Famiglia di hash standard. SHA-256 e superiori restano sicuri rispetto agli attacchi quantistici noti.
In sintesi
| Rischio quantistico | Resistente al quantum |
|---|
| Uso | Funzione di hash |
|---|
| Algoritmo post-quantistico | No |
|---|
Varianti e livello di sicurezza
| Variante | Sicurezza classica (bit) |
|---|
| SHA-224 | 112 |
| SHA-256 | 128 |
| SHA-384 | 192 |
| SHA-512 | 256 |
Posizioni e scadenze per autorità
| Autorità | Posizione | Decorrenza | Ambito | Dettagli |
|---|
| NIST | Accettabile | in vigore | tutte le varianti | |
| NSA (CNSA 2.0) | Raccomandato | in vigore | SHA-384, SHA-512 | CNSA 2.0 richiede SHA-384 o SHA-512. |
| NIST | Non consentito | dal 1 gennaio 2031 | SHA-224 | Hash a 224 bit non consentiti per applicare protezione dopo il 2030 (SP 800-131A Rev. 3, bozza). |
Fonti
- FIPS 180-4 — Secure Hash Standard (SHS) · NIST
- SP 800-131A Rev. 3 (Initial Public Draft) — Transitioning the Use of Cryptographic Algorithms and Key Lengths · NIST (bozza)
- CNSA 2.0 Algorithms (Cybersecurity Advisory) · NSA (raccomandazione)
Versione del catalogo: 2026-09-28. Ogni posizione rimanda alla fonte primaria; le bozze sono indicate come tali.