Tooleux

Compute a ParallelHash128 (tree-based) hash of any input.

Runs in your browser. Nothing leaves your device.
Calculate ParallelHash128 (NIST SP 800-185) of any input. Tree-based parallel hash for large data. Free, offline, runs client-side. Read more Show less

What is ParallelHash128?

ParallelHash128 is a hash function defined in NIST SP 800-185 for hashing large messages in parallel. It splits the input into fixed-size blocks, hashes each block independently, then combines the block hashes with cSHAKE.

The result is a hash whose computation can be parallelized across multiple CPU cores - which matters when hashing very large amounts of data (terabytes) where a single-threaded SHA-3 would be a bottleneck.

How to use

Type or paste the input. Choose the output length in bits. Optionally provide a customization string.

The tool uses the default block size: 168 bytes for ParallelHash128. This matches the NIST reference configuration and interops with the pycryptodome library and @noble/hashes.

How it works

The input is divided into blocks of B bytes (the block size). Each block is hashed independently using cSHAKE128 with the function name "ParallelHash". The resulting block hashes are concatenated and hashed once more with a final cSHAKE that encodes the block size B, the number of blocks, and the output length.

This is a Merkle-tree-like construction. Because each block is independent, they can be processed in any order and by any number of cores - which is the point.

FAQ

When should I use ParallelHash?

When you are hashing large amounts of data (a gigabyte or more) on multi-core hardware and SHA-3 is CPU-bound. For small inputs, ParallelHash has no advantage over plain cSHAKE and is slightly slower because of the tree overhead.

Is ParallelHash deterministic?

Yes, provided the block size is the same. Two implementations that use different block sizes produce different hashes for the same input. This tool uses the NIST default block size, which is what most libraries use.

ParallelHash vs SHAKE

SHAKE (and cSHAKE) are sequential - each block depends on the previous block's state, so the computation cannot be parallelized. ParallelHash breaks that dependency, at the cost of a slightly more complex construction.

Is ParallelHash secure?

Yes. Its security is based on the underlying cSHAKE. No practical attacks are known. For any input size, ParallelHash provides the same security level as cSHAKE.

Can I change the block size?

Yes in principle, but this tool uses the default (168 bytes for ParallelHash128) to match the standard configuration. For custom block sizes, use a native library that exposes the parameter.

Command line equivalent
# Python with pycryptodome
pip install pycryptodome
python3 -c '
from Crypto.Hash import ParallelHash128
h = ParallelHash128.new(block_size=168, digest_bytes=32, custom=b"")
h.update(b"abc")
print(h.hexdigest())
'

# Node with @noble/hashes
npm i @noble/hashes
node --input-type=module -e '
import { parallelhash128 } from "@noble/hashes/sha3-addons";
const out = parallelhash128(new TextEncoder().encode("abc"), { dkLen: 32 });
console.log(Buffer.from(out).toString("hex"));
'
Loads a test value into the form
Input
ParallelHash128