The Merkle-Damgard construction is a method for building a collision-resistant cryptographic hash function of arbitrary input length from a fixed-size, collision-resistant compression function, by padding the message and processing it in sequential blocks that chain into one another. SHA-256 and most other widely used hash functions of the SHA-1 and SHA-2 families are built on this construction. It is known to be vulnerable to length-extension attacks unless the hash output is further truncated or otherwise protected.

Provenance