 6 b2 8 0 3 60 c 5 67 8 a94 9 0 1 0 d7 c65 b2 6a4 0 9c
22 bad2 ee7 2 d7 c5 c5 d5 7 8 0 62 8 7 8 ab0 cbed2 0 d4 cd0 c4 b2 8 0 3 60 c 5 67 8 a94 9 0 1 0 d7 c65
23 bcf4 7 3 4 6 bad2 ee7 2 d7 c5 c5 d5 7 8 0 62 8 7 8 d6a1 9dc8 0 d4 cd0 c4 b2 8 0 3 60 c 5 67 8 a94 9
24 5 ecc4 1 7 b bcf4 7 3 4 6 bad2 ee7 2 d7 c5 c5 d5 3 3 3 7 a1 1 c d6a1 9dc8 0 d4 cd0 c4 b2 8 0 3 60 c
25 e1 5 bfa5 7 5 ecc4 1 7 b bcf4 7 3 4 6 bad2 ee7 2 0 ce1 5 1 7 3 3 3 3 7 a1 1 c d6a1 9dc8 0 d4 cd0 c4
26 fae61 67 b e1 5 bfa5 7 5 ecc4 1 7 b bcf4 7 3 4 6 7 3 dbe5 c7 0 ce1 5 1 7 3 3 3 3 7 a1 1 c d6a1 9dc8
27 991 c3 f99 fae61 67 b e1 5 bfa5 7 5 ecc4 1 7 b 8 60 2 a3 1 f 7 3 dbe5 c7 0 ce1 5 1 7 3 3 3 3 7 a1 1 c
28 7055843b 991 c3 f99 fae61 67 b e1 5 bfa5 7 eb4 de5 f8 8 60 2 a3 1 f 7 3 dbe5 c7 0 ce1 5 1 7 3
29 0 8 dcfb6d 7055843b 991 c3 f99 fae61 67 b 4 60 6d1 2 6 eb4 de5 f8 8 60 2 a3 1 f 7 3 dbe5 c7
30 2 964 b3 4 0 0 8 dcfb6d 7055843b 991 c3 f99 2 1 3 b3 e63 4 60 6d1 2 6 eb4 de5 f8 8 60 2 a3 1 f
31 5 b3 67 7 d0 2 964 b3 4 0 0 8 dcfb6d 7055843b c968 9cb0 2 1 3 b3 e63 4 60 6d1 2 6 eb4 de5 f8
32 1 ee0 fe7 d 5 b3 67 7 d0 2 964 b3 4 0 0 8 dcfb6d 1 4 3 1 8 a4 d c968 9cb0 2 1 3 b3 e63 4 60 6d1 2 6
33 6b91 8 d6e 1 ee0 fe7 d 5 b3 67 7 d0 2 964 b3 4 0 2 1 60 5 4 a8 1 4 3 1 8 a4 d c968 9cb0 2 1 3 b3 e63
34 a67 1 0 d0 d 6b91 8 d6e 1 ee0 fe7 d 5 b3 67 7 d0 bc8 2 3 a5 8 2 1 60 5 4 a8 1 4 3 1 8 a4 d c968 9cb0
35 5 e1 98 fed a67 1 0 d0 d 6b91 8 d6e 1 ee0 fe7 d c4 993 3 fe bc8 2 3 a5 8 2 1 60 5 4 a8 1 4 3 1 8 a4 d
36 1 3 6c3 2 0 a 5 e1 98 fed a67 1 0 d0 d 6b91 8 d6e 7 5 68 7 ccb c4 993 3 fe bc8 2 3 a5 8 2 1 60 5 4 a8
37 4 0 ee0 c4 3 1 3 6c3 2 0 a 5 e1 98 fed a67 1 0 d0 d f1 c2 caf6 7 5 68 7 ccb c4 993 3 fe bc8 2 3 a5 8
38 aa96d7 8 c 4 0 ee0 c4 3 1 3 6c3 2 0 a 5 e1 98 fed f4 8 b4 ceb f1 c2 caf6 7 5 68 7 ccb c4 993 3 fe
39 2 7 c97 b8 6 aa96d7 8 c 4 0 ee0 c4 3 1 3 6c3 2 0 a b5 5 62 1 6a f4 8 b4 ceb f1 c2 caf6 7 5 68 7 ccb
40 b0 7 bd3 2 7 2 7 c97 b8 6 aa96d7 8 c 4 0 ee0 c4 3 3 0 ec2 d7 6 b5 5 62 1 6a f4 8 b4 ceb f1 c2 caf6
41 d8 8 d5 6bd b0 7 bd3 2 7 2 7 c97 b8 6 aa96d7 8 c dc2 fa5 a4 3 0 ec2 d7 6 b5 5 62 1 6a f4 8 b4 ceb
42 5 c7 7 5 0 7 7 d8 8 d5 6bd b0 7 bd3 2 7 2 7 c97 b8 6 5 fad6db5 dc2 fa5 a4 3 0 ec2 d7 6 b5 5 62 1 6a
