You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

关于利用哈希函数保障数据完整性抵御MITM攻击时中间人篡改哈希值的技术疑问

Why Can't an Attacker Just Modify Both the Message and Its Hash?

Great question—this is one of the most common "aha!" moments when learning about cryptographic integrity checks. Let's break this down clearly:

First, you're totally right about the basic problem: if all you do is send [原始消息, SHA256(原始消息)], a man-in-the-middle (MITM) can absolutely modify the message, recalculate the SHA256 hash of the tampered message, swap out the original hash, and the receiver would never know the difference. That setup only protects against accidental corruption (like a glitch in the network messing up bits), not intentional tampering.

So why do we say SHA-256 (and other hashes) help prevent tampering? Because we never use hashes alone for this purpose—we pair them with a secret or a digital signature to fix exactly this flaw. Here's how the two common solutions work:

1. HMAC (Hash-Based Message Authentication Code)

Instead of just hashing the message, the sender computes a hash that combines the message with a secret shared key known only to the sender and receiver. For example, using HMAC-SHA256(message, secret_key).

  • The MITM doesn't have access to the secret key, so even if they change the message, they can't generate a valid HMAC that matches the tampered message.
  • When the receiver gets the message and HMAC, they use the same secret key to compute the HMAC themselves. If it doesn't match the received HMAC, they know the message was tampered with.

2. Digital Signatures

For scenarios where sender and receiver don't share a secret key (like public communication), we use digital signatures. Here's the flow:

  • The sender computes the SHA256 hash of the original message.
  • They then encrypt this hash using their private key (only they have this). This encrypted hash is the signature.
  • The receiver gets the message and signature, computes the SHA256 hash of the received message, then decrypts the signature using the sender's public key (anyone can get this).
  • If the decrypted hash matches the one they computed, the message is authentic—because only the sender's private key could have generated that signature. A MITM can't forge a valid signature without the sender's private key, even if they modify the message.

To sum up: Bare hashes don't prevent MITM tampering, but hashes combined with secret keys (HMAC) or digital signatures do—because the attacker can't replicate the valid hash/sig without the secret or private key.

内容的提问来源于stack exchange,提问作者bob

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.04.27 13:07:45