A Salt is a randomly generated value appended or prepended to input data before it is processed by a cryptographic hash function, ensuring that two identical inputs produce distinct hash outputs. Salts defeat precomputed dictionary and rainbow-table attacks on hashed credentials and commitments by making each hash unique even when the underlying plaintext is shared. In blockchain contexts, salts appear in commitment schemes, zero-knowledge proofs, and password-based key derivation functions, where they guarantee that a hash reveals no information about the original value to an observer who does not know the salt.

A Salt is a randomly generated value appended or prepended to input data before processing by a cryptographic hash function, ensuring that identical inputs produce distinct hash outputs. Salts defeat precomputed dictionary and rainbow-table attacks on hashed credentials and commitments.

Content

The threat model that motivates salt usage is straightforward. If a system stores unsalted password hashes, an attacker who obtains the hash database can compare each hash against a pre-built table of common password hashes (a rainbow table) and recover many passwords in seconds. By prepending a unique, randomly generated salt to each password before hashing, the attacker must compute a separate hash table for every distinct salt value, making precomputation attacks infeasible even for weak passwords.

In blockchain commitment schemes, a party wishing to commit to a value v without revealing it broadcasts H(v ∥ salt), where H is a collision-resistant hash function and salt is a large random value kept secret. Later, the party reveals both v and salt; any observer can verify the commitment by recomputing the hash. Without the salt, an attacker who knows the space of possible values could hash all candidates and compare against the commitment, breaking the hiding property.

Salt requirements vary by context. For password hashing, cryptographic standards such as NIST SP 800-63b recommend at least 32 bits of salt entropy generated by a cryptographically secure pseudorandom number generator, with each credential receiving a fresh, independent salt. For commitment schemes in zero-knowledge proof systems, 128–256 bits of salt are typical to maintain security commensurate with the hash function’s output size. For key derivation, PBKDF2 specifies at least 128-bit random salts per the recommendations of RFC 8018.

The term should be distinguished from a Nonce, which in proof-of-work mining is an incrementing counter iterated by miners seeking a valid block hash—a different primitive with a different threat model.

Provenance