43 1 5 2 6cca3 5 c7 7 5 0 7 7 d8 8 d5 6bd b0 7 bd3 2 7 da8 a0 b1 c 5 fad6db5 dc2 fa5 a4 3 0 ec2 d7 6
44 c0 9dda1 4 1 5 2 6cca3 5 c7 7 5 0 7 7 d8 8 d5 6bd d98 ec2 3 a da8 a0 b1 c 5 fad6db5 dc2 fa5 a4
45 f8 8 5 e1 2 4 c0 9dda1 4 1 5 2 6cca3 5 c7 7 5 0 7 7 e4 f2 3 e4 1 d98 ec2 3 a da8 a0 b1 c 5 fad6db5
46 5 4 4 7 f0 ad f8 8 5 e1 2 4 c0 9dda1 4 1 5 2 6cca3 bfb7 4 97 c e4 f2 3 e4 1 d98 ec2 3 a da8 a0 b1 c
47 e62 2 7 0 61 5 4 4 7 f0 ad f8 8 5 e1 2 4 c0 9dda1 4 5 b0 961 9b bfb7 4 97 c e4 f2 3 e4 1 d98 ec2 3 a
48 0 0 9cebea e62 2 7 0 61 5 4 4 7 f0 ad f8 8 5 e1 2 4 5 9ecab4 6 5 b0 961 9b bfb7 4 97 c e4 f2 3 e4 1
49 92 b0 d1 69 0 0 9cebea e62 2 7 0 61 5 4 4 7 f0 ad 9a5 7 2 b8 5 5 9ecab4 6 5 b0 961 9b bfb7 4 97 c
50 8 d2 2 4 e5 4 92 b0 d1 69 0 0 9cebea e62 2 7 0 61 3 2 1 4 4 60 2 9a5 7 2 b8 5 5 9ecab4 6 5 b0 961 9b
51 c1 fcac7 1 8 d2 2 4 e5 4 92 b0 d1 69 0 0 9cebea 4 e98 a8 b7 3 2 1 4 4 60 2 9a5 7 2 b8 5 5 9ecab4 6
52 8 e6ce8 4 3 c1 fcac7 1 8 d2 2 4 e5 4 92 b0 d1 69 2 c1 8 2 3 be 4 e98 a8 b7 3 2 1 4 4 60 2 9a5 7 2 b8 5
53 0 0 0 f5 4 de 8 e6ce8 4 3 c1 fcac7 1 8 d2 2 4 e5 4 f3 2 cf2 a8 2 c1 8 2 3 be 4 e98 a8 b7 3 2 1 4 4 60 2
54 2 fe2 af3 a 0 0 0 f5 4 de 8 e6ce8 4 3 c1 fcac7 1 2 0 f7 63 ee f3 2 cf2 a8 2 c1 8 2 3 be 4 e98 a8 b7
55 1 fd5 3 9af 2 fe2 af3 a 0 0 0 f5 4 de 8 e6ce8 4 3 5 acdbd62 2 0 f7 63 ee f3 2 cf2 a8 2 c1 8 2 3 be
56 7 f8 664 4 e 1 fd5 3 9af 2 fe2 af3 a 0 0 0 f5 4 de 9fc1 0 2 1 6 5 acdbd62 2 0 f7 63 ee f3 2 cf2 a8
57 0 e0 8 dc7 7 7 f8 664 4 e 1 fd5 3 9af 2 fe2 af3 a 2 a4 ea7 4 9 9fc1 0 2 1 6 5 acdbd62 2 0 f7 63 ee
58 0 b9f4 8 5 1 0 e0 8 dc7 7 7 f8 664 4 e 1 fd5 3 9af 1 8 b1 dfb9 2 a4 ea7 4 9 9fc1 0 2 1 6 5 acdbd62
59 dbce97 c3 0 b9f4 8 5 1 0 e0 8 dc7 7 7 f8 664 4 e 6ec6ba5 b 1 8 b1 dfb9 2 a4 ea7 4 9 9fc1 0 2 1 6
60 3 cd7 8 fe1 dbce97 c3 0 b9f4 8 5 1 0 e0 8 dc7 7 3 e1 ca2 f1 6ec6ba5 b 1 8 b1 dfb9 2 a4 ea7 4 9
61 3 5 f4 bf1 c 3 cd7 8 fe1 dbce97 c3 0 b9f4 8 5 1 ba1 a8 a1 b 3 e1 ca2 f1 6ec6ba5 b 1 8 b1 dfb9
62 8 67 95 a7 d 3 5 f4 bf1 c 3 cd7 8 fe1 dbce97 c3 2 ce1 1 2 5 8 ba1 a8 a1 b 3 e1 ca2 f1 6ec6ba5 b
63 c1 4 b4 7 8 5 8 67 95 a7 d 3 5 f4 bf1 c 3 cd7 8 fe1 1 1 0 8 ac7 f 2 ce1 1 2 5 8 ba1 a8 a1 b 3 e1 ca2 f1

