🔒 Pro · Component 1 · 1.3.1 Compression, Encryption and Hashing
1.3.1c Hashing
OCR H446 · A Level Computer Science · ~11 min read
Notes
Video
Slides
Worksheet
Quiz

What is Hashing?

A hash function is an algorithm that takes an input of any size and produces a fixed-length output called a hash, hash value, or message digest. Hashing is a one-way process — it is computationally infeasible to reverse it to find the original input from the hash value alone.

Properties of a Good Hash Function

  • Deterministic: the same input always produces the same hash output.
  • Fixed output size: regardless of input length, the output is always the same size (e.g. SHA-256 always produces 256 bits).
  • One-way (pre-image resistant): given a hash value, it is computationally infeasible to reverse-engineer the original input.
  • Avalanche effect: a tiny change to the input (even a single bit) produces a completely different hash — the output appears random and unrelated to the original.
  • Collision resistant: it should be computationally infeasible to find two different inputs that produce the same hash output. (A collision is when two different inputs hash to the same value.)
  • Efficient: computing the hash should be fast for any input size.

Common Hash Algorithms

AlgorithmOutput SizeStatusNotes
MD5128 bits (32 hex chars)Broken — do not use for securityCollisions found; still used as a checksum for non-security purposes
SHA-1160 bits (40 hex chars)Deprecated — brokenCollisions demonstrated; replaced by SHA-2
SHA-256256 bits (64 hex chars)Current standardPart of SHA-2 family; widely used in TLS, digital signatures, Bitcoin
SHA-512512 bits (128 hex chars)Current standardStronger; used where higher security is needed

Uses of Hashing

1. Storing Passwords Securely

Websites must never store passwords in plaintext. Instead:

  • When a user sets a password, the system hashes the password and stores only the hash.
  • When the user logs in, the entered password is hashed and compared with the stored hash.
  • If they match → login accepted. If not → rejected.
  • Even if the database is stolen, the attacker sees only hashes — they cannot reverse them to get the original passwords.
  • Salting: a salt is a random value added to the password before hashing. This prevents rainbow table attacks (precomputed tables of hash values for common passwords). Each user gets a unique salt, so identical passwords produce different hashes. The salt is stored alongside the hash (not secret — its purpose is uniqueness, not secrecy).

2. Data Integrity / Checksums

Hashing is used to verify that data has not been corrupted or tampered with during transmission or storage:

  • The sender computes a hash of the data and sends both the data and the hash.
  • The receiver independently hashes the received data and compares it with the received hash.
  • If hashes match → data arrived intact. If hashes differ → data was corrupted or tampered with.
  • Examples: file downloads (SHA-256 checksum published alongside), ISO images, software releases.

3. Digital Signatures

As covered in 1.3.1b, a digital signature involves hashing the message and encrypting the hash with the sender's private key. The hash ensures that even small changes to the message are detected (due to the avalanche effect).

4. Hash Tables (Data Structure)

Hash functions are also used in hash tables (covered in 1.4.2e). A hash function maps a key to an index in an array, providing O(1) average-case lookup. This is a different application from cryptographic hashing.

Hashing vs Encryption — Key Differences

FeatureHashingEncryption
ReversibilityOne-way — CANNOT be reversedReversible — can decrypt with correct key
Output sizeFixed size regardless of inputOutput roughly same size as input
Key required?No key neededRequires a key (symmetric or asymmetric)
PurposeIntegrity checking, password storage, fingerprintingConfidentiality — keeping data secret
ExamplesSHA-256, MD5AES, RSA

Rainbow Table Attacks and Salting

A rainbow table is a precomputed database mapping common passwords to their hash values. An attacker who steals a password database can look up hashes to find the original passwords.

Salting defeats rainbow tables: by adding a unique random salt to each password before hashing, two users with the same password produce different hashes — so the attacker cannot use a precomputed table. They would have to brute-force each password individually.

  • Example without salt: password "letmein" always hashes to the same value — easily looked up in a rainbow table.
  • Example with salt: "letmein" + random salt "a8f3k9" → completely different hash; "letmein" + different salt "x7m2q1" → another different hash.
Exam tip: Know the key properties of hash functions: one-way (cannot reverse), fixed output size, deterministic, and avalanche effect (small input change → completely different hash). These are frequently examined.
Exam tip: Know WHY salting is used — it prevents rainbow table attacks by ensuring identical passwords produce different hashes for different users. State clearly: the salt is stored with the hash (not secret).
⚠ Common Mistakes
  • Saying hashing is the same as encryption — hashing is IRREVERSIBLE (one-way); encryption is REVERSIBLE with the correct key. Never say a hash can be 'decrypted'.
  • Saying the salt must be secret — the salt does NOT need to be kept secret. Its purpose is to make each hash unique, preventing rainbow tables. The salt is stored alongside the hash in the database.
  • Confusing a collision with the avalanche effect — a collision is two DIFFERENT inputs producing the SAME hash (bad — a weakness). The avalanche effect is a SMALL change to the input producing a COMPLETELY DIFFERENT hash (good — a desirable property).
✓ Notes completed!
Video coming soon
Click to advance · Arrow keys also work
Click slide or press arrow keys to navigate

