What is SHA-3?
The short version: SHA-3 is the newest member of the Secure Hash Algorithm family, standardised by NIST in FIPS 202 (2015). It is built on Keccak, a design that works nothing like SHA-2, so the two families do not share weaknesses.
Where it came from
In 2007 NIST opened a public competition for a new hash function, as insurance in case attacks on MD5 and SHA-1 ever carried over to SHA-2. Sixty-four designs were submitted. In 2012 NIST chose Keccak, by Guido Bertoni, Joan Daemen, Michaƫl Peeters and Gilles Van Assche, and published it as SHA-3 in FIPS 202 in August 2015.
SHA-3 was never a replacement for SHA-2, which remains secure. It is a second, independent standard, so the world has a well-tested fallback built on different mathematics.
The sponge construction
SHA-3 keeps a 1600-bit internal state and works in two phases:
- Absorbing. The padded message is split into blocks. Each block is XORed into the first part of the state (the rate), then the whole state is scrambled by the Keccak-f[1600] permutation (24 rounds).
- Squeezing. Output is read from the rate part of the state, running the permutation again whenever more output is needed.
The rest of the state, the capacity, is never directly touched by input or output. Its size sets the security level. Because the internal state is much larger than the output, SHA-3 is not vulnerable to the length-extension attacks that affect SHA-256 and SHA-512 when used naively as a MAC.
The SHA-3 family
| Function | Output | Rate (bits) | Capacity (bits) | Collision resistance |
|---|---|---|---|---|
| SHA3-224 | 224 bits | 1152 | 448 | 112 bits |
| SHA3-256 | 256 bits | 1088 | 512 | 128 bits |
| SHA3-384 | 384 bits | 832 | 768 | 192 bits |
| SHA3-512 | 512 bits | 576 | 1024 | 256 bits |
| SHAKE128 | any length | 1344 | 256 | up to 128 bits |
| SHAKE256 | any length | 1088 | 512 | up to 256 bits |
SHAKE128 and SHAKE256 are extendable-output functions (XOFs): you choose how many bytes you want. NIST SP 800-185 builds more tools on the same core: cSHAKE, KMAC (a MAC), TupleHash and ParallelHash.
Where SHA-3 is used
- Post-quantum cryptography. The new NIST standards ML-KEM (FIPS 203) and ML-DSA (FIPS 204) use SHA3-256, SHA3-512, SHAKE128 and SHAKE256 internally, so SHA-3 is in the core of the next generation of public-key cryptography.
- Blockchains. Ethereum uses Keccak-256 (the pre-standard version) for addresses, transaction hashes and storage. See SHA-3 vs Keccak.
- Libraries and protocols. SHA-3 is available in OpenSSL, the Python and Go standard libraries, Java, .NET, PHP and Node.js. See the code examples.
Example
SHA3-256("hello world"):
644bcc7e564373040999aac89e7622f3ca71fba1d972fd94a31c3bfbf24e3938
Try your own input in the calculator.
Own sha3.si
A short, exact-match domain for one of the world's core cryptographic standards. Ideal for a security, cryptography, blockchain or developer-tools brand.
Buy now or make an offer Why this name