6 © ISO/IEC 2006 – All rights reserved


I S O/I E C 1 0 1 1 8-3: 2 0 0 4/Am d . 1 : 2 0 0 6(E )

The following eight words Y0, Y1 , Y2, Y3, Y4, Y5, Y6, Y7 represent the output of the round-function in the first
block process.

Y 0 = c1 0 5 9ed8 » c1 4 b4 7 8 5 = 8 2 5 0 e65 d
Y 1 = 3 67 cd5 0 7 » 8 67 9 5 a7 d = bcf62 f8 4
Y 2 = 3 0 7 0 dd1 7 » 3 5 f4 bf1 c = 6665 9c3 3
Y 3 = f7 0 e5 93 9 » 3 cd7 8 fe1 = 3 3 e5 e91 a
Y 4 = ffc0 0 b3 1 » 1 1 0 8 ac7 f = 1 0 c8 b7 b0
Y 5 = 68 5 8 1 5 1 1 » 2 ce1 1 2 5 8 = 95 3 92 7 69
Y 6 = 64 f98 fa7 » ba1 a8 a1 b = 1 f1 4 1 9c2
Y 7 = befa4 fa4 » 3 e1 ca2 f1 = fd1 6f2 95

The following are (hexadecimal representations of) the successive values of the variables Y0, Y1 , Y2, Y3, Y4,
Y5, Y6, Y7 in the second block process.
init: 8 2 5 0 e65 d bcf62 f8 4 6665 9c3 3 3 3 e5 e91 a 1 0 c8 b7 b0 95 3 92 7 69 1 f1 4 1 9c2 fd1 6f2 95
0 692 e4 0 7 d 8 2 5 0 e65 d bcf62 f8 4 6665 9c3 3 e4 be1 e69 1 0 c8 b7 b0 95 3 92 7 69 1 f1 4 1 9c2
1 60 8 d8 3 e1 692 e4 0 7 d 8 2 5 0 e65 d bcf62 f8 4 3 ddb8 cee e4 be1 e69 1 0 c8 b7 b0 95 3 92 7 69
2 0 9bfa8 9f 60 8 d8 3 e1 692 e4 0 7 d 8 2 5 0 e65 d f5 8 1 3 4 90 3 ddb8 cee e4 be1 e69 1 0 c8 b7 b0
3 2 3 7 5 fbc5 0 9bfa8 9f 60 8 d8 3 e1 692 e4 0 7 d c3 e1 8 5 2 9 f5 8 1 3 4 90 3 ddb8 cee e4 be1 e69
4 7 1 7 e7 9e7 2 3 7 5 fbc5 0 9bfa8 9f 60 8 d8 3 e1 7 7 d3 9ccc c3 e1 8 5 2 9 f5 8 1 3 4 90 3 ddb8 cee
5 a93 1 97 4 8 7 1 7 e7 9e7 2 3 7 5 fbc5 0 9bfa8 9f fdbb991 3 7 7 d3 9ccc c3 e1 8 5 2 9 f5 8 1 3 4 90
6 2 7 a4 2 f0 4 a93 1 97 4 8 7 1 7 e7 9e7 2 3 7 5 fbc5 b999cce4 fdbb991 3 7 7 d3 9ccc c3 e1 8 5 2 9
7 3 4 1 90 8 1 e 2 7 a4 2 f0 4 a93 1 97 4 8 7 1 7 e7 9e7 5 4 e69e2 1 b999cce4 fdbb991 3 7 7 d3 9ccc