Worksheet — 1.3.1c Hashing

8 questions · 20 marks · instantly marked

Q1State FOUR properties that a good cryptographic hash function must possess.[4 marks]
✓ Mark scheme
Any 4 from: deterministic — same input always produces same output [1]; fixed output size — output is always the same length regardless of input size [1]; one-way/pre-image resistant — computationally infeasible to reverse the hash to find the original input [1]; avalanche effect — a tiny change to the input produces a completely different hash [1]; collision resistant — computationally infeasible to find two different inputs that produce the same hash [1]; efficient — hash should be computed quickly [1].
Q2Explain how hashing is used to store passwords securely in a database. Include in your answer what is stored and what happens when a user logs in.[3 marks]
✓ Mark scheme
When a user sets a password, the system hashes it and stores only the hash in the database — the plaintext password is never stored [1]; when the user logs in, they enter their password; the system hashes the entered password and compares it with the stored hash [1]; if the hashes match, access is granted; if not, access is denied; even if the database is stolen, an attacker sees only hashes and cannot reverse them to get the original passwords [1].
Q3Explain what a 'rainbow table' attack is, and describe how 'salting' passwords prevents it.[4 marks]
✓ Mark scheme
A rainbow table is a precomputed database of hash values for many common passwords — an attacker who steals a hashed password database can look up the hash values in the table to identify the original password [1]; without salting, all users who share the same password produce the same hash — so one rainbow table lookup can crack many accounts [1]; salting: before hashing, a unique random value (the salt) is appended to each user's password; different users have different salts, so even identical passwords produce completely different hashes [1]; the attacker's rainbow table is useless because it was not computed with those specific salts — they would need to brute-force each password individually [1].
Q4Distinguish clearly between hashing and encryption. State three differences.[3 marks]
✓ Mark scheme
Any 3 from: reversibility — hashing is one-way (cannot be reversed to find input); encryption is reversible with the correct key [1]; key requirement — hashing requires no key; encryption requires a key (symmetric or asymmetric) [1]; output size — hashing always produces a fixed-length output regardless of input size; encryption output is proportional to input size [1]; purpose — hashing is used for integrity checking and password storage; encryption is used for confidentiality (keeping data secret) [1]; you cannot 'decrypt' a hash — but you can decrypt ciphertext [1].
Q5Describe how hashing is used to verify the integrity of a downloaded file.[3 marks]
✓ Mark scheme
The file creator computes a hash of the file (e.g. SHA-256) and publishes it alongside the download link [1]; after downloading, the user also computes the hash of the downloaded file using the same algorithm [1]; if the computed hash matches the published hash, the file is intact and unmodified; if the hashes differ, the file was corrupted during download or tampered with (e.g. replaced with malicious software) [1].
Q6What is the 'avalanche effect' in hashing? Why is this property important?[2 marks]
✓ Mark scheme
The avalanche effect means that even a tiny change to the input (e.g. changing a single character or bit) produces a completely different and seemingly random hash output — there is no discernible pattern between the two hashes [1]; this is important because it means an attacker cannot make small changes to the input and predict how the hash will change — they cannot use the hash to learn anything about the input, and any tampering with data will be immediately detected [1].
Q7Explain why storing passwords as MD5 hashes (without salting) is now considered insecure. Name TWO reasons.[2 marks]
✓ Mark scheme
Any 2 from: MD5 has known collision vulnerabilities — two different inputs have been found to produce the same MD5 hash, making it cryptographically broken [1]; without salting, all users with the same password produce identical MD5 hashes — a rainbow table attack can crack many accounts at once by looking up the hashes [1]; MD5 is fast to compute — attackers can run billions of hash attempts per second on modern GPUs, making brute-force and dictionary attacks feasible [1].
Q8SHA-256 is described as 'fixed output size'. What does this mean in practice, and why is this a useful property?[2 marks]
✓ Mark scheme
Fixed output size means SHA-256 always produces a 256-bit (64 hexadecimal character) hash regardless of input length — whether the input is a single character, a 1 GB video file, or a terabyte of data, the hash is always exactly 256 bits [1]; this is useful because it allows hashes to be compared in constant time and stored in a consistent, predictable space; it also means a hash cannot reveal the size or other properties of the original data [1].
Topic Quiz
1 of 15
You scored
out of 15
🎯

Mini Test — 1.3.1c Hashing

  • 10 questions · 10 marks · 10 minutes
  • 5 MCQ + 5 short answer
Card 1 of 15
Click to reveal
🎉
Complete!
TermDefinition
← 1.3.1b Encryption 1.3.1 Compression, Encryption and Hashing Next: 1.3.2a Relational Databases →
🔒
Pro Content
Subscribe to access all 69 OCR H446 A Level lessons.
£7.99/month
or £59/year
Subscribe now →