Knowledge Base
Browse the concepts behind Truestamp. Follow the links between concepts, or search across everything.
Tagged: domain-separation
7
Cryptography
Byte-Prefix Registry
The complete lookup table of every single-byte SHA-256 domain-separation prefix Truestamp reserves, mapping each prefix value to the object and domain it isolates, so a verifier can reproduce any hash exactly.
Domain-Separated Hashing (SHA-256 Byte Prefixes)
How Truestamp separates SHA-256 hash contexts with single-byte domain prefixes, keeping leaf hashes, node hashes, and each kind of hashed object in distinct hash spaces to prevent ambiguity and second-preimage confusion.
Glossary
Byte prefix
The reserved single byte prepended to data before SHA-256 hashing for domain separation; every hashed object kind in Truestamp has its own registered prefix (0x00 Merkle leaf, 0x01 internal node, 0x11 item claims, 0x61 proof signing payload), enumerated in the byte-prefix registry.
Domain separation
Truestamp's rule that every hash over its own evidence is SHA-256 computed over a reserved single-byte prefix plus the data, so a hash made for one purpose (Merkle leaf, node, item claims, proof payload) can never collide with or be replayed as a hash for another purpose.
Merkle leaf
The bottom-level entry of a Merkle tree, hashed as SHA-256(0x00 || hash) under the reserved leaf prefix so it can never be confused with an interior node (prefix 0x01); block-tree leaves are item and entropy observation hashes, epoch-tree leaves are block hashes.
RFC 6962
The Certificate Transparency standard Truestamp takes its Merkle hash primitives from - SHA-256 with 0x00 leaf and 0x01 node domain-separation prefixes, and the empty-tree root - while shaping the tree above them by its own key-sort and power-of-two padding rules.