8 0 ab3 93 c2 3 4 1 90 8 1 e 2 7 a4 2 f0 4 a93 1 97 4 8 ad2 964 7 e 5 4 e69e2 1 b999cce4 fdbb991 3
9 0 0 67 8 4 eb 0 ab3 93 c2 3 4 1 90 8 1 e 2 7 a4 2 f0 4 aff4 5 7 e7 ad2 964 7 e 5 4 e69e2 1 b999cce4
10 ecd5 c9db 0 0 67 8 4 eb 0 ab3 93 c2 3 4 1 90 8 1 e 9af4 2 a0 e aff4 5 7 e7 ad2 964 7 e 5 4 e69e2 1
11 4 7 62 e8 f0 ecd5 c9db 0 0 67 8 4 eb 0 ab3 93 c2 8 fb6f3 d8 9af4 2 a0 e aff4 5 7 e7 ad2 964 7 e
12 af93 b2 a8 4 7 62 e8 f0 ecd5 c9db 0 0 67 8 4 eb 97 e63 d3 9 8 fb6f3 d8 9af4 2 a0 e aff4 5 7 e7
13 5 3 3 c5 1 7 c af93 b2 a8 4 7 62 e8 f0 ecd5 c9db 7 3 64 bae6 97 e63 d3 9 8 fb6f3 d8 9af4 2 a0 e
14 0 3 c0 a5 1 b 5 3 3 c5 1 7 c af93 b2 a8 4 7 62 e8 f0 3 afb0 1 0 d 7 3 64 bae6 97 e63 d3 9 8 fb6f3 d8
15 5 fd0 65 bd 0 3 c0 a5 1 b 5 3 3 c5 1 7 c af93 b2 a8 b8 e64 2 2 9 3 afb0 1 0 d 7 3 64 bae6 97 e63 d3 9
16 1 8 b2 68 b5 5 fd0 65 bd 0 3 c0 a5 1 b 5 3 3 c5 1 7 c 3 8 eda3 8 d b8 e64 2 2 9 3 afb0 1 0 d 7 3 64 bae6
17 b8 7 d63 b4 1 8 b2 68 b5 5 fd0 65 bd 0 3 c0 a5 1 b 2 5 c2 c3 97 3 8 eda3 8 d b8 e64 2 2 9 3 afb0 1 0 d
18 b1 d8 4 6e0 b8 7 d63 b4 1 8 b2 68 b5 5 fd0 65 bd d67 4 4 0 5 f 2 5 c2 c3 97 3 8 eda3 8 d b8 e64 2 2 9
19 8 ba0 aed6 b1 d8 4 6e0 b8 7 d63 b4 1 8 b2 68 b5 b8 1 0 94 2 2 d67 4 4 0 5 f 2 5 c2 c3 97 3 8 eda3 8 d
20 1 4 8 5 f8 4 3 8 ba0 aed6 b1 d8 4 6e0 b8 7 d63 b4 1 c5 8 cd66 b8 1 0 94 2 2 d67 4 4 0 5 f 2 5 c2 c3 97
21 2 3 8 f4 cda 1 4 8 5 f8 4 3 8 ba0 aed6 b1 d8 4 6e0 3 9b2 eb5 f 1 c5 8 cd66 b8 1 0 94 2 2 d67 4 4 0 5 f
22 7 0 3 1 b0 61 2 3 8 f4 cda 1 4 8 5 f8 4 3 8 ba0 aed6 4 b8 2 62 ad 3 9b2 eb5 f 1 c5 8 cd66 b8 1 0 94 2 2
23 d4 e7 ec62 7 0 3 1 b0 61 2 3 8 f4 cda 1 4 8 5 f8 4 3 1 63 c3 aa0 4 b8 2 62 ad 3 9b2 eb5 f 1 c5 8 cd66
