Understanding Ethereum’s Two Hash Functions: OP_HASH160 vs OP_SHA256
The Ethereum blockchain uses two hash functions to store and verify transactions, each with its own strengths and weaknesses. In this article, we’ll look at the differences between OP_HASH160 and OP_SHA256, and when to use one over the other and in what situations.
What are hash functions?
Hash functions take input data of any size and produce a fixed-size string (or hash) that uniquely represents that data. In the context of Ethereum, both OP_HASH160 and OP_SHA256 are used for message authentication and data integrity.
OP_HASH160:
- Version: Introduced in BIP 0012
- Description: SHA-256 based hash function
- Key Features:
+ Uses a 20-byte (128-bit) input block
+ Signed with the private key using ECDSA (Elliptic Curve Digital Signature Algorithm)
+ More resistant to collisions and preimage attacks due to its fixed length
- Why use OP_HASH160?
- Higher Security: OP_HASH160 is more secure than OP_SHA256, making it a better choice for sensitive transactions.
- Easier to Implement: Since OP_HASH160 uses SHA-256, which has been widely adopted and understood, the implementation of OP_HASH160 is relatively simpler.
- Better Collision Resistance: Fixed length of 20 bytes provides stronger protection against attacks that attempt to alter the input data.
OP_SHA256:
- Version: Introduced in BIP 0013
- Description: Hash function based on SHA-256 (same as ECDSA)
- Key Features:
+ Uses variable length input block up to 32 bytes
+ Signed with private key via ECDSA
+ Less resistant to collisions and preimage attacks due to its dynamic length
- Why use OP_SHA256?
- Simplified Implementation: Since OP_SHA256 uses SHA-256, which is well established, implementing it can be simpler than OP_HASH160.
- Better resistance to preimage attacks: The variable-length input block provides stronger protection against attacks that attempt to alter input data.
When to use OP_HASH160:
- Sensitive transactions: When handling sensitive information, such as personal data or financial transactions, the increased security of OP_HASH160 is a better choice.
- Longer input blocks:
If you need to store longer input blocks (for example, larger data structures), the fixed length of OP_HASH160 provides stronger protection against collisions.
When to use OP_SHA256:
- Variable-length input: When handling variable-length input blocks, such as images or other media, OP_SHA256 is a better choice.
- Existing Infrastructure: If you are already using an existing infrastructure that relies on ECDSA (e.g. wallets, libraries), implementing OP_SHA256 can be easier.
Example Unlock Scripts:
Here are some examples of BIP 199 scripts that use both OP_HASH160 and OP_SHA256 for message authentication:
OP_HASH160:
contract Unlock(
bytes32 _input,
address _privateKey,
bytes _signature
) {
// Verify the signature using ECDSA (ECDSA is used here)
require ECDSAVerify(_signature, _privateKey, _input);
}
function _ecdsaVerify(byte memory _signature, address _privateKey, bytes32 _input) public {
// ... (ECDSA verification logic)
// Verify input via SHA-256
require Sha256(_input).equals(_signature);
}
OP_SHA256:
contract Unlock(
bytes32 _input,
address _privateKey,
bytes _signature
) {
// Signature verification via ECDSA (ECDSA is used here)
require ECDSAVerify(_signature, _privateKey, _input);
// Verify input via SHA-256
require Sha256(_input).equals(_signature);
}
In conclusion, while both OP_HASH160 and OP_SHA256 offer unique strengths and weaknesses, choosing between them depends on your specific use case.
