EN
Back to the archive

The encyclopedia · R&D & Science · Technical decision · 2007–2015

Keccak won the SHA-3 contest by being an open, royalty-free design NIST could verify

NIST ran a public hash competition and Keccak won on simplicity and cost, becoming the SHA-3 standard.

National Institute of Standards and Technology · Keccak Team · STMicroelectronics

the move

After attacks on SHA-1 and worries about SHA-2, NIST opened a hash-algorithm competition in 2007.

Any team could submit; the entries were public, and the cryptographic community attacked them for years.

Keccak, designed by two Belgian cryptographers, won on October 2, 2012 for its sponge construction, large security margin and simplicity.

NIST standardized it as FIPS 202 in 2015, and because the winner was open and royalty-free, adoption was never gated on licensing.

why it works

  • The contest was fully public, so the design was vetted by the whole world.
  • Keccak's sponge construction is simple and fast in both software and hardware.
  • The winning algorithm was royalty-free, so no one had to pay to use it.
  • Standardizing as FIPS 202 gave every vendor one reference to implement.
the payoffRun an open contest; pick the free, vetted designinspired

what transfers

When trust is the product, publish the contest and the design; public vetting and no royalties make adoption a foregone conclusion.

what came after

SHA-3 joined SHA-2 as a Federal standard (FIPS 202) and is used in TLS, blockchain and general-purpose hashing. It also seeded the Keccak team's authenticated-encryption schemes.

references

spotted an error? The archive wants to know.

same kind of clever