24 665 8 2 df3 d4 e7 ec62 7 0 3 1 b0 61 2 3 8 f4 cda c0 97 62 60 1 63 c3 aa0 4 b8 2 62 ad 3 9b2 eb5 f
25 dedb8 1 99 665 8 2 df3 d4 e7 ec62 7 0 3 1 b0 61 b7 3 e2 dec c0 97 62 60 1 63 c3 aa0 4 b8 2 62 ad
26 f8 5 3 691 7 dedb8 1 99 665 8 2 df3 d4 e7 ec62 7 c2 af9c4 b7 3 e2 dec c0 97 62 60 1 63 c3 aa0
27 d7 3 3 3 b8 a f8 5 3 691 7 dedb8 1 99 665 8 2 df3 b2 b0 b7 1 a 7 c2 af9c4 b7 3 e2 dec c0 97 62 60
28 7 60 8 4 7 c1 d7 3 3 3 b8 a f8 5 3 691 7 dedb8 1 99 5 8 98 eff2 b2 b0 b7 1 a 7 c2 af9c4 b7 3 e2 dec
29 7 eabc6d7 7 60 8 4 7 c1 d7 3 3 3 b8 a f8 5 3 691 7 2 4 dd3 8 8 3 5 8 98 eff2 b2 b0 b7 1 a 7 c2 af9c4
30 90 c4 962 4 7 eabc6d7 7 60 8 4 7 c1 d7 3 3 3 b8 a cce2 5 e67 2 4 dd3 8 8 3 5 8 98 eff2 b2 b0 b7 1 a
31 0 b8 7 62 64 90 c4 962 4 7 eabc6d7 7 60 8 4 7 c1 e4 e4 a5 3 b cce2 5 e67 2 4 dd3 8 8 3 5 8 98 eff2
32 0 4 cb3 6c0 0 b8 7 62 64 90 c4 962 4 7 eabc6d7 5 4 0 3 a3 91 e4 e4 a5 3 b cce2 5 e67 2 4 dd3 8 8 3
33 d5 8 cc3 4 a 0 4 cb3 6c0 0 b8 7 62 64 90 c4 962 4 b7 8 7 67 c3 5 4 0 3 a3 91 e4 e4 a5 3 b cce2 5 e67
34 0 ed1 4 dd7 d5 8 cc3 4 a 0 4 cb3 6c0 0 b8 7 62 64 fdcdc9d9 b7 8 7 67 c3 5 4 0 3 a3 91 e4 e4 a5 3 b
35 5 a8 9a94 2 0 ed1 4 dd7 d5 8 cc3 4 a 0 4 cb3 6c0 7 90 c4 a2 0 fdcdc9d9 b7 8 7 67 c3 5 4 0 3 a3 91
36 4 d3 0 4 2 4 c 5 a8 9a94 2 0 ed1 4 dd7 d5 8 cc3 4 a f95 bf8 5 3 7 90 c4 a2 0 fdcdc9d9 b7 8 7 67 c3
37 4 7 f5 8 c5 c 4 d3 0 4 2 4 c 5 a8 9a94 2 0 ed1 4 dd7 0 ec9be3 b f95 bf8 5 3 7 90 c4 a2 0 fdcdc9d9
38 b5 ad8 5 d7 4 7 f5 8 c5 c 4 d3 0 4 2 4 c 5 a8 9a94 2 cf9f1 dbe 0 ec9be3 b f95 bf8 5 3 7 90 c4 a2 0
39 7 62 fecbc b5 ad8 5 d7 4 7 f5 8 c5 c 4 d3 0 4 2 4 c 1 5 4 2 7 ed3 cf9f1 dbe 0 ec9be3 b f95 bf8 5 3

