SHAKE-256 Hash Conformance
Verifies that the Only OS hashing subsystem provides SHAKE-256 (SHA-3 Extendable-Output Function, NIST FIPS 202) as a quantum-resistant alternative to SHA-2. SHAKE-256 is required for DGV Level 3 post-quantum readiness and is used for commitment schemes in ML-DSA and ML-KEM. Two properties are tested: (1) determinism — the same input always produces the same digest, and (2) non-collision resistance — distinct inputs produce distinct digests.
Operational Purpose & Scope
Determinism: only-gate computes SHAKE-256 of the same input three times using the sha3 0.10 RustCrypto crate and verifies all outputs are identical. A non-deterministic hash function would fail this test.
Verification Context
- Target Scope:
Only OS hash computation path; FIPS 202 SHAKE-256 XOF; post-quantum hash primitive baseline - Audit Strategy:
exact-match - Verification Metrics:
hash_functionfips_202_compliantshake256_deterministicshake256_non_collision_confirmedall_digests_identicaldigests_differdigestdigest_1digest_2 - Framework Origin:DGV v0.5.0 Expansion
- Mandatory:Yes — must pass for certification
Governance Risk & Penalty
Expected Outcome
- pass:
true - gate_status:
"OPEN" - hash_function:
"SHAKE-256" - fips_202_compliant:
true - shake256_deterministic:
true - all_digests_identical:
true
Explore this card in 3D
Open DGV-TC-042 in the interactive scenario replay. This illustrates the test flow; it does not run the verifier or generate a cryptographic receipt.
Open DGV Live →