You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

基于比特币课程Hash Hiding属性:哈希前拼接随机串'r'的原因探究

Why Append Random String r to Input x Before Hashing?

Great question! Let's break down the key reasons for this practice, especially tied to the "Hiding" property of cryptographic hash functions like those used in Bitcoin:

  • Thwart enumeration of high-probability inputs
    Your initial guess is spot-on. If x is a low-entropy value (like a common password, short PIN, or frequently used string), attackers can easily precompute hashes for all likely x values and compare them against the target hash to reverse-engineer the input. By appending a random r, the actual input to the hash becomes r||x (the concatenation of r and x). Even if two users have the same x, their unique r values will produce completely different hashes—making it impossible for attackers to use precomputed lists of common x hashes to match the output.

  • Neutralize rainbow table attacks
    Rainbow tables are massive precomputed databases mapping common inputs to their hashes, designed to speed up reverse hash lookups. Adding a random r renders these tables useless. Since r is unpredictable and high-entropy, the number of possible r||x combinations is astronomically large—attackers can't possibly precompute hashes for every potential r and x pair.

  • Strengthen the core "Hiding" property
    The Hiding property requires that given a hash output, it's computationally infeasible to determine the original input. When x has low entropy (limited possible values), direct hashing fails this property because brute-forcing x is easy. By combining x with a high-entropy random r, the total entropy of the input skyrockets. Even if an attacker guesses a possible x, they'd also need to guess the exact r to verify their guess—and the randomness of r makes this computationally unfeasible for large enough r sizes.

In cryptography, this random r is often called a salt, and it's a standard technique used in password storage, blind signatures (a concept relevant to Bitcoin's privacy features), and any scenario where we need to protect the privacy of low-entropy inputs.

内容的提问来源于stack exchange,提问作者rahs

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.19 08:51:53