© ISO/IEC 2006 – All rights reserved 7


I S O/I E C 1 0 1 1 8-3: 2 0 0 4/Am d . 1 : 2 0 0 6(E )

40 3 2 abe7 4 6 7 62 fecbc b5 ad8 5 d7 4 7 f5 8 c5 c 4 0 5 3 e1 2 e 1 5 4 2 7 ed3 cf9f1 dbe 0 ec9be3 b


41 8 4 adb2 a0 3 2 abe7 4 6 7 62 fecbc b5 ad8 5 d7 7 cece4 e2 4 0 5 3 e1 2 e 1 5 4 2 7 ed3 cf9f1 dbe
42 c6e1 c5 af 8 4 adb2 a0 3 2 abe7 4 6 7 62 fecbc 4 2 f9990 b 7 cece4 e2 4 0 5 3 e1 2 e 1 5 4 2 7 ed3
43 3 5 e1 4 bfa c6e1 c5 af 8 4 adb2 a0 3 2 abe7 4 6 c9965 7 92 4 2 f9990 b 7 cece4 e2 4 0 5 3 e1 2 e
44 7 4 1 0 bfd8 3 5 e1 4 bfa c6e1 c5 af 8 4 adb2 a0 ca5 4 ce5 1 c9965 7 92 4 2 f9990 b 7 cece4 e2
45 3 fe9e7 63 7 4 1 0 bfd8 3 5 e1 4 bfa c6e1 c5 af ae7 cdb66 ca5 4 ce5 1 c9965 7 92 4 2 f9990 b
46 8 5 3 c3 a0 0 3 fe9e7 63 7 4 1 0 bfd8 3 5 e1 4 bfa c2 be0 5 4 d ae7 cdb66 ca5 4 ce5 1 c9965 7 92
47 f7 d0 3 5 e7 8 5 3 c3 a0 0 3 fe9e7 63 7 4 1 0 bfd8 f6d5 9d2 c c2 be0 5 4 d ae7 cdb66 ca5 4 ce5 1
48 2 0 bae2 b8 f7 d0 3 5 e7 8 5 3 c3 a0 0 3 fe9e7 63 cab7 3 f0 6 f6d5 9d2 c c2 be0 5 4 d ae7 cdb66
49 ae6bf667 2 0 bae2 b8 f7 d0 3 5 e7 8 5 3 c3 a0 0 5 2 3 8 4 d2 f cab7 3 f0 6 f6d5 9d2 c c2 be0 5 4 d
50 1 2 e5 0 4 e5 ae6bf667 2 0 bae2 b8 f7 d0 3 5 e7 f9a8 3 7 7 f 5 2 3 8 4 d2 f cab7 3 f0 6 f6d5 9d2 c
51 f3 4 97 0 5 4 1 2 e5 0 4 e5 ae6bf667 2 0 bae2 b8 d0 ab7 cfc f9a8 3 7 7 f 5 2 3 8 4 d2 f cab7 3 f0 6
52 9f1 66cdb f3 4 97 0 5 4 1 2 e5 0 4 e5 ae6bf667 7 1 b3 4 5 9b d0 ab7 cfc f9a8 3 7 7 f 5 2 3 8 4 d2 f
53 ccd8 fa4 4 9f1 66cdb f3 4 97 0 5 4 1 2 e5 0 4 e5 0 f5 5 7 ddd 7 1 b3 4 5 9b d0 ab7 cfc f9a8 3 7 7 f
54 f5 e664 bd ccd8 fa4 4 9f1 66cdb f3 4 97 0 5 4 a67 9a5 e9 0 f5 5 7 ddd 7 1 b3 4 5 9b d0 ab7 cfc
55 d4 ea8 c7 e f5 e664 bd ccd8 fa4 4 9f1 66cdb 2 95 8 ce2 a a67 9a5 e9 0 f5 5 7 ddd 7 1 b3 4 5 9b
56 e8 c8 fec7 d4 ea8 c7 e f5 e664 bd ccd8 fa4 4 3 5 f68 0 0 e 2 95 8 ce2 a a67 9a5 e9 0 f5 5 7 ddd
57 8 8 2 ed69e e8 c8 fec7 d4 ea8 c7 e f5 e664 bd 3 0 2 67 d8 e 3 5 f68 0 0 e 2 95 8 ce2 a a67 9a5 e9
58 4 ec7 2 5 f6 8 8 2 ed69e e8 c8 fec7 d4 ea8 c7 e ce1 d1 ce4 3 0 2 67 d8 e 3 5 f68 0 0 e 2 95 8 ce2 a
59 5 c9cfc69 4 ec7 2 5 f6 8 8 2 ed69e e8 c8 fec7 c8 2 4 2 b92 ce1 d1 ce4 3 0 2 67 d8 e 3 5 f68 0 0 e
60 c9a3 1 8 3 6 5 c9cfc69 4 ec7 2 5 f6 8 8 2 ed69e 9e4 0 a3 7 0 c8 2 4 2 b92 ce1 d1 ce4 3 0 2 67 d8 e
61 f7 5 4 c1 6e c9a3 1 8 3 6 5 c9cfc69 4 ec7 2 5 f6 3 3 3 e0 b63 9e4 0 a3 7 0 c8 2 4 2 b92 ce1 d1 ce4
62 94 3 1 4 7 4 8 f7 5 4 c1 6e c9a3 1 8 3 6 5 c9cfc69 1 fbc63 b0 3 3 3 e0 b63 9e4 0 a3 7 0 c8 2 4 2 b92
63 f2 e7 a4 b9 94 3 1 4 7 4 8 f7 5 4 c1 6e c9a3 1 8 3 6 9ffd8 dac 1 fbc63 b0 3 3 3 e0 b63 9e4 0 a3 7 0

