Knowledge Base

Browse the concepts behind Truestamp. Follow the links between concepts, or search across everything.

Domain separation

Truestamp's rule that every hash over its own evidence is SHA-256 computed over a reserved single-byte prefix plus the data, so a hash made for one purpose (Merkle leaf, node, item claims, proof payload) can never collide with or be replayed as a hash for another purpose.

Overview

Domain separation is the rule that every hash Truestamp computes over its own evidence is SHA-256 over a distinct reserved single-byte prefix followed by the data. Because the prefix differs per context, a hash computed for one purpose (a Merkle leaf, an internal node, an item’s claims, the proof signing payload) can never collide with or be replayed as a hash for another purpose, even when the underlying bytes are identical. The reserved byte for each context is called a byte prefix, and every reserved value is listed in the byte-prefix registry. A prefix marks a kind of hashed object, not a use of one, so quoting a block hash or an entropy hash somewhere new, as an item’s witness for instance, reuses that object’s own prefix rather than reserving another. The full rationale, the attacks it blocks, and cross-language reproduction examples are in domain-separated hashing.

Citations

  1. RFC 6962: Certificate Transparency. Source of the byte-prefix domain-separation approach, including the 0x00 leaf and 0x01 node prefixes.