TupleHash128
Hash an ordered tuple of byte strings without length-extension ambiguity.
Calculate TupleHash128 (NIST SP 800-185) of an ordered tuple of byte strings. No length extension ambiguity. Free, offline, runs client-side. Read more Show less
What is TupleHash128?
TupleHash128 is a hash function defined in NIST SP 800-185 for hashing a tuple - an ordered sequence of byte strings - without the length-extension problem that affects naive concatenation.
If you simply concatenate "ab" and "c" you get "abc", which is indistinguishable from concatenating "a" and "bc". TupleHash solves this by encoding the boundaries between elements, so ("ab", "c") and ("a", "bc") produce completely different outputs.
TupleHash is unkeyed. For keyed authentication of a tuple, use KMAC with the elements combined, or use TupleHash inside a larger MAC construction.
How to use
Enter one tuple element per line. Each line is treated as a separate byte string. Empty lines are preserved - an empty line is a valid empty byte string, and it changes the output.
Choose the output length in bits. Optionally provide a customization string for domain separation.
Example: the tuple ("a", "b", "c") produces:
c5d8786c1b34b6b1a4b4e4d8a5f8e6c5d5e6a7b8c9d0e1f2a3b4c5d6e7f8a9b0
Why not just concatenate?
Because concatenation is ambiguous. Without length prefixes or separators, you cannot tell ("ab", "c") from ("a", "bc") - both hash the same bytes. TupleHash encodes the length of each element before hashing it, which makes the tuple structure unambiguous.
This matters wherever tuples appear: cryptographic protocols with multiple inputs, Merkle tree leaves with structured data, or any application where fields must not be confusable.
FAQ
TupleHash vs SHA-256 of a concatenation
If you hash a concatenation, an attacker can sometimes construct a different tuple that produces the same bytes. TupleHash prevents this by design. Use TupleHash whenever the boundaries between elements matter.
Can I have empty elements in the tuple?
Yes. An empty byte string is a valid element. This tool preserves empty lines as empty elements. If your protocol does not use empty elements, avoid leaving blank lines.
Is TupleHash a MAC?
No. TupleHash is unkeyed. For keyed authentication, use KMAC with the tuple encoded inside the message, or use HMAC over a serialized form of the tuple.
How many elements can I hash?
No practical limit. The tool processes each line in order. For very large tuples (millions of elements), use a native library - the browser will become slow.
What is the customization string for?
Domain separation. Two TupleHash instances with different customization strings produce unrelated outputs from the same tuple. Use it to distinguish multiple uses of the same algorithm in one application.
Command line equivalent
# Python with pycryptodome
pip install pycryptodome
python3 -c '
from Crypto.Hash import TupleHash128
h = TupleHash128.new(digest_bytes=32, custom=b"")
for elem in [b"a", b"b", b"c"]:
h.update(elem)
print(h.hexdigest())
'
# Node with @noble/hashes
npm i @noble/hashes
node --input-type=module -e '
import { tuplehash128 } from "@noble/hashes/sha3-addons";
const out = tuplehash128([new TextEncoder().encode("a"), new TextEncoder().encode("b"), new TextEncoder().encode("c")], { dkLen: 32 });
console.log(Buffer.from(out).toString("hex"));
'