The following eight words Y0 , Y1 , Y2 , Y3, Y4, Y5, Y6, Y7 represent the output of the final iteration of the round-
function.

Y 0 = 8 2 5 0 e65 d » f2 e7 a4 b9 = 7 5 3 8 8 b1 6
Y 1 = bcf62 f8 4 » 94 3 1 4 7 4 8 = 5 1 2 7 7 6cc
Y 2 = 6665 9c3 3 » f7 5 4 c1 6e = 5 dba5 da1
Y 3 = 3 3 e5 e91 a » c9a3 1 8 3 6 = fd8 90 1 5 0
Y 4 = 1 0 c8 b7 b0 » 9ffd8 dac = b0 c64 5 5 c
Y 5 = 95 3 92 7 69 » 1 fbc63 b0 = b4 f5 8 b1 9
Y 6 = 1 f1 4 1 9c2 » 3 3 3 e0 b63 = 5 2 5 2 2 5 2 5
Y 7 = fd1 6f2 95 » 9e4 0 a3 7 0 = 63 5 65 1 e5

The hash value is the following 224-bit string.

7 5 3 8 8 b1 6 5 1 2 7 7 6cc 5 dba5 da1 fd8 90 1 5 0 b0 c64 5 5 c b4 f5 8 b1 9 5 2 5 2 2 5 2 5

A. 8 . 8 E xam pl e 8

In this example the data-string is the 1 ,000,000-byte string consisting of the ASCII-coded version of ‘a’
repeated 1 0 6 times.

The hash-code is the following 224-bit string.

2 0 7 94 65 5 98 0 c91 d8 bbb4 c1 ea 97 61 8 a4 b f0 3 f4 2 5 8 1 94 8 b2 ee 4 ee7 ad67

8 © ISO/IEC 2006 – All rights reserved


I S O/I E C 1 0 1 1 8-3: 2 0 0 4/Am d . 1 : 2 0 0 6(E )

A. 8 . 9 E xam pl e 9

In this example the data-string consists of a single bit, namely 0 .

The hash-code is the following 224-bit string.

d3 fe5 7 cb 7 6cdd2 4 e 9eb2 3 e7 e 1 5 68 4 e0 3 9c7 5 4 5 9b eaae1 0 0 f 8 97 1 2 e9d

A. 8 . 1 0 E xam pl e 1 0

In this example the data-string consists of a single bit, namely 1 .

The hash-code is the following 224-bit string.

0 d0 5 0 96b ca2 a4 a7 7 a2 b4 7 a0 5 a5 961 8 d0 1 1 7 4 b3 7 8 92 3 7 61 3 5 c1 b6e95 7

A. 8 . 1 1 E xam pl e 1 1

In this example the data-string consists of 1 01 bits, namely 1 0 1 0 1 0 1 …0 1 .

The hash-code is the following 224-bit string.

2 b1 d4 a3 4 1 5 5 c0 4 d7 a5 1 0 65 d6 a4 4 7 62 0 3 9a3 8 dffd 7 3 e7 6b1 7 b0 4 3 5 5 5 c

A. 8 . 1 2 E xam pl e 1 2

In this example the data-string consists of 256 octets, namely 0 0 0 1 0 2 0 3 … FE FF .

The hash-code is the following 224-bit string.

