EMZETT.
Login

SHA-512

In short: A hashing algorithm from the SHA-2 family that produces a 512-bit (64-byte) hash value — the “big brother” of SHA-256.

In more detail: SHA-512 works internally with 64-bit words instead of 32-bit like SHA-256, which often makes it even faster than SHA-256 on 64-bit processors, despite the output value being twice as long. The longer output theoretically offers more resistance against collision attacks; in practice SHA-256 is considered sufficiently secure for most use cases.

In Depth

The internal structure of SHA-512 is almost identical to SHA-256 (both are based on the same Merkle-Damgård construction), just with larger internal state variables and more rounds:

SHA-256: 32-bit words, 64 rounds, 256-bit output
SHA-512: 64-bit words, 80 rounds, 512-bit output

On modern 64-bit servers (practically every server processor today), SHA-512 can thereby work more efficiently per byte than SHA-256, because the internal 64-bit operations are executed directly in a single processor instruction, whereas SHA-256 needs two 32-bit operations for the same amount of data. On 32-bit systems (e.g. some embedded devices), the advantage reverses — there SHA-256 is usually faster.

There’s also SHA-384, a variant that computes internally like SHA-512 but truncates the output to 384 bits (through different initialisation values, not simply by cutting it off) — useful when a somewhat shorter, but still very secure, hash is wanted. For the vast majority of applications (TLS certificates, signatures, file integrity), the security gain of SHA-512 over SHA-256 is practically negligible — both are considered cryptographically secure, and SHA-256 has become the de-facto standard simply because it performs equally well on more systems (especially 32-bit and embedded systems).

Typical uses of SHA-512

In practice SHA-512 is encountered directly less often than SHA-256, but it’s the basis of several widely used systems: Linux systems often use SHA-512-based crypt (the $6$ prefix in /etc/shadow) for hashed user passwords. Digital signature schemes with high security requirements (e.g. certain government or military systems) prefer SHA-512, to benefit from the larger theoretical security margin, even if it doesn’t need to be practically exploited for the foreseeable future. Some blockchain and cryptocurrency systems beyond Bitcoin (which uses SHA-256) also rely on SHA-512 or variants of it.

SHA-2 vs. SHA-3 competition

In addition to the SHA-2 family (to which SHA-256 and SHA-512 belong), NIST published a completely new, structurally independent hash standard, SHA-3, in 2015 — not because SHA-2 was broken, but as a precautionary safeguard (“diversity”), in case a structural weakness were ever found in SHA-2 in the future. SHA-3 is based on a completely different internal construction (the Keccak sponge function instead of Merkle-Damgård) and so far is used considerably less often than SHA-2, since SHA-2 (including SHA-256 and SHA-512) is still considered fully secure and there’s correspondingly little urgency to switch.

Why the theoretical security margin is rarely practically relevant

A 512-bit hash theoretically offers collision resistance of 2^256 (because of the birthday paradox, practical security against collisions is roughly half the bit length) — a number that exceeds any imagination and is far beyond what could be attacked with today’s or foreseeable future computing power. SHA-256, with 2^128 collision resistance, also offers an astronomically large security margin — the difference between “unimaginably secure” and “even more unimaginably secure” is barely relevant for practical purposes. The choice between SHA-256 and SHA-512 is therefore almost never made in practice based on security considerations, but based on performance on the target platform and the conventions of the system or standard being used.

See also: SHA-256, SHA types, Hashing