SHA-256 does bit append still required if input is already N x 512 bit?

Viewed 153

If my input is less than a multiple of 512 bit , i need to append bit and length bits to my input so that it is a multiple of 512 bit .
https://infosecwriteups.com/breaking-down-sha-256-algorithm-2ce61d86f7a3

But what if my input is already a multiple of 512 bit ? is it still required to do the bit append ? for example , if my message is already 512 bit long , do i need to bit append it to become 1024 bit long ?

And what if my input is less than a multiple of 512 bit , but long enough to not allow append length bits ? for example , my input is 504 bit long.

2 Answers

It seems to explain it rather clearly:

The number of bits we add is calculated as such so that after addition of these bits the length of the message should be exactly 64 bits less than a multiple of 512.

If there were 512 bits, you have to pad it to 960 bits, then add 64 bits for length for a total of 1024. The same with 504, since 504 > 512-64. Otherwise you'd have a situation where the last 64 bits are sometimes the length bits and sometimes not, which doesn't seem right.

The only case where you wouldn't add any padding is if the data is already 512*n-64, e.g. if it were 448 bits. Then you add no padding but still add the length bits, and end up with 512.

According to RFC 62634, you should always pad data with atleast one bit set to 1 and append length (64-bit).

Even if input is 448 bit long you should pad it resulting in two 512-bit chunks:

[448 bits of input]['1']['0' x 511][64 bits representing input length]

So this is wrong:

The only case where you wouldn't add any padding is if the data is already 512*n-64, e.g. if it were 448 bits. Then you add no padding but still add the length bits, and end up with 512.

Note: If you accept input only as byte array, minimum padding is 1 byte set to 10000000 (binary).

Related