8 8 7 0 2 e63 2 3 7 8 2 4 c4 eb0 d0 fcf e4 1 4 69a4 62 4 93 e8 b eb2 a7 5 bb e5 98 1 7 3 4

A. 8 . 1 3 E xam pl e 1 3

In this example the data-string is the H0 consists of 224 0 bits. For i = 1 to 1 00 let Hi be the hash-code of Hi-1 .

The hash-code H
1 00 is the following 224-bit string.

a0 8 8 4 cc1 a3 3 5 0 4 2 b fe4 5 2 bf4 67 7 7 ed2 0 2 1 7 a3 4 7 2 8 1 dc3 8 9e 7 b1 fbfee

A. 9 C om pl ete tes t vectors for D ed i cated H as h -F u n cti on s 4, 5, 6 an d 8

As a part of ISO/IEC 1 01 1 8-3, the dedicated hash-functions SHA-256, SHA-384, SHA-51 2 and SHA-224 are
described. Annex A.4, A.5, A.6 and A.8 respectively provide example test vectors for these four hash
functions. An important shortcoming of these examples is that all of the input values are composed solely of
ASCII-encoded alphanumeric characters. This addendum contains a more complete set of test vectors for
these hash functions.

The choice of test vectors is based on the following considerations:

1 . Inputs of length 1 up to 51 2 (for SHA-224 and SHA-256) or 1 024 (for SHA-384 and SHA-51 2) have been
defined in order to test the padding scheme. (The examples in Annex A.4 – A.6 and A.8 contain only
messages with lengths that are a multiple of 8.) A small number of test vectors with greater length have been
included.

© ISO/IEC 2006 – All rights reserved 9


I S O/I E C 1 0 1 1 8-3: 2 0 0 4/Am d . 1 : 2 0 0 6(E )

2. It has been ensured that all 32-bit words (SHA-224 and SHA-256) or all 64-bit words (SHA-384 and SHA-
51 2) with Hamming weight 1 occur at least once as part of the input. This has been done in order to test the
message expansion functions.
3. The treatment of carry overflow from one byte to another is tested by ensuring that the following additions
occur at least once:
a. For SHA-224 and SHA-256
i. 0 xFFFFFFFF + 0 x0 0 0 0 0 0 0 1
ii. 0 xFFFF0 0 0 0 + 0 x0 0 0 1 0 0 0 0
iii. 0 x0 0 0 0 FFFF + 0 x0 0 0 0 0 0 0 1
iv. 0 xFF0 0 FF0 0 + 0 x0 1 0 0 0 1 0 0
v. 0 x0 0 FF0 0 FF + 0 x0 0 0 1 0 0 0 1

b. For SHA-384 and SHA-51 2


i. 0 xFFFFFFFFFFFFFFFF + 0 x0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1
ii. 0 xFFFFFFFF0 0 0 0 0 0 0 0 + 0 x0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0
iii. 0 x0 0 0 0 0 0 0 0 FFFFFFFF + 0 x0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1
iv. 0 xFFFF0 0 0 0 FFFF0 0 0 0 + 0 x0 0 0 1 0 0 0 0 0 0 0 1 0 0 0 0
v. 0 x0 0 0 0 FFFF0 0 0 0 FFFF + 0 x0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 1
vi. 0 xFF0 0 FF0 0 FF0 0 FF0 0 + 0 x0 1 0 0 0 1 0 0 0 1 0 0 0 1 0 0
vii. 0 x0 0 FF0 0 FF0 0 FF0 0 FF + 0 x0 0 0 1 0 0 0 1 0 0 0 1 0 0 0 1

The complete list of test vectors can be found at the following URL:
http://www.iaik.tu-graz.ac.at/research/sha2_testvectors.zip.
NOTE Complete test vectors for the remaining hash functions contained in this part of ISO/IEC 1 01 1 8 are not
available at the above referenced URL. Analysis is currently ongoing to determine whether additional test vectors will be
required for the remaining hash functions, and if so, what the required considerations will be. If additional test vectors are
necessary, a second amendment to this part of ISO/IEC 1 01 1 8 may be considered.

10 © ISO/IEC 2006 – All rights reserved


I S O/I E C 1 0 1 1 8-3: 2 0 0 4/Am d . 1 : 2 0 0 6(E )

I CS 35. 0 40

Price based on 1 0 pages

© ISO/IEC 2006 – All rights reserved

You might also like